################################################################ # abuse.ch URLhaus IDS ruleset (Snort / Suricata) # # Last updated: 2026-10-10 10:51:17 (UTC) # # # # Terms Of Use: https://urlhaus.abuse.ch/api/ # # For questions please contact urlhaus [at] abuse.ch # ################################################################ # # url alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947460)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.97.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947460/; classtype:trojan-activity;sid:84810560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947459)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"77.79.160.210"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947459/; classtype:trojan-activity;sid:84810559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947458)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.239.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947458/; classtype:trojan-activity;sid:84810558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947457)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.250.127"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947457/; classtype:trojan-activity;sid:84810557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947456)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.10.133.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947456/; classtype:trojan-activity;sid:84810556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947455)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.189.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947455/; classtype:trojan-activity;sid:84810555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947454)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.42.81.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947454/; classtype:trojan-activity;sid:84810554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947453)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.4.108"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947453/; classtype:trojan-activity;sid:84810553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947452)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.114.33.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947452/; classtype:trojan-activity;sid:84810552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947449)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.240.218"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947449/; classtype:trojan-activity;sid:84810549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947450)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"63.245.153.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947450/; classtype:trojan-activity;sid:84810550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947451)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.245.62.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947451/; classtype:trojan-activity;sid:84810551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947448)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.156.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947448/; classtype:trojan-activity;sid:84810548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947447)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.105.74.195"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947447/; classtype:trojan-activity;sid:84810547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947446)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.102.102.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947446/; classtype:trojan-activity;sid:84810546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947444)"; flow:established,from_client; content:"GET"; http_method; content:"/tot"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947444/; classtype:trojan-activity;sid:84810544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947445)"; flow:established,from_client; content:"GET"; http_method; content:"/ezo"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"66.116.196.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947445/; classtype:trojan-activity;sid:84810545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947442)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.236.213.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947442/; classtype:trojan-activity;sid:84810542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947438)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"96.246.230.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947438/; classtype:trojan-activity;sid:84810538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947439)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"98.36.141.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947439/; classtype:trojan-activity;sid:84810539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947440)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.150.255.147"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947440/; classtype:trojan-activity;sid:84810540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947441)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"110.136.60.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947441/; classtype:trojan-activity;sid:84810541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947437)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.152.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947437/; classtype:trojan-activity;sid:84810537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947436)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.49.37"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947436/; classtype:trojan-activity;sid:84810536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947427)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.42.81.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947427/; classtype:trojan-activity;sid:84810527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947428)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.149.80.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947428/; classtype:trojan-activity;sid:84810528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947429)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.236.213.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947429/; classtype:trojan-activity;sid:84810529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947430)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.9.193.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947430/; classtype:trojan-activity;sid:84810530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947431)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.218.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947431/; classtype:trojan-activity;sid:84810531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947432)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.126.90"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947432/; classtype:trojan-activity;sid:84810532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947433)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.137.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947433/; classtype:trojan-activity;sid:84810533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947434)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.243.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947434/; classtype:trojan-activity;sid:84810534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947435)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.156.81.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947435/; classtype:trojan-activity;sid:84810535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947426)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"160.176.248.175"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947426/; classtype:trojan-activity;sid:84810526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947425)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.152.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947425/; classtype:trojan-activity;sid:84810525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947424)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.115.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947424/; classtype:trojan-activity;sid:84810524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947423)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.69.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947423/; classtype:trojan-activity;sid:84810523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947422)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.8.241"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947422/; classtype:trojan-activity;sid:84810522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947421)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.59.228.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947421/; classtype:trojan-activity;sid:84810521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947419)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.130.230.248"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947419/; classtype:trojan-activity;sid:84810519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947420)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.239.81.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947420/; classtype:trojan-activity;sid:84810520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947418)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.111.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947418/; classtype:trojan-activity;sid:84810518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947417)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.140.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947417/; classtype:trojan-activity;sid:84810517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947413)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.140.7.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947413/; classtype:trojan-activity;sid:84810513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947414)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947414/; classtype:trojan-activity;sid:84810514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947415)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.53.69.165"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947415/; classtype:trojan-activity;sid:84810515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947412)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.93.228.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947412/; classtype:trojan-activity;sid:84810512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947411)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.90.26.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947411/; classtype:trojan-activity;sid:84810511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947410)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.86.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947410/; classtype:trojan-activity;sid:84810510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947409)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.194.28.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947409/; classtype:trojan-activity;sid:84810509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947408)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.225.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947408/; classtype:trojan-activity;sid:84810508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947407)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947407/; classtype:trojan-activity;sid:84810507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947405)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.140.7.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947405/; classtype:trojan-activity;sid:84810505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947406)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.107.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947406/; classtype:trojan-activity;sid:84810506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947404)"; flow:established,from_client; content:"GET"; http_method; content:"/dl/thwin_ev.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"situations-clarity-pill-preceding.trycloudflare.com"; http_host; depth:51; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947404/; classtype:trojan-activity;sid:84810504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947403)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.49.52.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947403/; classtype:trojan-activity;sid:84810503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947402)"; flow:established,from_client; content:"GET"; http_method; content:"/st_x86_64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947402/; classtype:trojan-activity;sid:84810502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947401)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1558364083370074233/1558364277403033711/bundle_4.zip|3f|ex=6acb2b54|7c|26|7c|is=6ac9d9d4|7c|26|7c|hm=ffd2c51dd209735f2a2ccc8de812c0c0f8854b2babe383cab988e03265f1272f|7c|26|7c|"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947401/; classtype:trojan-activity;sid:84810501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947400)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.13.151.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947400/; classtype:trojan-activity;sid:84810500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947399)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.77.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947399/; classtype:trojan-activity;sid:84810499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947398)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.139.186.161"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947398/; classtype:trojan-activity;sid:84810498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947397)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.114.134.132"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947397/; classtype:trojan-activity;sid:84810497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947396)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.113.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947396/; classtype:trojan-activity;sid:84810496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947395)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.249.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947395/; classtype:trojan-activity;sid:84810495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947394)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.13.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947394/; classtype:trojan-activity;sid:84810494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947393)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.70.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947393/; classtype:trojan-activity;sid:84810493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947392)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.135.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947392/; classtype:trojan-activity;sid:84810492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947391)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.19.240.170"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947391/; classtype:trojan-activity;sid:84810491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947384)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_arc"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947384/; classtype:trojan-activity;sid:84810484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947385)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_arm"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947385/; classtype:trojan-activity;sid:84810485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947386)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_i586"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947386/; classtype:trojan-activity;sid:84810486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947387)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_arm6"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947387/; classtype:trojan-activity;sid:84810487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947388)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_i486"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947388/; classtype:trojan-activity;sid:84810488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947389)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_mpsl"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947389/; classtype:trojan-activity;sid:84810489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947390)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_arm64"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947390/; classtype:trojan-activity;sid:84810490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947377)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_arm7"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947377/; classtype:trojan-activity;sid:84810477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947378)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_x64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947378/; classtype:trojan-activity;sid:84810478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947379)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_ppc"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947379/; classtype:trojan-activity;sid:84810479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947380)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_sh4"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947380/; classtype:trojan-activity;sid:84810480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947381)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_riscv32"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947381/; classtype:trojan-activity;sid:84810481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947382)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_m68k"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947382/; classtype:trojan-activity;sid:84810482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947383)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_i686"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947383/; classtype:trojan-activity;sid:84810483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947372)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_riscv64"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947372/; classtype:trojan-activity;sid:84810472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947373)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_spc"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947373/; classtype:trojan-activity;sid:84810473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947374)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_mps64"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947374/; classtype:trojan-activity;sid:84810474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947375)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_arm5"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947375/; classtype:trojan-activity;sid:84810475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947376)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/android/akuma_mips"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947376/; classtype:trojan-activity;sid:84810476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947371)"; flow:established,from_client; content:"GET"; http_method; content:"/|3f|download=1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"videosnw-ru.vercel.app"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947371/; classtype:trojan-activity;sid:84810471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947369)"; flow:established,from_client; content:"GET"; http_method; content:"/|3f|download=1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"dttjjkkllzbvesjzndtp.vercel.app"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947369/; classtype:trojan-activity;sid:84810469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947370)"; flow:established,from_client; content:"GET"; http_method; content:"/|3f|download=1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"gibddru.vercel.app"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947370/; classtype:trojan-activity;sid:84810470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947368)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.168.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947368/; classtype:trojan-activity;sid:84810468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947367)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.240.194.49"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947367/; classtype:trojan-activity;sid:84810467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947366)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.76.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947366/; classtype:trojan-activity;sid:84810466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947365)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.214.23.166"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947365/; classtype:trojan-activity;sid:84810465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947355)"; flow:established,from_client; content:"GET"; http_method; content:"/rainii686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"191.44.114.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947355/; classtype:trojan-activity;sid:84810455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947356)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.92.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947356/; classtype:trojan-activity;sid:84810456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947357)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"201.159.91.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947357/; classtype:trojan-activity;sid:84810457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947348)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/vchxh1gexd1y52wjpyqtk/racingsimulator.zip|3f|rlkey=8bveooct7irzfn71nlpcthfxk|7c|26|7c|st=xnvu11qh|7c|26|7c|dl=1"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947348/; classtype:trojan-activity;sid:84810448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947347)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1554373007819014229/1558219073161138186/bundle1.zip|3f|ex=6acaa419|7c|26|7c|is=6ac95299|7c|26|7c|hm=fa6648fcec9a979c9d2264ff4bc3876e20722df68a2bcc323ae3486cbeff6f06|7c|26|7c|"; http_uri; depth:187; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947347/; classtype:trojan-activity;sid:84810447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947345)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557133169877192734/1558228090285465730/bundle.zip|3f|ex=6acaac7f|7c|26|7c|is=6ac95aff|7c|26|7c|hm=bb44fe8c4acac88ab665d8bc71152b3f45f31e3400264e1c65564af8e85f7d50|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947345/; classtype:trojan-activity;sid:84810445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947346)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1558076945571512441/1558250513563127869/bundle.zip|3f|ex=6acac161|7c|26|7c|is=6ac96fe1|7c|26|7c|hm=79b498e5eacc3b365af817340bee9189c40cc8f81e9918bef84d8302872abc83|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947346/; classtype:trojan-activity;sid:84810446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947344)"; flow:established,from_client; content:"GET"; http_method; content:"/0upm68k"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"45.198.224.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947344/; classtype:trojan-activity;sid:84810444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947337)"; flow:established,from_client; content:"GET"; http_method; content:"/0upppc"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.198.224.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947337/; classtype:trojan-activity;sid:84810437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947331)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947331/; classtype:trojan-activity;sid:84810431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947328)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/payloads/w.sh"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947328/; classtype:trojan-activity;sid:84810428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947329)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/payloads/c.sh"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947329/; classtype:trojan-activity;sid:84810429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947324)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.193.50.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947324/; classtype:trojan-activity;sid:84810424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947323)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.193.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947323/; classtype:trojan-activity;sid:84810423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947322)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.202.91.248"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947322/; classtype:trojan-activity;sid:84810422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947319)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.202.91.248"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947319/; classtype:trojan-activity;sid:84810419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947318)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.42.2"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947318/; classtype:trojan-activity;sid:84810418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947317)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.237.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947317/; classtype:trojan-activity;sid:84810417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947316)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.199.56.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947316/; classtype:trojan-activity;sid:84810416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947315)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.91.113.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947315/; classtype:trojan-activity;sid:84810415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947314)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947314/; classtype:trojan-activity;sid:84810414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947312)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.190.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947312/; classtype:trojan-activity;sid:84810412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947313)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.190.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947313/; classtype:trojan-activity;sid:84810413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947311)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.158.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947311/; classtype:trojan-activity;sid:84810411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947310)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.42.2"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947310/; classtype:trojan-activity;sid:84810410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947309)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.1.172"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947309/; classtype:trojan-activity;sid:84810409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947308)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.199.56.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947308/; classtype:trojan-activity;sid:84810408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947305)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.192.204.30"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947305/; classtype:trojan-activity;sid:84810405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947306)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.70.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947306/; classtype:trojan-activity;sid:84810406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947307)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.177.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947307/; classtype:trojan-activity;sid:84810407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947303)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.118.39.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947303/; classtype:trojan-activity;sid:84810403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947304)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.118.39.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947304/; classtype:trojan-activity;sid:84810404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947302)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.239.20.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947302/; classtype:trojan-activity;sid:84810402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947301)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.228.41.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947301/; classtype:trojan-activity;sid:84810401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947300)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.52.192.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947300/; classtype:trojan-activity;sid:84810400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947299)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.150.255.147"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947299/; classtype:trojan-activity;sid:84810399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947298)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.246.159.52"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947298/; classtype:trojan-activity;sid:84810398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947297)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.192.204.30"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947297/; classtype:trojan-activity;sid:84810397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947295)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.14.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947295/; classtype:trojan-activity;sid:84810395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947296)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.177.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947296/; classtype:trojan-activity;sid:84810396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947294)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947294/; classtype:trojan-activity;sid:84810394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947291)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.44.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947291/; classtype:trojan-activity;sid:84810391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947292)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.209.183.7"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947292/; classtype:trojan-activity;sid:84810392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947289)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.190.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947289/; classtype:trojan-activity;sid:84810389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947290)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.90.146.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947290/; classtype:trojan-activity;sid:84810390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947288)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.52.192.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947288/; classtype:trojan-activity;sid:84810388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947287)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.239.20.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947287/; classtype:trojan-activity;sid:84810387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947286)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947286/; classtype:trojan-activity;sid:84810386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947280)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947280/; classtype:trojan-activity;sid:84810380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947281)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947281/; classtype:trojan-activity;sid:84810381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947282)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947282/; classtype:trojan-activity;sid:84810382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947283)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947283/; classtype:trojan-activity;sid:84810383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947284)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947284/; classtype:trojan-activity;sid:84810384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947285)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947285/; classtype:trojan-activity;sid:84810385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947279)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.203.206.182"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947279/; classtype:trojan-activity;sid:84810379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947277)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.85.190.91"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947277/; classtype:trojan-activity;sid:84810377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947276)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.139.77.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947276/; classtype:trojan-activity;sid:84810376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947275)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.150.73"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947275/; classtype:trojan-activity;sid:84810375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947273)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.90.146.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947273/; classtype:trojan-activity;sid:84810373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947272)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947272/; classtype:trojan-activity;sid:84810372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947270)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"96.246.230.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947270/; classtype:trojan-activity;sid:84810370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947269)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.245.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947269/; classtype:trojan-activity;sid:84810369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947267)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.84.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947267/; classtype:trojan-activity;sid:84810367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947266)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.223.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947266/; classtype:trojan-activity;sid:84810366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947265)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.55.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947265/; classtype:trojan-activity;sid:84810365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947263)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.190.84.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947263/; classtype:trojan-activity;sid:84810363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947264)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.79.160.210"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947264/; classtype:trojan-activity;sid:84810364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947262)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.135.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947262/; classtype:trojan-activity;sid:84810362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947261)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.115.163.180"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947261/; classtype:trojan-activity;sid:84810361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947259)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.166.61.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947259/; classtype:trojan-activity;sid:84810359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947258)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.238.153"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947258/; classtype:trojan-activity;sid:84810358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947255)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.190.84.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947255/; classtype:trojan-activity;sid:84810355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947252)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.232.238.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947252/; classtype:trojan-activity;sid:84810352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947250)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.84.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947250/; classtype:trojan-activity;sid:84810350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.161.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947249/; classtype:trojan-activity;sid:84810349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.161.116.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947248/; classtype:trojan-activity;sid:84810348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947247)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.36.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947247/; classtype:trojan-activity;sid:84810347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947245)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.161.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947245/; classtype:trojan-activity;sid:84810345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947246)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.90.186.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947246/; classtype:trojan-activity;sid:84810346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947244)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.243.27"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947244/; classtype:trojan-activity;sid:84810344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947243)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947243/; classtype:trojan-activity;sid:84810343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947242)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.195"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947242/; classtype:trojan-activity;sid:84810342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947237)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.5.88.205"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947237/; classtype:trojan-activity;sid:84810337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947239)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.185.242.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947239/; classtype:trojan-activity;sid:84810339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947240)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.22.51.222"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947240/; classtype:trojan-activity;sid:84810340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947233)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.185.242.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947233/; classtype:trojan-activity;sid:84810333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947234)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.92.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947234/; classtype:trojan-activity;sid:84810334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947236)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.183.184.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947236/; classtype:trojan-activity;sid:84810336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947229)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.227.61.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947229/; classtype:trojan-activity;sid:84810329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947230)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.85.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947230/; classtype:trojan-activity;sid:84810330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947231)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.36.243.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947231/; classtype:trojan-activity;sid:84810331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947220)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.52.233.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947220/; classtype:trojan-activity;sid:84810320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947221)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.207.38.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947221/; classtype:trojan-activity;sid:84810321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947222)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.194.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947222/; classtype:trojan-activity;sid:84810322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947223)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.86.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947223/; classtype:trojan-activity;sid:84810323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947224)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.16.160"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947224/; classtype:trojan-activity;sid:84810324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947225)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.199.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947225/; classtype:trojan-activity;sid:84810325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947226)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.86.145.22"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947226/; classtype:trojan-activity;sid:84810326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947219)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.176.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947219/; classtype:trojan-activity;sid:84810319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947218)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.134.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947218/; classtype:trojan-activity;sid:84810318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947217)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.42.200.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_10; reference:url, urlhaus.abuse.ch/url/3947217/; classtype:trojan-activity;sid:84810317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947214)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.155.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947214/; classtype:trojan-activity;sid:84810314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947213)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.8.241"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947213/; classtype:trojan-activity;sid:84810313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947212)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.227.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947212/; classtype:trojan-activity;sid:84810312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947210)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.25.109.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947210/; classtype:trojan-activity;sid:84810310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947211)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.104.214.25"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947211/; classtype:trojan-activity;sid:84810311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947208)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.162.76"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947208/; classtype:trojan-activity;sid:84810308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947209)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.143.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947209/; classtype:trojan-activity;sid:84810309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947207)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.4.232.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947207/; classtype:trojan-activity;sid:84810307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947206)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.204.7"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947206/; classtype:trojan-activity;sid:84810306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947205)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.202.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947205/; classtype:trojan-activity;sid:84810305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947204)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.148.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947204/; classtype:trojan-activity;sid:84810304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947200)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.139.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947200/; classtype:trojan-activity;sid:84810300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947201)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.1"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947201/; classtype:trojan-activity;sid:84810301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947202)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.139.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947202/; classtype:trojan-activity;sid:84810302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947203)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.47.191"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947203/; classtype:trojan-activity;sid:84810303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947199)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.1"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947199/; classtype:trojan-activity;sid:84810299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947197)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.54.57.22"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947197/; classtype:trojan-activity;sid:84810297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947198)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.92.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947198/; classtype:trojan-activity;sid:84810298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947196)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.200.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947196/; classtype:trojan-activity;sid:84810296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947195)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.23.127.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947195/; classtype:trojan-activity;sid:84810295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947194)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.148.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947194/; classtype:trojan-activity;sid:84810294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947192)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.38.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947192/; classtype:trojan-activity;sid:84810292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947193)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.148.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947193/; classtype:trojan-activity;sid:84810293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947185)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.190.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947185/; classtype:trojan-activity;sid:84810285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947186)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.194.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947186/; classtype:trojan-activity;sid:84810286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947187)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.202.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947187/; classtype:trojan-activity;sid:84810287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947188)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.69.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947188/; classtype:trojan-activity;sid:84810288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.249.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947189/; classtype:trojan-activity;sid:84810289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947190)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.235.86.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947190/; classtype:trojan-activity;sid:84810290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947191)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.218.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947191/; classtype:trojan-activity;sid:84810291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947184)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.127.20"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947184/; classtype:trojan-activity;sid:84810284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947183)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_4b6b014c4c8f9ec9.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947183/; classtype:trojan-activity;sid:84810283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947182)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.238.123.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947182/; classtype:trojan-activity;sid:84810282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947181)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.238.123.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947181/; classtype:trojan-activity;sid:84810281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947180)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.253.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947180/; classtype:trojan-activity;sid:84810280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947175)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.228.53"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947175/; classtype:trojan-activity;sid:84810275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947176)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.223.128.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947176/; classtype:trojan-activity;sid:84810276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947177)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.228.53"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947177/; classtype:trojan-activity;sid:84810277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947178)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.141.147.7"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947178/; classtype:trojan-activity;sid:84810278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947179)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.33.248"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947179/; classtype:trojan-activity;sid:84810279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947173)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.59.247.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947173/; classtype:trojan-activity;sid:84810273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947174)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.60.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947174/; classtype:trojan-activity;sid:84810274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947172)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.206.171.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947172/; classtype:trojan-activity;sid:84810272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947171)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"121.202.142.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947171/; classtype:trojan-activity;sid:84810271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947170)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.138.25"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947170/; classtype:trojan-activity;sid:84810270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.153.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947169/; classtype:trojan-activity;sid:84810269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947167)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.146.225.101"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947167/; classtype:trojan-activity;sid:84810267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947168)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.153.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947168/; classtype:trojan-activity;sid:84810268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947166)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.7.222.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947166/; classtype:trojan-activity;sid:84810266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947165)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.10.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947165/; classtype:trojan-activity;sid:84810265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947164)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.86.145.22"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947164/; classtype:trojan-activity;sid:84810264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947161)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.51.222"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947161/; classtype:trojan-activity;sid:84810261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947162)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.156.89"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947162/; classtype:trojan-activity;sid:84810262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947163)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.185.150.241"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947163/; classtype:trojan-activity;sid:84810263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947160)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.89.252.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947160/; classtype:trojan-activity;sid:84810260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947159)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.89.252.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947159/; classtype:trojan-activity;sid:84810259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947153)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947153/; classtype:trojan-activity;sid:84810253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947154)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947154/; classtype:trojan-activity;sid:84810254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947155)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947155/; classtype:trojan-activity;sid:84810255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947156)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947156/; classtype:trojan-activity;sid:84810256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947157)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947157/; classtype:trojan-activity;sid:84810257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947158)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947158/; classtype:trojan-activity;sid:84810258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947151)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.25.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947151/; classtype:trojan-activity;sid:84810251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947152)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.220.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947152/; classtype:trojan-activity;sid:84810252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947147)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.38.158.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947147/; classtype:trojan-activity;sid:84810247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947148)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.20.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947148/; classtype:trojan-activity;sid:84810248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947149)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.41.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947149/; classtype:trojan-activity;sid:84810249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947150)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.223.128.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947150/; classtype:trojan-activity;sid:84810250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947146)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.111.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947146/; classtype:trojan-activity;sid:84810246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947145)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.76.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947145/; classtype:trojan-activity;sid:84810245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947144)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.215.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947144/; classtype:trojan-activity;sid:84810244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947143)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.93.49"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947143/; classtype:trojan-activity;sid:84810243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947142)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.41.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947142/; classtype:trojan-activity;sid:84810242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947141)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.118.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947141/; classtype:trojan-activity;sid:84810241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947140)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/6fb78459bea435c0_remus.exe"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947140/; classtype:trojan-activity;sid:84810240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947138)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.228.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947138/; classtype:trojan-activity;sid:84810238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947139)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.47.191"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947139/; classtype:trojan-activity;sid:84810239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947137)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.44.200"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947137/; classtype:trojan-activity;sid:84810237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947136)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_b3cc296623105902.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947136/; classtype:trojan-activity;sid:84810236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947135)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.168.237.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947135/; classtype:trojan-activity;sid:84810235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947134)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.168.237.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947134/; classtype:trojan-activity;sid:84810234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947133)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/4e984c028b501402_pyinfector.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947133/; classtype:trojan-activity;sid:84810233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947132)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.142.92"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947132/; classtype:trojan-activity;sid:84810232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947131)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.4.232.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947131/; classtype:trojan-activity;sid:84810231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947130)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/6cbea551e8cbc1bb_global_8668.3380.0.0_install.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947130/; classtype:trojan-activity;sid:84810230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947129)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/cc58391f679b5479_cryptoclipper.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947129/; classtype:trojan-activity;sid:84810229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947128)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.223.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947128/; classtype:trojan-activity;sid:84810228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947127)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.186.189"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947127/; classtype:trojan-activity;sid:84810227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947126)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_50f8dc1f79af08b7.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947126/; classtype:trojan-activity;sid:84810226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947125)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.142.92"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947125/; classtype:trojan-activity;sid:84810225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947124)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.81.239.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947124/; classtype:trojan-activity;sid:84810224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947121)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.228.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947121/; classtype:trojan-activity;sid:84810221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947122)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.47.113.53"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947122/; classtype:trojan-activity;sid:84810222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947123)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.254.10.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947123/; classtype:trojan-activity;sid:84810223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947119)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"130.0.43.154"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947119/; classtype:trojan-activity;sid:84810219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947120)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.31.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947120/; classtype:trojan-activity;sid:84810220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947118)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947118/; classtype:trojan-activity;sid:84810218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947117)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.115.65.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947117/; classtype:trojan-activity;sid:84810217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947116)"; flow:established,from_client; content:"GET"; http_method; content:"/phil/pdmjhdk.txt"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"www.tmcksa.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947116/; classtype:trojan-activity;sid:84810216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947115)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.200.81"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947115/; classtype:trojan-activity;sid:84810215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947114)"; flow:established,from_client; content:"GET"; http_method; content:"/new/odirrbk.txt"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"www.tmcksa.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947114/; classtype:trojan-activity;sid:84810214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947113)"; flow:established,from_client; content:"GET"; http_method; content:"/img/2.jpg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.224.17.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947113/; classtype:trojan-activity;sid:84810213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947112)"; flow:established,from_client; content:"GET"; http_method; content:"/2.jpg"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"107.173.227.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947112/; classtype:trojan-activity;sid:84810212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947111)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"216.126.80.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947111/; classtype:trojan-activity;sid:84810211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947110)"; flow:established,from_client; content:"GET"; http_method; content:"/img_191633.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"micstndasap.world"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947110/; classtype:trojan-activity;sid:84810210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947109)"; flow:established,from_client; content:"GET"; http_method; content:"/uu49yjw5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"micstndasap.world"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947109/; classtype:trojan-activity;sid:84810209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947108)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_194218.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947108/; classtype:trojan-activity;sid:84810208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947107)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_uzcqfkdbh4wncf92tw54h57khybkee4"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947107/; classtype:trojan-activity;sid:84810207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947105)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.123.192.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947105/; classtype:trojan-activity;sid:84810205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947106)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.126.201.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947106/; classtype:trojan-activity;sid:84810206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947104)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/588751559681376259/1558186147249922178/bundle_3.zip|3f|ex=6aca856f|7c|26|7c|is=6ac933ef|7c|26|7c|hm=caed6be90052bcc12e387eec9349a1d023e94c865e2da5a9964d07bad665b617|7c|26|7c|"; http_uri; depth:187; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947104/; classtype:trojan-activity;sid:84810204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947102)"; flow:established,from_client; content:"GET"; http_method; content:"/3pnxr9p2"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947102/; classtype:trojan-activity;sid:84810202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947103)"; flow:established,from_client; content:"GET"; http_method; content:"/img_002333.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947103/; classtype:trojan-activity;sid:84810203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947101)"; flow:established,from_client; content:"GET"; http_method; content:"/img_005350.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947101/; classtype:trojan-activity;sid:84810201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947099)"; flow:established,from_client; content:"GET"; http_method; content:"/q196t8mz"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947099/; classtype:trojan-activity;sid:84810199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947100)"; flow:established,from_client; content:"GET"; http_method; content:"/07j45qil"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947100/; classtype:trojan-activity;sid:84810200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947097)"; flow:established,from_client; content:"GET"; http_method; content:"/nine23423423/fbi-openup/raw/refs/heads/main/servicemanager.exe"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947097/; classtype:trojan-activity;sid:84810197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947098)"; flow:established,from_client; content:"GET"; http_method; content:"/nine23423423/reload1/raw/refs/heads/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947098/; classtype:trojan-activity;sid:84810198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947096)"; flow:established,from_client; content:"GET"; http_method; content:"/nine23423423/reload1/raw/refs/heads/main/rtkauduservice.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947096/; classtype:trojan-activity;sid:84810196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947095)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.226.200.81"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947095/; classtype:trojan-activity;sid:84810195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947093)"; flow:established,from_client; content:"GET"; http_method; content:"/szvazo0m"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947093/; classtype:trojan-activity;sid:84810193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947094)"; flow:established,from_client; content:"GET"; http_method; content:"/img_010548.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"tronzadorasnng.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947094/; classtype:trojan-activity;sid:84810194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947091)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.200.85"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947091/; classtype:trojan-activity;sid:84810191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947092)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.155.201.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947092/; classtype:trojan-activity;sid:84810192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947090)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.232.179.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947090/; classtype:trojan-activity;sid:84810190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947089)"; flow:established,from_client; content:"GET"; http_method; content:"/api/public/download/downloads/1791496929044-deathboundcraft.jar"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"deathboundcraft.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947089/; classtype:trojan-activity;sid:84810189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947088)"; flow:established,from_client; content:"GET"; http_method; content:"/femboy.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"156.226.174.251"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947088/; classtype:trojan-activity;sid:84810188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947087)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/telnet/wget.sh"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947087/; classtype:trojan-activity;sid:84810187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947086)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1553488282396926035/1558148289726124083/bundle_4.zip|3f|ex=6aca622d|7c|26|7c|is=6ac910ad|7c|26|7c|hm=a29f02ede4160432f5f0b145316bb617b54a372d514d06fa425c725e81f9d366|7c|26|7c|"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947086/; classtype:trojan-activity;sid:84810186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947085)"; flow:established,from_client; content:"GET"; http_method; content:"/7c961ce9-af0a-499d-ae15-a860978354a0/dupe-mod_1.0.0_0.jar|3f|download=true"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"filegoat.s3.de.io.cloud.ovh.net"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947085/; classtype:trojan-activity;sid:84810185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947084)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"natashamohan.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947084/; classtype:trojan-activity;sid:84810184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947082)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/payloads//wget.sh"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947082/; classtype:trojan-activity;sid:84810182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947083)"; flow:established,from_client; content:"GET"; http_method; content:"/dep_kr29.sh"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947083/; classtype:trojan-activity;sid:84810183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947080)"; flow:established,from_client; content:"GET"; http_method; content:"/cap/chored.cur"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"briannacorporation.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947080/; classtype:trojan-activity;sid:84810180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947081)"; flow:established,from_client; content:"GET"; http_method; content:"/cap/ezlhodowq46.bin"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"briannacorporation.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947081/; classtype:trojan-activity;sid:84810181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947079)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"212.54.86.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947079/; classtype:trojan-activity;sid:84810179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947078)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.237.2.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947078/; classtype:trojan-activity;sid:84810178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947077)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.202.215.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947077/; classtype:trojan-activity;sid:84810177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947076)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.28.39.38"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947076/; classtype:trojan-activity;sid:84810176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947075)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.88.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947075/; classtype:trojan-activity;sid:84810175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947072)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"78.188.196.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947072/; classtype:trojan-activity;sid:84810172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947073)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.4.108"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947073/; classtype:trojan-activity;sid:84810173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947074)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.140.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947074/; classtype:trojan-activity;sid:84810174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947071)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.226.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947071/; classtype:trojan-activity;sid:84810171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947070)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.9.150"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947070/; classtype:trojan-activity;sid:84810170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947069)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.238.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947069/; classtype:trojan-activity;sid:84810169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947068)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.233.55.80"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947068/; classtype:trojan-activity;sid:84810168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947067)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.229.115"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947067/; classtype:trojan-activity;sid:84810167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947066)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.59.115.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947066/; classtype:trojan-activity;sid:84810166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947065)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.164.23.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947065/; classtype:trojan-activity;sid:84810165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947063)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.1.246.222"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947063/; classtype:trojan-activity;sid:84810163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947064)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.41.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947064/; classtype:trojan-activity;sid:84810164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947062)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.6.71.251"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947062/; classtype:trojan-activity;sid:84810162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947060)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.238.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947060/; classtype:trojan-activity;sid:84810160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947061)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.179.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947061/; classtype:trojan-activity;sid:84810161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947059)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.253.32"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947059/; classtype:trojan-activity;sid:84810159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947058)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.53.2.94"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947058/; classtype:trojan-activity;sid:84810158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947057)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.1.204"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947057/; classtype:trojan-activity;sid:84810157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947056)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.90.26.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947056/; classtype:trojan-activity;sid:84810156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947055)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.137.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947055/; classtype:trojan-activity;sid:84810155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947051)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.179.167.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947051/; classtype:trojan-activity;sid:84810151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947052)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.171.252"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947052/; classtype:trojan-activity;sid:84810152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947053)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.194.57.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947053/; classtype:trojan-activity;sid:84810153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947054)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.194.57.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947054/; classtype:trojan-activity;sid:84810154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947050)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.236.44.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947050/; classtype:trojan-activity;sid:84810150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947049)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.113.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947049/; classtype:trojan-activity;sid:84810149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947048)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.59.115.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947048/; classtype:trojan-activity;sid:84810148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947047)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.236.44.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947047/; classtype:trojan-activity;sid:84810147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947046)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_8dece6c27473f5d2.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947046/; classtype:trojan-activity;sid:84810146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947044)"; flow:established,from_client; content:"GET"; http_method; content:"/goxlr.zip"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"downloads.go-xlr.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947044/; classtype:trojan-activity;sid:84810144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947045)"; flow:established,from_client; content:"GET"; http_method; content:"/download/winhost"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"hardwood-studio-obviously-briefing.trycloudflare.com"; http_host; depth:52; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947045/; classtype:trojan-activity;sid:84810145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947043)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.149.88.179"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947043/; classtype:trojan-activity;sid:84810143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947042)"; flow:established,from_client; content:"GET"; http_method; content:"/riddents/eulencheats/raw/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947042/; classtype:trojan-activity;sid:84810142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947041)"; flow:established,from_client; content:"GET"; http_method; content:"/wakkaflipps/fivem-server-unban/raw/head/silentum_spoofer.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947041/; classtype:trojan-activity;sid:84810141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947040)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyraws/roblox-script-executor/raw/head/wave.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947040/; classtype:trojan-activity;sid:84810140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947038)"; flow:established,from_client; content:"GET"; http_method; content:"/washington0812/fivem-spoofer/raw/head/cfxbypass.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947038/; classtype:trojan-activity;sid:84810138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947039)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/f9xcikvn08lnp7oscsr8d/bundle.zip|3f|rlkey=jbzk4as9yhesbvbdqaz26u0hz|7c|26|7c|st=pb9wyr3r|7c|26|7c|dl=1"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947039/; classtype:trojan-activity;sid:84810139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947032)"; flow:established,from_client; content:"GET"; http_method; content:"/stehts/eulencheats/raw/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947032/; classtype:trojan-activity;sid:84810132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947033)"; flow:established,from_client; content:"GET"; http_method; content:"/sfbbbvp9pg-cpu/swift-executor/raw/head/swift.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947033/; classtype:trojan-activity;sid:84810133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947034)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947034/; classtype:trojan-activity;sid:84810134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947035)"; flow:established,from_client; content:"GET"; http_method; content:"/stellacriss/eulencheats/raw/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947035/; classtype:trojan-activity;sid:84810135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947036)"; flow:established,from_client; content:"GET"; http_method; content:"/vall3stecch/eulencheats/raw/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947036/; classtype:trojan-activity;sid:84810136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947037)"; flow:established,from_client; content:"GET"; http_method; content:"/shademilliage/roblox-script-executor/raw/head/wave.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947037/; classtype:trojan-activity;sid:84810137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947031)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1558114186817437841/1558114355260948561/bundle.zip|3f|ex=6aca4292|7c|26|7c|is=6ac8f112|7c|26|7c|hm=e36aabee94a40f1c93398f5708dd71cd89f70a2b2e4f0233028f00621b5a5f2e|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947031/; classtype:trojan-activity;sid:84810131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947030)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1558090546633904308/1558090607027683399/bundle.zip|3f|ex=6aca2c74|7c|26|7c|is=6ac8daf4|7c|26|7c|hm=f368654270984309f3f052b7969d1fdafb6fb00f448a68614de3746823cc20a4|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947030/; classtype:trojan-activity;sid:84810130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947029)"; flow:established,from_client; content:"GET"; http_method; content:"/lanferry/fivem-server-unban/raw/head/silentum_spoofer.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947029/; classtype:trojan-activity;sid:84810129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947028)"; flow:established,from_client; content:"GET"; http_method; content:"/roverles/fivem-server-unban/raw/head/silentum_spoofer.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947028/; classtype:trojan-activity;sid:84810128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947021)"; flow:established,from_client; content:"GET"; http_method; content:"/archcalls/fivem-server-unban/raw/head/silentum_spoofer.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947021/; classtype:trojan-activity;sid:84810121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947022)"; flow:established,from_client; content:"GET"; http_method; content:"/hennisle/eulencheats/raw/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947022/; classtype:trojan-activity;sid:84810122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947023)"; flow:established,from_client; content:"GET"; http_method; content:"/chamysooel/fivem-server-unban/raw/head/silentum_spoofer.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947023/; classtype:trojan-activity;sid:84810123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947024)"; flow:established,from_client; content:"GET"; http_method; content:"/sevv1lsy/eulencheats/raw/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947024/; classtype:trojan-activity;sid:84810124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947025)"; flow:established,from_client; content:"GET"; http_method; content:"/elchapogta/redengine-fivem/raw/head/license.dll"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947025/; classtype:trojan-activity;sid:84810125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947026)"; flow:established,from_client; content:"GET"; http_method; content:"/blestoff/monotone-hwid-spoofer/raw/head/monotone.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947026/; classtype:trojan-activity;sid:84810126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947027)"; flow:established,from_client; content:"GET"; http_method; content:"/l3mmn1ia/temp-spoofer-lifetime/raw/head/tempspoofer.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947027/; classtype:trojan-activity;sid:84810127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947009)"; flow:established,from_client; content:"GET"; http_method; content:"/candyblow/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947009/; classtype:trojan-activity;sid:84810109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947010)"; flow:established,from_client; content:"GET"; http_method; content:"/mineslance/eulencheats/raw/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947010/; classtype:trojan-activity;sid:84810110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947011)"; flow:established,from_client; content:"GET"; http_method; content:"/cansiorly/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947011/; classtype:trojan-activity;sid:84810111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947012)"; flow:established,from_client; content:"GET"; http_method; content:"/gratelond/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947012/; classtype:trojan-activity;sid:84810112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947013)"; flow:established,from_client; content:"GET"; http_method; content:"/derrixhan/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947013/; classtype:trojan-activity;sid:84810113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947014)"; flow:established,from_client; content:"GET"; http_method; content:"/archrace/fivem-server-unban/raw/head/silentum_spoofer.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947014/; classtype:trojan-activity;sid:84810114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947015)"; flow:established,from_client; content:"GET"; http_method; content:"/deelcis/roblox-script-executor/raw/head/wave.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947015/; classtype:trojan-activity;sid:84810115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947016)"; flow:established,from_client; content:"GET"; http_method; content:"/clatths/eulencheats/raw/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947016/; classtype:trojan-activity;sid:84810116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947017)"; flow:established,from_client; content:"GET"; http_method; content:"/mentall1s/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947017/; classtype:trojan-activity;sid:84810117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947018)"; flow:established,from_client; content:"GET"; http_method; content:"/lannher/eulencheats/raw/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947018/; classtype:trojan-activity;sid:84810118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947019)"; flow:established,from_client; content:"GET"; http_method; content:"/lierghs/eulencheats/raw/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947019/; classtype:trojan-activity;sid:84810119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947020)"; flow:established,from_client; content:"GET"; http_method; content:"/bonnylith/roblox-script-executor/raw/head/wave.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947020/; classtype:trojan-activity;sid:84810120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947000)"; flow:established,from_client; content:"GET"; http_method; content:"/aerosteeld/eulencheats/raw/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947000/; classtype:trojan-activity;sid:84810100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947001)"; flow:established,from_client; content:"GET"; http_method; content:"/enzowipe/eulencheats/raw/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947001/; classtype:trojan-activity;sid:84810101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947002)"; flow:established,from_client; content:"GET"; http_method; content:"/limmadays/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947002/; classtype:trojan-activity;sid:84810102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947003)"; flow:established,from_client; content:"GET"; http_method; content:"/adapp1t/eulencheats/raw/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947003/; classtype:trojan-activity;sid:84810103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947004)"; flow:established,from_client; content:"GET"; http_method; content:"/champywiss/roblox-script-executor/raw/head/wave.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947004/; classtype:trojan-activity;sid:84810104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947005)"; flow:established,from_client; content:"GET"; http_method; content:"/artlims/eulencheats/raw/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947005/; classtype:trojan-activity;sid:84810105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947006)"; flow:established,from_client; content:"GET"; http_method; content:"/download/epsi"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"emphasis-friday-even-administrator.trycloudflare.com"; http_host; depth:52; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947006/; classtype:trojan-activity;sid:84810106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947007)"; flow:established,from_client; content:"GET"; http_method; content:"/cassiefinney/roblox-script-executor/raw/head/wave.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947007/; classtype:trojan-activity;sid:84810107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3947008)"; flow:established,from_client; content:"GET"; http_method; content:"/dirlands/eulencheats/raw/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3947008/; classtype:trojan-activity;sid:84810108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946997)"; flow:established,from_client; content:"GET"; http_method; content:"/hannertmax/eulencheats/raw/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946997/; classtype:trojan-activity;sid:84810097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946998)"; flow:established,from_client; content:"GET"; http_method; content:"/rarr1ve/eulencheats/raw/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946998/; classtype:trojan-activity;sid:84810098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946999)"; flow:established,from_client; content:"GET"; http_method; content:"/fansyhook/eulencheats/raw/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946999/; classtype:trojan-activity;sid:84810099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946996)"; flow:established,from_client; content:"GET"; http_method; content:"/download/winhost"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"duo-strengthening-essex-ian.trycloudflare.com"; http_host; depth:45; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946996/; classtype:trojan-activity;sid:84810096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946994)"; flow:established,from_client; content:"GET"; http_method; content:"/download/rvxupdate"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"surround-tough-method-zinc.trycloudflare.com"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946994/; classtype:trojan-activity;sid:84810094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946995)"; flow:established,from_client; content:"GET"; http_method; content:"/download/extupdate"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"surround-tough-method-zinc.trycloudflare.com"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946995/; classtype:trojan-activity;sid:84810095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946992)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.115.166.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946992/; classtype:trojan-activity;sid:84810092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946993)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.35.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946993/; classtype:trojan-activity;sid:84810093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946990)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.237.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946990/; classtype:trojan-activity;sid:84810090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946991)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.36.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946991/; classtype:trojan-activity;sid:84810091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946988)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"95.15.69.204"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946988/; classtype:trojan-activity;sid:84810088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946989)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.15.69.204"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946989/; classtype:trojan-activity;sid:84810089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946987)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.90.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946987/; classtype:trojan-activity;sid:84810087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946986)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946986/; classtype:trojan-activity;sid:84810086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946985)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946985/; classtype:trojan-activity;sid:84810085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946980)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946980/; classtype:trojan-activity;sid:84810080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946981)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946981/; classtype:trojan-activity;sid:84810081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946982)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946982/; classtype:trojan-activity;sid:84810082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946983)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946983/; classtype:trojan-activity;sid:84810083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946984)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946984/; classtype:trojan-activity;sid:84810084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946979)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946979/; classtype:trojan-activity;sid:84810079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946978)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.201.171.252"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946978/; classtype:trojan-activity;sid:84810078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946975)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946975/; classtype:trojan-activity;sid:84810075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946976)"; flow:established,from_client; content:"GET"; http_method; content:"/x86-64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946976/; classtype:trojan-activity;sid:84810076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946977)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946977/; classtype:trojan-activity;sid:84810077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946972)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946972/; classtype:trojan-activity;sid:84810072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946973)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946973/; classtype:trojan-activity;sid:84810073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946974)"; flow:established,from_client; content:"GET"; http_method; content:"/arm4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946974/; classtype:trojan-activity;sid:84810074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946969)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946969/; classtype:trojan-activity;sid:84810069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946970)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946970/; classtype:trojan-activity;sid:84810070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946971)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946971/; classtype:trojan-activity;sid:84810071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946968)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.148.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946968/; classtype:trojan-activity;sid:84810068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946967)"; flow:established,from_client; content:"GET"; http_method; content:"/karinatt0/file/d5c3219dfcec05e58843f4c4b6e5bd78cbed634d/img_053520.png"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946967/; classtype:trojan-activity;sid:84810067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946966)"; flow:established,from_client; content:"GET"; http_method; content:"/karinatt0/file/d5c3219dfcec05e58843f4c4b6e5bd78cbed634d/img_065109.png"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946966/; classtype:trojan-activity;sid:84810066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946965)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.185.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946965/; classtype:trojan-activity;sid:84810065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946964)"; flow:established,from_client; content:"GET"; http_method; content:"/karinatt0/file/d5c3219dfcec05e58843f4c4b6e5bd78cbed634d/img_015611.png"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946964/; classtype:trojan-activity;sid:84810064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946963)"; flow:established,from_client; content:"GET"; http_method; content:"/dxnobk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946963/; classtype:trojan-activity;sid:84810063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946962)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946962/; classtype:trojan-activity;sid:84810062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946960)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.81.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946960/; classtype:trojan-activity;sid:84810060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946961)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.239.81.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946961/; classtype:trojan-activity;sid:84810061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946959)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.76.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946959/; classtype:trojan-activity;sid:84810059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946958)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.96.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946958/; classtype:trojan-activity;sid:84810058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946957)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.206.139.244"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946957/; classtype:trojan-activity;sid:84810057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946956)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/osoxrcdabdbir95t2nroe/bundle.zip|3f|rlkey=1yutmbqxcbs1xrqzqgvcxiu3j|7c|26|7c|st=xwbjhv80|7c|26|7c|dl=1"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946956/; classtype:trojan-activity;sid:84810056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946955)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/sxgw5icz1z9uybznqkrys/bundle.zip|3f|rlkey=5h9pn4ve617fzmcyzogt45xtx|7c|26|7c|st=kvy82hgi|7c|26|7c|dl=1"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946955/; classtype:trojan-activity;sid:84810055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946954)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/73j5kqqa8g7karyf1pl2f/bundle.zip|3f|rlkey=jj0d9efhorrjzys39jw7nuz2t|7c|26|7c|st=3yj3q2ti|7c|26|7c|dl=1"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946954/; classtype:trojan-activity;sid:84810054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946953)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557133169877192734/1557824344401387601/bundle.zip|3f|ex=6ac9347a|7c|26|7c|is=6ac7e2fa|7c|26|7c|hm=2a5f26806d9c70a78cb91291d892ac9e9bc378a37ecbe88088c3af02e6eac519|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946953/; classtype:trojan-activity;sid:84810053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946951)"; flow:established,from_client; content:"GET"; http_method; content:"/osmb.jar"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"www.osmb.net"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946951/; classtype:trojan-activity;sid:84810051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946952)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557944891575762984/1557945395277996133/bundle_2.zip|3f|ex=6ac9a537|7c|26|7c|is=6ac853b7|7c|26|7c|hm=6437d45cffc49ae16bc731d5aa1a09e76f71e006877171928c5be1ab33ccb6a5|7c|26|7c|"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946952/; classtype:trojan-activity;sid:84810052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946948)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1555273446441881600/1558075552412344351/bundle_1.zip|3f|ex=6aca1e6f|7c|26|7c|is=6ac8ccef|7c|26|7c|hm=c693cad9ae038f0226317909a6df51d7dc5c389429612a19c970e648b9d18a57|7c|26|7c|"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946948/; classtype:trojan-activity;sid:84810048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946949)"; flow:established,from_client; content:"GET"; http_method; content:"/mindgone/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946949/; classtype:trojan-activity;sid:84810049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946950)"; flow:established,from_client; content:"GET"; http_method; content:"/mysterybless/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946950/; classtype:trojan-activity;sid:84810050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946947)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.66.250"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946947/; classtype:trojan-activity;sid:84810047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946943)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.235.22.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946943/; classtype:trojan-activity;sid:84810043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946944)"; flow:established,from_client; content:"GET"; http_method; content:"/devilsprite/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946944/; classtype:trojan-activity;sid:84810044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946945)"; flow:established,from_client; content:"GET"; http_method; content:"/amillyrow/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946945/; classtype:trojan-activity;sid:84810045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946946)"; flow:established,from_client; content:"GET"; http_method; content:"/prsur"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"qq.kipsharijan.cfd"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946946/; classtype:trojan-activity;sid:84810046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946942)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1519428468599951424/1558057878890221588/bundle.zip|3f|ex=6aca0df9|7c|26|7c|is=6ac8bc79|7c|26|7c|hm=c778990da8edb87cc9953a1997b9b988223e71f0dfb4c2aba8061880522c9145|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946942/; classtype:trojan-activity;sid:84810042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946940)"; flow:established,from_client; content:"GET"; http_method; content:"/osbot.jar"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"osbot.net"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946940/; classtype:trojan-activity;sid:84810040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946941)"; flow:established,from_client; content:"GET"; http_method; content:"/stylyshconc/swift-executor/raw/head/swift.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946941/; classtype:trojan-activity;sid:84810041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946936)"; flow:established,from_client; content:"GET"; http_method; content:"/spazedurk/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946936/; classtype:trojan-activity;sid:84810036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946937)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.55.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946937/; classtype:trojan-activity;sid:84810037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946938)"; flow:established,from_client; content:"GET"; http_method; content:"/voicesinari/warzone-dominator/raw/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946938/; classtype:trojan-activity;sid:84810038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946939)"; flow:established,from_client; content:"GET"; http_method; content:"/hallermsy/exodus-larp-tool/raw/head/exodus.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946939/; classtype:trojan-activity;sid:84810039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946934)"; flow:established,from_client; content:"GET"; http_method; content:"/shellmadys/dma-spoofer/raw/head/dma_spoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946934/; classtype:trojan-activity;sid:84810034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946935)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557151123666763786/1557507870440947742/bundle4.zip|3f|backend=b2|7c|26|7c|ex=6ac80dbd|7c|26|7c|is=6ac6bc3d|7c|26|7c|hm=9d9216ccb4b0698324afcbda3711d2f532ca976e1175c12edcde0fa068066530|7c|26|7c|"; http_uri; depth:207; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946935/; classtype:trojan-activity;sid:84810035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946930)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1555611683316305982/1555632019642515546/bundle.zip|3f|ex=6ac13ab7|7c|26|7c|is=6abfe937|7c|26|7c|hm=f78314b38fb572c2ace948cb0068c4d71cd7493b505d47672174a69bbf272fb7|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946930/; classtype:trojan-activity;sid:84810030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946931)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1553488282396926035/1556771267728638023/bundle_3.zip|3f|ex=6ac55fb9|7c|26|7c|is=6ac40e39|7c|26|7c|hm=efa2b25ba5e817917e130e8f8c8c8a8ca7bcce83e035074538c4aaafa4e32461|7c|26|7c|"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946931/; classtype:trojan-activity;sid:84810031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946932)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557151123666763786/1557506286818689064/bundle3.zip|3f|backend=b2|7c|26|7c|ex=6ac80c43|7c|26|7c|is=6ac6bac3|7c|26|7c|hm=9eb18ad120f69df8b9c032049a833bd4d50ef669d2dd08aef02bd98b364960f4|7c|26|7c|"; http_uri; depth:207; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946932/; classtype:trojan-activity;sid:84810032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946933)"; flow:established,from_client; content:"GET"; http_method; content:"/redhenns/xeno-executor/raw/head/xeno.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946933/; classtype:trojan-activity;sid:84810033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946928)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/993236836841422971/1557641602426478682/bundle.zip|3f|ex=6ac88a49|7c|26|7c|is=6ac738c9|7c|26|7c|hm=8151c0d825b59b075c4eef4a239d409cd405aed1c4d3d1fa6b5ca015822e7ebc|7c|26|7c|"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946928/; classtype:trojan-activity;sid:84810028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946929)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1303859286715269124/1555998705453371482/bundle.zip|3f|ex=6ac29038|7c|26|7c|is=6ac13eb8|7c|26|7c|hm=e6fb2b369bb78799a75be531a2c6c500f194ac5c31d5b46f4441e4ceff52219d|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946929/; classtype:trojan-activity;sid:84810029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946923)"; flow:established,from_client; content:"GET"; http_method; content:"/channyl9/fivem-external-cheat/raw/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946923/; classtype:trojan-activity;sid:84810023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946924)"; flow:established,from_client; content:"GET"; http_method; content:"/b3at1z/umbrella-hwid-tool/raw/head/umbrella/umbrella.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946924/; classtype:trojan-activity;sid:84810024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946925)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1554540331729428512/1554540941933813840/bundle.zip|3f|ex=6abd4292|7c|26|7c|is=6abbf112|7c|26|7c|hm=0982d18aca5a6a5abe4f1a55e15681e17db3f66655954508c0c3f0d79c2c9ff8|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946925/; classtype:trojan-activity;sid:84810025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946926)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557540794322255916/1557547273469304852/docsend.exe|3f|ex=6ac8326f|7c|26|7c|is=6ac6e0ef|7c|26|7c|hm=a63457051c583761f1cec716699654537fd53498bb136ce8a68644779594d09a|7c|26|7c|"; http_uri; depth:187; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946926/; classtype:trojan-activity;sid:84810026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946927)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/752745910659842148/1557611729121312829/bundle_2.zip|3f|ex=6ac86e77|7c|26|7c|is=6ac71cf7|7c|26|7c|hm=0f48e7d8f63791c99c8fdfabde15419c91e5e5741110a3a362d68fa7639748b0|7c|26|7c|"; http_uri; depth:187; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946927/; classtype:trojan-activity;sid:84810027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946921)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/gya8fwl2yikrrmfhvwc8g/bundle-7.zip|3f|rlkey=l7t8znbg4rgmv33z87ztomvnc|7c|26|7c|st=pa02mzfs|7c|26|7c|dl=1"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946921/; classtype:trojan-activity;sid:84810021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946922)"; flow:established,from_client; content:"GET"; http_method; content:"/jehhn1l/fivem-spoofer/raw/head/cfxbypass.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946922/; classtype:trojan-activity;sid:84810022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946918)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/447108878963048458/1556697211415568496/bundle.zip|3f|ex=6ac51ac1|7c|26|7c|is=6ac3c941|7c|26|7c|hm=d582c4a45d48757252452c2d9050d0cf82209b833f1915a3d912056a63588578|7c|26|7c|"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946918/; classtype:trojan-activity;sid:84810018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946919)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1554681741015392331/1554985138352562306/bundle.zip|3f|ex=6abee043|7c|26|7c|is=6abd8ec3|7c|26|7c|hm=56c329e3ff2f1efec739365225dedb588e208d1c7016d5bd7ff3aaecb7b35495|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946919/; classtype:trojan-activity;sid:84810019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946920)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557035542208712774/1557698845453058160/bundle.zip|3f|ex=6ac8bf99|7c|26|7c|is=6ac76e19|7c|26|7c|hm=9fcc0058789315b7cea328c7d341ba2e05fe16aaa8d1d524f2acb68c3e507fe4|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946920/; classtype:trojan-activity;sid:84810020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946916)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.42.71.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946916/; classtype:trojan-activity;sid:84810016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946917)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.239.81.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946917/; classtype:trojan-activity;sid:84810017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946914)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.156.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946914/; classtype:trojan-activity;sid:84810014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946915)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.156.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946915/; classtype:trojan-activity;sid:84810015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946913)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.129.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946913/; classtype:trojan-activity;sid:84810013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946912)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.177.29.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946912/; classtype:trojan-activity;sid:84810012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946911)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.51.129.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946911/; classtype:trojan-activity;sid:84810011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946910)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946910/; classtype:trojan-activity;sid:84810010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946909)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.180.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946909/; classtype:trojan-activity;sid:84810009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946908)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.240.255.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946908/; classtype:trojan-activity;sid:84810008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946907)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.2.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946907/; classtype:trojan-activity;sid:84810007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946906)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.16.164.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946906/; classtype:trojan-activity;sid:84810006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946905)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.191.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946905/; classtype:trojan-activity;sid:84810005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946904)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.219.118.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946904/; classtype:trojan-activity;sid:84810004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946903)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.90.186.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946903/; classtype:trojan-activity;sid:84810003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946902)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.154.155.199"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946902/; classtype:trojan-activity;sid:84810002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946901)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.142.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946901/; classtype:trojan-activity;sid:84810001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946900)"; flow:established,from_client; content:"GET"; http_method; content:"/g.php"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"1rvrental.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946900/; classtype:trojan-activity;sid:84810000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946899)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.68.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946899/; classtype:trojan-activity;sid:84809999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946898)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"5.83.134.80"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946898/; classtype:trojan-activity;sid:84809998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946897)"; flow:established,from_client; content:"GET"; http_method; content:"/r"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"1rvrental.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946897/; classtype:trojan-activity;sid:84809997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946896)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.142.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946896/; classtype:trojan-activity;sid:84809996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946895)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.126.80.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946895/; classtype:trojan-activity;sid:84809995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946891)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.24.252.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946891/; classtype:trojan-activity;sid:84809991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946892)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.146.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946892/; classtype:trojan-activity;sid:84809992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946893)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.227.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946893/; classtype:trojan-activity;sid:84809993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946894)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.190.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946894/; classtype:trojan-activity;sid:84809994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946884)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.221.145.214"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946884/; classtype:trojan-activity;sid:84809984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946885)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.130.28"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946885/; classtype:trojan-activity;sid:84809985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946886)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.241.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946886/; classtype:trojan-activity;sid:84809986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946887)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.188.75.58"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946887/; classtype:trojan-activity;sid:84809987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946888)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.188.75.58"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946888/; classtype:trojan-activity;sid:84809988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946889)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"201.159.91.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946889/; classtype:trojan-activity;sid:84809989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946890)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.204.193.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946890/; classtype:trojan-activity;sid:84809990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946883)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.148.148.31"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946883/; classtype:trojan-activity;sid:84809983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946882)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.65.211.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946882/; classtype:trojan-activity;sid:84809982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946881)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.11.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946881/; classtype:trojan-activity;sid:84809981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946880)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.87.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946880/; classtype:trojan-activity;sid:84809980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946879)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.31.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946879/; classtype:trojan-activity;sid:84809979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946878)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.130.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946878/; classtype:trojan-activity;sid:84809978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946876)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.185.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946876/; classtype:trojan-activity;sid:84809976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946877)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.34.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946877/; classtype:trojan-activity;sid:84809977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946875)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.87.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946875/; classtype:trojan-activity;sid:84809975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946873)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.2.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946873/; classtype:trojan-activity;sid:84809973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946874)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.241.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946874/; classtype:trojan-activity;sid:84809974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946872)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.31.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946872/; classtype:trojan-activity;sid:84809972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946871)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.190.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946871/; classtype:trojan-activity;sid:84809971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946870)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.32.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946870/; classtype:trojan-activity;sid:84809970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946869)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.253.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946869/; classtype:trojan-activity;sid:84809969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946868)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.170.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946868/; classtype:trojan-activity;sid:84809968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946867)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946867/; classtype:trojan-activity;sid:84809967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946866)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.194.28.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946866/; classtype:trojan-activity;sid:84809966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946865)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.190.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946865/; classtype:trojan-activity;sid:84809965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946864)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946864/; classtype:trojan-activity;sid:84809964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946863)"; flow:established,from_client; content:"GET"; http_method; content:"/d/432936b3a0439572/o/nnnnnede/init.sh2"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"195.178.110.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946863/; classtype:trojan-activity;sid:84809963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946862)"; flow:established,from_client; content:"GET"; http_method; content:"/d/432936b3a0439572/o/nnnnnede/init.sh"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"195.178.110.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946862/; classtype:trojan-activity;sid:84809962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946861)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.145.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946861/; classtype:trojan-activity;sid:84809961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946860)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.31.103.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946860/; classtype:trojan-activity;sid:84809960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946859)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.88.227.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946859/; classtype:trojan-activity;sid:84809959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946858)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.145.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946858/; classtype:trojan-activity;sid:84809958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946856)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.214.23.166"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946856/; classtype:trojan-activity;sid:84809956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946857)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.159.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946857/; classtype:trojan-activity;sid:84809957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946853)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.31.103.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946853/; classtype:trojan-activity;sid:84809953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946854)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.215.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946854/; classtype:trojan-activity;sid:84809954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946855)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.6.167.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946855/; classtype:trojan-activity;sid:84809955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946852)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946852/; classtype:trojan-activity;sid:84809952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946850)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.arm64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946850/; classtype:trojan-activity;sid:84809950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946851)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946851/; classtype:trojan-activity;sid:84809951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946847)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.i686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946847/; classtype:trojan-activity;sid:84809947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946848)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946848/; classtype:trojan-activity;sid:84809948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946849)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946849/; classtype:trojan-activity;sid:84809949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946842)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946842/; classtype:trojan-activity;sid:84809942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946843)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946843/; classtype:trojan-activity;sid:84809943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946844)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946844/; classtype:trojan-activity;sid:84809944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946845)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946845/; classtype:trojan-activity;sid:84809945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946846)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946846/; classtype:trojan-activity;sid:84809946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946841)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"146.103.43.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946841/; classtype:trojan-activity;sid:84809941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946840)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.186.189"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946840/; classtype:trojan-activity;sid:84809940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946839)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.122.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946839/; classtype:trojan-activity;sid:84809939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946838)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.59.79.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946838/; classtype:trojan-activity;sid:84809938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946837)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.101.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946837/; classtype:trojan-activity;sid:84809937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946836)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.101.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946836/; classtype:trojan-activity;sid:84809936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946835)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.98.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946835/; classtype:trojan-activity;sid:84809935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946832)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.236.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946832/; classtype:trojan-activity;sid:84809932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946833)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"165.98.243.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946833/; classtype:trojan-activity;sid:84809933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946834)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.26.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946834/; classtype:trojan-activity;sid:84809934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946831)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.43.223.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946831/; classtype:trojan-activity;sid:84809931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946830)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_146f8720a4894bd8.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946830/; classtype:trojan-activity;sid:84809930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946829)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.180.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946829/; classtype:trojan-activity;sid:84809929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946828)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.236.46.199"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946828/; classtype:trojan-activity;sid:84809928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946827)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.122.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946827/; classtype:trojan-activity;sid:84809927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946826)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.51.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946826/; classtype:trojan-activity;sid:84809926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946825)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1l_cku7gnkfeuffiu2vesvhdzjbsvzjmx"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946825/; classtype:trojan-activity;sid:84809925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946824)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=14oekhhfto_xx6x0db-qpzwul_arxfhio"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946824/; classtype:trojan-activity;sid:84809924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946823)"; flow:established,from_client; content:"GET"; http_method; content:"/asset/update.dat"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"stanarcservice.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946823/; classtype:trojan-activity;sid:84809923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946822)"; flow:established,from_client; content:"GET"; http_method; content:"/payload/18d92fc0860cc33a.bin"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"stanarcservice.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946822/; classtype:trojan-activity;sid:84809922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946821)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.177.21"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946821/; classtype:trojan-activity;sid:84809921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946820)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.78.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946820/; classtype:trojan-activity;sid:84809920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946819)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.242.174"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946819/; classtype:trojan-activity;sid:84809919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946818)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946818/; classtype:trojan-activity;sid:84809918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946804)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/metrics-agents/-/raw/main/agent-install.sh"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946804/; classtype:trojan-activity;sid:84809904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946805)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.177.28.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946805/; classtype:trojan-activity;sid:84809905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946806)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946806/; classtype:trojan-activity;sid:84809906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946807)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946807/; classtype:trojan-activity;sid:84809907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946808)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946808/; classtype:trojan-activity;sid:84809908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946809)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946809/; classtype:trojan-activity;sid:84809909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946810)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946810/; classtype:trojan-activity;sid:84809910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946811)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946811/; classtype:trojan-activity;sid:84809911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946812)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/i686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946812/; classtype:trojan-activity;sid:84809912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946813)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946813/; classtype:trojan-activity;sid:84809913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946814)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946814/; classtype:trojan-activity;sid:84809914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946815)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946815/; classtype:trojan-activity;sid:84809915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946816)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946816/; classtype:trojan-activity;sid:84809916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946817)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.128.125.255"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946817/; classtype:trojan-activity;sid:84809917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946803)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946803/; classtype:trojan-activity;sid:84809903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946802)"; flow:established,from_client; content:"GET"; http_method; content:"/payload/1ay0eknhal4o/6lpiz8.sh"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"83.168.110.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946802/; classtype:trojan-activity;sid:84809902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946795)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/metrics-agents/-/raw/main/collector-linux-arm64"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946795/; classtype:trojan-activity;sid:84809895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946796)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/metrics-agents/-/raw/main/collector-linux-x64"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946796/; classtype:trojan-activity;sid:84809896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946797)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/static-assets/-/raw/main/collector-linux-arm64"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946797/; classtype:trojan-activity;sid:84809897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946798)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/static-assets/-/raw/main/agentd-linux-arm64"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946798/; classtype:trojan-activity;sid:84809898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946799)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/metrics-agents/-/raw/main/agentd-linux-x64"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946799/; classtype:trojan-activity;sid:84809899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946800)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/static-assets/-/raw/main/agent-install.sh"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946800/; classtype:trojan-activity;sid:84809900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946801)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/static-assets/-/raw/main/collector-linux-x64"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946801/; classtype:trojan-activity;sid:84809901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946794)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/metrics-agents/-/raw/main/agentd-linux-arm64"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946794/; classtype:trojan-activity;sid:84809894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946793)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.14.169.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946793/; classtype:trojan-activity;sid:84809893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946791)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/static-assets/-/raw/main/agentd-linux-x64"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946791/; classtype:trojan-activity;sid:84809891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946792)"; flow:established,from_client; content:"GET"; http_method; content:"/wj0s.arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946792/; classtype:trojan-activity;sid:84809892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946790)"; flow:established,from_client; content:"GET"; http_method; content:"/mogh739/metrics-agents/-/raw/main/collector-legacy-linux-x64"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946790/; classtype:trojan-activity;sid:84809890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946787)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"109.123.243.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946787/; classtype:trojan-activity;sid:84809887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946788)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.179.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946788/; classtype:trojan-activity;sid:84809888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946789)"; flow:established,from_client; content:"GET"; http_method; content:"/lol.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946789/; classtype:trojan-activity;sid:84809889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946785)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1557973486176043018/1557974426660905030/bettersurvival.jar|3f|ex=6ac9c041|7c|26|7c|is=6ac86ec1|7c|26|7c|hm=9436b20ab3fc47cc6db0eb41943bc7cf49a68f1bf0b10e89fa539b3aa9e38e55|7c|26|7c|"; http_uri; depth:194; isdataat:!1,relative; nocase; content:"media.discordapp.net"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946785/; classtype:trojan-activity;sid:84809885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946786)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"w5q.eu"; http_host; depth:6; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946786/; classtype:trojan-activity;sid:84809886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946784)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.115.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946784/; classtype:trojan-activity;sid:84809884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946783)"; flow:established,from_client; content:"GET"; http_method; content:"/api/download.php"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"qwfwhg4.lol"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946783/; classtype:trojan-activity;sid:84809883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946782)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946782/; classtype:trojan-activity;sid:84809882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946781)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.120.3.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946781/; classtype:trojan-activity;sid:84809881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946780)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.89.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946780/; classtype:trojan-activity;sid:84809880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946779)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.51.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946779/; classtype:trojan-activity;sid:84809879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946778)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.225.46.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946778/; classtype:trojan-activity;sid:84809878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946777)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.123.192.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946777/; classtype:trojan-activity;sid:84809877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946776)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.120.3.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946776/; classtype:trojan-activity;sid:84809876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946775)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.112.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946775/; classtype:trojan-activity;sid:84809875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946774)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.210.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946774/; classtype:trojan-activity;sid:84809874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946772)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.54.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946772/; classtype:trojan-activity;sid:84809872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946773)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.210.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946773/; classtype:trojan-activity;sid:84809873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946771)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.9.203.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946771/; classtype:trojan-activity;sid:84809871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946770)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.75.204"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946770/; classtype:trojan-activity;sid:84809870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946769)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.103.174.195"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946769/; classtype:trojan-activity;sid:84809869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946768)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.140.187.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946768/; classtype:trojan-activity;sid:84809868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946767)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.104.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946767/; classtype:trojan-activity;sid:84809867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946766)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.9.203.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946766/; classtype:trojan-activity;sid:84809866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946765)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_27539cb69c52484f.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946765/; classtype:trojan-activity;sid:84809865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946764)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.215.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946764/; classtype:trojan-activity;sid:84809864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946763)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.4.127.9"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946763/; classtype:trojan-activity;sid:84809863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946762)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.48.148.108"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946762/; classtype:trojan-activity;sid:84809862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946760)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.181.226"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946760/; classtype:trojan-activity;sid:84809860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946761)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.119.243"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946761/; classtype:trojan-activity;sid:84809861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946759)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.177.29.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946759/; classtype:trojan-activity;sid:84809859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946758)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.216.248"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946758/; classtype:trojan-activity;sid:84809858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946757)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.120.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946757/; classtype:trojan-activity;sid:84809857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946756)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946756/; classtype:trojan-activity;sid:84809856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946753)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"151.237.28.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946753/; classtype:trojan-activity;sid:84809853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946754)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.104.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946754/; classtype:trojan-activity;sid:84809854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946755)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.86.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946755/; classtype:trojan-activity;sid:84809855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946750)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"160.176.170.101"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946750/; classtype:trojan-activity;sid:84809850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946751)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.97.100.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946751/; classtype:trojan-activity;sid:84809851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946752)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.146.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946752/; classtype:trojan-activity;sid:84809852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946749)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.65.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946749/; classtype:trojan-activity;sid:84809849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946748)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.8.194"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946748/; classtype:trojan-activity;sid:84809848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946746)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.67.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946746/; classtype:trojan-activity;sid:84809846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946747)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.176.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946747/; classtype:trojan-activity;sid:84809847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946743)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.215.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946743/; classtype:trojan-activity;sid:84809843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946744)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.7.122.114"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946744/; classtype:trojan-activity;sid:84809844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946745)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.52.173.208"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946745/; classtype:trojan-activity;sid:84809845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946742)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.65.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946742/; classtype:trojan-activity;sid:84809842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946741)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.58.106.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946741/; classtype:trojan-activity;sid:84809841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946740)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.146.225.101"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946740/; classtype:trojan-activity;sid:84809840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946736)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.46.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946736/; classtype:trojan-activity;sid:84809836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946737)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.198.242.174"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946737/; classtype:trojan-activity;sid:84809837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946738)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.25.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946738/; classtype:trojan-activity;sid:84809838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946739)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.11.133.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946739/; classtype:trojan-activity;sid:84809839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946735)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"2.85.58.246"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946735/; classtype:trojan-activity;sid:84809835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946734)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.152.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946734/; classtype:trojan-activity;sid:84809834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946733)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.28.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946733/; classtype:trojan-activity;sid:84809833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946732)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.81.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946732/; classtype:trojan-activity;sid:84809832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946729)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.151.248.162"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946729/; classtype:trojan-activity;sid:84809829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946730)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.190.23.91"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946730/; classtype:trojan-activity;sid:84809830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946731)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.114.33.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946731/; classtype:trojan-activity;sid:84809831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946728)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.209.183.7"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946728/; classtype:trojan-activity;sid:84809828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946726)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.151.248.162"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946726/; classtype:trojan-activity;sid:84809826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946727)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.120.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946727/; classtype:trojan-activity;sid:84809827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946725)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.152.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946725/; classtype:trojan-activity;sid:84809825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946723)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.6.56.231"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946723/; classtype:trojan-activity;sid:84809823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946724)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.162.250"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946724/; classtype:trojan-activity;sid:84809824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946722)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.7.84.109"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946722/; classtype:trojan-activity;sid:84809822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946721)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.7.84.109"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946721/; classtype:trojan-activity;sid:84809821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946720)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.67.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946720/; classtype:trojan-activity;sid:84809820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946719)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.51.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946719/; classtype:trojan-activity;sid:84809819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946718)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.35.50.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946718/; classtype:trojan-activity;sid:84809818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946717)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.26.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946717/; classtype:trojan-activity;sid:84809817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946716)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.233.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946716/; classtype:trojan-activity;sid:84809816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946715)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.161.100.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946715/; classtype:trojan-activity;sid:84809815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946714)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.156.63.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946714/; classtype:trojan-activity;sid:84809814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946713)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.63.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946713/; classtype:trojan-activity;sid:84809813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946711)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.233.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946711/; classtype:trojan-activity;sid:84809811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946712)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.111.23.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946712/; classtype:trojan-activity;sid:84809812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946710)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946710/; classtype:trojan-activity;sid:84809810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946709)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.47.218.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946709/; classtype:trojan-activity;sid:84809809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946705)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946705/; classtype:trojan-activity;sid:84809805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946706)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.ppc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946706/; classtype:trojan-activity;sid:84809806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946707)"; flow:established,from_client; content:"GET"; http_method; content:"/mirai.mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946707/; classtype:trojan-activity;sid:84809807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946708)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946708/; classtype:trojan-activity;sid:84809808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946701)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946701/; classtype:trojan-activity;sid:84809801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946702)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946702/; classtype:trojan-activity;sid:84809802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946703)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946703/; classtype:trojan-activity;sid:84809803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946704)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946704/; classtype:trojan-activity;sid:84809804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946693)"; flow:established,from_client; content:"GET"; http_method; content:"/mirai.arm5n"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946693/; classtype:trojan-activity;sid:84809793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946694)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946694/; classtype:trojan-activity;sid:84809794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946695)"; flow:established,from_client; content:"GET"; http_method; content:"/mirai.arm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946695/; classtype:trojan-activity;sid:84809795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946696)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946696/; classtype:trojan-activity;sid:84809796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946697)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.i686"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946697/; classtype:trojan-activity;sid:84809797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946698)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946698/; classtype:trojan-activity;sid:84809798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946699)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.spc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946699/; classtype:trojan-activity;sid:84809799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946700)"; flow:established,from_client; content:"GET"; http_method; content:"/mirai.x86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946700/; classtype:trojan-activity;sid:84809800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946692)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.16.164.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946692/; classtype:trojan-activity;sid:84809792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946691)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.216.226.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946691/; classtype:trojan-activity;sid:84809791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946689)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.50.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946689/; classtype:trojan-activity;sid:84809789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946690)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.76.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946690/; classtype:trojan-activity;sid:84809790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946688)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.186.138.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946688/; classtype:trojan-activity;sid:84809788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946687)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.196.0.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946687/; classtype:trojan-activity;sid:84809787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946686)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.251.163"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946686/; classtype:trojan-activity;sid:84809786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946685)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.254.114"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946685/; classtype:trojan-activity;sid:84809785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946684)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.18.23"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946684/; classtype:trojan-activity;sid:84809784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946683)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.63.157.145"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946683/; classtype:trojan-activity;sid:84809783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946682)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.133.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946682/; classtype:trojan-activity;sid:84809782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946681)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.247.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946681/; classtype:trojan-activity;sid:84809781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946680)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.92.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946680/; classtype:trojan-activity;sid:84809780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946679)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.46.198.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946679/; classtype:trojan-activity;sid:84809779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946678)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.170.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946678/; classtype:trojan-activity;sid:84809778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946677)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.164.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946677/; classtype:trojan-activity;sid:84809777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946676)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.186.138.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946676/; classtype:trojan-activity;sid:84809776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946675)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.163.187.224"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_09; reference:url, urlhaus.abuse.ch/url/3946675/; classtype:trojan-activity;sid:84809775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946674)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.141.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946674/; classtype:trojan-activity;sid:84809774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946672)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.77.13"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946672/; classtype:trojan-activity;sid:84809772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946673)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.214.58.89"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946673/; classtype:trojan-activity;sid:84809773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946671)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.238.89"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946671/; classtype:trojan-activity;sid:84809771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946670)"; flow:established,from_client; content:"GET"; http_method; content:"/files/7782139129/sqrgijn.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946670/; classtype:trojan-activity;sid:84809770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946669)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.49.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946669/; classtype:trojan-activity;sid:84809769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946668)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"108.170.136.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946668/; classtype:trojan-activity;sid:84809768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946667)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.52.20.56"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946667/; classtype:trojan-activity;sid:84809767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946666)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_7d6e0a8ed54f5bd4.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946666/; classtype:trojan-activity;sid:84809766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946665)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.238.27.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946665/; classtype:trojan-activity;sid:84809765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946664)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.189.157.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946664/; classtype:trojan-activity;sid:84809764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946663)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.9.84.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946663/; classtype:trojan-activity;sid:84809763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946662)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.189.176.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946662/; classtype:trojan-activity;sid:84809762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946661)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.134.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946661/; classtype:trojan-activity;sid:84809761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946660)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.187.101.209"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946660/; classtype:trojan-activity;sid:84809760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946659)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.229.175.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946659/; classtype:trojan-activity;sid:84809759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946658)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.144.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946658/; classtype:trojan-activity;sid:84809758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946657)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.111.23.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946657/; classtype:trojan-activity;sid:84809757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946656)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.115.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946656/; classtype:trojan-activity;sid:84809756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946655)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.179.145"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946655/; classtype:trojan-activity;sid:84809755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946654)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.144.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946654/; classtype:trojan-activity;sid:84809754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946653)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.158.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946653/; classtype:trojan-activity;sid:84809753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946652)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.236.46.199"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946652/; classtype:trojan-activity;sid:84809752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946651)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.242.174"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946651/; classtype:trojan-activity;sid:84809751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946648)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.222.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946648/; classtype:trojan-activity;sid:84809748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946649)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.120.45"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946649/; classtype:trojan-activity;sid:84809749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946650)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.219.118.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946650/; classtype:trojan-activity;sid:84809750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946647)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.202.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946647/; classtype:trojan-activity;sid:84809747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946646)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.sh4"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946646/; classtype:trojan-activity;sid:84809746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946638)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mips"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946638/; classtype:trojan-activity;sid:84809738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946639)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946639/; classtype:trojan-activity;sid:84809739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946640)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mpsl"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946640/; classtype:trojan-activity;sid:84809740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946641)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.ppc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946641/; classtype:trojan-activity;sid:84809741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946642)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946642/; classtype:trojan-activity;sid:84809742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946643)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm5"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946643/; classtype:trojan-activity;sid:84809743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946644)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm7"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946644/; classtype:trojan-activity;sid:84809744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946645)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.x86_64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946645/; classtype:trojan-activity;sid:84809745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946629)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946629/; classtype:trojan-activity;sid:84809729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946630)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946630/; classtype:trojan-activity;sid:84809730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946631)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946631/; classtype:trojan-activity;sid:84809731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946632)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946632/; classtype:trojan-activity;sid:84809732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946633)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946633/; classtype:trojan-activity;sid:84809733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946634)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.i686"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946634/; classtype:trojan-activity;sid:84809734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946635)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.m68k"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946635/; classtype:trojan-activity;sid:84809735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946636)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946636/; classtype:trojan-activity;sid:84809736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946637)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946637/; classtype:trojan-activity;sid:84809737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946627)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946627/; classtype:trojan-activity;sid:84809727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946628)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.i586"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946628/; classtype:trojan-activity;sid:84809728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946624)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.sparc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946624/; classtype:trojan-activity;sid:84809724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946625)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946625/; classtype:trojan-activity;sid:84809725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946626)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.sparc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946626/; classtype:trojan-activity;sid:84809726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946620)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.arc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946620/; classtype:trojan-activity;sid:84809720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946621)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946621/; classtype:trojan-activity;sid:84809721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946622)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.mips64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946622/; classtype:trojan-activity;sid:84809722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946623)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mips64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946623/; classtype:trojan-activity;sid:84809723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946619)"; flow:established,from_client; content:"GET"; http_method; content:"//violet.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946619/; classtype:trojan-activity;sid:84809719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946618)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/putty.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946618/; classtype:trojan-activity;sid:84809718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946616)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/px86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946616/; classtype:trojan-activity;sid:84809716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946617)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946617/; classtype:trojan-activity;sid:84809717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946615)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.220.145.39"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946615/; classtype:trojan-activity;sid:84809715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946614)"; flow:established,from_client; content:"GET"; http_method; content:"/file/5zdr3wzj48j8odd/setup_package_(key=2088).zip/file"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"www.mediafire.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946614/; classtype:trojan-activity;sid:84809714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946612)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.193.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946612/; classtype:trojan-activity;sid:84809712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946613)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.89.252.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946613/; classtype:trojan-activity;sid:84809713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946611)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.220.145.39"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946611/; classtype:trojan-activity;sid:84809711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946610)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.199.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946610/; classtype:trojan-activity;sid:84809710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946609)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.23.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946609/; classtype:trojan-activity;sid:84809709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946608)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.103.174.195"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946608/; classtype:trojan-activity;sid:84809708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946607)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.86.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946607/; classtype:trojan-activity;sid:84809707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946600)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946600/; classtype:trojan-activity;sid:84809700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946601)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946601/; classtype:trojan-activity;sid:84809701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946602)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946602/; classtype:trojan-activity;sid:84809702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946603)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946603/; classtype:trojan-activity;sid:84809703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946604)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946604/; classtype:trojan-activity;sid:84809704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946605)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946605/; classtype:trojan-activity;sid:84809705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946606)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946606/; classtype:trojan-activity;sid:84809706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946577)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.52.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946577/; classtype:trojan-activity;sid:84809677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946578)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946578/; classtype:trojan-activity;sid:84809678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946579)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946579/; classtype:trojan-activity;sid:84809679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946580)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946580/; classtype:trojan-activity;sid:84809680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946581)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946581/; classtype:trojan-activity;sid:84809681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946582)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.i686"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946582/; classtype:trojan-activity;sid:84809682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946583)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.211"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946583/; classtype:trojan-activity;sid:84809683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946584)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946584/; classtype:trojan-activity;sid:84809684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946585)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946585/; classtype:trojan-activity;sid:84809685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946586)"; flow:established,from_client; content:"GET"; http_method; content:"/main_m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.211"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946586/; classtype:trojan-activity;sid:84809686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946587)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946587/; classtype:trojan-activity;sid:84809687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946588)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946588/; classtype:trojan-activity;sid:84809688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946589)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.i486"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946589/; classtype:trojan-activity;sid:84809689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946590)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946590/; classtype:trojan-activity;sid:84809690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946591)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946591/; classtype:trojan-activity;sid:84809691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946592)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.spc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946592/; classtype:trojan-activity;sid:84809692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946593)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.132.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946593/; classtype:trojan-activity;sid:84809693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946594)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946594/; classtype:trojan-activity;sid:84809694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946595)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946595/; classtype:trojan-activity;sid:84809695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946596)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946596/; classtype:trojan-activity;sid:84809696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946597)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946597/; classtype:trojan-activity;sid:84809697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946598)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946598/; classtype:trojan-activity;sid:84809698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946599)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"77.90.14.60"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946599/; classtype:trojan-activity;sid:84809699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946566)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite_arm8"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946566/; classtype:trojan-activity;sid:84809666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946567)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite_x86-64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946567/; classtype:trojan-activity;sid:84809667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946568)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_agent_x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946568/; classtype:trojan-activity;sid:84809668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946569)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_agent_mips64le"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946569/; classtype:trojan-activity;sid:84809669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946570)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_agent_mipsle"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946570/; classtype:trojan-activity;sid:84809670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946571)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_agent_arm64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946571/; classtype:trojan-activity;sid:84809671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946572)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite_arm"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946572/; classtype:trojan-activity;sid:84809672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946573)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_agent_c.c"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946573/; classtype:trojan-activity;sid:84809673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946574)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite_mips"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946574/; classtype:trojan-activity;sid:84809674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946575)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite_armv7l"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946575/; classtype:trojan-activity;sid:84809675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946576)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite_arm64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946576/; classtype:trojan-activity;sid:84809676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946564)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_lite.c"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946564/; classtype:trojan-activity;sid:84809664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946565)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_agent_armv7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"123.56.0.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946565/; classtype:trojan-activity;sid:84809665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946554)"; flow:established,from_client; content:"GET"; http_method; content:"/zhr_debug_mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946554/; classtype:trojan-activity;sid:84809654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946555)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_i686"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946555/; classtype:trojan-activity;sid:84809655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946556)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.mpsl"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946556/; classtype:trojan-activity;sid:84809656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946557)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_armv6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946557/; classtype:trojan-activity;sid:84809657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946558)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.x86_64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946558/; classtype:trojan-activity;sid:84809658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946559)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946559/; classtype:trojan-activity;sid:84809659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946560)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946560/; classtype:trojan-activity;sid:84809660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946561)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946561/; classtype:trojan-activity;sid:84809661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946562)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_i686.gz"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946562/; classtype:trojan-activity;sid:84809662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946563)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.i386"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946563/; classtype:trojan-activity;sid:84809663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946546)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mips64el"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946546/; classtype:trojan-activity;sid:84809646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946547)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.mipsel"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946547/; classtype:trojan-activity;sid:84809647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946548)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_mipsel.gz"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946548/; classtype:trojan-activity;sid:84809648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946549)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946549/; classtype:trojan-activity;sid:84809649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946550)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armel.gz"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946550/; classtype:trojan-activity;sid:84809650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946551)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946551/; classtype:trojan-activity;sid:84809651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946552)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_arm64.gz"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946552/; classtype:trojan-activity;sid:84809652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946553)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv5tel"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946553/; classtype:trojan-activity;sid:84809653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946545)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_powerpc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946545/; classtype:trojan-activity;sid:84809645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946544)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_m68k"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946544/; classtype:trojan-activity;sid:84809644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946537)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_i486"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946537/; classtype:trojan-activity;sid:84809637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946538)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_i686"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946538/; classtype:trojan-activity;sid:84809638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946539)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_np.gz"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946539/; classtype:trojan-activity;sid:84809639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946540)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_riscv64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946540/; classtype:trojan-activity;sid:84809640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946541)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.android.arm64"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946541/; classtype:trojan-activity;sid:84809641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946542)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_i386"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946542/; classtype:trojan-activity;sid:84809642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946543)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armhf.gz"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946543/; classtype:trojan-activity;sid:84809643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946506)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm8"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946506/; classtype:trojan-activity;sid:84809606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946507)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_i386.gz"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946507/; classtype:trojan-activity;sid:84809607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946508)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv5tel.gz"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946508/; classtype:trojan-activity;sid:84809608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946509)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv6l.gz"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946509/; classtype:trojan-activity;sid:84809609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946510)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946510/; classtype:trojan-activity;sid:84809610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946511)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.arm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946511/; classtype:trojan-activity;sid:84809611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946512)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.armv7l"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946512/; classtype:trojan-activity;sid:84809612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946513)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.sh4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946513/; classtype:trojan-activity;sid:84809613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946514)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946514/; classtype:trojan-activity;sid:84809614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946515)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_aarch64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946515/; classtype:trojan-activity;sid:84809615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946516)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent.gz"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946516/; classtype:trojan-activity;sid:84809616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946517)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.i686"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946517/; classtype:trojan-activity;sid:84809617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946518)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_aarch64.gz"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946518/; classtype:trojan-activity;sid:84809618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946519)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946519/; classtype:trojan-activity;sid:84809619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946520)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946520/; classtype:trojan-activity;sid:84809620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946521)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv7"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946521/; classtype:trojan-activity;sid:84809621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946522)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.m68k"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946522/; classtype:trojan-activity;sid:84809622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946523)"; flow:established,from_client; content:"GET"; http_method; content:"/zhr_debug"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946523/; classtype:trojan-activity;sid:84809623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946524)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946524/; classtype:trojan-activity;sid:84809624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946525)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.x86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946525/; classtype:trojan-activity;sid:84809625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946526)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_armv5l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946526/; classtype:trojan-activity;sid:84809626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946527)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mips64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946527/; classtype:trojan-activity;sid:84809627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946528)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.android.arm"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946528/; classtype:trojan-activity;sid:84809628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946529)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent.tar"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946529/; classtype:trojan-activity;sid:84809629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946530)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mips64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946530/; classtype:trojan-activity;sid:84809630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946531)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv6l"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946531/; classtype:trojan-activity;sid:84809631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946532)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946532/; classtype:trojan-activity;sid:84809632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946533)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_aarch64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946533/; classtype:trojan-activity;sid:84809633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946534)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946534/; classtype:trojan-activity;sid:84809634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946535)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_amd64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946535/; classtype:trojan-activity;sid:84809635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946536)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.aarch64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946536/; classtype:trojan-activity;sid:84809636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946505)"; flow:established,from_client; content:"GET"; http_method; content:"/frps"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"108.137.82.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946505/; classtype:trojan-activity;sid:84809605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946504)"; flow:established,from_client; content:"GET"; http_method; content:"/frpc_linux_arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"108.137.82.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946504/; classtype:trojan-activity;sid:84809604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946468)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946468/; classtype:trojan-activity;sid:84809568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946469)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946469/; classtype:trojan-activity;sid:84809569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946470)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_aarch64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946470/; classtype:trojan-activity;sid:84809570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946471)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946471/; classtype:trojan-activity;sid:84809571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946472)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.amd64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946472/; classtype:trojan-activity;sid:84809572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946473)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.i586"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946473/; classtype:trojan-activity;sid:84809573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946474)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_amd64.gz"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946474/; classtype:trojan-activity;sid:84809574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946475)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_powerpc64le"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946475/; classtype:trojan-activity;sid:84809575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946476)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_np"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946476/; classtype:trojan-activity;sid:84809576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946477)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_powerpc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946477/; classtype:trojan-activity;sid:84809577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946478)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_m68k"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946478/; classtype:trojan-activity;sid:84809578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946479)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946479/; classtype:trojan-activity;sid:84809579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946480)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv6"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946480/; classtype:trojan-activity;sid:84809580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946481)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv6.gz"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946481/; classtype:trojan-activity;sid:84809581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946482)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_arm64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946482/; classtype:trojan-activity;sid:84809582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946483)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946483/; classtype:trojan-activity;sid:84809583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946484)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946484/; classtype:trojan-activity;sid:84809584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946485)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_mipsel"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946485/; classtype:trojan-activity;sid:84809585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946486)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_x86_64.gz"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946486/; classtype:trojan-activity;sid:84809586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946487)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.i386"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946487/; classtype:trojan-activity;sid:84809587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946488)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.ppc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946488/; classtype:trojan-activity;sid:84809588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946489)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_armv7l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946489/; classtype:trojan-activity;sid:84809589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946490)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armhf"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946490/; classtype:trojan-activity;sid:84809590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946491)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv7.gz"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946491/; classtype:trojan-activity;sid:84809591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946492)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946492/; classtype:trojan-activity;sid:84809592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946493)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv7l.gz"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946493/; classtype:trojan-activity;sid:84809593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946494)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_arm.gz"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946494/; classtype:trojan-activity;sid:84809594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946495)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_mips.gz"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946495/; classtype:trojan-activity;sid:84809595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946496)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_x86_64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946496/; classtype:trojan-activity;sid:84809596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946497)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_sh4"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"15.207.188.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946497/; classtype:trojan-activity;sid:84809597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946498)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.x64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946498/; classtype:trojan-activity;sid:84809598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946499)"; flow:established,from_client; content:"GET"; http_method; content:"/z3hir.arm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"79.238.78.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946499/; classtype:trojan-activity;sid:84809599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946500)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm4"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946500/; classtype:trojan-activity;sid:84809600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946501)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.241.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946501/; classtype:trojan-activity;sid:84809601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946502)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946502/; classtype:trojan-activity;sid:84809602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946503)"; flow:established,from_client; content:"GET"; http_method; content:"/boat_agent_armv7l"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"46.247.108.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946503/; classtype:trojan-activity;sid:84809603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946465)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946465/; classtype:trojan-activity;sid:84809565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946466)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946466/; classtype:trojan-activity;sid:84809566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946467)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"170.64.142.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946467/; classtype:trojan-activity;sid:84809567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946464)"; flow:established,from_client; content:"GET"; http_method; content:"/frpc_mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"108.137.82.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946464/; classtype:trojan-activity;sid:84809564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946463)"; flow:established,from_client; content:"GET"; http_method; content:"/kkvettgaaasecnnaaaa.arm"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"176.65.139.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946463/; classtype:trojan-activity;sid:84809563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946462)"; flow:established,from_client; content:"GET"; http_method; content:"/kkvettgaaasecnnaaaa.mips"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.139.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946462/; classtype:trojan-activity;sid:84809562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946461)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-x64-musl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946461/; classtype:trojan-activity;sid:84809561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946459)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946459/; classtype:trojan-activity;sid:84809559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946460)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946460/; classtype:trojan-activity;sid:84809560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946457)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946457/; classtype:trojan-activity;sid:84809557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946458)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946458/; classtype:trojan-activity;sid:84809558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946454)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946454/; classtype:trojan-activity;sid:84809554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946455)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-ppc-603f"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946455/; classtype:trojan-activity;sid:84809555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946456)"; flow:established,from_client; content:"GET"; http_method; content:"/frpc"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"108.137.82.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946456/; classtype:trojan-activity;sid:84809556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946453)"; flow:established,from_client; content:"GET"; http_method; content:"/rathole-164-v5te"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946453/; classtype:trojan-activity;sid:84809553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946451)"; flow:established,from_client; content:"GET"; http_method; content:"/kkvettgaaasecnnaaaa.i486"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.139.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946451/; classtype:trojan-activity;sid:84809551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946452)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-v048-x64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946452/; classtype:trojan-activity;sid:84809552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946450)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-freebsd"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946450/; classtype:trojan-activity;sid:84809550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946449)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946449/; classtype:trojan-activity;sid:84809549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946444)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-164-v5te"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946444/; classtype:trojan-activity;sid:84809544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946445)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946445/; classtype:trojan-activity;sid:84809545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946446)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946446/; classtype:trojan-activity;sid:84809546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946447)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-ppc-final"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946447/; classtype:trojan-activity;sid:84809547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946448)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_arm5.p"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946448/; classtype:trojan-activity;sid:84809548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946443)"; flow:established,from_client; content:"GET"; http_method; content:"/beacon_windows_amd64.exe"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946443/; classtype:trojan-activity;sid:84809543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946438)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946438/; classtype:trojan-activity;sid:84809538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946439)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-ppc603"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946439/; classtype:trojan-activity;sid:84809539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946440)"; flow:established,from_client; content:"GET"; http_method; content:"/t_arm5.so"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946440/; classtype:trojan-activity;sid:84809540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946441)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-ppc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946441/; classtype:trojan-activity;sid:84809541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946442)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_mipsle.p"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946442/; classtype:trojan-activity;sid:84809542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946436)"; flow:established,from_client; content:"GET"; http_method; content:"/rathole-v048-amd64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946436/; classtype:trojan-activity;sid:84809536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946437)"; flow:established,from_client; content:"GET"; http_method; content:"/ohshit.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"172.245.106.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946437/; classtype:trojan-activity;sid:84809537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946432)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946432/; classtype:trojan-activity;sid:84809532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946433)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946433/; classtype:trojan-activity;sid:84809533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946434)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946434/; classtype:trojan-activity;sid:84809534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946435)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946435/; classtype:trojan-activity;sid:84809535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946425)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946425/; classtype:trojan-activity;sid:84809525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946426)"; flow:established,from_client; content:"GET"; http_method; content:"/beacon_linux_amd64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946426/; classtype:trojan-activity;sid:84809526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946427)"; flow:established,from_client; content:"GET"; http_method; content:"/kkvettgaaasecnnaaaa.arm7"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.139.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946427/; classtype:trojan-activity;sid:84809527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946428)"; flow:established,from_client; content:"GET"; http_method; content:"/kkvettgaaasecnnaaaa.x86_64"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"176.65.139.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946428/; classtype:trojan-activity;sid:84809528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946429)"; flow:established,from_client; content:"GET"; http_method; content:"/riscv64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946429/; classtype:trojan-activity;sid:84809529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946430)"; flow:established,from_client; content:"GET"; http_method; content:"/kkvettgaaasecnnaaaa.mpsl"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.139.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946430/; classtype:trojan-activity;sid:84809530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946431)"; flow:established,from_client; content:"GET"; http_method; content:"/frpc_arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"108.137.82.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946431/; classtype:trojan-activity;sid:84809531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946420)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.arc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946420/; classtype:trojan-activity;sid:84809520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946421)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.x86_debug"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946421/; classtype:trojan-activity;sid:84809521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946422)"; flow:established,from_client; content:"GET"; http_method; content:"/shitassbotttt.sh"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946422/; classtype:trojan-activity;sid:84809522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946423)"; flow:established,from_client; content:"GET"; http_method; content:"/boatnet.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"66.29.151.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946423/; classtype:trojan-activity;sid:84809523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946424)"; flow:established,from_client; content:"GET"; http_method; content:"/t_armhf.so"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946424/; classtype:trojan-activity;sid:84809524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946414)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_mipsle"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946414/; classtype:trojan-activity;sid:84809514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946415)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946415/; classtype:trojan-activity;sid:84809515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946416)"; flow:established,from_client; content:"GET"; http_method; content:"/comm.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946416/; classtype:trojan-activity;sid:84809516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946417)"; flow:established,from_client; content:"GET"; http_method; content:"/patch.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946417/; classtype:trojan-activity;sid:84809517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946418)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946418/; classtype:trojan-activity;sid:84809518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946419)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946419/; classtype:trojan-activity;sid:84809519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946408)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_arm5"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946408/; classtype:trojan-activity;sid:84809508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946409)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.spc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946409/; classtype:trojan-activity;sid:84809509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946410)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.mipsl"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946410/; classtype:trojan-activity;sid:84809510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946411)"; flow:established,from_client; content:"GET"; http_method; content:"/t5c.so"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946411/; classtype:trojan-activity;sid:84809511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946412)"; flow:established,from_client; content:"GET"; http_method; content:"/klogd-ppc-musl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946412/; classtype:trojan-activity;sid:84809512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946413)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946413/; classtype:trojan-activity;sid:84809513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946404)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.x86_32"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946404/; classtype:trojan-activity;sid:84809504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946405)"; flow:established,from_client; content:"GET"; http_method; content:"/beacon_rn"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946405/; classtype:trojan-activity;sid:84809505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946406)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_mips"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946406/; classtype:trojan-activity;sid:84809506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946407)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_arm"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946407/; classtype:trojan-activity;sid:84809507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946401)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946401/; classtype:trojan-activity;sid:84809501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946402)"; flow:established,from_client; content:"GET"; http_method; content:"/ga_armhfb.so"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946402/; classtype:trojan-activity;sid:84809502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946403)"; flow:established,from_client; content:"GET"; http_method; content:"/ga_mipsel.so"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946403/; classtype:trojan-activity;sid:84809503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946400)"; flow:established,from_client; content:"GET"; http_method; content:"/alte.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946400/; classtype:trojan-activity;sid:84809500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946399)"; flow:established,from_client; content:"GET"; http_method; content:"/rathole-v048-armv7"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946399/; classtype:trojan-activity;sid:84809499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946398)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946398/; classtype:trojan-activity;sid:84809498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946396)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946396/; classtype:trojan-activity;sid:84809496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946397)"; flow:established,from_client; content:"GET"; http_method; content:"/rathole_amd64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"154.83.85.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946397/; classtype:trojan-activity;sid:84809497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946394)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946394/; classtype:trojan-activity;sid:84809494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946395)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946395/; classtype:trojan-activity;sid:84809495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946379)"; flow:established,from_client; content:"GET"; http_method; content:"/ga_arm.so"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946379/; classtype:trojan-activity;sid:84809479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946380)"; flow:established,from_client; content:"GET"; http_method; content:"/ga_mips.so"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946380/; classtype:trojan-activity;sid:84809480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946381)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.i486"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946381/; classtype:trojan-activity;sid:84809481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946382)"; flow:established,from_client; content:"GET"; http_method; content:"/ga2_mips.so"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946382/; classtype:trojan-activity;sid:84809482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946383)"; flow:established,from_client; content:"GET"; http_method; content:"/ga_armb.so"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946383/; classtype:trojan-activity;sid:84809483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946384)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.arc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946384/; classtype:trojan-activity;sid:84809484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946385)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946385/; classtype:trojan-activity;sid:84809485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946386)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.ppc440"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946386/; classtype:trojan-activity;sid:84809486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946387)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.i686"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946387/; classtype:trojan-activity;sid:84809487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946388)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946388/; classtype:trojan-activity;sid:84809488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946389)"; flow:established,from_client; content:"GET"; http_method; content:"/t5b.so"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946389/; classtype:trojan-activity;sid:84809489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946390)"; flow:established,from_client; content:"GET"; http_method; content:"/all.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946390/; classtype:trojan-activity;sid:84809490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946391)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946391/; classtype:trojan-activity;sid:84809491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946392)"; flow:established,from_client; content:"GET"; http_method; content:"/ga_armhf.so"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946392/; classtype:trojan-activity;sid:84809492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946393)"; flow:established,from_client; content:"GET"; http_method; content:"/titanjr.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"40.160.135.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946393/; classtype:trojan-activity;sid:84809493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946378)"; flow:established,from_client; content:"GET"; http_method; content:"/ga2_mipsel.so"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946378/; classtype:trojan-activity;sid:84809478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946376)"; flow:established,from_client; content:"GET"; http_method; content:"/emp.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946376/; classtype:trojan-activity;sid:84809476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946377)"; flow:established,from_client; content:"GET"; http_method; content:"/wrd.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.12.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946377/; classtype:trojan-activity;sid:84809477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946375)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"38.55.99.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946375/; classtype:trojan-activity;sid:84809475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946374)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.225.228.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946374/; classtype:trojan-activity;sid:84809474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946373)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.253.80.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946373/; classtype:trojan-activity;sid:84809473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946372)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.193.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946372/; classtype:trojan-activity;sid:84809472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946370)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.69.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946370/; classtype:trojan-activity;sid:84809470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946371)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.86.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946371/; classtype:trojan-activity;sid:84809471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946366)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.236.36.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946366/; classtype:trojan-activity;sid:84809466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946367)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.199.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946367/; classtype:trojan-activity;sid:84809467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946368)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.34.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946368/; classtype:trojan-activity;sid:84809468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946369)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.189.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946369/; classtype:trojan-activity;sid:84809469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946365)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.14.84.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946365/; classtype:trojan-activity;sid:84809465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946364)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.113.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946364/; classtype:trojan-activity;sid:84809464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946363)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.69.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946363/; classtype:trojan-activity;sid:84809463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946361)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.48.146.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946361/; classtype:trojan-activity;sid:84809461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946362)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.253.80.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946362/; classtype:trojan-activity;sid:84809462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946360)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.125.174.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946360/; classtype:trojan-activity;sid:84809460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946359)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.196.41.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946359/; classtype:trojan-activity;sid:84809459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946358)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.215.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946358/; classtype:trojan-activity;sid:84809458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946357)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.34.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946357/; classtype:trojan-activity;sid:84809457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946354)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.236.36.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946354/; classtype:trojan-activity;sid:84809454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946355)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.32.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946355/; classtype:trojan-activity;sid:84809455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946356)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.136.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946356/; classtype:trojan-activity;sid:84809456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946352)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.38.120.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946352/; classtype:trojan-activity;sid:84809452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946353)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"223.10.5.93"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946353/; classtype:trojan-activity;sid:84809453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946351)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.48.146.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946351/; classtype:trojan-activity;sid:84809451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946349)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946349/; classtype:trojan-activity;sid:84809449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946350)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.205.204.128"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946350/; classtype:trojan-activity;sid:84809450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946346)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.206.110.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946346/; classtype:trojan-activity;sid:84809446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946347)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.145.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946347/; classtype:trojan-activity;sid:84809447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946348)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.52.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946348/; classtype:trojan-activity;sid:84809448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946344)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1553507397694267543/1555954495924473926/goobaclient-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8fe8c|7c|26|7c|is=6ac7ad0c|7c|26|7c|hm=30490a5f62bada0ce835ed0448d0c50f22e598bf29d409d1392a080ca82d3798|7c|26|7c|"; http_uri; depth:227; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946344/; classtype:trojan-activity;sid:84809444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946345)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556991568970256465/1556992019174395924/corzcracked.jar|3f|backend=b2|7c|26|7c|ex=6ac8d050|7c|26|7c|is=6ac77ed0|7c|26|7c|hm=3364e8b8209bda9ecad64fa88559296c84ab8d8b0d598c13387100c0489f4e88|7c|26|7c|"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946345/; classtype:trojan-activity;sid:84809445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946343)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1552081896521990165/1555955699362697216/kryptonclient-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8ffaa|7c|26|7c|is=6ac7ae2a|7c|26|7c|hm=32b960a4bf540c7fd00431a7ec304ddd1479175f7be2a9b58e6863530f0fb8ba|7c|26|7c|"; http_uri; depth:229; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946343/; classtype:trojan-activity;sid:84809443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946339)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1554893100869230603/1555954067048763453/zenns-addon-v4-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8fe25|7c|26|7c|is=6ac7aca5|7c|26|7c|hm=d4e0c6b375fa4a495ca11fbd00bca4c21ac78349d84321e29c5a878b1eca76b0|7c|26|7c|"; http_uri; depth:230; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946339/; classtype:trojan-activity;sid:84809439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946340)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1548811185716068484/1555955351206105219/zenns-addon-v4-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8ff57|7c|26|7c|is=6ac7add7|7c|26|7c|hm=30ee7fe8b95274195e39d69d6e7cb98ba63a847928ffd36d4a10117f56ece837|7c|26|7c|"; http_uri; depth:230; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946340/; classtype:trojan-activity;sid:84809440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946341)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1549548390751272981/1555954988667113542/opsec-1.21.11-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8ff01|7c|26|7c|is=6ac7ad81|7c|26|7c|hm=495621443a4b2ffeaee152ecdd0e6db99a74077c550043c0f6653cda754039a9|7c|26|7c|"; http_uri; depth:229; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946341/; classtype:trojan-activity;sid:84809441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946342)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1552082475117715466/1555956021954875493/gamblerig-bydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8fff7|7c|26|7c|is=6ac7ae77|7c|26|7c|hm=60a51d0b7812f7feb59b405104fc25e80f9895b97a3c48a55c9aee5a442ae792|7c|26|7c|"; http_uri; depth:218; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946342/; classtype:trojan-activity;sid:84809442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946337)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1553507058844696606/1555956170961854504/dupemodv2-bydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac9001b|7c|26|7c|is=6ac7ae9b|7c|26|7c|hm=3fa2bf9e9d1e2e1a2f0922f42e35eae758a67f45aaa2a85fea120ceecf68609a|7c|26|7c|"; http_uri; depth:218; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946337/; classtype:trojan-activity;sid:84809437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946338)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1548811292536610887/1555955159287201872/67client-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8ff2a|7c|26|7c|is=6ac7adaa|7c|26|7c|hm=9a556ee8f2a04bb6bf7b6e0d48dd9f70c6c11e1956a9c12895ffd3d2051a835f|7c|26|7c|"; http_uri; depth:224; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946338/; classtype:trojan-activity;sid:84809438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946336)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1552081896521990165/1555955699362697216/kryptonclient-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8ffaa|7c|26|7c|is=6ac7ae2a|7c|26|7c|hm=32b960a4bf540c7fd00431a7ec304ddd1479175f7be2a9b58e6863530f0fb8ba|7c|26|7c|https://cdn.discordapp.com/attachments/1552380411219288175/1555954669157621871/ikea_client-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8feb5|7c|26|7c|is=6ac7ad35|7c|26|7c|hm=bfdcbbaa3aee72faa061c2ccfa23c4b5d3f4c6640b5e5dd8c3e6d1f0c029d7b6|7c|26|7c|"; http_uri; depth:482; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946336/; classtype:trojan-activity;sid:84809436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946333)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1550498309259657247/1555954844391575632/mvaddon-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8fedf|7c|26|7c|is=6ac7ad5f|7c|26|7c|hm=040eabcf0360361a39cf6cea01fba5a346c592fcc725489f3112f3ca3f8b284e|7c|26|7c|"; http_uri; depth:223; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946333/; classtype:trojan-activity;sid:84809433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946334)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1553507130621825175/1555956345495228558/dupemodv1-bydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac90045|7c|26|7c|is=6ac7aec5|7c|26|7c|hm=d109270946e3f8e1f5c6de54f3c7f5bfed7c79c00c564f28ad2919761c2857eb|7c|26|7c|"; http_uri; depth:218; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946334/; classtype:trojan-activity;sid:84809434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946335)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1552380411219288175/1555954669157621871/ikea_client-crackedbydexter.jar|3f|backend=b2|7c|26|7c|ex=6ac8feb5|7c|26|7c|is=6ac7ad35|7c|26|7c|hm=bfdcbbaa3aee72faa061c2ccfa23c4b5d3f4c6640b5e5dd8c3e6d1f0c029d7b6|7c|26|7c|"; http_uri; depth:227; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946335/; classtype:trojan-activity;sid:84809435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946332)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.68.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946332/; classtype:trojan-activity;sid:84809432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946331)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.85.162.250"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946331/; classtype:trojan-activity;sid:84809431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946330)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.24.126.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946330/; classtype:trojan-activity;sid:84809430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946329)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.223.141.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946329/; classtype:trojan-activity;sid:84809429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946328)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"223.10.5.93"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946328/; classtype:trojan-activity;sid:84809428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946327)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.89.252.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946327/; classtype:trojan-activity;sid:84809427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946326)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/enjoyer-addon-1.21.11.jar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946326/; classtype:trojan-activity;sid:84809426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946325)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/wimpy-client-1.21.11.jar"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946325/; classtype:trojan-activity;sid:84809425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946324)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/corz-client-1.21.11.jar"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946324/; classtype:trojan-activity;sid:84809424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946323)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/shared-client-macro-tool.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946323/; classtype:trojan-activity;sid:84809423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946322)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/krypton-avengers-addon-1.21.11.jar"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946322/; classtype:trojan-activity;sid:84809422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946321)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946321/; classtype:trojan-activity;sid:84809421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946320)"; flow:established,from_client; content:"GET"; http_method; content:"/debug.dbg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946320/; classtype:trojan-activity;sid:84809420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946318)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/babo-debug-addon-1.21.11.jar"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946318/; classtype:trojan-activity;sid:84809418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946319)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/fake-skelly-and-elytra-mod-1.21.11.jar"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946319/; classtype:trojan-activity;sid:84809419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946316)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/krypton-client-1.21.11.jar"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946316/; classtype:trojan-activity;sid:84809416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946317)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/larp-addon-1.21.11.jar"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946317/; classtype:trojan-activity;sid:84809417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946315)"; flow:established,from_client; content:"GET"; http_method; content:"/5f55f63f-4335-4413-a67f-64c697161d58"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946315/; classtype:trojan-activity;sid:84809415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946313)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946313/; classtype:trojan-activity;sid:84809413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946314)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/bassa-addon-1.21.11.jar"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"donutclientsmods.xyz"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946314/; classtype:trojan-activity;sid:84809414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946312)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.239.103.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946312/; classtype:trojan-activity;sid:84809412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946311)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_9771925585841dc0.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946311/; classtype:trojan-activity;sid:84809411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946310)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.223.141.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946310/; classtype:trojan-activity;sid:84809410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946309)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.84.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946309/; classtype:trojan-activity;sid:84809409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946308)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.208.164.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946308/; classtype:trojan-activity;sid:84809408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946307)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.86.117.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946307/; classtype:trojan-activity;sid:84809407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946306)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.239.103.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946306/; classtype:trojan-activity;sid:84809406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946305)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.233.198.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946305/; classtype:trojan-activity;sid:84809405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946304)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.132.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946304/; classtype:trojan-activity;sid:84809404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946303)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.214.58.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946303/; classtype:trojan-activity;sid:84809403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946301)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.146.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946301/; classtype:trojan-activity;sid:84809401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946302)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.5.65.221"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946302/; classtype:trojan-activity;sid:84809402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946299)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.146.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946299/; classtype:trojan-activity;sid:84809399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946300)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.208.164.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946300/; classtype:trojan-activity;sid:84809400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946297)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.201.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946297/; classtype:trojan-activity;sid:84809397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946298)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.62.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946298/; classtype:trojan-activity;sid:84809398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946296)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"2.187.251.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946296/; classtype:trojan-activity;sid:84809396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946295)"; flow:established,from_client; content:"GET"; http_method; content:"/file/w1aqh6dqcft06ip/file"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"www.mediafire.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946295/; classtype:trojan-activity;sid:84809395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946294)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"87.5.64.246"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946294/; classtype:trojan-activity;sid:84809394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946293)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_9fc392f279df529c.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946293/; classtype:trojan-activity;sid:84809393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946292)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.147"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946292/; classtype:trojan-activity;sid:84809392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946290)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.197.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946290/; classtype:trojan-activity;sid:84809390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946291)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.72.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946291/; classtype:trojan-activity;sid:84809391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946289)"; flow:established,from_client; content:"GET"; http_method; content:"/svlromhuu0fgbet1vdgw6vzmexzvuu304wflhblzlpxwoklp17drhd-b4tneswce4dogsseiz3hw-ykzxqh44zzcjx3qn40p-khbao574f5pdkpcslkrhm4rra6eznkorrhcgpb1jxfhqy-pqlyo-xwcfmxiqyk8hqpfklc/b9htoqy9l9sgfdx/bfeegnota1q9tl2.95789.40552copia.zip"; http_uri; depth:221; isdataat:!1,relative; nocase; content:"download1472.mediafire.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946289/; classtype:trojan-activity;sid:84809389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946288)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.22.8.194"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946288/; classtype:trojan-activity;sid:84809388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946287)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.70.87.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946287/; classtype:trojan-activity;sid:84809387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946284)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.234.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946284/; classtype:trojan-activity;sid:84809384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946285)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.168.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946285/; classtype:trojan-activity;sid:84809385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946286)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.55.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946286/; classtype:trojan-activity;sid:84809386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946283)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.98.230.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946283/; classtype:trojan-activity;sid:84809383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946282)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.72.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946282/; classtype:trojan-activity;sid:84809382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946280)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.105.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946280/; classtype:trojan-activity;sid:84809380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946281)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.78.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946281/; classtype:trojan-activity;sid:84809381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946279)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_127db278893126d7.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946279/; classtype:trojan-activity;sid:84809379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946278)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_d7bf7d92c202104a.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946278/; classtype:trojan-activity;sid:84809378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946277)"; flow:established,from_client; content:"GET"; http_method; content:"/ycl"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"91.240.118.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946277/; classtype:trojan-activity;sid:84809377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946276)"; flow:established,from_client; content:"GET"; http_method; content:"/service"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"91.240.118.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946276/; classtype:trojan-activity;sid:84809376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946274)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.168.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946274/; classtype:trojan-activity;sid:84809374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946275)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.162.15.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946275/; classtype:trojan-activity;sid:84809375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946273)"; flow:established,from_client; content:"GET"; http_method; content:"/update"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.240.118.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946273/; classtype:trojan-activity;sid:84809373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946272)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.98.230.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946272/; classtype:trojan-activity;sid:84809372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946271)"; flow:established,from_client; content:"GET"; http_method; content:"/files/8351821253/ocnvpm7.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946271/; classtype:trojan-activity;sid:84809371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946270)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.8.211"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946270/; classtype:trojan-activity;sid:84809370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946269)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946269/; classtype:trojan-activity;sid:84809369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946268)"; flow:established,from_client; content:"GET"; http_method; content:"/cinstall.ps1"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"c23c1b-fa77-48e0-8272-692b579a574c.gorsefield.cc"; http_host; depth:48; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946268/; classtype:trojan-activity;sid:84809368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946267)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"sayosay.cc"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946267/; classtype:trojan-activity;sid:84809367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946266)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946266/; classtype:trojan-activity;sid:84809366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946263)"; flow:established,from_client; content:"GET"; http_method; content:"/ljezs/services.apk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946263/; classtype:trojan-activity;sid:84809363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946264)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.x86"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"104.64.0.199"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946264/; classtype:trojan-activity;sid:84809364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946265)"; flow:established,from_client; content:"GET"; http_method; content:"/services.apk"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"108.165.95.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946265/; classtype:trojan-activity;sid:84809365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946262)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.47.72.15"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946262/; classtype:trojan-activity;sid:84809362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946260)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.154.105.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946260/; classtype:trojan-activity;sid:84809360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946261)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.10.234.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946261/; classtype:trojan-activity;sid:84809361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946259)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.13.84.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946259/; classtype:trojan-activity;sid:84809359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946258)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"2.187.248.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946258/; classtype:trojan-activity;sid:84809358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946257)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.34.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946257/; classtype:trojan-activity;sid:84809357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946256)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.202.215.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946256/; classtype:trojan-activity;sid:84809356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946255)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.70.101.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946255/; classtype:trojan-activity;sid:84809355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946254)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.154.105.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946254/; classtype:trojan-activity;sid:84809354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946251)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.136.85.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946251/; classtype:trojan-activity;sid:84809351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946252)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.176.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946252/; classtype:trojan-activity;sid:84809352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946253)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.182.169"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946253/; classtype:trojan-activity;sid:84809353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946250)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.202.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946250/; classtype:trojan-activity;sid:84809350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946248/; classtype:trojan-activity;sid:84809348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.8.211"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946249/; classtype:trojan-activity;sid:84809349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946247)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.202.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946247/; classtype:trojan-activity;sid:84809347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946245)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.202.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946245/; classtype:trojan-activity;sid:84809345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946246)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.196.0.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946246/; classtype:trojan-activity;sid:84809346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946242)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.10.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946242/; classtype:trojan-activity;sid:84809342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946243)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.7.18"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946243/; classtype:trojan-activity;sid:84809343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946244)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.34.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946244/; classtype:trojan-activity;sid:84809344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946241)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.246.228.19"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946241/; classtype:trojan-activity;sid:84809341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946238)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.202.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946238/; classtype:trojan-activity;sid:84809338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946239)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.157.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946239/; classtype:trojan-activity;sid:84809339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946240)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.4.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946240/; classtype:trojan-activity;sid:84809340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946237)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.117.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946237/; classtype:trojan-activity;sid:84809337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946236)"; flow:established,from_client; content:"GET"; http_method; content:"/bussiness12/server/raw/main/newfloder.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"bitbucket.org"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946236/; classtype:trojan-activity;sid:84809336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946235)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.74.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946235/; classtype:trojan-activity;sid:84809335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946231)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.171.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946231/; classtype:trojan-activity;sid:84809331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946232)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.173.2.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946232/; classtype:trojan-activity;sid:84809332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946233)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.13.43.153"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946233/; classtype:trojan-activity;sid:84809333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946234)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.112.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946234/; classtype:trojan-activity;sid:84809334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946230)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946230/; classtype:trojan-activity;sid:84809330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946227)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946227/; classtype:trojan-activity;sid:84809327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946228)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pm68k"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946228/; classtype:trojan-activity;sid:84809328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946229)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946229/; classtype:trojan-activity;sid:84809329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946218)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946218/; classtype:trojan-activity;sid:84809318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946219)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946219/; classtype:trojan-activity;sid:84809319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946220)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946220/; classtype:trojan-activity;sid:84809320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946221)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946221/; classtype:trojan-activity;sid:84809321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946222)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946222/; classtype:trojan-activity;sid:84809322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946223)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946223/; classtype:trojan-activity;sid:84809323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946224)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946224/; classtype:trojan-activity;sid:84809324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946225)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946225/; classtype:trojan-activity;sid:84809325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946226)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.50.134.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946226/; classtype:trojan-activity;sid:84809326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946208)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm6"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946208/; classtype:trojan-activity;sid:84809308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946209)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946209/; classtype:trojan-activity;sid:84809309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946210)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946210/; classtype:trojan-activity;sid:84809310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946211)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946211/; classtype:trojan-activity;sid:84809311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946212)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946212/; classtype:trojan-activity;sid:84809312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946213)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946213/; classtype:trojan-activity;sid:84809313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946214)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946214/; classtype:trojan-activity;sid:84809314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946215)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946215/; classtype:trojan-activity;sid:84809315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946216)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.spc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946216/; classtype:trojan-activity;sid:84809316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946217)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"204.194.50.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946217/; classtype:trojan-activity;sid:84809317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946199)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946199/; classtype:trojan-activity;sid:84809299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946200)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946200/; classtype:trojan-activity;sid:84809300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946201)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946201/; classtype:trojan-activity;sid:84809301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946202)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946202/; classtype:trojan-activity;sid:84809302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946203)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmpsl"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946203/; classtype:trojan-activity;sid:84809303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946204)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946204/; classtype:trojan-activity;sid:84809304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946205)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946205/; classtype:trojan-activity;sid:84809305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946206)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/psh4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946206/; classtype:trojan-activity;sid:84809306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946207)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946207/; classtype:trojan-activity;sid:84809307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946197)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.4.17"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946197/; classtype:trojan-activity;sid:84809297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946198)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.216.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946198/; classtype:trojan-activity;sid:84809298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946196)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.140.187.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946196/; classtype:trojan-activity;sid:84809296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946195)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.173.212.106"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946195/; classtype:trojan-activity;sid:84809295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946194)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.4.17"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946194/; classtype:trojan-activity;sid:84809294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946193)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.101.213.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946193/; classtype:trojan-activity;sid:84809293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946192)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.146.93"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946192/; classtype:trojan-activity;sid:84809292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.34.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946189/; classtype:trojan-activity;sid:84809289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.54.182.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946190/; classtype:trojan-activity;sid:84809290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946191)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.19.83.106"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946191/; classtype:trojan-activity;sid:84809291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946187)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.52.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946187/; classtype:trojan-activity;sid:84809287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946188)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.232.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946188/; classtype:trojan-activity;sid:84809288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946186)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.110.9.54"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946186/; classtype:trojan-activity;sid:84809286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946184)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.236.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946184/; classtype:trojan-activity;sid:84809284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946185)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.59.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946185/; classtype:trojan-activity;sid:84809285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946182)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.52.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946182/; classtype:trojan-activity;sid:84809282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946183)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.228.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946183/; classtype:trojan-activity;sid:84809283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946181)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.176.103"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946181/; classtype:trojan-activity;sid:84809281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946180)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.232.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946180/; classtype:trojan-activity;sid:84809280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946179)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.176.103"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946179/; classtype:trojan-activity;sid:84809279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946178)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.34.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946178/; classtype:trojan-activity;sid:84809278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946177)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"200.115.102.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946177/; classtype:trojan-activity;sid:84809277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946176)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.30.44.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946176/; classtype:trojan-activity;sid:84809276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946175)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.11.118"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946175/; classtype:trojan-activity;sid:84809275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946174)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.71.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946174/; classtype:trojan-activity;sid:84809274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946173)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.59.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946173/; classtype:trojan-activity;sid:84809273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946168)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.236.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946168/; classtype:trojan-activity;sid:84809268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946169)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.61.11.118"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946169/; classtype:trojan-activity;sid:84809269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946170)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.214.58.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946170/; classtype:trojan-activity;sid:84809270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946171)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.156.34.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946171/; classtype:trojan-activity;sid:84809271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946172)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.113.53"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946172/; classtype:trojan-activity;sid:84809272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946165)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.232.228.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946165/; classtype:trojan-activity;sid:84809265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946166)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.178.216.181"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946166/; classtype:trojan-activity;sid:84809266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946167)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.117.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946167/; classtype:trojan-activity;sid:84809267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946164)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_234853.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ascomsecurity.com.au"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946164/; classtype:trojan-activity;sid:84809264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946163)"; flow:established,from_client; content:"GET"; http_method; content:"/hta/oo.txt"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"www.epibenie.dz"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946163/; classtype:trojan-activity;sid:84809263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946162)"; flow:established,from_client; content:"GET"; http_method; content:"/vuztq"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946162/; classtype:trojan-activity;sid:84809262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946161)"; flow:established,from_client; content:"GET"; http_method; content:"/wtyt1562/secured_stub.ps1"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"195.177.94.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946161/; classtype:trojan-activity;sid:84809261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946160)"; flow:established,from_client; content:"GET"; http_method; content:"/nnzez/secured_stub.ps1"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946160/; classtype:trojan-activity;sid:84809260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946159)"; flow:established,from_client; content:"GET"; http_method; content:"/masaabikz/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946159/; classtype:trojan-activity;sid:84809259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946158)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.98.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946158/; classtype:trojan-activity;sid:84809258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946157)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.46.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946157/; classtype:trojan-activity;sid:84809257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946155)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.52.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946155/; classtype:trojan-activity;sid:84809255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946156)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.46.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946156/; classtype:trojan-activity;sid:84809256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946154)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/connectwisecontrol.clientsetup.msi|3f|h=13.37.72.210|7c|26|7c|p=8041|7c|26|7c|k=bgiaaackaabsu0exaagaaaeaaqafj7zuwxp5bwvihjtbf5tpj7sz3vzwfq8m7qzruurh8ddt5zth16exqctqgtdc3%2f6cderipg90lvrjzx4%2fuh8mhic8wt2uhwg0ttg%2bw8jnkihaix5%2bak5v%2fblg7zv8vvpvipen%2bijwkto%2b%2ft2rajjkmneizxvhbdkkmcgloguooehqtd2zzee%2b%2bybikt2%2btii8jvjd9udccudkobtniilma4ld%2f18hsk9ixwik3cby%2bibrxpop6s%2ba2rbet3wdvt0np%2bdqruokf2a8iowrzdsyay9rezq6vqse0ufvmlhinz31aqkpmmomth4o%2bmavaj8l%2b4%2b2cando%2bb6%2bfylxuza|7c|26|7c|e=access|7c|26|7c|y=guest|7c|26|7c|t=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c="; http_uri; depth:636; isdataat:!1,relative; nocase; content:"13.37.72.210"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946154/; classtype:trojan-activity;sid:84809254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946153)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.30.44.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946153/; classtype:trojan-activity;sid:84809253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946152)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.177.28.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946152/; classtype:trojan-activity;sid:84809252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946151)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.203.183.158"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946151/; classtype:trojan-activity;sid:84809251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946150)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.147.208"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946150/; classtype:trojan-activity;sid:84809250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946148)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.161.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946148/; classtype:trojan-activity;sid:84809248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946149)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.134.173.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946149/; classtype:trojan-activity;sid:84809249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946146)"; flow:established,from_client; content:"GET"; http_method; content:"/api/settings/linux"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"trickgs-demo.vercel.app"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946146/; classtype:trojan-activity;sid:84809246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946147)"; flow:established,from_client; content:"GET"; http_method; content:"/api/settings/env"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"trickgs-demo.vercel.app"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946147/; classtype:trojan-activity;sid:84809247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946143)"; flow:established,from_client; content:"GET"; http_method; content:"/api/settings/windows"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"trickgs-demo.vercel.app"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946143/; classtype:trojan-activity;sid:84809243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946144)"; flow:established,from_client; content:"GET"; http_method; content:"/api/settings/mac"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"trickgs-demo.vercel.app"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946144/; classtype:trojan-activity;sid:84809244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946142)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.73.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946142/; classtype:trojan-activity;sid:84809242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946141)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.201.98.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946141/; classtype:trojan-activity;sid:84809241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946140)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.206.110.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946140/; classtype:trojan-activity;sid:84809240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946139)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.149.88.179"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946139/; classtype:trojan-activity;sid:84809239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946134)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.88.136.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946134/; classtype:trojan-activity;sid:84809234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946135)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.63.156.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946135/; classtype:trojan-activity;sid:84809235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946136)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"208.102.160.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946136/; classtype:trojan-activity;sid:84809236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946137)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.221.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946137/; classtype:trojan-activity;sid:84809237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946138)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.192.166"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946138/; classtype:trojan-activity;sid:84809238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946131)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.10.70.76"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946131/; classtype:trojan-activity;sid:84809231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946132)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.202.187.80"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946132/; classtype:trojan-activity;sid:84809232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946133)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"208.102.160.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946133/; classtype:trojan-activity;sid:84809233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946129)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.237.57.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946129/; classtype:trojan-activity;sid:84809229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946130)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.34.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946130/; classtype:trojan-activity;sid:84809230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946128)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.169.0.215"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946128/; classtype:trojan-activity;sid:84809228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946127)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.103.69.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946127/; classtype:trojan-activity;sid:84809227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946125)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.179.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946125/; classtype:trojan-activity;sid:84809225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946126)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.221.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946126/; classtype:trojan-activity;sid:84809226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946123)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.229.105.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946123/; classtype:trojan-activity;sid:84809223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946124)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.162.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946124/; classtype:trojan-activity;sid:84809224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946122)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.168.132.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946122/; classtype:trojan-activity;sid:84809222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946121)"; flow:established,from_client; content:"GET"; http_method; content:"/amkadmm.txt"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"31.40.204.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946121/; classtype:trojan-activity;sid:84809221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946120)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/geen.ps1"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946120/; classtype:trojan-activity;sid:84809220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946118)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/gg.ps1"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946118/; classtype:trojan-activity;sid:84809218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946119)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/secured_stub.ps1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946119/; classtype:trojan-activity;sid:84809219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946117)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/ttessttt.ps1"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946117/; classtype:trojan-activity;sid:84809217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946116)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/ss.ps1"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946116/; classtype:trojan-activity;sid:84809216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946115)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.162.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946115/; classtype:trojan-activity;sid:84809215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946114)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.169.0.215"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946114/; classtype:trojan-activity;sid:84809214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946112)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.239.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946112/; classtype:trojan-activity;sid:84809212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946113)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.96.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946113/; classtype:trojan-activity;sid:84809213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946111)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.82.142.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946111/; classtype:trojan-activity;sid:84809211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946110)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.88.227.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946110/; classtype:trojan-activity;sid:84809210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946108)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.197.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946108/; classtype:trojan-activity;sid:84809208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946109)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.229.105.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946109/; classtype:trojan-activity;sid:84809209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946107)"; flow:established,from_client; content:"GET"; http_method; content:"/fps/oocjafe.txt"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"nd.tdpqnf.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946107/; classtype:trojan-activity;sid:84809207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946106)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.164.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946106/; classtype:trojan-activity;sid:84809206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946105)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_7df6c134d8cd42cd.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946105/; classtype:trojan-activity;sid:84809205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946104)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.139.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946104/; classtype:trojan-activity;sid:84809204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946103)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.arm4"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946103/; classtype:trojan-activity;sid:84809203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946101)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.94.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946101/; classtype:trojan-activity;sid:84809201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946102)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.197.62.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946102/; classtype:trojan-activity;sid:84809202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946100)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.144.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946100/; classtype:trojan-activity;sid:84809200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946099)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.239.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946099/; classtype:trojan-activity;sid:84809199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946096)"; flow:established,from_client; content:"GET"; http_method; content:"/jklsh4"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946096/; classtype:trojan-activity;sid:84809196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946097)"; flow:established,from_client; content:"GET"; http_method; content:"/jklmpsl"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946097/; classtype:trojan-activity;sid:84809197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946098)"; flow:established,from_client; content:"GET"; http_method; content:"/jklm68k"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946098/; classtype:trojan-activity;sid:84809198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946092)"; flow:established,from_client; content:"GET"; http_method; content:"/jklppc"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946092/; classtype:trojan-activity;sid:84809192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946093)"; flow:established,from_client; content:"GET"; http_method; content:"/jklspc"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946093/; classtype:trojan-activity;sid:84809193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946094)"; flow:established,from_client; content:"GET"; http_method; content:"/jklx86"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946094/; classtype:trojan-activity;sid:84809194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946095)"; flow:established,from_client; content:"GET"; http_method; content:"/jklmips"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946095/; classtype:trojan-activity;sid:84809195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946088)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.153.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946088/; classtype:trojan-activity;sid:84809188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946089)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.42.122.31"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946089/; classtype:trojan-activity;sid:84809189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946090)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.222.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946090/; classtype:trojan-activity;sid:84809190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946091)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.206.175.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946091/; classtype:trojan-activity;sid:84809191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946087)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.177.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946087/; classtype:trojan-activity;sid:84809187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946086)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.93.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946086/; classtype:trojan-activity;sid:84809186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946085)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.ppc"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946085/; classtype:trojan-activity;sid:84809185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946084)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.x86"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946084/; classtype:trojan-activity;sid:84809184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946077)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.sh4"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946077/; classtype:trojan-activity;sid:84809177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946078)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.mpsl"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946078/; classtype:trojan-activity;sid:84809178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946079)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.m68k"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946079/; classtype:trojan-activity;sid:84809179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946080)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.mips"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946080/; classtype:trojan-activity;sid:84809180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946081)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.arm7"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946081/; classtype:trojan-activity;sid:84809181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946082)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.arm6"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946082/; classtype:trojan-activity;sid:84809182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946083)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.arm5"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946083/; classtype:trojan-activity;sid:84809183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946075)"; flow:established,from_client; content:"GET"; http_method; content:"/pandoras_box/pandora.arm"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946075/; classtype:trojan-activity;sid:84809175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946076)"; flow:established,from_client; content:"GET"; http_method; content:"/pandora.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.149.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946076/; classtype:trojan-activity;sid:84809176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946061)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946061/; classtype:trojan-activity;sid:84809161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946062)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946062/; classtype:trojan-activity;sid:84809162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946063)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946063/; classtype:trojan-activity;sid:84809163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946064)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946064/; classtype:trojan-activity;sid:84809164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946065)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946065/; classtype:trojan-activity;sid:84809165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946066)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946066/; classtype:trojan-activity;sid:84809166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946067)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946067/; classtype:trojan-activity;sid:84809167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946068)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946068/; classtype:trojan-activity;sid:84809168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946069)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946069/; classtype:trojan-activity;sid:84809169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946070)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946070/; classtype:trojan-activity;sid:84809170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946071)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946071/; classtype:trojan-activity;sid:84809171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946072)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946072/; classtype:trojan-activity;sid:84809172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946073)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946073/; classtype:trojan-activity;sid:84809173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946074)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"94.183.174.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946074/; classtype:trojan-activity;sid:84809174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946060)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.58.106.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946060/; classtype:trojan-activity;sid:84809160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946058)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.182.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946058/; classtype:trojan-activity;sid:84809158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946059)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.120.118"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946059/; classtype:trojan-activity;sid:84809159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946057)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.165.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946057/; classtype:trojan-activity;sid:84809157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946052)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.42.122.31"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946052/; classtype:trojan-activity;sid:84809152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946053)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.206.175.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946053/; classtype:trojan-activity;sid:84809153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946054)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.187.197.115"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946054/; classtype:trojan-activity;sid:84809154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946055)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.139.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946055/; classtype:trojan-activity;sid:84809155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946056)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"187.110.223.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946056/; classtype:trojan-activity;sid:84809156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946051)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.8.8.177"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946051/; classtype:trojan-activity;sid:84809151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946049)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"187.110.223.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946049/; classtype:trojan-activity;sid:84809149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946050)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.177.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946050/; classtype:trojan-activity;sid:84809150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946047)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.64.163.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946047/; classtype:trojan-activity;sid:84809147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946048)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.234.99.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946048/; classtype:trojan-activity;sid:84809148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946043)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946043/; classtype:trojan-activity;sid:84809143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946044)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946044/; classtype:trojan-activity;sid:84809144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946045)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946045/; classtype:trojan-activity;sid:84809145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946046)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946046/; classtype:trojan-activity;sid:84809146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946039)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946039/; classtype:trojan-activity;sid:84809139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946040)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946040/; classtype:trojan-activity;sid:84809140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946041)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946041/; classtype:trojan-activity;sid:84809141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946042)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946042/; classtype:trojan-activity;sid:84809142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946036)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.i586"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946036/; classtype:trojan-activity;sid:84809136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946037)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.i486"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946037/; classtype:trojan-activity;sid:84809137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946038)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/byte.powerpc"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946038/; classtype:trojan-activity;sid:84809138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946033)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.139.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946033/; classtype:trojan-activity;sid:84809133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946034)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.255.43.208"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946034/; classtype:trojan-activity;sid:84809134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946035)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.218.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946035/; classtype:trojan-activity;sid:84809135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946031)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.169.236.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946031/; classtype:trojan-activity;sid:84809131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946032)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.115.102.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946032/; classtype:trojan-activity;sid:84809132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946030)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.40.140.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946030/; classtype:trojan-activity;sid:84809130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946029)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.240.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946029/; classtype:trojan-activity;sid:84809129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946028)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.166.188.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946028/; classtype:trojan-activity;sid:84809128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946027)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.30.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946027/; classtype:trojan-activity;sid:84809127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946026)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.113.175.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946026/; classtype:trojan-activity;sid:84809126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946025)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.184.107.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946025/; classtype:trojan-activity;sid:84809125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946022)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.164.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946022/; classtype:trojan-activity;sid:84809122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946023)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.162.15.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946023/; classtype:trojan-activity;sid:84809123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946024)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.93.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946024/; classtype:trojan-activity;sid:84809124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946021)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.113.175.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946021/; classtype:trojan-activity;sid:84809121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946020)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.179.145"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946020/; classtype:trojan-activity;sid:84809120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946019)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.78.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946019/; classtype:trojan-activity;sid:84809119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946017)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.16.97"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946017/; classtype:trojan-activity;sid:84809117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946018)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.240.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946018/; classtype:trojan-activity;sid:84809118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946016)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.188.196.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946016/; classtype:trojan-activity;sid:84809116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946015)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.168.132.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946015/; classtype:trojan-activity;sid:84809115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946014)"; flow:established,from_client; content:"GET"; http_method; content:"/furiousfade/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946014/; classtype:trojan-activity;sid:84809114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946012)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.160.220.86"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946012/; classtype:trojan-activity;sid:84809112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946013)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.229.175.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946013/; classtype:trojan-activity;sid:84809113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946009)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.213.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946009/; classtype:trojan-activity;sid:84809109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946010)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.214.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946010/; classtype:trojan-activity;sid:84809110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946011)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.169.236.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946011/; classtype:trojan-activity;sid:84809111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946008)"; flow:established,from_client; content:"GET"; http_method; content:"/sorellyc/swift-executor/head/swift.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946008/; classtype:trojan-activity;sid:84809108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946007)"; flow:established,from_client; content:"GET"; http_method; content:"/12312d12e1/31/releases/download/michael/bundle.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946007/; classtype:trojan-activity;sid:84809107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946006)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/421625572146544650/1557485873053040820/bundle.zip|3f|backend=b2|7c|26|7c|ex=6ac7f940|7c|26|7c|is=6ac6a7c0|7c|26|7c|hm=21e27832c6b4e6ca2b2ea4e2fd13d863307d2fbc370e0ddaf0aa734c2d0a7b22|7c|26|7c|"; http_uri; depth:205; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946006/; classtype:trojan-activity;sid:84809106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946004)"; flow:established,from_client; content:"GET"; http_method; content:"/jennybenz/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946004/; classtype:trojan-activity;sid:84809104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946005)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/421625572146544650/1557483240623710298/bundle.zip|3f|backend=b2|7c|26|7c|ex=6ac7f6cd|7c|26|7c|is=6ac6a54d|7c|26|7c|hm=70027c5d396acff855a795907353c704ac0f7984562f173941ce2c381098eb57|7c|26|7c|"; http_uri; depth:205; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946005/; classtype:trojan-activity;sid:84809105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946003)"; flow:established,from_client; content:"GET"; http_method; content:"/darkmodss/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946003/; classtype:trojan-activity;sid:84809103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946001)"; flow:established,from_client; content:"GET"; http_method; content:"/kl1ssfa/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946001/; classtype:trojan-activity;sid:84809101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946002)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-33102/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946002/; classtype:trojan-activity;sid:84809102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945999)"; flow:established,from_client; content:"GET"; http_method; content:"/twistaflow/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945999/; classtype:trojan-activity;sid:84809099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3946000)"; flow:established,from_client; content:"GET"; http_method; content:"/britishway/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3946000/; classtype:trojan-activity;sid:84809100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945997)"; flow:established,from_client; content:"GET"; http_method; content:"/noelfeelin/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945997/; classtype:trojan-activity;sid:84809097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945998)"; flow:established,from_client; content:"GET"; http_method; content:"/monsterkiller00k/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945998/; classtype:trojan-activity;sid:84809098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945996)"; flow:established,from_client; content:"GET"; http_method; content:"/vampscore/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945996/; classtype:trojan-activity;sid:84809096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945995)"; flow:established,from_client; content:"GET"; http_method; content:"/layssh0/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945995/; classtype:trojan-activity;sid:84809095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945994)"; flow:established,from_client; content:"GET"; http_method; content:"/tiffanyscore/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945994/; classtype:trojan-activity;sid:84809094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945992)"; flow:established,from_client; content:"GET"; http_method; content:"/whitelines/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945992/; classtype:trojan-activity;sid:84809092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945993)"; flow:established,from_client; content:"GET"; http_method; content:"/ladycage/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945993/; classtype:trojan-activity;sid:84809093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945990)"; flow:established,from_client; content:"GET"; http_method; content:"/claryfine/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945990/; classtype:trojan-activity;sid:84809090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945991)"; flow:established,from_client; content:"GET"; http_method; content:"/amnesiacalms/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945991/; classtype:trojan-activity;sid:84809091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945989)"; flow:established,from_client; content:"GET"; http_method; content:"/daregods/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945989/; classtype:trojan-activity;sid:84809089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945988)"; flow:established,from_client; content:"GET"; http_method; content:"/raindroped/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945988/; classtype:trojan-activity;sid:84809088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945987)"; flow:established,from_client; content:"GET"; http_method; content:"/brjs5fcrfsoawqvux9xq"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"cdn.filestackcontent.com"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945987/; classtype:trojan-activity;sid:84809087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945982)"; flow:established,from_client; content:"GET"; http_method; content:"/centralmods/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945982/; classtype:trojan-activity;sid:84809082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945983)"; flow:established,from_client; content:"GET"; http_method; content:"/missgracess/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945983/; classtype:trojan-activity;sid:84809083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945984)"; flow:established,from_client; content:"GET"; http_method; content:"/camunlocks/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945984/; classtype:trojan-activity;sid:84809084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945985)"; flow:established,from_client; content:"GET"; http_method; content:"/andyrolls/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945985/; classtype:trojan-activity;sid:84809085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945986)"; flow:established,from_client; content:"GET"; http_method; content:"/bodycat/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945986/; classtype:trojan-activity;sid:84809086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945981)"; flow:established,from_client; content:"GET"; http_method; content:"/curl.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945981/; classtype:trojan-activity;sid:84809081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945980)"; flow:established,from_client; content:"GET"; http_method; content:"/southhood/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945980/; classtype:trojan-activity;sid:84809080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945978)"; flow:established,from_client; content:"GET"; http_method; content:"/lampage3/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945978/; classtype:trojan-activity;sid:84809078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945979)"; flow:established,from_client; content:"GET"; http_method; content:"/fireplane/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945979/; classtype:trojan-activity;sid:84809079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945976)"; flow:established,from_client; content:"GET"; http_method; content:"/enginedevs/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945976/; classtype:trojan-activity;sid:84809076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945977)"; flow:established,from_client; content:"GET"; http_method; content:"/ericknutty/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945977/; classtype:trojan-activity;sid:84809077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945975)"; flow:established,from_client; content:"GET"; http_method; content:"/eversply/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945975/; classtype:trojan-activity;sid:84809075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945967)"; flow:established,from_client; content:"GET"; http_method; content:"/lapurtk1n/fluxusexecutor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945967/; classtype:trojan-activity;sid:84809067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945968)"; flow:established,from_client; content:"GET"; http_method; content:"/recklessstyle/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945968/; classtype:trojan-activity;sid:84809068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945969)"; flow:established,from_client; content:"GET"; http_method; content:"/madglint/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945969/; classtype:trojan-activity;sid:84809069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945970)"; flow:established,from_client; content:"GET"; http_method; content:"/salivaenergy/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945970/; classtype:trojan-activity;sid:84809070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945971)"; flow:established,from_client; content:"GET"; http_method; content:"/r3tard3dn1gg3r/hwid-spoofer/-/raw/main/universalspoofer.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945971/; classtype:trojan-activity;sid:84809071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945972)"; flow:established,from_client; content:"GET"; http_method; content:"/shan1al/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945972/; classtype:trojan-activity;sid:84809072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945973)"; flow:established,from_client; content:"GET"; http_method; content:"/brandonhills/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945973/; classtype:trojan-activity;sid:84809073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945974)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/79k5p6k67h63.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945974/; classtype:trojan-activity;sid:84809074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945962)"; flow:established,from_client; content:"GET"; http_method; content:"/shanecall/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945962/; classtype:trojan-activity;sid:84809062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945963)"; flow:established,from_client; content:"GET"; http_method; content:"/m1ramme/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945963/; classtype:trojan-activity;sid:84809063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945964)"; flow:established,from_client; content:"GET"; http_method; content:"/huntyexiles/pubg-desync-menu/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945964/; classtype:trojan-activity;sid:84809064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945965)"; flow:established,from_client; content:"GET"; http_method; content:"/britneyspears/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945965/; classtype:trojan-activity;sid:84809065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945966)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-42512/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945966/; classtype:trojan-activity;sid:84809066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945961)"; flow:established,from_client; content:"GET"; http_method; content:"/flizzlebeep/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945961/; classtype:trojan-activity;sid:84809061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945960)"; flow:established,from_client; content:"GET"; http_method; content:"/akkil1fe/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945960/; classtype:trojan-activity;sid:84809060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945959)"; flow:established,from_client; content:"GET"; http_method; content:"/renn1chls/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945959/; classtype:trojan-activity;sid:84809059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945956)"; flow:established,from_client; content:"GET"; http_method; content:"/vvhsa/phoenixc2/head/phoenixc2.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945956/; classtype:trojan-activity;sid:84809056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945957)"; flow:established,from_client; content:"GET"; http_method; content:"/mobydevs/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945957/; classtype:trojan-activity;sid:84809057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945958)"; flow:established,from_client; content:"GET"; http_method; content:"/beyondstyle/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945958/; classtype:trojan-activity;sid:84809058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945950)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.147.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945950/; classtype:trojan-activity;sid:84809050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945951)"; flow:established,from_client; content:"GET"; http_method; content:"/prittery/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945951/; classtype:trojan-activity;sid:84809051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945952)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.71.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945952/; classtype:trojan-activity;sid:84809052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945953)"; flow:established,from_client; content:"GET"; http_method; content:"/jklarm5"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945953/; classtype:trojan-activity;sid:84809053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945954)"; flow:established,from_client; content:"GET"; http_method; content:"/draggelons/fortniteexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945954/; classtype:trojan-activity;sid:84809054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945955)"; flow:established,from_client; content:"GET"; http_method; content:"/vaitrex/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945955/; classtype:trojan-activity;sid:84809055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945949)"; flow:established,from_client; content:"GET"; http_method; content:"/r0undshann/phoenixc2/head/phoenixc2.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945949/; classtype:trojan-activity;sid:84809049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945947)"; flow:established,from_client; content:"GET"; http_method; content:"/darkobenz/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945947/; classtype:trojan-activity;sid:84809047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945948)"; flow:established,from_client; content:"GET"; http_method; content:"/limmaplessh/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945948/; classtype:trojan-activity;sid:84809048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945946)"; flow:established,from_client; content:"GET"; http_method; content:"/conzully/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945946/; classtype:trojan-activity;sid:84809046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945943)"; flow:established,from_client; content:"GET"; http_method; content:"/alterbridge/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945943/; classtype:trojan-activity;sid:84809043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945944)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenflows/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945944/; classtype:trojan-activity;sid:84809044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945945)"; flow:established,from_client; content:"GET"; http_method; content:"/louiremble/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945945/; classtype:trojan-activity;sid:84809045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945941)"; flow:established,from_client; content:"GET"; http_method; content:"/ainnessceth/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945941/; classtype:trojan-activity;sid:84809041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945942)"; flow:established,from_client; content:"GET"; http_method; content:"/barriels/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945942/; classtype:trojan-activity;sid:84809042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945940)"; flow:established,from_client; content:"GET"; http_method; content:"/escaless/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945940/; classtype:trojan-activity;sid:84809040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945938)"; flow:established,from_client; content:"GET"; http_method; content:"/duntees/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945938/; classtype:trojan-activity;sid:84809038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945939)"; flow:established,from_client; content:"GET"; http_method; content:"/alennciruous/valorantexternalcheat/head/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945939/; classtype:trojan-activity;sid:84809039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945936)"; flow:established,from_client; content:"GET"; http_method; content:"/realness/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945936/; classtype:trojan-activity;sid:84809036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945937)"; flow:established,from_client; content:"GET"; http_method; content:"/snaffl3k/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945937/; classtype:trojan-activity;sid:84809037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945932)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisrule/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945932/; classtype:trojan-activity;sid:84809032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945933)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.9.149.168"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945933/; classtype:trojan-activity;sid:84809033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945934)"; flow:established,from_client; content:"GET"; http_method; content:"/spellytfx/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945934/; classtype:trojan-activity;sid:84809034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945935)"; flow:established,from_client; content:"GET"; http_method; content:"/axielles/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945935/; classtype:trojan-activity;sid:84809035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945929)"; flow:established,from_client; content:"GET"; http_method; content:"/harnelly/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945929/; classtype:trojan-activity;sid:84809029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945930)"; flow:established,from_client; content:"GET"; http_method; content:"/shaerrlys/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945930/; classtype:trojan-activity;sid:84809030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945931)"; flow:established,from_client; content:"GET"; http_method; content:"/rainsofpist/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945931/; classtype:trojan-activity;sid:84809031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945925)"; flow:established,from_client; content:"GET"; http_method; content:"/raceway/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945925/; classtype:trojan-activity;sid:84809025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945926)"; flow:established,from_client; content:"GET"; http_method; content:"/1meonl1f/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945926/; classtype:trojan-activity;sid:84809026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945927)"; flow:established,from_client; content:"GET"; http_method; content:"/darkfantasy/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945927/; classtype:trojan-activity;sid:84809027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945928)"; flow:established,from_client; content:"GET"; http_method; content:"/socialwares/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945928/; classtype:trojan-activity;sid:84809028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945922)"; flow:established,from_client; content:"GET"; http_method; content:"/amelisy/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945922/; classtype:trojan-activity;sid:84809022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945923)"; flow:established,from_client; content:"GET"; http_method; content:"/mertzdev1/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945923/; classtype:trojan-activity;sid:84809023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945924)"; flow:established,from_client; content:"GET"; http_method; content:"/ivsoryeh/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945924/; classtype:trojan-activity;sid:84809024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945921)"; flow:established,from_client; content:"GET"; http_method; content:"/lanofierry/skriptgg/head/skriptgg.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945921/; classtype:trojan-activity;sid:84809021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945920)"; flow:established,from_client; content:"GET"; http_method; content:"/sullenst/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945920/; classtype:trojan-activity;sid:84809020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945918)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_4e463941a19f86ca.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945918/; classtype:trojan-activity;sid:84809018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945919)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"beschaffung-portal.de"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945919/; classtype:trojan-activity;sid:84809019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945909)"; flow:established,from_client; content:"GET"; http_method; content:"/queensmile/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945909/; classtype:trojan-activity;sid:84809009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945910)"; flow:established,from_client; content:"GET"; http_method; content:"/expensiveram/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945910/; classtype:trojan-activity;sid:84809010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945911)"; flow:established,from_client; content:"GET"; http_method; content:"/gleeshplace/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945911/; classtype:trojan-activity;sid:84809011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945912)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.229.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945912/; classtype:trojan-activity;sid:84809012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945913)"; flow:established,from_client; content:"GET"; http_method; content:"/c1ehrr/valorantexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945913/; classtype:trojan-activity;sid:84809013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945914)"; flow:established,from_client; content:"GET"; http_method; content:"/terr19/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945914/; classtype:trojan-activity;sid:84809014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945915)"; flow:established,from_client; content:"GET"; http_method; content:"/rainformage/verox-gta-enhanced/head/verox.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945915/; classtype:trojan-activity;sid:84809015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945916)"; flow:established,from_client; content:"GET"; http_method; content:"/minepluss/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945916/; classtype:trojan-activity;sid:84809016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945917)"; flow:established,from_client; content:"GET"; http_method; content:"/bleddymight/skriptgg/head/skriptgg.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945917/; classtype:trojan-activity;sid:84809017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945905)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"evergabe-bund.de"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945905/; classtype:trojan-activity;sid:84809005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945906)"; flow:established,from_client; content:"GET"; http_method; content:"/markendows/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945906/; classtype:trojan-activity;sid:84809006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945907)"; flow:established,from_client; content:"GET"; http_method; content:"/rudeboyy/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945907/; classtype:trojan-activity;sid:84809007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945908)"; flow:established,from_client; content:"GET"; http_method; content:"/nixxywors/redengine-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945908/; classtype:trojan-activity;sid:84809008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945904)"; flow:established,from_client; content:"GET"; http_method; content:"/h1endless/phoenixc2/head/phoenixc2.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945904/; classtype:trojan-activity;sid:84809004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945902)"; flow:established,from_client; content:"GET"; http_method; content:"/terrhl/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945902/; classtype:trojan-activity;sid:84809002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945903)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945903/; classtype:trojan-activity;sid:84809003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945900)"; flow:established,from_client; content:"GET"; http_method; content:"/hannesye/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945900/; classtype:trojan-activity;sid:84809000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945901)"; flow:established,from_client; content:"GET"; http_method; content:"/s.ps1"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"stanarcservice.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945901/; classtype:trojan-activity;sid:84809001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945899)"; flow:established,from_client; content:"GET"; http_method; content:"/mackneck/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945899/; classtype:trojan-activity;sid:84808999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945898)"; flow:established,from_client; content:"GET"; http_method; content:"/shantywss/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945898/; classtype:trojan-activity;sid:84808998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945895)"; flow:established,from_client; content:"GET"; http_method; content:"/risselys/swift-executor/head/swift.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945895/; classtype:trojan-activity;sid:84808995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945896)"; flow:established,from_client; content:"GET"; http_method; content:"/jklarm6"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945896/; classtype:trojan-activity;sid:84808996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945897)"; flow:established,from_client; content:"GET"; http_method; content:"/hornettsky/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945897/; classtype:trojan-activity;sid:84808997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945892)"; flow:established,from_client; content:"GET"; http_method; content:"/flokkysway/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945892/; classtype:trojan-activity;sid:84808992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945893)"; flow:established,from_client; content:"GET"; http_method; content:"/bradfleek/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945893/; classtype:trojan-activity;sid:84808993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945894)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.108.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945894/; classtype:trojan-activity;sid:84808994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945888)"; flow:established,from_client; content:"GET"; http_method; content:"/h1fflexd/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945888/; classtype:trojan-activity;sid:84808988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945889)"; flow:established,from_client; content:"GET"; http_method; content:"/flyenspride/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945889/; classtype:trojan-activity;sid:84808989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945890)"; flow:established,from_client; content:"GET"; http_method; content:"/archesst/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945890/; classtype:trojan-activity;sid:84808990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945891)"; flow:established,from_client; content:"GET"; http_method; content:"/seetherx/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945891/; classtype:trojan-activity;sid:84808991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945885)"; flow:established,from_client; content:"GET"; http_method; content:"/drawpool/fluxus-executor-53343/-/raw/main/fluxusexecutor.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945885/; classtype:trojan-activity;sid:84808985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945886)"; flow:established,from_client; content:"GET"; http_method; content:"/rainyforce/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945886/; classtype:trojan-activity;sid:84808986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945887)"; flow:established,from_client; content:"GET"; http_method; content:"/lemmapys/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945887/; classtype:trojan-activity;sid:84808987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945883)"; flow:established,from_client; content:"GET"; http_method; content:"/trecch1n/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945883/; classtype:trojan-activity;sid:84808983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945884)"; flow:established,from_client; content:"GET"; http_method; content:"/railthits/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945884/; classtype:trojan-activity;sid:84808984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945881)"; flow:established,from_client; content:"GET"; http_method; content:"/jaydoublee/fortniteexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945881/; classtype:trojan-activity;sid:84808981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945882)"; flow:established,from_client; content:"GET"; http_method; content:"/rillend/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945882/; classtype:trojan-activity;sid:84808982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945880)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-84738/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945880/; classtype:trojan-activity;sid:84808980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945879)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_ae2d99ac73163300.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945879/; classtype:trojan-activity;sid:84808979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945877)"; flow:established,from_client; content:"GET"; http_method; content:"/earlyshot/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945877/; classtype:trojan-activity;sid:84808977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945878)"; flow:established,from_client; content:"GET"; http_method; content:"/goldlife/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945878/; classtype:trojan-activity;sid:84808978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945875)"; flow:established,from_client; content:"GET"; http_method; content:"/mewhills/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945875/; classtype:trojan-activity;sid:84808975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945876)"; flow:established,from_client; content:"GET"; http_method; content:"/drawpool/fluxus-executor-69039/-/raw/main/fluxusexecutor.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945876/; classtype:trojan-activity;sid:84808976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945872)"; flow:established,from_client; content:"GET"; http_method; content:"/ameliamodel/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945872/; classtype:trojan-activity;sid:84808972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945873)"; flow:established,from_client; content:"GET"; http_method; content:"/slerthrgb/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945873/; classtype:trojan-activity;sid:84808973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945874)"; flow:established,from_client; content:"GET"; http_method; content:"/ryanghost/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945874/; classtype:trojan-activity;sid:84808974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945869)"; flow:established,from_client; content:"GET"; http_method; content:"/crandd1/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945869/; classtype:trojan-activity;sid:84808969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945870)"; flow:established,from_client; content:"GET"; http_method; content:"/phasecart/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945870/; classtype:trojan-activity;sid:84808970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945871)"; flow:established,from_client; content:"GET"; http_method; content:"/vanesslys/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945871/; classtype:trojan-activity;sid:84808971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945866)"; flow:established,from_client; content:"GET"; http_method; content:"/t1nellyne/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945866/; classtype:trojan-activity;sid:84808966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945867)"; flow:established,from_client; content:"GET"; http_method; content:"/lionbest/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945867/; classtype:trojan-activity;sid:84808967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945868)"; flow:established,from_client; content:"GET"; http_method; content:"/drawpool/fluxus-executor-25917/-/raw/main/fluxusexecutor.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945868/; classtype:trojan-activity;sid:84808968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945864)"; flow:established,from_client; content:"GET"; http_method; content:"/mianickel/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945864/; classtype:trojan-activity;sid:84808964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945865)"; flow:established,from_client; content:"GET"; http_method; content:"/chztreik/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945865/; classtype:trojan-activity;sid:84808965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945863)"; flow:established,from_client; content:"GET"; http_method; content:"/wilow/runner_ilove.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"107.175.82.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945863/; classtype:trojan-activity;sid:84808963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945862)"; flow:established,from_client; content:"GET"; http_method; content:"/littleviews/swift-executor/head/swift.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945862/; classtype:trojan-activity;sid:84808962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945861)"; flow:established,from_client; content:"GET"; http_method; content:"/albaees/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945861/; classtype:trojan-activity;sid:84808961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945858)"; flow:established,from_client; content:"GET"; http_method; content:"/lianxang/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945858/; classtype:trojan-activity;sid:84808958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945859)"; flow:established,from_client; content:"GET"; http_method; content:"/blazingfasts/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945859/; classtype:trojan-activity;sid:84808959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945860)"; flow:established,from_client; content:"GET"; http_method; content:"/shockriver/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945860/; classtype:trojan-activity;sid:84808960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945855)"; flow:established,from_client; content:"GET"; http_method; content:"/get-lin"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"reaffirm-neatness-rigid.ngrok-free.dev"; http_host; depth:38; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945855/; classtype:trojan-activity;sid:84808955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945856)"; flow:established,from_client; content:"GET"; http_method; content:"/brandycut/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945856/; classtype:trojan-activity;sid:84808956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945857)"; flow:established,from_client; content:"GET"; http_method; content:"/beepdevs/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945857/; classtype:trojan-activity;sid:84808957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945853)"; flow:established,from_client; content:"GET"; http_method; content:"/colleshake/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945853/; classtype:trojan-activity;sid:84808953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945854)"; flow:established,from_client; content:"GET"; http_method; content:"/nineslicks/redengine-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945854/; classtype:trojan-activity;sid:84808954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945852)"; flow:established,from_client; content:"GET"; http_method; content:"/w3stcoast/akebi-gc/head/akebi-gc.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945852/; classtype:trojan-activity;sid:84808952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945851)"; flow:established,from_client; content:"GET"; http_method; content:"/strephon.dias/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945851/; classtype:trojan-activity;sid:84808951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945850)"; flow:established,from_client; content:"GET"; http_method; content:"/ganseiss/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945850/; classtype:trojan-activity;sid:84808950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945849)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"bergmann-automobile.de"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945849/; classtype:trojan-activity;sid:84808949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945841)"; flow:established,from_client; content:"GET"; http_method; content:"/nyassol/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945841/; classtype:trojan-activity;sid:84808941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945842)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945842/; classtype:trojan-activity;sid:84808942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945843)"; flow:established,from_client; content:"GET"; http_method; content:"/creelsens/redengine-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945843/; classtype:trojan-activity;sid:84808943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945844)"; flow:established,from_client; content:"GET"; http_method; content:"/aidenlovs/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945844/; classtype:trojan-activity;sid:84808944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945845)"; flow:established,from_client; content:"GET"; http_method; content:"/tzxdevs/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945845/; classtype:trojan-activity;sid:84808945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945846)"; flow:established,from_client; content:"GET"; http_method; content:"/alientruths/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945846/; classtype:trojan-activity;sid:84808946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945847)"; flow:established,from_client; content:"GET"; http_method; content:"/l0vemillage/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945847/; classtype:trojan-activity;sid:84808947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945848)"; flow:established,from_client; content:"GET"; http_method; content:"/meinderrty/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945848/; classtype:trojan-activity;sid:84808948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945838)"; flow:established,from_client; content:"GET"; http_method; content:"/wenllishx/dma-spoofer/head/dma_spoofer.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945838/; classtype:trojan-activity;sid:84808938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945839)"; flow:established,from_client; content:"GET"; http_method; content:"/offthe1an/phoenixc2/head/phoenixc2.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945839/; classtype:trojan-activity;sid:84808939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945840)"; flow:established,from_client; content:"GET"; http_method; content:"/criesty/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945840/; classtype:trojan-activity;sid:84808940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945837)"; flow:established,from_client; content:"GET"; http_method; content:"/clainmeers/solara/head/solara%20v3.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945837/; classtype:trojan-activity;sid:84808937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945835)"; flow:established,from_client; content:"GET"; http_method; content:"/hammeis/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945835/; classtype:trojan-activity;sid:84808935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945836)"; flow:established,from_client; content:"GET"; http_method; content:"/insomnia2008/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945836/; classtype:trojan-activity;sid:84808936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945832)"; flow:established,from_client; content:"GET"; http_method; content:"/hansytruth/rezo-gen/head/rezogen.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945832/; classtype:trojan-activity;sid:84808932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945833)"; flow:established,from_client; content:"GET"; http_method; content:"/phineplane/fortniteexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945833/; classtype:trojan-activity;sid:84808933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945834)"; flow:established,from_client; content:"GET"; http_method; content:"/luckhonny/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945834/; classtype:trojan-activity;sid:84808934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945831)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-44974/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945831/; classtype:trojan-activity;sid:84808931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945826)"; flow:established,from_client; content:"GET"; http_method; content:"/socialtime/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945826/; classtype:trojan-activity;sid:84808926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945827)"; flow:established,from_client; content:"GET"; http_method; content:"/t3zw0rk/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945827/; classtype:trojan-activity;sid:84808927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945828)"; flow:established,from_client; content:"GET"; http_method; content:"/nationgloglo/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945828/; classtype:trojan-activity;sid:84808928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945829)"; flow:established,from_client; content:"GET"; http_method; content:"/minellysweb/skriptgg/head/skriptgg.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945829/; classtype:trojan-activity;sid:84808929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945830)"; flow:established,from_client; content:"GET"; http_method; content:"/pitclicks/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945830/; classtype:trojan-activity;sid:84808930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945824)"; flow:established,from_client; content:"GET"; http_method; content:"/crystaldior/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945824/; classtype:trojan-activity;sid:84808924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945825)"; flow:established,from_client; content:"GET"; http_method; content:"/flowmindss/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945825/; classtype:trojan-activity;sid:84808925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945823)"; flow:established,from_client; content:"GET"; http_method; content:"/just1nnlcsh/phoenixc2/head/phoenixc2.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945823/; classtype:trojan-activity;sid:84808923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945822)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/w52ue52xby31.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945822/; classtype:trojan-activity;sid:84808922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945821)"; flow:established,from_client; content:"GET"; http_method; content:"/musslygoch/eulencheats-fivem/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945821/; classtype:trojan-activity;sid:84808921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945819)"; flow:established,from_client; content:"GET"; http_method; content:"/aidenmill/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945819/; classtype:trojan-activity;sid:84808919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945820)"; flow:established,from_client; content:"GET"; http_method; content:"/layevv/fivem-mod-menu/head/loader.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945820/; classtype:trojan-activity;sid:84808920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945815)"; flow:established,from_client; content:"GET"; http_method; content:"/rreval1is/phoenixc2/head/phoenixc2.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945815/; classtype:trojan-activity;sid:84808915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945816)"; flow:established,from_client; content:"GET"; http_method; content:"/swimmingpools/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945816/; classtype:trojan-activity;sid:84808916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945817)"; flow:established,from_client; content:"GET"; http_method; content:"/drawpool/fluxus-executor-64534/-/raw/main/fluxusexecutor.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945817/; classtype:trojan-activity;sid:84808917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945818)"; flow:established,from_client; content:"GET"; http_method; content:"/cluelimsy/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945818/; classtype:trojan-activity;sid:84808918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945812)"; flow:established,from_client; content:"GET"; http_method; content:"/pierlymoat/fortniteexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945812/; classtype:trojan-activity;sid:84808912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945813)"; flow:established,from_client; content:"GET"; http_method; content:"/mnesshv1/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945813/; classtype:trojan-activity;sid:84808913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945814)"; flow:established,from_client; content:"GET"; http_method; content:"/tarm1ss/solara/head/solara%20v3.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945814/; classtype:trojan-activity;sid:84808914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945810)"; flow:established,from_client; content:"GET"; http_method; content:"/lienx7/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945810/; classtype:trojan-activity;sid:84808910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945811)"; flow:established,from_client; content:"GET"; http_method; content:"/riverrystore/swift-executor/head/swift.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945811/; classtype:trojan-activity;sid:84808911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945809)"; flow:established,from_client; content:"GET"; http_method; content:"/linorous/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945809/; classtype:trojan-activity;sid:84808909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945804)"; flow:established,from_client; content:"GET"; http_method; content:"/horneyddjs/xeno-executor/head/xeno.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945804/; classtype:trojan-activity;sid:84808904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945805)"; flow:established,from_client; content:"GET"; http_method; content:"/kknalh/warzoneexternalcheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945805/; classtype:trojan-activity;sid:84808905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945806)"; flow:established,from_client; content:"GET"; http_method; content:"/narr1h/skriptgg/head/skriptgg.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945806/; classtype:trojan-activity;sid:84808906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945807)"; flow:established,from_client; content:"GET"; http_method; content:"/ellisdraw/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945807/; classtype:trojan-activity;sid:84808907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945808)"; flow:established,from_client; content:"GET"; http_method; content:"/parellys/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945808/; classtype:trojan-activity;sid:84808908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945802)"; flow:established,from_client; content:"GET"; http_method; content:"/igmp24184/roblox-macro-v3.0.0/head/language/roblo-macr-v2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945802/; classtype:trojan-activity;sid:84808902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945803)"; flow:established,from_client; content:"GET"; http_method; content:"/seriouslycat/fluxus-roblox-executor/head/fluxus%20v7.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945803/; classtype:trojan-activity;sid:84808903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945800)"; flow:established,from_client; content:"GET"; http_method; content:"/rockwws/warzone-dominator/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945800/; classtype:trojan-activity;sid:84808900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945801)"; flow:established,from_client; content:"GET"; http_method; content:"/madstreets/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945801/; classtype:trojan-activity;sid:84808901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945798)"; flow:established,from_client; content:"GET"; http_method; content:"/el1nns/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945798/; classtype:trojan-activity;sid:84808898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945799)"; flow:established,from_client; content:"GET"; http_method; content:"/sherkdss/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945799/; classtype:trojan-activity;sid:84808899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945779)"; flow:established,from_client; content:"GET"; http_method; content:"/breakingnova/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945779/; classtype:trojan-activity;sid:84808879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945780)"; flow:established,from_client; content:"GET"; http_method; content:"/thearrms/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945780/; classtype:trojan-activity;sid:84808880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945781)"; flow:established,from_client; content:"GET"; http_method; content:"/blizzardstep/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945781/; classtype:trojan-activity;sid:84808881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945782)"; flow:established,from_client; content:"GET"; http_method; content:"/kristirogers/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945782/; classtype:trojan-activity;sid:84808882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945783)"; flow:established,from_client; content:"GET"; http_method; content:"/maddycat/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945783/; classtype:trojan-activity;sid:84808883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945784)"; flow:established,from_client; content:"GET"; http_method; content:"/janelees/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945784/; classtype:trojan-activity;sid:84808884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945785)"; flow:established,from_client; content:"GET"; http_method; content:"/billyjet/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945785/; classtype:trojan-activity;sid:84808885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945786)"; flow:established,from_client; content:"GET"; http_method; content:"/devilhunt/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945786/; classtype:trojan-activity;sid:84808886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945787)"; flow:established,from_client; content:"GET"; http_method; content:"/fivemstory/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945787/; classtype:trojan-activity;sid:84808887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945788)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/7pgv5x7885t8.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945788/; classtype:trojan-activity;sid:84808888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945789)"; flow:established,from_client; content:"GET"; http_method; content:"/hungup/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945789/; classtype:trojan-activity;sid:84808889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945790)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-78473/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945790/; classtype:trojan-activity;sid:84808890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945791)"; flow:established,from_client; content:"GET"; http_method; content:"/meil1s/quantv-january/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945791/; classtype:trojan-activity;sid:84808891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945792)"; flow:established,from_client; content:"GET"; http_method; content:"/nightmaressy/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945792/; classtype:trojan-activity;sid:84808892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945793)"; flow:established,from_client; content:"GET"; http_method; content:"/expertthief/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945793/; classtype:trojan-activity;sid:84808893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945794)"; flow:established,from_client; content:"GET"; http_method; content:"/sapphireworld/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945794/; classtype:trojan-activity;sid:84808894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945795)"; flow:established,from_client; content:"GET"; http_method; content:"/zlefth/warzoneexternalcheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945795/; classtype:trojan-activity;sid:84808895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945796)"; flow:established,from_client; content:"GET"; http_method; content:"/teoraze/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945796/; classtype:trojan-activity;sid:84808896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945797)"; flow:established,from_client; content:"GET"; http_method; content:"/clarr1ns/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945797/; classtype:trojan-activity;sid:84808897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945766)"; flow:established,from_client; content:"GET"; http_method; content:"/jetwater/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945766/; classtype:trojan-activity;sid:84808866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945767)"; flow:established,from_client; content:"GET"; http_method; content:"/nccerx/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945767/; classtype:trojan-activity;sid:84808867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945768)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/factor5323.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945768/; classtype:trojan-activity;sid:84808868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945769)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-51072/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945769/; classtype:trojan-activity;sid:84808869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945770)"; flow:established,from_client; content:"GET"; http_method; content:"/skyedges/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945770/; classtype:trojan-activity;sid:84808870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945771)"; flow:established,from_client; content:"GET"; http_method; content:"/stonerighhend/fortniteexternalcheat/head/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945771/; classtype:trojan-activity;sid:84808871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945772)"; flow:established,from_client; content:"GET"; http_method; content:"/carrl1e/eulencheats-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945772/; classtype:trojan-activity;sid:84808872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945773)"; flow:established,from_client; content:"GET"; http_method; content:"/charreyc/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945773/; classtype:trojan-activity;sid:84808873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945774)"; flow:established,from_client; content:"GET"; http_method; content:"/galbiaawi/galbiaawi-project67/-/raw/main/testing53.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945774/; classtype:trojan-activity;sid:84808874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945775)"; flow:established,from_client; content:"GET"; http_method; content:"/consines/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945775/; classtype:trojan-activity;sid:84808875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945776)"; flow:established,from_client; content:"GET"; http_method; content:"/worldsky/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945776/; classtype:trojan-activity;sid:84808876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945777)"; flow:established,from_client; content:"GET"; http_method; content:"/darkyf0x/fluxus-roblox-executor/head/fluxus%20v7.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945777/; classtype:trojan-activity;sid:84808877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945778)"; flow:established,from_client; content:"GET"; http_method; content:"/neonfeat/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945778/; classtype:trojan-activity;sid:84808878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945765)"; flow:established,from_client; content:"GET"; http_method; content:"/bringloves/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945765/; classtype:trojan-activity;sid:84808865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945763)"; flow:established,from_client; content:"GET"; http_method; content:"/lilbabys/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945763/; classtype:trojan-activity;sid:84808863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945764)"; flow:established,from_client; content:"GET"; http_method; content:"/brealstage3h/c2panel/head/c2panel.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945764/; classtype:trojan-activity;sid:84808864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945762)"; flow:established,from_client; content:"GET"; http_method; content:"/sellxd/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945762/; classtype:trojan-activity;sid:84808862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945759)"; flow:established,from_client; content:"GET"; http_method; content:"/avv3rral/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945759/; classtype:trojan-activity;sid:84808859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945760)"; flow:established,from_client; content:"GET"; http_method; content:"/grannywayss/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945760/; classtype:trojan-activity;sid:84808860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945761)"; flow:established,from_client; content:"GET"; http_method; content:"/davenorth/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945761/; classtype:trojan-activity;sid:84808861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945757)"; flow:established,from_client; content:"GET"; http_method; content:"/venn1sol/dmdgo-v1.20.1/head/dmdgo%20v1.20.1/discord-mass-dm-go.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945757/; classtype:trojan-activity;sid:84808857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945758)"; flow:established,from_client; content:"GET"; http_method; content:"/bestclims/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945758/; classtype:trojan-activity;sid:84808858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945756)"; flow:established,from_client; content:"GET"; http_method; content:"/burnstate/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945756/; classtype:trojan-activity;sid:84808856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945754)"; flow:established,from_client; content:"GET"; http_method; content:"/gre3ah2/warzoneexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945754/; classtype:trojan-activity;sid:84808854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945755)"; flow:established,from_client; content:"GET"; http_method; content:"/baldeeh/eulencheats-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945755/; classtype:trojan-activity;sid:84808855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945752)"; flow:established,from_client; content:"GET"; http_method; content:"/err1ys/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945752/; classtype:trojan-activity;sid:84808852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945753)"; flow:established,from_client; content:"GET"; http_method; content:"/wherres/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945753/; classtype:trojan-activity;sid:84808853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945751)"; flow:established,from_client; content:"GET"; http_method; content:"/sharrely/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945751/; classtype:trojan-activity;sid:84808851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945749)"; flow:established,from_client; content:"GET"; http_method; content:"/am1llsi/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945749/; classtype:trojan-activity;sid:84808849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945750)"; flow:established,from_client; content:"GET"; http_method; content:"/triplebreezy/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945750/; classtype:trojan-activity;sid:84808850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945748)"; flow:established,from_client; content:"GET"; http_method; content:"/ariem1ils/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945748/; classtype:trojan-activity;sid:84808848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945745)"; flow:established,from_client; content:"GET"; http_method; content:"/mcd99/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945745/; classtype:trojan-activity;sid:84808845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945746)"; flow:established,from_client; content:"GET"; http_method; content:"/finessesky/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945746/; classtype:trojan-activity;sid:84808846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945747)"; flow:established,from_client; content:"GET"; http_method; content:"/jenncarter/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945747/; classtype:trojan-activity;sid:84808847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945744)"; flow:established,from_client; content:"GET"; http_method; content:"/hevvylines/exodus-larp-tool/head/exodus.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945744/; classtype:trojan-activity;sid:84808844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945741)"; flow:established,from_client; content:"GET"; http_method; content:"/selli1nu/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945741/; classtype:trojan-activity;sid:84808841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945742)"; flow:established,from_client; content:"GET"; http_method; content:"/hsnall/hwid-bypass/head/tempspoofer.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945742/; classtype:trojan-activity;sid:84808842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945743)"; flow:established,from_client; content:"GET"; http_method; content:"/clydebee/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945743/; classtype:trojan-activity;sid:84808843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945739)"; flow:established,from_client; content:"GET"; http_method; content:"/magicloves/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945739/; classtype:trojan-activity;sid:84808839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945740)"; flow:established,from_client; content:"GET"; http_method; content:"/andyhills/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945740/; classtype:trojan-activity;sid:84808840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945737)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinhood/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945737/; classtype:trojan-activity;sid:84808837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945738)"; flow:established,from_client; content:"GET"; http_method; content:"/poloflocky/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945738/; classtype:trojan-activity;sid:84808838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945735)"; flow:established,from_client; content:"GET"; http_method; content:"/speedchase/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945735/; classtype:trojan-activity;sid:84808835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945736)"; flow:established,from_client; content:"GET"; http_method; content:"/valkyriesys/xeno-executor/head/xeno.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945736/; classtype:trojan-activity;sid:84808836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945731)"; flow:established,from_client; content:"GET"; http_method; content:"/cherrylight/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945731/; classtype:trojan-activity;sid:84808831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945732)"; flow:established,from_client; content:"GET"; http_method; content:"/eevvral1sh/c2panel/head/c2panel.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945732/; classtype:trojan-activity;sid:84808832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945733)"; flow:established,from_client; content:"GET"; http_method; content:"/finrefront/skriptgg/head/skriptgg.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945733/; classtype:trojan-activity;sid:84808833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945734)"; flow:established,from_client; content:"GET"; http_method; content:"/ssten1/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945734/; classtype:trojan-activity;sid:84808834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945729)"; flow:established,from_client; content:"GET"; http_method; content:"/caslm3th/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945729/; classtype:trojan-activity;sid:84808829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945730)"; flow:established,from_client; content:"GET"; http_method; content:"/allistatr/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945730/; classtype:trojan-activity;sid:84808830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945726)"; flow:established,from_client; content:"GET"; http_method; content:"/fadeaways/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945726/; classtype:trojan-activity;sid:84808826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945727)"; flow:established,from_client; content:"GET"; http_method; content:"/thewissh/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945727/; classtype:trojan-activity;sid:84808827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945728)"; flow:established,from_client; content:"GET"; http_method; content:"/m1rryhs/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945728/; classtype:trojan-activity;sid:84808828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945724)"; flow:established,from_client; content:"GET"; http_method; content:"/reversegunz/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945724/; classtype:trojan-activity;sid:84808824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945725)"; flow:established,from_client; content:"GET"; http_method; content:"/annerclith/pubg-desync-menu/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945725/; classtype:trojan-activity;sid:84808825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945723)"; flow:established,from_client; content:"GET"; http_method; content:"/switchylanes/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945723/; classtype:trojan-activity;sid:84808823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945721)"; flow:established,from_client; content:"GET"; http_method; content:"/malibuchrome/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945721/; classtype:trojan-activity;sid:84808821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945722)"; flow:established,from_client; content:"GET"; http_method; content:"/nithellys/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945722/; classtype:trojan-activity;sid:84808822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945717)"; flow:established,from_client; content:"GET"; http_method; content:"/rootfailures/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945717/; classtype:trojan-activity;sid:84808817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945718)"; flow:established,from_client; content:"GET"; http_method; content:"/ixsteff/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945718/; classtype:trojan-activity;sid:84808818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945719)"; flow:established,from_client; content:"GET"; http_method; content:"/blacktier/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945719/; classtype:trojan-activity;sid:84808819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945720)"; flow:established,from_client; content:"GET"; http_method; content:"/narrel1s/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945720/; classtype:trojan-activity;sid:84808820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945711)"; flow:established,from_client; content:"GET"; http_method; content:"/l0rdn0s/phoenixc2/head/phoenixc2.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945711/; classtype:trojan-activity;sid:84808811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945712)"; flow:established,from_client; content:"GET"; http_method; content:"/calleplee/fivem-external-cheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945712/; classtype:trojan-activity;sid:84808812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945713)"; flow:established,from_client; content:"GET"; http_method; content:"/h1endlls/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945713/; classtype:trojan-activity;sid:84808813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945714)"; flow:established,from_client; content:"GET"; http_method; content:"/sandyl1ns/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945714/; classtype:trojan-activity;sid:84808814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945715)"; flow:established,from_client; content:"GET"; http_method; content:"/cazzarel/eulencheats-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945715/; classtype:trojan-activity;sid:84808815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945716)"; flow:established,from_client; content:"GET"; http_method; content:"/cl0nerry/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945716/; classtype:trojan-activity;sid:84808816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945710)"; flow:established,from_client; content:"GET"; http_method; content:"/lovegones/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945710/; classtype:trojan-activity;sid:84808810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945709)"; flow:established,from_client; content:"GET"; http_method; content:"/runnyeps/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945709/; classtype:trojan-activity;sid:84808809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945707)"; flow:established,from_client; content:"GET"; http_method; content:"/lfieeys/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945707/; classtype:trojan-activity;sid:84808807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945708)"; flow:established,from_client; content:"GET"; http_method; content:"/primmslimx/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945708/; classtype:trojan-activity;sid:84808808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945706)"; flow:established,from_client; content:"GET"; http_method; content:"/bialykoteg/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945706/; classtype:trojan-activity;sid:84808806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945705)"; flow:established,from_client; content:"GET"; http_method; content:"/ycarocontas/skriptgg/-/raw/main/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945705/; classtype:trojan-activity;sid:84808805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945697)"; flow:established,from_client; content:"GET"; http_method; content:"/failureh/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945697/; classtype:trojan-activity;sid:84808797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945698)"; flow:established,from_client; content:"GET"; http_method; content:"/eistebells/pubg-desync-menu/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945698/; classtype:trojan-activity;sid:84808798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945699)"; flow:established,from_client; content:"GET"; http_method; content:"/nicoleprince/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945699/; classtype:trojan-activity;sid:84808799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945700)"; flow:established,from_client; content:"GET"; http_method; content:"/releasemylove/akebi-gc/head/akebi-gc.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945700/; classtype:trojan-activity;sid:84808800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945701)"; flow:established,from_client; content:"GET"; http_method; content:"/nurelles/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945701/; classtype:trojan-activity;sid:84808801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945702)"; flow:established,from_client; content:"GET"; http_method; content:"/huntlegssy/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945702/; classtype:trojan-activity;sid:84808802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945703)"; flow:established,from_client; content:"GET"; http_method; content:"/cnney28/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945703/; classtype:trojan-activity;sid:84808803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945704)"; flow:established,from_client; content:"GET"; http_method; content:"/allansixs/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945704/; classtype:trojan-activity;sid:84808804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945692)"; flow:established,from_client; content:"GET"; http_method; content:"/snowwress/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945692/; classtype:trojan-activity;sid:84808792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945693)"; flow:established,from_client; content:"GET"; http_method; content:"/stoulla/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945693/; classtype:trojan-activity;sid:84808793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945694)"; flow:established,from_client; content:"GET"; http_method; content:"/nteams/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945694/; classtype:trojan-activity;sid:84808794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945695)"; flow:established,from_client; content:"GET"; http_method; content:"/huntylight/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945695/; classtype:trojan-activity;sid:84808795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945696)"; flow:established,from_client; content:"GET"; http_method; content:"/gleemads/eulencheats-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945696/; classtype:trojan-activity;sid:84808796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945691)"; flow:established,from_client; content:"GET"; http_method; content:"/remakks/skriptgg/head/skriptgg.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945691/; classtype:trojan-activity;sid:84808791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945690)"; flow:established,from_client; content:"GET"; http_method; content:"/4rubbish/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945690/; classtype:trojan-activity;sid:84808790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945689)"; flow:established,from_client; content:"GET"; http_method; content:"/ermix1/pubg-desync-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945689/; classtype:trojan-activity;sid:84808789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945688)"; flow:established,from_client; content:"GET"; http_method; content:"/narrayel/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945688/; classtype:trojan-activity;sid:84808788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945686)"; flow:established,from_client; content:"GET"; http_method; content:"/mywhoress/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945686/; classtype:trojan-activity;sid:84808786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945687)"; flow:established,from_client; content:"GET"; http_method; content:"/flashrabbits/fortniteexternalcheat/head/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945687/; classtype:trojan-activity;sid:84808787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945655)"; flow:established,from_client; content:"GET"; http_method; content:"/nativewayne/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945655/; classtype:trojan-activity;sid:84808755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945656)"; flow:established,from_client; content:"GET"; http_method; content:"/chromeofancy/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945656/; classtype:trojan-activity;sid:84808756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945657)"; flow:established,from_client; content:"GET"; http_method; content:"/capproject/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945657/; classtype:trojan-activity;sid:84808757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945658)"; flow:established,from_client; content:"GET"; http_method; content:"/tinygray/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945658/; classtype:trojan-activity;sid:84808758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945659)"; flow:established,from_client; content:"GET"; http_method; content:"/lemussx/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945659/; classtype:trojan-activity;sid:84808759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945660)"; flow:established,from_client; content:"GET"; http_method; content:"/j1kksy/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945660/; classtype:trojan-activity;sid:84808760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945661)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/y0xc9og1lghx.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945661/; classtype:trojan-activity;sid:84808761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945662)"; flow:established,from_client; content:"GET"; http_method; content:"/rackzyes/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945662/; classtype:trojan-activity;sid:84808762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945663)"; flow:established,from_client; content:"GET"; http_method; content:"/kadenclimb/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945663/; classtype:trojan-activity;sid:84808763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945664)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/3qz7aatrn_q.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945664/; classtype:trojan-activity;sid:84808764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945665)"; flow:established,from_client; content:"GET"; http_method; content:"/kannethlin/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945665/; classtype:trojan-activity;sid:84808765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945666)"; flow:established,from_client; content:"GET"; http_method; content:"/nellyframe/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945666/; classtype:trojan-activity;sid:84808766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945667)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/4j8576a0e8v3.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945667/; classtype:trojan-activity;sid:84808767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945668)"; flow:established,from_client; content:"GET"; http_method; content:"/stonegrays/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945668/; classtype:trojan-activity;sid:84808768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945669)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/em1s573k9q2c.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945669/; classtype:trojan-activity;sid:84808769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945670)"; flow:established,from_client; content:"GET"; http_method; content:"/addrav1/warzoneexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945670/; classtype:trojan-activity;sid:84808770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945671)"; flow:established,from_client; content:"GET"; http_method; content:"/suspectengine/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945671/; classtype:trojan-activity;sid:84808771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945672)"; flow:established,from_client; content:"GET"; http_method; content:"/lovesplit/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945672/; classtype:trojan-activity;sid:84808772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945673)"; flow:established,from_client; content:"GET"; http_method; content:"/willymore/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945673/; classtype:trojan-activity;sid:84808773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945674)"; flow:established,from_client; content:"GET"; http_method; content:"/sidekill/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945674/; classtype:trojan-activity;sid:84808774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945675)"; flow:established,from_client; content:"GET"; http_method; content:"/drakethug/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945675/; classtype:trojan-activity;sid:84808775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945676)"; flow:established,from_client; content:"GET"; http_method; content:"/laparks/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945676/; classtype:trojan-activity;sid:84808776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945677)"; flow:established,from_client; content:"GET"; http_method; content:"/l3mmn1ia/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945677/; classtype:trojan-activity;sid:84808777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945678)"; flow:established,from_client; content:"GET"; http_method; content:"/earlreal/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945678/; classtype:trojan-activity;sid:84808778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945679)"; flow:established,from_client; content:"GET"; http_method; content:"/linorech/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945679/; classtype:trojan-activity;sid:84808779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945680)"; flow:established,from_client; content:"GET"; http_method; content:"/flyingspur/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945680/; classtype:trojan-activity;sid:84808780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945681)"; flow:established,from_client; content:"GET"; http_method; content:"/twochainz/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945681/; classtype:trojan-activity;sid:84808781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945682)"; flow:established,from_client; content:"GET"; http_method; content:"/davehoodie/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945682/; classtype:trojan-activity;sid:84808782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945683)"; flow:established,from_client; content:"GET"; http_method; content:"/m0llsbry/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945683/; classtype:trojan-activity;sid:84808783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945684)"; flow:established,from_client; content:"GET"; http_method; content:"/lamirgh/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945684/; classtype:trojan-activity;sid:84808784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945685)"; flow:established,from_client; content:"GET"; http_method; content:"/darlymigh/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945685/; classtype:trojan-activity;sid:84808785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945654)"; flow:established,from_client; content:"GET"; http_method; content:"/bellyrocky/xeno-executor/head/xeno.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945654/; classtype:trojan-activity;sid:84808754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945653)"; flow:established,from_client; content:"GET"; http_method; content:"/jaybaby/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945653/; classtype:trojan-activity;sid:84808753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945652)"; flow:established,from_client; content:"GET"; http_method; content:"/millionssky/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945652/; classtype:trojan-activity;sid:84808752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945649)"; flow:established,from_client; content:"GET"; http_method; content:"/deer1sh/fivem-mod-menu/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945649/; classtype:trojan-activity;sid:84808749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945650)"; flow:established,from_client; content:"GET"; http_method; content:"/calld9/fivem-external-cheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945650/; classtype:trojan-activity;sid:84808750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945651)"; flow:established,from_client; content:"GET"; http_method; content:"/nickelyblack/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945651/; classtype:trojan-activity;sid:84808751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945647)"; flow:established,from_client; content:"GET"; http_method; content:"/arielswaps/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945647/; classtype:trojan-activity;sid:84808747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945648)"; flow:established,from_client; content:"GET"; http_method; content:"/thebravery/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945648/; classtype:trojan-activity;sid:84808748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945646)"; flow:established,from_client; content:"GET"; http_method; content:"/machertlin/swift-executor/head/swift.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945646/; classtype:trojan-activity;sid:84808746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945644)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/505hfzin80f5.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945644/; classtype:trojan-activity;sid:84808744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945645)"; flow:established,from_client; content:"GET"; http_method; content:"/roachforever/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945645/; classtype:trojan-activity;sid:84808745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945641)"; flow:established,from_client; content:"GET"; http_method; content:"/drawpool/fluxus-executor-35793/-/raw/main/fluxusexecutor.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945641/; classtype:trojan-activity;sid:84808741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945642)"; flow:established,from_client; content:"GET"; http_method; content:"/maerlsss/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945642/; classtype:trojan-activity;sid:84808742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945643)"; flow:established,from_client; content:"GET"; http_method; content:"/skappyx/fivem-mod-menu/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945643/; classtype:trojan-activity;sid:84808743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945637)"; flow:established,from_client; content:"GET"; http_method; content:"/elissebell/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945637/; classtype:trojan-activity;sid:84808737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945638)"; flow:established,from_client; content:"GET"; http_method; content:"/seject/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945638/; classtype:trojan-activity;sid:84808738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945639)"; flow:established,from_client; content:"GET"; http_method; content:"/twowheel/wave-executor/-/raw/main/waveexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945639/; classtype:trojan-activity;sid:84808739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945640)"; flow:established,from_client; content:"GET"; http_method; content:"/sadofmy/warzone-dominator/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945640/; classtype:trojan-activity;sid:84808740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945635)"; flow:established,from_client; content:"GET"; http_method; content:"/captainhooks/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945635/; classtype:trojan-activity;sid:84808735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945636)"; flow:established,from_client; content:"GET"; http_method; content:"/nickellys/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945636/; classtype:trojan-activity;sid:84808736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945631)"; flow:established,from_client; content:"GET"; http_method; content:"/imaginsedragons/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945631/; classtype:trojan-activity;sid:84808731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945632)"; flow:established,from_client; content:"GET"; http_method; content:"/anclemidds/umbrella-hwid-tool/head/umbrella/umbrella.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945632/; classtype:trojan-activity;sid:84808732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945633)"; flow:established,from_client; content:"GET"; http_method; content:"/harrtys/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945633/; classtype:trojan-activity;sid:84808733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945634)"; flow:established,from_client; content:"GET"; http_method; content:"/takinfly/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945634/; classtype:trojan-activity;sid:84808734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945627)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyesflam/valorantexternalcheat/head/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945627/; classtype:trojan-activity;sid:84808727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945628)"; flow:established,from_client; content:"GET"; http_method; content:"/arcellys/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945628/; classtype:trojan-activity;sid:84808728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945629)"; flow:established,from_client; content:"GET"; http_method; content:"/phantomfax/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945629/; classtype:trojan-activity;sid:84808729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945630)"; flow:established,from_client; content:"GET"; http_method; content:"/highrivals/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945630/; classtype:trojan-activity;sid:84808730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945626)"; flow:established,from_client; content:"GET"; http_method; content:"/blackstars/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945626/; classtype:trojan-activity;sid:84808726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945625)"; flow:established,from_client; content:"GET"; http_method; content:"/meekmill/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945625/; classtype:trojan-activity;sid:84808725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945624)"; flow:established,from_client; content:"GET"; http_method; content:"/in0ns3/fivem-mod-menu/head/loader.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945624/; classtype:trojan-activity;sid:84808724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945621)"; flow:established,from_client; content:"GET"; http_method; content:"/nelccie/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945621/; classtype:trojan-activity;sid:84808721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945622)"; flow:established,from_client; content:"GET"; http_method; content:"/grandstarx/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945622/; classtype:trojan-activity;sid:84808722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945623)"; flow:established,from_client; content:"GET"; http_method; content:"/starfive/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945623/; classtype:trojan-activity;sid:84808723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945619)"; flow:established,from_client; content:"GET"; http_method; content:"/theorlysix/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945619/; classtype:trojan-activity;sid:84808719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945620)"; flow:established,from_client; content:"GET"; http_method; content:"/dailyscripts132/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945620/; classtype:trojan-activity;sid:84808720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945617)"; flow:established,from_client; content:"GET"; http_method; content:"/robloxexploiter/xeno-executor/-/raw/main/xeno.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945617/; classtype:trojan-activity;sid:84808717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945618)"; flow:established,from_client; content:"GET"; http_method; content:"/eliaseight/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945618/; classtype:trojan-activity;sid:84808718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945614)"; flow:established,from_client; content:"GET"; http_method; content:"/nettywipes/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945614/; classtype:trojan-activity;sid:84808714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945615)"; flow:established,from_client; content:"GET"; http_method; content:"/frankensteins/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945615/; classtype:trojan-activity;sid:84808715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945616)"; flow:established,from_client; content:"GET"; http_method; content:"/standprince/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945616/; classtype:trojan-activity;sid:84808716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945613)"; flow:established,from_client; content:"GET"; http_method; content:"/railguns/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945613/; classtype:trojan-activity;sid:84808713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945611)"; flow:established,from_client; content:"GET"; http_method; content:"/callyish/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945611/; classtype:trojan-activity;sid:84808711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945612)"; flow:established,from_client; content:"GET"; http_method; content:"/santigold/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945612/; classtype:trojan-activity;sid:84808712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945610)"; flow:established,from_client; content:"GET"; http_method; content:"/voidbest/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945610/; classtype:trojan-activity;sid:84808710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945608)"; flow:established,from_client; content:"GET"; http_method; content:"/blessytd/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945608/; classtype:trojan-activity;sid:84808708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945609)"; flow:established,from_client; content:"GET"; http_method; content:"/yesst1s/skriptgg/head/skriptgg.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945609/; classtype:trojan-activity;sid:84808709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945605)"; flow:established,from_client; content:"GET"; http_method; content:"/mixxyshev/solara/head/solara%20v3.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945605/; classtype:trojan-activity;sid:84808705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945606)"; flow:established,from_client; content:"GET"; http_method; content:"/crattier/dma-spoofer/head/dma_spoofer.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945606/; classtype:trojan-activity;sid:84808706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945607)"; flow:established,from_client; content:"GET"; http_method; content:"/brixst0ne/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945607/; classtype:trojan-activity;sid:84808707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945604)"; flow:established,from_client; content:"GET"; http_method; content:"/ellfect1ve/fivem-mod-menu-2024/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945604/; classtype:trojan-activity;sid:84808704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945603)"; flow:established,from_client; content:"GET"; http_method; content:"/rapidflow/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945603/; classtype:trojan-activity;sid:84808703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945600)"; flow:established,from_client; content:"GET"; http_method; content:"/crissty/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945600/; classtype:trojan-activity;sid:84808700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945601)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/hello.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945601/; classtype:trojan-activity;sid:84808701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945602)"; flow:established,from_client; content:"GET"; http_method; content:"/n1tteys/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945602/; classtype:trojan-activity;sid:84808702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945597)"; flow:established,from_client; content:"GET"; http_method; content:"/bizzyshifts/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945597/; classtype:trojan-activity;sid:84808697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945598)"; flow:established,from_client; content:"GET"; http_method; content:"/jetlags/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945598/; classtype:trojan-activity;sid:84808698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945599)"; flow:established,from_client; content:"GET"; http_method; content:"/slowbenz/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945599/; classtype:trojan-activity;sid:84808699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945594)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/259uzds8poxh.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945594/; classtype:trojan-activity;sid:84808694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945595)"; flow:established,from_client; content:"GET"; http_method; content:"/ollymade/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945595/; classtype:trojan-activity;sid:84808695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945596)"; flow:established,from_client; content:"GET"; http_method; content:"/laurelios/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945596/; classtype:trojan-activity;sid:84808696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945593)"; flow:established,from_client; content:"GET"; http_method; content:"/rickyflame/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945593/; classtype:trojan-activity;sid:84808693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945587)"; flow:established,from_client; content:"GET"; http_method; content:"/kaue9919a/skriptgg/-/raw/main/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945587/; classtype:trojan-activity;sid:84808687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945588)"; flow:established,from_client; content:"GET"; http_method; content:"/lexxals/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945588/; classtype:trojan-activity;sid:84808688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945589)"; flow:established,from_client; content:"GET"; http_method; content:"/tillatens/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945589/; classtype:trojan-activity;sid:84808689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945590)"; flow:established,from_client; content:"GET"; http_method; content:"/onceflix/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945590/; classtype:trojan-activity;sid:84808690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945591)"; flow:established,from_client; content:"GET"; http_method; content:"/spinbacks/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945591/; classtype:trojan-activity;sid:84808691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945592)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-93402/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945592/; classtype:trojan-activity;sid:84808692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945582)"; flow:established,from_client; content:"GET"; http_method; content:"/vipergod/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945582/; classtype:trojan-activity;sid:84808682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945583)"; flow:established,from_client; content:"GET"; http_method; content:"/rexrexs/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945583/; classtype:trojan-activity;sid:84808683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945584)"; flow:established,from_client; content:"GET"; http_method; content:"/skylends/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945584/; classtype:trojan-activity;sid:84808684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945585)"; flow:established,from_client; content:"GET"; http_method; content:"/lallyfine/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945585/; classtype:trojan-activity;sid:84808685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945586)"; flow:established,from_client; content:"GET"; http_method; content:"/dann1hes/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945586/; classtype:trojan-activity;sid:84808686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945581)"; flow:established,from_client; content:"GET"; http_method; content:"/sharandes/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945581/; classtype:trojan-activity;sid:84808681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945580)"; flow:established,from_client; content:"GET"; http_method; content:"/canterls/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945580/; classtype:trojan-activity;sid:84808680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945579)"; flow:established,from_client; content:"GET"; http_method; content:"/h1nkai/fivem-mod-menu-2024/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945579/; classtype:trojan-activity;sid:84808679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945578)"; flow:established,from_client; content:"GET"; http_method; content:"/stan1kll/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945578/; classtype:trojan-activity;sid:84808678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945577)"; flow:established,from_client; content:"GET"; http_method; content:"/atease50/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945577/; classtype:trojan-activity;sid:84808677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945576)"; flow:established,from_client; content:"GET"; http_method; content:"/frezzetag/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945576/; classtype:trojan-activity;sid:84808676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945574)"; flow:established,from_client; content:"GET"; http_method; content:"/elitecall/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945574/; classtype:trojan-activity;sid:84808674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945575)"; flow:established,from_client; content:"GET"; http_method; content:"/madchris/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945575/; classtype:trojan-activity;sid:84808675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945570)"; flow:established,from_client; content:"GET"; http_method; content:"/millycage/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945570/; classtype:trojan-activity;sid:84808670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945571)"; flow:established,from_client; content:"GET"; http_method; content:"/thiefbest/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945571/; classtype:trojan-activity;sid:84808671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945572)"; flow:established,from_client; content:"GET"; http_method; content:"/assicter/xeno-executor/head/xeno.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945572/; classtype:trojan-activity;sid:84808672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945573)"; flow:established,from_client; content:"GET"; http_method; content:"/d3xxth/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945573/; classtype:trojan-activity;sid:84808673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945568)"; flow:established,from_client; content:"GET"; http_method; content:"/nightdillar/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945568/; classtype:trojan-activity;sid:84808668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945569)"; flow:established,from_client; content:"GET"; http_method; content:"/ghosttowns/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945569/; classtype:trojan-activity;sid:84808669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945567)"; flow:established,from_client; content:"GET"; http_method; content:"/taccherl1s/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945567/; classtype:trojan-activity;sid:84808667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945564)"; flow:established,from_client; content:"GET"; http_method; content:"/badbunnyss/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945564/; classtype:trojan-activity;sid:84808664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945565)"; flow:established,from_client; content:"GET"; http_method; content:"/thatways/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945565/; classtype:trojan-activity;sid:84808665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945566)"; flow:established,from_client; content:"GET"; http_method; content:"/arrivalray/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945566/; classtype:trojan-activity;sid:84808666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945562)"; flow:established,from_client; content:"GET"; http_method; content:"/l1okeey/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945562/; classtype:trojan-activity;sid:84808662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945563)"; flow:established,from_client; content:"GET"; http_method; content:"/hellnights/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945563/; classtype:trojan-activity;sid:84808663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945561)"; flow:established,from_client; content:"GET"; http_method; content:"/lazzerris/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945561/; classtype:trojan-activity;sid:84808661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945560)"; flow:established,from_client; content:"GET"; http_method; content:"/claydring/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945560/; classtype:trojan-activity;sid:84808660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945559)"; flow:established,from_client; content:"GET"; http_method; content:"/fivemhub/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945559/; classtype:trojan-activity;sid:84808659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945558)"; flow:established,from_client; content:"GET"; http_method; content:"/kingvolts/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945558/; classtype:trojan-activity;sid:84808658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945557)"; flow:established,from_client; content:"GET"; http_method; content:"/mikealonsy/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945557/; classtype:trojan-activity;sid:84808657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945553)"; flow:established,from_client; content:"GET"; http_method; content:"/annellyfray/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945553/; classtype:trojan-activity;sid:84808653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945554)"; flow:established,from_client; content:"GET"; http_method; content:"/aw3rall/fivem-mod-menu/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945554/; classtype:trojan-activity;sid:84808654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945555)"; flow:established,from_client; content:"GET"; http_method; content:"/scelmm1/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945555/; classtype:trojan-activity;sid:84808655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945556)"; flow:established,from_client; content:"GET"; http_method; content:"/darksocietys/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945556/; classtype:trojan-activity;sid:84808656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945549)"; flow:established,from_client; content:"GET"; http_method; content:"/princedre/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945549/; classtype:trojan-activity;sid:84808649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945550)"; flow:established,from_client; content:"GET"; http_method; content:"/terehota/xeno-executor/-/raw/main/xenoexecutorsetup.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945550/; classtype:trojan-activity;sid:84808650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945551)"; flow:established,from_client; content:"GET"; http_method; content:"/catboyss/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945551/; classtype:trojan-activity;sid:84808651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945552)"; flow:established,from_client; content:"GET"; http_method; content:"/jeffhood/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945552/; classtype:trojan-activity;sid:84808652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945548)"; flow:established,from_client; content:"GET"; http_method; content:"/limmerbrowd/pubg-desync-menu/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945548/; classtype:trojan-activity;sid:84808648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945545)"; flow:established,from_client; content:"GET"; http_method; content:"/cerrtyhs/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945545/; classtype:trojan-activity;sid:84808645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945546)"; flow:established,from_client; content:"GET"; http_method; content:"/citizendope/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945546/; classtype:trojan-activity;sid:84808646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945547)"; flow:established,from_client; content:"GET"; http_method; content:"/rawspeed/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945547/; classtype:trojan-activity;sid:84808647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945544)"; flow:established,from_client; content:"GET"; http_method; content:"/etherlines/warzone-dominator/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945544/; classtype:trojan-activity;sid:84808644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945543)"; flow:established,from_client; content:"GET"; http_method; content:"/hlefmill/akebi-gc/head/akebi-gc.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945543/; classtype:trojan-activity;sid:84808643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945541)"; flow:established,from_client; content:"GET"; http_method; content:"/slo1nks/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945541/; classtype:trojan-activity;sid:84808641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945542)"; flow:established,from_client; content:"GET"; http_method; content:"/an1eers/redengine-fivem/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945542/; classtype:trojan-activity;sid:84808642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945539)"; flow:established,from_client; content:"GET"; http_method; content:"/adennaly/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945539/; classtype:trojan-activity;sid:84808639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945540)"; flow:established,from_client; content:"GET"; http_method; content:"/carterlowd/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945540/; classtype:trojan-activity;sid:84808640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945536)"; flow:established,from_client; content:"GET"; http_method; content:"/hanalteryy/fortniteexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945536/; classtype:trojan-activity;sid:84808636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945537)"; flow:established,from_client; content:"GET"; http_method; content:"/kevingatess/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945537/; classtype:trojan-activity;sid:84808637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945538)"; flow:established,from_client; content:"GET"; http_method; content:"/tiffanyprod/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945538/; classtype:trojan-activity;sid:84808638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945534)"; flow:established,from_client; content:"GET"; http_method; content:"/calleron/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945534/; classtype:trojan-activity;sid:84808634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945535)"; flow:established,from_client; content:"GET"; http_method; content:"/dannyrockets/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945535/; classtype:trojan-activity;sid:84808635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945533)"; flow:established,from_client; content:"GET"; http_method; content:"/porudsy/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945533/; classtype:trojan-activity;sid:84808633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945530)"; flow:established,from_client; content:"GET"; http_method; content:"/mysterris/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945530/; classtype:trojan-activity;sid:84808630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945531)"; flow:established,from_client; content:"GET"; http_method; content:"/sverrds/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945531/; classtype:trojan-activity;sid:84808631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945532)"; flow:established,from_client; content:"GET"; http_method; content:"/arkillx/redengine-fivem/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945532/; classtype:trojan-activity;sid:84808632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945528)"; flow:established,from_client; content:"GET"; http_method; content:"/emberclub/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945528/; classtype:trojan-activity;sid:84808628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945529)"; flow:established,from_client; content:"GET"; http_method; content:"/munuless/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945529/; classtype:trojan-activity;sid:84808629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945527)"; flow:established,from_client; content:"GET"; http_method; content:"/vagggs/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945527/; classtype:trojan-activity;sid:84808627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945526)"; flow:established,from_client; content:"GET"; http_method; content:"/handwheel/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945526/; classtype:trojan-activity;sid:84808626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945525)"; flow:established,from_client; content:"GET"; http_method; content:"/nexx1cross/xeno-executor/head/xeno.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945525/; classtype:trojan-activity;sid:84808625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945522)"; flow:established,from_client; content:"GET"; http_method; content:"/s1neer/fivem-external-cheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945522/; classtype:trojan-activity;sid:84808622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945523)"; flow:established,from_client; content:"GET"; http_method; content:"/lenssyw/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945523/; classtype:trojan-activity;sid:84808623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945524)"; flow:established,from_client; content:"GET"; http_method; content:"/seantejj/akebi-gc/head/akebi-gc.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945524/; classtype:trojan-activity;sid:84808624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945520)"; flow:established,from_client; content:"GET"; http_method; content:"/colleras/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945520/; classtype:trojan-activity;sid:84808620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945521)"; flow:established,from_client; content:"GET"; http_method; content:"/callygaes/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945521/; classtype:trojan-activity;sid:84808621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945518)"; flow:established,from_client; content:"GET"; http_method; content:"/lordesflax/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945518/; classtype:trojan-activity;sid:84808618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945519)"; flow:established,from_client; content:"GET"; http_method; content:"/painyclay/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945519/; classtype:trojan-activity;sid:84808619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945515)"; flow:established,from_client; content:"GET"; http_method; content:"/theftruin/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945515/; classtype:trojan-activity;sid:84808615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945516)"; flow:established,from_client; content:"GET"; http_method; content:"/legendstudio/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945516/; classtype:trojan-activity;sid:84808616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945517)"; flow:established,from_client; content:"GET"; http_method; content:"/devileight/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945517/; classtype:trojan-activity;sid:84808617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945513)"; flow:established,from_client; content:"GET"; http_method; content:"/mandyplug/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945513/; classtype:trojan-activity;sid:84808613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945514)"; flow:established,from_client; content:"GET"; http_method; content:"/l3monn4k/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945514/; classtype:trojan-activity;sid:84808614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945509)"; flow:established,from_client; content:"GET"; http_method; content:"/soulier.jeje30/fivem-external-cheat/-/raw/main/license.dll"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945509/; classtype:trojan-activity;sid:84808609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945510)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/s8d70ipcznaa.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945510/; classtype:trojan-activity;sid:84808610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945511)"; flow:established,from_client; content:"GET"; http_method; content:"/crazytowns/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945511/; classtype:trojan-activity;sid:84808611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945512)"; flow:established,from_client; content:"GET"; http_method; content:"/jazzybless/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945512/; classtype:trojan-activity;sid:84808612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945506)"; flow:established,from_client; content:"GET"; http_method; content:"/nylmak/valorantexternalcheats/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945506/; classtype:trojan-activity;sid:84808606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945507)"; flow:established,from_client; content:"GET"; http_method; content:"/huntlife/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945507/; classtype:trojan-activity;sid:84808607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945508)"; flow:established,from_client; content:"GET"; http_method; content:"/revvan1l/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945508/; classtype:trojan-activity;sid:84808608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945505)"; flow:established,from_client; content:"GET"; http_method; content:"/jayzhood/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945505/; classtype:trojan-activity;sid:84808605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945504)"; flow:established,from_client; content:"GET"; http_method; content:"/starkciss/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945504/; classtype:trojan-activity;sid:84808604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945503)"; flow:established,from_client; content:"GET"; http_method; content:"/lev1de/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945503/; classtype:trojan-activity;sid:84808603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945501)"; flow:established,from_client; content:"GET"; http_method; content:"/avenncerch/warzone-dominator/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945501/; classtype:trojan-activity;sid:84808601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945502)"; flow:established,from_client; content:"GET"; http_method; content:"/jayloves/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945502/; classtype:trojan-activity;sid:84808602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945500)"; flow:established,from_client; content:"GET"; http_method; content:"/on1leey/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945500/; classtype:trojan-activity;sid:84808600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945498)"; flow:established,from_client; content:"GET"; http_method; content:"/liarays/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945498/; classtype:trojan-activity;sid:84808598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945499)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodelite/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945499/; classtype:trojan-activity;sid:84808599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945496)"; flow:established,from_client; content:"GET"; http_method; content:"/twistycup/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945496/; classtype:trojan-activity;sid:84808596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945497)"; flow:established,from_client; content:"GET"; http_method; content:"/farrenths/swift-executor/head/swift.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945497/; classtype:trojan-activity;sid:84808597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945494)"; flow:established,from_client; content:"GET"; http_method; content:"/bhuvi1430/roblox-macro-v3.0.0/head/language/roblo-macr-1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945494/; classtype:trojan-activity;sid:84808594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945495)"; flow:established,from_client; content:"GET"; http_method; content:"/myl1tthsw/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945495/; classtype:trojan-activity;sid:84808595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945492)"; flow:established,from_client; content:"GET"; http_method; content:"/skinnydex/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945492/; classtype:trojan-activity;sid:84808592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945493)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-24740/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945493/; classtype:trojan-activity;sid:84808593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945490)"; flow:established,from_client; content:"GET"; http_method; content:"/clarityfloat/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945490/; classtype:trojan-activity;sid:84808590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945491)"; flow:established,from_client; content:"GET"; http_method; content:"/avra1ls/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945491/; classtype:trojan-activity;sid:84808591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945487)"; flow:established,from_client; content:"GET"; http_method; content:"/ciddur9/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945487/; classtype:trojan-activity;sid:84808587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945488)"; flow:established,from_client; content:"GET"; http_method; content:"/kly1assv/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945488/; classtype:trojan-activity;sid:84808588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945489)"; flow:established,from_client; content:"GET"; http_method; content:"/amalihs/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945489/; classtype:trojan-activity;sid:84808589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945486)"; flow:established,from_client; content:"GET"; http_method; content:"/mlw3ees/phoenixc2/head/phoenixc2.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945486/; classtype:trojan-activity;sid:84808586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945483)"; flow:established,from_client; content:"GET"; http_method; content:"/gennagds/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945483/; classtype:trojan-activity;sid:84808583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945484)"; flow:established,from_client; content:"GET"; http_method; content:"/landeliur/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945484/; classtype:trojan-activity;sid:84808584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945485)"; flow:established,from_client; content:"GET"; http_method; content:"/th1nnye/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945485/; classtype:trojan-activity;sid:84808585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945481)"; flow:established,from_client; content:"GET"; http_method; content:"/amiryblack/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945481/; classtype:trojan-activity;sid:84808581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945482)"; flow:established,from_client; content:"GET"; http_method; content:"/notescalm/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945482/; classtype:trojan-activity;sid:84808582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945480)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-33149/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945480/; classtype:trojan-activity;sid:84808580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945477)"; flow:established,from_client; content:"GET"; http_method; content:"/dillarone/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945477/; classtype:trojan-activity;sid:84808577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945478)"; flow:established,from_client; content:"GET"; http_method; content:"/himmles/fivem-mod-menu-2024/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945478/; classtype:trojan-activity;sid:84808578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945479)"; flow:established,from_client; content:"GET"; http_method; content:"/khanessal/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945479/; classtype:trojan-activity;sid:84808579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945472)"; flow:established,from_client; content:"GET"; http_method; content:"/fierl1eh/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945472/; classtype:trojan-activity;sid:84808572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945473)"; flow:established,from_client; content:"GET"; http_method; content:"/drakeremble/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945473/; classtype:trojan-activity;sid:84808573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945474)"; flow:established,from_client; content:"GET"; http_method; content:"/ameriathing/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945474/; classtype:trojan-activity;sid:84808574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945475)"; flow:established,from_client; content:"GET"; http_method; content:"/dustway/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945475/; classtype:trojan-activity;sid:84808575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945476)"; flow:established,from_client; content:"GET"; http_method; content:"/airland-tech/pubg-desync-menu/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945476/; classtype:trojan-activity;sid:84808576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945471)"; flow:established,from_client; content:"GET"; http_method; content:"/lollypops/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945471/; classtype:trojan-activity;sid:84808571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945469)"; flow:established,from_client; content:"GET"; http_method; content:"/maclayout/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945469/; classtype:trojan-activity;sid:84808569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945470)"; flow:established,from_client; content:"GET"; http_method; content:"/painkillers/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945470/; classtype:trojan-activity;sid:84808570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945467)"; flow:established,from_client; content:"GET"; http_method; content:"/stepbystep-mod/warzone-dominator/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945467/; classtype:trojan-activity;sid:84808567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945468)"; flow:established,from_client; content:"GET"; http_method; content:"/harmss9/fluxus-roblox-executor/head/fluxus%20v7.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945468/; classtype:trojan-activity;sid:84808568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945466)"; flow:established,from_client; content:"GET"; http_method; content:"/happynights/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945466/; classtype:trojan-activity;sid:84808566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945463)"; flow:established,from_client; content:"GET"; http_method; content:"/manchstrike/warzone-dominator/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945463/; classtype:trojan-activity;sid:84808563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945464)"; flow:established,from_client; content:"GET"; http_method; content:"/oceanhurt/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945464/; classtype:trojan-activity;sid:84808564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945465)"; flow:established,from_client; content:"GET"; http_method; content:"/h0llyest/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945465/; classtype:trojan-activity;sid:84808565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945462)"; flow:established,from_client; content:"GET"; http_method; content:"/jmenolls/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945462/; classtype:trojan-activity;sid:84808562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945460)"; flow:established,from_client; content:"GET"; http_method; content:"/wavedevs/wave-executor/-/raw/main/waveexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945460/; classtype:trojan-activity;sid:84808560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945461)"; flow:established,from_client; content:"GET"; http_method; content:"/linthouss/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945461/; classtype:trojan-activity;sid:84808561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945459)"; flow:established,from_client; content:"GET"; http_method; content:"/frankystorm/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945459/; classtype:trojan-activity;sid:84808559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945457)"; flow:established,from_client; content:"GET"; http_method; content:"/robinbatman/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945457/; classtype:trojan-activity;sid:84808557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945458)"; flow:established,from_client; content:"GET"; http_method; content:"/rayblazes/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945458/; classtype:trojan-activity;sid:84808558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945454)"; flow:established,from_client; content:"GET"; http_method; content:"/clayforce/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945454/; classtype:trojan-activity;sid:84808554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945455)"; flow:established,from_client; content:"GET"; http_method; content:"/lifecouges/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945455/; classtype:trojan-activity;sid:84808555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945456)"; flow:established,from_client; content:"GET"; http_method; content:"/smilecats/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945456/; classtype:trojan-activity;sid:84808556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945452)"; flow:established,from_client; content:"GET"; http_method; content:"/h1elssind/warzoneexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945452/; classtype:trojan-activity;sid:84808552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945453)"; flow:established,from_client; content:"GET"; http_method; content:"/marlyuw/fortniteexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945453/; classtype:trojan-activity;sid:84808553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945450)"; flow:established,from_client; content:"GET"; http_method; content:"/claudycode/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945450/; classtype:trojan-activity;sid:84808550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945451)"; flow:established,from_client; content:"GET"; http_method; content:"/slimlife/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945451/; classtype:trojan-activity;sid:84808551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945446)"; flow:established,from_client; content:"GET"; http_method; content:"/clatthys/eulencheats-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945446/; classtype:trojan-activity;sid:84808546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945447)"; flow:established,from_client; content:"GET"; http_method; content:"/ys3ngd/warzoneexternalcheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945447/; classtype:trojan-activity;sid:84808547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945448)"; flow:established,from_client; content:"GET"; http_method; content:"/comptess/exodus-larp-tool/head/exodus.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945448/; classtype:trojan-activity;sid:84808548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945449)"; flow:established,from_client; content:"GET"; http_method; content:"/anniselth/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945449/; classtype:trojan-activity;sid:84808549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945442)"; flow:established,from_client; content:"GET"; http_method; content:"/hannerlys/swift-executor/head/swift.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945442/; classtype:trojan-activity;sid:84808542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945443)"; flow:established,from_client; content:"GET"; http_method; content:"/bloodout/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945443/; classtype:trojan-activity;sid:84808543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945444)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-50955/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945444/; classtype:trojan-activity;sid:84808544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945445)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-20461/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945445/; classtype:trojan-activity;sid:84808545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945438)"; flow:established,from_client; content:"GET"; http_method; content:"/letter1s/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945438/; classtype:trojan-activity;sid:84808538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945439)"; flow:established,from_client; content:"GET"; http_method; content:"/hinnelyclair/fluxusexecutor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945439/; classtype:trojan-activity;sid:84808539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945440)"; flow:established,from_client; content:"GET"; http_method; content:"/youngdolp/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945440/; classtype:trojan-activity;sid:84808540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945441)"; flow:established,from_client; content:"GET"; http_method; content:"/lildemons/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945441/; classtype:trojan-activity;sid:84808541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945437)"; flow:established,from_client; content:"GET"; http_method; content:"/claymiss/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945437/; classtype:trojan-activity;sid:84808537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945436)"; flow:established,from_client; content:"GET"; http_method; content:"/cashenes/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945436/; classtype:trojan-activity;sid:84808536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945435)"; flow:established,from_client; content:"GET"; http_method; content:"/squezzeflip/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945435/; classtype:trojan-activity;sid:84808535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945432)"; flow:established,from_client; content:"GET"; http_method; content:"/icegang/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945432/; classtype:trojan-activity;sid:84808532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945433)"; flow:established,from_client; content:"GET"; http_method; content:"/idprotxd3n/akebi-gc/head/akebi-gc.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945433/; classtype:trojan-activity;sid:84808533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945434)"; flow:established,from_client; content:"GET"; http_method; content:"/directorcat/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945434/; classtype:trojan-activity;sid:84808534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945431)"; flow:established,from_client; content:"GET"; http_method; content:"/blackmatchs/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945431/; classtype:trojan-activity;sid:84808531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945429)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddemess/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945429/; classtype:trojan-activity;sid:84808529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945430)"; flow:established,from_client; content:"GET"; http_method; content:"/captelios/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945430/; classtype:trojan-activity;sid:84808530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945427)"; flow:established,from_client; content:"GET"; http_method; content:"/merlisshawk/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945427/; classtype:trojan-activity;sid:84808527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945428)"; flow:established,from_client; content:"GET"; http_method; content:"/tillysplit/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945428/; classtype:trojan-activity;sid:84808528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945426)"; flow:established,from_client; content:"GET"; http_method; content:"/dirreths/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945426/; classtype:trojan-activity;sid:84808526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945421)"; flow:established,from_client; content:"GET"; http_method; content:"/backflyes/fluxus-roblox-executor/head/fluxus%20v7.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945421/; classtype:trojan-activity;sid:84808521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945422)"; flow:established,from_client; content:"GET"; http_method; content:"/trustnobodys/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945422/; classtype:trojan-activity;sid:84808522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945423)"; flow:established,from_client; content:"GET"; http_method; content:"/graviesmetal/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945423/; classtype:trojan-activity;sid:84808523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945424)"; flow:established,from_client; content:"GET"; http_method; content:"/strikerstory/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945424/; classtype:trojan-activity;sid:84808524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945425)"; flow:established,from_client; content:"GET"; http_method; content:"/lampaschde/pubg-desync-menu/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945425/; classtype:trojan-activity;sid:84808525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945419)"; flow:established,from_client; content:"GET"; http_method; content:"/gahdess/valorantexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945419/; classtype:trojan-activity;sid:84808519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945420)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostmind/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945420/; classtype:trojan-activity;sid:84808520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945417)"; flow:established,from_client; content:"GET"; http_method; content:"/shafterbills/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945417/; classtype:trojan-activity;sid:84808517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945418)"; flow:established,from_client; content:"GET"; http_method; content:"/teaflip/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945418/; classtype:trojan-activity;sid:84808518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945413)"; flow:established,from_client; content:"GET"; http_method; content:"/rayclemten/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945413/; classtype:trojan-activity;sid:84808513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945414)"; flow:established,from_client; content:"GET"; http_method; content:"/centralfaint/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945414/; classtype:trojan-activity;sid:84808514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945415)"; flow:established,from_client; content:"GET"; http_method; content:"/ri1llays/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945415/; classtype:trojan-activity;sid:84808515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945416)"; flow:established,from_client; content:"GET"; http_method; content:"/ficctkysky/swift-executor/head/swift.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945416/; classtype:trojan-activity;sid:84808516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945411)"; flow:established,from_client; content:"GET"; http_method; content:"/risesun/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945411/; classtype:trojan-activity;sid:84808511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945412)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/stage_2_1.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945412/; classtype:trojan-activity;sid:84808512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945408)"; flow:established,from_client; content:"GET"; http_method; content:"/j0ssleyw/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945408/; classtype:trojan-activity;sid:84808508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945409)"; flow:established,from_client; content:"GET"; http_method; content:"/cl1mats/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945409/; classtype:trojan-activity;sid:84808509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945410)"; flow:established,from_client; content:"GET"; http_method; content:"/keeponly/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945410/; classtype:trojan-activity;sid:84808510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945407)"; flow:established,from_client; content:"GET"; http_method; content:"/charrl3x/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945407/; classtype:trojan-activity;sid:84808507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945404)"; flow:established,from_client; content:"GET"; http_method; content:"/dalleryh/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945404/; classtype:trojan-activity;sid:84808504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945405)"; flow:established,from_client; content:"GET"; http_method; content:"/n0winter/gtahaxui/head/gtahaxui.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945405/; classtype:trojan-activity;sid:84808505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945406)"; flow:established,from_client; content:"GET"; http_method; content:"/sevverna1/phoenixc2/head/phoenixc2.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945406/; classtype:trojan-activity;sid:84808506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945403)"; flow:established,from_client; content:"GET"; http_method; content:"/cheveyys/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945403/; classtype:trojan-activity;sid:84808503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945399)"; flow:established,from_client; content:"GET"; http_method; content:"/butterflys/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945399/; classtype:trojan-activity;sid:84808499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945400)"; flow:established,from_client; content:"GET"; http_method; content:"/acrhmasst/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945400/; classtype:trojan-activity;sid:84808500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945401)"; flow:established,from_client; content:"GET"; http_method; content:"/resculles/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945401/; classtype:trojan-activity;sid:84808501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945402)"; flow:established,from_client; content:"GET"; http_method; content:"/tessh/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945402/; classtype:trojan-activity;sid:84808502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945393)"; flow:established,from_client; content:"GET"; http_method; content:"/amillysh/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945393/; classtype:trojan-activity;sid:84808493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945394)"; flow:established,from_client; content:"GET"; http_method; content:"/tracerev/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945394/; classtype:trojan-activity;sid:84808494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945395)"; flow:established,from_client; content:"GET"; http_method; content:"/icedown/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945395/; classtype:trojan-activity;sid:84808495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945396)"; flow:established,from_client; content:"GET"; http_method; content:"/n1kkye/pubg-desync-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945396/; classtype:trojan-activity;sid:84808496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945397)"; flow:established,from_client; content:"GET"; http_method; content:"/luckystarss/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945397/; classtype:trojan-activity;sid:84808497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945398)"; flow:established,from_client; content:"GET"; http_method; content:"/enns1ial/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945398/; classtype:trojan-activity;sid:84808498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945390)"; flow:established,from_client; content:"GET"; http_method; content:"/jonnychevsy/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945390/; classtype:trojan-activity;sid:84808490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945391)"; flow:established,from_client; content:"GET"; http_method; content:"/claysky/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945391/; classtype:trojan-activity;sid:84808491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945392)"; flow:established,from_client; content:"GET"; http_method; content:"/nestlight/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945392/; classtype:trojan-activity;sid:84808492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945389)"; flow:established,from_client; content:"GET"; http_method; content:"/l3nn1sd/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945389/; classtype:trojan-activity;sid:84808489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945388)"; flow:established,from_client; content:"GET"; http_method; content:"/gamesources/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945388/; classtype:trojan-activity;sid:84808488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945387)"; flow:established,from_client; content:"GET"; http_method; content:"/spazerock/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945387/; classtype:trojan-activity;sid:84808487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945386)"; flow:established,from_client; content:"GET"; http_method; content:"/cardegsol/redengine-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945386/; classtype:trojan-activity;sid:84808486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945384)"; flow:established,from_client; content:"GET"; http_method; content:"/daveride/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945384/; classtype:trojan-activity;sid:84808484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945385)"; flow:established,from_client; content:"GET"; http_method; content:"/kidrockys/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945385/; classtype:trojan-activity;sid:84808485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945382)"; flow:established,from_client; content:"GET"; http_method; content:"/welrshaa/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945382/; classtype:trojan-activity;sid:84808482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945383)"; flow:established,from_client; content:"GET"; http_method; content:"/terrl1nd/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945383/; classtype:trojan-activity;sid:84808483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945379)"; flow:established,from_client; content:"GET"; http_method; content:"/shanneksy/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945379/; classtype:trojan-activity;sid:84808479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945380)"; flow:established,from_client; content:"GET"; http_method; content:"/chammerly/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945380/; classtype:trojan-activity;sid:84808480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945381)"; flow:established,from_client; content:"GET"; http_method; content:"/lightrecord/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945381/; classtype:trojan-activity;sid:84808481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945378)"; flow:established,from_client; content:"GET"; http_method; content:"/lrth1/akebi-gc/head/akebi-gc.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945378/; classtype:trojan-activity;sid:84808478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945376)"; flow:established,from_client; content:"GET"; http_method; content:"/rockyjones/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945376/; classtype:trojan-activity;sid:84808476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945377)"; flow:established,from_client; content:"GET"; http_method; content:"/nissmirld/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945377/; classtype:trojan-activity;sid:84808477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945374)"; flow:established,from_client; content:"GET"; http_method; content:"/astrovip/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945374/; classtype:trojan-activity;sid:84808474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945375)"; flow:established,from_client; content:"GET"; http_method; content:"/slydream/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945375/; classtype:trojan-activity;sid:84808475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945373)"; flow:established,from_client; content:"GET"; http_method; content:"/luxislands/skriptgg/head/skriptgg.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945373/; classtype:trojan-activity;sid:84808473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945370)"; flow:established,from_client; content:"GET"; http_method; content:"/rainydayss/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945370/; classtype:trojan-activity;sid:84808470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945371)"; flow:established,from_client; content:"GET"; http_method; content:"/robloxmod/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945371/; classtype:trojan-activity;sid:84808471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945372)"; flow:established,from_client; content:"GET"; http_method; content:"/jimmyshots/redengine-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945372/; classtype:trojan-activity;sid:84808472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945367)"; flow:established,from_client; content:"GET"; http_method; content:"/tellsofy/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945367/; classtype:trojan-activity;sid:84808467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945368)"; flow:established,from_client; content:"GET"; http_method; content:"/aamersctr/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945368/; classtype:trojan-activity;sid:84808468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945369)"; flow:established,from_client; content:"GET"; http_method; content:"/feelsprings/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945369/; classtype:trojan-activity;sid:84808469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945365)"; flow:established,from_client; content:"GET"; http_method; content:"/rgbcity/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945365/; classtype:trojan-activity;sid:84808465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945366)"; flow:established,from_client; content:"GET"; http_method; content:"/cmehrys/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945366/; classtype:trojan-activity;sid:84808466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945364)"; flow:established,from_client; content:"GET"; http_method; content:"/linnychers/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945364/; classtype:trojan-activity;sid:84808464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945363)"; flow:established,from_client; content:"GET"; http_method; content:"/honcymad/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945363/; classtype:trojan-activity;sid:84808463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945362)"; flow:established,from_client; content:"GET"; http_method; content:"/stinnyjones/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945362/; classtype:trojan-activity;sid:84808462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945360)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/clean4213.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945360/; classtype:trojan-activity;sid:84808460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945361)"; flow:established,from_client; content:"GET"; http_method; content:"/kannychers/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945361/; classtype:trojan-activity;sid:84808461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945355)"; flow:established,from_client; content:"GET"; http_method; content:"/annulims/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945355/; classtype:trojan-activity;sid:84808455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945356)"; flow:established,from_client; content:"GET"; http_method; content:"/longnights/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945356/; classtype:trojan-activity;sid:84808456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945357)"; flow:established,from_client; content:"GET"; http_method; content:"/call1neus/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945357/; classtype:trojan-activity;sid:84808457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945358)"; flow:established,from_client; content:"GET"; http_method; content:"/bl3ve/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945358/; classtype:trojan-activity;sid:84808458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945359)"; flow:established,from_client; content:"GET"; http_method; content:"/strikkeplugg/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945359/; classtype:trojan-activity;sid:84808459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945354)"; flow:established,from_client; content:"GET"; http_method; content:"/landonsmith/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945354/; classtype:trojan-activity;sid:84808454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945350)"; flow:established,from_client; content:"GET"; http_method; content:"/champebattle/xeno-executor/head/xeno.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945350/; classtype:trojan-activity;sid:84808450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945351)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-64627/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945351/; classtype:trojan-activity;sid:84808451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945352)"; flow:established,from_client; content:"GET"; http_method; content:"/amm3lr/fivem-external-cheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945352/; classtype:trojan-activity;sid:84808452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945353)"; flow:established,from_client; content:"GET"; http_method; content:"/ims9rry/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945353/; classtype:trojan-activity;sid:84808453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945347)"; flow:established,from_client; content:"GET"; http_method; content:"/haspower/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945347/; classtype:trojan-activity;sid:84808447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945348)"; flow:established,from_client; content:"GET"; http_method; content:"/ammacl/fivem-external-cheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945348/; classtype:trojan-activity;sid:84808448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945349)"; flow:established,from_client; content:"GET"; http_method; content:"/fliplovers/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945349/; classtype:trojan-activity;sid:84808449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945345)"; flow:established,from_client; content:"GET"; http_method; content:"/aniellys/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945345/; classtype:trojan-activity;sid:84808445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945346)"; flow:established,from_client; content:"GET"; http_method; content:"/hjellx/c2panel/head/c2panel.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945346/; classtype:trojan-activity;sid:84808446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945344)"; flow:established,from_client; content:"GET"; http_method; content:"/nalleysh/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945344/; classtype:trojan-activity;sid:84808444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945342)"; flow:established,from_client; content:"GET"; http_method; content:"/djkhaleds/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945342/; classtype:trojan-activity;sid:84808442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945343)"; flow:established,from_client; content:"GET"; http_method; content:"/mollyland/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945343/; classtype:trojan-activity;sid:84808443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945341)"; flow:established,from_client; content:"GET"; http_method; content:"/mylivess/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945341/; classtype:trojan-activity;sid:84808441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945339)"; flow:established,from_client; content:"GET"; http_method; content:"/linwayne0/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945339/; classtype:trojan-activity;sid:84808439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945340)"; flow:established,from_client; content:"GET"; http_method; content:"/nossiley/swift-executor/head/swift.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945340/; classtype:trojan-activity;sid:84808440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945338)"; flow:established,from_client; content:"GET"; http_method; content:"/rettlixs/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945338/; classtype:trojan-activity;sid:84808438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945335)"; flow:established,from_client; content:"GET"; http_method; content:"/icegreens/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945335/; classtype:trojan-activity;sid:84808435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945336)"; flow:established,from_client; content:"GET"; http_method; content:"/flawshot/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945336/; classtype:trojan-activity;sid:84808436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945337)"; flow:established,from_client; content:"GET"; http_method; content:"/therr1iel/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945337/; classtype:trojan-activity;sid:84808437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945332)"; flow:established,from_client; content:"GET"; http_method; content:"/milltpros/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945332/; classtype:trojan-activity;sid:84808432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945333)"; flow:established,from_client; content:"GET"; http_method; content:"/aiwwane/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945333/; classtype:trojan-activity;sid:84808433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945334)"; flow:established,from_client; content:"GET"; http_method; content:"/kirkydevvy/rezo-gen/head/rezogen.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945334/; classtype:trojan-activity;sid:84808434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945328)"; flow:established,from_client; content:"GET"; http_method; content:"/darreouls/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945328/; classtype:trojan-activity;sid:84808428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945329)"; flow:established,from_client; content:"GET"; http_method; content:"/moneytalkss/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945329/; classtype:trojan-activity;sid:84808429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945330)"; flow:established,from_client; content:"GET"; http_method; content:"/flashrun/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945330/; classtype:trojan-activity;sid:84808430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945331)"; flow:established,from_client; content:"GET"; http_method; content:"/linosterns/warzone-dominator/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945331/; classtype:trojan-activity;sid:84808431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945326)"; flow:established,from_client; content:"GET"; http_method; content:"/angelsaway/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945326/; classtype:trojan-activity;sid:84808426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945327)"; flow:established,from_client; content:"GET"; http_method; content:"/lustyniar/fivem-external-cheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945327/; classtype:trojan-activity;sid:84808427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945325)"; flow:established,from_client; content:"GET"; http_method; content:"/hellycrap/swift-executor/head/swift.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945325/; classtype:trojan-activity;sid:84808425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945319)"; flow:established,from_client; content:"GET"; http_method; content:"/twentyfury/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945319/; classtype:trojan-activity;sid:84808419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945320)"; flow:established,from_client; content:"GET"; http_method; content:"/triplehit/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945320/; classtype:trojan-activity;sid:84808420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945321)"; flow:established,from_client; content:"GET"; http_method; content:"/easycutes/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945321/; classtype:trojan-activity;sid:84808421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945322)"; flow:established,from_client; content:"GET"; http_method; content:"/kapp1el/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945322/; classtype:trojan-activity;sid:84808422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945323)"; flow:established,from_client; content:"GET"; http_method; content:"/ann1eys/fortniteexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945323/; classtype:trojan-activity;sid:84808423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945324)"; flow:established,from_client; content:"GET"; http_method; content:"/brukelly/umbrella-hwid-tool/head/umbrella/umbrella.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945324/; classtype:trojan-activity;sid:84808424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945318)"; flow:established,from_client; content:"GET"; http_method; content:"/cherrywavess/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945318/; classtype:trojan-activity;sid:84808418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945315)"; flow:established,from_client; content:"GET"; http_method; content:"/snairwalve/dma-spoofer/head/dma_spoofer.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945315/; classtype:trojan-activity;sid:84808415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945316)"; flow:established,from_client; content:"GET"; http_method; content:"/cassyud/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945316/; classtype:trojan-activity;sid:84808416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945317)"; flow:established,from_client; content:"GET"; http_method; content:"/faithhard/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945317/; classtype:trojan-activity;sid:84808417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945312)"; flow:established,from_client; content:"GET"; http_method; content:"/cml3nfod/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945312/; classtype:trojan-activity;sid:84808412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945313)"; flow:established,from_client; content:"GET"; http_method; content:"/1elience/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945313/; classtype:trojan-activity;sid:84808413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945314)"; flow:established,from_client; content:"GET"; http_method; content:"/ellzios/redengine-fivem/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945314/; classtype:trojan-activity;sid:84808414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945309)"; flow:established,from_client; content:"GET"; http_method; content:"/cutcash/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945309/; classtype:trojan-activity;sid:84808409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945310)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-95704/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945310/; classtype:trojan-activity;sid:84808410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945311)"; flow:established,from_client; content:"GET"; http_method; content:"/hhand3lbf/fivem-lua-executor/head/tiagoexecutor.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945311/; classtype:trojan-activity;sid:84808411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945307)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-67193/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945307/; classtype:trojan-activity;sid:84808407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945308)"; flow:established,from_client; content:"GET"; http_method; content:"/heenl1es/akebi-gc/head/akebi-gc.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945308/; classtype:trojan-activity;sid:84808408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945306)"; flow:established,from_client; content:"GET"; http_method; content:"/fancykings/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945306/; classtype:trojan-activity;sid:84808406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945305)"; flow:established,from_client; content:"GET"; http_method; content:"/champgo/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945305/; classtype:trojan-activity;sid:84808405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945304)"; flow:established,from_client; content:"GET"; http_method; content:"/sophieray/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945304/; classtype:trojan-activity;sid:84808404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945301)"; flow:established,from_client; content:"GET"; http_method; content:"/savalge/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945301/; classtype:trojan-activity;sid:84808401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945302)"; flow:established,from_client; content:"GET"; http_method; content:"/r1achtelld/phoenixc2/head/phoenixc2.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945302/; classtype:trojan-activity;sid:84808402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945303)"; flow:established,from_client; content:"GET"; http_method; content:"/middlestones/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945303/; classtype:trojan-activity;sid:84808403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945299)"; flow:established,from_client; content:"GET"; http_method; content:"/blowswitch/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945299/; classtype:trojan-activity;sid:84808399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945300)"; flow:established,from_client; content:"GET"; http_method; content:"/sverr1nado/fortniteexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945300/; classtype:trojan-activity;sid:84808400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945296)"; flow:established,from_client; content:"GET"; http_method; content:"/silentflash/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945296/; classtype:trojan-activity;sid:84808396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945297)"; flow:established,from_client; content:"GET"; http_method; content:"/lettis99/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945297/; classtype:trojan-activity;sid:84808397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945298)"; flow:established,from_client; content:"GET"; http_method; content:"/thr1llsdn/warzoneexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945298/; classtype:trojan-activity;sid:84808398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945295)"; flow:established,from_client; content:"GET"; http_method; content:"/dr1vgans/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945295/; classtype:trojan-activity;sid:84808395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945294)"; flow:established,from_client; content:"GET"; http_method; content:"/k.skr/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945294/; classtype:trojan-activity;sid:84808394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945292)"; flow:established,from_client; content:"GET"; http_method; content:"/lonelydare/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945292/; classtype:trojan-activity;sid:84808392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945293)"; flow:established,from_client; content:"GET"; http_method; content:"/ddnslh/phoenixc2/head/phoenixc2.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945293/; classtype:trojan-activity;sid:84808393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945291)"; flow:established,from_client; content:"GET"; http_method; content:"/intoyous/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945291/; classtype:trojan-activity;sid:84808391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945290)"; flow:established,from_client; content:"GET"; http_method; content:"/m1ssth/fivem-mod-menu/head/loader.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945290/; classtype:trojan-activity;sid:84808390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945289)"; flow:established,from_client; content:"GET"; http_method; content:"/bitraces/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945289/; classtype:trojan-activity;sid:84808389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945288)"; flow:established,from_client; content:"GET"; http_method; content:"/evill0v3/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945288/; classtype:trojan-activity;sid:84808388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945283)"; flow:established,from_client; content:"GET"; http_method; content:"/bajww1y/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945283/; classtype:trojan-activity;sid:84808383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945284)"; flow:established,from_client; content:"GET"; http_method; content:"/wh0ammal/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945284/; classtype:trojan-activity;sid:84808384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945285)"; flow:established,from_client; content:"GET"; http_method; content:"/niceones/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945285/; classtype:trojan-activity;sid:84808385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945286)"; flow:established,from_client; content:"GET"; http_method; content:"/alexsmile/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945286/; classtype:trojan-activity;sid:84808386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945287)"; flow:established,from_client; content:"GET"; http_method; content:"/rainshifter/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945287/; classtype:trojan-activity;sid:84808387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945282)"; flow:established,from_client; content:"GET"; http_method; content:"/tenzart/redengine-fivem/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945282/; classtype:trojan-activity;sid:84808382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945281)"; flow:established,from_client; content:"GET"; http_method; content:"/retrenscall3/fivem-mod-menu/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945281/; classtype:trojan-activity;sid:84808381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945279)"; flow:established,from_client; content:"GET"; http_method; content:"/urremad/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945279/; classtype:trojan-activity;sid:84808379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945280)"; flow:established,from_client; content:"GET"; http_method; content:"/flowwers/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945280/; classtype:trojan-activity;sid:84808380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945278)"; flow:established,from_client; content:"GET"; http_method; content:"/jayfive/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945278/; classtype:trojan-activity;sid:84808378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945277)"; flow:established,from_client; content:"GET"; http_method; content:"/litdemons/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945277/; classtype:trojan-activity;sid:84808377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945274)"; flow:established,from_client; content:"GET"; http_method; content:"/jaydeethray/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945274/; classtype:trojan-activity;sid:84808374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945275)"; flow:established,from_client; content:"GET"; http_method; content:"/fetchmods/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945275/; classtype:trojan-activity;sid:84808375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945276)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-83061/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945276/; classtype:trojan-activity;sid:84808376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945271)"; flow:established,from_client; content:"GET"; http_method; content:"/sm0vvk1/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945271/; classtype:trojan-activity;sid:84808371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945272)"; flow:established,from_client; content:"GET"; http_method; content:"/linodress/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945272/; classtype:trojan-activity;sid:84808372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945273)"; flow:established,from_client; content:"GET"; http_method; content:"/scratchmirror/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945273/; classtype:trojan-activity;sid:84808373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945270)"; flow:established,from_client; content:"GET"; http_method; content:"/myrrhys/valorantexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945270/; classtype:trojan-activity;sid:84808370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945269)"; flow:established,from_client; content:"GET"; http_method; content:"/bloodytears/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945269/; classtype:trojan-activity;sid:84808369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945268)"; flow:established,from_client; content:"GET"; http_method; content:"/cernayless/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945268/; classtype:trojan-activity;sid:84808368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945266)"; flow:established,from_client; content:"GET"; http_method; content:"/calccer/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945266/; classtype:trojan-activity;sid:84808366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945267)"; flow:established,from_client; content:"GET"; http_method; content:"/carcellis/rezo-gen/head/rezogen.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945267/; classtype:trojan-activity;sid:84808367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945264)"; flow:established,from_client; content:"GET"; http_method; content:"/clearsun/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945264/; classtype:trojan-activity;sid:84808364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945265)"; flow:established,from_client; content:"GET"; http_method; content:"/youngbuckss/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945265/; classtype:trojan-activity;sid:84808365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945262)"; flow:established,from_client; content:"GET"; http_method; content:"/a1ncreed/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945262/; classtype:trojan-activity;sid:84808362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945263)"; flow:established,from_client; content:"GET"; http_method; content:"/scarletty/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945263/; classtype:trojan-activity;sid:84808363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945260)"; flow:established,from_client; content:"GET"; http_method; content:"/coscosource/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945260/; classtype:trojan-activity;sid:84808360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945261)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/ex1h7ahs91s.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945261/; classtype:trojan-activity;sid:84808361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945259)"; flow:established,from_client; content:"GET"; http_method; content:"/m1llashendj/warzoneexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945259/; classtype:trojan-activity;sid:84808359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945258)"; flow:established,from_client; content:"GET"; http_method; content:"/backstreet/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945258/; classtype:trojan-activity;sid:84808358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945255)"; flow:established,from_client; content:"GET"; http_method; content:"/ninjaboost-hook/fortniteexternalcheat/head/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945255/; classtype:trojan-activity;sid:84808355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945256)"; flow:established,from_client; content:"GET"; http_method; content:"/derrystone/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945256/; classtype:trojan-activity;sid:84808356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945257)"; flow:established,from_client; content:"GET"; http_method; content:"/bennj1m/fluxusexecutor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945257/; classtype:trojan-activity;sid:84808357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945254)"; flow:established,from_client; content:"GET"; http_method; content:"/mvainauskas801/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945254/; classtype:trojan-activity;sid:84808354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945252)"; flow:established,from_client; content:"GET"; http_method; content:"/br4ko/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945252/; classtype:trojan-activity;sid:84808352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945253)"; flow:established,from_client; content:"GET"; http_method; content:"/renn1vys/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945253/; classtype:trojan-activity;sid:84808353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945251)"; flow:established,from_client; content:"GET"; http_method; content:"/coldlights/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945251/; classtype:trojan-activity;sid:84808351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945250)"; flow:established,from_client; content:"GET"; http_method; content:"/robloxstudios/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945250/; classtype:trojan-activity;sid:84808350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945246)"; flow:established,from_client; content:"GET"; http_method; content:"/harriles/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945246/; classtype:trojan-activity;sid:84808346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945247)"; flow:established,from_client; content:"GET"; http_method; content:"/kassyelims/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945247/; classtype:trojan-activity;sid:84808347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945248)"; flow:established,from_client; content:"GET"; http_method; content:"/squeezeflow/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945248/; classtype:trojan-activity;sid:84808348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945249)"; flow:established,from_client; content:"GET"; http_method; content:"/marisgale/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945249/; classtype:trojan-activity;sid:84808349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945245)"; flow:established,from_client; content:"GET"; http_method; content:"/2ddros/warzoneexternalcheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945245/; classtype:trojan-activity;sid:84808345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945244)"; flow:established,from_client; content:"GET"; http_method; content:"/devantsteff/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945244/; classtype:trojan-activity;sid:84808344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945240)"; flow:established,from_client; content:"GET"; http_method; content:"/dantestriker/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945240/; classtype:trojan-activity;sid:84808340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945241)"; flow:established,from_client; content:"GET"; http_method; content:"/tiggoshaw/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945241/; classtype:trojan-activity;sid:84808341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945242)"; flow:established,from_client; content:"GET"; http_method; content:"/addelky/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945242/; classtype:trojan-activity;sid:84808342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945243)"; flow:established,from_client; content:"GET"; http_method; content:"/assmerty/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945243/; classtype:trojan-activity;sid:84808343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945238)"; flow:established,from_client; content:"GET"; http_method; content:"/lonelyspaze/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945238/; classtype:trojan-activity;sid:84808338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945239)"; flow:established,from_client; content:"GET"; http_method; content:"/calcereeth/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945239/; classtype:trojan-activity;sid:84808339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945235)"; flow:established,from_client; content:"GET"; http_method; content:"/fivemmods/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945235/; classtype:trojan-activity;sid:84808335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945236)"; flow:established,from_client; content:"GET"; http_method; content:"/r3ssa/fortnitecheatexternal/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945236/; classtype:trojan-activity;sid:84808336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945237)"; flow:established,from_client; content:"GET"; http_method; content:"/sk1ew/c2panel/head/c2panel.exe"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945237/; classtype:trojan-activity;sid:84808337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945231)"; flow:established,from_client; content:"GET"; http_method; content:"/skymindss/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945231/; classtype:trojan-activity;sid:84808331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945232)"; flow:established,from_client; content:"GET"; http_method; content:"/k1errl/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945232/; classtype:trojan-activity;sid:84808332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945233)"; flow:established,from_client; content:"GET"; http_method; content:"/antracctios/dma-spoofer/head/dma_spoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945233/; classtype:trojan-activity;sid:84808333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945234)"; flow:established,from_client; content:"GET"; http_method; content:"/rivalshub/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945234/; classtype:trojan-activity;sid:84808334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945229)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-88824/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945229/; classtype:trojan-activity;sid:84808329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945230)"; flow:established,from_client; content:"GET"; http_method; content:"/climmenflora/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945230/; classtype:trojan-activity;sid:84808330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945228)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/draft3637.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945228/; classtype:trojan-activity;sid:84808328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945224)"; flow:established,from_client; content:"GET"; http_method; content:"/derriolst/swift-executor/head/swift.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945224/; classtype:trojan-activity;sid:84808324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945225)"; flow:established,from_client; content:"GET"; http_method; content:"/shairmes/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945225/; classtype:trojan-activity;sid:84808325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945226)"; flow:established,from_client; content:"GET"; http_method; content:"/decrepts/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945226/; classtype:trojan-activity;sid:84808326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945227)"; flow:established,from_client; content:"GET"; http_method; content:"/seumms/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945227/; classtype:trojan-activity;sid:84808327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945223)"; flow:established,from_client; content:"GET"; http_method; content:"/cahrlecute/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945223/; classtype:trojan-activity;sid:84808323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945222)"; flow:established,from_client; content:"GET"; http_method; content:"/treyten/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945222/; classtype:trojan-activity;sid:84808322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945221)"; flow:established,from_client; content:"GET"; http_method; content:"/ekxstar/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945221/; classtype:trojan-activity;sid:84808321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945218)"; flow:established,from_client; content:"GET"; http_method; content:"/mjjd9/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945218/; classtype:trojan-activity;sid:84808318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945219)"; flow:established,from_client; content:"GET"; http_method; content:"/sheeww09/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945219/; classtype:trojan-activity;sid:84808319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945220)"; flow:established,from_client; content:"GET"; http_method; content:"/marrymss/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945220/; classtype:trojan-activity;sid:84808320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945216)"; flow:established,from_client; content:"GET"; http_method; content:"/sanhilldy/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945216/; classtype:trojan-activity;sid:84808316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945217)"; flow:established,from_client; content:"GET"; http_method; content:"/srtlen/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945217/; classtype:trojan-activity;sid:84808317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945214)"; flow:established,from_client; content:"GET"; http_method; content:"/n1elcery/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945214/; classtype:trojan-activity;sid:84808314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945215)"; flow:established,from_client; content:"GET"; http_method; content:"/n0winter/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945215/; classtype:trojan-activity;sid:84808315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945210)"; flow:established,from_client; content:"GET"; http_method; content:"/clapeymeed/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945210/; classtype:trojan-activity;sid:84808310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945211)"; flow:established,from_client; content:"GET"; http_method; content:"/werst1ll/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945211/; classtype:trojan-activity;sid:84808311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945212)"; flow:established,from_client; content:"GET"; http_method; content:"/smokeloud/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945212/; classtype:trojan-activity;sid:84808312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945213)"; flow:established,from_client; content:"GET"; http_method; content:"/hannessybit/fivem-mod-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945213/; classtype:trojan-activity;sid:84808313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945207)"; flow:established,from_client; content:"GET"; http_method; content:"/coldrunnss/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945207/; classtype:trojan-activity;sid:84808307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945208)"; flow:established,from_client; content:"GET"; http_method; content:"/shuurens/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945208/; classtype:trojan-activity;sid:84808308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945209)"; flow:established,from_client; content:"GET"; http_method; content:"/babyfacess/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945209/; classtype:trojan-activity;sid:84808309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945206)"; flow:established,from_client; content:"GET"; http_method; content:"/1vaih3l/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945206/; classtype:trojan-activity;sid:84808306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945204)"; flow:established,from_client; content:"GET"; http_method; content:"/hitituo/solara/head/solara%20v3.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945204/; classtype:trojan-activity;sid:84808304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945205)"; flow:established,from_client; content:"GET"; http_method; content:"/aerostars99/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945205/; classtype:trojan-activity;sid:84808305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945202)"; flow:established,from_client; content:"GET"; http_method; content:"/draknones/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945202/; classtype:trojan-activity;sid:84808302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945203)"; flow:established,from_client; content:"GET"; http_method; content:"/h1llffy/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945203/; classtype:trojan-activity;sid:84808303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945201)"; flow:established,from_client; content:"GET"; http_method; content:"/flawlessss/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945201/; classtype:trojan-activity;sid:84808301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945199)"; flow:established,from_client; content:"GET"; http_method; content:"/lorrtheway/warzone-dominator/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945199/; classtype:trojan-activity;sid:84808299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945200)"; flow:established,from_client; content:"GET"; http_method; content:"/archilands/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945200/; classtype:trojan-activity;sid:84808300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945197)"; flow:established,from_client; content:"GET"; http_method; content:"/ghosthell/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945197/; classtype:trojan-activity;sid:84808297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945198)"; flow:established,from_client; content:"GET"; http_method; content:"/fessepsiol/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945198/; classtype:trojan-activity;sid:84808298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945195)"; flow:established,from_client; content:"GET"; http_method; content:"/annelyscod/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945195/; classtype:trojan-activity;sid:84808295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945196)"; flow:established,from_client; content:"GET"; http_method; content:"/clickforce/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945196/; classtype:trojan-activity;sid:84808296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945192)"; flow:established,from_client; content:"GET"; http_method; content:"/hellafines/redengine-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945192/; classtype:trojan-activity;sid:84808292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945193)"; flow:established,from_client; content:"GET"; http_method; content:"/spindarks/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945193/; classtype:trojan-activity;sid:84808293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945194)"; flow:established,from_client; content:"GET"; http_method; content:"/dalgfighter/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945194/; classtype:trojan-activity;sid:84808294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945191)"; flow:established,from_client; content:"GET"; http_method; content:"/louisbess/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945191/; classtype:trojan-activity;sid:84808291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945186)"; flow:established,from_client; content:"GET"; http_method; content:"/darkslimes/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945186/; classtype:trojan-activity;sid:84808286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945187)"; flow:established,from_client; content:"GET"; http_method; content:"/rinospot/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945187/; classtype:trojan-activity;sid:84808287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945188)"; flow:established,from_client; content:"GET"; http_method; content:"/camilessy/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945188/; classtype:trojan-activity;sid:84808288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945189)"; flow:established,from_client; content:"GET"; http_method; content:"/breadmakers/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945189/; classtype:trojan-activity;sid:84808289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945190)"; flow:established,from_client; content:"GET"; http_method; content:"/nellykit/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945190/; classtype:trojan-activity;sid:84808290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945185)"; flow:established,from_client; content:"GET"; http_method; content:"/lempacch/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945185/; classtype:trojan-activity;sid:84808285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945184)"; flow:established,from_client; content:"GET"; http_method; content:"/breathloves/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945184/; classtype:trojan-activity;sid:84808284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945182)"; flow:established,from_client; content:"GET"; http_method; content:"/hhl3mm/fivem-mod-menu-2024/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945182/; classtype:trojan-activity;sid:84808282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945183)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyxprod/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945183/; classtype:trojan-activity;sid:84808283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945174)"; flow:established,from_client; content:"GET"; http_method; content:"/windgods/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945174/; classtype:trojan-activity;sid:84808274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945175)"; flow:established,from_client; content:"GET"; http_method; content:"/lexx1ngs/c2panel/head/phoenixc2.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945175/; classtype:trojan-activity;sid:84808275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945176)"; flow:established,from_client; content:"GET"; http_method; content:"/littlesbit/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945176/; classtype:trojan-activity;sid:84808276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945177)"; flow:established,from_client; content:"GET"; http_method; content:"/derrikhawk/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945177/; classtype:trojan-activity;sid:84808277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945178)"; flow:established,from_client; content:"GET"; http_method; content:"/tellysmorph/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945178/; classtype:trojan-activity;sid:84808278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945179)"; flow:established,from_client; content:"GET"; http_method; content:"/hamtyshev/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945179/; classtype:trojan-activity;sid:84808279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945180)"; flow:established,from_client; content:"GET"; http_method; content:"/myleoonel/solara/head/solara%20v3.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945180/; classtype:trojan-activity;sid:84808280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945181)"; flow:established,from_client; content:"GET"; http_method; content:"/pressentg/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945181/; classtype:trojan-activity;sid:84808281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945172)"; flow:established,from_client; content:"GET"; http_method; content:"/nellyfeat/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945172/; classtype:trojan-activity;sid:84808272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945173)"; flow:established,from_client; content:"GET"; http_method; content:"/rickspeedin/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945173/; classtype:trojan-activity;sid:84808273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945170)"; flow:established,from_client; content:"GET"; http_method; content:"/buggfuture/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945170/; classtype:trojan-activity;sid:84808270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945171)"; flow:established,from_client; content:"GET"; http_method; content:"/reelland/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945171/; classtype:trojan-activity;sid:84808271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945169)"; flow:established,from_client; content:"GET"; http_method; content:"/bizzybanks/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945169/; classtype:trojan-activity;sid:84808269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945168)"; flow:established,from_client; content:"GET"; http_method; content:"/fashionkilla/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945168/; classtype:trojan-activity;sid:84808268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945167)"; flow:established,from_client; content:"GET"; http_method; content:"/realwhaff/c2panel/head/c2panel.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945167/; classtype:trojan-activity;sid:84808267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945166)"; flow:established,from_client; content:"GET"; http_method; content:"/blackvaults/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945166/; classtype:trojan-activity;sid:84808266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945160)"; flow:established,from_client; content:"GET"; http_method; content:"/nikravery/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945160/; classtype:trojan-activity;sid:84808260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945161)"; flow:established,from_client; content:"GET"; http_method; content:"/sleekprod/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945161/; classtype:trojan-activity;sid:84808261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945162)"; flow:established,from_client; content:"GET"; http_method; content:"/marniesally/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945162/; classtype:trojan-activity;sid:84808262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945163)"; flow:established,from_client; content:"GET"; http_method; content:"/fetterminds/rezo-gen/head/rezogen.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945163/; classtype:trojan-activity;sid:84808263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945164)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/7m260nmm3nqf.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945164/; classtype:trojan-activity;sid:84808264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945165)"; flow:established,from_client; content:"GET"; http_method; content:"/zell1ssh/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945165/; classtype:trojan-activity;sid:84808265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945158)"; flow:established,from_client; content:"GET"; http_method; content:"/christiancartier/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945158/; classtype:trojan-activity;sid:84808258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945159)"; flow:established,from_client; content:"GET"; http_method; content:"/breakingglights/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945159/; classtype:trojan-activity;sid:84808259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945157)"; flow:established,from_client; content:"GET"; http_method; content:"/shilfview/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945157/; classtype:trojan-activity;sid:84808257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945156)"; flow:established,from_client; content:"GET"; http_method; content:"/1taskl3n/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945156/; classtype:trojan-activity;sid:84808256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945154)"; flow:established,from_client; content:"GET"; http_method; content:"/lilflow/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945154/; classtype:trojan-activity;sid:84808254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945155)"; flow:established,from_client; content:"GET"; http_method; content:"/drakeflock/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945155/; classtype:trojan-activity;sid:84808255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945153)"; flow:established,from_client; content:"GET"; http_method; content:"/scarylayout/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945153/; classtype:trojan-activity;sid:84808253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945152)"; flow:established,from_client; content:"GET"; http_method; content:"/e1nsilver/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945152/; classtype:trojan-activity;sid:84808252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945149)"; flow:established,from_client; content:"GET"; http_method; content:"/loudyskys/fivem-external-cheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945149/; classtype:trojan-activity;sid:84808249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945150)"; flow:established,from_client; content:"GET"; http_method; content:"/arrenthc/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945150/; classtype:trojan-activity;sid:84808250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945151)"; flow:established,from_client; content:"GET"; http_method; content:"/kingvonx/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945151/; classtype:trojan-activity;sid:84808251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945147)"; flow:established,from_client; content:"GET"; http_method; content:"/chylesst/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945147/; classtype:trojan-activity;sid:84808247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945148)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyghost/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945148/; classtype:trojan-activity;sid:84808248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945142)"; flow:established,from_client; content:"GET"; http_method; content:"/rayvintage/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945142/; classtype:trojan-activity;sid:84808242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945143)"; flow:established,from_client; content:"GET"; http_method; content:"/faynelim/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945143/; classtype:trojan-activity;sid:84808243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945144)"; flow:established,from_client; content:"GET"; http_method; content:"/rovermercury/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945144/; classtype:trojan-activity;sid:84808244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945145)"; flow:established,from_client; content:"GET"; http_method; content:"/l3ahx/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945145/; classtype:trojan-activity;sid:84808245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945146)"; flow:established,from_client; content:"GET"; http_method; content:"/actiniy/fivem-spoofer/head/main/five_spoofer_v3.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945146/; classtype:trojan-activity;sid:84808246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945140)"; flow:established,from_client; content:"GET"; http_method; content:"/erryshsos/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945140/; classtype:trojan-activity;sid:84808240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945141)"; flow:established,from_client; content:"GET"; http_method; content:"/collygass/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945141/; classtype:trojan-activity;sid:84808241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945136)"; flow:established,from_client; content:"GET"; http_method; content:"/andyfive/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945136/; classtype:trojan-activity;sid:84808236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945137)"; flow:established,from_client; content:"GET"; http_method; content:"/galbiaawi/galbiaawi-project67/-/raw/main/program.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945137/; classtype:trojan-activity;sid:84808237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945138)"; flow:established,from_client; content:"GET"; http_method; content:"/streetleaks/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945138/; classtype:trojan-activity;sid:84808238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945139)"; flow:established,from_client; content:"GET"; http_method; content:"/highwayss/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945139/; classtype:trojan-activity;sid:84808239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945135)"; flow:established,from_client; content:"GET"; http_method; content:"/sn1ffworld/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945135/; classtype:trojan-activity;sid:84808235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945133)"; flow:established,from_client; content:"GET"; http_method; content:"/twistedlex/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945133/; classtype:trojan-activity;sid:84808233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945134)"; flow:established,from_client; content:"GET"; http_method; content:"/hollyleaks/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945134/; classtype:trojan-activity;sid:84808234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945131)"; flow:established,from_client; content:"GET"; http_method; content:"/chanelssbet/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945131/; classtype:trojan-activity;sid:84808231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945132)"; flow:established,from_client; content:"GET"; http_method; content:"/thehit/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945132/; classtype:trojan-activity;sid:84808232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945128)"; flow:established,from_client; content:"GET"; http_method; content:"/luccords/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945128/; classtype:trojan-activity;sid:84808228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945129)"; flow:established,from_client; content:"GET"; http_method; content:"/maxdemons/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945129/; classtype:trojan-activity;sid:84808229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945130)"; flow:established,from_client; content:"GET"; http_method; content:"/moderrys/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945130/; classtype:trojan-activity;sid:84808230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945125)"; flow:established,from_client; content:"GET"; http_method; content:"/feedmytrikc/fivem-mod-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945125/; classtype:trojan-activity;sid:84808225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945126)"; flow:established,from_client; content:"GET"; http_method; content:"/incredd1bl/stalcraft-wh-chams-speedhack-fb/head/loader.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945126/; classtype:trojan-activity;sid:84808226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945127)"; flow:established,from_client; content:"GET"; http_method; content:"/redstewart/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945127/; classtype:trojan-activity;sid:84808227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945124)"; flow:established,from_client; content:"GET"; http_method; content:"/vangstrong/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945124/; classtype:trojan-activity;sid:84808224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945122)"; flow:established,from_client; content:"GET"; http_method; content:"/smaddly/warzone-dominator/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945122/; classtype:trojan-activity;sid:84808222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945123)"; flow:established,from_client; content:"GET"; http_method; content:"/angelsfire/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945123/; classtype:trojan-activity;sid:84808223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945120)"; flow:established,from_client; content:"GET"; http_method; content:"/mrwollfs/akebi-gc/head/akebi-gc.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945120/; classtype:trojan-activity;sid:84808220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945121)"; flow:established,from_client; content:"GET"; http_method; content:"/sunshanes/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945121/; classtype:trojan-activity;sid:84808221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945119)"; flow:established,from_client; content:"GET"; http_method; content:"/claudycodes/dma-spoofer/head/dma_spoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945119/; classtype:trojan-activity;sid:84808219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945118)"; flow:established,from_client; content:"GET"; http_method; content:"/merrem1/skriptgg/head/skriptgg.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945118/; classtype:trojan-activity;sid:84808218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945117)"; flow:established,from_client; content:"GET"; http_method; content:"/rayn1e/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945117/; classtype:trojan-activity;sid:84808217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945115)"; flow:established,from_client; content:"GET"; http_method; content:"/eternnh/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945115/; classtype:trojan-activity;sid:84808215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945116)"; flow:established,from_client; content:"GET"; http_method; content:"/lexxyn1ght/solara/head/solara%20v3.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945116/; classtype:trojan-activity;sid:84808216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945113)"; flow:established,from_client; content:"GET"; http_method; content:"/ellamoon/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945113/; classtype:trojan-activity;sid:84808213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945114)"; flow:established,from_client; content:"GET"; http_method; content:"/earn1ys/solara/head/solara%20v3.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945114/; classtype:trojan-activity;sid:84808214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945111)"; flow:established,from_client; content:"GET"; http_method; content:"/asm1rall/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945111/; classtype:trojan-activity;sid:84808211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945112)"; flow:established,from_client; content:"GET"; http_method; content:"/cassieline/redengine-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945112/; classtype:trojan-activity;sid:84808212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945108)"; flow:established,from_client; content:"GET"; http_method; content:"/crystalmix/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945108/; classtype:trojan-activity;sid:84808208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945109)"; flow:established,from_client; content:"GET"; http_method; content:"/shadowmid/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945109/; classtype:trojan-activity;sid:84808209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945110)"; flow:established,from_client; content:"GET"; http_method; content:"/skieesbruh/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945110/; classtype:trojan-activity;sid:84808210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945106)"; flow:established,from_client; content:"GET"; http_method; content:"/blackeyex/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945106/; classtype:trojan-activity;sid:84808206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945107)"; flow:established,from_client; content:"GET"; http_method; content:"/rachelbenz/skriptgg/-/raw/main/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945107/; classtype:trojan-activity;sid:84808207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945104)"; flow:established,from_client; content:"GET"; http_method; content:"/millysouls/skriptgg/head/skriptgg.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945104/; classtype:trojan-activity;sid:84808204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945105)"; flow:established,from_client; content:"GET"; http_method; content:"/creyty1h/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945105/; classtype:trojan-activity;sid:84808205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945103)"; flow:established,from_client; content:"GET"; http_method; content:"/luckysharp/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945103/; classtype:trojan-activity;sid:84808203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945102)"; flow:established,from_client; content:"GET"; http_method; content:"/baddlybenz/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945102/; classtype:trojan-activity;sid:84808202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945099)"; flow:established,from_client; content:"GET"; http_method; content:"/einsspel/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945099/; classtype:trojan-activity;sid:84808199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945100)"; flow:established,from_client; content:"GET"; http_method; content:"/madmaxxxx/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945100/; classtype:trojan-activity;sid:84808200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945101)"; flow:established,from_client; content:"GET"; http_method; content:"/icespices/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945101/; classtype:trojan-activity;sid:84808201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945098)"; flow:established,from_client; content:"GET"; http_method; content:"/finnykland/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945098/; classtype:trojan-activity;sid:84808198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945097)"; flow:established,from_client; content:"GET"; http_method; content:"/levelcaps/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945097/; classtype:trojan-activity;sid:84808197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945096)"; flow:established,from_client; content:"GET"; http_method; content:"/etherist/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945096/; classtype:trojan-activity;sid:84808196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945095)"; flow:established,from_client; content:"GET"; http_method; content:"/rctshasl/c2panel/head/c2panel.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945095/; classtype:trojan-activity;sid:84808195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945093)"; flow:established,from_client; content:"GET"; http_method; content:"/larriedgs/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945093/; classtype:trojan-activity;sid:84808193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945094)"; flow:established,from_client; content:"GET"; http_method; content:"/m1nestakkl/tiago-executor-fivem/head/tiagoexecutor.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945094/; classtype:trojan-activity;sid:84808194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945092)"; flow:established,from_client; content:"GET"; http_method; content:"/futurebest/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945092/; classtype:trojan-activity;sid:84808192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945091)"; flow:established,from_client; content:"GET"; http_method; content:"/uterrfly/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945091/; classtype:trojan-activity;sid:84808191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945088)"; flow:established,from_client; content:"GET"; http_method; content:"/paingames/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945088/; classtype:trojan-activity;sid:84808188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945089)"; flow:established,from_client; content:"GET"; http_method; content:"/duoeer/pubg-desync-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945089/; classtype:trojan-activity;sid:84808189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945090)"; flow:established,from_client; content:"GET"; http_method; content:"/hellywayne/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945090/; classtype:trojan-activity;sid:84808190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945087)"; flow:established,from_client; content:"GET"; http_method; content:"/racktyga/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945087/; classtype:trojan-activity;sid:84808187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945086)"; flow:established,from_client; content:"GET"; http_method; content:"/arretx9/eulencheats-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945086/; classtype:trojan-activity;sid:84808186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945085)"; flow:established,from_client; content:"GET"; http_method; content:"/darkface/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945085/; classtype:trojan-activity;sid:84808185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945084)"; flow:established,from_client; content:"GET"; http_method; content:"/silencehit/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945084/; classtype:trojan-activity;sid:84808184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945082)"; flow:established,from_client; content:"GET"; http_method; content:"/chassmilty/swift-executor/head/swift.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945082/; classtype:trojan-activity;sid:84808182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945083)"; flow:established,from_client; content:"GET"; http_method; content:"/therapture/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945083/; classtype:trojan-activity;sid:84808183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945081)"; flow:established,from_client; content:"GET"; http_method; content:"/predatts/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945081/; classtype:trojan-activity;sid:84808181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945080)"; flow:established,from_client; content:"GET"; http_method; content:"/chammerth/xeno-executor/head/xeno.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945080/; classtype:trojan-activity;sid:84808180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945078)"; flow:established,from_client; content:"GET"; http_method; content:"/litthersy/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945078/; classtype:trojan-activity;sid:84808178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945079)"; flow:established,from_client; content:"GET"; http_method; content:"/beeloves/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945079/; classtype:trojan-activity;sid:84808179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945077)"; flow:established,from_client; content:"GET"; http_method; content:"/cellistin/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945077/; classtype:trojan-activity;sid:84808177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945076)"; flow:established,from_client; content:"GET"; http_method; content:"/calliloyars/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945076/; classtype:trojan-activity;sid:84808176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945075)"; flow:established,from_client; content:"GET"; http_method; content:"/h0fablood/akebi-gc/head/akebi-gc.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945075/; classtype:trojan-activity;sid:84808175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945074)"; flow:established,from_client; content:"GET"; http_method; content:"/looksydillar/skriptgg/head/skriptgg.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945074/; classtype:trojan-activity;sid:84808174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945073)"; flow:established,from_client; content:"GET"; http_method; content:"/cr1cragss/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945073/; classtype:trojan-activity;sid:84808173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945070)"; flow:established,from_client; content:"GET"; http_method; content:"/krissmind/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945070/; classtype:trojan-activity;sid:84808170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945071)"; flow:established,from_client; content:"GET"; http_method; content:"/flokkyslide/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945071/; classtype:trojan-activity;sid:84808171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945072)"; flow:established,from_client; content:"GET"; http_method; content:"/skallyer/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945072/; classtype:trojan-activity;sid:84808172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945069)"; flow:established,from_client; content:"GET"; http_method; content:"/purellys/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945069/; classtype:trojan-activity;sid:84808169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945067)"; flow:established,from_client; content:"GET"; http_method; content:"/spectreless/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945067/; classtype:trojan-activity;sid:84808167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945068)"; flow:established,from_client; content:"GET"; http_method; content:"/claimstars/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945068/; classtype:trojan-activity;sid:84808168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945065)"; flow:established,from_client; content:"GET"; http_method; content:"/bobsimit20/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945065/; classtype:trojan-activity;sid:84808165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945066)"; flow:established,from_client; content:"GET"; http_method; content:"/alisophy/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945066/; classtype:trojan-activity;sid:84808166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945064)"; flow:established,from_client; content:"GET"; http_method; content:"/flockyblock/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945064/; classtype:trojan-activity;sid:84808164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945060)"; flow:established,from_client; content:"GET"; http_method; content:"/smashcats/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945060/; classtype:trojan-activity;sid:84808160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945061)"; flow:established,from_client; content:"GET"; http_method; content:"/il3sh3n/fivem-mod-menu-2024/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945061/; classtype:trojan-activity;sid:84808161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945062)"; flow:established,from_client; content:"GET"; http_method; content:"/stehh1l/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945062/; classtype:trojan-activity;sid:84808162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945063)"; flow:established,from_client; content:"GET"; http_method; content:"/playoffx/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945063/; classtype:trojan-activity;sid:84808163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945057)"; flow:established,from_client; content:"GET"; http_method; content:"/sanzpro5/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945057/; classtype:trojan-activity;sid:84808157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945058)"; flow:established,from_client; content:"GET"; http_method; content:"/xennyflow/verox-gta-enhanced/head/verox.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945058/; classtype:trojan-activity;sid:84808158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945059)"; flow:established,from_client; content:"GET"; http_method; content:"/fluxusdeveloper/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945059/; classtype:trojan-activity;sid:84808159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945055)"; flow:established,from_client; content:"GET"; http_method; content:"/secidiots/exodus-larp-tool/head/exodus.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945055/; classtype:trojan-activity;sid:84808155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945056)"; flow:established,from_client; content:"GET"; http_method; content:"/drismad/warzoneexternalcheat/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945056/; classtype:trojan-activity;sid:84808156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945053)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-25933/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945053/; classtype:trojan-activity;sid:84808153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945054)"; flow:established,from_client; content:"GET"; http_method; content:"/firebirdss/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945054/; classtype:trojan-activity;sid:84808154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945051)"; flow:established,from_client; content:"GET"; http_method; content:"/slimthugs/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945051/; classtype:trojan-activity;sid:84808151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945052)"; flow:established,from_client; content:"GET"; http_method; content:"/brandonhillss/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945052/; classtype:trojan-activity;sid:84808152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945044)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-93119/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945044/; classtype:trojan-activity;sid:84808144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945045)"; flow:established,from_client; content:"GET"; http_method; content:"/k1leens/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945045/; classtype:trojan-activity;sid:84808145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945046)"; flow:established,from_client; content:"GET"; http_method; content:"/ennerlis/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945046/; classtype:trojan-activity;sid:84808146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945047)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyes/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945047/; classtype:trojan-activity;sid:84808147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945048)"; flow:established,from_client; content:"GET"; http_method; content:"/l1eyssh/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945048/; classtype:trojan-activity;sid:84808148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945049)"; flow:established,from_client; content:"GET"; http_method; content:"/miderrln/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945049/; classtype:trojan-activity;sid:84808149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945050)"; flow:established,from_client; content:"GET"; http_method; content:"/carre1ys/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945050/; classtype:trojan-activity;sid:84808150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945040)"; flow:established,from_client; content:"GET"; http_method; content:"/ninestalk/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945040/; classtype:trojan-activity;sid:84808140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945041)"; flow:established,from_client; content:"GET"; http_method; content:"/disneyworld/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945041/; classtype:trojan-activity;sid:84808141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945042)"; flow:established,from_client; content:"GET"; http_method; content:"/mrsquezze/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945042/; classtype:trojan-activity;sid:84808142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945043)"; flow:established,from_client; content:"GET"; http_method; content:"/atthry/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945043/; classtype:trojan-activity;sid:84808143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945036)"; flow:established,from_client; content:"GET"; http_method; content:"/ahhelsan/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945036/; classtype:trojan-activity;sid:84808136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945037)"; flow:established,from_client; content:"GET"; http_method; content:"/darkenclimbs/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945037/; classtype:trojan-activity;sid:84808137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945038)"; flow:established,from_client; content:"GET"; http_method; content:"/starlightoke/fivem-mod-menu/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945038/; classtype:trojan-activity;sid:84808138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945039)"; flow:established,from_client; content:"GET"; http_method; content:"/ccctennx/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945039/; classtype:trojan-activity;sid:84808139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945030)"; flow:established,from_client; content:"GET"; http_method; content:"/breddylee/eulencheats-fivem/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945030/; classtype:trojan-activity;sid:84808130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945031)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-52619/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945031/; classtype:trojan-activity;sid:84808131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945032)"; flow:established,from_client; content:"GET"; http_method; content:"/ashreal/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945032/; classtype:trojan-activity;sid:84808132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945033)"; flow:established,from_client; content:"GET"; http_method; content:"/dertlandd/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945033/; classtype:trojan-activity;sid:84808133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945034)"; flow:established,from_client; content:"GET"; http_method; content:"/callwave/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945034/; classtype:trojan-activity;sid:84808134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945035)"; flow:established,from_client; content:"GET"; http_method; content:"/nellamoon/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945035/; classtype:trojan-activity;sid:84808135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945029)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-73810/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945029/; classtype:trojan-activity;sid:84808129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945028)"; flow:established,from_client; content:"GET"; http_method; content:"/panssey/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945028/; classtype:trojan-activity;sid:84808128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945026)"; flow:established,from_client; content:"GET"; http_method; content:"/celmm1y/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945026/; classtype:trojan-activity;sid:84808126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945027)"; flow:established,from_client; content:"GET"; http_method; content:"/cocandrei88/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945027/; classtype:trojan-activity;sid:84808127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945024)"; flow:established,from_client; content:"GET"; http_method; content:"/hawkseven/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945024/; classtype:trojan-activity;sid:84808124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945025)"; flow:established,from_client; content:"GET"; http_method; content:"/urresst/redengine-fivem/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945025/; classtype:trojan-activity;sid:84808125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945023)"; flow:established,from_client; content:"GET"; http_method; content:"/linespectr/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945023/; classtype:trojan-activity;sid:84808123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945022)"; flow:established,from_client; content:"GET"; http_method; content:"/vrhall/c2panel/head/c2panel.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945022/; classtype:trojan-activity;sid:84808122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945021)"; flow:established,from_client; content:"GET"; http_method; content:"/curtyxdev/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945021/; classtype:trojan-activity;sid:84808121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945020)"; flow:established,from_client; content:"GET"; http_method; content:"/memphisrays/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945020/; classtype:trojan-activity;sid:84808120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945019)"; flow:established,from_client; content:"GET"; http_method; content:"/tha1lsh/warzoneexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945019/; classtype:trojan-activity;sid:84808119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945018)"; flow:established,from_client; content:"GET"; http_method; content:"/apprechs/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945018/; classtype:trojan-activity;sid:84808118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945017)"; flow:established,from_client; content:"GET"; http_method; content:"/springfieldss/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945017/; classtype:trojan-activity;sid:84808117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945011)"; flow:established,from_client; content:"GET"; http_method; content:"/peussh1ng/phoenixc2/head/phoenixc2.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945011/; classtype:trojan-activity;sid:84808111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945012)"; flow:established,from_client; content:"GET"; http_method; content:"/thousandscreams/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945012/; classtype:trojan-activity;sid:84808112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945013)"; flow:established,from_client; content:"GET"; http_method; content:"/screwlyhound/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945013/; classtype:trojan-activity;sid:84808113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945014)"; flow:established,from_client; content:"GET"; http_method; content:"/rockfeel/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945014/; classtype:trojan-activity;sid:84808114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945015)"; flow:established,from_client; content:"GET"; http_method; content:"/freeunlocks/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945015/; classtype:trojan-activity;sid:84808115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945016)"; flow:established,from_client; content:"GET"; http_method; content:"/lifefour/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945016/; classtype:trojan-activity;sid:84808116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945010)"; flow:established,from_client; content:"GET"; http_method; content:"/reckylessy/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945010/; classtype:trojan-activity;sid:84808110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945002)"; flow:established,from_client; content:"GET"; http_method; content:"/earltwin/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945002/; classtype:trojan-activity;sid:84808102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945003)"; flow:established,from_client; content:"GET"; http_method; content:"/flashbars/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945003/; classtype:trojan-activity;sid:84808103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945004)"; flow:established,from_client; content:"GET"; http_method; content:"/cllierys/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945004/; classtype:trojan-activity;sid:84808104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945005)"; flow:established,from_client; content:"GET"; http_method; content:"/fernniud/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945005/; classtype:trojan-activity;sid:84808105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945006)"; flow:established,from_client; content:"GET"; http_method; content:"/bleddimurs/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945006/; classtype:trojan-activity;sid:84808106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945007)"; flow:established,from_client; content:"GET"; http_method; content:"/tk3ssta/akebi-gc/head/akebi-gc.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945007/; classtype:trojan-activity;sid:84808107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945008)"; flow:established,from_client; content:"GET"; http_method; content:"/1nicchel/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945008/; classtype:trojan-activity;sid:84808108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945009)"; flow:established,from_client; content:"GET"; http_method; content:"/shvvl1n/fivem-mod-menu/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945009/; classtype:trojan-activity;sid:84808109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944996)"; flow:established,from_client; content:"GET"; http_method; content:"/fivelouds/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944996/; classtype:trojan-activity;sid:84808096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944997)"; flow:established,from_client; content:"GET"; http_method; content:"/thisfeelings/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944997/; classtype:trojan-activity;sid:84808097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944998)"; flow:established,from_client; content:"GET"; http_method; content:"/sweetsalty/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944998/; classtype:trojan-activity;sid:84808098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944999)"; flow:established,from_client; content:"GET"; http_method; content:"/arrychanel/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944999/; classtype:trojan-activity;sid:84808099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945000)"; flow:established,from_client; content:"GET"; http_method; content:"/levelspoints/warzone-dominator/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945000/; classtype:trojan-activity;sid:84808100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3945001)"; flow:established,from_client; content:"GET"; http_method; content:"/shannyis/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3945001/; classtype:trojan-activity;sid:84808101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944995)"; flow:established,from_client; content:"GET"; http_method; content:"/tegodives/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944995/; classtype:trojan-activity;sid:84808095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944994)"; flow:established,from_client; content:"GET"; http_method; content:"/ramdelice/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944994/; classtype:trojan-activity;sid:84808094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944992)"; flow:established,from_client; content:"GET"; http_method; content:"/lannydays/fivem-external-cheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944992/; classtype:trojan-activity;sid:84808092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944993)"; flow:established,from_client; content:"GET"; http_method; content:"/recctan1o/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944993/; classtype:trojan-activity;sid:84808093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944991)"; flow:established,from_client; content:"GET"; http_method; content:"/ameliajones/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944991/; classtype:trojan-activity;sid:84808091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944990)"; flow:established,from_client; content:"GET"; http_method; content:"/chileberryt/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944990/; classtype:trojan-activity;sid:84808090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944989)"; flow:established,from_client; content:"GET"; http_method; content:"/skapples/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944989/; classtype:trojan-activity;sid:84808089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944986)"; flow:established,from_client; content:"GET"; http_method; content:"/rhaddas/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944986/; classtype:trojan-activity;sid:84808086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944987)"; flow:established,from_client; content:"GET"; http_method; content:"/callensiy/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944987/; classtype:trojan-activity;sid:84808087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944988)"; flow:established,from_client; content:"GET"; http_method; content:"/accilely/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944988/; classtype:trojan-activity;sid:84808088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944984)"; flow:established,from_client; content:"GET"; http_method; content:"/uclets/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944984/; classtype:trojan-activity;sid:84808084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944985)"; flow:established,from_client; content:"GET"; http_method; content:"/houndblink/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944985/; classtype:trojan-activity;sid:84808085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944981)"; flow:established,from_client; content:"GET"; http_method; content:"/h1lfsald/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944981/; classtype:trojan-activity;sid:84808081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944982)"; flow:established,from_client; content:"GET"; http_method; content:"/li1aarh/fortniteexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944982/; classtype:trojan-activity;sid:84808082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944983)"; flow:established,from_client; content:"GET"; http_method; content:"/unitedstars/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944983/; classtype:trojan-activity;sid:84808083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944979)"; flow:established,from_client; content:"GET"; http_method; content:"/scriptshub/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944979/; classtype:trojan-activity;sid:84808079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944980)"; flow:established,from_client; content:"GET"; http_method; content:"/beettherains/pubg-desync-menu/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944980/; classtype:trojan-activity;sid:84808080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944973)"; flow:established,from_client; content:"GET"; http_method; content:"/amnesiacalmss/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944973/; classtype:trojan-activity;sid:84808073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944974)"; flow:established,from_client; content:"GET"; http_method; content:"/kaue9919a/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944974/; classtype:trojan-activity;sid:84808074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944975)"; flow:established,from_client; content:"GET"; http_method; content:"/charles998/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944975/; classtype:trojan-activity;sid:84808075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944976)"; flow:established,from_client; content:"GET"; http_method; content:"/myehax/c2panel/head/c2panel.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944976/; classtype:trojan-activity;sid:84808076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944977)"; flow:established,from_client; content:"GET"; http_method; content:"/diskej1/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944977/; classtype:trojan-activity;sid:84808077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944978)"; flow:established,from_client; content:"GET"; http_method; content:"/f1llsvy/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944978/; classtype:trojan-activity;sid:84808078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944972)"; flow:established,from_client; content:"GET"; http_method; content:"/nahh1ly/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944972/; classtype:trojan-activity;sid:84808072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944970)"; flow:established,from_client; content:"GET"; http_method; content:"/septhleft/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944970/; classtype:trojan-activity;sid:84808070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944971)"; flow:established,from_client; content:"GET"; http_method; content:"/achkills/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944971/; classtype:trojan-activity;sid:84808071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944968)"; flow:established,from_client; content:"GET"; http_method; content:"/f1nneyx/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944968/; classtype:trojan-activity;sid:84808068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944969)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-86014/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944969/; classtype:trojan-activity;sid:84808069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944967)"; flow:established,from_client; content:"GET"; http_method; content:"/merthsdx/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944967/; classtype:trojan-activity;sid:84808067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944966)"; flow:established,from_client; content:"GET"; http_method; content:"/paradiseleaks/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944966/; classtype:trojan-activity;sid:84808066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944965)"; flow:established,from_client; content:"GET"; http_method; content:"/kaccelir/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944965/; classtype:trojan-activity;sid:84808065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944964)"; flow:established,from_client; content:"GET"; http_method; content:"/sterrels/xeno-executor/head/xeno.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944964/; classtype:trojan-activity;sid:84808064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944959)"; flow:established,from_client; content:"GET"; http_method; content:"/chverr1/warzoneexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944959/; classtype:trojan-activity;sid:84808059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944960)"; flow:established,from_client; content:"GET"; http_method; content:"/ieddl1/eulencheats-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944960/; classtype:trojan-activity;sid:84808060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944961)"; flow:established,from_client; content:"GET"; http_method; content:"/changessy/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944961/; classtype:trojan-activity;sid:84808061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944962)"; flow:established,from_client; content:"GET"; http_method; content:"/m3shad/warzoneexternalcheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944962/; classtype:trojan-activity;sid:84808062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944963)"; flow:established,from_client; content:"GET"; http_method; content:"/br1nnasvag3/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944963/; classtype:trojan-activity;sid:84808063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944956)"; flow:established,from_client; content:"GET"; http_method; content:"/n0nwhy/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944956/; classtype:trojan-activity;sid:84808056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944957)"; flow:established,from_client; content:"GET"; http_method; content:"/denn1ers/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944957/; classtype:trojan-activity;sid:84808057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944958)"; flow:established,from_client; content:"GET"; http_method; content:"/lovelyfight/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944958/; classtype:trojan-activity;sid:84808058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944953)"; flow:established,from_client; content:"GET"; http_method; content:"/hollycat/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944953/; classtype:trojan-activity;sid:84808053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944954)"; flow:established,from_client; content:"GET"; http_method; content:"/bonfiress/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944954/; classtype:trojan-activity;sid:84808054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944955)"; flow:established,from_client; content:"GET"; http_method; content:"/linstarbig/fivem-mod-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944955/; classtype:trojan-activity;sid:84808055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944950)"; flow:established,from_client; content:"GET"; http_method; content:"/dindukes/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944950/; classtype:trojan-activity;sid:84808050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944951)"; flow:established,from_client; content:"GET"; http_method; content:"/hollyway/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944951/; classtype:trojan-activity;sid:84808051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944952)"; flow:established,from_client; content:"GET"; http_method; content:"/tierbess/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944952/; classtype:trojan-activity;sid:84808052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944948)"; flow:established,from_client; content:"GET"; http_method; content:"/ccvds/c2panel/head/c2panel.exe"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944948/; classtype:trojan-activity;sid:84808048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944949)"; flow:established,from_client; content:"GET"; http_method; content:"/heavenlees/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944949/; classtype:trojan-activity;sid:84808049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944945)"; flow:established,from_client; content:"GET"; http_method; content:"/fckuee/akebi-gc/head/akebi-gc.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944945/; classtype:trojan-activity;sid:84808045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944946)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/l7xh7ur9695u.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944946/; classtype:trojan-activity;sid:84808046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944947)"; flow:established,from_client; content:"GET"; http_method; content:"/djavvy/valorantexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944947/; classtype:trojan-activity;sid:84808047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944944)"; flow:established,from_client; content:"GET"; http_method; content:"/demonhorses/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944944/; classtype:trojan-activity;sid:84808044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944943)"; flow:established,from_client; content:"GET"; http_method; content:"/puzzlerdown/fivem-external-cheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944943/; classtype:trojan-activity;sid:84808043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944942)"; flow:established,from_client; content:"GET"; http_method; content:"/juellys/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944942/; classtype:trojan-activity;sid:84808042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944940)"; flow:established,from_client; content:"GET"; http_method; content:"/silvergolds/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944940/; classtype:trojan-activity;sid:84808040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944941)"; flow:established,from_client; content:"GET"; http_method; content:"/milleges/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944941/; classtype:trojan-activity;sid:84808041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944931)"; flow:established,from_client; content:"GET"; http_method; content:"/jamemood/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944931/; classtype:trojan-activity;sid:84808031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944932)"; flow:established,from_client; content:"GET"; http_method; content:"/madescape/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944932/; classtype:trojan-activity;sid:84808032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944933)"; flow:established,from_client; content:"GET"; http_method; content:"/quantvv/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944933/; classtype:trojan-activity;sid:84808033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944934)"; flow:established,from_client; content:"GET"; http_method; content:"/rayfierh/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944934/; classtype:trojan-activity;sid:84808034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944935)"; flow:established,from_client; content:"GET"; http_method; content:"/playitrocks/fortniteexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944935/; classtype:trojan-activity;sid:84808035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944936)"; flow:established,from_client; content:"GET"; http_method; content:"/mixteens/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944936/; classtype:trojan-activity;sid:84808036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944937)"; flow:established,from_client; content:"GET"; http_method; content:"/v1llenth/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944937/; classtype:trojan-activity;sid:84808037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944938)"; flow:established,from_client; content:"GET"; http_method; content:"/lonnelyduo/warzone-dominator/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944938/; classtype:trojan-activity;sid:84808038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944939)"; flow:established,from_client; content:"GET"; http_method; content:"/cleanwaves/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944939/; classtype:trojan-activity;sid:84808039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944930)"; flow:established,from_client; content:"GET"; http_method; content:"/rammlesta1/phoenixc2/head/phoenixc2.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944930/; classtype:trojan-activity;sid:84808030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944927)"; flow:established,from_client; content:"GET"; http_method; content:"/blasthood/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944927/; classtype:trojan-activity;sid:84808027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944928)"; flow:established,from_client; content:"GET"; http_method; content:"/ownsticky/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944928/; classtype:trojan-activity;sid:84808028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944929)"; flow:established,from_client; content:"GET"; http_method; content:"/lifesigns/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944929/; classtype:trojan-activity;sid:84808029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944926)"; flow:established,from_client; content:"GET"; http_method; content:"/mall1ey/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944926/; classtype:trojan-activity;sid:84808026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944925)"; flow:established,from_client; content:"GET"; http_method; content:"/revosplit/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944925/; classtype:trojan-activity;sid:84808025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944921)"; flow:established,from_client; content:"GET"; http_method; content:"/aohal3xxn/phoenixc2/head/skriptgg.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944921/; classtype:trojan-activity;sid:84808021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944922)"; flow:established,from_client; content:"GET"; http_method; content:"/n3llapixel/fivem-external-cheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944922/; classtype:trojan-activity;sid:84808022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944923)"; flow:established,from_client; content:"GET"; http_method; content:"/genaglouy/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944923/; classtype:trojan-activity;sid:84808023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944924)"; flow:established,from_client; content:"GET"; http_method; content:"/isslewwdd/akebigc/head/akebi-gc.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944924/; classtype:trojan-activity;sid:84808024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944916)"; flow:established,from_client; content:"GET"; http_method; content:"/goldyvip/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944916/; classtype:trojan-activity;sid:84808016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944917)"; flow:established,from_client; content:"GET"; http_method; content:"/starmicht/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944917/; classtype:trojan-activity;sid:84808017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944918)"; flow:established,from_client; content:"GET"; http_method; content:"/roycemind/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944918/; classtype:trojan-activity;sid:84808018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944919)"; flow:established,from_client; content:"GET"; http_method; content:"/culturefive/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944919/; classtype:trojan-activity;sid:84808019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944920)"; flow:established,from_client; content:"GET"; http_method; content:"/niessenlars1/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944920/; classtype:trojan-activity;sid:84808020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944915)"; flow:established,from_client; content:"GET"; http_method; content:"/cartersilence/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944915/; classtype:trojan-activity;sid:84808015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944913)"; flow:established,from_client; content:"GET"; http_method; content:"/m1sstfire/redengine-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944913/; classtype:trojan-activity;sid:84808013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944914)"; flow:established,from_client; content:"GET"; http_method; content:"/limmacouch/fivem-spoofer/head/cfxbypass.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944914/; classtype:trojan-activity;sid:84808014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944910)"; flow:established,from_client; content:"GET"; http_method; content:"/alwayshigh/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944910/; classtype:trojan-activity;sid:84808010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944911)"; flow:established,from_client; content:"GET"; http_method; content:"/stakemiss/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944911/; classtype:trojan-activity;sid:84808011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944912)"; flow:established,from_client; content:"GET"; http_method; content:"/lennysright/warzone-dominator/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944912/; classtype:trojan-activity;sid:84808012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944909)"; flow:established,from_client; content:"GET"; http_method; content:"/alicejeel/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944909/; classtype:trojan-activity;sid:84808009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944908)"; flow:established,from_client; content:"GET"; http_method; content:"/skyll1/hwid-spoofer-hwid-changer-bioguard/head/resethwid.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944908/; classtype:trojan-activity;sid:84808008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944905)"; flow:established,from_client; content:"GET"; http_method; content:"/linsqueeze/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944905/; classtype:trojan-activity;sid:84808005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944906)"; flow:established,from_client; content:"GET"; http_method; content:"/edd1nes/verox-gta-enhanced/head/verox.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944906/; classtype:trojan-activity;sid:84808006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944907)"; flow:established,from_client; content:"GET"; http_method; content:"/pinkslips/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944907/; classtype:trojan-activity;sid:84808007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944904)"; flow:established,from_client; content:"GET"; http_method; content:"/passlemr/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944904/; classtype:trojan-activity;sid:84808004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944899)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-47785/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944899/; classtype:trojan-activity;sid:84807999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944900)"; flow:established,from_client; content:"GET"; http_method; content:"/xillendy/vision-rage-fortnite-privatecheat/head/loader.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944900/; classtype:trojan-activity;sid:84808000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944901)"; flow:established,from_client; content:"GET"; http_method; content:"/mo1vs/fivem-external-cheat/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944901/; classtype:trojan-activity;sid:84808001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944902)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/e4j3q5825i7f.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944902/; classtype:trojan-activity;sid:84808002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944903)"; flow:established,from_client; content:"GET"; http_method; content:"/a2z51/hwid-spoofer/-/raw/main/universalspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944903/; classtype:trojan-activity;sid:84808003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944898)"; flow:established,from_client; content:"GET"; http_method; content:"/drglitchs/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944898/; classtype:trojan-activity;sid:84807998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944895)"; flow:established,from_client; content:"GET"; http_method; content:"/ostflord/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944895/; classtype:trojan-activity;sid:84807995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944896)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/s8d70ipcznaa.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944896/; classtype:trojan-activity;sid:84807996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944897)"; flow:established,from_client; content:"GET"; http_method; content:"/raydelt/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944897/; classtype:trojan-activity;sid:84807997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944891)"; flow:established,from_client; content:"GET"; http_method; content:"/deebillz/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944891/; classtype:trojan-activity;sid:84807991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944892)"; flow:established,from_client; content:"GET"; http_method; content:"/l3ossh1/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944892/; classtype:trojan-activity;sid:84807992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944893)"; flow:established,from_client; content:"GET"; http_method; content:"/candyliss/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944893/; classtype:trojan-activity;sid:84807993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944894)"; flow:established,from_client; content:"GET"; http_method; content:"/nelsonah7/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944894/; classtype:trojan-activity;sid:84807994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944888)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-92975/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944888/; classtype:trojan-activity;sid:84807988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944889)"; flow:established,from_client; content:"GET"; http_method; content:"/barrhp1na/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944889/; classtype:trojan-activity;sid:84807989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944890)"; flow:established,from_client; content:"GET"; http_method; content:"/therelax/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944890/; classtype:trojan-activity;sid:84807990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944887)"; flow:established,from_client; content:"GET"; http_method; content:"/dallymells/redengine-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944887/; classtype:trojan-activity;sid:84807987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944885)"; flow:established,from_client; content:"GET"; http_method; content:"/dailymurr/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944885/; classtype:trojan-activity;sid:84807985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944886)"; flow:established,from_client; content:"GET"; http_method; content:"/raffelsas/redengine-fivem/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944886/; classtype:trojan-activity;sid:84807986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944884)"; flow:established,from_client; content:"GET"; http_method; content:"/clarittes/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944884/; classtype:trojan-activity;sid:84807984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944881)"; flow:established,from_client; content:"GET"; http_method; content:"/dailyscripts132/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944881/; classtype:trojan-activity;sid:84807981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944882)"; flow:established,from_client; content:"GET"; http_method; content:"/facc1erhan/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944882/; classtype:trojan-activity;sid:84807982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944883)"; flow:established,from_client; content:"GET"; http_method; content:"/f0lkssvg/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944883/; classtype:trojan-activity;sid:84807983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944879)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/stage2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944879/; classtype:trojan-activity;sid:84807979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944880)"; flow:established,from_client; content:"GET"; http_method; content:"/airshade/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944880/; classtype:trojan-activity;sid:84807980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944878)"; flow:established,from_client; content:"GET"; http_method; content:"/dashspeed/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944878/; classtype:trojan-activity;sid:84807978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944877)"; flow:established,from_client; content:"GET"; http_method; content:"/blacklines/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944877/; classtype:trojan-activity;sid:84807977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944873)"; flow:established,from_client; content:"GET"; http_method; content:"/elipsydoll/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944873/; classtype:trojan-activity;sid:84807973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944874)"; flow:established,from_client; content:"GET"; http_method; content:"/lovelylifes/rezo-gen/head/rezogen.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944874/; classtype:trojan-activity;sid:84807974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944875)"; flow:established,from_client; content:"GET"; http_method; content:"/jettls/warzone-dominator/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944875/; classtype:trojan-activity;sid:84807975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944876)"; flow:established,from_client; content:"GET"; http_method; content:"/deviatfax/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944876/; classtype:trojan-activity;sid:84807976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944872)"; flow:established,from_client; content:"GET"; http_method; content:"/d4rkzyz12/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944872/; classtype:trojan-activity;sid:84807972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944868)"; flow:established,from_client; content:"GET"; http_method; content:"/novacarths/warzone-dominator/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944868/; classtype:trojan-activity;sid:84807968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944869)"; flow:established,from_client; content:"GET"; http_method; content:"/intergta5/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944869/; classtype:trojan-activity;sid:84807969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944870)"; flow:established,from_client; content:"GET"; http_method; content:"/radiantleaks/quantv-sp-fivem-ragemp-altv/-/raw/main/quantv_latest_2026.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944870/; classtype:trojan-activity;sid:84807970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944871)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-20492/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944871/; classtype:trojan-activity;sid:84807971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944867)"; flow:established,from_client; content:"GET"; http_method; content:"/l1nnsy/warzone-dominator/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944867/; classtype:trojan-activity;sid:84807967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944862)"; flow:established,from_client; content:"GET"; http_method; content:"/metroboomin/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944862/; classtype:trojan-activity;sid:84807962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944863)"; flow:established,from_client; content:"GET"; http_method; content:"/accleron/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944863/; classtype:trojan-activity;sid:84807963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944864)"; flow:established,from_client; content:"GET"; http_method; content:"/sandloj/warzoneexternalcheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944864/; classtype:trojan-activity;sid:84807964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944865)"; flow:established,from_client; content:"GET"; http_method; content:"/nellybenz/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944865/; classtype:trojan-activity;sid:84807965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944866)"; flow:established,from_client; content:"GET"; http_method; content:"/redfieldsy/valorantexternalcheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944866/; classtype:trojan-activity;sid:84807966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944859)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-67465/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944859/; classtype:trojan-activity;sid:84807959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944860)"; flow:established,from_client; content:"GET"; http_method; content:"/tifannyblessed/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944860/; classtype:trojan-activity;sid:84807960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944861)"; flow:established,from_client; content:"GET"; http_method; content:"/millyshake/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944861/; classtype:trojan-activity;sid:84807961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944858)"; flow:established,from_client; content:"GET"; http_method; content:"/humblecap/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944858/; classtype:trojan-activity;sid:84807958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944857)"; flow:established,from_client; content:"GET"; http_method; content:"/add1nales/c2panel/head/c2panel.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944857/; classtype:trojan-activity;sid:84807957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944854)"; flow:established,from_client; content:"GET"; http_method; content:"/n1tchess/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944854/; classtype:trojan-activity;sid:84807954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944855)"; flow:established,from_client; content:"GET"; http_method; content:"/rollouts/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944855/; classtype:trojan-activity;sid:84807955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944856)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostways/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944856/; classtype:trojan-activity;sid:84807956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944852)"; flow:established,from_client; content:"GET"; http_method; content:"/kayflock/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944852/; classtype:trojan-activity;sid:84807952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944853)"; flow:established,from_client; content:"GET"; http_method; content:"/derregy/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944853/; classtype:trojan-activity;sid:84807953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944851)"; flow:established,from_client; content:"GET"; http_method; content:"/earlieyd/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944851/; classtype:trojan-activity;sid:84807951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944850)"; flow:established,from_client; content:"GET"; http_method; content:"/hlesnw2/phoenixc2/head/phoenixc2.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944850/; classtype:trojan-activity;sid:84807950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944847)"; flow:established,from_client; content:"GET"; http_method; content:"/l1nnemurr/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944847/; classtype:trojan-activity;sid:84807947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944848)"; flow:established,from_client; content:"GET"; http_method; content:"/oerrlis/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944848/; classtype:trojan-activity;sid:84807948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944849)"; flow:established,from_client; content:"GET"; http_method; content:"/l1sstwe/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944849/; classtype:trojan-activity;sid:84807949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944845)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzoball/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944845/; classtype:trojan-activity;sid:84807945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944846)"; flow:established,from_client; content:"GET"; http_method; content:"/khanddjo/fluxusexecutor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944846/; classtype:trojan-activity;sid:84807946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944843)"; flow:established,from_client; content:"GET"; http_method; content:"/raccley/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944843/; classtype:trojan-activity;sid:84807943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944844)"; flow:established,from_client; content:"GET"; http_method; content:"/durkframe/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944844/; classtype:trojan-activity;sid:84807944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944840)"; flow:established,from_client; content:"GET"; http_method; content:"/lindycat/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944840/; classtype:trojan-activity;sid:84807940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944841)"; flow:established,from_client; content:"GET"; http_method; content:"/reelssticks/redengine-fivem/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944841/; classtype:trojan-activity;sid:84807941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944842)"; flow:established,from_client; content:"GET"; http_method; content:"/rhymesroy/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944842/; classtype:trojan-activity;sid:84807942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944839)"; flow:established,from_client; content:"GET"; http_method; content:"/lordfall/warzoneexternalcheat-67664/-/raw/main/loader.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944839/; classtype:trojan-activity;sid:84807939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944838)"; flow:established,from_client; content:"GET"; http_method; content:"/lancycath/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944838/; classtype:trojan-activity;sid:84807938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944835)"; flow:established,from_client; content:"GET"; http_method; content:"/beatog/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944835/; classtype:trojan-activity;sid:84807935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944836)"; flow:established,from_client; content:"GET"; http_method; content:"/slyboogy/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944836/; classtype:trojan-activity;sid:84807936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944837)"; flow:established,from_client; content:"GET"; http_method; content:"/terrysblack/warzone-dominator/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944837/; classtype:trojan-activity;sid:84807937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944834)"; flow:established,from_client; content:"GET"; http_method; content:"/astroworlds/valorantexternalcheat/-/raw/main/loader.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944834/; classtype:trojan-activity;sid:84807934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944830)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944830/; classtype:trojan-activity;sid:84807930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944831)"; flow:established,from_client; content:"GET"; http_method; content:"/hollycap/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944831/; classtype:trojan-activity;sid:84807931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944832)"; flow:established,from_client; content:"GET"; http_method; content:"/lesperrd/fivem-external-cheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944832/; classtype:trojan-activity;sid:84807932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944833)"; flow:established,from_client; content:"GET"; http_method; content:"/ci1ents9/swift-executor/head/swift.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944833/; classtype:trojan-activity;sid:84807933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944829)"; flow:established,from_client; content:"GET"; http_method; content:"/niyssol/pubg-desync-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944829/; classtype:trojan-activity;sid:84807929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944826)"; flow:established,from_client; content:"GET"; http_method; content:"/louierule/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944826/; classtype:trojan-activity;sid:84807926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944827)"; flow:established,from_client; content:"GET"; http_method; content:"/leftyou/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944827/; classtype:trojan-activity;sid:84807927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944828)"; flow:established,from_client; content:"GET"; http_method; content:"/rootnexty/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944828/; classtype:trojan-activity;sid:84807928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944824)"; flow:established,from_client; content:"GET"; http_method; content:"/middlesavage/warzone-dominator/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944824/; classtype:trojan-activity;sid:84807924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944825)"; flow:established,from_client; content:"GET"; http_method; content:"/swennhr/skriptgg/head/skriptgg.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944825/; classtype:trojan-activity;sid:84807925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944822)"; flow:established,from_client; content:"GET"; http_method; content:"/fettywapss/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944822/; classtype:trojan-activity;sid:84807922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944823)"; flow:established,from_client; content:"GET"; http_method; content:"/artiessx/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944823/; classtype:trojan-activity;sid:84807923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944821)"; flow:established,from_client; content:"GET"; http_method; content:"/lexxtsy/fortniteexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944821/; classtype:trojan-activity;sid:84807921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944819)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamscapes/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944819/; classtype:trojan-activity;sid:84807919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944820)"; flow:established,from_client; content:"GET"; http_method; content:"/runcover/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944820/; classtype:trojan-activity;sid:84807920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944817)"; flow:established,from_client; content:"GET"; http_method; content:"/litthewish/eulencheats-fivem/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944817/; classtype:trojan-activity;sid:84807917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944818)"; flow:established,from_client; content:"GET"; http_method; content:"/scratty/quantv-december/-/raw/main/quantv_latest_2025.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944818/; classtype:trojan-activity;sid:84807918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944815)"; flow:established,from_client; content:"GET"; http_method; content:"/ferrel1a/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944815/; classtype:trojan-activity;sid:84807915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944816)"; flow:established,from_client; content:"GET"; http_method; content:"/dellrux/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944816/; classtype:trojan-activity;sid:84807916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944812)"; flow:established,from_client; content:"GET"; http_method; content:"/elmarties/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944812/; classtype:trojan-activity;sid:84807912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944813)"; flow:established,from_client; content:"GET"; http_method; content:"/n1eys/solara/head/solara%20v3.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944813/; classtype:trojan-activity;sid:84807913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944814)"; flow:established,from_client; content:"GET"; http_method; content:"/luerst/warzone-dominator/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944814/; classtype:trojan-activity;sid:84807914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944811)"; flow:established,from_client; content:"GET"; http_method; content:"/oxfworld/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944811/; classtype:trojan-activity;sid:84807911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944808)"; flow:established,from_client; content:"GET"; http_method; content:"/andrekhan/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944808/; classtype:trojan-activity;sid:84807908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944809)"; flow:established,from_client; content:"GET"; http_method; content:"/stellehif/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944809/; classtype:trojan-activity;sid:84807909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944810)"; flow:established,from_client; content:"GET"; http_method; content:"/meggy99/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944810/; classtype:trojan-activity;sid:84807910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944803)"; flow:established,from_client; content:"GET"; http_method; content:"/nightclay/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944803/; classtype:trojan-activity;sid:84807903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944804)"; flow:established,from_client; content:"GET"; http_method; content:"/mrcrowld/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944804/; classtype:trojan-activity;sid:84807904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944805)"; flow:established,from_client; content:"GET"; http_method; content:"/madenhose/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944805/; classtype:trojan-activity;sid:84807905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944806)"; flow:established,from_client; content:"GET"; http_method; content:"/honnleys/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944806/; classtype:trojan-activity;sid:84807906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944807)"; flow:established,from_client; content:"GET"; http_method; content:"/hennelys/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944807/; classtype:trojan-activity;sid:84807907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944800)"; flow:established,from_client; content:"GET"; http_method; content:"/theressjj/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944800/; classtype:trojan-activity;sid:84807900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944801)"; flow:established,from_client; content:"GET"; http_method; content:"/linydev/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944801/; classtype:trojan-activity;sid:84807901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944802)"; flow:established,from_client; content:"GET"; http_method; content:"/overgrace/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944802/; classtype:trojan-activity;sid:84807902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944799)"; flow:established,from_client; content:"GET"; http_method; content:"/cevv1s/stalcraft-wh-chams-speedhack-fb/head/prg.rar"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944799/; classtype:trojan-activity;sid:84807899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944796)"; flow:established,from_client; content:"GET"; http_method; content:"/altarealt/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944796/; classtype:trojan-activity;sid:84807896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944797)"; flow:established,from_client; content:"GET"; http_method; content:"/billygod/silentum-spoofer/-/raw/main/silentumspoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944797/; classtype:trojan-activity;sid:84807897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944798)"; flow:established,from_client; content:"GET"; http_method; content:"/nellypools/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944798/; classtype:trojan-activity;sid:84807898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944795)"; flow:established,from_client; content:"GET"; http_method; content:"/slowwengeld/fivem-external-cheat/head/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944795/; classtype:trojan-activity;sid:84807895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944791)"; flow:established,from_client; content:"GET"; http_method; content:"/noterrls/eulencheats-fivem/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944791/; classtype:trojan-activity;sid:84807891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944792)"; flow:established,from_client; content:"GET"; http_method; content:"/tezstewart/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944792/; classtype:trojan-activity;sid:84807892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944793)"; flow:established,from_client; content:"GET"; http_method; content:"/monachlet/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944793/; classtype:trojan-activity;sid:84807893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944794)"; flow:established,from_client; content:"GET"; http_method; content:"/thayreactor/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944794/; classtype:trojan-activity;sid:84807894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944790)"; flow:established,from_client; content:"GET"; http_method; content:"/hancyones/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944790/; classtype:trojan-activity;sid:84807890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944785)"; flow:established,from_client; content:"GET"; http_method; content:"/x1leth/fluxusexecutor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944785/; classtype:trojan-activity;sid:84807885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944786)"; flow:established,from_client; content:"GET"; http_method; content:"/nellishs/fivem-cheat-with-lua-executor-and-dumper/head/loader.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944786/; classtype:trojan-activity;sid:84807886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944787)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyesh/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944787/; classtype:trojan-activity;sid:84807887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944788)"; flow:established,from_client; content:"GET"; http_method; content:"/splashgaps/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944788/; classtype:trojan-activity;sid:84807888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944789)"; flow:established,from_client; content:"GET"; http_method; content:"/takemass/fortniteexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944789/; classtype:trojan-activity;sid:84807889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944783)"; flow:established,from_client; content:"GET"; http_method; content:"/darrenbless/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944783/; classtype:trojan-activity;sid:84807883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944784)"; flow:established,from_client; content:"GET"; http_method; content:"/thayabrix/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944784/; classtype:trojan-activity;sid:84807884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944781)"; flow:established,from_client; content:"GET"; http_method; content:"/rinecchsy/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944781/; classtype:trojan-activity;sid:84807881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944782)"; flow:established,from_client; content:"GET"; http_method; content:"/crystalchase/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944782/; classtype:trojan-activity;sid:84807882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944779)"; flow:established,from_client; content:"GET"; http_method; content:"/smokedouts/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944779/; classtype:trojan-activity;sid:84807879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944780)"; flow:established,from_client; content:"GET"; http_method; content:"/rockystars/fivem-external-cheat-27309/-/raw/main/loader.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944780/; classtype:trojan-activity;sid:84807880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944776)"; flow:established,from_client; content:"GET"; http_method; content:"/leavealones/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944776/; classtype:trojan-activity;sid:84807876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944777)"; flow:established,from_client; content:"GET"; http_method; content:"/benztruck/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944777/; classtype:trojan-activity;sid:84807877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944778)"; flow:established,from_client; content:"GET"; http_method; content:"/blackdrose/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944778/; classtype:trojan-activity;sid:84807878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944775)"; flow:established,from_client; content:"GET"; http_method; content:"/tell1sy/valorantexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944775/; classtype:trojan-activity;sid:84807875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944773)"; flow:established,from_client; content:"GET"; http_method; content:"/alfredozorba018/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944773/; classtype:trojan-activity;sid:84807873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944774)"; flow:established,from_client; content:"GET"; http_method; content:"/luminatystage/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944774/; classtype:trojan-activity;sid:84807874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944770)"; flow:established,from_client; content:"GET"; http_method; content:"/l3sshand/warzoneexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944770/; classtype:trojan-activity;sid:84807870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944771)"; flow:established,from_client; content:"GET"; http_method; content:"/cry1jas/phoenixc2/head/phoenixc2.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944771/; classtype:trojan-activity;sid:84807871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944772)"; flow:established,from_client; content:"GET"; http_method; content:"/lorr3rk/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944772/; classtype:trojan-activity;sid:84807872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944769)"; flow:established,from_client; content:"GET"; http_method; content:"/n3aslem/fivem-mod-menu/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944769/; classtype:trojan-activity;sid:84807869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944765)"; flow:established,from_client; content:"GET"; http_method; content:"/mikellyss/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944765/; classtype:trojan-activity;sid:84807865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944766)"; flow:established,from_client; content:"GET"; http_method; content:"/ecce1yh/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944766/; classtype:trojan-activity;sid:84807866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944767)"; flow:established,from_client; content:"GET"; http_method; content:"/rockyhunts/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944767/; classtype:trojan-activity;sid:84807867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944768)"; flow:established,from_client; content:"GET"; http_method; content:"/ciao67926/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944768/; classtype:trojan-activity;sid:84807868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944764)"; flow:established,from_client; content:"GET"; http_method; content:"/castillogang/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944764/; classtype:trojan-activity;sid:84807864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944762)"; flow:established,from_client; content:"GET"; http_method; content:"/betakk1/roblox-macro-v3.0.0/head/spencer%20macro%20client.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944762/; classtype:trojan-activity;sid:84807862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944763)"; flow:established,from_client; content:"GET"; http_method; content:"/shannypolls/pubg-desync-menu/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944763/; classtype:trojan-activity;sid:84807863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944759)"; flow:established,from_client; content:"GET"; http_method; content:"/cherrisland/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944759/; classtype:trojan-activity;sid:84807859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944760)"; flow:established,from_client; content:"GET"; http_method; content:"/thevens/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944760/; classtype:trojan-activity;sid:84807860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944761)"; flow:established,from_client; content:"GET"; http_method; content:"/braa1rl/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944761/; classtype:trojan-activity;sid:84807861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944758)"; flow:established,from_client; content:"GET"; http_method; content:"/moreways/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944758/; classtype:trojan-activity;sid:84807858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944757)"; flow:established,from_client; content:"GET"; http_method; content:"/laugxs/skriptgg/head/skriptgg.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944757/; classtype:trojan-activity;sid:84807857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944754)"; flow:established,from_client; content:"GET"; http_method; content:"/nightfurys/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944754/; classtype:trojan-activity;sid:84807854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944755)"; flow:established,from_client; content:"GET"; http_method; content:"/evolintent/fluxus-executor/-/raw/main/fluxusexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944755/; classtype:trojan-activity;sid:84807855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944756)"; flow:established,from_client; content:"GET"; http_method; content:"/burnlights/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944756/; classtype:trojan-activity;sid:84807856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944748)"; flow:established,from_client; content:"GET"; http_method; content:"/jaygreens/skriptgg/-/raw/main/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944748/; classtype:trojan-activity;sid:84807848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944749)"; flow:established,from_client; content:"GET"; http_method; content:"/alessocream/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944749/; classtype:trojan-activity;sid:84807849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944750)"; flow:established,from_client; content:"GET"; http_method; content:"/istaffh/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944750/; classtype:trojan-activity;sid:84807850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944751)"; flow:established,from_client; content:"GET"; http_method; content:"/shevv1ls/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944751/; classtype:trojan-activity;sid:84807851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944752)"; flow:established,from_client; content:"GET"; http_method; content:"/n1essl/redengine-fivem/head/loader.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944752/; classtype:trojan-activity;sid:84807852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944753)"; flow:established,from_client; content:"GET"; http_method; content:"/sse1rls/valorantexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944753/; classtype:trojan-activity;sid:84807853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944745)"; flow:established,from_client; content:"GET"; http_method; content:"/luxxinay/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944745/; classtype:trojan-activity;sid:84807845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944746)"; flow:established,from_client; content:"GET"; http_method; content:"/blestoff/fivem-mod-menu/head/loader.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944746/; classtype:trojan-activity;sid:84807846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944747)"; flow:established,from_client; content:"GET"; http_method; content:"/grandstary/eulencheats-fivem/-/raw/main/loader.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944747/; classtype:trojan-activity;sid:84807847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944741)"; flow:established,from_client; content:"GET"; http_method; content:"/evanbluess/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944741/; classtype:trojan-activity;sid:84807841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944742)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisruth/genshin-impact-private-cheat-with-spoofer/-/raw/main/akebigc.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944742/; classtype:trojan-activity;sid:84807842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944743)"; flow:established,from_client; content:"GET"; http_method; content:"/renwayne/fluxus-roblox-executor/head/fluxus%20v7.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944743/; classtype:trojan-activity;sid:84807843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944744)"; flow:established,from_client; content:"GET"; http_method; content:"/rlyssl0v3/fivem-mod-menu/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944744/; classtype:trojan-activity;sid:84807844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944739)"; flow:established,from_client; content:"GET"; http_method; content:"/lestraccs/valorantexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944739/; classtype:trojan-activity;sid:84807839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944740)"; flow:established,from_client; content:"GET"; http_method; content:"/spindoctors/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944740/; classtype:trojan-activity;sid:84807840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944738)"; flow:established,from_client; content:"GET"; http_method; content:"/hinessylan/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944738/; classtype:trojan-activity;sid:84807838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944737)"; flow:established,from_client; content:"GET"; http_method; content:"/lutrhsww/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944737/; classtype:trojan-activity;sid:84807837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944735)"; flow:established,from_client; content:"GET"; http_method; content:"/graymid/tinnylieh/-/raw/main/u7q7r23u7669.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944735/; classtype:trojan-activity;sid:84807835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944736)"; flow:established,from_client; content:"GET"; http_method; content:"/calciers/valorantexternalcheat/head/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944736/; classtype:trojan-activity;sid:84807836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944734)"; flow:established,from_client; content:"GET"; http_method; content:"/tenn1kls/warzone-dominator/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944734/; classtype:trojan-activity;sid:84807834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944733)"; flow:established,from_client; content:"GET"; http_method; content:"/amem1lad/phoenixc2/head/phoenixc2.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944733/; classtype:trojan-activity;sid:84807833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944729)"; flow:established,from_client; content:"GET"; http_method; content:"/onel1ms/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944729/; classtype:trojan-activity;sid:84807829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944730)"; flow:established,from_client; content:"GET"; http_method; content:"/nutzerrm/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944730/; classtype:trojan-activity;sid:84807830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944731)"; flow:established,from_client; content:"GET"; http_method; content:"/grapmorphie/fivem-tz-project/-/raw/main/tz_project.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944731/; classtype:trojan-activity;sid:84807831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944732)"; flow:established,from_client; content:"GET"; http_method; content:"/sall1yt/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944732/; classtype:trojan-activity;sid:84807832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944724)"; flow:established,from_client; content:"GET"; http_method; content:"/stayflye/fortnite-ragdoll-v2-privcheat-including-softaim-esp-wallhack-triggerbot-and-more/-/raw/main/loader.exe"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944724/; classtype:trojan-activity;sid:84807824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944725)"; flow:established,from_client; content:"GET"; http_method; content:"/hennyks/swift-executor/head/swift.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944725/; classtype:trojan-activity;sid:84807825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944726)"; flow:established,from_client; content:"GET"; http_method; content:"/limpachs/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944726/; classtype:trojan-activity;sid:84807826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944727)"; flow:established,from_client; content:"GET"; http_method; content:"/l1tteys/quantv-sp-fivem-ragemp-altv/head/_uninstall/quantv_uninstall.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944727/; classtype:trojan-activity;sid:84807827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944728)"; flow:established,from_client; content:"GET"; http_method; content:"/kylerich/skriptgg/-/raw/main/skriptgg.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944728/; classtype:trojan-activity;sid:84807828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944722)"; flow:established,from_client; content:"GET"; http_method; content:"/piedeo/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944722/; classtype:trojan-activity;sid:84807822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944723)"; flow:established,from_client; content:"GET"; http_method; content:"/bitstackdev/valorantexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944723/; classtype:trojan-activity;sid:84807823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944716)"; flow:established,from_client; content:"GET"; http_method; content:"/mopies/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944716/; classtype:trojan-activity;sid:84807816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944717)"; flow:established,from_client; content:"GET"; http_method; content:"/vangerbit/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944717/; classtype:trojan-activity;sid:84807817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944718)"; flow:established,from_client; content:"GET"; http_method; content:"/fluxlyds/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944718/; classtype:trojan-activity;sid:84807818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944719)"; flow:established,from_client; content:"GET"; http_method; content:"/khannrover/fivem-external-cheat/-/raw/main/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944719/; classtype:trojan-activity;sid:84807819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944720)"; flow:established,from_client; content:"GET"; http_method; content:"/crashfine/escape-from-tarkov-cheat-undetected-with-aimbot-esp-wallhack-radar-hack-and-more/-/raw/main/eft_hack.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944720/; classtype:trojan-activity;sid:84807820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944721)"; flow:established,from_client; content:"GET"; http_method; content:"/frankblazz/redengine-fivem/-/raw/main/loader.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944721/; classtype:trojan-activity;sid:84807821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944715)"; flow:established,from_client; content:"GET"; http_method; content:"/all1and/c2panel/head/c2panel.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944715/; classtype:trojan-activity;sid:84807815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944714)"; flow:established,from_client; content:"GET"; http_method; content:"/stevehook/fortnitespoofer/-/raw/main/fortnitespoofer.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944714/; classtype:trojan-activity;sid:84807814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944713)"; flow:established,from_client; content:"GET"; http_method; content:"/hexxycally/code/-/raw/main/stage_2.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944713/; classtype:trojan-activity;sid:84807813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944711)"; flow:established,from_client; content:"GET"; http_method; content:"/lucklords/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944711/; classtype:trojan-activity;sid:84807811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944712)"; flow:established,from_client; content:"GET"; http_method; content:"/honsyxx/fortniteexternalcheat/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944712/; classtype:trojan-activity;sid:84807812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944710)"; flow:established,from_client; content:"GET"; http_method; content:"/janneclimb/lunaexecutor/-/raw/main/lunaexecutor.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944710/; classtype:trojan-activity;sid:84807810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944709)"; flow:established,from_client; content:"GET"; http_method; content:"/fierrids/skriptgg/head/skriptgg.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944709/; classtype:trojan-activity;sid:84807809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944708)"; flow:established,from_client; content:"GET"; http_method; content:"/gracerivals/warzone-dominator/head/loader.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944708/; classtype:trojan-activity;sid:84807808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944706)"; flow:established,from_client; content:"GET"; http_method; content:"/randydiva/monotone-hwid-spoofer/-/raw/main/monotone-hwid-spoofer-master.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944706/; classtype:trojan-activity;sid:84807806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944707)"; flow:established,from_client; content:"GET"; http_method; content:"/nikkyhalk/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944707/; classtype:trojan-activity;sid:84807807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944704)"; flow:established,from_client; content:"GET"; http_method; content:"/sophyeess/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944704/; classtype:trojan-activity;sid:84807804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944705)"; flow:established,from_client; content:"GET"; http_method; content:"/forrel1s/pubg-desync-menu/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944705/; classtype:trojan-activity;sid:84807805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944703)"; flow:established,from_client; content:"GET"; http_method; content:"/harribes/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944703/; classtype:trojan-activity;sid:84807803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944702)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisdior/temp-spoofer-lifetime/-/raw/main/temp-spoofer.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944702/; classtype:trojan-activity;sid:84807802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944701)"; flow:established,from_client; content:"GET"; http_method; content:"/cxdleer/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944701/; classtype:trojan-activity;sid:84807801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944700)"; flow:established,from_client; content:"GET"; http_method; content:"/pitmarky/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944700/; classtype:trojan-activity;sid:84807800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944699)"; flow:established,from_client; content:"GET"; http_method; content:"/playfuld/xeno-executor/-/raw/main/xenoexecutor.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944699/; classtype:trojan-activity;sid:84807799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944698)"; flow:established,from_client; content:"GET"; http_method; content:"/bennycastle/solaraexecutor/-/raw/main/solaraexecutor.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944698/; classtype:trojan-activity;sid:84807798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944696)"; flow:established,from_client; content:"GET"; http_method; content:"/ciao67926/fivem-mod-menu/-/raw/main/loader.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944696/; classtype:trojan-activity;sid:84807796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944697)"; flow:established,from_client; content:"GET"; http_method; content:"/sheffhallow/fivem-spoofer/-/raw/main/fivemspoofer.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944697/; classtype:trojan-activity;sid:84807797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944695)"; flow:established,from_client; content:"GET"; http_method; content:"/changehort/synapsex/-/raw/main/synapsex.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"gitlab.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944695/; classtype:trojan-activity;sid:84807795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944681)"; flow:established,from_client; content:"GET"; http_method; content:"/downesx/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944681/; classtype:trojan-activity;sid:84807781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944682)"; flow:established,from_client; content:"GET"; http_method; content:"/jaellds/fivem-external-cheat/head/loader.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944682/; classtype:trojan-activity;sid:84807782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944683)"; flow:established,from_client; content:"GET"; http_method; content:"/skannyhampt/fortniteexternalcheat/head/loader.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944683/; classtype:trojan-activity;sid:84807783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944684)"; flow:established,from_client; content:"GET"; http_method; content:"/addels7/warzone-dominator/head/loader.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944684/; classtype:trojan-activity;sid:84807784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944685)"; flow:established,from_client; content:"GET"; http_method; content:"/essywh/fivem-external-cheat/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944685/; classtype:trojan-activity;sid:84807785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944686)"; flow:established,from_client; content:"GET"; http_method; content:"/nicthlans/warzone-dominator/head/loader.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944686/; classtype:trojan-activity;sid:84807786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944687)"; flow:established,from_client; content:"GET"; http_method; content:"/limmomixxs/fortnitespoofer/head/tempspoofer.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944687/; classtype:trojan-activity;sid:84807787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944688)"; flow:established,from_client; content:"GET"; http_method; content:"/misserlys/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944688/; classtype:trojan-activity;sid:84807788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944689)"; flow:established,from_client; content:"GET"; http_method; content:"/sillentl0vely/swift-executor/head/swift.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944689/; classtype:trojan-activity;sid:84807789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944690)"; flow:established,from_client; content:"GET"; http_method; content:"/bittlanes/fluxus-roblox-executor/head/fluxus%20v7.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944690/; classtype:trojan-activity;sid:84807790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944691)"; flow:established,from_client; content:"GET"; http_method; content:"/lakecase/redengine-fivem/head/loader.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944691/; classtype:trojan-activity;sid:84807791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944692)"; flow:established,from_client; content:"GET"; http_method; content:"/kesslyy27/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944692/; classtype:trojan-activity;sid:84807792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944693)"; flow:established,from_client; content:"GET"; http_method; content:"/mallymeyh/fortniteexternalcheat/head/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944693/; classtype:trojan-activity;sid:84807793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944694)"; flow:established,from_client; content:"GET"; http_method; content:"/arilles99/temp-spoofer-lifetime/head/tempspoofer.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944694/; classtype:trojan-activity;sid:84807794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944679)"; flow:established,from_client; content:"GET"; http_method; content:"/exgraphs/swift-executor/head/swift.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944679/; classtype:trojan-activity;sid:84807779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944680)"; flow:established,from_client; content:"GET"; http_method; content:"/lpisstuck/skriptgg/head/skriptgg.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944680/; classtype:trojan-activity;sid:84807780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944676)"; flow:established,from_client; content:"GET"; http_method; content:"/nrevv1lad/pubg-desync-menu/head/loader.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944676/; classtype:trojan-activity;sid:84807776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944677)"; flow:established,from_client; content:"GET"; http_method; content:"/moffb/c2panel/head/c2panel.exe"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944677/; classtype:trojan-activity;sid:84807777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944678)"; flow:established,from_client; content:"GET"; http_method; content:"/badd1lucky/xeno-executor/head/xeno.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944678/; classtype:trojan-activity;sid:84807778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944675)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"183.158.16.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944675/; classtype:trojan-activity;sid:84807775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944674)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.160.220.86"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944674/; classtype:trojan-activity;sid:84807774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944670)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.220.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944670/; classtype:trojan-activity;sid:84807770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944671)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.242.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944671/; classtype:trojan-activity;sid:84807771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944672)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.147.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944672/; classtype:trojan-activity;sid:84807772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944673)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.228.32"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944673/; classtype:trojan-activity;sid:84807773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944669)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"177.84.28.147"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944669/; classtype:trojan-activity;sid:84807769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944668)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.220.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944668/; classtype:trojan-activity;sid:84807768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944666)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.242.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944666/; classtype:trojan-activity;sid:84807766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944667)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.134.168"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944667/; classtype:trojan-activity;sid:84807767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944665)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.229.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944665/; classtype:trojan-activity;sid:84807765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944664)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"121.234.248.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944664/; classtype:trojan-activity;sid:84807764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944663)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.80.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944663/; classtype:trojan-activity;sid:84807763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944661)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.85.13.115"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944661/; classtype:trojan-activity;sid:84807761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944662)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.223.141.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944662/; classtype:trojan-activity;sid:84807762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944659)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.118.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944659/; classtype:trojan-activity;sid:84807759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944660)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.85.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944660/; classtype:trojan-activity;sid:84807760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944658)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.67.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944658/; classtype:trojan-activity;sid:84807758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944657)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.223.141.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944657/; classtype:trojan-activity;sid:84807757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944656)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.67.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944656/; classtype:trojan-activity;sid:84807756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944655)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.121.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944655/; classtype:trojan-activity;sid:84807755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944653)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.3.1"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944653/; classtype:trojan-activity;sid:84807753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944654)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.3.1"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944654/; classtype:trojan-activity;sid:84807754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944652)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.118.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944652/; classtype:trojan-activity;sid:84807752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944650)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.213.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944650/; classtype:trojan-activity;sid:84807750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944651)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.254.58"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944651/; classtype:trojan-activity;sid:84807751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944648)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.104.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944648/; classtype:trojan-activity;sid:84807748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944649)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"163.142.94.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944649/; classtype:trojan-activity;sid:84807749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944647)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.213.235.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944647/; classtype:trojan-activity;sid:84807747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944645)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.201.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944645/; classtype:trojan-activity;sid:84807745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944646)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.47.113.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944646/; classtype:trojan-activity;sid:84807746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944641)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.253.76"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944641/; classtype:trojan-activity;sid:84807741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944642)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.6.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944642/; classtype:trojan-activity;sid:84807742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.87.145.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944643/; classtype:trojan-activity;sid:84807743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944644)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.8.177"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944644/; classtype:trojan-activity;sid:84807744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944640)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.208.136.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944640/; classtype:trojan-activity;sid:84807740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944639)"; flow:established,from_client; content:"GET"; http_method; content:"/files/sofa/file.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944639/; classtype:trojan-activity;sid:84807739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944638)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.5.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944638/; classtype:trojan-activity;sid:84807738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944634)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.25.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944634/; classtype:trojan-activity;sid:84807734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944635)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.60.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944635/; classtype:trojan-activity;sid:84807735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944636)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.47.105.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944636/; classtype:trojan-activity;sid:84807736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944637)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.6.242"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944637/; classtype:trojan-activity;sid:84807737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.216.248"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944633/; classtype:trojan-activity;sid:84807733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944630)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"164.163.25.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944630/; classtype:trojan-activity;sid:84807730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944631)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.254.10.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944631/; classtype:trojan-activity;sid:84807731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944632)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.253.76"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944632/; classtype:trojan-activity;sid:84807732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944628)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.8.6.242"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944628/; classtype:trojan-activity;sid:84807728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944629)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.117.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944629/; classtype:trojan-activity;sid:84807729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944626)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.38.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944626/; classtype:trojan-activity;sid:84807726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944627)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.53.1.177"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944627/; classtype:trojan-activity;sid:84807727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944625)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.69.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944625/; classtype:trojan-activity;sid:84807725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944621)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.47.121.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944621/; classtype:trojan-activity;sid:84807721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944622)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.4.127.9"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944622/; classtype:trojan-activity;sid:84807722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944623)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.214.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944623/; classtype:trojan-activity;sid:84807723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944624)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.19.83.106"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944624/; classtype:trojan-activity;sid:84807724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944617)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.72.83.225"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944617/; classtype:trojan-activity;sid:84807717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944618)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.72.83.225"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944618/; classtype:trojan-activity;sid:84807718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944619)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.80.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944619/; classtype:trojan-activity;sid:84807719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944620)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.175.27.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944620/; classtype:trojan-activity;sid:84807720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944615)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.103.165"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944615/; classtype:trojan-activity;sid:84807715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944616)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.103.165"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944616/; classtype:trojan-activity;sid:84807716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944613)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.171.177.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944613/; classtype:trojan-activity;sid:84807713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944614)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.53.1.177"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944614/; classtype:trojan-activity;sid:84807714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944612)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"1.62.112.38"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944612/; classtype:trojan-activity;sid:84807712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944611)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.121.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944611/; classtype:trojan-activity;sid:84807711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944610)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.188.110"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944610/; classtype:trojan-activity;sid:84807710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944609)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.32.163"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944609/; classtype:trojan-activity;sid:84807709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944604)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.73.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944604/; classtype:trojan-activity;sid:84807704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944605)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944605/; classtype:trojan-activity;sid:84807705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944606)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.208.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944606/; classtype:trojan-activity;sid:84807706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944607)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.175.27.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944607/; classtype:trojan-activity;sid:84807707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944608)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.185.222.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944608/; classtype:trojan-activity;sid:84807708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944603)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.208.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944603/; classtype:trojan-activity;sid:84807703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944602)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.231.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944602/; classtype:trojan-activity;sid:84807702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944601)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"140.237.48.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944601/; classtype:trojan-activity;sid:84807701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944600)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.167.87.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944600/; classtype:trojan-activity;sid:84807700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944599)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.90.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944599/; classtype:trojan-activity;sid:84807699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944597)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.174.15.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944597/; classtype:trojan-activity;sid:84807697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944598)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.174.15.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944598/; classtype:trojan-activity;sid:84807698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944596)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944596/; classtype:trojan-activity;sid:84807696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944595)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.102.186"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944595/; classtype:trojan-activity;sid:84807695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944594)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.106.111.244"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944594/; classtype:trojan-activity;sid:84807694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944593)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.40.42.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944593/; classtype:trojan-activity;sid:84807693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944592)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"140.237.48.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944592/; classtype:trojan-activity;sid:84807692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944591)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.243.51.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944591/; classtype:trojan-activity;sid:84807691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944590)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"111.178.127.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944590/; classtype:trojan-activity;sid:84807690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944588)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.154.102.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944588/; classtype:trojan-activity;sid:84807688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944589)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.7.18"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944589/; classtype:trojan-activity;sid:84807689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944585)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944585/; classtype:trojan-activity;sid:84807685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944586)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.242.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944586/; classtype:trojan-activity;sid:84807686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944587)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.175.239.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944587/; classtype:trojan-activity;sid:84807687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944584)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.237.52.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944584/; classtype:trojan-activity;sid:84807684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944582)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.157.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944582/; classtype:trojan-activity;sid:84807682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944583)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944583/; classtype:trojan-activity;sid:84807683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944581)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.178.127.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944581/; classtype:trojan-activity;sid:84807681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944579)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944579/; classtype:trojan-activity;sid:84807679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944580)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.154.43"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944580/; classtype:trojan-activity;sid:84807680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944578)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.231.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944578/; classtype:trojan-activity;sid:84807678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944576)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.228.200.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944576/; classtype:trojan-activity;sid:84807676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944577)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.157.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944577/; classtype:trojan-activity;sid:84807677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944574)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.42.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944574/; classtype:trojan-activity;sid:84807674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944575)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.170.145"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944575/; classtype:trojan-activity;sid:84807675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944573)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.195.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944573/; classtype:trojan-activity;sid:84807673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944572)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.221.78.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944572/; classtype:trojan-activity;sid:84807672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944571)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.87.252"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944571/; classtype:trojan-activity;sid:84807671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944570)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.42.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944570/; classtype:trojan-activity;sid:84807670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944566)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.113.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944566/; classtype:trojan-activity;sid:84807666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944567)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.114.195.35"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944567/; classtype:trojan-activity;sid:84807667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944568)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.93.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944568/; classtype:trojan-activity;sid:84807668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944569)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.10.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944569/; classtype:trojan-activity;sid:84807669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944564)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.152.11.189"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944564/; classtype:trojan-activity;sid:84807664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944565)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.252.202"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944565/; classtype:trojan-activity;sid:84807665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944563)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.7.36.42"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944563/; classtype:trojan-activity;sid:84807663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944561)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.79.4.2"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944561/; classtype:trojan-activity;sid:84807661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944562)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.77.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944562/; classtype:trojan-activity;sid:84807662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944559)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.114.195.35"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944559/; classtype:trojan-activity;sid:84807659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944560)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.161.100.55"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_08; reference:url, urlhaus.abuse.ch/url/3944560/; classtype:trojan-activity;sid:84807660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944558)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.38.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944558/; classtype:trojan-activity;sid:84807658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944557)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.91.113.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944557/; classtype:trojan-activity;sid:84807657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944555)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.71.177.225"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944555/; classtype:trojan-activity;sid:84807655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944556)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.148.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944556/; classtype:trojan-activity;sid:84807656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944554)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.233.65.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944554/; classtype:trojan-activity;sid:84807654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944551)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.87.252"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944551/; classtype:trojan-activity;sid:84807651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944552)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.113.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944552/; classtype:trojan-activity;sid:84807652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944553)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.1.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944553/; classtype:trojan-activity;sid:84807653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944549)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944549/; classtype:trojan-activity;sid:84807649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944550)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.78.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944550/; classtype:trojan-activity;sid:84807650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944548)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.233.65.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944548/; classtype:trojan-activity;sid:84807648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944547)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.161.100.55"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944547/; classtype:trojan-activity;sid:84807647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944546)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.251.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944546/; classtype:trojan-activity;sid:84807646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944541)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.157.210.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944541/; classtype:trojan-activity;sid:84807641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944542)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.130.203.216"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944542/; classtype:trojan-activity;sid:84807642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944543)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.78.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944543/; classtype:trojan-activity;sid:84807643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944544)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.71.177.225"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944544/; classtype:trojan-activity;sid:84807644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944545)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.202.187.80"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944545/; classtype:trojan-activity;sid:84807645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944540)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.79.177.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944540/; classtype:trojan-activity;sid:84807640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944539)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.132.92"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944539/; classtype:trojan-activity;sid:84807639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944538)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.255.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944538/; classtype:trojan-activity;sid:84807638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944537)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.253.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944537/; classtype:trojan-activity;sid:84807637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944534)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.67.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944534/; classtype:trojan-activity;sid:84807634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944535)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.94.58.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944535/; classtype:trojan-activity;sid:84807635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944536)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.132.92"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944536/; classtype:trojan-activity;sid:84807636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944533)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.236.234.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944533/; classtype:trojan-activity;sid:84807633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944532)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.121.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944532/; classtype:trojan-activity;sid:84807632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944530)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.122.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944530/; classtype:trojan-activity;sid:84807630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944531)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.79.177.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944531/; classtype:trojan-activity;sid:84807631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944528)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.58.38"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944528/; classtype:trojan-activity;sid:84807628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944529)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944529/; classtype:trojan-activity;sid:84807629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944527)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.95.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944527/; classtype:trojan-activity;sid:84807627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944526)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.67.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944526/; classtype:trojan-activity;sid:84807626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944524)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.32.223"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944524/; classtype:trojan-activity;sid:84807624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944525)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.44.248.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944525/; classtype:trojan-activity;sid:84807625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944523)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.171.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944523/; classtype:trojan-activity;sid:84807623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944522)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.42.54.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944522/; classtype:trojan-activity;sid:84807622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944519)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.122.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944519/; classtype:trojan-activity;sid:84807619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944520)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"63.245.153.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944520/; classtype:trojan-activity;sid:84807620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944521)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.141.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944521/; classtype:trojan-activity;sid:84807621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944517)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.152.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944517/; classtype:trojan-activity;sid:84807617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944518)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.82.142.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944518/; classtype:trojan-activity;sid:84807618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944516)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.117.173.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944516/; classtype:trojan-activity;sid:84807616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944515)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.205.133"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944515/; classtype:trojan-activity;sid:84807615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944513)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.194.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944513/; classtype:trojan-activity;sid:84807613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944514)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.161.32"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944514/; classtype:trojan-activity;sid:84807614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944512)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.224.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944512/; classtype:trojan-activity;sid:84807612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944511)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.222.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944511/; classtype:trojan-activity;sid:84807611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944510)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.222.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944510/; classtype:trojan-activity;sid:84807610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944508)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.145.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944508/; classtype:trojan-activity;sid:84807608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944509)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.12.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944509/; classtype:trojan-activity;sid:84807609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944507)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"85.95.191.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944507/; classtype:trojan-activity;sid:84807607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944506)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.238.161.32"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944506/; classtype:trojan-activity;sid:84807606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944505)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.219.74.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944505/; classtype:trojan-activity;sid:84807605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944502)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.203.225"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944502/; classtype:trojan-activity;sid:84807602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944503)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.49.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944503/; classtype:trojan-activity;sid:84807603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944504)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.78.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944504/; classtype:trojan-activity;sid:84807604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944501)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.159.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944501/; classtype:trojan-activity;sid:84807601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944500)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_a91bba92fab4558e.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944500/; classtype:trojan-activity;sid:84807600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944499)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.38.123.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944499/; classtype:trojan-activity;sid:84807599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944496)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.177.197.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944496/; classtype:trojan-activity;sid:84807596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944497)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.95.171"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944497/; classtype:trojan-activity;sid:84807597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944498)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.226.203.225"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944498/; classtype:trojan-activity;sid:84807598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944494)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.62.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944494/; classtype:trojan-activity;sid:84807594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944495)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.9.194.116"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944495/; classtype:trojan-activity;sid:84807595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944493)"; flow:established,from_client; content:"GET"; http_method; content:"/jklarm7"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944493/; classtype:trojan-activity;sid:84807593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944492)"; flow:established,from_client; content:"GET"; http_method; content:"/jklarm"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944492/; classtype:trojan-activity;sid:84807592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944491)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.235.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944491/; classtype:trojan-activity;sid:84807591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944490)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.255.162"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944490/; classtype:trojan-activity;sid:84807590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944489)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.239.160.128"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944489/; classtype:trojan-activity;sid:84807589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944488)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.49.52.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944488/; classtype:trojan-activity;sid:84807588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944487)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.158.71"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944487/; classtype:trojan-activity;sid:84807587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944486)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.5.255.162"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944486/; classtype:trojan-activity;sid:84807586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944485)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.249.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944485/; classtype:trojan-activity;sid:84807585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944484)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.99.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944484/; classtype:trojan-activity;sid:84807584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944483)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.187.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944483/; classtype:trojan-activity;sid:84807583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944477)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.64.184.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944477/; classtype:trojan-activity;sid:84807577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944478)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.109.122.254"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944478/; classtype:trojan-activity;sid:84807578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944479)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.158.225"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944479/; classtype:trojan-activity;sid:84807579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944480)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944480/; classtype:trojan-activity;sid:84807580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944481)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.22.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944481/; classtype:trojan-activity;sid:84807581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944482)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.172.26.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944482/; classtype:trojan-activity;sid:84807582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944476)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.172.26.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944476/; classtype:trojan-activity;sid:84807576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944472)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.51.3"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944472/; classtype:trojan-activity;sid:84807572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944473)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.58.201.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944473/; classtype:trojan-activity;sid:84807573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944474)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.82.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944474/; classtype:trojan-activity;sid:84807574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944475)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.35.52"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944475/; classtype:trojan-activity;sid:84807575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944471)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.158.225"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944471/; classtype:trojan-activity;sid:84807571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944468)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.159.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944468/; classtype:trojan-activity;sid:84807568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944469)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.22.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944469/; classtype:trojan-activity;sid:84807569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944470)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.109.122.254"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944470/; classtype:trojan-activity;sid:84807570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944467)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944467/; classtype:trojan-activity;sid:84807567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944466)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.106.206"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944466/; classtype:trojan-activity;sid:84807566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944462)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.98.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944462/; classtype:trojan-activity;sid:84807562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944463)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.234.248.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944463/; classtype:trojan-activity;sid:84807563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944464)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.94.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944464/; classtype:trojan-activity;sid:84807564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944465)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.51.3"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944465/; classtype:trojan-activity;sid:84807565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944460)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.177.197.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944460/; classtype:trojan-activity;sid:84807560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944461)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.153.38.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944461/; classtype:trojan-activity;sid:84807561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944458)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.235.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944458/; classtype:trojan-activity;sid:84807558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944459)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"177.86.229.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944459/; classtype:trojan-activity;sid:84807559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944457)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.72.71"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944457/; classtype:trojan-activity;sid:84807557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944456)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944456/; classtype:trojan-activity;sid:84807556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944453)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/envio3.txt"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944453/; classtype:trojan-activity;sid:84807553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944454)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.159.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944454/; classtype:trojan-activity;sid:84807554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944455)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.94.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944455/; classtype:trojan-activity;sid:84807555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944449)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.196.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944449/; classtype:trojan-activity;sid:84807549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944450)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.253.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944450/; classtype:trojan-activity;sid:84807550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944451)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.55.12.91"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944451/; classtype:trojan-activity;sid:84807551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944452)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/edr.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944452/; classtype:trojan-activity;sid:84807552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944447)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/a001envio.txt"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944447/; classtype:trojan-activity;sid:84807547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944448)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/savedstart.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944448/; classtype:trojan-activity;sid:84807548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944440)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/envio32b.txt"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944440/; classtype:trojan-activity;sid:84807540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944441)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/rain.txt"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944441/; classtype:trojan-activity;sid:84807541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944442)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/pure.txt"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944442/; classtype:trojan-activity;sid:84807542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944443)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/salvado26.txt"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944443/; classtype:trojan-activity;sid:84807543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944444)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/q.txt"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944444/; classtype:trojan-activity;sid:84807544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944445)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/v6envio.txt"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944445/; classtype:trojan-activity;sid:84807545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944446)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/a1enviogh.txt"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944446/; classtype:trojan-activity;sid:84807546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944428)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/saved%20test.txt"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944428/; classtype:trojan-activity;sid:84807528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944429)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/a1envionew.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944429/; classtype:trojan-activity;sid:84807529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944430)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/queso.txt"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944430/; classtype:trojan-activity;sid:84807530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944431)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/ramgipk.txt"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944431/; classtype:trojan-activity;sid:84807531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944432)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/wd.txt"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944432/; classtype:trojan-activity;sid:84807532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944433)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/envio1gh.txt"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944433/; classtype:trojan-activity;sid:84807533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944434)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/envio1uac.txt"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944434/; classtype:trojan-activity;sid:84807534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944435)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/bro.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944435/; classtype:trojan-activity;sid:84807535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944436)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/paste.txt"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944436/; classtype:trojan-activity;sid:84807536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944437)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/1uac.txt"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944437/; classtype:trojan-activity;sid:84807537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944438)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/pureza.txt"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944438/; classtype:trojan-activity;sid:84807538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944439)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/broxw.txt"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944439/; classtype:trojan-activity;sid:84807539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944426)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/anew.txt"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944426/; classtype:trojan-activity;sid:84807526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944427)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/refs/heads/main/a1envio.txt"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944427/; classtype:trojan-activity;sid:84807527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944425)"; flow:established,from_client; content:"GET"; http_method; content:"/update.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"plf7x.valci.store"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944425/; classtype:trojan-activity;sid:84807525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944424)"; flow:established,from_client; content:"GET"; http_method; content:"/ridoyp99/xxxxxx/blob/main/lol.jpg"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944424/; classtype:trojan-activity;sid:84807524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944423)"; flow:established,from_client; content:"GET"; http_method; content:"/ridoyp99/xxxxxx/blob/main/xxe.xml"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944423/; classtype:trojan-activity;sid:84807523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944422)"; flow:established,from_client; content:"GET"; http_method; content:"/abeasinf/archivos/raw/refs/heads/main/anew.txt"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944422/; classtype:trojan-activity;sid:84807522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944421)"; flow:established,from_client; content:"GET"; http_method; content:"/bleaty.toc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"athuselevadores.com.br"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944421/; classtype:trojan-activity;sid:84807521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944419)"; flow:established,from_client; content:"GET"; http_method; content:"/abjeyp"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944419/; classtype:trojan-activity;sid:84807519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944420)"; flow:established,from_client; content:"GET"; http_method; content:"/anyname/img_140637.png"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"217.60.76.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944420/; classtype:trojan-activity;sid:84807520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944418)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.5.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944418/; classtype:trojan-activity;sid:84807518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944417)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.49.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944417/; classtype:trojan-activity;sid:84807517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944416)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944416/; classtype:trojan-activity;sid:84807516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944412)"; flow:established,from_client; content:"GET"; http_method; content:"/sparc"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944412/; classtype:trojan-activity;sid:84807512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944413)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944413/; classtype:trojan-activity;sid:84807513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944414)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944414/; classtype:trojan-activity;sid:84807514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944415)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944415/; classtype:trojan-activity;sid:84807515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944409)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944409/; classtype:trojan-activity;sid:84807509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944410)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944410/; classtype:trojan-activity;sid:84807510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944411)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944411/; classtype:trojan-activity;sid:84807511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944408)"; flow:established,from_client; content:"GET"; http_method; content:"/img_233018.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"andbake.cam"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944408/; classtype:trojan-activity;sid:84807508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944407)"; flow:established,from_client; content:"GET"; http_method; content:"/ohtmruw3"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"andbake.cam"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944407/; classtype:trojan-activity;sid:84807507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944405)"; flow:established,from_client; content:"GET"; http_method; content:"/smpuvcjzd"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944405/; classtype:trojan-activity;sid:84807505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944406)"; flow:established,from_client; content:"GET"; http_method; content:"/roybin.png"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"pub-37f3a615586d47f4996e932bf6df7670.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944406/; classtype:trojan-activity;sid:84807506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944403)"; flow:established,from_client; content:"GET"; http_method; content:"/hzzgpvc7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"andbake.cam"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944403/; classtype:trojan-activity;sid:84807503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944404)"; flow:established,from_client; content:"GET"; http_method; content:"/img_233158.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"andbake.cam"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944404/; classtype:trojan-activity;sid:84807504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944402)"; flow:established,from_client; content:"GET"; http_method; content:"/img_060214.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"sandybeachesandsunsets.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944402/; classtype:trojan-activity;sid:84807502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944401)"; flow:established,from_client; content:"GET"; http_method; content:"/img_120922.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"fibernetperu.pe"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944401/; classtype:trojan-activity;sid:84807501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944400)"; flow:established,from_client; content:"GET"; http_method; content:"/dprtpu55"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"fibernetperu.pe"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944400/; classtype:trojan-activity;sid:84807500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944399)"; flow:established,from_client; content:"GET"; http_method; content:"/img_033922.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"sugarfreedcup.co.za"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944399/; classtype:trojan-activity;sid:84807499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944398)"; flow:established,from_client; content:"GET"; http_method; content:"/file/img_154255.png"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"wp.fujeigroup.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944398/; classtype:trojan-activity;sid:84807498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944397)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.54.110.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944397/; classtype:trojan-activity;sid:84807497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944396)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.253.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944396/; classtype:trojan-activity;sid:84807496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944394)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"110.138.1.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944394/; classtype:trojan-activity;sid:84807494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944395)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.87.126.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944395/; classtype:trojan-activity;sid:84807495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944393)"; flow:established,from_client; content:"GET"; http_method; content:"/nnnnnnzeeee/secured_stub.ps1"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944393/; classtype:trojan-activity;sid:84807493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944392)"; flow:established,from_client; content:"GET"; http_method; content:"/img_035907.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"sugarfreedcup.co.za"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944392/; classtype:trojan-activity;sid:84807492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944391)"; flow:established,from_client; content:"GET"; http_method; content:"/masabbikk/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944391/; classtype:trojan-activity;sid:84807491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944390)"; flow:established,from_client; content:"GET"; http_method; content:"/telnetbins.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944390/; classtype:trojan-activity;sid:84807490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944386)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944386/; classtype:trojan-activity;sid:84807486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944387)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944387/; classtype:trojan-activity;sid:84807487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944388)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944388/; classtype:trojan-activity;sid:84807488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944389)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.238.235.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944389/; classtype:trojan-activity;sid:84807489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944385)"; flow:established,from_client; content:"GET"; http_method; content:"/4.jpg"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.40.204.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944385/; classtype:trojan-activity;sid:84807485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944383)"; flow:established,from_client; content:"GET"; http_method; content:"/file/mccppcs.txt"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"nd.tdpqnf.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944383/; classtype:trojan-activity;sid:84807483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944384)"; flow:established,from_client; content:"GET"; http_method; content:"/img/1.jpg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"107.172.206.125"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944384/; classtype:trojan-activity;sid:84807484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944382)"; flow:established,from_client; content:"GET"; http_method; content:"/file/jpesoai.txt"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"nd.tdpqnf.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944382/; classtype:trojan-activity;sid:84807482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944380)"; flow:established,from_client; content:"GET"; http_method; content:"/sma/mnpckbo.txt"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"nd.tdpqnf.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944380/; classtype:trojan-activity;sid:84807480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944381)"; flow:established,from_client; content:"GET"; http_method; content:"/fiipisf.txt"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"31.40.204.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944381/; classtype:trojan-activity;sid:84807481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944379)"; flow:established,from_client; content:"GET"; http_method; content:"/1.jpg"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.40.204.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944379/; classtype:trojan-activity;sid:84807479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944377)"; flow:established,from_client; content:"GET"; http_method; content:"/55/wegoodforme.hta"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"107.172.206.125"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944377/; classtype:trojan-activity;sid:84807477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944378)"; flow:established,from_client; content:"GET"; http_method; content:"/60/wegivenbestthignswithme.hta"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"107.172.206.125"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944378/; classtype:trojan-activity;sid:84807478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944376)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.40.143"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944376/; classtype:trojan-activity;sid:84807476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944375)"; flow:established,from_client; content:"GET"; http_method; content:"/download/windowsupdate.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"hardly-signatures-loc-surf.trycloudflare.com"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944375/; classtype:trojan-activity;sid:84807475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944374)"; flow:established,from_client; content:"GET"; http_method; content:"/60/aakdhfi.txt"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"107.173.143.44"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944374/; classtype:trojan-activity;sid:84807474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944372)"; flow:established,from_client; content:"GET"; http_method; content:"/img/1.jpg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.224.17.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944372/; classtype:trojan-activity;sid:84807472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944373)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.243.51.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944373/; classtype:trojan-activity;sid:84807473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944362)"; flow:established,from_client; content:"GET"; http_method; content:"/fjvdaefanrcpqhxrqgrdi146.bin"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944362/; classtype:trojan-activity;sid:84807462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944363)"; flow:established,from_client; content:"GET"; http_method; content:"/yuvlizwyol185.bin"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944363/; classtype:trojan-activity;sid:84807463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944364)"; flow:established,from_client; content:"GET"; http_method; content:"/vlgprxhpuqegj205.bin"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944364/; classtype:trojan-activity;sid:84807464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944365)"; flow:established,from_client; content:"GET"; http_method; content:"/snderjyskens.hhk"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944365/; classtype:trojan-activity;sid:84807465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944366)"; flow:established,from_client; content:"GET"; http_method; content:"/mavede.asd"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944366/; classtype:trojan-activity;sid:84807466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944367)"; flow:established,from_client; content:"GET"; http_method; content:"/pereia.dsp"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944367/; classtype:trojan-activity;sid:84807467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944368)"; flow:established,from_client; content:"GET"; http_method; content:"/bothilde.mdp"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944368/; classtype:trojan-activity;sid:84807468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944369)"; flow:established,from_client; content:"GET"; http_method; content:"/wiimgn142.bin"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944369/; classtype:trojan-activity;sid:84807469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944370)"; flow:established,from_client; content:"GET"; http_method; content:"/aitptsjhq176.bin"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944370/; classtype:trojan-activity;sid:84807470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944371)"; flow:established,from_client; content:"GET"; http_method; content:"/jernholdiges.asi"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"194.116.236.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944371/; classtype:trojan-activity;sid:84807471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944361)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.225.100.68"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944361/; classtype:trojan-activity;sid:84807461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944359)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.46.175.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944359/; classtype:trojan-activity;sid:84807459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944360)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.87.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944360/; classtype:trojan-activity;sid:84807460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944358)"; flow:established,from_client; content:"GET"; http_method; content:"/d.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"192.162.199.159"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944358/; classtype:trojan-activity;sid:84807458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944357)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.198.113.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944357/; classtype:trojan-activity;sid:84807457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944356)"; flow:established,from_client; content:"GET"; http_method; content:"/update.ps1"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"45.137.201.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944356/; classtype:trojan-activity;sid:84807456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944355)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.152.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944355/; classtype:trojan-activity;sid:84807455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944354)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.136.85.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944354/; classtype:trojan-activity;sid:84807454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944353)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.59.88.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944353/; classtype:trojan-activity;sid:84807453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944349)"; flow:established,from_client; content:"GET"; http_method; content:"/yarn"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944349/; classtype:trojan-activity;sid:84807449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944350)"; flow:established,from_client; content:"GET"; http_method; content:"/pay"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944350/; classtype:trojan-activity;sid:84807450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944351)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944351/; classtype:trojan-activity;sid:84807451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944352)"; flow:established,from_client; content:"GET"; http_method; content:"/bin"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944352/; classtype:trojan-activity;sid:84807452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944348)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.x86"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944348/; classtype:trojan-activity;sid:84807448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944347)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.arm6"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944347/; classtype:trojan-activity;sid:84807447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944344)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.arm7"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944344/; classtype:trojan-activity;sid:84807444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944345)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.mpsl"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944345/; classtype:trojan-activity;sid:84807445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944346)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.arm5"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944346/; classtype:trojan-activity;sid:84807446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944343)"; flow:established,from_client; content:"GET"; http_method; content:"/exp.so"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944343/; classtype:trojan-activity;sid:84807443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944339)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.ppc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944339/; classtype:trojan-activity;sid:84807439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944340)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944340/; classtype:trojan-activity;sid:84807440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944341)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944341/; classtype:trojan-activity;sid:84807441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944342)"; flow:established,from_client; content:"GET"; http_method; content:"/disspoor"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944342/; classtype:trojan-activity;sid:84807442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944333)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944333/; classtype:trojan-activity;sid:84807433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944334)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.mpsl"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944334/; classtype:trojan-activity;sid:84807434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944335)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944335/; classtype:trojan-activity;sid:84807435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944336)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.arm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944336/; classtype:trojan-activity;sid:84807436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944337)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944337/; classtype:trojan-activity;sid:84807437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944338)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.sh4"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944338/; classtype:trojan-activity;sid:84807438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944331)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.111.23.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944331/; classtype:trojan-activity;sid:84807431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944332)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.52.20.56"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944332/; classtype:trojan-activity;sid:84807432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944330)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.192.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944330/; classtype:trojan-activity;sid:84807430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944329)"; flow:established,from_client; content:"GET"; http_method; content:"/e"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944329/; classtype:trojan-activity;sid:84807429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944328)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/classic/sevv.ps1"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"severidades.cfd"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944328/; classtype:trojan-activity;sid:84807428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944326)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"124.198.131.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944326/; classtype:trojan-activity;sid:84807426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944327)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"124.198.131.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944327/; classtype:trojan-activity;sid:84807427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944325)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.81.95.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944325/; classtype:trojan-activity;sid:84807425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944324)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.59.112.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944324/; classtype:trojan-activity;sid:84807424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944318)"; flow:established,from_client; content:"GET"; http_method; content:"/unrealclient-3.0.2-obf.jar"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"unrealclient.pages.dev"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944318/; classtype:trojan-activity;sid:84807418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944319)"; flow:established,from_client; content:"GET"; http_method; content:"/loader2-4.zip"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"loader2-4.github.io"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944319/; classtype:trojan-activity;sid:84807419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944320)"; flow:established,from_client; content:"GET"; http_method; content:"/stub.ps1"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"124.198.132.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944320/; classtype:trojan-activity;sid:84807420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944321)"; flow:established,from_client; content:"GET"; http_method; content:"/wrb.ps1"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"124.198.132.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944321/; classtype:trojan-activity;sid:84807421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944322)"; flow:established,from_client; content:"GET"; http_method; content:"/raw1.ps1"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"124.198.132.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944322/; classtype:trojan-activity;sid:84807422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944323)"; flow:established,from_client; content:"GET"; http_method; content:"/printspoofer64.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"124.198.132.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944323/; classtype:trojan-activity;sid:84807423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944317)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.arc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944317/; classtype:trojan-activity;sid:84807417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944315)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mipsel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944315/; classtype:trojan-activity;sid:84807415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944316)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944316/; classtype:trojan-activity;sid:84807416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944307)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944307/; classtype:trojan-activity;sid:84807407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944308)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944308/; classtype:trojan-activity;sid:84807408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944309)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944309/; classtype:trojan-activity;sid:84807409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944310)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944310/; classtype:trojan-activity;sid:84807410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944311)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv7l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944311/; classtype:trojan-activity;sid:84807411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944312)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv6l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944312/; classtype:trojan-activity;sid:84807412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944313)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.aarch64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944313/; classtype:trojan-activity;sid:84807413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944314)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944314/; classtype:trojan-activity;sid:84807414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944306)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944306/; classtype:trojan-activity;sid:84807406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944304)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944304/; classtype:trojan-activity;sid:84807404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944305)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944305/; classtype:trojan-activity;sid:84807405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944296)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944296/; classtype:trojan-activity;sid:84807396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944297)"; flow:established,from_client; content:"GET"; http_method; content:"/tadashi.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.140.176.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944297/; classtype:trojan-activity;sid:84807397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944298)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944298/; classtype:trojan-activity;sid:84807398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944299)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944299/; classtype:trojan-activity;sid:84807399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944300)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944300/; classtype:trojan-activity;sid:84807400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944301)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944301/; classtype:trojan-activity;sid:84807401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944302)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944302/; classtype:trojan-activity;sid:84807402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944303)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.99.95.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944303/; classtype:trojan-activity;sid:84807403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944295)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.118.189.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944295/; classtype:trojan-activity;sid:84807395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944294)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.65.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944294/; classtype:trojan-activity;sid:84807394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944293)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.189.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944293/; classtype:trojan-activity;sid:84807393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944292)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.172.218.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944292/; classtype:trojan-activity;sid:84807392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944291)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.177.199.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944291/; classtype:trojan-activity;sid:84807391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944290)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"130.0.33.104"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944290/; classtype:trojan-activity;sid:84807390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944289)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.227.84.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944289/; classtype:trojan-activity;sid:84807389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944287)"; flow:established,from_client; content:"GET"; http_method; content:"/33/wetrongiven.js"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"107.175.88.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944287/; classtype:trojan-activity;sid:84807387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944288)"; flow:established,from_client; content:"GET"; http_method; content:"/33/img_182647.png"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"107.175.88.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944288/; classtype:trojan-activity;sid:84807388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944286)"; flow:established,from_client; content:"GET"; http_method; content:"/33/brodaron.hta"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"107.175.88.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944286/; classtype:trojan-activity;sid:84807386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944285)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.203.183.158"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944285/; classtype:trojan-activity;sid:84807385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944274)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.172.78.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944274/; classtype:trojan-activity;sid:84807374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944275)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.17.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944275/; classtype:trojan-activity;sid:84807375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944276)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.25.126.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944276/; classtype:trojan-activity;sid:84807376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944277)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.15.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944277/; classtype:trojan-activity;sid:84807377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944278)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.0.33.104"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944278/; classtype:trojan-activity;sid:84807378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944279)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.83.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944279/; classtype:trojan-activity;sid:84807379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944280)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.60.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944280/; classtype:trojan-activity;sid:84807380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944281)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.1.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944281/; classtype:trojan-activity;sid:84807381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944282)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.192.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944282/; classtype:trojan-activity;sid:84807382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944283)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.138.1.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944283/; classtype:trojan-activity;sid:84807383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944284)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.147.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944284/; classtype:trojan-activity;sid:84807384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944266)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.232.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944266/; classtype:trojan-activity;sid:84807366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944267)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.147.40.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944267/; classtype:trojan-activity;sid:84807367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944268)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.48.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944268/; classtype:trojan-activity;sid:84807368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944269)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.118.245.201"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944269/; classtype:trojan-activity;sid:84807369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944270)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.202.142.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944270/; classtype:trojan-activity;sid:84807370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944271)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.38.158.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944271/; classtype:trojan-activity;sid:84807371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944272)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.233.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944272/; classtype:trojan-activity;sid:84807372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944273)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.83.129"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944273/; classtype:trojan-activity;sid:84807373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944265)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.189.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944265/; classtype:trojan-activity;sid:84807365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944264)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.255.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944264/; classtype:trojan-activity;sid:84807364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944263)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.99.255.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944263/; classtype:trojan-activity;sid:84807363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944262)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.34.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944262/; classtype:trojan-activity;sid:84807362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944256)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.32.223"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944256/; classtype:trojan-activity;sid:84807356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944257)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.84.133.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944257/; classtype:trojan-activity;sid:84807357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944258)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.53.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944258/; classtype:trojan-activity;sid:84807358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944259)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.194.28.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944259/; classtype:trojan-activity;sid:84807359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944260)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.140.44.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944260/; classtype:trojan-activity;sid:84807360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944261)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.177.21"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944261/; classtype:trojan-activity;sid:84807361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944255)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"108.168.10.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944255/; classtype:trojan-activity;sid:84807355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944253)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.mips"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944253/; classtype:trojan-activity;sid:84807353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944254)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.82.64.55"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944254/; classtype:trojan-activity;sid:84807354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944252)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/aetherius-1.8.2.jar"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"aetherius.live"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944252/; classtype:trojan-activity;sid:84807352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944251)"; flow:established,from_client; content:"GET"; http_method; content:"/hashmanager.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"growgreenhorizons.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944251/; classtype:trojan-activity;sid:84807351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944250)"; flow:established,from_client; content:"GET"; http_method; content:"/download/vlpjvpm4cqk"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"f74.workupload.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944250/; classtype:trojan-activity;sid:84807350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944249)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_6090c1ecb2a975aa.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944249/; classtype:trojan-activity;sid:84807349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944247)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_arm64.p"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944247/; classtype:trojan-activity;sid:84807347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944248)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_mips.p"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944248/; classtype:trojan-activity;sid:84807348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944246)"; flow:established,from_client; content:"GET"; http_method; content:"/f/m/.b0s_x86_64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"130.12.182.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944246/; classtype:trojan-activity;sid:84807346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944244)"; flow:established,from_client; content:"GET"; http_method; content:"/kabot/mig-logcleaner-resurrected.git"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944244/; classtype:trojan-activity;sid:84807344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944245)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.173.123.251"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944245/; classtype:trojan-activity;sid:84807345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944243)"; flow:established,from_client; content:"GET"; http_method; content:"/30/bestwishesgivenmebesttings.hta|3f|pic_4995459495.jpg"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"216.9.224.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944243/; classtype:trojan-activity;sid:84807343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944242)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.167.87.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944242/; classtype:trojan-activity;sid:84807342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944241)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.16.164.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944241/; classtype:trojan-activity;sid:84807341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944240)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.40.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944240/; classtype:trojan-activity;sid:84807340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944239)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.238.27.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944239/; classtype:trojan-activity;sid:84807339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944238)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.228.200.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944238/; classtype:trojan-activity;sid:84807338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944237)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.176.43"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944237/; classtype:trojan-activity;sid:84807337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944235)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.110.9.54"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944235/; classtype:trojan-activity;sid:84807335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944236)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.46.198.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944236/; classtype:trojan-activity;sid:84807336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944232)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"201.110.189.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944232/; classtype:trojan-activity;sid:84807332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944233)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"14.221.238.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944233/; classtype:trojan-activity;sid:84807333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944234)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944234/; classtype:trojan-activity;sid:84807334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944231)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.107.78.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944231/; classtype:trojan-activity;sid:84807331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944229)"; flow:established,from_client; content:"GET"; http_method; content:"/30/img_224029.png"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"216.9.224.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944229/; classtype:trojan-activity;sid:84807329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944230)"; flow:established,from_client; content:"GET"; http_method; content:"/30/greenangelkings.js"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"216.9.224.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944230/; classtype:trojan-activity;sid:84807330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944227)"; flow:established,from_client; content:"GET"; http_method; content:"/30/bestwishesgivenmebesttings.hta"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"216.9.224.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944227/; classtype:trojan-activity;sid:84807327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944228)"; flow:established,from_client; content:"GET"; http_method; content:"/ips.py"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"deffnelreports.bramblequarz.ru"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944228/; classtype:trojan-activity;sid:84807328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944226)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.58.38"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944226/; classtype:trojan-activity;sid:84807326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944225)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"165.98.243.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944225/; classtype:trojan-activity;sid:84807325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944222)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.106.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944222/; classtype:trojan-activity;sid:84807322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944223)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.194.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944223/; classtype:trojan-activity;sid:84807323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944224)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.43.173.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944224/; classtype:trojan-activity;sid:84807324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944221)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.235.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944221/; classtype:trojan-activity;sid:84807321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944220)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.5.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944220/; classtype:trojan-activity;sid:84807320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944219)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.114.195.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944219/; classtype:trojan-activity;sid:84807319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944215)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.237.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944215/; classtype:trojan-activity;sid:84807315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944216)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.49.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944216/; classtype:trojan-activity;sid:84807316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944217)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.234.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944217/; classtype:trojan-activity;sid:84807317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944218)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.81.95.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944218/; classtype:trojan-activity;sid:84807318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944214)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.114.195.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944214/; classtype:trojan-activity;sid:84807314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944213)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.193.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944213/; classtype:trojan-activity;sid:84807313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944212)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.144.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944212/; classtype:trojan-activity;sid:84807312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944208)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944208/; classtype:trojan-activity;sid:84807308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944209)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.141.165"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944209/; classtype:trojan-activity;sid:84807309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944210)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.88.136.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944210/; classtype:trojan-activity;sid:84807310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944211)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.145.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944211/; classtype:trojan-activity;sid:84807311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944206)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.52.180.238"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944206/; classtype:trojan-activity;sid:84807306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944207)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.139.99.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944207/; classtype:trojan-activity;sid:84807307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944205)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.181.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944205/; classtype:trojan-activity;sid:84807305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944204)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.159.171"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944204/; classtype:trojan-activity;sid:84807304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944203)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.141.165"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944203/; classtype:trojan-activity;sid:84807303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944202)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.104.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944202/; classtype:trojan-activity;sid:84807302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944201)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.179.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944201/; classtype:trojan-activity;sid:84807301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944200)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.55.2.151"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944200/; classtype:trojan-activity;sid:84807300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944198)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.86.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944198/; classtype:trojan-activity;sid:84807298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944199)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.134.173.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944199/; classtype:trojan-activity;sid:84807299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944185)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.81.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944185/; classtype:trojan-activity;sid:84807285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944186)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.139.99.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944186/; classtype:trojan-activity;sid:84807286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944187)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.213.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944187/; classtype:trojan-activity;sid:84807287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944188)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.108.59"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944188/; classtype:trojan-activity;sid:84807288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944189/; classtype:trojan-activity;sid:84807289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.229.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944190/; classtype:trojan-activity;sid:84807290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944191)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.26.131.236"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944191/; classtype:trojan-activity;sid:84807291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944192)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.179.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944192/; classtype:trojan-activity;sid:84807292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944193)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.215.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944193/; classtype:trojan-activity;sid:84807293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944194)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.72.71"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944194/; classtype:trojan-activity;sid:84807294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944195)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.176.43"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944195/; classtype:trojan-activity;sid:84807295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944196)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.133.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944196/; classtype:trojan-activity;sid:84807296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944197)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.234.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944197/; classtype:trojan-activity;sid:84807297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944184)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.82.32"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944184/; classtype:trojan-activity;sid:84807284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944183)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.113.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944183/; classtype:trojan-activity;sid:84807283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944182)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.52.180.238"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944182/; classtype:trojan-activity;sid:84807282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944181)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.15.69.204"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944181/; classtype:trojan-activity;sid:84807281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944178)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.139.36.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944178/; classtype:trojan-activity;sid:84807278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944179)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.87.126.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944179/; classtype:trojan-activity;sid:84807279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944180)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.78.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944180/; classtype:trojan-activity;sid:84807280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944177)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.69.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944177/; classtype:trojan-activity;sid:84807277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944176)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.179.240.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944176/; classtype:trojan-activity;sid:84807276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944175)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.113.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944175/; classtype:trojan-activity;sid:84807275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944174)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.179.240.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944174/; classtype:trojan-activity;sid:84807274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944173)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.161.1.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944173/; classtype:trojan-activity;sid:84807273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944172)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.6.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944172/; classtype:trojan-activity;sid:84807272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944170)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.51.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944170/; classtype:trojan-activity;sid:84807270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944171)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.40.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944171/; classtype:trojan-activity;sid:84807271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.227.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944169/; classtype:trojan-activity;sid:84807269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944167)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.172.218.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944167/; classtype:trojan-activity;sid:84807267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944168)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.245.56.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944168/; classtype:trojan-activity;sid:84807268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944165)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944165/; classtype:trojan-activity;sid:84807265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944166)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.227.65.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944166/; classtype:trojan-activity;sid:84807266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944164)"; flow:established,from_client; content:"GET"; http_method; content:"/bx_amd64.p"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944164/; classtype:trojan-activity;sid:84807264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944163)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.101.66"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944163/; classtype:trojan-activity;sid:84807263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944162)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.237.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944162/; classtype:trojan-activity;sid:84807262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944158)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.87.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944158/; classtype:trojan-activity;sid:84807258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944159)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"14.221.238.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944159/; classtype:trojan-activity;sid:84807259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944160)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.245.56.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944160/; classtype:trojan-activity;sid:84807260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944161)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.227.65.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944161/; classtype:trojan-activity;sid:84807261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944156)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.96.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944156/; classtype:trojan-activity;sid:84807256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944157)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.20.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944157/; classtype:trojan-activity;sid:84807257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944155)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.20.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944155/; classtype:trojan-activity;sid:84807255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944154)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.121.111"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944154/; classtype:trojan-activity;sid:84807254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944152)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.151.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944152/; classtype:trojan-activity;sid:84807252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944153)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.220.213.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944153/; classtype:trojan-activity;sid:84807253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944150)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.83.129"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944150/; classtype:trojan-activity;sid:84807250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944151)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.158.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944151/; classtype:trojan-activity;sid:84807251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944147)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"138.204.196.254"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944147/; classtype:trojan-activity;sid:84807247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944148)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.200.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944148/; classtype:trojan-activity;sid:84807248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944149)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.82.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944149/; classtype:trojan-activity;sid:84807249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944145)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.26.86.216"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944145/; classtype:trojan-activity;sid:84807245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944146)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.216.143"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944146/; classtype:trojan-activity;sid:84807246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944143)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.158.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944143/; classtype:trojan-activity;sid:84807243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944144)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.249.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944144/; classtype:trojan-activity;sid:84807244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944141)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.202.234.182"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944141/; classtype:trojan-activity;sid:84807241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944142)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.114.34.128"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944142/; classtype:trojan-activity;sid:84807242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944139)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.26.86.216"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944139/; classtype:trojan-activity;sid:84807239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944140)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.86.117.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944140/; classtype:trojan-activity;sid:84807240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944138)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.1.26.13"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944138/; classtype:trojan-activity;sid:84807238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944136)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.14.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944136/; classtype:trojan-activity;sid:84807236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944137)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.252.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944137/; classtype:trojan-activity;sid:84807237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944135)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.94.199"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944135/; classtype:trojan-activity;sid:84807235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944134)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.16.135.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944134/; classtype:trojan-activity;sid:84807234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944132)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.9.200.156"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944132/; classtype:trojan-activity;sid:84807232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944133)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.187.197.115"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944133/; classtype:trojan-activity;sid:84807233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944131)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.9.35.137"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944131/; classtype:trojan-activity;sid:84807231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944130)"; flow:established,from_client; content:"GET"; http_method; content:"/totemcounter-26.2.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944130/; classtype:trojan-activity;sid:84807230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944128)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.242.13.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944128/; classtype:trojan-activity;sid:84807228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944129)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.186.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944129/; classtype:trojan-activity;sid:84807229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944127)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.229.99"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944127/; classtype:trojan-activity;sid:84807227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944126)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.89.156.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944126/; classtype:trojan-activity;sid:84807226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944125)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/jnf0ecydm1z63frnge1mn/docsend.exe|3f|rlkey=01seodht5j6nnix645ejn3a5r|7c|26|7c|st=vcdaxsj2|7c|26|7c|dl=1"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944125/; classtype:trojan-activity;sid:84807225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944124)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/dcbo57pem0pjqzx65giot/matefalls-setup-1.0.0.exe|3f|rlkey=yc7kc4vm6iy1urr0wh1xwta91|7c|26|7c|dl=1"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944124/; classtype:trojan-activity;sid:84807224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944123)"; flow:established,from_client; content:"GET"; http_method; content:"/wps_setup_x64.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"xiazailianjie.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944123/; classtype:trojan-activity;sid:84807223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944122)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/jwhb6vojim0cfxrxip9fk/docsend.exe|3f|rlkey=zgpwwjbtsrnatafb9g24pjnxu|7c|26|7c|st=gwds3ryx|7c|26|7c|dl=1"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944122/; classtype:trojan-activity;sid:84807222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944121)"; flow:established,from_client; content:"GET"; http_method; content:"/2026scrill/client.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"stellaspicy.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944121/; classtype:trojan-activity;sid:84807221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944114)"; flow:established,from_client; content:"GET"; http_method; content:"/beacon_x"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.254.195.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944114/; classtype:trojan-activity;sid:84807214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944115)"; flow:established,from_client; content:"GET"; http_method; content:"/donutdupe-26.2.jar"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"donutdupe.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944115/; classtype:trojan-activity;sid:84807215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944116)"; flow:established,from_client; content:"GET"; http_method; content:"/2026scrill/runelite.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"stellaspicy.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944116/; classtype:trojan-activity;sid:84807216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944117)"; flow:established,from_client; content:"GET"; http_method; content:"/krypton-client-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944117/; classtype:trojan-activity;sid:84807217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944118)"; flow:established,from_client; content:"GET"; http_method; content:"/radium-client-26.2.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944118/; classtype:trojan-activity;sid:84807218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944119)"; flow:established,from_client; content:"GET"; http_method; content:"/shulker_box_tooltip-26.2.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944119/; classtype:trojan-activity;sid:84807219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944120)"; flow:established,from_client; content:"GET"; http_method; content:"/alycone-client-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944120/; classtype:trojan-activity;sid:84807220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944113)"; flow:established,from_client; content:"GET"; http_method; content:"/gamble-rig-26.2.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944113/; classtype:trojan-activity;sid:84807213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944112)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.16.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944112/; classtype:trojan-activity;sid:84807212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944111)"; flow:established,from_client; content:"GET"; http_method; content:"/radon-client-26.2.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944111/; classtype:trojan-activity;sid:84807211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944110)"; flow:established,from_client; content:"GET"; http_method; content:"/glazed-client-26.2.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944110/; classtype:trojan-activity;sid:84807210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944107)"; flow:established,from_client; content:"GET"; http_method; content:"/meteor-client-26.2.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944107/; classtype:trojan-activity;sid:84807207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944108)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.245.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944108/; classtype:trojan-activity;sid:84807208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944109)"; flow:established,from_client; content:"GET"; http_method; content:"/nova-client-26.2.jar"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944109/; classtype:trojan-activity;sid:84807209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944104)"; flow:established,from_client; content:"GET"; http_method; content:"/freelook-26.2.jar"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944104/; classtype:trojan-activity;sid:84807204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944105)"; flow:established,from_client; content:"GET"; http_method; content:"/donutextras-26.2.jar"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944105/; classtype:trojan-activity;sid:84807205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944106)"; flow:established,from_client; content:"GET"; http_method; content:"/mouse_tweaks-26.2.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944106/; classtype:trojan-activity;sid:84807206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944100)"; flow:established,from_client; content:"GET"; http_method; content:"/appleskin-26.2.jar"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944100/; classtype:trojan-activity;sid:84807200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944101)"; flow:established,from_client; content:"GET"; http_method; content:"/iris-26.2.jar"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944101/; classtype:trojan-activity;sid:84807201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944102)"; flow:established,from_client; content:"GET"; http_method; content:"/ferritecore-26.2.jar"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944102/; classtype:trojan-activity;sid:84807202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944103)"; flow:established,from_client; content:"GET"; http_method; content:"/baritone-26.2.jar"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944103/; classtype:trojan-activity;sid:84807203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944095)"; flow:established,from_client; content:"GET"; http_method; content:"/nuclearaddons-26.2.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944095/; classtype:trojan-activity;sid:84807195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944096)"; flow:established,from_client; content:"GET"; http_method; content:"/sodium-26.2.jar"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944096/; classtype:trojan-activity;sid:84807196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944097)"; flow:established,from_client; content:"GET"; http_method; content:"/zincaddons-26.2.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944097/; classtype:trojan-activity;sid:84807197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944098)"; flow:established,from_client; content:"GET"; http_method; content:"/litematica-26.2.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944098/; classtype:trojan-activity;sid:84807198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944099)"; flow:established,from_client; content:"GET"; http_method; content:"/bamboo-client-26.2.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944099/; classtype:trojan-activity;sid:84807199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944092)"; flow:established,from_client; content:"GET"; http_method; content:"/donut-duper-26.2.jar"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944092/; classtype:trojan-activity;sid:84807192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944093)"; flow:established,from_client; content:"GET"; http_method; content:"/lithium-26.2.jar"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944093/; classtype:trojan-activity;sid:84807193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944094)"; flow:established,from_client; content:"GET"; http_method; content:"/donutdupe-1.21.11.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"donutdupe.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944094/; classtype:trojan-activity;sid:84807194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944090)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"docs.cs-supplements.de"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944090/; classtype:trojan-activity;sid:84807190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944091)"; flow:established,from_client; content:"GET"; http_method; content:"/gamefiles/image.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"ikovrsps.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944091/; classtype:trojan-activity;sid:84807191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944086)"; flow:established,from_client; content:"GET"; http_method; content:"/zoomify-26.2.jar"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944086/; classtype:trojan-activity;sid:84807186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944087)"; flow:established,from_client; content:"GET"; http_method; content:"/xaeros_minimap-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944087/; classtype:trojan-activity;sid:84807187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944088)"; flow:established,from_client; content:"GET"; http_method; content:"/tiertagger-26.2.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944088/; classtype:trojan-activity;sid:84807188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944089)"; flow:established,from_client; content:"GET"; http_method; content:"/zav001/534rkyoj34oiy/releases/download/t/donutclient-1.21.11.jar"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944089/; classtype:trojan-activity;sid:84807189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944080)"; flow:established,from_client; content:"GET"; http_method; content:"/bnana-client-26.2.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944080/; classtype:trojan-activity;sid:84807180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944081)"; flow:established,from_client; content:"GET"; http_method; content:"/zav001/d3et2t23y3/releases/download/v1/goobaaclient.1.21.11.jar"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944081/; classtype:trojan-activity;sid:84807181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944082)"; flow:established,from_client; content:"GET"; http_method; content:"/5r3fqt67ew531has4231.arm"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"144.31.150.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944082/; classtype:trojan-activity;sid:84807182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944083)"; flow:established,from_client; content:"GET"; http_method; content:"/worldedit-26.2.jar"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944083/; classtype:trojan-activity;sid:84807183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944084)"; flow:established,from_client; content:"GET"; http_method; content:"/mina.jar"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"ikovrsps.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944084/; classtype:trojan-activity;sid:84807184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944085)"; flow:established,from_client; content:"GET"; http_method; content:"/exploitpreventer-26.2.jar"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"donutclients.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944085/; classtype:trojan-activity;sid:84807185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944079)"; flow:established,from_client; content:"GET"; http_method; content:"/alex3430/pecky777/blob/main/peckycloner.py"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944079/; classtype:trojan-activity;sid:84807179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944078)"; flow:established,from_client; content:"GET"; http_method; content:"/view/b757zwtqgif66uar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"docsend.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944078/; classtype:trojan-activity;sid:84807178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944077)"; flow:established,from_client; content:"GET"; http_method; content:"/alex3430/pecky777/peckycloner.py"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944077/; classtype:trojan-activity;sid:84807177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944076)"; flow:established,from_client; content:"GET"; http_method; content:"/b2f628/cronb.sh"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"b.clu-e.eu"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944076/; classtype:trojan-activity;sid:84807176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944075)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1521843051192909974/1557082337735475301/bundle.zip|3f|ex=6ac6816e|7c|26|7c|is=6ac52fee|7c|26|7c|hm=50797e9782aac04b40538d9ee9d26c6295597c9db1eb374572ffddf733d329bd|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944075/; classtype:trojan-activity;sid:84807175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944074)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.9.200.156"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944074/; classtype:trojan-activity;sid:84807174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944073)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.146.92.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944073/; classtype:trojan-activity;sid:84807173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944072)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.194.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944072/; classtype:trojan-activity;sid:84807172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944071)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.187.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944071/; classtype:trojan-activity;sid:84807171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944070)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.118.189.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944070/; classtype:trojan-activity;sid:84807170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944067)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.97.100.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944067/; classtype:trojan-activity;sid:84807167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944068)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.187.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944068/; classtype:trojan-activity;sid:84807168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944069)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.88.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944069/; classtype:trojan-activity;sid:84807169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944065)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.98.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944065/; classtype:trojan-activity;sid:84807165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944066)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.146.92.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944066/; classtype:trojan-activity;sid:84807166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944064)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.161.250.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944064/; classtype:trojan-activity;sid:84807164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944061)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.37.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944061/; classtype:trojan-activity;sid:84807161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944062)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.137.200.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944062/; classtype:trojan-activity;sid:84807162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944063)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.194.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944063/; classtype:trojan-activity;sid:84807163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944058)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.238.224"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944058/; classtype:trojan-activity;sid:84807158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944059)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.192.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944059/; classtype:trojan-activity;sid:84807159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944060)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.37.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944060/; classtype:trojan-activity;sid:84807160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944057)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944057/; classtype:trojan-activity;sid:84807157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944056)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.173.2.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944056/; classtype:trojan-activity;sid:84807156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944054)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.71.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944054/; classtype:trojan-activity;sid:84807154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944055)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.105.180"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944055/; classtype:trojan-activity;sid:84807155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944053)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"194.26.220.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944053/; classtype:trojan-activity;sid:84807153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944052)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944052/; classtype:trojan-activity;sid:84807152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944050)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.46.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944050/; classtype:trojan-activity;sid:84807150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944051)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.12.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944051/; classtype:trojan-activity;sid:84807151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944049)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.210.7.195"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944049/; classtype:trojan-activity;sid:84807149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944048)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.77.172.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944048/; classtype:trojan-activity;sid:84807148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944047)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.98.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944047/; classtype:trojan-activity;sid:84807147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944046)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.246.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944046/; classtype:trojan-activity;sid:84807146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944045)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.213.86.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944045/; classtype:trojan-activity;sid:84807145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944044)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.155"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944044/; classtype:trojan-activity;sid:84807144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944043)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.130.203.216"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944043/; classtype:trojan-activity;sid:84807143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944041)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.239.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944041/; classtype:trojan-activity;sid:84807141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944042)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.253.155.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944042/; classtype:trojan-activity;sid:84807142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944039)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.190.84.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944039/; classtype:trojan-activity;sid:84807139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944040)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944040/; classtype:trojan-activity;sid:84807140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944038)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.68.95.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944038/; classtype:trojan-activity;sid:84807138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944037)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.234.233.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944037/; classtype:trojan-activity;sid:84807137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944036)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.145.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944036/; classtype:trojan-activity;sid:84807136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944032)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.190.84.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944032/; classtype:trojan-activity;sid:84807132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944033)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.177.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944033/; classtype:trojan-activity;sid:84807133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944034)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.223.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944034/; classtype:trojan-activity;sid:84807134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944035)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.79.138.192"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944035/; classtype:trojan-activity;sid:84807135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944031)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.84.133.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944031/; classtype:trojan-activity;sid:84807131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944030)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"165.98.243.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944030/; classtype:trojan-activity;sid:84807130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944028)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.235.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944028/; classtype:trojan-activity;sid:84807128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944029)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.148.143.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944029/; classtype:trojan-activity;sid:84807129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944027)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.200.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944027/; classtype:trojan-activity;sid:84807127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944026)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.185.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944026/; classtype:trojan-activity;sid:84807126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944025)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.47.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944025/; classtype:trojan-activity;sid:84807125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944024)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.111.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944024/; classtype:trojan-activity;sid:84807124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944023)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.70.76"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944023/; classtype:trojan-activity;sid:84807123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944019)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.217.57.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944019/; classtype:trojan-activity;sid:84807119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944020)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.221.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944020/; classtype:trojan-activity;sid:84807120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944021)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.55.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944021/; classtype:trojan-activity;sid:84807121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944022)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.210.7.195"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944022/; classtype:trojan-activity;sid:84807122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944018)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.111.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944018/; classtype:trojan-activity;sid:84807118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944017)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.247.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944017/; classtype:trojan-activity;sid:84807117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944016)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.187.230.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944016/; classtype:trojan-activity;sid:84807116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944014)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.161.1.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944014/; classtype:trojan-activity;sid:84807114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944015)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.139.237"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944015/; classtype:trojan-activity;sid:84807115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944012)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"108.170.136.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944012/; classtype:trojan-activity;sid:84807112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944013)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.47.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944013/; classtype:trojan-activity;sid:84807113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944011)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.198.173"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944011/; classtype:trojan-activity;sid:84807111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944010)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.200.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944010/; classtype:trojan-activity;sid:84807110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944006)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.217.57.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944006/; classtype:trojan-activity;sid:84807106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944007)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.94.199"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944007/; classtype:trojan-activity;sid:84807107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944008)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.55.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944008/; classtype:trojan-activity;sid:84807108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944009)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.106.111.244"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944009/; classtype:trojan-activity;sid:84807109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944004)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.114.34.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944004/; classtype:trojan-activity;sid:84807104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944005)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.26.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944005/; classtype:trojan-activity;sid:84807105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944003)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.247.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944003/; classtype:trojan-activity;sid:84807103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944001)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.198.173"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944001/; classtype:trojan-activity;sid:84807101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944002)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.126.199"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944002/; classtype:trojan-activity;sid:84807102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3944000)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.159.44"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3944000/; classtype:trojan-activity;sid:84807100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943998)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.85.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943998/; classtype:trojan-activity;sid:84807098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943999)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.177.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943999/; classtype:trojan-activity;sid:84807099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943997)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.254.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943997/; classtype:trojan-activity;sid:84807097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943996)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943996/; classtype:trojan-activity;sid:84807096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943994)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.57.226.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943994/; classtype:trojan-activity;sid:84807094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943995)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.254.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943995/; classtype:trojan-activity;sid:84807095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943993)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.148.148.31"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943993/; classtype:trojan-activity;sid:84807093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943992)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.16.135.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943992/; classtype:trojan-activity;sid:84807092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943987)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.56.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943987/; classtype:trojan-activity;sid:84807087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943988)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.122.53"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943988/; classtype:trojan-activity;sid:84807088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943989)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.231.230.20"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943989/; classtype:trojan-activity;sid:84807089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943990)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.239.56.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943990/; classtype:trojan-activity;sid:84807090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943991)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.34.124.22"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943991/; classtype:trojan-activity;sid:84807091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943985)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.169.0"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943985/; classtype:trojan-activity;sid:84807085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943986)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_07; reference:url, urlhaus.abuse.ch/url/3943986/; classtype:trojan-activity;sid:84807086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943984)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.59.88.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943984/; classtype:trojan-activity;sid:84807084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943982)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.235.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943982/; classtype:trojan-activity;sid:84807082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943983)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"187.62.243.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943983/; classtype:trojan-activity;sid:84807083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943979)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"78.188.196.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943979/; classtype:trojan-activity;sid:84807079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943980)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.188.196.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943980/; classtype:trojan-activity;sid:84807080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943981)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.169.0"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943981/; classtype:trojan-activity;sid:84807081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943978)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.225.105.182"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943978/; classtype:trojan-activity;sid:84807078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943977)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.163.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943977/; classtype:trojan-activity;sid:84807077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943976)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.89.156.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943976/; classtype:trojan-activity;sid:84807076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943974)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.88.191"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943974/; classtype:trojan-activity;sid:84807074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943975)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.56.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943975/; classtype:trojan-activity;sid:84807075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943971)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"92.42.134.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943971/; classtype:trojan-activity;sid:84807071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943972)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.13.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943972/; classtype:trojan-activity;sid:84807072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943973)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.139.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943973/; classtype:trojan-activity;sid:84807073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943969)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.30.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943969/; classtype:trojan-activity;sid:84807069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943970)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.51.139.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943970/; classtype:trojan-activity;sid:84807070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943968)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.234.163.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943968/; classtype:trojan-activity;sid:84807068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943967)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.170.183"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943967/; classtype:trojan-activity;sid:84807067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943965)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.131.92.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943965/; classtype:trojan-activity;sid:84807065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943966)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.167.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943966/; classtype:trojan-activity;sid:84807066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943964)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.16.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943964/; classtype:trojan-activity;sid:84807064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943963)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.111.23.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943963/; classtype:trojan-activity;sid:84807063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943961)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.254.148"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943961/; classtype:trojan-activity;sid:84807061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943962)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.167.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943962/; classtype:trojan-activity;sid:84807062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943960)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.35.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943960/; classtype:trojan-activity;sid:84807060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943959)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.131.92.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943959/; classtype:trojan-activity;sid:84807059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943958)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.253.155.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943958/; classtype:trojan-activity;sid:84807058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943957)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.254.148"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943957/; classtype:trojan-activity;sid:84807057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943956)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.35.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943956/; classtype:trojan-activity;sid:84807056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943955)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.229.80.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943955/; classtype:trojan-activity;sid:84807055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943954)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.233.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943954/; classtype:trojan-activity;sid:84807054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943952)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.170.183"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943952/; classtype:trojan-activity;sid:84807052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943953)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.35.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943953/; classtype:trojan-activity;sid:84807053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943951)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.29.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943951/; classtype:trojan-activity;sid:84807051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943950)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.136.231.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943950/; classtype:trojan-activity;sid:84807050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943949)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.229.80.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943949/; classtype:trojan-activity;sid:84807049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943948)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.102.171"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943948/; classtype:trojan-activity;sid:84807048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943947)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.177.57.76"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943947/; classtype:trojan-activity;sid:84807047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943946)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.77.54"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943946/; classtype:trojan-activity;sid:84807046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943945)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.126.199"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943945/; classtype:trojan-activity;sid:84807045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943941)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.176.8.34"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943941/; classtype:trojan-activity;sid:84807041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943942)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.54.110.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943942/; classtype:trojan-activity;sid:84807042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943943)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.215.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943943/; classtype:trojan-activity;sid:84807043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943944)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.216.143"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943944/; classtype:trojan-activity;sid:84807044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943940)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.97.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943940/; classtype:trojan-activity;sid:84807040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943939)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.94.246.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943939/; classtype:trojan-activity;sid:84807039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943938)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.120.3.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943938/; classtype:trojan-activity;sid:84807038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943937)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.115.102.16"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943937/; classtype:trojan-activity;sid:84807037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943936)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.94.246.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943936/; classtype:trojan-activity;sid:84807036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943935)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.97.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943935/; classtype:trojan-activity;sid:84807035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943934)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.54.108.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943934/; classtype:trojan-activity;sid:84807034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943931)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.90.144.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943931/; classtype:trojan-activity;sid:84807031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943932)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.231.232.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943932/; classtype:trojan-activity;sid:84807032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943933)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"200.115.102.16"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943933/; classtype:trojan-activity;sid:84807033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943930)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.183.184.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943930/; classtype:trojan-activity;sid:84807030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943929)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.90.144.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943929/; classtype:trojan-activity;sid:84807029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943927)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.194.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943927/; classtype:trojan-activity;sid:84807027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943928)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943928/; classtype:trojan-activity;sid:84807028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943926)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943926/; classtype:trojan-activity;sid:84807026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943925)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.16.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943925/; classtype:trojan-activity;sid:84807025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943922)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.0.143"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943922/; classtype:trojan-activity;sid:84807022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943923)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.231.232.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943923/; classtype:trojan-activity;sid:84807023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943924)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.122.53"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943924/; classtype:trojan-activity;sid:84807024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943921)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.162.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943921/; classtype:trojan-activity;sid:84807021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943920)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.223.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943920/; classtype:trojan-activity;sid:84807020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943917)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.200.36"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943917/; classtype:trojan-activity;sid:84807017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943918)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.181.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943918/; classtype:trojan-activity;sid:84807018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943919)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.54.233.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943919/; classtype:trojan-activity;sid:84807019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943916)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.139.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943916/; classtype:trojan-activity;sid:84807016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943915)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.6.167.121"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943915/; classtype:trojan-activity;sid:84807015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943914)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.151.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943914/; classtype:trojan-activity;sid:84807014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943913)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.200.211.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943913/; classtype:trojan-activity;sid:84807013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943912)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.231.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943912/; classtype:trojan-activity;sid:84807012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943910)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.151.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943910/; classtype:trojan-activity;sid:84807010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943911)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.149.147.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943911/; classtype:trojan-activity;sid:84807011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943909)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.237.229.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943909/; classtype:trojan-activity;sid:84807009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943908)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.7.222.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943908/; classtype:trojan-activity;sid:84807008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943907)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.182.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943907/; classtype:trojan-activity;sid:84807007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943906)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"83.228.109.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943906/; classtype:trojan-activity;sid:84807006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943900)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.142.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943900/; classtype:trojan-activity;sid:84807000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943901)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.138.107.166"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943901/; classtype:trojan-activity;sid:84807001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943902)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.131.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943902/; classtype:trojan-activity;sid:84807002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943903)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.131.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943903/; classtype:trojan-activity;sid:84807003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943904)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.138.191.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943904/; classtype:trojan-activity;sid:84807004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943905)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.98.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943905/; classtype:trojan-activity;sid:84807005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943899)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.137.150.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943899/; classtype:trojan-activity;sid:84806999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943898)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.17.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943898/; classtype:trojan-activity;sid:84806998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943897)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.107.166"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943897/; classtype:trojan-activity;sid:84806997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943895)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.31.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943895/; classtype:trojan-activity;sid:84806995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943896)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"66.58.168.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943896/; classtype:trojan-activity;sid:84806996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943893)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.6.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943893/; classtype:trojan-activity;sid:84806993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943894)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.96.229.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943894/; classtype:trojan-activity;sid:84806994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943890)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.142.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943890/; classtype:trojan-activity;sid:84806990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943891)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.12.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943891/; classtype:trojan-activity;sid:84806991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943892)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.137.150.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943892/; classtype:trojan-activity;sid:84806992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943889)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.246.12.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943889/; classtype:trojan-activity;sid:84806989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943886)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.222.45.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943886/; classtype:trojan-activity;sid:84806986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943887)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.21.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943887/; classtype:trojan-activity;sid:84806987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943888)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.226.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943888/; classtype:trojan-activity;sid:84806988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943885)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"84.51.204.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943885/; classtype:trojan-activity;sid:84806985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943884)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.196.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943884/; classtype:trojan-activity;sid:84806984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943883)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.50.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943883/; classtype:trojan-activity;sid:84806983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943882)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.72.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943882/; classtype:trojan-activity;sid:84806982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943881)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.50.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943881/; classtype:trojan-activity;sid:84806981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943877)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.222.45.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943877/; classtype:trojan-activity;sid:84806977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943878)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.89.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943878/; classtype:trojan-activity;sid:84806978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943879)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.12.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943879/; classtype:trojan-activity;sid:84806979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943880)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.21.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943880/; classtype:trojan-activity;sid:84806980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943876)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.240.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943876/; classtype:trojan-activity;sid:84806976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943875)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.148.143.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943875/; classtype:trojan-activity;sid:84806975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943874)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.221.72.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943874/; classtype:trojan-activity;sid:84806974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943873)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943873/; classtype:trojan-activity;sid:84806973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943871)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo3/raw/refs/heads/main/fakepayclient-1.21.11.jar"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943871/; classtype:trojan-activity;sid:84806971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943872)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo3/raw/refs/heads/main/kryptonclient-1.21.11.jar"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943872/; classtype:trojan-activity;sid:84806972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943866)"; flow:established,from_client; content:"GET"; http_method; content:"/ikov.jar"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"ikovrsps.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943866/; classtype:trojan-activity;sid:84806966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943867)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo3/raw/refs/heads/main/xenonclient-1.21.11.jar"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943867/; classtype:trojan-activity;sid:84806967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943868)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.176.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943868/; classtype:trojan-activity;sid:84806968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943869)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo3/raw/refs/heads/main/radiumclient-clients-full.jar"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943869/; classtype:trojan-activity;sid:84806969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943870)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo3/raw/refs/heads/main/dqrkisclient-1.21.11.jar"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943870/; classtype:trojan-activity;sid:84806970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943865)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.246.43.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943865/; classtype:trojan-activity;sid:84806965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943864)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.3.87.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943864/; classtype:trojan-activity;sid:84806964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943863)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"130.12.209.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943863/; classtype:trojan-activity;sid:84806963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943862)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.227.63.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943862/; classtype:trojan-activity;sid:84806962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943861)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943861/; classtype:trojan-activity;sid:84806961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943849)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943849/; classtype:trojan-activity;sid:84806949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943850)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943850/; classtype:trojan-activity;sid:84806950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943851)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943851/; classtype:trojan-activity;sid:84806951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943852)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943852/; classtype:trojan-activity;sid:84806952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943853)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943853/; classtype:trojan-activity;sid:84806953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943854)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.arm8"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943854/; classtype:trojan-activity;sid:84806954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943855)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943855/; classtype:trojan-activity;sid:84806955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943856)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943856/; classtype:trojan-activity;sid:84806956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943857)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.ppc64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943857/; classtype:trojan-activity;sid:84806957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943858)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943858/; classtype:trojan-activity;sid:84806958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943859)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.mipsel"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943859/; classtype:trojan-activity;sid:84806959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943860)"; flow:established,from_client; content:"GET"; http_method; content:"/flutter.debug"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943860/; classtype:trojan-activity;sid:84806960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943848)"; flow:established,from_client; content:"GET"; http_method; content:"/dl.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943848/; classtype:trojan-activity;sid:84806948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943847)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943847/; classtype:trojan-activity;sid:84806947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943846)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/spc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943846/; classtype:trojan-activity;sid:84806946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943841)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943841/; classtype:trojan-activity;sid:84806941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943842)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943842/; classtype:trojan-activity;sid:84806942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943843)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943843/; classtype:trojan-activity;sid:84806943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943844)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943844/; classtype:trojan-activity;sid:84806944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943845)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943845/; classtype:trojan-activity;sid:84806945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943834)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943834/; classtype:trojan-activity;sid:84806934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943835)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943835/; classtype:trojan-activity;sid:84806935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943836)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943836/; classtype:trojan-activity;sid:84806936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943837)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943837/; classtype:trojan-activity;sid:84806937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943838)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64le"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943838/; classtype:trojan-activity;sid:84806938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943839)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943839/; classtype:trojan-activity;sid:84806939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943840)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64le"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943840/; classtype:trojan-activity;sid:84806940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943833)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"77.90.57.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943833/; classtype:trojan-activity;sid:84806933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943832)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943832/; classtype:trojan-activity;sid:84806932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943831)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.117.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943831/; classtype:trojan-activity;sid:84806931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943830)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"80.67.33.209"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943830/; classtype:trojan-activity;sid:84806930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943828)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"77.90.57.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943828/; classtype:trojan-activity;sid:84806928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943829)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"77.90.57.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943829/; classtype:trojan-activity;sid:84806929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943827)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv5l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943827/; classtype:trojan-activity;sid:84806927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943823)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943823/; classtype:trojan-activity;sid:84806923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943824)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv6l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943824/; classtype:trojan-activity;sid:84806924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943825)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943825/; classtype:trojan-activity;sid:84806925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943826)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943826/; classtype:trojan-activity;sid:84806926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943816)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.powerpc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943816/; classtype:trojan-activity;sid:84806916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943817)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943817/; classtype:trojan-activity;sid:84806917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943818)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943818/; classtype:trojan-activity;sid:84806918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943819)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943819/; classtype:trojan-activity;sid:84806919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943820)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sparc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943820/; classtype:trojan-activity;sid:84806920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943821)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv4l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943821/; classtype:trojan-activity;sid:84806921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943822)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsrouter"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943822/; classtype:trojan-activity;sid:84806922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943813)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv7l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943813/; classtype:trojan-activity;sid:84806913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943814)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943814/; classtype:trojan-activity;sid:84806914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943815)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943815/; classtype:trojan-activity;sid:84806915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943811)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.arc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943811/; classtype:trojan-activity;sid:84806911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943812)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943812/; classtype:trojan-activity;sid:84806912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943808)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943808/; classtype:trojan-activity;sid:84806908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943809)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943809/; classtype:trojan-activity;sid:84806909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943810)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.i486"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943810/; classtype:trojan-activity;sid:84806910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943807)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"79.106.231.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943807/; classtype:trojan-activity;sid:84806907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943806)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.43.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943806/; classtype:trojan-activity;sid:84806906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943805)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.105.180"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943805/; classtype:trojan-activity;sid:84806905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943801)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.4.214"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943801/; classtype:trojan-activity;sid:84806901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943802)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.20.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943802/; classtype:trojan-activity;sid:84806902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943803)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.115.161.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943803/; classtype:trojan-activity;sid:84806903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943804)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.177.251.31"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943804/; classtype:trojan-activity;sid:84806904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943800)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.187.91.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943800/; classtype:trojan-activity;sid:84806900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943798)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.194.101.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943798/; classtype:trojan-activity;sid:84806898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943799)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"77.90.57.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943799/; classtype:trojan-activity;sid:84806899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943793)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mpsl"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943793/; classtype:trojan-activity;sid:84806893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943794)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.sparc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943794/; classtype:trojan-activity;sid:84806894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943795)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mips"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943795/; classtype:trojan-activity;sid:84806895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943796)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943796/; classtype:trojan-activity;sid:84806896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943797)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.ppc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943797/; classtype:trojan-activity;sid:84806897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943792)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.sh4"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943792/; classtype:trojan-activity;sid:84806892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943787)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943787/; classtype:trojan-activity;sid:84806887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943788)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm5"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943788/; classtype:trojan-activity;sid:84806888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943789)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.m68k"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943789/; classtype:trojan-activity;sid:84806889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943790)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mips64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943790/; classtype:trojan-activity;sid:84806890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943791)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm7"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943791/; classtype:trojan-activity;sid:84806891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943786)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mpsl"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"77.90.57.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943786/; classtype:trojan-activity;sid:84806886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943785)"; flow:established,from_client; content:"GET"; http_method; content:"/download|3f|id=1zntk1iihb4tc_tnggamwtys_obebz9xv|7c|26|7c|export=download"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"drive.usercontent.google.com"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943785/; classtype:trojan-activity;sid:84806885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943784)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"157.66.146.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943784/; classtype:trojan-activity;sid:84806884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943783)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.177.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943783/; classtype:trojan-activity;sid:84806883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943782)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.4.214"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943782/; classtype:trojan-activity;sid:84806882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943781)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.190.133"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943781/; classtype:trojan-activity;sid:84806881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943780)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.195.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943780/; classtype:trojan-activity;sid:84806880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943779)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.190.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943779/; classtype:trojan-activity;sid:84806879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943777)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.98.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943777/; classtype:trojan-activity;sid:84806877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943778)"; flow:established,from_client; content:"GET"; http_method; content:"/bot"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"77.90.57.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943778/; classtype:trojan-activity;sid:84806878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943776)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.74.47.172"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943776/; classtype:trojan-activity;sid:84806876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943775)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.9.197.209"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943775/; classtype:trojan-activity;sid:84806875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943774)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/i4frru67ve46dbh42gxke/docsend.exe|3f|rlkey=385ywqxitj0l3g5yhfsecvoke|7c|26|7c|st=8a337sm5|7c|26|7c|dl=1"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943774/; classtype:trojan-activity;sid:84806874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943773)"; flow:established,from_client; content:"GET"; http_method; content:"/hibituninstaller-setup-4.0.10.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"pub-6a90252f6d70443d960d6ac029dbd446.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943773/; classtype:trojan-activity;sid:84806873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943772)"; flow:established,from_client; content:"GET"; http_method; content:"/miners/srbminer-3.5.6.zip"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"pub-ecb7161ffc7a4a67bdd8761583e21d16.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943772/; classtype:trojan-activity;sid:84806872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943770)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943770/; classtype:trojan-activity;sid:84806870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943771)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.227.63.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943771/; classtype:trojan-activity;sid:84806871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943769)"; flow:established,from_client; content:"GET"; http_method; content:"/s/n1w4p8gc6jzo0sg/supdate.ini"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943769/; classtype:trojan-activity;sid:84806869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943766)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.82.252"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943766/; classtype:trojan-activity;sid:84806866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943767)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.24.87.31"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943767/; classtype:trojan-activity;sid:84806867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943768)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.25"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943768/; classtype:trojan-activity;sid:84806868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943765)"; flow:established,from_client; content:"GET"; http_method; content:"/s/zhp1b06imehwylq/synaptics.rar"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943765/; classtype:trojan-activity;sid:84806865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943764)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.6.167.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943764/; classtype:trojan-activity;sid:84806864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943763)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.9.197.209"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943763/; classtype:trojan-activity;sid:84806863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943762)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.213.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943762/; classtype:trojan-activity;sid:84806862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943761)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.24.87.31"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943761/; classtype:trojan-activity;sid:84806861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943760)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.189.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943760/; classtype:trojan-activity;sid:84806860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943759)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943759/; classtype:trojan-activity;sid:84806859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943758)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.82.252"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943758/; classtype:trojan-activity;sid:84806858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943757)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.6.167.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943757/; classtype:trojan-activity;sid:84806857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943756)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.145.25"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943756/; classtype:trojan-activity;sid:84806856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943755)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.157.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943755/; classtype:trojan-activity;sid:84806855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943754)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.77.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943754/; classtype:trojan-activity;sid:84806854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943753)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.117.76.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943753/; classtype:trojan-activity;sid:84806853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943751)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.253.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943751/; classtype:trojan-activity;sid:84806851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943752)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.i686"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943752/; classtype:trojan-activity;sid:84806852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943750)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.144.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943750/; classtype:trojan-activity;sid:84806850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943749)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.0.143"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943749/; classtype:trojan-activity;sid:84806849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943748)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.29.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943748/; classtype:trojan-activity;sid:84806848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943747)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.117.76.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943747/; classtype:trojan-activity;sid:84806847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943743)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.109.227.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943743/; classtype:trojan-activity;sid:84806843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943744)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.x86_64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943744/; classtype:trojan-activity;sid:84806844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943745)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.x86"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943745/; classtype:trojan-activity;sid:84806845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943746)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.88.136.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943746/; classtype:trojan-activity;sid:84806846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943742)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.130.235.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943742/; classtype:trojan-activity;sid:84806842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943741)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.146.156"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943741/; classtype:trojan-activity;sid:84806841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943739)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.76.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943739/; classtype:trojan-activity;sid:84806839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943740)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.99.253"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943740/; classtype:trojan-activity;sid:84806840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943737)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.38.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943737/; classtype:trojan-activity;sid:84806837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943738)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"145.236.202.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943738/; classtype:trojan-activity;sid:84806838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943736)"; flow:established,from_client; content:"GET"; http_method; content:"/lnvoice/screenconnect.clientsetup.msi"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"omskin.org"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943736/; classtype:trojan-activity;sid:84806836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943734)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.231.230.20"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943734/; classtype:trojan-activity;sid:84806834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943735)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.38.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943735/; classtype:trojan-activity;sid:84806835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943731)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.195.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943731/; classtype:trojan-activity;sid:84806831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943732)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.40.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943732/; classtype:trojan-activity;sid:84806832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943733)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.190.195.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943733/; classtype:trojan-activity;sid:84806833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943730)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.187.91.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943730/; classtype:trojan-activity;sid:84806830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943729)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/5f11m34f13trts6jj7rhi/matefall-nstaller-setup-1.0.0.exe|3f|rlkey=fzctb8qe415ql6i8njxhy55c0|7c|26|7c|st=6u4vagho|7c|26|7c|dl=1"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943729/; classtype:trojan-activity;sid:84806829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943728)"; flow:established,from_client; content:"GET"; http_method; content:"/download.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"alotic.net"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943728/; classtype:trojan-activity;sid:84806828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943726)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943726/; classtype:trojan-activity;sid:84806826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943727)"; flow:established,from_client; content:"GET"; http_method; content:"/1.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"139.162.5.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943727/; classtype:trojan-activity;sid:84806827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943725)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.139.36.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943725/; classtype:trojan-activity;sid:84806825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943724)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.237.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943724/; classtype:trojan-activity;sid:84806824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943723)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.151.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943723/; classtype:trojan-activity;sid:84806823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943722)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.172.82.253"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943722/; classtype:trojan-activity;sid:84806822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943721)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.86.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943721/; classtype:trojan-activity;sid:84806821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943719)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943719/; classtype:trojan-activity;sid:84806819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943720)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.220.121.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943720/; classtype:trojan-activity;sid:84806820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943718)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"111.88.7.48"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943718/; classtype:trojan-activity;sid:84806818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943717)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.53.100.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943717/; classtype:trojan-activity;sid:84806817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943715)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.139.36.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943715/; classtype:trojan-activity;sid:84806815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943716)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.1.110.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943716/; classtype:trojan-activity;sid:84806816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943713)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.34.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943713/; classtype:trojan-activity;sid:84806813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943714)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.118.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943714/; classtype:trojan-activity;sid:84806814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943711)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.61.118.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943711/; classtype:trojan-activity;sid:84806811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943712)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.47.76"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943712/; classtype:trojan-activity;sid:84806812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943710)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.216.227.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943710/; classtype:trojan-activity;sid:84806810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943709)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.34.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943709/; classtype:trojan-activity;sid:84806809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943707)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"106.40.243.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943707/; classtype:trojan-activity;sid:84806807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943708)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.28.97.96"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943708/; classtype:trojan-activity;sid:84806808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943706)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.51.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943706/; classtype:trojan-activity;sid:84806806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943705)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.47.76"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943705/; classtype:trojan-activity;sid:84806805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943703)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.211.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943703/; classtype:trojan-activity;sid:84806803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943704)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.228.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943704/; classtype:trojan-activity;sid:84806804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943702)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.82.203.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943702/; classtype:trojan-activity;sid:84806802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943701)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.243.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943701/; classtype:trojan-activity;sid:84806801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943699)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.221.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943699/; classtype:trojan-activity;sid:84806799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943700)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.176.8.34"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943700/; classtype:trojan-activity;sid:84806800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943698)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"212.50.57.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943698/; classtype:trojan-activity;sid:84806798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943697)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.140.4.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943697/; classtype:trojan-activity;sid:84806797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943696)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.155.228.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943696/; classtype:trojan-activity;sid:84806796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943693)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.77.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943693/; classtype:trojan-activity;sid:84806793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943694)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943694/; classtype:trojan-activity;sid:84806794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943695)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.211.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943695/; classtype:trojan-activity;sid:84806795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943692)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.99.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943692/; classtype:trojan-activity;sid:84806792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943690)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.92.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943690/; classtype:trojan-activity;sid:84806790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943691)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.161.116.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943691/; classtype:trojan-activity;sid:84806791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943689)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.8.26.165"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943689/; classtype:trojan-activity;sid:84806789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943688)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.235.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943688/; classtype:trojan-activity;sid:84806788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943687)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.30.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943687/; classtype:trojan-activity;sid:84806787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943686)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"1.57.109.163"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943686/; classtype:trojan-activity;sid:84806786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943685)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.55.115.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943685/; classtype:trojan-activity;sid:84806785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943684)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.30.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943684/; classtype:trojan-activity;sid:84806784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943683)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.161.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943683/; classtype:trojan-activity;sid:84806783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943679)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.47.92.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943679/; classtype:trojan-activity;sid:84806779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943680)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.53.98.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943680/; classtype:trojan-activity;sid:84806780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943681)"; flow:established,from_client; content:"GET"; http_method; content:"/the-vishal-gupta/question_answering-_system/main/saasenv/include/site/python3.12/greenlet/system_question_answering_v2.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943681/; classtype:trojan-activity;sid:84806781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943682)"; flow:established,from_client; content:"GET"; http_method; content:"/jts36/languagemodel/main/alphabetist/model-language-v2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943682/; classtype:trojan-activity;sid:84806782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943678)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.77.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943678/; classtype:trojan-activity;sid:84806778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943672)"; flow:established,from_client; content:"GET"; http_method; content:"/sam1032/rust-macro-magic/raw/refs/heads/branch/coprojector/macro-rust-magic-v3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943672/; classtype:trojan-activity;sid:84806772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943673)"; flow:established,from_client; content:"GET"; http_method; content:"/aman29100/gpt-awesome-list-generator/raw/refs/heads/main/section_data_pipelines/list-awesome-generator-gp-v2.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943673/; classtype:trojan-activity;sid:84806773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943674)"; flow:established,from_client; content:"GET"; http_method; content:"/oliverquaye23/ai-directories/main/pholadacea/ai_directories_3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943674/; classtype:trojan-activity;sid:84806774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943675)"; flow:established,from_client; content:"GET"; http_method; content:"/palauzera/online-product-shop/main/src/main/online_shop_product_v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943675/; classtype:trojan-activity;sid:84806775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943676)"; flow:established,from_client; content:"GET"; http_method; content:"/spidy57/tools-void57/main/vulnerability-scanner/void-tools-2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943676/; classtype:trojan-activity;sid:84806776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943677)"; flow:established,from_client; content:"GET"; http_method; content:"/southla/supervised_learning/main/fiedlerite/supervised-learning-2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943677/; classtype:trojan-activity;sid:84806777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943667)"; flow:established,from_client; content:"GET"; http_method; content:"/dwifiqkri/pert5/main/galactoma/pert5.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943667/; classtype:trojan-activity;sid:84806767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943668)"; flow:established,from_client; content:"GET"; http_method; content:"/amoosghori/employeenodejs/raw/refs/heads/master/node_modules/yargs-parser/software-hubbly.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943668/; classtype:trojan-activity;sid:84806768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943669)"; flow:established,from_client; content:"GET"; http_method; content:"/pankaj376/autoniche-intelligence-engine/raw/refs/heads/main/automation/niche_engine_auto_intelligence_2.0.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943669/; classtype:trojan-activity;sid:84806769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943670)"; flow:established,from_client; content:"GET"; http_method; content:"/tarique775/uptime-monitoring-api-raw-nodejs/raw/refs/heads/main/.data/tokendata/api-monitoring-nodejs-raw-uptime-v3.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943670/; classtype:trojan-activity;sid:84806770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943671)"; flow:established,from_client; content:"GET"; http_method; content:"/vikodevik/focuscli/raw/refs/heads/main/focuscli/software_3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943671/; classtype:trojan-activity;sid:84806771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943662)"; flow:established,from_client; content:"GET"; http_method; content:"/bvnahush/term-lens-ai/main/web-client/ai_ter_len_v2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943662/; classtype:trojan-activity;sid:84806762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943663)"; flow:established,from_client; content:"GET"; http_method; content:"/kiran03-jagadeesh/es6-javascript-assignment/main/fitted/assignment_javascript_e_3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943663/; classtype:trojan-activity;sid:84806763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943664)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/javascript-test-solutions/raw/refs/heads/master/untunefully/test_script_java_solutions_2.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943664/; classtype:trojan-activity;sid:84806764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943665)"; flow:established,from_client; content:"GET"; http_method; content:"/rainesalvo/valtheria-lisence-system/main/bethrall/system_lisence_valtheria_1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943665/; classtype:trojan-activity;sid:84806765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943666)"; flow:established,from_client; content:"GET"; http_method; content:"/demogrito/docex/raw/refs/heads/main/disordexf/doc-ex-3.9-beta.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943666/; classtype:trojan-activity;sid:84806766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943660)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamlandsr/project/raw/refs/heads/main/public/vendors/typeahead.js/software_1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943660/; classtype:trojan-activity;sid:84806760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943661)"; flow:established,from_client; content:"GET"; http_method; content:"/catsoft321/chatdotnetus/releases/download/v1.0/release_x64.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943661/; classtype:trojan-activity;sid:84806761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943659)"; flow:established,from_client; content:"GET"; http_method; content:"/4feds/3d-portfolio/raw/refs/heads/main/src/components/models/d-portfolio-v3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943659/; classtype:trojan-activity;sid:84806759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943655)"; flow:established,from_client; content:"GET"; http_method; content:"/slepj/quiz-master-app-v1/main/instance/quiz_master_app_v3.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943655/; classtype:trojan-activity;sid:84806755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943656)"; flow:established,from_client; content:"GET"; http_method; content:"/itachiabimem/alpha/raw/refs/heads/main/testation/software-3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943656/; classtype:trojan-activity;sid:84806756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943657)"; flow:established,from_client; content:"GET"; http_method; content:"/henrybrewer/snu_2d_clouddrive_modes/main/nondyspeptic/cloud-drive-modes-sn-3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943657/; classtype:trojan-activity;sid:84806757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943658)"; flow:established,from_client; content:"GET"; http_method; content:"/tarakqovsu7/roblox-ronix/master/postrectal/roblox_ronix_2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943658/; classtype:trojan-activity;sid:84806758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943653)"; flow:established,from_client; content:"GET"; http_method; content:"/eslam-mohammed-saeed/survivalmod-tool/raw/refs/heads/main/glueyness/tool-survival-mod-v2.0-alpha.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943653/; classtype:trojan-activity;sid:84806753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943654)"; flow:established,from_client; content:"GET"; http_method; content:"/jones0chikwezga/usermanagement/main/src/models/software_tillodontidae.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943654/; classtype:trojan-activity;sid:84806754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943652)"; flow:established,from_client; content:"GET"; http_method; content:"/yamanl/ai-its-applications/main/pneumopyothorax/its-a-applications-2.9-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943652/; classtype:trojan-activity;sid:84806752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943646)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.21.24.136"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943646/; classtype:trojan-activity;sid:84806746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943647)"; flow:established,from_client; content:"GET"; http_method; content:"/yamaday88/gallery-of-lattice-boltzmann-code/raw/refs/heads/master/unmathematical/gallery_boltzmann_lattice_code_of_v2.8.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943647/; classtype:trojan-activity;sid:84806747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943648)"; flow:established,from_client; content:"GET"; http_method; content:"/shahriarrafi/petrichor-environment-testing/raw/refs/heads/main/components/petrichor-environment-testing-ultraenforcement.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943648/; classtype:trojan-activity;sid:84806748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943649)"; flow:established,from_client; content:"GET"; http_method; content:"/theclaverone/thelastyear/raw/refs/heads/main/public/last_year_the_2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943649/; classtype:trojan-activity;sid:84806749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943650)"; flow:established,from_client; content:"GET"; http_method; content:"/balamahesh7204/balamahesh7204/raw/refs/heads/main/ortalis/balamahesh-3.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943650/; classtype:trojan-activity;sid:84806750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943651)"; flow:established,from_client; content:"GET"; http_method; content:"/andreaignazio/notemanager/raw/refs/heads/main/frontend/src/stores/note_manager_2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943651/; classtype:trojan-activity;sid:84806751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943640)"; flow:established,from_client; content:"GET"; http_method; content:"/iftekharul01/trackersheet/main/web/software_1.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943640/; classtype:trojan-activity;sid:84806740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943641)"; flow:established,from_client; content:"GET"; http_method; content:"/elnatnael/alx_travel_app_0x02/raw/refs/heads/main/alx_travel_app/listings/travel-x-app-alx-v3.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943641/; classtype:trojan-activity;sid:84806741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943642)"; flow:established,from_client; content:"GET"; http_method; content:"/vinit77-op/electronics-store/master/store/store_electronics_v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943642/; classtype:trojan-activity;sid:84806742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943643)"; flow:established,from_client; content:"GET"; http_method; content:"/prasdionaditya/adpl-kelompok-6.1-6.2/main/bootstrap/cache/kelompok_adpl_v1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943643/; classtype:trojan-activity;sid:84806743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943644)"; flow:established,from_client; content:"GET"; http_method; content:"/venkateshpalagurla/cyberkit/main/tools/kit-cyber-3.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943644/; classtype:trojan-activity;sid:84806744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943645)"; flow:established,from_client; content:"GET"; http_method; content:"/dhazx95/clairobscurexpedition33-hacklab/main/miryachit/expedition_clair_lab_hack_obscur_2.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943645/; classtype:trojan-activity;sid:84806745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943637)"; flow:established,from_client; content:"GET"; http_method; content:"/usen99/esp32_ble_arduino/master/examples/ble_write/es_bl_arduino_v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943637/; classtype:trojan-activity;sid:84806737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943638)"; flow:established,from_client; content:"GET"; http_method; content:"/yoniespaa/pizzafrontend/master/src/app/home/pizza-end-front-3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943638/; classtype:trojan-activity;sid:84806738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943639)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/research-project-approval-part-1/master/static/approval_part_research_project_v1.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943639/; classtype:trojan-activity;sid:84806739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943634)"; flow:established,from_client; content:"GET"; http_method; content:"/carlrevive/syntecxhub_project_name/main/statuarist/name-syntecxhub-project-3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943634/; classtype:trojan-activity;sid:84806734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943635)"; flow:established,from_client; content:"GET"; http_method; content:"/rmnask2/chatterly-jwt-secured-realtime-communication-engine/raw/refs/heads/main/backend/src/routes/secured_jw_communication_engine_realtime_chatterly_v3.6.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943635/; classtype:trojan-activity;sid:84806735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943636)"; flow:established,from_client; content:"GET"; http_method; content:"/glakshya20/login_project/raw/refs/heads/main/natr/project_login_2.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943636/; classtype:trojan-activity;sid:84806736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943633)"; flow:established,from_client; content:"GET"; http_method; content:"/rajesh-1984/unireal/main/data_construct/subject_customization/training/assets/real-uni-v2.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943633/; classtype:trojan-activity;sid:84806733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943630)"; flow:established,from_client; content:"GET"; http_method; content:"/razvan777/atlyss-cheats/raw/refs/heads/main/prediscontented/atlyss-cheats-2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943630/; classtype:trojan-activity;sid:84806730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943631)"; flow:established,from_client; content:"GET"; http_method; content:"/jones0chikwezga/currency_converter_app/main/ios/runner/assets.xcassets/appicon.appiconset/currency-converter-app-leadable.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943631/; classtype:trojan-activity;sid:84806731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943632)"; flow:established,from_client; content:"GET"; http_method; content:"/vitao2222/nexa-music/main/twentymo/nexa-music.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943632/; classtype:trojan-activity;sid:84806732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943624)"; flow:established,from_client; content:"GET"; http_method; content:"/duduzin2301/growfit/main/lohana/fit_grow_v3.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943624/; classtype:trojan-activity;sid:84806724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943625)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/child-care-hospital-product-analysis/main/src/components/about/analysis-hospital-child-product-care-v1.7.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943625/; classtype:trojan-activity;sid:84806725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943626)"; flow:established,from_client; content:"GET"; http_method; content:"/kfirm1208/kfirm1208/raw/refs/heads/main/clepsine/kfirm-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943626/; classtype:trojan-activity;sid:84806726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943627)"; flow:established,from_client; content:"GET"; http_method; content:"/cavhd2/synthron-cfd-trader-pro/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943627/; classtype:trojan-activity;sid:84806727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943628)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/flutter_new_app/main/herbarism/flutter_new_app.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943628/; classtype:trojan-activity;sid:84806728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943629)"; flow:established,from_client; content:"GET"; http_method; content:"/binkeinsweater/kimi/main/ommateal/software-1.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943629/; classtype:trojan-activity;sid:84806729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943623)"; flow:established,from_client; content:"GET"; http_method; content:"/toniepiter/edius-grass-valley-premium-unlock/raw/refs/heads/branch/sphaeridial/premium-unlock-valley-edius-grass-v1.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943623/; classtype:trojan-activity;sid:84806723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943619)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"1.57.109.163"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943619/; classtype:trojan-activity;sid:84806719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943620)"; flow:established,from_client; content:"GET"; http_method; content:"/mnd35/devtest.github.io/main/docs/github-io-devtest-v2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943620/; classtype:trojan-activity;sid:84806720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943621)"; flow:established,from_client; content:"GET"; http_method; content:"/roynaldo1234/my.github.io/raw/refs/heads/master/images/my-io-github-v3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943621/; classtype:trojan-activity;sid:84806721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943622)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/moto-parts-client-side/raw/refs/heads/main/src/side-moto-client-parts-v2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943622/; classtype:trojan-activity;sid:84806722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943615)"; flow:established,from_client; content:"GET"; http_method; content:"/haffou/review-app/main/public/img/review_app_1.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943615/; classtype:trojan-activity;sid:84806715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943616)"; flow:established,from_client; content:"GET"; http_method; content:"/beginnerdevvn/celery-task-queue-latest-2025/main/folksiness/queue-latest-task-celery-2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943616/; classtype:trojan-activity;sid:84806716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943617)"; flow:established,from_client; content:"GET"; http_method; content:"/suman1214129/r-project-06/raw/refs/heads/main/src/app/profile/projec_v1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943617/; classtype:trojan-activity;sid:84806717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943618)"; flow:established,from_client; content:"GET"; http_method; content:"/chirikikuto/music-theory/main/pneumography/music_theory_3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943618/; classtype:trojan-activity;sid:84806718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943611)"; flow:established,from_client; content:"GET"; http_method; content:"/megog/code-mart/main/apps/billing/mart_code_3.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943611/; classtype:trojan-activity;sid:84806711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943612)"; flow:established,from_client; content:"GET"; http_method; content:"/whotz1320/communication-protocols-with-pic16f877a/master/images/f-a-pic-with-protocols-communication-v3.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943612/; classtype:trojan-activity;sid:84806712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943613)"; flow:established,from_client; content:"GET"; http_method; content:"/purelmnz/cloud-admin-proj/raw/refs/heads/main/aspergillin/admin_proj_cloud_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943613/; classtype:trojan-activity;sid:84806713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943614)"; flow:established,from_client; content:"GET"; http_method; content:"/joe826-studio/linkedin-sales-automation-suite/raw/refs/heads/main/antifelony/in-suite-sales-automation-linked-v2.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943614/; classtype:trojan-activity;sid:84806714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943609)"; flow:established,from_client; content:"GET"; http_method; content:"/peterodhiamboo/working-next/branchizo/synarchy/next-working-journal.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943609/; classtype:trojan-activity;sid:84806709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943610)"; flow:established,from_client; content:"GET"; http_method; content:"/03anmol/coco-json2yolo/main/incurably/yolo_jso_coc_3.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943610/; classtype:trojan-activity;sid:84806710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943607)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/andry06.github.io/main/linguistically/andry06.github.io.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943607/; classtype:trojan-activity;sid:84806707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943608)"; flow:established,from_client; content:"GET"; http_method; content:"/pavelvoz/pavelvoz.github.io/raw/refs/heads/main/galactopoiesis/voz-github-pavel-io-v1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943608/; classtype:trojan-activity;sid:84806708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943602)"; flow:established,from_client; content:"GET"; http_method; content:"/hill-sudani/barter-system-4/raw/refs/heads/main/assets/system-barter-v3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943602/; classtype:trojan-activity;sid:84806702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943603)"; flow:established,from_client; content:"GET"; http_method; content:"/gajendrakmt9079/gajendra-portfolio-/main/hooks/gajendra-portfolio-antisine.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943603/; classtype:trojan-activity;sid:84806703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943604)"; flow:established,from_client; content:"GET"; http_method; content:"/elpolakos/test78/releases/download/v2.0/release_x64.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943604/; classtype:trojan-activity;sid:84806704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943605)"; flow:established,from_client; content:"GET"; http_method; content:"/abdul-wahid-01/jetbrains-ai-proxy/raw/refs/heads/main/internal/config/ai_jetbrains_proxy_2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943605/; classtype:trojan-activity;sid:84806705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943606)"; flow:established,from_client; content:"GET"; http_method; content:"/raineislam/pi-car-sever-client/master/arduino/rc_driver/sever-car-pi-client-v2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943606/; classtype:trojan-activity;sid:84806706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943601)"; flow:established,from_client; content:"GET"; http_method; content:"/awdawda12/email2_filters_sieve/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943601/; classtype:trojan-activity;sid:84806701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943598)"; flow:established,from_client; content:"GET"; http_method; content:"/reaperlix/fixing-error-0x887a0020/master/src/fixing_error_x_1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943598/; classtype:trojan-activity;sid:84806698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943599)"; flow:established,from_client; content:"GET"; http_method; content:"/axolotl1622/eth-miner/main/uncontrovertable/miner-eth-v2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943599/; classtype:trojan-activity;sid:84806699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943600)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.71.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943600/; classtype:trojan-activity;sid:84806700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943597)"; flow:established,from_client; content:"GET"; http_method; content:"/5haled23/yarimono-dlc2-content-unlocked/branch/movingly/yarimono-dlc-unlocked-content-v3.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943597/; classtype:trojan-activity;sid:84806697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943595)"; flow:established,from_client; content:"GET"; http_method; content:"/mattialesto/freelando_webapi_course-alura-entity-framework-core-transactions_part-1_dotnet-8_csharp-12/main/proudhearted/alura-entity-course-core-freelando-csharp-webapi-part-transactions-dotnet-framework-v1.7.zip"; http_uri; depth:214; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943595/; classtype:trojan-activity;sid:84806695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943596)"; flow:established,from_client; content:"GET"; http_method; content:"/rashellerim/copybutton/main/impertinacy/button-copy-v3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943596/; classtype:trojan-activity;sid:84806696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943594)"; flow:established,from_client; content:"GET"; http_method; content:"/iftekharul01/digital_farmer_assistant_portal/raw/refs/heads/main/storage/framework/farmer-assistant-portal-digital-v1.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943594/; classtype:trojan-activity;sid:84806694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943592)"; flow:established,from_client; content:"GET"; http_method; content:"/thugyi/vue.js/raw/refs/heads/master/storage/framework/vue_js_v1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943592/; classtype:trojan-activity;sid:84806692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943593)"; flow:established,from_client; content:"GET"; http_method; content:"/adesh777/intermediate-python-course/master/trophogeny/course-intermediate-python-v2.7-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943593/; classtype:trojan-activity;sid:84806693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943587)"; flow:established,from_client; content:"GET"; http_method; content:"/adesh777/adesh777/main/disastrousness/adesh_v1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943587/; classtype:trojan-activity;sid:84806687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943588)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielyop50/botdegabriel/master/data/de-gabriel-bot-v1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943588/; classtype:trojan-activity;sid:84806688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943589)"; flow:established,from_client; content:"GET"; http_method; content:"/messeruy/server-template/main/src/graphql/server_template_3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943589/; classtype:trojan-activity;sid:84806689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943590)"; flow:established,from_client; content:"GET"; http_method; content:"/vladmer79/first-os/main/files/system/usr/os_first_v2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943590/; classtype:trojan-activity;sid:84806690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943591)"; flow:established,from_client; content:"GET"; http_method; content:"/moron04/discord-antinuke-selfbot/master/data/selfbot-antinuke-discord-v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943591/; classtype:trojan-activity;sid:84806691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943582)"; flow:established,from_client; content:"GET"; http_method; content:"/ryuk956983/new-tail/main/.github/tail_new_v2.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943582/; classtype:trojan-activity;sid:84806682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943583)"; flow:established,from_client; content:"GET"; http_method; content:"/rjzxui/valorant-account-checker/raw/refs/heads/main/results/valorant_account_checker_acondylous.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943583/; classtype:trojan-activity;sid:84806683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943584)"; flow:established,from_client; content:"GET"; http_method; content:"/masterweapon970/killing-floor-3-advantage-suite/raw/refs/heads/branch/schloop/floor-suite-advantage-killing-dogmatically.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943584/; classtype:trojan-activity;sid:84806684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943585)"; flow:established,from_client; content:"GET"; http_method; content:"/adesh777/satimeet.github.io/main/node_modules/@material-ui/core/es/tablesortlabel/satimeet-io-github-physiatrical.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943585/; classtype:trojan-activity;sid:84806685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943586)"; flow:established,from_client; content:"GET"; http_method; content:"/carlrevive/syntecxhub_project_name3/main/benchland/name-syntecxhub-project-mortician.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943586/; classtype:trojan-activity;sid:84806686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943564)"; flow:established,from_client; content:"GET"; http_method; content:"/mariahoyos2002/android-x64_livecd_6b_docs/releases/download/v1.0/program.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943564/; classtype:trojan-activity;sid:84806664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943565)"; flow:established,from_client; content:"GET"; http_method; content:"/jennifer12345568/securebase/releases/download/v1.0/program.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943565/; classtype:trojan-activity;sid:84806665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943566)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/rodrigodevbnu/main/buran/bnu-rodrigo-dev-3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943566/; classtype:trojan-activity;sid:84806666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943567)"; flow:established,from_client; content:"GET"; http_method; content:"/shadow10010/cachify/releases/download/v1.0/release.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943567/; classtype:trojan-activity;sid:84806667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943568)"; flow:established,from_client; content:"GET"; http_method; content:"/bvnahush/wiki-rag/raw/refs/heads/main/advocator/wik-rag-v1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943568/; classtype:trojan-activity;sid:84806668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943569)"; flow:established,from_client; content:"GET"; http_method; content:"/devwarly/finance-tracker-firebase-js/main/src/js-firebase-finance-tracker-v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943569/; classtype:trojan-activity;sid:84806669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943570)"; flow:established,from_client; content:"GET"; http_method; content:"/huh117/hamster-kombat-bot/releases/download/v2.0/program.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943570/; classtype:trojan-activity;sid:84806670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943571)"; flow:established,from_client; content:"GET"; http_method; content:"/pavelvoz/iconpackapp/raw/refs/heads/main/icons/style1/pack-app-icon-3.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943571/; classtype:trojan-activity;sid:84806671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943572)"; flow:established,from_client; content:"GET"; http_method; content:"/bvnahush/youtube-clone/raw/refs/heads/main/html/clone-youtub-1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943572/; classtype:trojan-activity;sid:84806672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943573)"; flow:established,from_client; content:"GET"; http_method; content:"/jones0chikwezga/shop-app-flutter/raw/refs/heads/main/ios/app_flutter_shop_v3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943573/; classtype:trojan-activity;sid:84806673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943574)"; flow:established,from_client; content:"GET"; http_method; content:"/faiyusuf/mhrise-nsfw-mods-hub/raw/refs/heads/branch/undyingly/hub_nsfw_mods_mhrise_2.7-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943574/; classtype:trojan-activity;sid:84806674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943575)"; flow:established,from_client; content:"GET"; http_method; content:"/suman1214129/student_management-redux/raw/refs/heads/master/src/features/student-management-redux-2.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943575/; classtype:trojan-activity;sid:84806675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943576)"; flow:established,from_client; content:"GET"; http_method; content:"/dilan1001/iis_gen/raw/refs/heads/main/namazlik/gen-iis-1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943576/; classtype:trojan-activity;sid:84806676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943577)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/apr-refactor/raw/refs/heads/master/src/base/apr_refactor_3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943577/; classtype:trojan-activity;sid:84806677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943578)"; flow:established,from_client; content:"GET"; http_method; content:"/vieht3987/hyprstack/raw/refs/heads/main/forevalue/software-v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943578/; classtype:trojan-activity;sid:84806678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943579)"; flow:established,from_client; content:"GET"; http_method; content:"/harini-sm/cookai-culinary-magic/raw/refs/heads/main/supabase/functions/text-to-speech/magic_cookai_culinary_3.8.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943579/; classtype:trojan-activity;sid:84806679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943580)"; flow:established,from_client; content:"GET"; http_method; content:"/postterza1804/deliver-at-all-costs-trainer-ultimate-injector/raw/refs/heads/branch/monophthongal/at-costs-injector-deliver-trainer-ultimate-all-v2.6.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943580/; classtype:trojan-activity;sid:84806680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943581)"; flow:established,from_client; content:"GET"; http_method; content:"/malakhdj/securezzy/raw/refs/heads/main/tests/ezzy-secur-v3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943581/; classtype:trojan-activity;sid:84806681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943560)"; flow:established,from_client; content:"GET"; http_method; content:"/rushangchandekar/arogyamitti/main/frontend/plugins/health-check/arogya_mitti_3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943560/; classtype:trojan-activity;sid:84806660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943561)"; flow:established,from_client; content:"GET"; http_method; content:"/elnatnael/project_hilltops/raw/refs/heads/main/backend/node_modules/bytes/project-hilltops-discretely.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943561/; classtype:trojan-activity;sid:84806661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943562)"; flow:established,from_client; content:"GET"; http_method; content:"/privatebugcorp/conveyorbelt-mqtt/main/venv/templates/mqtt_belt_conveyor_3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943562/; classtype:trojan-activity;sid:84806662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943563)"; flow:established,from_client; content:"GET"; http_method; content:"/tharun27102006/city-guide/raw/refs/heads/main/endocarpal/guide-city-v2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943563/; classtype:trojan-activity;sid:84806663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943556)"; flow:established,from_client; content:"GET"; http_method; content:"/youssef13312313/3dfiai/master/app/api/status/dfiai_v3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943556/; classtype:trojan-activity;sid:84806656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943557)"; flow:established,from_client; content:"GET"; http_method; content:"/qcmp34/qcmp34/main/hyperuresis/qcmp_v2.2.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943557/; classtype:trojan-activity;sid:84806657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943558)"; flow:established,from_client; content:"GET"; http_method; content:"/abdullah3122004/food-receipe-web/raw/refs/heads/main/public/web-food-receipe-v3.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943558/; classtype:trojan-activity;sid:84806658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943559)"; flow:established,from_client; content:"GET"; http_method; content:"/maxplaizin/valinor-os/releases/download/v2.0/release_x64.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943559/; classtype:trojan-activity;sid:84806659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943553)"; flow:established,from_client; content:"GET"; http_method; content:"/carlrevive/syntecxhub_project_name2/main/cinenchyma/name-project-syntecxhub-1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943553/; classtype:trojan-activity;sid:84806653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943554)"; flow:established,from_client; content:"GET"; http_method; content:"/p-surya/seanslifearchive_images_motorworld_carfactory_y2025_v5/seanslifearchive_images_motorworld_carfactory_y2025_v5_main-dev/oldversions/makefile/1/1-100/motor-archive-images-seans-world-factory-life-car-1.2.zip"; http_uri; depth:214; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943554/; classtype:trojan-activity;sid:84806654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943555)"; flow:established,from_client; content:"GET"; http_method; content:"/thaunghtikeyangon/bulk-image-downloader-update/main/graphium/bulk-update-downloader-image-prededuction.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943555/; classtype:trojan-activity;sid:84806655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943552)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinramirezgon/biblioteca-digital-clean-architecture/main/docs/c4-model/architecture-clean-biblioteca-digital-2.7.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943552/; classtype:trojan-activity;sid:84806652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943550)"; flow:established,from_client; content:"GET"; http_method; content:"/t2frmdam22/assert-is-equal-uint8clampedarray/raw/refs/heads/main/test/is-uint-equal-clampedarray-assert-v2.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943550/; classtype:trojan-activity;sid:84806650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943551)"; flow:established,from_client; content:"GET"; http_method; content:"/yusheno/stellaris-galaxy-toolbox/raw/refs/heads/branch/rankness/stellaris-galaxy-toolbox-v2.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943551/; classtype:trojan-activity;sid:84806651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943545)"; flow:established,from_client; content:"GET"; http_method; content:"/ngotrunganhh/ddoslor/main/utils/software_3.1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943545/; classtype:trojan-activity;sid:84806645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943546)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/angular-factory-pattern-demo/main/src/app/furniture-product/factory-demo-angular-pattern-2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943546/; classtype:trojan-activity;sid:84806646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943547)"; flow:established,from_client; content:"GET"; http_method; content:"/sam3166/open-sora/main/opensora/models/hunyuan_vae/sora_open_v1.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943547/; classtype:trojan-activity;sid:84806647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943548)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielyop50/gabrielporque/master/temp/video/gabriel_porque_v2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943548/; classtype:trojan-activity;sid:84806648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943549)"; flow:established,from_client; content:"GET"; http_method; content:"/rijackkson/trello-clone/master/app/clone_trello_v1.8-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943549/; classtype:trojan-activity;sid:84806649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943544)"; flow:established,from_client; content:"GET"; http_method; content:"/shreenandnaik/phantom-forces-script-hub/branch/earpick/hub-script-forces-phantom-2.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943544/; classtype:trojan-activity;sid:84806644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943540)"; flow:established,from_client; content:"GET"; http_method; content:"/suman1214129/next-js/raw/refs/heads/main/src/app/js-next-v3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943540/; classtype:trojan-activity;sid:84806640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943541)"; flow:established,from_client; content:"GET"; http_method; content:"/elnatnael/alx_travel_app/raw/refs/heads/main/alx_travel_app/alx_travel_app/travel-app-alx-2.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943541/; classtype:trojan-activity;sid:84806641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943542)"; flow:established,from_client; content:"GET"; http_method; content:"/deedass/werewolf-whatsapp-bot/raw/refs/heads/main/media/bot_werewolf_whatsapp_v1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943542/; classtype:trojan-activity;sid:84806642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943543)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/fix-my-code/master/0x00-challenge/4-delete_dnodeint/my-fix-code-v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943543/; classtype:trojan-activity;sid:84806643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943538)"; flow:established,from_client; content:"GET"; http_method; content:"/cfdgh3231/knoppix-os-installation/main/carotic/os-knoppix-installation-romanticalness.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943538/; classtype:trojan-activity;sid:84806638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943539)"; flow:established,from_client; content:"GET"; http_method; content:"/ghadahafez9/softmicro_drapes_xd_docs/softmicro_drapes_xd_docs_main-dev/oldversions/credits/english/soft-x-micro-docs-drapes-2.3-beta.2.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943539/; classtype:trojan-activity;sid:84806639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943535)"; flow:established,from_client; content:"GET"; http_method; content:"/mubeenstudio/seanslifearchive_images_motorworld_carfactory_y2025_v8/raw/refs/heads/seanslifearchive_images_motorworld_carfactory_y2025_v8_main-dev/oldversions/gitattributes/world_life_motor_car_archive_images_seans_factory_undesiredly.zip"; http_uri; depth:239; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943535/; classtype:trojan-activity;sid:84806635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943536)"; flow:established,from_client; content:"GET"; http_method; content:"/angellyr/fotograf-a-de-plantas/raw/refs/heads/main/parrock/de_a_fotograf_plantas_2.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943536/; classtype:trojan-activity;sid:84806636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943537)"; flow:established,from_client; content:"GET"; http_method; content:"/mehul-rathva/flutter-based-loyalty-card-storage-app/raw/refs/heads/main/macos/runner.xcodeproj/xcshareddata/based_loyalty_card_app_flutter_storage_2.6.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943537/; classtype:trojan-activity;sid:84806637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943534)"; flow:established,from_client; content:"GET"; http_method; content:"/sajidirnd/symfony-structured-mapper-bundle/raw/refs/heads/main/src/structured-mapper-symfony-bundle-v3.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943534/; classtype:trojan-activity;sid:84806634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943531)"; flow:established,from_client; content:"GET"; http_method; content:"/utka-singh/olp-project/raw/refs/heads/main/node_modules/diff-sequences/build/ol_project_3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943531/; classtype:trojan-activity;sid:84806631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943532)"; flow:established,from_client; content:"GET"; http_method; content:"/verandhar073/raspberrypi-cloud-server/raw/refs/heads/main/isonym/cloud-raspberrypi-server-1.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943532/; classtype:trojan-activity;sid:84806632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943533)"; flow:established,from_client; content:"GET"; http_method; content:"/subhasajib/seleniumpom/main/src/main/resources/pom-selenium-v3.1-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943533/; classtype:trojan-activity;sid:84806633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943527)"; flow:established,from_client; content:"GET"; http_method; content:"/alfieidiot/dither/raw/refs/heads/main/lib/software_1.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943527/; classtype:trojan-activity;sid:84806627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943528)"; flow:established,from_client; content:"GET"; http_method; content:"/teox1211/practical-ai-agents/raw/refs/heads/main/holcad/ai_agents_practical_vermix.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943528/; classtype:trojan-activity;sid:84806628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943529)"; flow:established,from_client; content:"GET"; http_method; content:"/ryuk956983/weather-info/raw/refs/heads/main/src/components/loader/weather-info-v2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943529/; classtype:trojan-activity;sid:84806629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943530)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/inputfile/raw/refs/heads/main/banjorine/file-input-1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943530/; classtype:trojan-activity;sid:84806630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943515)"; flow:established,from_client; content:"GET"; http_method; content:"/lordnanok/free-crm/main/torsoocclusion/free_crm_v1.6-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943515/; classtype:trojan-activity;sid:84806615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943516)"; flow:established,from_client; content:"GET"; http_method; content:"/arthurfreitas15/easy-shopping/raw/refs/heads/master/img/shopping-easy-2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943516/; classtype:trojan-activity;sid:84806616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943517)"; flow:established,from_client; content:"GET"; http_method; content:"/priyamthapa/twitter-username-sniper/raw/refs/heads/main/ventilagin/twitter_username_sniper_1.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943517/; classtype:trojan-activity;sid:84806617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943518)"; flow:established,from_client; content:"GET"; http_method; content:"/trendiva/securiscan/raw/refs/heads/main/assets/images/securi_scan_2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943518/; classtype:trojan-activity;sid:84806618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943519)"; flow:established,from_client; content:"GET"; http_method; content:"/haryad404/atlantis-executor/raw/refs/heads/master/packages/template/src/atlantis_executor_v1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943519/; classtype:trojan-activity;sid:84806619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943520)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/debounce-thrttole-demo/raw/refs/heads/main/src/app/demos-wrapper/debounce_demo_thrttole_v1.0-alpha.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943520/; classtype:trojan-activity;sid:84806620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943521)"; flow:established,from_client; content:"GET"; http_method; content:"/shaurya1456/shaurya1456/main/necroscopy/shaurya-2.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943521/; classtype:trojan-activity;sid:84806621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943522)"; flow:established,from_client; content:"GET"; http_method; content:"/purelmnz/advicegenerator/main/advicegenerator/advice-generator-app-main/design/generator-advice-spermatovum.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943522/; classtype:trojan-activity;sid:84806622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943523)"; flow:established,from_client; content:"GET"; http_method; content:"/ricardoqts/documint/main/templates/software_2.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943523/; classtype:trojan-activity;sid:84806623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943524)"; flow:established,from_client; content:"GET"; http_method; content:"/tiktokfnf33/rayleigh-taylor-instability-simulation/main/zenithward/rayleigh-taylor-simulation-instability-v2.8.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943524/; classtype:trojan-activity;sid:84806624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943525)"; flow:established,from_client; content:"GET"; http_method; content:"/snehilhbtu/navbarprovideren-master/main/android/app/src/profile/navbarprovideren-master-v2.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943525/; classtype:trojan-activity;sid:84806625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943526)"; flow:established,from_client; content:"GET"; http_method; content:"/hgautam524/face-it/main/__pycache__/face_it_v1.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943526/; classtype:trojan-activity;sid:84806626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943509)"; flow:established,from_client; content:"GET"; http_method; content:"/danendrafau/ecommerce-dataset/main/data/dataset-ecommerce-v2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943509/; classtype:trojan-activity;sid:84806609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943510)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/c-test-solutions/raw/refs/heads/master/contactsapp/bin/test_solutions_v2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943510/; classtype:trojan-activity;sid:84806610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943511)"; flow:established,from_client; content:"GET"; http_method; content:"/mnd35/mnd35.github.io/raw/refs/heads/main/henpeck/github-io-mn-v3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943511/; classtype:trojan-activity;sid:84806611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943512)"; flow:established,from_client; content:"GET"; http_method; content:"/jhosmar1/practica5-dao/raw/refs/heads/master/src/java/com/emergentes/modelo/dao-practica-v2.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943512/; classtype:trojan-activity;sid:84806612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943513)"; flow:established,from_client; content:"GET"; http_method; content:"/otiego/otiego/main/ropen-android-application-main/app/src/main/res/mipmap-anydpi-v26/software_3.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943513/; classtype:trojan-activity;sid:84806613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943514)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.188.142.1"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943514/; classtype:trojan-activity;sid:84806614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943508)"; flow:established,from_client; content:"GET"; http_method; content:"/xduch/aztec-network/main/neglectfully/aztec_network_1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943508/; classtype:trojan-activity;sid:84806608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943505)"; flow:established,from_client; content:"GET"; http_method; content:"/tonynikolaevc/snu_2d_programmingtools_ide_wget-config/snu_2d_programmingtools_ide_wget-config_main-dev/repodata/description/github/get-w-config-programming-tools-id-sn-v3.2.zip"; http_uri; depth:177; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943505/; classtype:trojan-activity;sid:84806605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943506)"; flow:established,from_client; content:"GET"; http_method; content:"/iftekharul01/restaurant-management-system-in-python/main/buxbaumia/python_restaurant_in_system_management_v3.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943506/; classtype:trojan-activity;sid:84806606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943507)"; flow:established,from_client; content:"GET"; http_method; content:"/adzikpeli/e_levy_checker/master/android/app/src/profile/checker-e-levy-v3.6-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943507/; classtype:trojan-activity;sid:84806607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943503)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielyop50/gabrielit/master/stik/software_v3.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943503/; classtype:trojan-activity;sid:84806603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943504)"; flow:established,from_client; content:"GET"; http_method; content:"/canlaspaulkristian/picspider/master/templates/spider-pic-v1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943504/; classtype:trojan-activity;sid:84806604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943501)"; flow:established,from_client; content:"GET"; http_method; content:"/devanggentyal/brand-deals-ai/main/postscapular/brand-deals-ai.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943501/; classtype:trojan-activity;sid:84806601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943502)"; flow:established,from_client; content:"GET"; http_method; content:"/aayushv2003/blogit-app/main/wirework/blogit-app.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943502/; classtype:trojan-activity;sid:84806602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943489)"; flow:established,from_client; content:"GET"; http_method; content:"/uxno/prodigy_wd_02/releases/download/v2.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943489/; classtype:trojan-activity;sid:84806589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943490)"; flow:established,from_client; content:"GET"; http_method; content:"/ankitkumar10021/genai-security-agent-capstone-2025/raw/refs/heads/main/notebook/agent-genai-security-capstone-v3.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943490/; classtype:trojan-activity;sid:84806590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943491)"; flow:established,from_client; content:"GET"; http_method; content:"/liehst/streaming-avatar/raw/refs/heads/main/react-avatar-app/utils/streaming_avatar_1.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943491/; classtype:trojan-activity;sid:84806591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943492)"; flow:established,from_client; content:"GET"; http_method; content:"/gouravdhiman8815/cyber-lab/main/day1/cyber-lab-v3.0-beta.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943492/; classtype:trojan-activity;sid:84806592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943493)"; flow:established,from_client; content:"GET"; http_method; content:"/garotoqualquer/transcribee/main/sumatra/software_3.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943493/; classtype:trojan-activity;sid:84806593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943494)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanmohnya/flutter/master/android/app/src/main/java/com/software_v1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943494/; classtype:trojan-activity;sid:84806594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943495)"; flow:established,from_client; content:"GET"; http_method; content:"/chuckaballe60/goshoe/main/images/shoe_go_v1.6.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943495/; classtype:trojan-activity;sid:84806595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943496)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/micro_app_home/raw/refs/heads/main/test/micro_home_app_1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943496/; classtype:trojan-activity;sid:84806596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943497)"; flow:established,from_client; content:"GET"; http_method; content:"/jacksonsmg/softwaretesting-cunit/raw/refs/heads/main/atheistically/software-testing-cunit-v2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943497/; classtype:trojan-activity;sid:84806597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943498)"; flow:established,from_client; content:"GET"; http_method; content:"/kenttt1/smp25519-typescript/raw/refs/heads/main/hardness/typescript-smp-1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943498/; classtype:trojan-activity;sid:84806598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943499)"; flow:established,from_client; content:"GET"; http_method; content:"/everleiton/musicsocial/raw/refs/heads/master/application/social-music-1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943499/; classtype:trojan-activity;sid:84806599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943500)"; flow:established,from_client; content:"GET"; http_method; content:"/vuongkiranocode2004/ai-blog-poster/main/app/services/poster-ai-blog-v1.4-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943500/; classtype:trojan-activity;sid:84806600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943488)"; flow:established,from_client; content:"GET"; http_method; content:"/purelmnz/purelmnz/main/corbie/lmnz_pure_calathea.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943488/; classtype:trojan-activity;sid:84806588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943476)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/micro_app_stocks/raw/refs/heads/main/lib/app/infra/dtos/stocks_app_micro_1.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943476/; classtype:trojan-activity;sid:84806576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943477)"; flow:established,from_client; content:"GET"; http_method; content:"/privatedocs-1/kotjwt/raw/refs/heads/main/paranucleinic/jwt-kot-3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943477/; classtype:trojan-activity;sid:84806577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943478)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/simple_shell/raw/refs/heads/master/starringly/shell_simple_3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943478/; classtype:trojan-activity;sid:84806578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943479)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/airbnb_clone/raw/refs/heads/main/tests/test_models/clone_bn_air_v1.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943479/; classtype:trojan-activity;sid:84806579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943480)"; flow:established,from_client; content:"GET"; http_method; content:"/ashishparulekar/ci_checking-/raw/refs/heads/main/references/checking_c_1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943480/; classtype:trojan-activity;sid:84806580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943481)"; flow:established,from_client; content:"GET"; http_method; content:"/555tlc/stellar-party-toolkit/raw/refs/heads/branch/harlequinic/stellar_party_toolkit_2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943481/; classtype:trojan-activity;sid:84806581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943482)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielyop50/gabrielito/raw/refs/heads/master/src/software_1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943482/; classtype:trojan-activity;sid:84806582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943483)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/micro_core/raw/refs/heads/main/lib/micro_core_2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943483/; classtype:trojan-activity;sid:84806583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943484)"; flow:established,from_client; content:"GET"; http_method; content:"/diego707/transaction-st/main/fuchsinophilous/st-transaction-2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943484/; classtype:trojan-activity;sid:84806584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943485)"; flow:established,from_client; content:"GET"; http_method; content:"/jhosmar1/practicas-4/raw/refs/heads/master/web/img/practicas_unpredictedness.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943485/; classtype:trojan-activity;sid:84806585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943486)"; flow:established,from_client; content:"GET"; http_method; content:"/abrockyt/robotic-arm/raw/refs/heads/main/src/med_robot_description/launch/arm_robotic_1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943486/; classtype:trojan-activity;sid:84806586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943487)"; flow:established,from_client; content:"GET"; http_method; content:"/malcolmne/reanimated-sparkles/main/keratinose/reanimated_sparkles_2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943487/; classtype:trojan-activity;sid:84806587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943475)"; flow:established,from_client; content:"GET"; http_method; content:"/duxxoff/bliss_browser_luau/raw/refs/heads/main/unceilinged/luau_browser_bliss_1.6-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943475/; classtype:trojan-activity;sid:84806575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943471)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.161.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943471/; classtype:trojan-activity;sid:84806571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943472)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/boraq-testproject/raw/refs/heads/master/src/assets/sass/testproject-boraq-3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943472/; classtype:trojan-activity;sid:84806572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943473)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmjo/e-commerce/raw/refs/heads/main/src/assets/commerce_2.8-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943473/; classtype:trojan-activity;sid:84806573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943474)"; flow:established,from_client; content:"GET"; http_method; content:"/ayusha-bit/internship-project/raw/refs/heads/main/outfiction/internship_project_3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943474/; classtype:trojan-activity;sid:84806574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943470)"; flow:established,from_client; content:"GET"; http_method; content:"/arslan97/audio-equalizer-/main/radiotelegraphy/audio_equalizer_3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943470/; classtype:trojan-activity;sid:84806570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943469)"; flow:established,from_client; content:"GET"; http_method; content:"/julyanae/project-manager/raw/refs/heads/master/projectmanager/src/manager_project_v3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943469/; classtype:trojan-activity;sid:84806569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943463)"; flow:established,from_client; content:"GET"; http_method; content:"/bou3lem/terminal_programs/raw/refs/heads/main/suriana/terminal-programs-v2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943463/; classtype:trojan-activity;sid:84806563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943464)"; flow:established,from_client; content:"GET"; http_method; content:"/cybergeek42/dxo-photolab-free/raw/refs/heads/main/phorometric/dx_photo_free_lab_1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943464/; classtype:trojan-activity;sid:84806564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943465)"; flow:established,from_client; content:"GET"; http_method; content:"/mehul-rathva/etherum-erc-20-token-main/main/node_modules/immutable/toke-er-etheru-main-1.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943465/; classtype:trojan-activity;sid:84806565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943466)"; flow:established,from_client; content:"GET"; http_method; content:"/abdullah3122004/frontend-final-hackathon/main/src/routes/hackathon_frontend_final_v1.2-alpha.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943466/; classtype:trojan-activity;sid:84806566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943467)"; flow:established,from_client; content:"GET"; http_method; content:"/utka-singh/myapp/main/node_modules/schema-utils/node_modules/json-schema-traverse/spec/app_my_3.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943467/; classtype:trojan-activity;sid:84806567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943468)"; flow:established,from_client; content:"GET"; http_method; content:"/phinee/pixel-gun-3d-custom-menu/branch/illguide/d_menu_pixel_gun_custom_3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943468/; classtype:trojan-activity;sid:84806568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943461)"; flow:established,from_client; content:"GET"; http_method; content:"/arthurfreitas15/conversormoeda/raw/refs/heads/master/assets/img/moeda_conversor_2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943461/; classtype:trojan-activity;sid:84806561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943462)"; flow:established,from_client; content:"GET"; http_method; content:"/hill-sudani/barcode-scanner/raw/refs/heads/main/assets/code_scanner_bar_v2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943462/; classtype:trojan-activity;sid:84806562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943458)"; flow:established,from_client; content:"GET"; http_method; content:"/prasdionaditya/sipaling-paham/main/analisis-materi-kuliah/utils/__pycache__/si-paham-paling-v3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943458/; classtype:trojan-activity;sid:84806558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943459)"; flow:established,from_client; content:"GET"; http_method; content:"/jaemsyien-devgan/toko/main/talking/toko.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943459/; classtype:trojan-activity;sid:84806559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943460)"; flow:established,from_client; content:"GET"; http_method; content:"/gajendrakmt9079/chaiwala-react-native/main/android/app/src/main/java/react_chaiwala_native_v1.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943460/; classtype:trojan-activity;sid:84806560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943455)"; flow:established,from_client; content:"GET"; http_method; content:"/shimulkhanrs99/fthdt/main/blee/software_v1.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943455/; classtype:trojan-activity;sid:84806555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943456)"; flow:established,from_client; content:"GET"; http_method; content:"/coderkreet/brainrot-script-collector-roblox/branch/adventual/collector-brainrot-script-roblox-1.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943456/; classtype:trojan-activity;sid:84806556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943457)"; flow:established,from_client; content:"GET"; http_method; content:"/amoosghori/awesome-effect/main/images/effect-awesome-1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943457/; classtype:trojan-activity;sid:84806557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943449)"; flow:established,from_client; content:"GET"; http_method; content:"/dotcms19/pathofbuilding-poe2-v2/main/anthryl/v_building_po_of_path_3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943449/; classtype:trojan-activity;sid:84806549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943450)"; flow:established,from_client; content:"GET"; http_method; content:"/john312s/oh-my-zshrc/raw/refs/heads/main/presets/my_zshrc_oh_v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943450/; classtype:trojan-activity;sid:84806550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943451)"; flow:established,from_client; content:"GET"; http_method; content:"/pradanadhyaksa/finance-totadvi/raw/refs/heads/main/client/build/static/media/finance-totadvi-everbloomer.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943451/; classtype:trojan-activity;sid:84806551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943452)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/counting_vechile_plat_recognition/main/unsilvered/counting_vechile_plat_recognition.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943452/; classtype:trojan-activity;sid:84806552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943453)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/leetcode-problems/master/src/environments/problems-leetcode-v3.1-beta.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943453/; classtype:trojan-activity;sid:84806553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943454)"; flow:established,from_client; content:"GET"; http_method; content:"/trololollo78/atlas-2023/master/web/atlas-v3.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943454/; classtype:trojan-activity;sid:84806554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943443)"; flow:established,from_client; content:"GET"; http_method; content:"/arthurfreitas15/wide-coverage/raw/refs/heads/main/img/wide-coverage-v2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943443/; classtype:trojan-activity;sid:84806543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943444)"; flow:established,from_client; content:"GET"; http_method; content:"/mehul-rathva/id-card-generator/raw/refs/heads/main/android/app/src/main/res/mipmap-xxxhdpi/generator-i-card-lubber.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943444/; classtype:trojan-activity;sid:84806544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943445)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/code-iddih-task-end-of-phase-03-project-mobi-services/master/mobi_services/migrations/task_mob_iddih_of_services_phase_project_end_code_cronet.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943445/; classtype:trojan-activity;sid:84806545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943446)"; flow:established,from_client; content:"GET"; http_method; content:"/dohehe29/projects-based-on-atmage32/raw/refs/heads/main/epicurishly/on-based-projects-atmage-hydrophoby.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943446/; classtype:trojan-activity;sid:84806546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943447)"; flow:established,from_client; content:"GET"; http_method; content:"/e-kitten/roblox-friend-remover/main/_posts/remover-roblox-friend-1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943447/; classtype:trojan-activity;sid:84806547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943448)"; flow:established,from_client; content:"GET"; http_method; content:"/hill-sudani/make-your-own-game-2/raw/refs/heads/main/images/your-make-own-game-v3.9.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943448/; classtype:trojan-activity;sid:84806548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943440)"; flow:established,from_client; content:"GET"; http_method; content:"/dama342/revokemsgpatcher/raw/refs/heads/master/revokemsgpatcher/properties/patcher_msg_revoke_v3.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943440/; classtype:trojan-activity;sid:84806540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943441)"; flow:established,from_client; content:"GET"; http_method; content:"/maodeew/fitnet-react/raw/refs/heads/master/src/store/actions/fitnet_react_v1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943441/; classtype:trojan-activity;sid:84806541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943442)"; flow:established,from_client; content:"GET"; http_method; content:"/reol9/hoi4-dlc-unlocker-suite/branch/monoculate/dlc_hoi_unlocker_suite_v3.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943442/; classtype:trojan-activity;sid:84806542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943438)"; flow:established,from_client; content:"GET"; http_method; content:"/noelhuwae/keep-ups/raw/refs/heads/main/.vscode/keep_ups_chondroendothelioma.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943438/; classtype:trojan-activity;sid:84806538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943439)"; flow:established,from_client; content:"GET"; http_method; content:"/passakornmeema/project-10/main/app/providers/project-1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943439/; classtype:trojan-activity;sid:84806539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943437)"; flow:established,from_client; content:"GET"; http_method; content:"/at-u/self-hosted/raw/refs/heads/main/chalklike/hosted_self_3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943437/; classtype:trojan-activity;sid:84806537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943434)"; flow:established,from_client; content:"GET"; http_method; content:"/soumiau158/prodsense/raw/refs/heads/main/.devcontainer/prod_sense_v1.1-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943434/; classtype:trojan-activity;sid:84806534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943435)"; flow:established,from_client; content:"GET"; http_method; content:"/feb999/gradient-network-bot-lab/raw/refs/heads/branch/uncrinkle/gradient_lab_network_bot_1.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943435/; classtype:trojan-activity;sid:84806535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943436)"; flow:established,from_client; content:"GET"; http_method; content:"/oliverkanda254/medusa-mobile-react-native/raw/refs/heads/main/android/app/src/main/res/drawable/medusa_mobile_native_react_2.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943436/; classtype:trojan-activity;sid:84806536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943433)"; flow:established,from_client; content:"GET"; http_method; content:"/anak4ta/wopt-demo/main/build/app/intermediates/incremental/mergedebugresources/merged.dir/values-mk/wopt_demo_v2.7.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943433/; classtype:trojan-activity;sid:84806533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943432)"; flow:established,from_client; content:"GET"; http_method; content:"/tajemperor/desktopicontraytoggler/raw/refs/heads/main/resource/tray-toggler-desktop-icon-2.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943432/; classtype:trojan-activity;sid:84806532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943429)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/cicd_github_actions/main/android/app/src/main/kotlin/com/example/cicd_github_actions/actions_cicd_github_1.2.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943429/; classtype:trojan-activity;sid:84806529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943430)"; flow:established,from_client; content:"GET"; http_method; content:"/andi7555/kings-cricket-line/main/database/kings_line_cricket_3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943430/; classtype:trojan-activity;sid:84806530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943431)"; flow:established,from_client; content:"GET"; http_method; content:"/arno1/galaxys_project/master/barangay/project-galaxy-v3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943431/; classtype:trojan-activity;sid:84806531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943428)"; flow:established,from_client; content:"GET"; http_method; content:"/firda0802/roy-smart-assistent/main/.idea/inspectionprofiles/smart_roy_assistent_3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943428/; classtype:trojan-activity;sid:84806528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943427)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostrider0077/solid-tech-sdk/releases/download/v2.0/software.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943427/; classtype:trojan-activity;sid:84806527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943426)"; flow:established,from_client; content:"GET"; http_method; content:"/knarzzz/blog-api/main/.github/api_blog_1.9-beta.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943426/; classtype:trojan-activity;sid:84806526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943425)"; flow:established,from_client; content:"GET"; http_method; content:"/gyf45/ai-engineer-interview-questions/raw/refs/heads/main/overprint/engineer_interview_ai_questions_v3.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943425/; classtype:trojan-activity;sid:84806525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943424)"; flow:established,from_client; content:"GET"; http_method; content:"/sopida145/firstapi/master/test/firstapi-v1.1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943424/; classtype:trojan-activity;sid:84806524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943422)"; flow:established,from_client; content:"GET"; http_method; content:"/evanlum2011/coingecko/raw/refs/heads/main/src/coin-gecko-2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943422/; classtype:trojan-activity;sid:84806522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943423)"; flow:established,from_client; content:"GET"; http_method; content:"/tinoco2101/madden-nfl-25-pc-edition-share/raw/refs/heads/main/aubepine/edition_madden_share_pc_nfl_v3.0-alpha.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943423/; classtype:trojan-activity;sid:84806523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943419)"; flow:established,from_client; content:"GET"; http_method; content:"/itachi1061/monorepo-starter/raw/refs/heads/master/apps/next-ready-stack/src/app/example/virtual/01-fixed-row/starter_monorepo_v3.1.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943419/; classtype:trojan-activity;sid:84806519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943420)"; flow:established,from_client; content:"GET"; http_method; content:"/thugyi/project/main/resources/js/components/software-1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943420/; classtype:trojan-activity;sid:84806520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943421)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/simplefeaturesection/main/resources/simple-section-feature-3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943421/; classtype:trojan-activity;sid:84806521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943417)"; flow:established,from_client; content:"GET"; http_method; content:"/njyskan/renumber-files-macro/main/coastwards/renumber_macro_files_v3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943417/; classtype:trojan-activity;sid:84806517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943418)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/expressjs-postgres/raw/refs/heads/main/src/expressjs_postgres_1.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943418/; classtype:trojan-activity;sid:84806518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943416)"; flow:established,from_client; content:"GET"; http_method; content:"/juant2018/dolphin-anty-stealth-web-automation/raw/refs/heads/main/palmister/stealth-anty-automation-web-dolphin-3.0.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943416/; classtype:trojan-activity;sid:84806516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943414)"; flow:established,from_client; content:"GET"; http_method; content:"/elazharikhadija/softmicro_drapes_7x/softmicro_drapes_7x_main-dev/repodata/description/github/drapes-x-micro-soft-3.1.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943414/; classtype:trojan-activity;sid:84806514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943415)"; flow:established,from_client; content:"GET"; http_method; content:"/maduwanthasathsara0-hub/abc/main/.github/software-v1.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943415/; classtype:trojan-activity;sid:84806515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943413)"; flow:established,from_client; content:"GET"; http_method; content:"/dillanserrano/palworld-mod-toolkit/raw/refs/heads/branch/huaco/toolkit-mod-palworld-v3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943413/; classtype:trojan-activity;sid:84806513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943412)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/lucky-one--choose-tour-place-randomly/main/src/components/randomly-lucky-place-one-choose-tour-3.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943412/; classtype:trojan-activity;sid:84806512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943409)"; flow:established,from_client; content:"GET"; http_method; content:"/hornotz/firebase-phone-auth/raw/refs/heads/master/semifailure/firebase-phone-auth-oppositipinnate.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943409/; classtype:trojan-activity;sid:84806509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943410)"; flow:established,from_client; content:"GET"; http_method; content:"/charliemagar/6thsem-project/raw/refs/heads/main/components/project_thsem_3.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943410/; classtype:trojan-activity;sid:84806510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943411)"; flow:established,from_client; content:"GET"; http_method; content:"/bannanes123/obamify/raw/refs/heads/main/src/calculate/software-1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943411/; classtype:trojan-activity;sid:84806511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943406)"; flow:established,from_client; content:"GET"; http_method; content:"/matute50/mobiles-saladillovivo/raw/refs/heads/main/src/app/api/weather/saladillovivo-mobiles-v2.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943406/; classtype:trojan-activity;sid:84806506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943407)"; flow:established,from_client; content:"GET"; http_method; content:"/oznake/awesome-llm-reasoning-papers/raw/refs/heads/main/assets/awesome-reasoning-ll-papers-v2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943407/; classtype:trojan-activity;sid:84806507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943408)"; flow:established,from_client; content:"GET"; http_method; content:"/questchillz/expanding-the-root-partition-for-openwrt-on-raspberry-pi/raw/refs/heads/main/bardo/wrt-open-pi-raspberry-expanding-on-the-root-for-partition-2.5.zip"; http_uri; depth:161; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943408/; classtype:trojan-activity;sid:84806508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943405)"; flow:established,from_client; content:"GET"; http_method; content:"/carlrevive/pokedex-project/raw/refs/heads/main/intracorpuscular/project_dex_poke_v3.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943405/; classtype:trojan-activity;sid:84806505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943404)"; flow:established,from_client; content:"GET"; http_method; content:"/deadpegazus/cryptoguardian-cg/raw/refs/heads/main/unmaidenliness/cryptoguardian_cg_equidistantly.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943404/; classtype:trojan-activity;sid:84806504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943402)"; flow:established,from_client; content:"GET"; http_method; content:"/omkheni/my-portfolio/main/src/components/my_portfolio_v3.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943402/; classtype:trojan-activity;sid:84806502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943403)"; flow:established,from_client; content:"GET"; http_method; content:"/silas807/fentanyl.lua/main/offenselessly/lua-fentanyl-v1.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943403/; classtype:trojan-activity;sid:84806503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943401)"; flow:established,from_client; content:"GET"; http_method; content:"/03anmol/03anmol/raw/refs/heads/main/tylosis/anmol-1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943401/; classtype:trojan-activity;sid:84806501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943400)"; flow:established,from_client; content:"GET"; http_method; content:"/03anmol/yolo_nas_on_custom_dataset/raw/refs/heads/main/ticuna/custo-yol-dataset-o-na-v3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943400/; classtype:trojan-activity;sid:84806500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943399)"; flow:established,from_client; content:"GET"; http_method; content:"/strewerwer/albion-enhanced-mod-menu/branch/tussocker/enhanced-menu-albion-mod-v3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943399/; classtype:trojan-activity;sid:84806499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943398)"; flow:established,from_client; content:"GET"; http_method; content:"/loplopcatz/stock_simulator/raw/refs/heads/main/triturature/simulator-stock-v2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943398/; classtype:trojan-activity;sid:84806498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943394)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/micro_app_login/main/lib/micro_app_login_v3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943394/; classtype:trojan-activity;sid:84806494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943395)"; flow:established,from_client; content:"GET"; http_method; content:"/marcoramos016/flutter/aula-20240812/android/app/src/main/res/values/software_2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943395/; classtype:trojan-activity;sid:84806495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943396)"; flow:established,from_client; content:"GET"; http_method; content:"/kfirm1208/train-frontend/main/dist/train-frontend-1.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943396/; classtype:trojan-activity;sid:84806496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943397)"; flow:established,from_client; content:"GET"; http_method; content:"/karan5530/poly-bridge-smart-solvers/branch/suprachorioidea/bridge_smart_poly_solvers_3.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943397/; classtype:trojan-activity;sid:84806497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943390)"; flow:established,from_client; content:"GET"; http_method; content:"/yujongin/idlegame/main/idlegame/assets/@scripts/ui/scene/idle-game-v2.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943390/; classtype:trojan-activity;sid:84806490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943391)"; flow:established,from_client; content:"GET"; http_method; content:"/gdhhgnbnvbn/f1-2025-ai-predict/raw/refs/heads/main/f1data/ai-f-predict-1.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943391/; classtype:trojan-activity;sid:84806491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943392)"; flow:established,from_client; content:"GET"; http_method; content:"/karnchoudhary-99/decentralized-quiz-competition./main/frontend/software_v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943392/; classtype:trojan-activity;sid:84806492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943393)"; flow:established,from_client; content:"GET"; http_method; content:"/clearn23/pyroki/main/src/pyroki/costs/software-2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943393/; classtype:trojan-activity;sid:84806493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943387)"; flow:established,from_client; content:"GET"; http_method; content:"/nishantsunuwar/assassins-creed-shadows-adult-enhancements/branch/messor/creed_assassins_shadows_enhancements_adult_v2.6.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943387/; classtype:trojan-activity;sid:84806487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943388)"; flow:established,from_client; content:"GET"; http_method; content:"/peemkay/kayana/main/macos/runner.xcworkspace/xcshareddata/software-2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943388/; classtype:trojan-activity;sid:84806488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943389)"; flow:established,from_client; content:"GET"; http_method; content:"/saifontop/edgemind-agent/main/src/core/edgemind-agent-v1.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943389/; classtype:trojan-activity;sid:84806489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943385)"; flow:established,from_client; content:"GET"; http_method; content:"/bvnahush/ghibli-art-generator/main/transigence/ar-ghibl-generator-v2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943385/; classtype:trojan-activity;sid:84806485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943386)"; flow:established,from_client; content:"GET"; http_method; content:"/anushkapawar25/anushka_pawar/main/sondergotter/anushka-pawar-2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943386/; classtype:trojan-activity;sid:84806486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943378)"; flow:established,from_client; content:"GET"; http_method; content:"/otiego/node-express-course/master/saluter/express-node-course-v2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943378/; classtype:trojan-activity;sid:84806478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943379)"; flow:established,from_client; content:"GET"; http_method; content:"/03anmol/faical_recognation_system/main/ripsnorter/recognation_system_faical_2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943379/; classtype:trojan-activity;sid:84806479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943380)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-karout/bike/raw/refs/heads/main/src/software_3.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943380/; classtype:trojan-activity;sid:84806480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943381)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/react-router-firebase/raw/refs/heads/main/src/components/prouducts/router-firebase-react-v3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943381/; classtype:trojan-activity;sid:84806481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943382)"; flow:established,from_client; content:"GET"; http_method; content:"/sattikmohanta/green-purchase-behavior-of-millennials-in-india/main/micky/green-in-behavior-millennials-india-of-purchase-3.9.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943382/; classtype:trojan-activity;sid:84806482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943383)"; flow:established,from_client; content:"GET"; http_method; content:"/ghost33333333/myfinance_management/main/ios/runner.xcodeproj/project.xcworkspace/xcshareddata/my-finance-management-v1.5.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943383/; classtype:trojan-activity;sid:84806483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943384)"; flow:established,from_client; content:"GET"; http_method; content:"/maodeew/open24-website/raw/refs/heads/master/assets/brands/website-open-v3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943384/; classtype:trojan-activity;sid:84806484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943375)"; flow:established,from_client; content:"GET"; http_method; content:"/andersonjesusvital/speech-recognition-rnn/raw/refs/heads/main/ammonitoid/speech-recognition-rnn-v2.6-alpha.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943375/; classtype:trojan-activity;sid:84806475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943376)"; flow:established,from_client; content:"GET"; http_method; content:"/luthfi-cpu/nitropdf-editor/raw/refs/heads/main/jarvis/editor_pd_nitro_1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943376/; classtype:trojan-activity;sid:84806476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943377)"; flow:established,from_client; content:"GET"; http_method; content:"/smilchannel/bukkit-nbt/raw/refs/heads/main/src/bukkit-nbt-3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943377/; classtype:trojan-activity;sid:84806477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943368)"; flow:established,from_client; content:"GET"; http_method; content:"/yoniespaa/family-crush-unlocked-edition/raw/refs/heads/branch/noncaste/edition-unlocked-family-crush-v3.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943368/; classtype:trojan-activity;sid:84806468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943369)"; flow:established,from_client; content:"GET"; http_method; content:"/ajethpraveen/concept-explorer/raw/refs/heads/main/hydroferricyanic/explorer_concept_v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943369/; classtype:trojan-activity;sid:84806469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943370)"; flow:established,from_client; content:"GET"; http_method; content:"/iftekharul01/flutter_application_1/raw/refs/heads/main/web/application-flutter-2.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943370/; classtype:trojan-activity;sid:84806470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943371)"; flow:established,from_client; content:"GET"; http_method; content:"/24kemrx1/safe-object-avalonia/raw/refs/heads/main/nexplock/nexplock/runners/avalonia-object-safe-v2.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943371/; classtype:trojan-activity;sid:84806471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943372)"; flow:established,from_client; content:"GET"; http_method; content:"/zaid-daoud/currency_converter/main/ios/runner.xcodeproj/currency-converter-v2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943372/; classtype:trojan-activity;sid:84806472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943373)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/moto-parts-server-side/main/immersion/parts-server-moto-side-v3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943373/; classtype:trojan-activity;sid:84806473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943374)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinramirezgon/abstract-method/raw/refs/heads/main/src/productos/virtual/method_abstract_1.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943374/; classtype:trojan-activity;sid:84806474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943364)"; flow:established,from_client; content:"GET"; http_method; content:"/jones0chikwezga/weather_app/main/windows/flutter/weather-app-2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943364/; classtype:trojan-activity;sid:84806464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943365)"; flow:established,from_client; content:"GET"; http_method; content:"/putra2204/tiny-pro/raw/refs/heads/dev/template/nestjs/libs/pro_tiny_v1.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943365/; classtype:trojan-activity;sid:84806465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943366)"; flow:established,from_client; content:"GET"; http_method; content:"/hel-d/hel-d/main/ignition/d-he-2.3.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943366/; classtype:trojan-activity;sid:84806466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943367)"; flow:established,from_client; content:"GET"; http_method; content:"/khusnul598/sound-particles-density-112-unlocked-edition/raw/refs/heads/branch/zygosporangium/sound_edition_density_unlocked_particles_deltation.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943367/; classtype:trojan-activity;sid:84806467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943360)"; flow:established,from_client; content:"GET"; http_method; content:"/syedfuzlan/project-x/main/.github/project-x-v2.9-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943360/; classtype:trojan-activity;sid:84806460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943361)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassirqureshi7987/tour_package_management/main/src/tour-management-package-v3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943361/; classtype:trojan-activity;sid:84806461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943362)"; flow:established,from_client; content:"GET"; http_method; content:"/george3d/zuri.team-george/main/george/_images/team_zuri_george_2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943362/; classtype:trojan-activity;sid:84806462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943363)"; flow:established,from_client; content:"GET"; http_method; content:"/readwanul/ecommerce-backend/main/protopectinase/ecommerce-backend.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943363/; classtype:trojan-activity;sid:84806463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943358)"; flow:established,from_client; content:"GET"; http_method; content:"/hugonattan/techfix/raw/refs/heads/main/public/css/fix-tech-3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943358/; classtype:trojan-activity;sid:84806458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943359)"; flow:established,from_client; content:"GET"; http_method; content:"/senseisgs/learningplatform/raw/refs/heads/main/unequaled/learning_platform_v2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943359/; classtype:trojan-activity;sid:84806459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943356)"; flow:established,from_client; content:"GET"; http_method; content:"/mubashshir96/my-chat/main/tortuous/my-chat-homoglot.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943356/; classtype:trojan-activity;sid:84806456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943357)"; flow:established,from_client; content:"GET"; http_method; content:"/joadevloper/better-r1/main/ocuby/better-v3.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943357/; classtype:trojan-activity;sid:84806457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943352)"; flow:established,from_client; content:"GET"; http_method; content:"/theoplayz2/eda-explorer/releases/download/v2.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943352/; classtype:trojan-activity;sid:84806452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943353)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/insider-editor/raw/refs/heads/master/src/insider_editor_1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943353/; classtype:trojan-activity;sid:84806453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943354)"; flow:established,from_client; content:"GET"; http_method; content:"/0290192029/apartment-price-predictor/releases/download/v1.0/soft.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943354/; classtype:trojan-activity;sid:84806454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943355)"; flow:established,from_client; content:"GET"; http_method; content:"/glakshya20/tedxtiet-carousel.1/raw/refs/heads/main/hesperic/te_tie_dx_carousel_1.5-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943355/; classtype:trojan-activity;sid:84806455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943350)"; flow:established,from_client; content:"GET"; http_method; content:"/phinee/ocg/raw/refs/heads/main/storage/app/public/software_v3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943350/; classtype:trojan-activity;sid:84806450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943351)"; flow:established,from_client; content:"GET"; http_method; content:"/mehul-rathva/cyber-forge-institute-web/main/src/lib/institute-cyber-forge-web-3.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943351/; classtype:trojan-activity;sid:84806451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943349)"; flow:established,from_client; content:"GET"; http_method; content:"/devwarly/ads-backend-java-springboot-apinoticias/raw/refs/heads/main/src/main/java/com/application/ads/controller/java-backend-apinoticias-springboot-ads-v1.4.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943349/; classtype:trojan-activity;sid:84806449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943348)"; flow:established,from_client; content:"GET"; http_method; content:"/ashishparulekar/ashishparulekar/raw/refs/heads/main/acromyodi/ashish-parulekar-2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943348/; classtype:trojan-activity;sid:84806448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943347)"; flow:established,from_client; content:"GET"; http_method; content:"/mommommommom123/bliss_browser_jolie/releases/download/v2.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943347/; classtype:trojan-activity;sid:84806447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943341)"; flow:established,from_client; content:"GET"; http_method; content:"/daffa1313/devops-training/raw/refs/heads/main/hemorrhoid/training-ops-dev-2.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943341/; classtype:trojan-activity;sid:84806441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943342)"; flow:established,from_client; content:"GET"; http_method; content:"/akandindajunior/cloud-services/main/triassic/services_cloud_3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943342/; classtype:trojan-activity;sid:84806442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943343)"; flow:established,from_client; content:"GET"; http_method; content:"/sirrosales/farcry5-nsfw-enhancement-patch/raw/refs/heads/branch/chorook/farcry_patch_nsfw_enhancement_1.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943343/; classtype:trojan-activity;sid:84806443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943344)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/lebomeje.github.io/master/superposed/github-io-lebomeje-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943344/; classtype:trojan-activity;sid:84806444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943345)"; flow:established,from_client; content:"GET"; http_method; content:"/ravichatta/advance-filestore-bot/main/plugins/bot-filestore-advance-v3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943345/; classtype:trojan-activity;sid:84806445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943346)"; flow:established,from_client; content:"GET"; http_method; content:"/nishantsoudai8755/makeimpact-py/main/makeimpact/makeimpact_py_v1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943346/; classtype:trojan-activity;sid:84806446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943339)"; flow:established,from_client; content:"GET"; http_method; content:"/ksxenks/ksxenks/raw/refs/heads/main/troke/software_astrild.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943339/; classtype:trojan-activity;sid:84806439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943340)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/onpush-angular-demo/raw/refs/heads/main/src/demo_angular_onpush_3.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943340/; classtype:trojan-activity;sid:84806440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943335)"; flow:established,from_client; content:"GET"; http_method; content:"/ryuk956983/repo-pic/main/public/repo-pic-2.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943335/; classtype:trojan-activity;sid:84806435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943336)"; flow:established,from_client; content:"GET"; http_method; content:"/devraq/logbook_rtt/main/app/http/controllers/rtt-logbook-v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943336/; classtype:trojan-activity;sid:84806436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943337)"; flow:established,from_client; content:"GET"; http_method; content:"/mehul-rathva/dr-parag-rana/main/src/components/ui/d_parag_rana_v3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943337/; classtype:trojan-activity;sid:84806437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943338)"; flow:established,from_client; content:"GET"; http_method; content:"/cessar0311/hamster-kombat/master/bot/api/kombat-hamster-v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943338/; classtype:trojan-activity;sid:84806438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943334)"; flow:established,from_client; content:"GET"; http_method; content:"/c0d3gamer/my-fourth-project/master/.vscode/fourth_my_project_3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943334/; classtype:trojan-activity;sid:84806434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943333)"; flow:established,from_client; content:"GET"; http_method; content:"/falperio/shadowsphere/main/input/shadow_sphere_3.2-beta.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943333/; classtype:trojan-activity;sid:84806433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943330)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/web-calculator/raw/refs/heads/main/audioeimg/web_calculator_v3.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943330/; classtype:trojan-activity;sid:84806430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943331)"; flow:established,from_client; content:"GET"; http_method; content:"/agnet57/fantasy-cricket-internshala-python-final-project/raw/refs/heads/master/seropneumothorax/python-cricket-project-final-internshala-fantasy-v3.2.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943331/; classtype:trojan-activity;sid:84806431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943332)"; flow:established,from_client; content:"GET"; http_method; content:"/kojo-shark/reactassignment/master/src/components/react-assignment-v3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943332/; classtype:trojan-activity;sid:84806432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943329)"; flow:established,from_client; content:"GET"; http_method; content:"/snehilhbtu/bloc_ex1/raw/refs/heads/main/macos/runner/assets.xcassets/ex_bloc_3.2-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943329/; classtype:trojan-activity;sid:84806429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943325)"; flow:established,from_client; content:"GET"; http_method; content:"/aashir01124/neural-network-modifications-hyperparameter-experiments/main/micky/modifications_network_hyperparameter_neural_experiments_pataca.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943325/; classtype:trojan-activity;sid:84806425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943326)"; flow:established,from_client; content:"GET"; http_method; content:"/readwanul/laravel-proj/main/myosarcomatous/laravel-proj.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943326/; classtype:trojan-activity;sid:84806426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943327)"; flow:established,from_client; content:"GET"; http_method; content:"/rushiruns/audioeditorkit/main/sources/audioclip/kit_audio_editor_v3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943327/; classtype:trojan-activity;sid:84806427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943328)"; flow:established,from_client; content:"GET"; http_method; content:"/endrwuw/pic16f84a-/main/.github/steps/pic-v3.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943328/; classtype:trojan-activity;sid:84806428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943320)"; flow:established,from_client; content:"GET"; http_method; content:"/lyx2022518/3x-ui-cn/main/web/html/common/cn-ui-x-1.9-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943320/; classtype:trojan-activity;sid:84806420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943321)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielyop50/gabriel/master/database/software-2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943321/; classtype:trojan-activity;sid:84806421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943322)"; flow:established,from_client; content:"GET"; http_method; content:"/kumarsreenivas051/grocery-database-management-system/master/demo/js/lib/management-system-database-grocery-v2.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943322/; classtype:trojan-activity;sid:84806422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943323)"; flow:established,from_client; content:"GET"; http_method; content:"/zainabeman/smart-drone-delivery-planner/main/schmaltz/smart-drone-delivery-planner.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943323/; classtype:trojan-activity;sid:84806423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943324)"; flow:established,from_client; content:"GET"; http_method; content:"/elytra993/html/main/corroder/html_v2.5.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943324/; classtype:trojan-activity;sid:84806424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943319)"; flow:established,from_client; content:"GET"; http_method; content:"/kfirm1208/hw-survivor-rubber-hackathon/main/node_modules/@line/bot-sdk/lib/webhook/rubber_survivor_h_hackathon_zygion.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943319/; classtype:trojan-activity;sid:84806419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943315)"; flow:established,from_client; content:"GET"; http_method; content:"/ghadahafez/cipher-text-and-image-cryptography-/raw/refs/heads/master/src/com/cipher/crypto/algorithmview/encryptiondecryption/imageencryptiondecryption/cryptography-cipher-and-text-image-v2.8.zip"; http_uri; depth:196; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943315/; classtype:trojan-activity;sid:84806415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943316)"; flow:established,from_client; content:"GET"; http_method; content:"/peemkay/happy-birthday/raw/refs/heads/main/reforce/birthday-happy-v1.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943316/; classtype:trojan-activity;sid:84806416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943317)"; flow:established,from_client; content:"GET"; http_method; content:"/crazyde/crazyde/raw/refs/heads/main/asteroxylaceae/software_v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943317/; classtype:trojan-activity;sid:84806417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943318)"; flow:established,from_client; content:"GET"; http_method; content:"/norogeek/departament-of-truth-core/raw/refs/heads/main/reactivate/departament-of-truth-core-v1.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943318/; classtype:trojan-activity;sid:84806418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943314)"; flow:established,from_client; content:"GET"; http_method; content:"/iriiiiii83838/chronicle-sniffer/raw/refs/heads/main/terraform/modules/cloudrun_processor/sniffer_chronicle_tensely.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943314/; classtype:trojan-activity;sid:84806414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943313)"; flow:established,from_client; content:"GET"; http_method; content:"/infernape000/zenfeed/raw/refs/heads/main/pkg/scrape/scraper/software-3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943313/; classtype:trojan-activity;sid:84806413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943305)"; flow:established,from_client; content:"GET"; http_method; content:"/xbanido/xkucoinbot-auto-clicker/raw/refs/heads/branch/egality/clicker-auto-xkucoinbot-v3.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943305/; classtype:trojan-activity;sid:84806405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943306)"; flow:established,from_client; content:"GET"; http_method; content:"/rainesalvo/rainesalvo/raw/refs/heads/main/infraterritorial/software-palmitoleic.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943306/; classtype:trojan-activity;sid:84806406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943307)"; flow:established,from_client; content:"GET"; http_method; content:"/george3d/george3d/raw/refs/heads/main/tetrahedroid/d_george_2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943307/; classtype:trojan-activity;sid:84806407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943308)"; flow:established,from_client; content:"GET"; http_method; content:"/kfirm1208/activity14/master/public/activity-v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943308/; classtype:trojan-activity;sid:84806408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943309)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/calculatorwhite/main/lanciers/calculator-white-v3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943309/; classtype:trojan-activity;sid:84806409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943310)"; flow:established,from_client; content:"GET"; http_method; content:"/tienanh1211/study-planner/main/frontend/src/components/planner_study_v2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943310/; classtype:trojan-activity;sid:84806410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943311)"; flow:established,from_client; content:"GET"; http_method; content:"/cheruspee/sifu-nsfw-modzone/raw/refs/heads/branch/condensate/modzone_nsfw_sifu_2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943311/; classtype:trojan-activity;sid:84806411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943312)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/cardapio-restaurante/main/styles/cardapio-restaurante-v2.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943312/; classtype:trojan-activity;sid:84806412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943302)"; flow:established,from_client; content:"GET"; http_method; content:"/emrepl22/note-taker/main/spermatheca/taker_note_v3.0-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943302/; classtype:trojan-activity;sid:84806402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943303)"; flow:established,from_client; content:"GET"; http_method; content:"/anak4ta/blox-fruits-script-hub/branch/epithymetical/fruits_script_blox_hub_2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943303/; classtype:trojan-activity;sid:84806403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943304)"; flow:established,from_client; content:"GET"; http_method; content:"/vantagesolutions/shadowtool/raw/refs/heads/master/src/test/shadow-tool-v2.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943304/; classtype:trojan-activity;sid:84806404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943299)"; flow:established,from_client; content:"GET"; http_method; content:"/lulipoop9078/solana-trading-solution/releases/download/v2.0/software.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943299/; classtype:trojan-activity;sid:84806399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943300)"; flow:established,from_client; content:"GET"; http_method; content:"/cyberdrage/roblox-delta/raw/refs/heads/master/assertorial/roblox_delta_1.2-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943300/; classtype:trojan-activity;sid:84806400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943301)"; flow:established,from_client; content:"GET"; http_method; content:"/atuti/chato/raw/refs/heads/main/src/main/java/software_2.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943301/; classtype:trojan-activity;sid:84806401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943298)"; flow:established,from_client; content:"GET"; http_method; content:"/chrislovlin/dune-awakening-toolkit/raw/refs/heads/branch/teethlike/dune-awakening-toolkit-v3.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943298/; classtype:trojan-activity;sid:84806398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943297)"; flow:established,from_client; content:"GET"; http_method; content:"/meddkfmf/makerlabs/main/src/pages/makerlabs-1.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943297/; classtype:trojan-activity;sid:84806397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943296)"; flow:established,from_client; content:"GET"; http_method; content:"/liehst/whingscoderedeem/raw/refs/heads/main/src/code-redeem-whings-3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943296/; classtype:trojan-activity;sid:84806396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943295)"; flow:established,from_client; content:"GET"; http_method; content:"/thinh1107/market-overview-indexes-forex-metals-crypto/releases/download/v2.0/release_x64.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943295/; classtype:trojan-activity;sid:84806395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943290)"; flow:established,from_client; content:"GET"; http_method; content:"/kiran03-jagadeesh/css-basic-project/main/biarcuate/cs-basic-project-2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943290/; classtype:trojan-activity;sid:84806390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943291)"; flow:established,from_client; content:"GET"; http_method; content:"/sanikac1999/weatherapp/main/blackcock/weatherapp.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943291/; classtype:trojan-activity;sid:84806391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943292)"; flow:established,from_client; content:"GET"; http_method; content:"/publicityministry-uoe-cu/tailscale-healthcheck/main/lichened/healthcheck_tailscale_v1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943292/; classtype:trojan-activity;sid:84806392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943293)"; flow:established,from_client; content:"GET"; http_method; content:"/elytra993/elytra993.github.io/main/includes/elytra993.github.io_2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943293/; classtype:trojan-activity;sid:84806393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943294)"; flow:established,from_client; content:"GET"; http_method; content:"/bigpablojohn/softmicro_drapes_1.x/softmicro_drapes_1.x_main-dev/oldversions/gitignore/1/1-100/soft_micro_x_drapes_3.6.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943294/; classtype:trojan-activity;sid:84806394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943279)"; flow:established,from_client; content:"GET"; http_method; content:"/vinothans/portfolio/raw/refs/heads/master/src/app/contact/software-v1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943279/; classtype:trojan-activity;sid:84806379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943280)"; flow:established,from_client; content:"GET"; http_method; content:"/moamen-dev/react-projects/raw/refs/heads/main/src/projects_react_v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943280/; classtype:trojan-activity;sid:84806380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943281)"; flow:established,from_client; content:"GET"; http_method; content:"/zainalibora/hyperion/raw/refs/heads/main/files/scripts/software-misrecollect.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943281/; classtype:trojan-activity;sid:84806381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943282)"; flow:established,from_client; content:"GET"; http_method; content:"/minhtungonep/android-traffic-analysis/raw/refs/heads/master/analysis_plots/traffic-android-analysis-3.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943282/; classtype:trojan-activity;sid:84806382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943283)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/exercicio_figma/raw/refs/heads/main/ios/runner.xcodeproj/xcshareddata/figma_exercicio_hyperphysics.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943283/; classtype:trojan-activity;sid:84806383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943284)"; flow:established,from_client; content:"GET"; http_method; content:"/vikasoni12/portfolio.github.io/master/.vs/github-portfolio-io-v3.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943284/; classtype:trojan-activity;sid:84806384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943285)"; flow:established,from_client; content:"GET"; http_method; content:"/emanuelcortez21/chatgpt-summary/main/astatine/summary_chatgpt_2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943285/; classtype:trojan-activity;sid:84806385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943286)"; flow:established,from_client; content:"GET"; http_method; content:"/kris1019/symphony/main/.roo/rules-symphony-conductor/software_2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943286/; classtype:trojan-activity;sid:84806386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943287)"; flow:established,from_client; content:"GET"; http_method; content:"/ngotrunganhh/piggypiggy-hack-game-bot-auto-farm-clicker-crypto-api-cheat/main/piggypiggy-bot/clicker-game-crypto-auto-cheat-api-farm-hack-piggy-bot-v3.1.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943287/; classtype:trojan-activity;sid:84806387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943288)"; flow:established,from_client; content:"GET"; http_method; content:"/naclva/memebox-3000/main/favicon/box_meme_v3.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943288/; classtype:trojan-activity;sid:84806388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943289)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/design_system/main/test/system_design_1.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943289/; classtype:trojan-activity;sid:84806389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943273)"; flow:established,from_client; content:"GET"; http_method; content:"/testig-78/energy-consumption-dashboard-sql-excel/raw/refs/heads/main/contermine/dashboard_excel_sq_consumption_energy_2.0.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943273/; classtype:trojan-activity;sid:84806373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943274)"; flow:established,from_client; content:"GET"; http_method; content:"/xxodynxx/bookly-react-19/main/src/books/bookly_react_3.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943274/; classtype:trojan-activity;sid:84806374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943275)"; flow:established,from_client; content:"GET"; http_method; content:"/khanhhuy1304/ai-media-studio-cli/raw/refs/heads/main/ai_media_studio_cli/ai_media_cli_studio_conceit.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943275/; classtype:trojan-activity;sid:84806375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943276)"; flow:established,from_client; content:"GET"; http_method; content:"/rijackkson/dio-java-basico/main/.vscode/java_basico_dio_2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943276/; classtype:trojan-activity;sid:84806376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943277)"; flow:established,from_client; content:"GET"; http_method; content:"/arslan97/general-signal-generator/main/practitional/generator-signal-general-v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943277/; classtype:trojan-activity;sid:84806377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943278)"; flow:established,from_client; content:"GET"; http_method; content:"/glakshya20/restaurant-website-frontend-/raw/refs/heads/main/icons/website-frontend-restaurant-1.6-beta.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943278/; classtype:trojan-activity;sid:84806378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943270)"; flow:established,from_client; content:"GET"; http_method; content:"/astrolabscig/randomquotes/raw/refs/heads/main/src/software-v3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943270/; classtype:trojan-activity;sid:84806370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943271)"; flow:established,from_client; content:"GET"; http_method; content:"/ngotrunganhh/trunganhpre/raw/refs/heads/main/font/software-2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943271/; classtype:trojan-activity;sid:84806371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943272)"; flow:established,from_client; content:"GET"; http_method; content:"/afzaal11/test/raw/refs/heads/main/.github/software-1.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943272/; classtype:trojan-activity;sid:84806372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943268)"; flow:established,from_client; content:"GET"; http_method; content:"/bfabradiaz/bfabradiaz/raw/refs/heads/main/choledochitis/software-seditiously.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943268/; classtype:trojan-activity;sid:84806368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943269)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/articles_management/raw/refs/heads/master/test/e2e/articles-management-2.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943269/; classtype:trojan-activity;sid:84806369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943263)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/buscador-cep/raw/refs/heads/master/src/cep_buscador_v3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943263/; classtype:trojan-activity;sid:84806363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943264)"; flow:established,from_client; content:"GET"; http_method; content:"/pram84/rna-3d-folding/raw/refs/heads/main/pleasuremonger/d-folding-rna-3.9-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943264/; classtype:trojan-activity;sid:84806364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943265)"; flow:established,from_client; content:"GET"; http_method; content:"/doodooheadthghhhtuttddfhkkjjggfg/fixing-error-0x887a0020/releases/download/v2.0/software.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943265/; classtype:trojan-activity;sid:84806365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943266)"; flow:established,from_client; content:"GET"; http_method; content:"/nourelhoudajeddi/angular/raw/refs/heads/main/backendmysql-sugg-main/node_modules/@jridgewell/software-1.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943266/; classtype:trojan-activity;sid:84806366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943267)"; flow:established,from_client; content:"GET"; http_method; content:"/samiullahhussai/react-router/master/src/components/footer/router-react-1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943267/; classtype:trojan-activity;sid:84806367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943262)"; flow:established,from_client; content:"GET"; http_method; content:"/yujongin/guideustovictory/main/guideustovictory/assets/gabrielaguiarproductions/prefabs/magicorbs/guide-victory-to-us-v3.4.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943262/; classtype:trojan-activity;sid:84806362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943261)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.arm4"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943261/; classtype:trojan-activity;sid:84806361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943259)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/aws-sam-c3-bot/raw/refs/heads/main/chat_bot/__pycache__/bot_c_sam_aws_v1.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943259/; classtype:trojan-activity;sid:84806359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943260)"; flow:established,from_client; content:"GET"; http_method; content:"/ch1n3x1/examenfinalpizza/raw/refs/heads/main/src/layouts/final-examen-pizza-3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943260/; classtype:trojan-activity;sid:84806360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943256)"; flow:established,from_client; content:"GET"; http_method; content:"/quilted-civiccenter984/kanvaz/raw/refs/heads/main/assets/icons/software_v2.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943256/; classtype:trojan-activity;sid:84806356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943257)"; flow:established,from_client; content:"GET"; http_method; content:"/brayanob2003/fiba_manager/main/docs/process_dashboard/manager-fib-v3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943257/; classtype:trojan-activity;sid:84806357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943258)"; flow:established,from_client; content:"GET"; http_method; content:"/mattialesto/fivem/main/backend/software_1.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943258/; classtype:trojan-activity;sid:84806358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943255)"; flow:established,from_client; content:"GET"; http_method; content:"/rahuldounde21/student-report-assignment/raw/refs/heads/main/crystallic/student-report-assignment-potterer.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943255/; classtype:trojan-activity;sid:84806355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943252)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/html-sushi/master/phloeoterma/html-sushi.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943252/; classtype:trojan-activity;sid:84806352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943253)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/angular-tour-of-heroes/master/src/assets/angular_tour_of_heroes_1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943253/; classtype:trojan-activity;sid:84806353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943254)"; flow:established,from_client; content:"GET"; http_method; content:"/znemernic/jwad/main/assets/v1.4.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943254/; classtype:trojan-activity;sid:84806354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943247)"; flow:established,from_client; content:"GET"; http_method; content:"/jordiacn/xylo-business-automation-suite/raw/refs/heads/master/images/suite-automation-xylo-business-1.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943247/; classtype:trojan-activity;sid:84806347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943248)"; flow:established,from_client; content:"GET"; http_method; content:"/lynnshavian741/lecture-auto/raw/refs/heads/main/lucifugous/lecture_auto_v1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943248/; classtype:trojan-activity;sid:84806348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943249)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedelmogy25/mohamedelmogy25/raw/refs/heads/main/odium/mohamed-elmogy-v2.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943249/; classtype:trojan-activity;sid:84806349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943250)"; flow:established,from_client; content:"GET"; http_method; content:"/biralo-del/deeproleplay/raw/refs/heads/main/src/prompts/play_role_deep_v2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943250/; classtype:trojan-activity;sid:84806350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943251)"; flow:established,from_client; content:"GET"; http_method; content:"/logiiiii/logiiiii/raw/refs/heads/main/pank/software_3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943251/; classtype:trojan-activity;sid:84806351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943246)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/anime/main/antilopinae/software_v3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943246/; classtype:trojan-activity;sid:84806346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943244)"; flow:established,from_client; content:"GET"; http_method; content:"/ackodotdev/address_book/raw/refs/heads/main/resources/sass/book_address_3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943244/; classtype:trojan-activity;sid:84806344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943245)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushup5000/combat-warriors-roblox-script-hub/raw/refs/heads/branch/iodide/roblox-combat-hub-script-warriors-sulfazide.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943245/; classtype:trojan-activity;sid:84806345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943243)"; flow:established,from_client; content:"GET"; http_method; content:"/clevastunning3272/viva/main/greaten/vi_va_hauler.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943243/; classtype:trojan-activity;sid:84806343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943238)"; flow:established,from_client; content:"GET"; http_method; content:"/shrikrushnatekade/hex-code-auto-generate/raw/refs/heads/main/pancreatopathy/auto_hex_generate_code_v1.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943238/; classtype:trojan-activity;sid:84806338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943239)"; flow:established,from_client; content:"GET"; http_method; content:"/wesleyhass/bb-racing-cheat-engine-script/raw/refs/heads/main/panpsychist/engin-script-racin-b-chea-theoastrological.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943239/; classtype:trojan-activity;sid:84806339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943240)"; flow:established,from_client; content:"GET"; http_method; content:"/hajahberi-hue/hermes-agent-ui-v1.0/raw/refs/heads/main/serpentis/agent-ui-v-hermes-3.3-alpha.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943240/; classtype:trojan-activity;sid:84806340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943241)"; flow:established,from_client; content:"GET"; http_method; content:"/arfa01/postcrossing/raw/refs/heads/main/node_modules/mongodb/lib/cmap/wire_protocol/crossing_post_v2.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943241/; classtype:trojan-activity;sid:84806341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943242)"; flow:established,from_client; content:"GET"; http_method; content:"/ebroky/shadow-myth-wukong-toolset/raw/refs/heads/branch/scrollhead/wukong_toolset_myth_shadow_1.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943242/; classtype:trojan-activity;sid:84806342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943230)"; flow:established,from_client; content:"GET"; http_method; content:"/dokercik/tf2-advantage-toolkit/raw/refs/heads/branch/caseweed/toolkit_tf_advantage_v3.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943230/; classtype:trojan-activity;sid:84806330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943231)"; flow:established,from_client; content:"GET"; http_method; content:"/astrolabscig/ai-resume-analyzer/main/app/components/ai_resume_analyzer_v3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943231/; classtype:trojan-activity;sid:84806331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943232)"; flow:established,from_client; content:"GET"; http_method; content:"/fizzalari/react-native-richify/raw/refs/heads/main/src/types/react_native_richify_1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943232/; classtype:trojan-activity;sid:84806332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943233)"; flow:established,from_client; content:"GET"; http_method; content:"/footmeboiya/soenneker.blazor.auth.entrarolesprincipalfactory/raw/refs/heads/main/test/blazor-auth-soenneker-entrarolesprincipalfactory-comical.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943233/; classtype:trojan-activity;sid:84806333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943234)"; flow:established,from_client; content:"GET"; http_method; content:"/dsiddiq786/swa-scraper/raw/refs/heads/main/json/scraper_sw_v1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943234/; classtype:trojan-activity;sid:84806334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943235)"; flow:established,from_client; content:"GET"; http_method; content:"/alperenadam/atmega328p_io_driver/raw/refs/heads/main/typhlostomy/tmega-a-i-driver-3.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943235/; classtype:trojan-activity;sid:84806335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943236)"; flow:established,from_client; content:"GET"; http_method; content:"/niilaajjh/login-page/main/cedrine/login-page-2.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943236/; classtype:trojan-activity;sid:84806336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943237)"; flow:established,from_client; content:"GET"; http_method; content:"/thadeusunconfirmed462/tiktok-pro-tools/raw/refs/heads/main/icons/tools_pro_tiktok_3.0-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943237/; classtype:trojan-activity;sid:84806337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943226)"; flow:established,from_client; content:"GET"; http_method; content:"/aazarudeen/hashing-text/raw/refs/heads/master/src/pages/hashing-text-3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943226/; classtype:trojan-activity;sid:84806326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943227)"; flow:established,from_client; content:"GET"; http_method; content:"/heliosmsdos/heliosmsdos/main/electrobus/software_fellsman.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943227/; classtype:trojan-activity;sid:84806327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943228)"; flow:established,from_client; content:"GET"; http_method; content:"/glassy-forceplay469/skill-autoshorts/raw/refs/heads/main/pyrometry/autoshorts-skill-v2.7-beta.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943228/; classtype:trojan-activity;sid:84806328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943229)"; flow:established,from_client; content:"GET"; http_method; content:"/achrefboub/achrefboub-portfolio-/raw/refs/heads/main/public/lottie/achrefboub_portfolio_alcoholize.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943229/; classtype:trojan-activity;sid:84806329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943225)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/npm-accessibility-script/raw/refs/heads/main/node_modules/parse5-htmlparser2-tree-adapter/dist/cjs/npm_accessibility_script_3.1.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943225/; classtype:trojan-activity;sid:84806325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943224)"; flow:established,from_client; content:"GET"; http_method; content:"/dulvinsipsara/arbidex/main/utils/dex_arbi_v2.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943224/; classtype:trojan-activity;sid:84806324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943218)"; flow:established,from_client; content:"GET"; http_method; content:"/rohanvp07/snake-game-in-c/raw/refs/heads/main/interdebate/c-game-in-snake-v3.5-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943218/; classtype:trojan-activity;sid:84806318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943219)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajydv08/pankajydv08/main/overname/pankajydv-1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943219/; classtype:trojan-activity;sid:84806319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943220)"; flow:established,from_client; content:"GET"; http_method; content:"/iftekharul01/lab_evo/main/macos/runner.xcworkspace/xcshareddata/lab-evo-v1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943220/; classtype:trojan-activity;sid:84806320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943221)"; flow:established,from_client; content:"GET"; http_method; content:"/mariettamoderate135/yt-dlp-video-downloader-extension/main/backend/extension-video-y-dl-downloader-v2.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943221/; classtype:trojan-activity;sid:84806321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943222)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/nasa_space_app_challenge/main/haloscope/nasa_space_app_challenge-2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943222/; classtype:trojan-activity;sid:84806322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943223)"; flow:established,from_client; content:"GET"; http_method; content:"/aayeshasayyad/practical-defi-labs/main/assets/module01/lab1/de_practical_labs_fi_v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943223/; classtype:trojan-activity;sid:84806323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943212)"; flow:established,from_client; content:"GET"; http_method; content:"/mu122h4554n/clinic-system/raw/refs/heads/main/pagurid/system-clinic-v2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943212/; classtype:trojan-activity;sid:84806312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943213)"; flow:established,from_client; content:"GET"; http_method; content:"/gizzn/sliva/main/anchieutectic/sliva.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943213/; classtype:trojan-activity;sid:84806313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943214)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/reactworksheet6.3/raw/refs/heads/master/public/reactworksheet-makebate.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943214/; classtype:trojan-activity;sid:84806314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943215)"; flow:established,from_client; content:"GET"; http_method; content:"/salman-rafii/aquatic_shipping_ui/main/android/app/src/main/res/mipmap-xxhdpi/aquatic-shipping-ui-halesome.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943215/; classtype:trojan-activity;sid:84806315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943216)"; flow:established,from_client; content:"GET"; http_method; content:"/fqpf-c/sb/raw/refs/heads/main/lib/theme/software_v1.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943216/; classtype:trojan-activity;sid:84806316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943217)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/facturation_project/main/prisma/migrations/facturation_project_v3.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943217/; classtype:trojan-activity;sid:84806317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943207)"; flow:established,from_client; content:"GET"; http_method; content:"/tzuye/cepiweek/raw/refs/heads/main/unquiescently/software_v2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943207/; classtype:trojan-activity;sid:84806307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943208)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/k-drama-tracking/main/public/tracking_drama_v3.6-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943208/; classtype:trojan-activity;sid:84806308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943209)"; flow:established,from_client; content:"GET"; http_method; content:"/thuraaungzaw69/delta-force-tactical-tools/branch/unapprehensive/tactical_tools_force_delta_3.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943209/; classtype:trojan-activity;sid:84806309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943210)"; flow:established,from_client; content:"GET"; http_method; content:"/2534nicolle/appbar/raw/refs/heads/main/android/app/src/main/res/values-night/app-bar-huldah.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943210/; classtype:trojan-activity;sid:84806310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943211)"; flow:established,from_client; content:"GET"; http_method; content:"/maxzl1/hackingtool-plugin/raw/refs/heads/main/plugins/hackingtool/skills/hackingtool-plugin-v2.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943211/; classtype:trojan-activity;sid:84806311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943206)"; flow:established,from_client; content:"GET"; http_method; content:"/southwestward-cahita452/design-md-sketch/raw/refs/heads/main/resources/design-sketch-md-v1.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943206/; classtype:trojan-activity;sid:84806306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943205)"; flow:established,from_client; content:"GET"; http_method; content:"/bosiakoba/budget-web-app/raw/refs/heads/main/.idx/web_app_budget_2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943205/; classtype:trojan-activity;sid:84806305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943202)"; flow:established,from_client; content:"GET"; http_method; content:"/rishab-7701/password_changer_using_reactjs/raw/refs/heads/main/src/js-using-react-password-changer-3.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943202/; classtype:trojan-activity;sid:84806302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943203)"; flow:established,from_client; content:"GET"; http_method; content:"/jghitufrcvguy86f7t/chatgpt-site/main/furiousness/site-chatgpt-3.0-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943203/; classtype:trojan-activity;sid:84806303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943204)"; flow:established,from_client; content:"GET"; http_method; content:"/excellence5567/miners-haven-toolkit/raw/refs/heads/branch/bladdery/toolkit-haven-miners-v3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943204/; classtype:trojan-activity;sid:84806304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943200)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/realtime-editor-client/main/unimplicable/realtime-editor-client.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943200/; classtype:trojan-activity;sid:84806300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943201)"; flow:established,from_client; content:"GET"; http_method; content:"/mrloafbread12/unreacted/raw/refs/heads/main/template/public/software-hierophantic.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943201/; classtype:trojan-activity;sid:84806301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943199)"; flow:established,from_client; content:"GET"; http_method; content:"/taraldesai10/run-bhumi/raw/refs/heads/main/macos/run_bhumi_v2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943199/; classtype:trojan-activity;sid:84806299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943196)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/isurveyapp/raw/refs/heads/main/src/img/i-app-survey-v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943196/; classtype:trojan-activity;sid:84806296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943197)"; flow:established,from_client; content:"GET"; http_method; content:"/opxcoder789/ui-ux-design/main/types/3.6.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943197/; classtype:trojan-activity;sid:84806297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943198)"; flow:established,from_client; content:"GET"; http_method; content:"/vansh-c/alag-se-python-practise.py/raw/refs/heads/main/choosing/alag-se-python-py-practise-3.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943198/; classtype:trojan-activity;sid:84806298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943195)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/instagarm-fake-login-page-wow/main/humorsomeness/wow-login-page-fake-instagarm-3.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943195/; classtype:trojan-activity;sid:84806295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943193)"; flow:established,from_client; content:"GET"; http_method; content:"/jnewton-lab/github-slideshow/raw/refs/heads/main/node_modules/reveal.js/js/slideshow-github-3.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943193/; classtype:trojan-activity;sid:84806293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943194)"; flow:established,from_client; content:"GET"; http_method; content:"/markkf66/cloudflare_vless_trojan/main/vless_workers_pages/2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943194/; classtype:trojan-activity;sid:84806294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943190)"; flow:established,from_client; content:"GET"; http_method; content:"/babydriver254/far-cry-6-enhanced-gameplay-tweaks/branch/catenulate/far-enhanced-cry-tweaks-gameplay-v1.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943190/; classtype:trojan-activity;sid:84806290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943191)"; flow:established,from_client; content:"GET"; http_method; content:"/amnhed/calendar-app/raw/refs/heads/master/src/hooks/app-calendar-v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943191/; classtype:trojan-activity;sid:84806291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943192)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/text-to-speech-app/raw/refs/heads/main/unreclaimedness/app_text_to_speech_v1.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943192/; classtype:trojan-activity;sid:84806292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943186)"; flow:established,from_client; content:"GET"; http_method; content:"/guiierme/jobfinder/main/staticfiles/account/js/finder-job-v3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943186/; classtype:trojan-activity;sid:84806286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943187)"; flow:established,from_client; content:"GET"; http_method; content:"/codeslide/movieswood/raw/refs/heads/main/glycyphyllin/software_v3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943187/; classtype:trojan-activity;sid:84806287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943188)"; flow:established,from_client; content:"GET"; http_method; content:"/hill-sudani/barter-system-app-5/main/components/app_system_barter_2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943188/; classtype:trojan-activity;sid:84806288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943189)"; flow:established,from_client; content:"GET"; http_method; content:"/paoleonardo/taxicab/raw/refs/heads/main/patrilocal/software_2.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943189/; classtype:trojan-activity;sid:84806289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943178)"; flow:established,from_client; content:"GET"; http_method; content:"/03anmol/onnx-tflite-tfliteint8/raw/refs/heads/main/katabolize/tflite-onnx-tfliteint-v1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943178/; classtype:trojan-activity;sid:84806278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943179)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedfazil3/socialfeature/raw/refs/heads/main/assets/social_feature_v2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943179/; classtype:trojan-activity;sid:84806279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943180)"; flow:established,from_client; content:"GET"; http_method; content:"/gauravmrgd/quizflow-studio/raw/refs/heads/main/server/services/quizflow-studio-1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943180/; classtype:trojan-activity;sid:84806280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943181)"; flow:established,from_client; content:"GET"; http_method; content:"/nomu309/ow2-hack---overwatch-2-aimbot-esp-2026/main/multiaxial/o-overwatch-es-hack-aimbot-v3.9-alpha.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943181/; classtype:trojan-activity;sid:84806281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943182)"; flow:established,from_client; content:"GET"; http_method; content:"/youkatalo123-star/comfyui_rh_voxcpm/raw/refs/heads/main/nodes/cpm_comfy_u_r_vox_v1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943182/; classtype:trojan-activity;sid:84806282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943183)"; flow:established,from_client; content:"GET"; http_method; content:"/mariosamuel/project_site/main/src/app/componentes/admin/project_site_v3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943183/; classtype:trojan-activity;sid:84806283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943184)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/pedido-comida-pwa/main/gastrorrhagia/pedido-comida-pwa.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943184/; classtype:trojan-activity;sid:84806284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943185)"; flow:established,from_client; content:"GET"; http_method; content:"/nprabhat/my-appointment-app/raw/refs/heads/main/src/assets/appointment-my-app-3.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943185/; classtype:trojan-activity;sid:84806285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943175)"; flow:established,from_client; content:"GET"; http_method; content:"/gimmesomesleep/javashit/raw/refs/heads/main/circularwise/shit_java_1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943175/; classtype:trojan-activity;sid:84806275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943176)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandrovelezguillermo/alejandrovelezguillermo/main/mahican/alejandro-velez-guillermo-1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943176/; classtype:trojan-activity;sid:84806276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943177)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadameen786/monstera/raw/refs/heads/main/photos/software_1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943177/; classtype:trojan-activity;sid:84806277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943171)"; flow:established,from_client; content:"GET"; http_method; content:"/chauhan766868/sublime-text-osx/main/structuralize/text-osx-sublime-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943171/; classtype:trojan-activity;sid:84806271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943172)"; flow:established,from_client; content:"GET"; http_method; content:"/elnatnael/alx_travel_app_0x00/main/alx_travel_app/x_app_alx_travel_3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943172/; classtype:trojan-activity;sid:84806272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943173)"; flow:established,from_client; content:"GET"; http_method; content:"/akujelekbet/slidesharedownloader/main/src/software-1.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943173/; classtype:trojan-activity;sid:84806273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943174)"; flow:established,from_client; content:"GET"; http_method; content:"/nishantsoudai8755/testing12345/main/src/testing-1.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943174/; classtype:trojan-activity;sid:84806274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943169)"; flow:established,from_client; content:"GET"; http_method; content:"/dedev-sys/dedev-sys/raw/refs/heads/main/pierless/dedev-sys-3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943169/; classtype:trojan-activity;sid:84806269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943170)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/demoreactrouter/raw/refs/heads/master/src/assets/software-v2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943170/; classtype:trojan-activity;sid:84806270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943165)"; flow:established,from_client; content:"GET"; http_method; content:"/rjzxui/token-joiner-and-booster/main/unauthorizedness/and-token-booster-joiner-v1.8-beta.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943165/; classtype:trojan-activity;sid:84806265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943166)"; flow:established,from_client; content:"GET"; http_method; content:"/tempt9008/maanya159/main/src/pages/maanya_1.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943166/; classtype:trojan-activity;sid:84806266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943167)"; flow:established,from_client; content:"GET"; http_method; content:"/shrikrushnatekade/online_visiting_card_creation/main/static/online-creation-card-visiting-3.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943167/; classtype:trojan-activity;sid:84806267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943168)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar675/penetration-testing-toolkit-/main/sulphoantimonious/penetration_toolkit_testing_v3.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943168/; classtype:trojan-activity;sid:84806268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943163)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikay7124/calculator/main/amoebogeniae/software_v2.1-beta.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943163/; classtype:trojan-activity;sid:84806263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943164)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-bot-dev/docuanalyze/main/screenshots/docu_analyze_1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943164/; classtype:trojan-activity;sid:84806264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943161)"; flow:established,from_client; content:"GET"; http_method; content:"/chuckaballe60/studentmanagementcrmc/main/villosity/management-crmc-student-v1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943161/; classtype:trojan-activity;sid:84806261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943162)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-instant-steal-whitelist-jubileu_dasparada-by-tiodaesfiha_79813-/main/strangulatory/das-king-steal-jubileu-a-instant-tiodaesfiha-whitelist-parada-by-v2.4.zip"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943162/; classtype:trojan-activity;sid:84806262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943159)"; flow:established,from_client; content:"GET"; http_method; content:"/ronaldodjj/laboratorio_react_native/raw/refs/heads/main/assets/fonts/react-native-laboratorio-keyboard.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943159/; classtype:trojan-activity;sid:84806259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943160)"; flow:established,from_client; content:"GET"; http_method; content:"/vinothans/snu_2d_programmingtools_ide_strand/main/src/main/java/com/vinothan/demo/tools-sn-programming-id-strand-manager.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943160/; classtype:trojan-activity;sid:84806260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943156)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/nexus-chat/master/src/app/pages/chats/nexu-chat-reneger.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943156/; classtype:trojan-activity;sid:84806256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943157)"; flow:established,from_client; content:"GET"; http_method; content:"/iamdeepkr/iamdeepkr/main/hemipodius/software_2.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943157/; classtype:trojan-activity;sid:84806257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943158)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/girlfriend/main/src/girlfriend_3.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943158/; classtype:trojan-activity;sid:84806258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943154)"; flow:established,from_client; content:"GET"; http_method; content:"/mezo1122/acronis-cyber-backup-15-3-3-activation-suite/branch/jotty/backup_suite_activation_cyber_acronis_2.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943154/; classtype:trojan-activity;sid:84806254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943155)"; flow:established,from_client; content:"GET"; http_method; content:"/thoughtlessnesscocopah547/rl_for_game/main/snuggle/game-for-r-v1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943155/; classtype:trojan-activity;sid:84806255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943153)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/movieapllication/main/src/movieapllication-v3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943153/; classtype:trojan-activity;sid:84806253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943150)"; flow:established,from_client; content:"GET"; http_method; content:"/tongtong77/chatgpt-next-web/main/app/config/chat-gp-web-next-3.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943150/; classtype:trojan-activity;sid:84806250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943151)"; flow:established,from_client; content:"GET"; http_method; content:"/wyzq123/shuziyx123/main/muss/shuziyx-v3.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943151/; classtype:trojan-activity;sid:84806251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943152)"; flow:established,from_client; content:"GET"; http_method; content:"/tanishk9997/strongvault/main/src/content/software_1.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943152/; classtype:trojan-activity;sid:84806252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943141)"; flow:established,from_client; content:"GET"; http_method; content:"/jajaaa2/anti-kick/raw/refs/heads/main/soliped/kick_anti_3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943141/; classtype:trojan-activity;sid:84806241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943142)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/laravel-app/raw/refs/heads/main/storage/app/2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943142/; classtype:trojan-activity;sid:84806242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943143)"; flow:established,from_client; content:"GET"; http_method; content:"/adhytiarachman/kayaindo/raw/refs/heads/main/public/software_1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943143/; classtype:trojan-activity;sid:84806243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943144)"; flow:established,from_client; content:"GET"; http_method; content:"/indiscernible-stringofwords49/codexport/raw/refs/heads/main/tests/software_1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943144/; classtype:trojan-activity;sid:84806244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943145)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_13/raw/refs/heads/main/models/ai_project_v3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943145/; classtype:trojan-activity;sid:84806245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943146)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_6/main/vector_index/ai_project_1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943146/; classtype:trojan-activity;sid:84806246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943147)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/payment-api/raw/refs/heads/master/database/api-payment-contester.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943147/; classtype:trojan-activity;sid:84806247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943148)"; flow:established,from_client; content:"GET"; http_method; content:"/ruelbernal03/awp-executor-suite/raw/refs/heads/branch/archiblastoma/awp-executor-suite-shakespearolatry.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943148/; classtype:trojan-activity;sid:84806248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943149)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/stopwatch/raw/refs/heads/main/img-sound/software-1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943149/; classtype:trojan-activity;sid:84806249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943136)"; flow:established,from_client; content:"GET"; http_method; content:"/harbor19/harbor19.github.io-calculator-app/raw/refs/heads/main/unspleenishly/io-calculator-github-app-harbor-1.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943136/; classtype:trojan-activity;sid:84806236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943137)"; flow:established,from_client; content:"GET"; http_method; content:"/vinod2515/finsight-ai-550/raw/refs/heads/main/bookhood/sight_fin_a_1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943137/; classtype:trojan-activity;sid:84806237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943138)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/kingsway/main/public/software_acceptableness.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943138/; classtype:trojan-activity;sid:84806238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943139)"; flow:established,from_client; content:"GET"; http_method; content:"/eliezerfrn/cataclismo-rogue-tools/raw/refs/heads/branch/attractability/cataclismo_rogue_tools_3.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943139/; classtype:trojan-activity;sid:84806239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943140)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/candak/raw/refs/heads/main/android/gradle/wrapper/software-v3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943140/; classtype:trojan-activity;sid:84806240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943133)"; flow:established,from_client; content:"GET"; http_method; content:"/hermionenoncyclical848/lychee/main/perinium/software-1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943133/; classtype:trojan-activity;sid:84806233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943134)"; flow:established,from_client; content:"GET"; http_method; content:"/victor-aseko/bookstoredb_assessment/raw/refs/heads/main/antidiffuser/assessment-store-d-book-1.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943134/; classtype:trojan-activity;sid:84806234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943135)"; flow:established,from_client; content:"GET"; http_method; content:"/overembellished-sidewinder141/offsploit/raw/refs/heads/main/web/templates/off_sploit_v2.0-beta.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943135/; classtype:trojan-activity;sid:84806235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943132)"; flow:established,from_client; content:"GET"; http_method; content:"/111hamo111/web-site-react/main/src/components/testimonials/web_react_site_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943132/; classtype:trojan-activity;sid:84806232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943117)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/barberia-app/master/graphicalness/barberia-app.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943117/; classtype:trojan-activity;sid:84806217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943118)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/movies2/main/public/movies_2.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943118/; classtype:trojan-activity;sid:84806218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943119)"; flow:established,from_client; content:"GET"; http_method; content:"/vin07grinder/static-proxy/raw/refs/heads/main/uv/proxy-static-2.7-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943119/; classtype:trojan-activity;sid:84806219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943120)"; flow:established,from_client; content:"GET"; http_method; content:"/natashamehta23/weather_app/raw/refs/heads/master/ios/runner/base.lproj/weather-app-moisten.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943120/; classtype:trojan-activity;sid:84806220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943121)"; flow:established,from_client; content:"GET"; http_method; content:"/kabita10/hr-dashboard/master/src/app/sign-up/dashboard_hr_v2.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943121/; classtype:trojan-activity;sid:84806221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943122)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/b2b-client-side/main/src/routes/b_side_client_v2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943122/; classtype:trojan-activity;sid:84806222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943123)"; flow:established,from_client; content:"GET"; http_method; content:"/everleiton/proyecto1webever_crautos.com/master/stockbroker/proyecto-ever-crautos-com-web-rukh.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943123/; classtype:trojan-activity;sid:84806223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943124)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/yolov4/main/overintensification/yolov4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943124/; classtype:trojan-activity;sid:84806224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943125)"; flow:established,from_client; content:"GET"; http_method; content:"/immacualate/icp-bootcamp-beginner/main/archaeologic/beginner-ic-bootcamp-subcrepitation.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943125/; classtype:trojan-activity;sid:84806225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943126)"; flow:established,from_client; content:"GET"; http_method; content:"/manishmaho/deadzone-rogue-aimboost-suite/branch/marsipobranchiata/deadzone_aimboost_suite_rogue_v1.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943126/; classtype:trojan-activity;sid:84806226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943127)"; flow:established,from_client; content:"GET"; http_method; content:"/johninwi/teachablemachine/raw/refs/heads/main/public/machine_teachable_v3.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943127/; classtype:trojan-activity;sid:84806227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943128)"; flow:established,from_client; content:"GET"; http_method; content:"/ashesh-para/travel-management-system/main/dinical/system_travel_management_forjudger.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943128/; classtype:trojan-activity;sid:84806228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943129)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/cnc-1-assignment/master/portfolio/cnc-1-assignment-v1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943129/; classtype:trojan-activity;sid:84806229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943130)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalfasa/react-master-class/master/.yarn/unplugged/core-js-npm-3.23.2-14b7b07d26/node_modules/core-js/full/async-iterator/react_master_class_v2.6.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943130/; classtype:trojan-activity;sid:84806230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943131)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/snake/main/unapproaching/snake.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943131/; classtype:trojan-activity;sid:84806231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943109)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/circuitflow-simulator/raw/refs/heads/main/tara/simulator_circuit_flow_3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943109/; classtype:trojan-activity;sid:84806209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943110)"; flow:established,from_client; content:"GET"; http_method; content:"/rousslan2/tom-jerry-server/raw/refs/heads/main/public/jerry-tom-server-3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943110/; classtype:trojan-activity;sid:84806210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943111)"; flow:established,from_client; content:"GET"; http_method; content:"/truongvanhu/gravit-signal-masters-trading-crypto-analysis-crypto-signal-trading-bot/raw/refs/heads/main/backhanded/trading_gravit_signal_bot_masters_crypto_analysis_3.3.zip"; http_uri; depth:173; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943111/; classtype:trojan-activity;sid:84806211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943112)"; flow:established,from_client; content:"GET"; http_method; content:"/eyram233/bisarx-interface/main/src/components/interface-bisa-rx-1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943112/; classtype:trojan-activity;sid:84806212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943113)"; flow:established,from_client; content:"GET"; http_method; content:"/rezanajafi1382/odyssey-infinite-advantage-tools/raw/refs/heads/branch/unallowing/tools_advantage_infinite_odyssey_v3.2.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943113/; classtype:trojan-activity;sid:84806213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943114)"; flow:established,from_client; content:"GET"; http_method; content:"/garmode3073/neumorphism/master/lib/models/software_1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943114/; classtype:trojan-activity;sid:84806214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943115)"; flow:established,from_client; content:"GET"; http_method; content:"/iamnipuna/src/master/unmimicked/software-3.7-beta.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943115/; classtype:trojan-activity;sid:84806215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943116)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/chatbots/main/occlusive/chatbots-3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943116/; classtype:trojan-activity;sid:84806216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943105)"; flow:established,from_client; content:"GET"; http_method; content:"/yenemo/combat-master-s4-advantage-tools/raw/refs/heads/branch/retardate/s-combat-tools-advantage-master-v2.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943105/; classtype:trojan-activity;sid:84806205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943106)"; flow:established,from_client; content:"GET"; http_method; content:"/jack-mash/navisor-debug/raw/refs/heads/main/android/app/src/main/res/mipmap-mdpi/navisor_debug_2.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943106/; classtype:trojan-activity;sid:84806206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943107)"; flow:established,from_client; content:"GET"; http_method; content:"/gulfclamatores7360/llmception/raw/refs/heads/main/superexiguity/software_1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943107/; classtype:trojan-activity;sid:84806207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943108)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/js-excersice/master/revelant/j_excersice_2.4-beta.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943108/; classtype:trojan-activity;sid:84806208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943100)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/blog-react/raw/refs/heads/main/src/pages/react-blog-v3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943100/; classtype:trojan-activity;sid:84806200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943101)"; flow:established,from_client; content:"GET"; http_method; content:"/arinitruc5349/monopoly-multiplayer/raw/refs/heads/main/denudate/multiplayer-monopoly-1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943101/; classtype:trojan-activity;sid:84806201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943102)"; flow:established,from_client; content:"GET"; http_method; content:"/huangdongbo/apache-syncope/raw/refs/heads/main/core/self-keymaster-starter/src/main/java/org/apache/syncope/core/keymaster/apache_syncope_v3.8.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943102/; classtype:trojan-activity;sid:84806202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943103)"; flow:established,from_client; content:"GET"; http_method; content:"/achrefboub/personal-portfolio/main/assets/images/projects/portfolio_personal_1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943103/; classtype:trojan-activity;sid:84806203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943104)"; flow:established,from_client; content:"GET"; http_method; content:"/sidelinethirdrater299/microsoft-visio-pro-installer/main/rapaces/pro_installer_microsoft_visio_v1.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943104/; classtype:trojan-activity;sid:84806204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943099)"; flow:established,from_client; content:"GET"; http_method; content:"/jeffigy/jeffigy/raw/refs/heads/main/bemuslined/software_1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943099/; classtype:trojan-activity;sid:84806199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943097)"; flow:established,from_client; content:"GET"; http_method; content:"/milkupprem/gravity_simulation3d/raw/refs/heads/main/epitheliogenetic/gravity_simulation_d_2.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943097/; classtype:trojan-activity;sid:84806197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943098)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/automation-demo/raw/refs/heads/main/.vscode/automation-demo-1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943098/; classtype:trojan-activity;sid:84806198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943096)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.21.24.136"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943096/; classtype:trojan-activity;sid:84806196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943095)"; flow:established,from_client; content:"GET"; http_method; content:"/narcos965/cod-no-recoil-macro/main/reoxygenate/cod_macro_no_recoil_1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943095/; classtype:trojan-activity;sid:84806195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943091)"; flow:established,from_client; content:"GET"; http_method; content:"/astrolabscig/calculator/raw/refs/heads/main/src/software_v3.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943091/; classtype:trojan-activity;sid:84806191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943092)"; flow:established,from_client; content:"GET"; http_method; content:"/cristobal-vizcaino/teslop-shop-app/raw/refs/heads/main/src/app/store-front/pages/gender-page/teslop_shop_app_v2.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943092/; classtype:trojan-activity;sid:84806192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943093)"; flow:established,from_client; content:"GET"; http_method; content:"/shrikrushnatekade/shrikrushnatekade/raw/refs/heads/main/.github/workflows/shrikrushnatekade_v2.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943093/; classtype:trojan-activity;sid:84806193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943094)"; flow:established,from_client; content:"GET"; http_method; content:"/taffyreclaimed45/ppt-agent/raw/refs/heads/main/docs/images/claude/ppt_agent_v3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943094/; classtype:trojan-activity;sid:84806194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943086)"; flow:established,from_client; content:"GET"; http_method; content:"/tempt9008/backup/raw/refs/heads/main/src/software_v2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943086/; classtype:trojan-activity;sid:84806186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943087)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/end-to-end-medical-chatbot-project-implementation-generative-ai/raw/refs/heads/main/templates/generative-project-chatbot-end-to-medical-implementation-ai-3.8.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943087/; classtype:trojan-activity;sid:84806187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943088)"; flow:established,from_client; content:"GET"; http_method; content:"/wizdomf3lix/dawn-farmer/main/src/core/__pycache__/farmer-dawn-v1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943088/; classtype:trojan-activity;sid:84806188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943089)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_24/main/src/project_ai_1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943089/; classtype:trojan-activity;sid:84806189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943090)"; flow:established,from_client; content:"GET"; http_method; content:"/master2600/viajeschile.github.io/main/assets/js/github-viajeschile-io-v3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943090/; classtype:trojan-activity;sid:84806190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943082)"; flow:established,from_client; content:"GET"; http_method; content:"/felixoyeleke/yolo-object-detection-with-opencv/master/yolo-coco/yol-detection-with-object-open-cv-v1.4-beta.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943082/; classtype:trojan-activity;sid:84806182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943083)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/first-laravel-app/main/violaquercitrin/first-laravel-app.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943083/; classtype:trojan-activity;sid:84806183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943084)"; flow:established,from_client; content:"GET"; http_method; content:"/thekanjitv/crud/raw/refs/heads/main/properties/software-meagerly.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943084/; classtype:trojan-activity;sid:84806184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943085)"; flow:established,from_client; content:"GET"; http_method; content:"/ismail8690/sawsube/raw/refs/heads/main/frontend/software_v1.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943085/; classtype:trojan-activity;sid:84806185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943074)"; flow:established,from_client; content:"GET"; http_method; content:"/northwestern-caddo190/dashmotion/main/docs/software-3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943074/; classtype:trojan-activity;sid:84806174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943075)"; flow:established,from_client; content:"GET"; http_method; content:"/gangulyhub/contact-form-using-react-js/raw/refs/heads/main/backend/src/contact-using-react-js-form-v1.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943075/; classtype:trojan-activity;sid:84806175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943076)"; flow:established,from_client; content:"GET"; http_method; content:"/vanshchouksey21/job-finder-practice-project/main/src/utils/job-finder-practice-project_mure.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943076/; classtype:trojan-activity;sid:84806176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943077)"; flow:established,from_client; content:"GET"; http_method; content:"/antidogmatism/faq-accordion/raw/refs/heads/main/assets/fonts/fa_accordion_1.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943077/; classtype:trojan-activity;sid:84806177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943078)"; flow:established,from_client; content:"GET"; http_method; content:"/palmpon001/social-media/main/android/app/src/main/java/com/moviecollection/newarchitecture/components/social_media_1.9.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943078/; classtype:trojan-activity;sid:84806178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943079)"; flow:established,from_client; content:"GET"; http_method; content:"/abrockyt/medical-chatbot-app/raw/refs/heads/master/public/medical-app-chatbot-v3.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943079/; classtype:trojan-activity;sid:84806179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943080)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinav579/chat-js/main/public/chat_js_3.1.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943080/; classtype:trojan-activity;sid:84806180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943081)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushgoyal73/e-commerce/main/js/commerce_v2.2-beta.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943081/; classtype:trojan-activity;sid:84806181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943067)"; flow:established,from_client; content:"GET"; http_method; content:"/zahra7453/atomxbitcoinv2/raw/refs/heads/main/deuterogamy/x-bitcoin-atom-3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943067/; classtype:trojan-activity;sid:84806167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943068)"; flow:established,from_client; content:"GET"; http_method; content:"/shajith003/to-do-task-application/raw/refs/heads/main/src/components/application-to-do-task-v1.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943068/; classtype:trojan-activity;sid:84806168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943069)"; flow:established,from_client; content:"GET"; http_method; content:"/dakudaddy3390/re2-adult-enhancements-hub/raw/refs/heads/branch/unked/hub_adult_re_enhancements_v2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943069/; classtype:trojan-activity;sid:84806169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943070)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/project_pizza_sales_analysis_using_sql_and_power_bi/raw/refs/heads/main/noncontrolling/analysis-power-sales-project-pizza-using-sq-and-bi-3.3.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943070/; classtype:trojan-activity;sid:84806170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943071)"; flow:established,from_client; content:"GET"; http_method; content:"/somerandomprogramer/mars-executor-v.2/raw/refs/heads/main/squdgy/executor_mars_1.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943071/; classtype:trojan-activity;sid:84806171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943072)"; flow:established,from_client; content:"GET"; http_method; content:"/caloriepainteddaisy527/rdr-2-menu-26/main/meromorphic/menu_rd_v1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943072/; classtype:trojan-activity;sid:84806172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943073)"; flow:established,from_client; content:"GET"; http_method; content:"/am17jx/natours-api/raw/refs/heads/master/dev-data/natours_api_2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943073/; classtype:trojan-activity;sid:84806173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943064)"; flow:established,from_client; content:"GET"; http_method; content:"/rbarmyarmy/b4bomber/raw/refs/heads/main/docs/bomber-3.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943064/; classtype:trojan-activity;sid:84806164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943065)"; flow:established,from_client; content:"GET"; http_method; content:"/milkaunmutilated455/anikotoapi/raw/refs/heads/main/src/routes/koto_ani_api_twinkless.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943065/; classtype:trojan-activity;sid:84806165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943066)"; flow:established,from_client; content:"GET"; http_method; content:"/0ogata0/qwen-php-client/main/phosphoglycerate/client_qwen_php_v2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943066/; classtype:trojan-activity;sid:84806166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943063)"; flow:established,from_client; content:"GET"; http_method; content:"/osbornefrozen840/esp-smoltcp/raw/refs/heads/main/components/esp_smoltcp/smoltcp-esp-3.4-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943063/; classtype:trojan-activity;sid:84806163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943062)"; flow:established,from_client; content:"GET"; http_method; content:"/pac-man-pt/lj-inventory/raw/refs/heads/main/html/css/inventory-lj-3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943062/; classtype:trojan-activity;sid:84806162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943056)"; flow:established,from_client; content:"GET"; http_method; content:"/joshualegado008/academe-student-app/raw/refs/heads/main/src/views/app_student_academe_v1.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943056/; classtype:trojan-activity;sid:84806156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943057)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-instant-steal-white-list-jubileu_dasparada/main/tetracoccus/v3.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943057/; classtype:trojan-activity;sid:84806157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943058)"; flow:established,from_client; content:"GET"; http_method; content:"/lavanthi/escape-from-kingdom-velmoria-lavanthi-/main/lucrative/escape_from_kingdom_lavanthi_velmoria_v3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943058/; classtype:trojan-activity;sid:84806158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943059)"; flow:established,from_client; content:"GET"; http_method; content:"/8070anurag/docs/main/src/software_1.5.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943059/; classtype:trojan-activity;sid:84806159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943060)"; flow:established,from_client; content:"GET"; http_method; content:"/shikayunamya/ieee-java-project-list-/main/clinopyroxene/java_project_list_iee_1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943060/; classtype:trojan-activity;sid:84806160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943061)"; flow:established,from_client; content:"GET"; http_method; content:"/subhopriyo/raindrops/raw/refs/heads/master/scapulovertebral/software_2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943061/; classtype:trojan-activity;sid:84806161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943055)"; flow:established,from_client; content:"GET"; http_method; content:"/hababi558/class-21/main/frighter/class-21-2.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943055/; classtype:trojan-activity;sid:84806155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943053)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamlandsr/dev_tools_hub/main/generatefiles/dev-tools-hub-3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943053/; classtype:trojan-activity;sid:84806153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943054)"; flow:established,from_client; content:"GET"; http_method; content:"/codewithmamoon/blockchain-project/raw/refs/heads/main/src/prisma/blockchain-project-3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943054/; classtype:trojan-activity;sid:84806154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943051)"; flow:established,from_client; content:"GET"; http_method; content:"/nogame154/bee-swarm-simulator-legacy-toolkit/branch/centerable/bee-legacy-swarm-simulator-toolkit-1.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943051/; classtype:trojan-activity;sid:84806151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943052)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-instant-steal-whitelist-jubileu_dasparada-by-tiodaesfiha_79813/main/inauspicious/v1.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943052/; classtype:trojan-activity;sid:84806152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943050)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/part-2/raw/refs/heads/main/public/part-neuronymy.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943050/; classtype:trojan-activity;sid:84806150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943046)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/expense-tracker/main/src/components/expense-tracker-loxia.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943046/; classtype:trojan-activity;sid:84806146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943047)"; flow:established,from_client; content:"GET"; http_method; content:"/jiggly1/smart-driver-care-pro-1.1.0.5280/main/colonitis/smart_pro_driver_care_3.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943047/; classtype:trojan-activity;sid:84806147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943048)"; flow:established,from_client; content:"GET"; http_method; content:"/nandanarajesh25/restaurant-menu-manager_tink-her-hack/main/frontend/src/components/header/menu_restaurant_manager_hack_her_tink_mechanicalist.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943048/; classtype:trojan-activity;sid:84806148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943049)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/my-portfolio/main/src/my_portfolio_1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943049/; classtype:trojan-activity;sid:84806149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943043)"; flow:established,from_client; content:"GET"; http_method; content:"/benitauncompartmented1891/qr-scanner-generator/main/android-app/app/src/main/java/com/itisuniqueofficial/qr-scanner-generator-piccalilli.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943043/; classtype:trojan-activity;sid:84806143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943044)"; flow:established,from_client; content:"GET"; http_method; content:"/k-t-design/aviz/main/android/app/.cxx/debug/4572331t/x86/cmakefiles/3.22.1-g37088a8-dirty/software-1.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943044/; classtype:trojan-activity;sid:84806144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943045)"; flow:established,from_client; content:"GET"; http_method; content:"/m4z-1ful/kcdeliverance2-deathbrink-toolkit/main/cowperian/kcdeliverance2-deathbrink-toolkit.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943045/; classtype:trojan-activity;sid:84806145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943041)"; flow:established,from_client; content:"GET"; http_method; content:"/gizzn/vinylplug-/main/graphometer/vinylplug-.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943041/; classtype:trojan-activity;sid:84806141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943042)"; flow:established,from_client; content:"GET"; http_method; content:"/pinquei/ble_scanner/master/templates/scanner-bl-mesoblastema.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943042/; classtype:trojan-activity;sid:84806142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943035)"; flow:established,from_client; content:"GET"; http_method; content:"/jourdaninorder609/mind-query/raw/refs/heads/main/src/infrastructure/llm/mind-query-v1.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943035/; classtype:trojan-activity;sid:84806135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943036)"; flow:established,from_client; content:"GET"; http_method; content:"/royalessential356/lce-emerald-launcher/main/sources/launcher-emerald-lc-v2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943036/; classtype:trojan-activity;sid:84806136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943037)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/simple-crud-client/raw/refs/heads/main/src/simple_crud_client_3.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943037/; classtype:trojan-activity;sid:84806137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943038)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/nsnsmendn/main/additamentary/software-intense.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943038/; classtype:trojan-activity;sid:84806138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943039)"; flow:established,from_client; content:"GET"; http_method; content:"/shevin0147/shevin0147.github.io/main/.opencode/skills/openspec-sync-specs/release_1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943039/; classtype:trojan-activity;sid:84806139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943040)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/grahaarutala/main/tests/feature/graha_arutala_v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943040/; classtype:trojan-activity;sid:84806140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943020)"; flow:established,from_client; content:"GET"; http_method; content:"/lemurhacep/sssssd/raw/refs/heads/main/cheat/src/events/joins/software-2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943020/; classtype:trojan-activity;sid:84806120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943021)"; flow:established,from_client; content:"GET"; http_method; content:"/winfieldmassspectroscopic818/vflux/raw/refs/heads/main/examples/icesugar-pro-blinky/src/software-v1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943021/; classtype:trojan-activity;sid:84806121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943022)"; flow:established,from_client; content:"GET"; http_method; content:"/omurkoc/enhanced-sentiment-analysis/main/moosebush/analysis-sentiment-enhanced-v1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943022/; classtype:trojan-activity;sid:84806122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943023)"; flow:established,from_client; content:"GET"; http_method; content:"/nur84/datatables/raw/refs/heads/main/anoplonemertini/software_3.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943023/; classtype:trojan-activity;sid:84806123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943024)"; flow:established,from_client; content:"GET"; http_method; content:"/hackerboy00/rust-force-hck/raw/refs/heads/main/werewolfism/rust_hck_force_1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943024/; classtype:trojan-activity;sid:84806124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943025)"; flow:established,from_client; content:"GET"; http_method; content:"/ranatarahumaraefoot475/mina-the-hollower-release/raw/refs/heads/main/sources/hollower_mina_the_release_v1.9-alpha.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943025/; classtype:trojan-activity;sid:84806125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943026)"; flow:established,from_client; content:"GET"; http_method; content:"/kalyanijawalekar/presentationkit/raw/refs/heads/main/demo/demo/assets.xcassets/appicon.appiconset/presentation_kit_v1.7.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943026/; classtype:trojan-activity;sid:84806126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943027)"; flow:established,from_client; content:"GET"; http_method; content:"/lpr021/my-app/raw/refs/heads/main/src/styles/my-app-1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943027/; classtype:trojan-activity;sid:84806127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943028)"; flow:established,from_client; content:"GET"; http_method; content:"/khn0x-khn0x/sui-bitcoin-spv/raw/refs/heads/master/tests/bitcoin-spv-sui-onondagan.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943028/; classtype:trojan-activity;sid:84806128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943029)"; flow:established,from_client; content:"GET"; http_method; content:"/natanrrocha/carneiroshidraulicos100/raw/refs/heads/main/public/carneiroshidraulicos_asthenopic.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943029/; classtype:trojan-activity;sid:84806129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943030)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/expense-tracker/raw/refs/heads/main/src/expense_tracker_1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943030/; classtype:trojan-activity;sid:84806130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943031)"; flow:established,from_client; content:"GET"; http_method; content:"/engineerbishnu/laravel-todolist-api-main/raw/refs/heads/main/vendor/phpunit/phpunit/src/metadata/parser/main_api_laravel_todolist_v1.0.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943031/; classtype:trojan-activity;sid:84806131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943032)"; flow:established,from_client; content:"GET"; http_method; content:"/iamdeepkr/portfolio/raw/refs/heads/main/src/assets/logo/software_2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943032/; classtype:trojan-activity;sid:84806132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943033)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/imagin_ai/raw/refs/heads/main/linux/runner/imagin_ai_v1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943033/; classtype:trojan-activity;sid:84806133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943034)"; flow:established,from_client; content:"GET"; http_method; content:"/fatinzark-stack/flowise/raw/refs/heads/main/packages/components/nodes/chains/retrievalqachain/software_3.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943034/; classtype:trojan-activity;sid:84806134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943018)"; flow:established,from_client; content:"GET"; http_method; content:"/maomaoguo89-star/fifmamaomaodeaiapp/raw/refs/heads/main/endotheliomyoma/software-v1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943018/; classtype:trojan-activity;sid:84806118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943019)"; flow:established,from_client; content:"GET"; http_method; content:"/sherali01/design-pattens-in-oops/raw/refs/heads/master/android/app/src/main/res/drawable-v21/in_oops_design_pattens_v2.6.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943019/; classtype:trojan-activity;sid:84806119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943016)"; flow:established,from_client; content:"GET"; http_method; content:"/binnguye/s2pk/raw/refs/heads/main/appdir/s_pk_3.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943016/; classtype:trojan-activity;sid:84806116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943017)"; flow:established,from_client; content:"GET"; http_method; content:"/selvaprakash-ramalingam/retrieval-augmented-generation-agricultural-text/raw/refs/heads/main/unnethis/generation_agricultural_tex_t_retrieval_augmented_3.8.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943017/; classtype:trojan-activity;sid:84806117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943013)"; flow:established,from_client; content:"GET"; http_method; content:"/mibrahiim786/art-gallery-simulator-roblox-toolkit/branch/nanosoma/art_roblox_toolkit_simulator_gallery_1.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943013/; classtype:trojan-activity;sid:84806113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943014)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadali832/login-page/main/overborrow/login-page.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943014/; classtype:trojan-activity;sid:84806114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943015)"; flow:established,from_client; content:"GET"; http_method; content:"/projectmunnoi/fm_1/raw/refs/heads/main/images/f_v1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943015/; classtype:trojan-activity;sid:84806115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943008)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedfat7i/my-projects/raw/refs/heads/master/palilogy/my-projects-2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943008/; classtype:trojan-activity;sid:84806108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943009)"; flow:established,from_client; content:"GET"; http_method; content:"/hydro1986/deltarune-trainer-toolkit/raw/refs/heads/branch/diketone/deltarune_trainer_toolkit_v2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943009/; classtype:trojan-activity;sid:84806109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943010)"; flow:established,from_client; content:"GET"; http_method; content:"/joaquincanete/test01/master/.vscode/test_2.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943010/; classtype:trojan-activity;sid:84806110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943011)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/si-mesin/master/biliteralism/si-mesin.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943011/; classtype:trojan-activity;sid:84806111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943012)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_11/main/utils/project-ai-2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943012/; classtype:trojan-activity;sid:84806112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943000)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/activity-3---task-app-router/raw/refs/heads/main/public/router-task-activity-app-abu.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943000/; classtype:trojan-activity;sid:84806100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943001)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/ui-/raw/refs/heads/main/src/u_v1.0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943001/; classtype:trojan-activity;sid:84806101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943002)"; flow:established,from_client; content:"GET"; http_method; content:"/ultf/shadowsocks-tunnel-install/raw/refs/heads/main/fauterer/install-shadowsocks-tunnel-v3.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943002/; classtype:trojan-activity;sid:84806102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943003)"; flow:established,from_client; content:"GET"; http_method; content:"/olathedevguy/manage-omega/main/src/design/manage-omega-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943003/; classtype:trojan-activity;sid:84806103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943004)"; flow:established,from_client; content:"GET"; http_method; content:"/lautarofrias/planet-burger-react-/raw/refs/heads/main/src/components/navbar/burger-planet-react-2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943004/; classtype:trojan-activity;sid:84806104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943005)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/store_sample_design_optimization/raw/refs/heads/main/bool/sample-design-optimization-store-3.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943005/; classtype:trojan-activity;sid:84806105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943006)"; flow:established,from_client; content:"GET"; http_method; content:"/gajendrakmt9079/personal-portfolio/raw/refs/heads/master/src/assets/portfolio_personal_2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943006/; classtype:trojan-activity;sid:84806106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3943007)"; flow:established,from_client; content:"GET"; http_method; content:"/fe4rlessxd/quieres-ser-mi-nobia-7w7/raw/refs/heads/master/trenchlet/ser_w_mi_nobia_quieres_1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3943007/; classtype:trojan-activity;sid:84806107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942998)"; flow:established,from_client; content:"GET"; http_method; content:"/03anmol/image_matching/raw/refs/heads/main/src/matching-image-v3.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942998/; classtype:trojan-activity;sid:84806098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942999)"; flow:established,from_client; content:"GET"; http_method; content:"/8070anurag/accessibility/raw/refs/heads/main/src/components/page404/software-rhodian.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942999/; classtype:trojan-activity;sid:84806099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942994)"; flow:established,from_client; content:"GET"; http_method; content:"/andreaignazio/asset-manager-fullstack/main/frontend/core_frontend/src/components/icons/asset-manager-fullstack-v2.8.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942994/; classtype:trojan-activity;sid:84806094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942995)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/collection_anime/main/anime-info/src/config/collection-anime-3.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942995/; classtype:trojan-activity;sid:84806095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942996)"; flow:established,from_client; content:"GET"; http_method; content:"/shaikhershad/bulk-image-downloader-free/main/variolic/bulk_downloader_free_image_3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942996/; classtype:trojan-activity;sid:84806096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942997)"; flow:established,from_client; content:"GET"; http_method; content:"/ghost02380/koikatsu-party-starter-pack/branch/ambitus/pack-koikatsu-starter-party-1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942997/; classtype:trojan-activity;sid:84806097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942992)"; flow:established,from_client; content:"GET"; http_method; content:"/rgoldr88/dispoflaress/raw/refs/heads/main/.design/cloudflare-icons/software-v2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942992/; classtype:trojan-activity;sid:84806092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942993)"; flow:established,from_client; content:"GET"; http_method; content:"/bvnahush/fashion-recommender-system-for-women/main/squamify/fashion-women-recommender-for-system-v3.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942993/; classtype:trojan-activity;sid:84806093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942989)"; flow:established,from_client; content:"GET"; http_method; content:"/aslinabegam-n/intern-project/raw/refs/heads/master/src/context/intern-project-v2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942989/; classtype:trojan-activity;sid:84806089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942990)"; flow:established,from_client; content:"GET"; http_method; content:"/goodnesskalu/marine-debris.github.io/raw/refs/heads/main/docs/marine_github_io_debris_v1.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942990/; classtype:trojan-activity;sid:84806090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942991)"; flow:established,from_client; content:"GET"; http_method; content:"/hiteknodeposit20241/autonomous-gemini-release-manager/raw/refs/heads/main/backend/src/websockets/manager-release-autonomous-gemini-v3.0.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942991/; classtype:trojan-activity;sid:84806091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942986)"; flow:established,from_client; content:"GET"; http_method; content:"/eniitanire/itproject/raw/refs/heads/main/images/it_project_2.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942986/; classtype:trojan-activity;sid:84806086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942987)"; flow:established,from_client; content:"GET"; http_method; content:"/kakaum2k/music-recommendation-based-on-facial-expression/main/feckless/based_recommendation_facial_expression_on_music_v2.5.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942987/; classtype:trojan-activity;sid:84806087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942988)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/editor-colaborativo/main/ambidexter/editor-colaborativo.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942988/; classtype:trojan-activity;sid:84806088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942982)"; flow:established,from_client; content:"GET"; http_method; content:"/srilaxman05/student-management-system/main/dichapetalum/management_system_student_v1.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942982/; classtype:trojan-activity;sid:84806082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942983)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangkhiem112/kale-text-editor/main/seraphism/editor_kale_text_2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942983/; classtype:trojan-activity;sid:84806083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942984)"; flow:established,from_client; content:"GET"; http_method; content:"/janani1625/emotion-music-recommender/main/screenshots/recommender-emotion-music-v3.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942984/; classtype:trojan-activity;sid:84806084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942985)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/frontend-arqueria-vue/main/downwith/frontend-arqueria-vue.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942985/; classtype:trojan-activity;sid:84806085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942975)"; flow:established,from_client; content:"GET"; http_method; content:"/karbine98kz/vectorpi/raw/refs/heads/main/app/components/login/vector-pi-3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942975/; classtype:trojan-activity;sid:84806075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942976)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/boyfriendcamera/raw/refs/heads/main/src/camera_boyfriend_v1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942976/; classtype:trojan-activity;sid:84806076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942977)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/ny-times-app/main/src/app/modules/core/material/ny-times-app-v3.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942977/; classtype:trojan-activity;sid:84806077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942978)"; flow:established,from_client; content:"GET"; http_method; content:"/radiographic-uncle4030/duh/raw/refs/heads/main/verumontanum/software-1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942978/; classtype:trojan-activity;sid:84806078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942979)"; flow:established,from_client; content:"GET"; http_method; content:"/khn0x-khn0x/sui-native/raw/refs/heads/master/nbtc_swap/docs/sui-native-3.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942979/; classtype:trojan-activity;sid:84806079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942980)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar675/fraud-detection-system/main/gablewise/detection_system_fraud_3.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942980/; classtype:trojan-activity;sid:84806080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942981)"; flow:established,from_client; content:"GET"; http_method; content:"/nejomeme/product-api/main/.github/api-product-v2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942981/; classtype:trojan-activity;sid:84806081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942971)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/internship1/main/src/component/navbar/internship_2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942971/; classtype:trojan-activity;sid:84806071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942972)"; flow:established,from_client; content:"GET"; http_method; content:"/eldricc/pyenv-inspector/raw/refs/heads/main/psychopompos/inspector-pyenv-1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942972/; classtype:trojan-activity;sid:84806072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942973)"; flow:established,from_client; content:"GET"; http_method; content:"/hunsulkaab66/hunsulkaab66/raw/refs/heads/main/indisposedness/hunsulkaab-v1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942973/; classtype:trojan-activity;sid:84806073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942974)"; flow:established,from_client; content:"GET"; http_method; content:"/iadnan21/git_exercise/master/serialize/git-exercise-v2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942974/; classtype:trojan-activity;sid:84806074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942968)"; flow:established,from_client; content:"GET"; http_method; content:"/giljames/kdcarrental/master/public/new_cardetails/scss/bootstrap/vendor/software-3.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942968/; classtype:trojan-activity;sid:84806068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942969)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/gramtalk02/main/src/app/new-group/gram-talk-tryptic.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942969/; classtype:trojan-activity;sid:84806069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942970)"; flow:established,from_client; content:"GET"; http_method; content:"/liooktoo288-pixel/webreversemcp/raw/refs/heads/main/browser/browser-engine/src/main/assets/wabt/1.9-beta.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942970/; classtype:trojan-activity;sid:84806070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942965)"; flow:established,from_client; content:"GET"; http_method; content:"/ch1n3x1/2025_proyectoparcial_v2/raw/refs/heads/main/src/pages/parcial-proyecto-1.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942965/; classtype:trojan-activity;sid:84806065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942966)"; flow:established,from_client; content:"GET"; http_method; content:"/rishab-7701/task_app/raw/refs/heads/master/addle/task_app_v1.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942966/; classtype:trojan-activity;sid:84806066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942967)"; flow:established,from_client; content:"GET"; http_method; content:"/wallyprintable180/qmdec/raw/refs/heads/main/assets/software_2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942967/; classtype:trojan-activity;sid:84806067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942960)"; flow:established,from_client; content:"GET"; http_method; content:"/97-soubise836/lunarclientminecraft-windows-installer/raw/refs/heads/main/prointervention/windows-installer-lunarclientminecraft-2.2.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942960/; classtype:trojan-activity;sid:84806060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942961)"; flow:established,from_client; content:"GET"; http_method; content:"/drakssounds/ai-lego-pinball-bot/main/externalfiles/a_pinball_leg_bot_v3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942961/; classtype:trojan-activity;sid:84806061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942962)"; flow:established,from_client; content:"GET"; http_method; content:"/ikbenproz/driving-empire-roblox-script-hub/branch/pluripartite/empire-hub-roblox-script-driving-v3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942962/; classtype:trojan-activity;sid:84806062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942963)"; flow:established,from_client; content:"GET"; http_method; content:"/davidlabrin/claude_proxy/raw/refs/heads/main/src/claude-proxy-importunement.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942963/; classtype:trojan-activity;sid:84806063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942964)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/client_react_deploy/raw/refs/heads/master/src/react-deploy-client-v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942964/; classtype:trojan-activity;sid:84806064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942955)"; flow:established,from_client; content:"GET"; http_method; content:"/hamloli/diskdeviceinfo/main/gddtest/disk-info-device-1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942955/; classtype:trojan-activity;sid:84806055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942956)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdani/frontendtest/main/src/actions/frontendtest_v1.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942956/; classtype:trojan-activity;sid:84806056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942957)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/event-management-from-end/main/src/store/event-management-from-end-1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942957/; classtype:trojan-activity;sid:84806057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942958)"; flow:established,from_client; content:"GET"; http_method; content:"/vctor03/vctor03/main/.github/vctor-v2.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942958/; classtype:trojan-activity;sid:84806058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942959)"; flow:established,from_client; content:"GET"; http_method; content:"/bhuwan070/ecommerce/master/public/software-1.0-beta.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942959/; classtype:trojan-activity;sid:84806059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942953)"; flow:established,from_client; content:"GET"; http_method; content:"/stanleyj03/mcp-for-security/raw/refs/heads/main/nmap-mcp/src/for-security-mcp-3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942953/; classtype:trojan-activity;sid:84806053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942954)"; flow:established,from_client; content:"GET"; http_method; content:"/senseisgs/fasomovies/raw/refs/heads/main/build/app/intermediates/incremental/debug/mergedebugresources/merged.dir/values-vi/faso_movies_springly.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942954/; classtype:trojan-activity;sid:84806054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942952)"; flow:established,from_client; content:"GET"; http_method; content:"/panzerking99267/mailcomboextractor/raw/refs/heads/main/mollifying/extractor-combo-mail-v3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942952/; classtype:trojan-activity;sid:84806052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942951)"; flow:established,from_client; content:"GET"; http_method; content:"/jonathanmutu2005/ml/raw/refs/heads/main/physiochemical/software-1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942951/; classtype:trojan-activity;sid:84806051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942945)"; flow:established,from_client; content:"GET"; http_method; content:"/ashish8485/talkink/main/sources/soylekit/software-v1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942945/; classtype:trojan-activity;sid:84806045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942946)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/reactworksheet6.2/master/src/assets/reactworksheet_3.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942946/; classtype:trojan-activity;sid:84806046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942947)"; flow:established,from_client; content:"GET"; http_method; content:"/harbor19/openai-article-summarizer/master/src/assets/article_a_summarizer_open_v1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942947/; classtype:trojan-activity;sid:84806047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942948)"; flow:established,from_client; content:"GET"; http_method; content:"/erenluffy/fbbb/raw/refs/heads/main/plugins/software_therapsida.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942948/; classtype:trojan-activity;sid:84806048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942949)"; flow:established,from_client; content:"GET"; http_method; content:"/kawanzi/astro-pixel-games/main/src/components/ui/astro-pixel-games_v3.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942949/; classtype:trojan-activity;sid:84806049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942950)"; flow:established,from_client; content:"GET"; http_method; content:"/micrometeoric-eye978/academic-research-skills/main/participatingly/research-academic-skills-leucitohedron.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942950/; classtype:trojan-activity;sid:84806050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942943)"; flow:established,from_client; content:"GET"; http_method; content:"/taraldesai10/park_here/main/ios/runner.xcodeproj/project.xcworkspace/xcshareddata/here-park-v2.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942943/; classtype:trojan-activity;sid:84806043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942944)"; flow:established,from_client; content:"GET"; http_method; content:"/dhacks-png/knightbot-md/main/session/knightbot_md_v2.6-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942944/; classtype:trojan-activity;sid:84806044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942938)"; flow:established,from_client; content:"GET"; http_method; content:"/carteldem5907/vibe-tuning/raw/refs/heads/main/references/vibe-tuning-shepherdess.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942938/; classtype:trojan-activity;sid:84806038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942939)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/ba_customer_reviews/raw/refs/heads/main/trousseau/b-reviews-customer-v2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942939/; classtype:trojan-activity;sid:84806039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942940)"; flow:established,from_client; content:"GET"; http_method; content:"/eibrunodev/app/master/src/pages/promotions/software_2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942940/; classtype:trojan-activity;sid:84806040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942941)"; flow:established,from_client; content:"GET"; http_method; content:"/2534nicolle/atv_imc/raw/refs/heads/main/android/app/src/main/kotlin/com/atv-imc-v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942941/; classtype:trojan-activity;sid:84806041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942942)"; flow:established,from_client; content:"GET"; http_method; content:"/golu0512/my_website/main/src/components/website_my_1.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942942/; classtype:trojan-activity;sid:84806042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942934)"; flow:established,from_client; content:"GET"; http_method; content:"/openplan-pricklyedgedleaf841/mackv-opt/raw/refs/heads/main/scripts/mac-opt-k-unrubified.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942934/; classtype:trojan-activity;sid:84806034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942935)"; flow:established,from_client; content:"GET"; http_method; content:"/josemanuelm9203/rumi/raw/refs/heads/main/vendean/software_v3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942935/; classtype:trojan-activity;sid:84806035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942936)"; flow:established,from_client; content:"GET"; http_method; content:"/perpaft11/ea-sports-college-football-25-save-crafter/raw/refs/heads/branch/incudostapedial/crafter_college_sports_save_ea_football_1.6.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942936/; classtype:trojan-activity;sid:84806036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942937)"; flow:established,from_client; content:"GET"; http_method; content:"/budrendition792/windowsdelta/raw/refs/heads/main/cocreatorship/windows-delta-v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942937/; classtype:trojan-activity;sid:84806037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942929)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/riskcare/main/src/pages/software-recitalist.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942929/; classtype:trojan-activity;sid:84806029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942930)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/netflix-clone/main/src/assets/clone_netflix_1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942930/; classtype:trojan-activity;sid:84806030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942931)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/myportfolio/main/public/myportfolio_v1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942931/; classtype:trojan-activity;sid:84806031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942932)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/oap_start_stop/main/gnathic/oap_start_stop_1.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942932/; classtype:trojan-activity;sid:84806032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942933)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/bigdataqna/main/sickbed/a-big-qn-data-2.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942933/; classtype:trojan-activity;sid:84806033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942927)"; flow:established,from_client; content:"GET"; http_method; content:"/kassiwaning586/yargi-pro-gemma-local/raw/refs/heads/main/docs/gemma-yargi-local-pro-v2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942927/; classtype:trojan-activity;sid:84806027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942928)"; flow:established,from_client; content:"GET"; http_method; content:"/shreyanxnova/rknhardering/raw/refs/heads/main/gnathostome/hardering-rkn-v2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942928/; classtype:trojan-activity;sid:84806028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942923)"; flow:established,from_client; content:"GET"; http_method; content:"/vm-janani/stone-segmentation/main/dentinocemental/stone-segmentation.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942923/; classtype:trojan-activity;sid:84806023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942924)"; flow:established,from_client; content:"GET"; http_method; content:"/0milovke0uwu0/dst-survival-toolkit/raw/refs/heads/branch/unwrestedly/toolkit-dst-survival-1.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942924/; classtype:trojan-activity;sid:84806024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942925)"; flow:established,from_client; content:"GET"; http_method; content:"/hirunjinadasa/villagerhapsody-open-access-edition/branch/opsonification/access_villagerhapsody_open_edition_2.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942925/; classtype:trojan-activity;sid:84806025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942926)"; flow:established,from_client; content:"GET"; http_method; content:"/spookyy120-web/toxibr/raw/refs/heads/main/src/software_v3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942926/; classtype:trojan-activity;sid:84806026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942922)"; flow:established,from_client; content:"GET"; http_method; content:"/rgoldr88/openwrt-app-actions/raw/refs/heads/main/applications/luci-app-photoprism/root/actions-app-openwrt-3.0.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942922/; classtype:trojan-activity;sid:84806022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942920)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedelmogy25/xai-assignment-dl/main/fluochloride/assignment-xa-dl-v3.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942920/; classtype:trojan-activity;sid:84806020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942921)"; flow:established,from_client; content:"GET"; http_method; content:"/87870/alchemist/raw/refs/heads/main/src/helpers/software-3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942921/; classtype:trojan-activity;sid:84806021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942919)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijitkayal10/abhijitkayal10/main/cecilite/abhijitkayal-v1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942919/; classtype:trojan-activity;sid:84806019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942916)"; flow:established,from_client; content:"GET"; http_method; content:"/joseontiveros/color-palet/raw/refs/heads/main/src/components/palette/palet-color-v3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942916/; classtype:trojan-activity;sid:84806016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942917)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/bmi_calculator_pro/raw/refs/heads/main/android/app/src/main/res/values-night/bm_pro_calculator_v3.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942917/; classtype:trojan-activity;sid:84806017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942918)"; flow:established,from_client; content:"GET"; http_method; content:"/sanithu16684/calculator_using_flutter/raw/refs/heads/master/ios/runner.xcworkspace/xcshareddata/using_calculator_flutter_v3.7.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942918/; classtype:trojan-activity;sid:84806018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942914)"; flow:established,from_client; content:"GET"; http_method; content:"/iamdeepkr/iamdeepkr.github.io/raw/refs/heads/main/src/assets/github-io-iamdeepkr-v3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942914/; classtype:trojan-activity;sid:84806014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942915)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/darktheme/raw/refs/heads/main/src/pages/dark-theme-v1.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942915/; classtype:trojan-activity;sid:84806015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942912)"; flow:established,from_client; content:"GET"; http_method; content:"/jamsyut/alung-pra-ukk/main/public/alung-ukk-pra-1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942912/; classtype:trojan-activity;sid:84806012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942913)"; flow:established,from_client; content:"GET"; http_method; content:"/jeliasrm/todo/master/headland/do_to_3.1.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942913/; classtype:trojan-activity;sid:84806013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942910)"; flow:established,from_client; content:"GET"; http_method; content:"/averagerobloxplayerabove15/alumni-management-system/raw/refs/heads/main/yestermorning/alumni_management_system_v1.3.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942910/; classtype:trojan-activity;sid:84806010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942911)"; flow:established,from_client; content:"GET"; http_method; content:"/rmnask2/pet-simulator-x-script-gm52/raw/refs/heads/main/homothallic/gm_simulator_script_pet_x_3.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942911/; classtype:trojan-activity;sid:84806011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942909)"; flow:established,from_client; content:"GET"; http_method; content:"/newsprogramedwinduboishayward228/newsprogramedwinduboishayward228.github.io/main/static/css/dist-embryophore.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942909/; classtype:trojan-activity;sid:84806009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942896)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/themetoggler/raw/refs/heads/main/src/components/theme-toggler-1.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942896/; classtype:trojan-activity;sid:84805996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942897)"; flow:established,from_client; content:"GET"; http_method; content:"/hantucloud/human-sense-ai-multimodal-emotion-recognition/raw/refs/heads/main/app/recognition_ai_emotion_multimodal_sense_human_1.9.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942897/; classtype:trojan-activity;sid:84805997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942898)"; flow:established,from_client; content:"GET"; http_method; content:"/thasinduniduwara/thasindu-new/main/session/thasindu_new_1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942898/; classtype:trojan-activity;sid:84805998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942899)"; flow:established,from_client; content:"GET"; http_method; content:"/karerunning645/neurogent/raw/refs/heads/main/benchman/software-v2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942899/; classtype:trojan-activity;sid:84805999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942900)"; flow:established,from_client; content:"GET"; http_method; content:"/arfa01/e-voting-system-c/main/housecraft/system_voting_e_c_1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942900/; classtype:trojan-activity;sid:84806000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942901)"; flow:established,from_client; content:"GET"; http_method; content:"/johndenvercandia/candia-midterm/raw/refs/heads/main/tests/midterm_candia_v1.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942901/; classtype:trojan-activity;sid:84806001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942902)"; flow:established,from_client; content:"GET"; http_method; content:"/ssevence/black_hole/raw/refs/heads/main/vs_code/hole-black-v2.3-beta.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942902/; classtype:trojan-activity;sid:84806002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942903)"; flow:established,from_client; content:"GET"; http_method; content:"/johnwall123459885/soulmask-unlocked-tactics/branch/holdenite/tactics-unlocked-soulmask-3.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942903/; classtype:trojan-activity;sid:84806003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942904)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgec020585/curso.prep.henry/master/05-js-iv/homework/tests/henry-prep-curso-actinocarpous.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942904/; classtype:trojan-activity;sid:84806004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942905)"; flow:established,from_client; content:"GET"; http_method; content:"/liyamuowner/aegis-crypt-key/master/src/assets/2.9-beta.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942905/; classtype:trojan-activity;sid:84806005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942906)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/baherindo/main/storage/framework/cache/software-v1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942906/; classtype:trojan-activity;sid:84806006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942907)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/database_design/main/vambrace/design-database-v1.8-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942907/; classtype:trojan-activity;sid:84806007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942908)"; flow:established,from_client; content:"GET"; http_method; content:"/trex740/boniphace-md/main/.github/md-boniphac-3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942908/; classtype:trojan-activity;sid:84806008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942892)"; flow:established,from_client; content:"GET"; http_method; content:"/sushitakahashi/sushitakahashi/raw/refs/heads/main/monoschemic/sushi-takahashi-v1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942892/; classtype:trojan-activity;sid:84805992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942893)"; flow:established,from_client; content:"GET"; http_method; content:"/ibahgat/kotlinudemy/raw/refs/heads/master/android/findmyphone/startup/app/src/main/java/com/kotlin_udemy_2.6.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942893/; classtype:trojan-activity;sid:84805993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942894)"; flow:established,from_client; content:"GET"; http_method; content:"/khaled8787/my-simple-react/main/riverlike/my-simple-react.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942894/; classtype:trojan-activity;sid:84805994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942895)"; flow:established,from_client; content:"GET"; http_method; content:"/jahdaganj00ki-netizen/ai-agent-cloud/raw/refs/heads/master/.github/agents/cloud_ai_agent_1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942895/; classtype:trojan-activity;sid:84805995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942888)"; flow:established,from_client; content:"GET"; http_method; content:"/ashishparulekar/dvc_checking/main/notebooks/checking_dv_v2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942888/; classtype:trojan-activity;sid:84805988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942889)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel-cf/amigosecretopsblackats/master/backend/node_modules/mongodb/lib/gridfs-stream/secreto_black_ps_amigo_ats_1.8.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942889/; classtype:trojan-activity;sid:84805989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942890)"; flow:established,from_client; content:"GET"; http_method; content:"/frankvol07/francis-jimenez/raw/refs/heads/main/coaxation/jimenez-francis-giraffesque.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942890/; classtype:trojan-activity;sid:84805990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942891)"; flow:established,from_client; content:"GET"; http_method; content:"/zakirullahzaki/yaar-admin-panel/raw/refs/heads/main/.idx/panel_yaar_admin_v3.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942891/; classtype:trojan-activity;sid:84805991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942885)"; flow:established,from_client; content:"GET"; http_method; content:"/juanjo157/new-bitcoin-sites/raw/refs/heads/main/cicindela/sites-bitcoin-new-v1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942885/; classtype:trojan-activity;sid:84805985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942886)"; flow:established,from_client; content:"GET"; http_method; content:"/andrix1234/knightbot-md/raw/refs/heads/main/commands/md_knightbot_v1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942886/; classtype:trojan-activity;sid:84805986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942887)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/python_alarm_clock/main/__pycache__/python_alarm_clock_v1.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942887/; classtype:trojan-activity;sid:84805987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942883)"; flow:established,from_client; content:"GET"; http_method; content:"/lynnastretched449/ai-hiring-workflow-engine/raw/refs/heads/main/sample_data/engine-workflow-ai-hiring-v3.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942883/; classtype:trojan-activity;sid:84805983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942884)"; flow:established,from_client; content:"GET"; http_method; content:"/benjiodhis/numpy_cheatsheet/main/commender/numpy_cheatsheet-3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942884/; classtype:trojan-activity;sid:84805984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942880)"; flow:established,from_client; content:"GET"; http_method; content:"/luwelle/bryanhappybirthday.github.io/raw/refs/heads/main/stiffly/io_bryanhappybirthday_github_v2.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942880/; classtype:trojan-activity;sid:84805980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942881)"; flow:established,from_client; content:"GET"; http_method; content:"/michimouse333/happy-moments-3d-webgl/main/public/textures/webgl_d_happy_moments_v2.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942881/; classtype:trojan-activity;sid:84805981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942882)"; flow:established,from_client; content:"GET"; http_method; content:"/rinday2005/fe_cinema/raw/refs/heads/main/src/pages/f-cinema-2.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942882/; classtype:trojan-activity;sid:84805982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942878)"; flow:established,from_client; content:"GET"; http_method; content:"/xheikhtalha2004/vertex-engineering-labs/raw/refs/heads/main/public/vertex_engineering_labs_v2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942878/; classtype:trojan-activity;sid:84805978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942879)"; flow:established,from_client; content:"GET"; http_method; content:"/zebratbone/open-source-ai-video-generator/branch/glowerer/ai-video-source-open-generator-3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942879/; classtype:trojan-activity;sid:84805979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942877)"; flow:established,from_client; content:"GET"; http_method; content:"/lupesalas836/umd-cmsc131-project-showcase/raw/refs/heads/main/stenocephalous/umd_project_showcase_cmsc_2.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942877/; classtype:trojan-activity;sid:84805977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942875)"; flow:established,from_client; content:"GET"; http_method; content:"/333nery333/python-prep/raw/refs/heads/main/m09_errorhandling/__pycache__/python_prep_inalienable.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942875/; classtype:trojan-activity;sid:84805975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942876)"; flow:established,from_client; content:"GET"; http_method; content:"/sevordw/mediacreationtool.bat/main/bypass11/creation-bat-media-tool-trustwoman.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942876/; classtype:trojan-activity;sid:84805976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942873)"; flow:established,from_client; content:"GET"; http_method; content:"/landouzefps/wos-format-converter/raw/refs/heads/main/basqued/converter-format-wos-1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942873/; classtype:trojan-activity;sid:84805973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942874)"; flow:established,from_client; content:"GET"; http_method; content:"/wheldnz/deeplearning-klasifikasi-diabetes-/main/images/deeplearning-klasifikasi-diabetes--1.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942874/; classtype:trojan-activity;sid:84805974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942865)"; flow:established,from_client; content:"GET"; http_method; content:"/adriadri333/full-stack-ecommerce-website/main/arvel/stack-full-ecommerce-website-succumbency.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942865/; classtype:trojan-activity;sid:84805965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942866)"; flow:established,from_client; content:"GET"; http_method; content:"/zth-en/auto_coursegrabber/raw/refs/heads/main/jwxt.shu.edu.cn/zftal-ui-v5-1.0.2/assets/plugins/i18n/grabber-course-auto-v3.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942866/; classtype:trojan-activity;sid:84805966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942867)"; flow:established,from_client; content:"GET"; http_method; content:"/opxcoder789/iptv/main/restrictedness/flowingly.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942867/; classtype:trojan-activity;sid:84805967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942868)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/resume_builder/main/src/resume_builder-v3.0-beta.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942868/; classtype:trojan-activity;sid:84805968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942869)"; flow:established,from_client; content:"GET"; http_method; content:"/bahruddinrm/pilketos/main/system/pager/software_v2.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942869/; classtype:trojan-activity;sid:84805969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942870)"; flow:established,from_client; content:"GET"; http_method; content:"/sofyanezzin/scalarstack/main/core/software-1.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942870/; classtype:trojan-activity;sid:84805970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942871)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/todo-app/todo-list/android/app/src/debug/app_todo_v2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942871/; classtype:trojan-activity;sid:84805971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942872)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik-singh-droid/age-gender-detection/main/outpoison/detection_gender_age_3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942872/; classtype:trojan-activity;sid:84805972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942864)"; flow:established,from_client; content:"GET"; http_method; content:"/narcos965/unluac/raw/refs/heads/master/src/unluac/test/software_1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942864/; classtype:trojan-activity;sid:84805964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942861)"; flow:established,from_client; content:"GET"; http_method; content:"/konquerortonguingandgroovingplane241/tabata-app/raw/refs/heads/main/android/app/src/test/java/app_tabata_1.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942861/; classtype:trojan-activity;sid:84805961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942862)"; flow:established,from_client; content:"GET"; http_method; content:"/kezzaku/bank-performance-analysis/raw/refs/heads/main/airflow_dags/performance_bank_analysis_2.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942862/; classtype:trojan-activity;sid:84805962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942863)"; flow:established,from_client; content:"GET"; http_method; content:"/euamobi4582/gemini-bridge-mcp/raw/refs/heads/main/lib/gemini-mcp-bridge-v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942863/; classtype:trojan-activity;sid:84805963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942857)"; flow:established,from_client; content:"GET"; http_method; content:"/jesus3476/fire-detection-siglip2/raw/refs/heads/main/cyclamine/detection-fire-siglip-tewly.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942857/; classtype:trojan-activity;sid:84805957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942858)"; flow:established,from_client; content:"GET"; http_method; content:"/m2msupport/modem-diagnostics-commands/master/kootcha/modem-diagnostics-commands_v2.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942858/; classtype:trojan-activity;sid:84805958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942859)"; flow:established,from_client; content:"GET"; http_method; content:"/decent-eightpennynail371/android-cli_one-click_kit/main/lib/kit_android_cl_click_one_v1.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942859/; classtype:trojan-activity;sid:84805959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942860)"; flow:established,from_client; content:"GET"; http_method; content:"/dotcom-armillariella353/story2audio/raw/refs/heads/main/templates/story_audio_v2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942860/; classtype:trojan-activity;sid:84805960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942852)"; flow:established,from_client; content:"GET"; http_method; content:"/codedbycj/statsnap/raw/refs/heads/main/lignicolous/software-amphictyony.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942852/; classtype:trojan-activity;sid:84805952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942853)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/notpixel-ad2/raw/refs/heads/main/pyarmor_runtime_004817/ad_notpixel_v2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942853/; classtype:trojan-activity;sid:84805953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942854)"; flow:established,from_client; content:"GET"; http_method; content:"/rinday2005/e-commerce_react/master/src/pages/signin/react_commerce_v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942854/; classtype:trojan-activity;sid:84805954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942855)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/devloy-laracel-varcel-din/main/resources/views/vendor/din-varcel-devloy-laracel-satisfyingness.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942855/; classtype:trojan-activity;sid:84805955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942856)"; flow:established,from_client; content:"GET"; http_method; content:"/othmane55/bongo-cat-tips-tricks/branch/overripeness/tricks_tips_cat_bongo_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942856/; classtype:trojan-activity;sid:84805956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942849)"; flow:established,from_client; content:"GET"; http_method; content:"/makcintoshawesome/php-mapping/raw/refs/heads/main/img/php-mapping-3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942849/; classtype:trojan-activity;sid:84805949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942850)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedfazil3/langchain-pdf-rag/raw/refs/heads/main/argentine/langchain_pdf_rag_v2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942850/; classtype:trojan-activity;sid:84805950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942851)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.161.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942851/; classtype:trojan-activity;sid:84805951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942844)"; flow:established,from_client; content:"GET"; http_method; content:"/keith986/react-express-electron-app/raw/refs/heads/main/public/backend/node_modules/fs-minipass/node_modules/minipass/app-express-electron-react-v2.6.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942844/; classtype:trojan-activity;sid:84805944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942845)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadameen786/books-recommendation/raw/refs/heads/main/booksrecommendation/books-recommendation-3.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942845/; classtype:trojan-activity;sid:84805945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942846)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/wikipedia-2.o/main/anatole/wikipedia-2.o-v3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942846/; classtype:trojan-activity;sid:84805946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942847)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/movie-app/main/src/components/movie-app-v2.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942847/; classtype:trojan-activity;sid:84805947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942848)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgewgouveia/bubble-gum-simulator-script-hub/branch/prophyllum/hub-bubble-simulator-script-gum-v2.7.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942848/; classtype:trojan-activity;sid:84805948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942841)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/alx-backend-user-data/raw/refs/heads/main/0x03-user_authentication_service/backend-data-alx-user-1.6.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942841/; classtype:trojan-activity;sid:84805941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942842)"; flow:established,from_client; content:"GET"; http_method; content:"/eliascurasiaquino-lgtm/phantomchattrending/raw/refs/heads/main/autodidactic/phantom_trending_chat_v2.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942842/; classtype:trojan-activity;sid:84805942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942843)"; flow:established,from_client; content:"GET"; http_method; content:"/marcoramos016/connectmatao-frontend/main/src/app/pages/components/card-evento-detalhes/connect-frontend-matao-1.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942843/; classtype:trojan-activity;sid:84805943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942836)"; flow:established,from_client; content:"GET"; http_method; content:"/foodless-inharmoniousness7408/lecture-notes/raw/refs/heads/main/diprotodont/notes_lecture_v2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942836/; classtype:trojan-activity;sid:84805936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942837)"; flow:established,from_client; content:"GET"; http_method; content:"/adilmaqsood1/code_alpha_projects/raw/refs/heads/main/url_shortener/assets/code_projects_alpha_v2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942837/; classtype:trojan-activity;sid:84805937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942838)"; flow:established,from_client; content:"GET"; http_method; content:"/2534nicolle/dart_project/raw/refs/heads/main/android/app/src/profile/project_dart_3.1-alpha.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942838/; classtype:trojan-activity;sid:84805938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942839)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/reactworksheet6.4/raw/refs/heads/master/src/assets/reactworksheet-2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942839/; classtype:trojan-activity;sid:84805939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942840)"; flow:established,from_client; content:"GET"; http_method; content:"/devtinker26/dark-cyber-mysql-workbench/main/docs/images/workbench-my-cyber-sq-dark-sequestration.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942840/; classtype:trojan-activity;sid:84805940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942835)"; flow:established,from_client; content:"GET"; http_method; content:"/loveavengers/mymalwaredatabase/raw/refs/heads/main/mymalwares/my_database_malware_1.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942835/; classtype:trojan-activity;sid:84805935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942834)"; flow:established,from_client; content:"GET"; http_method; content:"/neddin/anime-power-tycoon-roblox-scripts-studio/branch/endoscopic/studio_tycoon_anime_power_scripts_roblox_v3.7.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942834/; classtype:trojan-activity;sid:84805934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942830)"; flow:established,from_client; content:"GET"; http_method; content:"/rousslan2/cin-stre/raw/refs/heads/main/node_modules/object-assign/stre_cin_3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942830/; classtype:trojan-activity;sid:84805930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942831)"; flow:established,from_client; content:"GET"; http_method; content:"/tupopacherryy9/exynos990-payloads/raw/refs/heads/main/libc/payloads-exynos-v2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942831/; classtype:trojan-activity;sid:84805931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942832)"; flow:established,from_client; content:"GET"; http_method; content:"/anfographie/marvel-rivals-elite-toolkit/raw/refs/heads/branch/invitrifiable/rivals_toolkit_elite_marvel_3.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942832/; classtype:trojan-activity;sid:84805932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942833)"; flow:established,from_client; content:"GET"; http_method; content:"/arpita2424/simforge/main/symmetral/software_cirrous.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942833/; classtype:trojan-activity;sid:84805933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942829)"; flow:established,from_client; content:"GET"; http_method; content:"/joshualegado008/client-frontend/raw/refs/heads/master/src/frontend-client-v2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942829/; classtype:trojan-activity;sid:84805929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942827)"; flow:established,from_client; content:"GET"; http_method; content:"/jhyshy/battlefield-2042-aim-enhancer/branch/cathexis/aim_battlefield_enhancer_1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942827/; classtype:trojan-activity;sid:84805927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942828)"; flow:established,from_client; content:"GET"; http_method; content:"/nickderrick2005/clair-obscur-expedition-33-tips-tricks-toolkit/branch/unoccurring/tricks-toolkit-obscur-clair-tips-expedition-v1.4.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942828/; classtype:trojan-activity;sid:84805928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942825)"; flow:established,from_client; content:"GET"; http_method; content:"/contactcomputers2-ui/build/main/vocalism/software_v2.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942825/; classtype:trojan-activity;sid:84805925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942826)"; flow:established,from_client; content:"GET"; http_method; content:"/khaled8787/first-nextjs-project/raw/refs/heads/main/src/app/dashboard/first_project_next_js_v1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942826/; classtype:trojan-activity;sid:84805926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942824)"; flow:established,from_client; content:"GET"; http_method; content:"/sleepykkzy/comfyui-docker-cuda-preloaded/master/init_scripts/docker_comfy_cud_preloaded_u_v3.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942824/; classtype:trojan-activity;sid:84805924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942822)"; flow:established,from_client; content:"GET"; http_method; content:"/dissentient-displacement919/inlinemc/main/server/public/mc-inline-v3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942822/; classtype:trojan-activity;sid:84805922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942823)"; flow:established,from_client; content:"GET"; http_method; content:"/lufegaga/dise-o-y-construcci-n-de-sitio-web-de-la-coordinaci-n-de-investigaci-n-y-posgrado/raw/refs/heads/main/public/imagenes/la-y-coordinaci-construcci-de-investigaci-sitio-posgrado-dise-n-web-o-1.4.zip"; http_uri; depth:205; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942823/; classtype:trojan-activity;sid:84805923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942818)"; flow:established,from_client; content:"GET"; http_method; content:"/ventral-yenta893/ventral-yenta893.github.io/raw/refs/heads/main/.github/app-v2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942818/; classtype:trojan-activity;sid:84805918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942819)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/java_test_solutions/raw/refs/heads/master/overreliant/java_solutions_test_cocksureness.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942819/; classtype:trojan-activity;sid:84805919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942820)"; flow:established,from_client; content:"GET"; http_method; content:"/chandan1145/python-automation-toolkit/raw/refs/heads/main/durmast/automation-toolkit-python-v2.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942820/; classtype:trojan-activity;sid:84805920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942821)"; flow:established,from_client; content:"GET"; http_method; content:"/stcrispinshade76/unlocker-phone-tool-2026/raw/refs/heads/main/stunning/phone_tool_unlocker_ornithodelphia.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942821/; classtype:trojan-activity;sid:84805921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942813)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/portfolio/main/public/assets/portfolio_3.5-beta.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942813/; classtype:trojan-activity;sid:84805913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942814)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/crud-laravel-app/master/azygous/crud-laravel-app.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942814/; classtype:trojan-activity;sid:84805914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942815)"; flow:established,from_client; content:"GET"; http_method; content:"/f8899764/slippi-launcher-install/main/desktop/install_launcher_slippi_v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942815/; classtype:trojan-activity;sid:84805915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942816)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/weather_app/main/lib/app_weather_3.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942816/; classtype:trojan-activity;sid:84805916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942817)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/lag-bomb-by-tiodaesfiha/main/opiniastrous/by_lag_bomb_tiodaesfiha_2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942817/; classtype:trojan-activity;sid:84805917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942812)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulxyzrehman123-cloud/redxfreesteaminstaller/master/android/app/src/debug/1.3-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942812/; classtype:trojan-activity;sid:84805912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942811)"; flow:established,from_client; content:"GET"; http_method; content:"/rajiv-sapkota/cypress-bdd-cucumber/main/cypress/e2e/security/bd_cucumber_cypress_2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942811/; classtype:trojan-activity;sid:84805911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942809)"; flow:established,from_client; content:"GET"; http_method; content:"/makcintoshawesome/powerpoint-controller-mobile-app/main/tzotzil/controller-app-powerpoint-mobile-v3.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942809/; classtype:trojan-activity;sid:84805909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942810)"; flow:established,from_client; content:"GET"; http_method; content:"/kingdark444/kingdark444/raw/refs/heads/main/alkahestica/dark-king-v3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942810/; classtype:trojan-activity;sid:84805910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942805)"; flow:established,from_client; content:"GET"; http_method; content:"/ranjit123-yst/nextjs-boilerplate/raw/refs/heads/main/public/nextjs_boilerplate_v3.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942805/; classtype:trojan-activity;sid:84805905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942806)"; flow:established,from_client; content:"GET"; http_method; content:"/rennonly/likhonwebpages/releases/download/v2.0/release_x64.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942806/; classtype:trojan-activity;sid:84805906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942807)"; flow:established,from_client; content:"GET"; http_method; content:"/bigit1024/django-crm/main/website/templates/django-crm-3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942807/; classtype:trojan-activity;sid:84805907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942808)"; flow:established,from_client; content:"GET"; http_method; content:"/sachi7799/nba-2k26-trainer-pro-tools/branch/epiphysial/trainer_tools_nba_k_pro_3.9-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942808/; classtype:trojan-activity;sid:84805908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942804)"; flow:established,from_client; content:"GET"; http_method; content:"/idkunku/the-alters-advantage-tools/branch/roomth/the-alters-advantage-tools-thusgate.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942804/; classtype:trojan-activity;sid:84805904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942796)"; flow:established,from_client; content:"GET"; http_method; content:"/kasseloic5637/amyraxvpn-relay/raw/refs/heads/main/netlify/netlify/edge-functions/vp-relay-amyrax-counternoise.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942796/; classtype:trojan-activity;sid:84805896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942797)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/mitrana-textile/main/src/app/mitrana_textile_2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942797/; classtype:trojan-activity;sid:84805897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942798)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/zdb-data-hub/main/pieshop/zdb-data-hub.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942798/; classtype:trojan-activity;sid:84805898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942799)"; flow:established,from_client; content:"GET"; http_method; content:"/isaiahhodel7/broken-arrow-enhanced-tactics/branch/taintless/broken-arrow-enhanced-tactics-3.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942799/; classtype:trojan-activity;sid:84805899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942800)"; flow:established,from_client; content:"GET"; http_method; content:"/kiatun3434/pokemon-search-app-nextjs/main/complimentalness/app_js_search_pokemon_next_3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942800/; classtype:trojan-activity;sid:84805900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942801)"; flow:established,from_client; content:"GET"; http_method; content:"/harsh-kumar-tyagi/wechat-claude-bot/raw/refs/heads/main/charlady/bot-claude-wechat-v1.2-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942801/; classtype:trojan-activity;sid:84805901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942802)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/testing-larapong/raw/refs/heads/main/routes/testing-larapong-sorbate.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942802/; classtype:trojan-activity;sid:84805902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942803)"; flow:established,from_client; content:"GET"; http_method; content:"/yarrabolukittu/kittunaidu.github.io/raw/refs/heads/main/miscibility/github-kittunaidu-io-v2.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942803/; classtype:trojan-activity;sid:84805903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942790)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/gram-panchayat-kakrari/main/src/panchayat_kakrari_gram_3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942790/; classtype:trojan-activity;sid:84805890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942791)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/manajemeninventaris/raw/refs/heads/main/app/http/controllers/auth/software-v2.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942791/; classtype:trojan-activity;sid:84805891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942792)"; flow:established,from_client; content:"GET"; http_method; content:"/isaaciguanre001/biu-elibrary/raw/refs/heads/main/static/uploads/elibrary-biu-protestantly.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942792/; classtype:trojan-activity;sid:84805892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942793)"; flow:established,from_client; content:"GET"; http_method; content:"/rgoldr88/istore/main/luci/luci-lib-xterm/htdocs/luci-static/resources/software-v1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942793/; classtype:trojan-activity;sid:84805893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942794)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/carbiddingwebapp/main/src/assets/src/components/carbiddingwebapp_2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942794/; classtype:trojan-activity;sid:84805894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942795)"; flow:established,from_client; content:"GET"; http_method; content:"/ssevence/griddycode/master/icons/comments/software-3.0-alpha.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942795/; classtype:trojan-activity;sid:84805895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942788)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/blog-reactjs-jwt-redux/raw/refs/heads/main/src/reactjs_blog_jwt_redux_1.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942788/; classtype:trojan-activity;sid:84805888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942789)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/uncontrolled-form-fbc/main/public/uncontrolled-form-fbc-v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942789/; classtype:trojan-activity;sid:84805889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942784)"; flow:established,from_client; content:"GET"; http_method; content:"/franco-alt-cloud/sui-mev/raw/refs/heads/master/crates/utils/src/sui-mev-2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942784/; classtype:trojan-activity;sid:84805884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942785)"; flow:established,from_client; content:"GET"; http_method; content:"/y-0023/cua/raw/refs/heads/main/libs/agent/agent/core/software-1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942785/; classtype:trojan-activity;sid:84805885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942786)"; flow:established,from_client; content:"GET"; http_method; content:"/daelanthony/patchwerk/raw/refs/heads/main/hypereutectoid/software-1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942786/; classtype:trojan-activity;sid:84805886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942787)"; flow:established,from_client; content:"GET"; http_method; content:"/babtou34/common-ground-world-crypto-bot-crypto-game-auto-farm-clicker-cheat-api/main/ground-world-exp/wpfapp1/bot_api_cheat_world_game_ground_clicker_crypto_common_auto_farm_v2.3.zip"; http_uri; depth:183; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942787/; classtype:trojan-activity;sid:84805887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942782)"; flow:established,from_client; content:"GET"; http_method; content:"/danielm2994/monolith/raw/refs/heads/main/client/functions/cdn/software-v2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942782/; classtype:trojan-activity;sid:84805882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942783)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/digital-notebook/main/irruptive/digital-notebook.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942783/; classtype:trojan-activity;sid:84805883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942780)"; flow:established,from_client; content:"GET"; http_method; content:"/haidarjakiem/haidarjakiem/main/physitheism/software_2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942780/; classtype:trojan-activity;sid:84805880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942781)"; flow:established,from_client; content:"GET"; http_method; content:"/christianvmchvdfh/dev-cli/raw/refs/heads/main/devops/cli_dev_1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942781/; classtype:trojan-activity;sid:84805881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942777)"; flow:established,from_client; content:"GET"; http_method; content:"/mizistein/screentimer/raw/refs/heads/main/ios/runnertests/software_v2.8-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942777/; classtype:trojan-activity;sid:84805877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942778)"; flow:established,from_client; content:"GET"; http_method; content:"/imdiamand/ml-matrix3d/raw/refs/heads/main/examples/unposed-samples/arkitscenes/d_ml_matrix_2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942778/; classtype:trojan-activity;sid:84805878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942779)"; flow:established,from_client; content:"GET"; http_method; content:"/nithin050806/ai-plant-health-monitor/raw/refs/heads/main/unconfess/monitor-ai-plant-health-1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942779/; classtype:trojan-activity;sid:84805879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942775)"; flow:established,from_client; content:"GET"; http_method; content:"/rathan-code/a-b-test/raw/refs/heads/main/aylesbury/test_v3.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942775/; classtype:trojan-activity;sid:84805875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942776)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinramirezgon/cadenas-markov-solver/main/templates/markov-cadenas-solver-v1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942776/; classtype:trojan-activity;sid:84805876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942773)"; flow:established,from_client; content:"GET"; http_method; content:"/c0d3gamer/yellow-fever-awareness-dengue-/raw/refs/heads/main/sad/awareness-dengue-yellow-fever-v3.1-beta.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942773/; classtype:trojan-activity;sid:84805873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942774)"; flow:established,from_client; content:"GET"; http_method; content:"/alphonsofundamental519/reference-data-mcp-server/main/src/services/data-server-reference-mcp-v1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942774/; classtype:trojan-activity;sid:84805874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942768)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/thaysvs2/raw/refs/heads/main/unpolished/thaysvs_v3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942768/; classtype:trojan-activity;sid:84805868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942769)"; flow:established,from_client; content:"GET"; http_method; content:"/eltonyaw/nextjs-dashboard/master/public/customers/nextjs_dashboard_v1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942769/; classtype:trojan-activity;sid:84805869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942770)"; flow:established,from_client; content:"GET"; http_method; content:"/erenluffy/pip/main/helpers/software-phalarism.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942770/; classtype:trojan-activity;sid:84805870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942771)"; flow:established,from_client; content:"GET"; http_method; content:"/kiddo8059/flipper-sub-creator/raw/refs/heads/main/helpers/sub_flipper_creator_v1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942771/; classtype:trojan-activity;sid:84805871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942772)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdani/assignment12_ui_garden/main/storybook-static/assignment12_ui_garden-v3.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942772/; classtype:trojan-activity;sid:84805872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942765)"; flow:established,from_client; content:"GET"; http_method; content:"/renhakudo/business-finance-tracker/main/app/sign-up/business-finance-tracker-2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942765/; classtype:trojan-activity;sid:84805865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942766)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/airbnb_clone_v3/master/web_flask/templates/air_bn_clone_v_v2.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942766/; classtype:trojan-activity;sid:84805866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942767)"; flow:established,from_client; content:"GET"; http_method; content:"/kamikatsu62/opensea-bidding-bot-2024/raw/refs/heads/main/entemple/open_sea_bot_bidding_3.6-alpha.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942767/; classtype:trojan-activity;sid:84805867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942760)"; flow:established,from_client; content:"GET"; http_method; content:"/miki1044/ube-gui/raw/refs/heads/main/templates/ub_gui_2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942760/; classtype:trojan-activity;sid:84805860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942761)"; flow:established,from_client; content:"GET"; http_method; content:"/vanshchouksey21/json-deploy-react/main/images/json-deploy-react-2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942761/; classtype:trojan-activity;sid:84805861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942762)"; flow:established,from_client; content:"GET"; http_method; content:"/najib-rohana/early-backup/raw/refs/heads/main/packages/annotate_lerp/lib/backup_early_3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942762/; classtype:trojan-activity;sid:84805862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942763)"; flow:established,from_client; content:"GET"; http_method; content:"/ryuk956983/viveka-4.0/main/src/components/organizerscard/viveka_v1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942763/; classtype:trojan-activity;sid:84805863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942764)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/ffchvd/main/disenthral/software-2.9.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942764/; classtype:trojan-activity;sid:84805864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942759)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/react-knoledge/raw/refs/heads/main/src/components/bookmark/knoledge-react-v2.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942759/; classtype:trojan-activity;sid:84805859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942756)"; flow:established,from_client; content:"GET"; http_method; content:"/papaye974/nomad-measurements-afm/raw/refs/heads/main/unverified/afm_nomad_measurements_2.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942756/; classtype:trojan-activity;sid:84805856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942757)"; flow:established,from_client; content:"GET"; http_method; content:"/trsua2/teamrubiconaustr.org/master/degeneracy/org-teamrubiconaustr-2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942757/; classtype:trojan-activity;sid:84805857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942758)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/ultra_marathon_data_analysis_using_python/main/sturnella/data-ultra-python-analysis-marathon-using-1.8-beta.3.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942758/; classtype:trojan-activity;sid:84805858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942750)"; flow:established,from_client; content:"GET"; http_method; content:"/rishab-7701/leetcode_questions/raw/refs/heads/master/02.add_two_numbers/questions_leetcode_2.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942750/; classtype:trojan-activity;sid:84805850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942751)"; flow:established,from_client; content:"GET"; http_method; content:"/cholponai02/interactive-graphics-transformations/main/unprecipitate/transformations-graphics-interactive-v3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942751/; classtype:trojan-activity;sid:84805851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942752)"; flow:established,from_client; content:"GET"; http_method; content:"/drizzyisbetter/html-doc/main/docs/superpowers/plans/html-doc-1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942752/; classtype:trojan-activity;sid:84805852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942753)"; flow:established,from_client; content:"GET"; http_method; content:"/dulcineaeuphonic223/sifty/raw/refs/heads/main/packaging/scoop/software_v2.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942753/; classtype:trojan-activity;sid:84805853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942754)"; flow:established,from_client; content:"GET"; http_method; content:"/huseyinck/instagram-clone/main/melder/clone_instagram_2.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942754/; classtype:trojan-activity;sid:84805854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942755)"; flow:established,from_client; content:"GET"; http_method; content:"/rgoldr88/luci-app-xray/raw/refs/heads/master/core/root/usr/libexec/rpcd/luci-xray-app-v1.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942755/; classtype:trojan-activity;sid:84805855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942748)"; flow:established,from_client; content:"GET"; http_method; content:"/mayur9834/python-assistant/raw/refs/heads/master/neurogliosis/python-assistant-3.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942748/; classtype:trojan-activity;sid:84805848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942749)"; flow:established,from_client; content:"GET"; http_method; content:"/darell444/challenge-api/raw/refs/heads/main/prisma/migrations/20250417133521_init/api-challenge-v2.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942749/; classtype:trojan-activity;sid:84805849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942745)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/mern-application/raw/refs/heads/master/src/assets/application_mer_2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942745/; classtype:trojan-activity;sid:84805845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942746)"; flow:established,from_client; content:"GET"; http_method; content:"/taraldesai10/tic_tac_toe/raw/refs/heads/main/macos/runner.xcodeproj/xcshareddata/xcschemes/toe-tic-tac-2.9.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942746/; classtype:trojan-activity;sid:84805846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942747)"; flow:established,from_client; content:"GET"; http_method; content:"/enzo1311/ffbe-spritesheets/raw/refs/heads/main/classes/ffbe_spritesheets_v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942747/; classtype:trojan-activity;sid:84805847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942741)"; flow:established,from_client; content:"GET"; http_method; content:"/gizzn/sliva_fix/main/heritable/sliva_fix.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942741/; classtype:trojan-activity;sid:84805841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942742)"; flow:established,from_client; content:"GET"; http_method; content:"/shahryar-dev/booksearchapp/master/src/hooks/search-app-book-2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942742/; classtype:trojan-activity;sid:84805842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942743)"; flow:established,from_client; content:"GET"; http_method; content:"/iteguh08/blog-article/master/storage/framework/article_blog_3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942743/; classtype:trojan-activity;sid:84805843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942744)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/fitness-app/raw/refs/heads/main/src/fitness_app_3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942744/; classtype:trojan-activity;sid:84805844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942739)"; flow:established,from_client; content:"GET"; http_method; content:"/p-sushanth/typing-test/main/src/assets/typing-test-2.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942739/; classtype:trojan-activity;sid:84805839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942740)"; flow:established,from_client; content:"GET"; http_method; content:"/alosaupending874/sage/raw/refs/heads/main/docs/software_1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942740/; classtype:trojan-activity;sid:84805840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942737)"; flow:established,from_client; content:"GET"; http_method; content:"/leaflike-sleeplessperson662/sepiruai/raw/refs/heads/main/scoad/sepiru-ai-3.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942737/; classtype:trojan-activity;sid:84805837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942738)"; flow:established,from_client; content:"GET"; http_method; content:"/delacruzrlkq/top-5-full-stack-machine-learning-project-ideas/main/tricliniarch/learning-machine-project-top-ideas-full-stack-2.2.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942738/; classtype:trojan-activity;sid:84805838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942735)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/reactworksheet6/raw/refs/heads/master/src/assets/reactworksheet_1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942735/; classtype:trojan-activity;sid:84805835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942736)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/gaibandhasell/main/helenioid/gaibandhasell.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942736/; classtype:trojan-activity;sid:84805836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942732)"; flow:established,from_client; content:"GET"; http_method; content:"/sam3166/nitro-generator/main/results/generator_nitro_v3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942732/; classtype:trojan-activity;sid:84805832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942733)"; flow:established,from_client; content:"GET"; http_method; content:"/jnewton-lab/gottovote-rci/raw/refs/heads/gh-pages/fonts/vote-rci-to-got-3.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942733/; classtype:trojan-activity;sid:84805833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942734)"; flow:established,from_client; content:"GET"; http_method; content:"/mr-idiot-00003/recuva-file-recovery-installer-2025/raw/refs/heads/main/hoarseness/recovery-installer-recuva-file-v1.4.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942734/; classtype:trojan-activity;sid:84805834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942729)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-instant-steal/main/unrepresentative/a_steal_instant_king_3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942729/; classtype:trojan-activity;sid:84805829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942730)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/pi-pokemon-henry/main/client/public/henry-pokemon-p-v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942730/; classtype:trojan-activity;sid:84805830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942731)"; flow:established,from_client; content:"GET"; http_method; content:"/superordinate-complacence439/awesome-codex-pets/raw/refs/heads/main/pets/eddy-3/codex_pets_awesome_2.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942731/; classtype:trojan-activity;sid:84805831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942728)"; flow:established,from_client; content:"GET"; http_method; content:"/diakonrobel/indextts_v2am/raw/refs/heads/main/indextts/s2mel/modules/hifigan/indextts-am-3.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942728/; classtype:trojan-activity;sid:84805828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942726)"; flow:established,from_client; content:"GET"; http_method; content:"/devwarly/prova_engenharia_software/master/q1/software-prova-engenharia-otherist.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942726/; classtype:trojan-activity;sid:84805826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942727)"; flow:established,from_client; content:"GET"; http_method; content:"/kefilweditse/skills-introduction-to-github/raw/refs/heads/main/.github/steps/to_github_skills_introduction_1.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942727/; classtype:trojan-activity;sid:84805827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942725)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/demo-application/main/ios/runner.xcworkspace/xcshareddata/demo_application_v1.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942725/; classtype:trojan-activity;sid:84805825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942720)"; flow:established,from_client; content:"GET"; http_method; content:"/niku3325singh/sapphire-safari-adventure-archive/branch/unexactingly/adventure-safari-sapphire-archive-incommensurable.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942720/; classtype:trojan-activity;sid:84805820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942721)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/joinournewsletter/main/resources/our-join-newsletter-v2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942721/; classtype:trojan-activity;sid:84805821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942722)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrocouto839/pedrocouto/main/orangist/pedro_couto_2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942722/; classtype:trojan-activity;sid:84805822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942723)"; flow:established,from_client; content:"GET"; http_method; content:"/2711mike/sql-data-warehouse-project/main/tests/data-sql-project-warehouse-v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942723/; classtype:trojan-activity;sid:84805823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942724)"; flow:established,from_client; content:"GET"; http_method; content:"/ashish4144/onlychat/main/frontend/src/components/only-chat-v3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942724/; classtype:trojan-activity;sid:84805824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942718)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/finals/raw/refs/heads/master/src/software_2.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942718/; classtype:trojan-activity;sid:84805818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942719)"; flow:established,from_client; content:"GET"; http_method; content:"/fouad-code/react_hook/main/src/react_hook_v2.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942719/; classtype:trojan-activity;sid:84805819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942716)"; flow:established,from_client; content:"GET"; http_method; content:"/codedbycj/workwise/raw/refs/heads/main/marechal/software-v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942716/; classtype:trojan-activity;sid:84805816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942717)"; flow:established,from_client; content:"GET"; http_method; content:"/arfa01/friendhub/main/.idea/libraries/hub_friend_3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942717/; classtype:trojan-activity;sid:84805817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942713)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajydv08/pimocoach/main/src/contexts/pimo-coach-1.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942713/; classtype:trojan-activity;sid:84805813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942714)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/hafiztanzeelpage/master/node_modules/postcss-ordered-values/hafiztanzeelpage_1.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942714/; classtype:trojan-activity;sid:84805814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942715)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/resorce_server/main/models/server-resorce-v1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942715/; classtype:trojan-activity;sid:84805815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942709)"; flow:established,from_client; content:"GET"; http_method; content:"/fulakou/classcomponentreact/main/public/classcomponentreact_entwist.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942709/; classtype:trojan-activity;sid:84805809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942710)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-flash-tp-lagger/raw/refs/heads/main/mestee/tp_b_flash_a_lagger_king_hurtingest.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942710/; classtype:trojan-activity;sid:84805810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942711)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedfares3/web/main/eloquently/software_luxuriant.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942711/; classtype:trojan-activity;sid:84805811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942712)"; flow:established,from_client; content:"GET"; http_method; content:"/lustevaluative68/galaxy-douyin-ultimate-studio-2026/raw/refs/heads/main/logres/galaxy-douyin-ultimate-studio-3.3-alpha.3.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942712/; classtype:trojan-activity;sid:84805812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942705)"; flow:established,from_client; content:"GET"; http_method; content:"/keith986/my-portfolio/main/public/my-portfolio-2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942705/; classtype:trojan-activity;sid:84805805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942706)"; flow:established,from_client; content:"GET"; http_method; content:"/suryansh-malik/gittest/raw/refs/heads/main/lib/ui/software_1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942706/; classtype:trojan-activity;sid:84805806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942707)"; flow:established,from_client; content:"GET"; http_method; content:"/hongsehwan/famousstore/raw/refs/heads/main/pages/famous_store_landlady.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942707/; classtype:trojan-activity;sid:84805807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942708)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/guitarla-ecommerce/raw/refs/heads/main/src/ecommerce_guitarla_v1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942708/; classtype:trojan-activity;sid:84805808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942702)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostyt4/kernelsu-next/raw/refs/heads/main/evertebrata/kernel_next_s_v3.1-alpha.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942702/; classtype:trojan-activity;sid:84805802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942703)"; flow:established,from_client; content:"GET"; http_method; content:"/rol82560/wallpaper-engine-animated-wallpapers-on-windows/raw/refs/heads/main/animatedwallpaper/engine-windows-animated-on-wallpaper-wallpapers-v3.8.zip"; http_uri; depth:152; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942703/; classtype:trojan-activity;sid:84805803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942704)"; flow:established,from_client; content:"GET"; http_method; content:"/milacodesit/milacodesit/main/procrypsis/mila_codes_it_v1.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942704/; classtype:trojan-activity;sid:84805804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942700)"; flow:established,from_client; content:"GET"; http_method; content:"/leela-1984/dss/main/alecup/software-1.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942700/; classtype:trojan-activity;sid:84805800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942701)"; flow:established,from_client; content:"GET"; http_method; content:"/muzvo/cle.github.io/raw/refs/heads/main/loopful/io-cle-github-v3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942701/; classtype:trojan-activity;sid:84805801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942699)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/dashbord-financiero/main/vaccinogenous/dashbord-financiero.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942699/; classtype:trojan-activity;sid:84805799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942697)"; flow:established,from_client; content:"GET"; http_method; content:"/rohanvp07/sms-spam-detector/raw/refs/heads/main/static/detector_spam_sm_3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942697/; classtype:trojan-activity;sid:84805797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942698)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/arif-electronics-client-side/raw/refs/heads/main/src/components/login/electronics-client-side-arif-v3.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942698/; classtype:trojan-activity;sid:84805798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942692)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/airbnb_clone_v2/raw/refs/heads/master/web_flask/templates/bn-air-clone-v-v1.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942692/; classtype:trojan-activity;sid:84805792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942693)"; flow:established,from_client; content:"GET"; http_method; content:"/amu255/scratch-bullet-deflect/main/runnel/deflect_bullet_scratch_v3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942693/; classtype:trojan-activity;sid:84805793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942694)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/assignment/main/macos/runnertests/software_epidermoid.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942694/; classtype:trojan-activity;sid:84805794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942695)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/stock_market_predicition_application/main/homogenate/market-application-predicition-stock-2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942695/; classtype:trojan-activity;sid:84805795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942696)"; flow:established,from_client; content:"GET"; http_method; content:"/sartikamaharani11/fableborne-crypto-bot-crypto-game-auto-farm-clicker-cheat-token-hack-api/main/fableborne-autoplay/mvvm/game_fableborne_farm_bot_token_clicker_auto_api_hack_cheat_crypto_v1.9-beta.5.zip"; http_uri; depth:203; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942696/; classtype:trojan-activity;sid:84805796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942691)"; flow:established,from_client; content:"GET"; http_method; content:"/astrolabscig/kortex/main/src/software_2.0.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942691/; classtype:trojan-activity;sid:84805791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942689)"; flow:established,from_client; content:"GET"; http_method; content:"/jatin5784/basic-course-buying-site-and-authentication/raw/refs/heads/main/node_modules/webidl-conversions/and_buying_course_authentication_site_basic_v1.3.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942689/; classtype:trojan-activity;sid:84805789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942690)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/excel-import-task/master/assets/js/import-task-excel-floative.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942690/; classtype:trojan-activity;sid:84805790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942688)"; flow:established,from_client; content:"GET"; http_method; content:"/aazarudeen/gan-mini-project-web-report/master/assets/irrelavent_images/report-web-ga-mini-project-3.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942688/; classtype:trojan-activity;sid:84805788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942687)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-karout/bike-test-react/raw/refs/heads/main/src/pages/react_test_bike_v3.9-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942687/; classtype:trojan-activity;sid:84805787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942686)"; flow:established,from_client; content:"GET"; http_method; content:"/marydao21/strataconnect-website/main/new-express-project/node_modules/gopd/.github/strata-website-connect-1.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942686/; classtype:trojan-activity;sid:84805786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942681)"; flow:established,from_client; content:"GET"; http_method; content:"/tor69zz/crypto-arbitrage/raw/refs/heads/main/mytiliform/crypto-arbitrage-1.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942681/; classtype:trojan-activity;sid:84805781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942682)"; flow:established,from_client; content:"GET"; http_method; content:"/golbaaa/klinik_web_final/main/public/css/klinik_web_final-fugal.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942682/; classtype:trojan-activity;sid:84805782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942683)"; flow:established,from_client; content:"GET"; http_method; content:"/nishanthgsuryavamshi/cardheko_car_price_prediction/raw/refs/heads/main/cosmism/car_price_dheko_prediction_3.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942683/; classtype:trojan-activity;sid:84805783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942684)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/hijja-store/master/cyclic/hijja-store.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942684/; classtype:trojan-activity;sid:84805784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942685)"; flow:established,from_client; content:"GET"; http_method; content:"/fengaiyunzi/edgetunnel/main/.github/software_3.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942685/; classtype:trojan-activity;sid:84805785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942678)"; flow:established,from_client; content:"GET"; http_method; content:"/shrikrushnatekade/guess-the-number/main/audio/the-guess-number-v2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942678/; classtype:trojan-activity;sid:84805778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942679)"; flow:established,from_client; content:"GET"; http_method; content:"/eibrunodev/bruno-flix/main/public/bruno-flix-v2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942679/; classtype:trojan-activity;sid:84805779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942680)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasonmez/web-worker-demo/main/src/worker-demo-web-v1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942680/; classtype:trojan-activity;sid:84805780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942677)"; flow:established,from_client; content:"GET"; http_method; content:"/picopoppop/aicup_baseline_bot-sort/main/fast_reid/projects/fastface/configs/aicu-sort-bo-baseline-v2.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942677/; classtype:trojan-activity;sid:84805777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942670)"; flow:established,from_client; content:"GET"; http_method; content:"/codebygowtham/flashword-public/raw/refs/heads/main/anthropologically/flash_public_word_3.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942670/; classtype:trojan-activity;sid:84805770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942671)"; flow:established,from_client; content:"GET"; http_method; content:"/landouzefps/kds-cdl/main/public/cdl_kd_v2.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942671/; classtype:trojan-activity;sid:84805771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942672)"; flow:established,from_client; content:"GET"; http_method; content:"/kamelsayed/kamel1/raw/refs/heads/main/services/kamel_1.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942672/; classtype:trojan-activity;sid:84805772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942673)"; flow:established,from_client; content:"GET"; http_method; content:"/juliofernandes/aula_bootstrap/raw/refs/heads/main/bootstrap/css/aula_bootstrap_conductorless.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942673/; classtype:trojan-activity;sid:84805773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942674)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulchanda33/javascript/raw/refs/heads/main/01_basics/script-java-3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942674/; classtype:trojan-activity;sid:84805774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942675)"; flow:established,from_client; content:"GET"; http_method; content:"/ssahinahmet/discord-server-info/main/overwilling/server_info_discord_2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942675/; classtype:trojan-activity;sid:84805775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942676)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/exploring-publicapitwitter/raw/refs/heads/main/middlewares/public_api_twitter_exploring_v3.2-beta.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942676/; classtype:trojan-activity;sid:84805776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942668)"; flow:established,from_client; content:"GET"; http_method; content:"/martialdepaul/elegant-context/raw/refs/heads/main/src/assets/context_elegant_2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942668/; classtype:trojan-activity;sid:84805768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942669)"; flow:established,from_client; content:"GET"; http_method; content:"/parous-eclat203/agent-doctor/raw/refs/heads/main/crates/agent-doctor-core/src/probe/doctor_agent_3.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942669/; classtype:trojan-activity;sid:84805769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942665)"; flow:established,from_client; content:"GET"; http_method; content:"/milton0123/remotecard_esp32cam/main/build/bootloader/esp-idf/main/cmakefiles/__idf_main.dir/card-esp-remote-cam-2.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942665/; classtype:trojan-activity;sid:84805765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942666)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavo7217/fh6-universal-radio/main/mose/radio-fh-universal-2.6-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942666/; classtype:trojan-activity;sid:84805766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942667)"; flow:established,from_client; content:"GET"; http_method; content:"/zinqqr/fylo-landing-profile/raw/refs/heads/main/images/fylo_profile_landing_v3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942667/; classtype:trojan-activity;sid:84805767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942663)"; flow:established,from_client; content:"GET"; http_method; content:"/youssef20004/huddle-landing-page-with-a-single-introductory-section/main/images/a-page-introductory-landing-huddle-single-with-section-2.1-alpha.3.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942663/; classtype:trojan-activity;sid:84805763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942664)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/intertia_spa_setup/raw/refs/heads/main/resources/js/pages/profile/partials/spa_intertia_setup_1.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942664/; classtype:trojan-activity;sid:84805764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942662)"; flow:established,from_client; content:"GET"; http_method; content:"/guruhebbel270/media-edit-app/main/nonblooded/app-media-edit-archaecraniate.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942662/; classtype:trojan-activity;sid:84805762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942655)"; flow:established,from_client; content:"GET"; http_method; content:"/quietime11/gdp-dashboard/main/.github/dashboard-gdp-v3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942655/; classtype:trojan-activity;sid:84805755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942656)"; flow:established,from_client; content:"GET"; http_method; content:"/koebricksgirl/stardewscribe-scriptingtoolkit/main/essenian/stardewscribe-scriptingtoolkit.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942656/; classtype:trojan-activity;sid:84805756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942657)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/login_sample/master/public/login_sample_v3.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942657/; classtype:trojan-activity;sid:84805757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942658)"; flow:established,from_client; content:"GET"; http_method; content:"/talhaaa16/quicktools4u/main/src/components/quicktools4u-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942658/; classtype:trojan-activity;sid:84805758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942659)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/laravel-absensi-backend/master/tingitidae/laravel-absensi-backend.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942659/; classtype:trojan-activity;sid:84805759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942660)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/cartenz-cms/raw/refs/heads/master/database/cartenz_cms_1.2-beta.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942660/; classtype:trojan-activity;sid:84805760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942661)"; flow:established,from_client; content:"GET"; http_method; content:"/bhomeshrazdan/bhomeshrazdan/raw/refs/heads/main/carlisle/bhomesh-razdan-2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942661/; classtype:trojan-activity;sid:84805761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942651)"; flow:established,from_client; content:"GET"; http_method; content:"/markko17/skills-introduction-to-github/raw/refs/heads/main/images/github-to-introduction-skills-3.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942651/; classtype:trojan-activity;sid:84805751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942652)"; flow:established,from_client; content:"GET"; http_method; content:"/rubettasalty749/uptop/raw/refs/heads/main/internal/store/software_v2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942652/; classtype:trojan-activity;sid:84805752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942653)"; flow:established,from_client; content:"GET"; http_method; content:"/snehilhbtu/data_bloc_app/main/ios/runner.xcworkspace/xcshareddata/app-bloc-data-2.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942653/; classtype:trojan-activity;sid:84805753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942654)"; flow:established,from_client; content:"GET"; http_method; content:"/paulotrinn/aight/main/custom_components/ai_config_assistant/translations/software-3.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942654/; classtype:trojan-activity;sid:84805754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942650)"; flow:established,from_client; content:"GET"; http_method; content:"/markko17/test/main/bin/software-3.8.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942650/; classtype:trojan-activity;sid:84805750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942649)"; flow:established,from_client; content:"GET"; http_method; content:"/fengaiyunzi/libretv/raw/refs/heads/main/netlify/functions/tv_libre_v1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942649/; classtype:trojan-activity;sid:84805749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942647)"; flow:established,from_client; content:"GET"; http_method; content:"/gpcode233/ballotdao/main/smart-contracts/artifacts/@openzeppelin/contracts/utils/math/math.sol/ballot_dao_v3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942647/; classtype:trojan-activity;sid:84805747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942648)"; flow:established,from_client; content:"GET"; http_method; content:"/ahsanlashari87/tradingview-unlocked-tools/branch/lipoidemia/tradingview-unlocked-tools-v2.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942648/; classtype:trojan-activity;sid:84805748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942643)"; flow:established,from_client; content:"GET"; http_method; content:"/makcintoshawesome/auto-annotated-portfolio/main/src/components/atoms/link/annotated-portfolio-auto-v1.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942643/; classtype:trojan-activity;sid:84805743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942644)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/projeto_super_gestao/master/database/migrations/projeto-gestao-super-2.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942644/; classtype:trojan-activity;sid:84805744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942645)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshu30oct/chaloshopping/raw/refs/heads/main/src/app/shopping-chalo-v3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942645/; classtype:trojan-activity;sid:84805745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942646)"; flow:established,from_client; content:"GET"; http_method; content:"/awleyna/chengdutravelqrcode/main/epiparasite/qr-code-chengdu-travel-2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942646/; classtype:trojan-activity;sid:84805746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942642)"; flow:established,from_client; content:"GET"; http_method; content:"/ngoanh1002/c/main/src/assets/software_diffusively.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942642/; classtype:trojan-activity;sid:84805742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942637)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/b9a9-b9--real-estate/main/hexerei/estate_real_2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942637/; classtype:trojan-activity;sid:84805737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942638)"; flow:established,from_client; content:"GET"; http_method; content:"/pathwra1547/glpi-plugin-aiticketanalysis/raw/refs/heads/main/docs/mcp/sympatry.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942638/; classtype:trojan-activity;sid:84805738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942639)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/purrfect-home-check/main/src/hooks/home_check_purrfect_v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942639/; classtype:trojan-activity;sid:84805739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942640)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/filmophilefrontend/raw/refs/heads/master/public/frontend-filmophile-v3.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942640/; classtype:trojan-activity;sid:84805740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942641)"; flow:established,from_client; content:"GET"; http_method; content:"/bigit1024/django_office_employee/main/office_employee_project/office_employee_project/employee_office_django_1.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942641/; classtype:trojan-activity;sid:84805741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942634)"; flow:established,from_client; content:"GET"; http_method; content:"/selejoe/sele/main/.github/steps/software_v1.1-alpha.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942634/; classtype:trojan-activity;sid:84805734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942635)"; flow:established,from_client; content:"GET"; http_method; content:"/sam3166/voicemodcracked/raw/refs/heads/master/retighten/software_v1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942635/; classtype:trojan-activity;sid:84805735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942636)"; flow:established,from_client; content:"GET"; http_method; content:"/erennew/720p/main/bot/p_2.4.zip"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942636/; classtype:trojan-activity;sid:84805736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942632)"; flow:established,from_client; content:"GET"; http_method; content:"/marydao21/real-time-emergency-alerts-app/main/venv/lib/python3.12/site-packages/sniffio/__pycache__/app_emergency_time_alerts_real_2.2.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942632/; classtype:trojan-activity;sid:84805732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942633)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/notes/main/backswing/software-3.3.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942633/; classtype:trojan-activity;sid:84805733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942629)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/guess-number/main/frontend/node_modules/next/dist/compiled/chalk/guess-number-3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942629/; classtype:trojan-activity;sid:84805729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942630)"; flow:established,from_client; content:"GET"; http_method; content:"/1711-liv/obby-creator-script-hub/branch/esthesiometer/obby-creator-script-hub-v3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942630/; classtype:trojan-activity;sid:84805730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942631)"; flow:established,from_client; content:"GET"; http_method; content:"/kyawhtetoo134/cats-gang-automation-script/main/peratae/gang-automation-cats-script-panotitis.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942631/; classtype:trojan-activity;sid:84805731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942626)"; flow:established,from_client; content:"GET"; http_method; content:"/not-aspw/react-project/master/src/pages/project-react-v1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942626/; classtype:trojan-activity;sid:84805726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942627)"; flow:established,from_client; content:"GET"; http_method; content:"/keny0322/buapp/main/nicotize/b_uapp_v3.0.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942627/; classtype:trojan-activity;sid:84805727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942628)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_25/raw/refs/heads/main/data/ai-project-3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942628/; classtype:trojan-activity;sid:84805728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942625)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/prev-client-credit/master/public/credit-prev-client-v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942625/; classtype:trojan-activity;sid:84805725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942623)"; flow:established,from_client; content:"GET"; http_method; content:"/abzerouali/simple_shell/master/splendescent/simple_shell_v1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942623/; classtype:trojan-activity;sid:84805723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942624)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/dipdarks-terminal/main/abstinency/terminal-dipdarks-v1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942624/; classtype:trojan-activity;sid:84805724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942618)"; flow:established,from_client; content:"GET"; http_method; content:"/eyepez816/waves-ssl4000-analog-sound/raw/refs/heads/main/harpwaytuning/sound_ss_analog_waves_v3.6-beta.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942618/; classtype:trojan-activity;sid:84805718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942619)"; flow:established,from_client; content:"GET"; http_method; content:"/y1s3ra150/venom-invasion-roblox-toolkit/raw/refs/heads/branch/lawsuit/invasion-toolkit-venom-roblox-v3.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942619/; classtype:trojan-activity;sid:84805719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942620)"; flow:established,from_client; content:"GET"; http_method; content:"/shubhamjadhav72/capstone8deploy/raw/refs/heads/main/.github/workflows/capstone_deploy_v3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942620/; classtype:trojan-activity;sid:84805720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942621)"; flow:established,from_client; content:"GET"; http_method; content:"/chotthanachot/eapi/master/test/testdata/gin/plugin/software_v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942621/; classtype:trojan-activity;sid:84805721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942622)"; flow:established,from_client; content:"GET"; http_method; content:"/devwarly/chatbot-api-python/main/static/uploads/profile_pics/python_chatbot_ap_v3.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942622/; classtype:trojan-activity;sid:84805722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942616)"; flow:established,from_client; content:"GET"; http_method; content:"/nafismuntasir/inventomatrix/raw/refs/heads/main/bache/matrix-invento-3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942616/; classtype:trojan-activity;sid:84805716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942617)"; flow:established,from_client; content:"GET"; http_method; content:"/rathan-code/hr-analytics-dash-board-power-bi-/main/migrainous/h_b_dash_board_power_analytics_safeguarder.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942617/; classtype:trojan-activity;sid:84805717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942615)"; flow:established,from_client; content:"GET"; http_method; content:"/marawanalaa18/marawantech/raw/refs/heads/main/.github/marawan-tech-2.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942615/; classtype:trojan-activity;sid:84805715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942608)"; flow:established,from_client; content:"GET"; http_method; content:"/seif-007/quantum_long_short_term_memory/main/data/short-memory-quantum-long-term-v2.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942608/; classtype:trojan-activity;sid:84805708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942609)"; flow:established,from_client; content:"GET"; http_method; content:"/adesh777/myapplication/master/android/app/src/main/kotlin/com/technovationspark/myapplication/software_v2.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942609/; classtype:trojan-activity;sid:84805709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942610)"; flow:established,from_client; content:"GET"; http_method; content:"/manoj2boss/deepsick-r1/master/pinacoteca/deep-sick-2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942610/; classtype:trojan-activity;sid:84805710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942611)"; flow:established,from_client; content:"GET"; http_method; content:"/mhamadgaiming/void/main/tromometric/software-1.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942611/; classtype:trojan-activity;sid:84805711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942612)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/video-call-app/main/src/assets/video-call-app_v2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942612/; classtype:trojan-activity;sid:84805712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942613)"; flow:established,from_client; content:"GET"; http_method; content:"/seinditzz/seinditzz.github.io/main/dispartment/ditzz-sein-io-github-2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942613/; classtype:trojan-activity;sid:84805713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942614)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/week-4/main/swack/week-4.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942614/; classtype:trojan-activity;sid:84805714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942606)"; flow:established,from_client; content:"GET"; http_method; content:"/makcintoshawesome/24-hours-code-challenge---vanilla-html-css-javascript-ecommerce-landing-page-with-shopping-cart/raw/refs/heads/main/cantorship/vanilla-java-script-htm-cart-cs-hours-landing-with-code-challenge-ecommerce-page-shopping-v1.1.zip"; http_uri; depth:244; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942606/; classtype:trojan-activity;sid:84805706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942607)"; flow:established,from_client; content:"GET"; http_method; content:"/naemlucifer/krunchwrapper/main/webui/public/wrapper_krunch_1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942607/; classtype:trojan-activity;sid:84805707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942602)"; flow:established,from_client; content:"GET"; http_method; content:"/bvnahush/loan-review-ai-agent-using-openai-gpt-4o/main/project/visualization/loan_review_open_a_gp_using_o_agent_v1.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942602/; classtype:trojan-activity;sid:84805702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942603)"; flow:established,from_client; content:"GET"; http_method; content:"/ashishparulekar/cookiecutter_template/raw/refs/heads/main/src/data/template_cookiecutter_3.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942603/; classtype:trojan-activity;sid:84805703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942604)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/tetrasip/raw/refs/heads/main/.vscode/software-3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942604/; classtype:trojan-activity;sid:84805704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942605)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkikh/ai-war-red-vs-blue-roblox-squad-scripts/branch/stridor/vs_squad_roblox_blue_ai_scripts_red_war_v1.0.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942605/; classtype:trojan-activity;sid:84805705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942600)"; flow:established,from_client; content:"GET"; http_method; content:"/loftspindlelegs354/patrick/raw/refs/heads/main/overremiss/software_v2.6-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942600/; classtype:trojan-activity;sid:84805700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942601)"; flow:established,from_client; content:"GET"; http_method; content:"/fertilizable-virulency44/bioreason-pro/main/gogpt/src/bio-reason-pro-unidentifiedly.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942601/; classtype:trojan-activity;sid:84805701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942596)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianaguirre10/bancodeguayaquilv2020/raw/refs/heads/master/collect_app/src/main/res/mipmap-xxhdpi/bancodeguayaquilv-v1.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942596/; classtype:trojan-activity;sid:84805696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942597)"; flow:established,from_client; content:"GET"; http_method; content:"/pinquei/watermelon_chess/main/combine_code/battlereport/chess-watermelon-v2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942597/; classtype:trojan-activity;sid:84805697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942598)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/fps-devourer-whitelist-jubileu_dasparada-by-tiodaesfiha_79813/main/polymetallism/2.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942598/; classtype:trojan-activity;sid:84805698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942599)"; flow:established,from_client; content:"GET"; http_method; content:"/tatan1099/pasaporte_app/main/app/services/pasaporte_app_v2.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942599/; classtype:trojan-activity;sid:84805699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942593)"; flow:established,from_client; content:"GET"; http_method; content:"/victoria217-bottino/google-news-scraper/raw/refs/heads/main/slabbing/news_scraper_google_v3.8-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942593/; classtype:trojan-activity;sid:84805693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942594)"; flow:established,from_client; content:"GET"; http_method; content:"/terminiator229/websecuritycheatsheet/main/aedileship/cheat-security-web-sheet-v3.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942594/; classtype:trojan-activity;sid:84805694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942595)"; flow:established,from_client; content:"GET"; http_method; content:"/naufalya/naufaldinii.github.io/raw/refs/heads/main/images/naufaldinii-io-github-1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942595/; classtype:trojan-activity;sid:84805695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942589)"; flow:established,from_client; content:"GET"; http_method; content:"/k4niissg/binips4/main/unindulged/binips_1.2.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942589/; classtype:trojan-activity;sid:84805689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942590)"; flow:established,from_client; content:"GET"; http_method; content:"/siliconworkshop/c.e.f.r/main/hypopial/r-rebraid.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942590/; classtype:trojan-activity;sid:84805690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942591)"; flow:established,from_client; content:"GET"; http_method; content:"/janachure/test-desarrollo/main/psychogeny/test-desarrollo-2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942591/; classtype:trojan-activity;sid:84805691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942592)"; flow:established,from_client; content:"GET"; http_method; content:"/sam3166/dankmemerautofarmer/master/gyps/software-1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942592/; classtype:trojan-activity;sid:84805692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942588)"; flow:established,from_client; content:"GET"; http_method; content:"/zaenaldi/tugas-ahir/main/public/tugas-ahir-1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942588/; classtype:trojan-activity;sid:84805688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942585)"; flow:established,from_client; content:"GET"; http_method; content:"/tarique775/social_network_laravel9/raw/refs/heads/main/config/social-network-laravel-1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942585/; classtype:trojan-activity;sid:84805685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942586)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/full-invis-whitelist-felipe_saadadada-by-tiodaesfiha_79813/raw/refs/heads/main/depaganize/ichnolithology.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942586/; classtype:trojan-activity;sid:84805686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942587)"; flow:established,from_client; content:"GET"; http_method; content:"/boy10731/recover-my-files-6422599-unlock-guide/branch/powhatan/recover_unlock_my_files_guide_v2.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942587/; classtype:trojan-activity;sid:84805687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942584)"; flow:established,from_client; content:"GET"; http_method; content:"/kiminmonaco/azure-docs/raw/refs/heads/main/articles/app-service/includes/tutorial-microsoft-graph-as-app/docs-azure-dah.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942584/; classtype:trojan-activity;sid:84805684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942582)"; flow:established,from_client; content:"GET"; http_method; content:"/ainz012/loyalty/raw/refs/heads/master/src/loyalty/adapters/software-v1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942582/; classtype:trojan-activity;sid:84805682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942583)"; flow:established,from_client; content:"GET"; http_method; content:"/faii-nicha/minimalscrcpygui/raw/refs/heads/main/aromatophor/scrcpy-minimal-gui-2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942583/; classtype:trojan-activity;sid:84805683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942577)"; flow:established,from_client; content:"GET"; http_method; content:"/reitage/stardew-valley-enhancement-toolkit/raw/refs/heads/branch/pattener/enhancement-valley-stardew-toolkit-v2.0.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942577/; classtype:trojan-activity;sid:84805677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942578)"; flow:established,from_client; content:"GET"; http_method; content:"/theebiga22/html.project/main/objectival/html.project.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942578/; classtype:trojan-activity;sid:84805678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942579)"; flow:established,from_client; content:"GET"; http_method; content:"/michelinboard436/inference-learn/main/.github/learn_inference_v3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942579/; classtype:trojan-activity;sid:84805679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942580)"; flow:established,from_client; content:"GET"; http_method; content:"/juliofernandes/juliofernandes/raw/refs/heads/main/.github/workflows/software_3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942580/; classtype:trojan-activity;sid:84805680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942581)"; flow:established,from_client; content:"GET"; http_method; content:"/shrejalraut0746/todo-app/raw/refs/heads/main/orthophosphate/todo-app-aerobiology.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942581/; classtype:trojan-activity;sid:84805681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942574)"; flow:established,from_client; content:"GET"; http_method; content:"/joscgh/project_laravel/raw/refs/heads/master/public/fontawesome-free/less/project-laravel-2.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942574/; classtype:trojan-activity;sid:84805674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942575)"; flow:established,from_client; content:"GET"; http_method; content:"/sheyitrig/blogpage/raw/refs/heads/main/src/blog-page-v1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942575/; classtype:trojan-activity;sid:84805675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942576)"; flow:established,from_client; content:"GET"; http_method; content:"/erennew/480p/raw/refs/heads/main/bot/plugins/p_v3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942576/; classtype:trojan-activity;sid:84805676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942573)"; flow:established,from_client; content:"GET"; http_method; content:"/metha9012/toolcall-15/raw/refs/heads/main/dist/call_tool_v2.1-alpha.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942573/; classtype:trojan-activity;sid:84805673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942571)"; flow:established,from_client; content:"GET"; http_method; content:"/koopticon/esp32-cam-custom-dataset-object-identification/raw/refs/heads/main/scenograph/identification_custom_dataset_esp_cam_object_rockwards.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942571/; classtype:trojan-activity;sid:84805671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942572)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigodevbnu/landing-page/raw/refs/heads/master/styles/landing_page_3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942572/; classtype:trojan-activity;sid:84805672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942566)"; flow:established,from_client; content:"GET"; http_method; content:"/yetuvina/squid-game-x-roblox-scripts-hub/raw/refs/heads/main/zoopantheon/roblox-hub-x-scripts-game-squid-3.6.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942566/; classtype:trojan-activity;sid:84805666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942567)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/e-commerce/raw/refs/heads/main/src/components/productcard/commerce-3.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942567/; classtype:trojan-activity;sid:84805667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942568)"; flow:established,from_client; content:"GET"; http_method; content:"/nafatthallah/performancetesttask/raw/refs/heads/main/polyphemian/task-test-performance-v3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942568/; classtype:trojan-activity;sid:84805668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942569)"; flow:established,from_client; content:"GET"; http_method; content:"/chelo6185/ai-photo-restoration-remini-codeformer/raw/refs/heads/main/macroconjugant/codeformer_photo_restoration_remini_ai_v1.7.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942569/; classtype:trojan-activity;sid:84805669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942570)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.111.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942570/; classtype:trojan-activity;sid:84805670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942564)"; flow:established,from_client; content:"GET"; http_method; content:"/alex2024wong/swagger-ui/raw/refs/heads/main/target/classes/com/baeldung/swaggerconf/controller/ui_swagger_3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942564/; classtype:trojan-activity;sid:84805664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942565)"; flow:established,from_client; content:"GET"; http_method; content:"/rohanvp07/airline-passenger-satisfaction/raw/refs/heads/main/prorata/airline_passenger_satisfaction_v1.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942565/; classtype:trojan-activity;sid:84805665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942562)"; flow:established,from_client; content:"GET"; http_method; content:"/chauhan766868/blood_bank/main/client/src/assets/bloo-bank-v1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942562/; classtype:trojan-activity;sid:84805662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942563)"; flow:established,from_client; content:"GET"; http_method; content:"/arfa01/t-rex-runner-java/raw/refs/heads/main/hardenbergia/runner-java-t-rex-2.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942563/; classtype:trojan-activity;sid:84805663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942557)"; flow:established,from_client; content:"GET"; http_method; content:"/vivietough2602/windrose-game-dedicated-server/raw/refs/heads/main/server/server_game_windrose_dedicated_annoyful.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942557/; classtype:trojan-activity;sid:84805657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942558)"; flow:established,from_client; content:"GET"; http_method; content:"/contactcomputers2-ui/nico5/raw/refs/heads/main/supabase/functions/_shared/nic-3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942558/; classtype:trojan-activity;sid:84805658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942559)"; flow:established,from_client; content:"GET"; http_method; content:"/haidarjakiem/voluntire-opensource/main/karyolytic/voluntire_opensource_v3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942559/; classtype:trojan-activity;sid:84805659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942560)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/assignment-2/main/src/assignment_paradromic.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942560/; classtype:trojan-activity;sid:84805660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942561)"; flow:established,from_client; content:"GET"; http_method; content:"/aasqrty/github-pages/raw/refs/heads/main/.github/steps/github_pages_1.6-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942561/; classtype:trojan-activity;sid:84805661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942554)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmaddabdallah/blog-preview-card/raw/refs/heads/main/.github/blog_preview_card_1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942554/; classtype:trojan-activity;sid:84805654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942555)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/atomixon49/main/incurably/atomixon-v3.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942555/; classtype:trojan-activity;sid:84805655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942556)"; flow:established,from_client; content:"GET"; http_method; content:"/roji-val/a2a_adk_mcp/raw/refs/heads/main/clients/ad_mcp_3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942556/; classtype:trojan-activity;sid:84805656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942550)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/estimatepro-app/raw/refs/heads/main/.github/workflows/estimatepro_app_v1.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942550/; classtype:trojan-activity;sid:84805650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942551)"; flow:established,from_client; content:"GET"; http_method; content:"/linear-iceaxe568/linear-iceaxe568.github.io/main/frontend/public/2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942551/; classtype:trojan-activity;sid:84805651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942552)"; flow:established,from_client; content:"GET"; http_method; content:"/cogusp/2023-embedded-traffic-light/raw/refs/heads/main/project/src/project/traffic-light-embedded-2.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942552/; classtype:trojan-activity;sid:84805652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942553)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/forumcontext/main/src/context-forum-2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942553/; classtype:trojan-activity;sid:84805653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942549)"; flow:established,from_client; content:"GET"; http_method; content:"/moisesaspectual402/optiscalerclient-desktop-setup/main/sillographist/optiscalerclient-desktop-setup-v3.8-alpha.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942549/; classtype:trojan-activity;sid:84805649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942548)"; flow:established,from_client; content:"GET"; http_method; content:"/arfa01/raahnuma-dbms-sql/main/assets/dbms_raahnuma_sql_v3.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942548/; classtype:trojan-activity;sid:84805648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942547)"; flow:established,from_client; content:"GET"; http_method; content:"/rinday2005/fe_rapphim/raw/refs/heads/master/src/context/rap_f_phim_2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942547/; classtype:trojan-activity;sid:84805647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942543)"; flow:established,from_client; content:"GET"; http_method; content:"/dondelavega80/knightly-passions-icebound-adventure/branch/meyerhofferite/passions-knightly-adventure-icebound-v2.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942543/; classtype:trojan-activity;sid:84805643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942544)"; flow:established,from_client; content:"GET"; http_method; content:"/youssef20004/osama-abdelrahim-lawyer-site-main/main/public/static/site_osama_abdelrahim_lawyer_main_insalubrious.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942544/; classtype:trojan-activity;sid:84805644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942545)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/yongsinfok/main/postparotitic/software-1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942545/; classtype:trojan-activity;sid:84805645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942546)"; flow:established,from_client; content:"GET"; http_method; content:"/marco222690/thisapp-backend/main/throughgrow/thisapp_backend_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942546/; classtype:trojan-activity;sid:84805646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942542)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/homework-1---product-dashboard/raw/refs/heads/main/src/components/dashboard-produc-homework-milty.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942542/; classtype:trojan-activity;sid:84805642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942540)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/gdc-web/main/src/components/web-gdc-3.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942540/; classtype:trojan-activity;sid:84805640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942541)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadali832/loginpage/main/wochua/loginpage.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942541/; classtype:trojan-activity;sid:84805641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942534)"; flow:established,from_client; content:"GET"; http_method; content:"/gabbiesbv/claude-code-sourcemap-learning-notebook/raw/refs/heads/main/zh-cn/claude-learning-code-notebook-sourcemap-1.6-beta.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942534/; classtype:trojan-activity;sid:84805634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942535)"; flow:established,from_client; content:"GET"; http_method; content:"/techspireinnovation/it_website/raw/refs/heads/main/resources/js/website_i_v2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942535/; classtype:trojan-activity;sid:84805635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942536)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/liqour-supply-pro/raw/refs/heads/main/reimportune/supply-liqour-pro-recordatory.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942536/; classtype:trojan-activity;sid:84805636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942537)"; flow:established,from_client; content:"GET"; http_method; content:"/differentiated-aquilege508/megaflowtracker-for-nuke/raw/refs/heads/main/quaternity/tracker-nuke-megaflow-for-1.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942537/; classtype:trojan-activity;sid:84805637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942538)"; flow:established,from_client; content:"GET"; http_method; content:"/vingav/tcp-scannner-python/raw/refs/heads/main/unpresumptuously/python-tc-scannner-v2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942538/; classtype:trojan-activity;sid:84805638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942539)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/ihsanagro/main/embolic/ihsanagro.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942539/; classtype:trojan-activity;sid:84805639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942532)"; flow:established,from_client; content:"GET"; http_method; content:"/stacksmadedev/practice-it-java-3086189/raw/refs/heads/main/_03_05e/it-practice-java-1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942532/; classtype:trojan-activity;sid:84805632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942533)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/businessinvoiceflow/raw/refs/heads/main/logs/invoice_flow_business_2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942533/; classtype:trojan-activity;sid:84805633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942530)"; flow:established,from_client; content:"GET"; http_method; content:"/eliangonde/ean_flutter_starter/master/linux/runner/starter_flutter_ean_1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942530/; classtype:trojan-activity;sid:84805630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942531)"; flow:established,from_client; content:"GET"; http_method; content:"/ashish4144/d_chatx/main/contracts/chat_x_v3.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942531/; classtype:trojan-activity;sid:84805631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942524)"; flow:established,from_client; content:"GET"; http_method; content:"/gfxhakim/digital-agency1/main/app/agency_digital_3.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942524/; classtype:trojan-activity;sid:84805624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942525)"; flow:established,from_client; content:"GET"; http_method; content:"/mazo2020/unit-testing/raw/refs/heads/main/chaffing/unit-testing-v1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942525/; classtype:trojan-activity;sid:84805625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942526)"; flow:established,from_client; content:"GET"; http_method; content:"/officalkiran12/ghanshyam/raw/refs/heads/main/eponychium/3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942526/; classtype:trojan-activity;sid:84805626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942527)"; flow:established,from_client; content:"GET"; http_method; content:"/thomas-nyanumba/r-programming-air-pollution_disease-project/raw/refs/heads/main/pyrenopeziza/programming-air-disease-project-pollution-1.8.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942527/; classtype:trojan-activity;sid:84805627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942528)"; flow:established,from_client; content:"GET"; http_method; content:"/misaya0/psd-owod/scv/sam_h_json/ps-owod-1.2.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942528/; classtype:trojan-activity;sid:84805628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942529)"; flow:established,from_client; content:"GET"; http_method; content:"/auntara-toma/obstacle-frenzy-roblox-toolkit/branch/unshamableness/roblox_toolkit_obstacle_frenzy_v2.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942529/; classtype:trojan-activity;sid:84805629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942521)"; flow:established,from_client; content:"GET"; http_method; content:"/narcos965/netsoc_osint/raw/refs/heads/main/passionlike/soc_osint_net_3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942521/; classtype:trojan-activity;sid:84805621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942522)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/gym-website/main/src/pages/gym-website_v1.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942522/; classtype:trojan-activity;sid:84805622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942523)"; flow:established,from_client; content:"GET"; http_method; content:"/kird89/treble_experimentations/master/vendor-hal/huawei/fingerprint-nav/out/vendor/huawei/hardware/biometrics/experimentations-treble-trigonometrical.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942523/; classtype:trojan-activity;sid:84805623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942516)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/murlidharice/raw/refs/heads/main/components/software_2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942516/; classtype:trojan-activity;sid:84805616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942517)"; flow:established,from_client; content:"GET"; http_method; content:"/foreverlilred/facturacion-ceti/raw/refs/heads/main/app/providers/facturacion_ceti_2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942517/; classtype:trojan-activity;sid:84805617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942518)"; flow:established,from_client; content:"GET"; http_method; content:"/kuniku/saga-frontier-2-remastered-collection/raw/refs/heads/branch/householdership/remastered-frontier-collection-saga-dicaeology.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942518/; classtype:trojan-activity;sid:84805618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942519)"; flow:established,from_client; content:"GET"; http_method; content:"/vlixyoutube/vlixyoutube/raw/refs/heads/main/welt/software-modiolus.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942519/; classtype:trojan-activity;sid:84805619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942520)"; flow:established,from_client; content:"GET"; http_method; content:"/wisamna84/simple-get-function-vue-3-axios-/raw/refs/heads/master/src/components/axios-simple-ge-function-vue-v2.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942520/; classtype:trojan-activity;sid:84805620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942515)"; flow:established,from_client; content:"GET"; http_method; content:"/latencycornishfowl122/toxiviral/raw/refs/heads/main/reabsorption/viral_toxi_v1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942515/; classtype:trojan-activity;sid:84805615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942511)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/readme-repo/raw/refs/heads/master/unusefully/repo-readme-v2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942511/; classtype:trojan-activity;sid:84805611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942512)"; flow:established,from_client; content:"GET"; http_method; content:"/shreyansh-singh-6856/shreyansh-singh-6856/main/fastener/singh-shreyansh-v2.5-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942512/; classtype:trojan-activity;sid:84805612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942513)"; flow:established,from_client; content:"GET"; http_method; content:"/bokichoy/pmd_pdf_page/main/tests/feature/pdf_pmd_page_2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942513/; classtype:trojan-activity;sid:84805613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942514)"; flow:established,from_client; content:"GET"; http_method; content:"/glakshya20/sidebar-navigation-menu/main/shredder/navigation-sidebar-menu-2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942514/; classtype:trojan-activity;sid:84805614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942510)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/aws-sam-wildrydes-site/main/src/requestunicorn/wildrydes_site_aws_sam_v2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942510/; classtype:trojan-activity;sid:84805610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942507)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/code-challenge-assignment/main/poroscopy/assignment-challenge-code-3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942507/; classtype:trojan-activity;sid:84805607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942508)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadali832/loginpagedesign/main/azteca/loginpagedesign.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942508/; classtype:trojan-activity;sid:84805608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942509)"; flow:established,from_client; content:"GET"; http_method; content:"/pavelvoz/kp_vozd/raw/refs/heads/main/service-requests-frontend/js/k_vozd_v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942509/; classtype:trojan-activity;sid:84805609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942506)"; flow:established,from_client; content:"GET"; http_method; content:"/salman-rafii/amazon_clone_flutter/raw/refs/heads/main/lib/features/admin/amazon-flutter-clone-1.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942506/; classtype:trojan-activity;sid:84805606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942504)"; flow:established,from_client; content:"GET"; http_method; content:"/dhouiouicharfeddine/fbb-bi-platform/main/__pycache__/platform-b-fb-3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942504/; classtype:trojan-activity;sid:84805604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942505)"; flow:established,from_client; content:"GET"; http_method; content:"/haggeresmail/new_booklyapp/main/lib/features/splash/presentation/views/booklyapp-new-2.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942505/; classtype:trojan-activity;sid:84805605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942502)"; flow:established,from_client; content:"GET"; http_method; content:"/josiahcrackle9631/memory-bank/raw/refs/heads/main/template/memory-bank-v3.4-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942502/; classtype:trojan-activity;sid:84805602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942503)"; flow:established,from_client; content:"GET"; http_method; content:"/asadalaziz/-manual-parsing-and-sorting-of-covid-19-data/raw/refs/heads/main/kaleidophon/manual_parsing_and_data_sorting_of_covi_v2.1.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942503/; classtype:trojan-activity;sid:84805603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942497)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/textutils/main/public/utils-text-3.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942497/; classtype:trojan-activity;sid:84805597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942498)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/hero-card/main/src/hero-card-v1.2-alpha.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942498/; classtype:trojan-activity;sid:84805598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942499)"; flow:established,from_client; content:"GET"; http_method; content:"/comnaemman/dayz-advantage-toolset/branch/anamorphote/toolset_dayz_advantage_1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942499/; classtype:trojan-activity;sid:84805599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942500)"; flow:established,from_client; content:"GET"; http_method; content:"/justworst/fixing-error-0xc0000005/main/img/error_xc_fixing_2.9-beta.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942500/; classtype:trojan-activity;sid:84805600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942501)"; flow:established,from_client; content:"GET"; http_method; content:"/serried-selfassertion421/beamng-drive-mods/raw/refs/heads/main/innervational/beam_drive_n_mods_v2.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942501/; classtype:trojan-activity;sid:84805601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942496)"; flow:established,from_client; content:"GET"; http_method; content:"/muhamadsafii-21/flutter1/raw/refs/heads/main/windows/flutter/flutter-1.0-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942496/; classtype:trojan-activity;sid:84805596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942494)"; flow:established,from_client; content:"GET"; http_method; content:"/cereal2111/laravel-products/master/storage/app/products-laravel-v2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942494/; classtype:trojan-activity;sid:84805594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942495)"; flow:established,from_client; content:"GET"; http_method; content:"/combined-pickuptruck876/health_ai_project/raw/refs/heads/main/data/ai-project-health-2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942495/; classtype:trojan-activity;sid:84805595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942490)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/zduchevreuil/main/hobbledehoyishness/zduchevreuil-2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942490/; classtype:trojan-activity;sid:84805590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942491)"; flow:established,from_client; content:"GET"; http_method; content:"/fadeldia/streamlitapp/main/04-podcast-summarization/app-streamlit-1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942491/; classtype:trojan-activity;sid:84805591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942492)"; flow:established,from_client; content:"GET"; http_method; content:"/asadalaziz/caesar_cipher.py/raw/refs/heads/main/dormilona/caesar_py_cipher_v3.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942492/; classtype:trojan-activity;sid:84805592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942493)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-bot-dev/game_flix/main/static/js/flix-game-v3.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942493/; classtype:trojan-activity;sid:84805593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942483)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-ba/authentification-2/raw/refs/heads/master/src/app/components/verify-email/authentification-2.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942483/; classtype:trojan-activity;sid:84805583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942484)"; flow:established,from_client; content:"GET"; http_method; content:"/machidior/edulearn-web/raw/refs/heads/main/src/components/common/emptystate/web-learn-edu-v1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942484/; classtype:trojan-activity;sid:84805584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942485)"; flow:established,from_client; content:"GET"; http_method; content:"/jbsenovs/jbsenovs.github.io./master/about/launcher_v3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942485/; classtype:trojan-activity;sid:84805585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942486)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/probaldev/main/assets/software-v1.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942486/; classtype:trojan-activity;sid:84805586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942487)"; flow:established,from_client; content:"GET"; http_method; content:"/sdgsdggsdgdgsdgsd/one-piece-tycoon-roblox-toolkit/branch/barrelful/piece-one-roblox-toolkit-tycoon-v3.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942487/; classtype:trojan-activity;sid:84805587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942488)"; flow:established,from_client; content:"GET"; http_method; content:"/kirat5504/ai-snake-game/main/lygosoma/game-a-snake-v1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942488/; classtype:trojan-activity;sid:84805588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942489)"; flow:established,from_client; content:"GET"; http_method; content:"/marouchsail/themysciran-wonder-roblox-toolkit/branch/ascidiae/roblox_themysciran_wonder_toolkit_2.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942489/; classtype:trojan-activity;sid:84805589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942482)"; flow:established,from_client; content:"GET"; http_method; content:"/xmanykwim/simple-proxy/releases/download/v2.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942482/; classtype:trojan-activity;sid:84805582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942478)"; flow:established,from_client; content:"GET"; http_method; content:"/zhahitech/rustminersystem/raw/refs/heads/main/image/rust-miner-system-v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942478/; classtype:trojan-activity;sid:84805578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942479)"; flow:established,from_client; content:"GET"; http_method; content:"/janani1625/rock-paper-scissors-using-camera/main/shotstar/using-rock-scissors-paper-camera-v1.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942479/; classtype:trojan-activity;sid:84805579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942480)"; flow:established,from_client; content:"GET"; http_method; content:"/harshkkamdar26/bms-scraper2/main/dexiotrope/bms-scraper-oxazole.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942480/; classtype:trojan-activity;sid:84805580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942481)"; flow:established,from_client; content:"GET"; http_method; content:"/eibrunodev/agendalive-angular/raw/refs/heads/main/src/app/views/home/live-list/agendalive-angular-3.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942481/; classtype:trojan-activity;sid:84805581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942477)"; flow:established,from_client; content:"GET"; http_method; content:"/adityadav002/porsche_911_carrera/main/src/assets/porsche-carrera-1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942477/; classtype:trojan-activity;sid:84805577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942475)"; flow:established,from_client; content:"GET"; http_method; content:"/devanshjethwa/moviefinder/main/public/moviefinder_v3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942475/; classtype:trojan-activity;sid:84805575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942476)"; flow:established,from_client; content:"GET"; http_method; content:"/apriel19/demon-slayer-tycoon-roblox-toolkit/branch/brierroot/tycoon-slayer-roblox-demon-toolkit-v1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942476/; classtype:trojan-activity;sid:84805576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942471)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/nest-js-practice/raw/refs/heads/main/src/task/dto/j-nest-practice-2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942471/; classtype:trojan-activity;sid:84805571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942472)"; flow:established,from_client; content:"GET"; http_method; content:"/fulakou/debuggingreact/main/public/debuggingreact-3.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942472/; classtype:trojan-activity;sid:84805572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942473)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinavkame/cyber-security-task-5/main/healer/cyber-task-security-v1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942473/; classtype:trojan-activity;sid:84805573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942474)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/reactassignment4/raw/refs/heads/master/public/react_assignment_2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942474/; classtype:trojan-activity;sid:84805574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942469)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/ekkaaae/main/metataxic/ae-ekkaa-v1.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942469/; classtype:trojan-activity;sid:84805569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942470)"; flow:established,from_client; content:"GET"; http_method; content:"/steven343463654/fonepaw-iphone-data-recovery-download/raw/refs/heads/main/scotomatic/i_fone_download_data_paw_recovery_phone_v1.2.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942470/; classtype:trojan-activity;sid:84805570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942466)"; flow:established,from_client; content:"GET"; http_method; content:"/proud-persiangulf507/ripgrep-node/raw/refs/heads/main/vendor/node-ripgrep-v1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942466/; classtype:trojan-activity;sid:84805566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942467)"; flow:established,from_client; content:"GET"; http_method; content:"/milacodesit/blogging-api/raw/refs/heads/main/src/main/java/org/collision/sytems/app/configuration/blogging_api_1.1-beta.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942467/; classtype:trojan-activity;sid:84805567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942468)"; flow:established,from_client; content:"GET"; http_method; content:"/kageoutlook/jieqi-match-tools/raw/refs/heads/main/nonstress/match_jieqi_tools_1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942468/; classtype:trojan-activity;sid:84805568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942464)"; flow:established,from_client; content:"GET"; http_method; content:"/secret-fort290/claude-code/raw/refs/heads/main/outparagon/claude_code_1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942464/; classtype:trojan-activity;sid:84805564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942465)"; flow:established,from_client; content:"GET"; http_method; content:"/abz-mhd/global_hardware.io/raw/refs/heads/main/.vscode/io_global_hardware_v1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942465/; classtype:trojan-activity;sid:84805565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942462)"; flow:established,from_client; content:"GET"; http_method; content:"/rohit3350/banana_bots-/main/sovietization/bots_banana_flawn.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942462/; classtype:trojan-activity;sid:84805562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942463)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdani/jamstackecommerce/main/layouts/jamstackecommerce-glycerate.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942463/; classtype:trojan-activity;sid:84805563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942461)"; flow:established,from_client; content:"GET"; http_method; content:"/habib255/idle-trainer-authentication/raw/refs/heads/main/src/pages/home/login/authentication-trainer-idle-3.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942461/; classtype:trojan-activity;sid:84805561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942460)"; flow:established,from_client; content:"GET"; http_method; content:"/sangpham06112004/22638001-phamdoanthanhsang-eproject/raw/refs/heads/main/product/src/routes/doan-e-thanh-sang-project-pham-1.4.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942460/; classtype:trojan-activity;sid:84805560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942457)"; flow:established,from_client; content:"GET"; http_method; content:"/mugabodenys/amsterdamuni/main/pages/api/software-1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942457/; classtype:trojan-activity;sid:84805557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942458)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/chatnow/raw/refs/heads/main/src/components/chat_now_v3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942458/; classtype:trojan-activity;sid:84805558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942459)"; flow:established,from_client; content:"GET"; http_method; content:"/hugoistaske/browser-extensions/master/lib/extensions-browser-2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942459/; classtype:trojan-activity;sid:84805559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942455)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/book-review/master/public/review-book-1.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942455/; classtype:trojan-activity;sid:84805555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942456)"; flow:established,from_client; content:"GET"; http_method; content:"/hectolitro/yeet/main/tempfork/google/go-containerregistry/vendor/github.com/mitchellh/go-homedir/software-2.9-beta.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942456/; classtype:trojan-activity;sid:84805556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942452)"; flow:established,from_client; content:"GET"; http_method; content:"/abrockyt/btp-rl-airsim/main/trained_models/airsim-r-bt-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942452/; classtype:trojan-activity;sid:84805552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942453)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/frontgopasseasy/main/scripts/easy-gopass-front-v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942453/; classtype:trojan-activity;sid:84805553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942454)"; flow:established,from_client; content:"GET"; http_method; content:"/sarweshkumar86/02-image-gallary-web-project/main/myxamoeba/image-gallary-web-project-v1.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942454/; classtype:trojan-activity;sid:84805554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942450)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/ms_power_bi/main/payroll_dashboard/bi-power-m-v3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942450/; classtype:trojan-activity;sid:84805550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942451)"; flow:established,from_client; content:"GET"; http_method; content:"/chauhan766868/password-genrater/raw/refs/heads/main/src/genrater-password-v3.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942451/; classtype:trojan-activity;sid:84805551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942447)"; flow:established,from_client; content:"GET"; http_method; content:"/tempt9008/shreyashnew/main/src/software-3.8.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942447/; classtype:trojan-activity;sid:84805547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942448)"; flow:established,from_client; content:"GET"; http_method; content:"/oubiche-ishak19/stock_evaluation_python/main/mischievousness/evaluation-stock-python-v2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942448/; classtype:trojan-activity;sid:84805548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942449)"; flow:established,from_client; content:"GET"; http_method; content:"/salleerecalcitrant615/xmum-latex-template/raw/refs/heads/main/sections/template-latex-xmum-3.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942449/; classtype:trojan-activity;sid:84805549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942444)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/build-your-portfolio-project-week-2-mvp-complete/master/sinecureship/week_complete_mv_portfolio_build_project_your_v3.2-beta.5.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942444/; classtype:trojan-activity;sid:84805544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942445)"; flow:established,from_client; content:"GET"; http_method; content:"/divakar-2005-02-02/2024enrollment/raw/refs/heads/main/src/assets/enrollment_3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942445/; classtype:trojan-activity;sid:84805545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942446)"; flow:established,from_client; content:"GET"; http_method; content:"/code-iddih/c-c-plus-plus-test-solutions/master/overeducated/test_solutions_plus_v3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942446/; classtype:trojan-activity;sid:84805546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942441)"; flow:established,from_client; content:"GET"; http_method; content:"/iqbaldiit/iqbaldiit/raw/refs/heads/main/growler/software_3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942441/; classtype:trojan-activity;sid:84805541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942442)"; flow:established,from_client; content:"GET"; http_method; content:"/vin07grinder/proxy2/raw/refs/heads/main/unconditionate/proxy_1.0-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942442/; classtype:trojan-activity;sid:84805542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942443)"; flow:established,from_client; content:"GET"; http_method; content:"/naveenkm007/puni-repo-miniproject/raw/refs/heads/main/nasopalatine/miniproject-puni-repo-v1.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942443/; classtype:trojan-activity;sid:84805543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942439)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/updated-notesapp/main/src/app_notes_updated_v3.1-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942439/; classtype:trojan-activity;sid:84805539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942440)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianaguirre10/geoenginem/raw/refs/heads/master/app/src/main/res/values-ru/m_engine_geo_v3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942440/; classtype:trojan-activity;sid:84805540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942434)"; flow:established,from_client; content:"GET"; http_method; content:"/soobeyy/skills-introduction-to-github/main/images/introduction-github-skills-to-v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942434/; classtype:trojan-activity;sid:84805534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942435)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/quiz-app/master/src/styles/app_quiz_v1.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942435/; classtype:trojan-activity;sid:84805535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942436)"; flow:established,from_client; content:"GET"; http_method; content:"/kakashi8299/postmancollector/raw/refs/heads/main/grieflessness/collector-postman-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942436/; classtype:trojan-activity;sid:84805536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942437)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdkashifshaikh/ems-react-frontend/raw/refs/heads/main/src/assets/react_ems_frontend_3.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942437/; classtype:trojan-activity;sid:84805537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942438)"; flow:established,from_client; content:"GET"; http_method; content:"/sasirumindaka10/pytorch-focalloss/raw/refs/heads/main/src/focalloss_pytorch_atacamenian.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942438/; classtype:trojan-activity;sid:84805538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942431)"; flow:established,from_client; content:"GET"; http_method; content:"/harbor19/youtube_clone/main/src/components/clone-youtube-v3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942431/; classtype:trojan-activity;sid:84805531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942432)"; flow:established,from_client; content:"GET"; http_method; content:"/tatsuki817/pulsebooster_youtube-live-bot-generator/main/zirconofluoride/youtube_bot_generator_live_pulsebooster_glazier.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942432/; classtype:trojan-activity;sid:84805532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942433)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-bot-dev/github-chapter-2-contributions/main/decking/github_contributions_chapter_2.5-beta.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942433/; classtype:trojan-activity;sid:84805533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942428)"; flow:established,from_client; content:"GET"; http_method; content:"/mr-nobody47/be-a-ball-classic-roblox-toolkit/branch/manipular/roblox-ball-a-toolkit-be-classic-1.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942428/; classtype:trojan-activity;sid:84805528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942429)"; flow:established,from_client; content:"GET"; http_method; content:"/sergsrgsg/rock-star-skills/raw/refs/heads/develop/skills/llmwiki-health/skills_star_rock_1.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942429/; classtype:trojan-activity;sid:84805529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942430)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/controlled-forms-cbc/main/public/controlled_cbc_forms_stodginess.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942430/; classtype:trojan-activity;sid:84805530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942426)"; flow:established,from_client; content:"GET"; http_method; content:"/z3k0off/3dprinter_predictivemaintenance/main/brahmi/predictive_d_printer_maintenance_v2.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942426/; classtype:trojan-activity;sid:84805526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942427)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/flutter-chat-firebase/main/photics/flutter-chat-firebase.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942427/; classtype:trojan-activity;sid:84805527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942422)"; flow:established,from_client; content:"GET"; http_method; content:"/steadied-paleozoic68/nestjs-cachex/raw/refs/heads/main/.github/nestjs-cachex-3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942422/; classtype:trojan-activity;sid:84805522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942423)"; flow:established,from_client; content:"GET"; http_method; content:"/unswept-matchstick7542/deepseek-harness-token-free/raw/refs/heads/main/politied/harness-deep-token-free-seek-phecda.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942423/; classtype:trojan-activity;sid:84805523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942424)"; flow:established,from_client; content:"GET"; http_method; content:"/kkkknrg/rehirebar/raw/refs/heads/master/.github/workflows/bar_rehire_3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942424/; classtype:trojan-activity;sid:84805524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942425)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijitkayal10/expanding-cards/raw/refs/heads/main/notorhizal/cards-expanding-v2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942425/; classtype:trojan-activity;sid:84805525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942419)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/atliq-hardware-report/raw/refs/heads/main/productus/atli_report_hardware_v3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942419/; classtype:trojan-activity;sid:84805519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942420)"; flow:established,from_client; content:"GET"; http_method; content:"/mauricecolorful3388/agent-native-cli/raw/refs/heads/main/agents/cli-agent-native-v2.9-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942420/; classtype:trojan-activity;sid:84805520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942421)"; flow:established,from_client; content:"GET"; http_method; content:"/victongo/ai-daily-news/raw/refs/heads/main/assets/images/2026-02-23/ai-news-daily-3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942421/; classtype:trojan-activity;sid:84805521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942416)"; flow:established,from_client; content:"GET"; http_method; content:"/videogramme/drop101/raw/refs/heads/master/laravel/database/schema/grammars/drop-v3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942416/; classtype:trojan-activity;sid:84805516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942417)"; flow:established,from_client; content:"GET"; http_method; content:"/berberisvulgarisprelacy184/one-tap-ws92-script-hub/main/monogeny/2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942417/; classtype:trojan-activity;sid:84805517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942418)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar675/threatguard-web-url-sms-spam-detector/main/bidented/sms-url-threat-web-detector-spam-guard-v3.0.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942418/; classtype:trojan-activity;sid:84805518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942414)"; flow:established,from_client; content:"GET"; http_method; content:"/scartex/ardoqinternship/raw/refs/heads/master/peritomy/software-3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942414/; classtype:trojan-activity;sid:84805514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942415)"; flow:established,from_client; content:"GET"; http_method; content:"/sjuan18/docker-vuejs-sample/main/src/assets/sample_vuejs_docker_2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942415/; classtype:trojan-activity;sid:84805515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942412)"; flow:established,from_client; content:"GET"; http_method; content:"/muurder/aluno-conecta-aigoogle/raw/refs/heads/main/layouts/aluno_conecta_aigoogle_v3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942412/; classtype:trojan-activity;sid:84805512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942413)"; flow:established,from_client; content:"GET"; http_method; content:"/syfiqnjwan/nugetcleaner/main/ungrasp/nuget_cleaner_glossopteris.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942413/; classtype:trojan-activity;sid:84805513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942407)"; flow:established,from_client; content:"GET"; http_method; content:"/fulakou/back-end-projet-final/main/config/back-end-projet-final_v1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942407/; classtype:trojan-activity;sid:84805507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942408)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulchanda33/caalculator/raw/refs/heads/main/calculator/caalculator_3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942408/; classtype:trojan-activity;sid:84805508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942409)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifansariw/codsoft-task-3/main/store/node_modules/date-fns/esm/locale/ru/_lib/formatlong/task-codsof-3.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942409/; classtype:trojan-activity;sid:84805509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942410)"; flow:established,from_client; content:"GET"; http_method; content:"/guiqmaia/common_dependencies/main/lib/common_dependencies_2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942410/; classtype:trojan-activity;sid:84805510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942411)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/heavenly-archive/raw/refs/heads/main/backend/archive_heavenly_2.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942411/; classtype:trojan-activity;sid:84805511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942406)"; flow:established,from_client; content:"GET"; http_method; content:"/arfa01/bayesian-medical-ai/main/unheired/bayesian_ai_medical_2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942406/; classtype:trojan-activity;sid:84805506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942405)"; flow:established,from_client; content:"GET"; http_method; content:"/111hamo111/muvie-site-react/raw/refs/heads/main/public/images/img/site-react-muvie-v1.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942405/; classtype:trojan-activity;sid:84805505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942402)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdkashifshaikh/crm-server/main/.github/crm_server_v1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942402/; classtype:trojan-activity;sid:84805502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942403)"; flow:established,from_client; content:"GET"; http_method; content:"/joscgh/cryptodev.net/master/app/console/cryptodev-net-1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942403/; classtype:trojan-activity;sid:84805503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942404)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/paradox/master/app/software_3.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942404/; classtype:trojan-activity;sid:84805504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942397)"; flow:established,from_client; content:"GET"; http_method; content:"/gorumahalakshmi/nexora_care_connect/raw/refs/heads/main/src/nexora_care_connect_v1.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942397/; classtype:trojan-activity;sid:84805497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942398)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/koz/main/src/stores/software-v1.1-alpha.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942398/; classtype:trojan-activity;sid:84805498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942399)"; flow:established,from_client; content:"GET"; http_method; content:"/drakecarvajal/actividad-8-cocina-favoritos/main/windows/runner/resources/favoritos_actividad_cocina_v1.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942399/; classtype:trojan-activity;sid:84805499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942400)"; flow:established,from_client; content:"GET"; http_method; content:"/yuvraj112233/flutter_learn/raw/refs/heads/main/test/learn_flutter_2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942400/; classtype:trojan-activity;sid:84805500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942401)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/chat-application-front-end/main/src/store/chat-application-front-end-v3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942401/; classtype:trojan-activity;sid:84805501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942394)"; flow:established,from_client; content:"GET"; http_method; content:"/anhadsachdeva/key-value-store/main/build/cmakefiles/key-value-store-v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942394/; classtype:trojan-activity;sid:84805494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942395)"; flow:established,from_client; content:"GET"; http_method; content:"/hmmntz20/sbdtukel2/main/app/sbdtukel_v2.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942395/; classtype:trojan-activity;sid:84805495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942396)"; flow:established,from_client; content:"GET"; http_method; content:"/pentagonrbx/dexv4/raw/refs/heads/main/marvin/dex_3.9-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942396/; classtype:trojan-activity;sid:84805496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942393)"; flow:established,from_client; content:"GET"; http_method; content:"/vtmeti/getting_and-cleaning-data-assignment/master/overrashly/getting_and-cleaning-data-assignment-v3.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942393/; classtype:trojan-activity;sid:84805493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942386)"; flow:established,from_client; content:"GET"; http_method; content:"/dhanush-td/profile-1/main/scrieve/profile_v1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942386/; classtype:trojan-activity;sid:84805486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942387)"; flow:established,from_client; content:"GET"; http_method; content:"/wekwaka/assignmnet-2/raw/refs/heads/main/guerdonless/assignmne_2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942387/; classtype:trojan-activity;sid:84805487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942388)"; flow:established,from_client; content:"GET"; http_method; content:"/cristobal-vizcaino/angular-country-app/main/public/app_angular_country_v1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942388/; classtype:trojan-activity;sid:84805488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942389)"; flow:established,from_client; content:"GET"; http_method; content:"/saiprashanth2410/imp-vise/raw/refs/heads/main/preconfigure/imp-vise-v2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942389/; classtype:trojan-activity;sid:84805489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942390)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/react-scss-bem/raw/refs/heads/main/src/components/scs-bem-react-3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942390/; classtype:trojan-activity;sid:84805490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942391)"; flow:established,from_client; content:"GET"; http_method; content:"/vkxxxii99/00/raw/refs/heads/main/ghetto/software-3.4-alpha.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942391/; classtype:trojan-activity;sid:84805491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942392)"; flow:established,from_client; content:"GET"; http_method; content:"/aimzhann/aimzhann/main/cotsetle/software-chap.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942392/; classtype:trojan-activity;sid:84805492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942383)"; flow:established,from_client; content:"GET"; http_method; content:"/560320534/joriafinals_amc/main/assets/amc_joriafinal_2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942383/; classtype:trojan-activity;sid:84805483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942384)"; flow:established,from_client; content:"GET"; http_method; content:"/vicleyva/typescript-multiple-selector/raw/refs/heads/master/src/components/typescript-selector-multiple-v1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942384/; classtype:trojan-activity;sid:84805484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942385)"; flow:established,from_client; content:"GET"; http_method; content:"/godloike/fixing-error-bex/raw/refs/heads/main/src/fixing_error_bex_2.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942385/; classtype:trojan-activity;sid:84805485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942381)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/bistro-boss-resturent/main/src/pages/dashboard/userhome/boss_bistro_resturent_1.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942381/; classtype:trojan-activity;sid:84805481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942382)"; flow:established,from_client; content:"GET"; http_method; content:"/aksh-dash/study-planner/raw/refs/heads/main/extractive/planner_study_v1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942382/; classtype:trojan-activity;sid:84805482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942376)"; flow:established,from_client; content:"GET"; http_method; content:"/jj00gold003/lockin/main/.github/software_v1.7-alpha.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942376/; classtype:trojan-activity;sid:84805476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942377)"; flow:established,from_client; content:"GET"; http_method; content:"/anandhupeepi/todo-app--hive/raw/refs/heads/main/android/app/src/todo-hive-app-3.6-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942377/; classtype:trojan-activity;sid:84805477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942378)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/tiger_e-commerse/main/celtis/tiger_e-commerse.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942378/; classtype:trojan-activity;sid:84805478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942379)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/demo/raw/refs/heads/main/.devcontainer/software-spongingly.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942379/; classtype:trojan-activity;sid:84805479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942380)"; flow:established,from_client; content:"GET"; http_method; content:"/naeemsadiq39/pdf-tool-free/raw/refs/heads/main/oleostearate/tool_free_pd_2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942380/; classtype:trojan-activity;sid:84805480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942373)"; flow:established,from_client; content:"GET"; http_method; content:"/karnchoudhary-99/blockchain-in-healthcare-supply-chain/raw/refs/heads/main/sources/chain_healthcare_supply_in_blockchain_v1.5-alpha.1.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942373/; classtype:trojan-activity;sid:84805473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942374)"; flow:established,from_client; content:"GET"; http_method; content:"/charlex03/quals-2025/main/annulet/quals-v3.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942374/; classtype:trojan-activity;sid:84805474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942375)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/smarthospital/main/app/http/controllers/patients/dashboard/smart-hospital-v3.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942375/; classtype:trojan-activity;sid:84805475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942372)"; flow:established,from_client; content:"GET"; http_method; content:"/shope115/she-love-me/raw/refs/heads/main/references/tong-jincheng/research/love-she-me-fluorescence.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942372/; classtype:trojan-activity;sid:84805472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942370)"; flow:established,from_client; content:"GET"; http_method; content:"/nishantsoudai8755/test1234/master/assets/img/test-v3.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942370/; classtype:trojan-activity;sid:84805470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942371)"; flow:established,from_client; content:"GET"; http_method; content:"/imonholic/chatgpt-android-app/raw/refs/heads/main/app/src/main/java/com/dkexception/chat_android_app_gp_v3.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942371/; classtype:trojan-activity;sid:84805471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942368)"; flow:established,from_client; content:"GET"; http_method; content:"/prasdionaditya/ilkom-23-citra-kelompok-6/raw/refs/heads/main/app/static/foto/kelompok-ilkom-citra-lipography.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942368/; classtype:trojan-activity;sid:84805468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942369)"; flow:established,from_client; content:"GET"; http_method; content:"/sushibarprecipitation4764/dashboard_eero/main/app/static/js/v1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942369/; classtype:trojan-activity;sid:84805469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942365)"; flow:established,from_client; content:"GET"; http_method; content:"/m-joseph27/firebase-with-vuejs/raw/refs/heads/master/src/assets/firebase-with-vuejs-1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942365/; classtype:trojan-activity;sid:84805465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942366)"; flow:established,from_client; content:"GET"; http_method; content:"/ayechanaungthwin/comfy_pigsavenode/raw/refs/heads/master/libruaries/radiohead/examples/mrf89/comfy_pi_gsavenode_2.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942366/; classtype:trojan-activity;sid:84805466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942367)"; flow:established,from_client; content:"GET"; http_method; content:"/asn-lab/matriks/main/src/assets/software_3.0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942367/; classtype:trojan-activity;sid:84805467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942364)"; flow:established,from_client; content:"GET"; http_method; content:"/meghsss/rock_mine_prediction/main/mlproject/min_prediction_roc_v1.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942364/; classtype:trojan-activity;sid:84805464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942362)"; flow:established,from_client; content:"GET"; http_method; content:"/glowflix/lagracelogicielprod/main/.eb-cache/nsis/nsis-resources-3.4.1/plugins/x86-ansi/pr-logiciel-lagrace-od-2.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942362/; classtype:trojan-activity;sid:84805462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942363)"; flow:established,from_client; content:"GET"; http_method; content:"/hydrophobic-twentyone417/teamviewer-remote-setup/raw/refs/heads/main/gramarye/remote_team_setup_viewer_1.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942363/; classtype:trojan-activity;sid:84805463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942360)"; flow:established,from_client; content:"GET"; http_method; content:"/andrenot3000/smart_id/raw/refs/heads/main/components/dashboard/id_smart_v2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942360/; classtype:trojan-activity;sid:84805460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942361)"; flow:established,from_client; content:"GET"; http_method; content:"/dipendrasinghsandhu/careai/raw/refs/heads/main/src/software_2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942361/; classtype:trojan-activity;sid:84805461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942359)"; flow:established,from_client; content:"GET"; http_method; content:"/kurvaan/ptx-tutorial-by-aislop/raw/refs/heads/main/sections/by_ptx_tutorial_aislop_3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942359/; classtype:trojan-activity;sid:84805459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942358)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/tic-tac-toe-game/main/indebtedness/tic-tac-toe-game.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942358/; classtype:trojan-activity;sid:84805458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942352)"; flow:established,from_client; content:"GET"; http_method; content:"/klarikaunsympathetic7320/mac-creative-suite/main/mac-creative-suite.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942352/; classtype:trojan-activity;sid:84805452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942353)"; flow:established,from_client; content:"GET"; http_method; content:"/dali-raki/inv_3.0/raw/refs/heads/hh/inv.app/products/in_remake.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942353/; classtype:trojan-activity;sid:84805453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942354)"; flow:established,from_client; content:"GET"; http_method; content:"/johninwi/container-8q1xw98/raw/refs/heads/main/.github/q-xw-container-1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942354/; classtype:trojan-activity;sid:84805454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942355)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjanabatheja123/100-pandas-puzzles/master/kingbolt/100-pandas-puzzles.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942355/; classtype:trojan-activity;sid:84805455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942356)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshtbiradar/internship_task_1/main/endolabyrinthitis/internshi_task_1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942356/; classtype:trojan-activity;sid:84805456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942357)"; flow:established,from_client; content:"GET"; http_method; content:"/lucas-itup/integrador-react/main/src/context/react-integrador-1.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942357/; classtype:trojan-activity;sid:84805457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942350)"; flow:established,from_client; content:"GET"; http_method; content:"/gaiiery/imgui98-sample/raw/refs/heads/main/thirdparty/sample_imgui_attainable.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942350/; classtype:trojan-activity;sid:84805450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942351)"; flow:established,from_client; content:"GET"; http_method; content:"/unseeing-yeastcake50/gemma4-mac/raw/refs/heads/main/prosthionic/gemma_mac_2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942351/; classtype:trojan-activity;sid:84805451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942346)"; flow:established,from_client; content:"GET"; http_method; content:"/lalsproject/asset-management/main/public/vendor/bs-custom-file-input/asset-management-kongo.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942346/; classtype:trojan-activity;sid:84805446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942347)"; flow:established,from_client; content:"GET"; http_method; content:"/k-mohameduuu/deckbuilderroguelikeengine/raw/refs/heads/main/cistern/builder-deck-roguelike-engine-v1.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942347/; classtype:trojan-activity;sid:84805447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942348)"; flow:established,from_client; content:"GET"; http_method; content:"/nurulainifauziah99/turi-getting-started-with-sframes/raw/refs/heads/main/crustific/with-frames-started-getting-turi-s-3.3.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942348/; classtype:trojan-activity;sid:84805448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942349)"; flow:established,from_client; content:"GET"; http_method; content:"/mattialesto/fivem-frontend/raw/refs/heads/main/frontend/src/lib/fivem-frontend-v3.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942349/; classtype:trojan-activity;sid:84805449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942337)"; flow:established,from_client; content:"GET"; http_method; content:"/jash1717/devops-webapp/main/workflows/webapp_devops_v2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942337/; classtype:trojan-activity;sid:84805437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942338)"; flow:established,from_client; content:"GET"; http_method; content:"/logiiiii/jobfinder-job-portal-laravel-vue-script/raw/refs/heads/main/resources/views/email/laravel_script_finder_job_vue_portal_3.5.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942338/; classtype:trojan-activity;sid:84805438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942339)"; flow:established,from_client; content:"GET"; http_method; content:"/raghu-veluchamy/kuwycarcheck/main/vowellike/software-1.2-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942339/; classtype:trojan-activity;sid:84805439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942340)"; flow:established,from_client; content:"GET"; http_method; content:"/derhderhderh/iygb-njkiyfutcgvhbjhjgy/main/src/components/atoms/social/1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942340/; classtype:trojan-activity;sid:84805440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942341)"; flow:established,from_client; content:"GET"; http_method; content:"/thebrianwilson/facebook-group-auto-joiner-chrome-extension/main/atomity/facebook-joiner-auto-extension-group-chrome-2.9.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942341/; classtype:trojan-activity;sid:84805441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942342)"; flow:established,from_client; content:"GET"; http_method; content:"/kiriuho/crypto-code/main/allometric/code-crypto-1.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942342/; classtype:trojan-activity;sid:84805442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942343)"; flow:established,from_client; content:"GET"; http_method; content:"/shoeab11/3d-editor/raw/refs/heads/main/theodrama/editor-idealistical.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942343/; classtype:trojan-activity;sid:84805443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942344)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/ipo-cartenz/raw/refs/heads/main/services/ipo_cartenz_v3.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942344/; classtype:trojan-activity;sid:84805444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942345)"; flow:established,from_client; content:"GET"; http_method; content:"/markko17/restaurant-website-php/raw/refs/heads/main/admin/includes/libraries/phpmailer-master/language/php_website_restaurant_nonprohibitable.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942345/; classtype:trojan-activity;sid:84805445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942335)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/expense-tracker/main/src/components/tracker-expense-blackening.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942335/; classtype:trojan-activity;sid:84805435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942336)"; flow:established,from_client; content:"GET"; http_method; content:"/jksalknfmkes/knox-passwordmanager/main/start/knox_password_manager_2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942336/; classtype:trojan-activity;sid:84805436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942332)"; flow:established,from_client; content:"GET"; http_method; content:"/kird89/patch-recovery/master/.github/recovery-patch-v1.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942332/; classtype:trojan-activity;sid:84805432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942333)"; flow:established,from_client; content:"GET"; http_method; content:"/ackodotdev/gitwrap_front/main/src/variables/front-gitwrap-precreditor.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942333/; classtype:trojan-activity;sid:84805433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942334)"; flow:established,from_client; content:"GET"; http_method; content:"/kaniooo/levanter/raw/refs/heads/master/.yarn/releases/software_v1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942334/; classtype:trojan-activity;sid:84805434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942330)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/laravel-lagu-daerah-backend/main/indiscipline/laravel-lagu-daerah-backend.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942330/; classtype:trojan-activity;sid:84805430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942331)"; flow:established,from_client; content:"GET"; http_method; content:"/suelisena/spring-boot-api-rest-/master/springboot-rest-api-sample-dio/src/test/java/br/com/spring_ap_rest_boot_1.6.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942331/; classtype:trojan-activity;sid:84805431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942329)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/binance_trade_data_analysis/raw/refs/heads/main/hydrorrhachis/analysis-data-binance-trade-3.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942329/; classtype:trojan-activity;sid:84805429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942324)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinramirezgon/timeoutandsidecar/main/node_modules/fast-levenshtein/sidecar-timeoutand-1.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942324/; classtype:trojan-activity;sid:84805424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942325)"; flow:established,from_client; content:"GET"; http_method; content:"/lo-l192/aspirehub./raw/refs/heads/main/assets/images/onboarding/application-seekerism.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942325/; classtype:trojan-activity;sid:84805425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942326)"; flow:established,from_client; content:"GET"; http_method; content:"/mariosamuel/ang-exercicio20/main/src/environments/ang-exercicio-1.7-alpha.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942326/; classtype:trojan-activity;sid:84805426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942327)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/redux-udemy/main/src/store/udemy_redux_1.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942327/; classtype:trojan-activity;sid:84805427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942328)"; flow:established,from_client; content:"GET"; http_method; content:"/aksh-dash/python-assignements/main/roset/python_assignements_v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942328/; classtype:trojan-activity;sid:84805428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942323)"; flow:established,from_client; content:"GET"; http_method; content:"/jkmala666/wallpaper-engine/main/sources/wallpaper_engine_holomorphosis.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942323/; classtype:trojan-activity;sid:84805423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942321)"; flow:established,from_client; content:"GET"; http_method; content:"/prajankumar001/frontend/master/src/components/software_2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942321/; classtype:trojan-activity;sid:84805421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942322)"; flow:established,from_client; content:"GET"; http_method; content:"/senseisgs/ml-project/main/src/pipeline/project-m-v3.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942322/; classtype:trojan-activity;sid:84805422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942319)"; flow:established,from_client; content:"GET"; http_method; content:"/xerxesanoxemic375/cagecheck/main/cmd/software_v3.8-beta.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942319/; classtype:trojan-activity;sid:84805419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942320)"; flow:established,from_client; content:"GET"; http_method; content:"/gajaa-azhura/reactworksheet3/raw/refs/heads/master/src/components/reactworksheet_3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942320/; classtype:trojan-activity;sid:84805420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942317)"; flow:established,from_client; content:"GET"; http_method; content:"/sarweshkumar86/01-css-layout/main/balanorrhagia/layout-css-v2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942317/; classtype:trojan-activity;sid:84805417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942318)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/notpixel-ad3/main/pyarmor_runtime_004817/ad_notpixel_v1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942318/; classtype:trojan-activity;sid:84805418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942314)"; flow:established,from_client; content:"GET"; http_method; content:"/tetooozx/rimworld-modder-toolkit/raw/refs/heads/branch/sita/rimworld-toolkit-modder-v3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942314/; classtype:trojan-activity;sid:84805414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942315)"; flow:established,from_client; content:"GET"; http_method; content:"/lin982711/bclswl0827_v2ray-heroku/raw/refs/heads/main/unpurchased/v-bclswl-heroku-ray-1.1-beta.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942315/; classtype:trojan-activity;sid:84805415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942316)"; flow:established,from_client; content:"GET"; http_method; content:"/lucngossinga/react-la-maison-jungle/main/src/datas/react_maison_jungle_la_3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942316/; classtype:trojan-activity;sid:84805416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942312)"; flow:established,from_client; content:"GET"; http_method; content:"/ffgsusysg/astro-platform-starter/main/src/pages/blobs/platform-starter-astro-v1.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942312/; classtype:trojan-activity;sid:84805412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942313)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/-event-management-backend/main/controller/-event-management-backend-3.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942313/; classtype:trojan-activity;sid:84805413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942309)"; flow:established,from_client; content:"GET"; http_method; content:"/codedbycj/campusbuddy/main/parapraxis/software_v3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942309/; classtype:trojan-activity;sid:84805409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942310)"; flow:established,from_client; content:"GET"; http_method; content:"/hossamesam/uiecommerce/main/src/assets/shop/commerce_ie_u_v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942310/; classtype:trojan-activity;sid:84805410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942311)"; flow:established,from_client; content:"GET"; http_method; content:"/riansryn/adasi_admm/raw/refs/heads/main/app/http/middleware/admm-adasi-v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942311/; classtype:trojan-activity;sid:84805411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942303)"; flow:established,from_client; content:"GET"; http_method; content:"/santant20/pg/raw/refs/heads/main/proyecto/software-2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942303/; classtype:trojan-activity;sid:84805403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942304)"; flow:established,from_client; content:"GET"; http_method; content:"/markko17/lagdaan_lab1/main/src/main/java/com/mycompany/app/lagdaan-lab-2.4-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942304/; classtype:trojan-activity;sid:84805404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942305)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/kaizer-random-anime-universe/main/src/types/kaizer-anime-universe-random-v3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942305/; classtype:trojan-activity;sid:84805405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942306)"; flow:established,from_client; content:"GET"; http_method; content:"/arish-mhrjn/newsmonkey/main/public/monkey-news-2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942306/; classtype:trojan-activity;sid:84805406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942307)"; flow:established,from_client; content:"GET"; http_method; content:"/encapsulationraingauge334/black-hole/main/unmysticize/hole_black_v3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942307/; classtype:trojan-activity;sid:84805407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942308)"; flow:established,from_client; content:"GET"; http_method; content:"/subclassexopterygotarhd973/python-one/raw/refs/heads/main/unauthentical/python-one-1.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942308/; classtype:trojan-activity;sid:84805408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942299)"; flow:established,from_client; content:"GET"; http_method; content:"/joshualegado008/lab_exam/raw/refs/heads/main/.vscode/exam-lab-3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942299/; classtype:trojan-activity;sid:84805399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942300)"; flow:established,from_client; content:"GET"; http_method; content:"/edimich5520/vsix-finder/raw/refs/heads/main/screenshots/vsix_finder_2.6-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942300/; classtype:trojan-activity;sid:84805400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942301)"; flow:established,from_client; content:"GET"; http_method; content:"/gokulsai6543/dunco/main/src/software_1.0.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942301/; classtype:trojan-activity;sid:84805401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942302)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmayto/pneumonia-detection-app/raw/refs/heads/main/__pycache__/detection_app_pneumonia_v2.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942302/; classtype:trojan-activity;sid:84805402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942297)"; flow:established,from_client; content:"GET"; http_method; content:"/sisira430/snake/raw/refs/heads/main/semicostiferous/software-2.5-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942297/; classtype:trojan-activity;sid:84805397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942298)"; flow:established,from_client; content:"GET"; http_method; content:"/utkarshsir552/flood-escape-2-remastered-controller/branch/perflate/escape-controller-remastered-flood-2.0.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942298/; classtype:trojan-activity;sid:84805398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942296)"; flow:established,from_client; content:"GET"; http_method; content:"/vinnyamz2/izabela-cosmeticos-magic/main/supabase/migrations/cosmeticos-izabela-magic-3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942296/; classtype:trojan-activity;sid:84805396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942294)"; flow:established,from_client; content:"GET"; http_method; content:"/recchan13/e-surat/main/public/assets/plugins/echarts/e_surat_subruler.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942294/; classtype:trojan-activity;sid:84805394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942295)"; flow:established,from_client; content:"GET"; http_method; content:"/brayanob2003/recycling_collector_app/raw/refs/heads/main/ios/runner/assets.xcassets/appicon.appiconset/collector_app_recycling_3.0.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942295/; classtype:trojan-activity;sid:84805395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942292)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar052/devopsproject/raw/refs/heads/main/monitoring/elk/dev_project_ops_1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942292/; classtype:trojan-activity;sid:84805392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942293)"; flow:established,from_client; content:"GET"; http_method; content:"/kotasrinuaa/mila-shrimp-farming-app/raw/refs/heads/main/android/app/src/main/shrimp-app-mila-farming-2.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942293/; classtype:trojan-activity;sid:84805393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942291)"; flow:established,from_client; content:"GET"; http_method; content:"/owusuaduamerenorbert-oss/cloudflare-scanner/main/birddom/cloudflare_scanner_3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942291/; classtype:trojan-activity;sid:84805391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942290)"; flow:established,from_client; content:"GET"; http_method; content:"/rylen1829123/ssssssssssss/main/chromedriver/ssssssssssss-v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942290/; classtype:trojan-activity;sid:84805390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942287)"; flow:established,from_client; content:"GET"; http_method; content:"/xerthiys/driver-genius-professional-platinum-23.0.0.137/main/poltroonery/professional-platinum-genius-driver-v3.3-alpha.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942287/; classtype:trojan-activity;sid:84805387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942288)"; flow:established,from_client; content:"GET"; http_method; content:"/jonirey/jonirey/raw/refs/heads/main/pitmirk/software-1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942288/; classtype:trojan-activity;sid:84805388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942289)"; flow:established,from_client; content:"GET"; http_method; content:"/jibon247/forwardwidgets/raw/refs/heads/main/widgets/forward_widgets_holotonia.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942289/; classtype:trojan-activity;sid:84805389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942283)"; flow:established,from_client; content:"GET"; http_method; content:"/fadimvp/authcrack-v8/main/cagayan/crack-auth-v-3.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942283/; classtype:trojan-activity;sid:84805383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942284)"; flow:established,from_client; content:"GET"; http_method; content:"/harrystark01/python-mini-projects/master/projects/password_generator/mini_python_projects_precoagulation.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942284/; classtype:trojan-activity;sid:84805384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942285)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmaddabdallah/isamic-prayer/main/.vscode/isamic_prayer_v3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942285/; classtype:trojan-activity;sid:84805385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942286)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/auction-platform-backend/main/utils/auction-platform-backend-v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942286/; classtype:trojan-activity;sid:84805386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942280)"; flow:established,from_client; content:"GET"; http_method; content:"/prajankumar001/rec_client_frontend/main/src/rec-frontend-client-2.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942280/; classtype:trojan-activity;sid:84805380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942281)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-karout/dashboard-user/main/.vscode/dashboard_user_veneration.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942281/; classtype:trojan-activity;sid:84805381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942282)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjanabatheja123/-to-do-list-application-console-based-/main/couniversal/-to-do-list-application-console-based-.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942282/; classtype:trojan-activity;sid:84805382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942278)"; flow:established,from_client; content:"GET"; http_method; content:"/coordinated-toychest161/skotwind-tailwind-dashboard/main/src/assets/images/small/skotwind_dashboard_tailwind_1.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942278/; classtype:trojan-activity;sid:84805378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942279)"; flow:established,from_client; content:"GET"; http_method; content:"/cookiewoolv/bo3-unlock-suite/branch/gracileness/unlock_bo_suite_v1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942279/; classtype:trojan-activity;sid:84805379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942276)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-full-invisible-whitelist-jubileu_dasparada-by-tiodaesfiha_79813/main/eudipleural/das_a_whitelist_parada_king_by_full_tiodaesfiha_invisible_jubileu_1.7.zip"; http_uri; depth:184; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942276/; classtype:trojan-activity;sid:84805376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942277)"; flow:established,from_client; content:"GET"; http_method; content:"/johndenvercandia/candia-activity9/raw/refs/heads/main/database/factories/candia-activity-2.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942277/; classtype:trojan-activity;sid:84805377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942271)"; flow:established,from_client; content:"GET"; http_method; content:"/tatituptech/ta2-core-jobs-n-services-script/main/prerestrict/job_t_service_cor_script_v1.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942271/; classtype:trojan-activity;sid:84805371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942272)"; flow:established,from_client; content:"GET"; http_method; content:"/aathithya123/raspberrypi_pico_distance_measure/main/arachnophagous/pi_measure_raspberry_distance_pico_v1.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942272/; classtype:trojan-activity;sid:84805372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942273)"; flow:established,from_client; content:"GET"; http_method; content:"/miqman/newmkpdashboard/raw/refs/heads/main/src/pages/laporantransaksi/mkp_dashboard_new_objecthood.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942273/; classtype:trojan-activity;sid:84805373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942274)"; flow:established,from_client; content:"GET"; http_method; content:"/sacrilegem688/awesome-markdown-editors-list/main/hemihydrate/markdown_awesome_editors_list_2.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942274/; classtype:trojan-activity;sid:84805374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942275)"; flow:established,from_client; content:"GET"; http_method; content:"/hieumaster05/virustotal-file-scanner/raw/refs/heads/main/pyarmor_runtime_000000/scanner_file_total_virus_2.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942275/; classtype:trojan-activity;sid:84805375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942270)"; flow:established,from_client; content:"GET"; http_method; content:"/cyran-kyle/cycletech/raw/refs/heads/main/src/ai/flows/cycle_tech_2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942270/; classtype:trojan-activity;sid:84805370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942267)"; flow:established,from_client; content:"GET"; http_method; content:"/kaniooo/wa-ban/main/sleuthlike/wa_ban_v2.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942267/; classtype:trojan-activity;sid:84805367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942268)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/ai-chat-bot/main/project-bolt-sb1-k3fuc168/chat_bot_ai_v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942268/; classtype:trojan-activity;sid:84805368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942269)"; flow:established,from_client; content:"GET"; http_method; content:"/kobmol/tugas-front-end/raw/refs/heads/master/src/styles/front_tugas_end_v3.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942269/; classtype:trojan-activity;sid:84805369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942264)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadali832/muhammad-ali-portfolio-website/main/optate/muhammad-ali-portfolio-website.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942264/; classtype:trojan-activity;sid:84805364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942265)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-magdy-1/gsap-gta-vi/raw/refs/heads/main/public/images/vi_gt_gsa_1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942265/; classtype:trojan-activity;sid:84805365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942266)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/cryptoclustering/main/module_19/crypto-clustering-v3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942266/; classtype:trojan-activity;sid:84805366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942261)"; flow:established,from_client; content:"GET"; http_method; content:"/jamsyut/gallery-ukk-alung/raw/refs/heads/main/config/alung_galler_uk_2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942261/; classtype:trojan-activity;sid:84805361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942262)"; flow:established,from_client; content:"GET"; http_method; content:"/dedeafriandy/ddos-attack/raw/refs/heads/main/zoetropic/attack_ddos_3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942262/; classtype:trojan-activity;sid:84805362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942263)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/portofolio-react/master/interstation/portofolio-react.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942263/; classtype:trojan-activity;sid:84805363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942256)"; flow:established,from_client; content:"GET"; http_method; content:"/gansbett/only-for-tania/raw/refs/heads/main/js/tania_only_for_v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942256/; classtype:trojan-activity;sid:84805356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942257)"; flow:established,from_client; content:"GET"; http_method; content:"/psyprogrammmer/fungus-funk-portal/raw/refs/heads/main/transpolar/funk_portal_fungus_v3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942257/; classtype:trojan-activity;sid:84805357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942258)"; flow:established,from_client; content:"GET"; http_method; content:"/rinday2005/movie_ticket_app/raw/refs/heads/master/src/movie-app-ticket-v3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942258/; classtype:trojan-activity;sid:84805358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942259)"; flow:established,from_client; content:"GET"; http_method; content:"/delacruzrlkq/sadadsadas/raw/refs/heads/main/uninvaded/software-2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942259/; classtype:trojan-activity;sid:84805359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942260)"; flow:established,from_client; content:"GET"; http_method; content:"/domi23774/facebook-login-page/raw/refs/heads/main/.idea/facebook_page_login_v1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942260/; classtype:trojan-activity;sid:84805360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942254)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-flash-tp-whitelist-noobprolegal123-feito-por-tiodaesfiha_79813/raw/refs/heads/main/observational/whitelist-feito-tiodaesfiha-king-a-por-tp-noobprolegal-flash-1.5-beta.5.zip"; http_uri; depth:202; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942254/; classtype:trojan-activity;sid:84805354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942255)"; flow:established,from_client; content:"GET"; http_method; content:"/erennew/en480p/main/bot/p_en_3.5.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942255/; classtype:trojan-activity;sid:84805355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942249)"; flow:established,from_client; content:"GET"; http_method; content:"/5xso/restful-payment-gateway-api/raw/refs/heads/main/phlebectasy/api_res_tful_gateway_payment_3.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942249/; classtype:trojan-activity;sid:84805349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942250)"; flow:established,from_client; content:"GET"; http_method; content:"/foreverlilred/genuineinterface/main/src/assets/interface-genuine-v3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942250/; classtype:trojan-activity;sid:84805350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942251)"; flow:established,from_client; content:"GET"; http_method; content:"/khn0x-khn0x/faucet-frontend/raw/refs/heads/main/src/components/frontend-faucet-1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942251/; classtype:trojan-activity;sid:84805351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942252)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhdevelop/progressui/main/sources/progressui/ui_progress_v3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942252/; classtype:trojan-activity;sid:84805352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942253)"; flow:established,from_client; content:"GET"; http_method; content:"/i14maxiii/portal-judicial.chrpcm/main/server/chrpcm-judicial-portal-v1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942253/; classtype:trojan-activity;sid:84805353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942246)"; flow:established,from_client; content:"GET"; http_method; content:"/akor35th/javascript/raw/refs/heads/master/desafios/d011/software_3.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942246/; classtype:trojan-activity;sid:84805346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942247)"; flow:established,from_client; content:"GET"; http_method; content:"/chuckaballe60/aballe-sql/main/greathearted/sql_aballe_v2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942247/; classtype:trojan-activity;sid:84805347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942248)"; flow:established,from_client; content:"GET"; http_method; content:"/dedeafriandy/tri/main/germanity/software-1.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942248/; classtype:trojan-activity;sid:84805348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942243)"; flow:established,from_client; content:"GET"; http_method; content:"/eldino162/packvisual/master/thwittle/software_2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942243/; classtype:trojan-activity;sid:84805343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942244)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianastudillo/aptein-santaana/raw/refs/heads/main/.github/aptein_santa_ana_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942244/; classtype:trojan-activity;sid:84805344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942245)"; flow:established,from_client; content:"GET"; http_method; content:"/cookiewoolv/cookiewoolv/main/archpontiff/software-v1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942245/; classtype:trojan-activity;sid:84805345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942242)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/toko_online/raw/refs/heads/main/app/http/controllers/auth/online-toko-v3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942242/; classtype:trojan-activity;sid:84805342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942241)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/ejerciciosgym/main/orchichorea/ejerciciosgym.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942241/; classtype:trojan-activity;sid:84805341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942239)"; flow:established,from_client; content:"GET"; http_method; content:"/lorenzodruif/shinobi-tycoon-roblox-toolkit/branch/manneristic/shinobi_tycoon_toolkit_roblox_2.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942239/; classtype:trojan-activity;sid:84805339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942240)"; flow:established,from_client; content:"GET"; http_method; content:"/learningdisordercapital35/cve_2025_24257----not-mine/raw/refs/heads/main/immixture/no_cv_mine_v2.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942240/; classtype:trojan-activity;sid:84805340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942238)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/password-reset/main/utlis/password-reset-2.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942238/; classtype:trojan-activity;sid:84805338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942233)"; flow:established,from_client; content:"GET"; http_method; content:"/avishekinvincible/house-transformer/master/public/house-transformer-v3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942233/; classtype:trojan-activity;sid:84805333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942234)"; flow:established,from_client; content:"GET"; http_method; content:"/rykr32/discrawl/1.21/src/software-v3.5.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942234/; classtype:trojan-activity;sid:84805334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942235)"; flow:established,from_client; content:"GET"; http_method; content:"/agnet57/smart-streetlight/main/articulite/smart_streetlight_respersive.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942235/; classtype:trojan-activity;sid:84805335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942236)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmayto/crop-prediction/raw/refs/heads/main/templates/prediction-cro-3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942236/; classtype:trojan-activity;sid:84805336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942237)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/address/master/saburra/address.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942237/; classtype:trojan-activity;sid:84805337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942230)"; flow:established,from_client; content:"GET"; http_method; content:"/crisss234/poe2-arcane-advantage/branch/nonaction/poe_advantage_arcane_v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942230/; classtype:trojan-activity;sid:84805330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942231)"; flow:established,from_client; content:"GET"; http_method; content:"/th3k1ll/minimalworker/master/src/minimal_worker_v1.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942231/; classtype:trojan-activity;sid:84805331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942232)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/blogsite/main/periodide/blogsite.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942232/; classtype:trojan-activity;sid:84805332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942229)"; flow:established,from_client; content:"GET"; http_method; content:"/karan211/yguc.github.io/main/immeritous/ygu-github-io-2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942229/; classtype:trojan-activity;sid:84805329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942216)"; flow:established,from_client; content:"GET"; http_method; content:"/fpeople4646/mindful-modern-living/raw/refs/heads/main/nahuan/mindful-modern-living.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942216/; classtype:trojan-activity;sid:84805316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942217)"; flow:established,from_client; content:"GET"; http_method; content:"/lenardclimatical374/mt5-volume-profile-indicator/raw/refs/heads/main/volumeprofile/obj/volume-profile-indicator-m-ulster.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942217/; classtype:trojan-activity;sid:84805317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942218)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/crypto-flower/raw/refs/heads/main/.github/issue_template/flower-crypt-3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942218/; classtype:trojan-activity;sid:84805318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942219)"; flow:established,from_client; content:"GET"; http_method; content:"/latestplayz/awesome-persona-skills/raw/refs/heads/main/woozle/persona_awesome_skills_1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942219/; classtype:trojan-activity;sid:84805319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942220)"; flow:established,from_client; content:"GET"; http_method; content:"/adesh777/adesh777.github.io/main/oarage/io-adesh-github-v3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942220/; classtype:trojan-activity;sid:84805320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942221)"; flow:established,from_client; content:"GET"; http_method; content:"/aathithya123/llama2-powered-rag-retrieval-augmented-generation-chatbot/raw/refs/heads/main/cat/chatbot-generation-augmented-ra-retrieval-powered-llama-iridal.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942221/; classtype:trojan-activity;sid:84805321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942222)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisjustice600/auroraschool/raw/refs/heads/main/src/_components/software_2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942222/; classtype:trojan-activity;sid:84805322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942223)"; flow:established,from_client; content:"GET"; http_method; content:"/sam3166/tiktok-bot/raw/refs/heads/main/datil/bot_tiktok_hemisphere.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942223/; classtype:trojan-activity;sid:84805323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942224)"; flow:established,from_client; content:"GET"; http_method; content:"/janaahmedfahmy/sister-monochrome-fantasy-mod-gem-atelier/raw/refs/heads/branch/panhellenium/sister_gem_mod_atelier_fantasy_monochrome_v3.4.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942224/; classtype:trojan-activity;sid:84805324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942225)"; flow:established,from_client; content:"GET"; http_method; content:"/serbian-groundwork422/printfit/raw/refs/heads/main/src/print-fit-litopterna.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942225/; classtype:trojan-activity;sid:84805325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942226)"; flow:established,from_client; content:"GET"; http_method; content:"/tazic123/bakery-place-roblox-essentials/raw/refs/heads/branch/electrodynamic/bakery-roblox-place-essentials-2.7.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942226/; classtype:trojan-activity;sid:84805326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942227)"; flow:established,from_client; content:"GET"; http_method; content:"/izodiaco/container-tzhlw7u/raw/refs/heads/main/src/container_u_tzhlw_v2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942227/; classtype:trojan-activity;sid:84805327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942228)"; flow:established,from_client; content:"GET"; http_method; content:"/nm993398/maqro/main/app/api/billing/webhook/software_3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942228/; classtype:trojan-activity;sid:84805328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942209)"; flow:established,from_client; content:"GET"; http_method; content:"/lebomeje/monty/raw/refs/heads/master/bf/software_2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942209/; classtype:trojan-activity;sid:84805309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942210)"; flow:established,from_client; content:"GET"; http_method; content:"/irdk1242s/corelcad-mac-resource-hub/raw/refs/heads/main/entepicondylar/resource-mac-hub-corelcad-v2.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942210/; classtype:trojan-activity;sid:84805310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942211)"; flow:established,from_client; content:"GET"; http_method; content:"/kanak-debug/calculate-me/raw/refs/heads/main/dyotheism/me-calculate-3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942211/; classtype:trojan-activity;sid:84805311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942212)"; flow:established,from_client; content:"GET"; http_method; content:"/blinkwilly/dbank-app/master/src/dbank_backend/dbank-app-3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942212/; classtype:trojan-activity;sid:84805312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942213)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/bajista-app/main/tropical/bajista-app.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942213/; classtype:trojan-activity;sid:84805313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942214)"; flow:established,from_client; content:"GET"; http_method; content:"/yash-9-9-5/pdf-conversion-project/raw/refs/heads/main/static/pdf_conversion_project_1.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942214/; classtype:trojan-activity;sid:84805314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942215)"; flow:established,from_client; content:"GET"; http_method; content:"/jakariyaox-dot/ict-olympiad-s1/raw/refs/heads/main/services/ic-olympia-v1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942215/; classtype:trojan-activity;sid:84805315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942203)"; flow:established,from_client; content:"GET"; http_method; content:"/godofstrategy/temperature-converter/main/nabobishly/converter-temperature-1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942203/; classtype:trojan-activity;sid:84805303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942204)"; flow:established,from_client; content:"GET"; http_method; content:"/ronaldodjj/bsc-sandwich-bot/raw/refs/heads/main/contracts/test/utils/bot_bs_sandwich_1.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942204/; classtype:trojan-activity;sid:84805304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942205)"; flow:established,from_client; content:"GET"; http_method; content:"/duyettrautre/wsl/raw/refs/heads/master/src/windows/service/stub/software-3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942205/; classtype:trojan-activity;sid:84805305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942206)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjay17122002/fort-polio/raw/refs/heads/main/src/common/fort-polio-v3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942206/; classtype:trojan-activity;sid:84805306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942207)"; flow:established,from_client; content:"GET"; http_method; content:"/paulomiguelvidal/lojafake/raw/refs/heads/main/src/components/loja-fake-3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942207/; classtype:trojan-activity;sid:84805307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942208)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/full-stack-notes-app/raw/refs/heads/main/note_app/src/assets/full_stack_notes_app_1.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942208/; classtype:trojan-activity;sid:84805308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942200)"; flow:established,from_client; content:"GET"; http_method; content:"/lemurhacep/sla-cheeto/main/injector/src/sl_cheeto_v2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942200/; classtype:trojan-activity;sid:84805300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942201)"; flow:established,from_client; content:"GET"; http_method; content:"/mihirlathigara012/ai-chatbot/main/backend/chatbot-a-tufthunter.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942201/; classtype:trojan-activity;sid:84805301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942202)"; flow:established,from_client; content:"GET"; http_method; content:"/rainesalvo/fivem-genel-yonetim-v13/raw/refs/heads/main/config/genel-fivem-yonetim-v3.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942202/; classtype:trojan-activity;sid:84805302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942199)"; flow:established,from_client; content:"GET"; http_method; content:"/holecardvoltampere165/telefeed/raw/refs/heads/main/hydroxyacetic/tele-feed-2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942199/; classtype:trojan-activity;sid:84805299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942196)"; flow:established,from_client; content:"GET"; http_method; content:"/kaito1999-script/cardealersim-freeedition/main/anthratriol/sim_edition_dealer_car_free_2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942196/; classtype:trojan-activity;sid:84805296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942197)"; flow:established,from_client; content:"GET"; http_method; content:"/theualves/lojaroupa-sql/main/img/lojaroupa-sql_2.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942197/; classtype:trojan-activity;sid:84805297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942198)"; flow:established,from_client; content:"GET"; http_method; content:"/khn0x-khn0x/synthra-info/main/src/constants/abis/info-synthra-1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942198/; classtype:trojan-activity;sid:84805298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942187)"; flow:established,from_client; content:"GET"; http_method; content:"/keith986/simple-logistics-react-website/raw/refs/heads/main/src/react_simple_website_logistics_resail.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942187/; classtype:trojan-activity;sid:84805287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942188)"; flow:established,from_client; content:"GET"; http_method; content:"/gustafoutrigged242/mongodb-nosql-airbnb/raw/refs/heads/main/business_intelligence/scripts/mongodb_nosql_airbnb_1.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942188/; classtype:trojan-activity;sid:84805288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942189)"; flow:established,from_client; content:"GET"; http_method; content:"/emmanue9881/mass-ads-app-ads-checker/raw/refs/heads/main/icons/ads-app-mass-checker-v2.8-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942189/; classtype:trojan-activity;sid:84805289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942190)"; flow:established,from_client; content:"GET"; http_method; content:"/tatituptech/qb-fllight/main/mirabilite/1.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942190/; classtype:trojan-activity;sid:84805290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942191)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/azureml-automl/main/sdk/python/responsible-ai/tabular/responsibleaidashboard-diabetes-decision-making/data-diabetes-regression/azureml-automl-1.9-alpha.3.zip"; http_uri; depth:170; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942191/; classtype:trojan-activity;sid:84805291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942192)"; flow:established,from_client; content:"GET"; http_method; content:"/seamountseneciodoublasii661/beeper-matrix-proxy/raw/refs/heads/main/scripts/proxy-beeper-matrix-v3.2-alpha.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942192/; classtype:trojan-activity;sid:84805292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942193)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik359/iplproject/main/src/assets/ipl_project_1.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942193/; classtype:trojan-activity;sid:84805293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942194)"; flow:established,from_client; content:"GET"; http_method; content:"/sookongi/dousql/raw/refs/heads/main/src/main/java/burp/api/montoya/scope/dou_sql_v2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942194/; classtype:trojan-activity;sid:84805294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942195)"; flow:established,from_client; content:"GET"; http_method; content:"/zlostyzzzz/openstack-ft-demo/raw/refs/heads/master/modules/network/ft-openstack-demo-1.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942195/; classtype:trojan-activity;sid:84805295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942184)"; flow:established,from_client; content:"GET"; http_method; content:"/trieuduy27051999/quiz-games/raw/refs/heads/main/ios/runnertests/quiz_games_1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942184/; classtype:trojan-activity;sid:84805284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942185)"; flow:established,from_client; content:"GET"; http_method; content:"/jerusalemthornviscountess959/8enterprise-public/raw/refs/heads/main/other/enterprise_public_v3.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942185/; classtype:trojan-activity;sid:84805285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942186)"; flow:established,from_client; content:"GET"; http_method; content:"/andres1163/hisaab/raw/refs/heads/main/lib/analytics/software_v1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942186/; classtype:trojan-activity;sid:84805286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942183)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/ds_module_5/raw/refs/heads/main/pymaceuticals/data/ds_module_v1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942183/; classtype:trojan-activity;sid:84805283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942182)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-magdy-1/strapi_my_profile_v2/raw/refs/heads/main/src/api/project/routes/strapi_profile_my_1.0-alpha.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942182/; classtype:trojan-activity;sid:84805282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942181)"; flow:established,from_client; content:"GET"; http_method; content:"/iorminanonlegal213/agente-monitoramento-carteirinhas/main/frontend/src/app/importacao/carteirinhas_monitoramento_agente_cleveite.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942181/; classtype:trojan-activity;sid:84805281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942180)"; flow:established,from_client; content:"GET"; http_method; content:"/anujtheking9/r-shiny-dice-roller-app/raw/refs/heads/master/docs/dice_roller_shiny_r_app_3.4-beta.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942180/; classtype:trojan-activity;sid:84805280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942179)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/laravel-cbt-tpa-backend/master/macehead/laravel-cbt-tpa-backend.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942179/; classtype:trojan-activity;sid:84805279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942178)"; flow:established,from_client; content:"GET"; http_method; content:"/robindenticulate222/fastforge/main/backend/fastforge_core/software_aptyalia.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942178/; classtype:trojan-activity;sid:84805278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942177)"; flow:established,from_client; content:"GET"; http_method; content:"/norrielisted782/free-games-claimer-automation/main/test/claimer_free_games_automation_2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942177/; classtype:trojan-activity;sid:84805277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942175)"; flow:established,from_client; content:"GET"; http_method; content:"/tarique775/express-rest-api/raw/refs/heads/main/api/controller/api-res-express-corbeling.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942175/; classtype:trojan-activity;sid:84805275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942176)"; flow:established,from_client; content:"GET"; http_method; content:"/genusamblyrhynchusbrunooftoul602/dsh-attachment-formats/main/lib/py/v1.0-alpha.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942176/; classtype:trojan-activity;sid:84805276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942168)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/moodmate/main/strey/moodmate_v1.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942168/; classtype:trojan-activity;sid:84805268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942169)"; flow:established,from_client; content:"GET"; http_method; content:"/ertiprenci/teamora/raw/refs/heads/main/vendor/filament/tables/resources/lang/no/software_cottager.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942169/; classtype:trojan-activity;sid:84805269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942170)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_5/raw/refs/heads/main/slided/project-ai-2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942170/; classtype:trojan-activity;sid:84805270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942171)"; flow:established,from_client; content:"GET"; http_method; content:"/joshunspeakable173/reviewer/raw/refs/heads/main/outputs/software_v2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942171/; classtype:trojan-activity;sid:84805271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942172)"; flow:established,from_client; content:"GET"; http_method; content:"/gwenorabespoken424/cborndockflow/raw/refs/heads/main/cborn_docflow/software-3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942172/; classtype:trojan-activity;sid:84805272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942173)"; flow:established,from_client; content:"GET"; http_method; content:"/m-joseph27/clone_libraray/raw/refs/heads/master/src/router/clone-libraray-3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942173/; classtype:trojan-activity;sid:84805273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942174)"; flow:established,from_client; content:"GET"; http_method; content:"/khn0x-khn0x/nexus-cli/raw/refs/heads/main/clients/cli/examples/src/nexus-cli-3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942174/; classtype:trojan-activity;sid:84805274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942163)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/sistem_pendataan_sekolah/raw/refs/heads/main/public/sistem_pendataan_sekolah_v1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942163/; classtype:trojan-activity;sid:84805263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942164)"; flow:established,from_client; content:"GET"; http_method; content:"/henriksidelong63/7-days-to-die-trainer/main/7-days-to-die-trainer/src/test/java/com/sevendaystodie/die-trainer-days-to-1.5.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942164/; classtype:trojan-activity;sid:84805264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942165)"; flow:established,from_client; content:"GET"; http_method; content:"/ioanadelirious841/scail-auto-extend/main/web/scail-auto-extend-v3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942165/; classtype:trojan-activity;sid:84805265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942166)"; flow:established,from_client; content:"GET"; http_method; content:"/lyrothanak20/my-portfolio/raw/refs/heads/main/src/components/portfolio-my-v2.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942166/; classtype:trojan-activity;sid:84805266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942167)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/gpcv-backend/main/middlewares/gpcv-backend-1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942167/; classtype:trojan-activity;sid:84805267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942158)"; flow:established,from_client; content:"GET"; http_method; content:"/sandipjadhav7698/my-project/portfolio/node_modules/nanoid/my-project-v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942158/; classtype:trojan-activity;sid:84805258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942159)"; flow:established,from_client; content:"GET"; http_method; content:"/huyhuy091/hoa-hoc/raw/refs/heads/main/jower/hoc-hoa-v3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942159/; classtype:trojan-activity;sid:84805259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942160)"; flow:established,from_client; content:"GET"; http_method; content:"/jaclynsaline206/manifold/main/philematology/software_appropinquity.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942160/; classtype:trojan-activity;sid:84805260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942161)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianaguirre10/customswitch/raw/refs/heads/master/example/ios/runner.xcodeproj/custom_switch_1.8-alpha.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942161/; classtype:trojan-activity;sid:84805261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942162)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/filtering_data_t1/main/src/app/api/filtering-t-data-diaphysial.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942162/; classtype:trojan-activity;sid:84805262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942152)"; flow:established,from_client; content:"GET"; http_method; content:"/marydao21/2048-game/raw/refs/heads/main/build/resources/game-v1.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942152/; classtype:trojan-activity;sid:84805252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942153)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/ajax-task/raw/refs/heads/main/storage/app/ajax-task-3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942153/; classtype:trojan-activity;sid:84805253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942154)"; flow:established,from_client; content:"GET"; http_method; content:"/m2msupport/raspberrypi-signal-meter/master/diadelphic/raspberrypi-signal-meter_v1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942154/; classtype:trojan-activity;sid:84805254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942155)"; flow:established,from_client; content:"GET"; http_method; content:"/mame-1213/car-rental-system-django/raw/refs/heads/master/customer_portal/django_car_rental_system_1.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942155/; classtype:trojan-activity;sid:84805255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942156)"; flow:established,from_client; content:"GET"; http_method; content:"/reactflowbrasil-lgtm/centurial-studio/main/public/centurial-studio-2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942156/; classtype:trojan-activity;sid:84805256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942157)"; flow:established,from_client; content:"GET"; http_method; content:"/barrylecherous932/eurostat-mcp-server/raw/refs/heads/main/changelog/eurostat-server-mcp-mannishness.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942157/; classtype:trojan-activity;sid:84805257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942147)"; flow:established,from_client; content:"GET"; http_method; content:"/nishanthgsuryavamshi/face-and-eye-detection-using-haarcasacde/raw/refs/heads/main/haarcascades/and_using_detection_haarcasacde_eye_face_v1.5.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942147/; classtype:trojan-activity;sid:84805247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942148)"; flow:established,from_client; content:"GET"; http_method; content:"/iskerol/llm-hallucination-detector/raw/refs/heads/main/data/detector_llm_hallucination_1.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942148/; classtype:trojan-activity;sid:84805248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942149)"; flow:established,from_client; content:"GET"; http_method; content:"/creaky-gaspar847/coolboard/raw/refs/heads/main/sources/coolboard/views/cool_board_3.6-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942149/; classtype:trojan-activity;sid:84805249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942150)"; flow:established,from_client; content:"GET"; http_method; content:"/ifanifan791/toko-online-ci4/raw/refs/heads/main/app/helpers/c-online-toko-v3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942150/; classtype:trojan-activity;sid:84805250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942151)"; flow:established,from_client; content:"GET"; http_method; content:"/parentwavemechanics578/ai-photo-background-remover/raw/refs/heads/main/oncography/a_background_photo_remover_3.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942151/; classtype:trojan-activity;sid:84805251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942142)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/15-proyecto-carrito/raw/refs/heads/main/js/proyect_carrito_v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942142/; classtype:trojan-activity;sid:84805242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942143)"; flow:established,from_client; content:"GET"; http_method; content:"/constancywoodsy286/agentic-rag-for-practice/raw/refs/heads/main/project/rag_agent/agentic-for-practice-rag-electrolytic.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942143/; classtype:trojan-activity;sid:84805243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942144)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/prahita/master/macrology/prahita.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942144/; classtype:trojan-activity;sid:84805244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942145)"; flow:established,from_client; content:"GET"; http_method; content:"/adductbenefitofclergy918/smart-home-button/main/components/sendspin/text_sensor/home-button-smart-v3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942145/; classtype:trojan-activity;sid:84805245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942146)"; flow:established,from_client; content:"GET"; http_method; content:"/imadosan/worldwise/main/src/wise_world_1.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942146/; classtype:trojan-activity;sid:84805246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942140)"; flow:established,from_client; content:"GET"; http_method; content:"/sound-humulusjaponicus635/open-webui-local-2026/raw/refs/heads/main/titularity/local-open-webui-2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942140/; classtype:trojan-activity;sid:84805240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942141)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/jobme-client/raw/refs/heads/main/src/components/homecomponents/client-jobme-3.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942141/; classtype:trojan-activity;sid:84805241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942139)"; flow:established,from_client; content:"GET"; http_method; content:"/salman3757/codestar-framework-examples/main/friendlike/framework_examples_codestar_v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942139/; classtype:trojan-activity;sid:84805239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942137)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/gettingfirstnamefunction/raw/refs/heads/main/country/state/getting-function-name-first-2.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942137/; classtype:trojan-activity;sid:84805237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942138)"; flow:established,from_client; content:"GET"; http_method; content:"/syedabdullahuddin/syedabdullahuddin/raw/refs/heads/main/semiprotectorate/software-v3.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942138/; classtype:trojan-activity;sid:84805238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942135)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairsolanki/my_projects/main/roomful/my_projects.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942135/; classtype:trojan-activity;sid:84805235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942136)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/human_vs_horse_prediction_with_dl/main/liquidize/human-dl-horse-vs-with-prediction-v3.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942136/; classtype:trojan-activity;sid:84805236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942133)"; flow:established,from_client; content:"GET"; http_method; content:"/joseontiveros/pilis-mod3-ontiveros/raw/refs/heads/main/src/routes/login/mod-ontiveros-pilis-1.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942133/; classtype:trojan-activity;sid:84805233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942134)"; flow:established,from_client; content:"GET"; http_method; content:"/shironekoe/register_dart/main/web/register_dart_3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942134/; classtype:trojan-activity;sid:84805234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942132)"; flow:established,from_client; content:"GET"; http_method; content:"/niku3325singh/ukrainian-stats-mcp-server/raw/refs/heads/develop/src/assets/server_mcp_stats_ukrainian_3.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942132/; classtype:trojan-activity;sid:84805232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942127)"; flow:established,from_client; content:"GET"; http_method; content:"/aqilaapril4330/hermes-agent-desktop/main/src/renderer/src/screens/soul/desktop_hermes_agent_suffocation.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942127/; classtype:trojan-activity;sid:84805227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942128)"; flow:established,from_client; content:"GET"; http_method; content:"/fqpf-c/skillbenchwebapp/main/src/assets/icons/bench_webapp_skill_v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942128/; classtype:trojan-activity;sid:84805228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942129)"; flow:established,from_client; content:"GET"; http_method; content:"/jefffergunson118-beep/smara/raw/refs/heads/main/assets/software-3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942129/; classtype:trojan-activity;sid:84805229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942130)"; flow:established,from_client; content:"GET"; http_method; content:"/runningpostmanibeam943/gradio-streamlit-ai-demos/main/heartwood/demos-streamlit-ai-gradio-3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942130/; classtype:trojan-activity;sid:84805230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942131)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/editflow_frontend/main/src/assets/editflow_frontend-v1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942131/; classtype:trojan-activity;sid:84805231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942117)"; flow:established,from_client; content:"GET"; http_method; content:"/seinditzz/pembuatan-domain.github.io/main/hypnologic/pembuatan-io-domain-github-v1.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942117/; classtype:trojan-activity;sid:84805217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942118)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.111.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942118/; classtype:trojan-activity;sid:84805218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942119)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/rabbanictgbd/raw/refs/heads/main/images/software_v3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942119/; classtype:trojan-activity;sid:84805219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942120)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/educational_website/master/src/components/navbar/website-educational-3.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942120/; classtype:trojan-activity;sid:84805220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942121)"; flow:established,from_client; content:"GET"; http_method; content:"/hermitcrablewisiacotyledon3164/uac-bypass-fud/raw/refs/heads/main/uacbypass/my/resources/ua_bypass_fud_cacoepist.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942121/; classtype:trojan-activity;sid:84805221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942122)"; flow:established,from_client; content:"GET"; http_method; content:"/lilianecomposed370/python-sdk/raw/refs/heads/main/src/python-sdk-2.6-alpha.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942122/; classtype:trojan-activity;sid:84805222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942123)"; flow:established,from_client; content:"GET"; http_method; content:"/guruexpl8276/llm_inference_lab/raw/refs/heads/main/docs/lab_inference_ll_v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942123/; classtype:trojan-activity;sid:84805223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942124)"; flow:established,from_client; content:"GET"; http_method; content:"/mariosamuel/-projeanuglar/raw/refs/heads/main/src/assets/img/proje_anuglar_v2.3-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942124/; classtype:trojan-activity;sid:84805224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942125)"; flow:established,from_client; content:"GET"; http_method; content:"/muhamadsafii-21/kasir/raw/refs/heads/main/tests/feature/kasir-2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942125/; classtype:trojan-activity;sid:84805225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942126)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/shopee_app_clone/raw/refs/heads/main/app/shopee-clone-app-2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942126/; classtype:trojan-activity;sid:84805226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942109)"; flow:established,from_client; content:"GET"; http_method; content:"/yaumilikrom/a-tale-of-one-city-v3-enhanced-patch/raw/refs/heads/branch/orthography/one_a_patch_of_v_tale_city_enhanced_1.8.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942109/; classtype:trojan-activity;sid:84805209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942110)"; flow:established,from_client; content:"GET"; http_method; content:"/seraphic-disagreement4030/claude-voice/raw/refs/heads/main/tarsioid/claude_voice_sunken.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942110/; classtype:trojan-activity;sid:84805210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942111)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/chatuz_app/master/macos/runner.xcodeproj/project.xcworkspace/xcshareddata/app_chatuz_managerdom.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942111/; classtype:trojan-activity;sid:84805211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942112)"; flow:established,from_client; content:"GET"; http_method; content:"/phamdo627/ai-detection-bypass-gptzero-turnitin/raw/refs/heads/main/tonsilitic/gptzero_bypass_turnitin_detection_ai_v3.4-beta.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942112/; classtype:trojan-activity;sid:84805212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942113)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/printf/master/test_files/printf-2.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942113/; classtype:trojan-activity;sid:84805213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942114)"; flow:established,from_client; content:"GET"; http_method; content:"/dupa110/ravenco/raw/refs/heads/live/web/co_raven_3.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942114/; classtype:trojan-activity;sid:84805214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942115)"; flow:established,from_client; content:"GET"; http_method; content:"/pqv611/zeroeddayz-aimbotsuite/raw/refs/heads/main/protectoral/aimbot_zeroed_suite_day_v1.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942115/; classtype:trojan-activity;sid:84805215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942116)"; flow:established,from_client; content:"GET"; http_method; content:"/nejomeme/ts-ddd-template/raw/refs/heads/main/tests/contexts/mooc/template_ts_ddd_1.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942116/; classtype:trojan-activity;sid:84805216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942103)"; flow:established,from_client; content:"GET"; http_method; content:"/imadosan/nft-preview-card-component/main/images/component-card-nft-preview-1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942103/; classtype:trojan-activity;sid:84805203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942104)"; flow:established,from_client; content:"GET"; http_method; content:"/gangulyhub/candidate-application-platform/raw/refs/heads/master/public/candidate-application-platform-2.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942104/; classtype:trojan-activity;sid:84805204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942105)"; flow:established,from_client; content:"GET"; http_method; content:"/kamal266me/sentinel/raw/refs/heads/main/cmd/predictor/software_v3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942105/; classtype:trojan-activity;sid:84805205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942106)"; flow:established,from_client; content:"GET"; http_method; content:"/carltonromansh946/davinci-llm/raw/refs/heads/main/fig/vinci-da-llm-v3.1-alpha.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942106/; classtype:trojan-activity;sid:84805206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942107)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/rabbani-portfolio-2/main/src/3.4-beta.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942107/; classtype:trojan-activity;sid:84805207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942108)"; flow:established,from_client; content:"GET"; http_method; content:"/wakeless-artemisia25/dota2-performance-predictor/main/workflows/dota_performance_predictor_v3.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942108/; classtype:trojan-activity;sid:84805208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942100)"; flow:established,from_client; content:"GET"; http_method; content:"/ddd97336/aomei-partition-assistant-setup/raw/refs/heads/main/anthropopsychic/partition_assistant_aome_setup_2.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942100/; classtype:trojan-activity;sid:84805200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942101)"; flow:established,from_client; content:"GET"; http_method; content:"/sarajanenaming545/sarajanenaming545.github.io/main/assets/app_gaonate.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942101/; classtype:trojan-activity;sid:84805201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942102)"; flow:established,from_client; content:"GET"; http_method; content:"/noncommissioned-reformation342/automegakernel/raw/refs/heads/main/docs/auto_mega_kernel_1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942102/; classtype:trojan-activity;sid:84805202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942099)"; flow:established,from_client; content:"GET"; http_method; content:"/n3therlands/katana-blade-master-roblox-toolset/branch/pretext/katana-blade-master-roblox-toolset-3.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942099/; classtype:trojan-activity;sid:84805199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942097)"; flow:established,from_client; content:"GET"; http_method; content:"/novabiriseg/painel-seguros/main/.streamlit/painel-seguros-v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942097/; classtype:trojan-activity;sid:84805197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942098)"; flow:established,from_client; content:"GET"; http_method; content:"/erickduraes/erickduraes/main/homage/erickduraes.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942098/; classtype:trojan-activity;sid:84805198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942096)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikay7124/stop-watch/main/hemospastic/stop_watch_v2.7-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942096/; classtype:trojan-activity;sid:84805196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942095)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/music-streaming-app-backend/main/controller/music-streaming-app-backend-v3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942095/; classtype:trojan-activity;sid:84805195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942094)"; flow:established,from_client; content:"GET"; http_method; content:"/unconfirmed-darky804/xposter/raw/refs/heads/main/scripts/software_v2.6-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942094/; classtype:trojan-activity;sid:84805194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942093)"; flow:established,from_client; content:"GET"; http_method; content:"/goatuchia/astral/raw/refs/heads/main/src/shared/tral-as-v2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942093/; classtype:trojan-activity;sid:84805193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942088)"; flow:established,from_client; content:"GET"; http_method; content:"/waydemandforidentification573/arabic-pii-py/raw/refs/heads/main/tests/eval/real_bulk/arabic-py-pii-1.3-alpha.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942088/; classtype:trojan-activity;sid:84805188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942089)"; flow:established,from_client; content:"GET"; http_method; content:"/ionic-slavicpeople725/mlclassification/raw/refs/heads/main/sample_data/software-v2.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942089/; classtype:trojan-activity;sid:84805189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942090)"; flow:established,from_client; content:"GET"; http_method; content:"/out-treatyofversailles910/grounded-research/raw/refs/heads/main/references/grounded_research_v2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942090/; classtype:trojan-activity;sid:84805190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942091)"; flow:established,from_client; content:"GET"; http_method; content:"/godlinessgenusbrassavola663/antiox/raw/refs/heads/main/src/collections/software_v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942091/; classtype:trojan-activity;sid:84805191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942092)"; flow:established,from_client; content:"GET"; http_method; content:"/advectioncontinentalshelf225/image-paster/raw/refs/heads/main/obambulate/paster_image_v2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942092/; classtype:trojan-activity;sid:84805192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942084)"; flow:established,from_client; content:"GET"; http_method; content:"/naveenkm007/automated-resume-relevance-check-system/raw/refs/heads/main/api/__pycache__/system-relevance-check-resume-automated-v2.2.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942084/; classtype:trojan-activity;sid:84805184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942085)"; flow:established,from_client; content:"GET"; http_method; content:"/giffiepenurious252/agent-launch-scripts/raw/refs/heads/main/atrocha/scripts_agent_launch_benzotetrazine.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942085/; classtype:trojan-activity;sid:84805185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942086)"; flow:established,from_client; content:"GET"; http_method; content:"/sizzling-corpuschristi661/game/main/js/software_2.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942086/; classtype:trojan-activity;sid:84805186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942087)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/pandas-challenge/main/pycityschools/resources/pandas-challenge-v3.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942087/; classtype:trojan-activity;sid:84805187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942078)"; flow:established,from_client; content:"GET"; http_method; content:"/allyez4269/trilli/main/trilli-cmx/interface/src/contexts/3.8-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942078/; classtype:trojan-activity;sid:84805178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942079)"; flow:established,from_client; content:"GET"; http_method; content:"/elfed2059/deskive/raw/refs/heads/main/matzo/software_unfried.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942079/; classtype:trojan-activity;sid:84805179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942080)"; flow:established,from_client; content:"GET"; http_method; content:"/hettieunacquisitive388/ai-chat-sdk/raw/refs/heads/main/src/ui/sources-panel/ai-sdk-chat-stable.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942080/; classtype:trojan-activity;sid:84805180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942081)"; flow:established,from_client; content:"GET"; http_method; content:"/sheyitrig/login-/master/ios/runner.xcodeproj/xcshareddata/xcschemes/login_1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942081/; classtype:trojan-activity;sid:84805181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942082)"; flow:established,from_client; content:"GET"; http_method; content:"/dhinesh1817/lust-goddess-florence-mascot-express/raw/refs/heads/branch/endosclerite/lust-mascot-express-goddess-florence-v2.7.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942082/; classtype:trojan-activity;sid:84805182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942083)"; flow:established,from_client; content:"GET"; http_method; content:"/akhila4564/007-first-light-thailocalization/raw/refs/heads/main/src/thailocalization-light-first-v2.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942083/; classtype:trojan-activity;sid:84805183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942073)"; flow:established,from_client; content:"GET"; http_method; content:"/powerful-cabbagebutterfly911/api-sentinel-downloads/raw/refs/heads/main/docs/screenshots/api-downloads-sentinel-1.0.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942073/; classtype:trojan-activity;sid:84805173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942074)"; flow:established,from_client; content:"GET"; http_method; content:"/specialeducationnabob584/ppppp/raw/refs/heads/main/bassalia/software_v2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942074/; classtype:trojan-activity;sid:84805174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942075)"; flow:established,from_client; content:"GET"; http_method; content:"/samoracletus/abomq-client/raw/refs/heads/main/src/pages/client_abomq_v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942075/; classtype:trojan-activity;sid:84805175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942076)"; flow:established,from_client; content:"GET"; http_method; content:"/ruturajbhaskarnawale/rehabilation_project/raw/refs/heads/main/excercises/arm_raise/rehabilation-project-2.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942076/; classtype:trojan-activity;sid:84805176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942077)"; flow:established,from_client; content:"GET"; http_method; content:"/jalancantini/geoleadscraper/raw/refs/heads/main/incondensable/software-v3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942077/; classtype:trojan-activity;sid:84805177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942069)"; flow:established,from_client; content:"GET"; http_method; content:"/rohankumar011/rohankumar011/raw/refs/heads/main/echolalia/rohankumar-3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942069/; classtype:trojan-activity;sid:84805169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942070)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/ford-clone/main/public/clone-ford-v3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942070/; classtype:trojan-activity;sid:84805170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942071)"; flow:established,from_client; content:"GET"; http_method; content:"/ravichatta/manga/main/models/software_2.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942071/; classtype:trojan-activity;sid:84805171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942072)"; flow:established,from_client; content:"GET"; http_method; content:"/corabellanonextant92/goodboy-framework/raw/refs/heads/main/stage-01-basic-loader/framework-goodboy-3.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942072/; classtype:trojan-activity;sid:84805172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942064)"; flow:established,from_client; content:"GET"; http_method; content:"/youssef20004/osama-abdelrahim-lawyer-site-19928239ea43b6ba41af013a66f4b2690347e7a0/main/src/lib/ea_lawyer_osama_e_af_abdelrahim_site_f_ba_b_a_v3.6.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942064/; classtype:trojan-activity;sid:84805164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942065)"; flow:established,from_client; content:"GET"; http_method; content:"/vicleyva/shoppingcartdemo/master/public/imgs/cart-shopping-demo-2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942065/; classtype:trojan-activity;sid:84805165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942066)"; flow:established,from_client; content:"GET"; http_method; content:"/ardellashuddery616/modularity/raw/refs/heads/main/skills/document/software-filoselle.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942066/; classtype:trojan-activity;sid:84805166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942067)"; flow:established,from_client; content:"GET"; http_method; content:"/sohaibmos/da3ua/raw/refs/heads/main/next.js/.next/static/chunks/ua-da-ectosphenoid.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942067/; classtype:trojan-activity;sid:84805167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942068)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-bot-dev/filterfox/raw/refs/heads/main/templates/software_2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942068/; classtype:trojan-activity;sid:84805168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942061)"; flow:established,from_client; content:"GET"; http_method; content:"/vinnyamz2/mae-mais-forte/raw/refs/heads/main/src/components/forte_mae_mais_2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942061/; classtype:trojan-activity;sid:84805161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942062)"; flow:established,from_client; content:"GET"; http_method; content:"/johanbad524/gitlab-actions/raw/refs/heads/main/_locales/actions_gitlab_v3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942062/; classtype:trojan-activity;sid:84805162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942063)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdani/bluecube/main/templates/mutable/bluecube_v2.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942063/; classtype:trojan-activity;sid:84805163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942057)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/diabetes-prediction/main/rationality/prediction_diabetes_v2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942057/; classtype:trojan-activity;sid:84805157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942058)"; flow:established,from_client; content:"GET"; http_method; content:"/shobfrank28/cs2wallhackelite/releases/download/main/ziparchive.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942058/; classtype:trojan-activity;sid:84805158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942059)"; flow:established,from_client; content:"GET"; http_method; content:"/eshanak-dev/my-portfolio/raw/refs/heads/main/src/lib/my-portfolio-2.0-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942059/; classtype:trojan-activity;sid:84805159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942060)"; flow:established,from_client; content:"GET"; http_method; content:"/monopolyboymeaze/remix-project/raw/refs/heads/master/libs/remix-ui/run-tab/src/lib/types/project-remix-3.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942060/; classtype:trojan-activity;sid:84805160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942056)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/19831288/crack.nurik.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942056/; classtype:trojan-activity;sid:84805156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942055)"; flow:established,from_client; content:"GET"; http_method; content:"/madhurgoel2116/2048/main/style/software_v2.9-beta.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942055/; classtype:trojan-activity;sid:84805155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942054)"; flow:established,from_client; content:"GET"; http_method; content:"/xods-id/postmortem/raw/refs/heads/master/img/software_unliberated.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942054/; classtype:trojan-activity;sid:84805154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942051)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/vue-test-reaction-timer/raw/refs/heads/main/public/timer_reaction_test_vue_1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942051/; classtype:trojan-activity;sid:84805151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942052)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-full-gui-whitelist-dark_fogo8-by-tiodaesfiha_79813/main/unaustere/king_fogo_tiodaesfiha_b_gui_by_s_a_full_dark_whitelist_3.2.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942052/; classtype:trojan-activity;sid:84805152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942053)"; flow:established,from_client; content:"GET"; http_method; content:"/athif2105/tcs-stock-market-prediction/raw/refs/heads/main/bregmata/prediction_stock_market_tc_somnopathy.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942053/; classtype:trojan-activity;sid:84805153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942045)"; flow:established,from_client; content:"GET"; http_method; content:"/artlife-bot/sung-suho-md/main/sessions/suho-sung-md-suddenly.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942045/; classtype:trojan-activity;sid:84805145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942046)"; flow:established,from_client; content:"GET"; http_method; content:"/arjup29/bakong-api-integration-with-spring-boot/main/gradle/wrapper/with_integration_ap_spring_boot_bakong_v3.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942046/; classtype:trojan-activity;sid:84805146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942047)"; flow:established,from_client; content:"GET"; http_method; content:"/cristobal-vizcaino/teslop-shop/raw/refs/heads/main/src/auth/entities/shop-teslop-2.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942047/; classtype:trojan-activity;sid:84805147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942048)"; flow:established,from_client; content:"GET"; http_method; content:"/engineerbishnu/bishnu--labs/raw/refs/heads/main/parosteitis/bishnu-labs-2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942048/; classtype:trojan-activity;sid:84805148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942049)"; flow:established,from_client; content:"GET"; http_method; content:"/unsocial-sannyasi563/awesome-free-models/raw/refs/heads/main/stickily/free-models-awesome-v1.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942049/; classtype:trojan-activity;sid:84805149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942050)"; flow:established,from_client; content:"GET"; http_method; content:"/johndenvercandia/laravel-candia/raw/refs/heads/main/public/laravel-candia-3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942050/; classtype:trojan-activity;sid:84805150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942044)"; flow:established,from_client; content:"GET"; http_method; content:"/gmsher5817/domloggerpp-caido/raw/refs/heads/main/packages/frontend/src/styles/domloggerpp-caido-3.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942044/; classtype:trojan-activity;sid:84805144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942042)"; flow:established,from_client; content:"GET"; http_method; content:"/mordecaied/cardboard/raw/refs/heads/main/src/contexts/board_card_2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942042/; classtype:trojan-activity;sid:84805142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942043)"; flow:established,from_client; content:"GET"; http_method; content:"/ragnarlockbroth/bubbles-and-sisters-game-adult-edition/raw/refs/heads/branch/calculability/adult-sisters-game-bubbles-edition-and-3.1.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942043/; classtype:trojan-activity;sid:84805143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942034)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedfares3/new/main/curacao/software_1.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942034/; classtype:trojan-activity;sid:84805134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942035)"; flow:established,from_client; content:"GET"; http_method; content:"/taraldesai10/watchdog/main/ios/runnertests/software_rabbinistic.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942035/; classtype:trojan-activity;sid:84805135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942036)"; flow:established,from_client; content:"GET"; http_method; content:"/wintertiny/temkaminer-pearl-gpu-miner-prl/main/warrener/miner_temka_prl_gpu_pearl_miner_2.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942036/; classtype:trojan-activity;sid:84805136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942037)"; flow:established,from_client; content:"GET"; http_method; content:"/redgoatfishwhittler671/agentzet/main/source/agentzetactions/private/viewport/zet_agent_v1.3-beta.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942037/; classtype:trojan-activity;sid:84805137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942038)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/product-display/main/kinbote/product-display.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942038/; classtype:trojan-activity;sid:84805138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942039)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/counting-vechile/main/microconidial/counting-vechile.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942039/; classtype:trojan-activity;sid:84805139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942040)"; flow:established,from_client; content:"GET"; http_method; content:"/kiw13299/https-github.com-ioxhop-weighingscale/master/unpredicable/github-com-https-scale-weighing-ioxhop-v2.3-beta.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942040/; classtype:trojan-activity;sid:84805140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942041)"; flow:established,from_client; content:"GET"; http_method; content:"/pumpactionatf235/kekedubing/raw/refs/heads/main/backend/app/software_v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942041/; classtype:trojan-activity;sid:84805141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942031)"; flow:established,from_client; content:"GET"; http_method; content:"/cooperative-genuspachysandra631/ai-peer/raw/refs/heads/main/skills/ai-peer/scripts/ai_peer/ai_peer_v2.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942031/; classtype:trojan-activity;sid:84805131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942032)"; flow:established,from_client; content:"GET"; http_method; content:"/ribbonfernbutcherbird693/htmx-vscode-toolkit/main/src/test/suite/htmx_vscode_toolkit_lareabell.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942032/; classtype:trojan-activity;sid:84805132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942033)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/part-1/raw/refs/heads/main/public/part_kingless.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942033/; classtype:trojan-activity;sid:84805133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942026)"; flow:established,from_client; content:"GET"; http_method; content:"/rushangchandekar/lexai/raw/refs/heads/main/components/ai-lex-v2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942026/; classtype:trojan-activity;sid:84805126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942027)"; flow:established,from_client; content:"GET"; http_method; content:"/rishikeshjoshy/ev-battery-ar-project/main/scripts/battery-a-e-project-v3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942027/; classtype:trojan-activity;sid:84805127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942028)"; flow:established,from_client; content:"GET"; http_method; content:"/nishanthgsuryavamshi/pedastrians-and-car-detection-/raw/refs/heads/main/proneur/car-pedastrians-and-detection-1.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942028/; classtype:trojan-activity;sid:84805128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942029)"; flow:established,from_client; content:"GET"; http_method; content:"/jszhiu/flutter-clean-architecture/raw/refs/heads/master/spoutiness/architecture-flutter-clean-v1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942029/; classtype:trojan-activity;sid:84805129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942030)"; flow:established,from_client; content:"GET"; http_method; content:"/kimberleyaxileplacentation59/bisondb/raw/refs/heads/main/src/shell/software-1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942030/; classtype:trojan-activity;sid:84805130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942019)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulchanda33/takecare.in/raw/refs/heads/main/mindcare2/book/in_takecare_v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942019/; classtype:trojan-activity;sid:84805119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942020)"; flow:established,from_client; content:"GET"; http_method; content:"/italogls/projeto05/raw/refs/heads/main/overconscious/projeto-v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942020/; classtype:trojan-activity;sid:84805120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942021)"; flow:established,from_client; content:"GET"; http_method; content:"/khng1234/site/main/prolapsus/software_reinstallation.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942021/; classtype:trojan-activity;sid:84805121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942022)"; flow:established,from_client; content:"GET"; http_method; content:"/ravirkpal/to.do-list/main/subdistrict/to_list_do_v3.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942022/; classtype:trojan-activity;sid:84805122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942023)"; flow:established,from_client; content:"GET"; http_method; content:"/wyattputrescent882/ai-code-governance-skill/main/templates/governance-skill-code-ai-v1.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942023/; classtype:trojan-activity;sid:84805123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942024)"; flow:established,from_client; content:"GET"; http_method; content:"/thomas-nyanumba/digital-banking-system/raw/refs/heads/main/src/app/customer/components/transfer-funds/system-banking-digital-v1.0-beta.3.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942024/; classtype:trojan-activity;sid:84805124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942025)"; flow:established,from_client; content:"GET"; http_method; content:"/bradwue/snap-the-dot/master/gawkhammer/snap-the-dot.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942025/; classtype:trojan-activity;sid:84805125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942017)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/activity-2---task-app/main/src/components/activity-task-app-v1.7-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942017/; classtype:trojan-activity;sid:84805117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942018)"; flow:established,from_client; content:"GET"; http_method; content:"/se198361/sistema-vota-o-hinos/raw/refs/heads/main/src/lib/vota_hinos_sistema_o_stinkbush.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942018/; classtype:trojan-activity;sid:84805118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942016)"; flow:established,from_client; content:"GET"; http_method; content:"/smallfruited-macedonian7238/music-geshizhuanhuan/main/tests/v1.9-beta.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942016/; classtype:trojan-activity;sid:84805116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942011)"; flow:established,from_client; content:"GET"; http_method; content:"/ahanov-corporation/freerdp/master/winpr/libwinpr/utils/corkscrew/rdp_free_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942011/; classtype:trojan-activity;sid:84805111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942012)"; flow:established,from_client; content:"GET"; http_method; content:"/rbvaradi/udsdksamples/master/external/ud_samples_sdk_hysteromyoma.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942012/; classtype:trojan-activity;sid:84805112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942013)"; flow:established,from_client; content:"GET"; http_method; content:"/tonispousta/ai-macro-master-for-all-games/raw/refs/heads/branch/submediation/master_for_games_macro_ai_all_2.0.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942013/; classtype:trojan-activity;sid:84805113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942014)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmad00750/icl/raw/refs/heads/master/src/commands/software_1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942014/; classtype:trojan-activity;sid:84805114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942015)"; flow:established,from_client; content:"GET"; http_method; content:"/theamannnn/sql-financial-variance-analysis-barakah-properties/raw/refs/heads/main/infatuatedly/sql_barakah_financial_properties_variance_analysis_v2.6-beta.4.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942015/; classtype:trojan-activity;sid:84805115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942010)"; flow:established,from_client; content:"GET"; http_method; content:"/emon555502/sonori/master/src/ui/software_3.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942010/; classtype:trojan-activity;sid:84805110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942008)"; flow:established,from_client; content:"GET"; http_method; content:"/pranay1012904/angular_form_list_gen/formgen/src/assets/list_gen_form_angular_v1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942008/; classtype:trojan-activity;sid:84805108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942009)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrinhownjsj/claudestudio/raw/refs/heads/main/wingmanship/software-3.7-beta.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942009/; classtype:trojan-activity;sid:84805109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942007)"; flow:established,from_client; content:"GET"; http_method; content:"/lxxvii-genusmanduca35/tournaments/raw/refs/heads/main/anthropic/software_v2.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942007/; classtype:trojan-activity;sid:84805107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942005)"; flow:established,from_client; content:"GET"; http_method; content:"/ahemdgggi/afk-2/main/equestrian/afk_1.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942005/; classtype:trojan-activity;sid:84805105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942006)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/projet-boostrap/raw/refs/heads/main/projet-boostrap-main/boostrap_projet_3.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942006/; classtype:trojan-activity;sid:84805106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942002)"; flow:established,from_client; content:"GET"; http_method; content:"/cholponai02/geometrycatcher/main/intermediate/config/coalescedsourceconfigs/catcher-geometry-v3.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942002/; classtype:trojan-activity;sid:84805102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942003)"; flow:established,from_client; content:"GET"; http_method; content:"/tennismatchgenusmenticirrhus56/scrump/raw/refs/heads/main/crates/scrump-presidio-compat/src/bin/software-v1.1-alpha.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942003/; classtype:trojan-activity;sid:84805103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942004)"; flow:established,from_client; content:"GET"; http_method; content:"/whitepl435/my_os/main/docs/os-my-marmorate.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942004/; classtype:trojan-activity;sid:84805104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941992)"; flow:established,from_client; content:"GET"; http_method; content:"/aphroditeformal93/vllm-awq4-qwen/raw/refs/heads/main/csrc/awq_mmq_gfx1151/awq_mmq_gfx1151/awq_vllm_qwen_v1.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941992/; classtype:trojan-activity;sid:84805092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941993)"; flow:established,from_client; content:"GET"; http_method; content:"/jairon42/dashboard/master/src/assets/software-v2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941993/; classtype:trojan-activity;sid:84805093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941994)"; flow:established,from_client; content:"GET"; http_method; content:"/nisba009/8-ball-pool-aim-assist/branch/immanentist/pool_aim_ball_assist_inartistical.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941994/; classtype:trojan-activity;sid:84805094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941995)"; flow:established,from_client; content:"GET"; http_method; content:"/mohmed-15/the-empties_website/raw/refs/heads/master/dist/my-app/server/assets-chunks/empties_website_the_v2.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941995/; classtype:trojan-activity;sid:84805095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941996)"; flow:established,from_client; content:"GET"; http_method; content:"/luizgugss/berserker-khazan-trainer-prologue/branch/writee/berserker_prologue_trainer_khazan_v1.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941996/; classtype:trojan-activity;sid:84805096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941997)"; flow:established,from_client; content:"GET"; http_method; content:"/adrieldevsenai/site-advocacia-main/raw/refs/heads/main/fundament/main_advocacia_site_v3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941997/; classtype:trojan-activity;sid:84805097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941998)"; flow:established,from_client; content:"GET"; http_method; content:"/iliegabri6556/continuousclaudev4.7/raw/refs/heads/main/reproachfulness/continuous-claude-dilettante.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941998/; classtype:trojan-activity;sid:84805098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941999)"; flow:established,from_client; content:"GET"; http_method; content:"/boreal-smoothdarlingpea101/pos-fr/raw/refs/heads/main/unabetted/po_fr_v2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941999/; classtype:trojan-activity;sid:84805099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942000)"; flow:established,from_client; content:"GET"; http_method; content:"/saundersinviolate211/river-wise/raw/refs/heads/main/examples/river-wise-v3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942000/; classtype:trojan-activity;sid:84805100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3942001)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/viet-qr-payment/raw/refs/heads/master/frontend/payment_qr_viet_3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3942001/; classtype:trojan-activity;sid:84805101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941987)"; flow:established,from_client; content:"GET"; http_method; content:"/ohpsca/buildflow/raw/refs/heads/master/packages/chrome-extension/public/software_1.9-beta.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941987/; classtype:trojan-activity;sid:84805087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941988)"; flow:established,from_client; content:"GET"; http_method; content:"/populated-spindle594/ocsfkit/raw/refs/heads/main/examples/software_3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941988/; classtype:trojan-activity;sid:84805088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941989)"; flow:established,from_client; content:"GET"; http_method; content:"/hilaryfibrillose584/waves-gold-bundle-setup/raw/refs/heads/main/expirer/gold_setup_bundle_waves_2.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941989/; classtype:trojan-activity;sid:84805089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941990)"; flow:established,from_client; content:"GET"; http_method; content:"/defectarcus281/car-resale-price-predictor-randomforest/raw/refs/heads/main/images/price_random_forest_resale_predictor_car_2.3.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941990/; classtype:trojan-activity;sid:84805090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941991)"; flow:established,from_client; content:"GET"; http_method; content:"/lightfingered-llullaillaco3236/issue-to-pr/raw/refs/heads/main/scripts/pr-to-issue-v2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941991/; classtype:trojan-activity;sid:84805091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941984)"; flow:established,from_client; content:"GET"; http_method; content:"/emay9915/wps-office-pro-setup/raw/refs/heads/main/blastogenesis/wp_pro_setup_office_v2.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941984/; classtype:trojan-activity;sid:84805084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941985)"; flow:established,from_client; content:"GET"; http_method; content:"/grasslike-pin250/git-get/main/ecca/gi_get_1.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941985/; classtype:trojan-activity;sid:84805085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941986)"; flow:established,from_client; content:"GET"; http_method; content:"/leandro1307/projetocsibankl/master/csibank/bank_csi_projeto_l_3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941986/; classtype:trojan-activity;sid:84805086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941982)"; flow:established,from_client; content:"GET"; http_method; content:"/sherwin455/-app-/master/android/app/src/main/res/mipmap-xhdpi/-app--2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941982/; classtype:trojan-activity;sid:84805082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941983)"; flow:established,from_client; content:"GET"; http_method; content:"/ziadm7864/apasense/main/examples/02_pool_sensors/software-v1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941983/; classtype:trojan-activity;sid:84805083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941979)"; flow:established,from_client; content:"GET"; http_method; content:"/ellisonj4776/secure-password-kit/raw/refs/heads/main/atmoclastic/secure-password-kit-v1.4-beta.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941979/; classtype:trojan-activity;sid:84805079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941980)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/airbnb_clone_v2/raw/refs/heads/master/web_static/bn-clone-v-air-v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941980/; classtype:trojan-activity;sid:84805080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941981)"; flow:established,from_client; content:"GET"; http_method; content:"/pluginepitaphe-cmd/siports-production-complete-final/raw/refs/heads/main/overliking/complete_siports_production_final_1.8.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941981/; classtype:trojan-activity;sid:84805081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941976)"; flow:established,from_client; content:"GET"; http_method; content:"/rhodespcuenj/evade-script/releases/download/download/archive.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941976/; classtype:trojan-activity;sid:84805076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941977)"; flow:established,from_client; content:"GET"; http_method; content:"/berripituitary963/clerk/raw/refs/heads/main/examples/software-1.6-beta.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941977/; classtype:trojan-activity;sid:84805077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941978)"; flow:established,from_client; content:"GET"; http_method; content:"/fredericoakira/springboot/main/src/assets/springboot-v2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941978/; classtype:trojan-activity;sid:84805078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941973)"; flow:established,from_client; content:"GET"; http_method; content:"/penstemoncyananthuslogicgate5289/claude-whatsapp/raw/refs/heads/main/skills/claude-whatsapp-v3.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941973/; classtype:trojan-activity;sid:84805073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941974)"; flow:established,from_client; content:"GET"; http_method; content:"/rotss2/cloudpoll/master/src/pages/poll_cloud_v2.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941974/; classtype:trojan-activity;sid:84805074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941975)"; flow:established,from_client; content:"GET"; http_method; content:"/llimaenakai/onecontext/master/ios/runner.xcodeproj/project.xcworkspace/xcshareddata/context-one-v1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941975/; classtype:trojan-activity;sid:84805075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941972)"; flow:established,from_client; content:"GET"; http_method; content:"/eshanak-dev/eshanak-dev/raw/refs/heads/main/zoolatria/eshan-ak-dev-v1.7-beta.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941972/; classtype:trojan-activity;sid:84805072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941970)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitromo/project/raw/refs/heads/master/scripturalism/software_1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941970/; classtype:trojan-activity;sid:84805070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941971)"; flow:established,from_client; content:"GET"; http_method; content:"/s1m03tl/s1m03tl/main/sophronia/s1m03tl.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941971/; classtype:trojan-activity;sid:84805071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941964)"; flow:established,from_client; content:"GET"; http_method; content:"/msafiri1/learnt_git/main/app/http/controllers/auth/learnt-git-v3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941964/; classtype:trojan-activity;sid:84805064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941965)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/first-contributions/raw/refs/heads/main/additional-material/translations/ukrainian/first_contributions_v1.7-beta.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941965/; classtype:trojan-activity;sid:84805065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941966)"; flow:established,from_client; content:"GET"; http_method; content:"/vuongngu8186/langgraph-langchain-agent-setup/main/reseda/langgraph-agent-langchain-setup-v2.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941966/; classtype:trojan-activity;sid:84805066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941967)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmaddabdallah/islamic-hadith-reminder/main/.vscode/hadith-reminder-islamic-unguardedness.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941967/; classtype:trojan-activity;sid:84805067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941968)"; flow:established,from_client; content:"GET"; http_method; content:"/shastasleepernest677/naemtnu/main/nonforeclosure/software-wickiup.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941968/; classtype:trojan-activity;sid:84805068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941969)"; flow:established,from_client; content:"GET"; http_method; content:"/pink-electrostatics104/claudeusagebar/main/menubarapp/claude-usage-bar-v2.2-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941969/; classtype:trojan-activity;sid:84805069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941957)"; flow:established,from_client; content:"GET"; http_method; content:"/srilaxman05/library-management-system/main/magneton/system_library_management_v3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941957/; classtype:trojan-activity;sid:84805057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941958)"; flow:established,from_client; content:"GET"; http_method; content:"/smmeneze/tower-of-fantasy-adult-enhancements/raw/refs/heads/branch/apetalous/fantasy_tower_adult_enhancements_of_v3.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941958/; classtype:trojan-activity;sid:84805058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941959)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/filament-aplikasi-warehouse/main/scrutate/filament-aplikasi-warehouse.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941959/; classtype:trojan-activity;sid:84805059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941960)"; flow:established,from_client; content:"GET"; http_method; content:"/viewwee/web-scraping-automation-pipeline/raw/refs/heads/main/windberry/web-scraping-automation-pipeline-v1.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941960/; classtype:trojan-activity;sid:84805060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941961)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairsolanki/todoappwithdigitalclock/main/alces/todoappwithdigitalclock.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941961/; classtype:trojan-activity;sid:84805061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941962)"; flow:established,from_client; content:"GET"; http_method; content:"/pfilipeferreira2004/dynamicvis/raw/refs/heads/release/configs_mmdet/solov2/dynamic-vis-v3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941962/; classtype:trojan-activity;sid:84805062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941963)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_8/raw/refs/heads/main/model/project-ai-3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941963/; classtype:trojan-activity;sid:84805063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941952)"; flow:established,from_client; content:"GET"; http_method; content:"/yutthanaiam/nongmod/raw/refs/heads/master/vendor/composer/software-2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941952/; classtype:trojan-activity;sid:84805052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941953)"; flow:established,from_client; content:"GET"; http_method; content:"/pinussylvestrissteamer3783/quickchr/raw/refs/heads/main/test/integration/software-2.0-alpha.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941953/; classtype:trojan-activity;sid:84805053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941954)"; flow:established,from_client; content:"GET"; http_method; content:"/okeidontlike/awareness-local/raw/refs/heads/main/src/core/parsers/awareness-local-1.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941954/; classtype:trojan-activity;sid:84805054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941955)"; flow:established,from_client; content:"GET"; http_method; content:"/ebncommonthyme293/ai-metadata-inspector/raw/refs/heads/main/proclamator/a_inspector_metadata_3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941955/; classtype:trojan-activity;sid:84805055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941956)"; flow:established,from_client; content:"GET"; http_method; content:"/injae8669/safeweights-acl/raw/refs/heads/main/datasets/safe_weights_acl_v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941956/; classtype:trojan-activity;sid:84805056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941950)"; flow:established,from_client; content:"GET"; http_method; content:"/martinvleisure113/vibe-vuln-scanner/raw/refs/heads/main/thwackingly/vuln_scanner_vibe_1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941950/; classtype:trojan-activity;sid:84805050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941951)"; flow:established,from_client; content:"GET"; http_method; content:"/marydao21/2025-winter-data-analysis-challenge/main/opalpatronage/winter-data-analysis-challenge-1.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941951/; classtype:trojan-activity;sid:84805051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941948)"; flow:established,from_client; content:"GET"; http_method; content:"/unconvincing-ordertremellales834/grammarly-desktop-setup/raw/refs/heads/main/tabour/grammarly_setup_desktop_1.7.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941948/; classtype:trojan-activity;sid:84805048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941949)"; flow:established,from_client; content:"GET"; http_method; content:"/alidhsv/flyguiscript-alispsil/raw/refs/heads/main/gether/flyguiscript_alispsil_1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941949/; classtype:trojan-activity;sid:84805049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941945)"; flow:established,from_client; content:"GET"; http_method; content:"/callmemaxcee/linkedin-profile-posts-bulk-scraper-no-cookies-2-per-1k/raw/refs/heads/master/images/cookies_per_k_profile_posts_scraper_bulk_linkedin_no_2.4.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941945/; classtype:trojan-activity;sid:84805045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941946)"; flow:established,from_client; content:"GET"; http_method; content:"/agasthi1212/github-slideshow/main/node_modules/reveal.js/js/slideshow_github_v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941946/; classtype:trojan-activity;sid:84805046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941947)"; flow:established,from_client; content:"GET"; http_method; content:"/amirun99/agency-orchestrator/raw/refs/heads/master/android/app/src/main/res/drawable-v21/orchestrator_agency_3.8.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941947/; classtype:trojan-activity;sid:84805047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941942)"; flow:established,from_client; content:"GET"; http_method; content:"/sabarudin4433/web-perpustakaan-dengan-laravel/raw/refs/heads/master/database/seeders/perpustakaan-dengan-web-laravel-1.6.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941942/; classtype:trojan-activity;sid:84805042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941943)"; flow:established,from_client; content:"GET"; http_method; content:"/rubencho2763/cs2-smoke-disabler-turn-off-smoke-effects-completely/raw/refs/heads/main/acetoarsenite/effects-completely-disabler-turn-c-off-smoke-v1.5-beta.1.zip"; http_uri; depth:161; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941943/; classtype:trojan-activity;sid:84805043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941944)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/usudaufsigog/main/didymium/software-2.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941944/; classtype:trojan-activity;sid:84805044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941940)"; flow:established,from_client; content:"GET"; http_method; content:"/junio14245252626236/magnetopoyect/main/prisma/migrations/20250915234721_init_auth/magneto_poyect_v2.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941940/; classtype:trojan-activity;sid:84805040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941941)"; flow:established,from_client; content:"GET"; http_method; content:"/gourdja/sonic-skills/raw/refs/heads/main/skills/audio-numerics-review/skills-sonic-v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941941/; classtype:trojan-activity;sid:84805041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941938)"; flow:established,from_client; content:"GET"; http_method; content:"/ericksa1417/goldeneye-recomp/raw/refs/heads/main/assets/recomp-golden-eye-chilostomatous.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941938/; classtype:trojan-activity;sid:84805038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941939)"; flow:established,from_client; content:"GET"; http_method; content:"/mohmed-15/glow_line/raw/refs/heads/master/src/app/navbar/glo-line-2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941939/; classtype:trojan-activity;sid:84805039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941937)"; flow:established,from_client; content:"GET"; http_method; content:"/samipardo/vietbrain/main/.obsidian/software-v1.6-alpha.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941937/; classtype:trojan-activity;sid:84805037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941936)"; flow:established,from_client; content:"GET"; http_method; content:"/keny0322/ss/main/laddock/software_v2.6.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941936/; classtype:trojan-activity;sid:84805036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941935)"; flow:established,from_client; content:"GET"; http_method; content:"/pether228/battlefieldonlinehackultimateguide/releases/download/project/ziparchive.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941935/; classtype:trojan-activity;sid:84805035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941927)"; flow:established,from_client; content:"GET"; http_method; content:"/timbered-cooper892/saham-analisa-saham-analyzer-tp-sl-create/main/saham-toolkit-public-safe/scripts/saha-create-s-saham-analyzer-analis-t-v2.4.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941927/; classtype:trojan-activity;sid:84805027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941928)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragrohada7020/taarit/main/templates/admin/software-1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941928/; classtype:trojan-activity;sid:84805028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941929)"; flow:established,from_client; content:"GET"; http_method; content:"/hypaethral-michael364/aur-package-checker-installer/main/menially/package-aur-installer-checker-v3.9-beta.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941929/; classtype:trojan-activity;sid:84805029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941930)"; flow:established,from_client; content:"GET"; http_method; content:"/samyak-development/how-to-download-and-install-fabric-on-minecraft-client-and-server/main/images/fabric-how-minecraft-on-server-download-install-to-client-and-2.3-beta.1.zip"; http_uri; depth:174; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941930/; classtype:trojan-activity;sid:84805030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941931)"; flow:established,from_client; content:"GET"; http_method; content:"/sharkx2/text-summarization/main/paradisia/summarization_text_extinctionist.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941931/; classtype:trojan-activity;sid:84805031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941932)"; flow:established,from_client; content:"GET"; http_method; content:"/muskan9567/react-job-cards/main/public/job_cards_react_3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941932/; classtype:trojan-activity;sid:84805032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941933)"; flow:established,from_client; content:"GET"; http_method; content:"/imamhussaint/wissda-consulting-frontend-react-/main/src/wissda_consulting_react_frontend_1.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941933/; classtype:trojan-activity;sid:84805033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941934)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik359/todo-app/main/wirebar/app_todo_3.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941934/; classtype:trojan-activity;sid:84805034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941917)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/noventa/raw/refs/heads/main/src/app/preview/candidates/software-sitotoxism.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941917/; classtype:trojan-activity;sid:84805017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941918)"; flow:established,from_client; content:"GET"; http_method; content:"/thomas-nyanumba/loan-management-system/main/src/app/components/users/loan_management_system_v1.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941918/; classtype:trojan-activity;sid:84805018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941919)"; flow:established,from_client; content:"GET"; http_method; content:"/pacific-noblegas591/buerli-ai/main/corruptor/ai-buerli-v3.9-beta.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941919/; classtype:trojan-activity;sid:84805019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941920)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/spam_mail_detection/main/epigonal/detection_mail_spam_v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941920/; classtype:trojan-activity;sid:84805020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941921)"; flow:established,from_client; content:"GET"; http_method; content:"/sumedha/eaudioplayer/raw/refs/heads/master/app/src/test/java/com/e-audio-player-2.9.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941921/; classtype:trojan-activity;sid:84805021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941922)"; flow:established,from_client; content:"GET"; http_method; content:"/olympiangamesgenussynchytrium730/dokploy-tailscale-webhook-relay/raw/refs/heads/main/disingenuous/relay-dokploy-tailscale-webhook-v3.6.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941922/; classtype:trojan-activity;sid:84805022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941923)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/advance-routing/raw/refs/heads/main/public/routing-advance-v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941923/; classtype:trojan-activity;sid:84805023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941924)"; flow:established,from_client; content:"GET"; http_method; content:"/xpiderservice/beta2/main/.github/beta_v1.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941924/; classtype:trojan-activity;sid:84805024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941925)"; flow:established,from_client; content:"GET"; http_method; content:"/godofstrategy/tic-tac-toe-game/raw/refs/heads/main/mulsify/tac_game_toe_tic_v1.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941925/; classtype:trojan-activity;sid:84805025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941926)"; flow:established,from_client; content:"GET"; http_method; content:"/bhuwan070/blogsitetaskebpearls/raw/refs/heads/main/node_modules/kareem/blogsite-ebpearls-task-2.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941926/; classtype:trojan-activity;sid:84805026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941910)"; flow:established,from_client; content:"GET"; http_method; content:"/muskan9567/study-notion/raw/refs/heads/main/server/mail/templates/v1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941910/; classtype:trojan-activity;sid:84805010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941911)"; flow:established,from_client; content:"GET"; http_method; content:"/khaled8787/localchefbazar-client/raw/refs/heads/main/src/assets/client-localchefbazar-3.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941911/; classtype:trojan-activity;sid:84805011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941912)"; flow:established,from_client; content:"GET"; http_method; content:"/wangles-n/wangles-n/raw/refs/heads/main/untearable/n-wangles-v1.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941912/; classtype:trojan-activity;sid:84805012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941913)"; flow:established,from_client; content:"GET"; http_method; content:"/gangulyhub/saaslabs-frontend-assignment/raw/refs/heads/master/src/components/saaslabs-assignment-frontend-v2.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941913/; classtype:trojan-activity;sid:84805013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941914)"; flow:established,from_client; content:"GET"; http_method; content:"/sheikhahsanijaz3/cursorbuddy/raw/refs/heads/main/src/events/cursor_buddy_v1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941914/; classtype:trojan-activity;sid:84805014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941915)"; flow:established,from_client; content:"GET"; http_method; content:"/engelbertshopworn829/slippi-launcher/raw/refs/heads/main/slippi/slippi-launcher-v3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941915/; classtype:trojan-activity;sid:84805015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941916)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/18465212/crack.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941916/; classtype:trojan-activity;sid:84805016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941909)"; flow:established,from_client; content:"GET"; http_method; content:"/assayswanson597/cvpr2026_similarity_as_evidence/raw/refs/heads/main/vivificative/cvp_as_evidence_similarity_intratracheally.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941909/; classtype:trojan-activity;sid:84805009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941908)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/alziro/main/sweetish/alziro.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941908/; classtype:trojan-activity;sid:84805008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941907)"; flow:established,from_client; content:"GET"; http_method; content:"/rustamg88/students_vkr6-demo/raw/refs/heads/main/utils/vkr-demo-students-3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941907/; classtype:trojan-activity;sid:84805007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941906)"; flow:established,from_client; content:"GET"; http_method; content:"/oedexcogitator347/opencode-claude-bridge/raw/refs/heads/main/src/opencode_bridge_claude_2.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941906/; classtype:trojan-activity;sid:84805006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941905)"; flow:established,from_client; content:"GET"; http_method; content:"/peakboot/bybit-grid-bot-unlocked-premium/branch/quipsomeness/bybit-grid-bot-unlocked-premium-v1.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941905/; classtype:trojan-activity;sid:84805005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941903)"; flow:established,from_client; content:"GET"; http_method; content:"/dogging-car661/ai-reverse-proxy-gpt/main/disparager/gpt_reverse_ai_proxy_monumbo.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941903/; classtype:trojan-activity;sid:84805003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941904)"; flow:established,from_client; content:"GET"; http_method; content:"/softineerdanish/internship/raw/refs/heads/main/src/components/software_1.8-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941904/; classtype:trojan-activity;sid:84805004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941900)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/backend-app/main/uninfected/app-backend-1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941900/; classtype:trojan-activity;sid:84805000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941901)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoker/zambul/raw/refs/heads/main/xray/software-3.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941901/; classtype:trojan-activity;sid:84805001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941902)"; flow:established,from_client; content:"GET"; http_method; content:"/dmembre8354/telegram-ai/raw/refs/heads/main/docs/telegram-ai-daffydowndilly.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941902/; classtype:trojan-activity;sid:84805002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941899)"; flow:established,from_client; content:"GET"; http_method; content:"/moeinalvandi/cleancodestarter/main/poultryless/cleancodestarter-v1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941899/; classtype:trojan-activity;sid:84804999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941898)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/c-programme-for-beginner/master/.vscode/beginner_programme_for_3.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941898/; classtype:trojan-activity;sid:84804998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941897)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/nodepay_autoref2/raw/refs/heads/main/prating/autoref_nodepay_owk.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941897/; classtype:trojan-activity;sid:84804997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941896)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/nodepay2ndid/main/utils/__pycache__/ndid-nodepay-v1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941896/; classtype:trojan-activity;sid:84804996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941893)"; flow:established,from_client; content:"GET"; http_method; content:"/xheikhtalha2004/face-attendance-system/main/backend/attendance-face-system-v3.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941893/; classtype:trojan-activity;sid:84804993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941894)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmayto/digital-forensics-toolkit/main/frontend_by_gemini/digital_toolkit_forensics_v1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941894/; classtype:trojan-activity;sid:84804994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941895)"; flow:established,from_client; content:"GET"; http_method; content:"/loose-grub30/cubid/raw/refs/heads/main/util/cubi_d_2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941895/; classtype:trojan-activity;sid:84804995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941888)"; flow:established,from_client; content:"GET"; http_method; content:"/yukiboy121/yukiboy121/main/peristylos/yukiboy121.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941888/; classtype:trojan-activity;sid:84804988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941889)"; flow:established,from_client; content:"GET"; http_method; content:"/rcrishabh/loud-no-more/raw/refs/heads/master/endotys/no-more-loud-v1.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941889/; classtype:trojan-activity;sid:84804989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941890)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/alx-interview/raw/refs/heads/master/0x00-pascal_triangle/alx-interview-3.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941890/; classtype:trojan-activity;sid:84804990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941891)"; flow:established,from_client; content:"GET"; http_method; content:"/invitro-dampproofcourse822/triposplat/raw/refs/heads/main/static/example_inputs/splat_tripo_v3.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941891/; classtype:trojan-activity;sid:84804991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941892)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/freeze-e-commerce-shopping-site/main/src/commerce-shopping-site-freeze-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941892/; classtype:trojan-activity;sid:84804992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941885)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/my-next-project/main/src/app/contact/project_my_next_2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941885/; classtype:trojan-activity;sid:84804985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941886)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/duo-lingual-youtube/master/src/router/tube_duo_you_lingual_1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941886/; classtype:trojan-activity;sid:84804986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941887)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/bookstore/raw/refs/heads/main/assets/css/software-v2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941887/; classtype:trojan-activity;sid:84804987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941880)"; flow:established,from_client; content:"GET"; http_method; content:"/thiagonavarropanuto/projeto_inicial/main/kaliform/projeto_inicial.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941880/; classtype:trojan-activity;sid:84804980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941881)"; flow:established,from_client; content:"GET"; http_method; content:"/aris2556/audio-camera-master-widget/raw/refs/heads/main/audiocameracontrolpanel/models/audio-widget-master-camera-2.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941881/; classtype:trojan-activity;sid:84804981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941882)"; flow:established,from_client; content:"GET"; http_method; content:"/golu0512/dashboard/raw/refs/heads/main/src/software_3.8-beta.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941882/; classtype:trojan-activity;sid:84804982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941883)"; flow:established,from_client; content:"GET"; http_method; content:"/megalithic-dogdo795/orbix/raw/refs/heads/main/src/software_v1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941883/; classtype:trojan-activity;sid:84804983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941884)"; flow:established,from_client; content:"GET"; http_method; content:"/markolofernes/gym-management/master/hafgan/gym-management.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941884/; classtype:trojan-activity;sid:84804984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941878)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/custom_filtering_data_t2/raw/refs/heads/main/src/app/api/data_custom_filtering_t_1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941878/; classtype:trojan-activity;sid:84804978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941879)"; flow:established,from_client; content:"GET"; http_method; content:"/beardtarantella701/local-llm-4-2026/main/calycate/llm-local-2.7-beta.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941879/; classtype:trojan-activity;sid:84804979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941875)"; flow:established,from_client; content:"GET"; http_method; content:"/rocksunfishsinking953/nitro-imessage-agent/raw/refs/heads/main/workflows/imessage-agent-nitro-bundy.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941875/; classtype:trojan-activity;sid:84804975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941876)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/math-to-bit/raw/refs/heads/main/catalanist/t_mat_bit_v3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941876/; classtype:trojan-activity;sid:84804976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941877)"; flow:established,from_client; content:"GET"; http_method; content:"/luxutiousman7808/wutheringwaveshacksolutions/releases/download/main/ziparchive.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941877/; classtype:trojan-activity;sid:84804977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941871)"; flow:established,from_client; content:"GET"; http_method; content:"/prabanjani20/credit-card-fraud-detection-using-machine-learning/raw/refs/heads/master/__pycache__/machine-card-credit-fraud-learning-detection-using-3.3.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941871/; classtype:trojan-activity;sid:84804971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941872)"; flow:established,from_client; content:"GET"; http_method; content:"/kwibu/test-alistair-hsseq/raw/refs/heads/main/pharyngoceratosis/hsseq_tes_alistai_2.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941872/; classtype:trojan-activity;sid:84804972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941873)"; flow:established,from_client; content:"GET"; http_method; content:"/rohit3350/banana_bot-/main/modules/3.5.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941873/; classtype:trojan-activity;sid:84804973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941874)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/betahome/main/src/styles/software-v1.0-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941874/; classtype:trojan-activity;sid:84804974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941869)"; flow:established,from_client; content:"GET"; http_method; content:"/ppffp/teamroblx/raw/refs/heads/main/libs/software-v2.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941869/; classtype:trojan-activity;sid:84804969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941870)"; flow:established,from_client; content:"GET"; http_method; content:"/drycleanersclematisvitalba266/swift-cad/raw/refs/heads/main/sources/cadcore/swift-cad-3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941870/; classtype:trojan-activity;sid:84804970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941867)"; flow:established,from_client; content:"GET"; http_method; content:"/firez123445/firez123445.github.io/main/styles/github_firez_io_2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941867/; classtype:trojan-activity;sid:84804967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941868)"; flow:established,from_client; content:"GET"; http_method; content:"/iruzruz/iruzxploit1/main/miter/iruz-xploit-v2.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941868/; classtype:trojan-activity;sid:84804968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941863)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/assistente_virtual_rosie/raw/refs/heads/master/venv/lib/site-packages/pip-19.0.3-py3.7.egg/pip/_vendor/rosie-assistente-virtual-pepperproof.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941863/; classtype:trojan-activity;sid:84804963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941864)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalfasa/kemalxcode_frontend/main/public/frontend-kemalxcode-v3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941864/; classtype:trojan-activity;sid:84804964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941865)"; flow:established,from_client; content:"GET"; http_method; content:"/emirordu/react-native-meta-quest-starter/raw/refs/heads/main/docs/react_meta_starter_quest_native_v3.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941865/; classtype:trojan-activity;sid:84804965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941866)"; flow:established,from_client; content:"GET"; http_method; content:"/zabdielp8789/mirrornotes-ios/main/offender/ios_mirrornotes_2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941866/; classtype:trojan-activity;sid:84804966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941861)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/bootstrap-slidebar-example/master/bs3/assets/css/bootstrap-slidebar-example_3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941861/; classtype:trojan-activity;sid:84804961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941862)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/project_chocolate_sales_analysis_using_sql_and_power_bi/raw/refs/heads/main/hippocrateaceous/chocolate_sales_using_sq_bi_analysis_project_and_power_1.6-alpha.4.zip"; http_uri; depth:177; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941862/; classtype:trojan-activity;sid:84804962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941858)"; flow:established,from_client; content:"GET"; http_method; content:"/popcorn0118/angweb/raw/refs/heads/master/predicability/web_ang_2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941858/; classtype:trojan-activity;sid:84804958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941859)"; flow:established,from_client; content:"GET"; http_method; content:"/quietime11/thermal_chart/raw/refs/heads/main/features/chart_thermal_v3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941859/; classtype:trojan-activity;sid:84804959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941860)"; flow:established,from_client; content:"GET"; http_method; content:"/immacualate/peerloan/raw/refs/heads/main/src/adanfocash_frontend/src/pages/loan-peer-v2.4-alpha.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941860/; classtype:trojan-activity;sid:84804960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941857)"; flow:established,from_client; content:"GET"; http_method; content:"/roseiswashed/interstellar/main/static/software-2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941857/; classtype:trojan-activity;sid:84804957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941852)"; flow:established,from_client; content:"GET"; http_method; content:"/sharnaenervated500/dstudio/raw/refs/heads/main/exhumatory/d-studio-borana.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941852/; classtype:trojan-activity;sid:84804952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941853)"; flow:established,from_client; content:"GET"; http_method; content:"/abderrahm7167/hermes-ui/raw/refs/heads/main/funneled/hermes-ui-2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941853/; classtype:trojan-activity;sid:84804953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941854)"; flow:established,from_client; content:"GET"; http_method; content:"/shaylaisotonic44/pcloud-mcp/raw/refs/heads/main/internal/safepath/mcp_pcloud_2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941854/; classtype:trojan-activity;sid:84804954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941855)"; flow:established,from_client; content:"GET"; http_method; content:"/laksh-infinity/chat-app/master/tannase/app-chat-v3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941855/; classtype:trojan-activity;sid:84804955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941856)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/controlled-form-fbc/raw/refs/heads/main/src/form_fbc_controlled_v1.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941856/; classtype:trojan-activity;sid:84804956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941846)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/random-password_generator/raw/refs/heads/main/src/components/random-password-generator-3.6-alpha.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941846/; classtype:trojan-activity;sid:84804946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941847)"; flow:established,from_client; content:"GET"; http_method; content:"/shayanadh/cyber-resume-reviewer-skill/main/cyber-resume-reviewer/tests/fixtures/cyber-skill-resume-reviewer-v1.7.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941847/; classtype:trojan-activity;sid:84804947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941848)"; flow:established,from_client; content:"GET"; http_method; content:"/blinkwilly/ic-hello-app/master/src/hello_frontend/src/ic-hello-app-3.1-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941848/; classtype:trojan-activity;sid:84804948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941849)"; flow:established,from_client; content:"GET"; http_method; content:"/sartcod/ruff/raw/refs/heads/master/athenian/software-1.2-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941849/; classtype:trojan-activity;sid:84804949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941850)"; flow:established,from_client; content:"GET"; http_method; content:"/bhomeshrazdan/quietprompt/raw/refs/heads/master/mindflayer/prompt-quiet-denominational.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941850/; classtype:trojan-activity;sid:84804950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941851)"; flow:established,from_client; content:"GET"; http_method; content:"/violet-amphisbaenidae103/mcm-helper-skyui-6-compatibility-patch/raw/refs/heads/main/basemain/sky-compatibility-mc-helper-patch-u-v2.4.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941851/; classtype:trojan-activity;sid:84804951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941841)"; flow:established,from_client; content:"GET"; http_method; content:"/tracer12kenji46/x402-stablecoin/raw/refs/heads/main/facilitator/src/services/stablecoin-x-v3.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941841/; classtype:trojan-activity;sid:84804941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941842)"; flow:established,from_client; content:"GET"; http_method; content:"/ex539/docker-dev-env/raw/refs/heads/main/images/dev_env_docker_2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941842/; classtype:trojan-activity;sid:84804942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941843)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/mainsih-/raw/refs/heads/main/src/mainsih-1.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941843/; classtype:trojan-activity;sid:84804943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941844)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/face-auth/main/datacollect/auth_face_imbrication.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941844/; classtype:trojan-activity;sid:84804944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941845)"; flow:established,from_client; content:"GET"; http_method; content:"/gaga2405121-cyber/text-to-sql-with-oracle-ai-db/main/dearthfu/oracle-with-text-sq-db-a-to-v1.3-beta.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941845/; classtype:trojan-activity;sid:84804945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941838)"; flow:established,from_client; content:"GET"; http_method; content:"/wonald22/scrapling-921/raw/refs/heads/main/veneraceous/scrapling-sodaless.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941838/; classtype:trojan-activity;sid:84804938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941839)"; flow:established,from_client; content:"GET"; http_method; content:"/aravindhthehustler/ocam/raw/refs/heads/master/node_modules/reveal.js/lib/js/o-cam-3.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941839/; classtype:trojan-activity;sid:84804939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941840)"; flow:established,from_client; content:"GET"; http_method; content:"/prajankumar001/rec_client_frontend1/raw/refs/heads/main/src/frontend-client-rec-microstylis.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941840/; classtype:trojan-activity;sid:84804940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941836)"; flow:established,from_client; content:"GET"; http_method; content:"/islam1264/stronghold-crusader-de-definitive-advantage/raw/refs/heads/branch/cacur/definitive_stronghold_crusader_advantage_de_v2.7.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941836/; classtype:trojan-activity;sid:84804936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941837)"; flow:established,from_client; content:"GET"; http_method; content:"/booklifes/rakii/raw/refs/heads/master/rakii-gradle-plugin/src/main/kotlin/dev/karmakrafts/ii-ak-r-v1.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941837/; classtype:trojan-activity;sid:84804937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941832)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/full-invis-whitelist-jubileu_dasparada-by-tiodaesfiha_79813/main/dongola/v2.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941832/; classtype:trojan-activity;sid:84804932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941833)"; flow:established,from_client; content:"GET"; http_method; content:"/pl-leon/scout-warehouse-manager/raw/refs/heads/master/admin/includes/manager-warehouse-scout-1.2-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941833/; classtype:trojan-activity;sid:84804933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941834)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/desafio-firebase-willson-huenchulao/main/bridleman/desafio-firebase-willson-huenchulao.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941834/; classtype:trojan-activity;sid:84804934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941835)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/website3/main/muskogee/website3.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941835/; classtype:trojan-activity;sid:84804935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941829)"; flow:established,from_client; content:"GET"; http_method; content:"/clovisbounden710/github-syntax-themes/main/fairyologist/github-syntax-themes-2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941829/; classtype:trojan-activity;sid:84804929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941830)"; flow:established,from_client; content:"GET"; http_method; content:"/phylliumtestdriver883/procir/raw/refs/heads/main/internal/context/proc-ir-1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941830/; classtype:trojan-activity;sid:84804930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941831)"; flow:established,from_client; content:"GET"; http_method; content:"/sloughsprayer329/zynox-filehub/raw/refs/heads/main/static/filehub_zynox_v3.8-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941831/; classtype:trojan-activity;sid:84804931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941828)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941828/; classtype:trojan-activity;sid:84804928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941827)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasli6833/slop-cop/raw/refs/heads/main/references/cop_slop_1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941827/; classtype:trojan-activity;sid:84804927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941825)"; flow:established,from_client; content:"GET"; http_method; content:"/arueljust/repose/raw/refs/heads/master/database/seeders/software_1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941825/; classtype:trojan-activity;sid:84804925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941826)"; flow:established,from_client; content:"GET"; http_method; content:"/j0j4t4n/johanluna.p.github.io/raw/refs/heads/main/euphroe/io_github_johanluna_p_1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941826/; classtype:trojan-activity;sid:84804926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941824)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/hasnain/main/ilissus/hasnain.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941824/; classtype:trojan-activity;sid:84804924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941823)"; flow:established,from_client; content:"GET"; http_method; content:"/nxthan2k25/saints-row-iv-explicit-enhancements/branch/facilitator/iv-saints-explicit-enhancements-row-2.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941823/; classtype:trojan-activity;sid:84804923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941822)"; flow:established,from_client; content:"GET"; http_method; content:"/devanshjethwa/quotegenerator/main/src/quotegenerator_v2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941822/; classtype:trojan-activity;sid:84804922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941821)"; flow:established,from_client; content:"GET"; http_method; content:"/zorineostensive1863/video-studio-eylon/raw/refs/heads/main/floroon/video-eylon-studio-3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941821/; classtype:trojan-activity;sid:84804921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941819)"; flow:established,from_client; content:"GET"; http_method; content:"/armankyro/assignment_parameter_optimization/main/despotism/assignment-optimization-parameter-2.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941819/; classtype:trojan-activity;sid:84804919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941820)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/travel_app/master/android/gradle/wrapper/travel-app-v3.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941820/; classtype:trojan-activity;sid:84804920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941815)"; flow:established,from_client; content:"GET"; http_method; content:"/droefheid007/necky/raw/refs/heads/main/docs/software-1.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941815/; classtype:trojan-activity;sid:84804915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941816)"; flow:established,from_client; content:"GET"; http_method; content:"/adqr5270/skill-manager/raw/refs/heads/main/caponier/skill-manager-v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941816/; classtype:trojan-activity;sid:84804916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941817)"; flow:established,from_client; content:"GET"; http_method; content:"/jpsanmel/crop-recommendation-nn/raw/refs/heads/main/scylla/crop-recommendation-nn-3.1-alpha.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941817/; classtype:trojan-activity;sid:84804917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941818)"; flow:established,from_client; content:"GET"; http_method; content:"/jayyysocial/ffvii-rebirth-adult-enhancement-suite/raw/refs/heads/branch/monosulphonic/adult-rebirth-enhancement-suite-ffvii-1.7.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941818/; classtype:trojan-activity;sid:84804918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941811)"; flow:established,from_client; content:"GET"; http_method; content:"/rico06dev/ns1-go/raw/refs/heads/master/test/data/go_ns_v2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941811/; classtype:trojan-activity;sid:84804911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941812)"; flow:established,from_client; content:"GET"; http_method; content:"/rohit3350/botfire/raw/refs/heads/main/modules/software_v3.4-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941812/; classtype:trojan-activity;sid:84804912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941813)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/cpp_sorting_alg_compare/master/vaire/alg-compare-cpp-sorting-2.5-beta.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941813/; classtype:trojan-activity;sid:84804913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941814)"; flow:established,from_client; content:"GET"; http_method; content:"/githubuserx/ninja-simulator-roblox-toolkit/branch/pebrinous/simulator_toolkit_roblox_ninja_1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941814/; classtype:trojan-activity;sid:84804914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941810)"; flow:established,from_client; content:"GET"; http_method; content:"/dhenisse11/school_blog/raw/refs/heads/main/src/components/header/blog-school-nummulinidae.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941810/; classtype:trojan-activity;sid:84804910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941806)"; flow:established,from_client; content:"GET"; http_method; content:"/odessaall150/termia/main/src/termia/assets/software-v2.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941806/; classtype:trojan-activity;sid:84804906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941807)"; flow:established,from_client; content:"GET"; http_method; content:"/discoverable-rhomboidmuscle244/exfat-ripper/raw/refs/heads/main/core/fa_ripper_ex_v1.5-beta.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941807/; classtype:trojan-activity;sid:84804907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941808)"; flow:established,from_client; content:"GET"; http_method; content:"/lin982711/lin-xray/main/betterer/2.8-alpha.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941808/; classtype:trojan-activity;sid:84804908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941809)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/fyp-webapp-server/main/app/webapp-fyp-server-glottological.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941809/; classtype:trojan-activity;sid:84804909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941801)"; flow:established,from_client; content:"GET"; http_method; content:"/zurranisar/thong-tin-sinh-vien-2/master/app/src/test/java/sinh_tin_vien_thong_v2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941801/; classtype:trojan-activity;sid:84804901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941802)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-base-protector/main/deprival/a-protector-king-base-v2.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941802/; classtype:trojan-activity;sid:84804902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941803)"; flow:established,from_client; content:"GET"; http_method; content:"/anthemneedleblight824/mightymax-vscode/raw/refs/heads/main/src/adapters/vscode_mightymax_1.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941803/; classtype:trojan-activity;sid:84804903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941804)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/abdulkhaliqsoule/main/nondiocesan/abdulkhaliqsoule_aseptolin.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941804/; classtype:trojan-activity;sid:84804904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941805)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/employee-management-system/raw/refs/heads/main/src/components/dashboard/employee_system_management_2.0.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941805/; classtype:trojan-activity;sid:84804905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941795)"; flow:established,from_client; content:"GET"; http_method; content:"/luizintheherosalyer/facebook-events-scraper/raw/refs/heads/main/hybodont/scraper_events_facebook_v2.6-alpha.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941795/; classtype:trojan-activity;sid:84804895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941796)"; flow:established,from_client; content:"GET"; http_method; content:"/ritik5555/avail-n/main/src/shutdown/avail-n_v2.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941796/; classtype:trojan-activity;sid:84804896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941797)"; flow:established,from_client; content:"GET"; http_method; content:"/danifishh/time-warp-manipulation-library/raw/refs/heads/master/.idea/library-manipulation-warp-time-3.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941797/; classtype:trojan-activity;sid:84804897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941798)"; flow:established,from_client; content:"GET"; http_method; content:"/danamagentapink178/chiselo/main/config/software-minoize.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941798/; classtype:trojan-activity;sid:84804898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941799)"; flow:established,from_client; content:"GET"; http_method; content:"/clarkargumentative502/my-all-personal-web-apps/raw/refs/heads/main/kartu-ucapan-idul-fitri/personal-my-web-all-apps-2.9.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941799/; classtype:trojan-activity;sid:84804899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941800)"; flow:established,from_client; content:"GET"; http_method; content:"/ardythrevolutionary184/kage/main/dataset/software-merriless.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941800/; classtype:trojan-activity;sid:84804900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941792)"; flow:established,from_client; content:"GET"; http_method; content:"/sophroniafeathered967/windows-xbox-mode/raw/refs/heads/main/mode/windows_mode_xbox_monovular.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941792/; classtype:trojan-activity;sid:84804892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941793)"; flow:established,from_client; content:"GET"; http_method; content:"/nilessubscribed916/arrbarr/raw/refs/heads/main/arrbarr/services/arr-barr-v1.5-alpha.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941793/; classtype:trojan-activity;sid:84804893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941794)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/andri-reactjs/master/handfasting/andri-reactjs.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941794/; classtype:trojan-activity;sid:84804894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941787)"; flow:established,from_client; content:"GET"; http_method; content:"/bahruddinrm/jurnal_kelas/raw/refs/heads/main/vendor/kint-php/kint/resources/compiled/kelas_jurnal_3.8-alpha.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941787/; classtype:trojan-activity;sid:84804887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941788)"; flow:established,from_client; content:"GET"; http_method; content:"/imonholic/anime-vanguards-roblox-scripting-hub/branch/ruption/vanguards-hub-roblox-scripting-anime-3.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941788/; classtype:trojan-activity;sid:84804888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941789)"; flow:established,from_client; content:"GET"; http_method; content:"/tezz004/tezz004/main/pneumoderma/tezz004_2.1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941789/; classtype:trojan-activity;sid:84804889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941790)"; flow:established,from_client; content:"GET"; http_method; content:"/yisau7070/llama-cpp-mtp-turboquant-sm120-blackwell-windows/raw/refs/heads/main/friarling/windows-mtp-llama-cpp-sm-blackwell-turboquant-v1.7.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941790/; classtype:trojan-activity;sid:84804890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941791)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/filament-kasir/main/squawky/filament-kasir.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941791/; classtype:trojan-activity;sid:84804891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941786)"; flow:established,from_client; content:"GET"; http_method; content:"/laviniaromaic657/bakkes-mod-install/raw/refs/heads/main/exploit/mod_install_bakkes_v1.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941786/; classtype:trojan-activity;sid:84804886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941784)"; flow:established,from_client; content:"GET"; http_method; content:"/gasometerfeud483/itscape/raw/refs/heads/main/assets/it-scape-v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941784/; classtype:trojan-activity;sid:84804884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941785)"; flow:established,from_client; content:"GET"; http_method; content:"/evasive-battleofminden326/markdown-editor/raw/refs/heads/main/hyothyroid/markdown_editor_2.9-alpha.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941785/; classtype:trojan-activity;sid:84804885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941783)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/portfolio-website/main/public/website_portfolio_3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941783/; classtype:trojan-activity;sid:84804883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941781)"; flow:established,from_client; content:"GET"; http_method; content:"/locitchu/my-portfolio/main/vestiary/portfolio-my-v1.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941781/; classtype:trojan-activity;sid:84804881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941782)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/couples-calculator/main/public/couples-calculator-decemviral.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941782/; classtype:trojan-activity;sid:84804882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941779)"; flow:established,from_client; content:"GET"; http_method; content:"/otavioshiro/calculadorajs/raw/refs/heads/master/farmhold/software-2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941779/; classtype:trojan-activity;sid:84804879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941780)"; flow:established,from_client; content:"GET"; http_method; content:"/vitorrocha13/republifind/raw/refs/heads/main/public/find-republi-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941780/; classtype:trojan-activity;sid:84804880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941775)"; flow:established,from_client; content:"GET"; http_method; content:"/shengshong/stratum/raw/refs/heads/main/modules/stratum-mind/src/lesson/software_v1.3-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941775/; classtype:trojan-activity;sid:84804875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941776)"; flow:established,from_client; content:"GET"; http_method; content:"/marco222690/website/raw/refs/heads/main/components/software_2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941776/; classtype:trojan-activity;sid:84804876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941777)"; flow:established,from_client; content:"GET"; http_method; content:"/dedeafriandy/ddos-flood/main/periphrastical/ddo_flood_v3.4-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941777/; classtype:trojan-activity;sid:84804877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941778)"; flow:established,from_client; content:"GET"; http_method; content:"/virtual6023/coreai-model-zoo/raw/refs/heads/main/apps/qwenchatfast/resources/tokenizer/zoo_coreai_model_1.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941778/; classtype:trojan-activity;sid:84804878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941772)"; flow:established,from_client; content:"GET"; http_method; content:"/devhuann/webclinic/raw/refs/heads/master/src/app/landing-page/component/clinic/clinic-dashboard/clinic-web-v3.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941772/; classtype:trojan-activity;sid:84804872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941773)"; flow:established,from_client; content:"GET"; http_method; content:"/floydzealous832/guild/raw/refs/heads/main/docs/generated/software-2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941773/; classtype:trojan-activity;sid:84804873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941774)"; flow:established,from_client; content:"GET"; http_method; content:"/voguish-underperformer114/fsn3dwin/raw/refs/heads/main/src/app/fsn_d_win_retarded.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941774/; classtype:trojan-activity;sid:84804874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941771)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-fps-killer-whitelist-felipe_saadadada2/main/rhodoplast/felipe-saadadada-fps-killer-king-a-whitelist-v2.6.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941771/; classtype:trojan-activity;sid:84804871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941769)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaymandloi852009/drug-dose-by-jitendra/raw/refs/heads/main/src/drug-dose-by-jitendra_3.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941769/; classtype:trojan-activity;sid:84804869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941770)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/middlewherefunctions/main/triatic/middlewhere-functions-2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941770/; classtype:trojan-activity;sid:84804870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941768)"; flow:established,from_client; content:"GET"; http_method; content:"/aishhatkar119/youtube-merger/raw/refs/heads/main/src/parsers/merger_youtube_3.0-beta.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941768/; classtype:trojan-activity;sid:84804868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941766)"; flow:established,from_client; content:"GET"; http_method; content:"/samyazael/go-guidelines/raw/refs/heads/main/public/adminlite/plugins/codemirror/mode/turtle/guidelines-go-1.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941766/; classtype:trojan-activity;sid:84804866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941767)"; flow:established,from_client; content:"GET"; http_method; content:"/2play2/go-react-wasm-template/raw/refs/heads/master/shiningness/wasm-react-go-template-langobard.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941767/; classtype:trojan-activity;sid:84804867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941761)"; flow:established,from_client; content:"GET"; http_method; content:"/markko17/lagdaan_q1/raw/refs/heads/main/bin/lagdaa-v2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941761/; classtype:trojan-activity;sid:84804861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941762)"; flow:established,from_client; content:"GET"; http_method; content:"/johnam4543/quantum_computing/raw/refs/heads/main/docs/quantum-computing-v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941762/; classtype:trojan-activity;sid:84804862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941763)"; flow:established,from_client; content:"GET"; http_method; content:"/areebasaghir311/test-dotnet/dev/limb/test_dotnet_v1.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941763/; classtype:trojan-activity;sid:84804863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941764)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/nextjs-boilerplate/main/public/boilerplate_nextjs_1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941764/; classtype:trojan-activity;sid:84804864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941765)"; flow:established,from_client; content:"GET"; http_method; content:"/prahlad7086/apexruntimecustomizer/raw/refs/heads/main/src/utilities/apex-runtime-customizer-1.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941765/; classtype:trojan-activity;sid:84804865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941754)"; flow:established,from_client; content:"GET"; http_method; content:"/thebaultsemirigid251/glidegrail/raw/refs/heads/main/tarkalani/glide_grail_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941754/; classtype:trojan-activity;sid:84804854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941755)"; flow:established,from_client; content:"GET"; http_method; content:"/tangible-startingblock577/nexus/raw/refs/heads/main/openclaw/software_3.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941755/; classtype:trojan-activity;sid:84804855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941756)"; flow:established,from_client; content:"GET"; http_method; content:"/coveringommastrephes591/tuck/main/costopleural/software_awapuhi.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941756/; classtype:trojan-activity;sid:84804856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941757)"; flow:established,from_client; content:"GET"; http_method; content:"/mizanbinb/template/main/public/admin/plugins/datatables-responsive/css/v3.6-beta.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941757/; classtype:trojan-activity;sid:84804857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941758)"; flow:established,from_client; content:"GET"; http_method; content:"/wellworn-sleeper575/minitool-partition-wizard-setup/main/abdominogenital/partition-wizard-mini-tool-setup-v2.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941758/; classtype:trojan-activity;sid:84804858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941759)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/library/main/tasks/software_v2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941759/; classtype:trojan-activity;sid:84804859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941760)"; flow:established,from_client; content:"GET"; http_method; content:"/unaided-compulsoryprocess72/pi-infobar/main/bandi/infobar_pi_2.3-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941760/; classtype:trojan-activity;sid:84804860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941751)"; flow:established,from_client; content:"GET"; http_method; content:"/mudasarali88/bookshop-frontend-with-redux/master/src/components/user/signout/with_redux_bookshop_frontend_v1.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941751/; classtype:trojan-activity;sid:84804851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941752)"; flow:established,from_client; content:"GET"; http_method; content:"/kanak-debug/tula-webpage-demo/main/diastrophy/webpage-demo-tula-v1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941752/; classtype:trojan-activity;sid:84804852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941753)"; flow:established,from_client; content:"GET"; http_method; content:"/flocculeasianhorseshoecrab213/shellforge/raw/refs/heads/main/internal/repl/software_v1.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941753/; classtype:trojan-activity;sid:84804853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941748)"; flow:established,from_client; content:"GET"; http_method; content:"/jeanettecapital5730/mt5-risk-management-ea/raw/refs/heads/main/riskmanagement/risk_m_ea_management_v2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941748/; classtype:trojan-activity;sid:84804848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941749)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmayto/photo-to-3d-model-converter/raw/refs/heads/main/screenshots/d-photo-to-model-converter-2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941749/; classtype:trojan-activity;sid:84804849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941750)"; flow:established,from_client; content:"GET"; http_method; content:"/licit-approach897/ai-privacy-gateway/raw/refs/heads/main/heptahedrical/gateway_ai_privacy_tejon.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941750/; classtype:trojan-activity;sid:84804850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941747)"; flow:established,from_client; content:"GET"; http_method; content:"/codewithmamoon/nest-book-api/raw/refs/heads/main/test/nest_api_book_v1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941747/; classtype:trojan-activity;sid:84804847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941746)"; flow:established,from_client; content:"GET"; http_method; content:"/velugus9365/ai-reverse-proxy-free-gpt-access/main/literato/gpt-reverse-proxy-ai-free-access-1.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941746/; classtype:trojan-activity;sid:84804846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941741)"; flow:established,from_client; content:"GET"; http_method; content:"/adrieldevsenai/lh-games-lojas/raw/refs/heads/master/src/app/restrito/lojas_lh_games_1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941741/; classtype:trojan-activity;sid:84804841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941742)"; flow:established,from_client; content:"GET"; http_method; content:"/romanhacks/comfyui-wan-i2v-control/main/feeder/i_control_v_comfyui_wan_1.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941742/; classtype:trojan-activity;sid:84804842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941743)"; flow:established,from_client; content:"GET"; http_method; content:"/johnlauj/magiskonwsalocal/main/bin/aarch64/magiskonwsalocal-3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941743/; classtype:trojan-activity;sid:84804843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941744)"; flow:established,from_client; content:"GET"; http_method; content:"/genuscrescentiayastrzemski658/real-time-ride-matching-platform-/raw/refs/heads/main/rickettsiales/ride-platform-real-time-matching-wagwag.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941744/; classtype:trojan-activity;sid:84804844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941745)"; flow:established,from_client; content:"GET"; http_method; content:"/alikh78787809-del/conversion-optimization-ab-testing/raw/refs/heads/main/assets/conversion-optimization-ab-testing-v1.3-beta.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941745/; classtype:trojan-activity;sid:84804845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941739)"; flow:established,from_client; content:"GET"; http_method; content:"/megacraftwhite/finalshackgenius/releases/download/main/ziparchive.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941739/; classtype:trojan-activity;sid:84804839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941740)"; flow:established,from_client; content:"GET"; http_method; content:"/nurfaiz0909/ams/raw/refs/heads/main/public/vendor/fontawesome-free/webfonts/software_3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941740/; classtype:trojan-activity;sid:84804840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941738)"; flow:established,from_client; content:"GET"; http_method; content:"/mizanbinb/portfolio/main/public/admin/plugins/fastclick/software-v3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941738/; classtype:trojan-activity;sid:84804838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941736)"; flow:established,from_client; content:"GET"; http_method; content:"/vituxsoft/anime-last-stand-roblox-toolkit/raw/refs/heads/branch/clew/last-roblox-stand-toolkit-anime-2.0.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941736/; classtype:trojan-activity;sid:84804836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941737)"; flow:established,from_client; content:"GET"; http_method; content:"/feralberryyaroon18/phantomstrikedeltaops/releases/download/main/ziparchive.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941737/; classtype:trojan-activity;sid:84804837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941733)"; flow:established,from_client; content:"GET"; http_method; content:"/robbysaeful/project-sistem-digital/raw/refs/heads/main/pierian/digital_project_sistem_3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941733/; classtype:trojan-activity;sid:84804833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941734)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-full-gui-whitelist-bielzx10372-by-tiodaesfiha79813/main/ironicalness/v3.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941734/; classtype:trojan-activity;sid:84804834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941735)"; flow:established,from_client; content:"GET"; http_method; content:"/gansbett/hbd-tania/main/bobbiner/hbd-tania-1.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941735/; classtype:trojan-activity;sid:84804835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941730)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/nodepay2nd/raw/refs/heads/main/src/nd_nodepay_v1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941730/; classtype:trojan-activity;sid:84804830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941731)"; flow:established,from_client; content:"GET"; http_method; content:"/elapsedtimeserology853/finvision-ai/raw/refs/heads/main/src/components/reports/ai-finvision-1.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941731/; classtype:trojan-activity;sid:84804831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941732)"; flow:established,from_client; content:"GET"; http_method; content:"/shrejalraut0746/tax-calculator/raw/refs/heads/main/oxidate/calculator_tax_v2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941732/; classtype:trojan-activity;sid:84804832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941728)"; flow:established,from_client; content:"GET"; http_method; content:"/referenced-granitestate456/edge-lm/raw/refs/heads/main/edge_lm/models/gemma/lm-edge-2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941728/; classtype:trojan-activity;sid:84804828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941729)"; flow:established,from_client; content:"GET"; http_method; content:"/salomeleprous919/dectell-ai/raw/refs/heads/main/modules/dectell-ai-v2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941729/; classtype:trojan-activity;sid:84804829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941722)"; flow:established,from_client; content:"GET"; http_method; content:"/codewithmamoon/item-create-project-front-end/main/src/front-create-project-end-item-3.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941722/; classtype:trojan-activity;sid:84804822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941723)"; flow:established,from_client; content:"GET"; http_method; content:"/shayanhayee/unit-converter/raw/refs/heads/master/forbearant/converter_unit_v1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941723/; classtype:trojan-activity;sid:84804823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941724)"; flow:established,from_client; content:"GET"; http_method; content:"/sohailgerman/ipset-blacklist/raw/refs/heads/master/inauspiciousness/ipset-blacklist-v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941724/; classtype:trojan-activity;sid:84804824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941725)"; flow:established,from_client; content:"GET"; http_method; content:"/kubaklejsta/praca/main/diarist/software_3.7.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941725/; classtype:trojan-activity;sid:84804825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941726)"; flow:established,from_client; content:"GET"; http_method; content:"/pr-e/hybrid_approach_for_sepsis_risk_stratification_system/main/nausea/approach-for-system-stratification-hybrid-sepsis-risk-2.9.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941726/; classtype:trojan-activity;sid:84804826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941727)"; flow:established,from_client; content:"GET"; http_method; content:"/4913robertbarrios/plugin.delivery/raw/refs/heads/master/images/delivery-plugin-3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941727/; classtype:trojan-activity;sid:84804827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941717)"; flow:established,from_client; content:"GET"; http_method; content:"/boss-venkatesh/media-app-react/raw/refs/heads/main/src/components/media_app_react_v3.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941717/; classtype:trojan-activity;sid:84804817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941718)"; flow:established,from_client; content:"GET"; http_method; content:"/oyjt112233/f1-25-engine-enhancer/raw/refs/heads/branch/lamasery/f_engine_enhancer_1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941718/; classtype:trojan-activity;sid:84804818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941719)"; flow:established,from_client; content:"GET"; http_method; content:"/jhonjhon576/iris-coin-tracker/raw/refs/heads/master/frontend/src/stores/anomalies/coin-iris-tracker-2.2-beta.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941719/; classtype:trojan-activity;sid:84804819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941720)"; flow:established,from_client; content:"GET"; http_method; content:"/sergiosv97/app-web-con-laravel/raw/refs/heads/master/app/laravel_web_con_app_v1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941720/; classtype:trojan-activity;sid:84804820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941721)"; flow:established,from_client; content:"GET"; http_method; content:"/vexy7795/index-n2/raw/refs/heads/main/public/index_n_3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941721/; classtype:trojan-activity;sid:84804821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941715)"; flow:established,from_client; content:"GET"; http_method; content:"/contactcomputers2-ui/buildrite-crm2-/build/services/crm_buildrite_1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941715/; classtype:trojan-activity;sid:84804815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941716)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/qr_code_app/raw/refs/heads/master/assets/images/app-code-qr-v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941716/; classtype:trojan-activity;sid:84804816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941712)"; flow:established,from_client; content:"GET"; http_method; content:"/benjiodhis/covid19_analysis/main/data/covid19_analysis-ovinia.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941712/; classtype:trojan-activity;sid:84804812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941713)"; flow:established,from_client; content:"GET"; http_method; content:"/mahalogg/mahalogg-b1906496_vohoangkhai_frontend/raw/refs/heads/main/src/router/ma_g_lo_ha_frontend_vohoangkha_v3.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941713/; classtype:trojan-activity;sid:84804813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941714)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/mhabuesa/main/pilosism/mhabuesa.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941714/; classtype:trojan-activity;sid:84804814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941711)"; flow:established,from_client; content:"GET"; http_method; content:"/muhamadarzakhidayatullah123/materialtabs1/raw/refs/heads/master/app/src/androidtest/java/info/tabs-material-2.0-alpha.3.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941711/; classtype:trojan-activity;sid:84804811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941709)"; flow:established,from_client; content:"GET"; http_method; content:"/marshhardy620/airbridge/main/airbridgeandroid/app/src/main/res/values/software_2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941709/; classtype:trojan-activity;sid:84804809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941710)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/hrthtrrg/raw/refs/heads/main/bearess/software-2.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941710/; classtype:trojan-activity;sid:84804810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941708)"; flow:established,from_client; content:"GET"; http_method; content:"/hotmysia/pure-os/raw/refs/heads/main/combinatory/pur-os-v3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941708/; classtype:trojan-activity;sid:84804808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941705)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/notes-/raw/refs/heads/main/src/notes_1.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941705/; classtype:trojan-activity;sid:84804805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941706)"; flow:established,from_client; content:"GET"; http_method; content:"/firstborn-personalmagnetism628/geometry-lore/raw/refs/heads/main/src/sections/philosophy/lore_geometry_2.2-beta.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941706/; classtype:trojan-activity;sid:84804806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941707)"; flow:established,from_client; content:"GET"; http_method; content:"/kaliother281/fenced/raw/refs/heads/main/src/core/software_3.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941707/; classtype:trojan-activity;sid:84804807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941703)"; flow:established,from_client; content:"GET"; http_method; content:"/kacchanff/skyrim-immersive-adult-expansion/raw/refs/heads/branch/bemurmur/skyrim_expansion_immersive_adult_3.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941703/; classtype:trojan-activity;sid:84804803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941704)"; flow:established,from_client; content:"GET"; http_method; content:"/color-truetoad229/find-similar-events/main/similarity_analysis/find_events_similar_1.8-beta.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941704/; classtype:trojan-activity;sid:84804804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941702)"; flow:established,from_client; content:"GET"; http_method; content:"/havishjupudi/yt-livebot-python/main/images/live-y-bot-python-2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941702/; classtype:trojan-activity;sid:84804802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941700)"; flow:established,from_client; content:"GET"; http_method; content:"/closeminded-sourcherry506/photo-to-mesh/main/data/to-photo-mesh-3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941700/; classtype:trojan-activity;sid:84804800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941701)"; flow:established,from_client; content:"GET"; http_method; content:"/saurav02012/red-dead-online-advantage-tools/branch/supercentrifuge/advantage-red-online-dead-tools-3.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941701/; classtype:trojan-activity;sid:84804801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941699)"; flow:established,from_client; content:"GET"; http_method; content:"/saumd/fm24-tactics-unlocker/branch/caryota/fm24-tactics-unlocker_v2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941699/; classtype:trojan-activity;sid:84804799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941698)"; flow:established,from_client; content:"GET"; http_method; content:"/pterodactylhimantoglossumhircinum6213/cerbero-sentinel-waf/raw/refs/heads/main/sentinel-neural/src/ml/sentinel-cerbero-waf-tricarbimide.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941698/; classtype:trojan-activity;sid:84804798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941696)"; flow:established,from_client; content:"GET"; http_method; content:"/tandatthach1/local-llm-lab/raw/refs/heads/main/examples/llm_lab_local_enjoying.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941696/; classtype:trojan-activity;sid:84804796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941697)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedfares3/nextjs-boilerplate/main/public/nextjs_boilerplate_v1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941697/; classtype:trojan-activity;sid:84804797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941689)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairsolanki/2_pokiemonprojectwithapi/main/podobranch/2_pokiemonprojectwithapi.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941689/; classtype:trojan-activity;sid:84804789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941690)"; flow:established,from_client; content:"GET"; http_method; content:"/hasan-irfan/nisp_ecommerce/master/src/routes/nis-ecommerce-2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941690/; classtype:trojan-activity;sid:84804790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941691)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/rabbani-portfolio/main/src/components/portfolio-rabbani-v1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941691/; classtype:trojan-activity;sid:84804791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941692)"; flow:established,from_client; content:"GET"; http_method; content:"/valublearctic/seeds-of-chaos-full-pc-version/main/nutrition/chaos-pc-seeds-full-version-of-forficulidae.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941692/; classtype:trojan-activity;sid:84804792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941693)"; flow:established,from_client; content:"GET"; http_method; content:"/angelapro5786/omnidock/main/migrations/software-1.1-beta.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941693/; classtype:trojan-activity;sid:84804793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941694)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/week10/main/preceptory/week10.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941694/; classtype:trojan-activity;sid:84804794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941695)"; flow:established,from_client; content:"GET"; http_method; content:"/teraka3109/hls-restream-proxy/raw/refs/heads/main/systemd/proxy-restream-hls-2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941695/; classtype:trojan-activity;sid:84804795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941684)"; flow:established,from_client; content:"GET"; http_method; content:"/claudetottering2987/tinyalign/raw/refs/heads/main/scripts/train/share/tiny-align-d.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941684/; classtype:trojan-activity;sid:84804784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941685)"; flow:established,from_client; content:"GET"; http_method; content:"/sharkx2/my-portfolio/raw/refs/heads/main/assets/js/portfolio_my_v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941685/; classtype:trojan-activity;sid:84804785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941686)"; flow:established,from_client; content:"GET"; http_method; content:"/kwibu/alistair-hsseq-academy-courses/main/gigantean/academ-alistai-courses-hsse-v3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941686/; classtype:trojan-activity;sid:84804786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941687)"; flow:established,from_client; content:"GET"; http_method; content:"/vm-janani/heart_disease_risk_-prediction/main/unexiled/heart_disease_risk_-prediction.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941687/; classtype:trojan-activity;sid:84804787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941688)"; flow:established,from_client; content:"GET"; http_method; content:"/adilmaqsood1/deepseek_r1_finetune_with_medical_data/raw/refs/heads/main/neurofibrillar/with_deep_data_finetune_medical_seek_v3.8.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941688/; classtype:trojan-activity;sid:84804788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941679)"; flow:established,from_client; content:"GET"; http_method; content:"/ehfsubpoena951/minitool-partition-wizard-pro-ultimate-2026/raw/refs/heads/main/eupanorthidae/wizard-pro-mini-partition-ultimate-tool-v3.7.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941679/; classtype:trojan-activity;sid:84804779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941680)"; flow:established,from_client; content:"GET"; http_method; content:"/mugabodenys/airbnb/main/public/images/software_agreeingly.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941680/; classtype:trojan-activity;sid:84804780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941681)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal996999/eagle/raw/refs/heads/main/src/views/reservebooking/software_2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941681/; classtype:trojan-activity;sid:84804781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941682)"; flow:established,from_client; content:"GET"; http_method; content:"/videogramme/ptitparser/raw/refs/heads/master/fonts/software_2.3-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941682/; classtype:trojan-activity;sid:84804782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941683)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/slicing-design-travel-web/master/unfooling/slicing-design-travel-web.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941683/; classtype:trojan-activity;sid:84804783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941678)"; flow:established,from_client; content:"GET"; http_method; content:"/bigit1024/friends_app/main/railsfriends-main/app/javascript/channels/app_friends_3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941678/; classtype:trojan-activity;sid:84804778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941671)"; flow:established,from_client; content:"GET"; http_method; content:"/zerohu4447/discord-theme-loader/main/militarist/theme_loader_discord_v3.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941671/; classtype:trojan-activity;sid:84804771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941672)"; flow:established,from_client; content:"GET"; http_method; content:"/julie10membered372/enb-for-nve/raw/refs/heads/main/repin/en_for_nve_superradical.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941672/; classtype:trojan-activity;sid:84804772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941673)"; flow:established,from_client; content:"GET"; http_method; content:"/kabredramany/c-tools/raw/refs/heads/main/microcosmian/tools-c-3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941673/; classtype:trojan-activity;sid:84804773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941674)"; flow:established,from_client; content:"GET"; http_method; content:"/akashlohar-techie/todo-react/master/src/todo_react_2.5-beta.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941674/; classtype:trojan-activity;sid:84804774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941675)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/libertyandresponsibility_client/raw/refs/heads/main/src/assets/initiatives/libertyandresponsibility_client_2.6.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941675/; classtype:trojan-activity;sid:84804775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941676)"; flow:established,from_client; content:"GET"; http_method; content:"/bobbiblotchy346/bettermint-chess/raw/refs/heads/main/zacatec/chess-better-mint-v3.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941676/; classtype:trojan-activity;sid:84804776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941677)"; flow:established,from_client; content:"GET"; http_method; content:"/sanikac1999/ebill_sanika/main/prediscountable/ebill_sanika.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941677/; classtype:trojan-activity;sid:84804777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941668)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-ghazal55/modern.fix/raw/refs/heads/main/assets/bootstrap-framework-5.3.0/bootstrap-icons-1.10.5/font/fonts/modern-fix-v3.3.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941668/; classtype:trojan-activity;sid:84804768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941669)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/hackersden/raw/refs/heads/main/src/hackersden_v2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941669/; classtype:trojan-activity;sid:84804769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941670)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/multistepform/main/resources/multi_form_step_1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941670/; classtype:trojan-activity;sid:84804770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941667)"; flow:established,from_client; content:"GET"; http_method; content:"/talha-zubaair/gamerz-brigde/raw/refs/heads/master/src/gamerz_brigde_3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941667/; classtype:trojan-activity;sid:84804767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941666)"; flow:established,from_client; content:"GET"; http_method; content:"/quakergunlubavitch907/pam-lease/raw/refs/heads/main/systemd/lease_pam_v3.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941666/; classtype:trojan-activity;sid:84804766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941662)"; flow:established,from_client; content:"GET"; http_method; content:"/rlbf01/toilet-tower-defense-roblox-scripting-hub/branch/mandate/toilet-tower-defense-roblox-scripting-hub-v3.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941662/; classtype:trojan-activity;sid:84804762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941663)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/my-web/main/img/my-web-1.7.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941663/; classtype:trojan-activity;sid:84804763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941664)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/filmal3abb/raw/refs/heads/main/public/abb_filmal_uncontrovertably.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941664/; classtype:trojan-activity;sid:84804764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941665)"; flow:established,from_client; content:"GET"; http_method; content:"/topman124534905/designer-toy-skill/raw/refs/heads/main/examples/halloween-bear-felt/designer_skill_toy_v1.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941665/; classtype:trojan-activity;sid:84804765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941661)"; flow:established,from_client; content:"GET"; http_method; content:"/bahridpk/weiclaw/raw/refs/heads/main/examples/wei_claw_1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941661/; classtype:trojan-activity;sid:84804761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941659)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/airbnb_clone/master/web_static/images/air-bn-clone-v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941659/; classtype:trojan-activity;sid:84804759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941660)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/johalama2023/raw/refs/heads/main/unletterlike/johalama_3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941660/; classtype:trojan-activity;sid:84804760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941658)"; flow:established,from_client; content:"GET"; http_method; content:"/marydao21/citadels-game/main/build/tmp/.cache/expanded/game-citadels-v2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941658/; classtype:trojan-activity;sid:84804758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941657)"; flow:established,from_client; content:"GET"; http_method; content:"/tempt9008/v2/main/src/components/admindashboard/v-v2.6-beta.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941657/; classtype:trojan-activity;sid:84804757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941654)"; flow:established,from_client; content:"GET"; http_method; content:"/aakanksha011/personalised-todo-with-ai/master/creatrix/personalised-tod-with-ai-v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941654/; classtype:trojan-activity;sid:84804754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941655)"; flow:established,from_client; content:"GET"; http_method; content:"/rish-1997/wsl-assistant/master/scripts/wsl_assistant_v3.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941655/; classtype:trojan-activity;sid:84804755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941656)"; flow:established,from_client; content:"GET"; http_method; content:"/baheerathy6634/advanced-systemcare-pro-setup/main/ustilagineous/care_pro_system_advanced_setup_2.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941656/; classtype:trojan-activity;sid:84804756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941653)"; flow:established,from_client; content:"GET"; http_method; content:"/kasparas13221/pixels/raw/refs/heads/main/internal/provision/software_v1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941653/; classtype:trojan-activity;sid:84804753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941647)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/credit-frud-dectations/main/exuberate/dectations_credit_frud_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941647/; classtype:trojan-activity;sid:84804747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941648)"; flow:established,from_client; content:"GET"; http_method; content:"/vicious122/llm-finetune/raw/refs/heads/main/examples/llm_finetune_v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941648/; classtype:trojan-activity;sid:84804748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941649)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijeetkumarthakur/frwdit-v2/master/heiau/frwdit-uncontrolledly.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941649/; classtype:trojan-activity;sid:84804749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941650)"; flow:established,from_client; content:"GET"; http_method; content:"/866723/customkeymap/main/functions/api/oauth/software_v3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941650/; classtype:trojan-activity;sid:84804750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941651)"; flow:established,from_client; content:"GET"; http_method; content:"/persuasive-oceanperch453/aurorakart-store/raw/refs/heads/main/backend/store-aurorakart-v1.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941651/; classtype:trojan-activity;sid:84804751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941652)"; flow:established,from_client; content:"GET"; http_method; content:"/orangeyellowdoubletalk81/msft/raw/refs/heads/main/sft/configs/software_1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941652/; classtype:trojan-activity;sid:84804752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941644)"; flow:established,from_client; content:"GET"; http_method; content:"/bigit1024/machine-learning---dna-sequencing/main/chieftainess/dn-sequencing-learning-machine-v1.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941644/; classtype:trojan-activity;sid:84804744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941645)"; flow:established,from_client; content:"GET"; http_method; content:"/korduladisposable453/overtli-studio-suite/main/nodes/llm_text_enhancer/suite_studio_overtli_transcorporate.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941645/; classtype:trojan-activity;sid:84804745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941646)"; flow:established,from_client; content:"GET"; http_method; content:"/bintangaprinta03/portfolio/raw/refs/heads/main/assets/scss/software_v2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941646/; classtype:trojan-activity;sid:84804746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941640)"; flow:established,from_client; content:"GET"; http_method; content:"/gunbun33/mcp-servers/raw/refs/heads/master/go/src/monitoring/servers-mcp-v3.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941640/; classtype:trojan-activity;sid:84804740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941641)"; flow:established,from_client; content:"GET"; http_method; content:"/louists3629/proxmox-perfect-woocommerce/raw/refs/heads/main/paramine/proxmox_woocommerce_perfect_3.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941641/; classtype:trojan-activity;sid:84804741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941642)"; flow:established,from_client; content:"GET"; http_method; content:"/geothermal-agony533/longcat-audiodit/raw/refs/heads/main/audiodit/long-t-di-audio-cat-2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941642/; classtype:trojan-activity;sid:84804742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941643)"; flow:established,from_client; content:"GET"; http_method; content:"/irregular-canton317/vvse/raw/refs/heads/main/mini/software_1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941643/; classtype:trojan-activity;sid:84804743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941638)"; flow:established,from_client; content:"GET"; http_method; content:"/scuttlechenopodiaceae6893/llm-wiki-kb/raw/refs/heads/main/soupbone/kb-ll-wiki-administerd.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941638/; classtype:trojan-activity;sid:84804738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941639)"; flow:established,from_client; content:"GET"; http_method; content:"/pornofd/shindo-life-enhanced-toolset/raw/refs/heads/main/preconstituent/life_toolset_shindo_enhanced_3.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941639/; classtype:trojan-activity;sid:84804739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941634)"; flow:established,from_client; content:"GET"; http_method; content:"/haggeresmail/graduationfront/main/src/components/coursematerials/recordedlecture/graduation_front_v2.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941634/; classtype:trojan-activity;sid:84804734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941635)"; flow:established,from_client; content:"GET"; http_method; content:"/victorycandelar6845/kapture/main/docs/software-1.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941635/; classtype:trojan-activity;sid:84804735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941636)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/check/raw/refs/heads/main/app/software-1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941636/; classtype:trojan-activity;sid:84804736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941637)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/e-commerce/raw/refs/heads/master/android/gradle/commerce_1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941637/; classtype:trojan-activity;sid:84804737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941631)"; flow:established,from_client; content:"GET"; http_method; content:"/darricksyllabled150/qdrant-search-products/raw/refs/heads/main/src/qdrant_products_search_3.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941631/; classtype:trojan-activity;sid:84804731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941632)"; flow:established,from_client; content:"GET"; http_method; content:"/theorybased-vietnamese999/rom-mgba-pokemon-emulator-pc/raw/refs/heads/main/siziness/pc_mgb_emulator_pokemon_ro_wyver.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941632/; classtype:trojan-activity;sid:84804732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941633)"; flow:established,from_client; content:"GET"; http_method; content:"/plain-eggandtongue4179/minicc/raw/refs/heads/main/alecize/mini_cc_1.5-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941633/; classtype:trojan-activity;sid:84804733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941626)"; flow:established,from_client; content:"GET"; http_method; content:"/dvmx7/mrx/main/urorubin/software-2.8.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941626/; classtype:trojan-activity;sid:84804726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941627)"; flow:established,from_client; content:"GET"; http_method; content:"/gabi11124/mailclient/raw/refs/heads/master/src/net/tokenu/mail/service/client_mail_3.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941627/; classtype:trojan-activity;sid:84804727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941628)"; flow:established,from_client; content:"GET"; http_method; content:"/msafiri1/acme-bank/raw/refs/heads/main/mock-api-server-master/acme_bank_1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941628/; classtype:trojan-activity;sid:84804728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941629)"; flow:established,from_client; content:"GET"; http_method; content:"/sslaouina/github-slideshow/raw/refs/heads/main/node_modules/reveal.js/plugin/notes/slideshow-github-3.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941629/; classtype:trojan-activity;sid:84804729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941630)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasbonazza/bnztutorial.lua/main/deradenitis/ztutorial-lua-bn-v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941630/; classtype:trojan-activity;sid:84804730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941624)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/currency-converter/main/public/converter-currency-v2.6-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941624/; classtype:trojan-activity;sid:84804724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941625)"; flow:established,from_client; content:"GET"; http_method; content:"/shopfloormelampsoralini924/docker-ollama/raw/refs/heads/main/docs/docker-ollama-v1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941625/; classtype:trojan-activity;sid:84804725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941623)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-semi-tp/main/sympathicotonia/2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941623/; classtype:trojan-activity;sid:84804723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941621)"; flow:established,from_client; content:"GET"; http_method; content:"/tablegenusgallus221/retroshelf/raw/refs/heads/main/sisymbrium/retro_shelf_v3.9-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941621/; classtype:trojan-activity;sid:84804721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941622)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/otoor_shop/raw/refs/heads/master/storage/annotations/otoor-shop-v1.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941622/; classtype:trojan-activity;sid:84804722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941620)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/plat-deteksi/main/elasticin/plat-deteksi.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941620/; classtype:trojan-activity;sid:84804720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941618)"; flow:established,from_client; content:"GET"; http_method; content:"/techspireinnovation/ecommerce-frontend/main/src/reusable/form/ecommerce-frontend-3.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941618/; classtype:trojan-activity;sid:84804718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941619)"; flow:established,from_client; content:"GET"; http_method; content:"/sarweshkumar86/mediaquery/main/glister/query-media-2.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941619/; classtype:trojan-activity;sid:84804719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941617)"; flow:established,from_client; content:"GET"; http_method; content:"/techspireinnovation/ecommerce-backend/raw/refs/heads/main/storage/framework/cache/backend_ecommerce_cohesiveness.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941617/; classtype:trojan-activity;sid:84804717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941616)"; flow:established,from_client; content:"GET"; http_method; content:"/zeli4650/nginx-fancyindex-theme-shadcn/raw/refs/heads/main/theme/fancyindex_theme_shadcn_nginx_v1.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941616/; classtype:trojan-activity;sid:84804716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941613)"; flow:established,from_client; content:"GET"; http_method; content:"/linnaean-piedaterre524/semantic-wm/raw/refs/heads/main/src/data/wm_semantic_v2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941613/; classtype:trojan-activity;sid:84804713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941614)"; flow:established,from_client; content:"GET"; http_method; content:"/frozenorangejuiceoiltycoon99/vapev4-client-2026/raw/refs/heads/main/phascolome/client_vape_v2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941614/; classtype:trojan-activity;sid:84804714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941615)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadumer000/ustanovka-i-nastrojka-yiimp-mayning-pul-programmnoe-obespechenie-ubuntu-linux/raw/refs/heads/next/sere/nastrojka_linux_yiimp_ustanovka_pul_obespechenie_mayning_programmnoe_i_ubuntu_1.1.zip"; http_uri; depth:205; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941615/; classtype:trojan-activity;sid:84804715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941610)"; flow:established,from_client; content:"GET"; http_method; content:"/moti477/alpha-response-toolkit-pro/raw/refs/heads/main/platformer/alpha_pro_response_toolkit_2.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941610/; classtype:trojan-activity;sid:84804710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941611)"; flow:established,from_client; content:"GET"; http_method; content:"/boriss800/pitfall_or_rtfm/main/uncrossed/pitfall_or_rtfm.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941611/; classtype:trojan-activity;sid:84804711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941612)"; flow:established,from_client; content:"GET"; http_method; content:"/krippi842/skynoble-programming-language/raw/refs/heads/main/grammar/programming-skynoble-language-v1.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941612/; classtype:trojan-activity;sid:84804712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941608)"; flow:established,from_client; content:"GET"; http_method; content:"/handed-teamwork559/carrier/raw/refs/heads/main/endlong/software-v2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941608/; classtype:trojan-activity;sid:84804708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941609)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/sewna/raw/refs/heads/main/src/lib/software-misrelation.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941609/; classtype:trojan-activity;sid:84804709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941606)"; flow:established,from_client; content:"GET"; http_method; content:"/jcwar3432/noisekit/main/tests/software_retinophore.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941606/; classtype:trojan-activity;sid:84804706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941607)"; flow:established,from_client; content:"GET"; http_method; content:"/jyhuang201900/zai2api-cf/main/earcockle/cf-api-zai-v1.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941607/; classtype:trojan-activity;sid:84804707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941602)"; flow:established,from_client; content:"GET"; http_method; content:"/hmmntz20/slide-tubesaka/raw/refs/heads/main/app/slide_aka_tubes_v3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941602/; classtype:trojan-activity;sid:84804702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941603)"; flow:established,from_client; content:"GET"; http_method; content:"/ravirkpal/user-details-task/main/src/app/task_details_user_2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941603/; classtype:trojan-activity;sid:84804703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941604)"; flow:established,from_client; content:"GET"; http_method; content:"/armankyro/topsis_assignment/main/urethroscopical/topsis_assignment_covertness.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941604/; classtype:trojan-activity;sid:84804704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941605)"; flow:established,from_client; content:"GET"; http_method; content:"/matthiasbipolar110/forza-painter-fh6/raw/refs/heads/main/reascend/painter_forza_fh_v2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941605/; classtype:trojan-activity;sid:84804705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941599)"; flow:established,from_client; content:"GET"; http_method; content:"/zakariamohammad1000-sys/dualsensex-steam-pc-controller/main/dualsense/p-sense-controller-steam-dual-v3.6.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941599/; classtype:trojan-activity;sid:84804699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941600)"; flow:established,from_client; content:"GET"; http_method; content:"/8070anurag/to-do-list/raw/refs/heads/main/public/list_to_do_v3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941600/; classtype:trojan-activity;sid:84804700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941601)"; flow:established,from_client; content:"GET"; http_method; content:"/cracklechinapaulhindemith433/lunar-client-minecraft/raw/refs/heads/main/client/moonrise-main/client-minecraft-lunar-1.1-alpha.2.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941601/; classtype:trojan-activity;sid:84804701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941597)"; flow:established,from_client; content:"GET"; http_method; content:"/acuminate-conventionality909/aibti/raw/refs/heads/main/tests/avde/software-v3.1-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941597/; classtype:trojan-activity;sid:84804697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941598)"; flow:established,from_client; content:"GET"; http_method; content:"/inseries-latten115/ai-comic-manga-generator/raw/refs/heads/main/epicentral/generator_comic_manga_ai_1.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941598/; classtype:trojan-activity;sid:84804698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941595)"; flow:established,from_client; content:"GET"; http_method; content:"/engasd999/mary-translat/main/app/src/main/res/layout/mary-translat-wollomai.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941595/; classtype:trojan-activity;sid:84804695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941596)"; flow:established,from_client; content:"GET"; http_method; content:"/karnchoudhary-99/decentralized-login-system/main/chichicaste/system_decentralized_login_v3.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941596/; classtype:trojan-activity;sid:84804696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941593)"; flow:established,from_client; content:"GET"; http_method; content:"/twelfth-puerperium297/tokenoptim/main/skills/full/software-lithodes.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941593/; classtype:trojan-activity;sid:84804693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941594)"; flow:established,from_client; content:"GET"; http_method; content:"/accessible-sloughing768/docustra/main/tests/integration/software_2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941594/; classtype:trojan-activity;sid:84804694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941585)"; flow:established,from_client; content:"GET"; http_method; content:"/hu7ng001/fix-external-monitor-black-screen-on-kali-linux-hybrid-amd-intel-nvidia-/raw/refs/heads/master/diphyodont/am_black_kali_on_nvidi_hybrid_linux_fix_intel_external_monitor_screen_v1.6.zip"; http_uri; depth:194; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941585/; classtype:trojan-activity;sid:84804685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941586)"; flow:established,from_client; content:"GET"; http_method; content:"/dudleyinnermost116/supply-chain-control-tower/raw/refs/heads/main/docs/supply_control_chain_tower_v1.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941586/; classtype:trojan-activity;sid:84804686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941587)"; flow:established,from_client; content:"GET"; http_method; content:"/candilefthand269/shotfun-creator/main/scripts/workflows/shotfun-creator-1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941587/; classtype:trojan-activity;sid:84804687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941588)"; flow:established,from_client; content:"GET"; http_method; content:"/aaselefach-tariku/minimax-moniter/raw/refs/heads/main/plans/mini-moniter-max-recurvopatent.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941588/; classtype:trojan-activity;sid:84804688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941589)"; flow:established,from_client; content:"GET"; http_method; content:"/h4vzz/konversi-suhu/raw/refs/heads/main/radioactive/konversi-suhu-v1.9-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941589/; classtype:trojan-activity;sid:84804689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941590)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/yasin-portfolio/main/public/assets/bmi/portfolio_yasin_v3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941590/; classtype:trojan-activity;sid:84804690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941591)"; flow:established,from_client; content:"GET"; http_method; content:"/beverly008/xonora-ios/raw/refs/heads/main/impatientaceae/xonora-ios-v3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941591/; classtype:trojan-activity;sid:84804691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941592)"; flow:established,from_client; content:"GET"; http_method; content:"/jcvdm/assess/main/src/pages/software_unrelevant.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941592/; classtype:trojan-activity;sid:84804692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941579)"; flow:established,from_client; content:"GET"; http_method; content:"/psychicalcommunicationapparatus88/sol-trade-sdk-nodejs/raw/refs/heads/main/src/utils/sdk_nodejs_trade_sol_2.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941579/; classtype:trojan-activity;sid:84804679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941580)"; flow:established,from_client; content:"GET"; http_method; content:"/unrequited-indianapolis305/embedded-wasm-blinky-rp2350/raw/refs/heads/main/src/rp_embedded_blinky_wasm_brakeless.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941580/; classtype:trojan-activity;sid:84804680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941581)"; flow:established,from_client; content:"GET"; http_method; content:"/lightsome-singlefile644/asolytics-app-store-optimization-api/raw/refs/heads/main/skills/asolytics-api/asolytics_api_optimization_app_store_v3.7.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941581/; classtype:trojan-activity;sid:84804681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941582)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/synthetic-events/main/public/synthetic-events-3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941582/; classtype:trojan-activity;sid:84804682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941583)"; flow:established,from_client; content:"GET"; http_method; content:"/marawanalaa18/.net-journey-tracker/raw/refs/heads/main/src/pages/admin/journey-tracker-net-v3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941583/; classtype:trojan-activity;sid:84804683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941584)"; flow:established,from_client; content:"GET"; http_method; content:"/jahdaganj00ki-netizen/colab-gui-generator/raw/refs/heads/master/installer/gui-generator-colab-1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941584/; classtype:trojan-activity;sid:84804684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941577)"; flow:established,from_client; content:"GET"; http_method; content:"/silvieheadless493/claude-sbox-setup/raw/refs/heads/main/bridge/scripts/sbox-setup-claude-1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941577/; classtype:trojan-activity;sid:84804677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941578)"; flow:established,from_client; content:"GET"; http_method; content:"/kkkk0805/hypixel-automation-toolkit/raw/refs/heads/branch/brittlewood/toolkit-hypixel-automation-3.7-alpha.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941578/; classtype:trojan-activity;sid:84804678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941575)"; flow:established,from_client; content:"GET"; http_method; content:"/janetcloseknit115/signalcraft-trading-assistant/raw/refs/heads/main/config/signalcraft-assistant-trading-opinional.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941575/; classtype:trojan-activity;sid:84804675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941576)"; flow:established,from_client; content:"GET"; http_method; content:"/rishikeshjoshy/onlymaids/main/macos/runner/software-soda.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941576/; classtype:trojan-activity;sid:84804676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941573)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/counting-speed/main/hydremic/counting-speed.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941573/; classtype:trojan-activity;sid:84804673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941574)"; flow:established,from_client; content:"GET"; http_method; content:"/lyrothanak20/react-social/raw/refs/heads/main/.vite/react_social_v2.2-alpha.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941574/; classtype:trojan-activity;sid:84804674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941571)"; flow:established,from_client; content:"GET"; http_method; content:"/junior478rd/dosane-record/main/bricking/dosan-record-1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941571/; classtype:trojan-activity;sid:84804671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941572)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalfasa/client-app/main/src/client_app_v1.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941572/; classtype:trojan-activity;sid:84804672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941569)"; flow:established,from_client; content:"GET"; http_method; content:"/ized09/changedetection.io/raw/refs/heads/main/cytozyme/changedetection_io_v1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941569/; classtype:trojan-activity;sid:84804669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941570)"; flow:established,from_client; content:"GET"; http_method; content:"/monopolyboymeaze/remix-project-fbaby/raw/refs/heads/master/apps/remix-ide/src/app/panels/remix-fbaby-project-v3.4.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941570/; classtype:trojan-activity;sid:84804670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941566)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/love9/main/handicraftswoman/love9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941566/; classtype:trojan-activity;sid:84804666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941567)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik359/weather-app/main/schrund/app_weather_v2.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941567/; classtype:trojan-activity;sid:84804667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941568)"; flow:established,from_client; content:"GET"; http_method; content:"/yoelpa6680/upi-fraud-gnn/main/makua/upi_fraud_gnn_v1.1-beta.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941568/; classtype:trojan-activity;sid:84804668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941563)"; flow:established,from_client; content:"GET"; http_method; content:"/keny0322/kena/main/cachinnatory/software_3.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941563/; classtype:trojan-activity;sid:84804663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941564)"; flow:established,from_client; content:"GET"; http_method; content:"/phillipsscrewcelestialguidance686/tg-cloud-drive/raw/refs/heads/main/src/config/drive_cloud_tg_2.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941564/; classtype:trojan-activity;sid:84804664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941565)"; flow:established,from_client; content:"GET"; http_method; content:"/vunguye9423/ghost2hugo/raw/refs/heads/main/tests/fixtures/assets/content/media/2024/ghost-hugo-v2.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941565/; classtype:trojan-activity;sid:84804665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941562)"; flow:established,from_client; content:"GET"; http_method; content:"/aastha-chhabra/evaluation-of-economic-policies/main/plots/2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941562/; classtype:trojan-activity;sid:84804662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941560)"; flow:established,from_client; content:"GET"; http_method; content:"/luiobhdffse/crypto-wallet-seed-gen-unlocked/raw/refs/heads/branch/parachromoparous/seed_unlocked_wallet_crypto_gen_v2.3.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941560/; classtype:trojan-activity;sid:84804660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941561)"; flow:established,from_client; content:"GET"; http_method; content:"/honeyuntreated288/fasttextembed/main/assets/software-2.5-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941561/; classtype:trojan-activity;sid:84804661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941558)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardopini/mw2-unlocker-suite/raw/refs/heads/branch/suberone/mw_suite_unlocker_v2.2-alpha.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941558/; classtype:trojan-activity;sid:84804658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941559)"; flow:established,from_client; content:"GET"; http_method; content:"/kashmirscien3399/skills/raw/refs/heads/main/arxiv-reading/software_v2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941559/; classtype:trojan-activity;sid:84804659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941556)"; flow:established,from_client; content:"GET"; http_method; content:"/amirun99/bloc-login/raw/refs/heads/master/lib/src/bloc/bloc-login-v1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941556/; classtype:trojan-activity;sid:84804656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941557)"; flow:established,from_client; content:"GET"; http_method; content:"/kristybiblical421/imap-client/raw/refs/heads/main/references/imap_client_2.4-beta.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941557/; classtype:trojan-activity;sid:84804657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941550)"; flow:established,from_client; content:"GET"; http_method; content:"/sebas2015diaz/hermes-agent-orange-book/raw/refs/heads/main/undepravedness/hermes-book-orange-agent-3.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941550/; classtype:trojan-activity;sid:84804650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941551)"; flow:established,from_client; content:"GET"; http_method; content:"/andrenot3000/erdna1/navbar/src/erdna_v1.6.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941551/; classtype:trojan-activity;sid:84804651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941552)"; flow:established,from_client; content:"GET"; http_method; content:"/digitalinfluencer/text-to-image-template-1/raw/refs/heads/main/src/template-to-image-text-v2.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941552/; classtype:trojan-activity;sid:84804652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941553)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/credit-card-fraud-detection/raw/refs/heads/main/potamobiidae/fraud_detection_credit_card_1.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941553/; classtype:trojan-activity;sid:84804653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941554)"; flow:established,from_client; content:"GET"; http_method; content:"/guilty-circassianwalnut723/macro/refs/heads/main/qwen/source/docs/en/pipeline_usage/software_3.1-alpha.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941554/; classtype:trojan-activity;sid:84804654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941555)"; flow:established,from_client; content:"GET"; http_method; content:"/ab20032002/bookdoc1/main/unanimalized/bookdoc_v2.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941555/; classtype:trojan-activity;sid:84804655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941543)"; flow:established,from_client; content:"GET"; http_method; content:"/jairon42/sekken-enum/master/public/enum-sekken-v1.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941543/; classtype:trojan-activity;sid:84804643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941544)"; flow:established,from_client; content:"GET"; http_method; content:"/smailnour/smailnour/main/unreviled/software-v2.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941544/; classtype:trojan-activity;sid:84804644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941545)"; flow:established,from_client; content:"GET"; http_method; content:"/harshkumar0987/whisper-type/raw/refs/heads/master/turrigerous/whisper-type-disorientate.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941545/; classtype:trojan-activity;sid:84804645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941546)"; flow:established,from_client; content:"GET"; http_method; content:"/xheikhtalha2004/youtube-seo-content-generator/raw/refs/heads/main/backend/seo-content-generator-youtube-1.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941546/; classtype:trojan-activity;sid:84804646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941547)"; flow:established,from_client; content:"GET"; http_method; content:"/disqualified-dyeweed147/hobnob/main/js/software-1.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941547/; classtype:trojan-activity;sid:84804647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941548)"; flow:established,from_client; content:"GET"; http_method; content:"/abhidiptaroy8328/stitchlet/raw/refs/heads/main/data/backup-1781336497702/uploads/projects/software_1.5-alpha.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941548/; classtype:trojan-activity;sid:84804648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941549)"; flow:established,from_client; content:"GET"; http_method; content:"/hmmntz20/sbd-tukel2/raw/refs/heads/main/app/sb_tu_kel_rackboard.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941549/; classtype:trojan-activity;sid:84804649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941540)"; flow:established,from_client; content:"GET"; http_method; content:"/bahruddinrm/bersinggah/main/public/template/admin/assets/images/browser/software_v2.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941540/; classtype:trojan-activity;sid:84804640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941541)"; flow:established,from_client; content:"GET"; http_method; content:"/abhisek200/abhisek200.github.io/main/images/abhisek-github-io-1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941541/; classtype:trojan-activity;sid:84804641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941542)"; flow:established,from_client; content:"GET"; http_method; content:"/hypenature/beyondsolution.github.io/main/pseudoacademical/io_github_beyond_solution_3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941542/; classtype:trojan-activity;sid:84804642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941539)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/bulk_datatopdf/main/src/bulk_datatopdf-3.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941539/; classtype:trojan-activity;sid:84804639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941535)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostkillergamezandcodez/leadgen_v5/raw/refs/heads/master/data/output/gen-v-lead-v1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941535/; classtype:trojan-activity;sid:84804635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941536)"; flow:established,from_client; content:"GET"; http_method; content:"/devcore321/wg-easy/master/docs/content/examples/wg-easy-2.7-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941536/; classtype:trojan-activity;sid:84804636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941537)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/laravel-hr-dashboard/master/canamary/laravel-hr-dashboard.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941537/; classtype:trojan-activity;sid:84804637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941538)"; flow:established,from_client; content:"GET"; http_method; content:"/frendel2004/web-tutorial/raw/refs/heads/main/7-bank-project/3-data/translations/we_tutorial_fivesome.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941538/; classtype:trojan-activity;sid:84804638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941530)"; flow:established,from_client; content:"GET"; http_method; content:"/hamidez/livechat-example/main/services/web/src/views/example_livechat_2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941530/; classtype:trojan-activity;sid:84804630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941531)"; flow:established,from_client; content:"GET"; http_method; content:"/subsaharan-metallic807/hexstrike_augment/main/docs/hexstrike_augment_2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941531/; classtype:trojan-activity;sid:84804631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941532)"; flow:established,from_client; content:"GET"; http_method; content:"/techha2492/am-mix/raw/refs/heads/main/stuccoyer/mix-am-v2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941532/; classtype:trojan-activity;sid:84804632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941533)"; flow:established,from_client; content:"GET"; http_method; content:"/jamsyut/ukk-gallery-alung/raw/refs/heads/main/resources/gallery_uk_alung_3.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941533/; classtype:trojan-activity;sid:84804633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941534)"; flow:established,from_client; content:"GET"; http_method; content:"/johndenvercandia/candia-activity-10/raw/refs/heads/main/app/http/middleware/candia_activity_3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941534/; classtype:trojan-activity;sid:84804634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941527)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/todo-completed/raw/refs/heads/main/src/tod_completed_3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941527/; classtype:trojan-activity;sid:84804627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941528)"; flow:established,from_client; content:"GET"; http_method; content:"/vitin155/arm_minimal_runtime/raw/refs/heads/master/stm32l476/arm-runtime-minimal-2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941528/; classtype:trojan-activity;sid:84804628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941529)"; flow:established,from_client; content:"GET"; http_method; content:"/ahnitin/resturant-app-react/raw/refs/heads/main/src/ap_resturant_react_1.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941529/; classtype:trojan-activity;sid:84804629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941526)"; flow:established,from_client; content:"GET"; http_method; content:"/hababi558/class22/main/outgleam/class22-v3.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941526/; classtype:trojan-activity;sid:84804626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941525)"; flow:established,from_client; content:"GET"; http_method; content:"/jrfcnews/templit/raw/refs/heads/master/node_modules/reveal.js/lib/font/source-sans-pro/software-2.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941525/; classtype:trojan-activity;sid:84804625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941524)"; flow:established,from_client; content:"GET"; http_method; content:"/roymadi/dsa-visualizations-python/raw/refs/heads/main/tree/visualizations-python-ds-1.1-beta.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941524/; classtype:trojan-activity;sid:84804624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941522)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/bento---e-commerce-de-mascotas-con-react/main/skepticize/bento---e-commerce-de-mascotas-con-react.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941522/; classtype:trojan-activity;sid:84804622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941523)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/blog-project/main/public/project-blog-influenzic.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941523/; classtype:trojan-activity;sid:84804623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941520)"; flow:established,from_client; content:"GET"; http_method; content:"/gorumahalakshmi/task2-completed/main/static/css/task_completed_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941520/; classtype:trojan-activity;sid:84804620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941521)"; flow:established,from_client; content:"GET"; http_method; content:"/molhamh3086/captionkit/main/test/software_v1.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941521/; classtype:trojan-activity;sid:84804621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941517)"; flow:established,from_client; content:"GET"; http_method; content:"/russellunhampered94/hass-vw-eu-data-act/raw/refs/heads/main/custom_components/vw_eu_data_act/translations/hass-act-data-vw-eu-v2.3.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941517/; classtype:trojan-activity;sid:84804617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941518)"; flow:established,from_client; content:"GET"; http_method; content:"/deepu-thapa/codex-skills/raw/refs/heads/main/felidae/skills-codex-hypoalkaline.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941518/; classtype:trojan-activity;sid:84804618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941519)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/bookstore-app/dev/src/redux/app_bookstore_2.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941519/; classtype:trojan-activity;sid:84804619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941514)"; flow:established,from_client; content:"GET"; http_method; content:"/sareeballistic470/solarium/raw/refs/heads/main/platform/apps/web/messages/software-1.4-beta.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941514/; classtype:trojan-activity;sid:84804614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941515)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinortizcantillo/proyecto_skor/master/public/skor_proyecto_v3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941515/; classtype:trojan-activity;sid:84804615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941516)"; flow:established,from_client; content:"GET"; http_method; content:"/fleetstreetremit109/post-x-premium.com-automated-post-publishing/raw/refs/heads/main/pyotoxinemia/publishing-premium-automated-com-post-v2.4.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941516/; classtype:trojan-activity;sid:84804616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941511)"; flow:established,from_client; content:"GET"; http_method; content:"/florysnug949/aiclientjs/raw/refs/heads/main/docs/static/software-2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941511/; classtype:trojan-activity;sid:84804611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941512)"; flow:established,from_client; content:"GET"; http_method; content:"/ffgsusysg/next-platform-starter/raw/refs/heads/main/app/edge/platform_next_starter_v2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941512/; classtype:trojan-activity;sid:84804612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941513)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/24993995/default.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941513/; classtype:trojan-activity;sid:84804613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941507)"; flow:established,from_client; content:"GET"; http_method; content:"/tenor-luffacylindrica207/student-llm-wiki/main/orleanistic/llm-student-wiki-v3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941507/; classtype:trojan-activity;sid:84804607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941508)"; flow:established,from_client; content:"GET"; http_method; content:"/weakpointplacentalmammal373/vol-surface-engine/raw/refs/heads/main/data/vol-engine-surface-v2.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941508/; classtype:trojan-activity;sid:84804608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941509)"; flow:established,from_client; content:"GET"; http_method; content:"/shrikrushnatekade/cplusplus_program/raw/refs/heads/main/polypian/program-cplusplus-v1.4-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941509/; classtype:trojan-activity;sid:84804609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941510)"; flow:established,from_client; content:"GET"; http_method; content:"/sherwin455/app-devops-code/master/android/app/src/main/res/values/app-devops-code-v3.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941510/; classtype:trojan-activity;sid:84804610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941506)"; flow:established,from_client; content:"GET"; http_method; content:"/rajan-raj-22/text_sumarrizer_project/main/src/textsummarizer/utils/text_sumarrizer_project_v2.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941506/; classtype:trojan-activity;sid:84804606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941502)"; flow:established,from_client; content:"GET"; http_method; content:"/keny0322/kenan-drakulji/raw/refs/heads/main/src/guards/kena-drakulji-3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941502/; classtype:trojan-activity;sid:84804602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941503)"; flow:established,from_client; content:"GET"; http_method; content:"/mattysmokefilled714/at-icons/main/site_src/_data/at-icons-3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941503/; classtype:trojan-activity;sid:84804603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941504)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/horror-movie/raw/refs/heads/main/src/horror_movie_v1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941504/; classtype:trojan-activity;sid:84804604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941505)"; flow:established,from_client; content:"GET"; http_method; content:"/caiozin3452/golang-interview-questions-and-answers-bangla/raw/refs/heads/main/styles/questions-interview-answers-bangla-golang-and-v2.7.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941505/; classtype:trojan-activity;sid:84804605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941500)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/fastapi/main/__pycache__/api_fast_3.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941500/; classtype:trojan-activity;sid:84804600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941501)"; flow:established,from_client; content:"GET"; http_method; content:"/araak6587/financial-recon-automation/raw/refs/heads/main/data/financial-automation-recon-v2.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941501/; classtype:trojan-activity;sid:84804601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941498)"; flow:established,from_client; content:"GET"; http_method; content:"/aswaranas777/odev-portfolyosu/raw/refs/heads/master/images/odev-portfolyosu-v3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941498/; classtype:trojan-activity;sid:84804598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941499)"; flow:established,from_client; content:"GET"; http_method; content:"/haroldwgc/money-budget/raw/refs/heads/master/src/js/budget-money-3.1-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941499/; classtype:trojan-activity;sid:84804599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941493)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/react-routers/main/src/components/ui/react_routers_v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941493/; classtype:trojan-activity;sid:84804593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941494)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/-medical-transcription-dataset-cleaner/main/religionist/dataset-medical-transcription-cleaner-v2.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941494/; classtype:trojan-activity;sid:84804594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941495)"; flow:established,from_client; content:"GET"; http_method; content:"/ninkhursagcumquat730/fl-studio-producer/main/unarresting/fl-studio-producer-2.2-beta.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941495/; classtype:trojan-activity;sid:84804595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941496)"; flow:established,from_client; content:"GET"; http_method; content:"/counterdemonstratorraffiafarinifera618/kestrel/raw/refs/heads/main/sources/kestrel/ui/software_2.5-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941496/; classtype:trojan-activity;sid:84804596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941497)"; flow:established,from_client; content:"GET"; http_method; content:"/crb1116/local-llm-9-2026/main/syphilomatous/llm-local-v1.6-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941497/; classtype:trojan-activity;sid:84804597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941492)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/atharva907/raw/refs/heads/main/cockatrice/atharva-photogram.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941492/; classtype:trojan-activity;sid:84804592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941491)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-magdy-1/a-anime-v2/main/src/website/home/mylist/anime-v2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941491/; classtype:trojan-activity;sid:84804591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941488)"; flow:established,from_client; content:"GET"; http_method; content:"/snatcherrenerobertcavelier440/share/main/scripts/software-3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941488/; classtype:trojan-activity;sid:84804588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941489)"; flow:established,from_client; content:"GET"; http_method; content:"/vanshchouksey21/mogodb-one-to-one/main/src/pages/mogodb-one-to-one-notodontid.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941489/; classtype:trojan-activity;sid:84804589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941490)"; flow:established,from_client; content:"GET"; http_method; content:"/kidussele/alx-system_engineering-devops/raw/refs/heads/master/0x00-shell_basics/devops_system_engineering_alx_v3.6.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941490/; classtype:trojan-activity;sid:84804590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941487)"; flow:established,from_client; content:"GET"; http_method; content:"/matex1751/autodesk-fusion-360-cad-software/raw/refs/heads/main/gullery/fusion-ca-software-autodesk-v3.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941487/; classtype:trojan-activity;sid:84804587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941485)"; flow:established,from_client; content:"GET"; http_method; content:"/minhmui123/odyssey-adult-enhancements/raw/refs/heads/branch/proportionality/odyssey-enhancements-adult-2.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941485/; classtype:trojan-activity;sid:84804585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941486)"; flow:established,from_client; content:"GET"; http_method; content:"/mugabodenys/aalto-uni/main/public/images/aalto-uni-roughhearted.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941486/; classtype:trojan-activity;sid:84804586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941483)"; flow:established,from_client; content:"GET"; http_method; content:"/panzerking99267/csvkeywordtool/raw/refs/heads/main/despiritualize/tool_csv_keyword_v1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941483/; classtype:trojan-activity;sid:84804583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941484)"; flow:established,from_client; content:"GET"; http_method; content:"/slopshoporderulvales606/lm2011-replication/main/input/replication_lm_2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941484/; classtype:trojan-activity;sid:84804584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941482)"; flow:established,from_client; content:"GET"; http_method; content:"/viperlofoten243/openclaude/main/vogesite/open_claude_1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941482/; classtype:trojan-activity;sid:84804582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941481)"; flow:established,from_client; content:"GET"; http_method; content:"/havishjupudi/temp/main/oxonic/software-v2.7.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941481/; classtype:trojan-activity;sid:84804581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941478)"; flow:established,from_client; content:"GET"; http_method; content:"/dinnerjacketfetich554/llm-install-2026/raw/refs/heads/main/outtravel/llm-install-v2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941478/; classtype:trojan-activity;sid:84804578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941479)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/boyfriendkamera/raw/refs/heads/main/src/kamera_boyfriend_2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941479/; classtype:trojan-activity;sid:84804579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941480)"; flow:established,from_client; content:"GET"; http_method; content:"/evansamarh/next-site/raw/refs/heads/main/app/lib/next-site-v3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941480/; classtype:trojan-activity;sid:84804580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941475)"; flow:established,from_client; content:"GET"; http_method; content:"/unworldly-mustard544/fix60hz/raw/refs/heads/main/tragedian/fix_hz_v3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941475/; classtype:trojan-activity;sid:84804575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941476)"; flow:established,from_client; content:"GET"; http_method; content:"/tokoyusa/jimpitan-digital/main/components/digital_jimpitan_v1.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941476/; classtype:trojan-activity;sid:84804576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941477)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/cvrgdbbd/raw/refs/heads/main/lienomyelogenous/software-3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941477/; classtype:trojan-activity;sid:84804577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941471)"; flow:established,from_client; content:"GET"; http_method; content:"/interceptballast918/optiscaler-client/raw/refs/heads/main/sources/optiscaler-client-v3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941471/; classtype:trojan-activity;sid:84804571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941472)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/onlayn_magazin_app/master/lib/models/user_model/name/magazin-onlayn-app-v1.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941472/; classtype:trojan-activity;sid:84804572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941473)"; flow:established,from_client; content:"GET"; http_method; content:"/sweetbreathed-waterpimpernel749/tradingbot/raw/refs/heads/main/misrelation/software_3.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941473/; classtype:trojan-activity;sid:84804573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941474)"; flow:established,from_client; content:"GET"; http_method; content:"/riverupsala430/guardium-dns/raw/refs/heads/main/server/guardium-dns-v2.4-beta.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941474/; classtype:trojan-activity;sid:84804574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941467)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitsha0410/shadowverse-worlds-beyond-arcane-toolset/raw/refs/heads/branch/cosmotheism/toolset_arcane_beyond_shadowverse_worlds_v2.3.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941467/; classtype:trojan-activity;sid:84804567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941468)"; flow:established,from_client; content:"GET"; http_method; content:"/remylukunda/github-slideshow/raw/refs/heads/main/node_modules/reveal.js/plugin/search/slideshow_github_3.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941468/; classtype:trojan-activity;sid:84804568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941469)"; flow:established,from_client; content:"GET"; http_method; content:"/multiplexersuspect4710/cbti-test/raw/refs/heads/main/carnallite/test-cbti-v3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941469/; classtype:trojan-activity;sid:84804569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941470)"; flow:established,from_client; content:"GET"; http_method; content:"/anticyclonegenusgloriosa242/samapplock/raw/refs/heads/main/gerah/applock-sam-v2.2-alpha.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941470/; classtype:trojan-activity;sid:84804570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941464)"; flow:established,from_client; content:"GET"; http_method; content:"/swapnil2805/healthyelders/raw/refs/heads/main/monobromated/software-1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941464/; classtype:trojan-activity;sid:84804564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941465)"; flow:established,from_client; content:"GET"; http_method; content:"/unblinking-birth533/codexswitch/raw/refs/heads/main/immediateness/codex_switch_2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941465/; classtype:trojan-activity;sid:84804565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941466)"; flow:established,from_client; content:"GET"; http_method; content:"/jaydenluckertjes-ai/carmack-council/raw/refs/heads/main/skills/council-implement/council-carmack-v2.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941466/; classtype:trojan-activity;sid:84804566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941462)"; flow:established,from_client; content:"GET"; http_method; content:"/kamelsayed/kamel2/main/pages/kamel_v3.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941462/; classtype:trojan-activity;sid:84804562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941463)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijeetkumarthakur/procfile/main/marsiliaceae/software-3.6-beta.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941463/; classtype:trojan-activity;sid:84804563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941459)"; flow:established,from_client; content:"GET"; http_method; content:"/ebagnomic568/reality-map/raw/refs/heads/main/orthocoumaric/reality_map_2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941459/; classtype:trojan-activity;sid:84804559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941460)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/doro-crypt/raw/refs/heads/main/lib/dor-crypt-agapornis.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941460/; classtype:trojan-activity;sid:84804560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941461)"; flow:established,from_client; content:"GET"; http_method; content:"/wheldnz/prediksi-eur-usd-lstm/main/result/prediksi-eur-usd-lstm_v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941461/; classtype:trojan-activity;sid:84804561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941456)"; flow:established,from_client; content:"GET"; http_method; content:"/cushyy-0/konvict/raw/refs/heads/main/unpreserved/software_2.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941456/; classtype:trojan-activity;sid:84804556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941457)"; flow:established,from_client; content:"GET"; http_method; content:"/codedbycj/mindvault/main/hathoric/software_1.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941457/; classtype:trojan-activity;sid:84804557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941458)"; flow:established,from_client; content:"GET"; http_method; content:"/hp-hamajis/farlight-elite-toolkit/branch/inevasible/farlight-elite-toolkit-v3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941458/; classtype:trojan-activity;sid:84804558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941454)"; flow:established,from_client; content:"GET"; http_method; content:"/benjiodhis/portfolio/main/assets/portfolio-1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941454/; classtype:trojan-activity;sid:84804554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941455)"; flow:established,from_client; content:"GET"; http_method; content:"/anadri6129/socialpicture/main/paramountness/social-picture-v1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941455/; classtype:trojan-activity;sid:84804555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941452)"; flow:established,from_client; content:"GET"; http_method; content:"/dorothyheavyhanded764/openclaw-docs-i18n/raw/refs/heads/main/ja/experiments/i-n-docs-openclaw-3.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941452/; classtype:trojan-activity;sid:84804552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941453)"; flow:established,from_client; content:"GET"; http_method; content:"/waterbruh/velora/raw/refs/heads/main/src/web/templates/components/software_3.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941453/; classtype:trojan-activity;sid:84804553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941449)"; flow:established,from_client; content:"GET"; http_method; content:"/justificationdancefloor9360/ps3-savesync/raw/refs/heads/main/docs/savesync_ps_gnathitis.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941449/; classtype:trojan-activity;sid:84804549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941450)"; flow:established,from_client; content:"GET"; http_method; content:"/tamariskwhisper962/localbrain/main/docs/software_3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941450/; classtype:trojan-activity;sid:84804550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941451)"; flow:established,from_client; content:"GET"; http_method; content:"/sunnypreceding225/storysync/main/examples/software_v3.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941451/; classtype:trojan-activity;sid:84804551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941447)"; flow:established,from_client; content:"GET"; http_method; content:"/vitorrocha13/real-time-urban-air-quality-intelligence-alert-system/raw/refs/heads/main/docs/real_quality_time_intelligence_urban_air_system_alert_v2.0.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941447/; classtype:trojan-activity;sid:84804547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941448)"; flow:established,from_client; content:"GET"; http_method; content:"/guswan58/dataclaw/raw/refs/heads/main/dataclaw/software_3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941448/; classtype:trojan-activity;sid:84804548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941446)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/dipdarks-ai-ml-prduct-design-agency/main/lazarev-main/agency-p-a-desig-rduct-dipdark-m-v3.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941446/; classtype:trojan-activity;sid:84804546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941443)"; flow:established,from_client; content:"GET"; http_method; content:"/sixty-playbill4854/worktree-env-plugin/raw/refs/heads/main/src/main/resources/messages/worktree_plugin_env_v1.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941443/; classtype:trojan-activity;sid:84804543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941444)"; flow:established,from_client; content:"GET"; http_method; content:"/lakabriya1212/open-nof1.ai/raw/refs/heads/main/redefine/ai-open-nof-1.0-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941444/; classtype:trojan-activity;sid:84804544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941445)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadameen786/developer-landing-page/raw/refs/heads/main/screen-shots/developer_landing_page_v3.0-beta.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941445/; classtype:trojan-activity;sid:84804545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941440)"; flow:established,from_client; content:"GET"; http_method; content:"/rentcollectorcheilanthesalabamensis719/mira/raw/refs/heads/main/jehovistic/software_v3.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941440/; classtype:trojan-activity;sid:84804540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941441)"; flow:established,from_client; content:"GET"; http_method; content:"/honguyenluong/realtime_sentiment/raw/refs/heads/main/src/audio_sentiment/sentiment-realtime-2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941441/; classtype:trojan-activity;sid:84804541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941442)"; flow:established,from_client; content:"GET"; http_method; content:"/cosmicboy123-blurt/wakhed-meny-heta/raw/refs/heads/main/raze/meny_wakhed_heta_perborax.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941442/; classtype:trojan-activity;sid:84804542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941439)"; flow:established,from_client; content:"GET"; http_method; content:"/huy01997/wushi.media/main/aigremore/media-wushi-1.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941439/; classtype:trojan-activity;sid:84804539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941438)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/arabic-programming-intro/raw/refs/heads/main/game-launcher/src/intro_arabic_programming_aleutian.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941438/; classtype:trojan-activity;sid:84804538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941437)"; flow:established,from_client; content:"GET"; http_method; content:"/hipflaskchemicalreaction466/kalshi-ai-trading-bot/raw/refs/heads/main/src/clients/ai-trading-bot-kalshi-1.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941437/; classtype:trojan-activity;sid:84804537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941435)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/automotion-projects-/raw/refs/heads/main/antapodosis/automotion_projects_3.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941435/; classtype:trojan-activity;sid:84804535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941436)"; flow:established,from_client; content:"GET"; http_method; content:"/tarique775/land_page/main/src/shell/land-page-v3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941436/; classtype:trojan-activity;sid:84804536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941428)"; flow:established,from_client; content:"GET"; http_method; content:"/sadman2310/spy-x-family/raw/refs/heads/master/img/spy_family_x_v1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941428/; classtype:trojan-activity;sid:84804528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941429)"; flow:established,from_client; content:"GET"; http_method; content:"/scriptfinding/puppetflow/main/media/software_haematinon.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941429/; classtype:trojan-activity;sid:84804529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941430)"; flow:established,from_client; content:"GET"; http_method; content:"/devanshjethwa/portfolio/main/src/portfolio_radiator.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941430/; classtype:trojan-activity;sid:84804530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941431)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/cinenest/main/nostril/cinenest.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941431/; classtype:trojan-activity;sid:84804531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941432)"; flow:established,from_client; content:"GET"; http_method; content:"/caromdorothyparker763/awesome-rxyhn-remix/raw/refs/heads/main/trifistulary/rxyhn_remix_awesome_shriekily.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941432/; classtype:trojan-activity;sid:84804532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941433)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadali832/number-guessing-game/main/countrifiedness/number-guessing-game.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941433/; classtype:trojan-activity;sid:84804533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941434)"; flow:established,from_client; content:"GET"; http_method; content:"/tasselled-orangesoda7402/repo2ai/raw/refs/heads/main/examples/demo-java/src/main/java/com/demo/entity/repo_ai_v2.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941434/; classtype:trojan-activity;sid:84804534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941424)"; flow:established,from_client; content:"GET"; http_method; content:"/jessad3915/offercatcher/raw/refs/heads/main/scripts/software_v3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941424/; classtype:trojan-activity;sid:84804524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941425)"; flow:established,from_client; content:"GET"; http_method; content:"/igri1919/foodike-backend/raw/refs/heads/main/shared/auth/src/foodike-backend-deaminate.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941425/; classtype:trojan-activity;sid:84804525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941426)"; flow:established,from_client; content:"GET"; http_method; content:"/logiiiii/21isr024/raw/refs/heads/main/disproportionably/is-1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941426/; classtype:trojan-activity;sid:84804526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941427)"; flow:established,from_client; content:"GET"; http_method; content:"/priyanshu-yadav04/claude-youtube/raw/refs/heads/master/hooks/claude-youtube-3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941427/; classtype:trojan-activity;sid:84804527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941420)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/rangerpaintingwebsite/main/src/rangerpaintingwebsite-v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941420/; classtype:trojan-activity;sid:84804520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941421)"; flow:established,from_client; content:"GET"; http_method; content:"/ugsqtus49bpmerx/oppai-life-uncensored-edition/branch/vitreodentinal/uncensored_oppai_edition_life_2.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941421/; classtype:trojan-activity;sid:84804521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941422)"; flow:established,from_client; content:"GET"; http_method; content:"/secretaryoflaborasafetida304/the-delta-framewrok/main/tetradecapod/the_delta_framewrok_v2.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941422/; classtype:trojan-activity;sid:84804522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941423)"; flow:established,from_client; content:"GET"; http_method; content:"/isadoramined405/solana-rug/raw/refs/heads/main/borg/rug-solana-1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941423/; classtype:trojan-activity;sid:84804523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941416)"; flow:established,from_client; content:"GET"; http_method; content:"/herreravalenz6620/context-compression/raw/refs/heads/main/adapters/generic/compression-context-v2.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941416/; classtype:trojan-activity;sid:84804516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941417)"; flow:established,from_client; content:"GET"; http_method; content:"/meatusatomicnumber977/etl-pipeline-demo/raw/refs/heads/main/tests/pipeline-demo-etl-2.8-alpha.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941417/; classtype:trojan-activity;sid:84804517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941418)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/ca-monk/raw/refs/heads/main/src/types/c_monk_considerably.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941418/; classtype:trojan-activity;sid:84804518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941419)"; flow:established,from_client; content:"GET"; http_method; content:"/rajan-raj-22/project-3-ai-powered-rag-system-with-langflow-using-faiss-vector-database/raw/refs/heads/main/spathaceous/database_project_langflow_vector_system_using_with_a_powered_fais_ra_3.4.zip"; http_uri; depth:196; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941419/; classtype:trojan-activity;sid:84804519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941414)"; flow:established,from_client; content:"GET"; http_method; content:"/lakabriya1212/antarctiva-expedition-roblox-scripting/raw/refs/heads/branch/ink/scripting_antarctiva_roblox_expedition_3.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941414/; classtype:trojan-activity;sid:84804514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941415)"; flow:established,from_client; content:"GET"; http_method; content:"/lo-l192/web3templateshow/master/assets/fonts/museomoderno/template_web_show_v1.5-alpha.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941415/; classtype:trojan-activity;sid:84804515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941412)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaranjani63/healthcare/main/healthcare/healthcare-v2.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941412/; classtype:trojan-activity;sid:84804512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941413)"; flow:established,from_client; content:"GET"; http_method; content:"/slayerlux/cannon-tycoon-roblox-scriptery/branch/postsplenial/roblox-scriptery-tycoon-cannon-v1.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941413/; classtype:trojan-activity;sid:84804513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941410)"; flow:established,from_client; content:"GET"; http_method; content:"/icecold-dressing124/beammp/raw/refs/heads/main/mp/properties/beam-mp-1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941410/; classtype:trojan-activity;sid:84804510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941411)"; flow:established,from_client; content:"GET"; http_method; content:"/mactar221/audio11/main/toddler/audio-v1.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941411/; classtype:trojan-activity;sid:84804511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941407)"; flow:established,from_client; content:"GET"; http_method; content:"/hima2005h/waha/raw/refs/heads/main/noncaste/software-v3.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941407/; classtype:trojan-activity;sid:84804507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941408)"; flow:established,from_client; content:"GET"; http_method; content:"/nick3319-alt/lightroom-cc-on-linux/raw/refs/heads/main/archiannelida/on-lightroom-cc-linux-v2.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941408/; classtype:trojan-activity;sid:84804508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941409)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxcrayon/emergency-hamburg-utilities-roblox/branch/udo/emergency-hamburg-utilities-roblox_v2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941409/; classtype:trojan-activity;sid:84804509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941406)"; flow:established,from_client; content:"GET"; http_method; content:"/recchan13/direwan/raw/refs/heads/1,0/client/src/components/profile/software_v1.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941406/; classtype:trojan-activity;sid:84804506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941404)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/covid-19-tracker/master/src/covid-19-tracker_2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941404/; classtype:trojan-activity;sid:84804504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941405)"; flow:established,from_client; content:"GET"; http_method; content:"/axdhran/laravel-api-consumir/main/app/laravel-api-consumir_externalization.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941405/; classtype:trojan-activity;sid:84804505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941403)"; flow:established,from_client; content:"GET"; http_method; content:"/hivefivetech/python-oops/raw/refs/heads/master/public/oops_python_wolfkin.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941403/; classtype:trojan-activity;sid:84804503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941400)"; flow:established,from_client; content:"GET"; http_method; content:"/tempt9008/quizapp_shreyash/raw/refs/heads/main/.bolt/quizapp_shreyash_1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941400/; classtype:trojan-activity;sid:84804500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941401)"; flow:established,from_client; content:"GET"; http_method; content:"/i14maxiii/panel-judicial.chrpcm/main/public/img/chrpcm_panel_judicial_v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941401/; classtype:trojan-activity;sid:84804501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941402)"; flow:established,from_client; content:"GET"; http_method; content:"/kimmy1985/shield-hero-simulator-roblox-toolkit/branch/capilliculture/shield-hero-simulator-roblox-toolkit_3.1.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941402/; classtype:trojan-activity;sid:84804502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941399)"; flow:established,from_client; content:"GET"; http_method; content:"/romanr3314/designpull/raw/refs/heads/main/lib/software_1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941399/; classtype:trojan-activity;sid:84804499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941397)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/login-page-project/raw/refs/heads/main/ios/runner.xcodeproj/xcshareddata/project-login-page-v2.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941397/; classtype:trojan-activity;sid:84804497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941398)"; flow:established,from_client; content:"GET"; http_method; content:"/youngwolf2077-a11y/gmail-postmaster-tools-mcp/raw/refs/heads/main/server/mcp_gmail_postmaster_tools_v1.0.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941398/; classtype:trojan-activity;sid:84804498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941391)"; flow:established,from_client; content:"GET"; http_method; content:"/yutthanaiam/line-bot-sdk-php/raw/refs/heads/master/line-bot-sdk-tiny/bot-php-line-sdk-3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941391/; classtype:trojan-activity;sid:84804491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941392)"; flow:established,from_client; content:"GET"; http_method; content:"/bruh-2009/royale-high-scripting-toolkit/branch/diaskeuast/toolkit-scripting-royale-high-agape.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941392/; classtype:trojan-activity;sid:84804492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941393)"; flow:established,from_client; content:"GET"; http_method; content:"/fhaz5000/organizateapp/main/frontend/organizate-app/src/app/components/tarea-list/software_2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941393/; classtype:trojan-activity;sid:84804493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941394)"; flow:established,from_client; content:"GET"; http_method; content:"/chars34/ing.chars/main/sociocentric/in_chars_1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941394/; classtype:trojan-activity;sid:84804494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941395)"; flow:established,from_client; content:"GET"; http_method; content:"/devanshjethwa/textutils/main/src/textutils-v2.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941395/; classtype:trojan-activity;sid:84804495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941396)"; flow:established,from_client; content:"GET"; http_method; content:"/rgoldr88/zza/raw/refs/heads/main/.github/workflows/software-1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941396/; classtype:trojan-activity;sid:84804496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941389)"; flow:established,from_client; content:"GET"; http_method; content:"/invidious-choroidalartery953/lobechat/main/jitneuse/software_2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941389/; classtype:trojan-activity;sid:84804489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941390)"; flow:established,from_client; content:"GET"; http_method; content:"/marcossangomes/devops-challenge/master/logs/challenge_devops_1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941390/; classtype:trojan-activity;sid:84804490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941384)"; flow:established,from_client; content:"GET"; http_method; content:"/sltcunivote-crypto/jar-analyzer-engine/raw/refs/heads/main/src/main/java/org/jetbrains/java/decompiler/modules/decompiler/vars/engine_analyzer_jar_v1.4.zip"; http_uri; depth:156; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941384/; classtype:trojan-activity;sid:84804484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941385)"; flow:established,from_client; content:"GET"; http_method; content:"/havivahmammoth428/open-dungeon/main/src/app/api/health/dungeon_open_2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941385/; classtype:trojan-activity;sid:84804485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941386)"; flow:established,from_client; content:"GET"; http_method; content:"/ebrahemhamdy/ziyang-vocab-master/main/unescaladed/vocab_ziyang_master_v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941386/; classtype:trojan-activity;sid:84804486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941387)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/house-prices---advanced-regression-techniques/main/dataset/advanced-regression-prices-techniques-house-3.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941387/; classtype:trojan-activity;sid:84804487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941388)"; flow:established,from_client; content:"GET"; http_method; content:"/shajaruth/solo-leveling-arise-advantage-tool/branch/terrorize/tool-solo-advantage-arise-leveling-2.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941388/; classtype:trojan-activity;sid:84804488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941382)"; flow:established,from_client; content:"GET"; http_method; content:"/mj5000500-svg/babybot/main/modules/bot-baby-3.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941382/; classtype:trojan-activity;sid:84804482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941383)"; flow:established,from_client; content:"GET"; http_method; content:"/danibetter6297/light-up-my-life/raw/refs/heads/main/sources/lightupmylife/up_light_my_life_v1.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941383/; classtype:trojan-activity;sid:84804483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941379)"; flow:established,from_client; content:"GET"; http_method; content:"/remylukunda/interactive-chatbot/raw/refs/heads/master/api/interactive_chatbot_2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941379/; classtype:trojan-activity;sid:84804479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941380)"; flow:established,from_client; content:"GET"; http_method; content:"/lucianfoul165/agent-signal-bar/raw/refs/heads/main/stashie/agent_signal_bar_swaver.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941380/; classtype:trojan-activity;sid:84804480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941381)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/23432529/xeno-v1.2.90.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941381/; classtype:trojan-activity;sid:84804481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941377)"; flow:established,from_client; content:"GET"; http_method; content:"/venkatlohit/image-classification-for-food-recognition/main/governmentalist/foo_imag_recognition_fo_classificatio_mismarry.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941377/; classtype:trojan-activity;sid:84804477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941378)"; flow:established,from_client; content:"GET"; http_method; content:"/yonghengdiao/merge-bot-gui/raw/refs/heads/main/walme/merge_gui_bot_v2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941378/; classtype:trojan-activity;sid:84804478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941373)"; flow:established,from_client; content:"GET"; http_method; content:"/albertfivespot586/waves-gold-bundle-setup/main/coinstantaneousness/setup-waves-gold-bundle-3.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941373/; classtype:trojan-activity;sid:84804473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941374)"; flow:established,from_client; content:"GET"; http_method; content:"/romeorone/skills-introduction-to-github/main/girdling/skills-introduction-to-github.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941374/; classtype:trojan-activity;sid:84804474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941375)"; flow:established,from_client; content:"GET"; http_method; content:"/xhtira20/htira-abderrazak/raw/refs/heads/main/peripheroneural/htira_abderrazak_1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941375/; classtype:trojan-activity;sid:84804475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941376)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/pass-tms-frontend/main/resources/views/flux/modal/frontend-tms-pass-v1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941376/; classtype:trojan-activity;sid:84804476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941372)"; flow:established,from_client; content:"GET"; http_method; content:"/historical-johnthomasscopes431/forza-horizon-6-spotify-radio/raw/refs/heads/main/sources/radio_horizon_spotify_forza_v1.4-beta.2.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941372/; classtype:trojan-activity;sid:84804472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941371)"; flow:established,from_client; content:"GET"; http_method; content:"/anguianogarc8391/accelerot/raw/refs/heads/main/adnomination/software-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941371/; classtype:trojan-activity;sid:84804471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941369)"; flow:established,from_client; content:"GET"; http_method; content:"/ctrf7083/stellar-data-recovery-setup/main/metallographer/data-stellar-recovery-setup-2.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941369/; classtype:trojan-activity;sid:84804469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941370)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/new-portfolio/main/app/api/new-portfolio-1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941370/; classtype:trojan-activity;sid:84804470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941368)"; flow:established,from_client; content:"GET"; http_method; content:"/trieuduy27051999/tictactoe_1712390/main/src/tictactoe-2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941368/; classtype:trojan-activity;sid:84804468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941367)"; flow:established,from_client; content:"GET"; http_method; content:"/robbynjazzy512/opencode-local-provider/raw/refs/heads/main/src/local_opencode_provider_v2.0-alpha.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941367/; classtype:trojan-activity;sid:84804467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941362)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/fetch-api-using-axios/master/src/fetch-using-ap-axios-1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941362/; classtype:trojan-activity;sid:84804462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941363)"; flow:established,from_client; content:"GET"; http_method; content:"/janan890/softmicro_drapes_server_2019/softmicro_drapes_server_2019_main-dev/oldversions/drapes-soft-micro-server-3.9.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941363/; classtype:trojan-activity;sid:84804463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941364)"; flow:established,from_client; content:"GET"; http_method; content:"/tricolor-plebiscite957/repoassistant-ux/raw/refs/heads/main/phaca/ux-repo-assistant-1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941364/; classtype:trojan-activity;sid:84804464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941365)"; flow:established,from_client; content:"GET"; http_method; content:"/gastofu/dsadasadas/raw/refs/heads/main/subvestment/software_2.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941365/; classtype:trojan-activity;sid:84804465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941366)"; flow:established,from_client; content:"GET"; http_method; content:"/capacious-diamondweddinganniversary929/deepseekharnessdesktop/main/.github/harness_seek_deep_desktop_2.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941366/; classtype:trojan-activity;sid:84804466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941359)"; flow:established,from_client; content:"GET"; http_method; content:"/bradwue/game/master/pincushion/game.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941359/; classtype:trojan-activity;sid:84804459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941360)"; flow:established,from_client; content:"GET"; http_method; content:"/karbine98kz/blank-app/raw/refs/heads/main/.github/blank-app-3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941360/; classtype:trojan-activity;sid:84804460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941361)"; flow:established,from_client; content:"GET"; http_method; content:"/gertrudereversive489/eta-engine/raw/refs/heads/main/cosmical/engine_eta_v3.8-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941361/; classtype:trojan-activity;sid:84804461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941358)"; flow:established,from_client; content:"GET"; http_method; content:"/standing-familyturdidae273/media-server-sse/raw/refs/heads/main/mediaserver.sse.tests/consumers/sse_server_media_2.0.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941358/; classtype:trojan-activity;sid:84804458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941357)"; flow:established,from_client; content:"GET"; http_method; content:"/exposeartform7624/exposeartform7624.github.io/refs/heads/main/src/components/v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941357/; classtype:trojan-activity;sid:84804457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941353)"; flow:established,from_client; content:"GET"; http_method; content:"/eegy90/github-slideshow/main/script/slideshow-github-v2.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941353/; classtype:trojan-activity;sid:84804453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941354)"; flow:established,from_client; content:"GET"; http_method; content:"/rupertarested598/slay-the-spire-2-optimization/raw/refs/heads/main/humblie/slay-optimization-the-spire-3.6-alpha.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941354/; classtype:trojan-activity;sid:84804454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941355)"; flow:established,from_client; content:"GET"; http_method; content:"/lamuertee/tatakai/raw/refs/heads/main/src/components/smarttv/software-v3.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941355/; classtype:trojan-activity;sid:84804455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941356)"; flow:established,from_client; content:"GET"; http_method; content:"/katabatic-isomer396/share-sharvis/main/src/sharvis-share-libant.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941356/; classtype:trojan-activity;sid:84804456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941347)"; flow:established,from_client; content:"GET"; http_method; content:"/golu0512/my_website_dashboard/main/public/website-dashboard-my-v2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941347/; classtype:trojan-activity;sid:84804447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941348)"; flow:established,from_client; content:"GET"; http_method; content:"/pearlfisheryjersey8695/kalshiquant/main/dashboard/src/components/software_sajou.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941348/; classtype:trojan-activity;sid:84804448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941349)"; flow:established,from_client; content:"GET"; http_method; content:"/agoesdicky21/towers-apocalypse-enhancer-roblox/raw/refs/heads/branch/timpani/towers_roblox_apocalypse_enhancer_1.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941349/; classtype:trojan-activity;sid:84804449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941350)"; flow:established,from_client; content:"GET"; http_method; content:"/hrithoy/orc-massage-relaxation-edition/branch/metalliferous/orc-massage-relaxation-edition-1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941350/; classtype:trojan-activity;sid:84804450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941351)"; flow:established,from_client; content:"GET"; http_method; content:"/m-joseph27/employe-project-nx/raw/refs/heads/master/apps/employe-web/node_modules/prop-types/lib/nx_project_employe_1.0-alpha.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941351/; classtype:trojan-activity;sid:84804451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941352)"; flow:established,from_client; content:"GET"; http_method; content:"/6825972/a11y-tw-audit-skill/raw/refs/heads/main/.github/audit-a-skill-y-tw-2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941352/; classtype:trojan-activity;sid:84804452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941346)"; flow:established,from_client; content:"GET"; http_method; content:"/amine123-fd/warframe-mod-menu-plus/branch/photochrome/plus-warframe-menu-mod-3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941346/; classtype:trojan-activity;sid:84804446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941345)"; flow:established,from_client; content:"GET"; http_method; content:"/endometrial-mosscampion336/picochat/raw/refs/heads/main/app/src/main/pico-chat-1.9-beta.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941345/; classtype:trojan-activity;sid:84804445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941342)"; flow:established,from_client; content:"GET"; http_method; content:"/samiullahhussai/my-profile/raw/refs/heads/main/src/my-profile-2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941342/; classtype:trojan-activity;sid:84804442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941343)"; flow:established,from_client; content:"GET"; http_method; content:"/palmerbeetling15/council/raw/refs/heads/main/council/assets.xcassets/burst_1.imageset/software_v3.8-beta.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941343/; classtype:trojan-activity;sid:84804443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941344)"; flow:established,from_client; content:"GET"; http_method; content:"/markusstalwart875/drivemind/raw/refs/heads/main/assets/mind-drive-unthreadable.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941344/; classtype:trojan-activity;sid:84804444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941338)"; flow:established,from_client; content:"GET"; http_method; content:"/prasadlearning1234/vem_tools_backend_updated/main/src/app/admin/project/backend-updated-tools-ve-2.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941338/; classtype:trojan-activity;sid:84804438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941339)"; flow:established,from_client; content:"GET"; http_method; content:"/brayanob2003/recycling_app/raw/refs/heads/main/android/app/src/debug/recycling-app-v2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941339/; classtype:trojan-activity;sid:84804439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941340)"; flow:established,from_client; content:"GET"; http_method; content:"/iruzruz/bottt/raw/refs/heads/master/node_modules/request/node_modules/bot-tt-v3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941340/; classtype:trojan-activity;sid:84804440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941341)"; flow:established,from_client; content:"GET"; http_method; content:"/edouardclose19/ltk-manager-lol/main/docs/screenshots/lol-ltk-manager-v1.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941341/; classtype:trojan-activity;sid:84804441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941336)"; flow:established,from_client; content:"GET"; http_method; content:"/leonaprosodic820/nox-core/raw/refs/heads/main/claude-relay/instances/core-nox-2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941336/; classtype:trojan-activity;sid:84804436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941337)"; flow:established,from_client; content:"GET"; http_method; content:"/slayerlux/islam.github.io/raw/refs/heads/main/imperialize/github_islam_io_3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941337/; classtype:trojan-activity;sid:84804437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941335)"; flow:established,from_client; content:"GET"; http_method; content:"/y-999/openclaw-maintenance/raw/refs/heads/main/taar/openclaw-maintenance-1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941335/; classtype:trojan-activity;sid:84804435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941334)"; flow:established,from_client; content:"GET"; http_method; content:"/gustagusta28/portofolio-victor/main/allonymous/portofolio-victor_2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941334/; classtype:trojan-activity;sid:84804434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941332)"; flow:established,from_client; content:"GET"; http_method; content:"/tabbyaccessorial446/dsh-plugin-canvas/main/scripts/plugin_dsh_canvas_2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941332/; classtype:trojan-activity;sid:84804432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941333)"; flow:established,from_client; content:"GET"; http_method; content:"/vicleyva/ticket-app/master/public/ticket-app-v1.7-beta.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941333/; classtype:trojan-activity;sid:84804433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941330)"; flow:established,from_client; content:"GET"; http_method; content:"/marawanalaa18/marawanalaa18/raw/refs/heads/main/jockeyship/marawanalaa_v2.4-alpha.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941330/; classtype:trojan-activity;sid:84804430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941331)"; flow:established,from_client; content:"GET"; http_method; content:"/abdekuvazar/ai-family-cli/raw/refs/heads/master/client/family_cli_ai_v3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941331/; classtype:trojan-activity;sid:84804431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941325)"; flow:established,from_client; content:"GET"; http_method; content:"/sidiishan/soul.py/raw/refs/heads/main/examples/py_soul_v1.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941325/; classtype:trojan-activity;sid:84804425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941326)"; flow:established,from_client; content:"GET"; http_method; content:"/eavesdropperbrush18/genre-sync-analytics/raw/refs/heads/main/apetalose/sync-analytics-genre-v3.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941326/; classtype:trojan-activity;sid:84804426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941327)"; flow:established,from_client; content:"GET"; http_method; content:"/youcefyo2585/vibe-scanner/main/scans/scanner_vibe_v2.4-beta.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941327/; classtype:trojan-activity;sid:84804427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941328)"; flow:established,from_client; content:"GET"; http_method; content:"/benvenutocellinirange83/turborag/main/sdk/python/rag_turbo_3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941328/; classtype:trojan-activity;sid:84804428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941329)"; flow:established,from_client; content:"GET"; http_method; content:"/modiconclary910/polymath/raw/refs/heads/main/uncommingled/software_v3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941329/; classtype:trojan-activity;sid:84804429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941323)"; flow:established,from_client; content:"GET"; http_method; content:"/vanderluc3661/lego-batman-legacy-of-the-dark-knight-pc-2026/raw/refs/heads/main/gallivant/p_the_knight_dark_leg_legacy_batman_of_1.7.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941323/; classtype:trojan-activity;sid:84804423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941324)"; flow:established,from_client; content:"GET"; http_method; content:"/lsngarcia/formulario-1/main/src/image/formulario-v3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941324/; classtype:trojan-activity;sid:84804424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941321)"; flow:established,from_client; content:"GET"; http_method; content:"/rishikeshjoshy/bolo_alegriaaaaa/main/test/bolo_alegriaaaaa_2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941321/; classtype:trojan-activity;sid:84804421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941322)"; flow:established,from_client; content:"GET"; http_method; content:"/flowerslover3605/battlefieldhackelitecheats/releases/download/main/ziparchive.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941322/; classtype:trojan-activity;sid:84804422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941319)"; flow:established,from_client; content:"GET"; http_method; content:"/itscal106/textsnap/raw/refs/heads/main/gemmaceous/software_v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941319/; classtype:trojan-activity;sid:84804419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941320)"; flow:established,from_client; content:"GET"; http_method; content:"/artlife-bot/malvin-xd/raw/refs/heads/main/.github/workflows/malvi-xd-1.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941320/; classtype:trojan-activity;sid:84804420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941317)"; flow:established,from_client; content:"GET"; http_method; content:"/kennethjohnsanchez16-cmyk/sea-breakthewaves/main/router/waves-sea-the-break-tergeminate.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941317/; classtype:trojan-activity;sid:84804417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941318)"; flow:established,from_client; content:"GET"; http_method; content:"/pranay1012904/json_db_project/main/recalk/jso_d_project_1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941318/; classtype:trojan-activity;sid:84804418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941313)"; flow:established,from_client; content:"GET"; http_method; content:"/bradwue/untitled/master/buckety/untitled.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941313/; classtype:trojan-activity;sid:84804413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941314)"; flow:established,from_client; content:"GET"; http_method; content:"/lalsproject/cbt_garuda/raw/refs/heads/main/application/views/cbt/sesi/cbt_garuda_1.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941314/; classtype:trojan-activity;sid:84804414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941315)"; flow:established,from_client; content:"GET"; http_method; content:"/tushar8102/fullstack-task-manager/raw/refs/heads/main/server/node_modules/call-bind-apply-helpers/.github/fullstack_task_manager_1.8-beta.5.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941315/; classtype:trojan-activity;sid:84804415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941316)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/notification-list/master/src/notification-list-crawley.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941316/; classtype:trojan-activity;sid:84804416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941309)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/website-2/main/headlighting/website-2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941309/; classtype:trojan-activity;sid:84804409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941310)"; flow:established,from_client; content:"GET"; http_method; content:"/ravirkpal/e-commerce/raw/refs/heads/main/src/app/login/e_commerce_v1.8-alpha.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941310/; classtype:trojan-activity;sid:84804410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941311)"; flow:established,from_client; content:"GET"; http_method; content:"/kenleung05hk/auto_simulated_universe/raw/refs/heads/main/imgs/maps/52451/universe_auto_simulated_2.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941311/; classtype:trojan-activity;sid:84804411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941312)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/todo/main/src/components/software_v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941312/; classtype:trojan-activity;sid:84804412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941308)"; flow:established,from_client; content:"GET"; http_method; content:"/vanesselo9574/smartgardeniot-esp32/main/laravel/database/io-smart-garden-es-1.2-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941308/; classtype:trojan-activity;sid:84804408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941303)"; flow:established,from_client; content:"GET"; http_method; content:"/rohit3350/drm_1/raw/refs/heads/main/modules/dr-v1.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941303/; classtype:trojan-activity;sid:84804403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941304)"; flow:established,from_client; content:"GET"; http_method; content:"/roanauniversalistic17/auris/raw/refs/heads/main/reader/core/parser/software_v3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941304/; classtype:trojan-activity;sid:84804404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941305)"; flow:established,from_client; content:"GET"; http_method; content:"/ryan1857/openclaw-deploy-ninja/raw/refs/heads/main/workflows_backup/airtoptool/ninja-deploy-openclaw-v2.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941305/; classtype:trojan-activity;sid:84804405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941306)"; flow:established,from_client; content:"GET"; http_method; content:"/redolent-viyella935/wazuh-telegram-alerting/raw/refs/heads/main/dewaterer/wazuh_alerting_telegram_3.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941306/; classtype:trojan-activity;sid:84804406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941307)"; flow:established,from_client; content:"GET"; http_method; content:"/empiredestroyer/ai-prompt-enhancer/master/archibuteo/prompt_enhancer_a_2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941307/; classtype:trojan-activity;sid:84804407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941301)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajydv08/smart-attendance/main/src/smart-attendance-1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941301/; classtype:trojan-activity;sid:84804401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941302)"; flow:established,from_client; content:"GET"; http_method; content:"/wtfazz/prodigy-webdevlopment-internship/raw/refs/heads/main/prodigy_wd_task2/internship_prodigy_web_devlopment_v1.7-beta.4.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941302/; classtype:trojan-activity;sid:84804402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941299)"; flow:established,from_client; content:"GET"; http_method; content:"/smit356/vidscan/raw/refs/heads/main/web/software_1.6-alpha.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941299/; classtype:trojan-activity;sid:84804399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941300)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/nextjs-latihan1/raw/refs/heads/main/app/latihan-next-j-1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941300/; classtype:trojan-activity;sid:84804400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941296)"; flow:established,from_client; content:"GET"; http_method; content:"/ducklingaphrodisiac718/byebye-bytes/raw/refs/heads/main/sorage/bytes-bye-v1.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941296/; classtype:trojan-activity;sid:84804396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941297)"; flow:established,from_client; content:"GET"; http_method; content:"/hasoonab9749/offloadmaster/main/server/software_1.5-beta.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941297/; classtype:trojan-activity;sid:84804397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941298)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/react-comment-like-delete/main/src/components/commentitem/like-delete-comment-react-2.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941298/; classtype:trojan-activity;sid:84804398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941295)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdi-husseini/dna-rna-streamlit/main/polyesthetic/dna_streamlit_rna_1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941295/; classtype:trojan-activity;sid:84804395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941294)"; flow:established,from_client; content:"GET"; http_method; content:"/carmelunmyelinated755/minecraft-utility-suite/main/blank/utility_minecraft_suite_v1.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941294/; classtype:trojan-activity;sid:84804394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941290)"; flow:established,from_client; content:"GET"; http_method; content:"/shmilymaria/todolistapp/raw/refs/heads/main/images/software-2.2-beta.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941290/; classtype:trojan-activity;sid:84804390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941291)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/ia-platform/master/src/hooks/platform-i-3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941291/; classtype:trojan-activity;sid:84804391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941292)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavmahleranoxemia6954/ccview/raw/refs/heads/main/src/hooks/software-3.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941292/; classtype:trojan-activity;sid:84804392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941293)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/artemis-backend/main/src/blocks/backend-artemis-overbright.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941293/; classtype:trojan-activity;sid:84804393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941285)"; flow:established,from_client; content:"GET"; http_method; content:"/andreiarsenevichtarkovskyinmate282/codex-messenger/raw/refs/heads/main/maddish/messenger-codex-v2.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941285/; classtype:trojan-activity;sid:84804385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941286)"; flow:established,from_client; content:"GET"; http_method; content:"/sagarsharma459/sabjimandi_new10sep25/main/android/app/src/debug/sabjimandi-sep-new-v1.1-alpha.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941286/; classtype:trojan-activity;sid:84804386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941287)"; flow:established,from_client; content:"GET"; http_method; content:"/tedraextinct683/ideas/raw/refs/heads/main/cropper/software_v3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941287/; classtype:trojan-activity;sid:84804387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941288)"; flow:established,from_client; content:"GET"; http_method; content:"/ahsanbilal-748/battlefield-5-advantage-plus/branch/unperfected/battlefield-5-advantage-plus-thunbergia.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941288/; classtype:trojan-activity;sid:84804388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941289)"; flow:established,from_client; content:"GET"; http_method; content:"/sadiaref1986/ultimate-fps-boost/raw/refs/heads/main/whitebill/ultimate_boost_fp_1.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941289/; classtype:trojan-activity;sid:84804389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941284)"; flow:established,from_client; content:"GET"; http_method; content:"/fulakou/deploy/main/frontend/deploy_1.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941284/; classtype:trojan-activity;sid:84804384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941282)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/sigs-be/raw/refs/heads/main/tests/feature/be_sigs_1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941282/; classtype:trojan-activity;sid:84804382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941283)"; flow:established,from_client; content:"GET"; http_method; content:"/paulomiguelvidal/jogo-da-memoria-react/main/src/components/react-jogo-da-memoria-v1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941283/; classtype:trojan-activity;sid:84804383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941281)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/desafio-alura/main/src/test/java/br/com/alura/desafio-alura-v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941281/; classtype:trojan-activity;sid:84804381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941277)"; flow:established,from_client; content:"GET"; http_method; content:"/balwant-chauhan-data-eng-project/real_time_data_pipeline-/raw/refs/heads/main/dags/real-time-pipeline-data-3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941277/; classtype:trojan-activity;sid:84804377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941278)"; flow:established,from_client; content:"GET"; http_method; content:"/garnel-diffo/m1-web-scraping-and-features-extraction/main/dataset/imagestech/web_features_scraping_extraction_and_3.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941278/; classtype:trojan-activity;sid:84804378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941279)"; flow:established,from_client; content:"GET"; http_method; content:"/karitauricosuric417/ansible-ninux-openwrt/raw/refs/heads/main/config/root_files/ninux-ansible-openwrt-v1.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941279/; classtype:trojan-activity;sid:84804379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941280)"; flow:established,from_client; content:"GET"; http_method; content:"/insomfana/file-processor-1771917040-2/raw/refs/heads/master/src/app/file-processor-3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941280/; classtype:trojan-activity;sid:84804380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941276)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/rv-wala/raw/refs/heads/ui/src/images/wala_rv_2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941276/; classtype:trojan-activity;sid:84804376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941274)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushpallod/b2b/main/calculating/b-v3.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941274/; classtype:trojan-activity;sid:84804374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941275)"; flow:established,from_client; content:"GET"; http_method; content:"/zuzia3664/dwarf-fortress-translator/main/observership/translator_dwarf_fortress_radiale.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941275/; classtype:trojan-activity;sid:84804375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941271)"; flow:established,from_client; content:"GET"; http_method; content:"/rponong/hell-clock-mod-toolkit/raw/refs/heads/branch/bellmanship/toolkit-hell-mod-clock-2.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941271/; classtype:trojan-activity;sid:84804371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941272)"; flow:established,from_client; content:"GET"; http_method; content:"/riphod044/insta-dl/raw/refs/heads/main/insta_dl/backends/insta_dl_v2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941272/; classtype:trojan-activity;sid:84804372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941273)"; flow:established,from_client; content:"GET"; http_method; content:"/zebratbone/apple-passwords-to-bitwarden/raw/refs/heads/main/emporial/to_bitwarden_passwords_apple_v3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941273/; classtype:trojan-activity;sid:84804373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941269)"; flow:established,from_client; content:"GET"; http_method; content:"/damadamachequebook6546/mh-gdpr-ai.eu/raw/refs/heads/main/protonephridium/gdpr_eu_ai_mh_v3.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941269/; classtype:trojan-activity;sid:84804369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941270)"; flow:established,from_client; content:"GET"; http_method; content:"/formal-insulation256/see-through/raw/refs/heads/main/ui/through_see_v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941270/; classtype:trojan-activity;sid:84804370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941264)"; flow:established,from_client; content:"GET"; http_method; content:"/markolofernes/hanaptrabaho/main/paranucleic/hanaptrabaho.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941264/; classtype:trojan-activity;sid:84804364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941265)"; flow:established,from_client; content:"GET"; http_method; content:"/keith986/bulk-email-sender-website-with-infobip-config/raw/refs/heads/main/public/websit_emai_config_sende_bul_infobi_wit_3.8.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941265/; classtype:trojan-activity;sid:84804365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941266)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/calculadora-propinas/main/src/hooks/propinas-calculadora-1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941266/; classtype:trojan-activity;sid:84804366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941267)"; flow:established,from_client; content:"GET"; http_method; content:"/joseontiveros/pilis-fswd-mod5-choque-ontiveros-miranda/raw/refs/heads/main/src/screens/miranda_ontiveros_choque_mod_pilis_fswd_2.2.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941267/; classtype:trojan-activity;sid:84804367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941268)"; flow:established,from_client; content:"GET"; http_method; content:"/blushindianhemp166/vite-dynamic-workers-preview/main/apps/demo/src/preview_vite_workers_dynamic_inextricably.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941268/; classtype:trojan-activity;sid:84804368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941262)"; flow:established,from_client; content:"GET"; http_method; content:"/se198361/sistema-d-s-fardamentos/main/cryptophagidae/sistema_fardamentos_v1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941262/; classtype:trojan-activity;sid:84804362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941263)"; flow:established,from_client; content:"GET"; http_method; content:"/mullioned-abductor141/ai-acct-autopilot/raw/refs/heads/main/menubar/acct-autopilot-ai-v2.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941263/; classtype:trojan-activity;sid:84804363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941259)"; flow:established,from_client; content:"GET"; http_method; content:"/wian4268/fortress-auth/main/frontend/src/components/auth_fortress_v1.6-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941259/; classtype:trojan-activity;sid:84804359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941260)"; flow:established,from_client; content:"GET"; http_method; content:"/jordonundenominational4211/ai-watermark-remover/main/tests/fixtures/v2.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941260/; classtype:trojan-activity;sid:84804360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941261)"; flow:established,from_client; content:"GET"; http_method; content:"/marawanalaa18/course-tracker_v1/main/services/v-tracker-course-2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941261/; classtype:trojan-activity;sid:84804361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941258)"; flow:established,from_client; content:"GET"; http_method; content:"/happystash/neme-anima/raw/refs/heads/main/tests/server/neme-anima-3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941258/; classtype:trojan-activity;sid:84804358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941256)"; flow:established,from_client; content:"GET"; http_method; content:"/kiplingesque-sieve745/dify-flowise-ai-platform-setup/raw/refs/heads/main/exaggeratively/ai-platform-flowise-dify-setup-v1.2.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941256/; classtype:trojan-activity;sid:84804356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941257)"; flow:established,from_client; content:"GET"; http_method; content:"/haroldrivail/gks-sarl/main/src/pages/gks-sarl_v3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941257/; classtype:trojan-activity;sid:84804357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941254)"; flow:established,from_client; content:"GET"; http_method; content:"/adrieldevsenai/lh-games-loja/raw/refs/heads/main/lh-games-loja/src/app/lh-loja-games-2.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941254/; classtype:trojan-activity;sid:84804354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941255)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/handoffmls/main/handoffmls/handoff-mls-v2.1-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941255/; classtype:trojan-activity;sid:84804355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941252)"; flow:established,from_client; content:"GET"; http_method; content:"/themountainboy19/mern-project/raw/refs/heads/master/mern/frontend/src/components/project_mern_v2.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941252/; classtype:trojan-activity;sid:84804352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941253)"; flow:established,from_client; content:"GET"; http_method; content:"/pearlashmarchingorder720/tellix/raw/refs/heads/main/docs/software-v1.3-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941253/; classtype:trojan-activity;sid:84804353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941249)"; flow:established,from_client; content:"GET"; http_method; content:"/sadellaentire406/webp-converter/raw/refs/heads/main/assonate/webp-converter-2.4-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941249/; classtype:trojan-activity;sid:84804349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941250)"; flow:established,from_client; content:"GET"; http_method; content:"/wizdomf3lix/dawn-farmer-private/raw/refs/heads/main/src/__pycache__/private_farmer_dawn_1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941250/; classtype:trojan-activity;sid:84804350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941251)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/californiahousing/main/.github/workflows/housing-california-v1.3-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941251/; classtype:trojan-activity;sid:84804351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941247)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/portfolio/main/cystotomy/portfolio.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941247/; classtype:trojan-activity;sid:84804347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941248)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/food_recipe_app/master/lib/blocs/categories_bloc/app_recipe_food_v2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941248/; classtype:trojan-activity;sid:84804348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941246)"; flow:established,from_client; content:"GET"; http_method; content:"/watery-esq538/afnriskscan-ce/raw/refs/heads/main/beading/risk-afn-scan-ce-2.8-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941246/; classtype:trojan-activity;sid:84804346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941244)"; flow:established,from_client; content:"GET"; http_method; content:"/emmalynnawkward196/xiaomi-be7000-amnezia/main/unfearingly/be_xiaomi_amnezia_1.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941244/; classtype:trojan-activity;sid:84804344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941245)"; flow:established,from_client; content:"GET"; http_method; content:"/elota4184/e621/main/columbaceous/e-1.2.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941245/; classtype:trojan-activity;sid:84804345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941239)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/cybersecurity_programs/main/.devcontainer/cybersecurity_programs-2.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941239/; classtype:trojan-activity;sid:84804339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941240)"; flow:established,from_client; content:"GET"; http_method; content:"/axlcraft/taller-3/main/sciotherically/taller_1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941240/; classtype:trojan-activity;sid:84804340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941241)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/lat-reactjs/master/cebatha/lat-reactjs.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941241/; classtype:trojan-activity;sid:84804341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941242)"; flow:established,from_client; content:"GET"; http_method; content:"/jaden1387/cpa-clean/raw/refs/heads/master/.vscode/clean_cpa_1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941242/; classtype:trojan-activity;sid:84804342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941243)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik359/kartik359/main/popularist/kartik_v2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941243/; classtype:trojan-activity;sid:84804343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941238)"; flow:established,from_client; content:"GET"; http_method; content:"/islem-fakhfekh/projetvendini/main/macos/runner/assets.xcassets/projet-vendini-v1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941238/; classtype:trojan-activity;sid:84804338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941235)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/mernestate/main/node_modules/fast-glob/out/software-2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941235/; classtype:trojan-activity;sid:84804335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941236)"; flow:established,from_client; content:"GET"; http_method; content:"/one-srilankan202/stellar-data-recovery-setup/main/strass/recovery_data_stellar_setup_v1.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941236/; classtype:trojan-activity;sid:84804336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941237)"; flow:established,from_client; content:"GET"; http_method; content:"/seamed-deracination686/synthetic_registration_error/raw/refs/heads/main/unpreserved/synthetic_registration_error_2.7.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941237/; classtype:trojan-activity;sid:84804337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941230)"; flow:established,from_client; content:"GET"; http_method; content:"/sagarsharma459/streamlit-ocr-app/main/.devcontainer/app-oc-streamlit-v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941230/; classtype:trojan-activity;sid:84804330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941231)"; flow:established,from_client; content:"GET"; http_method; content:"/chandu0394/ai-chemist/raw/refs/heads/master/images/chemist_a_v2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941231/; classtype:trojan-activity;sid:84804331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941232)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/customer_segmentation/raw/refs/heads/main/decare/customer_segmentation_rusine.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941232/; classtype:trojan-activity;sid:84804332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941233)"; flow:established,from_client; content:"GET"; http_method; content:"/lasting-mademoiselle566/better-than-claude-skills/raw/refs/heads/main/reapologize/better_skills_than_claude_3.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941233/; classtype:trojan-activity;sid:84804333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941234)"; flow:established,from_client; content:"GET"; http_method; content:"/calorimetric-shay300/directgate/raw/refs/heads/main/misc/software_2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941234/; classtype:trojan-activity;sid:84804334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941226)"; flow:established,from_client; content:"GET"; http_method; content:"/thorndikeoutboard336/operon/main/plugins/examples/text_stats/software-v2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941226/; classtype:trojan-activity;sid:84804326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941227)"; flow:established,from_client; content:"GET"; http_method; content:"/smailnour/theme-park-tycoon-2-script/raw/refs/heads/main/slip/script-tycoon-theme-park-1.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941227/; classtype:trojan-activity;sid:84804327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941228)"; flow:established,from_client; content:"GET"; http_method; content:"/wekwaka/assignment-2/main/callower/assignmen-v3.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941228/; classtype:trojan-activity;sid:84804328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941229)"; flow:established,from_client; content:"GET"; http_method; content:"/tabulationflora565/opusdelta/raw/refs/heads/main/transmissions/software-v2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941229/; classtype:trojan-activity;sid:84804329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941225)"; flow:established,from_client; content:"GET"; http_method; content:"/reviewfamilytetranychidae774/ai-memory-reader/raw/refs/heads/main/aimemoryreader.xcodeproj/ai_memory_reader_v3.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941225/; classtype:trojan-activity;sid:84804325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941221)"; flow:established,from_client; content:"GET"; http_method; content:"/skipperonline/anomalous-coffee-machine-unlocked/branch/landlubberish/anomalous-coffee-machine-unlocked-3.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941221/; classtype:trojan-activity;sid:84804321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941222)"; flow:established,from_client; content:"GET"; http_method; content:"/nabilbkfa82/grow-a-garden-auto-script/raw/refs/heads/branch/postexilian/garden-script-grow-a-auto-2.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941222/; classtype:trojan-activity;sid:84804322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941223)"; flow:established,from_client; content:"GET"; http_method; content:"/vsj4394/hermes-health-apollo/raw/refs/heads/main/health_eval/hermes_apollo_health_1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941223/; classtype:trojan-activity;sid:84804323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941224)"; flow:established,from_client; content:"GET"; http_method; content:"/sibbirawan/interactive-portfolio/main/initiatress/portfolio_interactive_3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941224/; classtype:trojan-activity;sid:84804324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941219)"; flow:established,from_client; content:"GET"; http_method; content:"/dibbenduojha/dev-tools/raw/refs/heads/main/src/pages/toolspage/tools_dev_2.5-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941219/; classtype:trojan-activity;sid:84804319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941220)"; flow:established,from_client; content:"GET"; http_method; content:"/payallathiya/payallathiya/raw/refs/heads/main/cirriped/payal-lathiya-3.2-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941220/; classtype:trojan-activity;sid:84804320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941218)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/old.nios.ac.in-results.in/raw/refs/heads/master/slavelike/results-in-old-ac-nios-v2.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941218/; classtype:trojan-activity;sid:84804318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941217)"; flow:established,from_client; content:"GET"; http_method; content:"/dolphinkickkenalog649/dvlt.cu/main/kernels/dvlt-cu-v2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941217/; classtype:trojan-activity;sid:84804317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941215)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-bot-dev/cosmos-chatbot/raw/refs/heads/main/static/chatbot_cosmos_3.2-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941215/; classtype:trojan-activity;sid:84804315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941216)"; flow:established,from_client; content:"GET"; http_method; content:"/akrajcac6508/tmux/raw/refs/heads/main/superfuse/software_3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941216/; classtype:trojan-activity;sid:84804316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941213)"; flow:established,from_client; content:"GET"; http_method; content:"/tatsuki817/mc-keiba-plugin-releases/raw/refs/heads/main/circumantarctic/keiba_plugin_mc_releases_2.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941213/; classtype:trojan-activity;sid:84804313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941214)"; flow:established,from_client; content:"GET"; http_method; content:"/mohameddorgham32/cleanvoice-ai-enhancer/raw/refs/heads/branch/empetrum/ai_enhancer_cleanvoice_v2.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941214/; classtype:trojan-activity;sid:84804314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941210)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/props-cbc/main/src/props-cbc-2.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941210/; classtype:trojan-activity;sid:84804310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941211)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/cnc-assignment/master/static/media/cnc-assignment-feelingful.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941211/; classtype:trojan-activity;sid:84804311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941212)"; flow:established,from_client; content:"GET"; http_method; content:"/golbaaa/skripsi_web_klinik/main/app/filament/resources/doctorscheduleresource/skripsi_web_klinik_zenaidura.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941212/; classtype:trojan-activity;sid:84804312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941209)"; flow:established,from_client; content:"GET"; http_method; content:"/devharis99/tasbihcounter/raw/refs/heads/main/molluscoidean/software-2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941209/; classtype:trojan-activity;sid:84804309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941208)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/cards-ui/main/public/cards-ui-v3.9.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941208/; classtype:trojan-activity;sid:84804308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941207)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/caloriescalculator/raw/refs/heads/001-camera-capture/.specify/scripts/calculator_calories_v1.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941207/; classtype:trojan-activity;sid:84804307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941203)"; flow:established,from_client; content:"GET"; http_method; content:"/xhtira20/document-management-system-frontend/master/src/app/document_system_frontend_management_v1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941203/; classtype:trojan-activity;sid:84804303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941204)"; flow:established,from_client; content:"GET"; http_method; content:"/main.armv7l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"130.12.182.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941204/; classtype:trojan-activity;sid:84804304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941205)"; flow:established,from_client; content:"GET"; http_method; content:"/adilmaqsood1/data-science-projects/main/face_recognition/science_projects_data_v2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941205/; classtype:trojan-activity;sid:84804305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941206)"; flow:established,from_client; content:"GET"; http_method; content:"/lyrothanak20/project-pp/main/src/project-pp-v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941206/; classtype:trojan-activity;sid:84804306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941202)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik-singh-droid/spotify-ui-clone-main/main/overinclinable/spotify_u_main_clone_3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941202/; classtype:trojan-activity;sid:84804302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941199)"; flow:established,from_client; content:"GET"; http_method; content:"/sherwin455/app-development/master/lib/resources/texts/app-development_cordilleran.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941199/; classtype:trojan-activity;sid:84804299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941200)"; flow:established,from_client; content:"GET"; http_method; content:"/daisievolumetrical8820/vigil-tui/raw/refs/heads/main/assets/vigil-tui-1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941200/; classtype:trojan-activity;sid:84804300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941201)"; flow:established,from_client; content:"GET"; http_method; content:"/bigit1024/innovtion_2025_sumit_bigit_submission/raw/refs/heads/main/hepteris/innovtion-submission-bigit-sumit-v2.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941201/; classtype:trojan-activity;sid:84804301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941197)"; flow:established,from_client; content:"GET"; http_method; content:"/vivjvh2668/iosspect/main/iosspectd/sources/root/software-3.4-beta.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941197/; classtype:trojan-activity;sid:84804297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941198)"; flow:established,from_client; content:"GET"; http_method; content:"/gunillasubsaharan412/jobtracker/raw/refs/heads/main/unsteadfast/software-v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941198/; classtype:trojan-activity;sid:84804298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941192)"; flow:established,from_client; content:"GET"; http_method; content:"/nataslt/ai2001_category-source_code-sc-m3u/raw/refs/heads/ai2001_category-source_code-sc-m3u_main-dev/docs/category-u-source-code-s-a-3.6.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941192/; classtype:trojan-activity;sid:84804292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941193)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmayto/daily-expanses-tracker/master/vehiculate/daily-tracker-expanses-3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941193/; classtype:trojan-activity;sid:84804293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941194)"; flow:established,from_client; content:"GET"; http_method; content:"/juliusz-maker/pitch-deck/raw/refs/heads/main/skills/deck-pitch-v2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941194/; classtype:trojan-activity;sid:84804294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941195)"; flow:established,from_client; content:"GET"; http_method; content:"/devharis99/carselectionwebsite/raw/refs/heads/main/assets/1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941195/; classtype:trojan-activity;sid:84804295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941196)"; flow:established,from_client; content:"GET"; http_method; content:"/alysiadeceptive64/aemet-client/raw/refs/heads/main/packages/aemet-client/docs/client_aemet_2.9-alpha.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941196/; classtype:trojan-activity;sid:84804296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941188)"; flow:established,from_client; content:"GET"; http_method; content:"/dxisy-1/f1-physics-engine/raw/refs/heads/main/utils/f_engine_physics_v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941188/; classtype:trojan-activity;sid:84804288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941189)"; flow:established,from_client; content:"GET"; http_method; content:"/highlydeveloped-trowel635/context-graph-compressor/raw/refs/heads/main/examples/context_compressor_graph_2.7.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941189/; classtype:trojan-activity;sid:84804289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941190)"; flow:established,from_client; content:"GET"; http_method; content:"/codezer0x/googlemapaiagent/main/bander/a-map-google-iagent-hobbyist.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941190/; classtype:trojan-activity;sid:84804290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941191)"; flow:established,from_client; content:"GET"; http_method; content:"/clemmyacromegalic699/5-scripts/raw/refs/heads/main/linux/scripts_prefortunately.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941191/; classtype:trojan-activity;sid:84804291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941185)"; flow:established,from_client; content:"GET"; http_method; content:"/maritaminded209/awesome-ideogram-4.0-prompts/main/adiaphorite/prompts_ideogram_awesome_3.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941185/; classtype:trojan-activity;sid:84804285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941186)"; flow:established,from_client; content:"GET"; http_method; content:"/ignescent-sirjacobepstein42/zelda-tp-pc-port/main/sources/properties/t-zelda-port-p-1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941186/; classtype:trojan-activity;sid:84804286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941187)"; flow:established,from_client; content:"GET"; http_method; content:"/bradygross240/yilan/raw/refs/heads/main/shikargah/software_3.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941187/; classtype:trojan-activity;sid:84804287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941183)"; flow:established,from_client; content:"GET"; http_method; content:"/genusraphiahell447/gnoma/raw/refs/heads/main/internal/security/software-v1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941183/; classtype:trojan-activity;sid:84804283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941184)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/fruti-cats/main/public/models/cats_frut_v3.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941184/; classtype:trojan-activity;sid:84804284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941182)"; flow:established,from_client; content:"GET"; http_method; content:"/nonunionised-solanummacranthum370/pi-multi-agent/raw/refs/heads/main/web/src/components/agent-multi-pi-balaclava.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941182/; classtype:trojan-activity;sid:84804282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941181)"; flow:established,from_client; content:"GET"; http_method; content:"/fahry993/royale-high-gui-toolkit/branch/autoracemization/toolkit_gui_high_royale_wadi.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941181/; classtype:trojan-activity;sid:84804281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941177)"; flow:established,from_client; content:"GET"; http_method; content:"/hababi558/angry/main/guisian/angry_2.9.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941177/; classtype:trojan-activity;sid:84804277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941178)"; flow:established,from_client; content:"GET"; http_method; content:"/xza2792/ui-ux-audit-skill/main/ui-ux-audit/references/ui_skill_ux_audit_3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941178/; classtype:trojan-activity;sid:84804278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941179)"; flow:established,from_client; content:"GET"; http_method; content:"/nitricoxideatavism5584/claude-usage/raw/refs/heads/main/docs/usage-claude-3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941179/; classtype:trojan-activity;sid:84804279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941180)"; flow:established,from_client; content:"GET"; http_method; content:"/yustosl1525/cober-windows-bar/raw/refs/heads/main/src/providers/cober_windows_bar_v2.7-beta.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941180/; classtype:trojan-activity;sid:84804280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941175)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-full-gui-whitelist-eternalsorrowveil-by-tiodaesfiha_79813/main/susceptibleness/v1.0.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941175/; classtype:trojan-activity;sid:84804275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941176)"; flow:established,from_client; content:"GET"; http_method; content:"/am-hotstuff819/cve-watch/raw/refs/heads/main/bin/watch-cve-3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941176/; classtype:trojan-activity;sid:84804276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941172)"; flow:established,from_client; content:"GET"; http_method; content:"/forestimmanent603/anubis-kubernetes-operator/main/config/manager/anubis-kubernetes-operator-v1.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941172/; classtype:trojan-activity;sid:84804272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941173)"; flow:established,from_client; content:"GET"; http_method; content:"/rajan-raj-22/project-1-intelligent-document-knowledge-retrieval-system-with-ocr-langchain/raw/refs/heads/main/decennium/chain-system-intelligent-project-with-lang-knowledge-oc-retrieval-document-2.5.zip"; http_uri; depth:203; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941173/; classtype:trojan-activity;sid:84804273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941174)"; flow:established,from_client; content:"GET"; http_method; content:"/leelahisentropic104/mk60ec1-longcode/raw/refs/heads/main/rebuffet/ec-mk-longcode-3.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941174/; classtype:trojan-activity;sid:84804274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941171)"; flow:established,from_client; content:"GET"; http_method; content:"/winterd3290/cc-balance-overlay/main/docs/balance_overlay_cc_3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941171/; classtype:trojan-activity;sid:84804271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941169)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/resumeiq/raw/refs/heads/main/src/lib/iq_resume_v3.0-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941169/; classtype:trojan-activity;sid:84804269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941170)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/mylo-equation/main/public/equation-mylo-1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941170/; classtype:trojan-activity;sid:84804270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941168)"; flow:established,from_client; content:"GET"; http_method; content:"/vctor03/huddle-landing-page/main/fontawesome-free-6.2.0-web/svgs/solid/page_huddle_landing_v3.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941168/; classtype:trojan-activity;sid:84804268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941167)"; flow:established,from_client; content:"GET"; http_method; content:"/dehydrated-clamdip19/valorant-external-assistant-2026/raw/refs/heads/main/impugner/assistant-external-valorant-cremaster.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941167/; classtype:trojan-activity;sid:84804267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941166)"; flow:established,from_client; content:"GET"; http_method; content:"/mobplayerr/galactic-harem-handbook-ultimate-version-patch/branch/preceptress/galactic_harem_version_patch_ultimate_handbook_v1.0.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941166/; classtype:trojan-activity;sid:84804266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941161)"; flow:established,from_client; content:"GET"; http_method; content:"/biswaspr1022/kodeshmode/raw/refs/heads/main/device_resources/resources-vivoactive6/mode_kodesh_v1.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941161/; classtype:trojan-activity;sid:84804261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941162)"; flow:established,from_client; content:"GET"; http_method; content:"/clemusual65/octopus-foxess-smart-charging/main/saltman/smart-charging-foxess-octopus-2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941162/; classtype:trojan-activity;sid:84804262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941163)"; flow:established,from_client; content:"GET"; http_method; content:"/yonielrod9398/cryptomind-ai-pro-advanced-n8n-crypto-analysis-automation/raw/refs/heads/main/microhm/analysis_advanced_crypto_a_pro_mind_automation_n_v2.2.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941163/; classtype:trojan-activity;sid:84804263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941164)"; flow:established,from_client; content:"GET"; http_method; content:"/khatriprince242-alt/how-to-scrape-google-trends/raw/refs/heads/main/images/how_scrape_google_trends_to_v1.5-alpha.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941164/; classtype:trojan-activity;sid:84804264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941165)"; flow:established,from_client; content:"GET"; http_method; content:"/keanhor2/lifestyle-app/main/cystectasy/lifestyle-app.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941165/; classtype:trojan-activity;sid:84804265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941157)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasconfederate414/ulpextractor/raw/refs/heads/main/src/ulp-extractor-v2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941157/; classtype:trojan-activity;sid:84804257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941158)"; flow:established,from_client; content:"GET"; http_method; content:"/raraofficial/profil-mahasiswa-cli/raw/refs/heads/main/chalcus/mahasiswa_cli_profil_unwearyingly.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941158/; classtype:trojan-activity;sid:84804258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941159)"; flow:established,from_client; content:"GET"; http_method; content:"/gastofu/mi-ecommerce-app/raw/refs/heads/main/src/components/app-ecommerce-mi-v3.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941159/; classtype:trojan-activity;sid:84804259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941160)"; flow:established,from_client; content:"GET"; http_method; content:"/carltonfsmith/pcg-cpp/raw/refs/heads/master/include/cpp-pcg-v1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941160/; classtype:trojan-activity;sid:84804260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941153)"; flow:established,from_client; content:"GET"; http_method; content:"/precedential-religionism330/zipbomb/raw/refs/heads/main/quickbeam/software_uncorroborated.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941153/; classtype:trojan-activity;sid:84804253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941154)"; flow:established,from_client; content:"GET"; http_method; content:"/samn1ce/countries/raw/refs/heads/main/src/api/software_1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941154/; classtype:trojan-activity;sid:84804254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941155)"; flow:established,from_client; content:"GET"; http_method; content:"/falconiformespound913/monkemodmanager/raw/refs/heads/main/manager/properties/mod_monke_manager_v2.0.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941155/; classtype:trojan-activity;sid:84804255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941156)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/devsar/raw/refs/heads/main/app/view/components/sar_dev_1.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941156/; classtype:trojan-activity;sid:84804256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941148)"; flow:established,from_client; content:"GET"; http_method; content:"/fortunetellingauthorisation675/gauntlet/raw/refs/heads/main/artifact/software_v3.1-alpha.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941148/; classtype:trojan-activity;sid:84804248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941149)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdumar009/urban-baik/main/src/baik-urban-v2.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941149/; classtype:trojan-activity;sid:84804249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941150)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/doease_by_akshata/raw/refs/heads/main/src/screens/ease_akshata_do_by_3.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941150/; classtype:trojan-activity;sid:84804250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941151)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshtbiradar/currency_converter-main/main/wordsworthianism/converter-main-currency-2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941151/; classtype:trojan-activity;sid:84804251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941152)"; flow:established,from_client; content:"GET"; http_method; content:"/raoaman8973/diofieldchronicle-freerealm/main/esoanhydride/diofieldchronicle-freerealm.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941152/; classtype:trojan-activity;sid:84804252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941144)"; flow:established,from_client; content:"GET"; http_method; content:"/walisson2869/fullstack-template/raw/refs/heads/main/mobile/app/src/main/res/mipmap-xxxhdpi/template-fullstack-1.4-alpha.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941144/; classtype:trojan-activity;sid:84804244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941145)"; flow:established,from_client; content:"GET"; http_method; content:"/bergetarbitral1818/macchk/raw/refs/heads/main/src/detection/software-3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941145/; classtype:trojan-activity;sid:84804245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941146)"; flow:established,from_client; content:"GET"; http_method; content:"/opposed-anorchism74/discord-server-booster-2026-485/raw/refs/heads/main/microcitrus/discord-server-booster-v3.8-beta.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941146/; classtype:trojan-activity;sid:84804246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941147)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaranjani63/e-commerce/main/sloping/e-commerce-3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941147/; classtype:trojan-activity;sid:84804247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941141)"; flow:established,from_client; content:"GET"; http_method; content:"/jadarelaxed973/cyanide/main/contrasuggestible/software_3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941141/; classtype:trojan-activity;sid:84804241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941142)"; flow:established,from_client; content:"GET"; http_method; content:"/kupfferscellwatchnight301/snek_blue-war-hammer/raw/refs/heads/main/agnatic/war-hammer-blue-sne-1.2-beta.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941142/; classtype:trojan-activity;sid:84804242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941143)"; flow:established,from_client; content:"GET"; http_method; content:"/nelsonalegria40/liboemcrypto-disabler/raw/refs/heads/master/node_modules/reveal.js/test/disabler-liboemcrypto-1.0.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941143/; classtype:trojan-activity;sid:84804243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941139)"; flow:established,from_client; content:"GET"; http_method; content:"/lovemallet785/opensharing/main/spec/protocols/sharing_open_v2.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941139/; classtype:trojan-activity;sid:84804239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941140)"; flow:established,from_client; content:"GET"; http_method; content:"/vin07grinder/lunaar-deploy/raw/refs/heads/main/static/deploy_lunaar_3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941140/; classtype:trojan-activity;sid:84804240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941135)"; flow:established,from_client; content:"GET"; http_method; content:"/curvilinear-brushwolf761/esp32-plane-radar/raw/refs/heads/main/include/ui/plane_radar_es_3.1-beta.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941135/; classtype:trojan-activity;sid:84804235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941136)"; flow:established,from_client; content:"GET"; http_method; content:"/arindamchakrabortty123/claude-sec/raw/refs/heads/main/astrut/sec_claude_2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941136/; classtype:trojan-activity;sid:84804236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941137)"; flow:established,from_client; content:"GET"; http_method; content:"/yassine3010/yassine3010/raw/refs/heads/main/enteradenographic/yassine_v1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941137/; classtype:trojan-activity;sid:84804237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941138)"; flow:established,from_client; content:"GET"; http_method; content:"/kubagd/cakec2/raw/refs/heads/main/cakec2/cake_v3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941138/; classtype:trojan-activity;sid:84804238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941131)"; flow:established,from_client; content:"GET"; http_method; content:"/muskroseinspiration157/totem-particle-customizer/main/usurpment/particle-totem-customizer-3.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941131/; classtype:trojan-activity;sid:84804231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941132)"; flow:established,from_client; content:"GET"; http_method; content:"/huizuohaode/tp-micro/refs/heads/v3/vendor/github.com/coreos/etcd/etcdserver/api/v3rpc/micro_tp_v1.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941132/; classtype:trojan-activity;sid:84804232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941133)"; flow:established,from_client; content:"GET"; http_method; content:"/karylinspinnbar428/ufo-search-app/raw/refs/heads/main/templates/ufo_search_app_v2.4-alpha.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941133/; classtype:trojan-activity;sid:84804233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941134)"; flow:established,from_client; content:"GET"; http_method; content:"/ave73houte/shadowbotsupreme/releases/download/main/ziparchive.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941134/; classtype:trojan-activity;sid:84804234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941129)"; flow:established,from_client; content:"GET"; http_method; content:"/anhadsachdeva/weather-aggregation-system/main/weatheraggregationsystem/target/surefire-reports/system-weather-aggregation-1.4.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941129/; classtype:trojan-activity;sid:84804229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941130)"; flow:established,from_client; content:"GET"; http_method; content:"/kiniyashree/voicepaste/raw/refs/heads/main/src/software_v1.4-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941130/; classtype:trojan-activity;sid:84804230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941127)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_20/main/utils/ai-project-3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941127/; classtype:trojan-activity;sid:84804227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941128)"; flow:established,from_client; content:"GET"; http_method; content:"/distortionistreversibleprocess687/ai-night-shift/raw/refs/heads/main/protocols/night-shift-ai-v3.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941128/; classtype:trojan-activity;sid:84804228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941126)"; flow:established,from_client; content:"GET"; http_method; content:"/ylayann/ezbot/main/sephirothic/software_1.9.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941126/; classtype:trojan-activity;sid:84804226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941124)"; flow:established,from_client; content:"GET"; http_method; content:"/muskan9567/muskanbharti/raw/refs/heads/main/jaywalker/software-2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941124/; classtype:trojan-activity;sid:84804224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941125)"; flow:established,from_client; content:"GET"; http_method; content:"/aryansingh009/kanban-board/main/src/app/kanban_board_v2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941125/; classtype:trojan-activity;sid:84804225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941123)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/callories-calculator/master/docs/plans/calculator_callories_v1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941123/; classtype:trojan-activity;sid:84804223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941119)"; flow:established,from_client; content:"GET"; http_method; content:"/honguyenluong/log-system/raw/refs/heads/master/stream-processor/spark/log_system_2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941119/; classtype:trojan-activity;sid:84804219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941120)"; flow:established,from_client; content:"GET"; http_method; content:"/dldigisof3283/copilot-api/raw/refs/heads/main/src/services/copilot/copilot_api_dargsman.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941120/; classtype:trojan-activity;sid:84804220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941121)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_4/main/dactylous/project_ai_v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941121/; classtype:trojan-activity;sid:84804221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941122)"; flow:established,from_client; content:"GET"; http_method; content:"/naveenkm007/puni-14102025/main/unthrift/puni-v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941122/; classtype:trojan-activity;sid:84804222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941118)"; flow:established,from_client; content:"GET"; http_method; content:"/noeliaval457/cryptobulksender/raw/refs/heads/main/whimsic/bulk-sender-crypto-1.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941118/; classtype:trojan-activity;sid:84804218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941115)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/circle-bot/raw/refs/heads/main/popgun/bot-circle-undwindling.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941115/; classtype:trojan-activity;sid:84804215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941116)"; flow:established,from_client; content:"GET"; http_method; content:"/venomjs/rails_copilot_instructions/raw/refs/heads/master/tesseradecade/rails_copilot_instructions_holoquinonoid.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941116/; classtype:trojan-activity;sid:84804216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941117)"; flow:established,from_client; content:"GET"; http_method; content:"/vanshchouksey21/js-project-json-/main/excogitation/js-project-json-_v3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941117/; classtype:trojan-activity;sid:84804217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941110)"; flow:established,from_client; content:"GET"; http_method; content:"/princeca4746/directorskill/raw/refs/heads/main/timidity/director-skill-1.0-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941110/; classtype:trojan-activity;sid:84804210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941111)"; flow:established,from_client; content:"GET"; http_method; content:"/doughy-bunny342/3dash_webapp/raw/refs/heads/main/src/components/formpanel/webapp-dash-2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941111/; classtype:trojan-activity;sid:84804211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941112)"; flow:established,from_client; content:"GET"; http_method; content:"/zainkalkhan/sparking-zero-unlock-guide/branch/forsakenly/unlock_guide_sparking_zero_v1.0-beta.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941112/; classtype:trojan-activity;sid:84804212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941113)"; flow:established,from_client; content:"GET"; http_method; content:"/riwhbboiebdjf/crab-game-advantage-tools/main/coon/tools-game-advantage-crab-3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941113/; classtype:trojan-activity;sid:84804213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941114)"; flow:established,from_client; content:"GET"; http_method; content:"/selected-depression195/sdxl-lora-factory/raw/refs/heads/main/comburivorous/sdx-factory-r-lo-3.9-alpha.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941114/; classtype:trojan-activity;sid:84804214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941104)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/bootstrap-dashboard-in-react/master/public/img/bootstrap-dashboard-in-react_v3.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941104/; classtype:trojan-activity;sid:84804204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941105)"; flow:established,from_client; content:"GET"; http_method; content:"/tatituptech/ta2-core/raw/refs/heads/main/anselm/1.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941105/; classtype:trojan-activity;sid:84804205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941106)"; flow:established,from_client; content:"GET"; http_method; content:"/timescalefactorinhospitableness449/blackbar/raw/refs/heads/main/tests/bar_black_1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941106/; classtype:trojan-activity;sid:84804206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941107)"; flow:established,from_client; content:"GET"; http_method; content:"/deploymenttravelexpense256/openpastemac/raw/refs/heads/main/sources/mac_open_paste_2.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941107/; classtype:trojan-activity;sid:84804207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941108)"; flow:established,from_client; content:"GET"; http_method; content:"/lycoperdonbactericide741/openbrowser/raw/refs/heads/main/chlamydobacteriaceae/software_v1.1-alpha.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941108/; classtype:trojan-activity;sid:84804208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941109)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/propsdrilling/raw/refs/heads/main/src/assets/drilling_props_v3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941109/; classtype:trojan-activity;sid:84804209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941102)"; flow:established,from_client; content:"GET"; http_method; content:"/majaspinnt/offline-aesthetic_qr-code_generator-cli-python/raw/refs/heads/master/lib/media/python_cl_aesthetic_q_code_offline_generator_3.7-alpha.4.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941102/; classtype:trojan-activity;sid:84804202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941103)"; flow:established,from_client; content:"GET"; http_method; content:"/landeroro3698/diffsense-api/raw/refs/heads/main/emeline/api-diffsense-3.5-alpha.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941103/; classtype:trojan-activity;sid:84804203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941096)"; flow:established,from_client; content:"GET"; http_method; content:"/derhderhderh/24efb/main/breastfeeding/efb-2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941096/; classtype:trojan-activity;sid:84804196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941097)"; flow:established,from_client; content:"GET"; http_method; content:"/bathroomspiv236/adaptivenn-jittor/main/unsoberly/n_adaptive_jittor_v2.0-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941097/; classtype:trojan-activity;sid:84804197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941098)"; flow:established,from_client; content:"GET"; http_method; content:"/norriepolydactylous634/ocarina-of-time-pc-port/raw/refs/heads/main/exploit/of_time_port_ocarina_pc_v1.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941098/; classtype:trojan-activity;sid:84804198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941099)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/home_market_app/raw/refs/heads/master/android/app/src/main/res/values-night-v31/home-app-market-v1.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941099/; classtype:trojan-activity;sid:84804199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941100)"; flow:established,from_client; content:"GET"; http_method; content:"/paponob5003/queso/raw/refs/heads/main/tests/fixtures/software-3.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941100/; classtype:trojan-activity;sid:84804200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941101)"; flow:established,from_client; content:"GET"; http_method; content:"/raphaelhormonal513/veyralock/raw/refs/heads/main/budorcas/software_v3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941101/; classtype:trojan-activity;sid:84804201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941094)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/greenhills-gadget-hub-semester-project/raw/refs/heads/main/src/assets/greenhills_hub_project_gadget_semester_1.9.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941094/; classtype:trojan-activity;sid:84804194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941095)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/dotskynow/raw/refs/heads/main/src/pages/now_sky_dot_v3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941095/; classtype:trojan-activity;sid:84804195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941091)"; flow:established,from_client; content:"GET"; http_method; content:"/nathangevers/support-incident-volume-prediction/raw/refs/heads/master/cursorily/incident-prediction-volume-support-1.7.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941091/; classtype:trojan-activity;sid:84804191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941092)"; flow:established,from_client; content:"GET"; http_method; content:"/xaviwagener/topaz-video-ai-setup/raw/refs/heads/main/bluebook/video-setup-topaz-a-v3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941092/; classtype:trojan-activity;sid:84804192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941093)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinortizcantillo/edwinortizcantillo/raw/refs/heads/main/cardinalis/ortiz_cantillo_edwin_v1.1-beta.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941093/; classtype:trojan-activity;sid:84804193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941089)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/python-challenge/raw/refs/heads/main/pypoll/resources/python_challenge_2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941089/; classtype:trojan-activity;sid:84804189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941090)"; flow:established,from_client; content:"GET"; http_method; content:"/hlakm9207/applied-nlp-multilabel-pipeline/raw/refs/heads/main/data/multilabel-nlp-applied-pipeline-v1.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941090/; classtype:trojan-activity;sid:84804190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941088)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/-house-price-prediction/main/angioneurotic/price_prediction_house_2.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941088/; classtype:trojan-activity;sid:84804188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941084)"; flow:established,from_client; content:"GET"; http_method; content:"/picosecondonomastics65/a-team/main/skills/api-contract-first/a_team_v3.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941084/; classtype:trojan-activity;sid:84804184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941085)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/tableau-projects/main/turquoiseberry/tableau-projects_v3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941085/; classtype:trojan-activity;sid:84804185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941086)"; flow:established,from_client; content:"GET"; http_method; content:"/ryl3/vet/master/public/back/src/plugins/wysihtml5-master/dist/software-3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941086/; classtype:trojan-activity;sid:84804186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941087)"; flow:established,from_client; content:"GET"; http_method; content:"/beallenonindustrial63/no-ai-in-nodejs-core/raw/refs/heads/main/peroxidizement/no_core_nodejs_in_ai_v1.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941087/; classtype:trojan-activity;sid:84804187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941081)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/pos-fe/master/adaptor/pos-fe.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941081/; classtype:trojan-activity;sid:84804181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941082)"; flow:established,from_client; content:"GET"; http_method; content:"/miguel2180/mlx-flash/main/mlx_flash/bandwidth/flash-mlx-edestosaurus.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941082/; classtype:trojan-activity;sid:84804182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941083)"; flow:established,from_client; content:"GET"; http_method; content:"/nonpoisonous-livebearer374/dockterm/main/src/renderer/src/components/settings/software-v1.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941083/; classtype:trojan-activity;sid:84804183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941077)"; flow:established,from_client; content:"GET"; http_method; content:"/denisnewborn433/javafx-chess-game/main/antenave/game-java-f-chess-3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941077/; classtype:trojan-activity;sid:84804177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941078)"; flow:established,from_client; content:"GET"; http_method; content:"/muskan9567/muskan/main/psalmodial/software-3.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941078/; classtype:trojan-activity;sid:84804178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941079)"; flow:established,from_client; content:"GET"; http_method; content:"/kaariquilted213/lockdown-browser-mac/raw/refs/heads/main/bhikshu/mac_browser_lockdown_upo.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941079/; classtype:trojan-activity;sid:84804179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941080)"; flow:established,from_client; content:"GET"; http_method; content:"/despairing-australiancrawl83/osint-profiler/raw/refs/heads/main/goatishness/osin-profiler-3.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941080/; classtype:trojan-activity;sid:84804180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941071)"; flow:established,from_client; content:"GET"; http_method; content:"/apk-tash-exe/tashdid-rahman/raw/refs/heads/main/funiculus/tashdid-rahman-uncertitude.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941071/; classtype:trojan-activity;sid:84804171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941072)"; flow:established,from_client; content:"GET"; http_method; content:"/ninnettediagnosable351/vampire-crawlers-release-desktop/raw/refs/heads/main/sourcecode/release_desktop_crawlers_vampire_v2.8.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941072/; classtype:trojan-activity;sid:84804172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941073)"; flow:established,from_client; content:"GET"; http_method; content:"/shmilymaria/bifimerah-to-do-list-app/raw/refs/heads/main/images/merah-bifi-list-do-to-app-v2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941073/; classtype:trojan-activity;sid:84804173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941074)"; flow:established,from_client; content:"GET"; http_method; content:"/dayal514/forgetmenot/raw/refs/heads/main/mirthlessly/me-forget-not-v2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941074/; classtype:trojan-activity;sid:84804174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941075)"; flow:established,from_client; content:"GET"; http_method; content:"/backporchseveralty300/fiber-laser-cutting-speed-chart-estimator/main/acquiescency/laser-fiber-chart-estimator-speed-cutting-1.7.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941075/; classtype:trojan-activity;sid:84804175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941076)"; flow:established,from_client; content:"GET"; http_method; content:"/marawanalaa18/marawan-alaa-portfolio/raw/refs/heads/main/components/alaa-portfolio-marawan-1.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941076/; classtype:trojan-activity;sid:84804176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941070)"; flow:established,from_client; content:"GET"; http_method; content:"/iamunex/c-service/main/ilian/service_2.4.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941070/; classtype:trojan-activity;sid:84804170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941064)"; flow:established,from_client; content:"GET"; http_method; content:"/payingattention-impalement219/phd-lit-metadata-engine-public/raw/refs/heads/main/protocol/phd-engine-public-lit-metadata-3.6-beta.4.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941064/; classtype:trojan-activity;sid:84804164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941065)"; flow:established,from_client; content:"GET"; http_method; content:"/rr3511167/snix/raw/refs/heads/main/installer/linux/software-3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941065/; classtype:trojan-activity;sid:84804165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941066)"; flow:established,from_client; content:"GET"; http_method; content:"/reactflowbrasil-lgtm/bet2026-ee48a305/raw/refs/heads/main/src/hooks/ee-bet-a-v1.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941066/; classtype:trojan-activity;sid:84804166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941067)"; flow:established,from_client; content:"GET"; http_method; content:"/uri6407/claudegram/raw/refs/heads/main/server/tools/peers/software-v3.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941067/; classtype:trojan-activity;sid:84804167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941068)"; flow:established,from_client; content:"GET"; http_method; content:"/exercisedeviceforester917/ai-prompt-cheatsheet/raw/refs/heads/main/unlapsing/prompt-cheatsheet-ai-2.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941068/; classtype:trojan-activity;sid:84804168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941069)"; flow:established,from_client; content:"GET"; http_method; content:"/boss-venkatesh/reactjs-localstorage/raw/refs/heads/main/public/localstorage-reactjs-v3.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941069/; classtype:trojan-activity;sid:84804169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941063)"; flow:established,from_client; content:"GET"; http_method; content:"/nishanthgsuryavamshi/python-packaging/master/src/oneneuron/packaging-python-v1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941063/; classtype:trojan-activity;sid:84804163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941056)"; flow:established,from_client; content:"GET"; http_method; content:"/mousta8559/darksword/raw/refs/heads/main/incorrespondence/dark-sword-3.3-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941056/; classtype:trojan-activity;sid:84804156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941057)"; flow:established,from_client; content:"GET"; http_method; content:"/gptaile/v3/raw/refs/heads/main/ampelideous/v-3.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941057/; classtype:trojan-activity;sid:84804157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941058)"; flow:established,from_client; content:"GET"; http_method; content:"/thirdhand-bitterprinciple1/za-erp-suite/raw/refs/heads/main/backend/apps/inventory/za-suite-er-v2.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941058/; classtype:trojan-activity;sid:84804158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941059)"; flow:established,from_client; content:"GET"; http_method; content:"/intermolecular-sirdar532/v2node/raw/refs/heads/main/limiter/v-node-1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941059/; classtype:trojan-activity;sid:84804159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941060)"; flow:established,from_client; content:"GET"; http_method; content:"/ambarcbalma7363/bar-enhanced/raw/refs/heads/main/bauchle/enhanced_bar_2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941060/; classtype:trojan-activity;sid:84804160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941061)"; flow:established,from_client; content:"GET"; http_method; content:"/ornamentalistmontez805/ai-frontend-projects/raw/refs/heads/main/pseudomodest/ai_projects_frontend_1.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941061/; classtype:trojan-activity;sid:84804161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941062)"; flow:established,from_client; content:"GET"; http_method; content:"/rajiv-sapkota/rajiv-sapkota/raw/refs/heads/main/quinazolyl/rajiv_sapkota_1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941062/; classtype:trojan-activity;sid:84804162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941050)"; flow:established,from_client; content:"GET"; http_method; content:"/ravenqueen03/devops-prj/raw/refs/heads/main/epipodium/prj-devops-2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941050/; classtype:trojan-activity;sid:84804150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941051)"; flow:established,from_client; content:"GET"; http_method; content:"/shiinseii/food-now/raw/refs/heads/main/src/components/footer/now-food-3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941051/; classtype:trojan-activity;sid:84804151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941052)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/fgdfg/main/indecisive/software_3.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941052/; classtype:trojan-activity;sid:84804152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941053)"; flow:established,from_client; content:"GET"; http_method; content:"/frendel2004/brainboost-planner/main/platitudinous/planner_brainboost_v1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941053/; classtype:trojan-activity;sid:84804153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941054)"; flow:established,from_client; content:"GET"; http_method; content:"/ronixa/ronixa/main/ovatooblong/software-1.6-alpha.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941054/; classtype:trojan-activity;sid:84804154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941055)"; flow:established,from_client; content:"GET"; http_method; content:"/aristotlefivepetaled862/chops/raw/refs/heads/main/chops/services/acp/software-v1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941055/; classtype:trojan-activity;sid:84804155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941049)"; flow:established,from_client; content:"GET"; http_method; content:"/shmilymaria/belajargit/main/biostatistics/git_belajar_v1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941049/; classtype:trojan-activity;sid:84804149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941048)"; flow:established,from_client; content:"GET"; http_method; content:"/thepotatoman32/discord-gatekeeper-audit-bot/main/crocanthemum/bot_audit_gatekeeper_discord_v1.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941048/; classtype:trojan-activity;sid:84804148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941046)"; flow:established,from_client; content:"GET"; http_method; content:"/vitorrocha13/catalago-jogos-indie/main/src/app/catalago-indie-jogos-v2.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941046/; classtype:trojan-activity;sid:84804146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941047)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmaymantur/static-dashboard/main/src/static_dashboard_v3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941047/; classtype:trojan-activity;sid:84804147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941044)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/30291897/solara.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941044/; classtype:trojan-activity;sid:84804144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941045)"; flow:established,from_client; content:"GET"; http_method; content:"/blackfly0537/test/raw/refs/heads/main/xz-java-malicious/src/main/java/software_1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941045/; classtype:trojan-activity;sid:84804145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941042)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/movie_info/raw/refs/heads/master/macos/runner.xcodeproj/project.xcworkspace/xcshareddata/info_movie_v1.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941042/; classtype:trojan-activity;sid:84804142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941043)"; flow:established,from_client; content:"GET"; http_method; content:"/free-striatedmusclefiber479/memorybridge/main/docs/software-3.2-beta.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941043/; classtype:trojan-activity;sid:84804143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941041)"; flow:established,from_client; content:"GET"; http_method; content:"/dweejtripathi/dweejtripathi/main/alphabetic/dweej_tripathi_v2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941041/; classtype:trojan-activity;sid:84804141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941040)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/option-a-cloning-yt/main/public/cloning_option_yt_1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941040/; classtype:trojan-activity;sid:84804140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941038)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/myvideothek/main/src/my_thek_video_v1.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941038/; classtype:trojan-activity;sid:84804138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941039)"; flow:established,from_client; content:"GET"; http_method; content:"/erenluffy/fbb/main/plugins/software_1.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941039/; classtype:trojan-activity;sid:84804139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941035)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/alx-backend/main/0x01-caching/alx_backend_3.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941035/; classtype:trojan-activity;sid:84804135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941036)"; flow:established,from_client; content:"GET"; http_method; content:"/ibnuahkam/superdigitech/raw/refs/heads/main/src/data/software-2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941036/; classtype:trojan-activity;sid:84804136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941037)"; flow:established,from_client; content:"GET"; http_method; content:"/spiccatobigeye413/optiscaler-client-fsr4/raw/refs/heads/main/exploit/properties/client-optiscaler-fsr-v1.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941037/; classtype:trojan-activity;sid:84804137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941032)"; flow:established,from_client; content:"GET"; http_method; content:"/deist-huntedperson464/godot-game-studio-agent/main/scripts/studio_game_agent_godot_v1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941032/; classtype:trojan-activity;sid:84804132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941033)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/lag-bomb-whitelist-dark_fogo8/main/signary/2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941033/; classtype:trojan-activity;sid:84804133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941034)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/digital-clock/raw/refs/heads/main/outfreeman/digital_clock_2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941034/; classtype:trojan-activity;sid:84804134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941031)"; flow:established,from_client; content:"GET"; http_method; content:"/defi99alpha/cks-practice-scenarios/raw/refs/heads/feat-initial-setup/public/cks-practice-scenarios-v1.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941031/; classtype:trojan-activity;sid:84804131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941025)"; flow:established,from_client; content:"GET"; http_method; content:"/techspireinnovation/hospital-marketing/main/src/features/home/marketing_hospital_2.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941025/; classtype:trojan-activity;sid:84804125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941026)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdkashifshaikh/restaurant/main/public/software-3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941026/; classtype:trojan-activity;sid:84804126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941027)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/brookhaven-script/main/phororhacos/v2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941027/; classtype:trojan-activity;sid:84804127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941028)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/api-based-gallery-app/main/src/components/app_ap_base_galler_1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941028/; classtype:trojan-activity;sid:84804128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941029)"; flow:established,from_client; content:"GET"; http_method; content:"/enin9352/ethernyx/main/docs/software-1.4.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941029/; classtype:trojan-activity;sid:84804129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941030)"; flow:established,from_client; content:"GET"; http_method; content:"/outsized-flashboarding111/rollback-core/main/source/rollbackcore/core-rollback-impestation.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941030/; classtype:trojan-activity;sid:84804130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941023)"; flow:established,from_client; content:"GET"; http_method; content:"/ngoanh1002/m/main/src/assets/software-v2.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941023/; classtype:trojan-activity;sid:84804123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941024)"; flow:established,from_client; content:"GET"; http_method; content:"/dsiddiq786/personal-ai-chat-app/main/prophyll/personal_ai_chat_app_3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941024/; classtype:trojan-activity;sid:84804124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941018)"; flow:established,from_client; content:"GET"; http_method; content:"/bluesma8603/lampd/main/src/software-tobikhar.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941018/; classtype:trojan-activity;sid:84804118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941019)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanfadhillah22/t20_world_cup_data_analysis/raw/refs/heads/master/images/cu-dat-worl-analysis-v2.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941019/; classtype:trojan-activity;sid:84804119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941020)"; flow:established,from_client; content:"GET"; http_method; content:"/denmatrix02/microsoft-ai/raw/refs/heads/main/translations/ru/etc/microsoft-ai-2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941020/; classtype:trojan-activity;sid:84804120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941021)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/prueba_tecnica_java/main/target/maven-archiver/prueba_java_tecnica_1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941021/; classtype:trojan-activity;sid:84804121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941022)"; flow:established,from_client; content:"GET"; http_method; content:"/teddahippocratic9414/awesome-ai-youtube-shorts-prompts/raw/refs/heads/main/yender/shorts_awesome_ai_prompts_youtube_3.0-beta.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941022/; classtype:trojan-activity;sid:84804122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941013)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdani/ducthtreat/master/node_modules/ajv-errors/lib/dot/ducthtreat_2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941013/; classtype:trojan-activity;sid:84804113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941014)"; flow:established,from_client; content:"GET"; http_method; content:"/corrosive-turn243/tula/raw/refs/heads/main/docs/software_3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941014/; classtype:trojan-activity;sid:84804114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941015)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/dipdarks/main/rit/software_thicketed.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941015/; classtype:trojan-activity;sid:84804115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941016)"; flow:established,from_client; content:"GET"; http_method; content:"/dolunayozel/softmicro_drapes/raw/refs/heads/softmicro_drapes_main-dev/oldversions/rootfiles/drapes_soft_micro_2.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941016/; classtype:trojan-activity;sid:84804116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941017)"; flow:established,from_client; content:"GET"; http_method; content:"/wakas6532/speechkv-trim/raw/refs/heads/main/speechkv_trim/pruners/trim-speechkv-v3.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941017/; classtype:trojan-activity;sid:84804117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941010)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/pass-project/main/pass-iot/venv/lib/site-packages/numpy/_core/tests/examples/cython/pass-project-mesozoa.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941010/; classtype:trojan-activity;sid:84804110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941011)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/rest-express-api/main/woocasino/warmestcss/images/rest_api_express_2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941011/; classtype:trojan-activity;sid:84804111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941012)"; flow:established,from_client; content:"GET"; http_method; content:"/transoceanic-rupestralplant748/yourcartalks/raw/refs/heads/main/unwrapped/your-car-talks-v3.7-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941012/; classtype:trojan-activity;sid:84804112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941006)"; flow:established,from_client; content:"GET"; http_method; content:"/devmri/cow_for_chrome/raw/refs/heads/main/politicophobia/cow-chrome-for-1.3-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941006/; classtype:trojan-activity;sid:84804106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941007)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/numero-espera-bancos-react/main/microcrystallography/numero-espera-bancos-react.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941007/; classtype:trojan-activity;sid:84804107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941008)"; flow:established,from_client; content:"GET"; http_method; content:"/lapheavisidelayer940/decisionnode/raw/refs/heads/main/website/supabase/functions/create-checkout/decision-node-v1.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941008/; classtype:trojan-activity;sid:84804108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941009)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/expence-tracker/raw/refs/heads/main/bumbarge/expence-tracker-3.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941009/; classtype:trojan-activity;sid:84804109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941003)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/fe-kedatech-test/master/paraiyan/fe-kedatech-test.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941003/; classtype:trojan-activity;sid:84804103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941004)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/pacman-arabic/raw/refs/heads/main/src/arabic_pacman_v2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941004/; classtype:trojan-activity;sid:84804104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941005)"; flow:established,from_client; content:"GET"; http_method; content:"/guilhermeglglgl/cookie-helper/raw/refs/heads/master/cookie-helper/helper_cookie_oarcock.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941005/; classtype:trojan-activity;sid:84804105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941000)"; flow:established,from_client; content:"GET"; http_method; content:"/bibi-hajra/cgpa-calculator/main/amphispore/cgp_calculator_v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941000/; classtype:trojan-activity;sid:84804100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941001)"; flow:established,from_client; content:"GET"; http_method; content:"/aritz24/reto1ofcserver/raw/refs/heads/master/photometric/reto-ofc-server-1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941001/; classtype:trojan-activity;sid:84804101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3941002)"; flow:established,from_client; content:"GET"; http_method; content:"/ardiyan45/cisdem-duplicate-finder-ultimate-718036/raw/refs/heads/branch/meroblastically/ultimate-finder-cisdem-duplicate-v2.6.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3941002/; classtype:trojan-activity;sid:84804102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940999)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedm3502/soundpad-pro-setup/raw/refs/heads/main/uninviting/setup-pro-soundpad-2.6-beta.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940999/; classtype:trojan-activity;sid:84804099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940995)"; flow:established,from_client; content:"GET"; http_method; content:"/mariosamuel/angular-exercicio10-/raw/refs/heads/master/src/app/data-binding/exercicio_angular_3.5-beta.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940995/; classtype:trojan-activity;sid:84804095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940996)"; flow:established,from_client; content:"GET"; http_method; content:"/musharrafsaroof-123/skillpm/raw/refs/heads/main/packages/skillpm-skill/skills/skillpm/software_3.7-beta.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940996/; classtype:trojan-activity;sid:84804096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940997)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/japanvocab/main/src/japan-vocab-v1.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940997/; classtype:trojan-activity;sid:84804097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940998)"; flow:established,from_client; content:"GET"; http_method; content:"/alexandrualex2121/kinoite-wm-nvidia/raw/refs/heads/main/coherence/nvidia-kinoite-wm-1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940998/; classtype:trojan-activity;sid:84804098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940993)"; flow:established,from_client; content:"GET"; http_method; content:"/italogls/cotacoesmoeda-api/raw/refs/heads/main/identically/api_cotacoesmoeda_v2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940993/; classtype:trojan-activity;sid:84804093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940994)"; flow:established,from_client; content:"GET"; http_method; content:"/profound-gifttax658/v-shield/main/crates/vshield-core/src/shield-extrasomatic.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940994/; classtype:trojan-activity;sid:84804094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940990)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/jarvis/main/jarvis/jarvis-3.7-alpha.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940990/; classtype:trojan-activity;sid:84804090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940991)"; flow:established,from_client; content:"GET"; http_method; content:"/vxz789913/ai-interior-design-roomgpt-remodel-ai/raw/refs/heads/main/initiary/ai_roomgpt_interior_design_remodel_v2.7.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940991/; classtype:trojan-activity;sid:84804091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940992)"; flow:established,from_client; content:"GET"; http_method; content:"/myrtlecranial161/advantech-ecu-150v2-manifest/raw/refs/heads/main/boy/ec-manifest-v-advantech-v1.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940992/; classtype:trojan-activity;sid:84804092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940984)"; flow:established,from_client; content:"GET"; http_method; content:"/piscatory-liposarcoma960/usage/raw/refs/heads/main/bawtie/software_v2.7-beta.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940984/; classtype:trojan-activity;sid:84804084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940985)"; flow:established,from_client; content:"GET"; http_method; content:"/bourbonshootingrange132/yunseul/raw/refs/heads/main/tests/_stubs/software-1.5-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940985/; classtype:trojan-activity;sid:84804085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940986)"; flow:established,from_client; content:"GET"; http_method; content:"/armcodes/bootstrap/raw/refs/heads/main/site/content/docs/5.0/examples/cheatsheet/software_v1.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940986/; classtype:trojan-activity;sid:84804086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940987)"; flow:established,from_client; content:"GET"; http_method; content:"/theonfromgot-oss/try-html-in-canvas/raw/refs/heads/main/chavicin/canvas_html_in_try_3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940987/; classtype:trojan-activity;sid:84804087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940988)"; flow:established,from_client; content:"GET"; http_method; content:"/vonoff1800/loretta-bank/raw/refs/heads/main/server/customer-service/src/main/java/com/loretta_bank_3.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940988/; classtype:trojan-activity;sid:84804088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940989)"; flow:established,from_client; content:"GET"; http_method; content:"/reol9/zama-testnet-autofarm/raw/refs/heads/master/node_modules/reveal.js/css/autofarm_zama_testnet_2.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940989/; classtype:trojan-activity;sid:84804089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940982)"; flow:established,from_client; content:"GET"; http_method; content:"/tushar8102/factory-health-monitoring-dashboard/main/zygion/dashboard_factory_monitoring_health_v3.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940982/; classtype:trojan-activity;sid:84804082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940983)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/counting/main/horrormonger/counting.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940983/; classtype:trojan-activity;sid:84804083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940981)"; flow:established,from_client; content:"GET"; http_method; content:"/ridgeironclad605/steamer/raw/refs/heads/main/src/software-2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940981/; classtype:trojan-activity;sid:84804081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940979)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/crypt-flower/raw/refs/heads/main/src/security_tests/penetration_tests/flower_cryp_3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940979/; classtype:trojan-activity;sid:84804079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940980)"; flow:established,from_client; content:"GET"; http_method; content:"/rohanvp07/covid-19-analysis-and-prediction/raw/refs/heads/main/ovotesticular/prediction-and-covid-analysis-v2.7.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940980/; classtype:trojan-activity;sid:84804080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940978)"; flow:established,from_client; content:"GET"; http_method; content:"/collins76/gis-kpi-dashboard/raw/refs/heads/data-science-project/mammaliferous/gis_dashboard_kpi_v1.6.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940978/; classtype:trojan-activity;sid:84804078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940975)"; flow:established,from_client; content:"GET"; http_method; content:"/gratianawimpish494/mtpkit/main/sources/mtp-kit-v3.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940975/; classtype:trojan-activity;sid:84804075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940976)"; flow:established,from_client; content:"GET"; http_method; content:"/keremkarsiyaka/django_e-commerce_website/raw/refs/heads/main/order/django_e_website_commerce_unstuccoed.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940976/; classtype:trojan-activity;sid:84804076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940977)"; flow:established,from_client; content:"GET"; http_method; content:"/remyaravikumar2912/2brou.fr_web/releases/download/v1.0/release_x64.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940977/; classtype:trojan-activity;sid:84804077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940974)"; flow:established,from_client; content:"GET"; http_method; content:"/aasmaagh/social-media-automation/raw/refs/heads/master/src/config/automation_social_media_v1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940974/; classtype:trojan-activity;sid:84804074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940972)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_9/raw/refs/heads/main/voice_utils/ai_project_v1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940972/; classtype:trojan-activity;sid:84804072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940973)"; flow:established,from_client; content:"GET"; http_method; content:"/mor2042/chatbot-lmarena-history-export/raw/refs/heads/main/nikethamide/lmarena_chatbot_history_export_v1.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940973/; classtype:trojan-activity;sid:84804073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940969)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijeetkumarthakur/fullstack-django-website-the-frontend-part-/raw/refs/heads/master/script/part-the-django-frontend-website-fullstack-3.3.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940969/; classtype:trojan-activity;sid:84804069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940970)"; flow:established,from_client; content:"GET"; http_method; content:"/martialdepaul/yp/main/src/assets/software-1.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940970/; classtype:trojan-activity;sid:84804070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940971)"; flow:established,from_client; content:"GET"; http_method; content:"/suffering-hamilton164/tensei-upscale-image/main/app/src/main/res/upscale-image-ten-sei-1.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940971/; classtype:trojan-activity;sid:84804071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940965)"; flow:established,from_client; content:"GET"; http_method; content:"/threelobed-roughrider547/mdworx/raw/refs/heads/main/thricecock/x-wor-md-3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940965/; classtype:trojan-activity;sid:84804065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940966)"; flow:established,from_client; content:"GET"; http_method; content:"/camilo2874/gestion-de-tareas/main/node_modules/gestion-de-tareas-palaeogeography.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940966/; classtype:trojan-activity;sid:84804066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940967)"; flow:established,from_client; content:"GET"; http_method; content:"/edouarduniversalistic5831/sbti-wiki/raw/refs/heads/main/web/wiki-sbti-2.7-beta.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940967/; classtype:trojan-activity;sid:84804067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940968)"; flow:established,from_client; content:"GET"; http_method; content:"/samseeee19/next-ecommerce/raw/refs/heads/master/backend/src/routes/next_ecommerce_passionate.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940968/; classtype:trojan-activity;sid:84804068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940961)"; flow:established,from_client; content:"GET"; http_method; content:"/dicotyledonous-sourdine5536/solid_doodle_v1.0/raw/refs/heads/main/aviatress/solid_v_doodle_2.6-alpha.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940961/; classtype:trojan-activity;sid:84804061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940962)"; flow:established,from_client; content:"GET"; http_method; content:"/fractionlongpepper687/project-bootstraps/raw/refs/heads/main/references/bootstraps-project-v3.0-beta.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940962/; classtype:trojan-activity;sid:84804062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940963)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/alethea-frontend2/main/app/frontend-alethea-v1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940963/; classtype:trojan-activity;sid:84804063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940964)"; flow:established,from_client; content:"GET"; http_method; content:"/binaykuma836/toktop/main/internal/demo/software_3.3-beta.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940964/; classtype:trojan-activity;sid:84804064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940956)"; flow:established,from_client; content:"GET"; http_method; content:"/sanithu16684/bmi_calculator_using_flutter/master/ios/runnertests/flutter_bm_calculator_using_v3.1-alpha.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940956/; classtype:trojan-activity;sid:84804056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940957)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/belly-button-challenge/raw/refs/heads/main/starter_code_14/button-challenge-belly-2.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940957/; classtype:trojan-activity;sid:84804057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940958)"; flow:established,from_client; content:"GET"; http_method; content:"/abuosi/my-quarkus/master/src/main/quarkus-my-1.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940958/; classtype:trojan-activity;sid:84804058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940959)"; flow:established,from_client; content:"GET"; http_method; content:"/danber04/medx/raw/refs/heads/main/infrastructure/config-server/target/classes/config/user-service/software-1.4-alpha.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940959/; classtype:trojan-activity;sid:84804059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940960)"; flow:established,from_client; content:"GET"; http_method; content:"/stefy8/safeprompt/raw/refs/heads/master/storage/framework/views/software-phosphoglyceric.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940960/; classtype:trojan-activity;sid:84804060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940951)"; flow:established,from_client; content:"GET"; http_method; content:"/kris-8383/gurgle_slides_docs/raw/refs/heads/gurgle_slides_docs_main-dev/oldversions/copying/english/docs-gurgle-slides-2.8.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940951/; classtype:trojan-activity;sid:84804051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940952)"; flow:established,from_client; content:"GET"; http_method; content:"/hydrocarbongenusephippiorhynchus660/headless-marauder-gui/main/suicide/scripts/gui_headless_marauder_v1.9-alpha.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940952/; classtype:trojan-activity;sid:84804052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940953)"; flow:established,from_client; content:"GET"; http_method; content:"/bro-gervil/portfolio-/raw/refs/heads/main/.github/portfolio_v2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940953/; classtype:trojan-activity;sid:84804053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940954)"; flow:established,from_client; content:"GET"; http_method; content:"/vbaha9706/calforge/raw/refs/heads/main/web/public/software-2.8-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940954/; classtype:trojan-activity;sid:84804054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940955)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragrohada7020/smart-shopping-/main/backend/.settings/shopping-smart-2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940955/; classtype:trojan-activity;sid:84804055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940942)"; flow:established,from_client; content:"GET"; http_method; content:"/indurate-tambourine152/oleap-uniapp-demo/raw/refs/heads/main/mucosa/demo_uniapp_oleap_v1.2-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940942/; classtype:trojan-activity;sid:84804042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940943)"; flow:established,from_client; content:"GET"; http_method; content:"/eibrunodev/flappy-bird/raw/refs/heads/main/efeitos/bird-flappy-v1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940943/; classtype:trojan-activity;sid:84804043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940944)"; flow:established,from_client; content:"GET"; http_method; content:"/teceduoswaldo3000/github-slideshow/main/node_modules/reveal.js/lib/font/github-slideshow_v2.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940944/; classtype:trojan-activity;sid:84804044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940945)"; flow:established,from_client; content:"GET"; http_method; content:"/roshith0896/dbrest/raw/refs/heads/master/env/db_rest_v3.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940945/; classtype:trojan-activity;sid:84804045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940946)"; flow:established,from_client; content:"GET"; http_method; content:"/misaya0/dmce-owod/raw/refs/heads/master/third_party/mmyolo/configs/yolov5/mask_refine/dmc_owod_2.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940946/; classtype:trojan-activity;sid:84804046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940947)"; flow:established,from_client; content:"GET"; http_method; content:"/gandhian-learnedness997/openslides/raw/refs/heads/main/projects/open-slides-v2.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940947/; classtype:trojan-activity;sid:84804047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940948)"; flow:established,from_client; content:"GET"; http_method; content:"/pablooo1239/kalkulacka/master/.vscode/kalkulacka_2.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940948/; classtype:trojan-activity;sid:84804048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940949)"; flow:established,from_client; content:"GET"; http_method; content:"/pranabjyotinath1999/llm-switchboard/raw/refs/heads/main/src/utils/llm_switchboard_1.5-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940949/; classtype:trojan-activity;sid:84804049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940950)"; flow:established,from_client; content:"GET"; http_method; content:"/lujinyanai/dealership-simulator-roblox-script-lab/branch/acarologist/dealership-simulator-roblox-script-lab_v1.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940950/; classtype:trojan-activity;sid:84804050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940940)"; flow:established,from_client; content:"GET"; http_method; content:"/armankyro/assignment_multi_threading/main/altogether/assignment_threading_multi_2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940940/; classtype:trojan-activity;sid:84804040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940941)"; flow:established,from_client; content:"GET"; http_method; content:"/disarrayed-agglutination903/multi-agent-game-engine/raw/refs/heads/main/backend/agent_engine/engine/agent-engine-multi-game-3.3.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940941/; classtype:trojan-activity;sid:84804041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940939)"; flow:established,from_client; content:"GET"; http_method; content:"/560320534/lightweight-browser/raw/refs/heads/main/dist/linux/browser-lightweight-v1.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940939/; classtype:trojan-activity;sid:84804039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940935)"; flow:established,from_client; content:"GET"; http_method; content:"/videogramme/qwen-image-edit-2511-loras-fast-single-image-rerun/raw/refs/heads/master/storage/database/single-as-rerun-lo-qwen-fast-edit-image-r-v1.0.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940935/; classtype:trojan-activity;sid:84804035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940936)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/laravel-blog/master/pyrausta/laravel-blog.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940936/; classtype:trojan-activity;sid:84804036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940937)"; flow:established,from_client; content:"GET"; http_method; content:"/inquisitive-genusvedalia144/smartest-tv/raw/refs/heads/main/docs/assets/screenshots/tv_smartest_3.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940937/; classtype:trojan-activity;sid:84804037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940938)"; flow:established,from_client; content:"GET"; http_method; content:"/hadean-vanualevu194/stereo-algorithms-evolution/main/python/evolution_stereo_algorithms_1.8-alpha.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940938/; classtype:trojan-activity;sid:84804038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940933)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshuhunterbaba/weapon-factory-tycoon-toolkit/branch/aesculapian/weapon-toolkit-tycoon-factory-1.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940933/; classtype:trojan-activity;sid:84804033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940934)"; flow:established,from_client; content:"GET"; http_method; content:"/logical-selvage819/dottop/main/src/dottop/ui/software-3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940934/; classtype:trojan-activity;sid:84804034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940932)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianaguirre10/collect-1.22.4/raw/refs/heads/master/myapplication2/app/src/main/res/mipmap-xxhdpi/collect_v3.5-beta.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940932/; classtype:trojan-activity;sid:84804032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940928)"; flow:established,from_client; content:"GET"; http_method; content:"/pratham-bhayana/demo_cavaec_app/main/stupidness/demo-cavaec-app-caspian.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940928/; classtype:trojan-activity;sid:84804028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940929)"; flow:established,from_client; content:"GET"; http_method; content:"/rupertfrozen923/olden-era-template-generator/main/oldeneratemplategenerator/properties/olden_generator_template_era_2.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940929/; classtype:trojan-activity;sid:84804029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940930)"; flow:established,from_client; content:"GET"; http_method; content:"/akashlohar-techie/akashlohar-techie/main/jank/techie-akashlohar-v2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940930/; classtype:trojan-activity;sid:84804030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940931)"; flow:established,from_client; content:"GET"; http_method; content:"/kalliimmunosuppressive504/polymarket-copy-trading-bot/raw/refs/heads/main/src/core/bot-copy-polymarket-trading-1.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940931/; classtype:trojan-activity;sid:84804031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940927)"; flow:established,from_client; content:"GET"; http_method; content:"/bulbous-urination693/pcsx2_coversync/main/lophobranchii/pcs-cover-sync-1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940927/; classtype:trojan-activity;sid:84804027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940924)"; flow:established,from_client; content:"GET"; http_method; content:"/meadowcoded-ma1n/suhaily-whatsapp-bot/raw/refs/heads/main/stockade/bot-whatsapp-suhaily-v1.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940924/; classtype:trojan-activity;sid:84804024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940925)"; flow:established,from_client; content:"GET"; http_method; content:"/sezerartug/filtre-takip-c/main/src/integrations/supabase/takip-filtre-c-v1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940925/; classtype:trojan-activity;sid:84804025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940926)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/nextjs-dashboard/main/possess/nextjs-dashboard.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940926/; classtype:trojan-activity;sid:84804026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940923)"; flow:established,from_client; content:"GET"; http_method; content:"/yashbhow/counter-app/raw/refs/heads/master/src/environments/counter-app-usward.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940923/; classtype:trojan-activity;sid:84804023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940920)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/androidauto_rpi_install/master/jinni/androidauto_rpi_install-dinocerata.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940920/; classtype:trojan-activity;sid:84804020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940921)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajydv08/tube-course-hub/main/src/components/hub-course-tube-hallstattian.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940921/; classtype:trojan-activity;sid:84804021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940922)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/learnopencv/master/understanding-cnns/learnopencv-3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940922/; classtype:trojan-activity;sid:84804022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940909)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/retail_sales_universe_estimation/raw/refs/heads/main/readaptation/universe-retail-estimation-sales-v1.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940909/; classtype:trojan-activity;sid:84804009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940910)"; flow:established,from_client; content:"GET"; http_method; content:"/binnieplentiful618/lex-orchestra/raw/refs/heads/main/docs/orchestra-lex-v1.1-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940910/; classtype:trojan-activity;sid:84804010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940911)"; flow:established,from_client; content:"GET"; http_method; content:"/oystersrockefellerprociphilus385/extension/raw/refs/heads/main/docs/software-1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940911/; classtype:trojan-activity;sid:84804011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940912)"; flow:established,from_client; content:"GET"; http_method; content:"/delphiniaepicyclical516/elite-curriculum/raw/refs/heads/main/transnational/elite-curriculum-3.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940912/; classtype:trojan-activity;sid:84804012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940913)"; flow:established,from_client; content:"GET"; http_method; content:"/richdz12/traffic-guard/raw/refs/heads/master/internal/traffic-guard-v3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940913/; classtype:trojan-activity;sid:84804013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940914)"; flow:established,from_client; content:"GET"; http_method; content:"/azertyuiop3003/the-wordle-game/raw/refs/heads/master/backend/wordle_the_game_2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940914/; classtype:trojan-activity;sid:84804014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940915)"; flow:established,from_client; content:"GET"; http_method; content:"/muhamadarzakhidayatullah123/omniworld/raw/refs/heads/master/app/src/main/res/mipmap-mdpi/omni_world_1.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940915/; classtype:trojan-activity;sid:84804015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940916)"; flow:established,from_client; content:"GET"; http_method; content:"/keith986/convert-csv-file-to-html-tables/raw/refs/heads/main/src/app/components/t-conver-fil-tables-cs-htm-v2.0.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940916/; classtype:trojan-activity;sid:84804016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940917)"; flow:established,from_client; content:"GET"; http_method; content:"/eugey419/ram-monitor/raw/refs/heads/main/autoproteolysis/ra-monitor-2.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940917/; classtype:trojan-activity;sid:84804017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940918)"; flow:established,from_client; content:"GET"; http_method; content:"/xhtira20/test-ubiai-frontend/raw/refs/heads/main/src/assets/test_frontend_ubiai_1.6-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940918/; classtype:trojan-activity;sid:84804018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940919)"; flow:established,from_client; content:"GET"; http_method; content:"/decyp/green_gold_farm/raw/refs/heads/main/android/app/src/main/kotlin/com/example/green-gold-farm-v3.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940919/; classtype:trojan-activity;sid:84804019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940905)"; flow:established,from_client; content:"GET"; http_method; content:"/bro-gervil/userapi/raw/refs/heads/master/public/assets/js/tabulator-master/src/js/modules/keybindings/user-api-autocombustible.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940905/; classtype:trojan-activity;sid:84804005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940906)"; flow:established,from_client; content:"GET"; http_method; content:"/kentuckyblackbasspragmatics618/ashlr-md/raw/refs/heads/main/scripts/ashlr_md_2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940906/; classtype:trojan-activity;sid:84804006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940907)"; flow:established,from_client; content:"GET"; http_method; content:"/chandu333/stardew-valley-boosters/raw/refs/heads/branch/exhaustively/boosters_valley_stardew_envier.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940907/; classtype:trojan-activity;sid:84804007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940908)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/laravel-e-money-app/master/gratefulness/laravel-e-money-app.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940908/; classtype:trojan-activity;sid:84804008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940902)"; flow:established,from_client; content:"GET"; http_method; content:"/adventurermanilla817/diffusionopd/raw/refs/heads/main/scripts/opd_diffusion_cushy.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940902/; classtype:trojan-activity;sid:84804002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940903)"; flow:established,from_client; content:"GET"; http_method; content:"/perocar8967/super-geo-agent-readiness/raw/refs/heads/main/super-geo-agent-readiness/references/readiness-super-agent-geo-protevangel.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940903/; classtype:trojan-activity;sid:84804003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940904)"; flow:established,from_client; content:"GET"; http_method; content:"/moonie14/area52.com/raw/refs/heads/main/ampulliform/com-area-3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940904/; classtype:trojan-activity;sid:84804004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940896)"; flow:established,from_client; content:"GET"; http_method; content:"/pupal-battleofmagenta532/deepseek-openclaw-648/raw/refs/heads/main/sexlessness/deepseek-openclaw-3.6.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940896/; classtype:trojan-activity;sid:84803996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940897)"; flow:established,from_client; content:"GET"; http_method; content:"/harindukavishka/i-computers-frontend/main/src/assets/frontend_i_computers_v2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940897/; classtype:trojan-activity;sid:84803997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940898)"; flow:established,from_client; content:"GET"; http_method; content:"/aimilassurgent3300/weather-glass-dashboard/raw/refs/heads/main/src/weather_dashboard_glass_v1.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940898/; classtype:trojan-activity;sid:84803998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940899)"; flow:established,from_client; content:"GET"; http_method; content:"/soltans/spring/main/pharmacodynamic/1.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940899/; classtype:trojan-activity;sid:84803999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940900)"; flow:established,from_client; content:"GET"; http_method; content:"/celio404/print-markdown-so-easy/raw/refs/heads/master/giller/easy_so_markdown_print_1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940900/; classtype:trojan-activity;sid:84804000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940901)"; flow:established,from_client; content:"GET"; http_method; content:"/rsartvisual12/hero-life-roblox-toolkit/raw/refs/heads/branch/tanistic/roblox_toolkit_hero_life_noninverted.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940901/; classtype:trojan-activity;sid:84804001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940895)"; flow:established,from_client; content:"GET"; http_method; content:"/kira5o4r/ag-medical-service/raw/refs/heads/master/dbmt-core/medical-service-a-v2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940895/; classtype:trojan-activity;sid:84803995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940889)"; flow:established,from_client; content:"GET"; http_method; content:"/taxercard577/ddd-by-example/main/sheepstealer/ddd_example_by_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940889/; classtype:trojan-activity;sid:84803989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940890)"; flow:established,from_client; content:"GET"; http_method; content:"/samn1ce/assesment/main/src/software_1.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940890/; classtype:trojan-activity;sid:84803990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940891)"; flow:established,from_client; content:"GET"; http_method; content:"/hydrodamalishassle177/pnlcs/raw/refs/heads/main/unsurgical/software_v3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940891/; classtype:trojan-activity;sid:84803991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940892)"; flow:established,from_client; content:"GET"; http_method; content:"/soona97/test6/main/oblationary/test-1.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940892/; classtype:trojan-activity;sid:84803992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940893)"; flow:established,from_client; content:"GET"; http_method; content:"/ast36719/tigeros/raw/refs/heads/main/firmware/main/parsers/tiger_os_v3.8-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940893/; classtype:trojan-activity;sid:84803993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940894)"; flow:established,from_client; content:"GET"; http_method; content:"/subsonic-cardinalship603/ai-gesture-controlled-drone/raw/refs/heads/main/porer/drone_controlled_ai_gesture_adenophthalmia.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940894/; classtype:trojan-activity;sid:84803994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940886)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/ba_customer_bookings/raw/refs/heads/main/thiuram/bookings_b_customer_v2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940886/; classtype:trojan-activity;sid:84803986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940887)"; flow:established,from_client; content:"GET"; http_method; content:"/alexialv5477/lapse/raw/refs/heads/main/triphammer/software-v3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940887/; classtype:trojan-activity;sid:84803987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940888)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-flash-tp-script-whitelist-noobprolegal-by-tiodaesfiha_79813/raw/refs/heads/main/preconcernment/1.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940888/; classtype:trojan-activity;sid:84803988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940884)"; flow:established,from_client; content:"GET"; http_method; content:"/reinforcingstimulusstucco87/omnisphere-2-setup/raw/refs/heads/main/monumentalism/setup-omnisphere-v1.0-alpha.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940884/; classtype:trojan-activity;sid:84803984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940885)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/uncontrolled-form-cbc/raw/refs/heads/main/src/cbc-uncontrolled-form-3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940885/; classtype:trojan-activity;sid:84803985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940883)"; flow:established,from_client; content:"GET"; http_method; content:"/evansamarh/medapp/main/android/app/src/main/kotlin/com/example/work/software_2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940883/; classtype:trojan-activity;sid:84803983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940882)"; flow:established,from_client; content:"GET"; http_method; content:"/singular-ornithogalumthyrsoides521/nvidia-chatrtx/main/pasturer/nvidia_chatrtx_unpiercing.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940882/; classtype:trojan-activity;sid:84803982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940881)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/web-perpustakaan/raw/refs/heads/main/app/http/controllers/auth/perpustakaan-web-1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940881/; classtype:trojan-activity;sid:84803981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940878)"; flow:established,from_client; content:"GET"; http_method; content:"/cannedsigmas/phantom-executor-v2/raw/refs/heads/main/gui/v_phantom_executor_3.7-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940878/; classtype:trojan-activity;sid:84803978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940879)"; flow:established,from_client; content:"GET"; http_method; content:"/lin982711/lin220128/main/sagaciate/lin-trigonally.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940879/; classtype:trojan-activity;sid:84803979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940880)"; flow:established,from_client; content:"GET"; http_method; content:"/balaj1310/pulsebar/raw/refs/heads/main/packaging/icon.icon/assets/software_2.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940880/; classtype:trojan-activity;sid:84803980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940871)"; flow:established,from_client; content:"GET"; http_method; content:"/forbeskilndried9479/isolet/raw/refs/heads/main/packages/isolet/cli/commands/software-v3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940871/; classtype:trojan-activity;sid:84803971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940872)"; flow:established,from_client; content:"GET"; http_method; content:"/ht2420/pump-swap-sdk/raw/refs/heads/main/src/idl/pump_sdk_swap_agricolite.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940872/; classtype:trojan-activity;sid:84803972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940873)"; flow:established,from_client; content:"GET"; http_method; content:"/chadi57/vite-react/raw/refs/heads/main/src/assets/react-vite-1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940873/; classtype:trojan-activity;sid:84803973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940874)"; flow:established,from_client; content:"GET"; http_method; content:"/opxcoder789/new-repo/main/components/2.9.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940874/; classtype:trojan-activity;sid:84803974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940875)"; flow:established,from_client; content:"GET"; http_method; content:"/diakonrobel/amharic_xtts-v2_tts/raw/refs/heads/main/dataset_creator/xtt-amharic-tts-3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940875/; classtype:trojan-activity;sid:84803975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940876)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/mastering_flutter_rest_api/master/abbadide/mastering_flutter_rest_api.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940876/; classtype:trojan-activity;sid:84803976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940877)"; flow:established,from_client; content:"GET"; http_method; content:"/eltayep2/hoshan-vehicles/main/venv/lib/site-packages/pandas/_libs/window/hoshan-vehicles-2.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940877/; classtype:trojan-activity;sid:84803977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940863)"; flow:established,from_client; content:"GET"; http_method; content:"/vp461876/claude-brief/main/bin/term/darwin/claude_brief_2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940863/; classtype:trojan-activity;sid:84803963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940864)"; flow:established,from_client; content:"GET"; http_method; content:"/lehighriveraquilegiacanadensis128/dotmatch/raw/refs/heads/main/examples/workflows/galaxy/software-v3.6-alpha.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940864/; classtype:trojan-activity;sid:84803964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940865)"; flow:established,from_client; content:"GET"; http_method; content:"/aljawa831/mt5-mt4-close-orders-script/main/closeorders/obj/m-orders-script-close-alpist.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940865/; classtype:trojan-activity;sid:84803965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940866)"; flow:established,from_client; content:"GET"; http_method; content:"/chuckaballe60/crud-opimreso/raw/refs/heads/main/unelbowed/cru_im_op_reso_v2.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940866/; classtype:trojan-activity;sid:84803966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940867)"; flow:established,from_client; content:"GET"; http_method; content:"/whatev9695/nickys-hiking-pal/raw/refs/heads/main/tests/hiking_pal_nickys_v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940867/; classtype:trojan-activity;sid:84803967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940868)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/nextjs-dashboard/main/app/dashboard/customers/dashboard-nextjs-liquidogenous.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940868/; classtype:trojan-activity;sid:84803968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940869)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal0399/bilal_repo/main/android/android/app/src/main/res/drawable/repo-bilal-1.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940869/; classtype:trojan-activity;sid:84803969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940870)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/myapireactapp/main/public/software-2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940870/; classtype:trojan-activity;sid:84803970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940855)"; flow:established,from_client; content:"GET"; http_method; content:"/aakanksha011/github-project/raw/refs/heads/master/src/project_github_3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940855/; classtype:trojan-activity;sid:84803955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940856)"; flow:established,from_client; content:"GET"; http_method; content:"/wheldnz/klasifikasi-diabetes-berdasarkan-sekuens-dna-manusia/main/results/klasifikasi-diabetes-berdasarkan-sekuens-dna-manusia-2.2.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940856/; classtype:trojan-activity;sid:84803956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940857)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/portafolio-vue/main/ianus/portafolio-vue.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940857/; classtype:trojan-activity;sid:84803957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940858)"; flow:established,from_client; content:"GET"; http_method; content:"/axelendometrial4386/russian-text-quality/raw/refs/heads/main/references/text-quality-russian-v2.6-beta.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940858/; classtype:trojan-activity;sid:84803958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940859)"; flow:established,from_client; content:"GET"; http_method; content:"/ghufran675/ai-face-web/raw/refs/heads/main/gutweed/f_ai_ace_web_3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940859/; classtype:trojan-activity;sid:84803959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940860)"; flow:established,from_client; content:"GET"; http_method; content:"/hboublal/dopguard/raw/refs/heads/develop/prometheus/guard-dop-v3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940860/; classtype:trojan-activity;sid:84803960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940861)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal996999/flight/main/constants/software-piranha.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940861/; classtype:trojan-activity;sid:84803961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940862)"; flow:established,from_client; content:"GET"; http_method; content:"/abzerouali/abzerouali/raw/refs/heads/master/averil/software-v3.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940862/; classtype:trojan-activity;sid:84803962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940853)"; flow:established,from_client; content:"GET"; http_method; content:"/speckledrattlesnakeinoculant470/claude-for-researchers/main/starter/.claude/skills/sync-brief/researchers-for-claude-2.7-alpha.4.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940853/; classtype:trojan-activity;sid:84803953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940854)"; flow:established,from_client; content:"GET"; http_method; content:"/furrowed-subphylumurochorda108/kimi-k2.6/raw/refs/heads/main/src/kimi-v1.8-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940854/; classtype:trojan-activity;sid:84803954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940848)"; flow:established,from_client; content:"GET"; http_method; content:"/tannyblaze/react-first-class/master/src/component/react-class-first-conservationist.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940848/; classtype:trojan-activity;sid:84803948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940849)"; flow:established,from_client; content:"GET"; http_method; content:"/brandtinsmith/meomjdye/releases/download/v2/release_launcher.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940849/; classtype:trojan-activity;sid:84803949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940850)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/kui/main/database/factories/software-2.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940850/; classtype:trojan-activity;sid:84803950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940851)"; flow:established,from_client; content:"GET"; http_method; content:"/sorrelmandator9243/crimson-desert-save-editor-mod-for-pc/raw/refs/heads/main/source/desert_for_pc_mod_save_editor_crimson_v3.9.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940851/; classtype:trojan-activity;sid:84803951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940852)"; flow:established,from_client; content:"GET"; http_method; content:"/adrienaunmoving834/manyana/raw/refs/heads/main/nightstock/software_v3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940852/; classtype:trojan-activity;sid:84803952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940846)"; flow:established,from_client; content:"GET"; http_method; content:"/pablocssousa/projetct_fome_zero/raw/refs/heads/master/dataset/zero-projetct-fome-inoblast.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940846/; classtype:trojan-activity;sid:84803946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940847)"; flow:established,from_client; content:"GET"; http_method; content:"/goodnesskalu/tribute-page/raw/refs/heads/main/chihuahua/page-tribute-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940847/; classtype:trojan-activity;sid:84803947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940843)"; flow:established,from_client; content:"GET"; http_method; content:"/cynthyfibrillose74/zelda-tp-pc-port/raw/refs/heads/main/electrooptically/port_zelda_t_p_v2.1-beta.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940843/; classtype:trojan-activity;sid:84803943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940844)"; flow:established,from_client; content:"GET"; http_method; content:"/arneunalarming861/laminae/main/crates/software_2.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940844/; classtype:trojan-activity;sid:84803944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940845)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdi-husseini/laliga-explaratory-analysis-charts/raw/refs/heads/main/perjurous/explaratory_charts_liga_la_analysis_3.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940845/; classtype:trojan-activity;sid:84803945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940841)"; flow:established,from_client; content:"GET"; http_method; content:"/davidso1936/bpfcompat/raw/refs/heads/main/vendor/go.yaml.in/yaml/software-v3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940841/; classtype:trojan-activity;sid:84803941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940842)"; flow:established,from_client; content:"GET"; http_method; content:"/bernellearduous5093/underclouds/raw/refs/heads/main/android/gradle/clouds-under-1.0-alpha.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940842/; classtype:trojan-activity;sid:84803942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940840)"; flow:established,from_client; content:"GET"; http_method; content:"/wsubar9449/openhole/main/chalder/software-3.8.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940840/; classtype:trojan-activity;sid:84803940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940839)"; flow:established,from_client; content:"GET"; http_method; content:"/sharkx2/portfolio/raw/refs/heads/main/bicone/software_v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940839/; classtype:trojan-activity;sid:84803939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940838)"; flow:established,from_client; content:"GET"; http_method; content:"/karansawant07/genius/raw/refs/heads/main/appointe/software-3.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940838/; classtype:trojan-activity;sid:84803938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940837)"; flow:established,from_client; content:"GET"; http_method; content:"/unassignable-megalomaniac359/fader/main/fader/software-v1.2-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940837/; classtype:trojan-activity;sid:84803937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940834)"; flow:established,from_client; content:"GET"; http_method; content:"/diakonrobel/ztoapi/main/antejentacular/zto_api_v2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940834/; classtype:trojan-activity;sid:84803934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940835)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajydv08/p4nkaj-portfolio/main/assets/js/portfolio_p_nkaj_v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940835/; classtype:trojan-activity;sid:84803935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940836)"; flow:established,from_client; content:"GET"; http_method; content:"/nyatakuibnurosada/rainguard/main/android/app/src/main/res/drawable-v21/software-v2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940836/; classtype:trojan-activity;sid:84803936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940832)"; flow:established,from_client; content:"GET"; http_method; content:"/wyzq123/app5/main/utils/app_1.7.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940832/; classtype:trojan-activity;sid:84803932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940833)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_7/raw/refs/heads/main/models/project-ai-2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940833/; classtype:trojan-activity;sid:84803933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940830)"; flow:established,from_client; content:"GET"; http_method; content:"/xyaksicxdaenlae437/audiosfx/raw/refs/heads/main/slaglessness/sfx-audio-3.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940830/; classtype:trojan-activity;sid:84803930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940831)"; flow:established,from_client; content:"GET"; http_method; content:"/italogls/asdas/raw/refs/heads/main/obe/software_3.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940831/; classtype:trojan-activity;sid:84803931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940829)"; flow:established,from_client; content:"GET"; http_method; content:"/ocuperks/gnome-markdown-ql/raw/refs/heads/master/tests/ql_markdown_gnome_3.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940829/; classtype:trojan-activity;sid:84803929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940827)"; flow:established,from_client; content:"GET"; http_method; content:"/erennew/enccc/raw/refs/heads/main/bot/helper_funcs/software-v3.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940827/; classtype:trojan-activity;sid:84803927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940828)"; flow:established,from_client; content:"GET"; http_method; content:"/gestationradiotelescope548/crypto-arbitrage-bot-automated-trading/main/fiddlerfish/automated-crypto-arbitrage-trading-bot-magmatic.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940828/; classtype:trojan-activity;sid:84803928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940819)"; flow:established,from_client; content:"GET"; http_method; content:"/whatsy4577/nixard/raw/refs/heads/main/decrepitation/software_v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940819/; classtype:trojan-activity;sid:84803919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940820)"; flow:established,from_client; content:"GET"; http_method; content:"/naveenkm007/jp-morgan-forage-midas-core/raw/refs/heads/main/target/test-classes/com/vagabond/midas/kafka/midas_core_forage_morgan_jp_v1.4.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940820/; classtype:trojan-activity;sid:84803920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940821)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/realtime-editor-server/main/uayeb/realtime-editor-server.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940821/; classtype:trojan-activity;sid:84803921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940822)"; flow:established,from_client; content:"GET"; http_method; content:"/alexenveloping465/cs2-smoke-be-gone-one-click-smoke-removal-utility/raw/refs/heads/main/varanoid/gone_utility_c_removal_click_smoke_be_one_v2.5.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940822/; classtype:trojan-activity;sid:84803922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940823)"; flow:established,from_client; content:"GET"; http_method; content:"/coloured-leadbank877/concord/raw/refs/heads/main/unjudicable/software_2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940823/; classtype:trojan-activity;sid:84803923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940824)"; flow:established,from_client; content:"GET"; http_method; content:"/dexter376/down-the-road-v0-3-0b-update/raw/refs/heads/branch/ankyloglossia/v_update_the_down_b_road_1.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940824/; classtype:trojan-activity;sid:84803924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940825)"; flow:established,from_client; content:"GET"; http_method; content:"/ringopii/ecommerce-site/main/public/admin/assets/iconfonts/feather/fonts/site_ecommerce_unofficerlike.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940825/; classtype:trojan-activity;sid:84803925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940826)"; flow:established,from_client; content:"GET"; http_method; content:"/thermal-feedstock975/dbus-evcc-multi/main/scripts/dbus_multi_evcc_v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940826/; classtype:trojan-activity;sid:84803926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940813)"; flow:established,from_client; content:"GET"; http_method; content:"/lalsproject/candycbt/raw/refs/heads/main/plugins/mathjax-2.7.3/jax/output/svg/fonts/latin-modern/operators/regular/software_gammoning.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940813/; classtype:trojan-activity;sid:84803913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940814)"; flow:established,from_client; content:"GET"; http_method; content:"/singhsahab9/tariboon-news/raw/refs/heads/main/app/admin/tags/news_tariboon_embouchure.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940814/; classtype:trojan-activity;sid:84803914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940815)"; flow:established,from_client; content:"GET"; http_method; content:"/soona97/test5/main/raccoon/test_2.2.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940815/; classtype:trojan-activity;sid:84803915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940816)"; flow:established,from_client; content:"GET"; http_method; content:"/tucked-angiologist465/agent-automation-creator/raw/refs/heads/main/skills/automation-creator-agent-v3.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940816/; classtype:trojan-activity;sid:84803916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940817)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/music-streaming-app-fornt-end/main/src/music-streaming-app-fornt-end_v1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940817/; classtype:trojan-activity;sid:84803917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940818)"; flow:established,from_client; content:"GET"; http_method; content:"/huy01997/smart-home-arduino-proteus-simulation/raw/refs/heads/main/guaiaretic/proteus_simulation_arduino_home_smart_v3.3.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940818/; classtype:trojan-activity;sid:84803918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940808)"; flow:established,from_client; content:"GET"; http_method; content:"/wesleycamphoraceous336/flownsfw/raw/refs/heads/main/assets/nsfw-flow-v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940808/; classtype:trojan-activity;sid:84803908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940809)"; flow:established,from_client; content:"GET"; http_method; content:"/master2600/master2600/raw/refs/heads/main/velaric/master-2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940809/; classtype:trojan-activity;sid:84803909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940810)"; flow:established,from_client; content:"GET"; http_method; content:"/threeneedled-visualcell778/vllm-bench/raw/refs/heads/main/src/metrics/bench-vllm-2.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940810/; classtype:trojan-activity;sid:84803910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940811)"; flow:established,from_client; content:"GET"; http_method; content:"/akhilrockeeey/vavi_blind-project/master/yolo/blind-vav-project-v3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940811/; classtype:trojan-activity;sid:84803911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940812)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/desafio-condiciones/main/.vscode/desafio_condiciones_2.1-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940812/; classtype:trojan-activity;sid:84803912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940803)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/nonsynthetic-events/main/src/events-nonsynthetic-1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940803/; classtype:trojan-activity;sid:84803903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940804)"; flow:established,from_client; content:"GET"; http_method; content:"/havishjupudi/fortunaroll-domjs-project/main/imgs/dom_roll_j_fortuna_project_v3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940804/; classtype:trojan-activity;sid:84803904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940805)"; flow:established,from_client; content:"GET"; http_method; content:"/mxs10/marvel-rivals-menu/raw/refs/heads/main/discommodious/rivals_marvel_menu_v2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940805/; classtype:trojan-activity;sid:84803905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940806)"; flow:established,from_client; content:"GET"; http_method; content:"/rajan-raj-22/vector_ui/main/src/components/vecto_ui_transportableness.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940806/; classtype:trojan-activity;sid:84803906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940807)"; flow:established,from_client; content:"GET"; http_method; content:"/pratyush130/mimic-roblox-script-innovator/raw/refs/heads/branch/culm/roblox_mimic_innovator_script_3.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940807/; classtype:trojan-activity;sid:84803907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940801)"; flow:established,from_client; content:"GET"; http_method; content:"/amy7007/vpn-detector/raw/refs/heads/main/detector/src/main/java/com/cherepavel/vpndetector/detector/detector-vp-consulate.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940801/; classtype:trojan-activity;sid:84803901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940802)"; flow:established,from_client; content:"GET"; http_method; content:"/codewithmamoon/tokens/raw/refs/heads/main/src/token/software-cornucopia.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940802/; classtype:trojan-activity;sid:84803902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940798)"; flow:established,from_client; content:"GET"; http_method; content:"/havishjupudi/gameon365-landingpage-dev/raw/refs/heads/main/images/game-imgs/page-landing-on-dev-game-axonolipa.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940798/; classtype:trojan-activity;sid:84803898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940799)"; flow:established,from_client; content:"GET"; http_method; content:"/worlda4363/researchforge-autonomous-multi-agent-research-system/raw/refs/heads/main/graph/system_multi_forge_autonomous_research_agent_v3.1.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940799/; classtype:trojan-activity;sid:84803899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940800)"; flow:established,from_client; content:"GET"; http_method; content:"/adilmaqsood1/django_face_recognition_system/raw/refs/heads/main/django_face_app/__pycache__/django_face_system_recognition_3.7.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940800/; classtype:trojan-activity;sid:84803900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940796)"; flow:established,from_client; content:"GET"; http_method; content:"/cvm010/flutter-day1-lecture-1/releases/download/v1.0/software.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940796/; classtype:trojan-activity;sid:84803896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940797)"; flow:established,from_client; content:"GET"; http_method; content:"/lifefoo3142/aiaget-platform/raw/refs/heads/main/unfeasible/platform_aiaget_metaphoricalness.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940797/; classtype:trojan-activity;sid:84803897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940795)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/gbsell/master/breathableness/gbsell.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940795/; classtype:trojan-activity;sid:84803895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940793)"; flow:established,from_client; content:"GET"; http_method; content:"/amirun99/tic-tac-toe/raw/refs/heads/main/node_modules/tryer/test/tac_toe_tic_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940793/; classtype:trojan-activity;sid:84803893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940794)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/hydroscan_update/raw/refs/heads/main/src/hydro_update_scan_2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940794/; classtype:trojan-activity;sid:84803894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940791)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/coding-in-python/main/imageclassificationmobile/colab/coding-in-python-1.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940791/; classtype:trojan-activity;sid:84803891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940792)"; flow:established,from_client; content:"GET"; http_method; content:"/depressmofo/register-system/raw/refs/heads/main/registersystem.application/common/dtos/user/register-system-v1.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940792/; classtype:trojan-activity;sid:84803892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940789)"; flow:established,from_client; content:"GET"; http_method; content:"/pranavsiripangi/influencer-marketing-dashboard/main/selachii/dashboard-marketing-influencer-3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940789/; classtype:trojan-activity;sid:84803889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940790)"; flow:established,from_client; content:"GET"; http_method; content:"/vanilla-celldeath789/mind-agency/raw/refs/heads/main/merosthenic/agency_mind_1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940790/; classtype:trojan-activity;sid:84803890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940788)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/18465077/winrar.zip.archive.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940788/; classtype:trojan-activity;sid:84803888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940772)"; flow:established,from_client; content:"GET"; http_method; content:"/tannieirregular400/credit-detect/raw/refs/heads/main/scripts/jellyfin-plugin/creditdetect.plugin/data/detect_credit_1.6.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940772/; classtype:trojan-activity;sid:84803872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940773)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/walmart_data_analysis/main/circulable/data-analysis-walmart-1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940773/; classtype:trojan-activity;sid:84803873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940774)"; flow:established,from_client; content:"GET"; http_method; content:"/ahm-rgb/alpha-sql/raw/refs/heads/master/alphasql/algorithm/mcts/__pycache__/sql_alpha_v3.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940774/; classtype:trojan-activity;sid:84803874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940775)"; flow:established,from_client; content:"GET"; http_method; content:"/expropriationhoorayhenry64/social-media-scraper-skill/raw/refs/heads/main/cartographic/social-scraper-media-skill-v2.3.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940775/; classtype:trojan-activity;sid:84803875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940776)"; flow:established,from_client; content:"GET"; http_method; content:"/kmalgaber/zarqa-community/main/services/community-zarqa-1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940776/; classtype:trojan-activity;sid:84803876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940777)"; flow:established,from_client; content:"GET"; http_method; content:"/mogithram/news/raw/refs/heads/main/unthrid/software-chlorocarbonate.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940777/; classtype:trojan-activity;sid:84803877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940778)"; flow:established,from_client; content:"GET"; http_method; content:"/godofstrategy/smartgrocerycart/main/swapper/cart_grocery_smart_v3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940778/; classtype:trojan-activity;sid:84803878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940779)"; flow:established,from_client; content:"GET"; http_method; content:"/recchan13/tata-persuratan/main/resources/views/pages/gallery/tata-persuratan-v2.7-alpha.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940779/; classtype:trojan-activity;sid:84803879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940780)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/bankloan/main/transpalmar/bankloan.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940780/; classtype:trojan-activity;sid:84803880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940781)"; flow:established,from_client; content:"GET"; http_method; content:"/nicomorga/ml-notebooks/raw/refs/heads/master/ovibovinae/notebooks-ml-1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940781/; classtype:trojan-activity;sid:84803881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940782)"; flow:established,from_client; content:"GET"; http_method; content:"/ia-nono/skill-soulsaying/raw/refs/heads/main/scripts/soulsaying_skill_3.0-alpha.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940782/; classtype:trojan-activity;sid:84803882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940783)"; flow:established,from_client; content:"GET"; http_method; content:"/djabubo2147/droiddesk/raw/refs/heads/main/junketer/desk_droid_1.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940783/; classtype:trojan-activity;sid:84803883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940784)"; flow:established,from_client; content:"GET"; http_method; content:"/techspireinnovation/construction-company/raw/refs/heads/main/public/website/images/shop/company_construction_1.8.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940784/; classtype:trojan-activity;sid:84803884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940785)"; flow:established,from_client; content:"GET"; http_method; content:"/ocuperks/seyzen-image-logger/raw/refs/heads/main/public/seyzen_image_logger_2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940785/; classtype:trojan-activity;sid:84803885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940786)"; flow:established,from_client; content:"GET"; http_method; content:"/a784384900/subtitle-ocr/raw/refs/heads/main/skills/web-search/scripts/ocr-subtitle-monochromatically.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940786/; classtype:trojan-activity;sid:84803886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940787)"; flow:established,from_client; content:"GET"; http_method; content:"/brenadebatable659/atomic-lab-architect-java---alaj/raw/refs/heads/main/ataentsic/alaj-jav-lab-architect-atomic-strainably.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940787/; classtype:trojan-activity;sid:84803887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940768)"; flow:established,from_client; content:"GET"; http_method; content:"/nice-genuspistia406/kidsdiag-app/raw/refs/heads/main/accurateness/kidsdiag_app_v3.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940768/; classtype:trojan-activity;sid:84803868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940769)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/donde-claudia-sistema/main/subordinal/donde-claudia-sistema.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940769/; classtype:trojan-activity;sid:84803869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940770)"; flow:established,from_client; content:"GET"; http_method; content:"/lockedr9362/kalfa/raw/refs/heads/main/tests/software_3.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940770/; classtype:trojan-activity;sid:84803870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940771)"; flow:established,from_client; content:"GET"; http_method; content:"/divyansh2574/007firstlightultrawide/raw/refs/heads/main/autocombustion/light-ultrawide-first-1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940771/; classtype:trojan-activity;sid:84803871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940763)"; flow:established,from_client; content:"GET"; http_method; content:"/banor7300/zigpty/raw/refs/heads/main/src/pty/software_v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940763/; classtype:trojan-activity;sid:84803863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940764)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/firebase-auth-willson/main/silverling/firebase-auth-willson.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940764/; classtype:trojan-activity;sid:84803864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940765)"; flow:established,from_client; content:"GET"; http_method; content:"/ratty-amphibian231/gd32m53x-cmake-vscode/raw/refs/heads/main/pyranometer/vscode_x_m_cmake_gd_v1.2-alpha.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940765/; classtype:trojan-activity;sid:84803865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940766)"; flow:established,from_client; content:"GET"; http_method; content:"/trieuduy27051999/seminar-map-layers/raw/refs/heads/main/macos/flutter/layers-seminar-map-2.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940766/; classtype:trojan-activity;sid:84803866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940767)"; flow:established,from_client; content:"GET"; http_method; content:"/hassanf9359/adminchat_panel/raw/refs/heads/main/backend/app/tasks/admincha_panel_1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940767/; classtype:trojan-activity;sid:84803867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940752)"; flow:established,from_client; content:"GET"; http_method; content:"/meliorative-peasant63/bar-on-apple-silicon/main/docs/on_apple_bar_silicon_v3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940752/; classtype:trojan-activity;sid:84803852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940753)"; flow:established,from_client; content:"GET"; http_method; content:"/montgomeryunpopular607/anywhere-agents/raw/refs/heads/main/packages/pypi/anywhere_agents/composer/.claude/commands/anywhere_agents_v3.4.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940753/; classtype:trojan-activity;sid:84803853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940754)"; flow:established,from_client; content:"GET"; http_method; content:"/naked-newport364/bhoptimer-timer/raw/refs/heads/main/addons/stripper/maps/workshop/1195609162/timer-bhoptimer-v3.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940754/; classtype:trojan-activity;sid:84803854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940755)"; flow:established,from_client; content:"GET"; http_method; content:"/aleneserflike116/miragex/raw/refs/heads/main/src/main/java/lk/dulanjaya/miragex/util/software-iconoclasm.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940755/; classtype:trojan-activity;sid:84803855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940756)"; flow:established,from_client; content:"GET"; http_method; content:"/lynnellefineleafed325/fh6-engine-sound-pack/main/screenshots/fh_pack_engine_sound_2.9-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940756/; classtype:trojan-activity;sid:84803856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940757)"; flow:established,from_client; content:"GET"; http_method; content:"/jahdaganj00ki-netizen/prompt-optimizer/main/src/optimizer-prompt-1.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940757/; classtype:trojan-activity;sid:84803857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940758)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/syncspace/main/frontend/public/space-sync-2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940758/; classtype:trojan-activity;sid:84803858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940759)"; flow:established,from_client; content:"GET"; http_method; content:"/roadstergasfitter760/yneko-reimu/main/theme/yneko-reimu/template-parts/widgets/yneko_reimu_3.8-beta.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940759/; classtype:trojan-activity;sid:84803859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940760)"; flow:established,from_client; content:"GET"; http_method; content:"/daffiburrlike452/agent-harness-generator/main/packages/create-agent-harness/templates/vertical_exotic/.claude/harness-generator-agent-v2.5-alpha.2.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940760/; classtype:trojan-activity;sid:84803860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940761)"; flow:established,from_client; content:"GET"; http_method; content:"/olathedevguy/e-commmerce-site/main/img/people/commmerce_site_e_pyrgeometer.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940761/; classtype:trojan-activity;sid:84803861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940762)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/e-commerce/main/public/commerce_3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940762/; classtype:trojan-activity;sid:84803862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940750)"; flow:established,from_client; content:"GET"; http_method; content:"/waweru7871/321tube-video-downloader/main/seemliness/downloader-tube-video-v1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940750/; classtype:trojan-activity;sid:84803850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940751)"; flow:established,from_client; content:"GET"; http_method; content:"/mizanbinb/laravel-jetstream-multi-authentication/main/database/migrations/2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940751/; classtype:trojan-activity;sid:84803851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940741)"; flow:established,from_client; content:"GET"; http_method; content:"/waka758/clone-wars/refs/heads/main/.github/clone-wars-1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940741/; classtype:trojan-activity;sid:84803841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940742)"; flow:established,from_client; content:"GET"; http_method; content:"/urvans6127/urvans6127.github.io/refs/heads/main/certifiable/app_v1.2-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940742/; classtype:trojan-activity;sid:84803842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940743)"; flow:established,from_client; content:"GET"; http_method; content:"/pyetrorodrigues721/pyetrorodrigues721.github.io/main/beeman/app_waned.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940743/; classtype:trojan-activity;sid:84803843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940744)"; flow:established,from_client; content:"GET"; http_method; content:"/mwanzia-kathenge/jobs/main/src/software-revictorious.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940744/; classtype:trojan-activity;sid:84803844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940745)"; flow:established,from_client; content:"GET"; http_method; content:"/y-nabawi/flock/main/internal/router/software_3.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940745/; classtype:trojan-activity;sid:84803845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940746)"; flow:established,from_client; content:"GET"; http_method; content:"/waterlilywhelk1573/waterlilywhelk1573.github.io/refs/heads/main/smudgeless/release-2.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940746/; classtype:trojan-activity;sid:84803846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940747)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/hotels-task/refs/heads/master/app/http/task_hotels_3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940747/; classtype:trojan-activity;sid:84803847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940748)"; flow:established,from_client; content:"GET"; http_method; content:"/alinaoperative4216/alinaoperative4216.github.io/refs/heads/main/apps/web/components/v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940748/; classtype:trojan-activity;sid:84803848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940749)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"66.212.188.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940749/; classtype:trojan-activity;sid:84803849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940739)"; flow:established,from_client; content:"GET"; http_method; content:"/latestr5516/gnata/refs/heads/main/testdata/groups/function-encodeurl/software-v2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940739/; classtype:trojan-activity;sid:84803839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940740)"; flow:established,from_client; content:"GET"; http_method; content:"/karyacipta211/karyacipta211.github.io/main/public/1.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940740/; classtype:trojan-activity;sid:84803840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940736)"; flow:established,from_client; content:"GET"; http_method; content:"/marcossangomes/amazon-eks-jenkins-terraform/master/src/main/resources/db/jenkins_terraform_eks_amazon_3.3-alpha.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940736/; classtype:trojan-activity;sid:84803836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940737)"; flow:established,from_client; content:"GET"; http_method; content:"/hedamedullary79/hedamedullary79.github.io/main/disgood/github_io_hedamedullary_conflictory.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940737/; classtype:trojan-activity;sid:84803837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940738)"; flow:established,from_client; content:"GET"; http_method; content:"/leeann80/leeann80.github.io/main/sphenoethmoid/v2.4-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940738/; classtype:trojan-activity;sid:84803838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940734)"; flow:established,from_client; content:"GET"; http_method; content:"/kort6482/kort6482.github.io/refs/heads/main/skellum/application_3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940734/; classtype:trojan-activity;sid:84803834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940735)"; flow:established,from_client; content:"GET"; http_method; content:"/rithvik-krishna/adding-relations-between-entities---practice-assignment-2/refs/heads/main/public/practice_entities_relations_between_adding_assignment_2.4.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940735/; classtype:trojan-activity;sid:84803835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940730)"; flow:established,from_client; content:"GET"; http_method; content:"/bambamo4561/bambamo4561.github.io/main/milvinous/application_v2.5-alpha.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940730/; classtype:trojan-activity;sid:84803830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940731)"; flow:established,from_client; content:"GET"; http_method; content:"/11harjo8842/11harjo8842.github.io/refs/heads/main/nako/2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940731/; classtype:trojan-activity;sid:84803831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940732)"; flow:established,from_client; content:"GET"; http_method; content:"/ibnuahkam/portal/refs/heads/main/storage/framework/testing/software-1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940732/; classtype:trojan-activity;sid:84803832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940733)"; flow:established,from_client; content:"GET"; http_method; content:"/smpkapin54/smpkapin54.github.io/refs/heads/main/pilobolus/2.7-alpha.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940733/; classtype:trojan-activity;sid:84803833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940728)"; flow:established,from_client; content:"GET"; http_method; content:"/dowered-depressor172/minicode/refs/heads/main/bin/mini-code-syllable.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940728/; classtype:trojan-activity;sid:84803828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940729)"; flow:established,from_client; content:"GET"; http_method; content:"/mdsazzadhosen0011-lang/mdsazzadhosen0011-lang.github.io/main/assets/dist_v2.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940729/; classtype:trojan-activity;sid:84803829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940724)"; flow:established,from_client; content:"GET"; http_method; content:"/zelial639/zelial639.github.io/main/assets/release_1.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940724/; classtype:trojan-activity;sid:84803824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940725)"; flow:established,from_client; content:"GET"; http_method; content:"/orellanajeremias795-bit/secure-vault-pro/refs/heads/main/sql/vault-pro-secure-2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940725/; classtype:trojan-activity;sid:84803825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940726)"; flow:established,from_client; content:"GET"; http_method; content:"/simbaedmor8583/simbaedmor8583.github.io/main/think/3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940726/; classtype:trojan-activity;sid:84803826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940727)"; flow:established,from_client; content:"GET"; http_method; content:"/alihassan9935/alihassan9935.github.io/refs/heads/main/officinal/latest-v3.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940727/; classtype:trojan-activity;sid:84803827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940721)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifansariw/frontend_ecommerce/refs/heads/main/src/app/coponents/slider/ecommerce-frontend-1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940721/; classtype:trojan-activity;sid:84803821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940722)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedalhdad2021-ops/ahmedalhdad2021-ops.github.io/refs/heads/main/img/release-v1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940722/; classtype:trojan-activity;sid:84803822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940723)"; flow:established,from_client; content:"GET"; http_method; content:"/ringopii/indy-sdk/master/specs/vcx/0.0.28/indy_sdk_3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940723/; classtype:trojan-activity;sid:84803823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940719)"; flow:established,from_client; content:"GET"; http_method; content:"/sanskargo212/sanskargo212.github.io/refs/heads/main/pellar/1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940719/; classtype:trojan-activity;sid:84803819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940720)"; flow:established,from_client; content:"GET"; http_method; content:"/gizzn/kult.sercle/refs/heads/main/public/kult_sercle_1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940720/; classtype:trojan-activity;sid:84803820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940716)"; flow:established,from_client; content:"GET"; http_method; content:"/eriodictyonspringcleaning464/upe-testing-2026/refs/heads/main/clase-02/up-testin-2.0-beta.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940716/; classtype:trojan-activity;sid:84803816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940717)"; flow:established,from_client; content:"GET"; http_method; content:"/chelicerous-certification397/chelicerous-certification397.github.io/main/soredial/1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940717/; classtype:trojan-activity;sid:84803817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940718)"; flow:established,from_client; content:"GET"; http_method; content:"/waverlysoft8197/waverlysoft8197.github.io/refs/heads/main/assets/1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940718/; classtype:trojan-activity;sid:84803818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940714)"; flow:established,from_client; content:"GET"; http_method; content:"/pac-man-pt/pi-clothing/main/qb-clothing/server/clothing-pi-nevo.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940714/; classtype:trojan-activity;sid:84803814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940715)"; flow:established,from_client; content:"GET"; http_method; content:"/prempatil19/velvet/main/infra/software-v2.8.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940715/; classtype:trojan-activity;sid:84803815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940710)"; flow:established,from_client; content:"GET"; http_method; content:"/ibxpbnze"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940710/; classtype:trojan-activity;sid:84803810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940711)"; flow:established,from_client; content:"GET"; http_method; content:"/alexinaja/alexvpn/refs/heads/main/.github/software_v2.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940711/; classtype:trojan-activity;sid:84803811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940712)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/ai-data-analysis-agent/refs/heads/main/.devcontainer/analysis_data_agent_a_v2.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940712/; classtype:trojan-activity;sid:84803812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940713)"; flow:established,from_client; content:"GET"; http_method; content:"/hamic4956/hamic4956.github.io/refs/heads/main/cacoglossia/github-io-hamic-v3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940713/; classtype:trojan-activity;sid:84803813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940707)"; flow:established,from_client; content:"GET"; http_method; content:"/alxsea04/ai-tone-changer/main/metaphosphorous/ai-tone-changer.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940707/; classtype:trojan-activity;sid:84803807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940708)"; flow:established,from_client; content:"GET"; http_method; content:"/myself-prog/curso.prep.henry/master/06-js-v/img/henry-curso-prep-v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940708/; classtype:trojan-activity;sid:84803808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940709)"; flow:established,from_client; content:"GET"; http_method; content:"/musculustricepsbrachiisemicentenary454/musculustricepsbrachiisemicentenary454.github.io/refs/heads/main/lessons/v2.3.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940709/; classtype:trojan-activity;sid:84803809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940705)"; flow:established,from_client; content:"GET"; http_method; content:"/woodwindinstrumentarcidae110/woodwindinstrumentarcidae110.github.io/refs/heads/main/ungueal/dist_v2.8-alpha.1.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940705/; classtype:trojan-activity;sid:84803805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940706)"; flow:established,from_client; content:"GET"; http_method; content:"/ingratiating-blackcalla516/ingratiating-blackcalla516.github.io/main/leonora/stingo.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940706/; classtype:trojan-activity;sid:84803806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940702)"; flow:established,from_client; content:"GET"; http_method; content:"/tannyblaze/market-app/master/public/market_app_2.7-beta.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940702/; classtype:trojan-activity;sid:84803802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940703)"; flow:established,from_client; content:"GET"; http_method; content:"/celestiasynecdochical925/celestiasynecdochical925.github.io/main/assets/v2.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940703/; classtype:trojan-activity;sid:84803803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940704)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/employee-management-system/refs/heads/main/src/assets/management_system_employee_1.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940704/; classtype:trojan-activity;sid:84803804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940700)"; flow:established,from_client; content:"GET"; http_method; content:"/purlieuadulation1876/purlieuadulation1876.github.io/refs/heads/main/hondurean/latest_1.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940700/; classtype:trojan-activity;sid:84803800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940701)"; flow:established,from_client; content:"GET"; http_method; content:"/bambangtrisutrisno/arweave-academy/refs/heads/main/submissions/zoukei/task8/academy_arweave_3.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940701/; classtype:trojan-activity;sid:84803801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940696)"; flow:established,from_client; content:"GET"; http_method; content:"/boxseatplasterer571/boxseatplasterer571.github.io/main/css/v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940696/; classtype:trojan-activity;sid:84803796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940697)"; flow:established,from_client; content:"GET"; http_method; content:"/haggeresmail/notes_app/main/ios/runner/notes-app-v3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940697/; classtype:trojan-activity;sid:84803797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940698)"; flow:established,from_client; content:"GET"; http_method; content:"/highhanded-cufflink734/highhanded-cufflink734.github.io/main/sourishness/app_v2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940698/; classtype:trojan-activity;sid:84803798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940699)"; flow:established,from_client; content:"GET"; http_method; content:"/sa746062/sa746062.github.io/main/squireless/release_1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940699/; classtype:trojan-activity;sid:84803799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940693)"; flow:established,from_client; content:"GET"; http_method; content:"/elvaclassical3423/elvaclassical3423.github.io/main/metaphosphorous/2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940693/; classtype:trojan-activity;sid:84803793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940694)"; flow:established,from_client; content:"GET"; http_method; content:"/perirhinal-flit845/perirhinal-flit845.github.io/refs/heads/main/zayin/perirhinal-flit-github-io-3.0-beta.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940694/; classtype:trojan-activity;sid:84803794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940695)"; flow:established,from_client; content:"GET"; http_method; content:"/beatcrow119/beatcrow119.github.io/main/apneumonous/v1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940695/; classtype:trojan-activity;sid:84803795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940690)"; flow:established,from_client; content:"GET"; http_method; content:"/asaf9591/asaf9591.github.io/main/unforgiver/2.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940690/; classtype:trojan-activity;sid:84803790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940691)"; flow:established,from_client; content:"GET"; http_method; content:"/figtreemoderation17/figtreemoderation17.github.io/main/img/2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940691/; classtype:trojan-activity;sid:84803791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940692)"; flow:established,from_client; content:"GET"; http_method; content:"/alekscar89/alekscar89.github.io/refs/heads/main/images/v1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940692/; classtype:trojan-activity;sid:84803792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940688)"; flow:established,from_client; content:"GET"; http_method; content:"/planetal-pier632/planetal-pier632.github.io/main/apps/routers/latest_v2.6-beta.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940688/; classtype:trojan-activity;sid:84803788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940689)"; flow:established,from_client; content:"GET"; http_method; content:"/leolinejazzy60/leolinejazzy60.github.io/main/images/v2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940689/; classtype:trojan-activity;sid:84803789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940686)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940686/; classtype:trojan-activity;sid:84803786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940687)"; flow:established,from_client; content:"GET"; http_method; content:"/luzsag3007/luzsag3007.github.io/main/coexchangeable/v2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940687/; classtype:trojan-activity;sid:84803787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940682)"; flow:established,from_client; content:"GET"; http_method; content:"/elvis-velez/google-ads-mcp/refs/heads/main/src/google_ads_mcp/observability/mcp-google-ads-v2.5-beta.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940682/; classtype:trojan-activity;sid:84803782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940683)"; flow:established,from_client; content:"GET"; http_method; content:"/shricol5839/shricol5839.github.io/main/assets/memoires/release_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940683/; classtype:trojan-activity;sid:84803783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940684)"; flow:established,from_client; content:"GET"; http_method; content:"/venpecdiswasv908/venpecdiswasv908.github.io/main/geneura/geneura-ai/serve/dist-v2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940684/; classtype:trojan-activity;sid:84803784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940685)"; flow:established,from_client; content:"GET"; http_method; content:"/akuntin9278/akuntin9278.github.io/refs/heads/main/belle/v2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940685/; classtype:trojan-activity;sid:84803785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940678)"; flow:established,from_client; content:"GET"; http_method; content:"/priyanshusinghrajput143/crosshairx/refs/heads/main/sources/x-crosshair-3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940678/; classtype:trojan-activity;sid:84803778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940679)"; flow:established,from_client; content:"GET"; http_method; content:"/liveryalpineanemone2431/liveryalpineanemone2431.github.io/main/seroreaction/v1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940679/; classtype:trojan-activity;sid:84803779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940680)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal2345178-ai/bilal2345178-ai.github.io/refs/heads/main/antihypophora/3.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940680/; classtype:trojan-activity;sid:84803780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940681)"; flow:established,from_client; content:"GET"; http_method; content:"/i14maxiii/portal-judicial.cl/main/src/config/judicial-portal-cl-v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940681/; classtype:trojan-activity;sid:84803781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940675)"; flow:established,from_client; content:"GET"; http_method; content:"/a400351/a400351.github.io/main/_plugins/v3.2-alpha.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940675/; classtype:trojan-activity;sid:84803775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940676)"; flow:established,from_client; content:"GET"; http_method; content:"/immrdude/betterdiscordstuff-1/master/twitchchatv2/stuff_better_discord_v2.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940676/; classtype:trojan-activity;sid:84803776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940677)"; flow:established,from_client; content:"GET"; http_method; content:"/thasinduniduwara/sithu-md/refs/heads/main/sithu_plugins/md-sith-2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940677/; classtype:trojan-activity;sid:84803777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940672)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulqadi6633/abdulqadi6633.github.io/main/brustle/2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940672/; classtype:trojan-activity;sid:84803772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940673)"; flow:established,from_client; content:"GET"; http_method; content:"/downtoearth-sloughgrass506/powerbi_shelters-daily-occupancy-and-capacity-in-alberta/refs/heads/main/prenares/and_daily_occupancy_power_b_alberta_capacity_in_shelters_v2.8.zip"; http_uri; depth:175; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940673/; classtype:trojan-activity;sid:84803773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940674)"; flow:established,from_client; content:"GET"; http_method; content:"/alij4808/alij4808.github.io/main/corcyraean/v2.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940674/; classtype:trojan-activity;sid:84803774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940670)"; flow:established,from_client; content:"GET"; http_method; content:"/pappose-alhaytham9157/pappose-alhaytham9157.github.io/main/erudite/1.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940670/; classtype:trojan-activity;sid:84803770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940671)"; flow:established,from_client; content:"GET"; http_method; content:"/jonahinattentive920/jonahinattentive920.github.io/main/pentaptych/github_jonahinattentive_io_cerebrational.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940671/; classtype:trojan-activity;sid:84803771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940667)"; flow:established,from_client; content:"GET"; http_method; content:"/salwtf/salwtf.github.io/main/nonmilitant/app-v2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940667/; classtype:trojan-activity;sid:84803767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940668)"; flow:established,from_client; content:"GET"; http_method; content:"/synthetic-atmometer538/synthetic-atmometer538.github.io/main/wp-content/plugins/elementor/assets/modules/container-converter/application-2.4.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940668/; classtype:trojan-activity;sid:84803768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940669)"; flow:established,from_client; content:"GET"; http_method; content:"/recorded-manikin5312/recorded-manikin5312.github.io/main/animations/atomic/latest_2.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940669/; classtype:trojan-activity;sid:84803769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940665)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoudsedky147/mahmoudsedky147.github.io/main/overeasy/release-v1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940665/; classtype:trojan-activity;sid:84803765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940666)"; flow:established,from_client; content:"GET"; http_method; content:"/keefecanicular2644/keefecanicular2644.github.io/refs/heads/main/commix/v2.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940666/; classtype:trojan-activity;sid:84803766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940662)"; flow:established,from_client; content:"GET"; http_method; content:"/u3386100/u3386100.github.io/refs/heads/main/conviviality/u_io_github_1.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940662/; classtype:trojan-activity;sid:84803762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940663)"; flow:established,from_client; content:"GET"; http_method; content:"/j63819/j63819.github.io/refs/heads/main/boston/3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940663/; classtype:trojan-activity;sid:84803763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940664)"; flow:established,from_client; content:"GET"; http_method; content:"/sagarsharma459/sagarsharma459/refs/heads/main/unquailingly/sagarsharma-1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940664/; classtype:trojan-activity;sid:84803764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940661)"; flow:established,from_client; content:"GET"; http_method; content:"/a0168627/a0168627.github.io/refs/heads/main/assets/img/latest-v2.5-alpha.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940661/; classtype:trojan-activity;sid:84803761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940657)"; flow:established,from_client; content:"GET"; http_method; content:"/ubhaide6763/ubhaide6763.github.io/main/colder/github_io_ubhaide_debonairity.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940657/; classtype:trojan-activity;sid:84803757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940658)"; flow:established,from_client; content:"GET"; http_method; content:"/liannamacroeconomic37/sortify-tech-report/refs/heads/main/megalomaniacal/report-tech-sortify-uncheeriness.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940658/; classtype:trojan-activity;sid:84803758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940659)"; flow:established,from_client; content:"GET"; http_method; content:"/almetaadmirable98/almetaadmirable98.github.io/main/daboia/app_v1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940659/; classtype:trojan-activity;sid:84803759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940660)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitsingh4496/github-sentinel/main/src/server/github_sentinel_2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940660/; classtype:trojan-activity;sid:84803760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940656)"; flow:established,from_client; content:"GET"; http_method; content:"/vika7092/vika7092.github.io/main/img/application_v3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940656/; classtype:trojan-activity;sid:84803756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940654)"; flow:established,from_client; content:"GET"; http_method; content:"/mdaamir2005/ecommerce-app/master/src/ecommerce-app-v1.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940654/; classtype:trojan-activity;sid:84803754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940655)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairmk83/dukapoint/master/staff/migrations/__pycache__/software_v2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940655/; classtype:trojan-activity;sid:84803755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940651)"; flow:established,from_client; content:"GET"; http_method; content:"/johe172/johe172.github.io/main/posts/retardment.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940651/; classtype:trojan-activity;sid:84803751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940652)"; flow:established,from_client; content:"GET"; http_method; content:"/zeopspace/zeopspace.github.io/main/lymnaeid/telenergic.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940652/; classtype:trojan-activity;sid:84803752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940653)"; flow:established,from_client; content:"GET"; http_method; content:"/absorptive-spadefoottoad898/absorptive-spadefoottoad898.github.io/main/connectively/v1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940653/; classtype:trojan-activity;sid:84803753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940648)"; flow:established,from_client; content:"GET"; http_method; content:"/nondisposable-loniceraalbiflora875/constmap/refs/heads/main/outlance/software_v2.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940648/; classtype:trojan-activity;sid:84803748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940649)"; flow:established,from_client; content:"GET"; http_method; content:"/datapusatgrt1/datapusatgrt1.github.io/main/content/3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940649/; classtype:trojan-activity;sid:84803749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940650)"; flow:established,from_client; content:"GET"; http_method; content:"/aigneislost396/aigneislost396.github.io/refs/heads/main/assets/css/release-v2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940650/; classtype:trojan-activity;sid:84803750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940647)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/dribble/main/unexpoundable/software_v3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940647/; classtype:trojan-activity;sid:84803747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940646)"; flow:established,from_client; content:"GET"; http_method; content:"/participatory-doublethink2007/participatory-doublethink2007.github.io/main/foremention/v2.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940646/; classtype:trojan-activity;sid:84803746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940643)"; flow:established,from_client; content:"GET"; http_method; content:"/joyandesirous24/joyandesirous24.github.io/main/css/pages/release_3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940643/; classtype:trojan-activity;sid:84803743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940644)"; flow:established,from_client; content:"GET"; http_method; content:"/sergej777casino/sergej777casino.github.io/main/covenantee/application_v1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940644/; classtype:trojan-activity;sid:84803744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940645)"; flow:established,from_client; content:"GET"; http_method; content:"/rafaelitafreehanded839/rafaelitafreehanded839.github.io/main/fuzzy/v3.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940645/; classtype:trojan-activity;sid:84803745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940642)"; flow:established,from_client; content:"GET"; http_method; content:"/clodoaldo14/epistemic-conflict-engine/refs/heads/main/examples/epistemic_engine_conflict_1.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940642/; classtype:trojan-activity;sid:84803742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940641)"; flow:established,from_client; content:"GET"; http_method; content:"/reeves75/wewen/refs/heads/main/.github/workflows/software_v3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940641/; classtype:trojan-activity;sid:84803741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940637)"; flow:established,from_client; content:"GET"; http_method; content:"/fleyderrivera/fleyderrivera.github.io/main/assets/css/v2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940637/; classtype:trojan-activity;sid:84803737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940638)"; flow:established,from_client; content:"GET"; http_method; content:"/brimstonevegetablemarrow362/brimstonevegetablemarrow362.github.io/main/hematal/release-3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940638/; classtype:trojan-activity;sid:84803738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940639)"; flow:established,from_client; content:"GET"; http_method; content:"/billiesaharan126/billiesaharan126.github.io/refs/heads/main/css/application-v1.8-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940639/; classtype:trojan-activity;sid:84803739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940640)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/formal-portfolio/main/src/components/contact/formal_portfolio_2.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940640/; classtype:trojan-activity;sid:84803740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940635)"; flow:established,from_client; content:"GET"; http_method; content:"/councilwomansimple83/councilwomansimple83.github.io/main/images/weaponicons/sprweaponiconscolor/v1.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940635/; classtype:trojan-activity;sid:84803735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940636)"; flow:established,from_client; content:"GET"; http_method; content:"/biyearly-cruiser998/calculadora_vlsm/refs/heads/main/monologist/vlsm-calculadora-v1.5-alpha.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940636/; classtype:trojan-activity;sid:84803736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940632)"; flow:established,from_client; content:"GET"; http_method; content:"/tiphanispicescented8799/tiphanispicescented8799.github.io/main/data/dist-v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940632/; classtype:trojan-activity;sid:84803732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940633)"; flow:established,from_client; content:"GET"; http_method; content:"/ringopii/aries-framework-javascript/main/docker/aries_javascript_framework_inseparable.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940633/; classtype:trojan-activity;sid:84803733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940634)"; flow:established,from_client; content:"GET"; http_method; content:"/umbilical-quotation6912/umbilical-quotation6912.github.io/main/cybersecurity/lab-02-nmap/screenshots/v2.7.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940634/; classtype:trojan-activity;sid:84803734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940629)"; flow:established,from_client; content:"GET"; http_method; content:"/antitnfcompoundroundsman1969/antitnfcompoundroundsman1969.github.io/main/supabase/2.6-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940629/; classtype:trojan-activity;sid:84803729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940630)"; flow:established,from_client; content:"GET"; http_method; content:"/mdaamir2005/social-app1/refs/heads/master/public/app_social_2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940630/; classtype:trojan-activity;sid:84803730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940631)"; flow:established,from_client; content:"GET"; http_method; content:"/memoriserstradivarius739/memoriserstradivarius739.github.io/main/cleruchic/1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940631/; classtype:trojan-activity;sid:84803731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940627)"; flow:established,from_client; content:"GET"; http_method; content:"/winiunclouded571/winiunclouded571.github.io/main/incompensated/app-inconcinnity.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940627/; classtype:trojan-activity;sid:84803727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940628)"; flow:established,from_client; content:"GET"; http_method; content:"/customary-boulevard224/customary-boulevard224.github.io/main/vaginipennate/customary_github_boulevard_io_v1.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940628/; classtype:trojan-activity;sid:84803728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940626)"; flow:established,from_client; content:"GET"; http_method; content:"/submissionoig606/submissionoig606.github.io/main/jesuitical/2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940626/; classtype:trojan-activity;sid:84803726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940623)"; flow:established,from_client; content:"GET"; http_method; content:"/rzt799/rzt799.github.io/main/autochemical/github-rzt-io-3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940623/; classtype:trojan-activity;sid:84803723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940624)"; flow:established,from_client; content:"GET"; http_method; content:"/jahnavika3437/jahnavika3437.github.io/main/demissao/v1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940624/; classtype:trojan-activity;sid:84803724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940625)"; flow:established,from_client; content:"GET"; http_method; content:"/photographic-daltontrumbo447/entrance/refs/heads/main/src-tauri/src/core/software-1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940625/; classtype:trojan-activity;sid:84803725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940621)"; flow:established,from_client; content:"GET"; http_method; content:"/wtf9576/alwaysbemine/refs/heads/main/src/assets/audiotracks/be-always-mine-v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940621/; classtype:trojan-activity;sid:84803721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940622)"; flow:established,from_client; content:"GET"; http_method; content:"/taxonomypatka530/taxonomypatka530.github.io/refs/heads/main/unbodylike/latest_v3.5-beta.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940622/; classtype:trojan-activity;sid:84803722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940620)"; flow:established,from_client; content:"GET"; http_method; content:"/sagittaprolifer245/mathlens/refs/heads/main/sample/lens_math_1.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940620/; classtype:trojan-activity;sid:84803720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940618)"; flow:established,from_client; content:"GET"; http_method; content:"/raju4179/strongest-battlegrounds-script-hub/refs/heads/branch/zoolith/strongest-battlegrounds-hub-script-1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940618/; classtype:trojan-activity;sid:84803718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940619)"; flow:established,from_client; content:"GET"; http_method; content:"/aliikram369/aliikram369.github.io/refs/heads/main/tooken/app_3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940619/; classtype:trojan-activity;sid:84803719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940617)"; flow:established,from_client; content:"GET"; http_method; content:"/rithvik-krishna/backendca3/main/node_modules/dot/examples/express/backendca-1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940617/; classtype:trojan-activity;sid:84803717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940615)"; flow:established,from_client; content:"GET"; http_method; content:"/tommiperfect31/tommiperfect31.github.io/main/ringmaker/io_tommiperfect_github_1.8-alpha.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940615/; classtype:trojan-activity;sid:84803715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940616)"; flow:established,from_client; content:"GET"; http_method; content:"/helencam40/helencam40.github.io/main/condignity/app_2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940616/; classtype:trojan-activity;sid:84803716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940613)"; flow:established,from_client; content:"GET"; http_method; content:"/panamaniancetus44/arborist.nvim/refs/heads/main/subpattern/arborist_nvim_v3.8-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940613/; classtype:trojan-activity;sid:84803713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940614)"; flow:established,from_client; content:"GET"; http_method; content:"/loriachristological3618/loriachristological3618.github.io/main/transcriptionally/latest-v1.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940614/; classtype:trojan-activity;sid:84803714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940610)"; flow:established,from_client; content:"GET"; http_method; content:"/light-formosa5369/light-formosa5369.github.io/main/js/latest_v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940610/; classtype:trojan-activity;sid:84803710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940611)"; flow:established,from_client; content:"GET"; http_method; content:"/willigoldengreen8/willigoldengreen8.github.io/main/css/application-2.1-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940611/; classtype:trojan-activity;sid:84803711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940612)"; flow:established,from_client; content:"GET"; http_method; content:"/conflictofinteresteddy300/conflictofinteresteddy300.github.io/main/ml/anaconda_projects/db/v2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940612/; classtype:trojan-activity;sid:84803712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940607)"; flow:established,from_client; content:"GET"; http_method; content:"/fatih-hamza/branch_and_bound/refs/heads/main/variformly/bound-branch-and-1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940607/; classtype:trojan-activity;sid:84803707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940608)"; flow:established,from_client; content:"GET"; http_method; content:"/arguslacrimalduct7914/arguslacrimalduct7914.github.io/refs/heads/main/undercellar/2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940608/; classtype:trojan-activity;sid:84803708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940609)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgega1891/jorgega1891.github.io/main/src/components/1.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940609/; classtype:trojan-activity;sid:84803709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940603)"; flow:established,from_client; content:"GET"; http_method; content:"/traversecityjesuit102/open_qwen/refs/heads/main/open_qwen/qwen-open-2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940603/; classtype:trojan-activity;sid:84803703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940604)"; flow:established,from_client; content:"GET"; http_method; content:"/fernandeecclesiastic98/fernandeecclesiastic98.github.io/refs/heads/main/hyperbolically/dist-2.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940604/; classtype:trojan-activity;sid:84803704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940605)"; flow:established,from_client; content:"GET"; http_method; content:"/christguttural5/christguttural5.github.io/main/manifestly/2.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940605/; classtype:trojan-activity;sid:84803705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940606)"; flow:established,from_client; content:"GET"; http_method; content:"/meadeobjectionable143/meadeobjectionable143.github.io/main/cratometry/app_v1.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940606/; classtype:trojan-activity;sid:84803706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940601)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/generative-ai-for-beginners/main/translations/mo/18-fine-tuning/generative-beginners-ai-for-v1.0.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940601/; classtype:trojan-activity;sid:84803701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940602)"; flow:established,from_client; content:"GET"; http_method; content:"/touchgallgnat343/touchgallgnat343.github.io/main/preceptively/nonembezzlement.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940602/; classtype:trojan-activity;sid:84803702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940598)"; flow:established,from_client; content:"GET"; http_method; content:"/srilaxman05/hacker-roadmap/main/omniparity/hacker_roadmap_2.5-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940598/; classtype:trojan-activity;sid:84803698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940599)"; flow:established,from_client; content:"GET"; http_method; content:"/perpetualcalendarrockbass8243/perpetualcalendarrockbass8243.github.io/main/content/application_v1.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940599/; classtype:trojan-activity;sid:84803699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940600)"; flow:established,from_client; content:"GET"; http_method; content:"/steamshipcompanyallspice7618/steamshipcompanyallspice7618.github.io/refs/heads/main/subaquatic/3.8-alpha.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940600/; classtype:trojan-activity;sid:84803700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940596)"; flow:established,from_client; content:"GET"; http_method; content:"/hexmaxen8174/hexmaxen8174.github.io/refs/heads/main/sprinkler/application_v2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940596/; classtype:trojan-activity;sid:84803696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940597)"; flow:established,from_client; content:"GET"; http_method; content:"/cyran-kyle/100-project-website/main/dist/project_website_3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940597/; classtype:trojan-activity;sid:84803697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940592)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/chatstudy/main/tasmanite/chat_study_3.2-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940592/; classtype:trojan-activity;sid:84803692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940593)"; flow:established,from_client; content:"GET"; http_method; content:"/condemnable-prosom618/condemnable-prosom618.github.io/main/geodesical/2.1-beta.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940593/; classtype:trojan-activity;sid:84803693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940594)"; flow:established,from_client; content:"GET"; http_method; content:"/colorless-characterisicfunction4030/colorless-characterisicfunction4030.github.io/refs/heads/main/fonts/latest-3.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940594/; classtype:trojan-activity;sid:84803694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940595)"; flow:established,from_client; content:"GET"; http_method; content:"/rightofactiongarden532/rightofactiongarden532.github.io/main/driven/3.5-alpha.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940595/; classtype:trojan-activity;sid:84803695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940590)"; flow:established,from_client; content:"GET"; http_method; content:"/erickv8589/premirror/refs/heads/main/packages/software_1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940590/; classtype:trojan-activity;sid:84803690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940591)"; flow:established,from_client; content:"GET"; http_method; content:"/cookie9867563/omniemu-universal-emulator-2026/refs/heads/main/naval/universal_emulator_emu_omni_2.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940591/; classtype:trojan-activity;sid:84803691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940589)"; flow:established,from_client; content:"GET"; http_method; content:"/eliasxd890/eliasxd890.github.io/refs/heads/main/assets/application_2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940589/; classtype:trojan-activity;sid:84803689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940586)"; flow:established,from_client; content:"GET"; http_method; content:"/mwebesanorman/fixmystreet/refs/heads/master/bin/fixmystreet.com/software-v1.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940586/; classtype:trojan-activity;sid:84803686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940587)"; flow:established,from_client; content:"GET"; http_method; content:"/wildenbust542/wildenbust542.github.io/main/images/release-2.1-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940587/; classtype:trojan-activity;sid:84803687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940588)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/portfolio-website/refs/heads/main/src/components/portfolio-website-chamite.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940588/; classtype:trojan-activity;sid:84803688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940583)"; flow:established,from_client; content:"GET"; http_method; content:"/jefferycoarsened4549/jefferycoarsened4549.github.io/main/test/assets/css/3.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940583/; classtype:trojan-activity;sid:84803683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940584)"; flow:established,from_client; content:"GET"; http_method; content:"/ivorunrequested60/ivorunrequested60.github.io/refs/heads/main/afterwit/latest-v2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940584/; classtype:trojan-activity;sid:84803684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940585)"; flow:established,from_client; content:"GET"; http_method; content:"/peopleupperpeninsula500/peopleupperpeninsula500.github.io/main/conversationalist/3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940585/; classtype:trojan-activity;sid:84803685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940580)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/1046132228/0d3a3f66-736b-4a94-9790-76a6965ec5e3|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-10-05t22%3a07%3a54z|7c|26|7c|rscd=attachment%3b+filename%3dcrypto_mcp_onchain_dex_v2.1.zip|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-10-05t21%3a07%3a01z|7c|26|7c|ske=2026-10-05t22%3a07%3a54z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=ydguvr30sf87fta7t1j0it2qdzucximdgesgxbknhak%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc5mtizntc1ocwibmjmijoxnzkxmjm1ndu4lcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.klvlppmnhmtmtgwkkind6l0p30dw6a7le8jdseoksem|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dcrypto_mcp_onchain_dex_v2.1.zip|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1044; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940580/; classtype:trojan-activity;sid:84803680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940581)"; flow:established,from_client; content:"GET"; http_method; content:"/luxs239/filawidgets/refs/heads/main/src/support/widgets-fila-v3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940581/; classtype:trojan-activity;sid:84803681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940582)"; flow:established,from_client; content:"GET"; http_method; content:"/mobsben/mobsben.github.io/main/leukotic/app_2.9-alpha.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940582/; classtype:trojan-activity;sid:84803682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940577)"; flow:established,from_client; content:"GET"; http_method; content:"/aidentelega/malmar/refs/heads/main/tallyman/software_v3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940577/; classtype:trojan-activity;sid:84803677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940578)"; flow:established,from_client; content:"GET"; http_method; content:"/joantelocentric8639/joantelocentric8639.github.io/refs/heads/main/games/app-3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940578/; classtype:trojan-activity;sid:84803678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940579)"; flow:established,from_client; content:"GET"; http_method; content:"/opaque-sensitivefern190/opaque-sensitivefern190.github.io/refs/heads/main/templates/partials/v1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940579/; classtype:trojan-activity;sid:84803679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940576)"; flow:established,from_client; content:"GET"; http_method; content:"/quadrate-yamoussukro456/quadrate-yamoussukro456.github.io/main/assets/release-2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940576/; classtype:trojan-activity;sid:84803676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940573)"; flow:established,from_client; content:"GET"; http_method; content:"/overweight-don864/overweight-don864.github.io/refs/heads/main/src/pages/v1.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940573/; classtype:trojan-activity;sid:84803673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940574)"; flow:established,from_client; content:"GET"; http_method; content:"/gavadis3646/tamawatchy/refs/heads/main/pachymeninx/software-1.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940574/; classtype:trojan-activity;sid:84803674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940575)"; flow:established,from_client; content:"GET"; http_method; content:"/ileanenoxious96/ileanenoxious96.github.io/main/inductometer/v1.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940575/; classtype:trojan-activity;sid:84803675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940571)"; flow:established,from_client; content:"GET"; http_method; content:"/cresson-pinkroot917/cresson-pinkroot917.github.io/main/landing/release-minoress.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940571/; classtype:trojan-activity;sid:84803671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940572)"; flow:established,from_client; content:"GET"; http_method; content:"/juanhenriqueda2/juanhenriqueda2.github.io/main/jedcock/app_2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940572/; classtype:trojan-activity;sid:84803672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940569)"; flow:established,from_client; content:"GET"; http_method; content:"/omehaent1122/omehaent1122.github.io/main/src/app/chat/%28id%29/messager/1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940569/; classtype:trojan-activity;sid:84803669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940570)"; flow:established,from_client; content:"GET"; http_method; content:"/supercharged-body2228/supercharged-body2228.github.io/main/frenchily/app_v2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940570/; classtype:trojan-activity;sid:84803670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940566)"; flow:established,from_client; content:"GET"; http_method; content:"/oneperson-woollyadelgid1574/oneperson-woollyadelgid1574.github.io/main/css/fourpounder.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940566/; classtype:trojan-activity;sid:84803666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940567)"; flow:established,from_client; content:"GET"; http_method; content:"/yassine1005/vigembus/master/.github/issue_template/vi_g_em_bus_v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940567/; classtype:trojan-activity;sid:84803667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940568)"; flow:established,from_client; content:"GET"; http_method; content:"/misplaced-box965/misplaced-box965.github.io/refs/heads/main/trustify/v2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940568/; classtype:trojan-activity;sid:84803668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940565)"; flow:established,from_client; content:"GET"; http_method; content:"/palmalescup167/palmalescup167.github.io/refs/heads/main/pauciplicate/3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940565/; classtype:trojan-activity;sid:84803665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940561)"; flow:established,from_client; content:"GET"; http_method; content:"/blimpish-appendicitis915/blimpish-appendicitis915.github.io/main/manila/release-3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940561/; classtype:trojan-activity;sid:84803661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940562)"; flow:established,from_client; content:"GET"; http_method; content:"/attemptvichy661/attemptvichy661.github.io/main/images/dist-v2.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940562/; classtype:trojan-activity;sid:84803662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940563)"; flow:established,from_client; content:"GET"; http_method; content:"/imperialist-toastmistress704/imperialist-toastmistress704.github.io/main/straightup/io-github-imperialist-toastmistress-1.2.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940563/; classtype:trojan-activity;sid:84803663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940564)"; flow:established,from_client; content:"GET"; http_method; content:"/embryonalcarcinomasarcoidosis299/embryonalcarcinomasarcoidosis299.github.io/main/gymnodont/dist_v2.6-beta.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940564/; classtype:trojan-activity;sid:84803664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940559)"; flow:established,from_client; content:"GET"; http_method; content:"/a406241691/a406241691.github.io/main/audit/latest-3.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940559/; classtype:trojan-activity;sid:84803659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940560)"; flow:established,from_client; content:"GET"; http_method; content:"/fatih-hamza/mediaingest/refs/heads/master/node_modules/reveal.js/plugin/ingest_media_1.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940560/; classtype:trojan-activity;sid:84803660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940557)"; flow:established,from_client; content:"GET"; http_method; content:"/lazarusfactorial745/openclaw-hub-runtime/main/examples/minimal-hub/openclaw_hub_runtime_harpyia.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940557/; classtype:trojan-activity;sid:84803657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940558)"; flow:established,from_client; content:"GET"; http_method; content:"/inextricable-armenianmonetaryunit23/loophole/refs/heads/main/sessions/software_3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940558/; classtype:trojan-activity;sid:84803658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940554)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedr7041/ahmedr7041.github.io/refs/heads/main/quaintish/latest-1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940554/; classtype:trojan-activity;sid:84803654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940555)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenphammc/valkyria-3.schematic/refs/heads/main/monopteridae/schematic-valkyria-1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940555/; classtype:trojan-activity;sid:84803655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940556)"; flow:established,from_client; content:"GET"; http_method; content:"/rocoagustin028-cell/rocoagustin028-cell.github.io/refs/heads/main/js/2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940556/; classtype:trojan-activity;sid:84803656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940552)"; flow:established,from_client; content:"GET"; http_method; content:"/nickyberndt20-web/nickyberndt20-web.github.io/refs/heads/main/audition/v2.6-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940552/; classtype:trojan-activity;sid:84803652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940553)"; flow:established,from_client; content:"GET"; http_method; content:"/feliciaupbound595/auralogger-node/refs/heads/main/src/client/node-auralogger-v1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940553/; classtype:trojan-activity;sid:84803653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940550)"; flow:established,from_client; content:"GET"; http_method; content:"/spanish-tabi644/22b-kiosk-self-service-kiosk-builder-for-small-businesses-/refs/heads/main/src/app/admin/service_self_small_builder_for_kiosk_businesses_v3.3.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940550/; classtype:trojan-activity;sid:84803650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940551)"; flow:established,from_client; content:"GET"; http_method; content:"/razen92/tgto123-public/refs/heads/main/croppa/public-tgto-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940551/; classtype:trojan-activity;sid:84803651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940548)"; flow:established,from_client; content:"GET"; http_method; content:"/alphonsoduplex577/alphonsoduplex577.github.io/main/outpost/github-alphonsoduplex-io-softtack.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940548/; classtype:trojan-activity;sid:84803648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940549)"; flow:established,from_client; content:"GET"; http_method; content:"/pigmandioxin527/pigmandioxin527.github.io/main/img/epithem.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940549/; classtype:trojan-activity;sid:84803649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940545)"; flow:established,from_client; content:"GET"; http_method; content:"/ahaaad3759/promptskill4image/refs/heads/main/suicidist/skill-image-prompt-vetitive.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940545/; classtype:trojan-activity;sid:84803645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940546)"; flow:established,from_client; content:"GET"; http_method; content:"/resumeplanofaction939/resumeplanofaction939.github.io/refs/heads/main/js/2.6-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940546/; classtype:trojan-activity;sid:84803646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940547)"; flow:established,from_client; content:"GET"; http_method; content:"/achrefboub/seba-designer/main/assets/js/seba-designer-2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940547/; classtype:trojan-activity;sid:84803647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940543)"; flow:established,from_client; content:"GET"; http_method; content:"/adocor/adocor.github.io/main/css/dist_3.6-beta.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940543/; classtype:trojan-activity;sid:84803643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940544)"; flow:established,from_client; content:"GET"; http_method; content:"/ninnettesudanese653/claude-plugins/refs/heads/main/plugins/hive/skills/pull-workflow/claude-plugins-v1.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940544/; classtype:trojan-activity;sid:84803644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940541)"; flow:established,from_client; content:"GET"; http_method; content:"/knjnt4435/knjnt4435.github.io/main/pathway_explorer/release-2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940541/; classtype:trojan-activity;sid:84803641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940542)"; flow:established,from_client; content:"GET"; http_method; content:"/vasiliadem1986/vasiliadem1986.github.io/main/synthesization/v1.3-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940542/; classtype:trojan-activity;sid:84803642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940537)"; flow:established,from_client; content:"GET"; http_method; content:"/bennetseaward4867/bennetseaward4867.github.io/main/docs/application-petit.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940537/; classtype:trojan-activity;sid:84803637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940538)"; flow:established,from_client; content:"GET"; http_method; content:"/baldcypresssavingsandloan849/baldcypresssavingsandloan849.github.io/main/docs/latest_2.9-beta.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940538/; classtype:trojan-activity;sid:84803638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940539)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/hydro_scan/refs/heads/main/src/scan_hydro_1.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940539/; classtype:trojan-activity;sid:84803639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940540)"; flow:established,from_client; content:"GET"; http_method; content:"/anguslowcal299/anguslowcal299.github.io/refs/heads/main/exhibition/v3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940540/; classtype:trojan-activity;sid:84803640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940535)"; flow:established,from_client; content:"GET"; http_method; content:"/talalm7731/talalm7731.github.io/main/extortioner/application_3.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940535/; classtype:trojan-activity;sid:84803635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940536)"; flow:established,from_client; content:"GET"; http_method; content:"/vikynofebriputra-creator/orkas-awesome-agentskills/refs/heads/main/education/skills/math-tutor/references/orkas_awesome_agent_skills_1.2-alpha.1.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940536/; classtype:trojan-activity;sid:84803636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940531)"; flow:established,from_client; content:"GET"; http_method; content:"/yorkshireterriertyrant786/yorkshireterriertyrant786.github.io/main/ind/release_1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940531/; classtype:trojan-activity;sid:84803631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940532)"; flow:established,from_client; content:"GET"; http_method; content:"/unsurpassable-adalia371/unsurpassable-adalia371.github.io/main/plenty/unsurpassable_adalia_github_io_2.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940532/; classtype:trojan-activity;sid:84803632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940533)"; flow:established,from_client; content:"GET"; http_method; content:"/moonbhat3914/moonbhat3914.github.io/refs/heads/main/myomere/1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940533/; classtype:trojan-activity;sid:84803633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940534)"; flow:established,from_client; content:"GET"; http_method; content:"/lukasriedinger1501-alt/datahub/refs/heads/main/docs/software_v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940534/; classtype:trojan-activity;sid:84803634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940528)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinavv22/abhinavv22/main/wharfinger/abhinavv-3.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940528/; classtype:trojan-activity;sid:84803628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940529)"; flow:established,from_client; content:"GET"; http_method; content:"/waleedoilsoluble656/waleedoilsoluble656.github.io/refs/heads/main/femininism/3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940529/; classtype:trojan-activity;sid:84803629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940530)"; flow:established,from_client; content:"GET"; http_method; content:"/habitforming-memorabilia64/habitforming-memorabilia64.github.io/refs/heads/main/depasturable/v1.4-alpha.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940530/; classtype:trojan-activity;sid:84803630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940526)"; flow:established,from_client; content:"GET"; http_method; content:"/udalefourfold471/udalefourfold471.github.io/main/revalenta/github_udalefourfold_io_v1.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940526/; classtype:trojan-activity;sid:84803626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940527)"; flow:established,from_client; content:"GET"; http_method; content:"/coopeconomy4265/coopeconomy4265.github.io/main/js/dist-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940527/; classtype:trojan-activity;sid:84803627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940523)"; flow:established,from_client; content:"GET"; http_method; content:"/heartbreaking-greenhouseeffect508/god-prompt/refs/heads/main/core/god_prompt_3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940523/; classtype:trojan-activity;sid:84803623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940524)"; flow:established,from_client; content:"GET"; http_method; content:"/daftartotovip-login/astro-platform-starter/main/src/pages/blobs/astro-starter-platform-moeritheriidae.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940524/; classtype:trojan-activity;sid:84803624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940525)"; flow:established,from_client; content:"GET"; http_method; content:"/francisnjavwa/francisnjavwa.github.io/main/assets/uploads/dist_v1.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940525/; classtype:trojan-activity;sid:84803625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940521)"; flow:established,from_client; content:"GET"; http_method; content:"/noisi1802/noisi1802.github.io/main/src/ble/latest-chylangioma.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940521/; classtype:trojan-activity;sid:84803621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940522)"; flow:established,from_client; content:"GET"; http_method; content:"/conniving-catechist742/conniving-catechist742.github.io/main/superglorious/tarrock.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940522/; classtype:trojan-activity;sid:84803622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940519)"; flow:established,from_client; content:"GET"; http_method; content:"/aditya974240/aditya974240.github.io/main/html_source_file/assets/files/3.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940519/; classtype:trojan-activity;sid:84803619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940520)"; flow:established,from_client; content:"GET"; http_method; content:"/seniorbirchbark481/seniorbirchbark481.github.io/refs/heads/main/_ds/double-impala-design-system-d3e56450-a6f9-4d9f-a458-70f58b4d2fed/tokens/v1.8.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940520/; classtype:trojan-activity;sid:84803620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940516)"; flow:established,from_client; content:"GET"; http_method; content:"/antony14816/antony14816.github.io/main/succinctly/application-1.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940516/; classtype:trojan-activity;sid:84803616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940517)"; flow:established,from_client; content:"GET"; http_method; content:"/fried-headlock977/wraithrun/refs/heads/main/outlash/wraith_run_v3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940517/; classtype:trojan-activity;sid:84803617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940518)"; flow:established,from_client; content:"GET"; http_method; content:"/tuesdaylogical990/tuesdaylogical990.github.io/main/deafforestation/1.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940518/; classtype:trojan-activity;sid:84803618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940514)"; flow:established,from_client; content:"GET"; http_method; content:"/thaih6448/thaih6448.github.io/main/supersovereign/application_1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940514/; classtype:trojan-activity;sid:84803614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940515)"; flow:established,from_client; content:"GET"; http_method; content:"/sable-falsepretense40/quipnetwork-node-autoinstall/refs/heads/main/postbulbar/quip_node_network_autoinstall_1.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940515/; classtype:trojan-activity;sid:84803615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940511)"; flow:established,from_client; content:"GET"; http_method; content:"/ap4993258/ap4993258.github.io/main/unstocked/app-3.8-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940511/; classtype:trojan-activity;sid:84803611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940512)"; flow:established,from_client; content:"GET"; http_method; content:"/tablesawuplink633/nextjs-mobile-app-template/refs/heads/main/src/app/timer/app_nextjs_mobile_template_v2.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940512/; classtype:trojan-activity;sid:84803612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940513)"; flow:established,from_client; content:"GET"; http_method; content:"/knackered-voice286/knackered-voice286.github.io/main/data/raw/application_v2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940513/; classtype:trojan-activity;sid:84803613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940508)"; flow:established,from_client; content:"GET"; http_method; content:"/zakariyawaelgweari2005-cyber/votingsystem/refs/heads/main/daleman/system-voting-1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940508/; classtype:trojan-activity;sid:84803608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940509)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaystunning129/ajaystunning129.github.io/main/site_libs/font-awesome-6.5.2/css/1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940509/; classtype:trojan-activity;sid:84803609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940510)"; flow:established,from_client; content:"GET"; http_method; content:"/alliebehindhand7878/alliebehindhand7878.github.io/refs/heads/main/assets/js/2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940510/; classtype:trojan-activity;sid:84803610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940506)"; flow:established,from_client; content:"GET"; http_method; content:"/ngthuy83/docs/refs/heads/main/docs/software-v2.8-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940506/; classtype:trojan-activity;sid:84803606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940507)"; flow:established,from_client; content:"GET"; http_method; content:"/connedigital/pirates-mediaserver/master/mono/mediaserver-pirates-2.4-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940507/; classtype:trojan-activity;sid:84803607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940503)"; flow:established,from_client; content:"GET"; http_method; content:"/test4prijedor/test4prijedor.github.io/main/diageotropic/release-nonpoisonous.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940503/; classtype:trojan-activity;sid:84803603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940504)"; flow:established,from_client; content:"GET"; http_method; content:"/flossyclose346/flossyclose346.github.io/main/colical/app_3.3-beta.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940504/; classtype:trojan-activity;sid:84803604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940505)"; flow:established,from_client; content:"GET"; http_method; content:"/genuscalendulaheadword712/genuscalendulaheadword712.github.io/main/biporose/release-3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940505/; classtype:trojan-activity;sid:84803605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940502)"; flow:established,from_client; content:"GET"; http_method; content:"/donnaraising222/donnaraising222.github.io/main/afterpeak/2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940502/; classtype:trojan-activity;sid:84803602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940500)"; flow:established,from_client; content:"GET"; http_method; content:"/swor3653/swor3653.github.io/main/undebased/application-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940500/; classtype:trojan-activity;sid:84803600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940501)"; flow:established,from_client; content:"GET"; http_method; content:"/thomas-nyanumba/atlanta-pd-power-bi-group-project/refs/heads/main/axoplasm/group_atlanta_p_power_project_b_v3.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940501/; classtype:trojan-activity;sid:84803601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940499)"; flow:established,from_client; content:"GET"; http_method; content:"/shortiaallurement927/shortiaallurement927.github.io/main/html_source_file/assets/files/v3.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940499/; classtype:trojan-activity;sid:84803599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940498)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/blockchain-for-business/refs/heads/main/mollycosset/business_blockchain_for_v1.6-beta.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940498/; classtype:trojan-activity;sid:84803598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940497)"; flow:established,from_client; content:"GET"; http_method; content:"/rerickh6565/rerickh6565.github.io/main/data/release-2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940497/; classtype:trojan-activity;sid:84803597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940494)"; flow:established,from_client; content:"GET"; http_method; content:"/malyndaoverbearing532/malyndaoverbearing532.github.io/main/nonreciprocity/v3.5-beta.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940494/; classtype:trojan-activity;sid:84803594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940495)"; flow:established,from_client; content:"GET"; http_method; content:"/rosanabullheaded2685/rosanabullheaded2685.github.io/main/content/courses/hugo-blox/guide/dist_v1.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940495/; classtype:trojan-activity;sid:84803595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940496)"; flow:established,from_client; content:"GET"; http_method; content:"/maudeunfledged834/startup-founder-skills/main/skills/interview-kit/skills-founder-startup-inexacting.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940496/; classtype:trojan-activity;sid:84803596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940493)"; flow:established,from_client; content:"GET"; http_method; content:"/shiftin7836/shiftin7836.github.io/main/images/v1.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940493/; classtype:trojan-activity;sid:84803593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940492)"; flow:established,from_client; content:"GET"; http_method; content:"/kfxuyang-web/second-brain/refs/heads/main/wiki/archives/brain-second-v1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940492/; classtype:trojan-activity;sid:84803592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940491)"; flow:established,from_client; content:"GET"; http_method; content:"/ansabmoeen444/ansabmoeen444.github.io/main/bargehouse/3.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940491/; classtype:trojan-activity;sid:84803591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940487)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/bank-of-flat-ion-phase-two/refs/heads/main/src/phase-two-flat-ion-of-bank-2.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940487/; classtype:trojan-activity;sid:84803587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940488)"; flow:established,from_client; content:"GET"; http_method; content:"/harmonic-marquee6439/harmonic-marquee6439.github.io/refs/heads/main/defunctness/v1.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940488/; classtype:trojan-activity;sid:84803588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940489)"; flow:established,from_client; content:"GET"; http_method; content:"/snowsuitgenushyssopus66/snowsuitgenushyssopus66.github.io/main/whaleback/application_2.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940489/; classtype:trojan-activity;sid:84803589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940490)"; flow:established,from_client; content:"GET"; http_method; content:"/clas8996/clas8996.github.io/refs/heads/main/images/dist_v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940490/; classtype:trojan-activity;sid:84803590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940479)"; flow:established,from_client; content:"GET"; http_method; content:"/3yyx/discord-dashboard/refs/heads/master/public/css/dashboard_discord_v1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940479/; classtype:trojan-activity;sid:84803579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940480)"; flow:established,from_client; content:"GET"; http_method; content:"/executive-steampipe578/executive-steampipe578.github.io/main/mimetene/latest_1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940480/; classtype:trojan-activity;sid:84803580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940481)"; flow:established,from_client; content:"GET"; http_method; content:"/fulfilled-stanford789/fulfilled-stanford789.github.io/main/dorsiflexion/release_hydnoid.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940481/; classtype:trojan-activity;sid:84803581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940482)"; flow:established,from_client; content:"GET"; http_method; content:"/rmdhaan/bricks-mcp-open/refs/heads/main/astrolabical/mcp-bricks-open-1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940482/; classtype:trojan-activity;sid:84803582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940483)"; flow:established,from_client; content:"GET"; http_method; content:"/sly7783/sly7783.github.io/main/assets/pic/release-3.3-beta.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940483/; classtype:trojan-activity;sid:84803583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940484)"; flow:established,from_client; content:"GET"; http_method; content:"/bijonkumarbd24566-dot/bijonkumarbd24566-dot.github.io/refs/heads/main/assets/images/app-v1.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940484/; classtype:trojan-activity;sid:84803584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940485)"; flow:established,from_client; content:"GET"; http_method; content:"/ruturajbhaskarnawale/deepfake/main/backend/ml_system/ff_env/scripts/software_repossessor.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940485/; classtype:trojan-activity;sid:84803585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940486)"; flow:established,from_client; content:"GET"; http_method; content:"/raghulravi08032007-collab/raghulravi08032007-collab.github.io/main/radiality/2.4-beta.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940486/; classtype:trojan-activity;sid:84803586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940476)"; flow:established,from_client; content:"GET"; http_method; content:"/0saifw11-blip/0saifw11-blip.github.io/main/inkwood/v2.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940476/; classtype:trojan-activity;sid:84803576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940477)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibofcx/mikrotik-tools/master/exploit-backup/mikrotik_tools_huskershredder.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940477/; classtype:trojan-activity;sid:84803577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940478)"; flow:established,from_client; content:"GET"; http_method; content:"/itoharuki929/itoharuki929.github.io/refs/heads/main/intergrade/app-v1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940478/; classtype:trojan-activity;sid:84803578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940474)"; flow:established,from_client; content:"GET"; http_method; content:"/ashutoshbanjare572-netizen/netset2p2p/refs/heads/main/tests/netset_p_v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940474/; classtype:trojan-activity;sid:84803574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940475)"; flow:established,from_client; content:"GET"; http_method; content:"/serviceswage2135/serviceswage2135.github.io/main/teriann/3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940475/; classtype:trojan-activity;sid:84803575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940472)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/deel-task/main/android/app/src/test/java/deel-task-3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940472/; classtype:trojan-activity;sid:84803572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940473)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibofcx/mikrotikexploit/master/onanistic/exploit-mikrotik-v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940473/; classtype:trojan-activity;sid:84803573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940470)"; flow:established,from_client; content:"GET"; http_method; content:"/timh1203/timh1203.github.io/main/multiliteral/2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940470/; classtype:trojan-activity;sid:84803570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940471)"; flow:established,from_client; content:"GET"; http_method; content:"/balwant-chauhan-data-eng-project/balwant-chauhan-data-eng-project/refs/heads/main/thallophyte/eng-project-data-chauhan-balwant-v3.3.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940471/; classtype:trojan-activity;sid:84803571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940468)"; flow:established,from_client; content:"GET"; http_method; content:"/kajusramanuskas/kajusramanuskas.github.io/main/gratitude/application_1.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940468/; classtype:trojan-activity;sid:84803568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940469)"; flow:established,from_client; content:"GET"; http_method; content:"/az326184/pomo/refs/heads/main/calculative/software-3.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940469/; classtype:trojan-activity;sid:84803569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940465)"; flow:established,from_client; content:"GET"; http_method; content:"/algernontraumatic377/algernontraumatic377.github.io/main/complex/1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940465/; classtype:trojan-activity;sid:84803565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940466)"; flow:established,from_client; content:"GET"; http_method; content:"/faijurrahman5947/faijurrahman5947.github.io/refs/heads/main/jiejia-homepage-upload/assets/latest-v1.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940466/; classtype:trojan-activity;sid:84803566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940467)"; flow:established,from_client; content:"GET"; http_method; content:"/salman3757/linkedin-skill-assessments-quizzes/master/adobe-acrobat/linkedin-skill-assessments-quizzes-v2.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940467/; classtype:trojan-activity;sid:84803567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940460)"; flow:established,from_client; content:"GET"; http_method; content:"/0hok/l0v3/root/public/v-l-3.4.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940460/; classtype:trojan-activity;sid:84803560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940461)"; flow:established,from_client; content:"GET"; http_method; content:"/nishigandhakhaire/nishigandhakhaire.github.io/refs/heads/main/posca/application_v1.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940461/; classtype:trojan-activity;sid:84803561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940462)"; flow:established,from_client; content:"GET"; http_method; content:"/branded12345/phishing_website_detection/main/.vscode/website-phishing-detection-v1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940462/; classtype:trojan-activity;sid:84803562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940463)"; flow:established,from_client; content:"GET"; http_method; content:"/img_073126.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"summitcapitalpatners.info"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940463/; classtype:trojan-activity;sid:84803563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940464)"; flow:established,from_client; content:"GET"; http_method; content:"/fast-newengland468/cyberclaw/refs/heads/main/interrupter/cyber-claw-v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940464/; classtype:trojan-activity;sid:84803564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940458)"; flow:established,from_client; content:"GET"; http_method; content:"/fragmentationcarolinalupine81/causal-image-embedding/refs/heads/main/src/experiment/image-embedding-causal-3.0.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940458/; classtype:trojan-activity;sid:84803558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940459)"; flow:established,from_client; content:"GET"; http_method; content:"/trenhol54/trenhol54.github.io/refs/heads/main/tenebrae/latest-v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940459/; classtype:trojan-activity;sid:84803559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940454)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/19ai547-blockchain-for-business/main/kung/for-a-business-blockchain-2.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940454/; classtype:trojan-activity;sid:84803554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940455)"; flow:established,from_client; content:"GET"; http_method; content:"/shr1324/cka-2024/main/resources/day14/ck_2.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940455/; classtype:trojan-activity;sid:84803555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940456)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/le-site/main/le-site--main/site_le_v3.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940456/; classtype:trojan-activity;sid:84803556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940457)"; flow:established,from_client; content:"GET"; http_method; content:"/limited-bulgurpilaf79/limited-bulgurpilaf79.github.io/refs/heads/main/superaural/app_v3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940457/; classtype:trojan-activity;sid:84803557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940452)"; flow:established,from_client; content:"GET"; http_method; content:"/dysphoriarathole151/dysphoriarathole151.github.io/refs/heads/main/_portfolio/1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940452/; classtype:trojan-activity;sid:84803552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940453)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammedenesb100/muhammedenesb100.github.io/main/bedragglement/1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940453/; classtype:trojan-activity;sid:84803553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940450)"; flow:established,from_client; content:"GET"; http_method; content:"/rajiv-sapkota/weatherappts/main/src/ts-weather-app-2.3-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940450/; classtype:trojan-activity;sid:84803550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940451)"; flow:established,from_client; content:"GET"; http_method; content:"/charlottejv/netflix-clone/refs/heads/main/pages/watch/clone-netflix-bookful.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940451/; classtype:trojan-activity;sid:84803551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940444)"; flow:established,from_client; content:"GET"; http_method; content:"/moatafa3263/moatafa3263.github.io/main/systasis/v3.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940444/; classtype:trojan-activity;sid:84803544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940445)"; flow:established,from_client; content:"GET"; http_method; content:"/ghost8246/ghost8246.github.io/main/app/experience/3.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940445/; classtype:trojan-activity;sid:84803545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940446)"; flow:established,from_client; content:"GET"; http_method; content:"/undefeated-eccentricity921/undefeated-eccentricity921.github.io/main/proslave/3.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940446/; classtype:trojan-activity;sid:84803546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940447)"; flow:established,from_client; content:"GET"; http_method; content:"/binarydigitjohnmilton633/binarydigitjohnmilton633.github.io/refs/heads/main/assets/img/dist_2.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940447/; classtype:trojan-activity;sid:84803547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940448)"; flow:established,from_client; content:"GET"; http_method; content:"/inclement-genusfistularia640/inclement-genusfistularia640.github.io/main/sulphoamid/app-2.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940448/; classtype:trojan-activity;sid:84803548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940449)"; flow:established,from_client; content:"GET"; http_method; content:"/indocindesertplant48/indocindesertplant48.github.io/refs/heads/main/assets/images/projects/dist_v2.0-beta.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940449/; classtype:trojan-activity;sid:84803549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940442)"; flow:established,from_client; content:"GET"; http_method; content:"/concluded-lahu708/concluded-lahu708.github.io/refs/heads/main/pistg/application-unprofitably.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940442/; classtype:trojan-activity;sid:84803542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940443)"; flow:established,from_client; content:"GET"; http_method; content:"/benjytufted641/benjytufted641.github.io/main/grandma/application_1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940443/; classtype:trojan-activity;sid:84803543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940440)"; flow:established,from_client; content:"GET"; http_method; content:"/arkhitrana-pixel/arkhitrana-pixel.github.io/main/superromantic/latest-3.7-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940440/; classtype:trojan-activity;sid:84803540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940441)"; flow:established,from_client; content:"GET"; http_method; content:"/nessytall275/skateboard-animation/refs/heads/main/image/animation_skateboard_2.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940441/; classtype:trojan-activity;sid:84803541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940436)"; flow:established,from_client; content:"GET"; http_method; content:"/fixed-logjam434/fixed-logjam434.github.io/main/oviparously/application-2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940436/; classtype:trojan-activity;sid:84803536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940437)"; flow:established,from_client; content:"GET"; http_method; content:"/eighteenthpodocarpaceae846/eighteenthpodocarpaceae846.github.io/refs/heads/main/sclerotia/v1.7-alpha.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940437/; classtype:trojan-activity;sid:84803537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940438)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/phase-0-completing-assignments-codegrade/main/test/codegrade-phase-completing-assignments-v3.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940438/; classtype:trojan-activity;sid:84803538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940439)"; flow:established,from_client; content:"GET"; http_method; content:"/tagj6807/tagj6807.github.io/main/dicondylian/tagj-github-io-v1.8-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940439/; classtype:trojan-activity;sid:84803539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940430)"; flow:established,from_client; content:"GET"; http_method; content:"/alex999898/htb-writeups/refs/heads/main/challenges/osint/writeups-htb-3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940430/; classtype:trojan-activity;sid:84803530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940431)"; flow:established,from_client; content:"GET"; http_method; content:"/norapr3339/norapr3339.github.io/main/en/application-v2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940431/; classtype:trojan-activity;sid:84803531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940432)"; flow:established,from_client; content:"GET"; http_method; content:"/princesuchak/simple-calculator/main/relishsome/calculator_simple_v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940432/; classtype:trojan-activity;sid:84803532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940433)"; flow:established,from_client; content:"GET"; http_method; content:"/lauracol26/lauracol26.github.io/main/img/stropharia.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940433/; classtype:trojan-activity;sid:84803533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940434)"; flow:established,from_client; content:"GET"; http_method; content:"/associative-cufflink159/associative-cufflink159.github.io/refs/heads/main/hymnography/github_cufflink_io_associative_sexdigitism.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940434/; classtype:trojan-activity;sid:84803534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940435)"; flow:established,from_client; content:"GET"; http_method; content:"/rushdudeboy/rushdudeboy.github.io/main/omicron/2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940435/; classtype:trojan-activity;sid:84803535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940428)"; flow:established,from_client; content:"GET"; http_method; content:"/exvideoclips/steins-gate-adventures-roblox-script-hub/refs/heads/branch/epitaphless/steins-roblox-adventures-hub-script-gate-v2.7.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940428/; classtype:trojan-activity;sid:84803528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940429)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar441/potato-disease-classification/main/saved_models/2/classification_disease_potato_1.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940429/; classtype:trojan-activity;sid:84803529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940424)"; flow:established,from_client; content:"GET"; http_method; content:"/aftonstudios888/aftonstudios888.github.io/main/fanwright/app_3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940424/; classtype:trojan-activity;sid:84803524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940425)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/960410294/33617674-9cd3-48d4-bb4b-c720067b9e88|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-10-05t22%3a00%3a41z|7c|26|7c|rscd=attachment%3b+filename%3ddocket.v2.2.5.zip|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-10-05t21%3a00%3a41z|7c|26|7c|ske=2026-10-05t22%3a00%3a41z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=l17z0kpfllfb8d%2bx72azoby%2bsgcythndhp5t%2fte5mag%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc5mtizntc1mcwibmjmijoxnzkxmjm1nduwlcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.pg6bfqhh4nqk5cummd8hlgqsbm8v05lucppy1zspijm|7c|26|7c|response-content-disposition=attachment%3b%20filename%3ddocket.v2.2.5.zip|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1021; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940425/; classtype:trojan-activity;sid:84803525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940426)"; flow:established,from_client; content:"GET"; http_method; content:"/alextan38/alextan38.github.io/main/postcalcarine/v2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940426/; classtype:trojan-activity;sid:84803526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940427)"; flow:established,from_client; content:"GET"; http_method; content:"/7dieuuoc/hello-world-app/refs/heads/master/public/world-hello-app-v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940427/; classtype:trojan-activity;sid:84803527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940421)"; flow:established,from_client; content:"GET"; http_method; content:"/resentful-hammerheadshark2276/resentful-hammerheadshark2276.github.io/main/discharging/1.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940421/; classtype:trojan-activity;sid:84803521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940422)"; flow:established,from_client; content:"GET"; http_method; content:"/apostolosreverse961/apostolosreverse961.github.io/refs/heads/main/assets/img/v1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940422/; classtype:trojan-activity;sid:84803522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940423)"; flow:established,from_client; content:"GET"; http_method; content:"/catchpenny-seatrout274/catchpenny-seatrout274.github.io/main/nonfiscal/seatrout_io_github_catchpenny_v2.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940423/; classtype:trojan-activity;sid:84803523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940415)"; flow:established,from_client; content:"GET"; http_method; content:"/worldwarhogmanay220/worldwarhogmanay220.github.io/main/lobose/v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940415/; classtype:trojan-activity;sid:84803515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940416)"; flow:established,from_client; content:"GET"; http_method; content:"/absentt2626/absentt2626.github.io/refs/heads/main/assets/application-3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940416/; classtype:trojan-activity;sid:84803516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940417)"; flow:established,from_client; content:"GET"; http_method; content:"/primetimerico/primetimerico.github.io/main/pamprodactyl/dist-clinium.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940417/; classtype:trojan-activity;sid:84803517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940418)"; flow:established,from_client; content:"GET"; http_method; content:"/aneteerl7226/aneteerl7226.github.io/main/cabuya/release-flimsily.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940418/; classtype:trojan-activity;sid:84803518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940419)"; flow:established,from_client; content:"GET"; http_method; content:"/kali99xx/frida/refs/heads/main/.github/workflows/software_v3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940419/; classtype:trojan-activity;sid:84803519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940420)"; flow:established,from_client; content:"GET"; http_method; content:"/abhishekkumarnaik34-hub/abhishekkumarnaik34-hub.github.io/main/assets/3.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940420/; classtype:trojan-activity;sid:84803520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940407)"; flow:established,from_client; content:"GET"; http_method; content:"/sabbatical-stuffedderma381/sabbatical-stuffedderma381.github.io/main/assets/v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940407/; classtype:trojan-activity;sid:84803507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940408)"; flow:established,from_client; content:"GET"; http_method; content:"/idkwhatismyname123/chatgpt-anywhere/main/src/types/chatgpt_anywhere_2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940408/; classtype:trojan-activity;sid:84803508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940409)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal996999/nodebattle/refs/heads/main/api/software_3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940409/; classtype:trojan-activity;sid:84803509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940410)"; flow:established,from_client; content:"GET"; http_method; content:"/testingzenz-sys/testingzenz-sys.github.io/main/bookstand/3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940410/; classtype:trojan-activity;sid:84803510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940411)"; flow:established,from_client; content:"GET"; http_method; content:"/brayanob2003/rsa-file-transfer/main/src/java/rsa-file-transfer_v2.4-alpha.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940411/; classtype:trojan-activity;sid:84803511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940412)"; flow:established,from_client; content:"GET"; http_method; content:"/adyg2387/adyg2387.github.io/refs/heads/main/img/application-v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940412/; classtype:trojan-activity;sid:84803512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940413)"; flow:established,from_client; content:"GET"; http_method; content:"/ardythrunresistant2575/ardythrunresistant2575.github.io/main/shared/types/latest_2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940413/; classtype:trojan-activity;sid:84803513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940414)"; flow:established,from_client; content:"GET"; http_method; content:"/impure-splenitis1799/impure-splenitis1799.github.io/refs/heads/main/ureteroenterostomy/2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940414/; classtype:trojan-activity;sid:84803514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940405)"; flow:established,from_client; content:"GET"; http_method; content:"/deepmined-macadamianut74/deepmined-macadamianut74.github.io/main/static/app_3.7-alpha.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940405/; classtype:trojan-activity;sid:84803505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940406)"; flow:established,from_client; content:"GET"; http_method; content:"/randhead470/randhead470.github.io/main/printer/randhead-io-github-2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940406/; classtype:trojan-activity;sid:84803506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940404)"; flow:established,from_client; content:"GET"; http_method; content:"/a2434132/a2434132.github.io/main/aire/2.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940404/; classtype:trojan-activity;sid:84803504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940402)"; flow:established,from_client; content:"GET"; http_method; content:"/coffeefernyam34/coffeefernyam34.github.io/main/flusher/3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940402/; classtype:trojan-activity;sid:84803502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940403)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/ideal-labs-assingment/main/californian/ideal-assingment-labs-v3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940403/; classtype:trojan-activity;sid:84803503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940400)"; flow:established,from_client; content:"GET"; http_method; content:"/privateersmanvogue8510/privateersmanvogue8510.github.io/refs/heads/main/bin/2.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940400/; classtype:trojan-activity;sid:84803500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940401)"; flow:established,from_client; content:"GET"; http_method; content:"/odessaspecial486/odessaspecial486.github.io/refs/heads/main/js/uplaid.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940401/; classtype:trojan-activity;sid:84803501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940399)"; flow:established,from_client; content:"GET"; http_method; content:"/fareseladel6-jpg/fareseladel6-jpg.github.io/main/src/release-v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940399/; classtype:trojan-activity;sid:84803499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940396)"; flow:established,from_client; content:"GET"; http_method; content:"/drexr9558/jit-viewer-sdk/refs/heads/main/vue-demo/dist/samples/sdk_viewer_jit_2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940396/; classtype:trojan-activity;sid:84803496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940397)"; flow:established,from_client; content:"GET"; http_method; content:"/barto1994/youtube-music/refs/heads/master/src/plugins/visualizer/music-youtube-v3.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940397/; classtype:trojan-activity;sid:84803497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940398)"; flow:established,from_client; content:"GET"; http_method; content:"/dextercool/approcket-preproject/refs/heads/master/public/build/css/preproject-approcket-v3.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940398/; classtype:trojan-activity;sid:84803498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940394)"; flow:established,from_client; content:"GET"; http_method; content:"/sergejapple78/sergejapple78.github.io/main/bismuthite/1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940394/; classtype:trojan-activity;sid:84803494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940395)"; flow:established,from_client; content:"GET"; http_method; content:"/deweyclimbable4960/deweyclimbable4960.github.io/refs/heads/main/liquidity/app-v1.4-beta.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940395/; classtype:trojan-activity;sid:84803495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940391)"; flow:established,from_client; content:"GET"; http_method; content:"/amexhub8998/amexhub8998.github.io/refs/heads/main/assets/android/release_1.6-beta.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940391/; classtype:trojan-activity;sid:84803491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940392)"; flow:established,from_client; content:"GET"; http_method; content:"/sakib701sa/sakib701sa.github.io/refs/heads/main/upthrust/3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940392/; classtype:trojan-activity;sid:84803492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940393)"; flow:established,from_client; content:"GET"; http_method; content:"/longsuitfala203/longsuitfala203.github.io/main/nodi/v1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940393/; classtype:trojan-activity;sid:84803493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940387)"; flow:established,from_client; content:"GET"; http_method; content:"/putoamo8579/putoamo8579.github.io/main/paramenia/v1.9-alpha.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940387/; classtype:trojan-activity;sid:84803487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940388)"; flow:established,from_client; content:"GET"; http_method; content:"/omar-20067/omar-pro2006/refs/heads/main/fritillaria/pro-omar-v1.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940388/; classtype:trojan-activity;sid:84803488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940389)"; flow:established,from_client; content:"GET"; http_method; content:"/zainmaryam876-source/zainmaryam876-source.github.io/main/docs/v3.3-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940389/; classtype:trojan-activity;sid:84803489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940390)"; flow:established,from_client; content:"GET"; http_method; content:"/stelliteswiftlet384/stelliteswiftlet384.github.io/main/unwarbled/v2.1-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940390/; classtype:trojan-activity;sid:84803490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940384)"; flow:established,from_client; content:"GET"; http_method; content:"/chuckaballe60/chrome/main/docs/software_3.9.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940384/; classtype:trojan-activity;sid:84803484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940385)"; flow:established,from_client; content:"GET"; http_method; content:"/psychical-recitative896/psychical-recitative896.github.io/main/papyrean/app-3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940385/; classtype:trojan-activity;sid:84803485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940386)"; flow:established,from_client; content:"GET"; http_method; content:"/keremkarsiyaka/django_google_clone/refs/heads/master/search/migrations/django-clone-google-1.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940386/; classtype:trojan-activity;sid:84803486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940381)"; flow:established,from_client; content:"GET"; http_method; content:"/boozy-familyupupidae150/boozy-familyupupidae150.github.io/main/publications/optimal-experimental-design/latest-2.4-alpha.3.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940381/; classtype:trojan-activity;sid:84803481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940382)"; flow:established,from_client; content:"GET"; http_method; content:"/afrazpindari14-commits/afrazpindari14-commits.github.io/main/_layouts/release-v2.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940382/; classtype:trojan-activity;sid:84803482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940383)"; flow:established,from_client; content:"GET"; http_method; content:"/rattrapgenuscalliandra840/rattrapgenuscalliandra840.github.io/refs/heads/main/imagens/notator.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940383/; classtype:trojan-activity;sid:84803483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940379)"; flow:established,from_client; content:"GET"; http_method; content:"/ibragullam/cloudstack/refs/heads/master/engine/components-api/src/main/java/com/cloud/hypervisor/software-2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940379/; classtype:trojan-activity;sid:84803479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940380)"; flow:established,from_client; content:"GET"; http_method; content:"/amir8523/amir8523.github.io/main/assets/css/3.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940380/; classtype:trojan-activity;sid:84803480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940376)"; flow:established,from_client; content:"GET"; http_method; content:"/alicia2859/alicia2859.github.io/refs/heads/main/img/2.4-beta.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940376/; classtype:trojan-activity;sid:84803476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940377)"; flow:established,from_client; content:"GET"; http_method; content:"/sharmara5602/sharmara5602.github.io/refs/heads/main/bastille/release-prosopon.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940377/; classtype:trojan-activity;sid:84803477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940378)"; flow:established,from_client; content:"GET"; http_method; content:"/asadalaziz/kamranasadalaziz.github.io/refs/heads/main/unlugged/io_github_kamranasadalaziz_v3.5-alpha.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940378/; classtype:trojan-activity;sid:84803478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940374)"; flow:established,from_client; content:"GET"; http_method; content:"/genuscalophyllumorderthysanoptera921/gova-saas-crm-cx-platform/refs/heads/main/entocoelic/saas_cx_platform_gova_crm_3.3.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940374/; classtype:trojan-activity;sid:84803474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940375)"; flow:established,from_client; content:"GET"; http_method; content:"/hellhoundcorpse/awesome-c64/master/oaklike/c_awesome_3.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940375/; classtype:trojan-activity;sid:84803475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940372)"; flow:established,from_client; content:"GET"; http_method; content:"/zalhat586/zalhat586.github.io/main/renes/v2.6.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940372/; classtype:trojan-activity;sid:84803472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940373)"; flow:established,from_client; content:"GET"; http_method; content:"/terezasluttie/gyroflow/refs/heads/main/chemic/software_v2.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940373/; classtype:trojan-activity;sid:84803473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940370)"; flow:established,from_client; content:"GET"; http_method; content:"/employeesavingsplanmelagra893/skillanything/refs/heads/main/references/anything-skill-v2.2-alpha.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940370/; classtype:trojan-activity;sid:84803470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940371)"; flow:established,from_client; content:"GET"; http_method; content:"/verisimilar-presidentpierce292/can-i-help/refs/heads/main/agents/can-i-help-v1.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940371/; classtype:trojan-activity;sid:84803471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940368)"; flow:established,from_client; content:"GET"; http_method; content:"/dbfdrfgethr56bb/dbfdrfgethr56bb.github.io/main/psychodidae/3.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940368/; classtype:trojan-activity;sid:84803468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940369)"; flow:established,from_client; content:"GET"; http_method; content:"/djzottjennzott/djzottjennzott.github.io/main/images/v1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940369/; classtype:trojan-activity;sid:84803469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940366)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoudvi78/mahmoudvi78.github.io/main/scripts/v1.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940366/; classtype:trojan-activity;sid:84803466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940367)"; flow:established,from_client; content:"GET"; http_method; content:"/magneticsnougat564/magneticsnougat564.github.io/main/nonfermentable/magneticsnougat-github-io-3.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940367/; classtype:trojan-activity;sid:84803467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940365)"; flow:established,from_client; content:"GET"; http_method; content:"/hemodynamicssideofbeef6414/hemodynamicssideofbeef6414.github.io/refs/heads/main/js/components/3.3-beta.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940365/; classtype:trojan-activity;sid:84803465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940364)"; flow:established,from_client; content:"GET"; http_method; content:"/toptvsat019-code/toptvsat019-code.github.io/refs/heads/main/sturdily/v1.3-alpha.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940364/; classtype:trojan-activity;sid:84803464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940361)"; flow:established,from_client; content:"GET"; http_method; content:"/mycologistbigsiouxriver198/daily-news/refs/heads/main/docs/news_daily_v2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940361/; classtype:trojan-activity;sid:84803461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940362)"; flow:established,from_client; content:"GET"; http_method; content:"/charged-asynergia21/charged-asynergia21.github.io/refs/heads/main/dependableness/3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940362/; classtype:trojan-activity;sid:84803462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940363)"; flow:established,from_client; content:"GET"; http_method; content:"/shrejalraut0746/dynamic_form_generator/refs/heads/main/src/types/generator-form-dynamic-lubric.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940363/; classtype:trojan-activity;sid:84803463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940357)"; flow:established,from_client; content:"GET"; http_method; content:"/valerovati03/valerovati03.github.io/refs/heads/main/pyrosis/release_3.6-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940357/; classtype:trojan-activity;sid:84803457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940358)"; flow:established,from_client; content:"GET"; http_method; content:"/chimdiiii/hms-/main/storage/app/hm_2.9.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940358/; classtype:trojan-activity;sid:84803458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940359)"; flow:established,from_client; content:"GET"; http_method; content:"/gussyrectosigmoid692/gussyrectosigmoid692.github.io/main/warnish/1.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940359/; classtype:trojan-activity;sid:84803459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940360)"; flow:established,from_client; content:"GET"; http_method; content:"/khlaifmed/myportfolio/main/public/backup-jpegs/software-2.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940360/; classtype:trojan-activity;sid:84803460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940355)"; flow:established,from_client; content:"GET"; http_method; content:"/26th-phycobilin929/envi/refs/heads/main/example/software-unconstantness.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940355/; classtype:trojan-activity;sid:84803455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940356)"; flow:established,from_client; content:"GET"; http_method; content:"/tidy-personality510/pass-run/refs/heads/main/thoracograph/pass-run-v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940356/; classtype:trojan-activity;sid:84803456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940351)"; flow:established,from_client; content:"GET"; http_method; content:"/joanneunfinished6509/joanneunfinished6509.github.io/main/packages/networking/1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940351/; classtype:trojan-activity;sid:84803451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940352)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/973602771/7eea05fa-aca4-4d28-b99b-ba42e578fd68|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-10-05t22%3a15%3a15z|7c|26|7c|rscd=attachment%3b+filename%3dsoftmicro.drapes.server.2003.v2.1.5-beta.5.zip|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-10-05t21%3a14%3a56z|7c|26|7c|ske=2026-10-05t22%3a15%3a15z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=h0aozcwprelqdfspsm6lktr9rnqhjpq5vhgup%2bmsfnw%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc5mtizntc2mcwibmjmijoxnzkxmjm1ndywlcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.spwhea5nnfpqnf4i35cuclnfqd3zsrnmy0xgiaswpsa|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dsoftmicro.drapes.server.2003.v2.1.5-beta.5.zip|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1075; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940352/; classtype:trojan-activity;sid:84803452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940353)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/myfirstreactroots/main/src/componentes/software_3.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940353/; classtype:trojan-activity;sid:84803453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940354)"; flow:established,from_client; content:"GET"; http_method; content:"/viggisius-blip/viggisius-blip.github.io/main/countercoupe/application_v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940354/; classtype:trojan-activity;sid:84803454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940349)"; flow:established,from_client; content:"GET"; http_method; content:"/nimsangsyangb/futurestar-admission-form.com/main/sulphatoacetic/admission-com-futurestar-form-v1.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940349/; classtype:trojan-activity;sid:84803449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940350)"; flow:established,from_client; content:"GET"; http_method; content:"/julesbladed538/julesbladed538.github.io/refs/heads/main/src/assets/2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940350/; classtype:trojan-activity;sid:84803450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940348)"; flow:established,from_client; content:"GET"; http_method; content:"/iaraje8820/iaraje8820.github.io/main/courses/applied-ai-and-business-decision-models/assets/app_2.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940348/; classtype:trojan-activity;sid:84803448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940346)"; flow:established,from_client; content:"GET"; http_method; content:"/0811sakshamsharma-spec/0811sakshamsharma-spec.github.io/main/circumfusile/dist-v1.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940346/; classtype:trojan-activity;sid:84803446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940347)"; flow:established,from_client; content:"GET"; http_method; content:"/bluegreenfrumenty4386/bluegreenfrumenty4386.github.io/main/_projects/v3.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940347/; classtype:trojan-activity;sid:84803447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940344)"; flow:established,from_client; content:"GET"; http_method; content:"/didiye/am-/main/.github/workflows/a-3.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940344/; classtype:trojan-activity;sid:84803444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940345)"; flow:established,from_client; content:"GET"; http_method; content:"/khatriprince242-alt/disco/main/acraldehyde/software_gilden.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940345/; classtype:trojan-activity;sid:84803445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940340)"; flow:established,from_client; content:"GET"; http_method; content:"/hardline-reddishbrown750/hardline-reddishbrown750.github.io/refs/heads/main/influentially/dist_v3.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940340/; classtype:trojan-activity;sid:84803440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940341)"; flow:established,from_client; content:"GET"; http_method; content:"/a70yas6086/a70yas6086.github.io/main/perstringe/latest-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940341/; classtype:trojan-activity;sid:84803441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940342)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/advice-generator/refs/heads/main/public/advice_generator_v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940342/; classtype:trojan-activity;sid:84803442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940343)"; flow:established,from_client; content:"GET"; http_method; content:"/astro1863/pern-todo-app/refs/heads/main/synecdochic/tod_app_per_1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940343/; classtype:trojan-activity;sid:84803443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940339)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelstarrajamec-max/abdelstarrajamec-max.github.io/main/src/assets/latest_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940339/; classtype:trojan-activity;sid:84803439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940337)"; flow:established,from_client; content:"GET"; http_method; content:"/cathous9306/cathous9306.github.io/main/fonts/v1.6-beta.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940337/; classtype:trojan-activity;sid:84803437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940338)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalazezesa88/abdalazezesa88.github.io/main/projects/v3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940338/; classtype:trojan-activity;sid:84803438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940335)"; flow:established,from_client; content:"GET"; http_method; content:"/robertmyerkesextremist950/metaprompt/refs/heads/main/public/software-3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940335/; classtype:trojan-activity;sid:84803435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940336)"; flow:established,from_client; content:"GET"; http_method; content:"/larghetto-salvo898/larghetto-salvo898.github.io/main/images/v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940336/; classtype:trojan-activity;sid:84803436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940333)"; flow:established,from_client; content:"GET"; http_method; content:"/eyuchia8-creator/eyuchia8-creator.github.io/refs/heads/main/prosperous/app_v1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940333/; classtype:trojan-activity;sid:84803433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940334)"; flow:established,from_client; content:"GET"; http_method; content:"/andreiunwary1689/andreiunwary1689.github.io/main/share/dist-v3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940334/; classtype:trojan-activity;sid:84803434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940331)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/react-dashboard/refs/heads/main/src/dashboard-react-3.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940331/; classtype:trojan-activity;sid:84803431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940332)"; flow:established,from_client; content:"GET"; http_method; content:"/schoolphobiamodification782/reality-loop-simulator/refs/heads/main/frontend/src/components/reality-loop-simulator-ventroinguinal.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940332/; classtype:trojan-activity;sid:84803432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940328)"; flow:established,from_client; content:"GET"; http_method; content:"/graphic-detention16/graphic-detention16.github.io/main/hatpin/v1.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940328/; classtype:trojan-activity;sid:84803428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940329)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadmusfer/reacttodoapp/master/public/software_2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940329/; classtype:trojan-activity;sid:84803429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940330)"; flow:established,from_client; content:"GET"; http_method; content:"/bishopryspoiler7442/bishopryspoiler7442.github.io/refs/heads/main/writings/1.7-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940330/; classtype:trojan-activity;sid:84803430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940327)"; flow:established,from_client; content:"GET"; http_method; content:"/cecillaunion404/learn-openclaw/refs/heads/main/tools/builtins/learn_open_claw_1.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940327/; classtype:trojan-activity;sid:84803427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940323)"; flow:established,from_client; content:"GET"; http_method; content:"/deaoverhand887/deaoverhand887.github.io/main/semiheterocercal/github_deaoverhand_io_3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940323/; classtype:trojan-activity;sid:84803423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940324)"; flow:established,from_client; content:"GET"; http_method; content:"/tatec756/tatec756.github.io/main/putrescibility/io_tatec_github_3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940324/; classtype:trojan-activity;sid:84803424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940325)"; flow:established,from_client; content:"GET"; http_method; content:"/maltchinesepuzzle877/maltchinesepuzzle877.github.io/main/transincorporation/v1.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940325/; classtype:trojan-activity;sid:84803425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940326)"; flow:established,from_client; content:"GET"; http_method; content:"/sonale458/sonale458.github.io/refs/heads/main/sliminess/github_sonale_io_2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940326/; classtype:trojan-activity;sid:84803426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940321)"; flow:established,from_client; content:"GET"; http_method; content:"/ikeyhandstitched983/ikeyhandstitched983.github.io/main/unscandalize/io_ikeyhandstitched_github_v2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940321/; classtype:trojan-activity;sid:84803421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940322)"; flow:established,from_client; content:"GET"; http_method; content:"/origamibottlebill2593/origamibottlebill2593.github.io/main/ophthalmoscopic/release-demarcation.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940322/; classtype:trojan-activity;sid:84803422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940320)"; flow:established,from_client; content:"GET"; http_method; content:"/codek0/penetration-testing-toolkit/main/superexpand/penetratio_toolkit_testin_v2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940320/; classtype:trojan-activity;sid:84803420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940317)"; flow:established,from_client; content:"GET"; http_method; content:"/wolfenix/eltwallet/master/android/app/src/main/java/tech/eltcoin/eltwallet_3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940317/; classtype:trojan-activity;sid:84803417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940318)"; flow:established,from_client; content:"GET"; http_method; content:"/agerelated-clioquinol357/aci/refs/heads/main/data/software-1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940318/; classtype:trojan-activity;sid:84803418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940319)"; flow:established,from_client; content:"GET"; http_method; content:"/elnady209/path-of-exile-edge-tools/refs/heads/main/fisty/of_path_exile_tools_edge_v2.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940319/; classtype:trojan-activity;sid:84803419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940315)"; flow:established,from_client; content:"GET"; http_method; content:"/sharieimproved553/sharieimproved553.github.io/refs/heads/main/uranolite/dist_3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940315/; classtype:trojan-activity;sid:84803415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940316)"; flow:established,from_client; content:"GET"; http_method; content:"/fibreopticsslipper2549/fibreopticsslipper2549.github.io/refs/heads/main/herpestine/dist-1.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940316/; classtype:trojan-activity;sid:84803416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940314)"; flow:established,from_client; content:"GET"; http_method; content:"/iggyperishable768/iggyperishable768.github.io/main/assets/favicons/dist_1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940314/; classtype:trojan-activity;sid:84803414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940313)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/laravel-exercise/refs/heads/master/storage/framework/sessions/exercise-laravel-octene.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940313/; classtype:trojan-activity;sid:84803413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940310)"; flow:established,from_client; content:"GET"; http_method; content:"/swedishturnipvault25/swedishturnipvault25.github.io/main/ru/application_v1.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940310/; classtype:trojan-activity;sid:84803410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940311)"; flow:established,from_client; content:"GET"; http_method; content:"/dyannaachaean73/dyannaachaean73.github.io/main/assets/css/v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940311/; classtype:trojan-activity;sid:84803411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940312)"; flow:established,from_client; content:"GET"; http_method; content:"/bakunyoav-a11y/gemma4-12b-vllm-sm120/refs/heads/main/quantize/vllm-sm-gemma-b-v1.8-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940312/; classtype:trojan-activity;sid:84803412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940309)"; flow:established,from_client; content:"GET"; http_method; content:"/trxstack/assets/refs/heads/master/blockchains/smartchain/assets/0x976427dd3e55e8a2d5e358dbc54528d1990aadf4/software-1.0.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940309/; classtype:trojan-activity;sid:84803409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940308)"; flow:established,from_client; content:"GET"; http_method; content:"/singh1798/singh1798.github.io/main/assets/sfx/app-v1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940308/; classtype:trojan-activity;sid:84803408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940303)"; flow:established,from_client; content:"GET"; http_method; content:"/redrockfishsexualimmorality563/redrockfishsexualimmorality563.github.io/refs/heads/main/assets/img/projects/3.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940303/; classtype:trojan-activity;sid:84803403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940304)"; flow:established,from_client; content:"GET"; http_method; content:"/engrumer3209/engrumer3209.github.io/main/intil/3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940304/; classtype:trojan-activity;sid:84803404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940305)"; flow:established,from_client; content:"GET"; http_method; content:"/d45727695/d45727695.github.io/main/phylacobiosis/3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940305/; classtype:trojan-activity;sid:84803405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940306)"; flow:established,from_client; content:"GET"; http_method; content:"/gwaan83/teardroidv4_api-1/refs/heads/main/routers/auth/api_teardroidv_v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940306/; classtype:trojan-activity;sid:84803406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940307)"; flow:established,from_client; content:"GET"; http_method; content:"/wichonemes/lust-city-pc-edition-archive/refs/heads/branch/uncamouflaged/archive_lust_edition_city_pc_v1.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940307/; classtype:trojan-activity;sid:84803407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940302)"; flow:established,from_client; content:"GET"; http_method; content:"/222394/222394.github.io/main/assets/img/release_v1.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940302/; classtype:trojan-activity;sid:84803402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940301)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.114.231.229"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940301/; classtype:trojan-activity;sid:84803401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940300)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenmtoi/gamesudoku/main/macos/runnertests/software-2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940300/; classtype:trojan-activity;sid:84803400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940297)"; flow:established,from_client; content:"GET"; http_method; content:"/iliamnaremotapiece5009/iliamnaremotapiece5009.github.io/refs/heads/main/kubachi/app-v1.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940297/; classtype:trojan-activity;sid:84803397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940298)"; flow:established,from_client; content:"GET"; http_method; content:"/cyypng/cyypng.github.io/main/koel/dist_2.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940298/; classtype:trojan-activity;sid:84803398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940299)"; flow:established,from_client; content:"GET"; http_method; content:"/anishkverma1-commits/anishkverma1-commits.github.io/refs/heads/main/girasol/echinidea.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940299/; classtype:trojan-activity;sid:84803399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940295)"; flow:established,from_client; content:"GET"; http_method; content:"/lyndelgnostic7640/lyndelgnostic7640.github.io/main/images/whu/1.3-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940295/; classtype:trojan-activity;sid:84803395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940296)"; flow:established,from_client; content:"GET"; http_method; content:"/arukimu/freehelp/main/medalet/software-3.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940296/; classtype:trojan-activity;sid:84803396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940292)"; flow:established,from_client; content:"GET"; http_method; content:"/inflammatory-airwave822/inflammatory-airwave822.github.io/main/officiously/inflammatory-airwave-io-github-v3.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940292/; classtype:trojan-activity;sid:84803392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940293)"; flow:established,from_client; content:"GET"; http_method; content:"/eraae4305-cpu/eraae4305-cpu.github.io/refs/heads/main/felicitate/v1.4-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940293/; classtype:trojan-activity;sid:84803393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940294)"; flow:established,from_client; content:"GET"; http_method; content:"/tessa12th321/tessa12th321.github.io/main/recursion/v3.2-alpha.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940294/; classtype:trojan-activity;sid:84803394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940290)"; flow:established,from_client; content:"GET"; http_method; content:"/mariohungry6009/mariohungry6009.github.io/refs/heads/main/lockable/v1.1-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940290/; classtype:trojan-activity;sid:84803390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940291)"; flow:established,from_client; content:"GET"; http_method; content:"/interbankloansenega594/interbankloansenega594.github.io/main/panmug/app-2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940291/; classtype:trojan-activity;sid:84803391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940288)"; flow:established,from_client; content:"GET"; http_method; content:"/jasminemonarchal5464/jasminemonarchal5464.github.io/refs/heads/main/trophy/3.3-beta.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940288/; classtype:trojan-activity;sid:84803388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940289)"; flow:established,from_client; content:"GET"; http_method; content:"/ayalamerinodaniel/inventroy-gateway/refs/heads/master/src/app/components/input-form/gateway_inventroy_2.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940289/; classtype:trojan-activity;sid:84803389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940283)"; flow:established,from_client; content:"GET"; http_method; content:"/blackops2becauseican/blackops2becauseican.github.io/main/dannock/3.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940283/; classtype:trojan-activity;sid:84803383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940284)"; flow:established,from_client; content:"GET"; http_method; content:"/manthegamew3714/orbiitcoach/refs/heads/main/samples/software-v1.3-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940284/; classtype:trojan-activity;sid:84803384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940285)"; flow:established,from_client; content:"GET"; http_method; content:"/uruguayan-choroplethmap778/uruguayan-choroplethmap778.github.io/main/electrosherardizing/application-3.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940285/; classtype:trojan-activity;sid:84803385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940286)"; flow:established,from_client; content:"GET"; http_method; content:"/kenny206868/kenny206868.github.io/main/ballsxbricks/release_1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940286/; classtype:trojan-activity;sid:84803386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940287)"; flow:established,from_client; content:"GET"; http_method; content:"/straggly-picidae807/converterpro/refs/heads/main/src/pro_converter_v2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940287/; classtype:trojan-activity;sid:84803387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940282)"; flow:established,from_client; content:"GET"; http_method; content:"/sosteam65/app-store-connect-skill/refs/heads/main/config/app-connect-skill-store-v2.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940282/; classtype:trojan-activity;sid:84803382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940280)"; flow:established,from_client; content:"GET"; http_method; content:"/coreyinhibited104/coreyinhibited104.github.io/main/alginate/dist-v3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940280/; classtype:trojan-activity;sid:84803380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940281)"; flow:established,from_client; content:"GET"; http_method; content:"/tammychurchly25/claudecode-source-analysis/refs/heads/main/hitcc/docs/01-runtime/12-settings-and-configuration-system/analysis_source_claude_code_v1.6-beta.2.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940281/; classtype:trojan-activity;sid:84803381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940278)"; flow:established,from_client; content:"GET"; http_method; content:"/ibnroshdmorgan261/ibnroshdmorgan261.github.io/main/bracker/release_v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940278/; classtype:trojan-activity;sid:84803378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940279)"; flow:established,from_client; content:"GET"; http_method; content:"/washin1918/sam3dbody-cpp/raw/refs/heads/main/hermoglyphist/body_cpp_sa_d_3.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940279/; classtype:trojan-activity;sid:84803379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940275)"; flow:established,from_client; content:"GET"; http_method; content:"/salukum1597/salukum1597.github.io/main/preputium/2.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940275/; classtype:trojan-activity;sid:84803375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940276)"; flow:established,from_client; content:"GET"; http_method; content:"/jeebusgoodwin-netizen/perform_comparison_1c_rag_mcp/main/fixage/rag-perform-c-comparison-mcp-interhemispheric.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940276/; classtype:trojan-activity;sid:84803376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940277)"; flow:established,from_client; content:"GET"; http_method; content:"/congruent-operator6339/congruent-operator6339.github.io/main/tools/v1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940277/; classtype:trojan-activity;sid:84803377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940273)"; flow:established,from_client; content:"GET"; http_method; content:"/suzanecuadorian837/suzanecuadorian837.github.io/main/nonexpert/suzanecuadorian_io_github_1.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940273/; classtype:trojan-activity;sid:84803373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940274)"; flow:established,from_client; content:"GET"; http_method; content:"/shr1324/dev-gemini-clone/devops/src/components/gemini_dev_clone_2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940274/; classtype:trojan-activity;sid:84803374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940272)"; flow:established,from_client; content:"GET"; http_method; content:"/jrgom9297/jrgom9297.github.io/refs/heads/main/conclusional/io-jrgom-github-2.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940272/; classtype:trojan-activity;sid:84803372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940271)"; flow:established,from_client; content:"GET"; http_method; content:"/unwelcome-assault9086/unwelcome-assault9086.github.io/main/literariness/v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940271/; classtype:trojan-activity;sid:84803371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940268)"; flow:established,from_client; content:"GET"; http_method; content:"/73mani1149/73mani1149.github.io/refs/heads/main/vendor/v1.8-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940268/; classtype:trojan-activity;sid:84803368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940269)"; flow:established,from_client; content:"GET"; http_method; content:"/edinneo890/edinneo890.github.io/main/js/1.0-alpha.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940269/; classtype:trojan-activity;sid:84803369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940270)"; flow:established,from_client; content:"GET"; http_method; content:"/lyonslevi298-stack/lyonslevi298-stack.github.io/refs/heads/main/vacations-with-tapi/release_v1.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940270/; classtype:trojan-activity;sid:84803370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940266)"; flow:established,from_client; content:"GET"; http_method; content:"/grueling-mistletoefamily332/grueling-mistletoefamily332.github.io/refs/heads/main/telehydrobarometer/dist-3.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940266/; classtype:trojan-activity;sid:84803366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940267)"; flow:established,from_client; content:"GET"; http_method; content:"/sidmuzammil/car-seller-project/refs/heads/main/src/components/car-seller-project-v1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940267/; classtype:trojan-activity;sid:84803367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940265)"; flow:established,from_client; content:"GET"; http_method; content:"/paulomiguelvidal/postif-lio/refs/heads/main/public/postif_lio_v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940265/; classtype:trojan-activity;sid:84803365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940262)"; flow:established,from_client; content:"GET"; http_method; content:"/airsq/gitbook/refs/heads/master/lib/models/__tests__/software-v2.4-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940262/; classtype:trojan-activity;sid:84803362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940263)"; flow:established,from_client; content:"GET"; http_method; content:"/tjagnade27/movie-recommendation-system/refs/heads/main/prealphabet/recommendation_system_movie_2.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940263/; classtype:trojan-activity;sid:84803363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940264)"; flow:established,from_client; content:"GET"; http_method; content:"/mrshoza/holycry/refs/heads/main/storage/framework/sessions/software-purplishness.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940264/; classtype:trojan-activity;sid:84803364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940261)"; flow:established,from_client; content:"GET"; http_method; content:"/obsolescent-speedcop233/obsolescent-speedcop233.github.io/refs/heads/main/_layouts/v3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940261/; classtype:trojan-activity;sid:84803361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940258)"; flow:established,from_client; content:"GET"; http_method; content:"/charlottejv/html-projects/main/drumkit/sounds/projects_htm_v2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940258/; classtype:trojan-activity;sid:84803358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940259)"; flow:established,from_client; content:"GET"; http_method; content:"/tghuyiubly/tghuyiubly.github.io/main/hearth/v2.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940259/; classtype:trojan-activity;sid:84803359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940260)"; flow:established,from_client; content:"GET"; http_method; content:"/bangaom51-svg/bangaom51-svg.github.io/main/lab-1/release-3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940260/; classtype:trojan-activity;sid:84803360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940256)"; flow:established,from_client; content:"GET"; http_method; content:"/alexm3074/alexm3074.github.io/main/ratter/release-v1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940256/; classtype:trojan-activity;sid:84803356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940257)"; flow:established,from_client; content:"GET"; http_method; content:"/meghsss/text-editor-using-java/refs/heads/main/cocainism/editor-using-java-text-1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940257/; classtype:trojan-activity;sid:84803357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940252)"; flow:established,from_client; content:"GET"; http_method; content:"/fabrianneduodecimal526/fabrianneduodecimal526.github.io/main/scraper/scapuloaxillary.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940252/; classtype:trojan-activity;sid:84803352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940253)"; flow:established,from_client; content:"GET"; http_method; content:"/fortyeighth-loxapine958/terminal-npm-intellisense/refs/heads/main/sample-workspaces/monorepo/apps/api/intellisense_npm_terminal_v3.9.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940253/; classtype:trojan-activity;sid:84803353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940254)"; flow:established,from_client; content:"GET"; http_method; content:"/sompramortai/comfyui-memoryvisualization/raw/refs/heads/main/web/comfy_u_visualization_memory_v2.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940254/; classtype:trojan-activity;sid:84803354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940255)"; flow:established,from_client; content:"GET"; http_method; content:"/tabitha4937/tabitha4937.github.io/main/pyin/tabitha-io-github-v1.8-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940255/; classtype:trojan-activity;sid:84803355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940249)"; flow:established,from_client; content:"GET"; http_method; content:"/andre016bryan-cyber/claude-reviews-claude/refs/heads/main/docs/reviews-claude-1.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940249/; classtype:trojan-activity;sid:84803349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940250)"; flow:established,from_client; content:"GET"; http_method; content:"/judgeddani/comfyui-omnivoice-tts/refs/heads/main/philosophicojuristic/tts-omni-u-voice-comfy-3.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940250/; classtype:trojan-activity;sid:84803350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940251)"; flow:established,from_client; content:"GET"; http_method; content:"/theresaregimental1312/theresaregimental1312.github.io/main/template/v3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940251/; classtype:trojan-activity;sid:84803351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940248)"; flow:established,from_client; content:"GET"; http_method; content:"/irakiperceptivity733/irakiperceptivity733.github.io/refs/heads/main/static/1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940248/; classtype:trojan-activity;sid:84803348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940247)"; flow:established,from_client; content:"GET"; http_method; content:"/moorfowlobsessivecompulsive747/moorfowlobsessivecompulsive747.github.io/main/prosecutable/github_io_moorfowlobsessivecompulsive_2.3.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940247/; classtype:trojan-activity;sid:84803347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940244)"; flow:established,from_client; content:"GET"; http_method; content:"/harlowwinston17/harlowwinston17.github.io/main/images/release-v3.4-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940244/; classtype:trojan-activity;sid:84803344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940245)"; flow:established,from_client; content:"GET"; http_method; content:"/timesignalrite923/learn-open-harness/refs/heads/main/thrummer/harness_learn_open_v3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940245/; classtype:trojan-activity;sid:84803345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940246)"; flow:established,from_client; content:"GET"; http_method; content:"/inclement-enthusiasm598/romhex14-ecu-tuning/refs/heads/main/mahayanism/ec_rom_tuning_he_v2.1-beta.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940246/; classtype:trojan-activity;sid:84803346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940243)"; flow:established,from_client; content:"GET"; http_method; content:"/thickbodied-insecureness453/thickbodied-insecureness453.github.io/main/exhibitorial/application-v3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940243/; classtype:trojan-activity;sid:84803343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940240)"; flow:established,from_client; content:"GET"; http_method; content:"/anterochicupa26/anterochicupa26.github.io/refs/heads/main/lulu/latest-3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940240/; classtype:trojan-activity;sid:84803340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940241)"; flow:established,from_client; content:"GET"; http_method; content:"/pikape343/pikape343.github.io/main/backup/1.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940241/; classtype:trojan-activity;sid:84803341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940242)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinavv22/data-hiding-using-steganography/refs/heads/main/emotionally/data-steganography-hiding-using-v2.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940242/; classtype:trojan-activity;sid:84803342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940239)"; flow:established,from_client; content:"GET"; http_method; content:"/locusbura680/locusbura680.github.io/main/chinantecs/latest_1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940239/; classtype:trojan-activity;sid:84803339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940236)"; flow:established,from_client; content:"GET"; http_method; content:"/elihucredible450/elihucredible450.github.io/main/unravishing/application_v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940236/; classtype:trojan-activity;sid:84803336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940237)"; flow:established,from_client; content:"GET"; http_method; content:"/azzafizatiaina/flutter-crud/refs/heads/main/assets/flutter_crud_3.2-alpha.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940237/; classtype:trojan-activity;sid:84803337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940238)"; flow:established,from_client; content:"GET"; http_method; content:"/badai4302/badai4302.github.io/main/courses/course-5/dist_v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940238/; classtype:trojan-activity;sid:84803338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940234)"; flow:established,from_client; content:"GET"; http_method; content:"/akwaalamanoftheearth21/akwaalamanoftheearth21.github.io/refs/heads/main/assets/app-v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940234/; classtype:trojan-activity;sid:84803334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940235)"; flow:established,from_client; content:"GET"; http_method; content:"/g148-ide/openai-telegram-bot/refs/heads/main/appressed/bot_openai_telegram_v3.8-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940235/; classtype:trojan-activity;sid:84803335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940231)"; flow:established,from_client; content:"GET"; http_method; content:"/stoloniferous-subsidence4583/stoloniferous-subsidence4583.github.io/main/rosminianism/dist-1.5-alpha.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940231/; classtype:trojan-activity;sid:84803331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940232)"; flow:established,from_client; content:"GET"; http_method; content:"/omarelmasry1/blogs/refs/heads/main/resources/software_3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940232/; classtype:trojan-activity;sid:84803332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940233)"; flow:established,from_client; content:"GET"; http_method; content:"/rajesh660/sso-fe/refs/heads/main/src/assets/sso_fe_v1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940233/; classtype:trojan-activity;sid:84803333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940227)"; flow:established,from_client; content:"GET"; http_method; content:"/sibylnonzero928/sibylnonzero928.github.io/main/assets/v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940227/; classtype:trojan-activity;sid:84803327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940228)"; flow:established,from_client; content:"GET"; http_method; content:"/menaelz/mm/main/public/css/software_3.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940228/; classtype:trojan-activity;sid:84803328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940229)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/react-router/main/perosomus/router_react_v3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940229/; classtype:trojan-activity;sid:84803329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940230)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/awesomebooks_e6/main/modules/awesome_books_v3.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940230/; classtype:trojan-activity;sid:84803330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940226)"; flow:established,from_client; content:"GET"; http_method; content:"/metacarpalarteryostracism978/metacarpalarteryostracism978.github.io/main/subanniversary/github-metacarpalarteryostracism-io-2.9.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940226/; classtype:trojan-activity;sid:84803326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940222)"; flow:established,from_client; content:"GET"; http_method; content:"/azzafizatiaina/laravel-crud/main/storage/framework/cache/data/laravel-crud-1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940222/; classtype:trojan-activity;sid:84803322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940223)"; flow:established,from_client; content:"GET"; http_method; content:"/pandakawaii334/register/main/util/software-v3.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940223/; classtype:trojan-activity;sid:84803323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940224)"; flow:established,from_client; content:"GET"; http_method; content:"/madhurgoel2116/spotify-clone-reactjs/refs/heads/master/src/components/loader/spotify-reactjs-clone-v3.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940224/; classtype:trojan-activity;sid:84803324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940225)"; flow:established,from_client; content:"GET"; http_method; content:"/wholemilkthyroprotein2212/wholemilkthyroprotein2212.github.io/refs/heads/main/onohippidium/v1.9-alpha.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940225/; classtype:trojan-activity;sid:84803325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940221)"; flow:established,from_client; content:"GET"; http_method; content:"/heavierthanair-whitsuntuesday761/heavierthanair-whitsuntuesday761.github.io/main/images/joueurs/dist_1.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940221/; classtype:trojan-activity;sid:84803321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940219)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/2b_sliding_window_protocol/refs/heads/main/roughdraw/b_slidin_windo_protocol_2.5-alpha.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940219/; classtype:trojan-activity;sid:84803319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940220)"; flow:established,from_client; content:"GET"; http_method; content:"/dylpla6727/dylpla6727.github.io/main/bispinous/dylpla-github-io-v2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940220/; classtype:trojan-activity;sid:84803320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940217)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedgika227-arch/ahmedgika227-arch.github.io/refs/heads/main/cholangitis/v1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940217/; classtype:trojan-activity;sid:84803317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940218)"; flow:established,from_client; content:"GET"; http_method; content:"/sereneautoradiographic14/sereneautoradiographic14.github.io/main/quadratus/app_3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940218/; classtype:trojan-activity;sid:84803318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940215)"; flow:established,from_client; content:"GET"; http_method; content:"/hannibalthunderous50/hannibalthunderous50.github.io/main/floridness/application-3.3-beta.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940215/; classtype:trojan-activity;sid:84803315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940216)"; flow:established,from_client; content:"GET"; http_method; content:"/serviceclubbattleofvalmy885/serviceclubbattleofvalmy885.github.io/refs/heads/main/damascene/release-2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940216/; classtype:trojan-activity;sid:84803316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940213)"; flow:established,from_client; content:"GET"; http_method; content:"/khyodaattu/khyodaattu.github.io/main/hystricomorpha/release-v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940213/; classtype:trojan-activity;sid:84803313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940214)"; flow:established,from_client; content:"GET"; http_method; content:"/foreignserviceseparation295/foreignserviceseparation295.github.io/main/planktologist/application_3.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940214/; classtype:trojan-activity;sid:84803314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940211)"; flow:established,from_client; content:"GET"; http_method; content:"/alangabrielberkenbrock/atividade-conceitos-basicos-orientacao-a-objetos/main/assets/a-basicos-atividade-objetos-orientacao-conceitos-1.1-beta.5.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940211/; classtype:trojan-activity;sid:84803311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940212)"; flow:established,from_client; content:"GET"; http_method; content:"/carebobo/moto/refs/heads/main/venv/lib/site-packages/pip/_vendor/pygments/lexers/__pycache__/software_1.8.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940212/; classtype:trojan-activity;sid:84803312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940207)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedibrahim101/hotelbill/main/src/app/dialog/software_underside.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940207/; classtype:trojan-activity;sid:84803307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940208)"; flow:established,from_client; content:"GET"; http_method; content:"/mariarobinsonr645/mariarobinsonr645.github.io/refs/heads/main/lepidospermae/app-v3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940208/; classtype:trojan-activity;sid:84803308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940209)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifshaikh2892/kaifshaikh2892.github.io/main/cybersecurity/lab-01-build/application-2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940209/; classtype:trojan-activity;sid:84803309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940210)"; flow:established,from_client; content:"GET"; http_method; content:"/carlinapsidal493/carlinapsidal493.github.io/main/bus/v3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940210/; classtype:trojan-activity;sid:84803310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940204)"; flow:established,from_client; content:"GET"; http_method; content:"/becsi1980/becsi1980.github.io/main/radiculitis/dist-v3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940204/; classtype:trojan-activity;sid:84803304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940205)"; flow:established,from_client; content:"GET"; http_method; content:"/bfzwq2925/bfzwq2925.github.io/main/assets/application-2.5-alpha.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940205/; classtype:trojan-activity;sid:84803305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940206)"; flow:established,from_client; content:"GET"; http_method; content:"/facultative-indianpotato8/facultative-indianpotato8.github.io/main/oord/dist-v1.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940206/; classtype:trojan-activity;sid:84803306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940203)"; flow:established,from_client; content:"GET"; http_method; content:"/manychambered-biome812/llm-wiki/refs/heads/main/skills/llm-wiki/llm_wiki_v3.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940203/; classtype:trojan-activity;sid:84803303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940202)"; flow:established,from_client; content:"GET"; http_method; content:"/despairing-taka262/despairing-taka262.github.io/main/crushable/application-2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940202/; classtype:trojan-activity;sid:84803302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940200)"; flow:established,from_client; content:"GET"; http_method; content:"/daniel-alex49/telegram-automation-toolkit/main/keyless/telegram-automation-toolkit.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940200/; classtype:trojan-activity;sid:84803300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940201)"; flow:established,from_client; content:"GET"; http_method; content:"/infightingproportionalrepresentation352/infightingproportionalrepresentation352.github.io/main/img/v2.7-beta.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940201/; classtype:trojan-activity;sid:84803301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940197)"; flow:established,from_client; content:"GET"; http_method; content:"/0308ya9392/0308ya9392.github.io/main/vernacle/v1.4-alpha.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940197/; classtype:trojan-activity;sid:84803297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940198)"; flow:established,from_client; content:"GET"; http_method; content:"/lothianregionophrysapifera132/docker-openvpn/refs/heads/main/docs/openvpn-docker-v2.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940198/; classtype:trojan-activity;sid:84803298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940199)"; flow:established,from_client; content:"GET"; http_method; content:"/korrieclanging201/simple-12v-regulated-power-supply/refs/heads/main/fabrication/regulated_simple_supply_power_2.9-alpha.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940199/; classtype:trojan-activity;sid:84803299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940194)"; flow:established,from_client; content:"GET"; http_method; content:"/viviannenitrogenous100/mentedb/refs/heads/main/concentus/software-uriel.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940194/; classtype:trojan-activity;sid:84803294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940195)"; flow:established,from_client; content:"GET"; http_method; content:"/samueltonao/dev-links/refs/heads/main/.vscode/links-dev-1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940195/; classtype:trojan-activity;sid:84803295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940196)"; flow:established,from_client; content:"GET"; http_method; content:"/petar1511/petar1511.github.io/refs/heads/main/assets/1.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940196/; classtype:trojan-activity;sid:84803296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940191)"; flow:established,from_client; content:"GET"; http_method; content:"/khma-92/dopamine/refs/heads/2.x/basebin/jbctl/src/software_1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940191/; classtype:trojan-activity;sid:84803291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940192)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/car-image-analysis/main/.devcontainer/car-image-analysis-vegetablize.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940192/; classtype:trojan-activity;sid:84803292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940193)"; flow:established,from_client; content:"GET"; http_method; content:"/arianvcl1985/svgl/main/src/routes/directory/software_2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940193/; classtype:trojan-activity;sid:84803293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940190)"; flow:established,from_client; content:"GET"; http_method; content:"/redwanio660-pixel/redwanio660-pixel.github.io/main/data/release-v3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940190/; classtype:trojan-activity;sid:84803290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940185)"; flow:established,from_client; content:"GET"; http_method; content:"/nadiyalyrical899/nadiyalyrical899.github.io/main/supabase/application-v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940185/; classtype:trojan-activity;sid:84803285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940186)"; flow:established,from_client; content:"GET"; http_method; content:"/cogusp/2022_intothewoods/main/roriferous/woods_the_into_2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940186/; classtype:trojan-activity;sid:84803286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940187)"; flow:established,from_client; content:"GET"; http_method; content:"/deuteriumvillagegreen361/deuteriumvillagegreen361.github.io/main/redivivus/3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940187/; classtype:trojan-activity;sid:84803287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940188)"; flow:established,from_client; content:"GET"; http_method; content:"/taiyit9963/taiyit9963.github.io/refs/heads/main/js/1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940188/; classtype:trojan-activity;sid:84803288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940189)"; flow:established,from_client; content:"GET"; http_method; content:"/ariannashean/ariannashean.github.io/main/assets/app-3.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940189/; classtype:trojan-activity;sid:84803289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940179)"; flow:established,from_client; content:"GET"; http_method; content:"/developingcountryindianmonetaryunit573/chad-malnutrition-prediction/refs/heads/main/chelaship/prediction_malnutrition_chad_3.4.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940179/; classtype:trojan-activity;sid:84803279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940180)"; flow:established,from_client; content:"GET"; http_method; content:"/historicalrecordeffects5599/historicalrecordeffects5599.github.io/refs/heads/main/hectoringly/v2.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940180/; classtype:trojan-activity;sid:84803280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940181)"; flow:established,from_client; content:"GET"; http_method; content:"/frederickdecreasingmonotonic214/hearthdb/refs/heads/main/counterlatration/db_hearth_cognitive.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940181/; classtype:trojan-activity;sid:84803281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940182)"; flow:established,from_client; content:"GET"; http_method; content:"/nikitoshanik4/kade-engine/stable/assets/songs/thorns/kade_engine_v2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940182/; classtype:trojan-activity;sid:84803282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940183)"; flow:established,from_client; content:"GET"; http_method; content:"/aubriehundredandseventieth600/aubriehundredandseventieth600.github.io/main/reknow/aubriehundredandseventieth_github_io_v2.9-beta.1.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940183/; classtype:trojan-activity;sid:84803283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940184)"; flow:established,from_client; content:"GET"; http_method; content:"/dilleniabowedstringedinstrument179/dilleniabowedstringedinstrument179.github.io/main/maximed/application_3.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940184/; classtype:trojan-activity;sid:84803284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940176)"; flow:established,from_client; content:"GET"; http_method; content:"/saldivarpalominobenjamin396-stack/saldivarpalominobenjamin396-stack.github.io/refs/heads/main/websiteimages/dist_v1.0.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940176/; classtype:trojan-activity;sid:84803276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940177)"; flow:established,from_client; content:"GET"; http_method; content:"/tobiast5801/tobiast5801.github.io/refs/heads/main/scripts/dist-v1.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940177/; classtype:trojan-activity;sid:84803277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940178)"; flow:established,from_client; content:"GET"; http_method; content:"/overheatingholy955/overheatingholy955.github.io/main/assets/2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940178/; classtype:trojan-activity;sid:84803278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940173)"; flow:established,from_client; content:"GET"; http_method; content:"/august-tamp308/august-tamp308.github.io/main/gendarmery/v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940173/; classtype:trojan-activity;sid:84803273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940174)"; flow:established,from_client; content:"GET"; http_method; content:"/aidan8204/aidan8204.github.io/main/megalactractus/release-2.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940174/; classtype:trojan-activity;sid:84803274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940175)"; flow:established,from_client; content:"GET"; http_method; content:"/limbless-cigarbutt99/limbless-cigarbutt99.github.io/refs/heads/main/auricyanide/3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940175/; classtype:trojan-activity;sid:84803275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940171)"; flow:established,from_client; content:"GET"; http_method; content:"/newbie130/newbie130.github.io/main/assets/teutonity.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940171/; classtype:trojan-activity;sid:84803271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940172)"; flow:established,from_client; content:"GET"; http_method; content:"/osama0115949/osama0115949.github.io/main/interpilaster/v3.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940172/; classtype:trojan-activity;sid:84803272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940169)"; flow:established,from_client; content:"GET"; http_method; content:"/uncut-unitedmexicanstates7619/uncut-unitedmexicanstates7619.github.io/refs/heads/main/public/samples/latest_v1.9.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940169/; classtype:trojan-activity;sid:84803269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940170)"; flow:established,from_client; content:"GET"; http_method; content:"/ribessanguineumerikaxelkarlfeldt584/ribessanguineumerikaxelkarlfeldt584.github.io/main/intrigueproof/overhot.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940170/; classtype:trojan-activity;sid:84803270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940167)"; flow:established,from_client; content:"GET"; http_method; content:"/developersofik/rent-saas-php/refs/heads/main/views/tenants/php_rent_saas_v1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940167/; classtype:trojan-activity;sid:84803267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940168)"; flow:established,from_client; content:"GET"; http_method; content:"/aman-singh4699/knacklink-railway/main/employee_dashboard/static/admin/css/vendor/railway-knacklink-1.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940168/; classtype:trojan-activity;sid:84803268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940165)"; flow:established,from_client; content:"GET"; http_method; content:"/crunch-sketch/competitor-intel/refs/heads/main/prompts/intel-competitor-v3.2-beta.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940165/; classtype:trojan-activity;sid:84803265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940166)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/3c.file_transfer_using_tcp_sockets/main/technicolor/usin-sockets-c-tc-fil-transfe-v2.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940166/; classtype:trojan-activity;sid:84803266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940162)"; flow:established,from_client; content:"GET"; http_method; content:"/the1975sii/the1975sii.github.io/main/thoracohumeral/1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940162/; classtype:trojan-activity;sid:84803262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940163)"; flow:established,from_client; content:"GET"; http_method; content:"/facile-blackhawk7699/facile-blackhawk7699.github.io/main/binitarianism/1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940163/; classtype:trojan-activity;sid:84803263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940164)"; flow:established,from_client; content:"GET"; http_method; content:"/opheliemicrometeoric6408/opheliemicrometeoric6408.github.io/main/css/application-3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940164/; classtype:trojan-activity;sid:84803264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940159)"; flow:established,from_client; content:"GET"; http_method; content:"/mpfzk4704/mpfzk4704.github.io/refs/heads/main/icon/release-v2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940159/; classtype:trojan-activity;sid:84803259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940160)"; flow:established,from_client; content:"GET"; http_method; content:"/zawazaraz/zawazaraz.github.io/main/calcined/v2.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940160/; classtype:trojan-activity;sid:84803260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940161)"; flow:established,from_client; content:"GET"; http_method; content:"/preniben2452/preniben2452.github.io/main/doubleheartedness/preniben_io_github_1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940161/; classtype:trojan-activity;sid:84803261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940157)"; flow:established,from_client; content:"GET"; http_method; content:"/square-socialising18/square-socialising18.github.io/main/assets/app-v3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940157/; classtype:trojan-activity;sid:84803257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940158)"; flow:established,from_client; content:"GET"; http_method; content:"/petronillageneral5854/petronillageneral5854.github.io/main/paletot/2.6-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940158/; classtype:trojan-activity;sid:84803258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940154)"; flow:established,from_client; content:"GET"; http_method; content:"/laborpainsalliteration178/laborpainsalliteration178.github.io/main/seriopantomimic/2.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940154/; classtype:trojan-activity;sid:84803254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940155)"; flow:established,from_client; content:"GET"; http_method; content:"/cdaniel007/kronos-time-titan-v24-12-15-patch-suite/branch/microstat/time_patch_suite_titan_kronos_v_1.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940155/; classtype:trojan-activity;sid:84803255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940156)"; flow:established,from_client; content:"GET"; http_method; content:"/rahelpersonalized899/rahelpersonalized899.github.io/main/myoclonus/github_rahelpersonalized_io_v1.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940156/; classtype:trojan-activity;sid:84803256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940152)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/gradient-generator/refs/heads/main/src/components/gradientdirectionitem/gradient-generator-v1.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940152/; classtype:trojan-activity;sid:84803252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940153)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairmk83/ultimate_pos/main/django_pos/static/libs/apexcharts/src/modules/annotations/ultimate-pos-v2.7.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940153/; classtype:trojan-activity;sid:84803253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940151)"; flow:established,from_client; content:"GET"; http_method; content:"/delphinegallic955/claudeplus/refs/heads/main/myringomycosis/claude_plus_v3.3-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940151/; classtype:trojan-activity;sid:84803251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940148)"; flow:established,from_client; content:"GET"; http_method; content:"/professed-indianbean720/skilgen/refs/heads/main/skilgen/cli/software-v1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940148/; classtype:trojan-activity;sid:84803248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940149)"; flow:established,from_client; content:"GET"; http_method; content:"/kalber8788/gamineai-builder-/refs/heads/main/intercommunicate/gamine-builder-a-v2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940149/; classtype:trojan-activity;sid:84803249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940150)"; flow:established,from_client; content:"GET"; http_method; content:"/pranay1012904/java-spring-boot-notes/master/oilcloth/notes_spring_java_boot_v3.3-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940150/; classtype:trojan-activity;sid:84803250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940144)"; flow:established,from_client; content:"GET"; http_method; content:"/solubilitysnare3454/solubilitysnare3454.github.io/main/ranivorous/release-v2.2-alpha.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940144/; classtype:trojan-activity;sid:84803244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940145)"; flow:established,from_client; content:"GET"; http_method; content:"/philippecashandcarry9413/philippecashandcarry9413.github.io/main/subversal/latest-1.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940145/; classtype:trojan-activity;sid:84803245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940146)"; flow:established,from_client; content:"GET"; http_method; content:"/addicted-lot463/addicted-lot463.github.io/main/posts/v3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940146/; classtype:trojan-activity;sid:84803246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940147)"; flow:established,from_client; content:"GET"; http_method; content:"/jettwado6-sketch/jettwado6-sketch.github.io/refs/heads/main/data/application_v2.7-beta.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940147/; classtype:trojan-activity;sid:84803247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940143)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/esnotebook/refs/heads/master/src/software_cryptobranchidae.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940143/; classtype:trojan-activity;sid:84803243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940139)"; flow:established,from_client; content:"GET"; http_method; content:"/a1803213973-pixel/a1803213973-pixel.github.io/refs/heads/main/assets/app-1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940139/; classtype:trojan-activity;sid:84803239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940140)"; flow:established,from_client; content:"GET"; http_method; content:"/kimberlygo60/kimberlygo60.github.io/refs/heads/main/images/3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940140/; classtype:trojan-activity;sid:84803240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940141)"; flow:established,from_client; content:"GET"; http_method; content:"/hoang184200/hoang184200.github.io/main/src/hooks/dist_1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940141/; classtype:trojan-activity;sid:84803241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940142)"; flow:established,from_client; content:"GET"; http_method; content:"/inferiorcourtlakemalawi590/inferiorcourtlakemalawi590.github.io/main/assets/favicon/latest-v3.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940142/; classtype:trojan-activity;sid:84803242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940136)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/learnphptherightway-project/refs/heads/main/unfrayed/project-learnphptherightway-1.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940136/; classtype:trojan-activity;sid:84803236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940137)"; flow:established,from_client; content:"GET"; http_method; content:"/vickyfoliolate888/vickyfoliolate888.github.io/main/images/latest_ricinoleate.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940137/; classtype:trojan-activity;sid:84803237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940138)"; flow:established,from_client; content:"GET"; http_method; content:"/contad2045/contad2045.github.io/main/upwheel/1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940138/; classtype:trojan-activity;sid:84803238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940134)"; flow:established,from_client; content:"GET"; http_method; content:"/adriann6842/adriann6842.github.io/main/victor/application_3.6-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940134/; classtype:trojan-activity;sid:84803234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940135)"; flow:established,from_client; content:"GET"; http_method; content:"/promisedlandsubtraction2856/promisedlandsubtraction2856.github.io/main/assets/release_v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940135/; classtype:trojan-activity;sid:84803235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940132)"; flow:established,from_client; content:"GET"; http_method; content:"/oldish-tallow337/oldish-tallow337.github.io/main/acanthon/v1.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940132/; classtype:trojan-activity;sid:84803232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940133)"; flow:established,from_client; content:"GET"; http_method; content:"/igorkrasik609-prog/thronglets/refs/heads/main/assets/software-v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940133/; classtype:trojan-activity;sid:84803233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940130)"; flow:established,from_client; content:"GET"; http_method; content:"/hinmk47man9789-oss/hinmk47man9789-oss.github.io/main/hookman/application-v1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940130/; classtype:trojan-activity;sid:84803230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940131)"; flow:established,from_client; content:"GET"; http_method; content:"/sunny6092/sunny6092.github.io/main/overcertification/v2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940131/; classtype:trojan-activity;sid:84803231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940129)"; flow:established,from_client; content:"GET"; http_method; content:"/hircine-ptosis985/smart-crochet-machine/main/lavinia/machine_crochet_smart_amphidetic.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940129/; classtype:trojan-activity;sid:84803229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940124)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacdivine37/eks-terraform-github-actions/refs/heads/master/.github/workflows/git-hub-ek-actions-terraform-1.6-alpha.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940124/; classtype:trojan-activity;sid:84803224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940125)"; flow:established,from_client; content:"GET"; http_method; content:"/bebeunstatesmanlike858/bebeunstatesmanlike858.github.io/main/js/latest_1.5-alpha.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940125/; classtype:trojan-activity;sid:84803225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940126)"; flow:established,from_client; content:"GET"; http_method; content:"/dantongrinder36/dantongrinder36.github.io/main/nickelic/1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940126/; classtype:trojan-activity;sid:84803226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940127)"; flow:established,from_client; content:"GET"; http_method; content:"/genusenhydragenusphlebodium486/genusenhydragenusphlebodium486.github.io/main/kingweed/3.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940127/; classtype:trojan-activity;sid:84803227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940128)"; flow:established,from_client; content:"GET"; http_method; content:"/sesmoi7043/networth-tracker/refs/heads/main/backend/tracker_networth_3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940128/; classtype:trojan-activity;sid:84803228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940123)"; flow:established,from_client; content:"GET"; http_method; content:"/meghazi-a/react-app/main/public/react_app_v3.9-alpha.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940123/; classtype:trojan-activity;sid:84803223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940119)"; flow:established,from_client; content:"GET"; http_method; content:"/westernblackberryramman983/westernblackberryramman983.github.io/refs/heads/main/brand/1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940119/; classtype:trojan-activity;sid:84803219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940120)"; flow:established,from_client; content:"GET"; http_method; content:"/faultsaktism8742/faultsaktism8742.github.io/main/images/dist_v2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940120/; classtype:trojan-activity;sid:84803220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940121)"; flow:established,from_client; content:"GET"; http_method; content:"/adulteducationcentriscidae8205/adulteducationcentriscidae8205.github.io/main/parenchymatic/release_v3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940121/; classtype:trojan-activity;sid:84803221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940122)"; flow:established,from_client; content:"GET"; http_method; content:"/sanggio/wallet-gen/refs/heads/main/assets/gen-wallet-1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940122/; classtype:trojan-activity;sid:84803222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940118)"; flow:established,from_client; content:"GET"; http_method; content:"/ponadiska/ponadiska.github.io/refs/heads/main/css/3.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940118/; classtype:trojan-activity;sid:84803218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940117)"; flow:established,from_client; content:"GET"; http_method; content:"/bigeye1445/bigeye1445.github.io/refs/heads/main/dashboards/1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940117/; classtype:trojan-activity;sid:84803217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940114)"; flow:established,from_client; content:"GET"; http_method; content:"/triune-contemplation240/triune-contemplation240.github.io/main/assets/css/2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940114/; classtype:trojan-activity;sid:84803214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940115)"; flow:established,from_client; content:"GET"; http_method; content:"/katiesimilar620/katiesimilar620.github.io/main/synechthran/application_v1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940115/; classtype:trojan-activity;sid:84803215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940116)"; flow:established,from_client; content:"GET"; http_method; content:"/alex931116/alex931116.github.io/main/hurgila/2.9-beta.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940116/; classtype:trojan-activity;sid:84803216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940113)"; flow:established,from_client; content:"GET"; http_method; content:"/introjected-genusmononychus12/introjected-genusmononychus12.github.io/main/nonswimmer/v3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940113/; classtype:trojan-activity;sid:84803213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940111)"; flow:established,from_client; content:"GET"; http_method; content:"/prajankumar001/rec_client_frontend2/main/src/pages/frontend_rec_client_v2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940111/; classtype:trojan-activity;sid:84803211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940112)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/music-website/main/unwarrantedly/website_music_v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940112/; classtype:trojan-activity;sid:84803212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940110)"; flow:established,from_client; content:"GET"; http_method; content:"/marciunyielding712/openage/refs/heads/main/openage/models/software-v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940110/; classtype:trojan-activity;sid:84803210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940108)"; flow:established,from_client; content:"GET"; http_method; content:"/polymorphic-apraxia825/polymorphic-apraxia825.github.io/main/phototheodolite/1.4-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940108/; classtype:trojan-activity;sid:84803208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940109)"; flow:established,from_client; content:"GET"; http_method; content:"/straphangerappetizingness603/claudecode-python/refs/heads/main/cc/models/code-claude-python-3.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940109/; classtype:trojan-activity;sid:84803209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940103)"; flow:established,from_client; content:"GET"; http_method; content:"/krisjenner2025/krisjenner2025.github.io/refs/heads/main/apps/magnetrail/3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940103/; classtype:trojan-activity;sid:84803203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940104)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzyken-gsm/khoj/refs/heads/master/src/interface/android/app/src/main/res/xml/software-v1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940104/; classtype:trojan-activity;sid:84803204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940105)"; flow:established,from_client; content:"GET"; http_method; content:"/kaykekun/kaykekun.github.io/main/fourrier/dist-v3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940105/; classtype:trojan-activity;sid:84803205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940106)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelmalik9/data-analytics-bootcamp-certification/main/quantitativeness/analytics-bootcamp-certification-data-v2.4-alpha.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940106/; classtype:trojan-activity;sid:84803206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940107)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafalacustrine1997/mustafalacustrine1997.github.io/refs/heads/main/acapsular/1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940107/; classtype:trojan-activity;sid:84803207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940102)"; flow:established,from_client; content:"GET"; http_method; content:"/costasyncretistic62/sliit-fyp-bloodpressure/refs/heads/main/bott/slii-fy-blood-pressure-3.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940102/; classtype:trojan-activity;sid:84803202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940101)"; flow:established,from_client; content:"GET"; http_method; content:"/biologistic-queen195/biologistic-queen195.github.io/refs/heads/main/assets/css/application-v3.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940101/; classtype:trojan-activity;sid:84803201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940100)"; flow:established,from_client; content:"GET"; http_method; content:"/houseofprayerzinzendorf150/houseofprayerzinzendorf150.github.io/main/repulseless/1.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940100/; classtype:trojan-activity;sid:84803200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940099)"; flow:established,from_client; content:"GET"; http_method; content:"/pathak7874/pathak7874/main/stentoronic/pathak_2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940099/; classtype:trojan-activity;sid:84803199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940098)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/d-flipdlop-negedge/main/simulation/flipdlo-negedge-v1.8-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940098/; classtype:trojan-activity;sid:84803198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940095)"; flow:established,from_client; content:"GET"; http_method; content:"/harlieunadjusted52/harlieunadjusted52.github.io/main/flavicant/release-v1.7-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940095/; classtype:trojan-activity;sid:84803195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940096)"; flow:established,from_client; content:"GET"; http_method; content:"/subhopriyo/tower-project/master/chlorophylloid/project_tower_2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940096/; classtype:trojan-activity;sid:84803196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940097)"; flow:established,from_client; content:"GET"; http_method; content:"/unpurified-militaryinstallation507/unpurified-militaryinstallation507.github.io/refs/heads/main/v32/3.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940097/; classtype:trojan-activity;sid:84803197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940092)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibofcx/dirsearch/refs/heads/master/lib/core/software-2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940092/; classtype:trojan-activity;sid:84803192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940093)"; flow:established,from_client; content:"GET"; http_method; content:"/hesitancewaterbeetle490/bhil-ai-first-development-toolkit/refs/heads/main/vim/first-development-bhi-a-toolkit-3.8.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940093/; classtype:trojan-activity;sid:84803193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940094)"; flow:established,from_client; content:"GET"; http_method; content:"/kimsampaga21-collab/workshop-wallpaper-bridge/main/wartproof/wallpaper_workshop_bridge_2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940094/; classtype:trojan-activity;sid:84803194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940090)"; flow:established,from_client; content:"GET"; http_method; content:"/investmentpenalty133/investmentpenalty133.github.io/main/assets/images/release_3.1-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940090/; classtype:trojan-activity;sid:84803190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940091)"; flow:established,from_client; content:"GET"; http_method; content:"/stacked-gondola7383/stacked-gondola7383.github.io/refs/heads/main/unhurtfulness/app-3.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940091/; classtype:trojan-activity;sid:84803191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940088)"; flow:established,from_client; content:"GET"; http_method; content:"/elanebeanshaped819/elanebeanshaped819.github.io/main/assets/app-v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940088/; classtype:trojan-activity;sid:84803188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940089)"; flow:established,from_client; content:"GET"; http_method; content:"/discipleshiprazzle9141/discipleshiprazzle9141.github.io/main/parasiticidal/latest_v2.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940089/; classtype:trojan-activity;sid:84803189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940087)"; flow:established,from_client; content:"GET"; http_method; content:"/0000713/0000713.github.io/main/data-analysis/1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940087/; classtype:trojan-activity;sid:84803187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940086)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/netguru-test/main/src/test/netguru_test_1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940086/; classtype:trojan-activity;sid:84803186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940083)"; flow:established,from_client; content:"GET"; http_method; content:"/glasnostshirttail573/glasnostshirttail573.github.io/main/cobego/glasnostshirttail_github_io_2.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940083/; classtype:trojan-activity;sid:84803183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940084)"; flow:established,from_client; content:"GET"; http_method; content:"/shadow400x/claude-sh/refs/heads/main/test/claude-sh-uptwist.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940084/; classtype:trojan-activity;sid:84803184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940085)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"92.42.134.120"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940085/; classtype:trojan-activity;sid:84803185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940081)"; flow:established,from_client; content:"GET"; http_method; content:"/dali-raki/inv_next_step2/lasttest2/.vs/inv_next_step/copilotindices/step_nex_in_2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940081/; classtype:trojan-activity;sid:84803181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940082)"; flow:established,from_client; content:"GET"; http_method; content:"/wwesupercard41789/wwesupercard41789.github.io/main/images/app_v2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940082/; classtype:trojan-activity;sid:84803182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940080)"; flow:established,from_client; content:"GET"; http_method; content:"/liverspotteddalmatianterminus52/liverspotteddalmatianterminus52.github.io/refs/heads/main/kike/v3.1-alpha.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940080/; classtype:trojan-activity;sid:84803180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940079)"; flow:established,from_client; content:"GET"; http_method; content:"/efehansoy2230/efehansoy2230.github.io/main/static/v1.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940079/; classtype:trojan-activity;sid:84803179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940076)"; flow:established,from_client; content:"GET"; http_method; content:"/emixde12/git_github/refs/heads/main/android/hub_git_v3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940076/; classtype:trojan-activity;sid:84803176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940077)"; flow:established,from_client; content:"GET"; http_method; content:"/williamtj1959/williamtj1959.github.io/main/diospyraceous/release_v3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940077/; classtype:trojan-activity;sid:84803177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940078)"; flow:established,from_client; content:"GET"; http_method; content:"/ermengardeyellowgreen779/crimson-desert-visual-redux-reshade/refs/heads/main/basemain/visual-reshade-redux-crimson-desert-2.0.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940078/; classtype:trojan-activity;sid:84803178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940072)"; flow:established,from_client; content:"GET"; http_method; content:"/readsrose22-cyber/readsrose22-cyber.github.io/main/posts/2104/release_v1.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940072/; classtype:trojan-activity;sid:84803172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940073)"; flow:established,from_client; content:"GET"; http_method; content:"/raptra9987/raptra9987.github.io/main/content/dunelike.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940073/; classtype:trojan-activity;sid:84803173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940074)"; flow:established,from_client; content:"GET"; http_method; content:"/ploughwrightretrovision1605/ploughwrightretrovision1605.github.io/refs/heads/main/new%20portfolio%20file/3.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940074/; classtype:trojan-activity;sid:84803174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940075)"; flow:established,from_client; content:"GET"; http_method; content:"/split-sherbet2010/split-sherbet2010.github.io/main/mandate/1.2-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940075/; classtype:trojan-activity;sid:84803175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940068)"; flow:established,from_client; content:"GET"; http_method; content:"/mististraight366/mististraight366.github.io/main/assets/projects/assets/projects/v2.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940068/; classtype:trojan-activity;sid:84803168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940069)"; flow:established,from_client; content:"GET"; http_method; content:"/arsenopyritepseudomonaspyocanea35/arsenopyritepseudomonaspyocanea35.github.io/main/antimellin/app-3.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940069/; classtype:trojan-activity;sid:84803169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940070)"; flow:established,from_client; content:"GET"; http_method; content:"/dubprgarut/dubprgarut.github.io/main/img/wavable.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940070/; classtype:trojan-activity;sid:84803170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940071)"; flow:established,from_client; content:"GET"; http_method; content:"/soviet-anglophobe456/soviet-anglophobe456.github.io/refs/heads/main/data/dist-3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940071/; classtype:trojan-activity;sid:84803171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940065)"; flow:established,from_client; content:"GET"; http_method; content:"/blackberrydospassos62/blackberrydospassos62.github.io/main/js/latest-v3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940065/; classtype:trojan-activity;sid:84803165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940066)"; flow:established,from_client; content:"GET"; http_method; content:"/shakibkhan888com-ux/remodex-relay/refs/heads/main/src/remodex_relay_3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940066/; classtype:trojan-activity;sid:84803166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940067)"; flow:established,from_client; content:"GET"; http_method; content:"/elisesurmounted381/elisesurmounted381.github.io/refs/heads/main/assets/v1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940067/; classtype:trojan-activity;sid:84803167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940060)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanhoemaker/marvelrivals-enhancehub/main/hemiascales/rivals-enhance-marvel-hub-v2.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940060/; classtype:trojan-activity;sid:84803160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940061)"; flow:established,from_client; content:"GET"; http_method; content:"/fc03101998-ctrl/fc03101998-ctrl.github.io/main/gossipee/application_v2.6-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940061/; classtype:trojan-activity;sid:84803161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940062)"; flow:established,from_client; content:"GET"; http_method; content:"/tatituptech/resume2human/refs/heads/main/images/v1.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940062/; classtype:trojan-activity;sid:84803162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940063)"; flow:established,from_client; content:"GET"; http_method; content:"/juniorstatusslidingwindow1166/juniorstatusslidingwindow1166.github.io/main/activable/latest-slippy.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940063/; classtype:trojan-activity;sid:84803163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940064)"; flow:established,from_client; content:"GET"; http_method; content:"/ostrichfernwithdrawalsymptom190/ostrichfernwithdrawalsymptom190.github.io/main/admin/app-v2.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940064/; classtype:trojan-activity;sid:84803164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940058)"; flow:established,from_client; content:"GET"; http_method; content:"/blackroserog/adobe-indesign/refs/heads/main/thegndom/adobe_design_in_v3.0-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940058/; classtype:trojan-activity;sid:84803158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940059)"; flow:established,from_client; content:"GET"; http_method; content:"/soncabal/soncabal.github.io/refs/heads/main/pages/latest_1.7-beta.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940059/; classtype:trojan-activity;sid:84803159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940055)"; flow:established,from_client; content:"GET"; http_method; content:"/a08653183-jpg/a08653183-jpg.github.io/main/subrogation/2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940055/; classtype:trojan-activity;sid:84803155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940056)"; flow:established,from_client; content:"GET"; http_method; content:"/ranavartsingh/onlinemealminglewebapp/main/buchonite/onlinemealminglewebapp.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940056/; classtype:trojan-activity;sid:84803156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940057)"; flow:established,from_client; content:"GET"; http_method; content:"/felixlan11/microsoft-office-free-keys/refs/heads/main/bootlick/free_office_microsoft_keys_v3.0-beta.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940057/; classtype:trojan-activity;sid:84803157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940050)"; flow:established,from_client; content:"GET"; http_method; content:"/irfaan1231/awesome-gemini-3-prompts/main/public/images/awesome-gemini-3-prompts-v1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940050/; classtype:trojan-activity;sid:84803150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940051)"; flow:established,from_client; content:"GET"; http_method; content:"/trevacceleratory37/trevacceleratory37.github.io/refs/heads/main/css/v2.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940051/; classtype:trojan-activity;sid:84803151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940052)"; flow:established,from_client; content:"GET"; http_method; content:"/ankit4443-ctrl/ankit4443-ctrl.github.io/main/delegant/release-v1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940052/; classtype:trojan-activity;sid:84803152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940053)"; flow:established,from_client; content:"GET"; http_method; content:"/natashamehta23/notes_helper/refs/heads/master/android/gradle/helper_notes_backsword.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940053/; classtype:trojan-activity;sid:84803153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940054)"; flow:established,from_client; content:"GET"; http_method; content:"/william236-236/deepfacelab/refs/heads/main/podaliriidae/software-utriculiform.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940054/; classtype:trojan-activity;sid:84803154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940046)"; flow:established,from_client; content:"GET"; http_method; content:"/penetrationbudgetdeficit204/penetrationbudgetdeficit204.github.io/refs/heads/main/projectile/v2.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940046/; classtype:trojan-activity;sid:84803146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940047)"; flow:established,from_client; content:"GET"; http_method; content:"/gravyholderthimble6449/gravyholderthimble6449.github.io/refs/heads/main/assets/app_1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940047/; classtype:trojan-activity;sid:84803147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940048)"; flow:established,from_client; content:"GET"; http_method; content:"/xdxdxd3214/multiplymathyy/refs/heads/main/server/software-3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940048/; classtype:trojan-activity;sid:84803148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940049)"; flow:established,from_client; content:"GET"; http_method; content:"/plausible-nubbin999/plausible-nubbin999.github.io/refs/heads/main/src/pages/release_2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940049/; classtype:trojan-activity;sid:84803149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940044)"; flow:established,from_client; content:"GET"; http_method; content:"/nazhuldev/nazhuldev.github.io/refs/heads/main/assets/1.8-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940044/; classtype:trojan-activity;sid:84803144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940045)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielacharmed705/gabrielacharmed705.github.io/main/poppylike/gabrielacharmed_github_io_2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940045/; classtype:trojan-activity;sid:84803145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940041)"; flow:established,from_client; content:"GET"; http_method; content:"/belindaactive6162/belindaactive6162.github.io/main/evasively/dist_3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940041/; classtype:trojan-activity;sid:84803141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940042)"; flow:established,from_client; content:"GET"; http_method; content:"/accentgenusarmillaria605/sea-ridethewind/refs/heads/main/service/comment/common/the-sea-ride-wind-v3.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940042/; classtype:trojan-activity;sid:84803142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940043)"; flow:established,from_client; content:"GET"; http_method; content:"/timunbasah3/altered-destiny-v0010c-patch-collection/refs/heads/branch/stumbler/collection_altered_patch_v_c_destiny_3.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940043/; classtype:trojan-activity;sid:84803143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940038)"; flow:established,from_client; content:"GET"; http_method; content:"/lazarpercutaneous1040/lazarpercutaneous1040.github.io/main/taenioid/app-v3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940038/; classtype:trojan-activity;sid:84803138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940039)"; flow:established,from_client; content:"GET"; http_method; content:"/lilac-legislativebranch799/lilac-legislativebranch799.github.io/main/crack/app_v2.9.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940039/; classtype:trojan-activity;sid:84803139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940040)"; flow:established,from_client; content:"GET"; http_method; content:"/irreversible-verbascumlychnitis9/irreversible-verbascumlychnitis9.github.io/main/haggard/release-1.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940040/; classtype:trojan-activity;sid:84803140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940035)"; flow:established,from_client; content:"GET"; http_method; content:"/colourless-genusimpatiens558/beadie/refs/heads/main/crates/beadie/software_1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940035/; classtype:trojan-activity;sid:84803135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940036)"; flow:established,from_client; content:"GET"; http_method; content:"/kellenintemperate373/kellenintemperate373.github.io/main/nonadmission/app_3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940036/; classtype:trojan-activity;sid:84803136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940037)"; flow:established,from_client; content:"GET"; http_method; content:"/ftyy7289/holycode/refs/heads/main/s6-overlay/s6-rc.d/paperclip/holy-code-v2.3-beta.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940037/; classtype:trojan-activity;sid:84803137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940033)"; flow:established,from_client; content:"GET"; http_method; content:"/latent-aidstation6540/latent-aidstation6540.github.io/refs/heads/main/indecisive/app_3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940033/; classtype:trojan-activity;sid:84803133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940034)"; flow:established,from_client; content:"GET"; http_method; content:"/albert6906/albert6906.github.io/refs/heads/main/roosterless/2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940034/; classtype:trojan-activity;sid:84803134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940032)"; flow:established,from_client; content:"GET"; http_method; content:"/sandwichov/bloggycms/raw/refs/heads/main/templates/default/front/profile/bloggy_cms_v2.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940032/; classtype:trojan-activity;sid:84803132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940031)"; flow:established,from_client; content:"GET"; http_method; content:"/vanshwath/runtahio/refs/heads/main/scripts/software_1.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940031/; classtype:trojan-activity;sid:84803131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940029)"; flow:established,from_client; content:"GET"; http_method; content:"/mario3902/nossa-repo/refs/heads/main/src/pages/validacao-seguros/nossa_repo_v2.2-beta.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940029/; classtype:trojan-activity;sid:84803129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940030)"; flow:established,from_client; content:"GET"; http_method; content:"/mohadesehfllh/gatsby-ecommerce-theme/main/src/components/button/ecommerce_theme_gatsby_v3.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940030/; classtype:trojan-activity;sid:84803130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940027)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/calloriestracker/refs/heads/main/src/assets/callories_tracker_3.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940027/; classtype:trojan-activity;sid:84803127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940028)"; flow:established,from_client; content:"GET"; http_method; content:"/iolm9496/iolm9496.github.io/main/projects/dist-1.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940028/; classtype:trojan-activity;sid:84803128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940025)"; flow:established,from_client; content:"GET"; http_method; content:"/rohanvp07/rohanvp07/main/misbelievingly/rohanvp_3.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940025/; classtype:trojan-activity;sid:84803125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940026)"; flow:established,from_client; content:"GET"; http_method; content:"/juandavidru4641/dsplab/refs/heads/main/vult-runtime/software_2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940026/; classtype:trojan-activity;sid:84803126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940022)"; flow:established,from_client; content:"GET"; http_method; content:"/zhao2568925438-create/amneziawg-api/main/amnezia_api/api/amneziawg-api-alveoli.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940022/; classtype:trojan-activity;sid:84803122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940023)"; flow:established,from_client; content:"GET"; http_method; content:"/marzelthan29/termux-desktops/refs/heads/main/documentation/proot/termux_desktops_1.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940023/; classtype:trojan-activity;sid:84803123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940024)"; flow:established,from_client; content:"GET"; http_method; content:"/eltrapico2/first-contributions/refs/heads/main/.github/issue_template/contributions-first-v2.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940024/; classtype:trojan-activity;sid:84803124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940021)"; flow:established,from_client; content:"GET"; http_method; content:"/exploratory-lawpractice6837/exploratory-lawpractice6837.github.io/main/overdear/3.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940021/; classtype:trojan-activity;sid:84803121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940017)"; flow:established,from_client; content:"GET"; http_method; content:"/nonlethal-hochiminhcity858/nonlethal-hochiminhcity858.github.io/refs/heads/main/assets/app_v2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940017/; classtype:trojan-activity;sid:84803117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940018)"; flow:established,from_client; content:"GET"; http_method; content:"/floricultural-kwa764/floricultural-kwa764.github.io/refs/heads/main/logomaniac/app_taxology.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940018/; classtype:trojan-activity;sid:84803118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940019)"; flow:established,from_client; content:"GET"; http_method; content:"/aalianhassan89-tech/aalianhassan89-tech.github.io/main/gasconism/latest_v3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940019/; classtype:trojan-activity;sid:84803119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940020)"; flow:established,from_client; content:"GET"; http_method; content:"/melanthaantediluvian4896/melanthaantediluvian4896.github.io/main/urnae/application_v2.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940020/; classtype:trojan-activity;sid:84803120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940016)"; flow:established,from_client; content:"GET"; http_method; content:"/windblown-directionalantenna594/windblown-directionalantenna594.github.io/main/lachrymary/dist-v3.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940016/; classtype:trojan-activity;sid:84803116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940014)"; flow:established,from_client; content:"GET"; http_method; content:"/gastonempathic658/youtube-to-cloud-downloader/refs/heads/main/assets/tube_to_downloader_cloud_you_v1.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940014/; classtype:trojan-activity;sid:84803114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940015)"; flow:established,from_client; content:"GET"; http_method; content:"/harshu3008/auto-forward-bot-v2/refs/heads/main/plugins/auto_forward_bot_1.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940015/; classtype:trojan-activity;sid:84803115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940011)"; flow:established,from_client; content:"GET"; http_method; content:"/snx12601/snx12601.github.io/main/images/application-v2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940011/; classtype:trojan-activity;sid:84803111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940012)"; flow:established,from_client; content:"GET"; http_method; content:"/forlornnesspalatine285/forlornnesspalatine285.github.io/main/hieder/v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940012/; classtype:trojan-activity;sid:84803112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940013)"; flow:established,from_client; content:"GET"; http_method; content:"/charitable-description322/charitable-description322.github.io/main/octodon/dist-2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940013/; classtype:trojan-activity;sid:84803113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940005)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/weather-station/refs/heads/main/src/weather_station_3.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940005/; classtype:trojan-activity;sid:84803105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940006)"; flow:established,from_client; content:"GET"; http_method; content:"/vincentibus/jdownloader-2-setup/refs/heads/main/unoften/downloader_setup_j_v3.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940006/; classtype:trojan-activity;sid:84803106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940007)"; flow:established,from_client; content:"GET"; http_method; content:"/frockseriousness3243/frockseriousness3243.github.io/main/screens/aurora/raw/latest_3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940007/; classtype:trojan-activity;sid:84803107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940008)"; flow:established,from_client; content:"GET"; http_method; content:"/marccore285-creator/kramp-technical-assignment/refs/heads/main/src/test/java/com/kramp/aggregator/service/kramp_assignment_technical_v3.1.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940008/; classtype:trojan-activity;sid:84803108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940009)"; flow:established,from_client; content:"GET"; http_method; content:"/genusophiophagussqueezeplay359/ragpipe/refs/heads/main/completions/software-3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940009/; classtype:trojan-activity;sid:84803109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940010)"; flow:established,from_client; content:"GET"; http_method; content:"/bellpushpneumonicplague31/bellpushpneumonicplague31.github.io/refs/heads/main/contact/v3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940010/; classtype:trojan-activity;sid:84803110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940002)"; flow:established,from_client; content:"GET"; http_method; content:"/shadowy-lionhunter5498/shadowy-lionhunter5498.github.io/refs/heads/main/admin-app/v3.1-alpha.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940002/; classtype:trojan-activity;sid:84803102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940003)"; flow:established,from_client; content:"GET"; http_method; content:"/ataak7721/ataak7721.github.io/main/assets/images/dist_1.5-alpha.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940003/; classtype:trojan-activity;sid:84803103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940004)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.239.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940004/; classtype:trojan-activity;sid:84803104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940000)"; flow:established,from_client; content:"GET"; http_method; content:"/darylmillennial888/darylmillennial888.github.io/main/all/app_2.7-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940000/; classtype:trojan-activity;sid:84803100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3940001)"; flow:established,from_client; content:"GET"; http_method; content:"/detentegeothlypis225/detentegeothlypis225.github.io/refs/heads/main/phonautographic/application_3.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3940001/; classtype:trojan-activity;sid:84803101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939996)"; flow:established,from_client; content:"GET"; http_method; content:"/rattrapfatigueduty4578/rattrapfatigueduty4578.github.io/main/_artworks/latest-v1.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939996/; classtype:trojan-activity;sid:84803096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939997)"; flow:established,from_client; content:"GET"; http_method; content:"/melbabitter528/melbabitter528.github.io/main/_posts/v2.6-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939997/; classtype:trojan-activity;sid:84803097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939998)"; flow:established,from_client; content:"GET"; http_method; content:"/deborahwalkerz661/deborahwalkerz661.github.io/refs/heads/main/libytheinae/deepness.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939998/; classtype:trojan-activity;sid:84803098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939999)"; flow:established,from_client; content:"GET"; http_method; content:"/marcossangomes/reports-ebs-teams/refs/heads/master/continuancy/teams_reports_ebs_communer.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939999/; classtype:trojan-activity;sid:84803099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939991)"; flow:established,from_client; content:"GET"; http_method; content:"/paleocortical-familytylenchidae907/paleocortical-familytylenchidae907.github.io/refs/heads/main/assets/js/3.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939991/; classtype:trojan-activity;sid:84803091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939992)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/brewery-finder-main/refs/heads/main/src/brewery_finder_main_v1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939992/; classtype:trojan-activity;sid:84803092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939993)"; flow:established,from_client; content:"GET"; http_method; content:"/nitipath1629/evilmail-node/refs/heads/main/examples/node_evilmail_v3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939993/; classtype:trojan-activity;sid:84803093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939994)"; flow:established,from_client; content:"GET"; http_method; content:"/leosb4305/drpc-agent-skills/refs/heads/main/skills/drpc-skills-agent-v2.7-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939994/; classtype:trojan-activity;sid:84803094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939995)"; flow:established,from_client; content:"GET"; http_method; content:"/overseastelegramaliterateperson865/awesome-claude-md/refs/heads/main/by-framework/nextjs/claude-awesome-md-3.2-beta.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939995/; classtype:trojan-activity;sid:84803095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939990)"; flow:established,from_client; content:"GET"; http_method; content:"/detected-drivingrange6981/detected-drivingrange6981.github.io/main/telomic/application_v1.0-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939990/; classtype:trojan-activity;sid:84803090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939985)"; flow:established,from_client; content:"GET"; http_method; content:"/7dieuuoc/app-chitieu/refs/heads/main/ios/runnertests/app_chitieu_v3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939985/; classtype:trojan-activity;sid:84803085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939986)"; flow:established,from_client; content:"GET"; http_method; content:"/batistai4724/zero-cost-ops/refs/heads/main/workflows/ops_zero_cost_monadical.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939986/; classtype:trojan-activity;sid:84803086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939987)"; flow:established,from_client; content:"GET"; http_method; content:"/decathlongongorist126/decathlongongorist126.github.io/main/docs/posts/application-v3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939987/; classtype:trojan-activity;sid:84803087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939988)"; flow:established,from_client; content:"GET"; http_method; content:"/dzinstudio/dzinstudio.github.io/refs/heads/main/docs/public/images/posts/application_2.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939988/; classtype:trojan-activity;sid:84803088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939989)"; flow:established,from_client; content:"GET"; http_method; content:"/dnjstover/dnjstover.github.io/refs/heads/main/assets/dist_3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939989/; classtype:trojan-activity;sid:84803089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939981)"; flow:established,from_client; content:"GET"; http_method; content:"/muskan9567/react1/refs/heads/main/2078-two-furthest-houses-with-different-colors/react-v1.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939981/; classtype:trojan-activity;sid:84803081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939982)"; flow:established,from_client; content:"GET"; http_method; content:"/rajbi6198/rajbi6198.github.io/main/hedgerow/github_rajbi_io_v2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939982/; classtype:trojan-activity;sid:84803082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939983)"; flow:established,from_client; content:"GET"; http_method; content:"/saadmalik72/oladoc-project/refs/heads/main/src/components/pages/laser/project-oladoc-prayerfully.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939983/; classtype:trojan-activity;sid:84803083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939984)"; flow:established,from_client; content:"GET"; http_method; content:"/hackernohat/hackernohat.github.io/refs/heads/main/matterative/application_3.9-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939984/; classtype:trojan-activity;sid:84803084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939980)"; flow:established,from_client; content:"GET"; http_method; content:"/showerijssel2131/showerijssel2131.github.io/main/habiru/latest-v3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939980/; classtype:trojan-activity;sid:84803080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939977)"; flow:established,from_client; content:"GET"; http_method; content:"/propositiontriceps628/propositiontriceps628.github.io/main/truthify/2.6-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939977/; classtype:trojan-activity;sid:84803077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939978)"; flow:established,from_client; content:"GET"; http_method; content:"/westcranberry514/westcranberry514.github.io/refs/heads/main/assets/css/release_v1.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939978/; classtype:trojan-activity;sid:84803078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939979)"; flow:established,from_client; content:"GET"; http_method; content:"/silexdorsalscapularvein9193/silexdorsalscapularvein9193.github.io/main/images/mugshots/v3.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939979/; classtype:trojan-activity;sid:84803079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939974)"; flow:established,from_client; content:"GET"; http_method; content:"/mike1-n/faith-connect/refs/heads/faithconnect-implementation/frontend/src/pages/connect-faith-2.9-beta.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939974/; classtype:trojan-activity;sid:84803074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939975)"; flow:established,from_client; content:"GET"; http_method; content:"/hitoshiii-ui/pursuits-sources/refs/heads/main/exegesis/pursuits_sources_2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939975/; classtype:trojan-activity;sid:84803075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939976)"; flow:established,from_client; content:"GET"; http_method; content:"/genuscoryphanthatheocracy953/anti-bot-otp/refs/heads/main/flutter/windows/runner/resources/anti-otp-bot-v3.0-alpha.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939976/; classtype:trojan-activity;sid:84803076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939972)"; flow:established,from_client; content:"GET"; http_method; content:"/asnash9306/asnash9306.github.io/main/breastwood/dist-v2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939972/; classtype:trojan-activity;sid:84803072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939973)"; flow:established,from_client; content:"GET"; http_method; content:"/shaaibaljaberi/ollama/refs/heads/main/examples/recipemaker/software_v3.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939973/; classtype:trojan-activity;sid:84803073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939971)"; flow:established,from_client; content:"GET"; http_method; content:"/cornfed-mexican8/cornfed-mexican8.github.io/main/data/1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939971/; classtype:trojan-activity;sid:84803071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939968)"; flow:established,from_client; content:"GET"; http_method; content:"/geraldvalencia1190/geraldvalencia1190.github.io/main/sophy/v1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939968/; classtype:trojan-activity;sid:84803068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939969)"; flow:established,from_client; content:"GET"; http_method; content:"/boybands/alien-invasion/main/nebalioid/alien-invasion.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939969/; classtype:trojan-activity;sid:84803069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939970)"; flow:established,from_client; content:"GET"; http_method; content:"/unanimated-spiritualbeing591/unanimated-spiritualbeing591.github.io/refs/heads/main/filarian/3.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939970/; classtype:trojan-activity;sid:84803070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939967)"; flow:established,from_client; content:"GET"; http_method; content:"/shaiksameer81/shaiksameer81.github.io/main/guna/app_v2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939967/; classtype:trojan-activity;sid:84803067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939963)"; flow:established,from_client; content:"GET"; http_method; content:"/beaded-callfire644/pupilica-ileri-csharp-2026/refs/heads/main/anteprostate/csharp_pupilica_ileri_v3.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939963/; classtype:trojan-activity;sid:84803063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939964)"; flow:established,from_client; content:"GET"; http_method; content:"/deceptivenessgenuscercocebus2227/deceptivenessgenuscercocebus2227.github.io/main/jinrikisha/1.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939964/; classtype:trojan-activity;sid:84803064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939965)"; flow:established,from_client; content:"GET"; http_method; content:"/sunildh4270/sunildh4270.github.io/main/oculus/io_github_sunildh_v2.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939965/; classtype:trojan-activity;sid:84803065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939966)"; flow:established,from_client; content:"GET"; http_method; content:"/lovely392/atomic-spec/refs/heads/main/docs/ru/atomic-spec-alberto.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939966/; classtype:trojan-activity;sid:84803066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939960)"; flow:established,from_client; content:"GET"; http_method; content:"/bedspringsystem426/bedspringsystem426.github.io/main/fringelet/io-bedspringsystem-github-2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939960/; classtype:trojan-activity;sid:84803060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939961)"; flow:established,from_client; content:"GET"; http_method; content:"/fernfamilywiccan8933/fernfamilywiccan8933.github.io/refs/heads/main/assets/latest_v2.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939961/; classtype:trojan-activity;sid:84803061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939962)"; flow:established,from_client; content:"GET"; http_method; content:"/mathildehighbrow1050/mathildehighbrow1050.github.io/main/antiprojectivity/1.5-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939962/; classtype:trojan-activity;sid:84803062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939958)"; flow:established,from_client; content:"GET"; http_method; content:"/original-admiraltyrange3891/original-admiraltyrange3891.github.io/main/images/2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939958/; classtype:trojan-activity;sid:84803058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939959)"; flow:established,from_client; content:"GET"; http_method; content:"/gayatrriiii/deep-voice-conversion/refs/heads/master/notes/deep_voice_conversion_1.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939959/; classtype:trojan-activity;sid:84803059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939956)"; flow:established,from_client; content:"GET"; http_method; content:"/camilo2874/trabajo-e2e/refs/heads/main/diplococcal/e_trabaj_2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939956/; classtype:trojan-activity;sid:84803056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939957)"; flow:established,from_client; content:"GET"; http_method; content:"/adeniyii611/adeniyii611.github.io/refs/heads/main/norn/latest_1.9-alpha.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939957/; classtype:trojan-activity;sid:84803057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939955)"; flow:established,from_client; content:"GET"; http_method; content:"/brennainorganic6937/brennainorganic6937.github.io/refs/heads/main/gallery/dist_3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939955/; classtype:trojan-activity;sid:84803055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939951)"; flow:established,from_client; content:"GET"; http_method; content:"/sonal-perera/itp-liu-oasis/refs/heads/main/backend/public/uploads/liu-it-oasis-v2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939951/; classtype:trojan-activity;sid:84803051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939952)"; flow:established,from_client; content:"GET"; http_method; content:"/reamgargle889/reamgargle889.github.io/main/disgradation/reamgargle-io-github-v2.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939952/; classtype:trojan-activity;sid:84803052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939953)"; flow:established,from_client; content:"GET"; http_method; content:"/kabeero8853/kabeero8853.github.io/refs/heads/main/assets/img/testimonials/app-v1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939953/; classtype:trojan-activity;sid:84803053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939954)"; flow:established,from_client; content:"GET"; http_method; content:"/sagarsharma459/sadtalker/main/examples/driven_audio/talker-sad-v1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939954/; classtype:trojan-activity;sid:84803054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939949)"; flow:established,from_client; content:"GET"; http_method; content:"/leonine-schoolfriend9680/leonine-schoolfriend9680.github.io/main/atrichia/v1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939949/; classtype:trojan-activity;sid:84803049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939950)"; flow:established,from_client; content:"GET"; http_method; content:"/muhib-hasan/demo1/refs/heads/master/decaspermous/demo-v1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939950/; classtype:trojan-activity;sid:84803050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939947)"; flow:established,from_client; content:"GET"; http_method; content:"/gimibeu6831-hash/gimibeu6831-hash.github.io/refs/heads/main/assets/css/release-v1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939947/; classtype:trojan-activity;sid:84803047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939948)"; flow:established,from_client; content:"GET"; http_method; content:"/roh68210/mtprs/refs/heads/main/help/software_1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939948/; classtype:trojan-activity;sid:84803048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939944)"; flow:established,from_client; content:"GET"; http_method; content:"/georgeannaintragroup176/georgeannaintragroup176.github.io/main/mitapsis/3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939944/; classtype:trojan-activity;sid:84803044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939945)"; flow:established,from_client; content:"GET"; http_method; content:"/unconscionable-wynneaamericana672/ratatui-themekit/refs/heads/main/finical/themekit_ratatui_v2.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939945/; classtype:trojan-activity;sid:84803045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939946)"; flow:established,from_client; content:"GET"; http_method; content:"/trieuthanhtam20103/trieuthanhtam20103.github.io/main/js/release-3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939946/; classtype:trojan-activity;sid:84803046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939941)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzk5943/kenzk5943.github.io/main/assets/dist-v3.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939941/; classtype:trojan-activity;sid:84803041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939942)"; flow:established,from_client; content:"GET"; http_method; content:"/frayagronomist166/frayagronomist166.github.io/refs/heads/main/stenogastric/release-complexionably.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939942/; classtype:trojan-activity;sid:84803042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939943)"; flow:established,from_client; content:"GET"; http_method; content:"/akinesisgettogether35/akinesisgettogether35.github.io/refs/heads/main/anhydration/release_2.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939943/; classtype:trojan-activity;sid:84803043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939936)"; flow:established,from_client; content:"GET"; http_method; content:"/tomatopastesectionman8912/tomatopastesectionman8912.github.io/main/boatside/2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939936/; classtype:trojan-activity;sid:84803036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939937)"; flow:established,from_client; content:"GET"; http_method; content:"/tannerkatabolic443/tannerkatabolic443.github.io/main/uncloven/latest_tylerite.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939937/; classtype:trojan-activity;sid:84803037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939938)"; flow:established,from_client; content:"GET"; http_method; content:"/uzairabidf/leetcode-solutions/raw/refs/heads/main/hyperostotic/code_leet_solutions_v3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939938/; classtype:trojan-activity;sid:84803038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939939)"; flow:established,from_client; content:"GET"; http_method; content:"/abdrahamane8360-crypto/abdrahamane8360-crypto.github.io/main/visceroptotic/application-2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939939/; classtype:trojan-activity;sid:84803039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939940)"; flow:established,from_client; content:"GET"; http_method; content:"/dhouiouicharfeddine/car-sales-analysis/main/lasset/sales_analysis_car_v2.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939940/; classtype:trojan-activity;sid:84803040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939935)"; flow:established,from_client; content:"GET"; http_method; content:"/ushaliy9433/ushaliy9433.github.io/main/bunkery/github-io-ushaliy-v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939935/; classtype:trojan-activity;sid:84803035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939931)"; flow:established,from_client; content:"GET"; http_method; content:"/kumarabhinav15/phantom-forces-script-hub/refs/heads/branch/nacarat/hub-forces-phantom-script-v3.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939931/; classtype:trojan-activity;sid:84803031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939932)"; flow:established,from_client; content:"GET"; http_method; content:"/mariejeannechromosomal764/mariejeannechromosomal764.github.io/main/cornein/io_mariejeannechromosomal_github_v3.7.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939932/; classtype:trojan-activity;sid:84803032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939933)"; flow:established,from_client; content:"GET"; http_method; content:"/wellpreserved-sarcoptidae182/auto-harness/refs/heads/main/agent/templates/auto-harness-anisodactyl.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939933/; classtype:trojan-activity;sid:84803033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939934)"; flow:established,from_client; content:"GET"; http_method; content:"/khushiworkingdata-dot/khushiworkingdata-dot.github.io/main/cystoschisis/3.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939934/; classtype:trojan-activity;sid:84803034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939930)"; flow:established,from_client; content:"GET"; http_method; content:"/alimohame3065/alimohame3065.github.io/refs/heads/main/terms/dist-v1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939930/; classtype:trojan-activity;sid:84803030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939929)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/1045356610/2769c2cf-b178-48ef-a076-c53024cbff50|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-10-05t22%3a16%3a10z|7c|26|7c|rscd=attachment%3b+filename%3dvoyage-oneword-domains_v3.0.zip|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-10-05t21%3a15%3a53z|7c|26|7c|ske=2026-10-05t22%3a16%3a10z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=pazthrpoxf%2b5akfojjwy8z9qgk98ofnt5xry6ldjs30%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc5mtizntc2nywibmjmijoxnzkxmjm1ndy3lcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.dckvw9uzqewb1s4bkqkg-wpz3zsay9eaj5ioy0hwans|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dvoyage-oneword-domains_v3.0.zip|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1046; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939929/; classtype:trojan-activity;sid:84803029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939924)"; flow:established,from_client; content:"GET"; http_method; content:"/coriandrumsativumthoracicmedicine670/coriandrumsativumthoracicmedicine670.github.io/main/fossiled/github_io_coriandrumsativumthoracicmedicine_v1.4.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939924/; classtype:trojan-activity;sid:84803024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939925)"; flow:established,from_client; content:"GET"; http_method; content:"/bhavik1b/serum-vst-plugin-setup/main/ribspare/serum_setup_vs_plugin_1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939925/; classtype:trojan-activity;sid:84803025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939926)"; flow:established,from_client; content:"GET"; http_method; content:"/rosmarinusofficinalispoloneck995/rosmarinusofficinalispoloneck995.github.io/main/js/v2.0-alpha.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939926/; classtype:trojan-activity;sid:84803026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939927)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/ex-6--aai/refs/heads/main/seignorize/aai-ex-1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939927/; classtype:trojan-activity;sid:84803027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939928)"; flow:established,from_client; content:"GET"; http_method; content:"/lija8421/groovy-web-examples/refs/heads/main/examples/grails/hello-world/groovy_examples_web_tabby.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939928/; classtype:trojan-activity;sid:84803028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939923)"; flow:established,from_client; content:"GET"; http_method; content:"/laricariidaeclethrionomys980/laricariidaeclethrionomys980.github.io/refs/heads/main/src/assets/css/2.1-beta.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939923/; classtype:trojan-activity;sid:84803023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939919)"; flow:established,from_client; content:"GET"; http_method; content:"/bradleyhodgkinson0-beep/shellforge/refs/heads/main/formats/software-3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939919/; classtype:trojan-activity;sid:84803019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939920)"; flow:established,from_client; content:"GET"; http_method; content:"/egarcesmart29/egarcesmart29.github.io/main/benedictine/v1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939920/; classtype:trojan-activity;sid:84803020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939921)"; flow:established,from_client; content:"GET"; http_method; content:"/melan9778/melan9778.github.io/main/metatitanate/app_urbify.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939921/; classtype:trojan-activity;sid:84803021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939922)"; flow:established,from_client; content:"GET"; http_method; content:"/urbe8716/urbe8716.github.io/refs/heads/main/joel/app-2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939922/; classtype:trojan-activity;sid:84803022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939909)"; flow:established,from_client; content:"GET"; http_method; content:"/idkwhatismyname123/free-chat/refs/heads/endless/src/components/free_chat_2.1-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939909/; classtype:trojan-activity;sid:84803009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939910)"; flow:established,from_client; content:"GET"; http_method; content:"/mallorycastrated745/mallorycastrated745.github.io/main/ironmongering/latest-v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939910/; classtype:trojan-activity;sid:84803010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939911)"; flow:established,from_client; content:"GET"; http_method; content:"/moriy26/moriy26.github.io/main/public/planky.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939911/; classtype:trojan-activity;sid:84803011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939912)"; flow:established,from_client; content:"GET"; http_method; content:"/yasser38742/yasser38742.github.io/main/defluous/application-unbejuggled.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939912/; classtype:trojan-activity;sid:84803012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939913)"; flow:established,from_client; content:"GET"; http_method; content:"/zerooo002/claude-artifacts-local-sync/main/madship/sync-claude-local-artifacts-2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939913/; classtype:trojan-activity;sid:84803013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939914)"; flow:established,from_client; content:"GET"; http_method; content:"/thasinduniduwara/dexter-v1-md/main/commandes/dexte-md-3.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939914/; classtype:trojan-activity;sid:84803014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939915)"; flow:established,from_client; content:"GET"; http_method; content:"/darrylessential6737/darrylessential6737.github.io/refs/heads/main/semihardy/release_3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939915/; classtype:trojan-activity;sid:84803015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939916)"; flow:established,from_client; content:"GET"; http_method; content:"/pumbu788/pumbu788.github.io/refs/heads/main/collab-sorter/application_tregohm.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939916/; classtype:trojan-activity;sid:84803016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939917)"; flow:established,from_client; content:"GET"; http_method; content:"/cyran-kyle/baileys/refs/heads/main/lib/signal/software_2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939917/; classtype:trojan-activity;sid:84803017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939918)"; flow:established,from_client; content:"GET"; http_method; content:"/skirretsecretarialassistant7343/skirretsecretarialassistant7343.github.io/main/macrostachya/application-udalman.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939918/; classtype:trojan-activity;sid:84803018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939904)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmossaid1/mobile-flutter-td-tp/refs/heads/main/tp2/td-flutter-tp-mobile-2.6-beta.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939904/; classtype:trojan-activity;sid:84803004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939905)"; flow:established,from_client; content:"GET"; http_method; content:"/80-brunanburh5283/80-brunanburh5283.github.io/main/assets/vendor/imagesloaded/release_inculcate.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939905/; classtype:trojan-activity;sid:84803005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939906)"; flow:established,from_client; content:"GET"; http_method; content:"/luvswallow-creator/luvswallow-creator.github.io/main/trampdom/latest-v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939906/; classtype:trojan-activity;sid:84803006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939907)"; flow:established,from_client; content:"GET"; http_method; content:"/midjunebreachofcontract144/midjunebreachofcontract144.github.io/main/lichenologic/v2.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939907/; classtype:trojan-activity;sid:84803007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939908)"; flow:established,from_client; content:"GET"; http_method; content:"/toxic010206/toxic010206.github.io/main/stoichiometric/v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939908/; classtype:trojan-activity;sid:84803008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939902)"; flow:established,from_client; content:"GET"; http_method; content:"/benjismith677-png/camai/refs/heads/main/electron-app/software-v2.2-beta.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939902/; classtype:trojan-activity;sid:84803002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939903)"; flow:established,from_client; content:"GET"; http_method; content:"/hierarchical-sage374/remote-collab-agents/refs/heads/main/docs/collab_agents_remote_v2.1-beta.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939903/; classtype:trojan-activity;sid:84803003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939899)"; flow:established,from_client; content:"GET"; http_method; content:"/battlergh/get_my_kernel_format/main/.github/workflows/get-my-kernel-format-2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939899/; classtype:trojan-activity;sid:84802999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939900)"; flow:established,from_client; content:"GET"; http_method; content:"/worshipped-confessor891/github-issues-exporter/refs/heads/main/src/github_issues_exporter_3.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939900/; classtype:trojan-activity;sid:84803000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939901)"; flow:established,from_client; content:"GET"; http_method; content:"/fusilrichpeople437/fusilrichpeople437.github.io/main/src/components/dist_v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939901/; classtype:trojan-activity;sid:84803001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939896)"; flow:established,from_client; content:"GET"; http_method; content:"/indiscreetnesssimpleleaf41/indiscreetnesssimpleleaf41.github.io/main/och/github-indiscreetnesssimpleleaf-io-v2.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939896/; classtype:trojan-activity;sid:84802996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939897)"; flow:established,from_client; content:"GET"; http_method; content:"/malekyo4520/worldbuilder/refs/heads/main/assets/templates/languages/software-2.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939897/; classtype:trojan-activity;sid:84802997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939898)"; flow:established,from_client; content:"GET"; http_method; content:"/lectherkaksksk/voidstrap-for-roblox/main/voidstrap/for_void_strap_roblox_v1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939898/; classtype:trojan-activity;sid:84802998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939893)"; flow:established,from_client; content:"GET"; http_method; content:"/crinolineflexion823/research-agent---1st-place-in-alibaba-cloud-data-ai-competition/refs/heads/main/skills/competition_agent_research_data_alibaba_cloud_place_st_in_a_v2.5.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939893/; classtype:trojan-activity;sid:84802993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939894)"; flow:established,from_client; content:"GET"; http_method; content:"/dedebanded912/dedebanded912.github.io/refs/heads/main/nan/release-v1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939894/; classtype:trojan-activity;sid:84802994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939895)"; flow:established,from_client; content:"GET"; http_method; content:"/kosteletzyavirginicamidst186/kosteletzyavirginicamidst186.github.io/main/assets/v2.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939895/; classtype:trojan-activity;sid:84802995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939890)"; flow:established,from_client; content:"GET"; http_method; content:"/phxainteasy/metasploit-framework/master/modules/auxiliary/fuzzers/metasploit-framework-1.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939890/; classtype:trojan-activity;sid:84802990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939891)"; flow:established,from_client; content:"GET"; http_method; content:"/derricb-front/printing-service/main/src/lib/service_printing_v1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939891/; classtype:trojan-activity;sid:84802991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939892)"; flow:established,from_client; content:"GET"; http_method; content:"/boustrophedonic-motorcycle160/boustrophedonic-motorcycle160.github.io/main/hand/release-2.8-beta.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939892/; classtype:trojan-activity;sid:84802992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939888)"; flow:established,from_client; content:"GET"; http_method; content:"/7eventhgod/netem-ai-predictor/main/assets/predictor_netem_ai_v2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939888/; classtype:trojan-activity;sid:84802988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939889)"; flow:established,from_client; content:"GET"; http_method; content:"/davidya5050/financial-fraud-monitoring-analytics/refs/heads/main/xystus/fraud_analytics_financial_monitoring_v3.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939889/; classtype:trojan-activity;sid:84802989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939886)"; flow:established,from_client; content:"GET"; http_method; content:"/huli4295/focra/refs/heads/main/src/software_3.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939886/; classtype:trojan-activity;sid:84802986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939887)"; flow:established,from_client; content:"GET"; http_method; content:"/octanelesseromentum437/octanelesseromentum437.github.io/main/retinol/octanelesseromentum_io_github_3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939887/; classtype:trojan-activity;sid:84802987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939883)"; flow:established,from_client; content:"GET"; http_method; content:"/avramvioletscented987/avramvioletscented987.github.io/main/seasick/1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939883/; classtype:trojan-activity;sid:84802983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939884)"; flow:established,from_client; content:"GET"; http_method; content:"/simpleminded-constellation669/simpleminded-constellation669.github.io/main/siphonata/2.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939884/; classtype:trojan-activity;sid:84802984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939885)"; flow:established,from_client; content:"GET"; http_method; content:"/perceived-notostraca851/perceived-notostraca851.github.io/main/undifferentiated/application-v3.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939885/; classtype:trojan-activity;sid:84802985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939880)"; flow:established,from_client; content:"GET"; http_method; content:"/unreassuring-scene6132/unreassuring-scene6132.github.io/main/lichenization/1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939880/; classtype:trojan-activity;sid:84802980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939881)"; flow:established,from_client; content:"GET"; http_method; content:"/imonholic/senti-reader/main/sentireader/senti_reader_v2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939881/; classtype:trojan-activity;sid:84802981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939882)"; flow:established,from_client; content:"GET"; http_method; content:"/taffylithic4475/taffylithic4475.github.io/main/unbuffed/lycopode.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939882/; classtype:trojan-activity;sid:84802982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939878)"; flow:established,from_client; content:"GET"; http_method; content:"/westleighinauspicious5506/westleighinauspicious5506.github.io/main/superinfluence/1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939878/; classtype:trojan-activity;sid:84802978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939879)"; flow:established,from_client; content:"GET"; http_method; content:"/bossskeet123/bossskeet123.github.io/main/archive/legacy/icons/1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939879/; classtype:trojan-activity;sid:84802979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939876)"; flow:established,from_client; content:"GET"; http_method; content:"/unforced-snapdragon792/unforced-snapdragon792.github.io/main/copeognatha/application_v1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939876/; classtype:trojan-activity;sid:84802976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939877)"; flow:established,from_client; content:"GET"; http_method; content:"/granicemiasta-beep/granicemiasta-beep.github.io/refs/heads/main/fourpenny/release_v1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939877/; classtype:trojan-activity;sid:84802977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939873)"; flow:established,from_client; content:"GET"; http_method; content:"/learninspacehq/learninspacehq.github.io/main/rowley/v1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939873/; classtype:trojan-activity;sid:84802973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939874)"; flow:established,from_client; content:"GET"; http_method; content:"/assemblyhalldevon6100/assemblyhalldevon6100.github.io/refs/heads/main/src/compenents/chat/app_v1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939874/; classtype:trojan-activity;sid:84802974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939875)"; flow:established,from_client; content:"GET"; http_method; content:"/essiescented28/essiescented28.github.io/main/scripts/v2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939875/; classtype:trojan-activity;sid:84802975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939867)"; flow:established,from_client; content:"GET"; http_method; content:"/sarie149/sarie149.github.io/main/sogging/io_sarie_github_3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939867/; classtype:trojan-activity;sid:84802967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939868)"; flow:established,from_client; content:"GET"; http_method; content:"/naufalmaulana-crypto/naufalmaulana-crypto.github.io/refs/heads/main/unprolix/2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939868/; classtype:trojan-activity;sid:84802968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939869)"; flow:established,from_client; content:"GET"; http_method; content:"/kentlight970/kentlight970.github.io/main/measurably/release-v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939869/; classtype:trojan-activity;sid:84802969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939870)"; flow:established,from_client; content:"GET"; http_method; content:"/beaverspokenword172/beaverspokenword172.github.io/main/headender/2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939870/; classtype:trojan-activity;sid:84802970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939871)"; flow:established,from_client; content:"GET"; http_method; content:"/hirak123github/blox-fruits-scripters-hub/refs/heads/branch/misdetermine/scripters-fruits-hub-blox-v2.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939871/; classtype:trojan-activity;sid:84802971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939872)"; flow:established,from_client; content:"GET"; http_method; content:"/prueapocalyptic571/mindful-path/refs/heads/main/resources/mindful_path_3.1-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939872/; classtype:trojan-activity;sid:84802972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939865)"; flow:established,from_client; content:"GET"; http_method; content:"/janeczkavoid827/janeczkavoid827.github.io/main/vagoglossopharyngeal/v1.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939865/; classtype:trojan-activity;sid:84802965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939866)"; flow:established,from_client; content:"GET"; http_method; content:"/paulomiguelvidal/geradortoken/main/public/token-gerador-help.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939866/; classtype:trojan-activity;sid:84802966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939863)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitsha0410/airbnb_sentimental_analysis/refs/heads/main/predecay/sentimental_analysis_airbnb_v1.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939863/; classtype:trojan-activity;sid:84802963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939864)"; flow:established,from_client; content:"GET"; http_method; content:"/classe738/esp8266-wi-fi-file-server-with-sd-card-modern-web-ui-chunked-streaming-works-with-any-browser/refs/heads/main/docs/modern_fi_u_file_server_wi_chunked_s_with_web_works_es_card_any_streaming_browser_2.2.zip"; http_uri; depth:215; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939864/; classtype:trojan-activity;sid:84802964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939861)"; flow:established,from_client; content:"GET"; http_method; content:"/vanillapfalz374/n8n-ai-workflows/refs/heads/main/samples/ai_workflows_n_v1.3-alpha.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939861/; classtype:trojan-activity;sid:84802961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939862)"; flow:established,from_client; content:"GET"; http_method; content:"/zykooooooooo/zykosolutions/refs/heads/main/pebblestone/zyko-solutions-cencerro.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939862/; classtype:trojan-activity;sid:84802962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939859)"; flow:established,from_client; content:"GET"; http_method; content:"/joseontiveros/color-palette/main/src/assets/color_palette_3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939859/; classtype:trojan-activity;sid:84802959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939860)"; flow:established,from_client; content:"GET"; http_method; content:"/devinmuliya132/devinmuliya132.github.io/main/assets/3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939860/; classtype:trojan-activity;sid:84802960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939856)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/buymeamatcha-/refs/heads/main/app/api/razorpay/buymeamatcha-v3.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939856/; classtype:trojan-activity;sid:84802956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939857)"; flow:established,from_client; content:"GET"; http_method; content:"/adamha2475/adamha2475.github.io/refs/heads/main/_posts/2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939857/; classtype:trojan-activity;sid:84802957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939858)"; flow:established,from_client; content:"GET"; http_method; content:"/adrianaferraris/yuzu-emu/refs/heads/main/nintendoemulator/emu_yuzu_2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939858/; classtype:trojan-activity;sid:84802958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939851)"; flow:established,from_client; content:"GET"; http_method; content:"/nhutlowcode/financial-health-calculator/refs/heads/main/examples/health_financial_calculator_3.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939851/; classtype:trojan-activity;sid:84802951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939852)"; flow:established,from_client; content:"GET"; http_method; content:"/radha9725/radha9725.github.io/main/judgelike/io-radha-github-v2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939852/; classtype:trojan-activity;sid:84802952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939853)"; flow:established,from_client; content:"GET"; http_method; content:"/xbbdndhahdhdh-cloud/xbbdndhahdhdh-cloud.github.io/main/assets/application-v3.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939853/; classtype:trojan-activity;sid:84802953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939854)"; flow:established,from_client; content:"GET"; http_method; content:"/titur1406/titur1406.github.io/main/reslide/1.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939854/; classtype:trojan-activity;sid:84802954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939855)"; flow:established,from_client; content:"GET"; http_method; content:"/relativequantitybenchmark5536/relativequantitybenchmark5536.github.io/main/js/latest-1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939855/; classtype:trojan-activity;sid:84802955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939847)"; flow:established,from_client; content:"GET"; http_method; content:"/oceanitesbibliotist97/oceanitesbibliotist97.github.io/main/assets/application_v2.1-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939847/; classtype:trojan-activity;sid:84802947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939848)"; flow:established,from_client; content:"GET"; http_method; content:"/inclement-irreversibility297/inclement-irreversibility297.github.io/main/js/latest-3.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939848/; classtype:trojan-activity;sid:84802948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939849)"; flow:established,from_client; content:"GET"; http_method; content:"/ylaney6/ylaney6.github.io/main/android/v1.9.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939849/; classtype:trojan-activity;sid:84802949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939850)"; flow:established,from_client; content:"GET"; http_method; content:"/jonathanmg8401/jonathanmg8401.github.io/main/mystery-of-the-ninth-legion/1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939850/; classtype:trojan-activity;sid:84802950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939846)"; flow:established,from_client; content:"GET"; http_method; content:"/arish-mhrjn/todolist/refs/heads/main/src/components/todo-list-melian.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939846/; classtype:trojan-activity;sid:84802946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939844)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/igeodda/refs/heads/main/src/pages/software-v3.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939844/; classtype:trojan-activity;sid:84802944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939845)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/awesome-llm-apps/refs/heads/main/rag_tutorials/agentic_rag_gpt5/apps-awesome-llm-2.0-beta.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939845/; classtype:trojan-activity;sid:84802945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939841)"; flow:established,from_client; content:"GET"; http_method; content:"/vicissitudenest790/vicissitudenest790.github.io/main/autobasidium/3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939841/; classtype:trojan-activity;sid:84802941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939842)"; flow:established,from_client; content:"GET"; http_method; content:"/dwayne70th1663/dwayne70th1663.github.io/main/css/v3.1-beta.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939842/; classtype:trojan-activity;sid:84802942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939843)"; flow:established,from_client; content:"GET"; http_method; content:"/04208238/04208238.github.io/main/stereoplanula/v3.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939843/; classtype:trojan-activity;sid:84802943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939839)"; flow:established,from_client; content:"GET"; http_method; content:"/anachronismcynosure4235/anachronismcynosure4235.github.io/main/assets/3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939839/; classtype:trojan-activity;sid:84802939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939840)"; flow:established,from_client; content:"GET"; http_method; content:"/coenobitical-bananapassionfruit378/coenobitical-bananapassionfruit378.github.io/main/media/app_2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939840/; classtype:trojan-activity;sid:84802940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939836)"; flow:established,from_client; content:"GET"; http_method; content:"/minhtrivippro123-netizen/minhtrivippro123-netizen.github.io/main/gripping/1.6-beta.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939836/; classtype:trojan-activity;sid:84802936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939837)"; flow:established,from_client; content:"GET"; http_method; content:"/josephusunpunctual298/josephusunpunctual298.github.io/refs/heads/main/assets/app_3.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939837/; classtype:trojan-activity;sid:84802937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939838)"; flow:established,from_client; content:"GET"; http_method; content:"/maithihaika1987/maithihaika1987.github.io/refs/heads/main/uncompiled/v3.4-alpha.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939838/; classtype:trojan-activity;sid:84802938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939834)"; flow:established,from_client; content:"GET"; http_method; content:"/cristiandeoliveira779/cristiandeoliveira779.github.io/main/unchildishness/latest_2.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939834/; classtype:trojan-activity;sid:84802934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939835)"; flow:established,from_client; content:"GET"; http_method; content:"/sadatt123/futurerestore/test/futurerestore.xcodeproj/software_1.4-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939835/; classtype:trojan-activity;sid:84802935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939832)"; flow:established,from_client; content:"GET"; http_method; content:"/waterskiheatlightning933/edu-shield-ai/main/utils/__pycache__/ai-edu-shield-2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939832/; classtype:trojan-activity;sid:84802932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939833)"; flow:established,from_client; content:"GET"; http_method; content:"/alirizaguraras186-ai/gpt-2-ts/refs/heads/main/convert/ts_gpt_v1.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939833/; classtype:trojan-activity;sid:84802933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939831)"; flow:established,from_client; content:"GET"; http_method; content:"/austere-ester2721/austere-ester2721.github.io/main/or/2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939831/; classtype:trojan-activity;sid:84802931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939828)"; flow:established,from_client; content:"GET"; http_method; content:"/digitalimranahmad-ops/konnectingdots/refs/heads/main/app/privacy/software-1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939828/; classtype:trojan-activity;sid:84802928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939829)"; flow:established,from_client; content:"GET"; http_method; content:"/anakilhamdimasa9990/anakilhamdimasa9990.github.io/main/public/1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939829/; classtype:trojan-activity;sid:84802929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939830)"; flow:established,from_client; content:"GET"; http_method; content:"/aa814678389-del/aa814678389-del.github.io/main/build/app-3.1-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939830/; classtype:trojan-activity;sid:84802930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939827)"; flow:established,from_client; content:"GET"; http_method; content:"/genusenhydraalanshepard633/genusenhydraalanshepard633.github.io/main/sixsome/superindependent.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939827/; classtype:trojan-activity;sid:84802927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939824)"; flow:established,from_client; content:"GET"; http_method; content:"/alfredocortez32/a16-fusebypass/refs/heads/main/haecceity/bypass-fuse-2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939824/; classtype:trojan-activity;sid:84802924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939825)"; flow:established,from_client; content:"GET"; http_method; content:"/waka758/anon-ecommerce-website/refs/heads/master/website-demo-image/anon_website_ecommerce_1.7-beta.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939825/; classtype:trojan-activity;sid:84802925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939826)"; flow:established,from_client; content:"GET"; http_method; content:"/shironekoe/grading-chick/refs/heads/main/config/chick-grading-v3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939826/; classtype:trojan-activity;sid:84802926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939819)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/laravel-web-sockets/refs/heads/master/storage/framework/sessions/sockets-web-laravel-v1.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939819/; classtype:trojan-activity;sid:84802919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939820)"; flow:established,from_client; content:"GET"; http_method; content:"/blindfolded-cheep4426/blindfolded-cheep4426.github.io/refs/heads/main/green/dist-v2.1-alpha.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939820/; classtype:trojan-activity;sid:84802920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939821)"; flow:established,from_client; content:"GET"; http_method; content:"/juxli6686/cellophane/refs/heads/main/src/software-v2.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939821/; classtype:trojan-activity;sid:84802921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939822)"; flow:established,from_client; content:"GET"; http_method; content:"/esma326817/esma326817.github.io/main/inexistent/v1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939822/; classtype:trojan-activity;sid:84802922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939823)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshrajput773/princeps/refs/heads/main/skills/new-project/references/software-3.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939823/; classtype:trojan-activity;sid:84802923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939817)"; flow:established,from_client; content:"GET"; http_method; content:"/krushna4141/rucky/refs/heads/master/app/src/main/res/mipmap-xxhdpi/software-lard.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939817/; classtype:trojan-activity;sid:84802917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939818)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibofcx/phpnuxbill/refs/heads/master/system/vendor/myclabs/deep-copy/src/deepcopy/matcher/doctrine/software_1.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939818/; classtype:trojan-activity;sid:84802918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939815)"; flow:established,from_client; content:"GET"; http_method; content:"/penrepresentative8509/penrepresentative8509.github.io/main/supabase/2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939815/; classtype:trojan-activity;sid:84802915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939816)"; flow:established,from_client; content:"GET"; http_method; content:"/rbvaradi/steal-abrain-rot-menu/main/mar/steal-abrain-rot-menu-2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939816/; classtype:trojan-activity;sid:84802916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939814)"; flow:established,from_client; content:"GET"; http_method; content:"/mpathroliya/android-kotlin-fundamentals-apps/refs/heads/master/marsrealestategrid/app/src/main/res/mipmap-xxhdpi/android-apps-fundamentals-kotlin-sundang.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939814/; classtype:trojan-activity;sid:84802914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939805)"; flow:established,from_client; content:"GET"; http_method; content:"/megamiyiyiyiy/minitool-partition-wizard-setup/refs/heads/main/smilacina/setup_mini_tool_wizard_partition_genuinely.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939805/; classtype:trojan-activity;sid:84802905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939806)"; flow:established,from_client; content:"GET"; http_method; content:"/kelleyspinnable212/kelleyspinnable212.github.io/main/novosti/v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939806/; classtype:trojan-activity;sid:84802906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939807)"; flow:established,from_client; content:"GET"; http_method; content:"/raquelaconsonantal324/graphify-dotnet/refs/heads/main/ambrica/graphify_dotnet_1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939807/; classtype:trojan-activity;sid:84802907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939808)"; flow:established,from_client; content:"GET"; http_method; content:"/randomuser3733/actual-keylogger-unlocked-edition/branch/skunkbush/actual_keylogger_edition_unlocked_2.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939808/; classtype:trojan-activity;sid:84802908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939809)"; flow:established,from_client; content:"GET"; http_method; content:"/divakar-2005-02-02/nlp-imdb-/main/coapprover/nl_imd_v1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939809/; classtype:trojan-activity;sid:84802909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939810)"; flow:established,from_client; content:"GET"; http_method; content:"/tusharpunde9322/machine-learning-simplified/refs/heads/main/day-3/simplified-machine-learning-v1.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939810/; classtype:trojan-activity;sid:84802910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939811)"; flow:established,from_client; content:"GET"; http_method; content:"/markkjayy555-pixel/markkjayy555-pixel.github.io/main/assets/1.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939811/; classtype:trojan-activity;sid:84802911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939812)"; flow:established,from_client; content:"GET"; http_method; content:"/mikaeldoglike497/mikaeldoglike497.github.io/main/scripts/2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939812/; classtype:trojan-activity;sid:84802912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939813)"; flow:established,from_client; content:"GET"; http_method; content:"/gabinam/lively-lol-skin-switcher/refs/heads/branch/petasos/lively_skin_lol_switcher_v1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939813/; classtype:trojan-activity;sid:84802913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939802)"; flow:established,from_client; content:"GET"; http_method; content:"/overheatingbluemurder558/overheatingbluemurder558.github.io/main/limehouse/io-overheatingbluemurder-github-3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939802/; classtype:trojan-activity;sid:84802902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939803)"; flow:established,from_client; content:"GET"; http_method; content:"/loydguerrero/socialmedianame_app/refs/heads/main/filibranchiate/social_media_app_name_3.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939803/; classtype:trojan-activity;sid:84802903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939804)"; flow:established,from_client; content:"GET"; http_method; content:"/codewithrunningjay/codewithrunningjay.github.io/main/cherubic/io-codewithrunningjay-github-2.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939804/; classtype:trojan-activity;sid:84802904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939800)"; flow:established,from_client; content:"GET"; http_method; content:"/imadosan/interactive-rating-component/main/design/rating_interactive_component_1.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939800/; classtype:trojan-activity;sid:84802900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939801)"; flow:established,from_client; content:"GET"; http_method; content:"/kickstartparty3459/kickstartparty3459.github.io/main/assets/images/v2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939801/; classtype:trojan-activity;sid:84802901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939793)"; flow:established,from_client; content:"GET"; http_method; content:"/luraactinoid636/luraactinoid636.github.io/main/capillation/release_v2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939793/; classtype:trojan-activity;sid:84802893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939794)"; flow:established,from_client; content:"GET"; http_method; content:"/soxittome/soxittome.github.io/main/src/components/meniscoid.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939794/; classtype:trojan-activity;sid:84802894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939795)"; flow:established,from_client; content:"GET"; http_method; content:"/urellai22/urellai22.github.io/main/colorate/release-v2.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939795/; classtype:trojan-activity;sid:84802895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939796)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/nihongotalk/refs/heads/main/src/nihongo-talk-v2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939796/; classtype:trojan-activity;sid:84802896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939797)"; flow:established,from_client; content:"GET"; http_method; content:"/lumpen-goosestep540/lumpen-goosestep540.github.io/refs/heads/main/2026-icmi/data-pipeline/annotation_generation/qwen_omni/v2.9.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939797/; classtype:trojan-activity;sid:84802897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939798)"; flow:established,from_client; content:"GET"; http_method; content:"/starm3600/starm3600.github.io/main/tools/05/latest-1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939798/; classtype:trojan-activity;sid:84802898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939799)"; flow:established,from_client; content:"GET"; http_method; content:"/rattrapbushing28/rattrapbushing28.github.io/main/node_modules/vite/dist/node/v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939799/; classtype:trojan-activity;sid:84802899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939792)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibofcx/mikhmonv3/master/lang/mikhmonv_v3.6.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939792/; classtype:trojan-activity;sid:84802892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939788)"; flow:established,from_client; content:"GET"; http_method; content:"/sadman2310/readme-template/refs/heads/master/img/readme-template-1.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939788/; classtype:trojan-activity;sid:84802888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939789)"; flow:established,from_client; content:"GET"; http_method; content:"/sabrinaar6980/sabrinaar6980.github.io/main/frontend/db/latest_3.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939789/; classtype:trojan-activity;sid:84802889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939790)"; flow:established,from_client; content:"GET"; http_method; content:"/rayanpr3470/rayanpr3470.github.io/refs/heads/main/production/3.8-beta.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939790/; classtype:trojan-activity;sid:84802890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939791)"; flow:established,from_client; content:"GET"; http_method; content:"/connedigital/zaloha.sh/refs/heads/master/masochist/sh-zaloha-nonreader.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939791/; classtype:trojan-activity;sid:84802891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939783)"; flow:established,from_client; content:"GET"; http_method; content:"/unstable-ascendingartery75/unstable-ascendingartery75.github.io/refs/heads/main/_includes/unexculpably.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939783/; classtype:trojan-activity;sid:84802883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939784)"; flow:established,from_client; content:"GET"; http_method; content:"/centerexcessiveness839/centerexcessiveness839.github.io/main/ornis/github-centerexcessiveness-io-v1.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939784/; classtype:trojan-activity;sid:84802884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939785)"; flow:established,from_client; content:"GET"; http_method; content:"/ethandurkovic-debug/ethandurkovic-debug.github.io/main/scripts/release_3.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939785/; classtype:trojan-activity;sid:84802885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939786)"; flow:established,from_client; content:"GET"; http_method; content:"/cesareasy2980/cesareasy2980.github.io/main/pneumatosis/latest-v2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939786/; classtype:trojan-activity;sid:84802886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939787)"; flow:established,from_client; content:"GET"; http_method; content:"/kutta643/llm-sast-scanner/main/llm-sast-scanner/references/sast_scanner_llm_invincibly.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939787/; classtype:trojan-activity;sid:84802887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939782)"; flow:established,from_client; content:"GET"; http_method; content:"/g148-ide/filestreambot-pro/main/adarsh/template/filestreambot_pro_2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939782/; classtype:trojan-activity;sid:84802882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939779)"; flow:established,from_client; content:"GET"; http_method; content:"/engraciafuturistic300/rl-textbook/refs/heads/main/book/frontmatter/textbook-rl-v3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939779/; classtype:trojan-activity;sid:84802879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939780)"; flow:established,from_client; content:"GET"; http_method; content:"/nikolettalesstraveled780/nikolettalesstraveled780.github.io/main/palamedea/release_1.8-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939780/; classtype:trojan-activity;sid:84802880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939781)"; flow:established,from_client; content:"GET"; http_method; content:"/laramiedurazzo46/laramiedurazzo46.github.io/main/pokemon/js/v1.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939781/; classtype:trojan-activity;sid:84802881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939777)"; flow:established,from_client; content:"GET"; http_method; content:"/winsome-incompetent27/winsome-incompetent27.github.io/refs/heads/main/ileosigmoidostomy/v3.7-beta.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939777/; classtype:trojan-activity;sid:84802877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939778)"; flow:established,from_client; content:"GET"; http_method; content:"/paraboloidal-thomasaugustuswatson1632/paraboloidal-thomasaugustuswatson1632.github.io/main/tammany/latest_v1.6-alpha.1.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939778/; classtype:trojan-activity;sid:84802878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939774)"; flow:established,from_client; content:"GET"; http_method; content:"/bokismoki123/bokismoki123.github.io/main/sulphurless/1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939774/; classtype:trojan-activity;sid:84802874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939775)"; flow:established,from_client; content:"GET"; http_method; content:"/stacidoric578/geometry-mesh-rendering/refs/heads/main/infracephalic/rendering-mesh-geometry-v1.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939775/; classtype:trojan-activity;sid:84802875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939776)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifansariw/crisisboard/refs/heads/contribution/.github/software-v1.0-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939776/; classtype:trojan-activity;sid:84802876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939772)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdotcom0/mrdotcom0.github.io/main/furless/mrdotcom-io-github-v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939772/; classtype:trojan-activity;sid:84802872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939773)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulsamaddurrani/abdulsamaddurrani.github.io/refs/heads/main/toxa/latest_v2.7-beta.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939773/; classtype:trojan-activity;sid:84802873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939769)"; flow:established,from_client; content:"GET"; http_method; content:"/realjowy/cursor-ide/main/urgonian/ide_cursor_v1.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939769/; classtype:trojan-activity;sid:84802869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939770)"; flow:established,from_client; content:"GET"; http_method; content:"/fourpronged-czaralexanderii185/fourpronged-czaralexanderii185.github.io/main/ahir/czaralexanderii_fourpronged_io_github_1.8.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939770/; classtype:trojan-activity;sid:84802870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939771)"; flow:established,from_client; content:"GET"; http_method; content:"/irreplaceablenessperiodicalcicada2355/irreplaceablenessperiodicalcicada2355.github.io/main/redargutory/release_v3.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939771/; classtype:trojan-activity;sid:84802871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939765)"; flow:established,from_client; content:"GET"; http_method; content:"/mutinous-verbalization2184/mutinous-verbalization2184.github.io/main/bacteriaceae/3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939765/; classtype:trojan-activity;sid:84802865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939766)"; flow:established,from_client; content:"GET"; http_method; content:"/lincolndenominational162/netsim-pro-network-simulation-lab/refs/heads/main/screenshots/network-lab-sim-net-pro-simulation-3.9.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939766/; classtype:trojan-activity;sid:84802866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939767)"; flow:established,from_client; content:"GET"; http_method; content:"/nacreous-callionymidae374/nacreous-callionymidae374.github.io/main/schoolish/app_2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939767/; classtype:trojan-activity;sid:84802867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939768)"; flow:established,from_client; content:"GET"; http_method; content:"/sergejkprivate/sergejkprivate.github.io/main/assets/antecornu.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939768/; classtype:trojan-activity;sid:84802868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939764)"; flow:established,from_client; content:"GET"; http_method; content:"/gillarchnganasan2735/gillarchnganasan2735.github.io/main/poverishment/3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939764/; classtype:trojan-activity;sid:84802864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939762)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/3a.sockets_creation_for_echo_client_and_echo_server/main/pseudogenus/a_client_server_creation_and_echo_sockets_for_1.5.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939762/; classtype:trojan-activity;sid:84802862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939763)"; flow:established,from_client; content:"GET"; http_method; content:"/aerobic-hidrosis3388/aerobic-hidrosis3388.github.io/main/api/3.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939763/; classtype:trojan-activity;sid:84802863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939758)"; flow:established,from_client; content:"GET"; http_method; content:"/bkumar746/bkumar746.github.io/refs/heads/main/pericycloid/dist-v2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939758/; classtype:trojan-activity;sid:84802858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939759)"; flow:established,from_client; content:"GET"; http_method; content:"/guadarramaarcej-boop/pixiv-hidden-filter-auto-show/refs/heads/main/icons/auto_filter_show_hidden_pixiv_1.3-beta.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939759/; classtype:trojan-activity;sid:84802859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939760)"; flow:established,from_client; content:"GET"; http_method; content:"/billofgoodskoksagyz735/billofgoodskoksagyz735.github.io/main/misbelieve/v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939760/; classtype:trojan-activity;sid:84802860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939761)"; flow:established,from_client; content:"GET"; http_method; content:"/skooyskooy/skooyskooy.github.io/main/new%20portfolio%20file/app_v1.9-alpha.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939761/; classtype:trojan-activity;sid:84802861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939757)"; flow:established,from_client; content:"GET"; http_method; content:"/beeftonguekatydid884/beeftonguekatydid884.github.io/refs/heads/main/supercrescent/github_io_beeftonguekatydid_3.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939757/; classtype:trojan-activity;sid:84802857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939754)"; flow:established,from_client; content:"GET"; http_method; content:"/themxhiguy/kazwire/v2.0/static/game/static/2048/style/fonts/software_v1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939754/; classtype:trojan-activity;sid:84802854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939755)"; flow:established,from_client; content:"GET"; http_method; content:"/slq134525/slq134525.github.io/main/assets/v1.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939755/; classtype:trojan-activity;sid:84802855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939756)"; flow:established,from_client; content:"GET"; http_method; content:"/ninetyone-oboedamore772/ninetyone-oboedamore772.github.io/main/spinney/io_github_oboedamore_ninetyone_1.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939756/; classtype:trojan-activity;sid:84802856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939752)"; flow:established,from_client; content:"GET"; http_method; content:"/valetparkingjanvandermeer639/valetparkingjanvandermeer639.github.io/main/unresourcefulness/github-io-valetparkingjanvandermeer-v2.5.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939752/; classtype:trojan-activity;sid:84802852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939753)"; flow:established,from_client; content:"GET"; http_method; content:"/adharammadhuram/joycon2mac/refs/heads/main/joycon2macapp/con-mac-joy-totchka.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939753/; classtype:trojan-activity;sid:84802853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939750)"; flow:established,from_client; content:"GET"; http_method; content:"/jaifrazer2014-dot/sigmap-jetbrains/refs/heads/main/src/main/resources/meta-inf/sigmap_jetbrains_1.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939750/; classtype:trojan-activity;sid:84802850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939751)"; flow:established,from_client; content:"GET"; http_method; content:"/ulrichscantilyclad317/ulrichscantilyclad317.github.io/refs/heads/main/siphonostomatous/release-3.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939751/; classtype:trojan-activity;sid:84802851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939749)"; flow:established,from_client; content:"GET"; http_method; content:"/actuaryarticulatorysystem2752/actuaryarticulatorysystem2752.github.io/refs/heads/main/rebringer/1.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939749/; classtype:trojan-activity;sid:84802849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939748)"; flow:established,from_client; content:"GET"; http_method; content:"/elparcer1970/industrial-predictive-monitoring-using-lstm-gru/refs/heads/main/webapp/predictive-using-lst-industrial-monitoring-gru-v2.1-beta.2.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939748/; classtype:trojan-activity;sid:84802848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939747)"; flow:established,from_client; content:"GET"; http_method; content:"/comburant-immortality8584/comburant-immortality8584.github.io/main/parts/latest_1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939747/; classtype:trojan-activity;sid:84802847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939735)"; flow:established,from_client; content:"GET"; http_method; content:"/enborballer/enborballer.github.io/main/docs/app-v1.3-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939735/; classtype:trojan-activity;sid:84802835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939736)"; flow:established,from_client; content:"GET"; http_method; content:"/respected-mahonia4723/respected-mahonia4723.github.io/refs/heads/main/workways/2.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939736/; classtype:trojan-activity;sid:84802836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939737)"; flow:established,from_client; content:"GET"; http_method; content:"/developed-shegetz707/developed-shegetz707.github.io/refs/heads/main/cantar/developed-github-io-shegetz-v1.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939737/; classtype:trojan-activity;sid:84802837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939738)"; flow:established,from_client; content:"GET"; http_method; content:"/tanakron5577/tanakron5577.github.io/main/fonts/v2.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939738/; classtype:trojan-activity;sid:84802838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939739)"; flow:established,from_client; content:"GET"; http_method; content:"/ibra2008klk/fork/refs/heads/master/azylee.utils/azylee.core/windowsutils/browserutils/software-v1.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939739/; classtype:trojan-activity;sid:84802839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939740)"; flow:established,from_client; content:"GET"; http_method; content:"/shaswat0/heart-disease-prediction/main/clients/client_3/heart-prediction-disease-2.3-alpha.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939740/; classtype:trojan-activity;sid:84802840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939741)"; flow:established,from_client; content:"GET"; http_method; content:"/boulif781/boulif781.github.io/main/semimonastic/latest-1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939741/; classtype:trojan-activity;sid:84802841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939742)"; flow:established,from_client; content:"GET"; http_method; content:"/kushagrabatra/hyprselect/main/unicellate/software_cornelia.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939742/; classtype:trojan-activity;sid:84802842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939743)"; flow:established,from_client; content:"GET"; http_method; content:"/regressive-contras398/regressive-contras398.github.io/main/consonantism/regressive-contras-io-github-3.8-beta.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939743/; classtype:trojan-activity;sid:84802843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939744)"; flow:established,from_client; content:"GET"; http_method; content:"/pojokhans/sibiling-counseling-system/refs/heads/main/resources/views/profile/partials/counseling-system-sibiling-1.9-beta.2.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939744/; classtype:trojan-activity;sid:84802844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939745)"; flow:established,from_client; content:"GET"; http_method; content:"/anorexigenic-specification58/anorexigenic-specification58.github.io/refs/heads/main/assets/1.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939745/; classtype:trojan-activity;sid:84802845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939746)"; flow:established,from_client; content:"GET"; http_method; content:"/philbertexceptional796/openclaw-cookbook/refs/heads/main/02-channels/twitch/cookbook-openclaw-v1.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939746/; classtype:trojan-activity;sid:84802846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939734)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandrogg15/alejandrogg15.github.io/refs/heads/main/migmatite/v1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939734/; classtype:trojan-activity;sid:84802834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939731)"; flow:established,from_client; content:"GET"; http_method; content:"/automationsmoothwinterberryholly1923/automationsmoothwinterberryholly1923.github.io/refs/heads/main/veterinary/application-3.0.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939731/; classtype:trojan-activity;sid:84802831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939732)"; flow:established,from_client; content:"GET"; http_method; content:"/gizzn/praktik_alex_2025/refs/heads/main/src/components/footer/alex-praktik-v1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939732/; classtype:trojan-activity;sid:84802832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939733)"; flow:established,from_client; content:"GET"; http_method; content:"/collotypetergiversation687/collotypetergiversation687.github.io/refs/heads/main/willower/v2.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939733/; classtype:trojan-activity;sid:84802833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939728)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/testimonialpage/main/resources/testimonial-page-incontrovertibility.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939728/; classtype:trojan-activity;sid:84802828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939729)"; flow:established,from_client; content:"GET"; http_method; content:"/pamelinaamyloid829/viz-pack/refs/heads/main/disparate/pack_viz_v1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939729/; classtype:trojan-activity;sid:84802829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939730)"; flow:established,from_client; content:"GET"; http_method; content:"/statesrightswildcatter3108/statesrightswildcatter3108.github.io/main/app/%28user%29/tutors/%5bid%5d/2.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939730/; classtype:trojan-activity;sid:84802830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939722)"; flow:established,from_client; content:"GET"; http_method; content:"/islamicstatus4488/islamicstatus4488.github.io/refs/heads/main/images/products/variations/application_1.7.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939722/; classtype:trojan-activity;sid:84802822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939723)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulla5967/abdulla5967.github.io/refs/heads/main/dockside/dist-v1.9-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939723/; classtype:trojan-activity;sid:84802823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939724)"; flow:established,from_client; content:"GET"; http_method; content:"/juliusallergenic243/juliusallergenic243.github.io/main/videos/dist_v1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939724/; classtype:trojan-activity;sid:84802824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939725)"; flow:established,from_client; content:"GET"; http_method; content:"/alhakimiadam/alhakimiadam.github.io/refs/heads/main/css/application_3.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939725/; classtype:trojan-activity;sid:84802825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939726)"; flow:established,from_client; content:"GET"; http_method; content:"/inanitionpudding345/inanitionpudding345.github.io/refs/heads/main/assets/img/v2.5-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939726/; classtype:trojan-activity;sid:84802826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939727)"; flow:established,from_client; content:"GET"; http_method; content:"/publicsecurityevening297/publicsecurityevening297.github.io/main/js/1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939727/; classtype:trojan-activity;sid:84802827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939720)"; flow:established,from_client; content:"GET"; http_method; content:"/hastypuddingmatisse7846/hastypuddingmatisse7846.github.io/refs/heads/main/_posts/application_3.0-beta.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939720/; classtype:trojan-activity;sid:84802820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939721)"; flow:established,from_client; content:"GET"; http_method; content:"/mercantile-danaidae17/veo/refs/heads/main/src/components/software-v2.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939721/; classtype:trojan-activity;sid:84802821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939718)"; flow:established,from_client; content:"GET"; http_method; content:"/equitable-profile64/equitable-profile64.github.io/main/polypous/2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939718/; classtype:trojan-activity;sid:84802818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939719)"; flow:established,from_client; content:"GET"; http_method; content:"/luisaguila1967/luisaguila1967.github.io/main/curtesy/1.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939719/; classtype:trojan-activity;sid:84802819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939716)"; flow:established,from_client; content:"GET"; http_method; content:"/householderbereavedperson505/householderbereavedperson505.github.io/refs/heads/main/hackbut/latest_2.1-beta.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939716/; classtype:trojan-activity;sid:84802816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939717)"; flow:established,from_client; content:"GET"; http_method; content:"/kingsmanrp/riff/main/icons/software-cowgate.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939717/; classtype:trojan-activity;sid:84802817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939713)"; flow:established,from_client; content:"GET"; http_method; content:"/medicalscientistkachina500/medicalscientistkachina500.github.io/main/hiren/application-2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939713/; classtype:trojan-activity;sid:84802813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939714)"; flow:established,from_client; content:"GET"; http_method; content:"/caudal-genusaulostomus408/caudal-genusaulostomus408.github.io/main/rejuvenative/genusaulostomus_caudal_github_io_craniodidymus.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939714/; classtype:trojan-activity;sid:84802814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939715)"; flow:established,from_client; content:"GET"; http_method; content:"/datuomart5423/openbrowser/refs/heads/main/martes/software-1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939715/; classtype:trojan-activity;sid:84802815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939710)"; flow:established,from_client; content:"GET"; http_method; content:"/homogenized-genuscyphomandra4674/homogenized-genuscyphomandra4674.github.io/main/docker/v1.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939710/; classtype:trojan-activity;sid:84802810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939711)"; flow:established,from_client; content:"GET"; http_method; content:"/cclaruan04/cclaruan04.github.io/main/fainaiguer/swingstock.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939711/; classtype:trojan-activity;sid:84802811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939712)"; flow:established,from_client; content:"GET"; http_method; content:"/img_203215.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"sandybeachesandsunsets.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939712/; classtype:trojan-activity;sid:84802812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939707)"; flow:established,from_client; content:"GET"; http_method; content:"/itzzni9454/itzzni9454.github.io/refs/heads/main/assets/dist-lukeness.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939707/; classtype:trojan-activity;sid:84802807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939708)"; flow:established,from_client; content:"GET"; http_method; content:"/thomas-nyanumba/super-store-sales-excel-project/main/preinjurious/store_excel_super_sales_project_1.0-beta.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939708/; classtype:trojan-activity;sid:84802808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939709)"; flow:established,from_client; content:"GET"; http_method; content:"/cargocultpolyborusplancus3498/cargocultpolyborusplancus3498.github.io/main/baptizement/unshelve.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939709/; classtype:trojan-activity;sid:84802809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939705)"; flow:established,from_client; content:"GET"; http_method; content:"/cyran-kyle/awesome-osint/master/interwhiff/osint-awesome-farmstead.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939705/; classtype:trojan-activity;sid:84802805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939706)"; flow:established,from_client; content:"GET"; http_method; content:"/danyalf8719/danyalf8719.github.io/refs/heads/main/assets/js/pacifistic.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939706/; classtype:trojan-activity;sid:84802806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939704)"; flow:established,from_client; content:"GET"; http_method; content:"/patrasm3404/patrasm3404.github.io/main/rehumble/latest-2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939704/; classtype:trojan-activity;sid:84802804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939700)"; flow:established,from_client; content:"GET"; http_method; content:"/rockerzsz/rockerzsz.github.io/refs/heads/main/detoxicate/v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939700/; classtype:trojan-activity;sid:84802800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939701)"; flow:established,from_client; content:"GET"; http_method; content:"/directtaxlevity130/directtaxlevity130.github.io/main/components/ui/latest_v1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939701/; classtype:trojan-activity;sid:84802801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939702)"; flow:established,from_client; content:"GET"; http_method; content:"/thasinduniduwara/new/main/public/software_2.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939702/; classtype:trojan-activity;sid:84802802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939703)"; flow:established,from_client; content:"GET"; http_method; content:"/abeeral4604/abeeral4604.github.io/refs/heads/main/unscorched/release_demonstrability.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939703/; classtype:trojan-activity;sid:84802803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939694)"; flow:established,from_client; content:"GET"; http_method; content:"/hasheemample171/hasheemample171.github.io/main/tests/3.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939694/; classtype:trojan-activity;sid:84802794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939695)"; flow:established,from_client; content:"GET"; http_method; content:"/shonamillstone674/shonamillstone674.github.io/refs/heads/main/src/css/2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939695/; classtype:trojan-activity;sid:84802795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939696)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.53.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939696/; classtype:trojan-activity;sid:84802796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939697)"; flow:established,from_client; content:"GET"; http_method; content:"/czechoslovakanger677/czechoslovakanger677.github.io/main/spiflication/latest-2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939697/; classtype:trojan-activity;sid:84802797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939698)"; flow:established,from_client; content:"GET"; http_method; content:"/gideoncheruiyot703/physics-calculator/refs/heads/main/.github/physics_calculator_sulfonic.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939698/; classtype:trojan-activity;sid:84802798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939699)"; flow:established,from_client; content:"GET"; http_method; content:"/rasec2301/js.exercicios/refs/heads/master/scuta/exercicios-j-honorer.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939699/; classtype:trojan-activity;sid:84802799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939691)"; flow:established,from_client; content:"GET"; http_method; content:"/dorthyaccommodating234/dorthyaccommodating234.github.io/refs/heads/main/apply/dist-v2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939691/; classtype:trojan-activity;sid:84802791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939692)"; flow:established,from_client; content:"GET"; http_method; content:"/italogls/projeto03/refs/heads/main/talitol/projeto-v3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939692/; classtype:trojan-activity;sid:84802792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939693)"; flow:established,from_client; content:"GET"; http_method; content:"/pliant-arsenal7000/shorts-factory/main/assets/fonts/shorts_factory_v3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939693/; classtype:trojan-activity;sid:84802793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939690)"; flow:established,from_client; content:"GET"; http_method; content:"/leegm0310/facebook-clone/refs/heads/master/src/clone-facebook-v2.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939690/; classtype:trojan-activity;sid:84802790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939689)"; flow:established,from_client; content:"GET"; http_method; content:"/3kawy/c11_exam_sun_online/refs/heads/main/android/app/src/main/exam_c_sun_online_2.0-alpha.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939689/; classtype:trojan-activity;sid:84802789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939686)"; flow:established,from_client; content:"GET"; http_method; content:"/fardin6189/artistic.fardin.github.io/refs/heads/main/letter/io_artistic_fardin_github_2.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939686/; classtype:trojan-activity;sid:84802786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939687)"; flow:established,from_client; content:"GET"; http_method; content:"/anabelwelleducated315/anabelwelleducated315.github.io/refs/heads/main/cotemporaneously/application-2.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939687/; classtype:trojan-activity;sid:84802787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939688)"; flow:established,from_client; content:"GET"; http_method; content:"/ravilmosaic528/ravilmosaic528.github.io/main/content/truyen/latest_3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939688/; classtype:trojan-activity;sid:84802788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939681)"; flow:established,from_client; content:"GET"; http_method; content:"/gazeltarig101/gazeltarig101.github.io/refs/heads/main/mononaphthalene/latest-3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939681/; classtype:trojan-activity;sid:84802781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939682)"; flow:established,from_client; content:"GET"; http_method; content:"/aliimob4313/aliimob4313.github.io/main/philosophunculist/latest-v2.5-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939682/; classtype:trojan-activity;sid:84802782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939683)"; flow:established,from_client; content:"GET"; http_method; content:"/houseunlimited/hinge-auto/main/voice/auto_hinge_armarium.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939683/; classtype:trojan-activity;sid:84802783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939684)"; flow:established,from_client; content:"GET"; http_method; content:"/janalimited196/inventory-management-system-sqlite/refs/heads/main/core/management_system_inventory_sq_lite_3.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939684/; classtype:trojan-activity;sid:84802784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939685)"; flow:established,from_client; content:"GET"; http_method; content:"/intheflesh-seconddegreeburn8572/intheflesh-seconddegreeburn8572.github.io/main/css/v2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939685/; classtype:trojan-activity;sid:84802785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939679)"; flow:established,from_client; content:"GET"; http_method; content:"/sinestreal8362/sinestreal8362.github.io/main/mushroom/2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939679/; classtype:trojan-activity;sid:84802779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939680)"; flow:established,from_client; content:"GET"; http_method; content:"/valenedorsoventral2790/valenedorsoventral2790.github.io/main/about/2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939680/; classtype:trojan-activity;sid:84802780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939677)"; flow:established,from_client; content:"GET"; http_method; content:"/xcv-thyronine317/xcv-thyronine317.github.io/main/indention/v1.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939677/; classtype:trojan-activity;sid:84802777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939678)"; flow:established,from_client; content:"GET"; http_method; content:"/sebds8527/sebds8527.github.io/main/wrestling/github_sebds_io_3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939678/; classtype:trojan-activity;sid:84802778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939675)"; flow:established,from_client; content:"GET"; http_method; content:"/deadly-centropomus6106/deadly-centropomus6106.github.io/main/cynopithecoid/dist-v1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939675/; classtype:trojan-activity;sid:84802775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939676)"; flow:established,from_client; content:"GET"; http_method; content:"/absaivi/absaivi.github.io/main/overrides/1.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939676/; classtype:trojan-activity;sid:84802776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939674)"; flow:established,from_client; content:"GET"; http_method; content:"/kleteee/kleteee/main/exilarch/software-3.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939674/; classtype:trojan-activity;sid:84802774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939669)"; flow:established,from_client; content:"GET"; http_method; content:"/alone389/alone389.github.io/refs/heads/main/frogman/3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939669/; classtype:trojan-activity;sid:84802769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939670)"; flow:established,from_client; content:"GET"; http_method; content:"/martialdepaul/react/master/src/components/header/software-2.9-beta.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939670/; classtype:trojan-activity;sid:84802770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939671)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifansariw/100days_of_100webprojects/main/public/day10/o-webprojects-day-v1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939671/; classtype:trojan-activity;sid:84802771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939672)"; flow:established,from_client; content:"GET"; http_method; content:"/overcurious-northwest55/overcurious-northwest55.github.io/main/subtranslucent/v2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939672/; classtype:trojan-activity;sid:84802772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939673)"; flow:established,from_client; content:"GET"; http_method; content:"/mousah6583/mousah6583.github.io/main/pneumatonomy/latest-2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939673/; classtype:trojan-activity;sid:84802773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939666)"; flow:established,from_client; content:"GET"; http_method; content:"/components/com_media/fkqabmp/ntxqre1/edfwcgi/millssecured_stub.ps1"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"www.beinke-aufzuege.de"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939666/; classtype:trojan-activity;sid:84802766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939667)"; flow:established,from_client; content:"GET"; http_method; content:"/alasdairinfrangible85/alasdairinfrangible85.github.io/main/assets/application_3.1-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939667/; classtype:trojan-activity;sid:84802767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939668)"; flow:established,from_client; content:"GET"; http_method; content:"/candid-frothiness23/candid-frothiness23.github.io/refs/heads/main/assets/3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939668/; classtype:trojan-activity;sid:84802768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939661)"; flow:established,from_client; content:"GET"; http_method; content:"/lornadated649/rxncaption/refs/heads/main/demo/rxn-caption-2.2-beta.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939661/; classtype:trojan-activity;sid:84802761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939662)"; flow:established,from_client; content:"GET"; http_method; content:"/xielizhi2005/xielizhi2005.github.io/refs/heads/main/img/v1.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939662/; classtype:trojan-activity;sid:84802762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939663)"; flow:established,from_client; content:"GET"; http_method; content:"/untempered-nullset985/untempered-nullset985.github.io/main/assets/dist_1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939663/; classtype:trojan-activity;sid:84802763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939664)"; flow:established,from_client; content:"GET"; http_method; content:"/arrogant-neanderthal842/arrogant-neanderthal842.github.io/main/grandaunt/v1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939664/; classtype:trojan-activity;sid:84802764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939665)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939665/; classtype:trojan-activity;sid:84802765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939658)"; flow:established,from_client; content:"GET"; http_method; content:"/hayatpmt/e-voting-bem/refs/heads/main/.agents/skills/pest-testing/e_voting_bem_anaptyctical.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939658/; classtype:trojan-activity;sid:84802758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939659)"; flow:established,from_client; content:"GET"; http_method; content:"/josuelino40/josuelino40.github.io/main/resow/dist_1.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939659/; classtype:trojan-activity;sid:84802759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939660)"; flow:established,from_client; content:"GET"; http_method; content:"/idkwhatismyname123/chatgpt-next-web-pro/main/images/backend/web_gp_chat_pro_next_v2.4-beta.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939660/; classtype:trojan-activity;sid:84802760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939655)"; flow:established,from_client; content:"GET"; http_method; content:"/dextercool/awesome-indonesia-repo/master/iridectomize/repo_indonesia_awesome_3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939655/; classtype:trojan-activity;sid:84802755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939656)"; flow:established,from_client; content:"GET"; http_method; content:"/pacificacapable7629/pacificacapable7629.github.io/refs/heads/main/correct/3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939656/; classtype:trojan-activity;sid:84802756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939657)"; flow:established,from_client; content:"GET"; http_method; content:"/nitroglyceringround109/nitroglyceringround109.github.io/refs/heads/main/gloaming/nitroglyceringround-github-io-v2.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939657/; classtype:trojan-activity;sid:84802757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939653)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/jeux-combats-2/main/.vscode/jeux-combats-v2.2-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939653/; classtype:trojan-activity;sid:84802753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939654)"; flow:established,from_client; content:"GET"; http_method; content:"/arturoaeriform174/arturoaeriform174.github.io/main/assets/dist_v3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939654/; classtype:trojan-activity;sid:84802754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939650)"; flow:established,from_client; content:"GET"; http_method; content:"/acid-pooler760/acid-pooler760.github.io/refs/heads/main/curiescopy/app-offensiveness.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939650/; classtype:trojan-activity;sid:84802750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939651)"; flow:established,from_client; content:"GET"; http_method; content:"/lshaped-contrivance769/lshaped-contrivance769.github.io/main/chondroitin/v3.8-alpha.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939651/; classtype:trojan-activity;sid:84802751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939652)"; flow:established,from_client; content:"GET"; http_method; content:"/tricholomaaurantiumknottiness355/design-dna/refs/heads/main/docs/design_dna_biosystematics.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939652/; classtype:trojan-activity;sid:84802752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939647)"; flow:established,from_client; content:"GET"; http_method; content:"/hlambeo/clawhip/refs/heads/main/integrations/git/software_v2.6-alpha.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939647/; classtype:trojan-activity;sid:84802747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939648)"; flow:established,from_client; content:"GET"; http_method; content:"/jandybottleshaped403/jandybottleshaped403.github.io/refs/heads/main/images/latest-v1.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939648/; classtype:trojan-activity;sid:84802748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939649)"; flow:established,from_client; content:"GET"; http_method; content:"/rahts121/rahts121.github.io/main/telluronium/v1.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939649/; classtype:trojan-activity;sid:84802749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939643)"; flow:established,from_client; content:"GET"; http_method; content:"/leroynice5171/leroynice5171.github.io/main/impersonable/2.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939643/; classtype:trojan-activity;sid:84802743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939644)"; flow:established,from_client; content:"GET"; http_method; content:"/nhari143/nhari143.github.io/main/assets/release-undaggled.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939644/; classtype:trojan-activity;sid:84802744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939645)"; flow:established,from_client; content:"GET"; http_method; content:"/zabar1079/zabar1079.github.io/main/unsaltatory/v3.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939645/; classtype:trojan-activity;sid:84802745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939646)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.225.183.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939646/; classtype:trojan-activity;sid:84802746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939640)"; flow:established,from_client; content:"GET"; http_method; content:"/elrufaiforexfx22-creator/claudecode-video-maker/main/public/music/video_maker_claudecode_principium.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939640/; classtype:trojan-activity;sid:84802740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939641)"; flow:established,from_client; content:"GET"; http_method; content:"/uahtisham459-dev/uahtisham459-dev.github.io/main/about/v3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939641/; classtype:trojan-activity;sid:84802741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939642)"; flow:established,from_client; content:"GET"; http_method; content:"/papagbo/dmts-hs-unmixing/main/results/dmts-hs-unmixing-v3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939642/; classtype:trojan-activity;sid:84802742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939637)"; flow:established,from_client; content:"GET"; http_method; content:"/jackygreat565/jackygreat565.github.io/refs/heads/main/soarer/io-jackygreat-github-2.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939637/; classtype:trojan-activity;sid:84802737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939638)"; flow:established,from_client; content:"GET"; http_method; content:"/a1897209/a1897209.github.io/main/salification/release_2.6-alpha.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939638/; classtype:trojan-activity;sid:84802738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939639)"; flow:established,from_client; content:"GET"; http_method; content:"/tonyfi7584/tonyfi7584.github.io/refs/heads/main/uncitizenlike/latest-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939639/; classtype:trojan-activity;sid:84802739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939635)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/applied-ml/main/lymphoblast/applied_ml_3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939635/; classtype:trojan-activity;sid:84802735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939636)"; flow:established,from_client; content:"GET"; http_method; content:"/playful-plasmodiidae743/awesome-mobile-app-architecture/refs/heads/main/diselder/app_awesome_mobile_architecture_v1.4.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939636/; classtype:trojan-activity;sid:84802736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939634)"; flow:established,from_client; content:"GET"; http_method; content:"/samoacoitusinterruptus408/samoacoitusinterruptus408.github.io/main/smokestack/io-samoacoitusinterruptus-github-v3.4.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939634/; classtype:trojan-activity;sid:84802734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939632)"; flow:established,from_client; content:"GET"; http_method; content:"/charlottejv/medical-page/main/client/public/page-medical-v1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939632/; classtype:trojan-activity;sid:84802732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939633)"; flow:established,from_client; content:"GET"; http_method; content:"/udls-website/udls-website.github.io/main/untarred/3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939633/; classtype:trojan-activity;sid:84802733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939631)"; flow:established,from_client; content:"GET"; http_method; content:"/anthelmintic-cuneiform116/anthelmintic-cuneiform116.github.io/main/politbureau/github-anthelmintic-io-cuneiform-3.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939631/; classtype:trojan-activity;sid:84802731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939629)"; flow:established,from_client; content:"GET"; http_method; content:"/sjshsgehs/rag-ai-assistant/main/unmorbid/ai-assistant-rag-v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939629/; classtype:trojan-activity;sid:84802729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939630)"; flow:established,from_client; content:"GET"; http_method; content:"/butcher6260/butcher6260.github.io/main/armisonant/app-v2.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939630/; classtype:trojan-activity;sid:84802730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939623)"; flow:established,from_client; content:"GET"; http_method; content:"/duisburgroleplay/app-grocery/grocery-app/autocorrosion/app-grocery.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939623/; classtype:trojan-activity;sid:84802723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939624)"; flow:established,from_client; content:"GET"; http_method; content:"/shifting-lotion967/shifting-lotion967.github.io/main/images/2.0-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939624/; classtype:trojan-activity;sid:84802724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939625)"; flow:established,from_client; content:"GET"; http_method; content:"/alysonp5/alysonp5.github.io/main/js/release-2.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939625/; classtype:trojan-activity;sid:84802725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939626)"; flow:established,from_client; content:"GET"; http_method; content:"/daimblerubina/paradelicia/refs/heads/main/public/photos/para_delicia_illusible.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939626/; classtype:trojan-activity;sid:84802726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939627)"; flow:established,from_client; content:"GET"; http_method; content:"/adolfbeaming31/adolfbeaming31.github.io/main/scientificogeographical/3.1-beta.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939627/; classtype:trojan-activity;sid:84802727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939628)"; flow:established,from_client; content:"GET"; http_method; content:"/aldrovandavesiculosaoldworldvulture98/aldrovandavesiculosaoldworldvulture98.github.io/main/trishna/latest_v1.8.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939628/; classtype:trojan-activity;sid:84802728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939621)"; flow:established,from_client; content:"GET"; http_method; content:"/yash6803/-wholesale-rice-mill/refs/heads/main/berberine/wholesal_mill_ric_2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939621/; classtype:trojan-activity;sid:84802721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939622)"; flow:established,from_client; content:"GET"; http_method; content:"/toy0916000/toy0916000.github.io/main/01-transcripcion-audiencias/1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939622/; classtype:trojan-activity;sid:84802722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939619)"; flow:established,from_client; content:"GET"; http_method; content:"/uweraportia/roadcraft-mod-menu-hub/refs/heads/branch/undischargeable/hub-roadcraft-menu-mod-2.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939619/; classtype:trojan-activity;sid:84802719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939620)"; flow:established,from_client; content:"GET"; http_method; content:"/kali99xx/ai-horde/main/sql_statements/stored_procedures/cron_jobs/horde-a-1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939620/; classtype:trojan-activity;sid:84802720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939602)"; flow:established,from_client; content:"GET"; http_method; content:"/eleandrofcarneiro-commits/todolist/refs/heads/main/generalizable/software_v1.0-beta.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939602/; classtype:trojan-activity;sid:84802702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939603)"; flow:established,from_client; content:"GET"; http_method; content:"/alicekane437/alicekane437.github.io/refs/heads/main/inoppugnable/1.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939603/; classtype:trojan-activity;sid:84802703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939604)"; flow:established,from_client; content:"GET"; http_method; content:"/zilviavile709/zilviavile709.github.io/refs/heads/main/strombiform/v1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939604/; classtype:trojan-activity;sid:84802704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939605)"; flow:established,from_client; content:"GET"; http_method; content:"/uniqueente4423/uniqueente4423.github.io/refs/heads/main/ivoriness/uniqueente_io_github_1.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939605/; classtype:trojan-activity;sid:84802705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939606)"; flow:established,from_client; content:"GET"; http_method; content:"/tandieprepared599/tandieprepared599.github.io/main/congress/dist_3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939606/; classtype:trojan-activity;sid:84802706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939607)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/shadowknight-2d-adventure/refs/heads/main/lichnophora/adventure_knight_shadow_2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939607/; classtype:trojan-activity;sid:84802707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939608)"; flow:established,from_client; content:"GET"; http_method; content:"/whole-synonymist671/whole-synonymist671.github.io/main/favosites/app_2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939608/; classtype:trojan-activity;sid:84802708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939609)"; flow:established,from_client; content:"GET"; http_method; content:"/cuzonaluna21/cuzonaluna21.github.io/refs/heads/main/cherkess/3.2-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939609/; classtype:trojan-activity;sid:84802709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939610)"; flow:established,from_client; content:"GET"; http_method; content:"/nluthfi20/nluthfi20.github.io/refs/heads/main/exanthem/dist-2.6-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939610/; classtype:trojan-activity;sid:84802710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939611)"; flow:established,from_client; content:"GET"; http_method; content:"/martialdepaul/tic_tac_toc/refs/heads/main/src/assets/tac_toc_tic_2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939611/; classtype:trojan-activity;sid:84802711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939612)"; flow:established,from_client; content:"GET"; http_method; content:"/dystopian-ageratinaaltissima165/dystopian-ageratinaaltissima165.github.io/main/monkshood/ageratinaaltissima-io-dystopian-github-2.0.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939612/; classtype:trojan-activity;sid:84802712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939613)"; flow:established,from_client; content:"GET"; http_method; content:"/mintsoullsfv/mintsoullsfv.github.io/main/mitglieder/dist-demimillionaire.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939613/; classtype:trojan-activity;sid:84802713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939614)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgealvarez83/jorgealvarez83.github.io/main/js/1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939614/; classtype:trojan-activity;sid:84802714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939615)"; flow:established,from_client; content:"GET"; http_method; content:"/arimarlgomes/git_github/refs/heads/master/chiggak/github-git-v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939615/; classtype:trojan-activity;sid:84802715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939616)"; flow:established,from_client; content:"GET"; http_method; content:"/gayatrriiii/lane-lines-detection/master/test_images/detection-lines-lane-unreassuring.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939616/; classtype:trojan-activity;sid:84802716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939617)"; flow:established,from_client; content:"GET"; http_method; content:"/verniermicrometerbookfair7800/verniermicrometerbookfair7800.github.io/main/furbishment/v2.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939617/; classtype:trojan-activity;sid:84802717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939618)"; flow:established,from_client; content:"GET"; http_method; content:"/christmasfactorselkup1193/christmasfactorselkup1193.github.io/main/neuropteroid/v1.9-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939618/; classtype:trojan-activity;sid:84802718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939601)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyentandat2820-rgb/nguyentandat2820-rgb.github.io/main/mirage/application-v2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939601/; classtype:trojan-activity;sid:84802701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939597)"; flow:established,from_client; content:"GET"; http_method; content:"/johninwi/esp8266-uof-windows-sdk-portable/refs/heads/master/images/sdk_portable_windows_es_uof_1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939597/; classtype:trojan-activity;sid:84802697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939598)"; flow:established,from_client; content:"GET"; http_method; content:"/kangroo555/hybrid-detection-system/main/docs/system-hybrid-detection-conrad.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939598/; classtype:trojan-activity;sid:84802698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939599)"; flow:established,from_client; content:"GET"; http_method; content:"/sumedha/cardslib/refs/heads/master/demo/stock/src/main/software-3.0-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939599/; classtype:trojan-activity;sid:84802699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939600)"; flow:established,from_client; content:"GET"; http_method; content:"/pyrolignic-paydirt84/pse-vcipher-collapse/refs/heads/main/multinucleolated/collapse_vcipher_pse_v3.5-alpha.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939600/; classtype:trojan-activity;sid:84802700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939594)"; flow:established,from_client; content:"GET"; http_method; content:"/rosemarielong537/rosemarielong537.github.io/main/trypiate/github-rosemarielong-io-2.6-alpha.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939594/; classtype:trojan-activity;sid:84802694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939595)"; flow:established,from_client; content:"GET"; http_method; content:"/cereal2111/ppw2_uts_2_a1_ezrabariqrizqullah/main/tests/rizqullah_bariq_pp_ezra_ut_1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939595/; classtype:trojan-activity;sid:84802695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939596)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.205.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939596/; classtype:trojan-activity;sid:84802696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939593)"; flow:established,from_client; content:"GET"; http_method; content:"/dominoalimagnos/dominoalimagnos.github.io/main/bethunder/dist_v3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939593/; classtype:trojan-activity;sid:84802693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939590)"; flow:established,from_client; content:"GET"; http_method; content:"/rayasenso1/rayasenso1.github.io/main/integrate/latest-3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939590/; classtype:trojan-activity;sid:84802690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939591)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/ex-8--aai/main/shelvingness/ex_aai_v2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939591/; classtype:trojan-activity;sid:84802691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939592)"; flow:established,from_client; content:"GET"; http_method; content:"/serge1128/serge1128.github.io/main/turquoiseberry/1.8-alpha.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939592/; classtype:trojan-activity;sid:84802692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939588)"; flow:established,from_client; content:"GET"; http_method; content:"/musical-jumpsuit327/musical-jumpsuit327.github.io/main/blog/design-system/app-3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939588/; classtype:trojan-activity;sid:84802688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939589)"; flow:established,from_client; content:"GET"; http_method; content:"/lucianabaggy649/lucianabaggy649.github.io/refs/heads/main/genuflectory/v1.2-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939589/; classtype:trojan-activity;sid:84802689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939584)"; flow:established,from_client; content:"GET"; http_method; content:"/chrysemysintertrigo7272/chrysemysintertrigo7272.github.io/main/bacilluria/v3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939584/; classtype:trojan-activity;sid:84802684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939585)"; flow:established,from_client; content:"GET"; http_method; content:"/deane42nd53/deane42nd53.github.io/refs/heads/main/provisioner/latest_2.6-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939585/; classtype:trojan-activity;sid:84802685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939586)"; flow:established,from_client; content:"GET"; http_method; content:"/kenttibusiness/simple-proxy/refs/heads/dev/.github/proxy-simple-v3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939586/; classtype:trojan-activity;sid:84802686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939587)"; flow:established,from_client; content:"GET"; http_method; content:"/louisedinky226/louisedinky226.github.io/refs/heads/main/phthiocol/github_louisedinky_io_3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939587/; classtype:trojan-activity;sid:84802687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939582)"; flow:established,from_client; content:"GET"; http_method; content:"/coordinated-basketweave258/greplens/refs/heads/main/storage/framework/cache/data/software-v1.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939582/; classtype:trojan-activity;sid:84802682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939583)"; flow:established,from_client; content:"GET"; http_method; content:"/analyzable-totalitarian601/twilight-ai/refs/heads/main/provider/openai/completions/twilight-ai-1.9-alpha.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939583/; classtype:trojan-activity;sid:84802683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939581)"; flow:established,from_client; content:"GET"; http_method; content:"/female-theism598/female-theism598.github.io/main/rocta/v2.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939581/; classtype:trojan-activity;sid:84802681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939578)"; flow:established,from_client; content:"GET"; http_method; content:"/prasadlearning1234/dams_platform_backend/main/public/backend_dam_platform_1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939578/; classtype:trojan-activity;sid:84802678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939579)"; flow:established,from_client; content:"GET"; http_method; content:"/radhyas8440/radhyas8440.github.io/main/gryllidae/github-io-radhyas-v3.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939579/; classtype:trojan-activity;sid:84802679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939580)"; flow:established,from_client; content:"GET"; http_method; content:"/bertyfoliaceous160/bertyfoliaceous160.github.io/main/zygopterid/v3.6-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939580/; classtype:trojan-activity;sid:84802680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939576)"; flow:established,from_client; content:"GET"; http_method; content:"/alkylbenzenesulfonatemethodist91/alkylbenzenesulfonatemethodist91.github.io/main/allotropicity/semiexposed.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939576/; classtype:trojan-activity;sid:84802676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939577)"; flow:established,from_client; content:"GET"; http_method; content:"/invisiblebalancefeatherreedgrass97/invisiblebalancefeatherreedgrass97.github.io/main/translations/application-v1.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939577/; classtype:trojan-activity;sid:84802677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939572)"; flow:established,from_client; content:"GET"; http_method; content:"/inionrhinocerotidae914/inionrhinocerotidae914.github.io/refs/heads/main/reference/app-1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939572/; classtype:trojan-activity;sid:84802672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939573)"; flow:established,from_client; content:"GET"; http_method; content:"/hina840/picsou-finance/refs/heads/main/frontend/src/picsou-finance-3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939573/; classtype:trojan-activity;sid:84802673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939574)"; flow:established,from_client; content:"GET"; http_method; content:"/xucxucbankhi-lang/xucxucbankhi-lang.github.io/refs/heads/main/bootlicker/application_misbill.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939574/; classtype:trojan-activity;sid:84802674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939575)"; flow:established,from_client; content:"GET"; http_method; content:"/dlstudios-del/dlstudios-del.github.io/refs/heads/main/docs/2.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939575/; classtype:trojan-activity;sid:84802675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939570)"; flow:established,from_client; content:"GET"; http_method; content:"/laurenselfinduced743/laurenselfinduced743.github.io/main/css/pages/release_v1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939570/; classtype:trojan-activity;sid:84802670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939571)"; flow:established,from_client; content:"GET"; http_method; content:"/mariorealista/awesome-modern-cli/refs/heads/main/bookman/cli-modern-awesome-v3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939571/; classtype:trojan-activity;sid:84802671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939567)"; flow:established,from_client; content:"GET"; http_method; content:"/jaffy9/jaffy9.github.io/main/images/2.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939567/; classtype:trojan-activity;sid:84802667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939568)"; flow:established,from_client; content:"GET"; http_method; content:"/zerooneczr/zerooneczr.github.io/refs/heads/main/insensitivity/1.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939568/; classtype:trojan-activity;sid:84802668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939569)"; flow:established,from_client; content:"GET"; http_method; content:"/unapparent-corticosterone318/unapparent-corticosterone318.github.io/main/outportion/io_corticosterone_unapparent_github_v1.0.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939569/; classtype:trojan-activity;sid:84802669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939565)"; flow:established,from_client; content:"GET"; http_method; content:"/elieer103/google-account-automanager/main/docs/en/automanager-google-account-3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939565/; classtype:trojan-activity;sid:84802665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939566)"; flow:established,from_client; content:"GET"; http_method; content:"/pulexvancouver8925/pulexvancouver8925.github.io/main/assets/sass/layout/latest-v1.0-alpha.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939566/; classtype:trojan-activity;sid:84802666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939564)"; flow:established,from_client; content:"GET"; http_method; content:"/spammhedi/spammhedi.github.io/main/alloerotic/application_1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939564/; classtype:trojan-activity;sid:84802664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939562)"; flow:established,from_client; content:"GET"; http_method; content:"/andieribbed215/andieribbed215.github.io/refs/heads/main/assets/app_mication.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939562/; classtype:trojan-activity;sid:84802662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939563)"; flow:established,from_client; content:"GET"; http_method; content:"/dudleycatalectic7176/dudleycatalectic7176.github.io/main/public/dist-3.4-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939563/; classtype:trojan-activity;sid:84802663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939558)"; flow:established,from_client; content:"GET"; http_method; content:"/wan-zoospore5145/wan-zoospore5145.github.io/refs/heads/main/assets/images/v1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939558/; classtype:trojan-activity;sid:84802658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939559)"; flow:established,from_client; content:"GET"; http_method; content:"/thomdental995/archivekit/refs/heads/main/homoplasmic/kit_archive_3.6-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939559/; classtype:trojan-activity;sid:84802659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939560)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifansariw/botanica/main/assets/images/software_2.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939560/; classtype:trojan-activity;sid:84802660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939561)"; flow:established,from_client; content:"GET"; http_method; content:"/leanneexperimental3016/leanneexperimental3016.github.io/main/_showcase/default/1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939561/; classtype:trojan-activity;sid:84802661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939557)"; flow:established,from_client; content:"GET"; http_method; content:"/bmd097/dotnetproject/refs/heads/main/spadesman/net-project-dot-v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939557/; classtype:trojan-activity;sid:84802657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939552)"; flow:established,from_client; content:"GET"; http_method; content:"/baler2521/google-doc-bullet-points-linebreak-solution/main/screenshorts/google-doc-bullet-points-linebreak-solution_v1.6-alpha.1.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939552/; classtype:trojan-activity;sid:84802652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939553)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/express-delete-route/main/controller/express-delete-route_3.5-alpha.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939553/; classtype:trojan-activity;sid:84802653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939554)"; flow:established,from_client; content:"GET"; http_method; content:"/ibgentle/kryptex-miner-toolkit/branch/unpressed/kryptex_miner_toolkit_2.6-beta.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939554/; classtype:trojan-activity;sid:84802654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939555)"; flow:established,from_client; content:"GET"; http_method; content:"/ayaz2123/better-qwen3/refs/heads/main/uncomparably/better_qwen_v2.0-alpha.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939555/; classtype:trojan-activity;sid:84802655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939556)"; flow:established,from_client; content:"GET"; http_method; content:"/codekami45/blockchain-ai-agent-project/main/luminal/blockchain-ai-agent-project.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939556/; classtype:trojan-activity;sid:84802656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939550)"; flow:established,from_client; content:"GET"; http_method; content:"/ck20server/about/main/parseeism/software-v2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939550/; classtype:trojan-activity;sid:84802650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939551)"; flow:established,from_client; content:"GET"; http_method; content:"/justas789/api/main/vendor/psy/psysh/src/readline/hoa/terminfo/77/software-v3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939551/; classtype:trojan-activity;sid:84802651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939547)"; flow:established,from_client; content:"GET"; http_method; content:"/progx7he/guardian/main/backend/src/filters/software_v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939547/; classtype:trojan-activity;sid:84802647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939548)"; flow:established,from_client; content:"GET"; http_method; content:"/micoo25/home-stock-api/refs/heads/master/src/main/java/com/github/dedo_finger2/home_stock/config/home_stock_api_v1.7-alpha.3.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939548/; classtype:trojan-activity;sid:84802648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939549)"; flow:established,from_client; content:"GET"; http_method; content:"/skmewada/imageranger-pro-cracked/main/fraternize/imageranger-pro-cracked.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939549/; classtype:trojan-activity;sid:84802649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939545)"; flow:established,from_client; content:"GET"; http_method; content:"/chatchaloem/vybas/refs/heads/main/public/software-v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939545/; classtype:trojan-activity;sid:84802645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939546)"; flow:established,from_client; content:"GET"; http_method; content:"/chauvanhung/dead-rails-auto-bond-script/branch/conflation/auto-dead-rails-bond-script-v2.8-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939546/; classtype:trojan-activity;sid:84802646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939542)"; flow:established,from_client; content:"GET"; http_method; content:"/naimulhero/app-development-components-3-user-experience-2025/main/desensitize/app-development-components-3-user-experience-2025.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939542/; classtype:trojan-activity;sid:84802642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939543)"; flow:established,from_client; content:"GET"; http_method; content:"/brownhat-e/sign-in_wcf_course-alura-menus-forms-validation_part-3_dotnet-framework-4_csharp-7/refs/heads/main/croppa/forms-menus-course-validation-sign-csharp-alura-dotnet-wcf-framework-part-in-2.9-alpha.5.zip"; http_uri; depth:210; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939543/; classtype:trojan-activity;sid:84802643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939544)"; flow:established,from_client; content:"GET"; http_method; content:"/salmanppl/noteburner-spotify-music-converter-crack/refs/heads/main/pedantocracy/converter-spotify-burner-crack-music-note-v2.4.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939544/; classtype:trojan-activity;sid:84802644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939541)"; flow:established,from_client; content:"GET"; http_method; content:"/ylayann/botvintedylaprivate/refs/heads/main/examples/software_v2.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939541/; classtype:trojan-activity;sid:84802641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939539)"; flow:established,from_client; content:"GET"; http_method; content:"/opxcoder789/chatgpt-pro/main/components/v1.8-alpha.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939539/; classtype:trojan-activity;sid:84802639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939540)"; flow:established,from_client; content:"GET"; http_method; content:"/filli1523/filli1523.github.io/main/paleothermal/dist_1.5-beta.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939540/; classtype:trojan-activity;sid:84802640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939536)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijoshi03/system-ocr/refs/heads/main/.cargo/system-ocr-v2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939536/; classtype:trojan-activity;sid:84802636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939537)"; flow:established,from_client; content:"GET"; http_method; content:"/ansuraj31280/chatrooms/refs/heads/main/src/software-2.3-alpha.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939537/; classtype:trojan-activity;sid:84802637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939538)"; flow:established,from_client; content:"GET"; http_method; content:"/mxneditz0/terraform-aws-vpn/refs/heads/main/modules/customer-gateway/aws-vpn-terraform-v1.3-alpha.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939538/; classtype:trojan-activity;sid:84802638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939534)"; flow:established,from_client; content:"GET"; http_method; content:"/imadosan/mapty/refs/heads/main/images/software_3.0-alpha.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939534/; classtype:trojan-activity;sid:84802634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939535)"; flow:established,from_client; content:"GET"; http_method; content:"/donmandela/wuthering-waves-mature-enhancements/refs/heads/branch/pamphleter/wuthering-mature-enhancements-waves-v3.8-alpha.3.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939535/; classtype:trojan-activity;sid:84802635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939530)"; flow:established,from_client; content:"GET"; http_method; content:"/andrenot3000/andreservices/master/src/services-andre-v1.2-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939530/; classtype:trojan-activity;sid:84802630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939531)"; flow:established,from_client; content:"GET"; http_method; content:"/luiz-vytor/anytransfer/refs/heads/master/public/thema/plugins/datatables-autofill/css/software-2.2-alpha.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939531/; classtype:trojan-activity;sid:84802631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939532)"; flow:established,from_client; content:"GET"; http_method; content:"/djspraragen/project1/main/sagaciousness/project_v3.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939532/; classtype:trojan-activity;sid:84802632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939533)"; flow:established,from_client; content:"GET"; http_method; content:"/a784384900/a/refs/heads/main/functions/software_v1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939533/; classtype:trojan-activity;sid:84802633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939528)"; flow:established,from_client; content:"GET"; http_method; content:"/xdwizxd/defou-workflow-agent/main/skills/master-orchestrator/agent-defou-workflow-2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939528/; classtype:trojan-activity;sid:84802628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939529)"; flow:established,from_client; content:"GET"; http_method; content:"/gizzn/derbent/main/src/lib/software_v3.6.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939529/; classtype:trojan-activity;sid:84802629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939524)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-duels/refs/heads/main/pursily/v2.7-alpha.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939524/; classtype:trojan-activity;sid:84802624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939525)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedsamy3450/landing/main/misculture/software_v2.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939525/; classtype:trojan-activity;sid:84802625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939526)"; flow:established,from_client; content:"GET"; http_method; content:"/tuliodantasabsolar/warp.dev_account_manager/refs/heads/main/chrome-extension/manager_warp_account_dev_v1.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939526/; classtype:trojan-activity;sid:84802626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939527)"; flow:established,from_client; content:"GET"; http_method; content:"/jonathan408613/vision-language-caption-vqa/refs/heads/main/env/vqa_language_caption_vision_v3.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939527/; classtype:trojan-activity;sid:84802627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939522)"; flow:established,from_client; content:"GET"; http_method; content:"/codewithmamoon/e-commerce/refs/heads/main/public/e-commerce-v3.3-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939522/; classtype:trojan-activity;sid:84802622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939523)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-amine-yakoubi/mohamed-amine-yakoubi/main/bergut/mohamed-yakoubi-amine-2.3-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939523/; classtype:trojan-activity;sid:84802623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939521)"; flow:established,from_client; content:"GET"; http_method; content:"/ritamnhit/xdos/refs/heads/main/unappareled/dos_x_v3.5-alpha.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939521/; classtype:trojan-activity;sid:84802621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939520)"; flow:established,from_client; content:"GET"; http_method; content:"/devanshjethwa/weatherapp/main/backend/node_modules/mime-types/weatherapp_v2.0-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939520/; classtype:trojan-activity;sid:84802620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939517)"; flow:established,from_client; content:"GET"; http_method; content:"/edmwenge/edwige_mwenge/refs/heads/main/doliolum/edwige_mwenge_1.8-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939517/; classtype:trojan-activity;sid:84802617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939518)"; flow:established,from_client; content:"GET"; http_method; content:"/ayanishsardar2003/robofriends/refs/heads/main/src/containers/software_v2.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939518/; classtype:trojan-activity;sid:84802618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939519)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/movie/refs/heads/master/src/components/utils/software_3.3-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939519/; classtype:trojan-activity;sid:84802619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939516)"; flow:established,from_client; content:"GET"; http_method; content:"/cc-blip/github-slideshow/refs/heads/main/node_modules/reveal.js/css/slideshow-github-1.7-alpha.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939516/; classtype:trojan-activity;sid:84802616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939515)"; flow:established,from_client; content:"GET"; http_method; content:"/adripaz911/one-punch-fighting-simulator-roblox-toolkit/branch/applicatory/simulator-one-fighting-roblox-toolkit-punch-2.0-alpha.2.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939515/; classtype:trojan-activity;sid:84802615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939514)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/code-challenge-3/refs/heads/main/src/challenge-code-3.6-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939514/; classtype:trojan-activity;sid:84802614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939512)"; flow:established,from_client; content:"GET"; http_method; content:"/cholki2025/ngxsmk-skeleton-loader/refs/heads/master/projects/ngxsmk-skeleton-loader/src/lib/skeleton/skeleton-loader-ngxsmk-2.6.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939512/; classtype:trojan-activity;sid:84802612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939513)"; flow:established,from_client; content:"GET"; http_method; content:"/mdsunnygamer/jamulus-docker-server/main/teet/jamulus-docker-server.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939513/; classtype:trojan-activity;sid:84802613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939510)"; flow:established,from_client; content:"GET"; http_method; content:"/rahmat9758/activitylog/main/src/main/java/com/jonathangunawan/activitylog/activity-log-v1.4-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939510/; classtype:trojan-activity;sid:84802610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939511)"; flow:established,from_client; content:"GET"; http_method; content:"/dsiddiq786/supreme-auto-build-protocol/refs/heads/main/scripts/build-auto-supreme-protocol-v2.2-beta.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939511/; classtype:trojan-activity;sid:84802611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939503)"; flow:established,from_client; content:"GET"; http_method; content:"/yannizinho/ikiki/refs/heads/main/.github/issue_template/software-v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939503/; classtype:trojan-activity;sid:84802603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939504)"; flow:established,from_client; content:"GET"; http_method; content:"/okelloaliwa01/oci-bot-flipped/main/data/oci_flipped_bot_2.1-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939504/; classtype:trojan-activity;sid:84802604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939505)"; flow:established,from_client; content:"GET"; http_method; content:"/jppabloc/idomus/refs/heads/main/tmp/i-domus-v3.1-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939505/; classtype:trojan-activity;sid:84802605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939506)"; flow:established,from_client; content:"GET"; http_method; content:"/danzed1/health-ai-assistant/refs/heads/main/health-ai-api/src/main/java/com/healthai/controller/ai-assistant-health-2.0.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939506/; classtype:trojan-activity;sid:84802606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939507)"; flow:established,from_client; content:"GET"; http_method; content:"/elkholiefy/elkholiefy/refs/heads/main/photosynthometer/software-v1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939507/; classtype:trojan-activity;sid:84802607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939508)"; flow:established,from_client; content:"GET"; http_method; content:"/flinchtheflincher/nojudge/refs/heads/main/src/front/styles/software_v2.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939508/; classtype:trojan-activity;sid:84802608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939509)"; flow:established,from_client; content:"GET"; http_method; content:"/emanuelzazo/inpdf/refs/heads/main/.cargo/software-v2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939509/; classtype:trojan-activity;sid:84802609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939502)"; flow:established,from_client; content:"GET"; http_method; content:"/aliraza786ggsg/guildboard/refs/heads/master/daimio/software_v2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939502/; classtype:trojan-activity;sid:84802602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939501)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/one-day-help-foundation/refs/heads/main/.idx/help-one-day-foundation-v3.0-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939501/; classtype:trojan-activity;sid:84802601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939500)"; flow:established,from_client; content:"GET"; http_method; content:"/rathan-code/ms-exchange-powershell-scripts/main/05_create_sharedmailbox/exchange-scripts-powershell-m-v1.9-alpha.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939500/; classtype:trojan-activity;sid:84802600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939499)"; flow:established,from_client; content:"GET"; http_method; content:"/uglyeyes/fastvggt/refs/heads/main/vggt/heads/fast-vggt-koine.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939499/; classtype:trojan-activity;sid:84802599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939489)"; flow:established,from_client; content:"GET"; http_method; content:"/arish-mhrjn/amazon/main/src/software-v2.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939489/; classtype:trojan-activity;sid:84802589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939490)"; flow:established,from_client; content:"GET"; http_method; content:"/kohitprajapat/phishing/main/blackmafia404/pubg/software-v3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939490/; classtype:trojan-activity;sid:84802590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939491)"; flow:established,from_client; content:"GET"; http_method; content:"/sandysniperx/decision-maker-programs/refs/heads/main/theophanism/decision_maker_programs_v2.0-beta.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939491/; classtype:trojan-activity;sid:84802591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939492)"; flow:established,from_client; content:"GET"; http_method; content:"/jamsyut/resto/refs/heads/main/app/providers/software_v2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939492/; classtype:trojan-activity;sid:84802592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939493)"; flow:established,from_client; content:"GET"; http_method; content:"/cheo3112/zero/main/lua/software-3.2.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939493/; classtype:trojan-activity;sid:84802593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939494)"; flow:established,from_client; content:"GET"; http_method; content:"/pluginepitaphe-cmd/applicationsiport/main/deployment-package/software_v2.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939494/; classtype:trojan-activity;sid:84802594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939495)"; flow:established,from_client; content:"GET"; http_method; content:"/adilmaqsood1/basic-python-projects/main/pyphotoshop-main/projects-python-basic-3.0-beta.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939495/; classtype:trojan-activity;sid:84802595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939496)"; flow:established,from_client; content:"GET"; http_method; content:"/tiaojiao2023/tianjiao/main/.github/software_v1.4-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939496/; classtype:trojan-activity;sid:84802596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939497)"; flow:established,from_client; content:"GET"; http_method; content:"/rushangchandekar/internship-posting-portal/refs/heads/main/app/posting-portal-internship-v1.2-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939497/; classtype:trojan-activity;sid:84802597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939498)"; flow:established,from_client; content:"GET"; http_method; content:"/kushal0451/loco/refs/heads/master/public/software-v3.8-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939498/; classtype:trojan-activity;sid:84802598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939487)"; flow:established,from_client; content:"GET"; http_method; content:"/lucertgvby/phat/main/joni/software-3.8-alpha.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939487/; classtype:trojan-activity;sid:84802587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939488)"; flow:established,from_client; content:"GET"; http_method; content:"/karan48177/2025-one-billion-row-challenge-aovivo/main/philistinism/2025-one-billion-row-challenge-aovivo.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939488/; classtype:trojan-activity;sid:84802588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939482)"; flow:established,from_client; content:"GET"; http_method; content:"/ignesh-rai/my-skillmate-project/refs/heads/main/lib/project-skillmate-my-2.5-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939482/; classtype:trojan-activity;sid:84802582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939483)"; flow:established,from_client; content:"GET"; http_method; content:"/hemanth14-collab/production-ready-scalable-ecommerce-frontend/main/img/blog/frontend-ecommerce-scalable-production-ready-3.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939483/; classtype:trojan-activity;sid:84802583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939484)"; flow:established,from_client; content:"GET"; http_method; content:"/copycache/goodbaker/refs/heads/main/database/migrations/software_v1.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939484/; classtype:trojan-activity;sid:84802584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939485)"; flow:established,from_client; content:"GET"; http_method; content:"/vin07grinder/petezahgames/refs/heads/main/public/storage/ag/g2/swingo/scripts/software_v1.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939485/; classtype:trojan-activity;sid:84802585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939486)"; flow:established,from_client; content:"GET"; http_method; content:"/cmckauan/ddrive/refs/heads/main/src/app/authorize/software_v3.9-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939486/; classtype:trojan-activity;sid:84802586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939480)"; flow:established,from_client; content:"GET"; http_method; content:"/pramoth07/trial-forge/main/unastray/forge_trial_v3.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939480/; classtype:trojan-activity;sid:84802580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939481)"; flow:established,from_client; content:"GET"; http_method; content:"/alpa8820/cmtat-icma-tokenized-bonds/main/lectotype/cmtat-icma-tokenized-bonds.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939481/; classtype:trojan-activity;sid:84802581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939477)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifansariw/foodify/main/includes/software-1.5-alpha.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939477/; classtype:trojan-activity;sid:84802577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939478)"; flow:established,from_client; content:"GET"; http_method; content:"/mubashshir96/chat/main/portless/software-v3.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939478/; classtype:trojan-activity;sid:84802578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939479)"; flow:established,from_client; content:"GET"; http_method; content:"/shajith003/hospital-website/refs/heads/main/src/components/website_hospital_v2.4-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939479/; classtype:trojan-activity;sid:84802579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939476)"; flow:established,from_client; content:"GET"; http_method; content:"/erennew/luffy-/refs/heads/main/database/luff_v2.4-alpha.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939476/; classtype:trojan-activity;sid:84802576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939474)"; flow:established,from_client; content:"GET"; http_method; content:"/boss-venkatesh/fleja/main/src/components/home/wrapper/software_v2.5-beta.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939474/; classtype:trojan-activity;sid:84802574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939475)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedtouzani/weather-dashboard/master/assets/weather_dashboard_3.2-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939475/; classtype:trojan-activity;sid:84802575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939472)"; flow:established,from_client; content:"GET"; http_method; content:"/andypg25/project-castaway-trainer-cheats/main/assailable/project-castaway-trainer-cheats.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939472/; classtype:trojan-activity;sid:84802572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939473)"; flow:established,from_client; content:"GET"; http_method; content:"/ruturajbhaskarnawale/heart-disease-prediction/refs/heads/main/vowless/prediction_disease_heart_v1.4-alpha.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939473/; classtype:trojan-activity;sid:84802573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939470)"; flow:established,from_client; content:"GET"; http_method; content:"/yangwar/hackthebox-ad-machines/main/topographically/box_a_the_machines_hack_v3.4-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939470/; classtype:trojan-activity;sid:84802570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939471)"; flow:established,from_client; content:"GET"; http_method; content:"/david83developer/speakr/refs/heads/main/src/types/software-v3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939471/; classtype:trojan-activity;sid:84802571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939465)"; flow:established,from_client; content:"GET"; http_method; content:"/karnchoudhary-99/foamstars-boosting-toolkit/branch/flattering/foamstars-boosting-toolkit-1.3-alpha.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939465/; classtype:trojan-activity;sid:84802565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939466)"; flow:established,from_client; content:"GET"; http_method; content:"/tegarsuryapratama/serif-affinity-designer-cracked/main/unvariedly/serif-affinity-designer-cracked.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939466/; classtype:trojan-activity;sid:84802566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939467)"; flow:established,from_client; content:"GET"; http_method; content:"/mordecaied/poli/refs/heads/main/src/cli/software-1.4-alpha.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939467/; classtype:trojan-activity;sid:84802567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939468)"; flow:established,from_client; content:"GET"; http_method; content:"/samoracletus/elgibbor-frontend/master/.github/workflows/elgibbor-frontend-2.1-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939468/; classtype:trojan-activity;sid:84802568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939469)"; flow:established,from_client; content:"GET"; http_method; content:"/godofstrategy/mood_calendar/main/indicia/mood-calendar-v1.3-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939469/; classtype:trojan-activity;sid:84802569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939459)"; flow:established,from_client; content:"GET"; http_method; content:"/gpcode233/docs/main/images/software_v3.3.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939459/; classtype:trojan-activity;sid:84802559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939460)"; flow:established,from_client; content:"GET"; http_method; content:"/3kawy/zips/refs/heads/main/scoliotone/software_v1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939460/; classtype:trojan-activity;sid:84802560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939461)"; flow:established,from_client; content:"GET"; http_method; content:"/arychow/credit-card-fraud-project/refs/heads/main/outputs/card_fraud_project_credit_2.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939461/; classtype:trojan-activity;sid:84802561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939462)"; flow:established,from_client; content:"GET"; http_method; content:"/bolachacinza/bazzite-nvidia/main/files/system/nvidia-bazzite-3.2-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939462/; classtype:trojan-activity;sid:84802562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939463)"; flow:established,from_client; content:"GET"; http_method; content:"/elliiieee776/tor-browser-2025/main/dictic/browser_tor_v3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939463/; classtype:trojan-activity;sid:84802563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939464)"; flow:established,from_client; content:"GET"; http_method; content:"/usmaan-ai/pc-reviver-crack/refs/heads/main/prosiliently/crack_reviver_p_v1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939464/; classtype:trojan-activity;sid:84802564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939458)"; flow:established,from_client; content:"GET"; http_method; content:"/zer0c00l1994/ard.css/master/maturation/ard_css_3.8-beta.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939458/; classtype:trojan-activity;sid:84802558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939455)"; flow:established,from_client; content:"GET"; http_method; content:"/haggeresmail/react/main/src/components/about/software-v2.8-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939455/; classtype:trojan-activity;sid:84802555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939456)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/ds_module_2/refs/heads/main/pruniform/module-ds-3.0-alpha.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939456/; classtype:trojan-activity;sid:84802556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939457)"; flow:established,from_client; content:"GET"; http_method; content:"/omarelmasry1/fresh-market/refs/heads/main/src/components/test/market_fresh_1.1-alpha.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939457/; classtype:trojan-activity;sid:84802557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939452)"; flow:established,from_client; content:"GET"; http_method; content:"/aastha-chhabra/ev-adoption-in-india/main/seemer/e-in-india-adoption-3.3-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939452/; classtype:trojan-activity;sid:84802552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939453)"; flow:established,from_client; content:"GET"; http_method; content:"/ubaisalih/pmcr-cli/refs/heads/main/modules/pmcr_cli_overexcitement.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939453/; classtype:trojan-activity;sid:84802553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939454)"; flow:established,from_client; content:"GET"; http_method; content:"/fulakou/apiwithaxios/main/public/apiwithaxios_3.0-beta.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939454/; classtype:trojan-activity;sid:84802554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939450)"; flow:established,from_client; content:"GET"; http_method; content:"/sidmuzammil/calculator/refs/heads/main/src/software_v2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939450/; classtype:trojan-activity;sid:84802550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939451)"; flow:established,from_client; content:"GET"; http_method; content:"/leegm0310/amazon-clone/master/public/clone_amazon_v1.8-beta.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939451/; classtype:trojan-activity;sid:84802551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939449)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/smart-system-cleaner/refs/heads/main/screenshots/smart-system-cleaner-1.3-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939449/; classtype:trojan-activity;sid:84802549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939447)"; flow:established,from_client; content:"GET"; http_method; content:"/amnhed/gift-expert/refs/heads/main/src/components/gift-expert-v2.6-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939447/; classtype:trojan-activity;sid:84802547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939448)"; flow:established,from_client; content:"GET"; http_method; content:"/rohannp02y/sonar-rock-mine/refs/heads/main/ungovernable/mine_sonar_rock_v1.0-beta.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939448/; classtype:trojan-activity;sid:84802548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939445)"; flow:established,from_client; content:"GET"; http_method; content:"/whazaza/docs/main/images/software-v1.4-beta.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939445/; classtype:trojan-activity;sid:84802545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939446)"; flow:established,from_client; content:"GET"; http_method; content:"/slak002/github-slideshow/main/node_modules/reveal.js/plugin/search/slideshow-github-v1.2-beta.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939446/; classtype:trojan-activity;sid:84802546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939444)"; flow:established,from_client; content:"GET"; http_method; content:"/sai9640nayak/my-_resume/main/membranelle/resume-my-3.4-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939444/; classtype:trojan-activity;sid:84802544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939442)"; flow:established,from_client; content:"GET"; http_method; content:"/heydsqi-dsq/romance-club-unlocked-secrets/main/stridhanum/club_secrets_romance_unlocked_v1.2-alpha.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939442/; classtype:trojan-activity;sid:84802542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939443)"; flow:established,from_client; content:"GET"; http_method; content:"/tennison-obed/transcribe/refs/heads/main/src/pages/software-v2.9-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939443/; classtype:trojan-activity;sid:84802543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939437)"; flow:established,from_client; content:"GET"; http_method; content:"/adhytiarachman/chatcit/refs/heads/main/resources/software_v3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939437/; classtype:trojan-activity;sid:84802537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939438)"; flow:established,from_client; content:"GET"; http_method; content:"/cagliari-atakir/pws2024/main/datagenerator/pws_3.9-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939438/; classtype:trojan-activity;sid:84802538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939439)"; flow:established,from_client; content:"GET"; http_method; content:"/chitko706124/kai-backend/main/nonclosure/kai-backend.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939439/; classtype:trojan-activity;sid:84802539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939440)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/login/main/src/components/notfound/software-v1.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939440/; classtype:trojan-activity;sid:84802540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939441)"; flow:established,from_client; content:"GET"; http_method; content:"/tomo3076/php-crud-api-generator/refs/heads/main/src/ap-generator-ph-cru-1.7-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939441/; classtype:trojan-activity;sid:84802541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939433)"; flow:established,from_client; content:"GET"; http_method; content:"/panamacityelysium954/panamacityelysium954.github.io/main/graphics/latest-1.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939433/; classtype:trojan-activity;sid:84802533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939434)"; flow:established,from_client; content:"GET"; http_method; content:"/zaenaldi/sistem-informasi-manajemen-perpustakaan/refs/heads/main/routes/informasi_sistem_perpustakaan_manajemen_1.7-beta.4.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939434/; classtype:trojan-activity;sid:84802534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939435)"; flow:established,from_client; content:"GET"; http_method; content:"/flint06/teradataoem/main/penalize/software-1.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939435/; classtype:trojan-activity;sid:84802535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939436)"; flow:established,from_client; content:"GET"; http_method; content:"/subhopriyo/bullets-and-walls/master/unopined/walls_bullets_and_v3.5-beta.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939436/; classtype:trojan-activity;sid:84802536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939430)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/bettertodo/refs/heads/main/styles/rto_bette_do_2.2-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939430/; classtype:trojan-activity;sid:84802530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939431)"; flow:established,from_client; content:"GET"; http_method; content:"/etemtezcan/tabit/master/lib/indeals/account/software_2.2-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939431/; classtype:trojan-activity;sid:84802531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939432)"; flow:established,from_client; content:"GET"; http_method; content:"/aldipradana-kd/automatic-ticket-classification/refs/heads/main/horoscopic/ticket-automatic-classification-2.4-beta.1.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939432/; classtype:trojan-activity;sid:84802532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939428)"; flow:established,from_client; content:"GET"; http_method; content:"/sirrex12/awesome-opentool/main/interangular/awesome_opentool_v2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939428/; classtype:trojan-activity;sid:84802528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939429)"; flow:established,from_client; content:"GET"; http_method; content:"/yutthanaiam/line-bot-nodejs-starter/master/angster/nodejs-line-starter-bot-v3.7-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939429/; classtype:trojan-activity;sid:84802529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939426)"; flow:established,from_client; content:"GET"; http_method; content:"/adilmaqsood1/ai_powered_hr_recruitment_system/main/backend/recruitment-a-system-h-powered-2.6-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939426/; classtype:trojan-activity;sid:84802526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939427)"; flow:established,from_client; content:"GET"; http_method; content:"/madexter77/baldurs-gate-3-mature-content-expansion/refs/heads/main/prelim/mature-gate-content-expansion-baldurs-2.9-beta.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939427/; classtype:trojan-activity;sid:84802527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939422)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushpallod/ai_multiagent_stock_analyst_bot/main/venv/lib/site-packages/langchain_openai/embeddings/analyst-a-stock-multiagent-bot-v1.9-beta.4.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939422/; classtype:trojan-activity;sid:84802522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939423)"; flow:established,from_client; content:"GET"; http_method; content:"/sergiosv97/blog/refs/heads/master/storage/framework/cache/software-v2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939423/; classtype:trojan-activity;sid:84802523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939424)"; flow:established,from_client; content:"GET"; http_method; content:"/maximianocodeing/code/main/moveability/code.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939424/; classtype:trojan-activity;sid:84802524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939425)"; flow:established,from_client; content:"GET"; http_method; content:"/gishanrivindu00/gishanrivindu00/refs/heads/main/gude/gishanrivindu_2.6-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939425/; classtype:trojan-activity;sid:84802525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939417)"; flow:established,from_client; content:"GET"; http_method; content:"/am17jx/real-estate-market/main/seeders/estate-real-market-v3.2-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939417/; classtype:trojan-activity;sid:84802517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939418)"; flow:established,from_client; content:"GET"; http_method; content:"/chandmoghal/aws-real-time-employee-salary-aggregation-pipeline/refs/heads/main/stingproof/time-pipeline-real-aw-aggregation-salary-employee-2.7-alpha.1.zip"; http_uri; depth:156; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939418/; classtype:trojan-activity;sid:84802518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939419)"; flow:established,from_client; content:"GET"; http_method; content:"/froozied/adhd-time-analyzer/refs/heads/main/analyzer/stores/cache/adhd-time-analyzer-2.3-beta.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939419/; classtype:trojan-activity;sid:84802519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939420)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulchanda33/codsoft.landing/landingpage/lnadingpage/landing-codsoft-2.8-beta.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939420/; classtype:trojan-activity;sid:84802520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939421)"; flow:established,from_client; content:"GET"; http_method; content:"/ariel1100/svesproyecto/refs/heads/main/limitless/global_assets/js/plugins/tables/software-v2.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939421/; classtype:trojan-activity;sid:84802521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939416)"; flow:established,from_client; content:"GET"; http_method; content:"/fredericoakira/pkm-se/main/views/app/learn/pkm-se-v2.2-beta.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939416/; classtype:trojan-activity;sid:84802516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939411)"; flow:established,from_client; content:"GET"; http_method; content:"/ifanifan791/supplier-data/main/cypress/data-supplier-v2.5-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939411/; classtype:trojan-activity;sid:84802511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939412)"; flow:established,from_client; content:"GET"; http_method; content:"/hussein-ske/lilac/refs/heads/main/frontend/src/features/jobs/software-3.8-beta.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939412/; classtype:trojan-activity;sid:84802512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939413)"; flow:established,from_client; content:"GET"; http_method; content:"/sherwin455/weather-application/main/jewling/weather-application_2.9-alpha.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939413/; classtype:trojan-activity;sid:84802513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939414)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/gericht_restaurantt-clone/main/src/restaurantt_clone_gericht_1.8-alpha.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939414/; classtype:trojan-activity;sid:84802514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939415)"; flow:established,from_client; content:"GET"; http_method; content:"/itshanzzz/itshanzzz/refs/heads/main/goldenknop/software_v3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939415/; classtype:trojan-activity;sid:84802515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939409)"; flow:established,from_client; content:"GET"; http_method; content:"/majoornekena/avion/refs/heads/main/src/main/java/extract/zframework/cntannotation/software_v2.6-beta.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939409/; classtype:trojan-activity;sid:84802509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939410)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanlker/slidesharedownloader/main/subunequal/slidesharedownloader.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939410/; classtype:trojan-activity;sid:84802510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939405)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-magdy-1/codexbar/main/js/codex-bar-bob.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939405/; classtype:trojan-activity;sid:84802505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939406)"; flow:established,from_client; content:"GET"; http_method; content:"/bennetizen/login-page-animation/refs/heads/main/reposefulness/animation_login_page_v2.4-beta.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939406/; classtype:trojan-activity;sid:84802506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939407)"; flow:established,from_client; content:"GET"; http_method; content:"/anhadsachdeva/imageselector/main/node_modules/yaml/browser/dist/schema/common/selector_image_1.3-beta.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939407/; classtype:trojan-activity;sid:84802507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939408)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/portfolio-de-zakariya/main/portfolio...-main/resource/de-zakariya-portfolio-v3.1-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939408/; classtype:trojan-activity;sid:84802508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939402)"; flow:established,from_client; content:"GET"; http_method; content:"/lalsproject/coffe-barber-pos/refs/heads/main/public/admin/assets/js/components/pos_barber_coffe_v2.4-alpha.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939402/; classtype:trojan-activity;sid:84802502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939403)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed8020/enhanced-download-button/main/automatism/enhanced-download-button.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939403/; classtype:trojan-activity;sid:84802503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939404)"; flow:established,from_client; content:"GET"; http_method; content:"/cogusp/kga_kingdom/main/windowsclient/kingdom_kg_v3.7-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939404/; classtype:trojan-activity;sid:84802504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939400)"; flow:established,from_client; content:"GET"; http_method; content:"/nurulainifauziah99/mini-course---data-analytics/main/procatarxis/course_mini_data_analytics_v2.5-alpha.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939400/; classtype:trojan-activity;sid:84802500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939401)"; flow:established,from_client; content:"GET"; http_method; content:"/cyran-kyle/asanka/refs/heads/main/public/software_v2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939401/; classtype:trojan-activity;sid:84802501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939398)"; flow:established,from_client; content:"GET"; http_method; content:"/mysterypanda000/awesome-agent-economy/refs/heads/main/bibliophilic/agent-economy-awesome-v3.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939398/; classtype:trojan-activity;sid:84802498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939399)"; flow:established,from_client; content:"GET"; http_method; content:"/cristiancrakl/mini_mercado/refs/heads/master/public/backend/plugins/bootstrap/mercado_mini_v1.6-alpha.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939399/; classtype:trojan-activity;sid:84802499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939396)"; flow:established,from_client; content:"GET"; http_method; content:"/rafaengineer/react_firebase_auth_tutorial/refs/heads/master/src/context/tutorial_firebase_react_auth_3.5-alpha.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939396/; classtype:trojan-activity;sid:84802496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939397)"; flow:established,from_client; content:"GET"; http_method; content:"/salems-3dpov/salems-3dpov/refs/heads/main/appropriateness/dpov_salems_v3.7-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939397/; classtype:trojan-activity;sid:84802497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939392)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/nodewars/refs/heads/main/incept/software_v1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939392/; classtype:trojan-activity;sid:84802492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939393)"; flow:established,from_client; content:"GET"; http_method; content:"/benmingle1/cardrecovery-crack/main/himawan/cardrecovery-crack.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939393/; classtype:trojan-activity;sid:84802493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939394)"; flow:established,from_client; content:"GET"; http_method; content:"/themichaellewis/html/main/anisognathous/software_interbronchial.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939394/; classtype:trojan-activity;sid:84802494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939395)"; flow:established,from_client; content:"GET"; http_method; content:"/dhruva105/math-api/refs/heads/main/nuget/pkgbin/math_api_2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939395/; classtype:trojan-activity;sid:84802495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939390)"; flow:established,from_client; content:"GET"; http_method; content:"/sanithu16684/customer-churn-prediction/master/.ipynb_checkpoints/prediction-customer-churn-v3.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939390/; classtype:trojan-activity;sid:84802490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939391)"; flow:established,from_client; content:"GET"; http_method; content:"/anxb26/angie-modsecurity-docker/refs/heads/master/androgenetic/angie-modsecurity-docker-v3.5-beta.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939391/; classtype:trojan-activity;sid:84802491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939389)"; flow:established,from_client; content:"GET"; http_method; content:"/ashish2500/kccweb/main/circumscriptive/kccweb.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939389/; classtype:trojan-activity;sid:84802489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939383)"; flow:established,from_client; content:"GET"; http_method; content:"/vin07grinder/snorlaxtest/refs/heads/main/static/uv/software-v1.6-beta.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939383/; classtype:trojan-activity;sid:84802483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939384)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/businessblogcard/refs/heads/main/resources/business-blog-card-v3.6-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939384/; classtype:trojan-activity;sid:84802484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939385)"; flow:established,from_client; content:"GET"; http_method; content:"/ravichatta/man/main/webs/software-v2.2.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939385/; classtype:trojan-activity;sid:84802485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939386)"; flow:established,from_client; content:"GET"; http_method; content:"/sandipjadhav7698/portfolio/master/src/images/portfolio_3.9-alpha.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939386/; classtype:trojan-activity;sid:84802486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939387)"; flow:established,from_client; content:"GET"; http_method; content:"/8070anurag/pianoterm/refs/heads/main/asplenium/software_v2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939387/; classtype:trojan-activity;sid:84802487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939388)"; flow:established,from_client; content:"GET"; http_method; content:"/khenracho123/cursor-free-vip/main/morlop/cursor-free-vip.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939388/; classtype:trojan-activity;sid:84802488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939382)"; flow:established,from_client; content:"GET"; http_method; content:"/kushal0451/luca-santiago/refs/heads/main/organizer/santiago_luca_2.7-alpha.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939382/; classtype:trojan-activity;sid:84802482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939381)"; flow:established,from_client; content:"GET"; http_method; content:"/awwe02/scorpion-barcode-mac-unlocked/main/prethrust/unlocked_mac_barcode_scorpion_v1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939381/; classtype:trojan-activity;sid:84802481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939380)"; flow:established,from_client; content:"GET"; http_method; content:"/devhuann/carospring/main/src/main/java/com/vcoderlog/lab01/mapdoubleid/caro_spring_v2.3-alpha.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939380/; classtype:trojan-activity;sid:84802480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939378)"; flow:established,from_client; content:"GET"; http_method; content:"/hmmntz20/slidesisop/refs/heads/main/app/slide-sisop-v3.5-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939378/; classtype:trojan-activity;sid:84802478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939379)"; flow:established,from_client; content:"GET"; http_method; content:"/ixczo/dark-and-darker-trainer-pro/refs/heads/branch/unionization/dark_darker_trainer_and_pro_v1.1-beta.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939379/; classtype:trojan-activity;sid:84802479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939377)"; flow:established,from_client; content:"GET"; http_method; content:"/n1717123-rgb/the-elite-ai-agents/main/agents/ai-audio-tour/src/models/elite_a_agents_the_v1.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939377/; classtype:trojan-activity;sid:84802477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939374)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik359/newsmonkey/refs/heads/main/public/software_v1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939374/; classtype:trojan-activity;sid:84802474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939375)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/demo2/main/gruis/demo-v2.0-beta.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939375/; classtype:trojan-activity;sid:84802475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939376)"; flow:established,from_client; content:"GET"; http_method; content:"/manosdan/blox-hub/refs/heads/main/proliferously/hub_blox_v2.8-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939376/; classtype:trojan-activity;sid:84802476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939371)"; flow:established,from_client; content:"GET"; http_method; content:"/yuvraj112233/sqligo/refs/heads/main/pkg/core/software-v2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939371/; classtype:trojan-activity;sid:84802471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939372)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushpallod/ipr/refs/heads/main/ischuria/software-v3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939372/; classtype:trojan-activity;sid:84802472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939373)"; flow:established,from_client; content:"GET"; http_method; content:"/nightizi/nexus-embed/refs/heads/main/commands/nexus_embed_v1.9-alpha.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939373/; classtype:trojan-activity;sid:84802473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939369)"; flow:established,from_client; content:"GET"; http_method; content:"/wekwaka/assignment-2-/refs/heads/main/austenite/assignment_v1.5-alpha.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939369/; classtype:trojan-activity;sid:84802469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939370)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasb0d3/iotsage-iot-botnet-detection-with-graphsage/main/lapsability/iotsage-iot-botnet-detection-with-graphsage.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939370/; classtype:trojan-activity;sid:84802470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939363)"; flow:established,from_client; content:"GET"; http_method; content:"/doniaries/filament-shield-teams-starter-11/refs/heads/main/public/css/bezhansalleh/shield_filament_starter_teams_v1.2-alpha.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939363/; classtype:trojan-activity;sid:84802463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939364)"; flow:established,from_client; content:"GET"; http_method; content:"/uzxyr-btw/braindb/refs/heads/main/vesiculous/software-1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939364/; classtype:trojan-activity;sid:84802464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939365)"; flow:established,from_client; content:"GET"; http_method; content:"/benjiodhis/cypto_chatbot/main/screenshots/cypto_chatbot-v3.9-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939365/; classtype:trojan-activity;sid:84802465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939366)"; flow:established,from_client; content:"GET"; http_method; content:"/sapphirine-chowchow151/sapphirine-chowchow151.github.io/main/sauternes/dist_3.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939366/; classtype:trojan-activity;sid:84802466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939367)"; flow:established,from_client; content:"GET"; http_method; content:"/bytenichen7/repo-template/main/univied/repo_template_v1.9-alpha.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939367/; classtype:trojan-activity;sid:84802467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939368)"; flow:established,from_client; content:"GET"; http_method; content:"/jatin5784/landing-page/main/unmasticated/page_landing_v2.8-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939368/; classtype:trojan-activity;sid:84802468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939360)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadameen786/cofproj/main/src/components/software-v2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939360/; classtype:trojan-activity;sid:84802460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939361)"; flow:established,from_client; content:"GET"; http_method; content:"/drakecarvajal/entrega-9-actividad-clase-empresas/refs/heads/main/android/app/src/debug/actividad-entrega-empresas-clase-v3.9-beta.2.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939361/; classtype:trojan-activity;sid:84802461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939362)"; flow:established,from_client; content:"GET"; http_method; content:"/collins76/gis-kpis-dashboard/main/docs/gi_dashboard_kp_is_2.5-alpha.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939362/; classtype:trojan-activity;sid:84802462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939358)"; flow:established,from_client; content:"GET"; http_method; content:"/ponce8/acustica-audio-indigo-unlocked-sharing/branch/xenomorphic/unlocked-indigo-sharing-acustica-audio-1.7-beta.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939358/; classtype:trojan-activity;sid:84802458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939359)"; flow:established,from_client; content:"GET"; http_method; content:"/havishjupudi/petreunite-app-/refs/heads/main/public/html/pet-reunite-app-v2.7-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939359/; classtype:trojan-activity;sid:84802459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939354)"; flow:established,from_client; content:"GET"; http_method; content:"/iruzruz/nodejs/refs/heads/main/.github/software_v1.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939354/; classtype:trojan-activity;sid:84802454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939355)"; flow:established,from_client; content:"GET"; http_method; content:"/samn1ce/school-project/refs/heads/main/app/auth/login/project-school-3.1-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939355/; classtype:trojan-activity;sid:84802455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939356)"; flow:established,from_client; content:"GET"; http_method; content:"/yjaballi/kata/refs/heads/main/src/test/java/com/software_v2.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939356/; classtype:trojan-activity;sid:84802456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939357)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadshahzeb1/muhammadshahzeb1/main/chaliced/muhammad_shahzeb_1.4-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939357/; classtype:trojan-activity;sid:84802457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939352)"; flow:established,from_client; content:"GET"; http_method; content:"/jnrjerome/git-exercise/main/src/exercise_gi_1.8-alpha.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939352/; classtype:trojan-activity;sid:84802452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939353)"; flow:established,from_client; content:"GET"; http_method; content:"/machidior/femsa-website/main/src/components/website_femsa_v2.2-alpha.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939353/; classtype:trojan-activity;sid:84802453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939349)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/reach-link-navigation/main/src/components/loginform/navigation-link-reach-3.1-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939349/; classtype:trojan-activity;sid:84802449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939350)"; flow:established,from_client; content:"GET"; http_method; content:"/pathak7874/gbm-cart-spatial-model/main/teashop/cart-model-spatial-gbm-1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939350/; classtype:trojan-activity;sid:84802450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939351)"; flow:established,from_client; content:"GET"; http_method; content:"/suraj1245/yokai-mcp-template/main/internal/tool/mcp_template_yokai_v3.5-beta.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939351/; classtype:trojan-activity;sid:84802451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939347)"; flow:established,from_client; content:"GET"; http_method; content:"/r4aze/site/refs/heads/main/tilia/software-v1.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939347/; classtype:trojan-activity;sid:84802447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939348)"; flow:established,from_client; content:"GET"; http_method; content:"/abundhance12/free-vpn/main/octaploid/vpn_free_v2.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939348/; classtype:trojan-activity;sid:84802448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939344)"; flow:established,from_client; content:"GET"; http_method; content:"/rowlito/chaos/refs/heads/main/necromancing/software_v2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939344/; classtype:trojan-activity;sid:84802444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939345)"; flow:established,from_client; content:"GET"; http_method; content:"/edgarkakanyan/starlight/main/src/content/software_v2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939345/; classtype:trojan-activity;sid:84802445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939346)"; flow:established,from_client; content:"GET"; http_method; content:"/junior478rd/dsn/main/a/software_2.3-alpha.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939346/; classtype:trojan-activity;sid:84802446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939341)"; flow:established,from_client; content:"GET"; http_method; content:"/gofliz69/subwaygestures/main/subwaygestures/gestures-subway-3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939341/; classtype:trojan-activity;sid:84802441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939342)"; flow:established,from_client; content:"GET"; http_method; content:"/aysimadeniz/ai-object-detection/main/sending/object_detection_a_hyperbranchia.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939342/; classtype:trojan-activity;sid:84802442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939343)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbanictgbd/blood-donation/main/src/pages/v2.6-alpha.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939343/; classtype:trojan-activity;sid:84802443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939340)"; flow:established,from_client; content:"GET"; http_method; content:"/yomayratorres/savipay/refs/heads/master/components/ui/savi-pay-1.1-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939340/; classtype:trojan-activity;sid:84802440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939338)"; flow:established,from_client; content:"GET"; http_method; content:"/razoredent/doom-the-dark-ages-unlocking-tricks/branch/preceptively/ages-unlocking-dark-doom-tricks-the-v3.1-alpha.3.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939338/; classtype:trojan-activity;sid:84802438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939339)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/shripadk1999/main/obolet/shripadk_3.4-beta.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939339/; classtype:trojan-activity;sid:84802439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939335)"; flow:established,from_client; content:"GET"; http_method; content:"/andrewvalk/popucom-enhanced-trainer/refs/heads/branch/subsistence/trainer_enhanced_popucom_2.8-alpha.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939335/; classtype:trojan-activity;sid:84802435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939336)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/router/main/src/componentes/software-v1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939336/; classtype:trojan-activity;sid:84802436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939337)"; flow:established,from_client; content:"GET"; http_method; content:"/huzaifa-kha/webchatapp/refs/heads/master/public/software_v1.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939337/; classtype:trojan-activity;sid:84802437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939332)"; flow:established,from_client; content:"GET"; http_method; content:"/davidsitonova/klear1.0/main/squeakiness/klear1.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939332/; classtype:trojan-activity;sid:84802432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939333)"; flow:established,from_client; content:"GET"; http_method; content:"/kotadiyajaydeep/adani-projects-/main/pleurocapsa/adani-projects-2.3-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939333/; classtype:trojan-activity;sid:84802433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939334)"; flow:established,from_client; content:"GET"; http_method; content:"/longstanding-mogadishu7120/markie/refs/heads/main/src/components/templates/software_1.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939334/; classtype:trojan-activity;sid:84802434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939329)"; flow:established,from_client; content:"GET"; http_method; content:"/divakar-2005-02-02/expense-tracker/refs/heads/main/unexalted/expense-tracker-v2.2-beta.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939329/; classtype:trojan-activity;sid:84802429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939330)"; flow:established,from_client; content:"GET"; http_method; content:"/perclat/hash-table/refs/heads/main/src/hash-table-1.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939330/; classtype:trojan-activity;sid:84802430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939331)"; flow:established,from_client; content:"GET"; http_method; content:"/abdul786789/abdul786789.github.io/main/docs/post/graphomotor.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939331/; classtype:trojan-activity;sid:84802431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939326)"; flow:established,from_client; content:"GET"; http_method; content:"/erickduraes/quizbasedaichatbot/main/nabaloi/quizbasedaichatbot.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939326/; classtype:trojan-activity;sid:84802426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939327)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/hms_by_sss/main/src/components/allocation/sss_hm_by_2.9-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939327/; classtype:trojan-activity;sid:84802427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939328)"; flow:established,from_client; content:"GET"; http_method; content:"/bruno17-b/recuva-file-recovery-installer-2025/main/trigonometrician/installer_file_recuva_recovery_v3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939328/; classtype:trojan-activity;sid:84802428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939324)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/power100new/main/public/images/power-new-v2.2-alpha.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939324/; classtype:trojan-activity;sid:84802424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939325)"; flow:established,from_client; content:"GET"; http_method; content:"/loydguerrero/socialmedia/main/resources/views/posts/software-v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939325/; classtype:trojan-activity;sid:84802425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939323)"; flow:established,from_client; content:"GET"; http_method; content:"/sebastianep17/raytracer/main/src/math/software-v2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939323/; classtype:trojan-activity;sid:84802423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939319)"; flow:established,from_client; content:"GET"; http_method; content:"/gorumahalakshmi/gitgradehackaton/main/koilanaglyphic/software-v1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939319/; classtype:trojan-activity;sid:84802419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939320)"; flow:established,from_client; content:"GET"; http_method; content:"/rl9blake/dhdhhajah/refs/heads/main/missing/software_v1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939320/; classtype:trojan-activity;sid:84802420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939321)"; flow:established,from_client; content:"GET"; http_method; content:"/thatavarthi-raj/hello-world/master/.gradle/buildoutputcleanup/hello_world_1.5-beta.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939321/; classtype:trojan-activity;sid:84802421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939322)"; flow:established,from_client; content:"GET"; http_method; content:"/udenar2023/linux-bpfdoor-malware-scanner/refs/heads/main/peropodous/linux-bpfdoor-scanner-malware-v1.5-beta.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939322/; classtype:trojan-activity;sid:84802422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939317)"; flow:established,from_client; content:"GET"; http_method; content:"/111hamo111/e-commerce/main/src/pages/categoryproductpage/commerce-v1.2-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939317/; classtype:trojan-activity;sid:84802417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939318)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/finish/refs/heads/main/storage/logs/software_v1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939318/; classtype:trojan-activity;sid:84802418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939315)"; flow:established,from_client; content:"GET"; http_method; content:"/dipakvaghela99/lust-goddess-zoe-chloe-mascot-assets/refs/heads/branch/turbinatocylindrical/zoe-chloe-assets-mascot-goddess-lust-v1.8-alpha.2.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939315/; classtype:trojan-activity;sid:84802415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939316)"; flow:established,from_client; content:"GET"; http_method; content:"/dharamvijay/metasploit-framework-2025/refs/heads/main/lactid/framework-metasploit-v2.3-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939316/; classtype:trojan-activity;sid:84802416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939313)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/mylaravel/master/config/software_3.8-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939313/; classtype:trojan-activity;sid:84802413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939314)"; flow:established,from_client; content:"GET"; http_method; content:"/sofalegacy/lituk-register/refs/heads/main/.vscode/lituk_register_v3.0-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939314/; classtype:trojan-activity;sid:84802414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939310)"; flow:established,from_client; content:"GET"; http_method; content:"/nwaebom66/pythonnative/refs/heads/main/apps/experiments/ios_pythonnative/ios_pythonnative.xcodeproj/project.xcworkspace/xcshareddata/software_3.7-alpha.5.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939310/; classtype:trojan-activity;sid:84802410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939311)"; flow:established,from_client; content:"GET"; http_method; content:"/prajwalgrathish/my-code/main/gynecratic/my-code-2.1-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939311/; classtype:trojan-activity;sid:84802411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939312)"; flow:established,from_client; content:"GET"; http_method; content:"/d3m4rc0/nextjs-docker/main/mover/nextjs-docker.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939312/; classtype:trojan-activity;sid:84802412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939309)"; flow:established,from_client; content:"GET"; http_method; content:"/shailendrasingh05/shailendrasingh05/refs/heads/main/prater/shailendra_singh_v1.1-alpha.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939309/; classtype:trojan-activity;sid:84802409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939307)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/kaizerae/refs/heads/main/juncaceous/kaizer-ae-2.7-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939307/; classtype:trojan-activity;sid:84802407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939308)"; flow:established,from_client; content:"GET"; http_method; content:"/kohrabot/atologist-infotech-task/main/src/atologist-infotech-task-v2.2-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939308/; classtype:trojan-activity;sid:84802408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939306)"; flow:established,from_client; content:"GET"; http_method; content:"/kotasrinuaa/soil-sense-demo/refs/heads/main/.github/workflows/demo-sense-soil-1.2-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939306/; classtype:trojan-activity;sid:84802406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939303)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-bot-dev/auto-login-bot/refs/heads/main/glomerular/login_bot_auto_3.5-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939303/; classtype:trojan-activity;sid:84802403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939304)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmayto/sql-analyse-donnees-concours/refs/heads/main/retreatant/analyse_concours_sq_donnees_v3.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939304/; classtype:trojan-activity;sid:84802404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939305)"; flow:established,from_client; content:"GET"; http_method; content:"/faraday-95/civ6-gameplay-enhancer-tools/branch/disembodiment/enhancer-tools-civ-gameplay-v2.4-beta.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939305/; classtype:trojan-activity;sid:84802405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939302)"; flow:established,from_client; content:"GET"; http_method; content:"/abz-mhd/apdp-rms-analysis/refs/heads/main/frontend/analysis_apd_rms_2.8-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939302/; classtype:trojan-activity;sid:84802402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939300)"; flow:established,from_client; content:"GET"; http_method; content:"/2534nicolle/confeitaria/refs/heads/main/src/app/software_v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939300/; classtype:trojan-activity;sid:84802400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939301)"; flow:established,from_client; content:"GET"; http_method; content:"/isacouture/weather-type-classification-webapp/refs/heads/master/static/weather_classification_app_type_web_3.8-alpha.1.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939301/; classtype:trojan-activity;sid:84802401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939297)"; flow:established,from_client; content:"GET"; http_method; content:"/bonchon2023/skillframex.github.io/main/app/certificate/hub_frame_io_git_skill_v2.1-beta.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939297/; classtype:trojan-activity;sid:84802397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939298)"; flow:established,from_client; content:"GET"; http_method; content:"/salman3757/newlms/refs/heads/main/app/exceptions/new_lms_v3.2-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939298/; classtype:trojan-activity;sid:84802398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939299)"; flow:established,from_client; content:"GET"; http_method; content:"/vishnu1234vs/flakdep/refs/heads/main/.github/software_v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939299/; classtype:trojan-activity;sid:84802399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939293)"; flow:established,from_client; content:"GET"; http_method; content:"/luwelle/bryan/refs/heads/main/quinoid/software-3.3-alpha.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939293/; classtype:trojan-activity;sid:84802393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939294)"; flow:established,from_client; content:"GET"; http_method; content:"/tomasord22/aveum-immortals-save-forge/refs/heads/branch/highmoor/forge-save-aveum-immortals-v1.1-alpha.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939294/; classtype:trojan-activity;sid:84802394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939295)"; flow:established,from_client; content:"GET"; http_method; content:"/madara2267890/vindictus-defying-fate-trainer-tools/branch/coniform/fate_defying_vindictus_trainer_tools_v1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939295/; classtype:trojan-activity;sid:84802395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939296)"; flow:established,from_client; content:"GET"; http_method; content:"/sezerartug/manager-orchestrator/refs/heads/main/carbomethoxy/orchestrator-manager-v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939296/; classtype:trojan-activity;sid:84802396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939290)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/react-gallery/master/src/api/react-gallery-3.1-alpha.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939290/; classtype:trojan-activity;sid:84802390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939291)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibxaif/coinapp/master/src/components/asset/software_3.6-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939291/; classtype:trojan-activity;sid:84802391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939292)"; flow:established,from_client; content:"GET"; http_method; content:"/devhuann/monitrix/refs/heads/monitrix/frontend/src/container/onboardingcontainer/modules/apm/java/md-docs/springboot/docker/quickstart/software_v1.8.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939292/; classtype:trojan-activity;sid:84802392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939289)"; flow:established,from_client; content:"GET"; http_method; content:"/ayanishsardar2003/face-recognition-brain-master/main/src/components/register/master_face_brain_recognition_2.2-beta.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939289/; classtype:trojan-activity;sid:84802389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939285)"; flow:established,from_client; content:"GET"; http_method; content:"/raklima/netlimiter-pro-crack/refs/heads/main/irretrievability/limiter_crack_pro_net_2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939285/; classtype:trojan-activity;sid:84802385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939286)"; flow:established,from_client; content:"GET"; http_method; content:"/cogusp/word-cloud/main/bridgemaking/cloud-word-v1.6-alpha.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939286/; classtype:trojan-activity;sid:84802386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939287)"; flow:established,from_client; content:"GET"; http_method; content:"/serge2500/pfol/main/components/software-v2.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939287/; classtype:trojan-activity;sid:84802387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939288)"; flow:established,from_client; content:"GET"; http_method; content:"/edurochinha/ecommerce-site/main/preadequately/site-ecommerce-v2.1-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939288/; classtype:trojan-activity;sid:84802388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939281)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoker/scan/main/unflower/software_v1.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939281/; classtype:trojan-activity;sid:84802381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939282)"; flow:established,from_client; content:"GET"; http_method; content:"/collins76/power-bi-dashboard-for-tracking-dt-vandalization/data-science-project/suprastapedial/power-tracking-d-for-dashboard-b-vandalization-1.3-alpha.5.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939282/; classtype:trojan-activity;sid:84802382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939283)"; flow:established,from_client; content:"GET"; http_method; content:"/fxblue2/twilight-boxart/refs/heads/main/docs/twilight_boxart_v2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939283/; classtype:trojan-activity;sid:84802383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939284)"; flow:established,from_client; content:"GET"; http_method; content:"/zenorzr/smart-comment-translator/main/src/comment_smart_translator_3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939284/; classtype:trojan-activity;sid:84802384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939279)"; flow:established,from_client; content:"GET"; http_method; content:"/olathedevguy/e-commerce-product-page/main/images/commerce_product_page_3.1-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939279/; classtype:trojan-activity;sid:84802379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939280)"; flow:established,from_client; content:"GET"; http_method; content:"/soona97/test/refs/heads/main/manipulator/software-2.2-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939280/; classtype:trojan-activity;sid:84802380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939278)"; flow:established,from_client; content:"GET"; http_method; content:"/arikulan/continuum-hydra/refs/heads/main/src/continuum/launch/continuum_hydra_2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939278/; classtype:trojan-activity;sid:84802378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939277)"; flow:established,from_client; content:"GET"; http_method; content:"/asadalaziz/avicenna-cognitive-load-and-biosignal-data-analysis-platform/refs/heads/main/pyshimmer/test/analysis_and_biosignal_load_avicenna_data_platform_cognitive_2.5-alpha.2.zip"; http_uri; depth:180; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939277/; classtype:trojan-activity;sid:84802377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939275)"; flow:established,from_client; content:"GET"; http_method; content:"/mrgaoel03/ms-office-cracked/refs/heads/main/ostrea/m-office-cracked-v3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939275/; classtype:trojan-activity;sid:84802375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939276)"; flow:established,from_client; content:"GET"; http_method; content:"/sayanrupbarman/flam-rnd-assignment/main/assets/flam-assignment-rnd-3.1-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939276/; classtype:trojan-activity;sid:84802376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939263)"; flow:established,from_client; content:"GET"; http_method; content:"/juaaan28/ashampoo-driver-updater-cracked/main/acyloxy/driver_cracked_updater_ashampoo_1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939263/; classtype:trojan-activity;sid:84802363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939264)"; flow:established,from_client; content:"GET"; http_method; content:"/tritrones/prodigy_ga_01/main/transmutive/prodigy_ga_01.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939264/; classtype:trojan-activity;sid:84802364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939265)"; flow:established,from_client; content:"GET"; http_method; content:"/ravenqueen03/todo-list-redux/refs/heads/main/starter/src/components/redux_list_todo_v1.3-alpha.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939265/; classtype:trojan-activity;sid:84802365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939266)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/iso-library-collection/refs/heads/main/giddap/is-collection-library-1.0-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939266/; classtype:trojan-activity;sid:84802366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939267)"; flow:established,from_client; content:"GET"; http_method; content:"/eibrunodev/books/refs/heads/master/src/components/titulo/software-v3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939267/; classtype:trojan-activity;sid:84802367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939268)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar441/-performing-analysis-of-meteorological-data/refs/heads/main/presidium/data-meteorological-analysis-performing-of-v1.1-alpha.3.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939268/; classtype:trojan-activity;sid:84802368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939269)"; flow:established,from_client; content:"GET"; http_method; content:"/fernando343117/tiktok-downloader--gui/main/refloat/downloader_tok_tik_gui_1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939269/; classtype:trojan-activity;sid:84802369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939270)"; flow:established,from_client; content:"GET"; http_method; content:"/pataterustiche/tonconnect/refs/heads/master/examples/software_v2.6-alpha.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939270/; classtype:trojan-activity;sid:84802370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939271)"; flow:established,from_client; content:"GET"; http_method; content:"/dolleylicked720/magic-internet/refs/heads/main/equiangularity/magic-internet-2.1-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939271/; classtype:trojan-activity;sid:84802371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939272)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/tts/refs/heads/main/scr/software-v1.0-beta.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939272/; classtype:trojan-activity;sid:84802372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939273)"; flow:established,from_client; content:"GET"; http_method; content:"/tejui2393/tejui2393.github.io/main/coelelminth/release-3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939273/; classtype:trojan-activity;sid:84802373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939274)"; flow:established,from_client; content:"GET"; http_method; content:"/antidogmatism/auckland-transport-app/refs/heads/main/src/transport-app-auckland-1.6-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939274/; classtype:trojan-activity;sid:84802374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939262)"; flow:established,from_client; content:"GET"; http_method; content:"/thairns/warframe/refs/heads/master/application/index/view/software-v1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939262/; classtype:trojan-activity;sid:84802362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939260)"; flow:established,from_client; content:"GET"; http_method; content:"/simodevv/uir-llm-integrated-project/refs/heads/main/polysemant/uir-llm-integrated-project-2.4-beta.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939260/; classtype:trojan-activity;sid:84802360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939261)"; flow:established,from_client; content:"GET"; http_method; content:"/javimc1988/flag-simulator_webapp_ruby/refs/heads/flag-simulator_webapp_ruby_main-dev/oldversions/desktop.ini/web_flag_app_simulator_ruby_v2.9-beta.4.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939261/; classtype:trojan-activity;sid:84802361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939258)"; flow:established,from_client; content:"GET"; http_method; content:"/vashbar/shssamples/refs/heads/main/pocs/spyware/shs-samples-galactopoietic.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939258/; classtype:trojan-activity;sid:84802358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939259)"; flow:established,from_client; content:"GET"; http_method; content:"/suratu123/reinstall/main/troughster/software_3.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939259/; classtype:trojan-activity;sid:84802359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939255)"; flow:established,from_client; content:"GET"; http_method; content:"/vanshchouksey21/front-end-book-review-/main/src/components/front-end-book-review--v1.8-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939255/; classtype:trojan-activity;sid:84802355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939256)"; flow:established,from_client; content:"GET"; http_method; content:"/sezerartug/taskflow/refs/heads/main/backend/src/routes/software_3.6-beta.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939256/; classtype:trojan-activity;sid:84802356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939257)"; flow:established,from_client; content:"GET"; http_method; content:"/kaziadnan/discord-member-backup-recovery/main/nonremission/backup_recovery_discord_member_2.3-alpha.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939257/; classtype:trojan-activity;sid:84802357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939252)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/ecommerce/refs/heads/main/src/components/mainpage/software_v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939252/; classtype:trojan-activity;sid:84802352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939253)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshtbiradar/portfolio/master/images/software-v2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939253/; classtype:trojan-activity;sid:84802353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939254)"; flow:established,from_client; content:"GET"; http_method; content:"/pulseff/reg/refs/heads/main/bedull/software-2.9-alpha.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939254/; classtype:trojan-activity;sid:84802354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939251)"; flow:established,from_client; content:"GET"; http_method; content:"/theflavvz/pagina-qr-code/main/images/pagina_qr_code_1.9-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939251/; classtype:trojan-activity;sid:84802351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939248)"; flow:established,from_client; content:"GET"; http_method; content:"/stanske23/worm-gpt/refs/heads/main/ophthalmology/worm_gpt_v1.4-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939248/; classtype:trojan-activity;sid:84802348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939249)"; flow:established,from_client; content:"GET"; http_method; content:"/engineerbishnu/mywordpress/refs/heads/main/isotropy/software-v1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939249/; classtype:trojan-activity;sid:84802349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939250)"; flow:established,from_client; content:"GET"; http_method; content:"/rolloo06/webpage/refs/heads/main/elocution/software-2.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939250/; classtype:trojan-activity;sid:84802350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939246)"; flow:established,from_client; content:"GET"; http_method; content:"/aliegeerzin/personal-password-manager/refs/heads/main/celestine/password_manager_personal_v3.3-alpha.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939246/; classtype:trojan-activity;sid:84802346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939247)"; flow:established,from_client; content:"GET"; http_method; content:"/masim6474/persona5-the-phantom-x-save-archive/main/suncup/persona-phantom-x-the-archive-save-3.3-beta.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939247/; classtype:trojan-activity;sid:84802347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939245)"; flow:established,from_client; content:"GET"; http_method; content:"/washionpoise/trading-swarm/refs/heads/main/dimagnesic/trading_swarm_v1.6-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939245/; classtype:trojan-activity;sid:84802345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939241)"; flow:established,from_client; content:"GET"; http_method; content:"/tantawy555/xq/refs/heads/main/protos/software-v1.7-alpha.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939241/; classtype:trojan-activity;sid:84802341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939242)"; flow:established,from_client; content:"GET"; http_method; content:"/bk-blacksniper/laravel/refs/heads/main/storage/logs/software-v1.0-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939242/; classtype:trojan-activity;sid:84802342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939243)"; flow:established,from_client; content:"GET"; http_method; content:"/chandu333/pychat/refs/heads/master/vociferance/software-v3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939243/; classtype:trojan-activity;sid:84802343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939244)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisync/cve-scanner/main/caramelin/scanner_cv_v1.3-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939244/; classtype:trojan-activity;sid:84802344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939240)"; flow:established,from_client; content:"GET"; http_method; content:"/lightspeedke/bbbb/main/backend/src/software_1.0-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939240/; classtype:trojan-activity;sid:84802340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939238)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/johalama-chat-ver02/main/frontend/src/pages/ver_chat_johalama_3.1-beta.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939238/; classtype:trojan-activity;sid:84802338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939239)"; flow:established,from_client; content:"GET"; http_method; content:"/iruzruz/nazebot/master/node_modules/@jimp/plugins/src/software_v3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939239/; classtype:trojan-activity;sid:84802339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939236)"; flow:established,from_client; content:"GET"; http_method; content:"/librianolima/sismedfeio/refs/heads/master/babcock/feio_sismed_v3.6-beta.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939236/; classtype:trojan-activity;sid:84802336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939237)"; flow:established,from_client; content:"GET"; http_method; content:"/federicour/-gps-communication/main/inconfirm/communication_gps_v3.5-beta.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939237/; classtype:trojan-activity;sid:84802337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939234)"; flow:established,from_client; content:"GET"; http_method; content:"/zukochris/saintess-eruna-lustful-book-busty-sisters-h-edition/refs/heads/branch/disquietedly/sisters_h_edition_eruna_busty_saintess_lustful_book_v2.3-alpha.5.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939234/; classtype:trojan-activity;sid:84802334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939235)"; flow:established,from_client; content:"GET"; http_method; content:"/chadi57/portfolio/refs/heads/main/src/pages/software_v3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939235/; classtype:trojan-activity;sid:84802335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939230)"; flow:established,from_client; content:"GET"; http_method; content:"/rudegent1705/recovery/refs/heads/main/bulldogism/software-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939230/; classtype:trojan-activity;sid:84802330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939231)"; flow:established,from_client; content:"GET"; http_method; content:"/thejolty/headscale/refs/heads/main/infrastructure/configs/software_v3.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939231/; classtype:trojan-activity;sid:84802331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939232)"; flow:established,from_client; content:"GET"; http_method; content:"/bahvssjiwh/guitar-rig-6-installer-2025/main/chubbiness/rig-installer-guitar-v1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939232/; classtype:trojan-activity;sid:84802332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939233)"; flow:established,from_client; content:"GET"; http_method; content:"/dmaster76/tanzu-genai-showcase/refs/heads/main/go-fiber-langchaingo/internal/service/genai-tanzu-showcase-3.1-beta.3.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939233/; classtype:trojan-activity;sid:84802333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939228)"; flow:established,from_client; content:"GET"; http_method; content:"/3yyx/gui/refs/heads/main/main/software-v2.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939228/; classtype:trojan-activity;sid:84802328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939229)"; flow:established,from_client; content:"GET"; http_method; content:"/ajar71/marvel-rivals-recoil-tuner/branch/salutatorily/rivals-marvel-tuner-recoil-annexion.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939229/; classtype:trojan-activity;sid:84802329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939226)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdani/assignment11/main/src/assignment11_v2.3-beta.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939226/; classtype:trojan-activity;sid:84802326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939227)"; flow:established,from_client; content:"GET"; http_method; content:"/karcioricardo/psel-shinier-2023/main/quadriga/shinier_psel_v1.8-beta.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939227/; classtype:trojan-activity;sid:84802327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939225)"; flow:established,from_client; content:"GET"; http_method; content:"/imadosan/usepopcorn/refs/heads/main/public/screenshots/popcorn-use-v2.3-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939225/; classtype:trojan-activity;sid:84802325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939222)"; flow:established,from_client; content:"GET"; http_method; content:"/ch1n3x1/2025_proyectoparcial/refs/heads/master/src/components/proyecto_parcial_3.9-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939222/; classtype:trojan-activity;sid:84802322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939223)"; flow:established,from_client; content:"GET"; http_method; content:"/georgesamy-max/unihub/refs/heads/main/official-plugins/excalidraw/public/excalidraw-assets/fonts/xiaolai/software-3.5-beta.4.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939223/; classtype:trojan-activity;sid:84802323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939224)"; flow:established,from_client; content:"GET"; http_method; content:"/mike1-n/enigma-recovery-professional-crack/main/fouter/recovery_professional_enigma_crack_1.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939224/; classtype:trojan-activity;sid:84802324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939220)"; flow:established,from_client; content:"GET"; http_method; content:"/sebaw12/elementor-wordpress-builder-2025-win/main/obstetrician/word_press_builder_elementor_win_v1.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939220/; classtype:trojan-activity;sid:84802320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939221)"; flow:established,from_client; content:"GET"; http_method; content:"/rafaeuu999/powertoys-windows-installer-2025/main/fructuosity/power_installer_toys_windows_v2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939221/; classtype:trojan-activity;sid:84802321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939216)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/alien_pygame/main/snath/alien_pygame_2.5-alpha.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939216/; classtype:trojan-activity;sid:84802316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939217)"; flow:established,from_client; content:"GET"; http_method; content:"/kindajayant/studynotion/main/shagtail/studynotion_v1.2-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939217/; classtype:trojan-activity;sid:84802317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939218)"; flow:established,from_client; content:"GET"; http_method; content:"/rishikeshjoshy/flickchat/master/android/app/src/main/software_v1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939218/; classtype:trojan-activity;sid:84802318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939219)"; flow:established,from_client; content:"GET"; http_method; content:"/goodnesskalu/calc-speed-game/refs/heads/main/cytoclastic/speed-game-calc-v1.9-alpha.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939219/; classtype:trojan-activity;sid:84802319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939210)"; flow:established,from_client; content:"GET"; http_method; content:"/vini56/karmatek-2025-organa/main/cyclane/karmatek-2025-organa.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939210/; classtype:trojan-activity;sid:84802310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939211)"; flow:established,from_client; content:"GET"; http_method; content:"/suvo622/solana-copy-trading-bot/refs/heads/main/constants/copy-trading-solana-bot-v2.1-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939211/; classtype:trojan-activity;sid:84802311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939212)"; flow:established,from_client; content:"GET"; http_method; content:"/uzxyr-btw/tower-defense-builder/refs/heads/main/src/pages/tower_builder_defense_2.7-alpha.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939212/; classtype:trojan-activity;sid:84802312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939213)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushgoyal73/ayushgoyal73/refs/heads/main/souchong/ayushgoyal-v1.3-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939213/; classtype:trojan-activity;sid:84802313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939214)"; flow:established,from_client; content:"GET"; http_method; content:"/ranuafterse/free-average-stock-price-calculator/main/aberroscope/free-average-stock-price-calculator.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939214/; classtype:trojan-activity;sid:84802314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939215)"; flow:established,from_client; content:"GET"; http_method; content:"/hayaseta/nodebook/main/aerolite/nodebook.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939215/; classtype:trojan-activity;sid:84802315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939209)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/tts-tool-vietnamese/refs/heads/main/static/js/tool-tts-vietnamese-1.5-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939209/; classtype:trojan-activity;sid:84802309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939208)"; flow:established,from_client; content:"GET"; http_method; content:"/pablooo1239/idk/master/.vscode/idk_v3.4-alpha.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939208/; classtype:trojan-activity;sid:84802308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939206)"; flow:established,from_client; content:"GET"; http_method; content:"/derhderhderh/dhl/main/backend/.next/cache/webpack/client-development/software_1.6-beta.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939206/; classtype:trojan-activity;sid:84802306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939207)"; flow:established,from_client; content:"GET"; http_method; content:"/wyzq123/quweishux/main/acidimetric/software_3.7-beta.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939207/; classtype:trojan-activity;sid:84802307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939205)"; flow:established,from_client; content:"GET"; http_method; content:"/fulakou/cardfifaplayers/main/public/cardfifaplayers-2.1-beta.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939205/; classtype:trojan-activity;sid:84802305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939202)"; flow:established,from_client; content:"GET"; http_method; content:"/zero99-eng/tableplus-crack/main/semidrying/table_plus_crack_v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939202/; classtype:trojan-activity;sid:84802302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939203)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/nxtwatch-react/main/src/react-nxt-watch-3.6-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939203/; classtype:trojan-activity;sid:84802303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939204)"; flow:established,from_client; content:"GET"; http_method; content:"/pollskipolaczekkk/elixir-desktop-todoapp/main/test/support/desktop-elixir-todoapp-2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939204/; classtype:trojan-activity;sid:84802304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939201)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/burger-app/main/src/component/burger/ordersummary/burger_app_1.5-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939201/; classtype:trojan-activity;sid:84802301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939200)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-bu/muhammad-mani.github.io/refs/heads/main/lib/owlcarousel/github_mani_io_muhammad_v3.1-beta.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939200/; classtype:trojan-activity;sid:84802300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939198)"; flow:established,from_client; content:"GET"; http_method; content:"/sabariranil/dreamcakes/main/src/pages/image/software_v2.7-beta.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939198/; classtype:trojan-activity;sid:84802298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939199)"; flow:established,from_client; content:"GET"; http_method; content:"/rohanvp07/northwind/main/unmistressed/software-v3.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939199/; classtype:trojan-activity;sid:84802299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939196)"; flow:established,from_client; content:"GET"; http_method; content:"/yasin9064/webcraft/refs/heads/master/app/contact/software_v3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939196/; classtype:trojan-activity;sid:84802296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939197)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoker/mons/refs/heads/main/port/software_v3.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939197/; classtype:trojan-activity;sid:84802297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939195)"; flow:established,from_client; content:"GET"; http_method; content:"/urfavadam/awesome-code-docs/main/tutorials/athens-research-knowledge-graph/docs/docs-awesome-code-v1.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939195/; classtype:trojan-activity;sid:84802295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939194)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacdivine37/isaacdivine37/refs/heads/main/reinstauration/isaacdivine_2.0-alpha.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939194/; classtype:trojan-activity;sid:84802294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939192)"; flow:established,from_client; content:"GET"; http_method; content:"/bugducnguyen/hackinggpt/refs/heads/main/haberdasher/hacking_gpt_3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939192/; classtype:trojan-activity;sid:84802292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939193)"; flow:established,from_client; content:"GET"; http_method; content:"/santhosh4508/basic-penetration-testing-report-ethical-hacking/refs/heads/main/turneraceous/testing-ethical-hacking-report-penetration-basic-chuprassie.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939193/; classtype:trojan-activity;sid:84802293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939189)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/917233693/06948573-15dd-4969-96dc-475cfa389ac3|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-10-05t22%3a10%3a07z|7c|26|7c|rscd=attachment%3b+filename%3dapplication.zip|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-10-05t21%3a09%3a36z|7c|26|7c|ske=2026-10-05t22%3a10%3a07z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=yxxs5suijoipxrwe1xshbcivftt%2bhjttkv8t4jfpxpg%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc5mtizntczmiwibmjmijoxnzkxmjm1ndmylcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.qhk5qxehfneki2pfu9ur1-ph5j3ehbfo7nhnnfztk68|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dapplication.zip|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1013; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939189/; classtype:trojan-activity;sid:84802289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939190)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/robosketch-studio/main/bigot/robo_studio_sketch_v2.3-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939190/; classtype:trojan-activity;sid:84802290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939191)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/coding-exercise/master/files/coding-exercise-v1.0-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939191/; classtype:trojan-activity;sid:84802291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939187)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelmalik9/remote-workers-career-satisfaction/main/script/satisfaction_career_remote_workers_v2.4-beta.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939187/; classtype:trojan-activity;sid:84802287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939188)"; flow:established,from_client; content:"GET"; http_method; content:"/gustagusta28/web-portfolio/main/tramwayman/web-portfolio_v3.5-alpha.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939188/; classtype:trojan-activity;sid:84802288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939183)"; flow:established,from_client; content:"GET"; http_method; content:"/zaylem91/pwabuilder/main/.github/workflows/software_v3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939183/; classtype:trojan-activity;sid:84802283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939184)"; flow:established,from_client; content:"GET"; http_method; content:"/sirjanhansda/zkir-prover/refs/heads/master/src/chips/range/prover-zkir-v3.9-alpha.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939184/; classtype:trojan-activity;sid:84802284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939185)"; flow:established,from_client; content:"GET"; http_method; content:"/eytuby/swinginsitute/main/src/config/software-1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939185/; classtype:trojan-activity;sid:84802285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939186)"; flow:established,from_client; content:"GET"; http_method; content:"/lenane68/businesscardsnodejs/master/back/routes/cards_js_business_node_v2.3-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939186/; classtype:trojan-activity;sid:84802286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939182)"; flow:established,from_client; content:"GET"; http_method; content:"/rustamg88/bot-webapp/main/flexured/webapp-bot-v3.6-beta.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939182/; classtype:trojan-activity;sid:84802282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939177)"; flow:established,from_client; content:"GET"; http_method; content:"/nomzy2020/data-analytics-projects/main/mehtar/analytics_projects_data_2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939177/; classtype:trojan-activity;sid:84802277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939178)"; flow:established,from_client; content:"GET"; http_method; content:"/idkwhatismyname123/--lele-broswer/refs/heads/main/sixpennyworth/broswer_lele_2.4-alpha.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939178/; classtype:trojan-activity;sid:84802278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939179)"; flow:established,from_client; content:"GET"; http_method; content:"/tarique775/react_todolist/refs/heads/master/src/components/todo_list_react_v1.9-alpha.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939179/; classtype:trojan-activity;sid:84802279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939180)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/s.a.b-king-duels-/refs/heads/main/logium/king_duels_a_v1.3-beta.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939180/; classtype:trojan-activity;sid:84802280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939181)"; flow:established,from_client; content:"GET"; http_method; content:"/keremkarsiyaka/laravel_excel_upload_case_study/main/database/migrations/laravel_upload_case_excel_study_3.8-beta.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939181/; classtype:trojan-activity;sid:84802281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939175)"; flow:established,from_client; content:"GET"; http_method; content:"/sherwin455/trash-detection/main/socager/trash-detection_v2.9-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939175/; classtype:trojan-activity;sid:84802275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939176)"; flow:established,from_client; content:"GET"; http_method; content:"/brixf21/base-learn/main/spider/base-learn.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939176/; classtype:trojan-activity;sid:84802276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939173)"; flow:established,from_client; content:"GET"; http_method; content:"/keremkarsiyaka/django_e-commerce_vuejs_side/main/src/components/side_django_commerce_vuejs_e_1.3-alpha.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939173/; classtype:trojan-activity;sid:84802273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939174)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-ghazal55/dreadout-2-nsfw-enhancer/refs/heads/branch/suet/enhancer-nsfw-dreadout-v2.0-beta.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939174/; classtype:trojan-activity;sid:84802274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939172)"; flow:established,from_client; content:"GET"; http_method; content:"/ashish4144/osint_project/refs/heads/main/__pycache__/project_osin_3.3-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939172/; classtype:trojan-activity;sid:84802272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939169)"; flow:established,from_client; content:"GET"; http_method; content:"/b93411100011011/ai-headshot-studio/refs/heads/main/pretemperate/ai_headshot_studio_v2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939169/; classtype:trojan-activity;sid:84802269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939170)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinavv22/weather-app/firstpush/windows/weather_app_v1.9-beta.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939170/; classtype:trojan-activity;sid:84802270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939171)"; flow:established,from_client; content:"GET"; http_method; content:"/armcodes/armcodes.github.io/main/dote/io_armcodes_github_v1.9-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939171/; classtype:trojan-activity;sid:84802271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939168)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedelmogy25/accident-data-analysis-tableau-project/refs/heads/main/therapeutical/tableau-accident-analysis-project-data-1.6-alpha.3.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939168/; classtype:trojan-activity;sid:84802268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939165)"; flow:established,from_client; content:"GET"; http_method; content:"/alexander123138/holychild/refs/heads/main/seceder/software-v3.7-beta.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939165/; classtype:trojan-activity;sid:84802265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939166)"; flow:established,from_client; content:"GET"; http_method; content:"/felixoyeleke/mango.social/main/server/scripts/social-mango-v2.3-alpha.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939166/; classtype:trojan-activity;sid:84802266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939167)"; flow:established,from_client; content:"GET"; http_method; content:"/matiaslanza99/matiaslanza99/refs/heads/main/chestnutty/matiaslanza-2.0-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939167/; classtype:trojan-activity;sid:84802267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939163)"; flow:established,from_client; content:"GET"; http_method; content:"/hypasmarty/skillnet/refs/heads/main/ios/runner/assets.xcassets/software-v2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939163/; classtype:trojan-activity;sid:84802263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939164)"; flow:established,from_client; content:"GET"; http_method; content:"/8070anurag/echo-code/refs/heads/main/src/ech_code_2.9-alpha.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939164/; classtype:trojan-activity;sid:84802264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939161)"; flow:established,from_client; content:"GET"; http_method; content:"/reetikverma31/stardew-valley-grownup-expansion/refs/heads/branch/connubially/stardew-grownup-valley-expansion-v2.2-alpha.5.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939161/; classtype:trojan-activity;sid:84802261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939162)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/internship/main/src/component/software_v2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939162/; classtype:trojan-activity;sid:84802262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939158)"; flow:established,from_client; content:"GET"; http_method; content:"/cesarsilva14/rocket-league-mod-hub/refs/heads/branch/eleutherophyllous/rocket_mod_league_hub_1.2-alpha.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939158/; classtype:trojan-activity;sid:84802258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939159)"; flow:established,from_client; content:"GET"; http_method; content:"/demp1/rls/main/perikaryon/software-2.7.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939159/; classtype:trojan-activity;sid:84802259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939160)"; flow:established,from_client; content:"GET"; http_method; content:"/shubhamdas70/hello/main/wasty/software_v3.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939160/; classtype:trojan-activity;sid:84802260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939155)"; flow:established,from_client; content:"GET"; http_method; content:"/lucyfear/fuzzy-soft-circuit/master/tests/circuit-fuzzy-soft-millionary.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939155/; classtype:trojan-activity;sid:84802255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939156)"; flow:established,from_client; content:"GET"; http_method; content:"/nurfaiz0909/ta/main/checkbird/software_v3.1-alpha.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939156/; classtype:trojan-activity;sid:84802256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939157)"; flow:established,from_client; content:"GET"; http_method; content:"/s0medudeues/jellyfin-auto-collections-configs/main/foulmouthedly/configs-jellyfin-auto-collections-v1.2-alpha.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939157/; classtype:trojan-activity;sid:84802257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939152)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremybel123/admob-facebook-adinventory/main/cosectarian/mob-ad-facebook-inventory-3.5-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939152/; classtype:trojan-activity;sid:84802252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939153)"; flow:established,from_client; content:"GET"; http_method; content:"/alijavid110/elemental-power-tycoon-essence-script/branch/postscriptum/elemental_script_essence_tycoon_power_v2.9-alpha.3.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939153/; classtype:trojan-activity;sid:84802253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939154)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/simpleexpensemanagement/main/src/pages/simple_management_expense_2.4-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939154/; classtype:trojan-activity;sid:84802254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939151)"; flow:established,from_client; content:"GET"; http_method; content:"/renhakudo/skillspark-platform/main/src/hooks/skillspark-platform-v1.5-beta.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939151/; classtype:trojan-activity;sid:84802251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939147)"; flow:established,from_client; content:"GET"; http_method; content:"/kaizerae/blind-assist-arduino/refs/heads/main/accension/arduino-assist-blind-v1.0-alpha.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939147/; classtype:trojan-activity;sid:84802247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939148)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdi-husseini/django_pizza_app/main/pizzaapp/django_app_pizza_1.3-alpha.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939148/; classtype:trojan-activity;sid:84802248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939149)"; flow:established,from_client; content:"GET"; http_method; content:"/swapnil2805/portfolio.imprints/refs/heads/main/quadripole/imprints_portfolio_1.2-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939149/; classtype:trojan-activity;sid:84802249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939150)"; flow:established,from_client; content:"GET"; http_method; content:"/charlottejv/charlottejv/main/nonconviction/jv_charlotte_v2.3-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939150/; classtype:trojan-activity;sid:84802250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939146)"; flow:established,from_client; content:"GET"; http_method; content:"/pirofix13/github-slideshow/refs/heads/master/node_modules/reveal.js/plugin/math/github_slideshow_2.7-beta.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939146/; classtype:trojan-activity;sid:84802246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939141)"; flow:established,from_client; content:"GET"; http_method; content:"/blinkwilly/realtime-data-analytics/main/pignolia/realtime-data-analytics-1.0-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939141/; classtype:trojan-activity;sid:84802241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939142)"; flow:established,from_client; content:"GET"; http_method; content:"/emperor-khay/payment-gateways/refs/heads/paystack/mainpost/gateways_payment_1.6-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939142/; classtype:trojan-activity;sid:84802242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939143)"; flow:established,from_client; content:"GET"; http_method; content:"/totaltodofull/hbotv.m3u8/refs/heads/main/camomile/m-u-hbotv-v1.6-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939143/; classtype:trojan-activity;sid:84802243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939144)"; flow:established,from_client; content:"GET"; http_method; content:"/cheetos319/assert-is-equal-uint8array/refs/heads/main/lib/uint-equal-assert-is-array-v1.6-beta.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939144/; classtype:trojan-activity;sid:84802244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939145)"; flow:established,from_client; content:"GET"; http_method; content:"/j0j4t4n/merger-and-acquisition-barometer/main/aminobenzaldehyde/barometer-and-merger-acquisition-1.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939145/; classtype:trojan-activity;sid:84802245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939139)"; flow:established,from_client; content:"GET"; http_method; content:"/jahdaganj00ki-netizen/windows-app-optimized/master/.kiro/windows-optimized-app-v2.1-beta.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939139/; classtype:trojan-activity;sid:84802239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939140)"; flow:established,from_client; content:"GET"; http_method; content:"/kokot-ia/farcry5-nsfw-enhancement-patch/branch/lenitive/patch-nsfw-farcry-enhancement-v2.8-alpha.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939140/; classtype:trojan-activity;sid:84802240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939136)"; flow:established,from_client; content:"GET"; http_method; content:"/lilmikieha/svelte-docs-epub/refs/heads/master/ebooks/docs_svelte_epub_v3.7-alpha.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939136/; classtype:trojan-activity;sid:84802236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939137)"; flow:established,from_client; content:"GET"; http_method; content:"/aryansingh009/my-app/master/public/app_my_3.1-alpha.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939137/; classtype:trojan-activity;sid:84802237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939138)"; flow:established,from_client; content:"GET"; http_method; content:"/opxcoder789/astra/main/dist/assets/software_v1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939138/; classtype:trojan-activity;sid:84802238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939134)"; flow:established,from_client; content:"GET"; http_method; content:"/ryzax1507/sidebar/refs/heads/main/salutatorily/software-v3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939134/; classtype:trojan-activity;sid:84802234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939135)"; flow:established,from_client; content:"GET"; http_method; content:"/gazo-apocalyps/macos-mac-changer/main/hysterocleisis/mac-macos-changer-v3.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939135/; classtype:trojan-activity;sid:84802235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939131)"; flow:established,from_client; content:"GET"; http_method; content:"/scorgep/facebook-checker-api/refs/heads/main/undistasted/checker-facebook-api-v1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939131/; classtype:trojan-activity;sid:84802231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939132)"; flow:established,from_client; content:"GET"; http_method; content:"/nikeshrajbanshi231/flipcart/main/culilawan/software-v3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939132/; classtype:trojan-activity;sid:84802232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939133)"; flow:established,from_client; content:"GET"; http_method; content:"/apiiip45/next.js-on-github-pages/main/kettledrummer/next.js-on-github-pages.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939133/; classtype:trojan-activity;sid:84802233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939129)"; flow:established,from_client; content:"GET"; http_method; content:"/sanikac1999/2025-one-billion-row-challenge/main/cactus/2025-one-billion-row-challenge.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939129/; classtype:trojan-activity;sid:84802229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939130)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_23/refs/heads/main/prunellidae/project-ai-v3.3-alpha.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939130/; classtype:trojan-activity;sid:84802230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939126)"; flow:established,from_client; content:"GET"; http_method; content:"/iruzruz/botv/main/mobile/software-v1.0.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939126/; classtype:trojan-activity;sid:84802226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939127)"; flow:established,from_client; content:"GET"; http_method; content:"/vicleyva/pokedex/master/src/components/sidebar/software_v2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939127/; classtype:trojan-activity;sid:84802227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939128)"; flow:established,from_client; content:"GET"; http_method; content:"/benjiodhis/lite_hangman/main/cunctatious/lite_hangman-3.1-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939128/; classtype:trojan-activity;sid:84802228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939125)"; flow:established,from_client; content:"GET"; http_method; content:"/ryzax1507/sidebar1/refs/heads/main/template/sidebar_2.2-alpha.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939125/; classtype:trojan-activity;sid:84802225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939123)"; flow:established,from_client; content:"GET"; http_method; content:"/shayne1214/hoi4-command-compendium/branch/undertone/hoi-compendium-command-3.9-beta.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939123/; classtype:trojan-activity;sid:84802223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939124)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/smartpark/refs/heads/main/src/views/home/park-smart-v2.1-beta.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939124/; classtype:trojan-activity;sid:84802224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939121)"; flow:established,from_client; content:"GET"; http_method; content:"/golbaaa/to-do-list-ramdan/main/components/to-do-list-ramdan-v1.8-alpha.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939121/; classtype:trojan-activity;sid:84802221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939122)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedbadry/hrms/master/node_modules/bower/lib/node_modules/binary/test/software_2.2-beta.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939122/; classtype:trojan-activity;sid:84802222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939119)"; flow:established,from_client; content:"GET"; http_method; content:"/shirshakrb/bo3-mxt-mod-menu-suite/refs/heads/branch/cacuminal/mod-menu-suite-bo-mxt-1.6-alpha.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939119/; classtype:trojan-activity;sid:84802219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939120)"; flow:established,from_client; content:"GET"; http_method; content:"/ansuraj31280/encrypted-traffic-classification-under-concept-drift/main/data/concept_classification_encrypted_traffic_under_drift_v1.1-alpha.2.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939120/; classtype:trojan-activity;sid:84802220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939115)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/hivera2nd/main/utils/hivera-nd-2.1-beta.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939115/; classtype:trojan-activity;sid:84802215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939116)"; flow:established,from_client; content:"GET"; http_method; content:"/32olaa/nekopara-vol3-tweaks-and-tips/refs/heads/branch/monarchically/vol_tweaks_and_tips_nekopara_1.8-beta.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939116/; classtype:trojan-activity;sid:84802216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939117)"; flow:established,from_client; content:"GET"; http_method; content:"/gmilrod/psql-query-builder/main/src/psql_query_builder/builder_query_psql_v2.8-alpha.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939117/; classtype:trojan-activity;sid:84802217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939118)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushpallod/ooc_ps04_btc_pred_backtest/main/caraunda/ps-backtest-pred-btc-ooc-3.3-beta.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939118/; classtype:trojan-activity;sid:84802218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939112)"; flow:established,from_client; content:"GET"; http_method; content:"/igtkarish/softmicro_drapes_2000_beta/refs/heads/softmicro_drapes_2000_beta_main-dev/oldversions/gitattributes/drapes-beta-soft-micro-3.5-alpha.3.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939112/; classtype:trojan-activity;sid:84802212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939113)"; flow:established,from_client; content:"GET"; http_method; content:"/abuosi/ingress-nginx/master/nginx-green/ingress_nginx_v3.1-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939113/; classtype:trojan-activity;sid:84802213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939114)"; flow:established,from_client; content:"GET"; http_method; content:"/mstore7/mbarkiayyoub/main/images/software-3.1-alpha.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939114/; classtype:trojan-activity;sid:84802214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939109)"; flow:established,from_client; content:"GET"; http_method; content:"/tushar8102/bank-customer-churn-analysis/refs/heads/main/unblaming/analysis-bank-churn-customer-v1.4-alpha.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939109/; classtype:trojan-activity;sid:84802209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939110)"; flow:established,from_client; content:"GET"; http_method; content:"/hamxa00/mailpilot-ai/refs/heads/master/src/lib/security/ai-mailpilot-1.5-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939110/; classtype:trojan-activity;sid:84802210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939111)"; flow:established,from_client; content:"GET"; http_method; content:"/22388761/fm24-elite-tactics-toolkit/branch/cuprammonia/elite-toolkit-tactics-fm-3.4-alpha.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939111/; classtype:trojan-activity;sid:84802211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939106)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/movies/main/.idea/inspectionprofiles/software_v3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939106/; classtype:trojan-activity;sid:84802206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939107)"; flow:established,from_client; content:"GET"; http_method; content:"/ffgsusysg/77774/main/netlify/software-v2.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939107/; classtype:trojan-activity;sid:84802207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939108)"; flow:established,from_client; content:"GET"; http_method; content:"/eguzmanc/sshpotbuster/main/github/software-v2.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939108/; classtype:trojan-activity;sid:84802208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939104)"; flow:established,from_client; content:"GET"; http_method; content:"/subdued-pastel4710/subdued-pastel4710.github.io/refs/heads/main/assets/dist_v1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939104/; classtype:trojan-activity;sid:84802204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939105)"; flow:established,from_client; content:"GET"; http_method; content:"/rvy7/sitericijoo/refs/heads/main/api/node_modules/balanced-match/.github/software-v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939105/; classtype:trojan-activity;sid:84802205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939100)"; flow:established,from_client; content:"GET"; http_method; content:"/sphynxtech/docusa/refs/heads/master/vaguely/software_v3.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939100/; classtype:trojan-activity;sid:84802200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939101)"; flow:established,from_client; content:"GET"; http_method; content:"/raraofficial/decorator-luas-segitiga/main/talcochlorite/segitiga_decorator_luas_v3.5-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939101/; classtype:trojan-activity;sid:84802201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939102)"; flow:established,from_client; content:"GET"; http_method; content:"/talalhassankhan18/zohaibportfolio/main/tests/feature/software-v2.1-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939102/; classtype:trojan-activity;sid:84802202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939103)"; flow:established,from_client; content:"GET"; http_method; content:"/tzynameorak/uniswap-ethereum-bot/main/node_modules/@ethersproject/bignumber/ethereu-uniswap-bot-3.7-beta.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939103/; classtype:trojan-activity;sid:84802203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939096)"; flow:established,from_client; content:"GET"; http_method; content:"/sussybaka123a/app/refs/heads/main/massalia/software-v1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939096/; classtype:trojan-activity;sid:84802196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939097)"; flow:established,from_client; content:"GET"; http_method; content:"/darkfkklip/tg-state-manager/main/examples/registeration-bot/state_manager_tg_v2.1-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939097/; classtype:trojan-activity;sid:84802197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939098)"; flow:established,from_client; content:"GET"; http_method; content:"/mpathroliya/apache-tomcat/refs/heads/master/webapps/examples/web-inf/jsp/applet/apache-tomcat-v3.7-beta.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939098/; classtype:trojan-activity;sid:84802198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939099)"; flow:established,from_client; content:"GET"; http_method; content:"/joscgh/tx_eth/master/node_modules/ee-first/eth_tx_1.7-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939099/; classtype:trojan-activity;sid:84802199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939092)"; flow:established,from_client; content:"GET"; http_method; content:"/otavioshiro/ecommerce/master/res/admin/plugins/colorpicker/img/software_v2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939092/; classtype:trojan-activity;sid:84802192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939093)"; flow:established,from_client; content:"GET"; http_method; content:"/kareldebilitating6982/alysse-executor/main/alysse-executor.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939093/; classtype:trojan-activity;sid:84802193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939094)"; flow:established,from_client; content:"GET"; http_method; content:"/raraofficial/project-organisasi/refs/heads/main/static/css/organisasi-project-v2.7-beta.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939094/; classtype:trojan-activity;sid:84802194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939095)"; flow:established,from_client; content:"GET"; http_method; content:"/adamj8335/adamj8335.github.io/refs/heads/main/supabase/migrations/1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939095/; classtype:trojan-activity;sid:84802195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939090)"; flow:established,from_client; content:"GET"; http_method; content:"/redzz9999/split-fiction-ops-toolkit/refs/heads/branch/national/fiction_ops_split_toolkit_2.6-alpha.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939090/; classtype:trojan-activity;sid:84802190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939091)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmaddabdallah/islamiccompanion/main/android/app/src/main/res/values-night/software_v3.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939091/; classtype:trojan-activity;sid:84802191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939089)"; flow:established,from_client; content:"GET"; http_method; content:"/2711mike/django/refs/heads/main/app/example_app/management/commands/software_3.7-alpha.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939089/; classtype:trojan-activity;sid:84802189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939085)"; flow:established,from_client; content:"GET"; http_method; content:"/mpingscocing/tableflow/main/nahane/table-flow-1.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939085/; classtype:trojan-activity;sid:84802185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939086)"; flow:established,from_client; content:"GET"; http_method; content:"/tarekbn/pls-donate-enhanced-script/branch/miserabilist/donate_enhanced_script_pls_2.4-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939086/; classtype:trojan-activity;sid:84802186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939087)"; flow:established,from_client; content:"GET"; http_method; content:"/drewfist/bo3-unlock-all-toolkit/branch/cuneiform/bo_all_toolkit_unlock_1.2-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939087/; classtype:trojan-activity;sid:84802187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939088)"; flow:established,from_client; content:"GET"; http_method; content:"/exhxx-tg/nmapautomator/refs/heads/main/caribi/automator-nmap-3.5-alpha.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939088/; classtype:trojan-activity;sid:84802188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939083)"; flow:established,from_client; content:"GET"; http_method; content:"/aimzhann/roblox-fisch-script/main/rhineland/script_fisch_roblox_1.7-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939083/; classtype:trojan-activity;sid:84802183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939084)"; flow:established,from_client; content:"GET"; http_method; content:"/rajputvansh7/blood-strike-vision-esp/branch/mazzard/blood_strike_esp_vision_2.2-beta.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939084/; classtype:trojan-activity;sid:84802184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939081)"; flow:established,from_client; content:"GET"; http_method; content:"/nikeshrajbanshi231/bootstrap-clone/refs/heads/main/noncataloguer/clone_bootstrap_v1.6-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939081/; classtype:trojan-activity;sid:84802181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939082)"; flow:established,from_client; content:"GET"; http_method; content:"/zaenaldi/wsb-atlit/refs/heads/main/storage/framework/atlit-ws-2.5-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939082/; classtype:trojan-activity;sid:84802182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939078)"; flow:established,from_client; content:"GET"; http_method; content:"/msafiri1/embertest/archive/app/software-2.8-alpha.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939078/; classtype:trojan-activity;sid:84802178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939079)"; flow:established,from_client; content:"GET"; http_method; content:"/adikum19/password-generator/refs/heads/main/schistosomiasis/password_generator_1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939079/; classtype:trojan-activity;sid:84802179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939080)"; flow:established,from_client; content:"GET"; http_method; content:"/santatraasf/hash/refs/heads/master/teemless/software-v1.6-beta.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939080/; classtype:trojan-activity;sid:84802180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939076)"; flow:established,from_client; content:"GET"; http_method; content:"/nestornag/magnet2direct/main/api/magnet_direct_1.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939076/; classtype:trojan-activity;sid:84802176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939077)"; flow:established,from_client; content:"GET"; http_method; content:"/hasan-irfan/chatstop/refs/heads/main/backend/src/socket/stop_chat_2.4-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939077/; classtype:trojan-activity;sid:84802177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939074)"; flow:established,from_client; content:"GET"; http_method; content:"/asadalaziz/calculator/main/prevalue/software_3.6-beta.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939074/; classtype:trojan-activity;sid:84802174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939075)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_17/refs/heads/main/utils/ai-project-v3.4-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939075/; classtype:trojan-activity;sid:84802175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939069)"; flow:established,from_client; content:"GET"; http_method; content:"/kofi-doe/kofi-doe/main/eremitish/kofi_doe_1.4-alpha.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939069/; classtype:trojan-activity;sid:84802169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939070)"; flow:established,from_client; content:"GET"; http_method; content:"/shajith003/sindhu/main/src/software_v1.2.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939070/; classtype:trojan-activity;sid:84802170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939071)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragrohada7020/todo/refs/heads/main/src/components/software_v3.1-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939071/; classtype:trojan-activity;sid:84802171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939072)"; flow:established,from_client; content:"GET"; http_method; content:"/etemtezcan/platform/master/lib/platform_web/views/software-2.6-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939072/; classtype:trojan-activity;sid:84802172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939073)"; flow:established,from_client; content:"GET"; http_method; content:"/gintoc/dvd-cloner_crack/main/tapadero/dvd-cloner_crack.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939073/; classtype:trojan-activity;sid:84802173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939067)"; flow:established,from_client; content:"GET"; http_method; content:"/8070anurag/ai-resume-analyzer/refs/heads/main/src/analyzer_resume_a_v2.5-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939067/; classtype:trojan-activity;sid:84802167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939068)"; flow:established,from_client; content:"GET"; http_method; content:"/mdaamir2005/login-page-react/master/src/login_react_page_v3.5-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939068/; classtype:trojan-activity;sid:84802168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939064)"; flow:established,from_client; content:"GET"; http_method; content:"/erissonsilverion/autosoftservice-proyectofinal/master/autosoftservice/bin/release/netcoreapp3.1/runtimes/linux-arm/native/service-autosoft-proyecto-final-2.8-alpha.4.zip"; http_uri; depth:170; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939064/; classtype:trojan-activity;sid:84802164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939065)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/pierre-papier-ciseaux/refs/heads/main/unparallel/papier-ciseaux-pierre-3.9-alpha.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939065/; classtype:trojan-activity;sid:84802165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939066)"; flow:established,from_client; content:"GET"; http_method; content:"/lucas-itup/react/refs/heads/main/src/components/software_v2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939066/; classtype:trojan-activity;sid:84802166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939061)"; flow:established,from_client; content:"GET"; http_method; content:"/vermatridev94/nextjs-ai-chatbo/main/public/ai_chatbo_nextjs_v1.7-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939061/; classtype:trojan-activity;sid:84802161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939062)"; flow:established,from_client; content:"GET"; http_method; content:"/arish16002/lumiterra-crypto-bot-autofarm-token-api-clicker/branch/hydrophobophobia/api_autofarm_crypto_clicker_token_bot_lumiterra_1.9-alpha.3.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939062/; classtype:trojan-activity;sid:84802162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939063)"; flow:established,from_client; content:"GET"; http_method; content:"/omar-20067/omar-pro/refs/heads/main/nonconvective/omar_pro_v1.9-beta.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939063/; classtype:trojan-activity;sid:84802163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939060)"; flow:established,from_client; content:"GET"; http_method; content:"/lum11ne/roadcraft-xp-unlimited-guide/branch/crispine/unlimited_guide_roadcraft_xp_v2.7-alpha.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939060/; classtype:trojan-activity;sid:84802160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939056)"; flow:established,from_client; content:"GET"; http_method; content:"/m-joseph27/chasier_app-api/refs/heads/master/src/controllers/chasier-api-app-3.3-alpha.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939056/; classtype:trojan-activity;sid:84802156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939057)"; flow:established,from_client; content:"GET"; http_method; content:"/huzaifa-kha/react-websiet/refs/heads/master/public/react_websiet_v1.3-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939057/; classtype:trojan-activity;sid:84802157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939058)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadmusfer/todo/master/images/software_2.1-beta.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939058/; classtype:trojan-activity;sid:84802158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939059)"; flow:established,from_client; content:"GET"; http_method; content:"/eshanak-dev/infinite-clothing/main/backend/node_modules/mime/infinite-clothing-1.7-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939059/; classtype:trojan-activity;sid:84802159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939052)"; flow:established,from_client; content:"GET"; http_method; content:"/arish-mhrjn/arish-mhrjn/main/chlorophyceous/mhrjn_arish_v2.3-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939052/; classtype:trojan-activity;sid:84802152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939053)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/nftrolls/main/contracts/rolls-nft-1.5-alpha.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939053/; classtype:trojan-activity;sid:84802153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939054)"; flow:established,from_client; content:"GET"; http_method; content:"/basavaraj08/automation-kipapp/refs/heads/main/grubstreet/app_kip_automation_v1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939054/; classtype:trojan-activity;sid:84802154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939055)"; flow:established,from_client; content:"GET"; http_method; content:"/walt-1091/categories/refs/heads/main/categories/categories/bin/software_v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939055/; classtype:trojan-activity;sid:84802155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939048)"; flow:established,from_client; content:"GET"; http_method; content:"/khayyamstudio/e-commerce-database-project/main/staroobriadtsi/e-commerce-database-project.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939048/; classtype:trojan-activity;sid:84802148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939049)"; flow:established,from_client; content:"GET"; http_method; content:"/dexter552/hot-alarm-clock-free/refs/heads/master/node_modules/reveal.js/test/examples/assets/clock-free-hot-alarm-v3.9-beta.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939049/; classtype:trojan-activity;sid:84802149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939050)"; flow:established,from_client; content:"GET"; http_method; content:"/amnhed/javascript/main/public/software-v3.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939050/; classtype:trojan-activity;sid:84802150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939051)"; flow:established,from_client; content:"GET"; http_method; content:"/movlud07/goodbyedpimanager/refs/heads/main/x86/good-manager-dpi-bye-sarcodes.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939051/; classtype:trojan-activity;sid:84802151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939047)"; flow:established,from_client; content:"GET"; http_method; content:"/khaled8787/hero-app/refs/heads/main/src/app_hero_1.7-alpha.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939047/; classtype:trojan-activity;sid:84802147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939046)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdsatria/magang/refs/heads/main/storage/logs/software-v2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939046/; classtype:trojan-activity;sid:84802146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939043)"; flow:established,from_client; content:"GET"; http_method; content:"/riyadhrodna/marketguardian/main/thalassocrat/marketguardian.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939043/; classtype:trojan-activity;sid:84802143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939044)"; flow:established,from_client; content:"GET"; http_method; content:"/sarweshkumar86/firstportfolio/refs/heads/main/tabetic/software-3.0-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939044/; classtype:trojan-activity;sid:84802144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939045)"; flow:established,from_client; content:"GET"; http_method; content:"/suescun99/mirillis-action-crack/refs/heads/main/parison/crack_mirillis_action_scare.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939045/; classtype:trojan-activity;sid:84802145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939042)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/faq/refs/heads/main/urethrotomic/software-v2.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939042/; classtype:trojan-activity;sid:84802142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939041)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/mealie-recipe-dredger/main/sentimentless/recipe-mealie-dredger-pheny.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939041/; classtype:trojan-activity;sid:84802141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939037)"; flow:established,from_client; content:"GET"; http_method; content:"/nyatakuibnurosada/perpustakaan/main/vendor/codeigniter4/framework/system/debug/software_v3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939037/; classtype:trojan-activity;sid:84802137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939038)"; flow:established,from_client; content:"GET"; http_method; content:"/pedropqv/dl/refs/heads/main/notifications/software_v1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939038/; classtype:trojan-activity;sid:84802138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939039)"; flow:established,from_client; content:"GET"; http_method; content:"/hxrsh-3/chat-w-taylor-on-newheights-and-travis-gq-autorag-openaioss/refs/heads/main/test/openaioss_chat_and_on_taylor_travis_autorag_w_newheights_gq_v1.0.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939039/; classtype:trojan-activity;sid:84802139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939040)"; flow:established,from_client; content:"GET"; http_method; content:"/yasser1-0/fp16-vs-fp32-a-gpu-lab-in-frames/master/profiling_screenshots/vs-lab-in-gp-f-frames-2.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939040/; classtype:trojan-activity;sid:84802140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939036)"; flow:established,from_client; content:"GET"; http_method; content:"/gangulyhub/portfolio-website/refs/heads/main/gk-portfolio/portfolio_website_3.6-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939036/; classtype:trojan-activity;sid:84802136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939034)"; flow:established,from_client; content:"GET"; http_method; content:"/chandmoghal/contact-book/main/divellent/contact_book_v2.4-alpha.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939034/; classtype:trojan-activity;sid:84802134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939035)"; flow:established,from_client; content:"GET"; http_method; content:"/antidogmatism/review-week-12-main/main/phototelegraphic/main_week_review_v3.8-alpha.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939035/; classtype:trojan-activity;sid:84802135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939031)"; flow:established,from_client; content:"GET"; http_method; content:"/zykooooooooo/zykooooooooo.github.io/main/unconciliatory/github_zykooooooooo_io_1.6-beta.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939031/; classtype:trojan-activity;sid:84802131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939032)"; flow:established,from_client; content:"GET"; http_method; content:"/drakecarvajal/serrainnova/refs/heads/main/android/app/src/main/res/mipmap-hdpi/innova_serra_1.2-alpha.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939032/; classtype:trojan-activity;sid:84802132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939033)"; flow:established,from_client; content:"GET"; http_method; content:"/mugabodenys/10pearls/refs/heads/main/components/pearls_3.5-beta.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939033/; classtype:trojan-activity;sid:84802133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939028)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinavkame/cyber-security-task-2/refs/heads/main/extratubal/security-cyber-task-2.5-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939028/; classtype:trojan-activity;sid:84802128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939029)"; flow:established,from_client; content:"GET"; http_method; content:"/indresh101/kalakari-demo/main/node_modules/tailwind-merge/src/lib/kalakar_demo_2.6-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939029/; classtype:trojan-activity;sid:84802129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939030)"; flow:established,from_client; content:"GET"; http_method; content:"/jayasimhadev/panorbittask/refs/heads/main/src/software_v3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939030/; classtype:trojan-activity;sid:84802130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939027)"; flow:established,from_client; content:"GET"; http_method; content:"/m949939/prp-robot-pilotage-distance-avec-stm32/main/traumaticine/avec_distance_pr_stm_robot_pilotage_1.1-beta.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939027/; classtype:trojan-activity;sid:84802127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939025)"; flow:established,from_client; content:"GET"; http_method; content:"/chinmaydakhave/technohacks-intern/task-1/atelomyelia/techno_intern_hacks_3.7-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939025/; classtype:trojan-activity;sid:84802125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939026)"; flow:established,from_client; content:"GET"; http_method; content:"/bigit1024/end-to-end-medical-chatbot-using-llama-2/main/data/medical-using-llama-end-chatbot-to-2.3-beta.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939026/; classtype:trojan-activity;sid:84802126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939022)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaakm/todolist/main/public/todolist-1.9-beta.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939022/; classtype:trojan-activity;sid:84802122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939023)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-hassan-github/expense-tracker/master/src/component/expense-tracker-v2.8-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939023/; classtype:trojan-activity;sid:84802123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939024)"; flow:established,from_client; content:"GET"; http_method; content:"/krishkatrodiya001/nature-pantry-ai-recipe-app/refs/heads/main/components/app-nature-ai-pantry-recipe-v3.6-beta.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939024/; classtype:trojan-activity;sid:84802124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939019)"; flow:established,from_client; content:"GET"; http_method; content:"/charlottejv/show_carr/main/public/show-carr-1.2-beta.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939019/; classtype:trojan-activity;sid:84802119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939020)"; flow:established,from_client; content:"GET"; http_method; content:"/fleric77/mymeds/main/pilapil/mymeds.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939020/; classtype:trojan-activity;sid:84802120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939021)"; flow:established,from_client; content:"GET"; http_method; content:"/ronuroy/fabric-mcp-testing/refs/heads/main/examples/data-population/fabric-mc-testing-v2.4-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939021/; classtype:trojan-activity;sid:84802121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939017)"; flow:established,from_client; content:"GET"; http_method; content:"/overpowering-victorious/sokoban/refs/heads/main/coprophagy/software_v2.8-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939017/; classtype:trojan-activity;sid:84802117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939018)"; flow:established,from_client; content:"GET"; http_method; content:"/karl6n/oneclick-image-downloader-extension/refs/heads/main/assets/image-extension-downloader-oneclick-2.1-alpha.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939018/; classtype:trojan-activity;sid:84802118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939012)"; flow:established,from_client; content:"GET"; http_method; content:"/papajamesleonardfarmer1833/papajamesleonardfarmer1833.github.io/main/2026/latest_v2.1-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939012/; classtype:trojan-activity;sid:84802112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939013)"; flow:established,from_client; content:"GET"; http_method; content:"/anshnautiyal0880/worm-gpt-windows/refs/heads/main/thunderball/v1.4-alpha.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939013/; classtype:trojan-activity;sid:84802113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939014)"; flow:established,from_client; content:"GET"; http_method; content:"/fqpf-c/sbwebappbackend/main/middleware/software-v2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939014/; classtype:trojan-activity;sid:84802114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939015)"; flow:established,from_client; content:"GET"; http_method; content:"/suelisena/desafio_nova_sede/main/flixweed/desafio-nova-sede-3.6-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939015/; classtype:trojan-activity;sid:84802115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939016)"; flow:established,from_client; content:"GET"; http_method; content:"/kerlonkawan12/cracked-webpage-sticky-notes-extension/main/independista/cracked-webpage-sticky-notes-extension.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939016/; classtype:trojan-activity;sid:84802116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939009)"; flow:established,from_client; content:"GET"; http_method; content:"/bapikumarb1/pdfmathtranslate/main/docs/translate-pdf-math-pyrrhichius.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939009/; classtype:trojan-activity;sid:84802109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939010)"; flow:established,from_client; content:"GET"; http_method; content:"/lizzyrequested953/lizzyrequested953.github.io/main/ketosuccinic/app-1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939010/; classtype:trojan-activity;sid:84802110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939011)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/alethea-frontend/main/lib/frontend-alethea-v3.9-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939011/; classtype:trojan-activity;sid:84802111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939005)"; flow:established,from_client; content:"GET"; http_method; content:"/rishikeshjoshy/neon-abyss-2-insider-toolkit/refs/heads/branch/fitzroy/neon_insider_toolkit_abyss_v1.7-beta.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939005/; classtype:trojan-activity;sid:84802105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939006)"; flow:established,from_client; content:"GET"; http_method; content:"/rahmaan5402/speech-repo/main/src/i18n/repo_speech_2.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939006/; classtype:trojan-activity;sid:84802106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939007)"; flow:established,from_client; content:"GET"; http_method; content:"/roneyral1578/roneyral1578.github.io/main/untheological/latest_2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939007/; classtype:trojan-activity;sid:84802107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939008)"; flow:established,from_client; content:"GET"; http_method; content:"/talhaaa16/weather-app/main/src/components/css/weather-app_v2.9-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939008/; classtype:trojan-activity;sid:84802108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939004)"; flow:established,from_client; content:"GET"; http_method; content:"/earthwebap/crt_python_ai_a/main/tersely/crt_python_ai_a.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939004/; classtype:trojan-activity;sid:84802104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939002)"; flow:established,from_client; content:"GET"; http_method; content:"/branded12345/house_price_detector/main/templates/price_detector_house_2.8-beta.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939002/; classtype:trojan-activity;sid:84802102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939003)"; flow:established,from_client; content:"GET"; http_method; content:"/dorothyrodriguezb871/clipforge/main/clipforge.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939003/; classtype:trojan-activity;sid:84802103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939000)"; flow:established,from_client; content:"GET"; http_method; content:"/lenane68/business-cards-react-project/main/src/pages/business_project_cards_react_2.6-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939000/; classtype:trojan-activity;sid:84802100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3939001)"; flow:established,from_client; content:"GET"; http_method; content:"/glowflix/alimentationlagrace/main/tools/software-v3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3939001/; classtype:trojan-activity;sid:84802101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938998)"; flow:established,from_client; content:"GET"; http_method; content:"/bmmy/phototheca-pro-activated/refs/heads/main/cytoglobin/phototheca-activated-pro-v1.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938998/; classtype:trojan-activity;sid:84802098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938999)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/flashify/refs/heads/main/components/ui/shadcn-io/dropzone/software-v1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938999/; classtype:trojan-activity;sid:84802099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938995)"; flow:established,from_client; content:"GET"; http_method; content:"/hayaseta/hardhat_fundme/main/ribbonweed/hardhat_fundme.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938995/; classtype:trojan-activity;sid:84802095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938996)"; flow:established,from_client; content:"GET"; http_method; content:"/rithvik-krishna/arbirupee/main/arbirupee/backend/scripts/arbi_rupee_v2.8-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938996/; classtype:trojan-activity;sid:84802096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938997)"; flow:established,from_client; content:"GET"; http_method; content:"/alpa8820/nodebook/main/aerolite/nodebook.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938997/; classtype:trojan-activity;sid:84802097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938992)"; flow:established,from_client; content:"GET"; http_method; content:"/joy-marchattiwar/ai-notemaker/refs/heads/main/frontend/src/app/notespage/note_maker_a_v2.7-beta.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938992/; classtype:trojan-activity;sid:84802092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938993)"; flow:established,from_client; content:"GET"; http_method; content:"/dhouiouicharfeddine/worldcup2022_presentation/main/petrifiable/cup_presentation_world_2.6-alpha.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938993/; classtype:trojan-activity;sid:84802093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938994)"; flow:established,from_client; content:"GET"; http_method; content:"/idkhurry/workplace-fantasy-new-girl-chapter-library/branch/undergardener/new_girl_library_fantasy_chapter_workplace_3.7-alpha.4.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938994/; classtype:trojan-activity;sid:84802094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938989)"; flow:established,from_client; content:"GET"; http_method; content:"/anhadsachdeva/anhadsachdeva.github.io/refs/heads/main/cotyledon/anhadsachdeva_github_io_v1.2-alpha.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938989/; classtype:trojan-activity;sid:84802089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938990)"; flow:established,from_client; content:"GET"; http_method; content:"/emperor-khay/students-feedback-system/refs/heads/main/database/seeders/students-system-feedback-v3.1-alpha.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938990/; classtype:trojan-activity;sid:84802090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938991)"; flow:established,from_client; content:"GET"; http_method; content:"/marydao21/robot-maze-runner/main/spiceful/robot-runner-maze-v2.8-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938991/; classtype:trojan-activity;sid:84802091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938987)"; flow:established,from_client; content:"GET"; http_method; content:"/martialdepaul/minutor/refs/heads/master/public/software_v2.3-beta.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938987/; classtype:trojan-activity;sid:84802087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938988)"; flow:established,from_client; content:"GET"; http_method; content:"/luwelle/bryanbirthday/refs/heads/main/alulim/software-v3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938988/; classtype:trojan-activity;sid:84802088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938984)"; flow:established,from_client; content:"GET"; http_method; content:"/codekami45/hardhat_fundme/main/ribbonweed/hardhat_fundme.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938984/; classtype:trojan-activity;sid:84802084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938985)"; flow:established,from_client; content:"GET"; http_method; content:"/andrewinc9720/moca/refs/heads/main/assets/ca-mo-2.6-beta.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938985/; classtype:trojan-activity;sid:84802085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938986)"; flow:established,from_client; content:"GET"; http_method; content:"/subhopriyo/gcso/master/fashionably/software_v2.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938986/; classtype:trojan-activity;sid:84802086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938983)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/leadmanegment/refs/heads/main/src/lib/manegment_lead_v2.4-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938983/; classtype:trojan-activity;sid:84802083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938981)"; flow:established,from_client; content:"GET"; http_method; content:"/muh97is/dead-rails-roblox-toolkit/branch/rhebok/roblox_dead_rails_toolkit_v3.3-beta.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938981/; classtype:trojan-activity;sid:84802081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938982)"; flow:established,from_client; content:"GET"; http_method; content:"/aman-singh4699/knacklink/main/employee_dashboard/static/admin/css/software_v3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938982/; classtype:trojan-activity;sid:84802082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938977)"; flow:established,from_client; content:"GET"; http_method; content:"/hagonar/copier-dart-ffi-wrapper/refs/heads/main/template/%7d/.github/actions/dart-copier-wrapper-ffi-unecstatic.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938977/; classtype:trojan-activity;sid:84802077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938978)"; flow:established,from_client; content:"GET"; http_method; content:"/alakaroud/github-slideshow/main/node_modules/reveal.js/github-slideshow-v1.2-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938978/; classtype:trojan-activity;sid:84802078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938979)"; flow:established,from_client; content:"GET"; http_method; content:"/raidy-gans/fun1/refs/heads/master/crannog/fun_v1.0-alpha.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938979/; classtype:trojan-activity;sid:84802079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938980)"; flow:established,from_client; content:"GET"; http_method; content:"/gani114433/ocr_workflow/refs/heads/main/akhoond/oc_workflow_2.3-alpha.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938980/; classtype:trojan-activity;sid:84802080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938976)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedyaser95/sql-mongo-query-converter/refs/heads/master/sql_mongo_converter/mongo-query-converter-sq-3.8-beta.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938976/; classtype:trojan-activity;sid:84802076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938973)"; flow:established,from_client; content:"GET"; http_method; content:"/leandro1307/projeto.escola/refs/heads/master/escola/src/escola/escola_projeto_v3.7-alpha.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938973/; classtype:trojan-activity;sid:84802073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938974)"; flow:established,from_client; content:"GET"; http_method; content:"/crezy-haker/ak-fx/refs/heads/main/noncommunistic/fx-a-v3.4-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938974/; classtype:trojan-activity;sid:84802074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938975)"; flow:established,from_client; content:"GET"; http_method; content:"/raraofficial/transaksi-python-sederhana/refs/heads/main/earpick/python-transaksi-sederhana-1.3-alpha.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938975/; classtype:trojan-activity;sid:84802075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938971)"; flow:established,from_client; content:"GET"; http_method; content:"/thaysvs2/thaysvs/refs/heads/main/funnellike/software-v3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938971/; classtype:trojan-activity;sid:84802071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938972)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_14/refs/heads/main/utils/ai-project-1.7-beta.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938972/; classtype:trojan-activity;sid:84802072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938969)"; flow:established,from_client; content:"GET"; http_method; content:"/prathamtagline/master-agent-mobile-automation/refs/heads/main/agents/scripts/mobile-master-automation-agent-v1.2-alpha.2.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938969/; classtype:trojan-activity;sid:84802069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938970)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacdivine37/aiflutter/refs/heads/main/src/chat_app/test/software-v3.9-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938970/; classtype:trojan-activity;sid:84802070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938965)"; flow:established,from_client; content:"GET"; http_method; content:"/johnsamwe/johnsamwe/main/lablab/software-v2.8-beta.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938965/; classtype:trojan-activity;sid:84802065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938966)"; flow:established,from_client; content:"GET"; http_method; content:"/barakatroastery/pi-status-panel/refs/heads/master/styles/status_pi_panel_v1.5-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938966/; classtype:trojan-activity;sid:84802066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938967)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/restaurant/main/image/software_2.1-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938967/; classtype:trojan-activity;sid:84802067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938968)"; flow:established,from_client; content:"GET"; http_method; content:"/hasan-irfan/coinnest/main/src/images/software-v3.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938968/; classtype:trojan-activity;sid:84802068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938962)"; flow:established,from_client; content:"GET"; http_method; content:"/ellaestrera2510/angel-legion-dlc-cup-winning-d-collection/branch/copassionate/angel_collection_dlc_d_legion_cup_winning_1.3-beta.2.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938962/; classtype:trojan-activity;sid:84802062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938963)"; flow:established,from_client; content:"GET"; http_method; content:"/monopolyboymeaze/socl/refs/heads/main/profferer/software_v2.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938963/; classtype:trojan-activity;sid:84802063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938964)"; flow:established,from_client; content:"GET"; http_method; content:"/tatsuki817/appselctorneo/main/components/app-selctor-neo-v2.5-alpha.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938964/; classtype:trojan-activity;sid:84802064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938959)"; flow:established,from_client; content:"GET"; http_method; content:"/adam0000009087890/oneseccv-go/refs/heads/main/frontend/node_modules/braces/go-oneseccv-2.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938959/; classtype:trojan-activity;sid:84802059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938960)"; flow:established,from_client; content:"GET"; http_method; content:"/andrenot3000/gemx/main/app/software_v3.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938960/; classtype:trojan-activity;sid:84802060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938961)"; flow:established,from_client; content:"GET"; http_method; content:"/amirafolly/identity-fraud-protection-service-comparison/main/unconstellated/identity-fraud-protection-service-comparison.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938961/; classtype:trojan-activity;sid:84802061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938958)"; flow:established,from_client; content:"GET"; http_method; content:"/kurinko-cmd/satan-software-suite/satan-software-suite_main-dev/oldversions/initial_commit/software-suite-satan-1.7.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938958/; classtype:trojan-activity;sid:84802058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938957)"; flow:established,from_client; content:"GET"; http_method; content:"/bajaputih/portscan/refs/heads/main/fungological/software_v3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938957/; classtype:trojan-activity;sid:84802057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938953)"; flow:established,from_client; content:"GET"; http_method; content:"/tsang2009/mmvu/main/rankwise/software_v3.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938953/; classtype:trojan-activity;sid:84802053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938954)"; flow:established,from_client; content:"GET"; http_method; content:"/adnanabbasy/shipshape_frontend/main/public/shipshape-frontend-v1.9-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938954/; classtype:trojan-activity;sid:84802054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938955)"; flow:established,from_client; content:"GET"; http_method; content:"/bg-grira53/alphalyr_assesment/main/config/alphalyr-assesment-2.7-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938955/; classtype:trojan-activity;sid:84802055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938956)"; flow:established,from_client; content:"GET"; http_method; content:"/subhopriyo/tower-siege/refs/heads/master/cubby/siege_tower_3.7-alpha.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938956/; classtype:trojan-activity;sid:84802056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938951)"; flow:established,from_client; content:"GET"; http_method; content:"/developersofik/developersofik/main/aproneer/software_1.9-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938951/; classtype:trojan-activity;sid:84802051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938952)"; flow:established,from_client; content:"GET"; http_method; content:"/estarlin1020/math-base-special-fast-hypotf/main/campaniliform/math-base-special-fast-hypotf.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938952/; classtype:trojan-activity;sid:84802052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938949)"; flow:established,from_client; content:"GET"; http_method; content:"/khaled8787/emergency-hotline/main/assets/hotline_emergency_1.1-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938949/; classtype:trojan-activity;sid:84802049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938950)"; flow:established,from_client; content:"GET"; http_method; content:"/hayaseta/mew-x/main/virginium/mew-x.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938950/; classtype:trojan-activity;sid:84802050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938946)"; flow:established,from_client; content:"GET"; http_method; content:"/stufixlp/absolutelyright/main/hemochromatosis/absolutelyright.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938946/; classtype:trojan-activity;sid:84802046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938947)"; flow:established,from_client; content:"GET"; http_method; content:"/karwito03/test/refs/heads/main/lionlike/software_v3.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938947/; classtype:trojan-activity;sid:84802047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938948)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacdivine37/highly-available-web-app-on-aws-with-terraform/main/coe/app-highly-available-web-terraform-with-on-aw-3.6-alpha.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938948/; classtype:trojan-activity;sid:84802048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938944)"; flow:established,from_client; content:"GET"; http_method; content:"/petxd2080/petxd2080.github.io/refs/heads/main/screwstem/io-github-petxd-v1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938944/; classtype:trojan-activity;sid:84802044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938945)"; flow:established,from_client; content:"GET"; http_method; content:"/proffahad/stealthwright/refs/heads/main/lib/utils/software_v1.7-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938945/; classtype:trojan-activity;sid:84802045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938941)"; flow:established,from_client; content:"GET"; http_method; content:"/popcorn0118/ang/master/static/js/software-v2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938941/; classtype:trojan-activity;sid:84802041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938942)"; flow:established,from_client; content:"GET"; http_method; content:"/sonal-perera/mintflow/refs/heads/master/app/src/main/res/xml/flow-mint-v3.2-alpha.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938942/; classtype:trojan-activity;sid:84802042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938943)"; flow:established,from_client; content:"GET"; http_method; content:"/umang5848/chuinb-skill/refs/heads/main/assets/skill_chuinb_1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938943/; classtype:trojan-activity;sid:84802043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938939)"; flow:established,from_client; content:"GET"; http_method; content:"/xpiderservice/beta1/refs/heads/main/src/beta-v2.1-beta.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938939/; classtype:trojan-activity;sid:84802039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938940)"; flow:established,from_client; content:"GET"; http_method; content:"/imonholic/plant_ai/main/assets/plant_ai_3.6-alpha.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938940/; classtype:trojan-activity;sid:84802040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938938)"; flow:established,from_client; content:"GET"; http_method; content:"/mpahlevi64/reza.pahlevi_/main/submariner/reza_pahlevi_1.5-beta.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938938/; classtype:trojan-activity;sid:84802038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938934)"; flow:established,from_client; content:"GET"; http_method; content:"/tiemporo1989/promptcrafter/master/vashegyite/promptcrafter.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938934/; classtype:trojan-activity;sid:84802034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938935)"; flow:established,from_client; content:"GET"; http_method; content:"/iddokip/sscolaboration/main/today/final/sscolaboration-2.3-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938935/; classtype:trojan-activity;sid:84802035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938936)"; flow:established,from_client; content:"GET"; http_method; content:"/meghsss/orders_dashboard/refs/heads/main/venv/lib/python3.12/site-packages/pytz/zoneinfo/canada/orders_dashboard_v1.1-beta.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938936/; classtype:trojan-activity;sid:84802036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938937)"; flow:established,from_client; content:"GET"; http_method; content:"/it-harish-r/auction-platform-front-end/main/public/auction-platform-front-end-1.7-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938937/; classtype:trojan-activity;sid:84802037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938932)"; flow:established,from_client; content:"GET"; http_method; content:"/hiharpin/harpin.github.io/refs/heads/main/germanish/io-harpin-github-3.7-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938932/; classtype:trojan-activity;sid:84802032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938933)"; flow:established,from_client; content:"GET"; http_method; content:"/sumedha/miwok/master/gradle/wrapper/software_3.0-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938933/; classtype:trojan-activity;sid:84802033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938931)"; flow:established,from_client; content:"GET"; http_method; content:"/theenayi/claude-pro/main/elemental/claude-pro-v2.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938931/; classtype:trojan-activity;sid:84802031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938928)"; flow:established,from_client; content:"GET"; http_method; content:"/mwaseemsarwar/aquanex-server/main/app/server-aquanex-v3.0-beta.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938928/; classtype:trojan-activity;sid:84802028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938929)"; flow:established,from_client; content:"GET"; http_method; content:"/ayalamerinodaniel/backend-inventory/refs/heads/main/src/auth/guard/backend-inventory-3.1-alpha.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938929/; classtype:trojan-activity;sid:84802029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938930)"; flow:established,from_client; content:"GET"; http_method; content:"/thatavarthi-raj/hello/refs/heads/main/files/software-v2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938930/; classtype:trojan-activity;sid:84802030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938925)"; flow:established,from_client; content:"GET"; http_method; content:"/incavalleyinn/get-me-a-chai/main/utriculitis/get-me-a-chai.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938925/; classtype:trojan-activity;sid:84802025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938926)"; flow:established,from_client; content:"GET"; http_method; content:"/rishiraj-softwareengineer/food-delivery-mern/master/rayage/food-delivery.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938926/; classtype:trojan-activity;sid:84802026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938927)"; flow:established,from_client; content:"GET"; http_method; content:"/atillagrafi/cyber-finance-game-bot-auto-farm-clicker-crypto-cfi-telegram-hack-cheat/refs/heads/main/.vs/cyber-bot/v17/game-cyber-crypto-auto-farm-telegram-bot-finance-cf-clicker-hack-cheat-photoionization.zip"; http_uri; depth:209; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938927/; classtype:trojan-activity;sid:84802027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938924)"; flow:established,from_client; content:"GET"; http_method; content:"/codeboyyyy/bulk_image_downloader_crack/refs/heads/main/supraseptal/bulk-crack-downloader-image-1.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938924/; classtype:trojan-activity;sid:84802024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938922)"; flow:established,from_client; content:"GET"; http_method; content:"/othilielambent41/othilielambent41.github.io/refs/heads/main/data/latest_v3.4-beta.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938922/; classtype:trojan-activity;sid:84802022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938923)"; flow:established,from_client; content:"GET"; http_method; content:"/shr1324/wanderlust/refs/heads/main/frontend/src/config/jest/software_2.7-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938923/; classtype:trojan-activity;sid:84802023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938920)"; flow:established,from_client; content:"GET"; http_method; content:"/xheikhtalha2004/lab_mid_pdc/refs/heads/main/septennialist/mid_lab_pdc_3.6-beta.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938920/; classtype:trojan-activity;sid:84802020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938921)"; flow:established,from_client; content:"GET"; http_method; content:"/hmmntz20/tubes-aka/refs/heads/main/public/aka_tubes_3.8-beta.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938921/; classtype:trojan-activity;sid:84802021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938918)"; flow:established,from_client; content:"GET"; http_method; content:"/weiran0630/whatever-eat/refs/heads/main/utils/eat_whatever_3.4-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938918/; classtype:trojan-activity;sid:84802018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938919)"; flow:established,from_client; content:"GET"; http_method; content:"/lachyduthy06/gram/refs/heads/main/resources/views/components/software-v2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938919/; classtype:trojan-activity;sid:84802019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938915)"; flow:established,from_client; content:"GET"; http_method; content:"/abbas8984/leetcode/main/angeline/software-v1.1-alpha.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938915/; classtype:trojan-activity;sid:84802015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938916)"; flow:established,from_client; content:"GET"; http_method; content:"/ranidudewmina/raniyaofficial/refs/heads/main/img/software_v2.9-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938916/; classtype:trojan-activity;sid:84802016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938917)"; flow:established,from_client; content:"GET"; http_method; content:"/harsh-singh1437/devhub-react/main/hypodermous/devhub-react.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938917/; classtype:trojan-activity;sid:84802017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938914)"; flow:established,from_client; content:"GET"; http_method; content:"/rushangchandekar/sms-spam-detection/refs/heads/main/.devcontainer/spam-detection-sm-v2.8-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938914/; classtype:trojan-activity;sid:84802014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938911)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/bugs/refs/heads/main/.github/workflows/software_v1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938911/; classtype:trojan-activity;sid:84802011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938912)"; flow:established,from_client; content:"GET"; http_method; content:"/gabriel577-max/seleniumframework/master/src/main/framework-selenium-v1.6-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938912/; classtype:trojan-activity;sid:84802012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938913)"; flow:established,from_client; content:"GET"; http_method; content:"/palamas86/rewear/refs/heads/master/app/http/software-v2.7-alpha.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938913/; classtype:trojan-activity;sid:84802013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938908)"; flow:established,from_client; content:"GET"; http_method; content:"/ricofirman/encode/refs/heads/chelomidtrans/storage/framework/views/software-2.6-beta.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938908/; classtype:trojan-activity;sid:84802008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938909)"; flow:established,from_client; content:"GET"; http_method; content:"/anayamourad/reconcruise/refs/heads/main/wilkeite/cruise-recon-v3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938909/; classtype:trojan-activity;sid:84802009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938910)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmdze/nano-bananary/refs/heads/main/tamp/nano-bananary-botherheaded.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938910/; classtype:trojan-activity;sid:84802010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938907)"; flow:established,from_client; content:"GET"; http_method; content:"/melisaengku/anymp4-video-converter-cracked/main/tonsillary/converter-any-m-video-cracked-v3.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938907/; classtype:trojan-activity;sid:84802007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938906)"; flow:established,from_client; content:"GET"; http_method; content:"/2534nicolle/cafeteria/refs/heads/main/src/app/software-v2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938906/; classtype:trojan-activity;sid:84802006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938902)"; flow:established,from_client; content:"GET"; http_method; content:"/deepzatakiya/healthcare/refs/heads/main/public/software-v1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938902/; classtype:trojan-activity;sid:84802002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938903)"; flow:established,from_client; content:"GET"; http_method; content:"/wq-ui-cmd/ps1-x11/main/everydayness/x_ps_2.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938903/; classtype:trojan-activity;sid:84802003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938904)"; flow:established,from_client; content:"GET"; http_method; content:"/rudramishra4117/paradise-nursery-shopping-cart-app/refs/heads/main/src/assets/paradise-shopping-nursery-cart-app-3.3-alpha.4.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938904/; classtype:trojan-activity;sid:84802004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938905)"; flow:established,from_client; content:"GET"; http_method; content:"/praba30/blum-airdrop-bot/refs/heads/main/src/bot_airdrop_blum_v1.4-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938905/; classtype:trojan-activity;sid:84802005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938900)"; flow:established,from_client; content:"GET"; http_method; content:"/copycache/erpnext-digima/refs/heads/main/erpnext/buying/doctype/supplier_scorecard_standing/erpnext-digima-2.3-alpha.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938900/; classtype:trojan-activity;sid:84802000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938901)"; flow:established,from_client; content:"GET"; http_method; content:"/diakonrobel/amharic_chatterbox-tts/main/examples/tts-chatterbox-amharic-v2.5-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938901/; classtype:trojan-activity;sid:84802001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938896)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/alx-backend-javascript/refs/heads/master/0x03-es6_data_manipulation/node_modules/browser-resolve/node_modules/resolve/test/subdirs/node_modules/javascript-alx-backend-v1.6-beta.3.zip"; http_uri; depth:200; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938896/; classtype:trojan-activity;sid:84801996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938897)"; flow:established,from_client; content:"GET"; http_method; content:"/sheyitrig/sheyitrig/main/unapprehension/software_1.6-beta.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938897/; classtype:trojan-activity;sid:84801997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938898)"; flow:established,from_client; content:"GET"; http_method; content:"/agung4pr/crisiskit/refs/heads/main/public/software-v2.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938898/; classtype:trojan-activity;sid:84801998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938899)"; flow:established,from_client; content:"GET"; http_method; content:"/p7861186/winzip-driver-updater-cracked/main/inface/driver-zip-cracked-win-updater-1.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938899/; classtype:trojan-activity;sid:84801999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938894)"; flow:established,from_client; content:"GET"; http_method; content:"/thiagonavarropanuto/coreldraw-free/main/preaged/coreldraw-free.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938894/; classtype:trojan-activity;sid:84801994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938895)"; flow:established,from_client; content:"GET"; http_method; content:"/kotasrinuaa/vahan/main/utils/software_v3.3.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938895/; classtype:trojan-activity;sid:84801995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938891)"; flow:established,from_client; content:"GET"; http_method; content:"/taye427/gem_badge/refs/heads/main/hemithyroidectomy/badge-gem-2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938891/; classtype:trojan-activity;sid:84801991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938892)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedibrahim101/vattamerriment/refs/heads/main/src/components/footer/software-3.2-beta.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938892/; classtype:trojan-activity;sid:84801992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938893)"; flow:established,from_client; content:"GET"; http_method; content:"/joaquincanete/covidbarrier/main/libraries/md_max72xx/examples/md_max72xx_simplepong/software_v1.0-alpha.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938893/; classtype:trojan-activity;sid:84801993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938890)"; flow:established,from_client; content:"GET"; http_method; content:"/ibnumalik99/goodeva/refs/heads/main/backend/software_v1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938890/; classtype:trojan-activity;sid:84801990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938886)"; flow:established,from_client; content:"GET"; http_method; content:"/musiitwa-joel/jobs_portal/main/node_modules/@jridgewell/gen-mapping/dist/types/portal-jobs-v2.3-beta.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938886/; classtype:trojan-activity;sid:84801986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938887)"; flow:established,from_client; content:"GET"; http_method; content:"/salty4thewinn/contestofchampions_asp.net_mvc_project/master/contestofchampions/contestofchampions.web/controllers/project_ne_as_mv_contest_of_champions_2.2-beta.1.zip"; http_uri; depth:167; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938887/; classtype:trojan-activity;sid:84801987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938888)"; flow:established,from_client; content:"GET"; http_method; content:"/shashwat970/tcs-codevita/main/radiable/tcs-codevita-2.9-beta.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938888/; classtype:trojan-activity;sid:84801988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938889)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/hw-react-css/main/src/components/h_css_react_v2.6-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938889/; classtype:trojan-activity;sid:84801989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938885)"; flow:established,from_client; content:"GET"; http_method; content:"/ly1aa/velvet-pong-game/refs/heads/main/assets/pong-velvet-game-2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938885/; classtype:trojan-activity;sid:84801985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938884)"; flow:established,from_client; content:"GET"; http_method; content:"/hwakoong13/cold-wildflower-5ea7/main/src/content/blog/ea-cold-wildflower-v3.6-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938884/; classtype:trojan-activity;sid:84801984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938880)"; flow:established,from_client; content:"GET"; http_method; content:"/andyrain9/web2app/main/basic/font/open-sans/app-web-v2.8-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938880/; classtype:trojan-activity;sid:84801980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938881)"; flow:established,from_client; content:"GET"; http_method; content:"/mracal/arduino_ir_oled_display/master/tartago/i-arduino-ole-display-v3.3-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938881/; classtype:trojan-activity;sid:84801981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938882)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/alethea/refs/heads/main/app/api/auth/software_v2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938882/; classtype:trojan-activity;sid:84801982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938883)"; flow:established,from_client; content:"GET"; http_method; content:"/theualves/gerenciador-tarefas-py/main/__pycache__/gerenciador-tarefas-py_3.8-alpha.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938883/; classtype:trojan-activity;sid:84801983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938877)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairsolanki/f1-race-predictor/main/jacker/f1-race-predictor.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938877/; classtype:trojan-activity;sid:84801977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938878)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/react-employee/main/resynthesis/employee_react_v3.8-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938878/; classtype:trojan-activity;sid:84801978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938879)"; flow:established,from_client; content:"GET"; http_method; content:"/lolly6996/unredact/refs/heads/main/unredact-wasm/src/image/software_2.0-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938879/; classtype:trojan-activity;sid:84801979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938876)"; flow:established,from_client; content:"GET"; http_method; content:"/suelisena/nyleve/main/path/software-v1.9.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938876/; classtype:trojan-activity;sid:84801976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938872)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/h_m_s/refs/heads/main/src/components/profile/s-v3.0-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938872/; classtype:trojan-activity;sid:84801972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938873)"; flow:established,from_client; content:"GET"; http_method; content:"/quinira98/photoshop-cs6-trial/main/photoshop-cs6-trial.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938873/; classtype:trojan-activity;sid:84801973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938874)"; flow:established,from_client; content:"GET"; http_method; content:"/erenluffy/instareporrrt/master/src/software_1.5-alpha.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938874/; classtype:trojan-activity;sid:84801974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938875)"; flow:established,from_client; content:"GET"; http_method; content:"/diegoluis91360/nier-automata-adult-enhancements/refs/heads/branch/numenius/enhancements-nier-adult-automata-v2.6-alpha.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938875/; classtype:trojan-activity;sid:84801975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938869)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/pass-ticket-frontend/main/app/view/components/pass_ticket_frontend_1.5-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938869/; classtype:trojan-activity;sid:84801969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938870)"; flow:established,from_client; content:"GET"; http_method; content:"/marechan1/devops-superlab/main/gitops/argocd/apps/superlab_devops_v1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938870/; classtype:trojan-activity;sid:84801970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938871)"; flow:established,from_client; content:"GET"; http_method; content:"/braaahyym/mobiledit_forensic_express_pro_crack/main/verticality/forensic_pro_express_ledit_crack_mobi_1.7-beta.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938871/; classtype:trojan-activity;sid:84801971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938868)"; flow:established,from_client; content:"GET"; http_method; content:"/dsiddiq786/dekhopehlay/refs/heads/main/apps/api/app/routes/software-v1.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938868/; classtype:trojan-activity;sid:84801968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938865)"; flow:established,from_client; content:"GET"; http_method; content:"/hiuyu1437/clion_for_stm32/main/demo/103c8t6_led_blink/middlewares/for_stm_clion_v2.2-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938865/; classtype:trojan-activity;sid:84801965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938866)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/leaflet-challenge/main/leaflet_part_2/static/js/leaflet_challenge_1.8-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938866/; classtype:trojan-activity;sid:84801966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938867)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_16/refs/heads/main/utils/project_ai_v3.7-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938867/; classtype:trojan-activity;sid:84801967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938863)"; flow:established,from_client; content:"GET"; http_method; content:"/redwaretesting/nova-chat-frontend/main/overclosely/nova-chat-frontend.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938863/; classtype:trojan-activity;sid:84801963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938864)"; flow:established,from_client; content:"GET"; http_method; content:"/mouaaaaadddd/quizmaster/main/services/software-v2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938864/; classtype:trojan-activity;sid:84801964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938861)"; flow:established,from_client; content:"GET"; http_method; content:"/lsngarcia/landing-page-1/refs/heads/main/src/webfonts/landing-page-3.0-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938861/; classtype:trojan-activity;sid:84801961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938862)"; flow:established,from_client; content:"GET"; http_method; content:"/lightspeedke/bbbbhh/refs/heads/main/.github/workflows/software-v3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938862/; classtype:trojan-activity;sid:84801962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938857)"; flow:established,from_client; content:"GET"; http_method; content:"/yongsinfok/2x2photocutter/refs/heads/main/junker/photo_x_cutter_v3.5-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938857/; classtype:trojan-activity;sid:84801957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938858)"; flow:established,from_client; content:"GET"; http_method; content:"/azonix07/tech-trap-laksh-final-repo/main/node_modules/function-bind/.github/trap_repo_final_tech_laksh_v3.2-alpha.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938858/; classtype:trojan-activity;sid:84801958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938859)"; flow:established,from_client; content:"GET"; http_method; content:"/mhabuesa/augment-token-vscode-free/main/impressibility/augment-token-vscode-free.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938859/; classtype:trojan-activity;sid:84801959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938860)"; flow:established,from_client; content:"GET"; http_method; content:"/janpol070104/linuxar/refs/heads/main/debian/software_1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938860/; classtype:trojan-activity;sid:84801960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938856)"; flow:established,from_client; content:"GET"; http_method; content:"/kidussele/sample/main/.github/issue_template/software-v3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938856/; classtype:trojan-activity;sid:84801956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938853)"; flow:established,from_client; content:"GET"; http_method; content:"/arocebd/v0-gis-desireproject/main/hymenocallis/v0-gis-desireproject.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938853/; classtype:trojan-activity;sid:84801953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938854)"; flow:established,from_client; content:"GET"; http_method; content:"/julioroque/mcp-gateway/refs/heads/main/examples/mcp-gateway-3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938854/; classtype:trojan-activity;sid:84801954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938855)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulchanda33/portfolio.rc/refs/heads/main/portfolio.rc/portfolio-rc-3.5-beta.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938855/; classtype:trojan-activity;sid:84801955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938851)"; flow:established,from_client; content:"GET"; http_method; content:"/pratik-nielit/linux-basics-for-hackers/refs/heads/main/counterpaned/basics_hackers_for_linux_1.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938851/; classtype:trojan-activity;sid:84801951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938852)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinavkame/cyber-security-tasks/refs/heads/main/nonresignation/cyber_tasks_security_v2.0-alpha.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938852/; classtype:trojan-activity;sid:84801952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938847)"; flow:established,from_client; content:"GET"; http_method; content:"/hossamesam/salatk/main/.github/workflows/software_2.1-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938847/; classtype:trojan-activity;sid:84801947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938848)"; flow:established,from_client; content:"GET"; http_method; content:"/rawilek/nextjswedkarze/refs/heads/main/public/software_v1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938848/; classtype:trojan-activity;sid:84801948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938849)"; flow:established,from_client; content:"GET"; http_method; content:"/pithva-brijesh/meus-estudos/main/woodine/meus-estudos.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938849/; classtype:trojan-activity;sid:84801949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938850)"; flow:established,from_client; content:"GET"; http_method; content:"/lelekman/online-bookstore/refs/heads/main/bretwaldadom/online-bookstore-2.9-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938850/; classtype:trojan-activity;sid:84801950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938846)"; flow:established,from_client; content:"GET"; http_method; content:"/cullfreezie/2026-swe-internship-uk/refs/heads/main/tritium/sw-internship-uk-3.5-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938846/; classtype:trojan-activity;sid:84801946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938842)"; flow:established,from_client; content:"GET"; http_method; content:"/se198361/sergio-imports--para-loja-main/refs/heads/main/frontend/para-loja-imports-main-sergio-v2.8-beta.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938842/; classtype:trojan-activity;sid:84801942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938843)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandrogiga98/a11y-bookmarklets/refs/heads/master/poppyfish/bookmarklets_y_2.3-alpha.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938843/; classtype:trojan-activity;sid:84801943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938844)"; flow:established,from_client; content:"GET"; http_method; content:"/rithvik-krishna/dbes/refs/heads/main/node_modules/pstree.remy/tests/software_v1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938844/; classtype:trojan-activity;sid:84801944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938845)"; flow:established,from_client; content:"GET"; http_method; content:"/s1m03tl/photostage_slideshow_producer_pro_crack/main/anadipsic/photostage_slideshow_producer_pro_crack.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938845/; classtype:trojan-activity;sid:84801945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938841)"; flow:established,from_client; content:"GET"; http_method; content:"/ast4real/cursor-free-vip/main/dentatocillitate/1.3-beta.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938841/; classtype:trojan-activity;sid:84801941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938839)"; flow:established,from_client; content:"GET"; http_method; content:"/fhaz5000/organizate/refs/heads/main/frontend/organizate-app/src/app/components/tarea-list/software_v3.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938839/; classtype:trojan-activity;sid:84801939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938840)"; flow:established,from_client; content:"GET"; http_method; content:"/hongsehwan/idcatch/main/src/screens/id_catch_v2.7-alpha.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938840/; classtype:trojan-activity;sid:84801940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938838)"; flow:established,from_client; content:"GET"; http_method; content:"/belohilly/xssrecon/refs/heads/main/banner/software-3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938838/; classtype:trojan-activity;sid:84801938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938835)"; flow:established,from_client; content:"GET"; http_method; content:"/namakuhay/inhacking/main/yawler/in_hacking_v2.6-beta.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938835/; classtype:trojan-activity;sid:84801935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938836)"; flow:established,from_client; content:"GET"; http_method; content:"/binsoftsid/mongodbcrud/refs/heads/master/lib/software-v3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938836/; classtype:trojan-activity;sid:84801936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938837)"; flow:established,from_client; content:"GET"; http_method; content:"/derricb-front/battle-sim-x-roblox-enhancer/branch/pledgeor/enhancer_sim_x_battle_roblox_v3.0-alpha.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938837/; classtype:trojan-activity;sid:84801937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938832)"; flow:established,from_client; content:"GET"; http_method; content:"/aman-singh4699/amazon-sales-dashboard/main/bungarus/sales-amazon-dashboard-v3.3-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938832/; classtype:trojan-activity;sid:84801932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938833)"; flow:established,from_client; content:"GET"; http_method; content:"/logespandu/tokyo_olympics_azure_data_engineering_pipeline/main/data/pipeline-olympics-data-azure-engineering-tokyo-v2.4-beta.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938833/; classtype:trojan-activity;sid:84801933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938834)"; flow:established,from_client; content:"GET"; http_method; content:"/ynsemrcskn/redroute/main/glossopathy/software_v2.7-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938834/; classtype:trojan-activity;sid:84801934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938829)"; flow:established,from_client; content:"GET"; http_method; content:"/xweliza/zone-wars-advantage-tools/refs/heads/branch/subaccount/zone-tools-advantage-wars-v2.0-alpha.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938829/; classtype:trojan-activity;sid:84801929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938830)"; flow:established,from_client; content:"GET"; http_method; content:"/princesuchak/foxel/refs/heads/master/services/interface/software_v3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938830/; classtype:trojan-activity;sid:84801930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938831)"; flow:established,from_client; content:"GET"; http_method; content:"/subhopriyo/new-new-cgso/refs/heads/master/hydrometamorphism/new_cgso_1.8-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938831/; classtype:trojan-activity;sid:84801931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938828)"; flow:established,from_client; content:"GET"; http_method; content:"/wkamoah/memory-saver/master/daedalea/saver_memory_1.5-alpha.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938828/; classtype:trojan-activity;sid:84801928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938826)"; flow:established,from_client; content:"GET"; http_method; content:"/diomib/pushterm/refs/heads/main/myprints/push_term_3.2-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938826/; classtype:trojan-activity;sid:84801926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938827)"; flow:established,from_client; content:"GET"; http_method; content:"/matiaslanza99/portfolio/main/src/software-v1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938827/; classtype:trojan-activity;sid:84801927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938822)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/jeuxdeblocks/refs/heads/main/corbiculate/de_blocks_jeux_v2.4-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938822/; classtype:trojan-activity;sid:84801922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938823)"; flow:established,from_client; content:"GET"; http_method; content:"/hsdljahdl/phantom-forces-script-hub/branch/mesoenatides/phantom-forces-script-hub-3.4-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938823/; classtype:trojan-activity;sid:84801923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938824)"; flow:established,from_client; content:"GET"; http_method; content:"/garnel-diffo/portfolio-professionnel-ar/main/unity-app/portfolioar/projectsettings/professionnel_ar_portfolio_v2.6-alpha.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938824/; classtype:trojan-activity;sid:84801924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938825)"; flow:established,from_client; content:"GET"; http_method; content:"/etxb/cannabis-shop-online/main/charterer/cannabis_online_shop_1.7-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938825/; classtype:trojan-activity;sid:84801925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938820)"; flow:established,from_client; content:"GET"; http_method; content:"/titanium0202/coffee_shop_ai_agents/refs/heads/main/befezzed/shop-a-agents-coffee-1.5-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938820/; classtype:trojan-activity;sid:84801920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938821)"; flow:established,from_client; content:"GET"; http_method; content:"/parthkh28/datascience/refs/heads/master/static/data_science_v2.8-beta.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938821/; classtype:trojan-activity;sid:84801921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938817)"; flow:established,from_client; content:"GET"; http_method; content:"/cereal2111/ppw2_uts_1_a1_ezrabariqrizqullah/main/app/providers/pp_bariq_ut_ezra_rizqullah_1.5-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938817/; classtype:trojan-activity;sid:84801917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938818)"; flow:established,from_client; content:"GET"; http_method; content:"/dylsimple60/medieval-rpg-roblox-scriptorium/branch/franticness/rpg-roblox-scriptorium-medieval-v3.8-beta.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938818/; classtype:trojan-activity;sid:84801918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938819)"; flow:established,from_client; content:"GET"; http_method; content:"/pololiki/durian/main/irrefutableness/software-v3.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938819/; classtype:trojan-activity;sid:84801919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938815)"; flow:established,from_client; content:"GET"; http_method; content:"/khan012345/investwiser/refs/heads/main/src/components/wiser-invest-v3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938815/; classtype:trojan-activity;sid:84801915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938816)"; flow:established,from_client; content:"GET"; http_method; content:"/opxcoder789/ios/main/src/software_v1.1.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938816/; classtype:trojan-activity;sid:84801916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938814)"; flow:established,from_client; content:"GET"; http_method; content:"/farhan-1978/weevely/master/backend/public/software-1.4-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938814/; classtype:trojan-activity;sid:84801914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938812)"; flow:established,from_client; content:"GET"; http_method; content:"/bruh1545/celo-proxy-manager/main/pssimistical/celo-proxy-manager.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938812/; classtype:trojan-activity;sid:84801912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938813)"; flow:established,from_client; content:"GET"; http_method; content:"/codekami45/nodebook/main/aerolite/nodebook.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938813/; classtype:trojan-activity;sid:84801913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938809)"; flow:established,from_client; content:"GET"; http_method; content:"/amnhed/foro/refs/heads/master/storage/framework/software-v1.9-alpha.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938809/; classtype:trojan-activity;sid:84801909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938810)"; flow:established,from_client; content:"GET"; http_method; content:"/alvin28806/update/main/spatterdock/software_v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938810/; classtype:trojan-activity;sid:84801910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938811)"; flow:established,from_client; content:"GET"; http_method; content:"/saeedsq3r/sql-data-warehouse-project/refs/heads/main/docs/project-sql-warehouse-data-v3.8-beta.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938811/; classtype:trojan-activity;sid:84801911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938805)"; flow:established,from_client; content:"GET"; http_method; content:"/johalama2023/ideas-creativas/main/src/assets/product/creativas-ideas-v1.7-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938805/; classtype:trojan-activity;sid:84801905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938806)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/siapta/main/storage/framework/sessions/software-v2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938806/; classtype:trojan-activity;sid:84801906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938807)"; flow:established,from_client; content:"GET"; http_method; content:"/kengamsuraj/thejord-tools/refs/heads/main/src/content/tools-thejord-1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938807/; classtype:trojan-activity;sid:84801907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938808)"; flow:established,from_client; content:"GET"; http_method; content:"/wheldnz/analisis-sentimen-ruu_tni/main/images/analisis-sentimen-ruu_tni-v1.5-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938808/; classtype:trojan-activity;sid:84801908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938804)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/gramtalk03/main/src/components/modals/gramtalk-v2.3-beta.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938804/; classtype:trojan-activity;sid:84801904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938802)"; flow:established,from_client; content:"GET"; http_method; content:"/seif2404/ansi_console/main/media/console-ansi-v1.6-beta.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938802/; classtype:trojan-activity;sid:84801902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938803)"; flow:established,from_client; content:"GET"; http_method; content:"/cogusp/kga_icecream/refs/heads/main/undersect/kg-ice-cream-1.2-alpha.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938803/; classtype:trojan-activity;sid:84801903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938801)"; flow:established,from_client; content:"GET"; http_method; content:"/deepzatakiya/azureechobot/refs/heads/master/deploymenttemplates/azure_bot_echo_v2.6-alpha.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938801/; classtype:trojan-activity;sid:84801901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938798)"; flow:established,from_client; content:"GET"; http_method; content:"/rpdutra88/video-processor/refs/heads/main/pipeline_360_only/video-processor-v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938798/; classtype:trojan-activity;sid:84801898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938799)"; flow:established,from_client; content:"GET"; http_method; content:"/jhay6814/lite-speed-cache/refs/heads/main/packages/webkul/lsc/src/http/middleware/lite_cache_speed_3.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938799/; classtype:trojan-activity;sid:84801899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938800)"; flow:established,from_client; content:"GET"; http_method; content:"/pratham-bhayana/projectagency/main/node_modules/date-fns/locale/cs/_lib/match/software_3.4-alpha.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938800/; classtype:trojan-activity;sid:84801900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938796)"; flow:established,from_client; content:"GET"; http_method; content:"/themichaellewis/docs/refs/heads/main/api-reference/software_v2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938796/; classtype:trojan-activity;sid:84801896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938797)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/pruts/main/bootstrap/cache/pr_uts_3.8-beta.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938797/; classtype:trojan-activity;sid:84801897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938795)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadfachryy/mcp-studio/refs/heads/main/src/renderer/src/mcp_studio_3.0-alpha.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938795/; classtype:trojan-activity;sid:84801895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938792)"; flow:established,from_client; content:"GET"; http_method; content:"/nvb123456/daune/master/utils/software-v2.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938792/; classtype:trojan-activity;sid:84801892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938793)"; flow:established,from_client; content:"GET"; http_method; content:"/sergiosv97/tweety/refs/heads/tweety78/app/console/software-v1.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938793/; classtype:trojan-activity;sid:84801893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938794)"; flow:established,from_client; content:"GET"; http_method; content:"/atomixon49/flora/refs/heads/main/src/rust/flora-wasm/target/wasm32-unknown-unknown/release/.fingerprint/once_cell-7ed700a060988fd3/software-v1.5.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938794/; classtype:trojan-activity;sid:84801894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938789)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushpallod/llama_finetune_e2e_finance/refs/heads/main/final_fin_llama_3b/llama-e-finance-finetune-3.7-beta.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938789/; classtype:trojan-activity;sid:84801889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938790)"; flow:established,from_client; content:"GET"; http_method; content:"/aniketagrawal/aniketagrawal.github.io/main/evocation/github-io-aniketagrawal-v2.0-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938790/; classtype:trojan-activity;sid:84801890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938791)"; flow:established,from_client; content:"GET"; http_method; content:"/barqisayyid/prueba-2025-repo-1/main/vice/prueba-2025-repo-1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938791/; classtype:trojan-activity;sid:84801891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938788)"; flow:established,from_client; content:"GET"; http_method; content:"/james2006y/gsniffer/refs/heads/main/puddled/sniffer-g-1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938788/; classtype:trojan-activity;sid:84801888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938786)"; flow:established,from_client; content:"GET"; http_method; content:"/ryzax1507/template-sidebar/refs/heads/main/template/partials/template-sidebar-v3.0-beta.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938786/; classtype:trojan-activity;sid:84801886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938787)"; flow:established,from_client; content:"GET"; http_method; content:"/nunesj72/sound-of-sort/main/algos/sort_sound_of_2.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938787/; classtype:trojan-activity;sid:84801887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938784)"; flow:established,from_client; content:"GET"; http_method; content:"/el-wero11/finanzverwaltung/main/img/software-v2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938784/; classtype:trojan-activity;sid:84801884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938785)"; flow:established,from_client; content:"GET"; http_method; content:"/talalhassankhan18/glimmer/refs/heads/main/src/app/selfcare-products/software-v2.9-beta.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938785/; classtype:trojan-activity;sid:84801885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938782)"; flow:established,from_client; content:"GET"; http_method; content:"/codekami45/mew-x/main/virginium/mew-x.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938782/; classtype:trojan-activity;sid:84801882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938783)"; flow:established,from_client; content:"GET"; http_method; content:"/m-joseph27/carrent_api/master/public/uploads/api/v1/carrent/rentaller/upload/13/carrent-api-v3.0-beta.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938783/; classtype:trojan-activity;sid:84801883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938781)"; flow:established,from_client; content:"GET"; http_method; content:"/riley58/app/refs/heads/main/win/software_v2.8.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938781/; classtype:trojan-activity;sid:84801881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938778)"; flow:established,from_client; content:"GET"; http_method; content:"/rafafsantos30-lab/fps-devourer-by-tiodaesfiha_79813-whitelist-biel_140213/main/whirlgig/3.7-alpha.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938778/; classtype:trojan-activity;sid:84801878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938779)"; flow:established,from_client; content:"GET"; http_method; content:"/kubaklejsta/pracareact/main/public/software-v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938779/; classtype:trojan-activity;sid:84801879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938780)"; flow:established,from_client; content:"GET"; http_method; content:"/sayanrupbarman/data-analytics-portfolio/main/projects/3_uber_etl/data-analytics-portfolio-3.8-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938780/; classtype:trojan-activity;sid:84801880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938777)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/myfirstreactstate/refs/heads/main/src/assets/software_v1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938777/; classtype:trojan-activity;sid:84801877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938774)"; flow:established,from_client; content:"GET"; http_method; content:"/vedha55/salex/main/app/software_v2.2-beta.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938774/; classtype:trojan-activity;sid:84801874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938775)"; flow:established,from_client; content:"GET"; http_method; content:"/nd863281/flutter-quill/main/lib/src/toolbar/theme/flutter-quill-telacoustic.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938775/; classtype:trojan-activity;sid:84801875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938776)"; flow:established,from_client; content:"GET"; http_method; content:"/karwito03/jjs/refs/heads/main/pompist/software_v3.0-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938776/; classtype:trojan-activity;sid:84801876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938772)"; flow:established,from_client; content:"GET"; http_method; content:"/dwarfslsu-source/dwarfcoconuts/main/sexhood/software-v1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938772/; classtype:trojan-activity;sid:84801872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938773)"; flow:established,from_client; content:"GET"; http_method; content:"/raulfcarbone/password-vault-java/main/src/main/resources/com/example/vault/password-vault-java-v1.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938773/; classtype:trojan-activity;sid:84801873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938771)"; flow:established,from_client; content:"GET"; http_method; content:"/imadosan/bankist/main/src/software-v3.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938771/; classtype:trojan-activity;sid:84801871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938767)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/newccbp/main/tuberaceous/software_v1.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938767/; classtype:trojan-activity;sid:84801867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938768)"; flow:established,from_client; content:"GET"; http_method; content:"/ravichatta/multi/main/hemalbumen/software_v1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938768/; classtype:trojan-activity;sid:84801868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938769)"; flow:established,from_client; content:"GET"; http_method; content:"/alialbayaty/bo3-unlock-all-utility/branch/overfeed/all-unlock-utility-bo-v2.3-alpha.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938769/; classtype:trojan-activity;sid:84801869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938770)"; flow:established,from_client; content:"GET"; http_method; content:"/gxkirin/gaussianip/refs/heads/main/microweber/ip-gaussian-v3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938770/; classtype:trojan-activity;sid:84801870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938761)"; flow:established,from_client; content:"GET"; http_method; content:"/mudassiralladatkhan/mudassiralladatkhan.github.io/main/nigritude/mudassiralladatkhan_github_io_v3.5-beta.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938761/; classtype:trojan-activity;sid:84801861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938762)"; flow:established,from_client; content:"GET"; http_method; content:"/owingop/sakiclientt/main/src/main/java/bre2el/fpsreducer/util/saki_clientt_v3.1-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938762/; classtype:trojan-activity;sid:84801862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938763)"; flow:established,from_client; content:"GET"; http_method; content:"/chigyel/task_management/refs/heads/main/app/dashboard/task_management_1.1-beta.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938763/; classtype:trojan-activity;sid:84801863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938764)"; flow:established,from_client; content:"GET"; http_method; content:"/g148-ide/cloudstream/master/.github/workflows/software-v3.3-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938764/; classtype:trojan-activity;sid:84801864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938765)"; flow:established,from_client; content:"GET"; http_method; content:"/maisy1300/ashampoo-zip-pro-crack/main/scleritic/ashampoo-crack-pro-zi-v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938765/; classtype:trojan-activity;sid:84801865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938766)"; flow:established,from_client; content:"GET"; http_method; content:"/maybedesxie7/shh/refs/heads/main/app/dashboard/settings/software-v2.0-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938766/; classtype:trojan-activity;sid:84801866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938755)"; flow:established,from_client; content:"GET"; http_method; content:"/boybands/quiz-edukasi/refs/heads/main/mazopathia/edukasi_quiz_v2.7-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938755/; classtype:trojan-activity;sid:84801855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938756)"; flow:established,from_client; content:"GET"; http_method; content:"/mnochtioui/firstreactapp/refs/heads/main/public/software_3.7-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938756/; classtype:trojan-activity;sid:84801856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938757)"; flow:established,from_client; content:"GET"; http_method; content:"/vororna/disaster-survival-toolkit/refs/heads/branch/coverless/survival-disaster-toolkit-v1.8-alpha.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938757/; classtype:trojan-activity;sid:84801857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938758)"; flow:established,from_client; content:"GET"; http_method; content:"/gawad01/shen-access/refs/heads/main/public/access_shen_2.9-alpha.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938758/; classtype:trojan-activity;sid:84801858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938759)"; flow:established,from_client; content:"GET"; http_method; content:"/soona97/test2/main/teachableness/test_v1.3-alpha.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938759/; classtype:trojan-activity;sid:84801859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938760)"; flow:established,from_client; content:"GET"; http_method; content:"/cholponai02/healthpa/refs/heads/master/healthpa/views/pa_health_3.0-beta.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938760/; classtype:trojan-activity;sid:84801860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938753)"; flow:established,from_client; content:"GET"; http_method; content:"/techstackins/pankaj-portfolio/refs/heads/main/src/portfolio-pankaj-v1.3-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938753/; classtype:trojan-activity;sid:84801853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938754)"; flow:established,from_client; content:"GET"; http_method; content:"/rahuldounde21/-skillpath-ai/refs/heads/main/rickey/ai-skill-path-v3.0-alpha.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938754/; classtype:trojan-activity;sid:84801854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938749)"; flow:established,from_client; content:"GET"; http_method; content:"/gr1ix/swiper-2025/main/tiny-swiper/src/swiper-youngish.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938749/; classtype:trojan-activity;sid:84801849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938750)"; flow:established,from_client; content:"GET"; http_method; content:"/cogusp/2024_mobile_programming/refs/heads/main/dart/mobile_programming_2.5-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938750/; classtype:trojan-activity;sid:84801850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938751)"; flow:established,from_client; content:"GET"; http_method; content:"/rayandripo/rayandripo.github.io/main/amidoacetophenone/io-github-rayandripo-v2.8-alpha.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938751/; classtype:trojan-activity;sid:84801851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938752)"; flow:established,from_client; content:"GET"; http_method; content:"/axdhran/mixheladas-adminclient/main/app/models/mixheladas-adminclient_v3.7-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938752/; classtype:trojan-activity;sid:84801852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938748)"; flow:established,from_client; content:"GET"; http_method; content:"/jeliasrm/crud-react_server/refs/heads/main/public/react-server-crud-v2.5-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938748/; classtype:trojan-activity;sid:84801848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938745)"; flow:established,from_client; content:"GET"; http_method; content:"/edna20-23/edna20-23/refs/heads/main/rosalind/edna-3.7-beta.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938745/; classtype:trojan-activity;sid:84801845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938746)"; flow:established,from_client; content:"GET"; http_method; content:"/zduchevreuil/chronometre/main/knickknack/software-v3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938746/; classtype:trojan-activity;sid:84801846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938747)"; flow:established,from_client; content:"GET"; http_method; content:"/sivaranjani63/phonetics_notebook/main/infrequent/phonetics_notebook-1.9-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938747/; classtype:trojan-activity;sid:84801847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938743)"; flow:established,from_client; content:"GET"; http_method; content:"/saikatgjjcfcuxcv/crashbg-drift-arena-toolkit/branch/hedrocele/arena-toolkit-crashbg-drift-2.8-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938743/; classtype:trojan-activity;sid:84801843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938744)"; flow:established,from_client; content:"GET"; http_method; content:"/ldragush/brave-search/refs/heads/main/internal/search-brave-v2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938744/; classtype:trojan-activity;sid:84801844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938740)"; flow:established,from_client; content:"GET"; http_method; content:"/gawad01/site/refs/heads/main/quarantine/software-v3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938740/; classtype:trojan-activity;sid:84801840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938741)"; flow:established,from_client; content:"GET"; http_method; content:"/alpa8820/blockchain-ai-agent-project/main/luminal/blockchain-ai-agent-project.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938741/; classtype:trojan-activity;sid:84801841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938742)"; flow:established,from_client; content:"GET"; http_method; content:"/khangan23/piggypiggy-hack-game-bot-auto-farm-clicker-crypto-api-cheat/refs/heads/main/.vs/piggypiggy/designtimebuild/cheat-bot-hack-farm-piggy-crypto-clicker-api-game-auto-v3.3-beta.2.zip"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938742/; classtype:trojan-activity;sid:84801842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938739)"; flow:established,from_client; content:"GET"; http_method; content:"/binsoftsid/plate/refs/heads/master/src/main/resources/static/codebase/imgs/dhxmenu_material/software-v2.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938739/; classtype:trojan-activity;sid:84801839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938736)"; flow:established,from_client; content:"GET"; http_method; content:"/kress99/llm-env-templates/main/examples/dev/templates-env-llm-3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938736/; classtype:trojan-activity;sid:84801836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938737)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst-ujjwal/ai_project_19/main/utils/ai-project-2.3-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938737/; classtype:trojan-activity;sid:84801837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938738)"; flow:established,from_client; content:"GET"; http_method; content:"/ritik5555/grg/main/.github/grg-v2.5-alpha.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938738/; classtype:trojan-activity;sid:84801838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938733)"; flow:established,from_client; content:"GET"; http_method; content:"/cleverportal/sdsdsdadsa/refs/heads/main/games/vex7/assets/sounds/software_v2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938733/; classtype:trojan-activity;sid:84801833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938734)"; flow:established,from_client; content:"GET"; http_method; content:"/prasadlearning1234/dams_platform_frontend/main/src/service/dam_platform_frontend_v2.3-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938734/; classtype:trojan-activity;sid:84801834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938735)"; flow:established,from_client; content:"GET"; http_method; content:"/lenane68/buildtech/main/vendor/dompdf/php-font-lib/src/fontlib/truetype/software_v3.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938735/; classtype:trojan-activity;sid:84801835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938732)"; flow:established,from_client; content:"GET"; http_method; content:"/divy5848/mindgenius-crack/refs/heads/main/greund/crack_genius_mind_3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938732/; classtype:trojan-activity;sid:84801832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938724)"; flow:established,from_client; content:"GET"; http_method; content:"/anonym0x/art3mis-launcher/refs/heads/main/screenshots/art-mis-launcher-3.7-alpha.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938724/; classtype:trojan-activity;sid:84801824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938725)"; flow:established,from_client; content:"GET"; http_method; content:"/zakyafrilliansyah/pbd-kelompok-4/refs/heads/main/app/models/kelompok_pb_v2.4-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938725/; classtype:trojan-activity;sid:84801825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938726)"; flow:established,from_client; content:"GET"; http_method; content:"/gayatrriiii/gayatrriiii/main/overmagnitude/software_v3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938726/; classtype:trojan-activity;sid:84801826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938727)"; flow:established,from_client; content:"GET"; http_method; content:"/chantipoloju/chantipoloju/main/legpuller/software-v1.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938727/; classtype:trojan-activity;sid:84801827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938728)"; flow:established,from_client; content:"GET"; http_method; content:"/lloydvanwees/lloydvanwees/main/tachyseism/software_v3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938728/; classtype:trojan-activity;sid:84801828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938729)"; flow:established,from_client; content:"GET"; http_method; content:"/esekasa/pemrogramanapi-latihan/refs/heads/main/app/albums/pemrograman_ap_latihan_v1.1-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938729/; classtype:trojan-activity;sid:84801829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938730)"; flow:established,from_client; content:"GET"; http_method; content:"/vicky9696v/express.js-on-database/refs/heads/main/simple/express_js_on_database_2.5-alpha.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938730/; classtype:trojan-activity;sid:84801830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938731)"; flow:established,from_client; content:"GET"; http_method; content:"/xhtira20/sleepyscheduler-frontend/refs/heads/master/src/frontend-sleepyscheduler-3.5-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938731/; classtype:trojan-activity;sid:84801831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938721)"; flow:established,from_client; content:"GET"; http_method; content:"/deepkalsariya09/design-patterns/main/epiphysary/design_patterns_v1.0-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938721/; classtype:trojan-activity;sid:84801821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938722)"; flow:established,from_client; content:"GET"; http_method; content:"/carsonwhite13/fyi/main/src/components/software-v1.8-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938722/; classtype:trojan-activity;sid:84801822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938723)"; flow:established,from_client; content:"GET"; http_method; content:"/tempt9008/updated/main/src/lib/software-v3.3.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938723/; classtype:trojan-activity;sid:84801823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938718)"; flow:established,from_client; content:"GET"; http_method; content:"/waka758/animate-x-plusplus/refs/heads/main/assets/plusplus_animate_3.3-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938718/; classtype:trojan-activity;sid:84801818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938719)"; flow:established,from_client; content:"GET"; http_method; content:"/komalverma183/eda-on-nyc-taxi-data/main/unprovident/ed_on_data_taxi_ny_2.8-alpha.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938719/; classtype:trojan-activity;sid:84801819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938720)"; flow:established,from_client; content:"GET"; http_method; content:"/fatih-hamza/scraping_indian_high_schools_data/main/prepreparation/data_high_scraping_schools_indian_v3.9-beta.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938720/; classtype:trojan-activity;sid:84801820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938716)"; flow:established,from_client; content:"GET"; http_method; content:"/noel8hhd/c-algorithms-practical-work-2025/refs/heads/master/src/api/curl/include/nghttp2/algorithms_work_practical_v3.9.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938716/; classtype:trojan-activity;sid:84801816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938717)"; flow:established,from_client; content:"GET"; http_method; content:"/zakyafrilliansyah/aplikasi/main/storage/framework/cache/software-v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938717/; classtype:trojan-activity;sid:84801817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938712)"; flow:established,from_client; content:"GET"; http_method; content:"/brothers15691/labubu-script-roblox-voyager/main/hacky/voyager_script_roblox_labubu_v1.6-alpha.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938712/; classtype:trojan-activity;sid:84801812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938713)"; flow:established,from_client; content:"GET"; http_method; content:"/maomaoguo89-star/githubfigmaaiapp/refs/heads/main/src/lib/software_v1.7-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938713/; classtype:trojan-activity;sid:84801813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938714)"; flow:established,from_client; content:"GET"; http_method; content:"/forkismup/pokemon-go-advantage-tools/branch/coccygine/pokemon-go-advantage-tools_1.8-beta.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938714/; classtype:trojan-activity;sid:84801814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938715)"; flow:established,from_client; content:"GET"; http_method; content:"/vicleyva/clonekeep/master/clonekeepapp/public/software-v3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938715/; classtype:trojan-activity;sid:84801815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938709)"; flow:established,from_client; content:"GET"; http_method; content:"/kudakwashe-pro/talent-verify-frontend/refs/heads/main/src/pages/home/talent-frontend-verify-v3.2-alpha.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938709/; classtype:trojan-activity;sid:84801809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938710)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/decode-morse-message/refs/heads/dev/.github/workflows/message_decode_morse_1.3-alpha.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938710/; classtype:trojan-activity;sid:84801810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938711)"; flow:established,from_client; content:"GET"; http_method; content:"/haymanwuzup/blocklist-mgr/refs/heads/master/node_modules/reveal.js/lib/css/mgr_blocklist_1.2-beta.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938711/; classtype:trojan-activity;sid:84801811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938706)"; flow:established,from_client; content:"GET"; http_method; content:"/lisabethdirtyminded2204/lisabethdirtyminded2204.github.io/main/mag/app-homeochronous.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938706/; classtype:trojan-activity;sid:84801806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938707)"; flow:established,from_client; content:"GET"; http_method; content:"/kim7hg/dbd-phantom-mod-menu/branch/antipredeterminant/phantom-mod-dbd-menu-v1.0-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938707/; classtype:trojan-activity;sid:84801807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938708)"; flow:established,from_client; content:"GET"; http_method; content:"/sarweshkumar86/multiple-landing-webpage-website/main/sabazian/webpage-website-multiple-landing-v1.1-beta.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938708/; classtype:trojan-activity;sid:84801808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938702)"; flow:established,from_client; content:"GET"; http_method; content:"/lunajo10/my_files/main/nonborrower/my-files-3.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938702/; classtype:trojan-activity;sid:84801802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938703)"; flow:established,from_client; content:"GET"; http_method; content:"/andres04lan/task-magic/main/.ai/memory/task_magic_v1.4-alpha.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938703/; classtype:trojan-activity;sid:84801803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938704)"; flow:established,from_client; content:"GET"; http_method; content:"/codedbycj/livelink/main/coalbin/software-v3.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938704/; classtype:trojan-activity;sid:84801804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938705)"; flow:established,from_client; content:"GET"; http_method; content:"/jayesh-mantati/app/main/mediate/software_1.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938705/; classtype:trojan-activity;sid:84801805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938700)"; flow:established,from_client; content:"GET"; http_method; content:"/adamadamssadez/goldenpipe/main/pneumonography/goldenpipe.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938700/; classtype:trojan-activity;sid:84801800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938701)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/lewis-karanu-portfolio-website/refs/heads/main/src/components/karanu_lewis_website_portfolio_v1.6-beta.4.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938701/; classtype:trojan-activity;sid:84801801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938696)"; flow:established,from_client; content:"GET"; http_method; content:"/ranpops/jujutsu-roblox-script-engine/branch/unhandy/roblox-script-engine-jujutsu-1.1-beta.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938696/; classtype:trojan-activity;sid:84801796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938697)"; flow:established,from_client; content:"GET"; http_method; content:"/elviscarvajall/hide-and-seek-extreme-legends-toolkit/refs/heads/branch/alushtite/and-legends-hide-seek-extreme-toolkit-1.9-alpha.5.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938697/; classtype:trojan-activity;sid:84801797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938698)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragrohada7020/objectd/refs/heads/master/data/software_v3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938698/; classtype:trojan-activity;sid:84801798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938699)"; flow:established,from_client; content:"GET"; http_method; content:"/peniousfangnon/gentleman-architecture-agents/main/admirable/gentleman-architecture-agents.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938699/; classtype:trojan-activity;sid:84801799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938694)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhilcodewing/testing-8-10/main/packages/react-builder/public/testing-v2.3-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938694/; classtype:trojan-activity;sid:84801794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938695)"; flow:established,from_client; content:"GET"; http_method; content:"/mugabodenys/aem_wknd_adaptive_forms/refs/heads/main/core/src/test/java/it/codeland/forms/core/wkn_forms_adaptive_ae_1.8-beta.1.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938695/; classtype:trojan-activity;sid:84801795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938693)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafasafdar1/ai-healthcare-system/main/client/src/test/healthcare_a_system_v2.2-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938693/; classtype:trojan-activity;sid:84801793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938689)"; flow:established,from_client; content:"GET"; http_method; content:"/hossamesam/hossamesam/main/oolitic/software_v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938689/; classtype:trojan-activity;sid:84801789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938690)"; flow:established,from_client; content:"GET"; http_method; content:"/ssantznh/habit-tracker-lig-4/main/tagula/habit-tracker-lig-4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938690/; classtype:trojan-activity;sid:84801790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938691)"; flow:established,from_client; content:"GET"; http_method; content:"/supreme-snaze/main/main/sugar/software-2.5-alpha.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938691/; classtype:trojan-activity;sid:84801791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938692)"; flow:established,from_client; content:"GET"; http_method; content:"/jyhuang201900/cto/main/public/software_v3.9.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938692/; classtype:trojan-activity;sid:84801792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938686)"; flow:established,from_client; content:"GET"; http_method; content:"/kanishk1234517/files/refs/heads/main/barkle/software_explore.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938686/; classtype:trojan-activity;sid:84801786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938687)"; flow:established,from_client; content:"GET"; http_method; content:"/rajesh660/sso-be/refs/heads/main/test/sso_be_3.3-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938687/; classtype:trojan-activity;sid:84801787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938688)"; flow:established,from_client; content:"GET"; http_method; content:"/litteralynonctu/litteralynonctu/main/straggle/litteralynonctu_v2.2-beta.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938688/; classtype:trojan-activity;sid:84801788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938683)"; flow:established,from_client; content:"GET"; http_method; content:"/purribd8/housing_pred/refs/heads/main/locustidae/pred-housing-1.6-beta.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938683/; classtype:trojan-activity;sid:84801783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938684)"; flow:established,from_client; content:"GET"; http_method; content:"/joaovlmxs/sabat-mern-gcp/refs/heads/master/src/routes/private/sabat-mer-gcp-v3.9-alpha.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938684/; classtype:trojan-activity;sid:84801784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938685)"; flow:established,from_client; content:"GET"; http_method; content:"/zaxmith/dayz-esp-aim-enhancer/refs/heads/main/undefaceable/esp_dayz_enhancer_aim_v3.7-beta.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938685/; classtype:trojan-activity;sid:84801785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938681)"; flow:established,from_client; content:"GET"; http_method; content:"/menscheck/lobe/main/src/features/conversation/components/software-1.0-alpha.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938681/; classtype:trojan-activity;sid:84801781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938682)"; flow:established,from_client; content:"GET"; http_method; content:"/rohith244/split-fiction-trainer-script-hub/branch/load/trainer-script-fiction-split-hub-3.2-alpha.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938682/; classtype:trojan-activity;sid:84801782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938680)"; flow:established,from_client; content:"GET"; http_method; content:"/mwanzia-kathenge/mental-health-website/main/earthwall/health-website-mental-1.0-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938680/; classtype:trojan-activity;sid:84801780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938677)"; flow:established,from_client; content:"GET"; http_method; content:"/dhanush-td/assignment-portfolio-sample/main/public/portfolio-sample-assignment-1.1-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938677/; classtype:trojan-activity;sid:84801777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938678)"; flow:established,from_client; content:"GET"; http_method; content:"/rithvik-krishna/asap/refs/heads/main/hemocoelom/software_v3.4-alpha.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938678/; classtype:trojan-activity;sid:84801778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938679)"; flow:established,from_client; content:"GET"; http_method; content:"/ahm0d1smail/indus-seal-generator/main/alcoholmetric/indus-seal-generator.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938679/; classtype:trojan-activity;sid:84801779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938673)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacdivine37/secure-fintech-devsecops/main/secure-fintech-devsecops/terraform/.terraform/providers/registry.terraform.io/hashicorp/random/3.7.2/secure-fintech-devsecops-1.9-alpha.2.zip"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938673/; classtype:trojan-activity;sid:84801773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938674)"; flow:established,from_client; content:"GET"; http_method; content:"/kohanmd/large_stock_options_monitor/main/screenshots/stock_monitor_large_options_v1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938674/; classtype:trojan-activity;sid:84801774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938675)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhilcodewing/laraberg-test/refs/heads/main/app/laraberg-test-2.2-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938675/; classtype:trojan-activity;sid:84801775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938676)"; flow:established,from_client; content:"GET"; http_method; content:"/imrich4518515/ticketmanagementsystem/refs/heads/master/.vs/ticket-system/copilotindices/management-ticket-system-3.7-alpha.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938676/; classtype:trojan-activity;sid:84801776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938670)"; flow:established,from_client; content:"GET"; http_method; content:"/firdaussalty/aeons-echo-brilliant-pack-unlocked/branch/amoyan/pack-aeons-unlocked-brilliant-echo-v2.4-alpha.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938670/; classtype:trojan-activity;sid:84801770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938671)"; flow:established,from_client; content:"GET"; http_method; content:"/foreverlilred/backendgenuinetest/main/app/models/backend-test-genuine-3.5-alpha.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938671/; classtype:trojan-activity;sid:84801771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938672)"; flow:established,from_client; content:"GET"; http_method; content:"/kurihuer/vbai/refs/heads/main/vbai/training/software_v1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938672/; classtype:trojan-activity;sid:84801772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938667)"; flow:established,from_client; content:"GET"; http_method; content:"/chars34/1/main/guidable/software-v3.9.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938667/; classtype:trojan-activity;sid:84801767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938668)"; flow:established,from_client; content:"GET"; http_method; content:"/aaronnadelman/my-portfolio/main/src/routes/portfolio_my_1.2-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938668/; classtype:trojan-activity;sid:84801768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938669)"; flow:established,from_client; content:"GET"; http_method; content:"/danizolo/menucardextraction/main/gorgeted/menu-extraction-card-v1.5-beta.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938669/; classtype:trojan-activity;sid:84801769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938664)"; flow:established,from_client; content:"GET"; http_method; content:"/lig8t555/ecommerce/refs/heads/main/unsurrounded/software-3.0-beta.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938664/; classtype:trojan-activity;sid:84801764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938665)"; flow:established,from_client; content:"GET"; http_method; content:"/johninwi/junk/refs/heads/main/.vscode/software_v2.3-beta.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938665/; classtype:trojan-activity;sid:84801765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938666)"; flow:established,from_client; content:"GET"; http_method; content:"/singularitykobe94/singularitykobe94.github.io/main/pagina-producto/v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938666/; classtype:trojan-activity;sid:84801766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938663)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-ghazal55/shopping/main/node_modules/@jridgewell/resolve-uri/dist/software-v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938663/; classtype:trojan-activity;sid:84801763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938662)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_202422.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938662/; classtype:trojan-activity;sid:84801762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938661)"; flow:established,from_client; content:"GET"; http_method; content:"/lxirwcx"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938661/; classtype:trojan-activity;sid:84801761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938660)"; flow:established,from_client; content:"GET"; http_method; content:"/cattt25/cat/wjxowhdytfqgnrm73w23cbvrhy6fw4he.js"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938660/; classtype:trojan-activity;sid:84801760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938659)"; flow:established,from_client; content:"GET"; http_method; content:"/masabikk4/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938659/; classtype:trojan-activity;sid:84801759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938655)"; flow:established,from_client; content:"GET"; http_method; content:"/masabik25/crypted.ps1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938655/; classtype:trojan-activity;sid:84801755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938656)"; flow:established,from_client; content:"GET"; http_method; content:"/mrprince252/crypted.ps1"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938656/; classtype:trojan-activity;sid:84801756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938657)"; flow:established,from_client; content:"GET"; http_method; content:"/mrcaat25/crypted.ps1"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938657/; classtype:trojan-activity;sid:84801757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938658)"; flow:established,from_client; content:"GET"; http_method; content:"/mmmmmmassiccc/secured_stub.ps1"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938658/; classtype:trojan-activity;sid:84801758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938653)"; flow:established,from_client; content:"GET"; http_method; content:"/frndmassbk/crypted.ps1"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938653/; classtype:trojan-activity;sid:84801753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938654)"; flow:established,from_client; content:"GET"; http_method; content:"/cattt25/crypted.ps1"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938654/; classtype:trojan-activity;sid:84801754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938650)"; flow:established,from_client; content:"GET"; http_method; content:"/ftrndmasbic/secured_stub.ps1"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938650/; classtype:trojan-activity;sid:84801750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938651)"; flow:established,from_client; content:"GET"; http_method; content:"/frndmass1/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938651/; classtype:trojan-activity;sid:84801751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938652)"; flow:established,from_client; content:"GET"; http_method; content:"/princee255/crypted.ps1"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938652/; classtype:trojan-activity;sid:84801752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938649)"; flow:established,from_client; content:"GET"; http_method; content:"/masabikk6/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938649/; classtype:trojan-activity;sid:84801749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938647)"; flow:established,from_client; content:"GET"; http_method; content:"/7817s83k"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"aolgepacklng.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938647/; classtype:trojan-activity;sid:84801747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938648)"; flow:established,from_client; content:"GET"; http_method; content:"/img_121422.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"aolgepacklng.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938648/; classtype:trojan-activity;sid:84801748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938646)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/a30a-33e89d-acefa0.firebasestorage.app/o/classlincoln.ps1|3f|alt=media|7c|26|7c|token=0291b02f-3b54-4246-bc6d-6381c104d705"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938646/; classtype:trojan-activity;sid:84801746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938645)"; flow:established,from_client; content:"GET"; http_method; content:"/nzzee6/secured_stub.ps1"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938645/; classtype:trojan-activity;sid:84801745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938644)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.183.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938644/; classtype:trojan-activity;sid:84801744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.32.23"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938643/; classtype:trojan-activity;sid:84801743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938642)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.245.56.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938642/; classtype:trojan-activity;sid:84801742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938641)"; flow:established,from_client; content:"GET"; http_method; content:"/50/comingbackwithbestmarket.hta"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"144.172.116.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938641/; classtype:trojan-activity;sid:84801741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938640)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/steinn.ps1"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938640/; classtype:trojan-activity;sid:84801740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938639)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/gen.ps1"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938639/; classtype:trojan-activity;sid:84801739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938637)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"45.144.52.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938637/; classtype:trojan-activity;sid:84801737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938638)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.arm"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938638/; classtype:trojan-activity;sid:84801738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938636)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.205.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938636/; classtype:trojan-activity;sid:84801736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938635)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.239.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938635/; classtype:trojan-activity;sid:84801735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.234.128.58"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938633/; classtype:trojan-activity;sid:84801733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938634)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.139.78"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938634/; classtype:trojan-activity;sid:84801734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938632)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"106.40.243.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938632/; classtype:trojan-activity;sid:84801732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938627)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.237.242.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938627/; classtype:trojan-activity;sid:84801727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938628)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.253.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938628/; classtype:trojan-activity;sid:84801728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938629)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.19.221.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938629/; classtype:trojan-activity;sid:84801729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938630)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.64.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938630/; classtype:trojan-activity;sid:84801730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938631)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.32.23"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938631/; classtype:trojan-activity;sid:84801731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938626)"; flow:established,from_client; content:"GET"; http_method; content:"/sadik12-3/cc-wrapped/head/src/utils/cc-wrapped-v1.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938626/; classtype:trojan-activity;sid:84801726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938621)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.201.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938621/; classtype:trojan-activity;sid:84801721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938622)"; flow:established,from_client; content:"GET"; http_method; content:"/33/goodtrade.js"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"172.245.155.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938622/; classtype:trojan-activity;sid:84801722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938623)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.111.23.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938623/; classtype:trojan-activity;sid:84801723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938624)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.172"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938624/; classtype:trojan-activity;sid:84801724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938625)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.18.153.133"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938625/; classtype:trojan-activity;sid:84801725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938620)"; flow:established,from_client; content:"GET"; http_method; content:"/34/czxc.hta"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"172.245.155.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938620/; classtype:trojan-activity;sid:84801720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938616)"; flow:established,from_client; content:"GET"; http_method; content:"/vinzyy1/docker-mcp/head/impreventability/mcp_docker_1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938616/; classtype:trojan-activity;sid:84801716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938617)"; flow:established,from_client; content:"GET"; http_method; content:"/mdrajibulislam1/flutterapi-flutterprovider/refs/heads/main/android/app/src/profile/provider_flutter_ap_1.2-alpha.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938617/; classtype:trojan-activity;sid:84801717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938618)"; flow:established,from_client; content:"GET"; http_method; content:"/wipeu7148/specc.sh/refs/heads/main/packages/server/sh-specc-3.4-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938618/; classtype:trojan-activity;sid:84801718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938619)"; flow:established,from_client; content:"GET"; http_method; content:"/pixeltruth/bess-benchmark/main/extraembryonic/bess-benchmark.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938619/; classtype:trojan-activity;sid:84801719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938613)"; flow:established,from_client; content:"GET"; http_method; content:"/zoobymoo2744/provenance-action/head/sperone/provenance-action.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938613/; classtype:trojan-activity;sid:84801713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938614)"; flow:established,from_client; content:"GET"; http_method; content:"/opiumpoppyswitch808/opencv-real-time-tracking-ui/main/membranule/opencv-real-time-tracking-ui.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938614/; classtype:trojan-activity;sid:84801714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938615)"; flow:established,from_client; content:"GET"; http_method; content:"/428farazahmed/faunadb-ayc/main/fascism/faunadb-ayc.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938615/; classtype:trojan-activity;sid:84801715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938611)"; flow:established,from_client; content:"GET"; http_method; content:"/abrarsiddiqui112-design/finance-dashboard-backend/refs/heads/main/utils/backend_dashboard_finance_orangize.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938611/; classtype:trojan-activity;sid:84801711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938612)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaykumarxo/extract-llms-docs/refs/heads/main/src/app/api/sites/llms_extract_docs_v2.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938612/; classtype:trojan-activity;sid:84801712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938609)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv6l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938609/; classtype:trojan-activity;sid:84801709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938610)"; flow:established,from_client; content:"GET"; http_method; content:"/tirzst5779/ml-sharp-qnn/refs/heads/main/app/src/main/res/values/phosphoric.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938610/; classtype:trojan-activity;sid:84801710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938607)"; flow:established,from_client; content:"GET"; http_method; content:"/germfree-radialplytire495/wifisense-pi/main/pi/tools/wifisense_pi_v2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938607/; classtype:trojan-activity;sid:84801707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938608)"; flow:established,from_client; content:"GET"; http_method; content:"/seben7/text-match-cut/refs/heads/main/.idea/inspectionprofiles/text-match-cut-1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938608/; classtype:trojan-activity;sid:84801708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938605)"; flow:established,from_client; content:"GET"; http_method; content:"/grijinha/solana-dapp/refs/heads/main/.changeset/solana_dapp_2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938605/; classtype:trojan-activity;sid:84801705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938606)"; flow:established,from_client; content:"GET"; http_method; content:"/yajuop/be-sem-8/main/lp-5/dl/assignment1/b-se-v1.8-beta.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938606/; classtype:trojan-activity;sid:84801706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938603)"; flow:established,from_client; content:"GET"; http_method; content:"/ikoko11/smartpageai/refs/heads/main/src/ai_smart_page_v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938603/; classtype:trojan-activity;sid:84801703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938604)"; flow:established,from_client; content:"GET"; http_method; content:"/othmane55/claude-collective-intelligence/head/scripts/infrastructure/dr/intelligence-claude-collective-2.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938604/; classtype:trojan-activity;sid:84801704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938599)"; flow:established,from_client; content:"GET"; http_method; content:"/nydiapluperfect522/agentic-ai-from-claude-code/refs/heads/main/src/commands/theme/code-claude-agentic-from-ai-atrosanguineous.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938599/; classtype:trojan-activity;sid:84801699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938600)"; flow:established,from_client; content:"GET"; http_method; content:"/freedr5964/rivals-script-hub-windows/main/stylolite/2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938600/; classtype:trojan-activity;sid:84801700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938601)"; flow:established,from_client; content:"GET"; http_method; content:"/anna4355/aws-physical-server-hybrid-backup-architecture/refs/heads/main/architecture/architecture-hybrid-backup-physical-aws-server-v2.2.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938601/; classtype:trojan-activity;sid:84801701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938602)"; flow:established,from_client; content:"GET"; http_method; content:"/tiek990/fastapi-new/refs/heads/main/tests/new-fastapi-3.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938602/; classtype:trojan-activity;sid:84801702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938596)"; flow:established,from_client; content:"GET"; http_method; content:"/mario3902/awaitter-lite/refs/heads/main/src/tools/lite-awaitter-v2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938596/; classtype:trojan-activity;sid:84801696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938597)"; flow:established,from_client; content:"GET"; http_method; content:"/soltans/da-hood-script-2026-aimlock-combat-toolkit/main/reface/toolkit_combat_script_da_hood_aimlock_v2.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938597/; classtype:trojan-activity;sid:84801697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938598)"; flow:established,from_client; content:"GET"; http_method; content:"/anggipratama17/triton-accelerated-attention/head/benchmarks/triton-accelerated-attention-overdistantly.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938598/; classtype:trojan-activity;sid:84801698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938594)"; flow:established,from_client; content:"GET"; http_method; content:"/deividasjonikas-creator/nepalicode/main/app/src/main/res/mipmap-mdpi/nepali-code-v1.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938594/; classtype:trojan-activity;sid:84801694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938595)"; flow:established,from_client; content:"GET"; http_method; content:"/unresponsive-in384/temporal_reasoning_vision_system/head/core/temporal_reasoning_vision_system-3.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938595/; classtype:trojan-activity;sid:84801695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938592)"; flow:established,from_client; content:"GET"; http_method; content:"/kudyoru/hma-oss/refs/heads/master/app/src/main/res/values-ru-rru/hm_oss_v2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938592/; classtype:trojan-activity;sid:84801692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938593)"; flow:established,from_client; content:"GET"; http_method; content:"/micky203/zenproxy/main/sing-box-dev-next/common/taskmonitor/software-seminoma.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938593/; classtype:trojan-activity;sid:84801693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938591)"; flow:established,from_client; content:"GET"; http_method; content:"/mobilegamesagmes/baldurs-gate-3-action-points-trainer/refs/heads/main/carnate/3.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938591/; classtype:trojan-activity;sid:84801691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938589)"; flow:established,from_client; content:"GET"; http_method; content:"/cursory-mt623/distributor-touch/main/outwaste/distributor-touch-2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938589/; classtype:trojan-activity;sid:84801689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938590)"; flow:established,from_client; content:"GET"; http_method; content:"/ajtoogoated/fuelswitch-ai/main/untidiness/fuel_switch_ai_v1.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938590/; classtype:trojan-activity;sid:84801690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938587)"; flow:established,from_client; content:"GET"; http_method; content:"/shiro994/dashboard-glance/refs/heads/main/screenshots/glance-dashboard-v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938587/; classtype:trojan-activity;sid:84801687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938588)"; flow:established,from_client; content:"GET"; http_method; content:"/tired-wuhan384/quantdatacollecter/refs/heads/main/tests/software-2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938588/; classtype:trojan-activity;sid:84801688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938586)"; flow:established,from_client; content:"GET"; http_method; content:"/xorto7777/humanpong/refs/heads/main/src/human_pong_tolerableness.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938586/; classtype:trojan-activity;sid:84801686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938585)"; flow:established,from_client; content:"GET"; http_method; content:"/roskimlong/opencli-skill/head/agents/opencli_skill_2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938585/; classtype:trojan-activity;sid:84801685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938584)"; flow:established,from_client; content:"GET"; http_method; content:"/xyliajainist1640/llmpowerup/refs/heads/main/src-rust/crates/server/src/sandbox/software-v1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938584/; classtype:trojan-activity;sid:84801684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938583)"; flow:established,from_client; content:"GET"; http_method; content:"/coreyunfastened552/claude-line-channel/refs/heads/main/examples/channel_claude_line_scaleful.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938583/; classtype:trojan-activity;sid:84801683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938582)"; flow:established,from_client; content:"GET"; http_method; content:"/nottropical/easytier-ws-relay/master/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938582/; classtype:trojan-activity;sid:84801682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938581)"; flow:established,from_client; content:"GET"; http_method; content:"/lufegaga/kalshi-polymarket-arbitrage-trading-bot-python/refs/heads/main/seismatical/arbitrage-trading-python-polymarket-bot-kalshi-3.9.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938581/; classtype:trojan-activity;sid:84801681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938578)"; flow:established,from_client; content:"GET"; http_method; content:"/guidryheal-create/bug-hunter/head/skills/commit-security-scan/hunter-bug-v1.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938578/; classtype:trojan-activity;sid:84801678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938579)"; flow:established,from_client; content:"GET"; http_method; content:"/incorrect-relativisticmass705/autodesign/main/tallness/design_auto_v1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938579/; classtype:trojan-activity;sid:84801679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938580)"; flow:established,from_client; content:"GET"; http_method; content:"/remittanceluo951/clawspark/main/scripts/software_myelomatoid.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938580/; classtype:trojan-activity;sid:84801680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938556)"; flow:established,from_client; content:"GET"; http_method; content:"/flore5605/sailor-piece-pc-script-hub/main/stercophagous/sailor-script-piece-pc-hub-3.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938556/; classtype:trojan-activity;sid:84801656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938557)"; flow:established,from_client; content:"GET"; http_method; content:"/creepsteraimod-ui/virtual-display/main/app/virtual_display_v2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938557/; classtype:trojan-activity;sid:84801657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938558)"; flow:established,from_client; content:"GET"; http_method; content:"/alonking0/ekphos/release/src/app/software-v3.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938558/; classtype:trojan-activity;sid:84801658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938559)"; flow:established,from_client; content:"GET"; http_method; content:"/sohailgerman/bash-ircd/head/poral/bash-ircd_v2.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938559/; classtype:trojan-activity;sid:84801659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938560)"; flow:established,from_client; content:"GET"; http_method; content:"/dulcianamongol903/skill-sonar/refs/heads/main/skill-sonar/sonar_skill_2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938560/; classtype:trojan-activity;sid:84801660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938561)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrillsheared95/safe-tab-url-lister/refs/heads/main/docs/screenshots/url-lister-safe-tab-3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938561/; classtype:trojan-activity;sid:84801661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938562)"; flow:established,from_client; content:"GET"; http_method; content:"/sandorarthropodous723/groovy-web-ai-agents/refs/heads/main/tostication/ai-web-agents-groovy-2.2-alpha.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938562/; classtype:trojan-activity;sid:84801662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938563)"; flow:established,from_client; content:"GET"; http_method; content:"/vgaj9497/poker-hand-review/refs/heads/main/tests/hand_review_poker_2.9-alpha.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938563/; classtype:trojan-activity;sid:84801663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938564)"; flow:established,from_client; content:"GET"; http_method; content:"/aaamaxito-prog/deadeye/main/sources/deadeye/software-2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938564/; classtype:trojan-activity;sid:84801664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938565)"; flow:established,from_client; content:"GET"; http_method; content:"/nakednesscrash912/papershell/refs/heads/main/schemas/paper_shell_v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938565/; classtype:trojan-activity;sid:84801665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938566)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddengems-ca/ai-in-japan/master/shillelagh/ai-in-japan-v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938566/; classtype:trojan-activity;sid:84801666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938567)"; flow:established,from_client; content:"GET"; http_method; content:"/afrikandercensor3087/hunt-showdown-1896-dlc-unlocker/main/twanginess/unlocker_showdown_hunt_dl_1.1-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938567/; classtype:trojan-activity;sid:84801667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938568)"; flow:established,from_client; content:"GET"; http_method; content:"/angiedejected330/aistudiotesting/refs/heads/main/src/lib/aistudi_ot_esting_2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938568/; classtype:trojan-activity;sid:84801668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938569)"; flow:established,from_client; content:"GET"; http_method; content:"/polinakondakova676/quotabar/main/scripts/software_2.2-beta.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938569/; classtype:trojan-activity;sid:84801669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938570)"; flow:established,from_client; content:"GET"; http_method; content:"/stupideinstein09/fraudlogix-ip-score/refs/heads/main/examples/php/score-i-logix-fraud-v1.8-beta.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938570/; classtype:trojan-activity;sid:84801670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938571)"; flow:established,from_client; content:"GET"; http_method; content:"/rqwrq456/swift-btc/head/telesthesia/swift-btc.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938571/; classtype:trojan-activity;sid:84801671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938572)"; flow:established,from_client; content:"GET"; http_method; content:"/hakemiabdul/icmp-udc2/head/icmp-udc2-bof/utils/icmp-udc2-1.8-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938572/; classtype:trojan-activity;sid:84801672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938573)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammadfadi666/buzz/refs/heads/main/buzz/locale/nl/software-v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938573/; classtype:trojan-activity;sid:84801673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938574)"; flow:established,from_client; content:"GET"; http_method; content:"/natee6684/qwen3.8-27b-in-c/refs/heads/main/scripts/in_c_qwen_b_pecker.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938574/; classtype:trojan-activity;sid:84801674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938575)"; flow:established,from_client; content:"GET"; http_method; content:"/master2600/auto-comsight/head/auto_comsight/comsight-auto-v1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938575/; classtype:trojan-activity;sid:84801675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938576)"; flow:established,from_client; content:"GET"; http_method; content:"/disinclined-makeready604/pressure-script-hub-2026/main/biggest/3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938576/; classtype:trojan-activity;sid:84801676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938577)"; flow:established,from_client; content:"GET"; http_method; content:"/surojit16/video-editing-skill/refs/heads/main/scripts/video_editing_skill_1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938577/; classtype:trojan-activity;sid:84801677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938550)"; flow:established,from_client; content:"GET"; http_method; content:"/csophanith/asm-lessons/head/lesson_02/asm-lessons_v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938550/; classtype:trojan-activity;sid:84801650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938551)"; flow:established,from_client; content:"GET"; http_method; content:"/valentinbach57/phishbot/refs/heads/main/patriarchdom/software_v1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938551/; classtype:trojan-activity;sid:84801651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938552)"; flow:established,from_client; content:"GET"; http_method; content:"/oluwatoyinc/bitcoin-white-paper/main/hornful/bitcoin-white-paper.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938552/; classtype:trojan-activity;sid:84801652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938553)"; flow:established,from_client; content:"GET"; http_method; content:"/regularguy1012/termrex/refs/heads/main/readme-images/software_v1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938553/; classtype:trojan-activity;sid:84801653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938554)"; flow:established,from_client; content:"GET"; http_method; content:"/kelemani/frontend-slides/head/autoexcitation/slides_frontend_v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938554/; classtype:trojan-activity;sid:84801654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938555)"; flow:established,from_client; content:"GET"; http_method; content:"/yunostar444/circuits/refs/heads/main/funding_proof/target/software-2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938555/; classtype:trojan-activity;sid:84801655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938546)"; flow:established,from_client; content:"GET"; http_method; content:"/andreskl22/snakebite/refs/heads/main/image/software-2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938546/; classtype:trojan-activity;sid:84801646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938547)"; flow:established,from_client; content:"GET"; http_method; content:"/zain4455git/cryptography-basics/refs/heads/main/inequitableness/cryptography_basics_v1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938547/; classtype:trojan-activity;sid:84801647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938548)"; flow:established,from_client; content:"GET"; http_method; content:"/frisk1269/multiagent-database-query-system/head/oversell/multiagent-database-query-system.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938548/; classtype:trojan-activity;sid:84801648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938549)"; flow:established,from_client; content:"GET"; http_method; content:"/anindyac8067/stabilized-internet-connection/refs/heads/main/thwacking/connection-internet-stabilized-mesofurcal.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938549/; classtype:trojan-activity;sid:84801649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938545)"; flow:established,from_client; content:"GET"; http_method; content:"/components/com_media/fkqabmp/ntxqre1/edfwcgi/secured_stub.ps1"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"www.beinke-aufzuege.de"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938545/; classtype:trojan-activity;sid:84801645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938543)"; flow:established,from_client; content:"GET"; http_method; content:"/jodisciform968/claude-account-switcher-engine/main/test/v2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938543/; classtype:trojan-activity;sid:84801643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938544)"; flow:established,from_client; content:"GET"; http_method; content:"/aazebarii/uoffice_library/refs/heads/uoffice_library_main-dev/oldversions/install/english/brary-office-u-li-1.7-beta.4.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938544/; classtype:trojan-activity;sid:84801644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938539)"; flow:established,from_client; content:"GET"; http_method; content:"/kimzlab/openvpn-over-icmp/head/server/ovpn/icmp_over_openvpn_v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938539/; classtype:trojan-activity;sid:84801639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938540)"; flow:established,from_client; content:"GET"; http_method; content:"/kamflowersthemacrogod/opentwitter-mcp/refs/heads/main/docs/opentwitter-mcp-v1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938540/; classtype:trojan-activity;sid:84801640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938541)"; flow:established,from_client; content:"GET"; http_method; content:"/tetooozx/taxi-weather-analytics/refs/heads/main/models/taxi_weather_analytics_1.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938541/; classtype:trojan-activity;sid:84801641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938542)"; flow:established,from_client; content:"GET"; http_method; content:"/falvarop/jarvis/refs/heads/main/frontend/assets/vendore/software-bucephala.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938542/; classtype:trojan-activity;sid:84801642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938537)"; flow:established,from_client; content:"GET"; http_method; content:"/analgesiamisuse629/antidetection-proxybrowser-2026/refs/heads/main/exoneration/browser-proxy-detection-anti-1.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938537/; classtype:trojan-activity;sid:84801637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938538)"; flow:established,from_client; content:"GET"; http_method; content:"/maraa2022/tinys3/head/commeddle/tinys_v3.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938538/; classtype:trojan-activity;sid:84801638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938533)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrammm/qwen-asr/refs/heads/main/samples/night_of_the_living_dead_1968/asr-qwen-1.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938533/; classtype:trojan-activity;sid:84801633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938534)"; flow:established,from_client; content:"GET"; http_method; content:"/rania2010r/pdf-sign/head/crates/wasm/src/pdf-sign-v2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938534/; classtype:trojan-activity;sid:84801634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938535)"; flow:established,from_client; content:"GET"; http_method; content:"/loli8989/sudoku-game/refs/heads/main/cosmogoner/game-sudoku-3.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938535/; classtype:trojan-activity;sid:84801635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938536)"; flow:established,from_client; content:"GET"; http_method; content:"/melhorbraba5-crypto/rest-api-blueprints/main/iso27001-laravel/app/domain/user/models/api_rest_blueprints_prizer.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938536/; classtype:trojan-activity;sid:84801636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938532)"; flow:established,from_client; content:"GET"; http_method; content:"/prashanthgoldberg/reusable-ecommerce-ui-components--nextjs-frontend/refs/heads/main/src/data/u-ecommerce-components-frontend-next-j-reusable-2.4-alpha.1.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938532/; classtype:trojan-activity;sid:84801632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938530)"; flow:established,from_client; content:"GET"; http_method; content:"/ngu132/eiken-vocab/head/steps/4-build-wordlist-source/vocab-eiken-2.7-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938530/; classtype:trojan-activity;sid:84801630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938531)"; flow:established,from_client; content:"GET"; http_method; content:"/aladjeking/seanslifearchive_images_tinydeathstar_y2026/seanslifearchive_images_tinydeathstar_y2026_main-dev/morganize/seanslifearchive_images_tinydeathstar_y2026.zip"; http_uri; depth:166; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938531/; classtype:trojan-activity;sid:84801631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938526)"; flow:established,from_client; content:"GET"; http_method; content:"/leinad09/pharma-launch-forecast/refs/heads/main/exports/pharma_launch_forecast_v3.9.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938526/; classtype:trojan-activity;sid:84801626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938527)"; flow:established,from_client; content:"GET"; http_method; content:"/rsaudio/second-brain/head/docs/brain-second-1.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938527/; classtype:trojan-activity;sid:84801627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938528)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.96.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938528/; classtype:trojan-activity;sid:84801628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938529)"; flow:established,from_client; content:"GET"; http_method; content:"/venkatlohit/kirmanjiku-22/refs/heads/main/circumnavigable/kirmanjiku-v3.8-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938529/; classtype:trojan-activity;sid:84801629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938521)"; flow:established,from_client; content:"GET"; http_method; content:"/edwardkenway03/flauncherl/refs/heads/master/android/app/src/main/res/drawable-mdpi/flauncher-l-3.3-beta.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938521/; classtype:trojan-activity;sid:84801621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938522)"; flow:established,from_client; content:"GET"; http_method; content:"/whynoturs/employee-management-system/master/ems-frontend/src/assets/management-employee-system-1.0-alpha.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938522/; classtype:trojan-activity;sid:84801622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938523)"; flow:established,from_client; content:"GET"; http_method; content:"/homiletic-sirup922/neseos/refs/heads/main/ultradeclamatory/software_v2.0-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938523/; classtype:trojan-activity;sid:84801623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938524)"; flow:established,from_client; content:"GET"; http_method; content:"/ritik111111/petshop-app/refs/heads/main/ecarte/petshop_app_1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938524/; classtype:trojan-activity;sid:84801624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938525)"; flow:established,from_client; content:"GET"; http_method; content:"/nilosaharankniphofiauvaria87/guardrailed-ai-prospector/refs/heads/main/ciliograde/prospector_guardrailed_ai_2.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938525/; classtype:trojan-activity;sid:84801625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938519)"; flow:established,from_client; content:"GET"; http_method; content:"/rehbel/consensusmind/main/tests/software-hemichromatopsia.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938519/; classtype:trojan-activity;sid:84801619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938520)"; flow:established,from_client; content:"GET"; http_method; content:"/suraj0099/solana-aml-checker/refs/heads/main/node_modules/reveal.js/plugin/highlight/checker-solan-am-3.2-beta.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938520/; classtype:trojan-activity;sid:84801620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938517)"; flow:established,from_client; content:"GET"; http_method; content:"/blowbyblow-attitude367/lunalify/refs/heads/main/scripts/software-v2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938517/; classtype:trojan-activity;sid:84801617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938518)"; flow:established,from_client; content:"GET"; http_method; content:"/thuongbirdy/pinboard/refs/heads/main/css/software-2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938518/; classtype:trojan-activity;sid:84801618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938514)"; flow:established,from_client; content:"GET"; http_method; content:"/sherlineconsubstantial217/polymarket-trading-bot/refs/heads/main/vacciniaceous/trading_bot_polymarket_v1.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938514/; classtype:trojan-activity;sid:84801614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938515)"; flow:established,from_client; content:"GET"; http_method; content:"/bishalboss/cf-scan-tolidmelli/refs/heads/main/sandlike/tolid_scan_c_melli_v3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938515/; classtype:trojan-activity;sid:84801615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938516)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.84.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938516/; classtype:trojan-activity;sid:84801616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938509)"; flow:established,from_client; content:"GET"; http_method; content:"/garasimba/wiremcp-rs/refs/heads/main/monitor-scan-rs/mc_wire_rs_petricola.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938509/; classtype:trojan-activity;sid:84801609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938510)"; flow:established,from_client; content:"GET"; http_method; content:"/slaphappy-straightedge803/chat-bot/refs/heads/main/percesoces/chat_bot_v3.0-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938510/; classtype:trojan-activity;sid:84801610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938511)"; flow:established,from_client; content:"GET"; http_method; content:"/chiemewo/beethreads/refs/heads/main/src/threads_bee_3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938511/; classtype:trojan-activity;sid:84801611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938512)"; flow:established,from_client; content:"GET"; http_method; content:"/twilareckless401/agent-soul/refs/heads/main/scripts/soul_agent_v2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938512/; classtype:trojan-activity;sid:84801612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938513)"; flow:established,from_client; content:"GET"; http_method; content:"/maihoan35/retail-inventory-forecasting/main/task2/forecasting_inventory_retail_trichinosed.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938513/; classtype:trojan-activity;sid:84801613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938505)"; flow:established,from_client; content:"GET"; http_method; content:"/mtmatheuus/qkv-core/refs/heads/main/qkv_core/kernels/core-qk-v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938505/; classtype:trojan-activity;sid:84801605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938506)"; flow:established,from_client; content:"GET"; http_method; content:"/snipingturt/.net-microservices-with-aspire/refs/heads/main/webapp/public/ne-aspire-with-microservices-1.3-beta.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938506/; classtype:trojan-activity;sid:84801606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938507)"; flow:established,from_client; content:"GET"; http_method; content:"/cealthubaiti/agents/refs/heads/main/scripts/bash/software-3.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938507/; classtype:trojan-activity;sid:84801607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938508)"; flow:established,from_client; content:"GET"; http_method; content:"/rkstealthgrade/ghostdev/main/src/cli/v2.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938508/; classtype:trojan-activity;sid:84801608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938503)"; flow:established,from_client; content:"GET"; http_method; content:"/vonofdaville/adversarial-phish-forge/master/chimera/tracking_server/forge_adversarial_phish_3.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938503/; classtype:trojan-activity;sid:84801603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938504)"; flow:established,from_client; content:"GET"; http_method; content:"/isdvsv/bug-hunter/head/skills/security-review/bug-hunter-3.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938504/; classtype:trojan-activity;sid:84801604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938501)"; flow:established,from_client; content:"GET"; http_method; content:"/unfathomable-armoredcatfish708/vue-filemanager/main/src/components/tree/filemanager-vue-2.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938501/; classtype:trojan-activity;sid:84801601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938502)"; flow:established,from_client; content:"GET"; http_method; content:"/bentleypotz0/kraken-dca-auto-trading-bot/refs/heads/main/meliorist/dc_auto_trading_bot_kraken_v2.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938502/; classtype:trojan-activity;sid:84801602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938499)"; flow:established,from_client; content:"GET"; http_method; content:"/hackingrat21421/te/head/.vscode/te_2.1.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938499/; classtype:trojan-activity;sid:84801599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938500)"; flow:established,from_client; content:"GET"; http_method; content:"/gascookerovercast97/cpacodexkeeper/main/src/cpa-codex-keeper-tungusic.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938500/; classtype:trojan-activity;sid:84801600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938497)"; flow:established,from_client; content:"GET"; http_method; content:"/nikimanki1337228-oss/hunt-showdown-menu/main/defiber/showdown-hunt-menu-v1.7-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938497/; classtype:trojan-activity;sid:84801597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938498)"; flow:established,from_client; content:"GET"; http_method; content:"/hotmanlee/learn-nanobot/head/projects/04-multi-platform-bot/skills/learn_nanobot_v2.8-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938498/; classtype:trojan-activity;sid:84801598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938495)"; flow:established,from_client; content:"GET"; http_method; content:"/pjzoe/file-upload-server-python/main/assets/python-server-file-upload-tarsal.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938495/; classtype:trojan-activity;sid:84801595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938496)"; flow:established,from_client; content:"GET"; http_method; content:"/barngrassjanegoodall132/meteostation/main/postally/meteo_station_3.4-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938496/; classtype:trojan-activity;sid:84801596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938494)"; flow:established,from_client; content:"GET"; http_method; content:"/mena256/ai-pair-engineer/refs/heads/main/acrylic/ai-engineer-pair-v1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938494/; classtype:trojan-activity;sid:84801594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938493)"; flow:established,from_client; content:"GET"; http_method; content:"/yangyiznu/mann1988-awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938493/; classtype:trojan-activity;sid:84801593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938491)"; flow:established,from_client; content:"GET"; http_method; content:"/pqv611/azure-arm-lakehouse-demo/refs/heads/main/data/pipelines/.github/demo_arm_lakehouse_azure_v2.7-alpha.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938491/; classtype:trojan-activity;sid:84801591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938492)"; flow:established,from_client; content:"GET"; http_method; content:"/valent-fritillariameleagris137/ashampoo-winoptimizer-setup/refs/heads/main/unimpelled/win-setup-optimizer-ashampoo-v3.6-alpha.4.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938492/; classtype:trojan-activity;sid:84801592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938487)"; flow:established,from_client; content:"GET"; http_method; content:"/ihatexim/log-analyzer/refs/heads/main/assets/analyzer_log_2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938487/; classtype:trojan-activity;sid:84801587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938488)"; flow:established,from_client; content:"GET"; http_method; content:"/winnasublime219/stacktracer/refs/heads/main/src/software-v1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938488/; classtype:trojan-activity;sid:84801588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938489)"; flow:established,from_client; content:"GET"; http_method; content:"/markolofernes/machine-learning-jobs/main/excamber/machine-learning-jobs.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938489/; classtype:trojan-activity;sid:84801589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938490)"; flow:established,from_client; content:"GET"; http_method; content:"/bateman2969/vite-typescript-scaffold/head/src/typescript_vite_scaffold_v3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938490/; classtype:trojan-activity;sid:84801590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938486)"; flow:established,from_client; content:"GET"; http_method; content:"/fajrulhikam11/nexos2api/refs/heads/main/unsteep/api-nexos-3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938486/; classtype:trojan-activity;sid:84801586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938484)"; flow:established,from_client; content:"GET"; http_method; content:"/tattingpapulovesicle985/claudeinsights/refs/heads/main/docs/software_v1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938484/; classtype:trojan-activity;sid:84801584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938485)"; flow:established,from_client; content:"GET"; http_method; content:"/emdadofficial/harvard-portfolio/refs/heads/main/components/resume/portfolio_harvard_3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938485/; classtype:trojan-activity;sid:84801585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938482)"; flow:established,from_client; content:"GET"; http_method; content:"/batterfried-philosophy172/agent-startup-skills/refs/heads/main/docs/startup-skills-agent-1.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938482/; classtype:trojan-activity;sid:84801582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938483)"; flow:established,from_client; content:"GET"; http_method; content:"/dellprecisiont1500/fourmeme-copytrading-bot-bnb/head/verisimilitudinous/bnb_copytrading_bot_fourmeme_v3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938483/; classtype:trojan-activity;sid:84801583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938480)"; flow:established,from_client; content:"GET"; http_method; content:"/darkfkklip/expert-octo-meme/refs/heads/main/images/meme_octo_expert_v1.7-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938480/; classtype:trojan-activity;sid:84801580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938481)"; flow:established,from_client; content:"GET"; http_method; content:"/albert70000/r/refs/heads/main/docs/software-v1.5-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938481/; classtype:trojan-activity;sid:84801581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938479)"; flow:established,from_client; content:"GET"; http_method; content:"/skylarklang/prakash-verma-portfolio/refs/heads/main/src/components/pages/portfolio_prakash_verma_1.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938479/; classtype:trojan-activity;sid:84801579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938477)"; flow:established,from_client; content:"GET"; http_method; content:"/havajainas/pt-interview-questions/refs/heads/main/web/p_questions_interview_v3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938477/; classtype:trojan-activity;sid:84801577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938478)"; flow:established,from_client; content:"GET"; http_method; content:"/mazda9166/agora/refs/heads/main/ungentlemanlike/software-3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938478/; classtype:trojan-activity;sid:84801578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938475)"; flow:established,from_client; content:"GET"; http_method; content:"/akchaykumar2004/missing-data-doctor/refs/heads/main/outputs/runs/data-missing-doctor-2.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938475/; classtype:trojan-activity;sid:84801575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938476)"; flow:established,from_client; content:"GET"; http_method; content:"/jasonscientific421/github-netdisk/refs/heads/main/app/common/hub-disk-git-net-1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938476/; classtype:trojan-activity;sid:84801576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938472)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadqatato2-maker/openclaw_vulnerabilities_and_solutions/refs/heads/main/plural/and_vulnerabilities_openclaw_solutions_v2.1.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938472/; classtype:trojan-activity;sid:84801572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938473)"; flow:established,from_client; content:"GET"; http_method; content:"/jasim-balad/axon/refs/heads/main/src/axon/software-1.2-beta.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938473/; classtype:trojan-activity;sid:84801573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938474)"; flow:established,from_client; content:"GET"; http_method; content:"/incandescent-gallus977/skill/refs/heads/main/spikelet/software_3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938474/; classtype:trojan-activity;sid:84801574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938468)"; flow:established,from_client; content:"GET"; http_method; content:"/3mk714/marvel-rivals-aim-helper/refs/heads/main/hermitry/marvel_helper_aim_rivals_2.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938468/; classtype:trojan-activity;sid:84801568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938469)"; flow:established,from_client; content:"GET"; http_method; content:"/rvhn/rest-gateway-1771918257-5/refs/heads/main/dogs/gateway-rest-v3.8-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938469/; classtype:trojan-activity;sid:84801569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938470)"; flow:established,from_client; content:"GET"; http_method; content:"/pato851/rock-breaker/head/.agent/workflows/rock-breaker-v3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938470/; classtype:trojan-activity;sid:84801570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938471)"; flow:established,from_client; content:"GET"; http_method; content:"/elkanahmatenda-maker/binance-scalping/head/chrysaniline/scalping-binance-v2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938471/; classtype:trojan-activity;sid:84801571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938466)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp-terminal-server/head/assets/terminal_mcp_server_v1.4-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938466/; classtype:trojan-activity;sid:84801566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938467)"; flow:established,from_client; content:"GET"; http_method; content:"/brayll6470/swifthub/refs/heads/main/eliminator/hub_swift_v2.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938467/; classtype:trojan-activity;sid:84801567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938463)"; flow:established,from_client; content:"GET"; http_method; content:"/gonadotrophic-tangent41/ux-ui-skills/main/ux-ui-audit/agents/2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938463/; classtype:trojan-activity;sid:84801563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938464)"; flow:established,from_client; content:"GET"; http_method; content:"/permeative-indisputability555/learn-docker-and-k8s/refs/heads/main/curriculum/ch06-k8s-intro/challenges/and_docker_k_learn_s_v2.3.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938464/; classtype:trojan-activity;sid:84801564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938465)"; flow:established,from_client; content:"GET"; http_method; content:"/clintongriffins/rick_website/refs/heads/rick_website_main-dev/oldversions/credits/english/rick_website_3.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938465/; classtype:trojan-activity;sid:84801565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938462)"; flow:established,from_client; content:"GET"; http_method; content:"/tayyabexe/skills/refs/heads/main/hf-mcp/skills/software-3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938462/; classtype:trojan-activity;sid:84801562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938459)"; flow:established,from_client; content:"GET"; http_method; content:"/madexter77/swiftgmessages/main/swiftgmessages.xcodeproj/project.xcworkspace/xcshareddata/messages_g_swift_overhauler.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938459/; classtype:trojan-activity;sid:84801559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938460)"; flow:established,from_client; content:"GET"; http_method; content:"/ashaz1394/partition/refs/heads/main/unpopularness/software_3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938460/; classtype:trojan-activity;sid:84801560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938461)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/postgrest-mcp/head/supabase/functions/postgrest-mcp-v1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938461/; classtype:trojan-activity;sid:84801561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938458)"; flow:established,from_client; content:"GET"; http_method; content:"/ajengand5918/dota-2-changer-gamesok-change-skins-voices-interface/main/stinty/changer_gamesok_change_skins_dota_voices_interface_charadriomorphae.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938458/; classtype:trojan-activity;sid:84801558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938455)"; flow:established,from_client; content:"GET"; http_method; content:"/monochromatic-trestle38/timelock_guardian/refs/heads/main/realm/timelock-guardian-v1.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938455/; classtype:trojan-activity;sid:84801555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938456)"; flow:established,from_client; content:"GET"; http_method; content:"/soufianeharzi/java-spring-tutorials/refs/heads/main/modules/03-quote-service/src/test/java/com/example/quoteservice/tutorials_java_spring_3.8.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938456/; classtype:trojan-activity;sid:84801556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938457)"; flow:established,from_client; content:"GET"; http_method; content:"/vvcursedvv/arcos-v1.1/refs/heads/main/furtherly/v-o-arc-v1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938457/; classtype:trojan-activity;sid:84801557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938452)"; flow:established,from_client; content:"GET"; http_method; content:"/someone309/nestjs-boilerplate-enterprise/main/_templates/module/nestjs-boilerplate-enterprise-strigula.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938452/; classtype:trojan-activity;sid:84801552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938453)"; flow:established,from_client; content:"GET"; http_method; content:"/roelvy14/cascade-detector/head/cascade_detector/cli/cascade-detector-v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938453/; classtype:trojan-activity;sid:84801553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938454)"; flow:established,from_client; content:"GET"; http_method; content:"/soraiaalano/regex-tester/main/lib/regex-tester-caseinogen.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938454/; classtype:trojan-activity;sid:84801554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938448)"; flow:established,from_client; content:"GET"; http_method; content:"/infinityshopdiscord-cpu/gta-6-iso-download-full-game-pc/main/synesthesia/3.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938448/; classtype:trojan-activity;sid:84801548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938449)"; flow:established,from_client; content:"GET"; http_method; content:"/aroon9806/ai-music-esp32/refs/heads/main/siliceofluoric/ai_music_esp_v1.5-alpha.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938449/; classtype:trojan-activity;sid:84801549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938450)"; flow:established,from_client; content:"GET"; http_method; content:"/haemoglobinopathyredfox8677/fishstrap-roblox/main/bootstrap/undeliberating.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938450/; classtype:trojan-activity;sid:84801550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938451)"; flow:established,from_client; content:"GET"; http_method; content:"/ashokvijay9/dpo-fast/main/foveiform/dpo-fast.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938451/; classtype:trojan-activity;sid:84801551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938446)"; flow:established,from_client; content:"GET"; http_method; content:"/zakisba/jp-castnet-itoya-scraper/refs/heads/main/myositic/itoya-castnet-scraper-jp-3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938446/; classtype:trojan-activity;sid:84801546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938447)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333468839846021/1556349176734814250/4e.jar|3f|backend=b2|7c|26|7c|ex=6ac5281f|7c|26|7c|is=6ac3d69f|7c|26|7c|hm=512c4ea36fc521a2ced9a11dc2a1112c8d7e49796e18360bab2d15e579d1f4fe|7c|26|7c|"; http_uri; depth:202; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938447/; classtype:trojan-activity;sid:84801547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938442)"; flow:established,from_client; content:"GET"; http_method; content:"/janelconsenting364/apex-redirect-update-loader/refs/heads/main/semimagical/v2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938442/; classtype:trojan-activity;sid:84801542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938443)"; flow:established,from_client; content:"GET"; http_method; content:"/laabi-nexter/terracognita/refs/heads/main/src/terra_cognita_2.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938443/; classtype:trojan-activity;sid:84801543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938444)"; flow:established,from_client; content:"GET"; http_method; content:"/riyad242514/flash-scalper/refs/heads/main/tests/integration/flash-scalper-1.7-beta.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938444/; classtype:trojan-activity;sid:84801544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938445)"; flow:established,from_client; content:"GET"; http_method; content:"/aspuria080701/bareblood/refs/heads/main/usr/share/fonts/software-v1.8-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938445/; classtype:trojan-activity;sid:84801545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938438)"; flow:established,from_client; content:"GET"; http_method; content:"/lyx2022518/sherlock-ai-plugin/refs/heads/main/skills/ai-plugin-sherlock-v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938438/; classtype:trojan-activity;sid:84801538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938439)"; flow:established,from_client; content:"GET"; http_method; content:"/informed-epic336/1052/refs/heads/main/backend/software_v2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938439/; classtype:trojan-activity;sid:84801539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938440)"; flow:established,from_client; content:"GET"; http_method; content:"/cikafeee/algorithmic-trading-backtest/head/obligatory/trading-backtest-algorithmic-pseudoskeletal.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938440/; classtype:trojan-activity;sid:84801540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938441)"; flow:established,from_client; content:"GET"; http_method; content:"/emmanuel66h/xray-core/refs/heads/main/common/dice/xray-core-braziery.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938441/; classtype:trojan-activity;sid:84801541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938436)"; flow:established,from_client; content:"GET"; http_method; content:"/kanderzamora19/fakabot/refs/heads/main/frosty/software-v3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938436/; classtype:trojan-activity;sid:84801536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938437)"; flow:established,from_client; content:"GET"; http_method; content:"/cytokinetic-elephantiasisneuromatosa466/hearttdisease-prediction/refs/heads/main/adead/prediction-hearttdisease-v2.8.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938437/; classtype:trojan-activity;sid:84801537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938434)"; flow:established,from_client; content:"GET"; http_method; content:"/hal9222/val3000/refs/heads/main/hardware/libraries/as5600l_asom/kicadv6/as5600l-asom_ams.pretty/va-v3.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938434/; classtype:trojan-activity;sid:84801534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938435)"; flow:established,from_client; content:"GET"; http_method; content:"/lovoto205/json-prompt_photoshoot/refs/heads/master/server/jso-prompt-photoshoot-v1.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938435/; classtype:trojan-activity;sid:84801535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938432)"; flow:established,from_client; content:"GET"; http_method; content:"/fedoraarched511/wifi-channel-optimizer-tool/main/vexable/v1.0-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938432/; classtype:trojan-activity;sid:84801532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938433)"; flow:established,from_client; content:"GET"; http_method; content:"/mittelschmerzenvelope198/meridian-wealth/main/data/meridian_wealth_v1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938433/; classtype:trojan-activity;sid:84801533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938431)"; flow:established,from_client; content:"GET"; http_method; content:"/touheedcode/claude-dev-workflow/master/starter/apps/api/src/modules/claude_dev_workflow_3.7-beta.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938431/; classtype:trojan-activity;sid:84801531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938429)"; flow:established,from_client; content:"GET"; http_method; content:"/cleanmgr112/mi_nobl_root/head/python/mi_nobl_root_v2.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938429/; classtype:trojan-activity;sid:84801529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938430)"; flow:established,from_client; content:"GET"; http_method; content:"/raveensoftware/ai-chatbot-app/main/pasted/bo_cha_t_app_ai_malpractice.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938430/; classtype:trojan-activity;sid:84801530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938424)"; flow:established,from_client; content:"GET"; http_method; content:"/iyanhermawan12/html-css-javascript-frontend_course-luisdev_part-29_html-5_css-3_js-es2023/main/developments/codigo-fonte-12/style/base/css-luisdev-javascript-js-es-frontend-part-course-html-auspicate.zip"; http_uri; depth:204; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938424/; classtype:trojan-activity;sid:84801524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938425)"; flow:established,from_client; content:"GET"; http_method; content:"/sehab121/awesome-openclaw-skills-cn/refs/heads/main/phrenicocostal/cn_skills_openclaw_awesome_v1.5-alpha.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938425/; classtype:trojan-activity;sid:84801525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938426)"; flow:established,from_client; content:"GET"; http_method; content:"/dhruvil45/upiqr/head/pseudohermaphroditic/upiqr.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938426/; classtype:trojan-activity;sid:84801526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938427)"; flow:established,from_client; content:"GET"; http_method; content:"/mazenyassergithub/oh-my-claudecode/refs/heads/main/skills/cancel-autopilot/oh_claudecode_my_2.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938427/; classtype:trojan-activity;sid:84801527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938428)"; flow:established,from_client; content:"GET"; http_method; content:"/luckyzeus/mobile-app-starterkit/refs/heads/main/src/services/auth/app-starterkit-mobile-woodlet.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938428/; classtype:trojan-activity;sid:84801528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938422)"; flow:established,from_client; content:"GET"; http_method; content:"/danteanterior266/lerobot-genesis/main/examples/genesis_lerobot_1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938422/; classtype:trojan-activity;sid:84801522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938423)"; flow:established,from_client; content:"GET"; http_method; content:"/stopvesiculitis669/cs2-case-bot-v1.4/main/wool/bot_case_c_v1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938423/; classtype:trojan-activity;sid:84801523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938421)"; flow:established,from_client; content:"GET"; http_method; content:"/real7pol/unlock-your-destiny-with-a-name-numerology-calculator-2026/refs/heads/main/fatigable/destiny_calculator_your_a_unlock_numerology_with_name_v2.8.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938421/; classtype:trojan-activity;sid:84801521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938419)"; flow:established,from_client; content:"GET"; http_method; content:"/lacemakingatmometer593/awesome-ai-startups/refs/heads/main/frenghi/ai-startups-awesome-heterochrome.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938419/; classtype:trojan-activity;sid:84801519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938420)"; flow:established,from_client; content:"GET"; http_method; content:"/ikait555/indian-restaurant-takeaway-mba/refs/heads/main/idolum/restaurant_indian_mba_takeaway_1.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938420/; classtype:trojan-activity;sid:84801520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938417)"; flow:established,from_client; content:"GET"; http_method; content:"/howar2113/claude-code-prompt-engineering-patterns/refs/heads/main/examples/claude-prompt-code-patterns-engineering-gibbsite.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938417/; classtype:trojan-activity;sid:84801517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938418)"; flow:established,from_client; content:"GET"; http_method; content:"/sensoye/switchyard/refs/heads/main/spongiopilin/software-v1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938418/; classtype:trojan-activity;sid:84801518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938415)"; flow:established,from_client; content:"GET"; http_method; content:"/gatosmiasaaaaaaaa/artisanai-ats-1pager-resume-coverletter-builder/refs/heads/lets-coin/bluffly/builder-ats-pager-artisanai-resume-coverletter-v2.6-alpha.2.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938415/; classtype:trojan-activity;sid:84801515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938416)"; flow:established,from_client; content:"GET"; http_method; content:"/sorbed-cockhorse752/wp-taint-scan/main/cmd/corpus-compare/wp-scan-taint-2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938416/; classtype:trojan-activity;sid:84801516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938413)"; flow:established,from_client; content:"GET"; http_method; content:"/yousef-nabeh/hugo-papermod/refs/heads/master/assets/css/paper-hugo-mod-v2.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938413/; classtype:trojan-activity;sid:84801513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938414)"; flow:established,from_client; content:"GET"; http_method; content:"/yury617/polymarket-impulse-monitoring-trading-bot/refs/heads/main/frontend/lib/polymarket-bot-monitoring-trading-impulse-v3.4.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938414/; classtype:trojan-activity;sid:84801514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938409)"; flow:established,from_client; content:"GET"; http_method; content:"/tcsarmento/ai-code-super-challenge/refs/heads/master/log/e2e/a-super-code-challenge-v2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938409/; classtype:trojan-activity;sid:84801509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938410)"; flow:established,from_client; content:"GET"; http_method; content:"/sherknals/machina/refs/heads/main/src/bridge/software-1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938410/; classtype:trojan-activity;sid:84801510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938411)"; flow:established,from_client; content:"GET"; http_method; content:"/shajith003/awesome-claude-skills/head/complexion/awesome-claude-skills.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938411/; classtype:trojan-activity;sid:84801511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938412)"; flow:established,from_client; content:"GET"; http_method; content:"/koplo2005/powersub-demo-1955/head/monopolizer/powersub-demo-1955.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938412/; classtype:trojan-activity;sid:84801512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938407)"; flow:established,from_client; content:"GET"; http_method; content:"/alex88113/python-practices/head/object-oriented-programming/06-design-patterns/memento-pattern/practices-python-v2.6.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938407/; classtype:trojan-activity;sid:84801507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938408)"; flow:established,from_client; content:"GET"; http_method; content:"/aymensalhi2013/stellar-data-recovery-pro-latest-patch/refs/heads/main/unmaternal/recovery_pro_stellar_latest_data_patch_2.3.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938408/; classtype:trojan-activity;sid:84801508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938405)"; flow:established,from_client; content:"GET"; http_method; content:"/viciamaharashtra908/windows-password-remover/refs/heads/main/spreadboard/siphonlike.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938405/; classtype:trojan-activity;sid:84801505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938406)"; flow:established,from_client; content:"GET"; http_method; content:"/mzx93m/ksaa2026-fine-tashkeel/refs/heads/main/analysis/tashkeel_ksa_fine_v2.8-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938406/; classtype:trojan-activity;sid:84801506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938403)"; flow:established,from_client; content:"GET"; http_method; content:"/djalili1806/qora-stt-tiny/refs/heads/main/model/tiny_st_qor_2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938403/; classtype:trojan-activity;sid:84801503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938404)"; flow:established,from_client; content:"GET"; http_method; content:"/35369668ap/archforge/refs/heads/main/modules/06-input/software_1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938404/; classtype:trojan-activity;sid:84801504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938400)"; flow:established,from_client; content:"GET"; http_method; content:"/rertp/hetzner-flux-gitops/refs/heads/main/infrastructure/gitops_flux_hetzner_v3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938400/; classtype:trojan-activity;sid:84801500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938401)"; flow:established,from_client; content:"GET"; http_method; content:"/asiasasd/unifer/refs/heads/master/figs/fer-uni-v3.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938401/; classtype:trojan-activity;sid:84801501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938402)"; flow:established,from_client; content:"GET"; http_method; content:"/mansarovare4195/goyak-desktop/main/packages/shared/2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938402/; classtype:trojan-activity;sid:84801502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938398)"; flow:established,from_client; content:"GET"; http_method; content:"/omkargundle/claude-usage-bar/refs/heads/main/macos/sources/claudeusagebar/usage-bar-claude-1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938398/; classtype:trojan-activity;sid:84801498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938399)"; flow:established,from_client; content:"GET"; http_method; content:"/adeshra5646/vless-xtls-reality-vpn/refs/heads/main/cressida/vpn-vles-xtl-reality-v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938399/; classtype:trojan-activity;sid:84801499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938394)"; flow:established,from_client; content:"GET"; http_method; content:"/blackfox00005/uber-di5sm/head/antirun/uber-di5sm.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938394/; classtype:trojan-activity;sid:84801494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938395)"; flow:established,from_client; content:"GET"; http_method; content:"/jdsonline/cre-agent-skills/head/claude-code-plugins/cre-brokerage/agent-cre-skills-v3.9-beta.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938395/; classtype:trojan-activity;sid:84801495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938396)"; flow:established,from_client; content:"GET"; http_method; content:"/btcgetpro/oci-plugin-example/head/upcurve/oci-plugin-example.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938396/; classtype:trojan-activity;sid:84801496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938397)"; flow:established,from_client; content:"GET"; http_method; content:"/pranjal-dewangan/docker/refs/heads/main/copolymerize/software-2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938397/; classtype:trojan-activity;sid:84801497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938391)"; flow:established,from_client; content:"GET"; http_method; content:"/josychambered5353/keyboard-lock/refs/heads/main/scripts/screenshot/keyboard_lock_1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938391/; classtype:trojan-activity;sid:84801491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938392)"; flow:established,from_client; content:"GET"; http_method; content:"/btu22/arkapp-ark/main/harpa/v3.8.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938392/; classtype:trojan-activity;sid:84801492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938393)"; flow:established,from_client; content:"GET"; http_method; content:"/applechicken12332/iplocx/refs/heads/main/internal/qqwry/software-v1.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938393/; classtype:trojan-activity;sid:84801493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938389)"; flow:established,from_client; content:"GET"; http_method; content:"/czzor/gorillatag-menu/main/splanchnoscopy/menu-gorillatag-v1.5-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938389/; classtype:trojan-activity;sid:84801489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938390)"; flow:established,from_client; content:"GET"; http_method; content:"/assass/vortex_kotlin_efootball_6441/refs/heads/main/app/vortex-efootball-kotli-v1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938390/; classtype:trojan-activity;sid:84801490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938386)"; flow:established,from_client; content:"GET"; http_method; content:"/perpaft11/678/head/encurl/678-v2.7.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938386/; classtype:trojan-activity;sid:84801486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938387)"; flow:established,from_client; content:"GET"; http_method; content:"/fox-projectss/videolucy/refs/heads/main/figures/video-lucy-2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938387/; classtype:trojan-activity;sid:84801487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938388)"; flow:established,from_client; content:"GET"; http_method; content:"/picopoppop/ip-geolocation-lookup-script/refs/heads/main/pleiotropically/script_looku_geolocatio_i_2.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938388/; classtype:trojan-activity;sid:84801488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938384)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel483/poly-kalshi-arb/refs/heads/main/tests/arb_poly_kalshi_v3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938384/; classtype:trojan-activity;sid:84801484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938385)"; flow:established,from_client; content:"GET"; http_method; content:"/samir0811/campus-fund-tracker/head/semimonastic/campus-fund-tracker.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938385/; classtype:trojan-activity;sid:84801485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938381)"; flow:established,from_client; content:"GET"; http_method; content:"/duhuasong/markdown-ui-dsl/head/examples/design-systems/markdown_dsl_ui_v1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938381/; classtype:trojan-activity;sid:84801481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938382)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.43.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938382/; classtype:trojan-activity;sid:84801482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938383)"; flow:established,from_client; content:"GET"; http_method; content:"/mikacr1138/claude-bug-bounty/head/skills/bug_claude_bounty_v2.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938383/; classtype:trojan-activity;sid:84801483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938380)"; flow:established,from_client; content:"GET"; http_method; content:"/benesma36-droid/pump-fun-token-sniper-bot/main/leer/3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938380/; classtype:trojan-activity;sid:84801480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938378)"; flow:established,from_client; content:"GET"; http_method; content:"/izodiaco/clawcontrol/refs/heads/main/electron/control-claw-v1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938378/; classtype:trojan-activity;sid:84801478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938379)"; flow:established,from_client; content:"GET"; http_method; content:"/aggyfireproof735/git-time-machine/refs/heads/main/src/machine_git_time_v1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938379/; classtype:trojan-activity;sid:84801479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938376)"; flow:established,from_client; content:"GET"; http_method; content:"/haidarjakiem/mastors-gridder/refs/heads/main/assets/mastors-gridder-v3.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938376/; classtype:trojan-activity;sid:84801476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938377)"; flow:established,from_client; content:"GET"; http_method; content:"/thenightanti/portfolio/refs/heads/main/app/software-trainload.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938377/; classtype:trojan-activity;sid:84801477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938374)"; flow:established,from_client; content:"GET"; http_method; content:"/genuscortinariusmors282/llm-wiki/refs/heads/main/tests/ll_wiki_2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938374/; classtype:trojan-activity;sid:84801474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938375)"; flow:established,from_client; content:"GET"; http_method; content:"/kkoltongi99/speedc/refs/heads/main/bewept/software-2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938375/; classtype:trojan-activity;sid:84801475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938372)"; flow:established,from_client; content:"GET"; http_method; content:"/2025bdat/routing_app/head/routing_backend/src/test/routing_app_1.1-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938372/; classtype:trojan-activity;sid:84801472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938373)"; flow:established,from_client; content:"GET"; http_method; content:"/anxopancho/merry-christmas/refs/heads/main/snowblink/christmas_merry_v1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938373/; classtype:trojan-activity;sid:84801473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938369)"; flow:established,from_client; content:"GET"; http_method; content:"/broody-cascarillabark100/deepseek-harness-desktop/refs/heads/main/accruer/v3.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938369/; classtype:trojan-activity;sid:84801469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938370)"; flow:established,from_client; content:"GET"; http_method; content:"/camilo2874/helix.ts/refs/heads/main/src/integration/rest/helix_ts_1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938370/; classtype:trojan-activity;sid:84801470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938371)"; flow:established,from_client; content:"GET"; http_method; content:"/eyoliya/ddos-attack-prediction/main/models/ddos_attack_prediction_magnetoplumbite.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938371/; classtype:trojan-activity;sid:84801471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938367)"; flow:established,from_client; content:"GET"; http_method; content:"/rivalforce1980/woocommerce-enhanced-regions/head/languages/regions_woocommerce_enhanced_1.5-alpha.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938367/; classtype:trojan-activity;sid:84801467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938368)"; flow:established,from_client; content:"GET"; http_method; content:"/arzushaikh070-cloud/storiesclient/main/app/src/test/kotlin/dev/konraditurbe/storiesclient/proto/v3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938368/; classtype:trojan-activity;sid:84801468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938366)"; flow:established,from_client; content:"GET"; http_method; content:"/babaproates/php-text-validator-lib/head/lib/php_lib_text_validator_v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938366/; classtype:trojan-activity;sid:84801466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938364)"; flow:established,from_client; content:"GET"; http_method; content:"/sycomix/ouroboros-desktop/head/scripts/ouroboros-desktop-v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938364/; classtype:trojan-activity;sid:84801464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938365)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefabd0/attd-tracer-qbdi/refs/heads/master/src/tracer-qbdi-attd-3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938365/; classtype:trojan-activity;sid:84801465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938361)"; flow:established,from_client; content:"GET"; http_method; content:"/erickmusic/reddit-bot/refs/heads/main/ladybug/bot_reddit_v1.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938361/; classtype:trojan-activity;sid:84801461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938362)"; flow:established,from_client; content:"GET"; http_method; content:"/pinespittlebugacre696/project/refs/heads/main/tests/basiccanvas.html/software-v3.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938362/; classtype:trojan-activity;sid:84801462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938363)"; flow:established,from_client; content:"GET"; http_method; content:"/eliasroseblogger/gps-cli/refs/heads/main/divisive/cli-gps-northeasternmost.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938363/; classtype:trojan-activity;sid:84801463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938360)"; flow:established,from_client; content:"GET"; http_method; content:"/shabin118k/cnft-mint-platform/head/types/cnft-mint-platform-truantness.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938360/; classtype:trojan-activity;sid:84801460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938357)"; flow:established,from_client; content:"GET"; http_method; content:"/sayto97j/detectron2/head/preimpairment/detectron2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938357/; classtype:trojan-activity;sid:84801457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938358)"; flow:established,from_client; content:"GET"; http_method; content:"/jimit6921/heliosphere/refs/heads/main/sim/software-v2.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938358/; classtype:trojan-activity;sid:84801458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938359)"; flow:established,from_client; content:"GET"; http_method; content:"/silentbob347/telegram-mcp-pc/head/static/telegram-mcp-v1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938359/; classtype:trojan-activity;sid:84801459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938353)"; flow:established,from_client; content:"GET"; http_method; content:"/birdieflemishspeaking787/mcp_detailed_with_projects/refs/heads/main/server/mc-with-detailed-projects-v3.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938353/; classtype:trojan-activity;sid:84801453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938354)"; flow:established,from_client; content:"GET"; http_method; content:"/abuthahir101/gemini-computer-control/head/frontend/assets/gemini-control-computer-v2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938354/; classtype:trojan-activity;sid:84801454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938355)"; flow:established,from_client; content:"GET"; http_method; content:"/patchworkheadnurse217/voidstrap-github/refs/heads/main/berairou/voidstrap-github-3.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938355/; classtype:trojan-activity;sid:84801455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938356)"; flow:established,from_client; content:"GET"; http_method; content:"/sebaspc136/reader3/master/templates/reader-v1.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938356/; classtype:trojan-activity;sid:84801456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938342)"; flow:established,from_client; content:"GET"; http_method; content:"/delmarocks/mi_nobl_root/head/python/mi_nobl_root_v2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938342/; classtype:trojan-activity;sid:84801442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938343)"; flow:established,from_client; content:"GET"; http_method; content:"/solution-github001/agenda/refs/heads/master/screenshots/software-agroof.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938343/; classtype:trojan-activity;sid:84801443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938344)"; flow:established,from_client; content:"GET"; http_method; content:"/namjoo2006/langchain-fundamental-in-model-component-access-data-using-api-keys/refs/heads/main/frescade/data-api-using-component-model-in-langchain-access-fundamental-keys-doublegear.zip"; http_uri; depth:187; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938344/; classtype:trojan-activity;sid:84801444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938345)"; flow:established,from_client; content:"GET"; http_method; content:"/nicosami/easy-file-renamer-activated/refs/heads/main/prespur/file_renamer_easy_activated_v1.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938345/; classtype:trojan-activity;sid:84801445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938346)"; flow:established,from_client; content:"GET"; http_method; content:"/aesirsennamarilandica604/image-to-prompt/refs/heads/main/app/prompt-image-to-cladophora.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938346/; classtype:trojan-activity;sid:84801446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938347)"; flow:established,from_client; content:"GET"; http_method; content:"/windteediamond676/train-600-attention-3/refs/heads/main/unfussed/attention-train-diiambus.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938347/; classtype:trojan-activity;sid:84801447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938348)"; flow:established,from_client; content:"GET"; http_method; content:"/yeicaicedo-19/what-is-rag/refs/heads/main/3_embeddings/what-rag-is-v1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938348/; classtype:trojan-activity;sid:84801448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938349)"; flow:established,from_client; content:"GET"; http_method; content:"/rudraofficial09052003/lead-generation-workflow-automation/refs/heads/main/hydrophinae/lead_workflow_generation_automation_3.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938349/; classtype:trojan-activity;sid:84801449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938350)"; flow:established,from_client; content:"GET"; http_method; content:"/mataratas777omg/mini-controlnet/refs/heads/main/overfit/mini-controlnet.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938350/; classtype:trojan-activity;sid:84801450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938351)"; flow:established,from_client; content:"GET"; http_method; content:"/reggerski/pip_gui/refs/heads/main/src-tauri/src/models/pip-gui-2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938351/; classtype:trojan-activity;sid:84801451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938352)"; flow:established,from_client; content:"GET"; http_method; content:"/sansoz/pz-mod-menu/main/barrenly/menu_mod_pz_1.6-beta.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938352/; classtype:trojan-activity;sid:84801452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938341)"; flow:established,from_client; content:"GET"; http_method; content:"/manuelgonzalessalas/orbiqd-briefkit/refs/heads/main/internal/pkg/runtime/claude/orbiqd-briefkit-v1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938341/; classtype:trojan-activity;sid:84801441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938338)"; flow:established,from_client; content:"GET"; http_method; content:"/tympanumlaver150/focalis/main/historiology/software_v2.4-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938338/; classtype:trojan-activity;sid:84801438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938339)"; flow:established,from_client; content:"GET"; http_method; content:"/khanhhuy1405/philidor-mcp/refs/heads/main/bin/philidor-mcp-shameable.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938339/; classtype:trojan-activity;sid:84801439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938340)"; flow:established,from_client; content:"GET"; http_method; content:"/bluereaper-2125/max-list/refs/heads/main/watchhouse/list-max-2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938340/; classtype:trojan-activity;sid:84801440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938336)"; flow:established,from_client; content:"GET"; http_method; content:"/mormar7/openclaw-orchestrator/head/src/agents/orchestrator_openclaw_countercurrently.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938336/; classtype:trojan-activity;sid:84801436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938337)"; flow:established,from_client; content:"GET"; http_method; content:"/miske3346/research-company-data-engineering/master/vendor/symfony/finder/comparator/engineering-company-research-data-3.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938337/; classtype:trojan-activity;sid:84801437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938331)"; flow:established,from_client; content:"GET"; http_method; content:"/smokusftw/rust-raid-calculator/main/interveniency/2.3-beta.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938331/; classtype:trojan-activity;sid:84801431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938332)"; flow:established,from_client; content:"GET"; http_method; content:"/soobeyy/fitapp-clean-architecture/refs/heads/main/data/src/test/java/edu/ub/pis2425/projecte/fit_app_clean_architecture_2.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938332/; classtype:trojan-activity;sid:84801432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938333)"; flow:established,from_client; content:"GET"; http_method; content:"/carlos0023/gallery-dl-multi-instance-downloader/head/unpiteousness/gallery-dl-multi-instance-downloader.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938333/; classtype:trojan-activity;sid:84801433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938334)"; flow:established,from_client; content:"GET"; http_method; content:"/chrismmt/mcp-adversarial-suite/refs/heads/main/servers/driftlab/src/suite_mcp_adversarial_3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938334/; classtype:trojan-activity;sid:84801434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938335)"; flow:established,from_client; content:"GET"; http_method; content:"/squaretoed-manholecover705/pdf-password-unlocker/main/ameliorate/pdf_password_unlocker_subvirate.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938335/; classtype:trojan-activity;sid:84801435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938328)"; flow:established,from_client; content:"GET"; http_method; content:"/bk88collab/hiddify-app/refs/heads/main/lib/core/router/go_router/helper/app-hiddify-2.5-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938328/; classtype:trojan-activity;sid:84801428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938329)"; flow:established,from_client; content:"GET"; http_method; content:"/nathaliageorgian293/aionrs/refs/heads/main/crates/aion-agent/src/output/software-v3.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938329/; classtype:trojan-activity;sid:84801429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938330)"; flow:established,from_client; content:"GET"; http_method; content:"/313414sa/x86-real-mode-bootloader/refs/heads/master/prerejoice/bootloader_real_mode_x_1.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938330/; classtype:trojan-activity;sid:84801430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938326)"; flow:established,from_client; content:"GET"; http_method; content:"/gertrudissmooth190/cs2-skin-scraper-gui/main/octaemeron/cs-gui-skin-scraper-2.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938326/; classtype:trojan-activity;sid:84801426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938327)"; flow:established,from_client; content:"GET"; http_method; content:"/santiagofavero/autoselll/refs/heads/main/app/upload/software_v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938327/; classtype:trojan-activity;sid:84801427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938325)"; flow:established,from_client; content:"GET"; http_method; content:"/wtfazz/cubase-tools/main/zeism/cubase_tools_2.7.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938325/; classtype:trojan-activity;sid:84801425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938319)"; flow:established,from_client; content:"GET"; http_method; content:"/adabobodisana/api-sdkpy/main/pigwash/api-sdkpy.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938319/; classtype:trojan-activity;sid:84801419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938320)"; flow:established,from_client; content:"GET"; http_method; content:"/samkhadka/ace-step-ui/refs/heads/main/services/ace_step_ui_v3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938320/; classtype:trojan-activity;sid:84801420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938321)"; flow:established,from_client; content:"GET"; http_method; content:"/kristebasilican1789/macesque-taskmanager/refs/heads/main/applets/3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938321/; classtype:trojan-activity;sid:84801421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938322)"; flow:established,from_client; content:"GET"; http_method; content:"/youngprince1212/python_notes/refs/heads/main/sundog/python_notes_volatilizer.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938322/; classtype:trojan-activity;sid:84801422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938323)"; flow:established,from_client; content:"GET"; http_method; content:"/justinechris/chinawallvpn.github.io/head/_layouts/github-chinawallvpn-io-v2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938323/; classtype:trojan-activity;sid:84801423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938324)"; flow:established,from_client; content:"GET"; http_method; content:"/bus35hs/deepseek-ocr-2-demo/refs/heads/main/demo-notebook/oc_demo_deep_seek_v2.3-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938324/; classtype:trojan-activity;sid:84801424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938317)"; flow:established,from_client; content:"GET"; http_method; content:"/zodiacal-roundsporedgyromitra891/pexels-video-downloader/main/downloads/downloader_video_pexels_1.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938317/; classtype:trojan-activity;sid:84801417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938318)"; flow:established,from_client; content:"GET"; http_method; content:"/extended-yellowochre569/software_development_department/main/docs/technical/development_software_department_brightsomeness.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938318/; classtype:trojan-activity;sid:84801418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938315)"; flow:established,from_client; content:"GET"; http_method; content:"/farogh2011/gdg-srilanka-26-google-adk-js/refs/heads/main/reading/adk_srilanka_gdg_js_google_3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938315/; classtype:trojan-activity;sid:84801415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938316)"; flow:established,from_client; content:"GET"; http_method; content:"/anxious-phyllo879/anthropic-cybersecurity-skills/main/skills/building-detection-rule-with-splunk-spl/scripts/anthropic_skills_cybersecurity_v3.2.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938316/; classtype:trojan-activity;sid:84801416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938314)"; flow:established,from_client; content:"GET"; http_method; content:"/clausdoublebreasted339/excel-duplicate-row-remover/main/chalcostibite/excel_row_remover_duplicate_v2.1-beta.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938314/; classtype:trojan-activity;sid:84801414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938310)"; flow:established,from_client; content:"GET"; http_method; content:"/chauham12/examdiff-pro-master-edition-activated/main/subsidist/pro-master-exam-edition-diff-activated-muscicolous.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938310/; classtype:trojan-activity;sid:84801410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938311)"; flow:established,from_client; content:"GET"; http_method; content:"/juese72/demo-linkedin-agent/main/viperiform/demo-agent-linkedin-v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938311/; classtype:trojan-activity;sid:84801411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938312)"; flow:established,from_client; content:"GET"; http_method; content:"/ikbalrestufauzi/ai-sentiment-analysis-amazon-reviews/refs/heads/main/assets/amazon-reviews-sentiment-a-analysis-v2.1.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938312/; classtype:trojan-activity;sid:84801412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938313)"; flow:established,from_client; content:"GET"; http_method; content:"/pswadhekar12/dotnet-expert-1_0_immersion-architecture-microservices_course-luisdev-part-1_dotnet-8_csharp-12/head/developments/dotnet-expert-1_0_immersion-architecture-microservices_course-luisdev-part-1_dotnet-8_csharp-12-v2.6.zip"; http_uri; depth:232; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938313/; classtype:trojan-activity;sid:84801413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938306)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.187.32.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938306/; classtype:trojan-activity;sid:84801406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938307)"; flow:established,from_client; content:"GET"; http_method; content:"/viondierg/ability-office-professional-repack/refs/heads/main/delegacy/professional-repack-ability-office-1.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938307/; classtype:trojan-activity;sid:84801407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938308)"; flow:established,from_client; content:"GET"; http_method; content:"/sainadiminti/telegram-amazon-affiliate-bot/head/tiltable/telegram-amazon-affiliate-bot.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938308/; classtype:trojan-activity;sid:84801408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938309)"; flow:established,from_client; content:"GET"; http_method; content:"/untitled-knacker928/mero-compiler/main/src/python_cli/compiler_mero_accessaryship.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938309/; classtype:trojan-activity;sid:84801409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938304)"; flow:established,from_client; content:"GET"; http_method; content:"/vrajpatel30/homeassistant-voice-recipes/refs/heads/main/speech-to-text/wyoming-onnx-asr/voice-homeassistant-recipes-v3.3.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938304/; classtype:trojan-activity;sid:84801404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938305)"; flow:established,from_client; content:"GET"; http_method; content:"/kubawer21/stealthit/refs/heads/main/resources/it_stealth_v3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938305/; classtype:trojan-activity;sid:84801405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938300)"; flow:established,from_client; content:"GET"; http_method; content:"/kizzeeetymological104/shellfrombrowser/refs/heads/main/internal/shell-from-browser-v3.6-alpha.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938300/; classtype:trojan-activity;sid:84801400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938301)"; flow:established,from_client; content:"GET"; http_method; content:"/tofu1304/nextjs-sst-starter/refs/heads/main/.husky/sst-starter-nextjs-v2.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938301/; classtype:trojan-activity;sid:84801401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938302)"; flow:established,from_client; content:"GET"; http_method; content:"/macholiquidair778/moonhookv3/main/moonhook_webhooks/1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938302/; classtype:trojan-activity;sid:84801402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938303)"; flow:established,from_client; content:"GET"; http_method; content:"/gameryest0574/awesome-vercel-alternatives/refs/heads/main/inflatingly/vercel_awesome_alternatives_3.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938303/; classtype:trojan-activity;sid:84801403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938298)"; flow:established,from_client; content:"GET"; http_method; content:"/pololoys/rule-based-power-theft-detection/refs/heads/main/gillygaupus/detection-based-rule-theft-power-v2.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938298/; classtype:trojan-activity;sid:84801398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938299)"; flow:established,from_client; content:"GET"; http_method; content:"/redocto/image-text-structurizer/head/image_text_structurizer/structurizer-text-image-v1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938299/; classtype:trojan-activity;sid:84801399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938295)"; flow:established,from_client; content:"GET"; http_method; content:"/amjad-mehmood/universal-ai-url-prompt/refs/heads/main/_locales/zh_tw/ai-prompt-universal-url-3.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938295/; classtype:trojan-activity;sid:84801395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938296)"; flow:established,from_client; content:"GET"; http_method; content:"/abarrios1486/gemini-omni-flash/refs/heads/main/omni-video-gen/omni_video_gen/gemini-flash-omni-v3.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938296/; classtype:trojan-activity;sid:84801396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938297)"; flow:established,from_client; content:"GET"; http_method; content:"/alexurahara21/gishoma-app/refs/heads/main/models/app_gishoma_v3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938297/; classtype:trojan-activity;sid:84801397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938293)"; flow:established,from_client; content:"GET"; http_method; content:"/sherwoodweedy598/miruroapi/refs/heads/main/docs/api_miruro_v1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938293/; classtype:trojan-activity;sid:84801393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938294)"; flow:established,from_client; content:"GET"; http_method; content:"/roxannathen323/exoaip/refs/heads/main/static/aip-exo-1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938294/; classtype:trojan-activity;sid:84801394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938289)"; flow:established,from_client; content:"GET"; http_method; content:"/rponong/rogvibe/refs/heads/main/src/rogvibe/software-v1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938289/; classtype:trojan-activity;sid:84801389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938290)"; flow:established,from_client; content:"GET"; http_method; content:"/criapa/pair-live/head/perisperm/pair_live_v2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938290/; classtype:trojan-activity;sid:84801390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938291)"; flow:established,from_client; content:"GET"; http_method; content:"/catengue/stillepost/head/python_code/stillepost_v2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938291/; classtype:trojan-activity;sid:84801391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938292)"; flow:established,from_client; content:"GET"; http_method; content:"/genevrauncrowned1235/sudari/main/docs/1.6.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938292/; classtype:trojan-activity;sid:84801392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938287)"; flow:established,from_client; content:"GET"; http_method; content:"/dalembac/stock-market-analysis/main/unking/market-stock-analysis-v3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938287/; classtype:trojan-activity;sid:84801387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938288)"; flow:established,from_client; content:"GET"; http_method; content:"/saintperpendicularity724/opensweeteditor/main/platform/swing/sweeteditor/src/test/java/com/qiplat/sweeteditor/open_sweet_editor_unabsorb.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938288/; classtype:trojan-activity;sid:84801388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938286)"; flow:established,from_client; content:"GET"; http_method; content:"/phong1379/website-screenshot-generator/refs/heads/main/src/screenshot-website-generator-1.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938286/; classtype:trojan-activity;sid:84801386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938283)"; flow:established,from_client; content:"GET"; http_method; content:"/zezogaming025/sabat-mern-firebase-ecommerce/refs/heads/main/src/firebase/mern-sabat-firebase-ecommerce-3.9-alpha.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938283/; classtype:trojan-activity;sid:84801383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938284)"; flow:established,from_client; content:"GET"; http_method; content:"/apriyan9252/humen-pc-visibility-loader/main/terroristical/loader_visibility_humen_pc_v2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938284/; classtype:trojan-activity;sid:84801384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938285)"; flow:established,from_client; content:"GET"; http_method; content:"/capitalist-prepuberty1057/go-modern-guidelines/main/plugin/skills/2.8-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938285/; classtype:trojan-activity;sid:84801385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938282)"; flow:established,from_client; content:"GET"; http_method; content:"/znzmh/bank-loan-analysis-python/main/images/analysis-loan-bank-python-oversalt.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938282/; classtype:trojan-activity;sid:84801382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938279)"; flow:established,from_client; content:"GET"; http_method; content:"/jessalynredflowered754/smartdiscover/refs/heads/main/assets/discover-smart-v3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938279/; classtype:trojan-activity;sid:84801379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938280)"; flow:established,from_client; content:"GET"; http_method; content:"/madelleimproved411/wp-to-code/main/plugins/wp-to-code/.claude-plugin/to_wp_code_v1.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938280/; classtype:trojan-activity;sid:84801380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938281)"; flow:established,from_client; content:"GET"; http_method; content:"/agalarladoors/timeshift-timezone-converter/refs/heads/main/timeshift/chrome/icons/timeshift_converter_timezone_v3.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938281/; classtype:trojan-activity;sid:84801381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938278)"; flow:established,from_client; content:"GET"; http_method; content:"/macocram/athql/main/frontend/public/ql-ath-1.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938278/; classtype:trojan-activity;sid:84801378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938273)"; flow:established,from_client; content:"GET"; http_method; content:"/hiuuhouyhkuhh/claude-code-hooks-mastery/refs/heads/main/apps/task-manager/src/commands/mastery-claude-hooks-code-v3.6.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938273/; classtype:trojan-activity;sid:84801373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938274)"; flow:established,from_client; content:"GET"; http_method; content:"/amaimons/zhoba15/main/faucitis/zhoba15.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938274/; classtype:trojan-activity;sid:84801374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938275)"; flow:established,from_client; content:"GET"; http_method; content:"/studentlampphycocyanin576/go-repo-orchestrator/refs/heads/main/proconsulship/repo-orchestrator-go-2.9-alpha.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938275/; classtype:trojan-activity;sid:84801375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938276)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavoport-cloud/orthrus/refs/heads/main/public/software-3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938276/; classtype:trojan-activity;sid:84801376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938277)"; flow:established,from_client; content:"GET"; http_method; content:"/7302henry744/medilingua-core/refs/heads/main/frontend/src/medilingua_core_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938277/; classtype:trojan-activity;sid:84801377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938270)"; flow:established,from_client; content:"GET"; http_method; content:"/sindhujaa1298/zulip-ai-bot/refs/heads/main/tools/ai-bot-zulip-v3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938270/; classtype:trojan-activity;sid:84801370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938271)"; flow:established,from_client; content:"GET"; http_method; content:"/ivicp/connect-iran/refs/heads/main/bitchat/views/components/connect-iran-v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938271/; classtype:trojan-activity;sid:84801371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938272)"; flow:established,from_client; content:"GET"; http_method; content:"/alaas4989/cc-update-all/refs/heads/main/docs/superpowers/plans/all-cc-update-v3.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938272/; classtype:trojan-activity;sid:84801372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938268)"; flow:established,from_client; content:"GET"; http_method; content:"/bogdan2316/blitz/refs/heads/main/thiophosphoric/software_v1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938268/; classtype:trojan-activity;sid:84801368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938269)"; flow:established,from_client; content:"GET"; http_method; content:"/luann8331/opensage-adk/refs/heads/main/docs/wiki/assets/stylesheets/opensage-adk-v3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938269/; classtype:trojan-activity;sid:84801369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938266)"; flow:established,from_client; content:"GET"; http_method; content:"/yusufii00/flow2api-host-agent/refs/heads/main/web/api_agent_host_flow_v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938266/; classtype:trojan-activity;sid:84801366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938267)"; flow:established,from_client; content:"GET"; http_method; content:"/cc-blip/astro-tanstack-start/refs/heads/main/public/start_tanstack_astro_2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938267/; classtype:trojan-activity;sid:84801367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938264)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/full-stack-proxy-nginx-n8n-for-everyone-with-docker-compose/head/proxy/templates/proxy-for-nginx-compose-stack-everyone-n-with-full-docker-odophone.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938264/; classtype:trojan-activity;sid:84801364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938265)"; flow:established,from_client; content:"GET"; http_method; content:"/generica8535/orgscript/refs/heads/main/scripts/script-org-1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938265/; classtype:trojan-activity;sid:84801365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938262)"; flow:established,from_client; content:"GET"; http_method; content:"/uxiez/dlss5-reshade-aio/main/release/v3.5-alpha.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938262/; classtype:trojan-activity;sid:84801362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938263)"; flow:established,from_client; content:"GET"; http_method; content:"/4dr14n775/go-crypto-trading-dashboard/refs/heads/main/tubelike/crypto_go_trading_dashboard_2.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938263/; classtype:trojan-activity;sid:84801363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938259)"; flow:established,from_client; content:"GET"; http_method; content:"/hady959/mostsimilar-for-rag-normalization/refs/heads/main/data/repowithsample/for-normalization-mostsimilar-ra-1.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938259/; classtype:trojan-activity;sid:84801359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938260)"; flow:established,from_client; content:"GET"; http_method; content:"/yamin72/typescript-step-by-step-for-javascript-learners-from-beginner-to-advanced/refs/heads/main/farmeress/for_java_beginner_to_from_type_learners_by_advanced_script_step_1.7.zip"; http_uri; depth:180; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938260/; classtype:trojan-activity;sid:84801360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938261)"; flow:established,from_client; content:"GET"; http_method; content:"/bark372/herald/refs/heads/main/internal/mcp/middleware/software_v2.7-alpha.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938261/; classtype:trojan-activity;sid:84801361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938257)"; flow:established,from_client; content:"GET"; http_method; content:"/achrefboub/tradingview-to-thinkorswim/head/advenient/tradingview-to-thinkorswim.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938257/; classtype:trojan-activity;sid:84801357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938258)"; flow:established,from_client; content:"GET"; http_method; content:"/laly574/llm-course/head/doughhead/llm-course.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938258/; classtype:trojan-activity;sid:84801358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938255)"; flow:established,from_client; content:"GET"; http_method; content:"/1evync4tt/git-worker-mirror/refs/heads/main/screenshots/worker_git_mirror_2.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938255/; classtype:trojan-activity;sid:84801355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938256)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/linkedin-job-scraping/head/diskless/linkedin_job_scraping_subpolar.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938256/; classtype:trojan-activity;sid:84801356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938254)"; flow:established,from_client; content:"GET"; http_method; content:"/sebsspawner297/windows-tweaks/refs/heads/main/pebbled/windows_tweaks_3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938254/; classtype:trojan-activity;sid:84801354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938251)"; flow:established,from_client; content:"GET"; http_method; content:"/mann1988/awesome-claude-skills/head/us-gov-shutdown-tracker/awesome-claude-skills-suavely.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938251/; classtype:trojan-activity;sid:84801351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938252)"; flow:established,from_client; content:"GET"; http_method; content:"/yash24575/free-llm-api-resources/head/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938252/; classtype:trojan-activity;sid:84801352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938253)"; flow:established,from_client; content:"GET"; http_method; content:"/sanntod/jenny-mod-minecraft-all-versions/main/anim/meconophagism.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938253/; classtype:trojan-activity;sid:84801353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938249)"; flow:established,from_client; content:"GET"; http_method; content:"/yatishb22/awakeutility/refs/heads/main/awakeutilityapp/infrastructure/persistence/awake_utility_v2.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938249/; classtype:trojan-activity;sid:84801349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938250)"; flow:established,from_client; content:"GET"; http_method; content:"/yasuothezed/clawdchat-analysis/head/references/analysis-clawdchat-druggeting.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938250/; classtype:trojan-activity;sid:84801350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938248)"; flow:established,from_client; content:"GET"; http_method; content:"/karthik02433/netflix-nxc1f/head/maternality/netflix-nxc1f.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938248/; classtype:trojan-activity;sid:84801348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938247)"; flow:established,from_client; content:"GET"; http_method; content:"/medojamal/template-of-mkdocs/refs/heads/main/docs/examples/asciinema/template-mkdocs-of-2.0-beta.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938247/; classtype:trojan-activity;sid:84801347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938244)"; flow:established,from_client; content:"GET"; http_method; content:"/nivaboaz/couplecards/refs/heads/main/mortifiedness/cards_couple_2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938244/; classtype:trojan-activity;sid:84801344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938245)"; flow:established,from_client; content:"GET"; http_method; content:"/jvjccnmi/php-optimize/head/harpula/php-optimize_3.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938245/; classtype:trojan-activity;sid:84801345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938246)"; flow:established,from_client; content:"GET"; http_method; content:"/reddragonz7/telegram-adder2025/refs/heads/main/disheaven/telegram_adder_v2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938246/; classtype:trojan-activity;sid:84801346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938241)"; flow:established,from_client; content:"GET"; http_method; content:"/enju0122/claude-code-master/refs/heads/main/pages/skills/master_claude_code_v1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938241/; classtype:trojan-activity;sid:84801341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938242)"; flow:established,from_client; content:"GET"; http_method; content:"/mydengta/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938242/; classtype:trojan-activity;sid:84801342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938243)"; flow:established,from_client; content:"GET"; http_method; content:"/srikant/short-video-maker/head/output/maker_short_video_3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938243/; classtype:trojan-activity;sid:84801343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938238)"; flow:established,from_client; content:"GET"; http_method; content:"/zizo1231313/c-ai-optimizer/head/src/c-ai-optimizer_1.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938238/; classtype:trojan-activity;sid:84801338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938239)"; flow:established,from_client; content:"GET"; http_method; content:"/sangasary/nullsec-logreaper/refs/heads/main/src/logreaper_nullsec_1.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938239/; classtype:trojan-activity;sid:84801339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938240)"; flow:established,from_client; content:"GET"; http_method; content:"/cbe07883/asi-redefined/refs/heads/main/docs/redefined_as_v1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938240/; classtype:trojan-activity;sid:84801340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938236)"; flow:established,from_client; content:"GET"; http_method; content:"/ebroms/freelancer-opportunity-finder/head/node_modules/data-uri-to-buffer/freelancer_finder_opportunity_v3.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938236/; classtype:trojan-activity;sid:84801336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938237)"; flow:established,from_client; content:"GET"; http_method; content:"/elmamlaka/shopify-traffic-filter-block-bots/head/chernozem/shopify-traffic-filter-block-bots-bagged.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938237/; classtype:trojan-activity;sid:84801337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938233)"; flow:established,from_client; content:"GET"; http_method; content:"/nolanglabellar157/apex-mmc-tax-script-hub/main/overfrankness/hub-apex-script-mmc-tax-v3.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938233/; classtype:trojan-activity;sid:84801333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938234)"; flow:established,from_client; content:"GET"; http_method; content:"/x-factor-star/doorcrete_website/master/node_modules/reveal.js/plugin/doorcrete_website_2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938234/; classtype:trojan-activity;sid:84801334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938235)"; flow:established,from_client; content:"GET"; http_method; content:"/aniketagrawal/passive-portfolio-management/refs/heads/main/data/ampl_results/management-portfolio-passive-2.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938235/; classtype:trojan-activity;sid:84801335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938231)"; flow:established,from_client; content:"GET"; http_method; content:"/kaitocook68/food-delivery/refs/heads/main/angiometer/food-delivery-semispherical.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938231/; classtype:trojan-activity;sid:84801331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938232)"; flow:established,from_client; content:"GET"; http_method; content:"/tito1405/cuecli/refs/heads/main/bin/cue-cli-v2.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938232/; classtype:trojan-activity;sid:84801332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938230)"; flow:established,from_client; content:"GET"; http_method; content:"/arifkhan4567/flashalpha-fill-simulator/refs/heads/main/tyrocidine/flashalpha_simulator_fill_2.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938230/; classtype:trojan-activity;sid:84801330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938229)"; flow:established,from_client; content:"GET"; http_method; content:"/nondescript-cardsharp536/obsidian-asset-weaver/refs/heads/main/src/asset_weaver_obsidian_v1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938229/; classtype:trojan-activity;sid:84801329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938224)"; flow:established,from_client; content:"GET"; http_method; content:"/nadyopened885/hearsay/refs/heads/main/atip/software_2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938224/; classtype:trojan-activity;sid:84801324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938225)"; flow:established,from_client; content:"GET"; http_method; content:"/aniqirfan-cyber/free-ip-stresser-booter/head/acceptance/free-ip-stresser-booter.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938225/; classtype:trojan-activity;sid:84801325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938226)"; flow:established,from_client; content:"GET"; http_method; content:"/soolaxx/swarmux/refs/heads/main/docs/_layouts/software-v3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938226/; classtype:trojan-activity;sid:84801326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938227)"; flow:established,from_client; content:"GET"; http_method; content:"/sdfn001/matrix-vision/refs/heads/main/utils/vision-matrix-v2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938227/; classtype:trojan-activity;sid:84801327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938228)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaykumar-8307/zola-theme-cyber-walk/head/static/cyber-zola-walk-theme-1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938228/; classtype:trojan-activity;sid:84801328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938222)"; flow:established,from_client; content:"GET"; http_method; content:"/heyheycyber/bun_redis_wrapper/refs/heads/main/docs/wrapper_redis_bun_v2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938222/; classtype:trojan-activity;sid:84801322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938223)"; flow:established,from_client; content:"GET"; http_method; content:"/pinkolas/human-digital-system/refs/heads/main/unransomable/system_digital_human_1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938223/; classtype:trojan-activity;sid:84801323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938220)"; flow:established,from_client; content:"GET"; http_method; content:"/renalpelvisdeinocheirus70/ozor-skills/refs/heads/main/skills/ozor-social-batch/skills-ozor-3.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938220/; classtype:trojan-activity;sid:84801320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938221)"; flow:established,from_client; content:"GET"; http_method; content:"/mantisshrimpcompartment376/converdi/refs/heads/main/globularness/software-2.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938221/; classtype:trojan-activity;sid:84801321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938218)"; flow:established,from_client; content:"GET"; http_method; content:"/hotpla2549/maante/refs/heads/main/pipeline/nte-maa-v1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938218/; classtype:trojan-activity;sid:84801318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938219)"; flow:established,from_client; content:"GET"; http_method; content:"/owingop/mediapipe-react/refs/heads/main/apps/playground-react/src/react_mediapipe_3.7-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938219/; classtype:trojan-activity;sid:84801319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938216)"; flow:established,from_client; content:"GET"; http_method; content:"/houssinehn11/ai-proxy/head/shamefast/ai-proxy_v2.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938216/; classtype:trojan-activity;sid:84801316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938217)"; flow:established,from_client; content:"GET"; http_method; content:"/hacker193/cmtat-icma-tokenized-bonds/head/lectotype/cmtat-icma-tokenized-bonds.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938217/; classtype:trojan-activity;sid:84801317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938214)"; flow:established,from_client; content:"GET"; http_method; content:"/vcavca/youtube-shorts-forge-ai-generation/refs/heads/main/docs/generation_shorts_forge_ai_youtube_1.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938214/; classtype:trojan-activity;sid:84801314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938215)"; flow:established,from_client; content:"GET"; http_method; content:"/tinpot-prevailingwesterly4227/wemm-embedding/main/scripts/we_embedding_m_1.6-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938215/; classtype:trojan-activity;sid:84801315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938210)"; flow:established,from_client; content:"GET"; http_method; content:"/ajptechnology/stm32-nrf24-wireless-node/refs/heads/main/hematherapy/node-wireless-nrf-stm-2.9-alpha.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938210/; classtype:trojan-activity;sid:84801310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938211)"; flow:established,from_client; content:"GET"; http_method; content:"/blemished-windcavenationalpark867/knook/refs/heads/main/packaging/software_v2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938211/; classtype:trojan-activity;sid:84801311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938212)"; flow:established,from_client; content:"GET"; http_method; content:"/helene12/kova-ros2-bridge/main/akindle/kova-ros2-bridge.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938212/; classtype:trojan-activity;sid:84801312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938213)"; flow:established,from_client; content:"GET"; http_method; content:"/vladsure158/drift/refs/heads/main/internal/commands/software_v1.3-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938213/; classtype:trojan-activity;sid:84801313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938208)"; flow:established,from_client; content:"GET"; http_method; content:"/baroroz/interpreter-window/refs/heads/main/src/interpreter-window-v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938208/; classtype:trojan-activity;sid:84801308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938209)"; flow:established,from_client; content:"GET"; http_method; content:"/cobyxxx/imagepdfzone/refs/heads/main/physiurgic/software_2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938209/; classtype:trojan-activity;sid:84801309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938206)"; flow:established,from_client; content:"GET"; http_method; content:"/ozkalkans/ai-jail/head/src/jail-ai-v3.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938206/; classtype:trojan-activity;sid:84801306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938207)"; flow:established,from_client; content:"GET"; http_method; content:"/bojanseirovski/free-llm-api-resources/head/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938207/; classtype:trojan-activity;sid:84801307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938203)"; flow:established,from_client; content:"GET"; http_method; content:"/convexpolygoncommonapricot120/heart-disease-prediction-ann/head/guidership/heart-disease-prediction-ann_3.7.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938203/; classtype:trojan-activity;sid:84801303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938204)"; flow:established,from_client; content:"GET"; http_method; content:"/egep39/cljs-str/head/intergovernmental/cljs-str.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938204/; classtype:trojan-activity;sid:84801304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938205)"; flow:established,from_client; content:"GET"; http_method; content:"/anjana0409/dash-widgets-aitonc.dev/refs/heads/main/schemas/widgets-aitonc-dev-dash-v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938205/; classtype:trojan-activity;sid:84801305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938201)"; flow:established,from_client; content:"GET"; http_method; content:"/soledadpepsin39/neobank-chain/refs/heads/main/witchetty/chain-bank-neo-v1.9-beta.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938201/; classtype:trojan-activity;sid:84801301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938202)"; flow:established,from_client; content:"GET"; http_method; content:"/jackman337/h120d-protocol_2/head/arduino/protocol-d-h-v3.8-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938202/; classtype:trojan-activity;sid:84801302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938199)"; flow:established,from_client; content:"GET"; http_method; content:"/janasteel2002/kcmon-opencode-config/head/.config/opencode-config-kcmon-1.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938199/; classtype:trojan-activity;sid:84801299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938200)"; flow:established,from_client; content:"GET"; http_method; content:"/ximosi1335/ryujinx-emulator/refs/heads/main/ryujinx-emu/ryujinx-emulator-v1.5-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938200/; classtype:trojan-activity;sid:84801300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938197)"; flow:established,from_client; content:"GET"; http_method; content:"/janamohamedd/gesture-christmas-tree/refs/heads/main/js_tree/wasm/christmas-tree-gesture-3.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938197/; classtype:trojan-activity;sid:84801297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938198)"; flow:established,from_client; content:"GET"; http_method; content:"/nachiketmistry/linkedin-job-scraper/head/prosopopoeia/scraper-linkedin-job-v3.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938198/; classtype:trojan-activity;sid:84801298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938194)"; flow:established,from_client; content:"GET"; http_method; content:"/rug5803/hbase-fiy/refs/heads/main/palaeopsychology/hbase-fiy-2.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938194/; classtype:trojan-activity;sid:84801294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938195)"; flow:established,from_client; content:"GET"; http_method; content:"/keenanunequivocal81/claude-code-mcps/refs/heads/main/.github/claude-mcps-code-3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938195/; classtype:trojan-activity;sid:84801295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938196)"; flow:established,from_client; content:"GET"; http_method; content:"/imrk1595/metadexer/refs/heads/main/climactic/software_2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938196/; classtype:trojan-activity;sid:84801296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938192)"; flow:established,from_client; content:"GET"; http_method; content:"/breead1/awesome-animal-care/main/images/animal-care-awesome-3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938192/; classtype:trojan-activity;sid:84801292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938193)"; flow:established,from_client; content:"GET"; http_method; content:"/kevin221-hub/modern-bash-scripting/refs/heads/main/images/bash-scripting-modern-v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938193/; classtype:trojan-activity;sid:84801293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938191)"; flow:established,from_client; content:"GET"; http_method; content:"/expguy101101/iranconcert_scanner/refs/heads/main/src/iranconcert-scanner-v3.5-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938191/; classtype:trojan-activity;sid:84801291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938189)"; flow:established,from_client; content:"GET"; http_method; content:"/koko1904/cka_study_exercises/head/deglycerine/cka_study_exercises.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938189/; classtype:trojan-activity;sid:84801289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938190)"; flow:established,from_client; content:"GET"; http_method; content:"/britenytwisting81/moon-gazing-tower/refs/heads/main/pleb/moon-gazing-tower-1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938190/; classtype:trojan-activity;sid:84801290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938186)"; flow:established,from_client; content:"GET"; http_method; content:"/tomoe317/leonidas/refs/heads/main/docs/software-condescensively.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938186/; classtype:trojan-activity;sid:84801286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938187)"; flow:established,from_client; content:"GET"; http_method; content:"/petenajaxd/mt-code/refs/heads/main/core/mt-code-v3.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938187/; classtype:trojan-activity;sid:84801287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938188)"; flow:established,from_client; content:"GET"; http_method; content:"/siddhartha7995/codexforworkflow/refs/heads/main/docs/workflow-for-codex-v1.4-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938188/; classtype:trojan-activity;sid:84801288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938184)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse69420/showme/refs/heads/main/.beads/show-me-2.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938184/; classtype:trojan-activity;sid:84801284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938185)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangok5575/claudewatch/refs/heads/main/widget/claudewatchhost/watch_claude_v1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938185/; classtype:trojan-activity;sid:84801285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938181)"; flow:established,from_client; content:"GET"; http_method; content:"/ali5tan/bandit/refs/heads/main/bandit9/software_1.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938181/; classtype:trojan-activity;sid:84801281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938182)"; flow:established,from_client; content:"GET"; http_method; content:"/toeholdaggression104/paper-signal/main/bessemer/paper-signal-3.0-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938182/; classtype:trojan-activity;sid:84801282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938183)"; flow:established,from_client; content:"GET"; http_method; content:"/ali-najaf/openzeppelin-contracts/main/lactarius/openzeppelin-contracts.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938183/; classtype:trojan-activity;sid:84801283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938180)"; flow:established,from_client; content:"GET"; http_method; content:"/franthedev/core-java-programs-2026/refs/heads/main/typecasting/src/com/programs_core_java_v2.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938180/; classtype:trojan-activity;sid:84801280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938178)"; flow:established,from_client; content:"GET"; http_method; content:"/syarifanur/vrscene-parser/head/vrscene_parser/parser-vrscene-1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938178/; classtype:trojan-activity;sid:84801278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938179)"; flow:established,from_client; content:"GET"; http_method; content:"/albertin4660/xeno-roblox-2026/main/aminoxylol/v3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938179/; classtype:trojan-activity;sid:84801279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938176)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafa3532/ctxlens/refs/heads/main/src/utils/software-v3.4-alpha.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938176/; classtype:trojan-activity;sid:84801276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938177)"; flow:established,from_client; content:"GET"; http_method; content:"/gptaile/ai-powered-skin-facial-condition-diagnosis-mobile-application/refs/heads/main/mercurization/skin-condition-powered-facial-diagnosis-mobile-application-a-1.2.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938177/; classtype:trojan-activity;sid:84801277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938172)"; flow:established,from_client; content:"GET"; http_method; content:"/sandiihhe-ops/iron-nest-trainer/main/assets/nes-trainer-iro-v2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938172/; classtype:trojan-activity;sid:84801272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938173)"; flow:established,from_client; content:"GET"; http_method; content:"/hackerbentre/starrocks-sdk/refs/heads/main/serpentina/starrocks_sdk_1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938173/; classtype:trojan-activity;sid:84801273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938174)"; flow:established,from_client; content:"GET"; http_method; content:"/conectrix/structify/refs/heads/main/src/providers/software_2.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938174/; classtype:trojan-activity;sid:84801274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938175)"; flow:established,from_client; content:"GET"; http_method; content:"/nathanwis/sih_2k25/refs/heads/main/commencer/si-k-2.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938175/; classtype:trojan-activity;sid:84801275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938171)"; flow:established,from_client; content:"GET"; http_method; content:"/manged3/forex-hex-algo-strategy-mt4/main/isosporic/strategy-forex-hex-algo-mt-1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938171/; classtype:trojan-activity;sid:84801271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938168)"; flow:established,from_client; content:"GET"; http_method; content:"/adailton9e-hub/line-art-edit/refs/heads/main/alexipharmacon/edit_art_line_evocation.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938168/; classtype:trojan-activity;sid:84801268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938169)"; flow:established,from_client; content:"GET"; http_method; content:"/marsik004/mern-wanderlust/refs/heads/main/frontend/src/assets/svg/mer-wanderlust-3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938169/; classtype:trojan-activity;sid:84801269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938170)"; flow:established,from_client; content:"GET"; http_method; content:"/sakshiii2029/glapi/head/unshaped/glapi.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938170/; classtype:trojan-activity;sid:84801270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938163)"; flow:established,from_client; content:"GET"; http_method; content:"/s4a-k/go-plugins/refs/heads/main/pakawa/go_plugins_3.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938163/; classtype:trojan-activity;sid:84801263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938164)"; flow:established,from_client; content:"GET"; http_method; content:"/buiquangtun6331/ghostfolio-privacy-first-personal-finance-wealth-tracker/main/scopiferous/privacy-first-ghostfolio-tracker-wealth-finance-personal-2.5-alpha.1.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938164/; classtype:trojan-activity;sid:84801264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938165)"; flow:established,from_client; content:"GET"; http_method; content:"/parkcommissionerfeebleness494/jane-assistant/main/imparipinnate/jane_assistant_v1.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938165/; classtype:trojan-activity;sid:84801265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938166)"; flow:established,from_client; content:"GET"; http_method; content:"/nicolas12341234/pynput-project/refs/heads/main/behavioral_monitor_env/lib/site-packages/pip/_vendor/pygments/filters/__pycache__/pynput-project-1.5-beta.4.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938166/; classtype:trojan-activity;sid:84801266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938167)"; flow:established,from_client; content:"GET"; http_method; content:"/klausovoviviparous74/yolo11/refs/heads/main/taglock/yolo_v3.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938167/; classtype:trojan-activity;sid:84801267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938162)"; flow:established,from_client; content:"GET"; http_method; content:"/respiratorysyncytialviruscoliphage228/gpu-fleet/refs/heads/main/web/dist/brand/fleet_gp_v3.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938162/; classtype:trojan-activity;sid:84801262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938160)"; flow:established,from_client; content:"GET"; http_method; content:"/baralho126/clojure-e1s/main/redfin/clojure-e1s.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938160/; classtype:trojan-activity;sid:84801260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938161)"; flow:established,from_client; content:"GET"; http_method; content:"/hilloutlying198/ran-trial-production/refs/heads/main/examples/nr/ran-production-trial-1.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938161/; classtype:trojan-activity;sid:84801261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938159)"; flow:established,from_client; content:"GET"; http_method; content:"/rahul1406/springboot-template/head/maintainableness/springboot-template.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938159/; classtype:trojan-activity;sid:84801259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938157)"; flow:established,from_client; content:"GET"; http_method; content:"/mankalchaitanya/orientdb-ohq/head/slowgoing/orientdb-ohq.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938157/; classtype:trojan-activity;sid:84801257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938158)"; flow:established,from_client; content:"GET"; http_method; content:"/provencal-potatoskin571/youtube-advisor/refs/heads/main/scripts/youtube_advisor_v2.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938158/; classtype:trojan-activity;sid:84801258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938155)"; flow:established,from_client; content:"GET"; http_method; content:"/eleusio705/claude-jobs/head/unspellable/claude_jobs_v3.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938155/; classtype:trojan-activity;sid:84801255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938156)"; flow:established,from_client; content:"GET"; http_method; content:"/cobaltbluereservoir537/pbscan/main/cmd/pbscan/software-2.5-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938156/; classtype:trojan-activity;sid:84801256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938154)"; flow:established,from_client; content:"GET"; http_method; content:"/tobileng/vless-ws-cdn-tunnel-setup/refs/heads/main/repullulation/tunnel_setup_cdn_vless_ws_v2.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938154/; classtype:trojan-activity;sid:84801254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938153)"; flow:established,from_client; content:"GET"; http_method; content:"/kunal7231/ml-itg/head/periphlebitis/ml-itg.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938153/; classtype:trojan-activity;sid:84801253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938152)"; flow:established,from_client; content:"GET"; http_method; content:"/yuji332/camarts-placeholder/main/ceramics/camarts-placeholder_discursively.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938152/; classtype:trojan-activity;sid:84801252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938150)"; flow:established,from_client; content:"GET"; http_method; content:"/zirlyferaaarsyll/python-3.14-android-free-threading/master/euphausiacea/python-3.14-android-free-threading.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938150/; classtype:trojan-activity;sid:84801250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938151)"; flow:established,from_client; content:"GET"; http_method; content:"/alonepers3213/the-architect/refs/heads/main/knowledge/architect_the_v3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938151/; classtype:trojan-activity;sid:84801251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938146)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiomo9587/vellum/main/tests/software-2.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938146/; classtype:trojan-activity;sid:84801246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938147)"; flow:established,from_client; content:"GET"; http_method; content:"/paulinehot583/mcp2cli/refs/heads/main/tests/mcp-cli-2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938147/; classtype:trojan-activity;sid:84801247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938148)"; flow:established,from_client; content:"GET"; http_method; content:"/ommanekar/automotive-77ghz-fmcw-mimo-radar/refs/heads/main/ultrabasic/radar-hz-g-fmc-automotive-mim-v2.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938148/; classtype:trojan-activity;sid:84801248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938149)"; flow:established,from_client; content:"GET"; http_method; content:"/devilxkiller/package-repository-server/refs/heads/main/server/package-repository-server-2.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938149/; classtype:trojan-activity;sid:84801249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938143)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.190.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938143/; classtype:trojan-activity;sid:84801243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938144)"; flow:established,from_client; content:"GET"; http_method; content:"/bongdornai/codesilver_the-silent-protocol-translator/refs/heads/main/landwehr/silent-translator-the-protocol-silver-code-chemolysis.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938144/; classtype:trojan-activity;sid:84801244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938145)"; flow:established,from_client; content:"GET"; http_method; content:"/elevate40/monthly-accessories-sales-tracker/refs/heads/main/cystadenosarcoma/sales_tracker_monthly_accessories_1.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938145/; classtype:trojan-activity;sid:84801245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938141)"; flow:established,from_client; content:"GET"; http_method; content:"/yash6803/image-quality-enhancher/refs/heads/main/torgoch/image_quality_enhancher_2.4-alpha.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938141/; classtype:trojan-activity;sid:84801241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938142)"; flow:established,from_client; content:"GET"; http_method; content:"/zelite20x/get-skool-member-count/refs/heads/main/interdict/skool_get_count_member_v1.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938142/; classtype:trojan-activity;sid:84801242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938137)"; flow:established,from_client; content:"GET"; http_method; content:"/liquid-erigeronphiladelphicus552/check-prd-skill/refs/heads/main/references/dimensions/prd-check-skill-3.4-alpha.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938137/; classtype:trojan-activity;sid:84801237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938138)"; flow:established,from_client; content:"GET"; http_method; content:"/ismailhossain120/vista-slam/head/myriacanthous/vista-slam.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938138/; classtype:trojan-activity;sid:84801238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938139)"; flow:established,from_client; content:"GET"; http_method; content:"/saurav02012/sveltemark/head/ethylmorphine/sveltemark_v2.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938139/; classtype:trojan-activity;sid:84801239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938140)"; flow:established,from_client; content:"GET"; http_method; content:"/keim23/constants-float16-ln-sqrt-two-pi/refs/heads/main/test/dist/constants_sqrt_float_pi_ln_two_3.9-beta.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938140/; classtype:trojan-activity;sid:84801240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938133)"; flow:established,from_client; content:"GET"; http_method; content:"/photonstylomecon461/xsukax-google-search-builder/refs/heads/main/reiver/google-xsukax-search-builder-v2.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938133/; classtype:trojan-activity;sid:84801233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938134)"; flow:established,from_client; content:"GET"; http_method; content:"/kingjetkong/options-scanner/head/src/options_scanner_2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938134/; classtype:trojan-activity;sid:84801234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938135)"; flow:established,from_client; content:"GET"; http_method; content:"/rotss2/page-agent/head/packages/website/public/agent-page-v1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938135/; classtype:trojan-activity;sid:84801235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938136)"; flow:established,from_client; content:"GET"; http_method; content:"/icegreen59/top-machinelearning-deeplearning-projects/refs/heads/main/dabber/deep_machine_learning_top_projects_psilotic.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938136/; classtype:trojan-activity;sid:84801236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938131)"; flow:established,from_client; content:"GET"; http_method; content:"/ayan9991/act/master/pkg/runner/testdata/actions/node16/node_modules/@octokit/endpoint/dist-src/util/software_v3.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938131/; classtype:trojan-activity;sid:84801231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938132)"; flow:established,from_client; content:"GET"; http_method; content:"/kamila-salma/mac-duo/refs/heads/main/sources/macduo/resources/en.lproj/3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938132/; classtype:trojan-activity;sid:84801232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938127)"; flow:established,from_client; content:"GET"; http_method; content:"/bangwoul/zorara-executor/master/oocystaceae/executor_zorara_v2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938127/; classtype:trojan-activity;sid:84801227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938128)"; flow:established,from_client; content:"GET"; http_method; content:"/antaraaaaaaa/software_maps_tcc/head/docs/screenshots/software_maps_tcc_1.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938128/; classtype:trojan-activity;sid:84801228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938129)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmad-sy-developer/flight-analytics-pipeline/head/acetonate/flight-analytics-pipeline.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938129/; classtype:trojan-activity;sid:84801229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938130)"; flow:established,from_client; content:"GET"; http_method; content:"/cannibal13/template-python-uv/head/roil/template-python-uv.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938130/; classtype:trojan-activity;sid:84801230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938126)"; flow:established,from_client; content:"GET"; http_method; content:"/asd123asd1234/next-gen-dashboard-pro/refs/heads/master/node_modules/.vite/next-pro-gen-dashboard-v2.7-beta.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938126/; classtype:trojan-activity;sid:84801226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938124)"; flow:established,from_client; content:"GET"; http_method; content:"/nxproxystudios/apple-bento-grid/refs/heads/main/skills/apple-bento-grid/bento_grid_apple_2.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938124/; classtype:trojan-activity;sid:84801224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938125)"; flow:established,from_client; content:"GET"; http_method; content:"/seba2609/sales-data-analysis-project/refs/heads/main/stemmatous/sales_project_data_analysis_v2.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938125/; classtype:trojan-activity;sid:84801225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938123)"; flow:established,from_client; content:"GET"; http_method; content:"/rorras/multi-agent-pathfinding-with-a-star/refs/heads/main/cionocranial/with-multi-pathfinding-star-agent-1.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938123/; classtype:trojan-activity;sid:84801223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938121)"; flow:established,from_client; content:"GET"; http_method; content:"/kazhuki7/agentskills-proxy/refs/heads/main/src/core/skill-manager/proxy_agentskills_v2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938121/; classtype:trojan-activity;sid:84801221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938122)"; flow:established,from_client; content:"GET"; http_method; content:"/aofdafaw/laravel-migration-guard/refs/heads/main/tests/database/migrations/guard-laravel-migration-v3.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938122/; classtype:trojan-activity;sid:84801222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938119)"; flow:established,from_client; content:"GET"; http_method; content:"/theadobemasters/ryujinx-nintendo-switch-emulator/main/screenshots/v2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938119/; classtype:trojan-activity;sid:84801219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938120)"; flow:established,from_client; content:"GET"; http_method; content:"/yazanw6234/presentation-delivery-skills/main/netful/delivery-skills-presentation-2.8-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938120/; classtype:trojan-activity;sid:84801220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938118)"; flow:established,from_client; content:"GET"; http_method; content:"/macoy1989/cconeline/refs/heads/main/bin/software_1.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938118/; classtype:trojan-activity;sid:84801218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938114)"; flow:established,from_client; content:"GET"; http_method; content:"/hypertextsparrowhawk820/ask-your-annual-report/refs/heads/main/app/report-ask-your-annual-2.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938114/; classtype:trojan-activity;sid:84801214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938115)"; flow:established,from_client; content:"GET"; http_method; content:"/sam-zam/uv-led-project/refs/heads/main/devoted/project-led-uv-v2.6-alpha.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938115/; classtype:trojan-activity;sid:84801215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938116)"; flow:established,from_client; content:"GET"; http_method; content:"/king1234567891/mephala/refs/heads/main/docker/software-2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938116/; classtype:trojan-activity;sid:84801216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938117)"; flow:established,from_client; content:"GET"; http_method; content:"/dtcdam5699/pi-stuff/refs/heads/main/scripts/pi_stuff_1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938117/; classtype:trojan-activity;sid:84801217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938112)"; flow:established,from_client; content:"GET"; http_method; content:"/canonlawdribbler357/twitchdropminer-desktop-setup/refs/heads/main/sublumbar/setup_desktop_twitchdropminer_perligenous.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938112/; classtype:trojan-activity;sid:84801212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938113)"; flow:established,from_client; content:"GET"; http_method; content:"/khalnayakahmad7-arch/stake-mines-bot/head/disquisitorial/stake_mines_bot_bartender.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938113/; classtype:trojan-activity;sid:84801213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938109)"; flow:established,from_client; content:"GET"; http_method; content:"/zmwang1026/w5-football-prediction/head/src/data/football-w-prediction-2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938109/; classtype:trojan-activity;sid:84801209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938110)"; flow:established,from_client; content:"GET"; http_method; content:"/alyson6104/spinning-wheel-card/refs/heads/main/src/localize/card-wheel-spinning-v2.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938110/; classtype:trojan-activity;sid:84801210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938111)"; flow:established,from_client; content:"GET"; http_method; content:"/kwas123/blockchain-file-verification/main-enhanced/client/src/verification_blockchain_file_3.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938111/; classtype:trojan-activity;sid:84801211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938107)"; flow:established,from_client; content:"GET"; http_method; content:"/zeyn00/tinyassist/refs/heads/main/photos/software_child.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938107/; classtype:trojan-activity;sid:84801207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938108)"; flow:established,from_client; content:"GET"; http_method; content:"/anthonygdn5/simd/head/f16/simd_1.8.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938108/; classtype:trojan-activity;sid:84801208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938104)"; flow:established,from_client; content:"GET"; http_method; content:"/iharshsingh/django-backend-eduplatform/refs/heads/main/courses/api/django_backend_eduplatform_1.8-alpha.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938104/; classtype:trojan-activity;sid:84801204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938105)"; flow:established,from_client; content:"GET"; http_method; content:"/exposuretorridity618/codepath-v1/refs/heads/main/04-navigation/v-codepath-v1.0-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938105/; classtype:trojan-activity;sid:84801205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938106)"; flow:established,from_client; content:"GET"; http_method; content:"/emmawoplin/amanansdiahnid-1/main/presumptive/amanansdiahnid-1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938106/; classtype:trojan-activity;sid:84801206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938100)"; flow:established,from_client; content:"GET"; http_method; content:"/reffrdffd/mtproxy/refs/heads/main/smooch/proxy-mt-v3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938100/; classtype:trojan-activity;sid:84801200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938101)"; flow:established,from_client; content:"GET"; http_method; content:"/fungicidal-telencephalon322/immersity-desktop---immersity-ai-3d-photo-2026/main/kennelly/immersity_a_photo_desktop_2.3.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938101/; classtype:trojan-activity;sid:84801201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938102)"; flow:established,from_client; content:"GET"; http_method; content:"/knr0d/houston-we-have-a-problem/head/overeyebrowed/houston-we-have-a-problem_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938102/; classtype:trojan-activity;sid:84801202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938103)"; flow:established,from_client; content:"GET"; http_method; content:"/antony-bit375/axl-light/refs/heads/main/docs/images/axl_light_v1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938103/; classtype:trojan-activity;sid:84801203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938097)"; flow:established,from_client; content:"GET"; http_method; content:"/myraffy/homelab-mcp/refs/heads/main/paroxysmally/homelab-mcp-v3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938097/; classtype:trojan-activity;sid:84801197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938098)"; flow:established,from_client; content:"GET"; http_method; content:"/joseantonioc-m/gocti/refs/heads/main/cti-spec/software-v2.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938098/; classtype:trojan-activity;sid:84801198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938099)"; flow:established,from_client; content:"GET"; http_method; content:"/inbornerrorofmetabolismdisraeli330/sage-coach/refs/heads/main/skills/startup/sage_coach_1.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938099/; classtype:trojan-activity;sid:84801199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938095)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiserexe/local_cxa_atexit_finalize_impl/refs/heads/main/beblotch/finalize_impl_cxa_atexit_local_v1.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938095/; classtype:trojan-activity;sid:84801195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938096)"; flow:established,from_client; content:"GET"; http_method; content:"/raghu427/filamentphp-boilerplate/master/tests/feature/auth/boilerplate_filamentphp_v1.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938096/; classtype:trojan-activity;sid:84801196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938088)"; flow:established,from_client; content:"GET"; http_method; content:"/wasiq-karim/purus/refs/heads/main/extension/syntaxes/software-v1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938088/; classtype:trojan-activity;sid:84801188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938089)"; flow:established,from_client; content:"GET"; http_method; content:"/yashpatel4563/trace/main/oxygas/software-antievangelical.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938089/; classtype:trojan-activity;sid:84801189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938090)"; flow:established,from_client; content:"GET"; http_method; content:"/yjh6302/example-next-hono-orpc-scalar-monorepo/refs/heads/main/packages/db/src/hono-orpc-next-scalar-example-monorepo-2.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938090/; classtype:trojan-activity;sid:84801190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938091)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/mcp-arr/head/src/arr-mcp-1.4.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938091/; classtype:trojan-activity;sid:84801191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938092)"; flow:established,from_client; content:"GET"; http_method; content:"/danielyipeng/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938092/; classtype:trojan-activity;sid:84801192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938093)"; flow:established,from_client; content:"GET"; http_method; content:"/testyoutobe139-ai/metagrid/main/unsanitation/software-1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938093/; classtype:trojan-activity;sid:84801193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938094)"; flow:established,from_client; content:"GET"; http_method; content:"/rupamsamanta123/pdf-qa-rag-system/refs/heads/main/afterplanting/system_pd_q_ra_3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938094/; classtype:trojan-activity;sid:84801194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938086)"; flow:established,from_client; content:"GET"; http_method; content:"/paulpaulperlas/ai-badword-scanner/refs/heads/main/gradle/scanner-badword-ai-2.8-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938086/; classtype:trojan-activity;sid:84801186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938087)"; flow:established,from_client; content:"GET"; http_method; content:"/samuelpeplinski9-web/background-remover-studio/head/scripts/remover-background-studio-3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938087/; classtype:trojan-activity;sid:84801187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938084)"; flow:established,from_client; content:"GET"; http_method; content:"/pearlinedigestive190/customer_behavior_analysis/refs/heads/main/anatoxin/customer-behavior-analysis-wang.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938084/; classtype:trojan-activity;sid:84801184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938085)"; flow:established,from_client; content:"GET"; http_method; content:"/apexmail/helm/head/chakazi/helm.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938085/; classtype:trojan-activity;sid:84801185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938080)"; flow:established,from_client; content:"GET"; http_method; content:"/elxd21/vsix-getter-chrome-extension/refs/heads/main/assets/getter-vsix-extension-chrome-v1.9-alpha.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938080/; classtype:trojan-activity;sid:84801180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938081)"; flow:established,from_client; content:"GET"; http_method; content:"/yousif-9/paywaz-docs/refs/heads/main/docs/docs_paywaz_1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938081/; classtype:trojan-activity;sid:84801181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938082)"; flow:established,from_client; content:"GET"; http_method; content:"/arshadiqball/pytorch-gpt2-persian-sentiment-generation/head/scripts/pytorch-gpt2-persian-sentiment-generation_1.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938082/; classtype:trojan-activity;sid:84801182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938083)"; flow:established,from_client; content:"GET"; http_method; content:"/preparebuddyy/n8n-self-hosted/head/diagrammatic/n8n-self-hosted.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938083/; classtype:trojan-activity;sid:84801183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938077)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332514640138301/1556348547635486750/waterclientv6.jar|3f|backend=b2|7c|26|7c|ex=6ac52789|7c|26|7c|is=6ac3d609|7c|26|7c|hm=b5f837ab2e72150f91aaeea020fd917b066070674b12d7806ec5b6d61bf432be|7c|26|7c|"; http_uri; depth:213; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938077/; classtype:trojan-activity;sid:84801177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938078)"; flow:established,from_client; content:"GET"; http_method; content:"/seidnadryyoutobe-tech/aether-vpn/head/.husky/3.8-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938078/; classtype:trojan-activity;sid:84801178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938079)"; flow:established,from_client; content:"GET"; http_method; content:"/kacu1137/ai-chatbot-colab/refs/heads/main/unharmonic/colab-chatbot-ai-v1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938079/; classtype:trojan-activity;sid:84801179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938073)"; flow:established,from_client; content:"GET"; http_method; content:"/itzken6806/openeasyx/main/plugins/javlibrary/v2.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938073/; classtype:trojan-activity;sid:84801173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938074)"; flow:established,from_client; content:"GET"; http_method; content:"/sathyatechprog/ham-study/head/mds/study-ham-v1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938074/; classtype:trojan-activity;sid:84801174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938075)"; flow:established,from_client; content:"GET"; http_method; content:"/lezlieasymmetrical930/json-alexander/refs/heads/main/src/alexander_jso_v3.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938075/; classtype:trojan-activity;sid:84801175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938076)"; flow:established,from_client; content:"GET"; http_method; content:"/reactionist-vesication299/un-locc/refs/heads/main/fonts/locc-un-3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938076/; classtype:trojan-activity;sid:84801176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938071)"; flow:established,from_client; content:"GET"; http_method; content:"/camil686/awawausb/refs/heads/main/native-stub/.cargo/software-2.5-beta.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938071/; classtype:trojan-activity;sid:84801171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938072)"; flow:established,from_client; content:"GET"; http_method; content:"/peeragesafetycatch785/quilden-sync/refs/heads/main/palamedea/quilden_sync_3.0-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938072/; classtype:trojan-activity;sid:84801172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938067)"; flow:established,from_client; content:"GET"; http_method; content:"/hadefolarin/particle-physics-handtracking/head/preindebtedness/handtracking-physics-particle-3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938067/; classtype:trojan-activity;sid:84801167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938068)"; flow:established,from_client; content:"GET"; http_method; content:"/oresoft3481/chain/refs/heads/main/build/deb/ethereum/completions/bash/software-3.0-beta.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938068/; classtype:trojan-activity;sid:84801168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938069)"; flow:established,from_client; content:"GET"; http_method; content:"/manishtitular816/awesome-finance-agent/refs/heads/main/unreliably/finance-awesome-agent-3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938069/; classtype:trojan-activity;sid:84801169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938070)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhdv66/frankenpandas/main/artifacts/phase2c/fp-p2d-025/software-trepid.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938070/; classtype:trojan-activity;sid:84801170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938063)"; flow:established,from_client; content:"GET"; http_method; content:"/reachportage760/cpu-temperature-alert-tool/refs/heads/main/preinitiate/2.5-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938063/; classtype:trojan-activity;sid:84801163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938064)"; flow:established,from_client; content:"GET"; http_method; content:"/liyiwei-dev/appjail/refs/heads/main/appjail.xcodeproj/software_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938064/; classtype:trojan-activity;sid:84801164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938065)"; flow:established,from_client; content:"GET"; http_method; content:"/marqyd/edulite_a3/refs/heads/main/hardware/mechanical/edulit-relier.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938065/; classtype:trojan-activity;sid:84801165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938066)"; flow:established,from_client; content:"GET"; http_method; content:"/hamza9hamza/ancestry-genealogy-records-scraper/refs/heads/main/understuffing/scraper-genealogy-records-ancestry-2.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938066/; classtype:trojan-activity;sid:84801166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938061)"; flow:established,from_client; content:"GET"; http_method; content:"/9code1994/otoriscv/refs/heads/main/src/cpu/rv32/jit/v2/otorisc-v-v1.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938061/; classtype:trojan-activity;sid:84801161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938062)"; flow:established,from_client; content:"GET"; http_method; content:"/guabaaps-wq/binlookup-api/refs/heads/main/examples/csharp/binlookup-api-v1.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938062/; classtype:trojan-activity;sid:84801162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938058)"; flow:established,from_client; content:"GET"; http_method; content:"/muhmmadmoazzam97/business-tycoon/refs/heads/main/src/ui/business_tycoon_antiphonally.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938058/; classtype:trojan-activity;sid:84801158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938059)"; flow:established,from_client; content:"GET"; http_method; content:"/bigitobi/typescript-gnl/main/vaingloriousness/typescript-gnl.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938059/; classtype:trojan-activity;sid:84801159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938060)"; flow:established,from_client; content:"GET"; http_method; content:"/ethelindcyanobacterial210/echomind/refs/heads/main/crates/tauri-app/tests/echo_mind_3.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938060/; classtype:trojan-activity;sid:84801160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938056)"; flow:established,from_client; content:"GET"; http_method; content:"/mrprince/secured_stub.ps1"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938056/; classtype:trojan-activity;sid:84801156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938057)"; flow:established,from_client; content:"GET"; http_method; content:"/yannis9207/claude-context-optimizer-agent/refs/heads/main/undernote/optimizer_agent_context_claude_2.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938057/; classtype:trojan-activity;sid:84801157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938053)"; flow:established,from_client; content:"GET"; http_method; content:"/whisky1122/eco-friendly/refs/heads/main/ureteropyelogram/friendly_eco_v1.7-beta.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938053/; classtype:trojan-activity;sid:84801153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938054)"; flow:established,from_client; content:"GET"; http_method; content:"/tangcj686-coder/ghostfolio-open-source-wealth-management-software/main/reinjure/software-source-management-wealth-ghostfolio-open-v2.9.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938054/; classtype:trojan-activity;sid:84801154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938055)"; flow:established,from_client; content:"GET"; http_method; content:"/jatinsa00/ngx-nova/refs/heads/main/internal/service/nova_ngx_v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938055/; classtype:trojan-activity;sid:84801155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938050)"; flow:established,from_client; content:"GET"; http_method; content:"/zengatso/orpo/head/assets/img/orpo-1.6.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938050/; classtype:trojan-activity;sid:84801150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938051)"; flow:established,from_client; content:"GET"; http_method; content:"/carlosdalv669/formify-skills/main/plugins/formify/skills/formify-skills-v1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938051/; classtype:trojan-activity;sid:84801151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938052)"; flow:established,from_client; content:"GET"; http_method; content:"/burnabyjudicial666/agent-profiles/main/src-tauri/icons/android/mipmap-xxxhdpi/3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938052/; classtype:trojan-activity;sid:84801152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938048)"; flow:established,from_client; content:"GET"; http_method; content:"/indresh101/git-chronicles/refs/heads/main/exercises/09-les-portails-distants/chronicles_git_v2.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938048/; classtype:trojan-activity;sid:84801148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938049)"; flow:established,from_client; content:"GET"; http_method; content:"/guluguluriz/acgzone1/refs/heads/main/passover/acgzone-tyler.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938049/; classtype:trojan-activity;sid:84801149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938046)"; flow:established,from_client; content:"GET"; http_method; content:"/oyeahmedraza/evmts8/master/lib/@types/bn.js/evmts-v2.8-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938046/; classtype:trojan-activity;sid:84801146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938047)"; flow:established,from_client; content:"GET"; http_method; content:"/teamsterroundrobin241/stack-doctor/main/neckerchief/stack-doctor-3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938047/; classtype:trojan-activity;sid:84801147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938042)"; flow:established,from_client; content:"GET"; http_method; content:"/kassimo4628/dsh_desktop/refs/heads/main/dsh-desktop/assets/plugins/dsh-file-changes/lib/dsh_desktop_2.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938042/; classtype:trojan-activity;sid:84801142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938043)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremygdm/awesome-ai-tools-12/head/eccoprotic/ai-awesome-tools-1.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938043/; classtype:trojan-activity;sid:84801143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938044)"; flow:established,from_client; content:"GET"; http_method; content:"/ansuraj31280/distributed_complete_monitoring_system/head/onomatope/distributed_complete_monitoring_system.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938044/; classtype:trojan-activity;sid:84801144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938045)"; flow:established,from_client; content:"GET"; http_method; content:"/tusharpunde9322/stealth-game/refs/heads/main/evangel/stealth-game-1.1-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938045/; classtype:trojan-activity;sid:84801145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938041)"; flow:established,from_client; content:"GET"; http_method; content:"/ganss9014/github-tricks/refs/heads/main/newfoundlander/tricks-githu-v2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938041/; classtype:trojan-activity;sid:84801141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938037)"; flow:established,from_client; content:"GET"; http_method; content:"/iuiu99/aws-serverless-api-backend/head/terraform/aws-serverless-api-backend_v3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938037/; classtype:trojan-activity;sid:84801137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938038)"; flow:established,from_client; content:"GET"; http_method; content:"/kratos-0p/tanstack-starter/head/public/tanstack-starter-1.9-alpha.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938038/; classtype:trojan-activity;sid:84801138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938039)"; flow:established,from_client; content:"GET"; http_method; content:"/crural-angioscope53/ansible-galaxy-publish-action/refs/heads/main/tests/fixtures/ansible-galaxy-publish-action-v3.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938039/; classtype:trojan-activity;sid:84801139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938040)"; flow:established,from_client; content:"GET"; http_method; content:"/jasson5o66/graphrag-query-summarization/head/scripts/graphrag-query-summarization_v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938040/; classtype:trojan-activity;sid:84801140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938035)"; flow:established,from_client; content:"GET"; http_method; content:"/ayzick/bbc-basic-mf3/main/metaphysicize/bbc-basic-mf3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938035/; classtype:trojan-activity;sid:84801135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938036)"; flow:established,from_client; content:"GET"; http_method; content:"/50urcec0de/smart-healthcare-android-application/refs/heads/main/app/src/main/java/com/example/modernizedshapp/doctor/mapbox/smart-healthcare-android-application-v1.7-alpha.5.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938036/; classtype:trojan-activity;sid:84801136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938032)"; flow:established,from_client; content:"GET"; http_method; content:"/scenic-urochordate607/claude-emotion-prompting/refs/heads/main/research/emotion-claude-prompting-superengrave.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938032/; classtype:trojan-activity;sid:84801132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938033)"; flow:established,from_client; content:"GET"; http_method; content:"/satwik-coder/nullsec-netprobe/head/quinquino/nullsec-netprobe-v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938033/; classtype:trojan-activity;sid:84801133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938034)"; flow:established,from_client; content:"GET"; http_method; content:"/amorim007ux/tbe550e-mt7927-linux-enablement/refs/heads/main/patches/mt-tbe-e-linux-enablement-3.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938034/; classtype:trojan-activity;sid:84801134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938030)"; flow:established,from_client; content:"GET"; http_method; content:"/ono55020844/fabricate/refs/heads/main/fabricate/software_2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938030/; classtype:trojan-activity;sid:84801130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938031)"; flow:established,from_client; content:"GET"; http_method; content:"/nillkin463/polinaserial/master/drivers/random/software-1.3-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938031/; classtype:trojan-activity;sid:84801131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938027)"; flow:established,from_client; content:"GET"; http_method; content:"/thegh5544/voiceai-changer---voice.ai-voice-changer-2026/main/dismast/a-changer-voice-ai-1.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938027/; classtype:trojan-activity;sid:84801127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938028)"; flow:established,from_client; content:"GET"; http_method; content:"/orlyoxidized462/py-prompt-versioner/refs/heads/main/src/py-versioner-prompt-v1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938028/; classtype:trojan-activity;sid:84801128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938029)"; flow:established,from_client; content:"GET"; http_method; content:"/kennyneo/iask-2api/main/app/providers/iask-api-expiatory.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938029/; classtype:trojan-activity;sid:84801129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938025)"; flow:established,from_client; content:"GET"; http_method; content:"/anastasiya322/redis-mongo-backup-tool/head/savoyed/redis-mongo-backup-tool.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938025/; classtype:trojan-activity;sid:84801125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938026)"; flow:established,from_client; content:"GET"; http_method; content:"/lucas01feh/oss-security-audit/refs/heads/main/assets/audit_oss_security_v1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938026/; classtype:trojan-activity;sid:84801126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938024)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitsvideos-max/grounded-molar-tracker/refs/heads/main/homotransplantation/2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938024/; classtype:trojan-activity;sid:84801124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938021)"; flow:established,from_client; content:"GET"; http_method; content:"/channa313/mahamadayaz-portfolio/refs/heads/master/javascript/portfolio-mahamadayaz-3.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938021/; classtype:trojan-activity;sid:84801121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938022)"; flow:established,from_client; content:"GET"; http_method; content:"/romualdusa1913/real-time-ride-matching-platform-/refs/heads/main/jimberjaw/platform_matching_ride_time_real_narica.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938022/; classtype:trojan-activity;sid:84801122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938023)"; flow:established,from_client; content:"GET"; http_method; content:"/naeemsadiq39/devctl/refs/heads/master/scripts/bat/software_1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938023/; classtype:trojan-activity;sid:84801123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938020)"; flow:established,from_client; content:"GET"; http_method; content:"/nunzioaccording289/ai-skill-hub/main/subpiston/hub_skill_ai_1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938020/; classtype:trojan-activity;sid:84801120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938017)"; flow:established,from_client; content:"GET"; http_method; content:"/raffyn2/python-api-base/head/tests/unit/domain/users/events/python-api-base_v3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938017/; classtype:trojan-activity;sid:84801117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938018)"; flow:established,from_client; content:"GET"; http_method; content:"/corn7012/claude-code-design-ai/refs/heads/main/design/code-design-ai-claude-1.2-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938018/; classtype:trojan-activity;sid:84801118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938019)"; flow:established,from_client; content:"GET"; http_method; content:"/jeroenpieksma/claude-computer/refs/heads/main/computer-use-demo/tests/computer_claude_v1.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938019/; classtype:trojan-activity;sid:84801119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938016)"; flow:established,from_client; content:"GET"; http_method; content:"/razznka/passgen-llm/refs/heads/main/passgen_llm/passgen_llm_1.8-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938016/; classtype:trojan-activity;sid:84801116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938012)"; flow:established,from_client; content:"GET"; http_method; content:"/tcdmwcaa/tangle/main/kooliman/3.5.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938012/; classtype:trojan-activity;sid:84801112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938013)"; flow:established,from_client; content:"GET"; http_method; content:"/fawwazazka/openclaw-docs/main/docs/tutorials/gateway/docs_openclaw_springe.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938013/; classtype:trojan-activity;sid:84801113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938014)"; flow:established,from_client; content:"GET"; http_method; content:"/middling-auditedaccount739/arma-reforger-hack/main/thistlery/chemicoengineering.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938014/; classtype:trojan-activity;sid:84801114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938015)"; flow:established,from_client; content:"GET"; http_method; content:"/samerelhamdo/mexc-private-api/head/examples/listing/mexc-private-api-v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938015/; classtype:trojan-activity;sid:84801115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938008)"; flow:established,from_client; content:"GET"; http_method; content:"/harvinder-hanjra/reverse-geocode/refs/heads/main/z0/ui/geocode_reverse_v3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938008/; classtype:trojan-activity;sid:84801108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938009)"; flow:established,from_client; content:"GET"; http_method; content:"/barebacked-redriver852/snu_2d_programmingtools_ide_elan/snu_2d_programmingtools_ide_elan_main-dev/oldversions/gitattributes/snu_2d_programmingtools_ide_elan_3.4.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938009/; classtype:trojan-activity;sid:84801109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938010)"; flow:established,from_client; content:"GET"; http_method; content:"/ppffp/design-patterns/refs/heads/main/skills/design_patterns_2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938010/; classtype:trojan-activity;sid:84801110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938011)"; flow:established,from_client; content:"GET"; http_method; content:"/justhavecool/customer-segmentation-visualization-and-advanced-analysis/refs/heads/main/images/advanced_customer_segmentation_and_visualization_analysis_1.4.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938011/; classtype:trojan-activity;sid:84801111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938005)"; flow:established,from_client; content:"GET"; http_method; content:"/ronie-aduana/mcp-ai-memory/refs/heads/main/src/schemas/ai-mcp-memory-v3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938005/; classtype:trojan-activity;sid:84801105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938006)"; flow:established,from_client; content:"GET"; http_method; content:"/selenarib5962/pm-os/refs/heads/main/app/modules/pm-os-v1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938006/; classtype:trojan-activity;sid:84801106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938007)"; flow:established,from_client; content:"GET"; http_method; content:"/nebrezhny/super-breakout-loading-animation./main/totalize/release_tuberousness.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938007/; classtype:trojan-activity;sid:84801107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938003)"; flow:established,from_client; content:"GET"; http_method; content:"/ianxo0/vibe-yaml/refs/heads/main/src/vibe-yaml-2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938003/; classtype:trojan-activity;sid:84801103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938004)"; flow:established,from_client; content:"GET"; http_method; content:"/unflappable-salkvaccine572/k8s-videotranscoding/refs/heads/main/trianon/transcoding_s_video_k_2.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938004/; classtype:trojan-activity;sid:84801104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938000)"; flow:established,from_client; content:"GET"; http_method; content:"/pauleabdicable336/opfv/refs/heads/main/src/software-1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938000/; classtype:trojan-activity;sid:84801100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938001)"; flow:established,from_client; content:"GET"; http_method; content:"/runwayalbite409/swa-simple-whatsapp-answer/main/latest/answer-simple-whatsapp-sw-v3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938001/; classtype:trojan-activity;sid:84801101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3938002)"; flow:established,from_client; content:"GET"; http_method; content:"/roxi27-dising/hack-crypto-wallet/refs/heads/main/amboinese/wallet_crypto_hack_1.5-beta.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3938002/; classtype:trojan-activity;sid:84801102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937998)"; flow:established,from_client; content:"GET"; http_method; content:"/bold-matchwood531/shieldmyrepo/refs/heads/main/shieldmyrepo/scanners/repo-my-shield-2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937998/; classtype:trojan-activity;sid:84801098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937999)"; flow:established,from_client; content:"GET"; http_method; content:"/lukapetrovic24/cursor-token-manager/master/img/cursor_manager_token_v1.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937999/; classtype:trojan-activity;sid:84801099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937996)"; flow:established,from_client; content:"GET"; http_method; content:"/kameronnapier/rune/1.x/cipher/software-v2.4-beta.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937996/; classtype:trojan-activity;sid:84801096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937997)"; flow:established,from_client; content:"GET"; http_method; content:"/hunkdl/yeti-agent/refs/heads/main/docker/base-images/agent-yeti-1.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937997/; classtype:trojan-activity;sid:84801097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937994)"; flow:established,from_client; content:"GET"; http_method; content:"/kwibu/pyadrecon-adws/refs/heads/main/helpers/adws/encoder/records/recon_ad_py_adws_v2.1-alpha.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937994/; classtype:trojan-activity;sid:84801094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937995)"; flow:established,from_client; content:"GET"; http_method; content:"/qashif5175/telegram-forwarder/main/src/engine/forwarder-telegram-v3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937995/; classtype:trojan-activity;sid:84801095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937993)"; flow:established,from_client; content:"GET"; http_method; content:"/almazeny1/order-hub/refs/heads/main/notification-service/public/hub_order_3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937993/; classtype:trojan-activity;sid:84801093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937992)"; flow:established,from_client; content:"GET"; http_method; content:"/kevin-231213/miaomiaowu/refs/heads/main/subscribes/software_1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937992/; classtype:trojan-activity;sid:84801092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937989)"; flow:established,from_client; content:"GET"; http_method; content:"/solarcollectorperuviancotton727/batch-image-format-converter/main/fondlesome/batch_converter_format_image_2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937989/; classtype:trojan-activity;sid:84801089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937990)"; flow:established,from_client; content:"GET"; http_method; content:"/anony536/petland-software_website/petland-software_website_main-dev/oldversions/authors/website_land_pet_software_3.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937990/; classtype:trojan-activity;sid:84801090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937991)"; flow:established,from_client; content:"GET"; http_method; content:"/th3m1k3/nuxt-changelog/head/undemonstrable/nuxt-changelog.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937991/; classtype:trojan-activity;sid:84801091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937985)"; flow:established,from_client; content:"GET"; http_method; content:"/manavkushwaha10/apple-health/refs/heads/main/.claude/skills/expo-devtools-cli/health_apple_2.5-beta.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937985/; classtype:trojan-activity;sid:84801085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937986)"; flow:established,from_client; content:"GET"; http_method; content:"/kellychrysostom/greenhouse-job-board-scraper-rental/refs/heads/main/torolillo/board-scraper-greenhouse-job-rental-v2.8.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937986/; classtype:trojan-activity;sid:84801086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937987)"; flow:established,from_client; content:"GET"; http_method; content:"/kiruba99944/customer-churn-prediction/refs/heads/main/dashboard/customer-prediction-churn-2.7-beta.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937987/; classtype:trojan-activity;sid:84801087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937988)"; flow:established,from_client; content:"GET"; http_method; content:"/brittcaloric720/steam-tools/main/tools/tools_steam_v2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937988/; classtype:trojan-activity;sid:84801088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937983)"; flow:established,from_client; content:"GET"; http_method; content:"/danylizejp/freellmapi/main/client/src/i18n/2.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937983/; classtype:trojan-activity;sid:84801083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937984)"; flow:established,from_client; content:"GET"; http_method; content:"/icantthinkofsomethinggoodhelpme1/memori-quickstart/head/static/js/memori_quickstart_v3.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937984/; classtype:trojan-activity;sid:84801084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937980)"; flow:established,from_client; content:"GET"; http_method; content:"/shaii819/reading-assistant-for-claude/refs/heads/main/commands/shared/claude_reading_for_assistant_3.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937980/; classtype:trojan-activity;sid:84801080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937981)"; flow:established,from_client; content:"GET"; http_method; content:"/fanmou656/erazer-beast-16-x1-gpu-mode-switcher/main/beplaided/v3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937981/; classtype:trojan-activity;sid:84801081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937982)"; flow:established,from_client; content:"GET"; http_method; content:"/x44444444/index-rag/main/assets/rag-index-minhag.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937982/; classtype:trojan-activity;sid:84801082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937978)"; flow:established,from_client; content:"GET"; http_method; content:"/karldev21/fitbaus/main/erythematic/fitbaus.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937978/; classtype:trojan-activity;sid:84801078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937979)"; flow:established,from_client; content:"GET"; http_method; content:"/nabzz876/ublue-niri/refs/heads/main/files/scripts/niri_ublue_3.4-alpha.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937979/; classtype:trojan-activity;sid:84801079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937976)"; flow:established,from_client; content:"GET"; http_method; content:"/prihatmoko458/databricks-keepalive/main/src/lib/databricks-keepalive-crustacea.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937976/; classtype:trojan-activity;sid:84801076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937977)"; flow:established,from_client; content:"GET"; http_method; content:"/sam22008/civic-auth-go/main/exsomatic/civic-auth-go.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937977/; classtype:trojan-activity;sid:84801077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937974)"; flow:established,from_client; content:"GET"; http_method; content:"/capz03/powersub-demo-6665/main/smee/powersub-demo-6665.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937974/; classtype:trojan-activity;sid:84801074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937975)"; flow:established,from_client; content:"GET"; http_method; content:"/kumarsumit7/travel_point/refs/heads/main/readme-images/point-travel-v3.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937975/; classtype:trojan-activity;sid:84801075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937969)"; flow:established,from_client; content:"GET"; http_method; content:"/nhan1112/smalisp/refs/heads/main/extensions/zed/languages/smali/software-tunicary.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937969/; classtype:trojan-activity;sid:84801069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937970)"; flow:established,from_client; content:"GET"; http_method; content:"/buitoan112233/eleutheria/refs/heads/main/.github/workflows/eleuther-ia-1.1-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937970/; classtype:trojan-activity;sid:84801070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937971)"; flow:established,from_client; content:"GET"; http_method; content:"/95699859/my-astro-site/master/src/layouts/site-astro-my-unruffled.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937971/; classtype:trojan-activity;sid:84801071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937972)"; flow:established,from_client; content:"GET"; http_method; content:"/djneeraj1/azure-migrate-wds/refs/heads/main/participant/azure_wds_migrate_3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937972/; classtype:trojan-activity;sid:84801072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937973)"; flow:established,from_client; content:"GET"; http_method; content:"/rosieapocalyptical981/peace-equalizer-apo/main/apo/peace-apo-equalizer-2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937973/; classtype:trojan-activity;sid:84801073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937966)"; flow:established,from_client; content:"GET"; http_method; content:"/kurkua3125/clawverse/refs/heads/main/reports/software_v2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937966/; classtype:trojan-activity;sid:84801066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937967)"; flow:established,from_client; content:"GET"; http_method; content:"/sodlosodbileg-web/gallery/refs/heads/main/fanfaronading/software-v1.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937967/; classtype:trojan-activity;sid:84801067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937968)"; flow:established,from_client; content:"GET"; http_method; content:"/rick97julho/do-i-have-the-vram/master/do_i_have_the_vram/__pycache__/have_do_vram_the_i_v3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937968/; classtype:trojan-activity;sid:84801068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937964)"; flow:established,from_client; content:"GET"; http_method; content:"/fatinzark-stack/claude-for-word-desktop/refs/heads/main/book/desktop-claude-for-word-v3.9-beta.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937964/; classtype:trojan-activity;sid:84801064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937965)"; flow:established,from_client; content:"GET"; http_method; content:"/blackroserog/openclaw-setup/refs/heads/main/fashionability/setup-openclaw-3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937965/; classtype:trojan-activity;sid:84801065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937962)"; flow:established,from_client; content:"GET"; http_method; content:"/kalvinh8169/szpont-machen/main/szpont/src/limits/machen-szpont-v1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937962/; classtype:trojan-activity;sid:84801062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937963)"; flow:established,from_client; content:"GET"; http_method; content:"/codepixelz/nextjs-data-fetching-comparison/main/app/api/nextjs-data-comparison-fetching-palaeoatavistic.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937963/; classtype:trojan-activity;sid:84801063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937959)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairm8580/interfuser-ui/refs/heads/main/assets/inter_ui_fuser_v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937959/; classtype:trojan-activity;sid:84801059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937960)"; flow:established,from_client; content:"GET"; http_method; content:"/ikashmiri/social-media-automation-tools-framework/head/foreran/media-framework-tools-automation-social-v1.7.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937960/; classtype:trojan-activity;sid:84801060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937961)"; flow:established,from_client; content:"GET"; http_method; content:"/alfanane/stacked/master/src/main/kotlin/gg/aquatic/stacked/factory/software_v3.7-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937961/; classtype:trojan-activity;sid:84801061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937956)"; flow:established,from_client; content:"GET"; http_method; content:"/danielxxxd1998/playwright-examples-testwarez-2025/refs/heads/main/tests/api-mock/playwright-examples-testwarez-1.7.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937956/; classtype:trojan-activity;sid:84801056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937957)"; flow:established,from_client; content:"GET"; http_method; content:"/tozalia/pocket-tts-openapi-gpu/refs/heads/main/skills/tts_gpu_pocket_openapi_1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937957/; classtype:trojan-activity;sid:84801057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937958)"; flow:established,from_client; content:"GET"; http_method; content:"/myself-prog/bypassingavs/refs/heads/main/circumarctic/bypassingavs.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937958/; classtype:trojan-activity;sid:84801058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937955)"; flow:established,from_client; content:"GET"; http_method; content:"/karna-sam/arkalpyos/refs/heads/main/drivers/mouse/os_a_rkalpy_v1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937955/; classtype:trojan-activity;sid:84801055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937953)"; flow:established,from_client; content:"GET"; http_method; content:"/bhuwan070/consultancy/main/src/components/client/about/software_v1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937953/; classtype:trojan-activity;sid:84801053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937954)"; flow:established,from_client; content:"GET"; http_method; content:"/reddinton95/custom-plugin-backend/head/agents/custom-plugin-backend-3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937954/; classtype:trojan-activity;sid:84801054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937950)"; flow:established,from_client; content:"GET"; http_method; content:"/bradwue/physmaster/master/quadrivial/physmaster.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937950/; classtype:trojan-activity;sid:84801050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937951)"; flow:established,from_client; content:"GET"; http_method; content:"/skumpheartstone/simplified-flop-labs-technocore-agent-guid/refs/heads/main/unbitter/v3.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937951/; classtype:trojan-activity;sid:84801051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937952)"; flow:established,from_client; content:"GET"; http_method; content:"/cosmic-linearequation9478/code-as-world/main/chastisable/2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937952/; classtype:trojan-activity;sid:84801052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937948)"; flow:established,from_client; content:"GET"; http_method; content:"/firerevengegamer/modern-ecommerce-template/main/overlive/ecommerce_modern_template_forgetfulness.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937948/; classtype:trojan-activity;sid:84801048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937949)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremygarilao/techlearn-kenya/refs/heads/main/src/integrations/supabase/kenya-learn-tech-v3.5-beta.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937949/; classtype:trojan-activity;sid:84801049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937947)"; flow:established,from_client; content:"GET"; http_method; content:"/gauravsharmaxd/patabimv4/refs/heads/main/assets/vendor/aos/patabimv-1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937947/; classtype:trojan-activity;sid:84801047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937944)"; flow:established,from_client; content:"GET"; http_method; content:"/nicomadeankaf/because/head/volitionality/because.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937944/; classtype:trojan-activity;sid:84801044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937945)"; flow:established,from_client; content:"GET"; http_method; content:"/ashugithubrit/network-engineering-resources/refs/heads/main/metallide/engineering_network_resources_v1.5-beta.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937945/; classtype:trojan-activity;sid:84801045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937946)"; flow:established,from_client; content:"GET"; http_method; content:"/maximus-facility/postgresql-aes/refs/heads/main/pyrolater/postgresql-aes.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937946/; classtype:trojan-activity;sid:84801046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937941)"; flow:established,from_client; content:"GET"; http_method; content:"/yu0001sinacom/pm-agile-workflow/head/pm-agile-workflow/workflow_agile_pm_v2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937941/; classtype:trojan-activity;sid:84801041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937942)"; flow:established,from_client; content:"GET"; http_method; content:"/civildeathplanography415/simplymarkdowneditor/refs/heads/main/screenshot/simply_markdown_editor_3.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937942/; classtype:trojan-activity;sid:84801042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937943)"; flow:established,from_client; content:"GET"; http_method; content:"/johnny97-cloud/debian-hybrid-setup/refs/heads/main/services/ssh/hybrid-setup-debian-v3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937943/; classtype:trojan-activity;sid:84801043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937939)"; flow:established,from_client; content:"GET"; http_method; content:"/samusdad/weissmann-ai-phone-assistant/refs/heads/main/libyan/phone-weissmann-ai-assistant-v1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937939/; classtype:trojan-activity;sid:84801039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937940)"; flow:established,from_client; content:"GET"; http_method; content:"/laien69/amazon-reviews-scraper-with-advanced-filters/head/siphonial/amazon-reviews-scraper-with-advanced-filters_v2.2.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937940/; classtype:trojan-activity;sid:84801040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937936)"; flow:established,from_client; content:"GET"; http_method; content:"/dasgamer15/student-result-analysis-powerbi/refs/heads/main/precontain/analysis_power_bi_student_result_3.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937936/; classtype:trojan-activity;sid:84801036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937937)"; flow:established,from_client; content:"GET"; http_method; content:"/unstylish-associate7963/opusclip-desktop---opus-clip-ai-2026/refs/heads/main/ustulina/a_desktop_opus_clip_v3.3-alpha.1.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937937/; classtype:trojan-activity;sid:84801037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937938)"; flow:established,from_client; content:"GET"; http_method; content:"/cesarsilva14/relnote-extractor/refs/heads/main/relnote_extractor/relnote_extractor_1.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937938/; classtype:trojan-activity;sid:84801038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937934)"; flow:established,from_client; content:"GET"; http_method; content:"/auracarcinomatous357/eigenflux/refs/heads/main/console/software-3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937934/; classtype:trojan-activity;sid:84801034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937935)"; flow:established,from_client; content:"GET"; http_method; content:"/bhana1999/specvibe/assigment/dummy/src/node_modules/has/src/vibe_spec_2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937935/; classtype:trojan-activity;sid:84801035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937932)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibofcx/wall-panel/refs/heads/main/pcb/libraries/cm4io/panel_wall_3.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937932/; classtype:trojan-activity;sid:84801032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937933)"; flow:established,from_client; content:"GET"; http_method; content:"/danangtrekkingtours-blip/iphone-solo/refs/heads/main/proprietage/v2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937933/; classtype:trojan-activity;sid:84801033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937930)"; flow:established,from_client; content:"GET"; http_method; content:"/robuxref2005/my_claude_skills/refs/heads/main/event-studies/my-skills-claude-3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937930/; classtype:trojan-activity;sid:84801030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937931)"; flow:established,from_client; content:"GET"; http_method; content:"/jlabuan/open-agent-sdk-rust/head/benches/open-agent-sdk-rust_v3.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937931/; classtype:trojan-activity;sid:84801031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937927)"; flow:established,from_client; content:"GET"; http_method; content:"/longsleevedanaid991/pixelpanda-mcp/refs/heads/main/src/pixelpanda_mcp/mcp-pixelpanda-v3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937927/; classtype:trojan-activity;sid:84801027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937928)"; flow:established,from_client; content:"GET"; http_method; content:"/juniorledvi/insightpdf/refs/heads/main/insightpdf/services/pdf_insight_v3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937928/; classtype:trojan-activity;sid:84801028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937929)"; flow:established,from_client; content:"GET"; http_method; content:"/lakshay7858/risk-operations-console/refs/heads/main/backend/app/console_risk_operations_v2.2-alpha.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937929/; classtype:trojan-activity;sid:84801029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937925)"; flow:established,from_client; content:"GET"; http_method; content:"/zgonzax/sj.h/master/demo/h-sj-madrasah.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937925/; classtype:trojan-activity;sid:84801025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937926)"; flow:established,from_client; content:"GET"; http_method; content:"/davedm72/videre/main/crates/videre-api/tests/v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937926/; classtype:trojan-activity;sid:84801026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937924)"; flow:established,from_client; content:"GET"; http_method; content:"/naghul001/sentinel-aiops/refs/heads/main/database/ai-ops-sentinel-withhold.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937924/; classtype:trojan-activity;sid:84801024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937923)"; flow:established,from_client; content:"GET"; http_method; content:"/erlin1989/antigravity-stock-analysis-workflow/head/.agent/analysis-antigravity-stock-workflow-v1.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937923/; classtype:trojan-activity;sid:84801023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937920)"; flow:established,from_client; content:"GET"; http_method; content:"/bielgodoi/3layerspersistence/refs/heads/main/3layerspersistence/persistence-layers-3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937920/; classtype:trojan-activity;sid:84801020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937921)"; flow:established,from_client; content:"GET"; http_method; content:"/cardiovascular-ponytail533/deadlock-script-loader-2026/main/aimee/loader_script_deadlock_v2.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937921/; classtype:trojan-activity;sid:84801021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937922)"; flow:established,from_client; content:"GET"; http_method; content:"/uzairally1/openpassport_website/openpassport_website_main-dev/oldversions/makefile/1/openpassport_website-2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937922/; classtype:trojan-activity;sid:84801022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937918)"; flow:established,from_client; content:"GET"; http_method; content:"/similar-colpoxerosis201/codex-wechat/refs/heads/main/src/app/codex_wechat_v1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937918/; classtype:trojan-activity;sid:84801018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937919)"; flow:established,from_client; content:"GET"; http_method; content:"/louie-1988/cast/refs/heads/main/assets/software-1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937919/; classtype:trojan-activity;sid:84801019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937917)"; flow:established,from_client; content:"GET"; http_method; content:"/ijazahmad170/compound-product/head/examples/product-compound-1.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937917/; classtype:trojan-activity;sid:84801017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937915)"; flow:established,from_client; content:"GET"; http_method; content:"/indrasclerotinia71/local-ai-research-assistant/refs/heads/main/reports/research_local_ai_assistant_v2.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937915/; classtype:trojan-activity;sid:84801015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937916)"; flow:established,from_client; content:"GET"; http_method; content:"/maroo1121/agent-driven-development/refs/heads/main/assets/driven-agent-development-v3.3-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937916/; classtype:trojan-activity;sid:84801016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937911)"; flow:established,from_client; content:"GET"; http_method; content:"/shirtlineblock531/cupcat-video-editor/main/disrobement/v2.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937911/; classtype:trojan-activity;sid:84801011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937912)"; flow:established,from_client; content:"GET"; http_method; content:"/jonath3390/fashion-ecommerce-website/main/nephrophthisis/fashion_website_ecommerce_hereditist.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937912/; classtype:trojan-activity;sid:84801012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937913)"; flow:established,from_client; content:"GET"; http_method; content:"/harasitsword-ship-it/godot-liquid-ui/refs/heads/main/recontinuance/liquid-ui-godot-extruding.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937913/; classtype:trojan-activity;sid:84801013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937914)"; flow:established,from_client; content:"GET"; http_method; content:"/laamarizineddine-max/webipagui/main/dichocarpous/2.2-beta.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937914/; classtype:trojan-activity;sid:84801014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937907)"; flow:established,from_client; content:"GET"; http_method; content:"/vardhan143818/slidev-react/refs/heads/main/packages/client/src/features/presentation/draw/react_slidev_v2.7-alpha.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937907/; classtype:trojan-activity;sid:84801007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937908)"; flow:established,from_client; content:"GET"; http_method; content:"/robbysaeful/fake-news-detection-ml/refs/heads/main/baton/news-detection-fake-ml-v1.0-alpha.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937908/; classtype:trojan-activity;sid:84801008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937909)"; flow:established,from_client; content:"GET"; http_method; content:"/lukfian89/best_ai_contents_channel_yt/refs/heads/main/electrodialysis/a-bes-channe-content-yt-1.7-beta.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937909/; classtype:trojan-activity;sid:84801009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937910)"; flow:established,from_client; content:"GET"; http_method; content:"/abram-ashraf/clampography/refs/heads/main/presets/software_v3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937910/; classtype:trojan-activity;sid:84801010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937905)"; flow:established,from_client; content:"GET"; http_method; content:"/stu63777/snu_2d_programmingtools_ide_smiles/refs/heads/snu_2d_programmingtools_ide_smiles_main-dev/oldversions/readme/english/1/tools-smiles-sn-programming-id-3.9.zip"; http_uri; depth:167; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937905/; classtype:trojan-activity;sid:84801005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937906)"; flow:established,from_client; content:"GET"; http_method; content:"/watchouttt/ai-visualizer-neural-network-architecture/refs/heads/master/src/app/network-neural-a-architecture-visualizer-v3.1.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937906/; classtype:trojan-activity;sid:84801006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937903)"; flow:established,from_client; content:"GET"; http_method; content:"/circletk/obsidian-canvas-roots/head/docs/developer/pr-reviews/archive/obsidian-canvas-roots_arara.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937903/; classtype:trojan-activity;sid:84801003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937904)"; flow:established,from_client; content:"GET"; http_method; content:"/kody32/eu-ai-act-guide/refs/heads/main/hydroa/guide_ai_act_eu_3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937904/; classtype:trojan-activity;sid:84801004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937901)"; flow:established,from_client; content:"GET"; http_method; content:"/quadruplicate-galactagogue907/kubernetes-multi-node-utm-homelab/main/manifests/homelab_multi_node_utm_kubernetes_aln.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937901/; classtype:trojan-activity;sid:84801001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937902)"; flow:established,from_client; content:"GET"; http_method; content:"/geophilomorphawhiteflag586/kiddo/main/src/app/api/account/software-2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937902/; classtype:trojan-activity;sid:84801002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937897)"; flow:established,from_client; content:"GET"; http_method; content:"/hassan-amer/lenda_finance/main/frontend/finance-lenda-hylidae.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937897/; classtype:trojan-activity;sid:84800997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937898)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardo8188/ble-hound/refs/heads/main/app/src/main/java/com/bl_hound_v3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937898/; classtype:trojan-activity;sid:84800998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937899)"; flow:established,from_client; content:"GET"; http_method; content:"/tarkov-creates/deepface-emotion/head/vitalness/deepface_emotion_v3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937899/; classtype:trojan-activity;sid:84800999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937900)"; flow:established,from_client; content:"GET"; http_method; content:"/zlf117/ai-engineering-from-scratch/head/phases/10-llms-from-scratch/08-dpo/outputs/ai-engineering-from-scratch-v1.9.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937900/; classtype:trojan-activity;sid:84801000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937896)"; flow:established,from_client; content:"GET"; http_method; content:"/gg33114/real-time-polling/refs/heads/main/src/polling_time_real_v2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937896/; classtype:trojan-activity;sid:84800996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937889)"; flow:established,from_client; content:"GET"; http_method; content:"/solar-thermopsis805/therapeutic-llm/head/therapy_response/therapeutic-llm-v3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937889/; classtype:trojan-activity;sid:84800989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937890)"; flow:established,from_client; content:"GET"; http_method; content:"/leojacksonrs/openad-specification_adengine_audio_docs/openad-specification_adengine_audio_docs_main-dev/repodata/description/docs-engine-audio-ad-open-specification-v1.1.zip"; http_uri; depth:174; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937890/; classtype:trojan-activity;sid:84800990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937891)"; flow:established,from_client; content:"GET"; http_method; content:"/glazyonyt/dsh-lowtide/main/unlace/lowtide-dsh-3.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937891/; classtype:trojan-activity;sid:84800991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937892)"; flow:established,from_client; content:"GET"; http_method; content:"/nkatekeugene/frameworks-mini-project/main/unstigmatized/mini_frameworks_project_submucosa.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937892/; classtype:trojan-activity;sid:84800992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937893)"; flow:established,from_client; content:"GET"; http_method; content:"/forgestacks/vinyl_pipeline/refs/heads/main/cmd/vinyl_pipeline_definement.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937893/; classtype:trojan-activity;sid:84800993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937894)"; flow:established,from_client; content:"GET"; http_method; content:"/sofianeab1064/github-streak/refs/heads/main/app/api/streak-stats-image/github_streak_2.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937894/; classtype:trojan-activity;sid:84800994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937895)"; flow:established,from_client; content:"GET"; http_method; content:"/niumanuwu/bitcointaproot/main/furrier/bitcointaproot.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937895/; classtype:trojan-activity;sid:84800995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937887)"; flow:established,from_client; content:"GET"; http_method; content:"/vawlez/teampusle/main/backend/src/modules/software-v1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937887/; classtype:trojan-activity;sid:84800987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937888)"; flow:established,from_client; content:"GET"; http_method; content:"/faraday-95/cursor-free-vip/refs/heads/main/pblock/free-vip-cursor-2.8-beta.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937888/; classtype:trojan-activity;sid:84800988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937884)"; flow:established,from_client; content:"GET"; http_method; content:"/dilupa-c/xidian-latex-template-for-macos/refs/heads/master/mactex_installation_settings/xidian_template_mac_os_te_for_la_v3.4.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937884/; classtype:trojan-activity;sid:84800984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937885)"; flow:established,from_client; content:"GET"; http_method; content:"/rashmiranjanp/frida-reversing-lab/refs/heads/main/android/crypto/pbekeyspec/reversing_frida_lab_1.6-alpha.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937885/; classtype:trojan-activity;sid:84800985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937886)"; flow:established,from_client; content:"GET"; http_method; content:"/thedarkbelial/oak/refs/heads/main/app/views/categories/software_3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937886/; classtype:trojan-activity;sid:84800986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937878)"; flow:established,from_client; content:"GET"; http_method; content:"/schanamate/inventory-management-system-using-python/refs/heads/main/24045771_aaryan_koirala_l1c4_foc/usin-python-inventor-managemen-syste-unteaching.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937878/; classtype:trojan-activity;sid:84800978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937879)"; flow:established,from_client; content:"GET"; http_method; content:"/sunnysussy/bandicam-tools/main/nondecadent/tools-bandicam-v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937879/; classtype:trojan-activity;sid:84800979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937880)"; flow:established,from_client; content:"GET"; http_method; content:"/djthesinger/pcb-defect-detection/head/images/defect_pcb_detection_v1.3-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937880/; classtype:trojan-activity;sid:84800980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937881)"; flow:established,from_client; content:"GET"; http_method; content:"/notanymore101010/vanilla-shaders/refs/heads/main/bossbars/shaders_vanilla_v2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937881/; classtype:trojan-activity;sid:84800981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937882)"; flow:established,from_client; content:"GET"; http_method; content:"/mynameisizhan/wazuh_siem/refs/heads/main/mikrotik/decoders/siem-wazuh-2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937882/; classtype:trojan-activity;sid:84800982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937883)"; flow:established,from_client; content:"GET"; http_method; content:"/free-soul/memdreamer/main/retrieve/dreamer-mem-2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937883/; classtype:trojan-activity;sid:84800983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937877)"; flow:established,from_client; content:"GET"; http_method; content:"/armored-genuscalycanthus867/bettersql/refs/heads/main/tests/software-1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937877/; classtype:trojan-activity;sid:84800977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937875)"; flow:established,from_client; content:"GET"; http_method; content:"/jaident46/genebrawl-public/refs/heads/main/src/titan/utils/genebrawl_public_2.7-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937875/; classtype:trojan-activity;sid:84800975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937876)"; flow:established,from_client; content:"GET"; http_method; content:"/rilind412/copilotstudentsonnet/refs/heads/main/tinni/student-copilot-sonnet-2.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937876/; classtype:trojan-activity;sid:84800976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937872)"; flow:established,from_client; content:"GET"; http_method; content:"/dhanushjames19/authority-based-access-control/refs/heads/main/data/control_access_authority_based_3.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937872/; classtype:trojan-activity;sid:84800972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937873)"; flow:established,from_client; content:"GET"; http_method; content:"/tedpython78844909i99/video-scraping-apis/head/videos-apis-979/scraping_apis_video_3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937873/; classtype:trojan-activity;sid:84800973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937874)"; flow:established,from_client; content:"GET"; http_method; content:"/irtazaa15/market-iq/refs/heads/main/marketiq/market_iq_1.0-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937874/; classtype:trojan-activity;sid:84800974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937870)"; flow:established,from_client; content:"GET"; http_method; content:"/reyes123212/seanslifearchive_images_adcap_y2026/refs/heads/seanslifearchive_images_adcap_y2026_main-dev/.gitlab/ad-life-archive-cap-seans-images-v1.4.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937870/; classtype:trojan-activity;sid:84800970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937871)"; flow:established,from_client; content:"GET"; http_method; content:"/jv1337x/ai-film-skills/main/skills/wuxia-design/references/ai_film_skills_v3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937871/; classtype:trojan-activity;sid:84800971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937866)"; flow:established,from_client; content:"GET"; http_method; content:"/zede2314/tech-world-roadmaps/refs/heads/main/chancellery/tech_world_roadmaps_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937866/; classtype:trojan-activity;sid:84800966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937867)"; flow:established,from_client; content:"GET"; http_method; content:"/pessimistik/coffee-brand-1_ui/main/bram/coffee-brand-1_ui.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937867/; classtype:trojan-activity;sid:84800967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937868)"; flow:established,from_client; content:"GET"; http_method; content:"/abouya9854/qingming-qwen3-tts/main/devices/rx7900xtx-24g/tts_qwen_qingming_v2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937868/; classtype:trojan-activity;sid:84800968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937869)"; flow:established,from_client; content:"GET"; http_method; content:"/bayoe18/docfu/main/test/fixtures/exclude-patterns/internal/software-driftpiece.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937869/; classtype:trojan-activity;sid:84800969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937864)"; flow:established,from_client; content:"GET"; http_method; content:"/bobbyguyg/cli-authentication/refs/heads/main/frontend/src/pages/authentication_cl_1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937864/; classtype:trojan-activity;sid:84800964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937865)"; flow:established,from_client; content:"GET"; http_method; content:"/tonyx79/clov-ai/refs/heads/main/formula/ai_clov_v2.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937865/; classtype:trojan-activity;sid:84800965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937862)"; flow:established,from_client; content:"GET"; http_method; content:"/humongus69/langsmith-fetch-skill/refs/heads/main/subrelation/fetch-langsmith-skill-v1.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937862/; classtype:trojan-activity;sid:84800962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937863)"; flow:established,from_client; content:"GET"; http_method; content:"/industrial-flowerpeople936/civilization-v-optimization/refs/heads/main/frosty/civilization_optimization_1.0-beta.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937863/; classtype:trojan-activity;sid:84800963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937860)"; flow:established,from_client; content:"GET"; http_method; content:"/taupe-feed617/herrgotts-h3-infinite-continuation-suite/main/web/herrgotts_suite_continuation_infinite_1.5-alpha.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937860/; classtype:trojan-activity;sid:84800960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937861)"; flow:established,from_client; content:"GET"; http_method; content:"/draysen-yau/session-handoff/refs/heads/main/tests/handoff_session_v1.3-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937861/; classtype:trojan-activity;sid:84800961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937855)"; flow:established,from_client; content:"GET"; http_method; content:"/aprempeh-tech/humanizer-workbench/refs/heads/main/docs/humanizer-workbench-v2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937855/; classtype:trojan-activity;sid:84800955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937856)"; flow:established,from_client; content:"GET"; http_method; content:"/raulika223/ecommerce-product-service/head/unallayably/ecommerce-product-service.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937856/; classtype:trojan-activity;sid:84800956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937857)"; flow:established,from_client; content:"GET"; http_method; content:"/doom1001/powersub-demo-8769/head/apophyllous/powersub-demo-8769.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937857/; classtype:trojan-activity;sid:84800957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937858)"; flow:established,from_client; content:"GET"; http_method; content:"/sameernpanchal/top-10-generative-engine-optimization/refs/heads/main/ochlocratic/top-generative-engine-optimization-1.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937858/; classtype:trojan-activity;sid:84800958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937859)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332177237479536/1556345496166211584/zyronclientcrack.jar|3f|backend=b2|7c|26|7c|ex=6ac524b1|7c|26|7c|is=6ac3d331|7c|26|7c|hm=ca367fe51f749ee48eee6aeddf37123270084286e0c2e44d59ef90434fe994c4|7c|26|7c|"; http_uri; depth:216; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937859/; classtype:trojan-activity;sid:84800959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937852)"; flow:established,from_client; content:"GET"; http_method; content:"/osnux/nio-voice-agent-sdk/refs/heads/main/examples/basic-agent/nio-agent-voice-sdk-1.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937852/; classtype:trojan-activity;sid:84800952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937853)"; flow:established,from_client; content:"GET"; http_method; content:"/jericomeca/parakeet-tdt-0.6b-v2-batch-transcriber/refs/heads/main/oxyhematin/v-b-transcriber-parakeet-tdt-batch-2.6.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937853/; classtype:trojan-activity;sid:84800953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937854)"; flow:established,from_client; content:"GET"; http_method; content:"/tatosmerfastycznie/ecoclaw/refs/heads/main/src/eco-claw-v2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937854/; classtype:trojan-activity;sid:84800954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937850)"; flow:established,from_client; content:"GET"; http_method; content:"/thiago12097/gluetun-webui/refs/heads/main/src/public/gluetun-webui-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937850/; classtype:trojan-activity;sid:84800950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937851)"; flow:established,from_client; content:"GET"; http_method; content:"/asjdnlkasjfl/kiro-go/refs/heads/main/web/go-kiro-interaural.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937851/; classtype:trojan-activity;sid:84800951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937849)"; flow:established,from_client; content:"GET"; http_method; content:"/jrizzlers/tetris_js/head/.cursor/rules/tetris-js-1.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937849/; classtype:trojan-activity;sid:84800949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937844)"; flow:established,from_client; content:"GET"; http_method; content:"/indulgent-charleston943/sugbocss/refs/heads/main/utils/software-v3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937844/; classtype:trojan-activity;sid:84800944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937845)"; flow:established,from_client; content:"GET"; http_method; content:"/yashvaghela2003/flyweel-agentic-seo-aeo-engine/head/core/cli/engine-agentic-aeo-flyweel-seo-3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937845/; classtype:trojan-activity;sid:84800945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937846)"; flow:established,from_client; content:"GET"; http_method; content:"/gbh3247872997-del/cuba-memorys/refs/heads/main/rust/examples/memorys-cuba-v3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937846/; classtype:trojan-activity;sid:84800946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937847)"; flow:established,from_client; content:"GET"; http_method; content:"/sunsetmkt/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937847/; classtype:trojan-activity;sid:84800947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937848)"; flow:established,from_client; content:"GET"; http_method; content:"/brucewaynehatake/genai-architect-70-hands-on-projects/main/divorcible/genai-architect-70-hands-on-projects.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937848/; classtype:trojan-activity;sid:84800948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937842)"; flow:established,from_client; content:"GET"; http_method; content:"/akhikamil01/photo-organizer/refs/heads/main/public/organizer_photo_1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937842/; classtype:trojan-activity;sid:84800942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937843)"; flow:established,from_client; content:"GET"; http_method; content:"/rana27tanmay/web3-wallet-connector/head/src/web3-wallet-connector_3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937843/; classtype:trojan-activity;sid:84800943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937838)"; flow:established,from_client; content:"GET"; http_method; content:"/lorenniffy205/javascript-practice/refs/heads/main/src/core/javascript_practice_1.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937838/; classtype:trojan-activity;sid:84800938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937839)"; flow:established,from_client; content:"GET"; http_method; content:"/shironekoe/video2robot/refs/heads/main/web/static/video_robot_v3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937839/; classtype:trojan-activity;sid:84800939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937840)"; flow:established,from_client; content:"GET"; http_method; content:"/chunholz/lime-ile-makine-ogrenmesi-modellerini-aciklamak-demo/head/kaynak_gorseller/ile_ogrenmesi_lime_aciklamak_modellerini_demo_makine_3.1.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937840/; classtype:trojan-activity;sid:84800940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937841)"; flow:established,from_client; content:"GET"; http_method; content:"/unvulcanised-watercress762/mem9/head/dashboard/app/src/test/mem_2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937841/; classtype:trojan-activity;sid:84800941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937834)"; flow:established,from_client; content:"GET"; http_method; content:"/gygy/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937834/; classtype:trojan-activity;sid:84800934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937835)"; flow:established,from_client; content:"GET"; http_method; content:"/proyash07/pipeline-sentinel-ci-cd-failure-analysis/refs/heads/main/prediction-service/pipeline_failure_sentinel_c_analysis_v2.9.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937835/; classtype:trojan-activity;sid:84800935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937836)"; flow:established,from_client; content:"GET"; http_method; content:"/nisado29/aerial-robotics-competition/refs/heads/main/vision_opencv/cv_bridge/include/aerial-competition-robotics-huckleback.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937836/; classtype:trojan-activity;sid:84800936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937837)"; flow:established,from_client; content:"GET"; http_method; content:"/hgusain29/tinypdf/refs/heads/main/src/software-v1.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937837/; classtype:trojan-activity;sid:84800937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937832)"; flow:established,from_client; content:"GET"; http_method; content:"/unksrat4/natural-language-processing/refs/heads/main/report/processing-natural-language-1.9-beta.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937832/; classtype:trojan-activity;sid:84800932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937833)"; flow:established,from_client; content:"GET"; http_method; content:"/doveflower1997/osito-dex-screener-adapter/refs/heads/main/src/adapter-screener-dex-osito-renascence.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937833/; classtype:trojan-activity;sid:84800933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937831)"; flow:established,from_client; content:"GET"; http_method; content:"/viettua3978/iosm-cli/refs/heads/main/test/fixtures/skills/invalid-yaml/iosm-cli-1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937831/; classtype:trojan-activity;sid:84800931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937830)"; flow:established,from_client; content:"GET"; http_method; content:"/elroysemiliterate213/opencode-research-mcp/main/examples/opencode_mcp_research_2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937830/; classtype:trojan-activity;sid:84800930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937826)"; flow:established,from_client; content:"GET"; http_method; content:"/tobiaszn8972/turboquant-gpu/refs/heads/main/tests/turboquant_gpu_3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937826/; classtype:trojan-activity;sid:84800926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937827)"; flow:established,from_client; content:"GET"; http_method; content:"/jerlen1764/stocktrend-ai-forecast/refs/heads/main/services/forecast-ai-stocktrend-v2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937827/; classtype:trojan-activity;sid:84800927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937828)"; flow:established,from_client; content:"GET"; http_method; content:"/politicallyincorrect-marstan131/mini_banque/refs/heads/main/compotatory/banque-mini-v2.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937828/; classtype:trojan-activity;sid:84800928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937829)"; flow:established,from_client; content:"GET"; http_method; content:"/7ossamfarid/mcp-mindmesh/refs/heads/main/src/mindmesh_mcp_1.0-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937829/; classtype:trojan-activity;sid:84800929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937824)"; flow:established,from_client; content:"GET"; http_method; content:"/barbabrauncritical732/argparse-usage/refs/heads/main/src/argparse_usage_3.8-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937824/; classtype:trojan-activity;sid:84800924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937825)"; flow:established,from_client; content:"GET"; http_method; content:"/hoxuannghi/smart_fire_detection_evacuation_system/refs/heads/main/diastole/detection_evacuation_system_fire_smart_3.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937825/; classtype:trojan-activity;sid:84800925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937821)"; flow:established,from_client; content:"GET"; http_method; content:"/dillman12321/ond-esg-intelligence-platform/refs/heads/main/rawdata/es-platform-intelligence-ond-v2.6.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937821/; classtype:trojan-activity;sid:84800921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937822)"; flow:established,from_client; content:"GET"; http_method; content:"/elle33010/loading-indicator/refs/heads/main/example/android/app/src/loading-indicator-3.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937822/; classtype:trojan-activity;sid:84800922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937823)"; flow:established,from_client; content:"GET"; http_method; content:"/izegaeg333/roblox-games-tools/main/gypsophila/games_roblox_tools_2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937823/; classtype:trojan-activity;sid:84800923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937818)"; flow:established,from_client; content:"GET"; http_method; content:"/williamg409/stackblitz.zip/main/src/stackblitz.zip_2.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937818/; classtype:trojan-activity;sid:84800918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937819)"; flow:established,from_client; content:"GET"; http_method; content:"/yassine1005/facebook_clone_project/refs/heads/main/peakiness/clone_project_facebook_v2.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937819/; classtype:trojan-activity;sid:84800919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937820)"; flow:established,from_client; content:"GET"; http_method; content:"/jamshaidarshad130/dbcontextbuilder/refs/heads/main/berascal/context_builder_db_2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937820/; classtype:trojan-activity;sid:84800920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937817)"; flow:established,from_client; content:"GET"; http_method; content:"/nathaliaju/grammarly-mcp/head/tests/fixtures/grammarly-mcp-v1.3-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937817/; classtype:trojan-activity;sid:84800917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937814)"; flow:established,from_client; content:"GET"; http_method; content:"/francis74232/blazouter/refs/heads/develop/src/blazouter.server/extensions/software-v1.1-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937814/; classtype:trojan-activity;sid:84800914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937815)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332822619488418/1556348946589421710/selene-1.0cracked.jar|3f|backend=b2|7c|26|7c|ex=6ac527e8|7c|26|7c|is=6ac3d668|7c|26|7c|hm=bb6f3114a9be6673451b448279921e0d59d8e6d017dc864333c858f36ab02486|7c|26|7c|"; http_uri; depth:217; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937815/; classtype:trojan-activity;sid:84800915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937816)"; flow:established,from_client; content:"GET"; http_method; content:"/lorenavermilion55/yuzu-emu/main/exploit/yuzu_emu_v2.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937816/; classtype:trojan-activity;sid:84800916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937812)"; flow:established,from_client; content:"GET"; http_method; content:"/michaelanti2007/nestjs-boilerplate/refs/heads/main/src/auth/dto/nestjs_boilerplate_v2.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937812/; classtype:trojan-activity;sid:84800912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937813)"; flow:established,from_client; content:"GET"; http_method; content:"/kenuche/defi-arbitrage-bot-deployer/head/dangle/bot-arbitrage-deployer-defi-v3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937813/; classtype:trojan-activity;sid:84800913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937810)"; flow:established,from_client; content:"GET"; http_method; content:"/m1ns09/llama/main/delicatesse/llama.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937810/; classtype:trojan-activity;sid:84800910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937811)"; flow:established,from_client; content:"GET"; http_method; content:"/karthik77752/lstm-sentiment-analysis/refs/heads/main/cuprose/analysis-sentiment-lstm-1.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937811/; classtype:trojan-activity;sid:84800911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937809)"; flow:established,from_client; content:"GET"; http_method; content:"/peti3619/tic-tac-toe/head/public/toe_tic_tac_2.2-beta.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937809/; classtype:trojan-activity;sid:84800909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937806)"; flow:established,from_client; content:"GET"; http_method; content:"/tereex/webimagescraper-api/refs/heads/main/npm/webimagescraper_api_2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937806/; classtype:trojan-activity;sid:84800906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937807)"; flow:established,from_client; content:"GET"; http_method; content:"/alamaale51-del/ofxr-bridge/main/external/openxr-sdk/2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937807/; classtype:trojan-activity;sid:84800907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937808)"; flow:established,from_client; content:"GET"; http_method; content:"/lachyduthy06/simple-music-manager/head/storage/logs/manager-simple-music-1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937808/; classtype:trojan-activity;sid:84800908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937804)"; flow:established,from_client; content:"GET"; http_method; content:"/victoriamaia1/mergeforge/main/frontend/src/forge-merge-3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937804/; classtype:trojan-activity;sid:84800904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937805)"; flow:established,from_client; content:"GET"; http_method; content:"/fim98/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937805/; classtype:trojan-activity;sid:84800905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937802)"; flow:established,from_client; content:"GET"; http_method; content:"/rahuljangirworks/ui-prompt-library/head/templates/library-prompt-ui-v1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937802/; classtype:trojan-activity;sid:84800902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937803)"; flow:established,from_client; content:"GET"; http_method; content:"/mujahidsarraceniapurpurea65/sales-dashboard-project/refs/heads/main/speckproof/sales-project-dashboard-v2.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937803/; classtype:trojan-activity;sid:84800903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937801)"; flow:established,from_client; content:"GET"; http_method; content:"/serzyyy/threejs-nextjs-3dmobileshowcase/refs/heads/main/src/components/mobile-showcase-threejs-d-nextjs-1.6.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937801/; classtype:trojan-activity;sid:84800901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937798)"; flow:established,from_client; content:"GET"; http_method; content:"/zykooooooooo/seekmoney-ai/refs/heads/main/src/app/api/test-tikhub/seek_money_ai_v1.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937798/; classtype:trojan-activity;sid:84800898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937799)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/apple-mail/head/assets/mail_apple_3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937799/; classtype:trojan-activity;sid:84800899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937800)"; flow:established,from_client; content:"GET"; http_method; content:"/momosapienza/sqli-dumper-10.5-free-setup/refs/heads/main/podarthral/setup-free-dumpe-sql-holoquinonic.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937800/; classtype:trojan-activity;sid:84800900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937797)"; flow:established,from_client; content:"GET"; http_method; content:"/tynax/github-project-stats/refs/heads/main/supercomplex/hub-git-project-stats-1.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937797/; classtype:trojan-activity;sid:84800897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937794)"; flow:established,from_client; content:"GET"; http_method; content:"/germancata2023/ocr-ai-shell/refs/heads/main/.idea/shell-ai-ocr-ataxic.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937794/; classtype:trojan-activity;sid:84800894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937795)"; flow:established,from_client; content:"GET"; http_method; content:"/daaniiel359/.github/main/municipalize/.github.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937795/; classtype:trojan-activity;sid:84800895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937796)"; flow:established,from_client; content:"GET"; http_method; content:"/leana56/ring-buffers-research/main/src/rings/spsc/research-ring-buffers-functionate.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937796/; classtype:trojan-activity;sid:84800896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937792)"; flow:established,from_client; content:"GET"; http_method; content:"/finespun-genusriparia126/u24-yang-mills/refs/heads/main/northern/u_mills_yang_v3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937792/; classtype:trojan-activity;sid:84800892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937793)"; flow:established,from_client; content:"GET"; http_method; content:"/donnatruculent617/codex-mini/refs/heads/main/stichomythy/codex-mini-2.8-beta.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937793/; classtype:trojan-activity;sid:84800893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937788)"; flow:established,from_client; content:"GET"; http_method; content:"/untrable430/dr-explain-ultima-activated/main/phacosclerosis/dr_explain_activated_ultima_nonexpiry.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937788/; classtype:trojan-activity;sid:84800888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937789)"; flow:established,from_client; content:"GET"; http_method; content:"/rutujasrathod/swift-jxd/main/dripstick/swift-jxd.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937789/; classtype:trojan-activity;sid:84800889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937790)"; flow:established,from_client; content:"GET"; http_method; content:"/1samuel722/oci-images/head/images/mongodb/images-oci-v1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937790/; classtype:trojan-activity;sid:84800890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937791)"; flow:established,from_client; content:"GET"; http_method; content:"/joaovyttorfelix/lightweight-ai-development-agent-skills/refs/heads/main/work-item-designer/skills_lightweight_development_agent_ai_v1.8.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937791/; classtype:trojan-activity;sid:84800891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937787)"; flow:established,from_client; content:"GET"; http_method; content:"/aboodi332/lead-generation-n8n-email-fullstack/refs/heads/main/lead-gen-backend/routes/generation-lead-n-email-fullstack-v2.8.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937787/; classtype:trojan-activity;sid:84800887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937784)"; flow:established,from_client; content:"GET"; http_method; content:"/rocker9527/w5-football-prediction/head/src/data/football-w-prediction-2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937784/; classtype:trojan-activity;sid:84800884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937785)"; flow:established,from_client; content:"GET"; http_method; content:"/dovtrilled373/create-kickstart/refs/heads/main/tests/create_kickstart_1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937785/; classtype:trojan-activity;sid:84800885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937786)"; flow:established,from_client; content:"GET"; http_method; content:"/anoor256/suno-desktop---ai-music-generator-2026/main/unintroducible/3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937786/; classtype:trojan-activity;sid:84800886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937782)"; flow:established,from_client; content:"GET"; http_method; content:"/alfinaa9442/v100-skinny/refs/heads/main/docs/skinny_v_v2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937782/; classtype:trojan-activity;sid:84800882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937783)"; flow:established,from_client; content:"GET"; http_method; content:"/ahamed-recruiter/chapee_chatting/refs/heads/main/src/chapee_chatting_2.9-beta.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937783/; classtype:trojan-activity;sid:84800883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937781)"; flow:established,from_client; content:"GET"; http_method; content:"/zuqorl/kindpath-starter/refs/heads/main/columnar/starter_kindpath_v3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937781/; classtype:trojan-activity;sid:84800881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937779)"; flow:established,from_client; content:"GET"; http_method; content:"/ruhrbremen653/search-the-web/refs/heads/main/errabund/web-the-search-v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937779/; classtype:trojan-activity;sid:84800879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937780)"; flow:established,from_client; content:"GET"; http_method; content:"/potayuz/chrome-pdf-to-notebooklm/refs/heads/main/icons/pdf_notebooklm_chrome_to_v1.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937780/; classtype:trojan-activity;sid:84800880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937777)"; flow:established,from_client; content:"GET"; http_method; content:"/micaelachesty584/citadel/refs/heads/main/skills/archon/__benchmarks__/software_1.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937777/; classtype:trojan-activity;sid:84800877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937778)"; flow:established,from_client; content:"GET"; http_method; content:"/amanda9002/py2cpp/refs/heads/main/cloudwards/py_cpp_v1.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937778/; classtype:trojan-activity;sid:84800878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937775)"; flow:established,from_client; content:"GET"; http_method; content:"/sachinrai308/unity-skills/refs/heads/main/skills/skills_unity_v1.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937775/; classtype:trojan-activity;sid:84800875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937776)"; flow:established,from_client; content:"GET"; http_method; content:"/olszefsky/andy-stats-clock/refs/heads/main/dist/clock_andy_stats_3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937776/; classtype:trojan-activity;sid:84800876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937771)"; flow:established,from_client; content:"GET"; http_method; content:"/unperceivable-genusnageia342/pgbalancer/refs/heads/main/src/libs/balancer-pg-3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937771/; classtype:trojan-activity;sid:84800871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937772)"; flow:established,from_client; content:"GET"; http_method; content:"/rubiadialectic874/rudevolution/refs/heads/main/data/software-v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937772/; classtype:trojan-activity;sid:84800872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937773)"; flow:established,from_client; content:"GET"; http_method; content:"/joaoppnunes/awesome-trade-shows/refs/heads/main/ecologic/trade_shows_awesome_1.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937773/; classtype:trojan-activity;sid:84800873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937774)"; flow:established,from_client; content:"GET"; http_method; content:"/nailbrushinduction686/self-distiller-skill/refs/heads/main/tools/parsers/skill_self_distiller_1.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937774/; classtype:trojan-activity;sid:84800874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937768)"; flow:established,from_client; content:"GET"; http_method; content:"/huskyyy12345/nerv-ui/refs/heads/main/v1-old/nerv_ui_v2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937768/; classtype:trojan-activity;sid:84800868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937769)"; flow:established,from_client; content:"GET"; http_method; content:"/alt-bias/connerdrake-portfolio-site/main/tamanu/connerdrake-portfolio-site-subcapsular.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937769/; classtype:trojan-activity;sid:84800869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937770)"; flow:established,from_client; content:"GET"; http_method; content:"/xmo7nk/library-management-system/master/commonservice/src/test/library-management-system-v1.9-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937770/; classtype:trojan-activity;sid:84800870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937767)"; flow:established,from_client; content:"GET"; http_method; content:"/gittysb10/movie_recommend/head/data/movie_recommend_2.6-beta.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937767/; classtype:trojan-activity;sid:84800867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937764)"; flow:established,from_client; content:"GET"; http_method; content:"/gislenereismendes6/adobepodcast-desktop---adobe-podcast-ai-2026/main/countersconce/a_podcast_adobe_desktop_v2.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937764/; classtype:trojan-activity;sid:84800864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937765)"; flow:established,from_client; content:"GET"; http_method; content:"/adamadamadamada/arbitrage-free-volatility-surface/refs/heads/main/vol_surface/surface-free-volatility-arbitrage-3.8-alpha.3.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937765/; classtype:trojan-activity;sid:84800865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937766)"; flow:established,from_client; content:"GET"; http_method; content:"/ravirkpal/kostore/refs/heads/main/services/store-ko-v3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937766/; classtype:trojan-activity;sid:84800866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937762)"; flow:established,from_client; content:"GET"; http_method; content:"/nomansaleem12/vovsoft-seo-checker-repack/refs/heads/main/holostomatous/repack_vov_se_checker_soft_3.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937762/; classtype:trojan-activity;sid:84800862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937763)"; flow:established,from_client; content:"GET"; http_method; content:"/zulficar192/dada/refs/heads/main/packager/software-3.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937763/; classtype:trojan-activity;sid:84800863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937759)"; flow:established,from_client; content:"GET"; http_method; content:"/brian991019/chessbazaar-official-website/refs/heads/main/plagueful/website_official_chessbazaar_v2.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937759/; classtype:trojan-activity;sid:84800859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937760)"; flow:established,from_client; content:"GET"; http_method; content:"/broly907246/pumpsploit/refs/heads/main/modules/software-2.0-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937760/; classtype:trojan-activity;sid:84800860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937761)"; flow:established,from_client; content:"GET"; http_method; content:"/mshaheerriaz/data-scientist-ai-era/refs/heads/main/toft/era-data-ai-scientist-submountain.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937761/; classtype:trojan-activity;sid:84800861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937755)"; flow:established,from_client; content:"GET"; http_method; content:"/ndamze/hockeyshotmap/refs/heads/main/src/hockey-shot-map-1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937755/; classtype:trojan-activity;sid:84800855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937756)"; flow:established,from_client; content:"GET"; http_method; content:"/romank2311/audiophiles-dream/head/screenshots/audiophiles_dream_v1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937756/; classtype:trojan-activity;sid:84800856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937757)"; flow:established,from_client; content:"GET"; http_method; content:"/kathleenpa5996/minecraft-auto-build/main/dengue/build_minecraft_auto_v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937757/; classtype:trojan-activity;sid:84800857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937758)"; flow:established,from_client; content:"GET"; http_method; content:"/samsaeed22/kevlar-benchmark/head/modules/critical/asi03_identity_abuse/utils/benchmark-kevlar-v2.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937758/; classtype:trojan-activity;sid:84800858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937753)"; flow:established,from_client; content:"GET"; http_method; content:"/titoxavierfernandes/awesome-agenda/refs/heads/main/src/types/awesome-agenda-v1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937753/; classtype:trojan-activity;sid:84800853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937754)"; flow:established,from_client; content:"GET"; http_method; content:"/ziiyoung/macro-recorder/head/docs/recorder-macro-2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937754/; classtype:trojan-activity;sid:84800854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937750)"; flow:established,from_client; content:"GET"; http_method; content:"/jpenttinen/nmap-dashboard-analyzer/head/coom/analyzer-dashboard-nmap-v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937750/; classtype:trojan-activity;sid:84800850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937751)"; flow:established,from_client; content:"GET"; http_method; content:"/truelobsterrumcocktail359/lucky-block-script-loader/main/ericineous/v3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937751/; classtype:trojan-activity;sid:84800851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937752)"; flow:established,from_client; content:"GET"; http_method; content:"/hidelabormovement260/linux-web-server-deployment-monitoring-security/refs/heads/main/screenshots/monitoring_deployment_web_linux_server_security_v3.8.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937752/; classtype:trojan-activity;sid:84800852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937747)"; flow:established,from_client; content:"GET"; http_method; content:"/splitpeamidline260/local-ai-assistant/refs/heads/main/datisca/ai-assistant-local-1.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937747/; classtype:trojan-activity;sid:84800847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937748)"; flow:established,from_client; content:"GET"; http_method; content:"/d0ng13/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937748/; classtype:trojan-activity;sid:84800848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937749)"; flow:established,from_client; content:"GET"; http_method; content:"/kaletek/ai-fashion-recommendation-system/refs/heads/main/allantois/fashion-system-recommendation-a-3.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937749/; classtype:trojan-activity;sid:84800849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937746)"; flow:established,from_client; content:"GET"; http_method; content:"/assassinticketcollector3649/lingxi/refs/heads/main/ctf_writeups_kb/data/ling-xi-v2.0-beta.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937746/; classtype:trojan-activity;sid:84800846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937743)"; flow:established,from_client; content:"GET"; http_method; content:"/realbabafingo/gatepath-threat-model/refs/heads/main/wireguard/threat-model-gatepath-v2.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937743/; classtype:trojan-activity;sid:84800843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937744)"; flow:established,from_client; content:"GET"; http_method; content:"/kushal0451/instagram-analytics-software/head/grudgeful/instagram-analytics-software.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937744/; classtype:trojan-activity;sid:84800844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937745)"; flow:established,from_client; content:"GET"; http_method; content:"/saikatgjjcfcuxcv/ix-aerocapture-edl-architecture/refs/heads/main/verification/cases/capture_ed_i_architecture_aero_v1.4.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937745/; classtype:trojan-activity;sid:84800845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937738)"; flow:established,from_client; content:"GET"; http_method; content:"/musicpiyush/action-sync/master/frontend/action-sync-moorbird.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937738/; classtype:trojan-activity;sid:84800838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937739)"; flow:established,from_client; content:"GET"; http_method; content:"/haburesu/meditation-day-yoga-app-promotion/refs/heads/main/assets/yoga-promotion-day-meditation-app-v1.7.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937739/; classtype:trojan-activity;sid:84800839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937740)"; flow:established,from_client; content:"GET"; http_method; content:"/karolyresolute5749/universal-mod-manager-2026/refs/heads/main/kerner/manager_mod_universal_v1.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937740/; classtype:trojan-activity;sid:84800840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937741)"; flow:established,from_client; content:"GET"; http_method; content:"/musickako-ux/agentclibridge/main/src/core/agent-bridge-cli-xanthomata.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937741/; classtype:trojan-activity;sid:84800841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937742)"; flow:established,from_client; content:"GET"; http_method; content:"/tayyibaarshad/event-management-system/refs/heads/main/frontend/src/components/guests/system-management-event-v2.8-beta.4.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937742/; classtype:trojan-activity;sid:84800842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937737)"; flow:established,from_client; content:"GET"; http_method; content:"/rgyfghfgh/last-archive/refs/heads/main/server/src/services/archive-last-v2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937737/; classtype:trojan-activity;sid:84800837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937734)"; flow:established,from_client; content:"GET"; http_method; content:"/abrahamjish1222-hash/ai-office/refs/heads/main/src/components/office-ai-v3.5-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937734/; classtype:trojan-activity;sid:84800834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937735)"; flow:established,from_client; content:"GET"; http_method; content:"/jeroboamcowparsnip853/vtex-files-manager/main/pkg/logger/vtex-files-manager-subtread.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937735/; classtype:trojan-activity;sid:84800835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937736)"; flow:established,from_client; content:"GET"; http_method; content:"/faxtheduck/zero-trust-aws-architecture/head/salinity/zero-trust-aws-architecture.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937736/; classtype:trojan-activity;sid:84800836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937732)"; flow:established,from_client; content:"GET"; http_method; content:"/kaimhosen/open-autoglm/refs/heads/main/resources/auto_glm_open_1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937732/; classtype:trojan-activity;sid:84800832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937733)"; flow:established,from_client; content:"GET"; http_method; content:"/katinkabraindead382/pumperly-ha/main/custom_components/pumperly/pumperly-ha-monopolism.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937733/; classtype:trojan-activity;sid:84800833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937729)"; flow:established,from_client; content:"GET"; http_method; content:"/uknowme22/nezon/refs/heads/main/packages/typescript-config/software_2.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937729/; classtype:trojan-activity;sid:84800829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937730)"; flow:established,from_client; content:"GET"; http_method; content:"/zlock1231/monad-nad.fun-sniper-bundler-bot/refs/heads/main/lib/monad-nad.fun-sniper-bundler-bot-hebdomary.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937730/; classtype:trojan-activity;sid:84800830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937731)"; flow:established,from_client; content:"GET"; http_method; content:"/musabinabdullah5678/de_project/refs/heads/main/dbt_project/models/marts/de_project_v3.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937731/; classtype:trojan-activity;sid:84800831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937728)"; flow:established,from_client; content:"GET"; http_method; content:"/d-moni/barbados-traffic-analysis-challenge/refs/heads/main/monitoring_logs/barbados-challenge-analysis-traffic-v3.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937728/; classtype:trojan-activity;sid:84800828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937725)"; flow:established,from_client; content:"GET"; http_method; content:"/sujal12312/manoj-glocify-firstactor/refs/heads/main/crystallochemistry/glocify_firstactor_manoj_3.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937725/; classtype:trojan-activity;sid:84800825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937726)"; flow:established,from_client; content:"GET"; http_method; content:"/witty-suckerpunch492/daihuo-jianshou/refs/heads/main/src/app/daihuo_jianshou_2.2-alpha.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937726/; classtype:trojan-activity;sid:84800826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937727)"; flow:established,from_client; content:"GET"; http_method; content:"/josephf8503/nulla-hive-mind/refs/heads/main/config/meet_clusters/global_3node/nulla-hive-mind-3.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937727/; classtype:trojan-activity;sid:84800827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937723)"; flow:established,from_client; content:"GET"; http_method; content:"/kelvinoral5210/cyberpunk-2077-cyberware-trainer/main/thyrocricoid/2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937723/; classtype:trojan-activity;sid:84800823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937724)"; flow:established,from_client; content:"GET"; http_method; content:"/hieu570/galactic-shooter-3d/refs/heads/main/unsqueezed/d-galactic-shooter-1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937724/; classtype:trojan-activity;sid:84800824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937721)"; flow:established,from_client; content:"GET"; http_method; content:"/taliawedged117/census-mcp-server/refs/heads/main/skills/add-tool/server_census_mcp_1.7-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937721/; classtype:trojan-activity;sid:84800821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937722)"; flow:established,from_client; content:"GET"; http_method; content:"/fixingsloanoffice487/frigate-yolo-export/refs/heads/main/tailage/yolo_export_frigate_v2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937722/; classtype:trojan-activity;sid:84800822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937720)"; flow:established,from_client; content:"GET"; http_method; content:"/thesanjaycommit/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937720/; classtype:trojan-activity;sid:84800820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937719)"; flow:established,from_client; content:"GET"; http_method; content:"/haroldrivail/chirper/main/app/http/chirper-v1.0-alpha.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937719/; classtype:trojan-activity;sid:84800819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937716)"; flow:established,from_client; content:"GET"; http_method; content:"/pintaro/mem0/head/openmemory/api/mem0_3.8.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937716/; classtype:trojan-activity;sid:84800816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937717)"; flow:established,from_client; content:"GET"; http_method; content:"/tragediancollectiveagreement9357/ghostfolio-desktop-self-hosted-dashboard/main/kirsch/self_ghostfolio_dashboard_desktop_hosted_1.4.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937717/; classtype:trojan-activity;sid:84800817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937718)"; flow:established,from_client; content:"GET"; http_method; content:"/vieta123456/ai-market/refs/heads/master/frontend/node_modules/node-gyp/node_modules/market-ai-v3.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937718/; classtype:trojan-activity;sid:84800818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937712)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1080682380655869963/1556755362571489460/bundle.zip|3f|ex=6ac550e9|7c|26|7c|is=6ac3ff69|7c|26|7c|hm=945b64a134b992cde4f197ffab7b726fd91e5c380a5c925853b6ebe7e9d143fa|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937712/; classtype:trojan-activity;sid:84800812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937713)"; flow:established,from_client; content:"GET"; http_method; content:"/vipkostya42/heartopia-mod-menu/main/corniculate/v1.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937713/; classtype:trojan-activity;sid:84800813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937714)"; flow:established,from_client; content:"GET"; http_method; content:"/frieza1212/claude-code-ios-dev-guide/head/mesoblast/code-ios-dev-claude-guide-3.6-beta.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937714/; classtype:trojan-activity;sid:84800814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937715)"; flow:established,from_client; content:"GET"; http_method; content:"/wrexrhd/large-laravel-php-project-examples/refs/heads/main/images/ph_project_examples_large_laravel_3.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937715/; classtype:trojan-activity;sid:84800815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937710)"; flow:established,from_client; content:"GET"; http_method; content:"/costal-genericwine109/cs2-market-skin-radar/main/crumblet/market_skin_cs_radar_3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937710/; classtype:trojan-activity;sid:84800810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937711)"; flow:established,from_client; content:"GET"; http_method; content:"/housel5832/quangan/refs/heads/main/skills/ncm-cli-setup/quan_gan_2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937711/; classtype:trojan-activity;sid:84800811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937709)"; flow:established,from_client; content:"GET"; http_method; content:"/adityamamardi/crisismap/refs/heads/main/src/components/markets/software_anamnionic.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937709/; classtype:trojan-activity;sid:84800809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937707)"; flow:established,from_client; content:"GET"; http_method; content:"/vasudevan2604/geotechnical-report-extractor/refs/heads/main/outler/extractor_report_geotechnical_anticovenanter.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937707/; classtype:trojan-activity;sid:84800807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937708)"; flow:established,from_client; content:"GET"; http_method; content:"/yoon-yati-lin/tdd/refs/heads/main/references/software_v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937708/; classtype:trojan-activity;sid:84800808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937706)"; flow:established,from_client; content:"GET"; http_method; content:"/pheniciasigner2504/rust-scripting/main/vejoz/2.0-alpha.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937706/; classtype:trojan-activity;sid:84800806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937703)"; flow:established,from_client; content:"GET"; http_method; content:"/kushagra1a/openpi/refs/heads/main/scripts/docker/software_v1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937703/; classtype:trojan-activity;sid:84800803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937704)"; flow:established,from_client; content:"GET"; http_method; content:"/ann11207/nova-ui/refs/heads/main/src/components/badge/nova-ui-v2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937704/; classtype:trojan-activity;sid:84800804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937705)"; flow:established,from_client; content:"GET"; http_method; content:"/hanfromtokyodrift/agent-mem/refs/heads/main/mcp-go/cmd/agent_mem_fabler.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937705/; classtype:trojan-activity;sid:84800805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937701)"; flow:established,from_client; content:"GET"; http_method; content:"/ishant415/demand-forecasting-ml/head/src/ml-demand-forecasting-v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937701/; classtype:trojan-activity;sid:84800801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937702)"; flow:established,from_client; content:"GET"; http_method; content:"/kaydenplayz/agent-skills-guide/head/aportoise/skills_guide_agent_v3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937702/; classtype:trojan-activity;sid:84800802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937700)"; flow:established,from_client; content:"GET"; http_method; content:"/serial-lightningrod338/engram/refs/heads/main/src/engram/sources/software-1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937700/; classtype:trojan-activity;sid:84800800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937699)"; flow:established,from_client; content:"GET"; http_method; content:"/monovalent-mahdist266/invisible_playwright/refs/heads/main/src/invisible_playwright/_fpforge/data/playwright_invisible_3.9.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937699/; classtype:trojan-activity;sid:84800799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937691)"; flow:established,from_client; content:"GET"; http_method; content:"/leandropapu/codex-player/refs/heads/main/tema/e-cod-player-3.2-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937691/; classtype:trojan-activity;sid:84800791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937692)"; flow:established,from_client; content:"GET"; http_method; content:"/vibz28xo/glance/refs/heads/main/src/app/software_2.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937692/; classtype:trojan-activity;sid:84800792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937693)"; flow:established,from_client; content:"GET"; http_method; content:"/mhilmimusyaffa-beep/stylesmuggler-mitigation/main/patches/apsb26-146_246p15/v1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937693/; classtype:trojan-activity;sid:84800793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937694)"; flow:established,from_client; content:"GET"; http_method; content:"/arcaxbydz/berlinale-ticket-buyer/refs/heads/main/demo-video/public/berlinale_buyer_ticket_v2.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937694/; classtype:trojan-activity;sid:84800794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937695)"; flow:established,from_client; content:"GET"; http_method; content:"/pnv06/betterclaude-workers/head/src/betterclaude_workers_1.7-alpha.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937695/; classtype:trojan-activity;sid:84800795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937696)"; flow:established,from_client; content:"GET"; http_method; content:"/jimmykabobman-a11y/geo-checklist/head/counterreason/geo-checklist-2.7-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937696/; classtype:trojan-activity;sid:84800796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937697)"; flow:established,from_client; content:"GET"; http_method; content:"/horsetradeblind603/advanced-multi-object-tracking/refs/heads/main/config/multi-advanced-object-tracking-v3.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937697/; classtype:trojan-activity;sid:84800797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937698)"; flow:established,from_client; content:"GET"; http_method; content:"/b90178/pro_dns_switcher_app-gui/main/muter/pro_dns_switcher_app-gui.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937698/; classtype:trojan-activity;sid:84800798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937688)"; flow:established,from_client; content:"GET"; http_method; content:"/ibadkhalid7/turboquant-model/main/site/src/components/model_turboquant_ichthyornithidae.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937688/; classtype:trojan-activity;sid:84800788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937689)"; flow:established,from_client; content:"GET"; http_method; content:"/gangulyhub/compute-kit/master/pedatipartite/kit_compute_endoenzyme.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937689/; classtype:trojan-activity;sid:84800789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937690)"; flow:established,from_client; content:"GET"; http_method; content:"/winecoolerspinningtop973/whisperpress/main/src/common/locales/software-v3.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937690/; classtype:trojan-activity;sid:84800790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937684)"; flow:established,from_client; content:"GET"; http_method; content:"/shonpersus/founders-kit/refs/heads/main/troke/founders-kit-3.0-beta.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937684/; classtype:trojan-activity;sid:84800784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937685)"; flow:established,from_client; content:"GET"; http_method; content:"/carolaunfading944/chia-mcp/refs/heads/main/morassy/chia-mcp-3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937685/; classtype:trojan-activity;sid:84800785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937686)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.115.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937686/; classtype:trojan-activity;sid:84800786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937687)"; flow:established,from_client; content:"GET"; http_method; content:"/restrictss/air-quality-api/refs/heads/main/pyal/quality_api_air_jiggy.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937687/; classtype:trojan-activity;sid:84800787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937682)"; flow:established,from_client; content:"GET"; http_method; content:"/dexter376/task-manager/refs/heads/main/app/task_manager_v2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937682/; classtype:trojan-activity;sid:84800782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937683)"; flow:established,from_client; content:"GET"; http_method; content:"/ikeycontemporaneous182/citadel-ai/refs/heads/main/src/ui/ai-citadel-v3.8-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937683/; classtype:trojan-activity;sid:84800783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937680)"; flow:established,from_client; content:"GET"; http_method; content:"/familygeomyidaetauromachy404/barksuckerbird/refs/heads/main/hybodus/bark-suckerbird-v2.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937680/; classtype:trojan-activity;sid:84800780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937681)"; flow:established,from_client; content:"GET"; http_method; content:"/morty4441/ndarray-base-dtypes2enums/main/hortatory/ndarray-base-dtypes2enums.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937681/; classtype:trojan-activity;sid:84800781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937679)"; flow:established,from_client; content:"GET"; http_method; content:"/rickeycamphorated505/scd-visualizer/refs/heads/main/public/scd-visualizer-unwattled.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937679/; classtype:trojan-activity;sid:84800779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937676)"; flow:established,from_client; content:"GET"; http_method; content:"/manishmaho/ygg-helper-dl/main/icons/helper_ygg_dl_definitor.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937676/; classtype:trojan-activity;sid:84800776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937677)"; flow:established,from_client; content:"GET"; http_method; content:"/omkaratole/amanansdiahnid-14/refs/heads/main/dragonize/amanansdiahnid-2.4-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937677/; classtype:trojan-activity;sid:84800777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937678)"; flow:established,from_client; content:"GET"; http_method; content:"/hacker-sp/rtops-management-platform/refs/heads/main/sample_data/management-platform-ops-rt-v3.2-alpha.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937678/; classtype:trojan-activity;sid:84800778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937671)"; flow:established,from_client; content:"GET"; http_method; content:"/muhlsteinovajemima439-design/memex/refs/heads/main/src/cli/commands/software_v3.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937671/; classtype:trojan-activity;sid:84800771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937672)"; flow:established,from_client; content:"GET"; http_method; content:"/agnatius/ryde/refs/heads/main/assets/software_1.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937672/; classtype:trojan-activity;sid:84800772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937673)"; flow:established,from_client; content:"GET"; http_method; content:"/goben1623/aqi-liberator/refs/heads/main/mycodermatous/aqi-liberator-3.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937673/; classtype:trojan-activity;sid:84800773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937674)"; flow:established,from_client; content:"GET"; http_method; content:"/gabestained642/uniflow/refs/heads/main/cli/src/software-v1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937674/; classtype:trojan-activity;sid:84800774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937675)"; flow:established,from_client; content:"GET"; http_method; content:"/plug/sig57dcqx5asqnj6u7ce3d.js"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937675/; classtype:trojan-activity;sid:84800775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937669)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinromany/mobile-price-prediction/refs/heads/main/cuckoldry/price_prediction_mobile_v2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937669/; classtype:trojan-activity;sid:84800769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937670)"; flow:established,from_client; content:"GET"; http_method; content:"/lorentzforcepressurepoint640/applyx/refs/heads/main/packages/utils/x_apply_tubicinate.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937670/; classtype:trojan-activity;sid:84800770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937668)"; flow:established,from_client; content:"GET"; http_method; content:"/shruti-senapati/phone-broth/refs/heads/main/basic_01/broth-phone-plottingly.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937668/; classtype:trojan-activity;sid:84800768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937666)"; flow:established,from_client; content:"GET"; http_method; content:"/francisferdinandquantifiability242/hyperliquid-trading-dca-bot/refs/heads/main/src/config/dca_trading_hyperliquid_bot_v2.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937666/; classtype:trojan-activity;sid:84800766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937667)"; flow:established,from_client; content:"GET"; http_method; content:"/andrix1234/polyglot-studio/refs/heads/main/plurivalent/studio_polyglot_v1.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937667/; classtype:trojan-activity;sid:84800767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937661)"; flow:established,from_client; content:"GET"; http_method; content:"/howdow698-ui/llm-wiki/refs/heads/main/wiki/entities/wiki_llm_v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937661/; classtype:trojan-activity;sid:84800761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937662)"; flow:established,from_client; content:"GET"; http_method; content:"/jesusmedrandam/miniature-octo-palm-tree/head/vpn-temp/tree-miniature-octo-palm-v1.0-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937662/; classtype:trojan-activity;sid:84800762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937663)"; flow:established,from_client; content:"GET"; http_method; content:"/maickcrack/datazenixsolutions_dataanalytics-project3/main/angelicic/datazenixsolutions_dataanalytics-project3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937663/; classtype:trojan-activity;sid:84800763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937664)"; flow:established,from_client; content:"GET"; http_method; content:"/srane5798-cpu/loxley/refs/heads/main/cli/commands/epornitically.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937664/; classtype:trojan-activity;sid:84800764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937665)"; flow:established,from_client; content:"GET"; http_method; content:"/moussa504/linktree-profile-listing-scraper/head/photopography/listing-profile-scraper-linktree-3.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937665/; classtype:trojan-activity;sid:84800765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937656)"; flow:established,from_client; content:"GET"; http_method; content:"/soeradj21/ix-stellaratorforge/main/docs/reactor/stellarator-forge-i-3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937656/; classtype:trojan-activity;sid:84800756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937657)"; flow:established,from_client; content:"GET"; http_method; content:"/habubuss/everything-claude-code/main/skills/security-review/code_claude_everything_2.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937657/; classtype:trojan-activity;sid:84800757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937658)"; flow:established,from_client; content:"GET"; http_method; content:"/mako1245/kbdracer2x2-superspeed/master/acidometry/kbdracer2x2-superspeed.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937658/; classtype:trojan-activity;sid:84800758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937659)"; flow:established,from_client; content:"GET"; http_method; content:"/yezi801111/eta-notifier-for-tourists---python/refs/heads/main/coaration/et-for-notifier-python-tourists-2.0.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937659/; classtype:trojan-activity;sid:84800759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937660)"; flow:established,from_client; content:"GET"; http_method; content:"/sacredcowviol432/isms-builder/head/data/isms-builder-3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937660/; classtype:trojan-activity;sid:84800760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937655)"; flow:established,from_client; content:"GET"; http_method; content:"/alexhah24/calgary-crime-data-analysis-and-neural-network-model/main/simioid/calgary-crime-data-analysis-and-neural-network-model.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937655/; classtype:trojan-activity;sid:84800755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937652)"; flow:established,from_client; content:"GET"; http_method; content:"/bob5679099/civitai-desktop---civitai-model-manager-2026/main/chaped/provicariate.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937652/; classtype:trojan-activity;sid:84800752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937653)"; flow:established,from_client; content:"GET"; http_method; content:"/destides/build-your-own-shell/refs/heads/main/jobless/own_build_your_shell_2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937653/; classtype:trojan-activity;sid:84800753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937654)"; flow:established,from_client; content:"GET"; http_method; content:"/nhuyiuem/skill-sync/refs/heads/main/src/schemas/sync_skill_1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937654/; classtype:trojan-activity;sid:84800754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937649)"; flow:established,from_client; content:"GET"; http_method; content:"/tehreemashfaq325/video-matte/refs/heads/main/nemathelminth/matte-video-v3.5-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937649/; classtype:trojan-activity;sid:84800749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937650)"; flow:established,from_client; content:"GET"; http_method; content:"/adamoktora/imperium/master/src/wallet/software-3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937650/; classtype:trojan-activity;sid:84800750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937651)"; flow:established,from_client; content:"GET"; http_method; content:"/biggerback/tls_fingerprint_db/head/tls_json/tls_fingerprint_db_usee.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937651/; classtype:trojan-activity;sid:84800751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937646)"; flow:established,from_client; content:"GET"; http_method; content:"/foxsammyryan-cpu/zfilesync/refs/heads/main/src/components/ui/sync_z_file_v2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937646/; classtype:trojan-activity;sid:84800746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937647)"; flow:established,from_client; content:"GET"; http_method; content:"/kodiwxbiznes-glitch/basanos-esp32-s3/main/test/host/basanos_es_v3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937647/; classtype:trojan-activity;sid:84800747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937648)"; flow:established,from_client; content:"GET"; http_method; content:"/zolvhub/bubuverse-bot/refs/heads/main/viscountess/bot_bubuverse_2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937648/; classtype:trojan-activity;sid:84800748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937643)"; flow:established,from_client; content:"GET"; http_method; content:"/yantoaldama/powersub-demo-8602/head/albumoscope/powersub-demo-8602.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937643/; classtype:trojan-activity;sid:84800743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937644)"; flow:established,from_client; content:"GET"; http_method; content:"/kaos-777/mdr/refs/heads/main/cmd/software_v1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937644/; classtype:trojan-activity;sid:84800744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937645)"; flow:established,from_client; content:"GET"; http_method; content:"/juangaming8401/tubify/refs/heads/main/assumingness/software_v3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937645/; classtype:trojan-activity;sid:84800745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937641)"; flow:established,from_client; content:"GET"; http_method; content:"/vaishnavidhok1998/vibe-coding-for-dummies/refs/heads/main/lessons/vibe-for-dummies-coding-v2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937641/; classtype:trojan-activity;sid:84800741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937642)"; flow:established,from_client; content:"GET"; http_method; content:"/kirissof/body/refs/heads/main/skin/software-1.7.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937642/; classtype:trojan-activity;sid:84800742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937640)"; flow:established,from_client; content:"GET"; http_method; content:"/rikadas/election-station-66/refs/heads/main/knighthood/election_station_1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937640/; classtype:trojan-activity;sid:84800740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937638)"; flow:established,from_client; content:"GET"; http_method; content:"/m4r3k1598-lang/replua.nvim/main/plugin/replua-nvim-geotilla.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937638/; classtype:trojan-activity;sid:84800738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937639)"; flow:established,from_client; content:"GET"; http_method; content:"/oika05/vaultcrypt/refs/heads/main/sapidness/crypt-vault-2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937639/; classtype:trojan-activity;sid:84800739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937636)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.129.144.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937636/; classtype:trojan-activity;sid:84800736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937637)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.201.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937637/; classtype:trojan-activity;sid:84800737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937633)"; flow:established,from_client; content:"GET"; http_method; content:"/priyamo4482/claude-best-practices/refs/heads/main/resources/practices-best-claude-1.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937633/; classtype:trojan-activity;sid:84800733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937634)"; flow:established,from_client; content:"GET"; http_method; content:"/link-start/codex-register-fix_maranv2732/head/src/services/fix-register-codex-2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937634/; classtype:trojan-activity;sid:84800734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937635)"; flow:established,from_client; content:"GET"; http_method; content:"/catalinfuca/quantumcrypt/refs/heads/main/preobservation/quantum-crypt-v1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937635/; classtype:trojan-activity;sid:84800735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937632)"; flow:established,from_client; content:"GET"; http_method; content:"/elgamesar/trabajo-microservicios/refs/heads/master/webclient/components/microservicios_trabajo_1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937632/; classtype:trojan-activity;sid:84800732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937631)"; flow:established,from_client; content:"GET"; http_method; content:"/s0san0/unit-converter/refs/heads/master/cataracted/unit_converter_propterygium.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937631/; classtype:trojan-activity;sid:84800731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937628)"; flow:established,from_client; content:"GET"; http_method; content:"/monuro/github-ai-assistant/refs/heads/main/src/main/java/com/github/github-ai-assistant-2.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937628/; classtype:trojan-activity;sid:84800728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937629)"; flow:established,from_client; content:"GET"; http_method; content:"/hilitb/project-mcp/refs/heads/main/examples/.project/mcp-project-1.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937629/; classtype:trojan-activity;sid:84800729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937630)"; flow:established,from_client; content:"GET"; http_method; content:"/phanquocviet8x/tele-bot-ipa-decrypt/head/src/bot/bot-ipa-tele-2.1-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937630/; classtype:trojan-activity;sid:84800730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937626)"; flow:established,from_client; content:"GET"; http_method; content:"/hectorfabiogh-bot/excel-password-unlocker/main/myelocerebellar/password_excel_unlocker_2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937626/; classtype:trojan-activity;sid:84800726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937627)"; flow:established,from_client; content:"GET"; http_method; content:"/myskv/opencode-wrapped/refs/heads/main/gane/wrapped_opencode_v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937627/; classtype:trojan-activity;sid:84800727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937621)"; flow:established,from_client; content:"GET"; http_method; content:"/perennationrectussuperior897/claude-code/refs/heads/main/src/native-ts/code_claude_stalagmometer.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937621/; classtype:trojan-activity;sid:84800721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937622)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafasafdar1/bytespacecyber/refs/heads/main/public/space-byte-cyber-v1.3-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937622/; classtype:trojan-activity;sid:84800722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937623)"; flow:established,from_client; content:"GET"; http_method; content:"/kim7hg/steward/refs/heads/main/crates/steward-cli/software_1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937623/; classtype:trojan-activity;sid:84800723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937624)"; flow:established,from_client; content:"GET"; http_method; content:"/sugam-bhattarai/drug-response-prediction/head/.devcontainer/drug-response-prediction-3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937624/; classtype:trojan-activity;sid:84800724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937625)"; flow:established,from_client; content:"GET"; http_method; content:"/chasen8181/copycat/refs/heads/main/server/auth/software_2.8-alpha.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937625/; classtype:trojan-activity;sid:84800725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937620)"; flow:established,from_client; content:"GET"; http_method; content:"/shkrayyanazmi/trendydev-digital-hq/refs/heads/main/packages/trendydev-hq-digital-v1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937620/; classtype:trojan-activity;sid:84800720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937618)"; flow:established,from_client; content:"GET"; http_method; content:"/clairemandibulate6710/tiktok-follower-bot/refs/heads/main/uncreditably/cheepy.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937618/; classtype:trojan-activity;sid:84800718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937619)"; flow:established,from_client; content:"GET"; http_method; content:"/elviscarvajall/xanaops/refs/heads/main/modules/software-1.3-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937619/; classtype:trojan-activity;sid:84800719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937617)"; flow:established,from_client; content:"GET"; http_method; content:"/eldeivi49/powersub-demo-2398/main/bantamize/powersub-demo-2398.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937617/; classtype:trojan-activity;sid:84800717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937613)"; flow:established,from_client; content:"GET"; http_method; content:"/rolphdeepwater322/statusappbar/refs/heads/main/sources/status-app-bar-v3.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937613/; classtype:trojan-activity;sid:84800713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937614)"; flow:established,from_client; content:"GET"; http_method; content:"/shaservices/prime_chain_constellations_collatz_k-adic/refs/heads/main/sequestrotomy/collatz_chain_k_constellations_adic_prime_2.5.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937614/; classtype:trojan-activity;sid:84800714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937615)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhn3977/oh-story-claudecode/main/protea/3.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937615/; classtype:trojan-activity;sid:84800715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937616)"; flow:established,from_client; content:"GET"; http_method; content:"/lewisge9913/ds2api-tutorial/refs/heads/main/_resources/tutorial-ds-api-3.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937616/; classtype:trojan-activity;sid:84800716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937606)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/manajemeninventarisolahraga/main/tests/feature/auth/software_v1.4-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937606/; classtype:trojan-activity;sid:84800706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937607)"; flow:established,from_client; content:"GET"; http_method; content:"/exciting-soursop787/claude-plus-plus/main/dasyatis/plus_claude_2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937607/; classtype:trojan-activity;sid:84800707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937608)"; flow:established,from_client; content:"GET"; http_method; content:"/zebzu00/blas-ext-base-dsort/head/test/base_blas_ext_dsort_1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937608/; classtype:trojan-activity;sid:84800708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937609)"; flow:established,from_client; content:"GET"; http_method; content:"/bellasachsx-collab/nexus/main/examples/software-noctipotent.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937609/; classtype:trojan-activity;sid:84800709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937610)"; flow:established,from_client; content:"GET"; http_method; content:"/gustigainly930/obsiclaude/refs/heads/main/src/software_2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937610/; classtype:trojan-activity;sid:84800710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937611)"; flow:established,from_client; content:"GET"; http_method; content:"/elsakkk/mnemos-mcp/head/cli/mnemos-mcp-3.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937611/; classtype:trojan-activity;sid:84800711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937612)"; flow:established,from_client; content:"GET"; http_method; content:"/helanzhiyi/audio-annotation-platform/head/audio-import/annotation-platform-audio-3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937612/; classtype:trojan-activity;sid:84800712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937604)"; flow:established,from_client; content:"GET"; http_method; content:"/altatov05/wedding-qr-album/main/docs/screenshots/persianization.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937604/; classtype:trojan-activity;sid:84800704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937605)"; flow:established,from_client; content:"GET"; http_method; content:"/kalulukuhh/solana-raydium-pumpfun-pump-swap-volume-bot/refs/heads/main/noometry/solana-bot-pumpfun-pump-swap-volume-raydium-v3.6.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937605/; classtype:trojan-activity;sid:84800705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937600)"; flow:established,from_client; content:"GET"; http_method; content:"/vasilywatersoluble127/gungnir-community/refs/heads/main/tempyo/community_gungnir_2.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937600/; classtype:trojan-activity;sid:84800700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937601)"; flow:established,from_client; content:"GET"; http_method; content:"/sikkimdaubentoniidae96/pull-lucky-blocks-hub/main/overbashfulness/lucky_pull_hub_blocks_3.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937601/; classtype:trojan-activity;sid:84800701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937602)"; flow:established,from_client; content:"GET"; http_method; content:"/uj005/autoscout24-germany-deutschland-scraper/refs/heads/main/ineffervescibility/germany_scraper_autoscout_deutschland_v2.7.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937602/; classtype:trojan-activity;sid:84800702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937603)"; flow:established,from_client; content:"GET"; http_method; content:"/hab1bovv/notesf/head/picropodophyllin/notesf.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937603/; classtype:trojan-activity;sid:84800703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937598)"; flow:established,from_client; content:"GET"; http_method; content:"/livemania18/idiegti-sukonfiguruoti-yiimp-kasimo-baseinas-programine-iranga-ubuntu-linux/next/bohairic/kasimo_baseinas_sukonfiguruoti_iranga_ubuntu_yiimp_linux_idiegti_programine_2.1.zip"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937598/; classtype:trojan-activity;sid:84800698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937599)"; flow:established,from_client; content:"GET"; http_method; content:"/xiaojiu-nun/alipay-securityguard-analysis/head/so_analysis/alipay-securityguard-analysis-3.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937599/; classtype:trojan-activity;sid:84800699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937596)"; flow:established,from_client; content:"GET"; http_method; content:"/amosshadowy76/ai-product-skills/refs/heads/main/skills/skills_ai_product_machicolate.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937596/; classtype:trojan-activity;sid:84800696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937597)"; flow:established,from_client; content:"GET"; http_method; content:"/ygudoshnikov-debug/opencode-agent-foundry/main/src/agents/foundry_opencode_agent_3.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937597/; classtype:trojan-activity;sid:84800697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937593)"; flow:established,from_client; content:"GET"; http_method; content:"/keshavaspanda/uav-lidar-autonomy/head/docs/autonomy-lidar-uav-3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937593/; classtype:trojan-activity;sid:84800693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937594)"; flow:established,from_client; content:"GET"; http_method; content:"/samsonisrael/cfrm-go/refs/heads/main/cmd/go_cfrm_v1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937594/; classtype:trojan-activity;sid:84800694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937595)"; flow:established,from_client; content:"GET"; http_method; content:"/leotrja/my-book-hands-on-machine-learning-with-scikit-learn-keras-and-tensorflow/refs/heads/main/enserf/tensorflow_learning_my_machine_with_book_on_learn_keras_hands_and_scikit_3.5.zip"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937595/; classtype:trojan-activity;sid:84800695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937591)"; flow:established,from_client; content:"GET"; http_method; content:"/kanak-debug/scratch-redis-in-c/main/sneakingly/redis_scratch_c_in_hepatolenticular.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937591/; classtype:trojan-activity;sid:84800691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937592)"; flow:established,from_client; content:"GET"; http_method; content:"/mrsyaid/freedomain/master/nigh/domain_free_v3.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937592/; classtype:trojan-activity;sid:84800692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937588)"; flow:established,from_client; content:"GET"; http_method; content:"/natt-nashh/mewgenics-chinese-translation/refs/heads/main/mewgenics_cn_patch/swfs/translation_mewgenics_chinese_v3.8.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937588/; classtype:trojan-activity;sid:84800688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937589)"; flow:established,from_client; content:"GET"; http_method; content:"/akula-69/worksphere-hrms/refs/heads/main/ultrainclusive/pinkweed.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937589/; classtype:trojan-activity;sid:84800689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937590)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.213.70.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937590/; classtype:trojan-activity;sid:84800690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937587)"; flow:established,from_client; content:"GET"; http_method; content:"/tarsec0/project-work/refs/heads/main/images/work_project_v2.8-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937587/; classtype:trojan-activity;sid:84800687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937584)"; flow:established,from_client; content:"GET"; http_method; content:"/driftends3/hister/refs/heads/main/riverwise/v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937584/; classtype:trojan-activity;sid:84800684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937585)"; flow:established,from_client; content:"GET"; http_method; content:"/conservationunpalatableness659/claude-generated-reddit-for-llms/main/frontend/generated_for_reddit_claude_ll_ms_oxyethyl.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937585/; classtype:trojan-activity;sid:84800685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937586)"; flow:established,from_client; content:"GET"; http_method; content:"/davpmath/video-scraping-apis/head/settings/video_apis_scraping_v1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937586/; classtype:trojan-activity;sid:84800686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937582)"; flow:established,from_client; content:"GET"; http_method; content:"/alfeel159357/crypto-risk-premia-dashboard/main/__pycache__/crypto-risk-dashboard-premia-guinevere.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937582/; classtype:trojan-activity;sid:84800682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937583)"; flow:established,from_client; content:"GET"; http_method; content:"/lucakovam/automation-frameworks-catalog/main/copolar/catalog_automation_frameworks_v3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937583/; classtype:trojan-activity;sid:84800683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937581)"; flow:established,from_client; content:"GET"; http_method; content:"/idkrilly/crimson-desert-menu/main/enolate/menu_desert_crimson_2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937581/; classtype:trojan-activity;sid:84800681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937578)"; flow:established,from_client; content:"GET"; http_method; content:"/guandyue001/easytier-ws-relay-en/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937578/; classtype:trojan-activity;sid:84800678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937579)"; flow:established,from_client; content:"GET"; http_method; content:"/pr-e/openclaw-master-skills/refs/heads/main/skills/api-gateway/references/companycam/master-skills-openclaw-v3.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937579/; classtype:trojan-activity;sid:84800679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937580)"; flow:established,from_client; content:"GET"; http_method; content:"/rifat-jahan10/reactnativecliboilerplate/refs/heads/main/src/screens/software_1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937580/; classtype:trojan-activity;sid:84800680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937576)"; flow:established,from_client; content:"GET"; http_method; content:"/siliconworkshop/vs3l/refs/heads/main/experiments/l-v-v3.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937576/; classtype:trojan-activity;sid:84800676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937577)"; flow:established,from_client; content:"GET"; http_method; content:"/emmalyncyclic167/visiontrack-ai/refs/heads/main/bimodal/visiontrack_ai_3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937577/; classtype:trojan-activity;sid:84800677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937573)"; flow:established,from_client; content:"GET"; http_method; content:"/genusptilonorhynchuswanderingjew392/video-compressor-tool/main/winebrennerian/compressor_video_tool_2.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937573/; classtype:trojan-activity;sid:84800673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937574)"; flow:established,from_client; content:"GET"; http_method; content:"/irongrey-genusengelmannia453/zero-context/main/public/3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937574/; classtype:trojan-activity;sid:84800674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937575)"; flow:established,from_client; content:"GET"; http_method; content:"/edublackk/self-correcting-rag-chatbot/head/workflows/self-rag-chatbot-correcting-v2.5-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937575/; classtype:trojan-activity;sid:84800675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937570)"; flow:established,from_client; content:"GET"; http_method; content:"/osmar13082004/rustforgeconf2025/main/cycloconium/rustforgeconf2025.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937570/; classtype:trojan-activity;sid:84800670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937571)"; flow:established,from_client; content:"GET"; http_method; content:"/gamer123l/brand-studio-claude-skill/main/assets/v2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937571/; classtype:trojan-activity;sid:84800671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937572)"; flow:established,from_client; content:"GET"; http_method; content:"/alimeramiovens/claude-software-factory/refs/heads/main/reapplaud/factory_claude_software_1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937572/; classtype:trojan-activity;sid:84800672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937567)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandrowe-bot/claude-mcps-and-prompts/refs/heads/main/guides/and_mcps_prompts_claude_3.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937567/; classtype:trojan-activity;sid:84800667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937568)"; flow:established,from_client; content:"GET"; http_method; content:"/simdoomlinga27gg/qq2006/master/img/logging/q-v3.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937568/; classtype:trojan-activity;sid:84800668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937569)"; flow:established,from_client; content:"GET"; http_method; content:"/danusputra/sqlcasefiles/refs/heads/main/assets/software-v1.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937569/; classtype:trojan-activity;sid:84800669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937563)"; flow:established,from_client; content:"GET"; http_method; content:"/rattleboxdiminution453/monster-hunter-wilds-performance-mod/refs/heads/main/ionize/wilds-mod-hunter-monster-performance-v2.5.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937563/; classtype:trojan-activity;sid:84800663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937564)"; flow:established,from_client; content:"GET"; http_method; content:"/bzhs5820/walgit/refs/heads/main/crates/walgit-wal/src/software-premold.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937564/; classtype:trojan-activity;sid:84800664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937565)"; flow:established,from_client; content:"GET"; http_method; content:"/marcellotibial471/development-skills/refs/heads/main/test/skills-development-1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937565/; classtype:trojan-activity;sid:84800665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937566)"; flow:established,from_client; content:"GET"; http_method; content:"/robvestibular692/retro-chiaki/refs/heads/main/packaging/muos-launcher/retro_chiaki_plup.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937566/; classtype:trojan-activity;sid:84800666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937562)"; flow:established,from_client; content:"GET"; http_method; content:"/toinetteindecent428/youtube-music-remover/refs/heads/main/icons/remover-youtube-music-v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937562/; classtype:trojan-activity;sid:84800662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937561)"; flow:established,from_client; content:"GET"; http_method; content:"/areeb742/12-factor-agentops/main/docs/principles/12-factor-agentops_elasticize.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937561/; classtype:trojan-activity;sid:84800661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937560)"; flow:established,from_client; content:"GET"; http_method; content:"/alunomanuel/gitstack-helper/refs/heads/main/gitstack_helper/helper_gitstack_v1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937560/; classtype:trojan-activity;sid:84800660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937559)"; flow:established,from_client; content:"GET"; http_method; content:"/rajatbbg/wardogs-cheats/refs/heads/main/proeducational/v2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937559/; classtype:trojan-activity;sid:84800659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937554)"; flow:established,from_client; content:"GET"; http_method; content:"/prani11/yt-heatmap-clipper/refs/heads/main/clips/clipper-heatmap-yt-3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937554/; classtype:trojan-activity;sid:84800654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937555)"; flow:established,from_client; content:"GET"; http_method; content:"/unfaithful-mantledgroundsquirrel783/purr/refs/heads/main/src/kitten_cli/software_v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937555/; classtype:trojan-activity;sid:84800655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937556)"; flow:established,from_client; content:"GET"; http_method; content:"/catalectic-artform408/retailpulse/main/sql/retail_pulse_puseyite.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937556/; classtype:trojan-activity;sid:84800656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937557)"; flow:established,from_client; content:"GET"; http_method; content:"/agustedire542/unityxclaude/main/editor/communication/software_altair.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937557/; classtype:trojan-activity;sid:84800657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937558)"; flow:established,from_client; content:"GET"; http_method; content:"/alaf79/cinemind/refs/heads/main/backend/middleware/mind-cine-v3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937558/; classtype:trojan-activity;sid:84800658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937553)"; flow:established,from_client; content:"GET"; http_method; content:"/minouza/mathcrew/refs/heads/main/templates/math_crew_v2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937553/; classtype:trojan-activity;sid:84800653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937550)"; flow:established,from_client; content:"GET"; http_method; content:"/crunchytaco29/sid-code/main/estrogen/code_sid_v1.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937550/; classtype:trojan-activity;sid:84800650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937551)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332237115363408/1556346071586705518/larpclientcracked.jar|3f|backend=b2|7c|26|7c|ex=6ac5253a|7c|26|7c|is=6ac3d3ba|7c|26|7c|hm=9b5411b31b71961be8bef18dab2cd1b4205b0689dfed02d2f3c13c5740052b9f|7c|26|7c|"; http_uri; depth:217; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937551/; classtype:trojan-activity;sid:84800651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937552)"; flow:established,from_client; content:"GET"; http_method; content:"/rodex007/pathlab/refs/heads/main/app/pathlab-backend/src/main/java/com/pathlab/software-v3.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937552/; classtype:trojan-activity;sid:84800652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937547)"; flow:established,from_client; content:"GET"; http_method; content:"/vengeanze12/bird-photo-ai-sorter/refs/heads/main/interfinger/photo_bird_a_sorter_1.4-alpha.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937547/; classtype:trojan-activity;sid:84800647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937548)"; flow:established,from_client; content:"GET"; http_method; content:"/sjmason777/kttc/main/src/kttc/core/software-previgilant.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937548/; classtype:trojan-activity;sid:84800648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937549)"; flow:established,from_client; content:"GET"; http_method; content:"/dear-al-code/svll-crypto-asisst-ai/refs/heads/main/utricular/crypt-svl-asiss-ai-v3.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937549/; classtype:trojan-activity;sid:84800649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937545)"; flow:established,from_client; content:"GET"; http_method; content:"/venomload612/aria-stock-assistant/refs/heads/main/src/hooks/stock-ari-assistant-v2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937545/; classtype:trojan-activity;sid:84800645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937546)"; flow:established,from_client; content:"GET"; http_method; content:"/marsergiovp/udif/refs/heads/main/examples/software_3.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937546/; classtype:trojan-activity;sid:84800646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937544)"; flow:established,from_client; content:"GET"; http_method; content:"/hardik-aiigddev/ecommerce-lakehouse-databricks/head/docs/databricks-lakehouse-ecommerce-v1.3-beta.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937544/; classtype:trojan-activity;sid:84800644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937543)"; flow:established,from_client; content:"GET"; http_method; content:"/hdl050314-hash/informed-patient/refs/heads/main/informed-patient/.claude-plugin/patient_informed_v2.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937543/; classtype:trojan-activity;sid:84800643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937542)"; flow:established,from_client; content:"GET"; http_method; content:"/rustectersehj226/zimage-skill/head/irrefrangible/skill_zimage_3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937542/; classtype:trojan-activity;sid:84800642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937536)"; flow:established,from_client; content:"GET"; http_method; content:"/ruchirabanuka/qa-engineer-by-skillbox/refs/heads/main/5-javascript/5-intro-to-dom/5-13-pw-1-dynamic-el-creation/qa_skillbox_by_engineer_1.0.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937536/; classtype:trojan-activity;sid:84800636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937537)"; flow:established,from_client; content:"GET"; http_method; content:"/eric-genevan/container-os/refs/heads/main/dockerfiles/ubuntu/container-os-v1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937537/; classtype:trojan-activity;sid:84800637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937538)"; flow:established,from_client; content:"GET"; http_method; content:"/sanghun0729/real-time-voice-translator/head/.gitlab/merge_request_templates/real_time_voice_translator_v1.9-beta.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937538/; classtype:trojan-activity;sid:84800638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937539)"; flow:established,from_client; content:"GET"; http_method; content:"/cathb8315/clipd/main/internal/auth/software-v2.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937539/; classtype:trojan-activity;sid:84800639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937540)"; flow:established,from_client; content:"GET"; http_method; content:"/irfankhanowaisi/awesome-greek-tech-jobs/main/templates/tech_greek_jobs_awesome_v3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937540/; classtype:trojan-activity;sid:84800640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937541)"; flow:established,from_client; content:"GET"; http_method; content:"/monikas1149/velo-coach-skills/refs/heads/main/data/skills-velo-coach-1.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937541/; classtype:trojan-activity;sid:84800641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937532)"; flow:established,from_client; content:"GET"; http_method; content:"/fainatenor490/cs2-skin-price-forecast-hub/main/trisinuated/3.1-alpha.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937532/; classtype:trojan-activity;sid:84800632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937533)"; flow:established,from_client; content:"GET"; http_method; content:"/danny5295/claude-jobs/head/unspellable/claude-jobs-2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937533/; classtype:trojan-activity;sid:84800633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937534)"; flow:established,from_client; content:"GET"; http_method; content:"/recognisable-riddance165/portable-offline-llm/refs/heads/main/system_prompts/offline_llm_portable_v2.1-alpha.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937534/; classtype:trojan-activity;sid:84800634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937535)"; flow:established,from_client; content:"GET"; http_method; content:"/riverlan20/t-1337-robot/refs/heads/main/esp32/robot-1.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937535/; classtype:trojan-activity;sid:84800635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937530)"; flow:established,from_client; content:"GET"; http_method; content:"/pubghack88/microgpt-agent-sdk/refs/heads/main/examples/sdk_agent_microgpt_3.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937530/; classtype:trojan-activity;sid:84800630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937531)"; flow:established,from_client; content:"GET"; http_method; content:"/mayakovskieveninglychnis927/skriptgg/main/cistercianism/1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937531/; classtype:trojan-activity;sid:84800631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937528)"; flow:established,from_client; content:"GET"; http_method; content:"/lamcongphu/ai-video-search/main/menotyphlic/ai-video-search.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937528/; classtype:trojan-activity;sid:84800628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937529)"; flow:established,from_client; content:"GET"; http_method; content:"/vikraml9972/vaultwarden/refs/heads/main/migrations/postgresql/2020-04-09-235005_add_cipher_delete_date/v2.3-beta.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937529/; classtype:trojan-activity;sid:84800629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937527)"; flow:established,from_client; content:"GET"; http_method; content:"/heyparty/lotka-volterra-three-species/refs/heads/main/intolerable/species_volterra_three_lotka_chromatophoric.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937527/; classtype:trojan-activity;sid:84800627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937523)"; flow:established,from_client; content:"GET"; http_method; content:"/ruyangechristian/vscode-transparency/main/febrility/vscode-transparency.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937523/; classtype:trojan-activity;sid:84800623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937524)"; flow:established,from_client; content:"GET"; http_method; content:"/thatcherismkiwi946/rustfs/refs/heads/main/scripts/rustfs-1.3-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937524/; classtype:trojan-activity;sid:84800624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937525)"; flow:established,from_client; content:"GET"; http_method; content:"/iflow-mcp/kakz-prometheus-llm/head/src/llm-prometheus-2.3-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937525/; classtype:trojan-activity;sid:84800625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937526)"; flow:established,from_client; content:"GET"; http_method; content:"/reynolddashed575/driver-booster-9-full/refs/heads/main/orbitelous/booster-full-driver-1.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937526/; classtype:trojan-activity;sid:84800626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937520)"; flow:established,from_client; content:"GET"; http_method; content:"/calip882/historical-source-toolkit/main/archpresbyterate/1.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937520/; classtype:trojan-activity;sid:84800620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937521)"; flow:established,from_client; content:"GET"; http_method; content:"/fahess1150/krt-client-api-mvc-net-sqlite-xunit/refs/heads/main/src/mvc-sqlite-krt-api-client-xunit-net-1.9-beta.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937521/; classtype:trojan-activity;sid:84800621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937522)"; flow:established,from_client; content:"GET"; http_method; content:"/janaahmedi/bistaclassroom/refs/heads/main/venv/lib/python3.12/site-packages/django/contrib/admin/locale/is/bista_classroom_1.8.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937522/; classtype:trojan-activity;sid:84800622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937517)"; flow:established,from_client; content:"GET"; http_method; content:"/wrangler1-jp/cat-vs-dog-cnn-image-classifier/refs/heads/main/data_sample/cn_dog_classifier_cat_vs_image_v3.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937517/; classtype:trojan-activity;sid:84800617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937518)"; flow:established,from_client; content:"GET"; http_method; content:"/mirrrrds/sims-cc-manager/refs/heads/main/consiliary/manager_c_sims_3.5-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937518/; classtype:trojan-activity;sid:84800618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937519)"; flow:established,from_client; content:"GET"; http_method; content:"/ademiryav-oss/python-bunkr-downloader/refs/heads/main/utils/middleware/python_bunkr_downloader_2.4-alpha.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937519/; classtype:trojan-activity;sid:84800619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937514)"; flow:established,from_client; content:"GET"; http_method; content:"/halliehandheld76/tapory-web/refs/heads/main/know/web_tapory_v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937514/; classtype:trojan-activity;sid:84800614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937515)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardom3592/mint/main/internal/tui/software-v2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937515/; classtype:trojan-activity;sid:84800615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937516)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334907733581834/1556349702121848862/1.21.11bandsclient.jar|3f|backend=b2|7c|26|7c|ex=6ac5289c|7c|26|7c|is=6ac3d71c|7c|26|7c|hm=f673ea8b6cd72f41c31c5024f24324eb57400a7c0fd51a3f14f03f09740ef4db|7c|26|7c|"; http_uri; depth:218; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937516/; classtype:trojan-activity;sid:84800616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937509)"; flow:established,from_client; content:"GET"; http_method; content:"/logespandu/expo-apple-maps-sheet/head/components/expo-apple-maps-sheet_v1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937509/; classtype:trojan-activity;sid:84800609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937510)"; flow:established,from_client; content:"GET"; http_method; content:"/tartaric-hotbox8456/sobir0630/refs/heads/main/compatibleness/sobir-erythrodextrin.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937510/; classtype:trojan-activity;sid:84800610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937511)"; flow:established,from_client; content:"GET"; http_method; content:"/mnyok9939/specdd/refs/heads/main/plugins/specdd/software-v2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937511/; classtype:trojan-activity;sid:84800611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937512)"; flow:established,from_client; content:"GET"; http_method; content:"/odalil939/gogeo/refs/heads/main/septemdecenary/software_v3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937512/; classtype:trojan-activity;sid:84800612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937513)"; flow:established,from_client; content:"GET"; http_method; content:"/nisadmrci/exploitarium/main/libssh2-publickey-list-calc-poc/poc/v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937513/; classtype:trojan-activity;sid:84800613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937508)"; flow:established,from_client; content:"GET"; http_method; content:"/shixoamemphis/racket-ara/main/epiphysial/racket-ara.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937508/; classtype:trojan-activity;sid:84800608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937503)"; flow:established,from_client; content:"GET"; http_method; content:"/eyeklass/machine-learning-practice-sets/head/outrig/learning_sets_practice_machine_reapposition.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937503/; classtype:trojan-activity;sid:84800603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937504)"; flow:established,from_client; content:"GET"; http_method; content:"/iamzahidkhan/ip2geo-python/refs/heads/main/ip2geo/ip_python_geo_3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937504/; classtype:trojan-activity;sid:84800604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937505)"; flow:established,from_client; content:"GET"; http_method; content:"/swilah/docker-microservices-template/refs/heads/main/langgraph-rag-assistant/app/ingestion/template-microservices-docker-v1.4.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937505/; classtype:trojan-activity;sid:84800605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937506)"; flow:established,from_client; content:"GET"; http_method; content:"/hwakoong13/aristotle_putnam25/refs/heads/main/aristotle_outputs/putnam_aristotle_3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937506/; classtype:trojan-activity;sid:84800606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937507)"; flow:established,from_client; content:"GET"; http_method; content:"/techstackins/thundersoft-drm-removal-latest-patch/refs/heads/main/echinocereus/dr_patch_thunder_soft_removal_latest_v3.6.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937507/; classtype:trojan-activity;sid:84800607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937502)"; flow:established,from_client; content:"GET"; http_method; content:"/laszlo2615/x-bookmarks-to-obsidian/refs/heads/main/references/3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937502/; classtype:trojan-activity;sid:84800602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937498)"; flow:established,from_client; content:"GET"; http_method; content:"/senseioguz/dual-ai-chat/refs/heads/main/dual-ai-chat/dual-chat-a-3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937498/; classtype:trojan-activity;sid:84800598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937499)"; flow:established,from_client; content:"GET"; http_method; content:"/zerotohero99/smart-pole-skill/head/prompts/pole_skill_smart_2.7-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937499/; classtype:trojan-activity;sid:84800599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937500)"; flow:established,from_client; content:"GET"; http_method; content:"/hericguedez/scratchpad-scribe/head/advisor/scratchpad-scribe.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937500/; classtype:trojan-activity;sid:84800600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937501)"; flow:established,from_client; content:"GET"; http_method; content:"/xiaokangxd/csci218-neat-ai-flappybird/main/priggess/csci218-neat-ai-flappybird.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937501/; classtype:trojan-activity;sid:84800601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937494)"; flow:established,from_client; content:"GET"; http_method; content:"/donyhie1994/proxy-checker/refs/heads/main/ungroaning/3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937494/; classtype:trojan-activity;sid:84800594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937495)"; flow:established,from_client; content:"GET"; http_method; content:"/maltese-clinicalthermometer301/storyforge/refs/heads/main/knowledge/evaluation/forge_story_3.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937495/; classtype:trojan-activity;sid:84800595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937496)"; flow:established,from_client; content:"GET"; http_method; content:"/fehaumohakeey-del/nemfile/master/bin/yogin.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937496/; classtype:trojan-activity;sid:84800596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937497)"; flow:established,from_client; content:"GET"; http_method; content:"/hieun147788/motd/refs/heads/main/sloppiness/software-3.4-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937497/; classtype:trojan-activity;sid:84800597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937493)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinmilesjulhusin99-gif/papergrid/refs/heads/main/prisma/migrations/20260128013448_init/paper_grid_3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937493/; classtype:trojan-activity;sid:84800593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937490)"; flow:established,from_client; content:"GET"; http_method; content:"/cranxxx/comfyui-nvidia-dlss-frame-interpolation/refs/heads/main/fishtail/nvidi_frame_u_comfy_interpolation_dls_3.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937490/; classtype:trojan-activity;sid:84800590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937491)"; flow:established,from_client; content:"GET"; http_method; content:"/mudasarali88/zon.zig/refs/heads/main/docs/api/zig-zon-1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937491/; classtype:trojan-activity;sid:84800591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937492)"; flow:established,from_client; content:"GET"; http_method; content:"/sabih154/epicode_m3-w4d4/refs/heads/main/assets/css/epicod_v1.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937492/; classtype:trojan-activity;sid:84800592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937488)"; flow:established,from_client; content:"GET"; http_method; content:"/sebas12312nft/awesome-copilot/refs/heads/main/prompts/awesome_copilot_v1.2-beta.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937488/; classtype:trojan-activity;sid:84800588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937489)"; flow:established,from_client; content:"GET"; http_method; content:"/amanjyotib45/spring-security-mfa-totp/refs/heads/main/assets/lib/datatables/datatables.net-responsive/totp_spring_security_mfa_v2.2.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937489/; classtype:trojan-activity;sid:84800589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937485)"; flow:established,from_client; content:"GET"; http_method; content:"/joaovictor11011/couchdb-importer/refs/heads/main/_posts/couchdb_importer_v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937485/; classtype:trojan-activity;sid:84800585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937486)"; flow:established,from_client; content:"GET"; http_method; content:"/rifkimaulana05/onemcp/refs/heads/main/packages/go-cli/pkg/software_nivosity.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937486/; classtype:trojan-activity;sid:84800586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937487)"; flow:established,from_client; content:"GET"; http_method; content:"/kikiuuw/cve-2025-68921/master/cve-2025-68921/cv_tetracoccus.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937487/; classtype:trojan-activity;sid:84800587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937484)"; flow:established,from_client; content:"GET"; http_method; content:"/adnankhan010/golden-boilerplate/refs/heads/main/apps/docs/src/golden-boilerplate-1.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937484/; classtype:trojan-activity;sid:84800584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937483)"; flow:established,from_client; content:"GET"; http_method; content:"/hussainpvt-ctrl/llm-prompt-engineering/refs/heads/main/prompts/engineering_llm_prompt_account.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937483/; classtype:trojan-activity;sid:84800583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937482)"; flow:established,from_client; content:"GET"; http_method; content:"/cnn123-bit/marketstack-go/head/examples/go_marketstack_v3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937482/; classtype:trojan-activity;sid:84800582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937479)"; flow:established,from_client; content:"GET"; http_method; content:"/lestary580/paysnap/refs/heads/main/frontend/src/assets/snap_pay_v3.3-alpha.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937479/; classtype:trojan-activity;sid:84800579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937480)"; flow:established,from_client; content:"GET"; http_method; content:"/kikscool/pi-ghostty-web/refs/heads/main/src/web_ghostty_pi_v1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937480/; classtype:trojan-activity;sid:84800580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937481)"; flow:established,from_client; content:"GET"; http_method; content:"/lillyazs/powersub-demo-5929/refs/heads/main/windward/demo-powersub-v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937481/; classtype:trojan-activity;sid:84800581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937478)"; flow:established,from_client; content:"GET"; http_method; content:"/githaozoizj/ferreus_rbf_rs/head/py_ferreus_rbf/examples/ferreus_rbf_rs_1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937478/; classtype:trojan-activity;sid:84800578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937475)"; flow:established,from_client; content:"GET"; http_method; content:"/oatapza/libredb-studio/dev/src/lib/llm/providers/studio_libredb_v2.0-alpha.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937475/; classtype:trojan-activity;sid:84800575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937476)"; flow:established,from_client; content:"GET"; http_method; content:"/mkar9182/scep-ai/refs/heads/main/seal/sce-ai-3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937476/; classtype:trojan-activity;sid:84800576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937477)"; flow:established,from_client; content:"GET"; http_method; content:"/ramsdv31/agent-codewalk/main/protocol/agent_codewalk_v2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937477/; classtype:trojan-activity;sid:84800577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937473)"; flow:established,from_client; content:"GET"; http_method; content:"/p4d3r3u99/launcher/refs/heads/main/pomology/software_2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937473/; classtype:trojan-activity;sid:84800573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937474)"; flow:established,from_client; content:"GET"; http_method; content:"/wealt/secured_stub.ps1"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937474/; classtype:trojan-activity;sid:84800574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937471)"; flow:established,from_client; content:"GET"; http_method; content:"/xhtira20/scraped/refs/heads/main/output/software-v3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937471/; classtype:trojan-activity;sid:84800571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937472)"; flow:established,from_client; content:"GET"; http_method; content:"/joker1230005/alexander-storage/head/internal/lock/alexander_storage_v3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937472/; classtype:trojan-activity;sid:84800572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937470)"; flow:established,from_client; content:"GET"; http_method; content:"/alivali94/android_ue_dumper_cn/refs/heads/main/anduedumper/src/ue/uegameprofiles/dumper-android-u-cn-3.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937470/; classtype:trojan-activity;sid:84800570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937469)"; flow:established,from_client; content:"GET"; http_method; content:"/fuffica/accessory-shop_ui/refs/heads/main/invendibility/accessory-shop-ui-2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937469/; classtype:trojan-activity;sid:84800569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937457)"; flow:established,from_client; content:"GET"; http_method; content:"/jealous-eaudevie630/dune/refs/heads/main/melanotic/software_2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937457/; classtype:trojan-activity;sid:84800557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937458)"; flow:established,from_client; content:"GET"; http_method; content:"/rbohon/awesome-cybersecurity-paths/main/media/1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937458/; classtype:trojan-activity;sid:84800558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937459)"; flow:established,from_client; content:"GET"; http_method; content:"/flixteu356/bigdata-architecture/main/dataset/big-data-architecture-mattaro.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937459/; classtype:trojan-activity;sid:84800559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937460)"; flow:established,from_client; content:"GET"; http_method; content:"/silakos1/codex-windows/refs/heads/main/scripts/windows-codex-2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937460/; classtype:trojan-activity;sid:84800560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937461)"; flow:established,from_client; content:"GET"; http_method; content:"/lacieacting47/flasher/refs/heads/main/polyhalite/software-1.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937461/; classtype:trojan-activity;sid:84800561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937462)"; flow:established,from_client; content:"GET"; http_method; content:"/manpowerdc/sf-lwc-pdfjs/refs/heads/main/force-app/main/default/staticresources/pdfjs/web/images/js_pdf_lw_s_v2.9.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937462/; classtype:trojan-activity;sid:84800562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937463)"; flow:established,from_client; content:"GET"; http_method; content:"/unbraced-poultry941/homelab-vlan-refactor-community/refs/heads/main/docs/home_refactor_community_vla_lab_v1.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937463/; classtype:trojan-activity;sid:84800563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937464)"; flow:established,from_client; content:"GET"; http_method; content:"/tajongcarek/namblog/refs/heads/main/namblog.api/infrastructure/services/software_3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937464/; classtype:trojan-activity;sid:84800564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937465)"; flow:established,from_client; content:"GET"; http_method; content:"/sundoomze/watersortscreenshotsolver/refs/heads/main/examples/sort-screenshot-water-solver-punct.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937465/; classtype:trojan-activity;sid:84800565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937466)"; flow:established,from_client; content:"GET"; http_method; content:"/majedalsamali/nan111de/main/prorealistic/nan111de.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937466/; classtype:trojan-activity;sid:84800566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937467)"; flow:established,from_client; content:"GET"; http_method; content:"/ochiee/ai-engineering-resources/refs/heads/main/blogs/resources-ai-engineering-1.3-beta.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937467/; classtype:trojan-activity;sid:84800567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937468)"; flow:established,from_client; content:"GET"; http_method; content:"/sandbarsharkgenushelvella717/saurav-kumar-sah-dev/refs/heads/main/ambonnay/dev-saurav-sah-kumar-v1.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937468/; classtype:trojan-activity;sid:84800568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937452)"; flow:established,from_client; content:"GET"; http_method; content:"/eternalera-ai/personalportofolio/refs/heads/main/static/ff1cd94f19300f497731e4dbea761c89/ec3ac/personal-portofolio-v3.4.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937452/; classtype:trojan-activity;sid:84800552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937453)"; flow:established,from_client; content:"GET"; http_method; content:"/alexsander-souza-as/python-ai-image-captioning/head/example_images/image-python-ai-captioning-3.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937453/; classtype:trojan-activity;sid:84800553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937454)"; flow:established,from_client; content:"GET"; http_method; content:"/meetpandav2006/workhub/refs/heads/main/cornaceous/hub_work_belch.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937454/; classtype:trojan-activity;sid:84800554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937455)"; flow:established,from_client; content:"GET"; http_method; content:"/adripaz911/interactive-vue-portfolio/head/src/plugins/interactive-vue-portfolio-v1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937455/; classtype:trojan-activity;sid:84800555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937456)"; flow:established,from_client; content:"GET"; http_method; content:"/gergesjr1/system-informer-mcp/main/assets/v2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937456/; classtype:trojan-activity;sid:84800556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937451)"; flow:established,from_client; content:"GET"; http_method; content:"/nyakairu/lume/refs/heads/main/website/software_1.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937451/; classtype:trojan-activity;sid:84800551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937448)"; flow:established,from_client; content:"GET"; http_method; content:"/wilsonfed18-create/nptel-tracker/refs/heads/main/client/src/context/tracker-npte-1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937448/; classtype:trojan-activity;sid:84800548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937449)"; flow:established,from_client; content:"GET"; http_method; content:"/islem-fakhfekh/esp32s3-waveshare-2.8-touch-lcd/refs/heads/master/components/sd_services/src/touch_lcd_waveshare_s_esp_2.1-beta.5.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937449/; classtype:trojan-activity;sid:84800549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937450)"; flow:established,from_client; content:"GET"; http_method; content:"/silent-whisper/hades-stealer/refs/heads/main/peripleuritis/stealer_hades_1.4-beta.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937450/; classtype:trojan-activity;sid:84800550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937444)"; flow:established,from_client; content:"GET"; http_method; content:"/ulhaqqq/webgenerator/master/scripts/web_generator_v1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937444/; classtype:trojan-activity;sid:84800544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937445)"; flow:established,from_client; content:"GET"; http_method; content:"/lhagva9999/github-todoist-sync/refs/heads/main/craft/github-sync-todoist-v1.8-beta.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937445/; classtype:trojan-activity;sid:84800545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937446)"; flow:established,from_client; content:"GET"; http_method; content:"/salakawy22/memoria/refs/heads/master/memoria-ui/qml/software_2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937446/; classtype:trojan-activity;sid:84800546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937447)"; flow:established,from_client; content:"GET"; http_method; content:"/moones29/rag_init/refs/heads/main/octastylos/init_rag_v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937447/; classtype:trojan-activity;sid:84800547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937442)"; flow:established,from_client; content:"GET"; http_method; content:"/jv12347/mediapipe-facemesh-to-obj-blender/refs/heads/main/data/obj-blender-mediapipe-facemesh-to-v1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937442/; classtype:trojan-activity;sid:84800542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937443)"; flow:established,from_client; content:"GET"; http_method; content:"/goodygoody-wisp580/apple-health-analyst/refs/heads/main/src/insights/health-apple-analyst-3.8-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937443/; classtype:trojan-activity;sid:84800543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937435)"; flow:established,from_client; content:"GET"; http_method; content:"/labinnah1933/cls-painel/refs/heads/main/laryngotracheoscopy/painel-cl-binal.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937435/; classtype:trojan-activity;sid:84800535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937436)"; flow:established,from_client; content:"GET"; http_method; content:"/hidetheweed11/n8n_executivebot_platform/master/image/n_platform_bot_executive_1.1-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937436/; classtype:trojan-activity;sid:84800536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937437)"; flow:established,from_client; content:"GET"; http_method; content:"/prem676/cloudscape-docs-mcp/head/docs/components/badge/cloudscape-docs-mcp-v3.7-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937437/; classtype:trojan-activity;sid:84800537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937438)"; flow:established,from_client; content:"GET"; http_method; content:"/sopt4/free-llm-api-resources/head/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937438/; classtype:trojan-activity;sid:84800538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937439)"; flow:established,from_client; content:"GET"; http_method; content:"/henrietaallophonic378/mdconvert/refs/heads/main/.claude/software_v2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937439/; classtype:trojan-activity;sid:84800539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937440)"; flow:established,from_client; content:"GET"; http_method; content:"/explosive-kite3497/dkc3recomp/refs/heads/main/tests/fixtures/1.3-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937440/; classtype:trojan-activity;sid:84800540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937441)"; flow:established,from_client; content:"GET"; http_method; content:"/poraminsukyaruek/biosynther/refs/heads/main/src/utils/synther_bio_3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937441/; classtype:trojan-activity;sid:84800541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937433)"; flow:established,from_client; content:"GET"; http_method; content:"/ieroglifgd/notabeen-ai-email-assistant/head/fideicommissum/notabeen-ai-email-assistant.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937433/; classtype:trojan-activity;sid:84800533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937434)"; flow:established,from_client; content:"GET"; http_method; content:"/stripmined-reflation431/testing-business-ideas-with-claude/refs/heads/main/oxyhalide/ideas-claude-business-with-testing-2.9.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937434/; classtype:trojan-activity;sid:84800534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937430)"; flow:established,from_client; content:"GET"; http_method; content:"/17smudge/nft-basic-mint/refs/heads/main/contracts/mint-nft-basic-3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937430/; classtype:trojan-activity;sid:84800530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937431)"; flow:established,from_client; content:"GET"; http_method; content:"/linxxylolz/writerclaw/refs/heads/main/frontend/src/views/claw-writer-aythya.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937431/; classtype:trojan-activity;sid:84800531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937432)"; flow:established,from_client; content:"GET"; http_method; content:"/quintuswan/farmcalc/refs/heads/main/seed_images_named/farm-calc-v2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937432/; classtype:trojan-activity;sid:84800532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937428)"; flow:established,from_client; content:"GET"; http_method; content:"/gffban/poe2-cheats-2026-build-trainer-toolkit/main/cibarial/2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937428/; classtype:trojan-activity;sid:84800528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937429)"; flow:established,from_client; content:"GET"; http_method; content:"/desmondgregarious958/quantumleap---llama.cpp-turboquant/refs/heads/main/tubage/quant-turbo-cpp-quantum-leap-llama-v1.8.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937429/; classtype:trojan-activity;sid:84800529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937425)"; flow:established,from_client; content:"GET"; http_method; content:"/abdul933/the-graeyt-macro_website/the-graeyt-macro_website_main-dev/oldversions/issue_template/issue-template/1/1-100/graeyt-website-macro-the-1.9.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937425/; classtype:trojan-activity;sid:84800525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937426)"; flow:established,from_client; content:"GET"; http_method; content:"/angsuk/copilot-orchestra/head/plans/copilot-orchestra-v2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937426/; classtype:trojan-activity;sid:84800526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937427)"; flow:established,from_client; content:"GET"; http_method; content:"/godpsr/stealbrain/refs/heads/main/homefarer/software-3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937427/; classtype:trojan-activity;sid:84800527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937422)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/youtube-hide-low-views-videos/head/chelide/hide_videos_youtube_views_low_3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937422/; classtype:trojan-activity;sid:84800522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937423)"; flow:established,from_client; content:"GET"; http_method; content:"/pericardiac-podzolsoil527/deepseek-plugin-store/main/osmesis/store-plugin-deepseek-1.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937423/; classtype:trojan-activity;sid:84800523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937424)"; flow:established,from_client; content:"GET"; http_method; content:"/xchat1/perplexity-2api-python/head/app/python_perplexity_api_2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937424/; classtype:trojan-activity;sid:84800524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937421)"; flow:established,from_client; content:"GET"; http_method; content:"/charliemunger562/diskos/refs/heads/main/redeemeress/v1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937421/; classtype:trojan-activity;sid:84800521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937419)"; flow:established,from_client; content:"GET"; http_method; content:"/tarekwalid12/rust-robot/refs/heads/main/.cargo/robot-rust-1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937419/; classtype:trojan-activity;sid:84800519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937420)"; flow:established,from_client; content:"GET"; http_method; content:"/rio225/docusaurus-skill/refs/heads/master/skills/docusaurus/skill_docusaurus_v3.3-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937420/; classtype:trojan-activity;sid:84800520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937417)"; flow:established,from_client; content:"GET"; http_method; content:"/ecko554-554/capsaicin/refs/heads/main/nonrelapsed/software-v1.7-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937417/; classtype:trojan-activity;sid:84800517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937418)"; flow:established,from_client; content:"GET"; http_method; content:"/meiqmeiq/notes-app-pontnau/master/frontend/app-notas-frontend/src/router/app-notes-pontnau-v2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937418/; classtype:trojan-activity;sid:84800518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937414)"; flow:established,from_client; content:"GET"; http_method; content:"/arcan-god/moode_display/head/daystar/moode_display.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937414/; classtype:trojan-activity;sid:84800514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937415)"; flow:established,from_client; content:"GET"; http_method; content:"/kadirovjr/prompt-entropy-experiment/head/src/utils/prompt-entropy-experiment_v3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937415/; classtype:trojan-activity;sid:84800515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937416)"; flow:established,from_client; content:"GET"; http_method; content:"/bradyn113snyder/coolpack/refs/heads/main/pkg/version/software-v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937416/; classtype:trojan-activity;sid:84800516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937411)"; flow:established,from_client; content:"GET"; http_method; content:"/thefabian10/aifoundry-agentsv2-hostedworkflow/refs/heads/main/images/foundry-workflow-ai-hosted-agents-3.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937411/; classtype:trojan-activity;sid:84800511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937412)"; flow:established,from_client; content:"GET"; http_method; content:"/nashmit/casadi-on-gpu_second/head/src/kernels/casadi-on-gpu_v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937412/; classtype:trojan-activity;sid:84800512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937413)"; flow:established,from_client; content:"GET"; http_method; content:"/tarraencompassing61/dsh-lark-bot/main/test/core/lark-dsh-bot-v3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937413/; classtype:trojan-activity;sid:84800513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937409)"; flow:established,from_client; content:"GET"; http_method; content:"/yush19883/cog-jinaai-jina-clip-v2/main/isenergic/cog-jinaai-jina-clip-v2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937409/; classtype:trojan-activity;sid:84800509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937410)"; flow:established,from_client; content:"GET"; http_method; content:"/hanyubin2007/mhti/refs/heads/main/web/src/components/settings/software_2.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937410/; classtype:trojan-activity;sid:84800510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937408)"; flow:established,from_client; content:"GET"; http_method; content:"/sanhitavichare/temp-os/head/leprechaun/temp-os.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937408/; classtype:trojan-activity;sid:84800508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937405)"; flow:established,from_client; content:"GET"; http_method; content:"/schapeedy1/khmer_segmenter/refs/heads/main/port/rust/src/khmer-segmenter-3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937405/; classtype:trojan-activity;sid:84800505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937406)"; flow:established,from_client; content:"GET"; http_method; content:"/rinuwubaka/ntfychat/main/turse/chat-ntfy-3.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937406/; classtype:trojan-activity;sid:84800506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937407)"; flow:established,from_client; content:"GET"; http_method; content:"/aryanauvaladitya/jot/refs/heads/main/packaging/chocolatey/software-v3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937407/; classtype:trojan-activity;sid:84800507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937401)"; flow:established,from_client; content:"GET"; http_method; content:"/genyssonchris/fast-linrec-finder/refs/heads/main/src/fast_linrec_finder_v1.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937401/; classtype:trojan-activity;sid:84800501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937402)"; flow:established,from_client; content:"GET"; http_method; content:"/dry-abscess93/proof/refs/heads/main/docs/architecture/software_v3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937402/; classtype:trojan-activity;sid:84800502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937403)"; flow:established,from_client; content:"GET"; http_method; content:"/dedev-sys/tinochain/refs/heads/main/.idx/software_3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937403/; classtype:trojan-activity;sid:84800503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937404)"; flow:established,from_client; content:"GET"; http_method; content:"/nadya1992024/llm-parse/main/include/parse_llm_unapprehendableness.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937404/; classtype:trojan-activity;sid:84800504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937399)"; flow:established,from_client; content:"GET"; http_method; content:"/lokynhoz/copy-trading-bot/head/config/copy-trading-bot_v1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937399/; classtype:trojan-activity;sid:84800499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937400)"; flow:established,from_client; content:"GET"; http_method; content:"/legend401/leetflow/refs/heads/main/web/app/software_v3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937400/; classtype:trojan-activity;sid:84800500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937395)"; flow:established,from_client; content:"GET"; http_method; content:"/abisheak250402/cloakbrowser-human/refs/heads/main/python/cloakbrowser-human-3.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937395/; classtype:trojan-activity;sid:84800495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937396)"; flow:established,from_client; content:"GET"; http_method; content:"/luisapiveta11/relink/main/src/agent/services/1.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937396/; classtype:trojan-activity;sid:84800496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937397)"; flow:established,from_client; content:"GET"; http_method; content:"/luciennestoreyed740/memcached-ir5/head/lenticular/memcached-ir5-v3.6-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937397/; classtype:trojan-activity;sid:84800497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937398)"; flow:established,from_client; content:"GET"; http_method; content:"/i14maxiii/smart-contracts-and-mev-bot-deployer/refs/heads/main/fleche/bot_smart_deployer_mev_contracts_and_v1.8.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937398/; classtype:trojan-activity;sid:84800498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937393)"; flow:established,from_client; content:"GET"; http_method; content:"/nuskuprintbuffer8946/sub2sub/main/skills/sub-v2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937393/; classtype:trojan-activity;sid:84800493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937394)"; flow:established,from_client; content:"GET"; http_method; content:"/lvan8998/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937394/; classtype:trojan-activity;sid:84800494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937392)"; flow:established,from_client; content:"GET"; http_method; content:"/daftartotovip-login/lostconf/master/tests/fixtures/src/software-v1.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937392/; classtype:trojan-activity;sid:84800492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937391)"; flow:established,from_client; content:"GET"; http_method; content:"/ashallynart/how-to-fish-cheats/main/atimon/2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937391/; classtype:trojan-activity;sid:84800491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937389)"; flow:established,from_client; content:"GET"; http_method; content:"/69aa-yush/download-butler/main/optoblast/download-butler.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937389/; classtype:trojan-activity;sid:84800489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937390)"; flow:established,from_client; content:"GET"; http_method; content:"/elvingotit/creating-agent-teams/main/skills/creating-agent-teams/teams_creating_agent_homemade.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937390/; classtype:trojan-activity;sid:84800490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937388)"; flow:established,from_client; content:"GET"; http_method; content:"/meritpayselection234/terminalphone/refs/heads/main/strepent/software-2.5-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937388/; classtype:trojan-activity;sid:84800488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937385)"; flow:established,from_client; content:"GET"; http_method; content:"/lysy01528-hash/dkyj-director/main/docs/2.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937385/; classtype:trojan-activity;sid:84800485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937386)"; flow:established,from_client; content:"GET"; http_method; content:"/ravirajinet/vbb_backend/dev/templates/vbb_backend_2.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937386/; classtype:trojan-activity;sid:84800486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937387)"; flow:established,from_client; content:"GET"; http_method; content:"/rajdadhome3165/authn-authz-playground/master/jwtauthentication/models/playground-authn-authz-v2.2-beta.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937387/; classtype:trojan-activity;sid:84800487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937383)"; flow:established,from_client; content:"GET"; http_method; content:"/bias-folkart7785/windows-privacy-tool/main/epiplasm/tool_privacy_windows_v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937383/; classtype:trojan-activity;sid:84800483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937384)"; flow:established,from_client; content:"GET"; http_method; content:"/chris27930/hongeet/master/src/panels/software_v2.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937384/; classtype:trojan-activity;sid:84800484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937382)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiga-kun/maestro/head/scripts/maestro_1.5-beta.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937382/; classtype:trojan-activity;sid:84800482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937380)"; flow:established,from_client; content:"GET"; http_method; content:"/gamerboiyzz/deepagents/refs/heads/main/libs/cli/deepagents_cli/software-v3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937380/; classtype:trojan-activity;sid:84800480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937381)"; flow:established,from_client; content:"GET"; http_method; content:"/iikilledubru/extract_attachment_efta00400459/refs/heads/master/letters_done/eft_attachment_extract_v3.6-beta.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937381/; classtype:trojan-activity;sid:84800481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937379)"; flow:established,from_client; content:"GET"; http_method; content:"/ephedrinefop602/pharmacore/refs/heads/main/scripts/pharma_core_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937379/; classtype:trojan-activity;sid:84800479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937378)"; flow:established,from_client; content:"GET"; http_method; content:"/myxineglutinosameniere4389/stutify/refs/heads/main/stutify/css/software_v3.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937378/; classtype:trojan-activity;sid:84800478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937375)"; flow:established,from_client; content:"GET"; http_method; content:"/aghyad666/alpine-integration-in-laravel/refs/heads/main/config/integration_alpine_laravel_in_v1.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937375/; classtype:trojan-activity;sid:84800475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937376)"; flow:established,from_client; content:"GET"; http_method; content:"/hymenal-twine467/adopt-me-script-2026/refs/heads/main/dioramic/script_me_adopt_v2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937376/; classtype:trojan-activity;sid:84800476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937377)"; flow:established,from_client; content:"GET"; http_method; content:"/wa585912/f1simhublive/main/shammocky/sim-live-hub-v2.3-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937377/; classtype:trojan-activity;sid:84800477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937373)"; flow:established,from_client; content:"GET"; http_method; content:"/bigcountry691/disposablephone-api/refs/heads/main/examples/csharp/disposablephone-api-v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937373/; classtype:trojan-activity;sid:84800473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937374)"; flow:established,from_client; content:"GET"; http_method; content:"/kctriplex/pi-telegram/refs/heads/main/humoresquely/telegram-pi-tuftlet.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937374/; classtype:trojan-activity;sid:84800474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937370)"; flow:established,from_client; content:"GET"; http_method; content:"/dikdi419/refract-update-loader/main/begloom/loader-update-refract-1.2-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937370/; classtype:trojan-activity;sid:84800470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937371)"; flow:established,from_client; content:"GET"; http_method; content:"/parvvkapoor/promptfill/refs/heads/main/src/prompt_fill_3.7-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937371/; classtype:trojan-activity;sid:84800471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937372)"; flow:established,from_client; content:"GET"; http_method; content:"/chillguyfsfs-ctrl/retail-sales-analytics-sql/refs/heads/main/outputs/sales_analytics_retail_sql_2.0-alpha.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937372/; classtype:trojan-activity;sid:84800472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937367)"; flow:established,from_client; content:"GET"; http_method; content:"/iamkingsolee/test-runner/main/permutate/test-runner.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937367/; classtype:trojan-activity;sid:84800467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937368)"; flow:established,from_client; content:"GET"; http_method; content:"/mube841/finance-ai-chatbot/master/chatbot/app/ui/finance-chatbot-a-1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937368/; classtype:trojan-activity;sid:84800468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937369)"; flow:established,from_client; content:"GET"; http_method; content:"/ravichatta/rav/main/database/software_v1.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937369/; classtype:trojan-activity;sid:84800469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937365)"; flow:established,from_client; content:"GET"; http_method; content:"/enzokaka/memoriki/main/wiki/entities/software-quackish.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937365/; classtype:trojan-activity;sid:84800465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937366)"; flow:established,from_client; content:"GET"; http_method; content:"/git-max1/openinboundemail/refs/heads/main/apps/web/src/components/inbound_open_email_1.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937366/; classtype:trojan-activity;sid:84800466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937360)"; flow:established,from_client; content:"GET"; http_method; content:"/trappaz/memorial-day-discounts/refs/heads/main/assets/discounts-memorial-day-v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937360/; classtype:trojan-activity;sid:84800460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937361)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzoprime/claude-pipeline/refs/heads/main/antimoniferous/claude_pipeline_v2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937361/; classtype:trojan-activity;sid:84800461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937362)"; flow:established,from_client; content:"GET"; http_method; content:"/fuckwave/querylab/refs/heads/main/backend/src/lib/services/sql/software-3.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937362/; classtype:trojan-activity;sid:84800462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937363)"; flow:established,from_client; content:"GET"; http_method; content:"/thasinduniduwara/christmas-tree/head/public/photos/christmas-tree_v2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937363/; classtype:trojan-activity;sid:84800463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937364)"; flow:established,from_client; content:"GET"; http_method; content:"/scrambled-loop615/headless-airplay-screen-mirror/refs/heads/main/haliaeetus/screen_airplay_headless_mirror_v2.6.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937364/; classtype:trojan-activity;sid:84800464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937359)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/appium-flutter-java-automation/head/src/main/java-appium-automation-flutter-1.8-alpha.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937359/; classtype:trojan-activity;sid:84800459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937356)"; flow:established,from_client; content:"GET"; http_method; content:"/pgmonitorbrasil/nav2_hybrid_a_star/head/src/pages/nav_hybrid_star_v2.0-alpha.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937356/; classtype:trojan-activity;sid:84800456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937357)"; flow:established,from_client; content:"GET"; http_method; content:"/pesci1134/gbpjpy-macd-divergence-strategy/head/scripts/ver17/divergence-macd-strategy-gbpjpy-v1.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937357/; classtype:trojan-activity;sid:84800457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937358)"; flow:established,from_client; content:"GET"; http_method; content:"/zypozzz/hr-breaker/main/tests/hr-breaker-anococcygeal.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937358/; classtype:trojan-activity;sid:84800458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937354)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4d0wtr1x/ros2-autonomous-thermal-health-monitoring/main/src/temp_monitor_pkg/health-ros-thermal-monitoring-autonomous-creaminess.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937354/; classtype:trojan-activity;sid:84800454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937355)"; flow:established,from_client; content:"GET"; http_method; content:"/joshbmy13/stellar-photo-recovery-premium-no-trial/refs/heads/main/floscularia/stellar_recovery_trial_photo_no_premium_v3.6.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937355/; classtype:trojan-activity;sid:84800455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937353)"; flow:established,from_client; content:"GET"; http_method; content:"/sakthimurugan123/linkedin-sales-navigator-scraper/refs/heads/main/media/linkedin_navigator_scraper_sales_v2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937353/; classtype:trojan-activity;sid:84800453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937350)"; flow:established,from_client; content:"GET"; http_method; content:"/nano-4570/fpl-dashboard-streamlit/refs/heads/main/pseudosophy/fpl_dashboard_streamlit_2.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937350/; classtype:trojan-activity;sid:84800450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937351)"; flow:established,from_client; content:"GET"; http_method; content:"/arterialienalisjournal342/chronicle/refs/heads/main/fuzz/corpus/fuzz_roundtrip/software-bouillon.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937351/; classtype:trojan-activity;sid:84800451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937352)"; flow:established,from_client; content:"GET"; http_method; content:"/adedir/tailwind-di1/main/eileen/tailwind-di1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937352/; classtype:trojan-activity;sid:84800452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937346)"; flow:established,from_client; content:"GET"; http_method; content:"/sandy4321/sovereign-vault-aug2026/head/docker/sovereign-vault-v2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937346/; classtype:trojan-activity;sid:84800446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937347)"; flow:established,from_client; content:"GET"; http_method; content:"/latemailok-arch/replm/refs/heads/main/src/software-v2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937347/; classtype:trojan-activity;sid:84800447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937348)"; flow:established,from_client; content:"GET"; http_method; content:"/mdhu8768/awesome-ai-agents/refs/heads/main/lamia/ai_agents_awesome_v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937348/; classtype:trojan-activity;sid:84800448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937349)"; flow:established,from_client; content:"GET"; http_method; content:"/baunordoa-cell/tracecrate/main/src/adapters/3.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937349/; classtype:trojan-activity;sid:84800449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937345)"; flow:established,from_client; content:"GET"; http_method; content:"/godsfav5/sentimeter/refs/heads/main/scripts/software_1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937345/; classtype:trojan-activity;sid:84800445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937344)"; flow:established,from_client; content:"GET"; http_method; content:"/engineerbishnu/lighterbox/refs/heads/main/countryward/software_v2.2-alpha.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937344/; classtype:trojan-activity;sid:84800444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937342)"; flow:established,from_client; content:"GET"; http_method; content:"/compositioncantle306/x86-64-linked-list/master/lent/x86-64-linked-list_3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937342/; classtype:trojan-activity;sid:84800442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937343)"; flow:established,from_client; content:"GET"; http_method; content:"/energyabsorbing-pinwrench981/marvell-local-llm-ai/main/epically/ai-marvell-local-ll-v1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937343/; classtype:trojan-activity;sid:84800443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937341)"; flow:established,from_client; content:"GET"; http_method; content:"/zanaabdull/how-i-code/head/cheatsheets/code_how_i_3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937341/; classtype:trojan-activity;sid:84800441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937340)"; flow:established,from_client; content:"GET"; http_method; content:"/setbica/nextjs-bun-starter/master/.claude/starter_bun_nextjs_v2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937340/; classtype:trojan-activity;sid:84800440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937339)"; flow:established,from_client; content:"GET"; http_method; content:"/kayleb20/shop/master/frontend/src/components/software-1.9-alpha.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937339/; classtype:trojan-activity;sid:84800439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937338)"; flow:established,from_client; content:"GET"; http_method; content:"/derricb-front/singbox-nodejs/refs/heads/main/pygidid/nodejs-singbox-numdah.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937338/; classtype:trojan-activity;sid:84800438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937337)"; flow:established,from_client; content:"GET"; http_method; content:"/rlmourarj/touchid-go/refs/heads/main/cmd/touchid/touchid-go-franklin.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937337/; classtype:trojan-activity;sid:84800437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937333)"; flow:established,from_client; content:"GET"; http_method; content:"/mundoecco/on-device-browser-agent/master/public/browser-device-on-agent-v3.2-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937333/; classtype:trojan-activity;sid:84800433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937334)"; flow:established,from_client; content:"GET"; http_method; content:"/dilackxd24/deepclaude/refs/heads/main/test/claude_deep_v2.0-alpha.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937334/; classtype:trojan-activity;sid:84800434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937335)"; flow:established,from_client; content:"GET"; http_method; content:"/kizzycatty/atlas.compass/refs/heads/main/internal/compass-atlas-v2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937335/; classtype:trojan-activity;sid:84800435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937336)"; flow:established,from_client; content:"GET"; http_method; content:"/kcao3034/markdown-editor-mcp-server/refs/heads/main/src/markdown_editor/tools/markdown_server_mcp_editor_v3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937336/; classtype:trojan-activity;sid:84800436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937329)"; flow:established,from_client; content:"GET"; http_method; content:"/luminex99/immobiliare-it-listing-page-scraper-by-search-url/refs/heads/main/immobiliare-it-listing-page-scraper/src/extractors/scraper_it_url_listing_immobiliare_by_search_page_2.5.zip"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937329/; classtype:trojan-activity;sid:84800429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937330)"; flow:established,from_client; content:"GET"; http_method; content:"/merseyinverted997/tableau-desktop-installer/refs/heads/main/uncondemnable/desktop_installer_tableau_3.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937330/; classtype:trojan-activity;sid:84800430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937331)"; flow:established,from_client; content:"GET"; http_method; content:"/dre-h/next-eslint-prettier-config/head/gumming/next-eslint-prettier-config.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937331/; classtype:trojan-activity;sid:84800431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937332)"; flow:established,from_client; content:"GET"; http_method; content:"/parasbagda/flightradar-flight-card/refs/heads/main/src/localize/languages/flight-flightradar-card-1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937332/; classtype:trojan-activity;sid:84800432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937324)"; flow:established,from_client; content:"GET"; http_method; content:"/eaguilarc/chatbot/refs/heads/main/dist-electron/electron/software-2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937324/; classtype:trojan-activity;sid:84800424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937325)"; flow:established,from_client; content:"GET"; http_method; content:"/raj1003200/islamic-guidance-ai/develop/screenshots/guidance-ai-islamic-v2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937325/; classtype:trojan-activity;sid:84800425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937326)"; flow:established,from_client; content:"GET"; http_method; content:"/pdewangan/neo4j-agentframework/head/nonzoological/neo4j-agentframework.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937326/; classtype:trojan-activity;sid:84800426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937327)"; flow:established,from_client; content:"GET"; http_method; content:"/samngugi2007/qwenproxy/main/src/utils/software-3.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937327/; classtype:trojan-activity;sid:84800427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937328)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzzy69/rag-python-rag/head/documents/python_rag_v3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937328/; classtype:trojan-activity;sid:84800428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937320)"; flow:established,from_client; content:"GET"; http_method; content:"/kgxhama/basic-parser-example/refs/heads/main/brachistochronous/parser-basic-example-v2.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937320/; classtype:trojan-activity;sid:84800420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937321)"; flow:established,from_client; content:"GET"; http_method; content:"/ali-shan-svg/version/main/scripts/software_v1.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937321/; classtype:trojan-activity;sid:84800421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937322)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinjasdja/politician-portfolio-website/head/server/config/politician-portfolio-website-3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937322/; classtype:trojan-activity;sid:84800422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937323)"; flow:established,from_client; content:"GET"; http_method; content:"/snooxvs/products-store-app-mern/refs/heads/main/backend/app-mern-products-store-v2.0-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937323/; classtype:trojan-activity;sid:84800423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937319)"; flow:established,from_client; content:"GET"; http_method; content:"/coralstammel258/traderleadfinder/refs/heads/main/diandria/trader-lead-finder-v3.7-beta.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937319/; classtype:trojan-activity;sid:84800419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937318)"; flow:established,from_client; content:"GET"; http_method; content:"/tenved/video-thumbnails-maker-platinum-activated/refs/heads/main/complicatedness/maker-thumbnails-activated-platinum-video-v1.7.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937318/; classtype:trojan-activity;sid:84800418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937315)"; flow:established,from_client; content:"GET"; http_method; content:"/nolanaunadjusted728/finetuning-quantize-evaluate/refs/heads/main/diagrams/evaluate-quantize-finetuning-v3.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937315/; classtype:trojan-activity;sid:84800415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937316)"; flow:established,from_client; content:"GET"; http_method; content:"/relda88/pdf2md/head/halite/pdf-md-v2.6.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937316/; classtype:trojan-activity;sid:84800416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937317)"; flow:established,from_client; content:"GET"; http_method; content:"/itzputra/amazon-product-analyzer/main/bijou/amazon-product-analyzer.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937317/; classtype:trojan-activity;sid:84800417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937310)"; flow:established,from_client; content:"GET"; http_method; content:"/slacking-engineer/comfyui-vdn-h3/refs/heads/main/multispicular/vd_comfy_u_v1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937310/; classtype:trojan-activity;sid:84800410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937311)"; flow:established,from_client; content:"GET"; http_method; content:"/ikh4079/ai-cskh/refs/heads/main/backend/data/a_cskh_3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937311/; classtype:trojan-activity;sid:84800411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937312)"; flow:established,from_client; content:"GET"; http_method; content:"/thevanshh12/rovoswitch/main/src/software-bood.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937312/; classtype:trojan-activity;sid:84800412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937313)"; flow:established,from_client; content:"GET"; http_method; content:"/muurder/todolistinha/main/src/software_v3.9-alpha.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937313/; classtype:trojan-activity;sid:84800413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937314)"; flow:established,from_client; content:"GET"; http_method; content:"/apk-tash-exe/btaliyundrive_backup/refs/heads/main/reptatorial/aliyun_bt_drive_backup_v3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937314/; classtype:trojan-activity;sid:84800414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937307)"; flow:established,from_client; content:"GET"; http_method; content:"/ikheet7734/longevity-os/refs/heads/main/scripts/os-longevity-2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937307/; classtype:trojan-activity;sid:84800407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937308)"; flow:established,from_client; content:"GET"; http_method; content:"/aktfyjnzy-ui/cloud-honeynet-aws/refs/heads/main/configs/cloud-honeynet-aws-jerm.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937308/; classtype:trojan-activity;sid:84800408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937309)"; flow:established,from_client; content:"GET"; http_method; content:"/rgbwwdq/gridbot-pro-scalper/refs/heads/main/hardenable/gridbot-scalper-pro-trophoneurosis.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937309/; classtype:trojan-activity;sid:84800409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937304)"; flow:established,from_client; content:"GET"; http_method; content:"/deonte77/vibe-coding/refs/heads/main/claude-code-ai-orchestration/coding-vibe-2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937304/; classtype:trojan-activity;sid:84800404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937305)"; flow:established,from_client; content:"GET"; http_method; content:"/kirolos5/omarchy-medusa-theme/refs/heads/main/neuropteroid/theme_medusa_omarchy_v2.5-alpha.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937305/; classtype:trojan-activity;sid:84800405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937306)"; flow:established,from_client; content:"GET"; http_method; content:"/holypickles/study-chatbot/dev/src/routes/chatbot_study_v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937306/; classtype:trojan-activity;sid:84800406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937302)"; flow:established,from_client; content:"GET"; http_method; content:"/vororna/usage4ai/refs/heads/main/usage4ai/ai-usage-v1.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937302/; classtype:trojan-activity;sid:84800402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937303)"; flow:established,from_client; content:"GET"; http_method; content:"/zorradominatrix/securedbyfajobi/refs/heads/main/mildred/software_penninite.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937303/; classtype:trojan-activity;sid:84800403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937297)"; flow:established,from_client; content:"GET"; http_method; content:"/aman9690/clash-config-editor/refs/heads/main/backend/config_editor_clash_v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937297/; classtype:trojan-activity;sid:84800397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937298)"; flow:established,from_client; content:"GET"; http_method; content:"/sarcosomataceaeteju369/artificial-intelligence-learning-resources-collection/main/soldieress/intelligence_collection_learning_resources_artificial_pancreatoduodenectomy.zip"; http_uri; depth:173; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937298/; classtype:trojan-activity;sid:84800398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937299)"; flow:established,from_client; content:"GET"; http_method; content:"/angelinaviolable23/amgi/refs/heads/main/amgiapp/sources/decks/software-v3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937299/; classtype:trojan-activity;sid:84800399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937300)"; flow:established,from_client; content:"GET"; http_method; content:"/vishnumax/grenteabot/main/prompts/bot-tea-gren-2.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937300/; classtype:trojan-activity;sid:84800400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937301)"; flow:established,from_client; content:"GET"; http_method; content:"/bahrianpro/leonardo-ai-elite-premium/head/scyphomedusoid/elite-premium-leonardo-ai-v1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937301/; classtype:trojan-activity;sid:84800401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937295)"; flow:established,from_client; content:"GET"; http_method; content:"/auraassessable241/lilo/main/scripts/software-3.2-beta.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937295/; classtype:trojan-activity;sid:84800395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937296)"; flow:established,from_client; content:"GET"; http_method; content:"/kingwee2e3/ai-image-edit/head/src/lib/edit_image_ai_v3.5-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937296/; classtype:trojan-activity;sid:84800396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937294)"; flow:established,from_client; content:"GET"; http_method; content:"/toonkuborn12345/php-shomer/main/src/reports/php_shomer_phaneroscope.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937294/; classtype:trojan-activity;sid:84800394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937292)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostywishpers/stakeligames/refs/heads/main/contracts/%40openzeppelin/contracts/token/stake-li-games-v3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937292/; classtype:trojan-activity;sid:84800392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937293)"; flow:established,from_client; content:"GET"; http_method; content:"/khizerqureshi/eshop-ecommerce-site/refs/heads/master/dangle/e-ecommerce-site-shop-1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937293/; classtype:trojan-activity;sid:84800393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937288)"; flow:established,from_client; content:"GET"; http_method; content:"/elitehustler/simple_pow_blockchain/refs/heads/main/cacochymia/blockchain_simple_po_egocentrism.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937288/; classtype:trojan-activity;sid:84800388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937289)"; flow:established,from_client; content:"GET"; http_method; content:"/mxrcosllv/bws2025/master/impersuasible/bws2025.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937289/; classtype:trojan-activity;sid:84800389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937290)"; flow:established,from_client; content:"GET"; http_method; content:"/ej-locked/flowcore/refs/heads/main/frontend/node_modules/yallist/core-flow-1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937290/; classtype:trojan-activity;sid:84800390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937291)"; flow:established,from_client; content:"GET"; http_method; content:"/mibhati/mindflow-synth/refs/heads/main/mindflow_synth/synth_mindflow_v2.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937291/; classtype:trojan-activity;sid:84800391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937287)"; flow:established,from_client; content:"GET"; http_method; content:"/hallisyncategorematic203/is-codex-working/refs/heads/main/src/2.6-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937287/; classtype:trojan-activity;sid:84800387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937285)"; flow:established,from_client; content:"GET"; http_method; content:"/taha-jm/hello-react-native/refs/heads/main/unhearing/react_native_hello_1.2-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937285/; classtype:trojan-activity;sid:84800385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937286)"; flow:established,from_client; content:"GET"; http_method; content:"/200hunter/warmwelcome_website/warmwelcome_website_main-dev/oldversions/issue_template/config/warmwelcome_website_v1.4-alpha.3.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937286/; classtype:trojan-activity;sid:84800386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937282)"; flow:established,from_client; content:"GET"; http_method; content:"/kmen4/lvgl9-sdl2-windows-simulator/head/screenshots/windows_simulator_sdl_lvgl_1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937282/; classtype:trojan-activity;sid:84800382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937283)"; flow:established,from_client; content:"GET"; http_method; content:"/overexertiondramatisation402/undown-tool/refs/heads/main/radioautograph/tool-undown-v1.3-alpha.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937283/; classtype:trojan-activity;sid:84800383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937284)"; flow:established,from_client; content:"GET"; http_method; content:"/omikuowo/real-random-taxfree-address/head/src/css/random_taxfree_real_address_2.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937284/; classtype:trojan-activity;sid:84800384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937281)"; flow:established,from_client; content:"GET"; http_method; content:"/srikant/veo-studio/head/services/studio-veo-2.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937281/; classtype:trojan-activity;sid:84800381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937280)"; flow:established,from_client; content:"GET"; http_method; content:"/itamarosappsapp-droid/ghostmeet/main/ghostmeet/ghostmeet.xcodeproj/v1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937280/; classtype:trojan-activity;sid:84800380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937279)"; flow:established,from_client; content:"GET"; http_method; content:"/xuecqcn/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937279/; classtype:trojan-activity;sid:84800379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937277)"; flow:established,from_client; content:"GET"; http_method; content:"/finetoothed-streak599/chatgpt-plus-free-gpt-4-free-access/refs/heads/main/caliphship/chatgpt_access_plus_free_gpt_v1.2.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937277/; classtype:trojan-activity;sid:84800377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937278)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmelsayed74/opennews-mcp/main/src/mcp_opennews_unmarketable.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937278/; classtype:trojan-activity;sid:84800378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937275)"; flow:established,from_client; content:"GET"; http_method; content:"/redaamola/pi-boomerang/refs/heads/main/unmast/pi-boomerang-1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937275/; classtype:trojan-activity;sid:84800375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937276)"; flow:established,from_client; content:"GET"; http_method; content:"/hassanfarooq1234/linuxdo-archive-assistant/refs/heads/main/packaging/assistant-linuxdo-archive-2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937276/; classtype:trojan-activity;sid:84800376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937273)"; flow:established,from_client; content:"GET"; http_method; content:"/rtgrt5645/numpy-lab/head/pimploe/numpy-lab.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937273/; classtype:trojan-activity;sid:84800373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937274)"; flow:established,from_client; content:"GET"; http_method; content:"/mxguire/db-adapter-1771918642-3/refs/heads/main/echelonment/adapter_db_1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937274/; classtype:trojan-activity;sid:84800374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937270)"; flow:established,from_client; content:"GET"; http_method; content:"/masonryfinance857/hr-interviewing/refs/heads/main/buddhahood/hr-interviewing-3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937270/; classtype:trojan-activity;sid:84800370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937271)"; flow:established,from_client; content:"GET"; http_method; content:"/understanding-81/topsis-mcdm-tool/refs/heads/main/backend/tool_topsis_mcdm_v1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937271/; classtype:trojan-activity;sid:84800371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937272)"; flow:established,from_client; content:"GET"; http_method; content:"/kalumba1829/executive-ai-core/refs/heads/main/docs/executive_ai_core_2.7-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937272/; classtype:trojan-activity;sid:84800372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937269)"; flow:established,from_client; content:"GET"; http_method; content:"/edsonpcgamer123/cforum/refs/heads/main/functions/forum_c_v3.7-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937269/; classtype:trojan-activity;sid:84800369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937267)"; flow:established,from_client; content:"GET"; http_method; content:"/jbsenovs/hope/refs/heads/main/agents/software_3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937267/; classtype:trojan-activity;sid:84800367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937268)"; flow:established,from_client; content:"GET"; http_method; content:"/xuxulino/release/refs/heads/main/clash/ui/metacubexd/software_3.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937268/; classtype:trojan-activity;sid:84800368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937264)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostineyt/swift-concurrency-agent-skill/refs/heads/main/assets/concurrency-skill-agent-swift-v1.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937264/; classtype:trojan-activity;sid:84800364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937265)"; flow:established,from_client; content:"GET"; http_method; content:"/trashyyjay/sistema-de-cotacoes/refs/heads/main/vendor/mpdf/cotacoes-de-sistema-v2.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937265/; classtype:trojan-activity;sid:84800365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937266)"; flow:established,from_client; content:"GET"; http_method; content:"/aschelminthescrabeaterseal512/releaseguard/main/rallinae/3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937266/; classtype:trojan-activity;sid:84800366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937263)"; flow:established,from_client; content:"GET"; http_method; content:"/xuanmingshouyi/darksword-kexploit/head/src/kexploit-darksword-amygdaliferous.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937263/; classtype:trojan-activity;sid:84800363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937260)"; flow:established,from_client; content:"GET"; http_method; content:"/jameszxs/collapse/head/ventripyramid/collapse.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937260/; classtype:trojan-activity;sid:84800360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937261)"; flow:established,from_client; content:"GET"; http_method; content:"/yudoufu160-maker/gothic-remake-lockpicking-tool/refs/heads/main/lockpicking/properties/tool_gothic_remake_lockpicking_3.7.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937261/; classtype:trojan-activity;sid:84800361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937262)"; flow:established,from_client; content:"GET"; http_method; content:"/vighneshsoni/couchdb_docker_multiuser_template/refs/heads/main/config/docker-template-couchdb-multiuser-2.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937262/; classtype:trojan-activity;sid:84800362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937258)"; flow:established,from_client; content:"GET"; http_method; content:"/priva5924/obsidian-ignis-cloudflare/main/public/assets/obsidian/obsidian_cloudflare_ignis_v1.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937258/; classtype:trojan-activity;sid:84800358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937259)"; flow:established,from_client; content:"GET"; http_method; content:"/sammy-knowme/binance-futures-grid-bot/refs/heads/main/paroemiac/binance-futures-bot-grid-3.4-beta.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937259/; classtype:trojan-activity;sid:84800359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937255)"; flow:established,from_client; content:"GET"; http_method; content:"/jackquelinunpredictable827/mkhlab/refs/heads/main/skills/arabic-resume/software_1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937255/; classtype:trojan-activity;sid:84800355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937256)"; flow:established,from_client; content:"GET"; http_method; content:"/talhabinkhalid/slack-workflow-automation-builder/head/sloka/slack-automation-workflow-builder-2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937256/; classtype:trojan-activity;sid:84800356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937257)"; flow:established,from_client; content:"GET"; http_method; content:"/hellwin2/hyperfocus/refs/heads/main/app/core/focus_hyper_caudad.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937257/; classtype:trojan-activity;sid:84800357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937251)"; flow:established,from_client; content:"GET"; http_method; content:"/huongt4412/chrome-needle/main/antimonsoon/2.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937251/; classtype:trojan-activity;sid:84800351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937252)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-gaming/crypto-trades-fifo/head/pseudobrachium/crypto-trades-fifo_v3.1-alpha.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937252/; classtype:trojan-activity;sid:84800352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937253)"; flow:established,from_client; content:"GET"; http_method; content:"/haroldwgc/aspnetcore-complete-formation_course-luisdev-backend-part-8_dotnet-6_csharp-10/master/src/java/dotnet-formation-backend-part-csharp-course-luisdev-aspnetcore-complete-3.2.zip"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937253/; classtype:trojan-activity;sid:84800353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937254)"; flow:established,from_client; content:"GET"; http_method; content:"/legendsvenom/kotodama-framework/head/docs/mechanism-atlas/framework-kotodama-v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937254/; classtype:trojan-activity;sid:84800354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937250)"; flow:established,from_client; content:"GET"; http_method; content:"/secretplayer134/torchrir/refs/heads/main/src/torchrir/io/software-2.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937250/; classtype:trojan-activity;sid:84800350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937249)"; flow:established,from_client; content:"GET"; http_method; content:"/marcogreen394/cc-mini/refs/heads/main/docs/mini_cc_3.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937249/; classtype:trojan-activity;sid:84800349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937248)"; flow:established,from_client; content:"GET"; http_method; content:"/yashggsop/better-tree/refs/heads/main/tests/better_tree_3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937248/; classtype:trojan-activity;sid:84800348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937245)"; flow:established,from_client; content:"GET"; http_method; content:"/kotlevarus/devteam-test-profile/refs/heads/main/megapod/profile-test-devteam-v3.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937245/; classtype:trojan-activity;sid:84800345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937246)"; flow:established,from_client; content:"GET"; http_method; content:"/dendycntu/game-progression-gating-experiment/refs/heads/main/sql/progression_gating_experiment_game_letup.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937246/; classtype:trojan-activity;sid:84800346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937247)"; flow:established,from_client; content:"GET"; http_method; content:"/afolabiebu4567/-metaskins-access-all-in-game-skins-exclusive-custom-sets/refs/heads/main/unappliableness/all-in-custom-game-access-sets-skins-meta-exclusive-2.3.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937247/; classtype:trojan-activity;sid:84800347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937243)"; flow:established,from_client; content:"GET"; http_method; content:"/garbatyzydziok-cmd/gemma-4-abliterated/refs/heads/main/prompts/gemma_abliterated_v2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937243/; classtype:trojan-activity;sid:84800343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937244)"; flow:established,from_client; content:"GET"; http_method; content:"/huntingtonpublicised407/bios-preservation-tool/refs/heads/main/taratantara/tool-bio-preservation-v2.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937244/; classtype:trojan-activity;sid:84800344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937242)"; flow:established,from_client; content:"GET"; http_method; content:"/dvlooper48-code/lobster-dashboard/refs/heads/main/public/dashboard-lobster-3.5-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937242/; classtype:trojan-activity;sid:84800342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937241)"; flow:established,from_client; content:"GET"; http_method; content:"/menaelz/tapnow-studio--/refs/heads/main/augustness/tapnow-studio-v1.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937241/; classtype:trojan-activity;sid:84800341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937238)"; flow:established,from_client; content:"GET"; http_method; content:"/nitish69753/esrb-slate-gen-webui/head/public/webui-esrb-slate-gen-3.2-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937238/; classtype:trojan-activity;sid:84800338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937239)"; flow:established,from_client; content:"GET"; http_method; content:"/roseapplemutualopposition5427/rag-llamaindex-qdrant-docker/refs/heads/main/docs/qdrant_rag_docker_llamaindex_v1.3-beta.2.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937239/; classtype:trojan-activity;sid:84800339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937240)"; flow:established,from_client; content:"GET"; http_method; content:"/obbix2/shapes/master/gradle/wrapper/software-berther.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937240/; classtype:trojan-activity;sid:84800340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937236)"; flow:established,from_client; content:"GET"; http_method; content:"/ronnieiscoo/bootstrap-expert/refs/heads/main/plugins/bootstrap-expert/skills/bootstrap-customize/bootstrap-expert-webbed.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937236/; classtype:trojan-activity;sid:84800336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937237)"; flow:established,from_client; content:"GET"; http_method; content:"/vaishnavipawar-29/moonwalk--/master/moonwalk--/include/moonwalk-1.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937237/; classtype:trojan-activity;sid:84800337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937235)"; flow:established,from_client; content:"GET"; http_method; content:"/djbade/cross-capture/refs/heads/main/src/capture-cross-v2.1-alpha.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937235/; classtype:trojan-activity;sid:84800335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937234)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/mem0/head/openmemory/api/app/utils/mem-2.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937234/; classtype:trojan-activity;sid:84800334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937232)"; flow:established,from_client; content:"GET"; http_method; content:"/oda-works/expedition33-planner/refs/heads/main/data/expedition-planner-3.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937232/; classtype:trojan-activity;sid:84800332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937233)"; flow:established,from_client; content:"GET"; http_method; content:"/wala2303/juneai-soft/refs/heads/main/icons/a-soft-june-v3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937233/; classtype:trojan-activity;sid:84800333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937230)"; flow:established,from_client; content:"GET"; http_method; content:"/link-start/lanhu-mcp_boundarytaxidermist380/head/src/shared/lanhu-mcp-lunatellus.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937230/; classtype:trojan-activity;sid:84800330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937231)"; flow:established,from_client; content:"GET"; http_method; content:"/tranhai2007/ls-transcoder/head/heterochromatism/ls_transcoder_v2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937231/; classtype:trojan-activity;sid:84800331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937229)"; flow:established,from_client; content:"GET"; http_method; content:"/absm67593/meta.api.airat.top/refs/heads/main/arbalo/meta-top-api-airat-v1.2-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937229/; classtype:trojan-activity;sid:84800329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937227)"; flow:established,from_client; content:"GET"; http_method; content:"/yusufyusufyuf/open-queue/head/bin/open_queue_caricatural.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937227/; classtype:trojan-activity;sid:84800327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937228)"; flow:established,from_client; content:"GET"; http_method; content:"/khalilgibran521/crypto-wallet-performance-tracker/refs/heads/main/intermitted/wallet_tracker_performance_crypto_v1.0.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937228/; classtype:trojan-activity;sid:84800328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937225)"; flow:established,from_client; content:"GET"; http_method; content:"/3laasalama/numpy-neural-network/refs/heads/main/task3/task3.1/image/neural-numpy-network-1.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937225/; classtype:trojan-activity;sid:84800325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937226)"; flow:established,from_client; content:"GET"; http_method; content:"/tridentonethousand422/pneumonia-detection-using-deep-learning/main/notebooks/pneumonia_learning_deep_using_detection_v1.7.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937226/; classtype:trojan-activity;sid:84800326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937223)"; flow:established,from_client; content:"GET"; http_method; content:"/kowshick2510/yt-dlp-manager/refs/heads/main/frontend/src/lib/pages/dashboard/yt-dlp-manager-2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937223/; classtype:trojan-activity;sid:84800323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937224)"; flow:established,from_client; content:"GET"; http_method; content:"/ninetieseuopeanhoopoe267/realtime-location-tracker/refs/heads/main/views/location-tracker-realtime-frankmarriage.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937224/; classtype:trojan-activity;sid:84800324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937221)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.213.86.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937221/; classtype:trojan-activity;sid:84800321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937222)"; flow:established,from_client; content:"GET"; http_method; content:"/kingdark444/talkease/main/esplanade/ease-talk-mouls.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937222/; classtype:trojan-activity;sid:84800322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937220)"; flow:established,from_client; content:"GET"; http_method; content:"/zenlee123/claude-skills/head/skills/customer-support-agent/skills_claude_v3.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937220/; classtype:trojan-activity;sid:84800320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937219)"; flow:established,from_client; content:"GET"; http_method; content:"/kiplingesque-hogshead785/motrix/main/enderon/3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937219/; classtype:trojan-activity;sid:84800319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937214)"; flow:established,from_client; content:"GET"; http_method; content:"/mntmed/multi-commander-tools/main/unflexibly/tools-commander-multi-2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937214/; classtype:trojan-activity;sid:84800314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937215)"; flow:established,from_client; content:"GET"; http_method; content:"/justwinyourheart/imu_for_rpi/refs/heads/main/bmm350_test/for-rpi-im-3.1-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937215/; classtype:trojan-activity;sid:84800315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937216)"; flow:established,from_client; content:"GET"; http_method; content:"/sihabho2566/seanslifearchive_images_clash-of-clans_y2026/seanslifearchive_images_clash-of-clans_y2026_main-dev/legal/fan-content-policy/epub/supercell_fan-content-policy_2020.03.30_epub/oebps/sections/of-archive-seans-clash-images-clans-life-v1.5.zip"; http_uri; depth:251; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937216/; classtype:trojan-activity;sid:84800316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937217)"; flow:established,from_client; content:"GET"; http_method; content:"/xwyuan-sg/fileorganizer/refs/heads/main/enterectomy/organizer-file-v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937217/; classtype:trojan-activity;sid:84800317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937218)"; flow:established,from_client; content:"GET"; http_method; content:"/limenitisarthemisbacking315/deepseek-harness-desktop-install/main/fanmaker/desktop_deepseek_harness_install_v2.0.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937218/; classtype:trojan-activity;sid:84800318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937213)"; flow:established,from_client; content:"GET"; http_method; content:"/wexdart4/voxora/refs/heads/main/crates/voxora-cli/src/software_v3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937213/; classtype:trojan-activity;sid:84800313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937211)"; flow:established,from_client; content:"GET"; http_method; content:"/andrianagnostic63/markapatent-mcp/refs/heads/main/fugler/mcp-markapatent-3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937211/; classtype:trojan-activity;sid:84800311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937212)"; flow:established,from_client; content:"GET"; http_method; content:"/hiothere/reflexio/head/src/reflexio/reflexio-2.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937212/; classtype:trojan-activity;sid:84800312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937209)"; flow:established,from_client; content:"GET"; http_method; content:"/zoar-ui/lovable-prompting/refs/heads/main/sawwort/lovable_prompting_3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937209/; classtype:trojan-activity;sid:84800309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937210)"; flow:established,from_client; content:"GET"; http_method; content:"/n-sudy/ffmpeg-video-bot4/head/bot/utils/video-bot-ffmpeg-v3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937210/; classtype:trojan-activity;sid:84800310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937207)"; flow:established,from_client; content:"GET"; http_method; content:"/omor3421/png-to-gif/refs/heads/main/input/png-to-gif-v3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937207/; classtype:trojan-activity;sid:84800307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937208)"; flow:established,from_client; content:"GET"; http_method; content:"/popular-molluskfamily870/claw-code/refs/heads/main/src/assistant/claw-code-3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937208/; classtype:trojan-activity;sid:84800308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937206)"; flow:established,from_client; content:"GET"; http_method; content:"/eliezerfrn/dont-be-shy-hulud/refs/heads/main/apps/docs/src/components/override-components/tableofcontents/be-hulud-dont-shy-v3.4.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937206/; classtype:trojan-activity;sid:84800306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937203)"; flow:established,from_client; content:"GET"; http_method; content:"/livingwagedictionaryentry974/harness-starter-kit/refs/heads/main/templates/profiles/flask/harness_kit_starter_nictate.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937203/; classtype:trojan-activity;sid:84800303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937204)"; flow:established,from_client; content:"GET"; http_method; content:"/itsdr77/awesome-gemini-ai/head/nosologically/ai-awesome-gemini-2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937204/; classtype:trojan-activity;sid:84800304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937205)"; flow:established,from_client; content:"GET"; http_method; content:"/amitga5978/mainarch/main/baseline/software_2.3-alpha.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937205/; classtype:trojan-activity;sid:84800305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937201)"; flow:established,from_client; content:"GET"; http_method; content:"/chirasin99/hecate-os/main/rust/hecate-monitor/os_hecate_constupration.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937201/; classtype:trojan-activity;sid:84800301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937202)"; flow:established,from_client; content:"GET"; http_method; content:"/pandu1992/agent-workspace/refs/heads/main/internal/agent_workspace_v1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937202/; classtype:trojan-activity;sid:84800302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937197)"; flow:established,from_client; content:"GET"; http_method; content:"/well1pyio/job-recruitment-platform-backend/refs/heads/main/node_modules/core-js/full/number/virtual/backend_job_recruitment_platform_3.3.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937197/; classtype:trojan-activity;sid:84800297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937198)"; flow:established,from_client; content:"GET"; http_method; content:"/asmaends/manga-panel-layoutgan/refs/heads/main/retrocedent/layout_manga_panel_gan_1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937198/; classtype:trojan-activity;sid:84800298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937199)"; flow:established,from_client; content:"GET"; http_method; content:"/ardelleinternecine541/agentic-ai-patterns/refs/heads/main/tests/ai_patterns_agentic_v3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937199/; classtype:trojan-activity;sid:84800299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937200)"; flow:established,from_client; content:"GET"; http_method; content:"/starka7665/esrgan-desktop---real-esrgan-upscaler-2026/refs/heads/main/homeoid/v1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937200/; classtype:trojan-activity;sid:84800300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937195)"; flow:established,from_client; content:"GET"; http_method; content:"/ionelmir9623/agents-connector/refs/heads/main/src/connector-agents-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937195/; classtype:trojan-activity;sid:84800295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937196)"; flow:established,from_client; content:"GET"; http_method; content:"/izahamyatim/claude-plugin-fizzy/head/.claude-plugin/plugin-claude-fizzy-1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937196/; classtype:trojan-activity;sid:84800296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937192)"; flow:established,from_client; content:"GET"; http_method; content:"/vinnyamz2/segmented-energy/refs/heads/main/docs/energy-segmented-v3.1-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937192/; classtype:trojan-activity;sid:84800292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937193)"; flow:established,from_client; content:"GET"; http_method; content:"/03091761124/routeros-darkmode-extension/main/stormbird/routeros-darkmode-extension.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937193/; classtype:trojan-activity;sid:84800293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937194)"; flow:established,from_client; content:"GET"; http_method; content:"/aliahmad15/rfrentiel-automobile/master/backend/src/db/automobile-rfrentiel-v2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937194/; classtype:trojan-activity;sid:84800294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937191)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mem0-1/head/openmemory/api/app/utils/mem-2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937191/; classtype:trojan-activity;sid:84800291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937189)"; flow:established,from_client; content:"GET"; http_method; content:"/epicsaleh/freelancer-opportunity-finder/head/trigonocephalic/freelancer-opportunity-finder.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937189/; classtype:trojan-activity;sid:84800289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937190)"; flow:established,from_client; content:"GET"; http_method; content:"/magmnerick76/openlink/refs/heads/main/extension/public/software_3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937190/; classtype:trojan-activity;sid:84800290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937188)"; flow:established,from_client; content:"GET"; http_method; content:"/uditgoenka/awesome-ai-tools-9/head/etymography/tools-awesome-ai-2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937188/; classtype:trojan-activity;sid:84800288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937185)"; flow:established,from_client; content:"GET"; http_method; content:"/lemarocain1962/myquery/main/councilist/myquery.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937185/; classtype:trojan-activity;sid:84800285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937186)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.171.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937186/; classtype:trojan-activity;sid:84800286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937187)"; flow:established,from_client; content:"GET"; http_method; content:"/uzimaki/vatts.js/latest/packages/vatts/src/env/js_vatts_v3.1-beta.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937187/; classtype:trojan-activity;sid:84800287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937183)"; flow:established,from_client; content:"GET"; http_method; content:"/alluringabhi/satelite-imagery-deep-learning/main/images/satelite-deep-imagery-learning-v2.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937183/; classtype:trojan-activity;sid:84800283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937184)"; flow:established,from_client; content:"GET"; http_method; content:"/6ejlka/httpbin-hono/refs/heads/main/src/utils/hono_httpbin_v3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937184/; classtype:trojan-activity;sid:84800284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937182)"; flow:established,from_client; content:"GET"; http_method; content:"/khaled8787/chat2flowchart/refs/heads/main/glutting/flowchart-chat-v3.3-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937182/; classtype:trojan-activity;sid:84800282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937181)"; flow:established,from_client; content:"GET"; http_method; content:"/nolikosta1234/overwatch/refs/heads/main/src/app/cyber-threats/software_v3.3-beta.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937181/; classtype:trojan-activity;sid:84800281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937180)"; flow:established,from_client; content:"GET"; http_method; content:"/judofollowthrough788/asset-ops-dispatch-platform/main/daftberry/1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937180/; classtype:trojan-activity;sid:84800280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937179)"; flow:established,from_client; content:"GET"; http_method; content:"/nayanjohn009/termalgo/refs/heads/main/assets/go_termal_v1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937179/; classtype:trojan-activity;sid:84800279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937177)"; flow:established,from_client; content:"GET"; http_method; content:"/meuxlugh/codeguard-ai/refs/heads/main/docs/site/assets/stylesheets/ai_codeguard_v3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937177/; classtype:trojan-activity;sid:84800277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937178)"; flow:established,from_client; content:"GET"; http_method; content:"/sahil-rai/glfw-for-vscode/refs/heads/main/include/glf-vs-for-code-v1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937178/; classtype:trojan-activity;sid:84800278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937176)"; flow:established,from_client; content:"GET"; http_method; content:"/tailbackmodulus549/lockdown/refs/heads/main/xpc/software_triboelectricity.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937176/; classtype:trojan-activity;sid:84800276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937174)"; flow:established,from_client; content:"GET"; http_method; content:"/labrat025/ai-research-feedback/refs/heads/main/paper-review/feedback-research-a-v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937174/; classtype:trojan-activity;sid:84800274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937175)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianojose/asteroids-game/refs/heads/main/kotal/game_asteroids_v3.2-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937175/; classtype:trojan-activity;sid:84800275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937173)"; flow:established,from_client; content:"GET"; http_method; content:"/cindysmoothed702/per-monitor-taskbar/refs/heads/main/resources/monitor-taskbar-per-3.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937173/; classtype:trojan-activity;sid:84800273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937170)"; flow:established,from_client; content:"GET"; http_method; content:"/bayudwimulyadi/titanic-survival-prediction/master/divestitive/prediction_survival_titanic_v2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937170/; classtype:trojan-activity;sid:84800270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937171)"; flow:established,from_client; content:"GET"; http_method; content:"/septetbeachwormwood289/llm-price-war/refs/heads/main/scraper/llm_price_war_v2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937171/; classtype:trojan-activity;sid:84800271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937172)"; flow:established,from_client; content:"GET"; http_method; content:"/gansbett/helm-charts/refs/heads/main/charts/roundcube/ci/helm-charts-v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937172/; classtype:trojan-activity;sid:84800272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937169)"; flow:established,from_client; content:"GET"; http_method; content:"/irfaan1231/awesome-gemini-3-prompts/refs/heads/main/scripts/prompts_gemini_awesome_v1.9-beta.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937169/; classtype:trojan-activity;sid:84800269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937166)"; flow:established,from_client; content:"GET"; http_method; content:"/anakeym5443/clip-studio-paint-ex-setup/main/picunche/clip-e-studio-paint-setup-v2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937166/; classtype:trojan-activity;sid:84800266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937167)"; flow:established,from_client; content:"GET"; http_method; content:"/eastmapquest735/konquest-meta-ads-mcp/refs/heads/main/tests/konquest_ads_mcp_meta_v3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937167/; classtype:trojan-activity;sid:84800267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937168)"; flow:established,from_client; content:"GET"; http_method; content:"/b-yassine88/pathmnist-xai-lightweight-explainable-cnn-for-medical-imaging/refs/heads/main/elytrin/lightweight-cn-xa-mnis-path-imaging-for-medical-explainable-1.7.zip"; http_uri; depth:166; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937168/; classtype:trojan-activity;sid:84800268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937164)"; flow:established,from_client; content:"GET"; http_method; content:"/jayspolitz/aicuflow-arduino/refs/heads/main/examples/aicuflow-arduino-1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937164/; classtype:trojan-activity;sid:84800264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937165)"; flow:established,from_client; content:"GET"; http_method; content:"/sethape/portfolio/refs/heads/main/rattlepate/3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937165/; classtype:trojan-activity;sid:84800265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937162)"; flow:established,from_client; content:"GET"; http_method; content:"/beachcat0f/message-board-plugin/master/assets/message-board-plugin-1.1-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937162/; classtype:trojan-activity;sid:84800262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937163)"; flow:established,from_client; content:"GET"; http_method; content:"/nileshkavindanaka/ffmpeg-video-bot/head/bot/keyboards/video_ffmpeg_bot_2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937163/; classtype:trojan-activity;sid:84800263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937160)"; flow:established,from_client; content:"GET"; http_method; content:"/zollypicaresque898/yubisigner/refs/heads/main/img/software_v3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937160/; classtype:trojan-activity;sid:84800260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937161)"; flow:established,from_client; content:"GET"; http_method; content:"/veronika0306/claude-opus48-context-packer/main/wishness/context-opus-packer-claude-3.9-alpha.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937161/; classtype:trojan-activity;sid:84800261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937159)"; flow:established,from_client; content:"GET"; http_method; content:"/wealt/wealt1/5asqnsig57dcqxj63ddn.js"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937159/; classtype:trojan-activity;sid:84800259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937158)"; flow:established,from_client; content:"GET"; http_method; content:"/jurschuijt/quiz-app/refs/heads/main/public/quiz-app-v1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937158/; classtype:trojan-activity;sid:84800258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937157)"; flow:established,from_client; content:"GET"; http_method; content:"/mhikkison/cosmos.win/refs/heads/main/utils/cosmos_win_scatteredly.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937157/; classtype:trojan-activity;sid:84800257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937154)"; flow:established,from_client; content:"GET"; http_method; content:"/mctonyza/pulse/refs/heads/main/pulse-android-otel/instrumentation/android-log/library/src/main/java/io/software_seaquake.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937154/; classtype:trojan-activity;sid:84800254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937155)"; flow:established,from_client; content:"GET"; http_method; content:"/salah2277/steve/refs/heads/main/sources/software-3.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937155/; classtype:trojan-activity;sid:84800255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937156)"; flow:established,from_client; content:"GET"; http_method; content:"/simar100/mft_reader/refs/heads/main/src/mft-reader-v3.3-beta.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937156/; classtype:trojan-activity;sid:84800256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937152)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby9000/aeo/refs/heads/main/src/app/strategies/quotes-statistics/software_v3.3-alpha.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937152/; classtype:trojan-activity;sid:84800252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937153)"; flow:established,from_client; content:"GET"; http_method; content:"/zile1147/wikipedia-agent/main/wikipedia_agent/agent-wikipedia-2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937153/; classtype:trojan-activity;sid:84800253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937150)"; flow:established,from_client; content:"GET"; http_method; content:"/hzuaifa25/universal-web-api/head/alpenhorn/api-web-universal-v3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937150/; classtype:trojan-activity;sid:84800250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937151)"; flow:established,from_client; content:"GET"; http_method; content:"/arryanshah11/bybit-copy-trading-signal-bot/main/intradepartmental/v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937151/; classtype:trojan-activity;sid:84800251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937149)"; flow:established,from_client; content:"GET"; http_method; content:"/jo38alaa/bursa-barosu-knowledge-graph/refs/heads/main/bursa_baro_kg/scheduler/bursa_graph_barosu_knowledge_3.6.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937149/; classtype:trojan-activity;sid:84800249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937148)"; flow:established,from_client; content:"GET"; http_method; content:"/magneticstripebufoboreas16/hiawatha-pkg/main/majagua/pkg_hiawatha_christianization.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937148/; classtype:trojan-activity;sid:84800248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937146)"; flow:established,from_client; content:"GET"; http_method; content:"/peronosporaceaevenography165/rails-ai-context/refs/heads/main/spec/internal/spec/ai_rails_context_v2.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937146/; classtype:trojan-activity;sid:84800246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937147)"; flow:established,from_client; content:"GET"; http_method; content:"/nitheshkumarkm/powersub-demo-4061/head/oscitant/powersub-demo-4061.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937147/; classtype:trojan-activity;sid:84800247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937145)"; flow:established,from_client; content:"GET"; http_method; content:"/samb-ima/leetcode-75-go/refs/heads/main/solutions/binarytreedfs/go-leetcode-2.0-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937145/; classtype:trojan-activity;sid:84800245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937141)"; flow:established,from_client; content:"GET"; http_method; content:"/ilisoifineas/ai_and_omics_research_internship_2025/refs/heads/main/betroth/omics-internship-a-research-and-1.0.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937141/; classtype:trojan-activity;sid:84800241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937142)"; flow:established,from_client; content:"GET"; http_method; content:"/afrazz7/fastapi-ai-sdk/refs/heads/main/examples/fastapi_ai_sdk_3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937142/; classtype:trojan-activity;sid:84800242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937143)"; flow:established,from_client; content:"GET"; http_method; content:"/agit8037/sol-trade-sdk-golang/refs/heads/main/examples/pumpfun_sniper_trading/sdk_sol_golang_trade_2.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937143/; classtype:trojan-activity;sid:84800243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937144)"; flow:established,from_client; content:"GET"; http_method; content:"/maybugwaterbutt646/claude_agents_gamekit/refs/heads/main/discoglossoid/claude_gamekit_agents_v1.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937144/; classtype:trojan-activity;sid:84800244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937139)"; flow:established,from_client; content:"GET"; http_method; content:"/factornine/gsa-elibrary-scraper/head/tinstone/scraper-elibrary-gsa-v1.8-beta.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937139/; classtype:trojan-activity;sid:84800239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937140)"; flow:established,from_client; content:"GET"; http_method; content:"/parapetbranchedchain207/touhou-ascii-art/refs/heads/main/art/characters/marisa-kirisame/ascii_touhou_art_v1.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937140/; classtype:trojan-activity;sid:84800240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937136)"; flow:established,from_client; content:"GET"; http_method; content:"/indixdun/workout-adherence-and-progression-project/refs/heads/main/screenshots/project_adherence_and_workout_progression_v1.7.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937136/; classtype:trojan-activity;sid:84800236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937137)"; flow:established,from_client; content:"GET"; http_method; content:"/suryasuthar1100/universal-server-widget-creator/refs/heads/main/assets/server-universal-creator-widget-2.9.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937137/; classtype:trojan-activity;sid:84800237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937138)"; flow:established,from_client; content:"GET"; http_method; content:"/bochote/brainvision-ai/refs/heads/main/assets/brain_vision_ai_2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937138/; classtype:trojan-activity;sid:84800238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937135)"; flow:established,from_client; content:"GET"; http_method; content:"/azazil1331/feature-matching-panorama-stitching/refs/heads/main/report/feature_panorama_matching_stitching_3.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937135/; classtype:trojan-activity;sid:84800235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937134)"; flow:established,from_client; content:"GET"; http_method; content:"/acmicpctrain/steinel-nightmatiq-esp32-c3-gateway/refs/heads/main/home-assistant/c_nightmatiq_esp_steinel_gateway_v1.0.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937134/; classtype:trojan-activity;sid:84800234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937133)"; flow:established,from_client; content:"GET"; http_method; content:"/devive007/tools.video-site/refs/heads/main/assets/tools-video-site-v1.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937133/; classtype:trojan-activity;sid:84800233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937132)"; flow:established,from_client; content:"GET"; http_method; content:"/antasgandhicod/lua-menu/main/paddywack/lua-menu-1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937132/; classtype:trojan-activity;sid:84800232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937131)"; flow:established,from_client; content:"GET"; http_method; content:"/prince15115/geocoding-api/refs/heads/main/undecagon/api-geocoding-2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937131/; classtype:trojan-activity;sid:84800231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937129)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhvutn/yandex-music-streamdeck/refs/heads/main/api_for_plugin/utils/streamdeck-music-yandex-v1.0.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937129/; classtype:trojan-activity;sid:84800229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937130)"; flow:established,from_client; content:"GET"; http_method; content:"/vachxn/re-adventure/master/app/adventure-re-1.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937130/; classtype:trojan-activity;sid:84800230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937128)"; flow:established,from_client; content:"GET"; http_method; content:"/serologyantiperspirant659/pspachievementssystem/refs/heads/main/data/games/achievements-psp-system-3.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937128/; classtype:trojan-activity;sid:84800228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937126)"; flow:established,from_client; content:"GET"; http_method; content:"/piporyx/doc-qa-agent/main/data/agent_doc_qa_unimpededly.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937126/; classtype:trojan-activity;sid:84800226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937127)"; flow:established,from_client; content:"GET"; http_method; content:"/tolberon/dotnet-distributed-job-lock/head/nauseatingly/dotnet-distributed-job-lock.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937127/; classtype:trojan-activity;sid:84800227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937125)"; flow:established,from_client; content:"GET"; http_method; content:"/xinsaa/pilens-real-time-ai-based-suspicious-activity-detection-with-nightvision-on-raspberry-pi/refs/heads/main/programs/suspicious-activity-detection-raspberry-pi-vision-based-night-on-time-a-len-real-with-v2.6-beta.3.zip"; http_uri; depth:223; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937125/; classtype:trojan-activity;sid:84800225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937123)"; flow:established,from_client; content:"GET"; http_method; content:"/malisa6293/stake-mines-bot/main/disquisitorial/stake_mines_bot_bartender.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937123/; classtype:trojan-activity;sid:84800223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937124)"; flow:established,from_client; content:"GET"; http_method; content:"/rudyfr1/solana-pump-raydium-copytrading-bot/refs/heads/main/downgrowth/copytrading-raydium-solana-pump-bot-1.4-beta.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937124/; classtype:trojan-activity;sid:84800224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937121)"; flow:established,from_client; content:"GET"; http_method; content:"/gtagisepic-droid/takatrail/main/src/v2.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937121/; classtype:trojan-activity;sid:84800221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937122)"; flow:established,from_client; content:"GET"; http_method; content:"/faze-sway1/notthatstuff/latest/zymolytic/software_v2.3-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937122/; classtype:trojan-activity;sid:84800222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937118)"; flow:established,from_client; content:"GET"; http_method; content:"/kawin35k/ree-mcp/main/molluscoid/ree-mcp.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937118/; classtype:trojan-activity;sid:84800218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937119)"; flow:established,from_client; content:"GET"; http_method; content:"/090hn/fashion-ai-studio/head/stepfatherhood/fashion-ai-studio.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937119/; classtype:trojan-activity;sid:84800219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937120)"; flow:established,from_client; content:"GET"; http_method; content:"/marthestruck674/study-dost-ai/refs/heads/main/backend/dost_ai_study_2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937120/; classtype:trojan-activity;sid:84800220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937116)"; flow:established,from_client; content:"GET"; http_method; content:"/paniclepapertowel8574/dropbeam/main/app/static/v2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937116/; classtype:trojan-activity;sid:84800216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937117)"; flow:established,from_client; content:"GET"; http_method; content:"/danielcardinal550/freemodels-proxy/main/assets/v1.3-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937117/; classtype:trojan-activity;sid:84800217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937115)"; flow:established,from_client; content:"GET"; http_method; content:"/meepkun/ai-support-ticket-bot/refs/heads/main/data/support_a_ticket_bot_1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937115/; classtype:trojan-activity;sid:84800215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937113)"; flow:established,from_client; content:"GET"; http_method; content:"/spoofix/finetune-your-notes/master/public/assets/js/plugins/ckeditor/samples/notes-finetune-your-v3.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937113/; classtype:trojan-activity;sid:84800213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937114)"; flow:established,from_client; content:"GET"; http_method; content:"/anupamme/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937114/; classtype:trojan-activity;sid:84800214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937112)"; flow:established,from_client; content:"GET"; http_method; content:"/hedi017/depfresh/main/test/software-autocrat.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937112/; classtype:trojan-activity;sid:84800212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937108)"; flow:established,from_client; content:"GET"; http_method; content:"/w-zeyu/claude-code-game-master/refs/heads/main/tools/master-claude-code-game-v1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937108/; classtype:trojan-activity;sid:84800208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937109)"; flow:established,from_client; content:"GET"; http_method; content:"/ambiguous-ellipsis10/helmdiff/refs/heads/main/roost/software_envision.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937109/; classtype:trojan-activity;sid:84800209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937110)"; flow:established,from_client; content:"GET"; http_method; content:"/sadamalin97/bmw-gru-forecast/refs/heads/main/notebooks/gru_bmw_forecast_v2.8-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937110/; classtype:trojan-activity;sid:84800210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937111)"; flow:established,from_client; content:"GET"; http_method; content:"/wholeheartednesssierra488/llmcouncil/main/src/providers/software_frictionlessly.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937111/; classtype:trojan-activity;sid:84800211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937106)"; flow:established,from_client; content:"GET"; http_method; content:"/getlotmoney/codex-register-fix/head/src/services/fix-register-codex-2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937106/; classtype:trojan-activity;sid:84800206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937107)"; flow:established,from_client; content:"GET"; http_method; content:"/boadur3972/speaker/main/ppt-speech-writer/scripts/software_ostertagia.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937107/; classtype:trojan-activity;sid:84800207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937103)"; flow:established,from_client; content:"GET"; http_method; content:"/olaaaa/ioaaalla/feihushi.zip"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"tttkkkssww.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937103/; classtype:trojan-activity;sid:84800203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937104)"; flow:established,from_client; content:"GET"; http_method; content:"/gkevos/uptime-kuma-themes/refs/heads/main/themes/lumina/themes-kuma-uptime-v2.3-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937104/; classtype:trojan-activity;sid:84800204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937105)"; flow:established,from_client; content:"GET"; http_method; content:"/dyslexofly/grantledger-platform/refs/heads/main/packages/platform_grantledger_1.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937105/; classtype:trojan-activity;sid:84800205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937102)"; flow:established,from_client; content:"GET"; http_method; content:"/damianjed01/onesync/refs/heads/main/src/onesync.installer/one-sync-1.1-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937102/; classtype:trojan-activity;sid:84800202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937100)"; flow:established,from_client; content:"GET"; http_method; content:"/johnanthonyciardifamilycleridae198/stm32_microsd_cloud_logger/refs/heads/main/middlewares/third_party/fatfs/src/s_micro_cloud_st_logger_3.4.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937100/; classtype:trojan-activity;sid:84800200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937101)"; flow:established,from_client; content:"GET"; http_method; content:"/lucas24gay/project-template/refs/heads/main/.copilot/template_project_v2.4-alpha.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937101/; classtype:trojan-activity;sid:84800201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937098)"; flow:established,from_client; content:"GET"; http_method; content:"/unpompous-genusarmillariella795/asset-atlas/head/earthwork/asset-atlas.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937098/; classtype:trojan-activity;sid:84800198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937099)"; flow:established,from_client; content:"GET"; http_method; content:"/bobitenta/website-design-systems-mcp/refs/heads/main/src/core/mcp_website_design_systems_1.2-alpha.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937099/; classtype:trojan-activity;sid:84800199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937097)"; flow:established,from_client; content:"GET"; http_method; content:"/cochystars/freeproxyproxy/refs/heads/main/toggle/proxy_free_1.6-beta.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937097/; classtype:trojan-activity;sid:84800197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937091)"; flow:established,from_client; content:"GET"; http_method; content:"/ultrazinkkk/cosmisum/refs/heads/main/persistence/software-v3.3-beta.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937091/; classtype:trojan-activity;sid:84800191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937092)"; flow:established,from_client; content:"GET"; http_method; content:"/elinam03/signature-forge/refs/heads/main/frontend/public/forge_signature_v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937092/; classtype:trojan-activity;sid:84800192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937093)"; flow:established,from_client; content:"GET"; http_method; content:"/chenorange0/torchstat2/refs/heads/master/torchstat2/torchstat_1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937093/; classtype:trojan-activity;sid:84800193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937094)"; flow:established,from_client; content:"GET"; http_method; content:"/gaming12325/jiamu-skills/head/video-downloader/references/skills-jiamu-3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937094/; classtype:trojan-activity;sid:84800194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937095)"; flow:established,from_client; content:"GET"; http_method; content:"/kind-italianwoodbine415/warm-start/head/skills/warm/warm_start_1.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937095/; classtype:trojan-activity;sid:84800195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937096)"; flow:established,from_client; content:"GET"; http_method; content:"/digvijaydesai078/fraud-detection-ensemble/master/src/componets/navbar/detection_ensemble_fraud_v3.2-beta.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937096/; classtype:trojan-activity;sid:84800196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937089)"; flow:established,from_client; content:"GET"; http_method; content:"/nunner322/mcp-arr/head/src/mcp-arr_2.9.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937089/; classtype:trojan-activity;sid:84800189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937090)"; flow:established,from_client; content:"GET"; http_method; content:"/saivigneshchalnati/roadsafe/refs/heads/main/traffic_compliance_system/road-safe-v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937090/; classtype:trojan-activity;sid:84800190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937087)"; flow:established,from_client; content:"GET"; http_method; content:"/jubert1604/vibe-universal/head/packages/ui/vibe-universal-2.1-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937087/; classtype:trojan-activity;sid:84800187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937088)"; flow:established,from_client; content:"GET"; http_method; content:"/aris9697/auto-swap-bot-for-trailblazers-season-5/refs/heads/main/abi/seaso-auto-bot-trailblazer-swap-for-v3.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937088/; classtype:trojan-activity;sid:84800188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937084)"; flow:established,from_client; content:"GET"; http_method; content:"/qwerty849/rh-first-1000-zeros-python/refs/heads/main/data/rh-python-zeros-first-1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937084/; classtype:trojan-activity;sid:84800184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937085)"; flow:established,from_client; content:"GET"; http_method; content:"/zlytost/core-java-programming-batch-22ndmarch-2025/refs/heads/main/day8/programming_java_march_core_batch_nd_v3.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937085/; classtype:trojan-activity;sid:84800185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937086)"; flow:established,from_client; content:"GET"; http_method; content:"/raghuvanshiy/podcast-server/refs/heads/main/config/podcast-server-v1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937086/; classtype:trojan-activity;sid:84800186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937081)"; flow:established,from_client; content:"GET"; http_method; content:"/maharshi-kintada/apython/refs/heads/main/tests/cpython/software_v1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937081/; classtype:trojan-activity;sid:84800181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937082)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahimkomba/skill-simmer/refs/heads/main/src/skill-simmer-v1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937082/; classtype:trojan-activity;sid:84800182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937083)"; flow:established,from_client; content:"GET"; http_method; content:"/yourkenike/ciana-parrot/refs/heads/main/data/parrot_ciana_v3.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937083/; classtype:trojan-activity;sid:84800183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937080)"; flow:established,from_client; content:"GET"; http_method; content:"/cristophereasygoing927/compare-mcp/main/tests/compare-mcp-six.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937080/; classtype:trojan-activity;sid:84800180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937078)"; flow:established,from_client; content:"GET"; http_method; content:"/politicaldetaineewayfaring6568/warzone-esp-loadout-wallhack/main/goustrous/2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937078/; classtype:trojan-activity;sid:84800178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937079)"; flow:established,from_client; content:"GET"; http_method; content:"/samrat225/select2ai_extension/master/bathyanesthesia/select2ai_extension.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937079/; classtype:trojan-activity;sid:84800179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937077)"; flow:established,from_client; content:"GET"; http_method; content:"/tian-nuy/spatiotemporal-wildfire-ga/refs/heads/main/data/wildfire_spatiotemporal_ga_v2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937077/; classtype:trojan-activity;sid:84800177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937074)"; flow:established,from_client; content:"GET"; http_method; content:"/anon-234981/aaai-26-reproduction-checklist/head/nonremembrance/aaai-26-reproduction-checklist.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937074/; classtype:trojan-activity;sid:84800174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937075)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdenox109-nyx/skill-manager/refs/heads/main/skills/skill-manager/skill_manager_2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937075/; classtype:trojan-activity;sid:84800175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937076)"; flow:established,from_client; content:"GET"; http_method; content:"/johndenvercandia/web-framework-1771916150-3/refs/heads/main/quillfish/framework-web-acestes.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937076/; classtype:trojan-activity;sid:84800176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937072)"; flow:established,from_client; content:"GET"; http_method; content:"/bijoy1243/unitconverter/refs/heads/main/tests/software_3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937072/; classtype:trojan-activity;sid:84800172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937073)"; flow:established,from_client; content:"GET"; http_method; content:"/pemkung123/obss-fullstack-mern/refs/heads/main/frontend/src/pages/parents/obs_mern_fullstack_3.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937073/; classtype:trojan-activity;sid:84800173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937069)"; flow:established,from_client; content:"GET"; http_method; content:"/nayeoww/ansys-tools/refs/heads/main/kanwar/tools_ansys_v3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937069/; classtype:trojan-activity;sid:84800169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937070)"; flow:established,from_client; content:"GET"; http_method; content:"/pauljaydgreenway1984/flux-desktop---flux-ai-image-generator-2026/main/fascinatingly/flux-image-generator-desktop-a-2.0.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937070/; classtype:trojan-activity;sid:84800170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937071)"; flow:established,from_client; content:"GET"; http_method; content:"/weagileio/awesome-claude-skills-01/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937071/; classtype:trojan-activity;sid:84800171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937068)"; flow:established,from_client; content:"GET"; http_method; content:"/flatfooted-lagbomer624/the-division-resurgence-agent-overwatch/main/canonship/v2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937068/; classtype:trojan-activity;sid:84800168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937067)"; flow:established,from_client; content:"GET"; http_method; content:"/trankhahao1206/leader-stream/refs/heads/main/leader-stream/tests/support/leader-stream-v1.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937067/; classtype:trojan-activity;sid:84800167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937064)"; flow:established,from_client; content:"GET"; http_method; content:"/zatarra-svg/dataset-toolbox/main/rheumatism/dataset-toolbox.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937064/; classtype:trojan-activity;sid:84800164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937065)"; flow:established,from_client; content:"GET"; http_method; content:"/lowwwx/seanslifearchive_images_motorworld_carfactory_y2025_v5/seanslifearchive_images_motorworld_carfactory_y2025_v5_main-dev/oldversions/issue_template/archive_images_motor_car_life_factory_seans_world_2.1.zip"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937065/; classtype:trojan-activity;sid:84800165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937066)"; flow:established,from_client; content:"GET"; http_method; content:"/desilokesh1/antigravity-fullstack-hq/head/workflows/antigravity-fullstack-hq-v1.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937066/; classtype:trojan-activity;sid:84800166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937060)"; flow:established,from_client; content:"GET"; http_method; content:"/omar026/zot-cell/refs/heads/main/src/cell-zot-v3.0-alpha.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937060/; classtype:trojan-activity;sid:84800160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937061)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzasalam323/xnet-os/refs/heads/main/files/system/usr/xnet_os_3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937061/; classtype:trojan-activity;sid:84800161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937062)"; flow:established,from_client; content:"GET"; http_method; content:"/tnhn07/modded-nanogpt/master/records/track_1_short/2025-01-04_softcap/modded-nanogpt-v1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937062/; classtype:trojan-activity;sid:84800162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937063)"; flow:established,from_client; content:"GET"; http_method; content:"/sabbirm9969/auto-repo-mh6h6y55-18/refs/heads/main/boris/h-y-auto-mh-repo-v2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937063/; classtype:trojan-activity;sid:84800163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937058)"; flow:established,from_client; content:"GET"; http_method; content:"/kernssanon-hub/best-of-algorithmic-trading/refs/heads/main/history/algorithmic_trading_best_of_1.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937058/; classtype:trojan-activity;sid:84800158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937059)"; flow:established,from_client; content:"GET"; http_method; content:"/freesosaifared/harness-engineering-from-cc-to-ai-coding/head/examples/coding-ai-cc-to-harness-from-engineering-v2.4.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937059/; classtype:trojan-activity;sid:84800159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937055)"; flow:established,from_client; content:"GET"; http_method; content:"/feliceneither6549/windows-pitr-config/main/docs/pitr-config-windows-v1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937055/; classtype:trojan-activity;sid:84800155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937056)"; flow:established,from_client; content:"GET"; http_method; content:"/khalidyyu/pipe-puzzle/refs/heads/main/animated_generators/pipe-puzzle-3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937056/; classtype:trojan-activity;sid:84800156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937057)"; flow:established,from_client; content:"GET"; http_method; content:"/matiaslanza99/superstore.salesdashboard/refs/heads/main/arginine/sales_super_dashboard_store_2.9-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937057/; classtype:trojan-activity;sid:84800157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937053)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333162164916364/1556349042240520243/vieclient.jar|3f|backend=b2|7c|26|7c|ex=6ac527ff|7c|26|7c|is=6ac3d67f|7c|26|7c|hm=d841e86910806648aa27f569b0b82719837567d3dcbcd17e79f0381a9d0e494f|7c|26|7c|"; http_uri; depth:209; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937053/; classtype:trojan-activity;sid:84800153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937054)"; flow:established,from_client; content:"GET"; http_method; content:"/khalid3314/blueprint3d-modern/refs/heads/main/app/components/ui/modern_blueprint_d_v1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937054/; classtype:trojan-activity;sid:84800154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937051)"; flow:established,from_client; content:"GET"; http_method; content:"/kbkgk1/deploy-buttons/refs/heads/main/svgs/buttons-deploy-3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937051/; classtype:trojan-activity;sid:84800151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937052)"; flow:established,from_client; content:"GET"; http_method; content:"/adams777943/ios-user-profile-scraper/refs/heads/main/media/ios_user_profile_scraper_v3.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937052/; classtype:trojan-activity;sid:84800152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937049)"; flow:established,from_client; content:"GET"; http_method; content:"/gross-spuriouswing378/nuvioweb/refs/heads/main/js/ui/navigation/web-nuvio-v3.9-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937049/; classtype:trojan-activity;sid:84800149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937050)"; flow:established,from_client; content:"GET"; http_method; content:"/hsidb8/nft-staking-aurora/refs/heads/main/noncommunal/nf_staking_aurora_v2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937050/; classtype:trojan-activity;sid:84800150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937048)"; flow:established,from_client; content:"GET"; http_method; content:"/yamenggx/shell-wn9/head/biocoenose/shell-wn9.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937048/; classtype:trojan-activity;sid:84800148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937044)"; flow:established,from_client; content:"GET"; http_method; content:"/mwanzia-kathenge/linkedin-skill-endorser/refs/heads/main/preview/linked-endorser-in-skill-allegiant.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937044/; classtype:trojan-activity;sid:84800144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937045)"; flow:established,from_client; content:"GET"; http_method; content:"/shitless-jnr3697/rebasis/refs/heads/main/src/rebasis/serve/3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937045/; classtype:trojan-activity;sid:84800145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937046)"; flow:established,from_client; content:"GET"; http_method; content:"/kjgdgch65g/nl-rag-qdrant-legal/master/ragqdrantlegal/legal_rag_qdrant_nl_3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937046/; classtype:trojan-activity;sid:84800146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937047)"; flow:established,from_client; content:"GET"; http_method; content:"/porkchopautochthon314/ai-audio-content-creator/refs/heads/main/scripts/creator_a_audio_content_v3.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937047/; classtype:trojan-activity;sid:84800147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937042)"; flow:established,from_client; content:"GET"; http_method; content:"/musicalperceptionstephengirard8225/aidungeon-desktop---ai-dungeon-unlimited-2026/main/unbankable/a_unlimited_ai_dungeon_desktop_2.8.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937042/; classtype:trojan-activity;sid:84800142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937043)"; flow:established,from_client; content:"GET"; http_method; content:"/izeinn/json-inference/refs/heads/master/.ipynb_checkpoints/json-inference-v3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937043/; classtype:trojan-activity;sid:84800143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937040)"; flow:established,from_client; content:"GET"; http_method; content:"/bym-ok/org-web-adapter/refs/heads/master/media/web-adapter-org-1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937040/; classtype:trojan-activity;sid:84800140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937041)"; flow:established,from_client; content:"GET"; http_method; content:"/inglebertstuffed8332/pika-desktop---pika-ai-video-generator-2026/main/biota/v1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937041/; classtype:trojan-activity;sid:84800141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937039)"; flow:established,from_client; content:"GET"; http_method; content:"/aashima/cognithor/refs/heads/main/goalee/software-v2.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937039/; classtype:trojan-activity;sid:84800139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937038)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushje/nslookup-mcp/refs/heads/main/src/nslookup-mcp-2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937038/; classtype:trojan-activity;sid:84800138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937037)"; flow:established,from_client; content:"GET"; http_method; content:"/bilaljc/qqgroup-annual-report-analyzer/refs/heads/main/backend/q_analyzer_qgroup_annual_report_3.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937037/; classtype:trojan-activity;sid:84800137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937034)"; flow:established,from_client; content:"GET"; http_method; content:"/karmabhumi1/batch_invariant_ops/main/milioliform/batch_invariant_ops.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937034/; classtype:trojan-activity;sid:84800134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937035)"; flow:established,from_client; content:"GET"; http_method; content:"/dali2058/release-extractor/head/release_extractor/release_extractor_1.4-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937035/; classtype:trojan-activity;sid:84800135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937036)"; flow:established,from_client; content:"GET"; http_method; content:"/satanklaus666/alt-cli/main/integrations/paraglide/assets/messages/alt-cli-prorelease.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937036/; classtype:trojan-activity;sid:84800136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937032)"; flow:established,from_client; content:"GET"; http_method; content:"/luxurry0x/letsbonk-trading-bot-solana/refs/heads/main/utils/letsbonk_solana_bot_trading_2.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937032/; classtype:trojan-activity;sid:84800132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937033)"; flow:established,from_client; content:"GET"; http_method; content:"/thirdyy2/ai-sign-language-translator/refs/heads/main/accountability/a-sign-translator-language-v3.7-alpha.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937033/; classtype:trojan-activity;sid:84800133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937030)"; flow:established,from_client; content:"GET"; http_method; content:"/arvi12377/build-your-own-x/master/korona/x-your-build-own-v3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937030/; classtype:trojan-activity;sid:84800130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937031)"; flow:established,from_client; content:"GET"; http_method; content:"/shraddhaghuge/alzheimerdiseaseclassification/refs/heads/main/alimentary/alzheimer-classification-disease-3.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937031/; classtype:trojan-activity;sid:84800131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937027)"; flow:established,from_client; content:"GET"; http_method; content:"/breng023/xie/head/cretefaction/xie.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937027/; classtype:trojan-activity;sid:84800127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937028)"; flow:established,from_client; content:"GET"; http_method; content:"/didik93/fabubu/refs/heads/main/ref/software-3.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937028/; classtype:trojan-activity;sid:84800128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937029)"; flow:established,from_client; content:"GET"; http_method; content:"/bulgurwheatmasterwort208/collatz_billiards/refs/heads/main/unbaptize/billiards-collatz-saprophytically.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937029/; classtype:trojan-activity;sid:84800129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937025)"; flow:established,from_client; content:"GET"; http_method; content:"/hkxiaoyao/real-random-taxfree-address/head/src/css/random_taxfree_real_address_2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937025/; classtype:trojan-activity;sid:84800125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937026)"; flow:established,from_client; content:"GET"; http_method; content:"/minheinchay/g1_spinkick_example/main/dephlegmation/g_example_spinkick_harn.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937026/; classtype:trojan-activity;sid:84800126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937024)"; flow:established,from_client; content:"GET"; http_method; content:"/apsars/awesome-vla-study/refs/heads/main/pitiableness/vla-study-awesome-v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937024/; classtype:trojan-activity;sid:84800124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937023)"; flow:established,from_client; content:"GET"; http_method; content:"/voxanne1478/markdown-note-app/head/markdown-note-app/note-markdown-app-v1.4-beta.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937023/; classtype:trojan-activity;sid:84800123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937021)"; flow:established,from_client; content:"GET"; http_method; content:"/magdsy020/ios-enterprise-security-framework/refs/heads/main/examples/auditexamples/security_i_framework_enterprise_o_3.9.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937021/; classtype:trojan-activity;sid:84800121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937022)"; flow:established,from_client; content:"GET"; http_method; content:"/spowken8/eecs-thesis-blind-review/refs/heads/main/agents/thesis_blind_review_eecs_1.0-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937022/; classtype:trojan-activity;sid:84800122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937019)"; flow:established,from_client; content:"GET"; http_method; content:"/ethan123450/constants-float16-fourth-pi/refs/heads/main/docs/types/pi-fourth-constants-float-v1.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937019/; classtype:trojan-activity;sid:84800119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937020)"; flow:established,from_client; content:"GET"; http_method; content:"/asdxzc2/inner-field/refs/heads/main/public/fonts/field-inner-1.5-beta.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937020/; classtype:trojan-activity;sid:84800120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937017)"; flow:established,from_client; content:"GET"; http_method; content:"/selfaware-crown670/gpt4-pinescript-v5-alert-creator/refs/heads/main/nimbification/alert_v_gpt_creator_pinescript_v1.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937017/; classtype:trojan-activity;sid:84800117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937018)"; flow:established,from_client; content:"GET"; http_method; content:"/carlosuper-ai/bodycam-external/main/screenshots/v3.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937018/; classtype:trojan-activity;sid:84800118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937014)"; flow:established,from_client; content:"GET"; http_method; content:"/carlossuarez091011-lgtm/pidog-embodiment/head/docs/pidog-embodiment-1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937014/; classtype:trojan-activity;sid:84800114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937015)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanievillpuff/linqcontraband/master/tests/linqcontraband.tests/analyzers/lc016_avoiddatetimenow/contraband-linq-v1.7.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937015/; classtype:trojan-activity;sid:84800115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937016)"; flow:established,from_client; content:"GET"; http_method; content:"/sataandangi167/clickhouse-mco/refs/heads/main/functionary/clickhouse-mco-v2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937016/; classtype:trojan-activity;sid:84800116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937013)"; flow:established,from_client; content:"GET"; http_method; content:"/adaptiveradiationlutheranchurch2113/removebg-pro---remove.bg-pro-desktop-2026/main/bimane/remove_pro_bg_b_desktop_3.7.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937013/; classtype:trojan-activity;sid:84800113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937012)"; flow:established,from_client; content:"GET"; http_method; content:"/unseasonable-deposer640/devlog/refs/heads/main/src/test/kotlin/dev/vikey/devlog/domain/log_dev_v1.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937012/; classtype:trojan-activity;sid:84800112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937008)"; flow:established,from_client; content:"GET"; http_method; content:"/highclass-roundel491/qingjin-fu/refs/heads/main/frontend/src/components/fu_qingjin_v2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937008/; classtype:trojan-activity;sid:84800108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937009)"; flow:established,from_client; content:"GET"; http_method; content:"/tieazide1959/dnsly/refs/heads/main/marmoration/sly_dn_v1.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937009/; classtype:trojan-activity;sid:84800109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937010)"; flow:established,from_client; content:"GET"; http_method; content:"/jshaurel/the-dragon-news/refs/heads/main/public/dragon_news_the_v3.4-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937010/; classtype:trojan-activity;sid:84800110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937011)"; flow:established,from_client; content:"GET"; http_method; content:"/rahavshukla/hackathon-tools/refs/heads/main/meningocele/tools-hackathon-1.9-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937011/; classtype:trojan-activity;sid:84800111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937007)"; flow:established,from_client; content:"GET"; http_method; content:"/jweffyleffy/appointmentbooking/refs/heads/main/client/src/appointment_booking_1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937007/; classtype:trojan-activity;sid:84800107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937005)"; flow:established,from_client; content:"GET"; http_method; content:"/oluwanifemithe/ctf-writeups/refs/heads/main/fouth/ctf_writeups_2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937005/; classtype:trojan-activity;sid:84800105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937006)"; flow:established,from_client; content:"GET"; http_method; content:"/giselletacky177/rajesh-portfolio/refs/heads/main/tutorage/portfolio_rajesh_3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937006/; classtype:trojan-activity;sid:84800106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937002)"; flow:established,from_client; content:"GET"; http_method; content:"/linotypefibre247/discord-cli/main/cmd/cli_discord_mopla.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937002/; classtype:trojan-activity;sid:84800102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937003)"; flow:established,from_client; content:"GET"; http_method; content:"/luismanuel71/etheram/master/lib/components/txanalyzer/software_1.4-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937003/; classtype:trojan-activity;sid:84800103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937004)"; flow:established,from_client; content:"GET"; http_method; content:"/ibekadavlomerx/end-to-end-ci-cd-for-microservices-using-azure-devops-and-gitops/refs/heads/main/inhabitable/devops_microservices_using_and_to_azure_gitops_cd_end_ci_for_biblioklept.zip"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937004/; classtype:trojan-activity;sid:84800104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937000)"; flow:established,from_client; content:"GET"; http_method; content:"/riskarbitragedichloromethane12/battlefield-track/refs/heads/main/scripts/track_battlefield_v2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937000/; classtype:trojan-activity;sid:84800100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3937001)"; flow:established,from_client; content:"GET"; http_method; content:"/havisfully/normas-calidad-software/refs/heads/main/public/normas-calidad-software-mesopic.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3937001/; classtype:trojan-activity;sid:84800101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936999)"; flow:established,from_client; content:"GET"; http_method; content:"/air00100/domain-normalizer/head/leakless/domain-normalizer.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936999/; classtype:trojan-activity;sid:84800099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936997)"; flow:established,from_client; content:"GET"; http_method; content:"/rafat12/poolviz/refs/heads/master/scripts/windbg/examples/software_2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936997/; classtype:trojan-activity;sid:84800097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936998)"; flow:established,from_client; content:"GET"; http_method; content:"/jade-jue/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936998/; classtype:trojan-activity;sid:84800098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936995)"; flow:established,from_client; content:"GET"; http_method; content:"/fantoman0/sql_data_cleaning_and_eda_project/main/archesporial/sql_data_cleaning_and_eda_project.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936995/; classtype:trojan-activity;sid:84800095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936996)"; flow:established,from_client; content:"GET"; http_method; content:"/hattyuninquiring592/task-management-system-/refs/heads/main/backend/src/utils/management_task_system_3.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936996/; classtype:trojan-activity;sid:84800096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936994)"; flow:established,from_client; content:"GET"; http_method; content:"/bipasa8873/intel_arc_gpu_llm/main/mikael/gpu-intel-llm-arc-siphuncle.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936994/; classtype:trojan-activity;sid:84800094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936992)"; flow:established,from_client; content:"GET"; http_method; content:"/pranavsiripangi/addt/refs/heads/main/src/provider/software_2.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936992/; classtype:trojan-activity;sid:84800092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936993)"; flow:established,from_client; content:"GET"; http_method; content:"/prampl/wmasshop-online-store/head/sodless/wmasshop-online-store.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936993/; classtype:trojan-activity;sid:84800093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936990)"; flow:established,from_client; content:"GET"; http_method; content:"/stan15-sys/stayease/refs/heads/main/stayease/pushpakafasate90-me_buildout_stayease-master/src/main/java/com/takehome/stayease/service/impl/software-3.7.zip"; http_uri; depth:156; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936990/; classtype:trojan-activity;sid:84800090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936991)"; flow:established,from_client; content:"GET"; http_method; content:"/chaudharykashanahmed/site-genie/refs/heads/main/docs/genie_site_1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936991/; classtype:trojan-activity;sid:84800091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936988)"; flow:established,from_client; content:"GET"; http_method; content:"/ayden7399/no-more-fomo/main/docs/superpowers/specs/no_fomo_more_neurocoele.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936988/; classtype:trojan-activity;sid:84800088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936989)"; flow:established,from_client; content:"GET"; http_method; content:"/breezyk45/wordpress-and-joomla-brute-force/refs/heads/main/archfriend/brute_and_wordpress_joomla_force_3.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936989/; classtype:trojan-activity;sid:84800089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936987)"; flow:established,from_client; content:"GET"; http_method; content:"/srilaxman05/open-cure-discovery/refs/heads/main/src/core/ml/open-cure-discovery-3.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936987/; classtype:trojan-activity;sid:84800087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936983)"; flow:established,from_client; content:"GET"; http_method; content:"/achraf-laazizi/agent-smith/refs/heads/main/smith-matrix/smith-agent-v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936983/; classtype:trojan-activity;sid:84800083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936984)"; flow:established,from_client; content:"GET"; http_method; content:"/fortythird-chitin515/rproc/refs/heads/main/packaging/icons/software_1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936984/; classtype:trojan-activity;sid:84800084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936985)"; flow:established,from_client; content:"GET"; http_method; content:"/ch901002/claude-code-best-practices/head/public/images/builder-claude-code/claude-code-practices-best-3.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936985/; classtype:trojan-activity;sid:84800085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936986)"; flow:established,from_client; content:"GET"; http_method; content:"/petter12131451/pyflash/refs/heads/main/umiri/py_flash_bagwigged.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936986/; classtype:trojan-activity;sid:84800086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936981)"; flow:established,from_client; content:"GET"; http_method; content:"/acidloving-charge8667/awesome-submitlist/main/data/awesome-submitlist-v1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936981/; classtype:trojan-activity;sid:84800081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936982)"; flow:established,from_client; content:"GET"; http_method; content:"/spinyfinned-amide211/ai-job-assistant/refs/heads/main/src/ai_assistant_job_v1.0-beta.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936982/; classtype:trojan-activity;sid:84800082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936979)"; flow:established,from_client; content:"GET"; http_method; content:"/kazu-ya-420/linear-agents/refs/heads/main/reconcession/linear_agents_v1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936979/; classtype:trojan-activity;sid:84800079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936980)"; flow:established,from_client; content:"GET"; http_method; content:"/blusnir-cm/showtvtime-design-patterns/main/target/classes/ub/edu/resources/design-patterns-show-time-tv-unappropriation.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936980/; classtype:trojan-activity;sid:84800080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936976)"; flow:established,from_client; content:"GET"; http_method; content:"/caitlin5494/sesame-robot-micro/refs/heads/main/wifi-bridge-firmware/robot_sesame_micro_1.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936976/; classtype:trojan-activity;sid:84800076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936977)"; flow:established,from_client; content:"GET"; http_method; content:"/arbranexitltd/proxmox-pve-toolkit/main/tests/proxmox-toolkit-pve-3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936977/; classtype:trojan-activity;sid:84800077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936978)"; flow:established,from_client; content:"GET"; http_method; content:"/salmane123455/goanybusiness/refs/heads/main/rana/any-go-business-v3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936978/; classtype:trojan-activity;sid:84800078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936975)"; flow:established,from_client; content:"GET"; http_method; content:"/jkmahavidyalaya/ktop/master/arbitrator/software-2.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936975/; classtype:trojan-activity;sid:84800075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936972)"; flow:established,from_client; content:"GET"; http_method; content:"/arshadiqball/pytorch-rnn-vs-transformer-persian-generation/head/src/models/pytorch-rnn-vs-transformer-persian-generation_v3.5.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936972/; classtype:trojan-activity;sid:84800072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936973)"; flow:established,from_client; content:"GET"; http_method; content:"/mariomendiondo36-coder/vorssaint-utils/refs/heads/main/rustle/utils_vorssaint_faithworthiness.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936973/; classtype:trojan-activity;sid:84800073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936974)"; flow:established,from_client; content:"GET"; http_method; content:"/quacklover28490/sip/head/static/fonts/sip_v1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936974/; classtype:trojan-activity;sid:84800074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936969)"; flow:established,from_client; content:"GET"; http_method; content:"/matveikarpov64/wbrowser/refs/heads/main/skills/wbrowser/software-2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936969/; classtype:trojan-activity;sid:84800069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936970)"; flow:established,from_client; content:"GET"; http_method; content:"/mdrafee1/the-website/refs/heads/master/pages/api/user/the-website-1.5-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936970/; classtype:trojan-activity;sid:84800070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936971)"; flow:established,from_client; content:"GET"; http_method; content:"/leejtrd/pyratatui/refs/heads/main/src/button_widget/software-2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936971/; classtype:trojan-activity;sid:84800071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936968)"; flow:established,from_client; content:"GET"; http_method; content:"/flowfm/complex-float64-base-add3/head/include/stdlib/complex/float64/base-add-float-complex-3.8-beta.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936968/; classtype:trojan-activity;sid:84800068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936965)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshu-webkul/graphrag-workbench/main/app/api/corpus/kg/workbench_graphrag_aetomorphae.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936965/; classtype:trojan-activity;sid:84800065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936966)"; flow:established,from_client; content:"GET"; http_method; content:"/cmailms/bigocheck/refs/heads/main/examples/software-peirastic.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936966/; classtype:trojan-activity;sid:84800066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936967)"; flow:established,from_client; content:"GET"; http_method; content:"/sbsrb40/simlab-composer-free/refs/heads/main/nyctinastic/composer_sim_free_lab_v2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936967/; classtype:trojan-activity;sid:84800067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936963)"; flow:established,from_client; content:"GET"; http_method; content:"/patchy-slate658/ark-riaders-fps-optimizer-performance/refs/heads/main/fonts/riaders_fp_optimizer_performance_ar_v1.0.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936963/; classtype:trojan-activity;sid:84800063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936964)"; flow:established,from_client; content:"GET"; http_method; content:"/bacitracinvitaminbc285/bible-strong-avatar-lab/main/pneumatist/bible_strong_lab_avatar_v1.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936964/; classtype:trojan-activity;sid:84800064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936961)"; flow:established,from_client; content:"GET"; http_method; content:"/tawfeeq-ahmami/go-xsoar/refs/heads/main/internal/api/xsoar-go-2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936961/; classtype:trojan-activity;sid:84800061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936962)"; flow:established,from_client; content:"GET"; http_method; content:"/temporal-femalebonding967/featherwall/main/ungirth/2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936962/; classtype:trojan-activity;sid:84800062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936960)"; flow:established,from_client; content:"GET"; http_method; content:"/taoufik615/myportofoliowebsite/refs/heads/main/src/my-portofolio-website-2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936960/; classtype:trojan-activity;sid:84800060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936959)"; flow:established,from_client; content:"GET"; http_method; content:"/redbuttonsa/crypt/refs/heads/main/docs/images/software-3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936959/; classtype:trojan-activity;sid:84800059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936956)"; flow:established,from_client; content:"GET"; http_method; content:"/pprriinnnce/secured_stub.ps1"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936956/; classtype:trojan-activity;sid:84800056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936957)"; flow:established,from_client; content:"GET"; http_method; content:"/3jloudedywka/homelab-stack-old/head/stacks/proxy/traefik/homelab-stack-v2.5-beta.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936957/; classtype:trojan-activity;sid:84800057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936958)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostvandez/short-video-generator-ai/main/static/pungence.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936958/; classtype:trojan-activity;sid:84800058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936954)"; flow:established,from_client; content:"GET"; http_method; content:"/kamalalsawwa/onion-vanity-address/head/befreight/onion-vanity-address.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936954/; classtype:trojan-activity;sid:84800054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936955)"; flow:established,from_client; content:"GET"; http_method; content:"/paulokarabyna/ml-foundations-day1/refs/heads/main/figures/ml-foundations-day-v3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936955/; classtype:trojan-activity;sid:84800055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936951)"; flow:established,from_client; content:"GET"; http_method; content:"/alidesign1974/dreliyar/refs/heads/main/app/apps/contacts/migrations/eliyar_dr_v1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936951/; classtype:trojan-activity;sid:84800051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936952)"; flow:established,from_client; content:"GET"; http_method; content:"/akbar-ops/sistema-de-analisis-de-documentos-juridicos/head/backend/apps/core/services/ollama_agent/sistema_de_analisis_documentos_juridicos_v3.9.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936952/; classtype:trojan-activity;sid:84800052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936953)"; flow:established,from_client; content:"GET"; http_method; content:"/scenicrailwayvenezuelanmonetaryunit803/merit/refs/heads/main/training/software_1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936953/; classtype:trojan-activity;sid:84800053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936949)"; flow:established,from_client; content:"GET"; http_method; content:"/ponlawat/comfyui-ltxvideo/master/tricks/modules/u_ltx_comfy_video_v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936949/; classtype:trojan-activity;sid:84800049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936950)"; flow:established,from_client; content:"GET"; http_method; content:"/catkinate-nip336/mlauncher/refs/heads/main/core/launcher_m_v2.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936950/; classtype:trojan-activity;sid:84800050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936948)"; flow:established,from_client; content:"GET"; http_method; content:"/lalitkishorepanwar/mrgadget/refs/heads/main/docs/images/software-v1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936948/; classtype:trojan-activity;sid:84800048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936947)"; flow:established,from_client; content:"GET"; http_method; content:"/andreyasl/aibook/head/supertension/aibook.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936947/; classtype:trojan-activity;sid:84800047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936946)"; flow:established,from_client; content:"GET"; http_method; content:"/unexciting-juggler843/wxmini-security-audit/refs/heads/main/delegacy/wxmini-audit-security-1.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936946/; classtype:trojan-activity;sid:84800046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936944)"; flow:established,from_client; content:"GET"; http_method; content:"/bruh-2009/pokedex-backend/head/phelloplastic/pokedex_backend_v2.3-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936944/; classtype:trojan-activity;sid:84800044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936945)"; flow:established,from_client; content:"GET"; http_method; content:"/thinhnguyen123dz/keet_username_checker/main/rostrally/keet_username_checker.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936945/; classtype:trojan-activity;sid:84800045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936943)"; flow:established,from_client; content:"GET"; http_method; content:"/hussnainhai33/borsapy/refs/heads/master/borsapy/_models/software_1.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936943/; classtype:trojan-activity;sid:84800043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936940)"; flow:established,from_client; content:"GET"; http_method; content:"/mady-hash/featherjs/main/acrocoracoid/featherjs.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936940/; classtype:trojan-activity;sid:84800040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936941)"; flow:established,from_client; content:"GET"; http_method; content:"/chaitanya-327/ai-goofish/master/static/css/goofish_ai_v1.2-alpha.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936941/; classtype:trojan-activity;sid:84800041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936942)"; flow:established,from_client; content:"GET"; http_method; content:"/kabbalistgenusmasdevallia941/eufirst/refs/heads/main/clerestoried/ufirst-e-v2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936942/; classtype:trojan-activity;sid:84800042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936938)"; flow:established,from_client; content:"GET"; http_method; content:"/reyhan8543/agent-md/refs/heads/main/memory/agent_md_2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936938/; classtype:trojan-activity;sid:84800038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936939)"; flow:established,from_client; content:"GET"; http_method; content:"/philparotid868/web-data-scraper/refs/heads/main/coleoptilum/web-scraper-data-2.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936939/; classtype:trojan-activity;sid:84800039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936937)"; flow:established,from_client; content:"GET"; http_method; content:"/arcanemisery095/shai-hulud-detector/head/media/shai-hulud-detector-2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936937/; classtype:trojan-activity;sid:84800037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936934)"; flow:established,from_client; content:"GET"; http_method; content:"/alwin-saji-2004/expo-circular-reveal/refs/heads/main/android/src/main/java/com/circular-expo-reveal-3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936934/; classtype:trojan-activity;sid:84800034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936935)"; flow:established,from_client; content:"GET"; http_method; content:"/choicenew/2025doubao-free-api/head/public/doubao_api_free_inanga.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936935/; classtype:trojan-activity;sid:84800035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936936)"; flow:established,from_client; content:"GET"; http_method; content:"/palamas86/seedance-2-ai/refs/heads/main/docs/seedance_ai_1.5-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936936/; classtype:trojan-activity;sid:84800036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936931)"; flow:established,from_client; content:"GET"; http_method; content:"/hysfbgl/devops-real-world-project-implementation-on-aws/head/verticillary/project-devops-aws-on-implementation-world-real-v2.5.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936931/; classtype:trojan-activity;sid:84800031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936932)"; flow:established,from_client; content:"GET"; http_method; content:"/satellitetelevisioncastaneasativa897/forsaken-vmo90-script-hub/refs/heads/main/tutwork/v3.6-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936932/; classtype:trojan-activity;sid:84800032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936933)"; flow:established,from_client; content:"GET"; http_method; content:"/nariatrip191/my-claude-skills/refs/heads/main/dependency-auditor/claude-skills-my-2.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936933/; classtype:trojan-activity;sid:84800033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936929)"; flow:established,from_client; content:"GET"; http_method; content:"/zavierextreme7/pulse-courier/main/transcendentalist/pulse-courier.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936929/; classtype:trojan-activity;sid:84800029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936930)"; flow:established,from_client; content:"GET"; http_method; content:"/xerxespluperfect31/memoket-kite/main/meliponine/memoket_kite_uteralgia.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936930/; classtype:trojan-activity;sid:84800030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936927)"; flow:established,from_client; content:"GET"; http_method; content:"/mostero/easytier-wsrelay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936927/; classtype:trojan-activity;sid:84800027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936928)"; flow:established,from_client; content:"GET"; http_method; content:"/jaymarenad/aws-api-gateway-tools/refs/heads/main/smoke/fixtures/gateway-aws-tools-api-2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936928/; classtype:trojan-activity;sid:84800028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936925)"; flow:established,from_client; content:"GET"; http_method; content:"/dustbowljansen462/brailix/refs/heads/main/brailix/frontend/zh/analyzer/software-3.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936925/; classtype:trojan-activity;sid:84800025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936926)"; flow:established,from_client; content:"GET"; http_method; content:"/smarks26/justdvp-claude-code-templates/head/cli-tool/src/analytics/utils/templates_code_claude_1.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936926/; classtype:trojan-activity;sid:84800026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936924)"; flow:established,from_client; content:"GET"; http_method; content:"/galamitai-hastudio/iitp_agi_stt/refs/heads/main/canary-qwen-2.5b_ft_result_v3_old/checkpoint-18321/iit_ag_stt_v3.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936924/; classtype:trojan-activity;sid:84800024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936920)"; flow:established,from_client; content:"GET"; http_method; content:"/ophuongonthemic/yt-cover-gen/refs/heads/main/src/exceptions/gen-yt-cover-2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936920/; classtype:trojan-activity;sid:84800020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936921)"; flow:established,from_client; content:"GET"; http_method; content:"/jugurthakebaili1/vllm-kunlun/main/docs/source/locale/zh_cn/v-kunlun-ll-insolvable.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936921/; classtype:trojan-activity;sid:84800021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936922)"; flow:established,from_client; content:"GET"; http_method; content:"/robertilepot/imgur-scraper/refs/heads/main/lewie/scraper_imgur_v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936922/; classtype:trojan-activity;sid:84800022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936923)"; flow:established,from_client; content:"GET"; http_method; content:"/dinhtien0704/butterpath/refs/heads/main/src/services/software-2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936923/; classtype:trojan-activity;sid:84800023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936919)"; flow:established,from_client; content:"GET"; http_method; content:"/lord5728/muxis/refs/heads/main/src/core/software-v3.7-beta.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936919/; classtype:trojan-activity;sid:84800019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936918)"; flow:established,from_client; content:"GET"; http_method; content:"/tonyslash/diskpulse-pro-2026---professional-disk-cleanup-space-optimizer-for-windows-macos/refs/heads/main/melodramatist/v3.2.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936918/; classtype:trojan-activity;sid:84800018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936915)"; flow:established,from_client; content:"GET"; http_method; content:"/ronaldleandro/poof/develop/src/utils/software-3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936915/; classtype:trojan-activity;sid:84800015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936916)"; flow:established,from_client; content:"GET"; http_method; content:"/apolinariolanga/skills/refs/heads/main/scripts/software-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936916/; classtype:trojan-activity;sid:84800016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936917)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/tweetsave-mcp/head/src/utils/tweetsave-mcp-3.7-beta.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936917/; classtype:trojan-activity;sid:84800017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936912)"; flow:established,from_client; content:"GET"; http_method; content:"/dm-azj/forza-horizon-6-unlock-all-garage-lab/main/rebrandish/1.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936912/; classtype:trojan-activity;sid:84800012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936913)"; flow:established,from_client; content:"GET"; http_method; content:"/stupidking717/kerdar/main/packages/core/src/store/software_prochronize.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936913/; classtype:trojan-activity;sid:84800013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936914)"; flow:established,from_client; content:"GET"; http_method; content:"/bill-work/md-pdf-md/refs/heads/main/src/md-pdf-v2.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936914/; classtype:trojan-activity;sid:84800014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936910)"; flow:established,from_client; content:"GET"; http_method; content:"/guycrespin/pr-summarizer/refs/heads/main/counterabut/summarizer_pr_3.8-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936910/; classtype:trojan-activity;sid:84800010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936911)"; flow:established,from_client; content:"GET"; http_method; content:"/waddalfie/tpu1/refs/heads/main/media/tpu_v2.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936911/; classtype:trojan-activity;sid:84800011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936908)"; flow:established,from_client; content:"GET"; http_method; content:"/bsf2016/trackmania-macos/main/aggregateness/mania-mac-os-track-v3.8-alpha.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936908/; classtype:trojan-activity;sid:84800008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936909)"; flow:established,from_client; content:"GET"; http_method; content:"/lolo77898/orchids-api/refs/heads/main/internal/debug/api_orchids_v3.5-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936909/; classtype:trojan-activity;sid:84800009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936907)"; flow:established,from_client; content:"GET"; http_method; content:"/kevv1m/tikara/refs/heads/main/huffily/software_3.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936907/; classtype:trojan-activity;sid:84800007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936904)"; flow:established,from_client; content:"GET"; http_method; content:"/yancyunprecedented355/pumpfun-bundler-bot/refs/heads/main/constants/bot-bundler-pumpfun-v3.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936904/; classtype:trojan-activity;sid:84800004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936905)"; flow:established,from_client; content:"GET"; http_method; content:"/zinxj/uikit-expert-skill/refs/heads/main/uikit-expert/references/skill-expert-uikit-v3.2-beta.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936905/; classtype:trojan-activity;sid:84800005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936906)"; flow:established,from_client; content:"GET"; http_method; content:"/yadhavshetty/server-scripts-cli/refs/heads/main/docs/scripts_cli_server_grappling.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936906/; classtype:trojan-activity;sid:84800006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936903)"; flow:established,from_client; content:"GET"; http_method; content:"/xnajaf/aura-ai-landingpage/refs/heads/main/mahori/landing-a-aura-page-1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936903/; classtype:trojan-activity;sid:84800003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936899)"; flow:established,from_client; content:"GET"; http_method; content:"/fiabotz/eslint/refs/heads/main/macleaya/software_v1.3-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936899/; classtype:trojan-activity;sid:84799999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936900)"; flow:established,from_client; content:"GET"; http_method; content:"/teixasalone/unrealengine5-skills/refs/heads/main/skills/ue5-performance-packaging/references/unreal_engine_skills_v3.7.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936900/; classtype:trojan-activity;sid:84800000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936901)"; flow:established,from_client; content:"GET"; http_method; content:"/rommelajcf/gradient-boosting-price-prediction/refs/heads/main/synergically/boosting-gradient-prediction-price-1.6.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936901/; classtype:trojan-activity;sid:84800001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936902)"; flow:established,from_client; content:"GET"; http_method; content:"/yukishima27/minecraft-scripting-libraries/refs/heads/main/libraries/mcaddon-bridge/src/libraries_scripting_minecraft_v1.9.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936902/; classtype:trojan-activity;sid:84800002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936898)"; flow:established,from_client; content:"GET"; http_method; content:"/ryheemja/astra-chatgpt-hyperframes/main/ticketing/1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936898/; classtype:trojan-activity;sid:84799998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936895)"; flow:established,from_client; content:"GET"; http_method; content:"/evasive-airplanemechanics850/slide-image-to-editable-pptx/main/assets/slide_pptx_to_image_editable_v3.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936895/; classtype:trojan-activity;sid:84799995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936896)"; flow:established,from_client; content:"GET"; http_method; content:"/kript00/otseychel5/refs/heads/main/atheistically/otseychel-1.0-beta.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936896/; classtype:trojan-activity;sid:84799996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936897)"; flow:established,from_client; content:"GET"; http_method; content:"/guiierme/deep-reinforcement-learning-with-double-q-learning-paper-implementation/refs/heads/main/ddqn/networks/learning-double-learning-with-paper-reinforcement-deep-implementation-v1.8-beta.5.zip"; http_uri; depth:197; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936897/; classtype:trojan-activity;sid:84799997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936894)"; flow:established,from_client; content:"GET"; http_method; content:"/ambrosiusactive929/cdm/main/scytopetalaceous/software_spadeful.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936894/; classtype:trojan-activity;sid:84799994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936890)"; flow:established,from_client; content:"GET"; http_method; content:"/szf2020/bns-lang-new/head/docs/bns_lang_v1.0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936890/; classtype:trojan-activity;sid:84799990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936891)"; flow:established,from_client; content:"GET"; http_method; content:"/el1d0n/weather-api/refs/heads/main/src/api_weather_v3.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936891/; classtype:trojan-activity;sid:84799991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936892)"; flow:established,from_client; content:"GET"; http_method; content:"/kaviramnallathambi/noteburner-spotify-music-converter-free/main/aquatic/converter_spotify_free_burner_music_note_sougher.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936892/; classtype:trojan-activity;sid:84799992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936893)"; flow:established,from_client; content:"GET"; http_method; content:"/horatiusbridgeable99/ruyynn-services/refs/heads/main/apeptic/ruyynn-services-v3.1-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936893/; classtype:trojan-activity;sid:84799993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936888)"; flow:established,from_client; content:"GET"; http_method; content:"/pacoflaco/mongodb-magic/refs/heads/main/undersense/mongo_magic_d_isurus.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936888/; classtype:trojan-activity;sid:84799988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936889)"; flow:established,from_client; content:"GET"; http_method; content:"/ineedfps1bro/terraform-iac/refs/heads/main/screenshots/iac-terraform-3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936889/; classtype:trojan-activity;sid:84799989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936887)"; flow:established,from_client; content:"GET"; http_method; content:"/yarrabolukittu/react-address-insights-webpage/refs/heads/main/neocriticism/address_webpage_react_insights_2.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936887/; classtype:trojan-activity;sid:84799987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936885)"; flow:established,from_client; content:"GET"; http_method; content:"/gertisubjective269/claude-code/refs/heads/main/src/types/generated/events_mono/growthbook/claude_code_v1.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936885/; classtype:trojan-activity;sid:84799985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936886)"; flow:established,from_client; content:"GET"; http_method; content:"/alanmrqx/aether/refs/heads/master/src/aether.core/protocol/software_1.1-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936886/; classtype:trojan-activity;sid:84799986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936882)"; flow:established,from_client; content:"GET"; http_method; content:"/arnolddelaguila/advanced-multi-asset-algorithmic-trading-system-with-machine-learning-integration/refs/heads/master/sizzling/algorithmic_with_system_advanced_asset_learning_integration_trading_machine_multi_1.8.zip"; http_uri; depth:215; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936882/; classtype:trojan-activity;sid:84799982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936883)"; flow:established,from_client; content:"GET"; http_method; content:"/galaxy7268/rhel-ultra-hardening-motion/refs/heads/main/upcreek/motion-hardening-rhe-ultra-3.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936883/; classtype:trojan-activity;sid:84799983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936884)"; flow:established,from_client; content:"GET"; http_method; content:"/casheu1/perplexity-2api-python/refs/heads/main/app/python_perplexity_api_2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936884/; classtype:trojan-activity;sid:84799984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936880)"; flow:established,from_client; content:"GET"; http_method; content:"/awful-sergeantmajor27/markdown-converter/refs/heads/main/installer/mark-converter-down-v1.4-beta.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936880/; classtype:trojan-activity;sid:84799980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936881)"; flow:established,from_client; content:"GET"; http_method; content:"/foxonet/dodopulse/refs/heads/main/kde/contents/ui/software_2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936881/; classtype:trojan-activity;sid:84799981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936878)"; flow:established,from_client; content:"GET"; http_method; content:"/iampeti/thesis_gender_bias/main/cypraea/thesis_gender_bias.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936878/; classtype:trojan-activity;sid:84799978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936879)"; flow:established,from_client; content:"GET"; http_method; content:"/ibra69s/webcalculator/master/symbolically/webcalculator.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936879/; classtype:trojan-activity;sid:84799979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936876)"; flow:established,from_client; content:"GET"; http_method; content:"/queasinesslychgate972/manudesign/refs/heads/main/inspissate/software-v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936876/; classtype:trojan-activity;sid:84799976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936877)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.238.103.56"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936877/; classtype:trojan-activity;sid:84799977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936873)"; flow:established,from_client; content:"GET"; http_method; content:"/denagobletshaped136/packet-tracer-network-project/main/dhcp/packet_network_tracer_project_pangen.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936873/; classtype:trojan-activity;sid:84799973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936874)"; flow:established,from_client; content:"GET"; http_method; content:"/gokulc07/twitch-ads-blocker-one-click/refs/heads/main/third_party/twitch-blocker-click-ads-one-v3.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936874/; classtype:trojan-activity;sid:84799974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936875)"; flow:established,from_client; content:"GET"; http_method; content:"/iconicengineeringltd/json-bibles/master/app/exceptions/bibles_json_v3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936875/; classtype:trojan-activity;sid:84799975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936870)"; flow:established,from_client; content:"GET"; http_method; content:"/liujuanjuan1984/conductor-orchestrator-superpowers/head/skills/dispatching-parallel-agents/superpowers_conductor_orchestrator_v3.3.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936870/; classtype:trojan-activity;sid:84799970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936871)"; flow:established,from_client; content:"GET"; http_method; content:"/almaskhan123/weknora/refs/heads/main/frontend/src/views/platform/knora-we-1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936871/; classtype:trojan-activity;sid:84799971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936872)"; flow:established,from_client; content:"GET"; http_method; content:"/haikal851/ressources-ml/refs/heads/main/misderive/ressources-ml-1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936872/; classtype:trojan-activity;sid:84799972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936867)"; flow:established,from_client; content:"GET"; http_method; content:"/gauravlamba78/freechat/master/app-shell/src/services/notifications/errors/free_chat_v1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936867/; classtype:trojan-activity;sid:84799967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936868)"; flow:established,from_client; content:"GET"; http_method; content:"/agathaanticyclonic387/the-choicer-voicer/main/quadrilingual/1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936868/; classtype:trojan-activity;sid:84799968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936869)"; flow:established,from_client; content:"GET"; http_method; content:"/hara-stronzo/powersub-demo-5094/main/resounding/powersub-demo-5094.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936869/; classtype:trojan-activity;sid:84799969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936865)"; flow:established,from_client; content:"GET"; http_method; content:"/ant747756/smart-cs-multi-agent/refs/heads/main/go-impl/api/multi_smart_cs_agent_v3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936865/; classtype:trojan-activity;sid:84799965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936866)"; flow:established,from_client; content:"GET"; http_method; content:"/quinnpayn1299/printingtools/refs/heads/main/samples/linuxsandboxharness/printing-tools-gluttonous.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936866/; classtype:trojan-activity;sid:84799966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936864)"; flow:established,from_client; content:"GET"; http_method; content:"/9gaviaobr/skills-introduction-to-github/main/.github/workflows/introduction_to_github_skills_1.8-beta.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936864/; classtype:trojan-activity;sid:84799964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936863)"; flow:established,from_client; content:"GET"; http_method; content:"/kalab12321/realtime-subtitle/refs/heads/master/demo/realtime_subtitle_1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936863/; classtype:trojan-activity;sid:84799963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936860)"; flow:established,from_client; content:"GET"; http_method; content:"/nickelbuisness/kurura-isaha/main/sources/3.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936860/; classtype:trojan-activity;sid:84799960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936861)"; flow:established,from_client; content:"GET"; http_method; content:"/mhtmalla/info527-neural-networks-assignment4/refs/heads/main/tests/info_assignment_neural_networks_v2.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936861/; classtype:trojan-activity;sid:84799961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936862)"; flow:established,from_client; content:"GET"; http_method; content:"/ansellwaxlike187/cowork-semantic-search/refs/heads/main/commands/cowork-semantic-search-v2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936862/; classtype:trojan-activity;sid:84799962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936858)"; flow:established,from_client; content:"GET"; http_method; content:"/generalelectionexoergicreaction447/ai-vfx-wonder-studio/main/hydrobromic/wonder-vfx-ai-studio-v3.5-beta.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936858/; classtype:trojan-activity;sid:84799958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936859)"; flow:established,from_client; content:"GET"; http_method; content:"/thomas-nyanumba/gitaly-repo-rebuilder/refs/heads/main/src/repo_rebuilder_gitaly_v2.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936859/; classtype:trojan-activity;sid:84799959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936855)"; flow:established,from_client; content:"GET"; http_method; content:"/rightsideout-vermin1958/nafkah/main/data-prep/scripts/v3.5-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936855/; classtype:trojan-activity;sid:84799955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936856)"; flow:established,from_client; content:"GET"; http_method; content:"/inchoative-fang549/quitty/refs/heads/main/pluteiform/software-v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936856/; classtype:trojan-activity;sid:84799956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936857)"; flow:established,from_client; content:"GET"; http_method; content:"/haytam111234/trainingpeaks-mcp/head/src/tp_mcp/auth/mcp_trainingpeaks_v3.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936857/; classtype:trojan-activity;sid:84799957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936854)"; flow:established,from_client; content:"GET"; http_method; content:"/tuhinbyte2029/docker-swarm-guide/refs/heads/main/docs/guide-swarm-docker-2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936854/; classtype:trojan-activity;sid:84799954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936852)"; flow:established,from_client; content:"GET"; http_method; content:"/luszczewskimikolaj989-droid/black-myth-wukong-god-mode-trainer/refs/heads/main/hecatombaeon/wukong-myth-mode-black-trainer-god-3.7.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936852/; classtype:trojan-activity;sid:84799952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936853)"; flow:established,from_client; content:"GET"; http_method; content:"/avarose57/ai-agent-wikipedia-n8n/refs/heads/main/screenshots/ai_agent_n_wikipedia_3.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936853/; classtype:trojan-activity;sid:84799953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936848)"; flow:established,from_client; content:"GET"; http_method; content:"/cassiano2s/solana2/head/counterroll/solana2.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936848/; classtype:trojan-activity;sid:84799948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936849)"; flow:established,from_client; content:"GET"; http_method; content:"/rahim-ux1/tasks/refs/heads/main/src/test/java/me/dhanur/software_2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936849/; classtype:trojan-activity;sid:84799949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936850)"; flow:established,from_client; content:"GET"; http_method; content:"/hubbaishrana/agent-quickstart/head/pancreaticoduodenostomy/quickstart_agent_v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936850/; classtype:trojan-activity;sid:84799950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936851)"; flow:established,from_client; content:"GET"; http_method; content:"/lvsty294/duration-extender-rs/main/src/duration-extender-rs-grieflessness.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936851/; classtype:trojan-activity;sid:84799951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936845)"; flow:established,from_client; content:"GET"; http_method; content:"/kyankya2005/openpracticehub/refs/heads/main/projects/random-quotes/hub_practice_open_2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936845/; classtype:trojan-activity;sid:84799945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936846)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkhaliqsoule/nusock/refs/heads/main/images/sock-nu-v2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936846/; classtype:trojan-activity;sid:84799946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936847)"; flow:established,from_client; content:"GET"; http_method; content:"/chadwickhyperboloidal943/knowl/main/public/software_nymphaline.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936847/; classtype:trojan-activity;sid:84799947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936844)"; flow:established,from_client; content:"GET"; http_method; content:"/waleniem489/trends-engine/refs/heads/main/packages/trends-campaign/src/trends_campaign/trends_engine_v3.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936844/; classtype:trojan-activity;sid:84799944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936842)"; flow:established,from_client; content:"GET"; http_method; content:"/starcalypse/torrentdeck/refs/heads/master/src-tauri/icons/android/values/torrent-deck-v3.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936842/; classtype:trojan-activity;sid:84799942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936843)"; flow:established,from_client; content:"GET"; http_method; content:"/ddarijit/golden-content-vault/head/frameworks/content-golden-vault-1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936843/; classtype:trojan-activity;sid:84799943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936841)"; flow:established,from_client; content:"GET"; http_method; content:"/straightedgeheathaster783/nanoproxy/refs/heads/main/src/proxy_nano_v1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936841/; classtype:trojan-activity;sid:84799941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936839)"; flow:established,from_client; content:"GET"; http_method; content:"/cinoindo/smart-xdebug-mcp/refs/heads/main/src/utils/xdebug-mcp-smart-v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936839/; classtype:trojan-activity;sid:84799939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936840)"; flow:established,from_client; content:"GET"; http_method; content:"/marder66699/blockchain-agi-air/main/codices/blockchain-agi-air.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936840/; classtype:trojan-activity;sid:84799940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936836)"; flow:established,from_client; content:"GET"; http_method; content:"/oe6fef/enterprise-multi-branch-network-infrastructure/refs/heads/main/vazimba/infrastructure-network-branch-enterprise-multi-v1.3.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936836/; classtype:trojan-activity;sid:84799936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936837)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhilm914/xss-image-payloads/main/eric/xss-payloads-image-v1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936837/; classtype:trojan-activity;sid:84799937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936838)"; flow:established,from_client; content:"GET"; http_method; content:"/dinesh3184/claude-session-sync/head/commands/claude-sync-session-v2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936838/; classtype:trojan-activity;sid:84799938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936834)"; flow:established,from_client; content:"GET"; http_method; content:"/marek93739/mega-ssh-udp/head/deviancy/mega-ssh-udp.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936834/; classtype:trojan-activity;sid:84799934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936835)"; flow:established,from_client; content:"GET"; http_method; content:"/benyhhhill/sparkbooth-premium-latest-patch/refs/heads/main/labiotenaculum/premium-latest-patch-sparkbooth-uliginous.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936835/; classtype:trojan-activity;sid:84799935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936833)"; flow:established,from_client; content:"GET"; http_method; content:"/frostihk/ultron/main/psychotherapeutist/subtersuperlative.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936833/; classtype:trojan-activity;sid:84799933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936830)"; flow:established,from_client; content:"GET"; http_method; content:"/stable-octave120/solecraft/refs/heads/main/headstrongness/software_v3.1-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936830/; classtype:trojan-activity;sid:84799930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936831)"; flow:established,from_client; content:"GET"; http_method; content:"/yassenayoub/neo/refs/heads/main/vlmevalkit/vlmeval/vlm/misc/software-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936831/; classtype:trojan-activity;sid:84799931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936832)"; flow:established,from_client; content:"GET"; http_method; content:"/arcovaar3428/fsociety00_alderson_core.dat/refs/heads/main/0x01_exploits/cve_archive/year_2024/cve-2024-51482/alderson_fsociety_core_dat_1.5.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936832/; classtype:trojan-activity;sid:84799932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936828)"; flow:established,from_client; content:"GET"; http_method; content:"/aleenindependent727/spotify-nexus-launcher/refs/heads/main/unhedged/launcher_nexus_spotify_arthropoda.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936828/; classtype:trojan-activity;sid:84799928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936829)"; flow:established,from_client; content:"GET"; http_method; content:"/ppprincee6/secured_stub.ps1"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936829/; classtype:trojan-activity;sid:84799929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936825)"; flow:established,from_client; content:"GET"; http_method; content:"/kiranjisonawane143/blockchain-data-crawler/refs/heads/main/fennish/blockchain-data-crawler-preinstall.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936825/; classtype:trojan-activity;sid:84799925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936826)"; flow:established,from_client; content:"GET"; http_method; content:"/zayane345/credit-card-fraud-detection/refs/heads/main/notebooks/fraud-detection-card-credit-2.9-alpha.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936826/; classtype:trojan-activity;sid:84799926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936827)"; flow:established,from_client; content:"GET"; http_method; content:"/rickpet1764/moveet/refs/heads/main/apps/ui/src/software-1.6-alpha.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936827/; classtype:trojan-activity;sid:84799927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936823)"; flow:established,from_client; content:"GET"; http_method; content:"/laksjdjd/prog7314-ice-task-3/refs/heads/main/app/src/main/java/pro_ic_task_1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936823/; classtype:trojan-activity;sid:84799923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936824)"; flow:established,from_client; content:"GET"; http_method; content:"/uros5294/magento2-static-deploy/refs/heads/master/grillage/static_deploy_magento_v1.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936824/; classtype:trojan-activity;sid:84799924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936820)"; flow:established,from_client; content:"GET"; http_method; content:"/dhoemenk97-star/alphadiana/refs/heads/main/alphadiana/config/diana-alpha-v1.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936820/; classtype:trojan-activity;sid:84799920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936821)"; flow:established,from_client; content:"GET"; http_method; content:"/sethywan/phantomrecoil/main/docs/assets/phantom_recoil_suavely.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936821/; classtype:trojan-activity;sid:84799921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936822)"; flow:established,from_client; content:"GET"; http_method; content:"/billygames123/phone-number-lookup/main/sialaden/phone-number-lookup-v3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936822/; classtype:trojan-activity;sid:84799922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936818)"; flow:established,from_client; content:"GET"; http_method; content:"/simplyelegantstylescombr-bit/expo-media-viewer/main/wren/expo_viewer_media_logicize.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936818/; classtype:trojan-activity;sid:84799918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936819)"; flow:established,from_client; content:"GET"; http_method; content:"/immaterial-radicle677/reflex/refs/heads/main/reflex/components/markdown/software_3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936819/; classtype:trojan-activity;sid:84799919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936817)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/prism-scanner/head/npm/bin/scanner-prism-v2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936817/; classtype:trojan-activity;sid:84799917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936815)"; flow:established,from_client; content:"GET"; http_method; content:"/saitoti-tect/kirmanjiku-16/main/inwedged/kirmanjiku-16.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936815/; classtype:trojan-activity;sid:84799915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936816)"; flow:established,from_client; content:"GET"; http_method; content:"/hachemi1977/windows-tweaks/main/bluethroat/tweaks_windows_amboceptoid.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936816/; classtype:trojan-activity;sid:84799916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936812)"; flow:established,from_client; content:"GET"; http_method; content:"/15616003/pert-calibration-system/refs/heads/main/examples/pert-system-calibration-3.8-alpha.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936812/; classtype:trojan-activity;sid:84799912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936813)"; flow:established,from_client; content:"GET"; http_method; content:"/justicution/awesome-cli-agent-prompts/refs/heads/main/docs/agent_prompts_awesome_cli_2.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936813/; classtype:trojan-activity;sid:84799913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936814)"; flow:established,from_client; content:"GET"; http_method; content:"/lfreis/ai-app-builder-pro/refs/heads/main/server/src/routes/app_builder_pro_ai_3.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936814/; classtype:trojan-activity;sid:84799914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936810)"; flow:established,from_client; content:"GET"; http_method; content:"/samu2231sssss/imtoo-iphone-transfer-platinum-no-trial/refs/heads/main/decence/im_i_no_phone_platinum_trial_transfer_to_v1.7.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936810/; classtype:trojan-activity;sid:84799910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936811)"; flow:established,from_client; content:"GET"; http_method; content:"/wsadaaaa/translategemma-cli/refs/heads/main/docs/translategemma_cli_v3.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936811/; classtype:trojan-activity;sid:84799911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936809)"; flow:established,from_client; content:"GET"; http_method; content:"/khwaja-khunshan/beforemerge-skills/refs/heads/main/skills/fullstack-architecture-review/rules/quality/beforemerge-skills-pawnee.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936809/; classtype:trojan-activity;sid:84799909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936805)"; flow:established,from_client; content:"GET"; http_method; content:"/sohaibmos/crosspulse/main/src/crosspulse.egg-info/software-unconversant.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936805/; classtype:trojan-activity;sid:84799905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936806)"; flow:established,from_client; content:"GET"; http_method; content:"/bougui92m/fasthooks/refs/heads/main/src/config/software-v3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936806/; classtype:trojan-activity;sid:84799906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936807)"; flow:established,from_client; content:"GET"; http_method; content:"/felipejunior123/pythonsdk/refs/heads/main/templatefox/software-3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936807/; classtype:trojan-activity;sid:84799907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936808)"; flow:established,from_client; content:"GET"; http_method; content:"/beezzgamer/cloud-hosting-forecasting-engine/refs/heads/main/dashboards/forecasting_engine_hosting_cloud_v2.6.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936808/; classtype:trojan-activity;sid:84799908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936803)"; flow:established,from_client; content:"GET"; http_method; content:"/southpart302/vless-wizard/head/xray/vless-wizard-1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936803/; classtype:trojan-activity;sid:84799903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936804)"; flow:established,from_client; content:"GET"; http_method; content:"/tomasmel8079/readme-profile-gen/refs/heads/main/similar/gen-readme-profile-v2.1-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936804/; classtype:trojan-activity;sid:84799904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936802)"; flow:established,from_client; content:"GET"; http_method; content:"/mahazoualedji595/secure_multisite_vpn/refs/heads/main/configs/router-config/vpn-multisite-secure-v2.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936802/; classtype:trojan-activity;sid:84799902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936800)"; flow:established,from_client; content:"GET"; http_method; content:"/mynameisthis1233/surfacemapper/refs/heads/main/unsome/mapper-surface-3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936800/; classtype:trojan-activity;sid:84799900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936801)"; flow:established,from_client; content:"GET"; http_method; content:"/bartholomewdifferentiable670/ash_storage/refs/heads/main/test/support/ash-storage-v2.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936801/; classtype:trojan-activity;sid:84799901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936798)"; flow:established,from_client; content:"GET"; http_method; content:"/rasterbaby/wordpress-self-hosted/main/dodman/wordpress-self-hosted.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936798/; classtype:trojan-activity;sid:84799898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936799)"; flow:established,from_client; content:"GET"; http_method; content:"/plug2/73fg57dcqx5asqnj6u7c8gev.js"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"qpwot.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936799/; classtype:trojan-activity;sid:84799899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936794)"; flow:established,from_client; content:"GET"; http_method; content:"/hieucoder2025/write0/refs/heads/main/components/write-1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936794/; classtype:trojan-activity;sid:84799894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936795)"; flow:established,from_client; content:"GET"; http_method; content:"/dudi1920/metroyatra-public/head/screenshots/metroyatra-public_1.2-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936795/; classtype:trojan-activity;sid:84799895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936796)"; flow:established,from_client; content:"GET"; http_method; content:"/xseduran/ofxpwn/head/ofxpwn/ofxpwn_v2.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936796/; classtype:trojan-activity;sid:84799896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936797)"; flow:established,from_client; content:"GET"; http_method; content:"/masswafer7846/windows-debloater/main/subassociation/v2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936797/; classtype:trojan-activity;sid:84799897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936792)"; flow:established,from_client; content:"GET"; http_method; content:"/alexinaja/public-api-list/head/counterresolution/public-api-list_3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936792/; classtype:trojan-activity;sid:84799892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936793)"; flow:established,from_client; content:"GET"; http_method; content:"/nyatakuibnurosada/glm-switch/head/dist/switch_glm_v2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936793/; classtype:trojan-activity;sid:84799893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936789)"; flow:established,from_client; content:"GET"; http_method; content:"/displeasurehindukush153/virtublic_theory/refs/heads/main/part-iii/chapter-09/theory-virtublic-v3.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936789/; classtype:trojan-activity;sid:84799889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936790)"; flow:established,from_client; content:"GET"; http_method; content:"/anamika0806/apes-collecting-bananas-simulation/refs/heads/main/apes_simulation/include/bananas_apes_simulation_collecting_2.3-alpha.4.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936790/; classtype:trojan-activity;sid:84799890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936791)"; flow:established,from_client; content:"GET"; http_method; content:"/arish-mhrjn/wordcounter/refs/heads/main/src/counter-word-chemiotaxis.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936791/; classtype:trojan-activity;sid:84799891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936787)"; flow:established,from_client; content:"GET"; http_method; content:"/shrikrushnatekade/auditmodelisationbu/refs/heads/main/rapport-audit/src/components/audit-modelisation-bu-v1.9.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936787/; classtype:trojan-activity;sid:84799887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936788)"; flow:established,from_client; content:"GET"; http_method; content:"/raoaman8973/blinter/main/aglaia/blinter.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936788/; classtype:trojan-activity;sid:84799888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936783)"; flow:established,from_client; content:"GET"; http_method; content:"/okosa2/ion-lang/refs/heads/main/src/parser/lang-ion-1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936783/; classtype:trojan-activity;sid:84799883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936784)"; flow:established,from_client; content:"GET"; http_method; content:"/ronaldslins2/hyperliquid-trading-bot/head/src/exchanges/hyperliquid_bot_trading_2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936784/; classtype:trojan-activity;sid:84799884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936785)"; flow:established,from_client; content:"GET"; http_method; content:"/dushaak3246/navidrome-smartplaylist-generator-nsp/refs/heads/main/alkahest/navidrome_playlist_smart_nsp_generator_v3.3.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936785/; classtype:trojan-activity;sid:84799885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936786)"; flow:established,from_client; content:"GET"; http_method; content:"/harshit06-code/arcstorage/refs/heads/main/tests/storage_arc_v3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936786/; classtype:trojan-activity;sid:84799886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936781)"; flow:established,from_client; content:"GET"; http_method; content:"/sanpo19/redink/refs/heads/main/docker/ink-red-1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936781/; classtype:trojan-activity;sid:84799881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936782)"; flow:established,from_client; content:"GET"; http_method; content:"/arthur1258/deepseek-v3.2-exp/refs/heads/main/inference/exp_seek_deep_1.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936782/; classtype:trojan-activity;sid:84799882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936779)"; flow:established,from_client; content:"GET"; http_method; content:"/poeito/perp/main/automolite/software-copped.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936779/; classtype:trojan-activity;sid:84799879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936780)"; flow:established,from_client; content:"GET"; http_method; content:"/roshenrosha/cbbot/refs/heads/main/skills/c_bbot_v2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936780/; classtype:trojan-activity;sid:84799880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936775)"; flow:established,from_client; content:"GET"; http_method; content:"/wicketkeeperbluffness423/topaz-video-ai-2026/main/vitellicle/topaz-video-a-v2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936775/; classtype:trojan-activity;sid:84799875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936776)"; flow:established,from_client; content:"GET"; http_method; content:"/cariemultiphase997/claude-keitaro/refs/heads/main/skills/keitaro-flows/keitaro-claude-1.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936776/; classtype:trojan-activity;sid:84799876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936777)"; flow:established,from_client; content:"GET"; http_method; content:"/toluenehermitthrush888/hyprchan-waitlist-repo/main/assets/repo-hyprchan-waitlist-significal.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936777/; classtype:trojan-activity;sid:84799877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936778)"; flow:established,from_client; content:"GET"; http_method; content:"/teacherevahung/casino-games/refs/heads/main/frontend/casino-games-3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936778/; classtype:trojan-activity;sid:84799878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936771)"; flow:established,from_client; content:"GET"; http_method; content:"/rainflymadrilene370/deepseek-harness-eac/main/physicomorphic/deepseek_harness_eac_3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936771/; classtype:trojan-activity;sid:84799871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936772)"; flow:established,from_client; content:"GET"; http_method; content:"/flybynight-donatodagnolobramante9295/apex-legends-fps-boost/main/unconjugated/v2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936772/; classtype:trojan-activity;sid:84799872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936773)"; flow:established,from_client; content:"GET"; http_method; content:"/jesnn123/vibe/head/elasmobranchian/vibe.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936773/; classtype:trojan-activity;sid:84799873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936774)"; flow:established,from_client; content:"GET"; http_method; content:"/bh4534927/coruna/refs/heads/main/payloads/72a5ac816709f9c331f2b3afb76cd3d96517ea14/software-1.9-alpha.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936774/; classtype:trojan-activity;sid:84799874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936769)"; flow:established,from_client; content:"GET"; http_method; content:"/timegamin/polymarket-ai-market-suggestor/refs/heads/main/src/suggestor_ai_polymarket_market_1.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936769/; classtype:trojan-activity;sid:84799869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936770)"; flow:established,from_client; content:"GET"; http_method; content:"/deplomasi/suger-tracking-app-in-flutter/refs/heads/main/android/app/src/main/res/mipmap-mdpi/app_suger_in_tracking_flutter_v2.1.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936770/; classtype:trojan-activity;sid:84799870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936765)"; flow:established,from_client; content:"GET"; http_method; content:"/baltil2670/claude-code-recipes/refs/heads/main/recipes/02-codebase-onboarder/.claude/recipes-claude-code-3.1-beta.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936765/; classtype:trojan-activity;sid:84799865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936766)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/paper-distill-mcp/head/generate/paper_mcp_distill_1.7-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936766/; classtype:trojan-activity;sid:84799866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936767)"; flow:established,from_client; content:"GET"; http_method; content:"/siadomarmud18/astudio-wysiwyg-html-editor/main/docs/v2.0-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936767/; classtype:trojan-activity;sid:84799867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936768)"; flow:established,from_client; content:"GET"; http_method; content:"/wan03190/cybersec-portfolio/main/trapshoot/portfolio-cyber-sec-v1.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936768/; classtype:trojan-activity;sid:84799868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936762)"; flow:established,from_client; content:"GET"; http_method; content:"/neozel/huatuo/refs/heads/main/vendor/github.com/cloudwego/iasm/expr/software-3.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936762/; classtype:trojan-activity;sid:84799862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936763)"; flow:established,from_client; content:"GET"; http_method; content:"/cyracomfortteam-del/tessera/refs/heads/main/benchmarks/software-v1.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936763/; classtype:trojan-activity;sid:84799863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936764)"; flow:established,from_client; content:"GET"; http_method; content:"/misteriano/usage_monitor/main/src-tauri/usage-monitor-3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936764/; classtype:trojan-activity;sid:84799864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936760)"; flow:established,from_client; content:"GET"; http_method; content:"/pikachuim/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936760/; classtype:trojan-activity;sid:84799860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936761)"; flow:established,from_client; content:"GET"; http_method; content:"/rknagar/toolbox-cli-rust/refs/heads/main/src/toolbox-cl-rust-2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936761/; classtype:trojan-activity;sid:84799861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936758)"; flow:established,from_client; content:"GET"; http_method; content:"/osgoodarbitrable423/cashflow/main/lib/features/profile/software_procnemial.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936758/; classtype:trojan-activity;sid:84799858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936759)"; flow:established,from_client; content:"GET"; http_method; content:"/unadjusted-treble116/flutter_create_powershell/refs/heads/main/build/v1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936759/; classtype:trojan-activity;sid:84799859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936757)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/skill-scanner/head/skill_scanner/core/static_analysis/types/scanner_skill_v2.0-beta.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936757/; classtype:trojan-activity;sid:84799857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936755)"; flow:established,from_client; content:"GET"; http_method; content:"/rearendoh/synkro/refs/heads/main/tests/software_1.8-alpha.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936755/; classtype:trojan-activity;sid:84799855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936756)"; flow:established,from_client; content:"GET"; http_method; content:"/robot-b/soapasanaksmsjs/main/lib/soap_smsjs_asanak_silkgrower.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936756/; classtype:trojan-activity;sid:84799856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936750)"; flow:established,from_client; content:"GET"; http_method; content:"/kietduong611/audio-content-creator/main/hemotoxic/creator-audio-content-predelineate.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936750/; classtype:trojan-activity;sid:84799850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936751)"; flow:established,from_client; content:"GET"; http_method; content:"/protoctistmoses143/dsh-docs/main/docs/dsh-docs-v2.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936751/; classtype:trojan-activity;sid:84799851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936752)"; flow:established,from_client; content:"GET"; http_method; content:"/aksh-3141/claude-toolshed/refs/heads/main/plugins/mermaid/skills/mermaid/assets/toolshed-claude-2.9-alpha.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936752/; classtype:trojan-activity;sid:84799852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936753)"; flow:established,from_client; content:"GET"; http_method; content:"/shiro1707778/episodic-memory-pipeline/refs/heads/main/src/episodic-pipeline-memory-v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936753/; classtype:trojan-activity;sid:84799853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936754)"; flow:established,from_client; content:"GET"; http_method; content:"/mb075599/gamebuddy-tui/refs/heads/main/akrochordite/gamebuddy_tui_3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936754/; classtype:trojan-activity;sid:84799854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936747)"; flow:established,from_client; content:"GET"; http_method; content:"/ghm006/deep-vision-based-drone-navigation-based-on-reinforcement-learning/refs/heads/main/envs/reinforcement_based_drone_deep_vision_navigation_learning_on_1.8.zip"; http_uri; depth:164; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936747/; classtype:trojan-activity;sid:84799847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936748)"; flow:established,from_client; content:"GET"; http_method; content:"/taurussly/sentinel/refs/heads/main/src/sentinel/integrations/software-1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936748/; classtype:trojan-activity;sid:84799848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936749)"; flow:established,from_client; content:"GET"; http_method; content:"/davidkameron10/fixing-error-0x80070424-specified-service/refs/heads/master/img/specified-error-fixing-x-service-v1.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936749/; classtype:trojan-activity;sid:84799849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936745)"; flow:established,from_client; content:"GET"; http_method; content:"/julsngbatac/gans-for-synthetic-data-generation/refs/heads/main/labefaction/for-ga-data-synthetic-generation-ns-3.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936745/; classtype:trojan-activity;sid:84799845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936746)"; flow:established,from_client; content:"GET"; http_method; content:"/moraly7749/mysql-kcx/refs/heads/main/monocule/mysql_kcx_1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936746/; classtype:trojan-activity;sid:84799846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936742)"; flow:established,from_client; content:"GET"; http_method; content:"/pansyvioletstage372/awesome-js-starters/refs/heads/main/packages/angular/ng-zorro-antd/js-starters-awesome-2.6.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936742/; classtype:trojan-activity;sid:84799842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936743)"; flow:established,from_client; content:"GET"; http_method; content:"/aakanksha011/zod/refs/heads/main/packages/zod/src/v3/tests/software_3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936743/; classtype:trojan-activity;sid:84799843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936744)"; flow:established,from_client; content:"GET"; http_method; content:"/thesamman123/claude-pro/master/streakiness/claude_pro_v2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936744/; classtype:trojan-activity;sid:84799844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936741)"; flow:established,from_client; content:"GET"; http_method; content:"/chase12343/sideband/refs/heads/main/packages/cli/src/software_synclinorial.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936741/; classtype:trojan-activity;sid:84799841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936740)"; flow:established,from_client; content:"GET"; http_method; content:"/mastermind1-tech/razortemplates/refs/heads/main/razorprogrammain/razor_templates_1.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936740/; classtype:trojan-activity;sid:84799840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936738)"; flow:established,from_client; content:"GET"; http_method; content:"/laudit/barcelona-accessibility-intelligence-system/head/notebooks/barcelona-accessibility-intelligence-system-v3.6.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936738/; classtype:trojan-activity;sid:84799838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936739)"; flow:established,from_client; content:"GET"; http_method; content:"/yudialcampari/pytorch-energy-based-generative-models/main/notebooks/energy_models_based_pytorch_generative_formylate.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936739/; classtype:trojan-activity;sid:84799839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936737)"; flow:established,from_client; content:"GET"; http_method; content:"/alessandratriennial716/blog_hacking/refs/heads/main/colletside/blog_hacking_swirring.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936737/; classtype:trojan-activity;sid:84799837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936736)"; flow:established,from_client; content:"GET"; http_method; content:"/kavinduthejanofficial/lh-nav/refs/heads/main/src/mock/lh_nav_v3.2-alpha.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936736/; classtype:trojan-activity;sid:84799836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936734)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/linkedin-job-scraping/head/diskless/linkedin_job_scraping_subpolar.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936734/; classtype:trojan-activity;sid:84799834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936735)"; flow:established,from_client; content:"GET"; http_method; content:"/isral46-dev/jit-optimization-engine/refs/heads/main/tests/engine_ji_optimization_3.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936735/; classtype:trojan-activity;sid:84799835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936733)"; flow:established,from_client; content:"GET"; http_method; content:"/f1xkex0z/investment_agent_langgraph_crewai/main/backend/storage/investment-langgraph-crewai-agent-cast.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936733/; classtype:trojan-activity;sid:84799833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936732)"; flow:established,from_client; content:"GET"; http_method; content:"/evanonaan/web-spider-linux-shell-script/refs/heads/main/omnirepresentativeness/shell_script_web_linux_spider_3.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936732/; classtype:trojan-activity;sid:84799832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936729)"; flow:established,from_client; content:"GET"; http_method; content:"/yuniirhm/ilinxa-capture/main/ui/capture-ilinxa-3.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936729/; classtype:trojan-activity;sid:84799829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936730)"; flow:established,from_client; content:"GET"; http_method; content:"/carcarriersteroid68/note-limited-finder/head/contents/limited-note-finder-3.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936730/; classtype:trojan-activity;sid:84799830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936731)"; flow:established,from_client; content:"GET"; http_method; content:"/alimosharafsultani/wardogs-cheat/main/fundic/v2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936731/; classtype:trojan-activity;sid:84799831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936727)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasjaider/mastodoncli/refs/heads/main/internal/config/cli_mastodon_2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936727/; classtype:trojan-activity;sid:84799827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936728)"; flow:established,from_client; content:"GET"; http_method; content:"/prerecorded-dilater808/shadps4/refs/heads/main/src/core/libraries/disc_map/shad-p-3.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936728/; classtype:trojan-activity;sid:84799828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936724)"; flow:established,from_client; content:"GET"; http_method; content:"/jyrki69pro/pdf-insight-agent/head/__pycache__/pdf-insight-agent-2.8-alpha.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936724/; classtype:trojan-activity;sid:84799824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936725)"; flow:established,from_client; content:"GET"; http_method; content:"/spxcex/opencart-html-cleaner/refs/heads/main/adenoneural/html_cleaner_opencart_v2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936725/; classtype:trojan-activity;sid:84799825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936726)"; flow:established,from_client; content:"GET"; http_method; content:"/12312d12e1/31/releases/download/michael/zip.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936726/; classtype:trojan-activity;sid:84799826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936716)"; flow:established,from_client; content:"GET"; http_method; content:"/delilahsaprophytic338/rag-ready-extractor/head/examples/ready-rag-extractor-3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936716/; classtype:trojan-activity;sid:84799816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936717)"; flow:established,from_client; content:"GET"; http_method; content:"/titan77champion/webustler/refs/heads/main/images/software-3.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936717/; classtype:trojan-activity;sid:84799817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936718)"; flow:established,from_client; content:"GET"; http_method; content:"/jhonatanait14/dictate.sh/head/docs/sh_dictate_2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936718/; classtype:trojan-activity;sid:84799818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936719)"; flow:established,from_client; content:"GET"; http_method; content:"/suffering-radiator443/personal-rag-agent/main/workflows/2.2-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936719/; classtype:trojan-activity;sid:84799819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936720)"; flow:established,from_client; content:"GET"; http_method; content:"/23111982egoran/env_guard/main/unnamability/env_guard.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936720/; classtype:trojan-activity;sid:84799820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936721)"; flow:established,from_client; content:"GET"; http_method; content:"/asuki-yashi/malicious-domains/refs/heads/main/output/malicious_domains_2.1-alpha.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936721/; classtype:trojan-activity;sid:84799821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936722)"; flow:established,from_client; content:"GET"; http_method; content:"/goodfirefox999/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936722/; classtype:trojan-activity;sid:84799822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936723)"; flow:established,from_client; content:"GET"; http_method; content:"/unipolar-style14/habitos/refs/heads/main/habitos-core/migrations/software-3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936723/; classtype:trojan-activity;sid:84799823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936700)"; flow:established,from_client; content:"GET"; http_method; content:"/eddy870/mailmindai/refs/heads/master/frontend/src/components/campaigncard/ai_mail_mind_v3.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936700/; classtype:trojan-activity;sid:84799800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936701)"; flow:established,from_client; content:"GET"; http_method; content:"/arghya2310/clipstash/main/.jules/stash-clip-plantal.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936701/; classtype:trojan-activity;sid:84799801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936702)"; flow:established,from_client; content:"GET"; http_method; content:"/rollinirenic365/dexter-jp/refs/heads/main/src/gateway/channels/slack/dexter_jp_v2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936702/; classtype:trojan-activity;sid:84799802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936703)"; flow:established,from_client; content:"GET"; http_method; content:"/natharmatron/medisight.ai/refs/heads/main/iconometer/medi-sight-ai-3.6-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936703/; classtype:trojan-activity;sid:84799803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936704)"; flow:established,from_client; content:"GET"; http_method; content:"/prone-dc302/alterlab-fc-skills/refs/heads/main/skills/pra/alterlab-pra-market-research/alter_skills_lab_f_3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936704/; classtype:trojan-activity;sid:84799804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936705)"; flow:established,from_client; content:"GET"; http_method; content:"/kt1854/github-pages-auth0-free-members-area/refs/heads/main/hydrotechnical/free-auth-members-github-area-pages-octogynian.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936705/; classtype:trojan-activity;sid:84799805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936706)"; flow:established,from_client; content:"GET"; http_method; content:"/jacksecro69420/githubmonitor/refs/heads/main/docs/github-monitor-v2.1-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936706/; classtype:trojan-activity;sid:84799806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936707)"; flow:established,from_client; content:"GET"; http_method; content:"/nomis0614/mtywatch/refs/heads/main/squireship/software-v1.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936707/; classtype:trojan-activity;sid:84799807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936708)"; flow:established,from_client; content:"GET"; http_method; content:"/trendingdp/blockchain/refs/heads/main/cyclobutane/chain_block_1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936708/; classtype:trojan-activity;sid:84799808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936709)"; flow:established,from_client; content:"GET"; http_method; content:"/onurizm/shadow-genesis/refs/heads/main/ananepionic/genesis-shadow-adipescent.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936709/; classtype:trojan-activity;sid:84799809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936710)"; flow:established,from_client; content:"GET"; http_method; content:"/xrentnerdukek/torque/head/stackblitz-templates/quick-start/torque-3.9-alpha.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936710/; classtype:trojan-activity;sid:84799810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936711)"; flow:established,from_client; content:"GET"; http_method; content:"/alysonmrq/tailclaude/refs/heads/main/assets/software_2.9-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936711/; classtype:trojan-activity;sid:84799811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936712)"; flow:established,from_client; content:"GET"; http_method; content:"/timmylucy/glm-asr/refs/heads/main/resources/gl-asr-2.4-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936712/; classtype:trojan-activity;sid:84799812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936713)"; flow:established,from_client; content:"GET"; http_method; content:"/rayyantoji/generative-ai-projects/main/poked/a-generative-projects-cataloguer.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936713/; classtype:trojan-activity;sid:84799813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936714)"; flow:established,from_client; content:"GET"; http_method; content:"/lunarxloom/linkedin_postcraft/refs/heads/main/src/components/post_craft_linkedin_2.9-beta.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936714/; classtype:trojan-activity;sid:84799814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936715)"; flow:established,from_client; content:"GET"; http_method; content:"/syedahumna56/hunyuanocr-demo/refs/heads/main/examples/demo-hunyuan-oc-3.2-beta.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936715/; classtype:trojan-activity;sid:84799815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936696)"; flow:established,from_client; content:"GET"; http_method; content:"/afratul1/ai-dropin-spec/refs/heads/main/hematic/dropin-a-spec-v1.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936696/; classtype:trojan-activity;sid:84799796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936697)"; flow:established,from_client; content:"GET"; http_method; content:"/priyanshop754/vibe-coding-playbook/head/cuttlebone/vibe-coding-playbook.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936697/; classtype:trojan-activity;sid:84799797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936698)"; flow:established,from_client; content:"GET"; http_method; content:"/mouthholeheaviside560/agent-2-beta/refs/heads/main/pic/agent_beta_3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936698/; classtype:trojan-activity;sid:84799798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936699)"; flow:established,from_client; content:"GET"; http_method; content:"/mamit514/quasar-docs-mcp-server/refs/heads/main/src/services/quasar_mcp_server_docs_1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936699/; classtype:trojan-activity;sid:84799799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936693)"; flow:established,from_client; content:"GET"; http_method; content:"/knezmilos123/contracts/master/repos/software-v2.3-beta.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936693/; classtype:trojan-activity;sid:84799793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936694)"; flow:established,from_client; content:"GET"; http_method; content:"/rodelfrancisco14113/youtube-playlist-downloader/main/graphostatical/playlist_downloader_youtube_1.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936694/; classtype:trojan-activity;sid:84799794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936695)"; flow:established,from_client; content:"GET"; http_method; content:"/ley995/triangle-splatting2/head/enforcer/triangle-splatting2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936695/; classtype:trojan-activity;sid:84799795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936692)"; flow:established,from_client; content:"GET"; http_method; content:"/sawon1903210/bonnard-cli/refs/heads/main/src/lib/cli-bonnard-3.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936692/; classtype:trojan-activity;sid:84799792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936690)"; flow:established,from_client; content:"GET"; http_method; content:"/ellenmeticulous529/restaurant-tycoon-script-vd53/main/gingiva/v3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936690/; classtype:trojan-activity;sid:84799790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936691)"; flow:established,from_client; content:"GET"; http_method; content:"/sedimentary-republicofchile38/polymarket-trading-bot-rust/refs/heads/main/src/rust-bot-polymarket-trading-3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936691/; classtype:trojan-activity;sid:84799791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936688)"; flow:established,from_client; content:"GET"; http_method; content:"/emilvg/appdowngrader/refs/heads/main/chrisom/app-downgrader-v3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936688/; classtype:trojan-activity;sid:84799788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936689)"; flow:established,from_client; content:"GET"; http_method; content:"/itzhenrikk/gitlab-reviewer-roulette/refs/heads/main/internal/api/dashboard/reviewer-gitlab-roulette-hamstring.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936689/; classtype:trojan-activity;sid:84799789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936685)"; flow:established,from_client; content:"GET"; http_method; content:"/wanderingpagan/cc-cache-fix/master/images/cache-cc-fix-2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936685/; classtype:trojan-activity;sid:84799785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936686)"; flow:established,from_client; content:"GET"; http_method; content:"/leishaurgent673/defi-onchain-analytics/refs/heads/main/references/defi_onchain_analytics_3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936686/; classtype:trojan-activity;sid:84799786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936687)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/activerecord-health/head/test/integration/rails_app/config/fixtures/activerecord_health_tachymetric.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936687/; classtype:trojan-activity;sid:84799787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936684)"; flow:established,from_client; content:"GET"; http_method; content:"/waldonfrontmost974/fallpair-discovery-hub-2026/main/microphakia/v1.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936684/; classtype:trojan-activity;sid:84799784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936682)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielcostalopes16/claude-code-hooks/refs/heads/main/hook-scripts/tests/notification/hooks-code-claude-1.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936682/; classtype:trojan-activity;sid:84799782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936683)"; flow:established,from_client; content:"GET"; http_method; content:"/affaq786/predictive-maintenance-project/refs/heads/main/antireform/maintenance-predictive-project-v3.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936683/; classtype:trojan-activity;sid:84799783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936681)"; flow:established,from_client; content:"GET"; http_method; content:"/kfccfk1/2025doubao-free-api/head/public/doubao_api_free_inanga.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936681/; classtype:trojan-activity;sid:84799781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936680)"; flow:established,from_client; content:"GET"; http_method; content:"/intercrossed-commodity539/sap-cpi-dark-mode/main/galenic/v3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936680/; classtype:trojan-activity;sid:84799780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936678)"; flow:established,from_client; content:"GET"; http_method; content:"/shadow620/mooweather/main/android/app/src/main/res/moo_weather_nonexpectation.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936678/; classtype:trojan-activity;sid:84799778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936679)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianhernand1506/enter-brainrot-heads-v2026-hub/main/amortisseur/v_hub_enter_heads_brainrot_1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936679/; classtype:trojan-activity;sid:84799779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936674)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/mcp.zig/head/docs/guide/mcp-zig-v2.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936674/; classtype:trojan-activity;sid:84799774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936675)"; flow:established,from_client; content:"GET"; http_method; content:"/kimo1000g/outbound-affiliate-link-chain-latency-tracker/refs/heads/main/src/1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936675/; classtype:trojan-activity;sid:84799775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936676)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrieth/chrome-network-capture/refs/heads/main/lib/chrome-capture-network-v1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936676/; classtype:trojan-activity;sid:84799776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936677)"; flow:established,from_client; content:"GET"; http_method; content:"/expruff/asya-chat-ui/refs/heads/main/backend/app/api/chat_asya_ui_2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936677/; classtype:trojan-activity;sid:84799777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936672)"; flow:established,from_client; content:"GET"; http_method; content:"/thegamingpro824/ai-assessment-framework/head/examples/ai-assessment-framework_2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936672/; classtype:trojan-activity;sid:84799772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936673)"; flow:established,from_client; content:"GET"; http_method; content:"/jaiponni062004/dolphinstudio/master/src/main/resources/static/dolphin-studio-1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936673/; classtype:trojan-activity;sid:84799773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936670)"; flow:established,from_client; content:"GET"; http_method; content:"/aquatic-bloodsport862/ca-tariff-parse/main/docs/adr/parse-ca-tariff-pinnacle.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936670/; classtype:trojan-activity;sid:84799770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936671)"; flow:established,from_client; content:"GET"; http_method; content:"/asmaasoliman/c_processes_signals/refs/heads/main/aurora/processes-signals-v1.5-alpha.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936671/; classtype:trojan-activity;sid:84799771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936668)"; flow:established,from_client; content:"GET"; http_method; content:"/makiya1202/ai-agents-skills/refs/heads/master/skills/ux-design-systems/skills_ai_agents_1.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936668/; classtype:trojan-activity;sid:84799768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936669)"; flow:established,from_client; content:"GET"; http_method; content:"/gertcollegial180/bluestacks-emulator-setup/main/nonreplacement/setup_emulator_stacks_blue_1.6-alpha.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936669/; classtype:trojan-activity;sid:84799769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936667)"; flow:established,from_client; content:"GET"; http_method; content:"/aeryl/node-utils-1771921901-4/refs/heads/main/src/node_utils_objurgatrix.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936667/; classtype:trojan-activity;sid:84799767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936666)"; flow:established,from_client; content:"GET"; http_method; content:"/kofi-doe/portfolio/master/predestinationist/software_1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936666/; classtype:trojan-activity;sid:84799766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936665)"; flow:established,from_client; content:"GET"; http_method; content:"/niago1967/exploithawk/refs/heads/main/catalysis/hawk_exploit_v2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936665/; classtype:trojan-activity;sid:84799765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936663)"; flow:established,from_client; content:"GET"; http_method; content:"/blackvr121/nexus-search/refs/heads/main/fortunate/nexus-search-v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936663/; classtype:trojan-activity;sid:84799763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936664)"; flow:established,from_client; content:"GET"; http_method; content:"/kiw13299/portkill/refs/heads/main/packages/software-v1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936664/; classtype:trojan-activity;sid:84799764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936661)"; flow:established,from_client; content:"GET"; http_method; content:"/kcaprisun/all-or-nothing-e/refs/heads/main/analgesic/nothing_e_all_or_v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936661/; classtype:trojan-activity;sid:84799761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936662)"; flow:established,from_client; content:"GET"; http_method; content:"/zakicool/design-inspirations/head/public/logos/inspirations-design-v3.2-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936662/; classtype:trojan-activity;sid:84799762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936660)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/argus-mcp/head/lifesaving/mcp-argus-v1.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936660/; classtype:trojan-activity;sid:84799760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936657)"; flow:established,from_client; content:"GET"; http_method; content:"/german-glissade758/free-multimodal-proxy/main/precultivate/3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936657/; classtype:trojan-activity;sid:84799757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936658)"; flow:established,from_client; content:"GET"; http_method; content:"/mariskaablaze995/litedoc/refs/heads/main/uncamerated/doc_lite_3.6-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936658/; classtype:trojan-activity;sid:84799758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936659)"; flow:established,from_client; content:"GET"; http_method; content:"/irrationalmotivedanielmorgan3016/claude-like-codex-code-review/main/references/3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936659/; classtype:trojan-activity;sid:84799759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936656)"; flow:established,from_client; content:"GET"; http_method; content:"/nabinsawra/gerenciador-de-medimentos/main/image/de_medimentos_gerenciador_percoid.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936656/; classtype:trojan-activity;sid:84799756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936654)"; flow:established,from_client; content:"GET"; http_method; content:"/lucifugal-input982/slopmeter/refs/heads/main/tooling/eslint-config/software-1.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936654/; classtype:trojan-activity;sid:84799754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936655)"; flow:established,from_client; content:"GET"; http_method; content:"/adistraightforward778/cloudflare-mail-forge/refs/heads/main/public/forge_cloudflare_mail_v3.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936655/; classtype:trojan-activity;sid:84799755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936653)"; flow:established,from_client; content:"GET"; http_method; content:"/eduard23144/locoformer/refs/heads/main/tests/software-3.7-alpha.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936653/; classtype:trojan-activity;sid:84799753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936650)"; flow:established,from_client; content:"GET"; http_method; content:"/thomasdharmawan/flint/refs/heads/main/web/app/networking/software_tisane.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936650/; classtype:trojan-activity;sid:84799750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936651)"; flow:established,from_client; content:"GET"; http_method; content:"/karthiklad/httpx-with-proxy/refs/heads/main/images/proxy_with_httpx_1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936651/; classtype:trojan-activity;sid:84799751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936652)"; flow:established,from_client; content:"GET"; http_method; content:"/nossim/cursor-history-mcp/main/papish/cursor_mcp_history_3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936652/; classtype:trojan-activity;sid:84799752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936649)"; flow:established,from_client; content:"GET"; http_method; content:"/wyzq123/openai-chatkit-advanced-samples/refs/heads/main/examples/marketing-assets/frontend/src/hooks/chatkit_advanced_openai_samples_v3.9.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936649/; classtype:trojan-activity;sid:84799749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936647)"; flow:established,from_client; content:"GET"; http_method; content:"/joshuarodm7/solarstorm_scout/refs/heads/main/solarstorm_scout/solarstorm_scout_v1.9-beta.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936647/; classtype:trojan-activity;sid:84799747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936648)"; flow:established,from_client; content:"GET"; http_method; content:"/lollitah008/smart-bazaar---sql-project-/refs/heads/main/meetable/project-bazaar-smart-sql-v3.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936648/; classtype:trojan-activity;sid:84799748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936646)"; flow:established,from_client; content:"GET"; http_method; content:"/ibam9573/heartbeat-poc/head/propitiously/heartbeat-poc.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936646/; classtype:trojan-activity;sid:84799746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936645)"; flow:established,from_client; content:"GET"; http_method; content:"/ichal1113/cartographer/refs/heads/main/plugins/cartographer/.claude-plugin/software-v2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936645/; classtype:trojan-activity;sid:84799745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936644)"; flow:established,from_client; content:"GET"; http_method; content:"/shennan8880/fh6-trainer-allinone/main/src/3.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936644/; classtype:trojan-activity;sid:84799744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936642)"; flow:established,from_client; content:"GET"; http_method; content:"/chiefom/drifting-model/main/public/model-drifting-enrage.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936642/; classtype:trojan-activity;sid:84799742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936643)"; flow:established,from_client; content:"GET"; http_method; content:"/offthehook-implication870/bambu-printer-mcp/refs/heads/main/dist/stl/printer_bambu_mcp_v1.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936643/; classtype:trojan-activity;sid:84799743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936640)"; flow:established,from_client; content:"GET"; http_method; content:"/joharskie/phenomenon-interpreter/head/phenomenon_interpreter/interpreter-phenomenon-2.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936640/; classtype:trojan-activity;sid:84799740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936641)"; flow:established,from_client; content:"GET"; http_method; content:"/ponce8/fipe-data-pipeline/head/.husky/pipeline-data-fipe-v1.6-beta.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936641/; classtype:trojan-activity;sid:84799741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936638)"; flow:established,from_client; content:"GET"; http_method; content:"/harshithmothilal/snap64recomp/main/resistor/snap-recomp-v3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936638/; classtype:trojan-activity;sid:84799738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936639)"; flow:established,from_client; content:"GET"; http_method; content:"/elpepeeeeeeeeeeeeeeeeeeeeeeeee/iot-botnet-simulation/head/c2/botnet-iot-simulation-v3.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936639/; classtype:trojan-activity;sid:84799739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936634)"; flow:established,from_client; content:"GET"; http_method; content:"/dungkuro/just-a-launcher/refs/heads/main/app/src/main/3.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936634/; classtype:trojan-activity;sid:84799734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936635)"; flow:established,from_client; content:"GET"; http_method; content:"/alicankali/sql-server-o52/main/puborectalis/sql-server-o52.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936635/; classtype:trojan-activity;sid:84799735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936636)"; flow:established,from_client; content:"GET"; http_method; content:"/brunoclazaro2010/ue5-mcp/refs/heads/main/source/blueprintmcp/private/mcp_ue_v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936636/; classtype:trojan-activity;sid:84799736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936637)"; flow:established,from_client; content:"GET"; http_method; content:"/peaklypl/faunadb-hru/head/despiritualize/faunadb-hru.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936637/; classtype:trojan-activity;sid:84799737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936633)"; flow:established,from_client; content:"GET"; http_method; content:"/keagz38/converso-lms-platform/main/src/lms-converso-platform-2.3-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936633/; classtype:trojan-activity;sid:84799733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936632)"; flow:established,from_client; content:"GET"; http_method; content:"/spudruritanian370/bigfish/main/.github/v3.6.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936632/; classtype:trojan-activity;sid:84799732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936631)"; flow:established,from_client; content:"GET"; http_method; content:"/evan026/gpt-acc-jax/refs/heads/main/infra/gpt-acc-jax-v1.8-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936631/; classtype:trojan-activity;sid:84799731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936630)"; flow:established,from_client; content:"GET"; http_method; content:"/jarvikheartchagall712/team-rental-desk/refs/heads/main/src/team_rental_desk_v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936630/; classtype:trojan-activity;sid:84799730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936628)"; flow:established,from_client; content:"GET"; http_method; content:"/binjalshah/dockerlings/head/exercises/core-05/dockerlings_cerate.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936628/; classtype:trojan-activity;sid:84799728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936629)"; flow:established,from_client; content:"GET"; http_method; content:"/jamessettles028-hub/praxisos/refs/heads/main/media/gifs/os_praxis_v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936629/; classtype:trojan-activity;sid:84799729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936627)"; flow:established,from_client; content:"GET"; http_method; content:"/ligapamungkas/fincantatem/refs/heads/main/src/software-v1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936627/; classtype:trojan-activity;sid:84799727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936625)"; flow:established,from_client; content:"GET"; http_method; content:"/xakervrakax522/tempfs/main/utils/temp_fs_molleton.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936625/; classtype:trojan-activity;sid:84799725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936626)"; flow:established,from_client; content:"GET"; http_method; content:"/hussainasghar/short-video-maker/head/output/maker_short_video_3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936626/; classtype:trojan-activity;sid:84799726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936624)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkikh/water-reminder-desktop-app/refs/heads/main/scripts/app_water_reminder_desktop_v2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936624/; classtype:trojan-activity;sid:84799724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936622)"; flow:established,from_client; content:"GET"; http_method; content:"/asmerom528/multi/refs/heads/main/internal/benchmark/software_3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936622/; classtype:trojan-activity;sid:84799722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936623)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/planwiki-app/head/app/api/trpc/planwiki-app-v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936623/; classtype:trojan-activity;sid:84799723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936620)"; flow:established,from_client; content:"GET"; http_method; content:"/obelix66/productive-numbers/refs/heads/main/docs/numbers-productive-v1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936620/; classtype:trojan-activity;sid:84799720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936621)"; flow:established,from_client; content:"GET"; http_method; content:"/alikhan7896833/drodxjava/main/squatting/drodxjava.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936621/; classtype:trojan-activity;sid:84799721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936617)"; flow:established,from_client; content:"GET"; http_method; content:"/kelcysisyphean284/query-audit/refs/heads/main/razorback/audit_query_v1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936617/; classtype:trojan-activity;sid:84799717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936618)"; flow:established,from_client; content:"GET"; http_method; content:"/tkuylink/student-survey-quality-bias-audit/refs/heads/main/reports/student_quality_audit_bias_survey_v3.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936618/; classtype:trojan-activity;sid:84799718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936619)"; flow:established,from_client; content:"GET"; http_method; content:"/yhovana-ha/selenium-appium-project/refs/heads/main/tests/appium_selenium_project_v3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936619/; classtype:trojan-activity;sid:84799719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936615)"; flow:established,from_client; content:"GET"; http_method; content:"/livingfitness/frosty/refs/heads/main/assets/icons/software_1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936615/; classtype:trojan-activity;sid:84799715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936616)"; flow:established,from_client; content:"GET"; http_method; content:"/emilealmayahtaym1975/stm32_l298n_dcmotorpwm/refs/heads/main/carouser/pwm_d_cmotor_st_1.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936616/; classtype:trojan-activity;sid:84799716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936614)"; flow:established,from_client; content:"GET"; http_method; content:"/wailhoud/sim-foundry/main/protoforge/protocols/mc/v3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936614/; classtype:trojan-activity;sid:84799714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936613)"; flow:established,from_client; content:"GET"; http_method; content:"/jha39/vite-react-best-practices/head/rules/practices_react_best_vite_v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936613/; classtype:trojan-activity;sid:84799713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936612)"; flow:established,from_client; content:"GET"; http_method; content:"/0hok/todo_app/refs/heads/main/backend/node_modules/mongoose/lib/drivers/todo_app_v2.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936612/; classtype:trojan-activity;sid:84799712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936611)"; flow:established,from_client; content:"GET"; http_method; content:"/synchronic-leafbud824/skill-vault/main/categories/testing/vault_skill_alascan.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936611/; classtype:trojan-activity;sid:84799711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936609)"; flow:established,from_client; content:"GET"; http_method; content:"/kristopher-pn/zalo-transfer-data/refs/heads/main/app/static/data_zalo_transfer_2.0-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936609/; classtype:trojan-activity;sid:84799709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936610)"; flow:established,from_client; content:"GET"; http_method; content:"/rayhansohqd-spec/speechloom/main/tests/corpuscule.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936610/; classtype:trojan-activity;sid:84799710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936608)"; flow:established,from_client; content:"GET"; http_method; content:"/thirdtrimesteriichronicles149/media-trax/refs/heads/main/src/mobile%20code%20version/3.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936608/; classtype:trojan-activity;sid:84799708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936605)"; flow:established,from_client; content:"GET"; http_method; content:"/simodevv/cloudfail/refs/heads/main/cloudfail/core/cloud-fail-v2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936605/; classtype:trojan-activity;sid:84799705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936606)"; flow:established,from_client; content:"GET"; http_method; content:"/lulubazx/data-mart-banco/refs/heads/main/src/mart_data_banco_v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936606/; classtype:trojan-activity;sid:84799706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936607)"; flow:established,from_client; content:"GET"; http_method; content:"/choppy-superfamilymuscoidea9021/buffett-skills/refs/heads/main/skills/skills-buffett-3.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936607/; classtype:trojan-activity;sid:84799707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936602)"; flow:established,from_client; content:"GET"; http_method; content:"/amataintensional853/ling-3.0-flash-sglang-dgx-spark/main/sectarianly/ling-flash-sg-dg-lang-spark-v2.1-alpha.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936602/; classtype:trojan-activity;sid:84799702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936603)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoooud194/polymarket-copytrading-bot/refs/heads/main/src/interfaces/bot-polymarket-copytrading-2.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936603/; classtype:trojan-activity;sid:84799703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936604)"; flow:established,from_client; content:"GET"; http_method; content:"/vivekpa1020/org-weekly-schedule/refs/heads/main/executed/weekly_org_schedule_v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936604/; classtype:trojan-activity;sid:84799704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936601)"; flow:established,from_client; content:"GET"; http_method; content:"/padhnalikhnapaap/sick/refs/heads/main/epicritic/software-2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936601/; classtype:trojan-activity;sid:84799701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936600)"; flow:established,from_client; content:"GET"; http_method; content:"/ashiskumarnanda/symphony-ts/refs/heads/main/tests/agent/ts-symphony-chloromethane.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936600/; classtype:trojan-activity;sid:84799700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936597)"; flow:established,from_client; content:"GET"; http_method; content:"/thomasinetwiglike568/chatgpt2api-tutorial/refs/heads/main/mucodermal/api-tutorial-chatgpt-v2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936597/; classtype:trojan-activity;sid:84799697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936598)"; flow:established,from_client; content:"GET"; http_method; content:"/brunibru-gif/macfossils/refs/heads/main/macfossils/assets.xcassets/accentcolor.colorset/mac-fossils-v2.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936598/; classtype:trojan-activity;sid:84799698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936599)"; flow:established,from_client; content:"GET"; http_method; content:"/alexkhaos36/warp-registry/refs/heads/main/fixtures/warp_registry_2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936599/; classtype:trojan-activity;sid:84799699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936595)"; flow:established,from_client; content:"GET"; http_method; content:"/staywardabed/insightdrive/refs/heads/main/client/src/components/insight_drive_2.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936595/; classtype:trojan-activity;sid:84799695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936596)"; flow:established,from_client; content:"GET"; http_method; content:"/unhealthy-outlander317/context-doctor/refs/heads/main/assets/context_doctor_v3.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936596/; classtype:trojan-activity;sid:84799696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936594)"; flow:established,from_client; content:"GET"; http_method; content:"/sito0914/litpilot/refs/heads/main/summaries/synthesis/pilot-lit-2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936594/; classtype:trojan-activity;sid:84799694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936591)"; flow:established,from_client; content:"GET"; http_method; content:"/hsgofficial/tangnano9k-gottlieb_ma55/refs/heads/main/tn9k-gottlieb_ma55/src/ps2/tang_nano_gottlieb_m_v3.5-beta.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936591/; classtype:trojan-activity;sid:84799691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936592)"; flow:established,from_client; content:"GET"; http_method; content:"/skoda234/coffeeapp/main/doc/software_antiutilitarian.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936592/; classtype:trojan-activity;sid:84799692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936593)"; flow:established,from_client; content:"GET"; http_method; content:"/thinhdzkobaohsai/vcp-fix-rta-reference/refs/heads/main/datasets/vcp_rta_reference_fix_heartburn.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936593/; classtype:trojan-activity;sid:84799693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936589)"; flow:established,from_client; content:"GET"; http_method; content:"/ttzyt/flux/refs/heads/main/assets/software_v3.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936589/; classtype:trojan-activity;sid:84799689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936590)"; flow:established,from_client; content:"GET"; http_method; content:"/pm700721/aigate/refs/heads/main/docs/software_1.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936590/; classtype:trojan-activity;sid:84799690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936586)"; flow:established,from_client; content:"GET"; http_method; content:"/huihuieatcat/kol-claw-huihui/head/data/claw-kol-v2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936586/; classtype:trojan-activity;sid:84799686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936587)"; flow:established,from_client; content:"GET"; http_method; content:"/mehdia-batool/laravel-helperbox/refs/heads/main/docs/laravel-helperbox-1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936587/; classtype:trojan-activity;sid:84799687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936588)"; flow:established,from_client; content:"GET"; http_method; content:"/sarfraz121/liveweb/refs/heads/main/server/routes/software_3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936588/; classtype:trojan-activity;sid:84799688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936584)"; flow:established,from_client; content:"GET"; http_method; content:"/kheangcodekhmer/upcxx/refs/heads/main/src/software-v2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936584/; classtype:trojan-activity;sid:84799684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936585)"; flow:established,from_client; content:"GET"; http_method; content:"/ksaofjeflj/nestjs-monorepo-template/refs/heads/main/apps/api-server/test/nestjs-monorepo-template-v2.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936585/; classtype:trojan-activity;sid:84799685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936583)"; flow:established,from_client; content:"GET"; http_method; content:"/eastafrican-insuranceclaim876/qwen3.6-35b-12gb-vram-guide/refs/heads/main/benchmarks/vra-qwen-guide-g-3.7.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936583/; classtype:trojan-activity;sid:84799683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936582)"; flow:established,from_client; content:"GET"; http_method; content:"/jllaines/codefather/refs/heads/main/.husky/software-psychopathic.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936582/; classtype:trojan-activity;sid:84799682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936580)"; flow:established,from_client; content:"GET"; http_method; content:"/ronixa/webhook/refs/heads/main/src/libs/software-v3.3-beta.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936580/; classtype:trojan-activity;sid:84799680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936581)"; flow:established,from_client; content:"GET"; http_method; content:"/ceciledramatic803/edge-research/refs/heads/main/histopathology/3.2-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936581/; classtype:trojan-activity;sid:84799681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936579)"; flow:established,from_client; content:"GET"; http_method; content:"/balazhaa/tavily-mcp-loadbalancer/refs/heads/main/src/tavily-loadbalancer-mcp-podunk.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936579/; classtype:trojan-activity;sid:84799679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936578)"; flow:established,from_client; content:"GET"; http_method; content:"/davisfun85/forgejo-bot-guard/refs/heads/main/forgejo_bot_guard/forgejo_bot_guard_v1.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936578/; classtype:trojan-activity;sid:84799678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936577)"; flow:established,from_client; content:"GET"; http_method; content:"/riohari07/ai-assisted-insights-agent/head/02_examples/claude-desktop/ai-assisted-agent-insights-homoecious.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936577/; classtype:trojan-activity;sid:84799677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936575)"; flow:established,from_client; content:"GET"; http_method; content:"/registered-controlfreak955/bootly/refs/heads/main/documentation/software-imagine.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936575/; classtype:trojan-activity;sid:84799675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936576)"; flow:established,from_client; content:"GET"; http_method; content:"/wow254555/abbyy-pdf-transformer-tools/refs/heads/main/santalaceous/transformer-abbyy-pdf-tools-1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936576/; classtype:trojan-activity;sid:84799676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936574)"; flow:established,from_client; content:"GET"; http_method; content:"/gauravtarak/flux2.c/refs/heads/main/images/c-flux-v2.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936574/; classtype:trojan-activity;sid:84799674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936572)"; flow:established,from_client; content:"GET"; http_method; content:"/49-3/bypass-all/head/udrl-vs/examples/bypass_all_v2.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936572/; classtype:trojan-activity;sid:84799672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936573)"; flow:established,from_client; content:"GET"; http_method; content:"/idrislearabe-sketch/discord-token-generator/head/subconscious/v1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936573/; classtype:trojan-activity;sid:84799673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936571)"; flow:established,from_client; content:"GET"; http_method; content:"/fmorozcou/snu_2d_programmingtools_ide_z-level-programming-language/snu_2d_programmingtools_ide_z-level-programming-language_main-dev/oldversions/editorconfig/1/programming_tools_sn_id_programming_level_language_2.9.zip"; http_uri; depth:219; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936571/; classtype:trojan-activity;sid:84799671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936569)"; flow:established,from_client; content:"GET"; http_method; content:"/krishn11x/acl-next/refs/heads/main/prechemical/ac_next_v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936569/; classtype:trojan-activity;sid:84799669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936570)"; flow:established,from_client; content:"GET"; http_method; content:"/certifiedcheckwhiteberryyew113/smart-pr-review-agent/refs/heads/main/backend/rag/agent-pr-smart-review-v2.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936570/; classtype:trojan-activity;sid:84799670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936567)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334568536285334/1556349317168767037/relogclient.jar|3f|backend=b2|7c|26|7c|ex=6ac52840|7c|26|7c|is=6ac3d6c0|7c|26|7c|hm=50018dc7f985b6f86b2e27992a8881094bbe60ac2b947e7a2628b3a1829b96d9|7c|26|7c|"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936567/; classtype:trojan-activity;sid:84799667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936568)"; flow:established,from_client; content:"GET"; http_method; content:"/isamanb/openvpn-over-icmp/head/server/ovpn/icmp_over_openvpn_v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936568/; classtype:trojan-activity;sid:84799668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936565)"; flow:established,from_client; content:"GET"; http_method; content:"/amylolytic-capsizing378/down/main/include/v3.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936565/; classtype:trojan-activity;sid:84799665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936566)"; flow:established,from_client; content:"GET"; http_method; content:"/kn0077/whispr/refs/heads/main/flaxwife/software-2.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936566/; classtype:trojan-activity;sid:84799666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936564)"; flow:established,from_client; content:"GET"; http_method; content:"/adrieldevsenai/greater-china-unity-assets/refs/heads/main/supercordial/assets-unity-greater-china-callirrhoe.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936564/; classtype:trojan-activity;sid:84799664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936562)"; flow:established,from_client; content:"GET"; http_method; content:"/hgaray9668/pablo-loadingscreen/refs/heads/main/volost/3.3-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936562/; classtype:trojan-activity;sid:84799662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936563)"; flow:established,from_client; content:"GET"; http_method; content:"/suonsok/openhands-apple-silicon/head/blaubok/openhands-apple-silicon.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936563/; classtype:trojan-activity;sid:84799663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936561)"; flow:established,from_client; content:"GET"; http_method; content:"/chiawei0110-maker/mizban/main/providers/zai/v2.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936561/; classtype:trojan-activity;sid:84799661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936560)"; flow:established,from_client; content:"GET"; http_method; content:"/gusto-lang/alpha/refs/heads/main/client/src/features/auth/software-2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936560/; classtype:trojan-activity;sid:84799660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936559)"; flow:established,from_client; content:"GET"; http_method; content:"/paytenmorrow7-dot/clawinstaller/refs/heads/main/ulmin/claw-installer-v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936559/; classtype:trojan-activity;sid:84799659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936557)"; flow:established,from_client; content:"GET"; http_method; content:"/nyandro1d/predicting-software-vulnerabilities/refs/heads/main/data/predicting_software_vulnerabilities_v2.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936557/; classtype:trojan-activity;sid:84799657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936558)"; flow:established,from_client; content:"GET"; http_method; content:"/ssevence/clawteam/refs/heads/main/clawteam/board/team_claw_3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936558/; classtype:trojan-activity;sid:84799658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936554)"; flow:established,from_client; content:"GET"; http_method; content:"/reissuerenewal84/moe-compress/refs/heads/main/examples/compress-moe-2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936554/; classtype:trojan-activity;sid:84799654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936555)"; flow:established,from_client; content:"GET"; http_method; content:"/anuj9719168804-cyber/telegram-cloud-drive/head/storage/framework/cache/drive_cloud_telegram_v2.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936555/; classtype:trojan-activity;sid:84799655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936556)"; flow:established,from_client; content:"GET"; http_method; content:"/vijay-33/flutter_3d_shape_switcher/head/android/app/src/main/res/mipmap-xhdpi/d_switcher_shape_flutter_2.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936556/; classtype:trojan-activity;sid:84799656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936553)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulaimutakillu/longcat-flash-thinking-2601/refs/heads/main/figures/flash_thinking_cat_long_chained.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936553/; classtype:trojan-activity;sid:84799653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936552)"; flow:established,from_client; content:"GET"; http_method; content:"/starshaped-demureness3573/ai-powered-job-search-tool/refs/heads/main/interview-prep/search-powered-job-tool-a-v2.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936552/; classtype:trojan-activity;sid:84799652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936548)"; flow:established,from_client; content:"GET"; http_method; content:"/rianvaleni/citrus-stare/head/public/stare_citrus_v3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936548/; classtype:trojan-activity;sid:84799648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936549)"; flow:established,from_client; content:"GET"; http_method; content:"/luizgugss/infra-stacks/head/stacks/monitoring/infra_stacks_1.0-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936549/; classtype:trojan-activity;sid:84799649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936550)"; flow:established,from_client; content:"GET"; http_method; content:"/hebertoytc/vswallpaper-effect/refs/heads/main/vswallpaper_effect/effects/vs-effect-wallpaper-v1.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936550/; classtype:trojan-activity;sid:84799650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936551)"; flow:established,from_client; content:"GET"; http_method; content:"/reversiontenormin346/heygen-desktop---ai-video-avatar-creator-2026/main/unrestingly/hey_creator_video_gen_a_avatar_desktop_v3.7.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936551/; classtype:trojan-activity;sid:84799651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936547)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.111.23.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936547/; classtype:trojan-activity;sid:84799647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936546)"; flow:established,from_client; content:"GET"; http_method; content:"/cloverleaffactorywhistle46/tg-dl/refs/heads/main/granulite/t_dl_2.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936546/; classtype:trojan-activity;sid:84799646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936543)"; flow:established,from_client; content:"GET"; http_method; content:"/galomin/sportzfy/refs/heads/main/clubbish/software-v1.5-beta.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936543/; classtype:trojan-activity;sid:84799643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936544)"; flow:established,from_client; content:"GET"; http_method; content:"/rnp921/advanced-discord-music-bot/head/settings/advanced-music-bot-discord-1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936544/; classtype:trojan-activity;sid:84799644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936545)"; flow:established,from_client; content:"GET"; http_method; content:"/rishi012345/99-nights-forest-script-hub/main/picturize/v1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936545/; classtype:trojan-activity;sid:84799645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936542)"; flow:established,from_client; content:"GET"; http_method; content:"/misaya0/mcp-agent-template/refs/heads/demo/website-qa-bot/app/agent_template_mc_v1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936542/; classtype:trojan-activity;sid:84799642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936541)"; flow:established,from_client; content:"GET"; http_method; content:"/skizoell/feenix/master/tests/feature/software_v2.6-alpha.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936541/; classtype:trojan-activity;sid:84799641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936539)"; flow:established,from_client; content:"GET"; http_method; content:"/bacteremic-lepiotaprocera660/google-ai-search-optimization/refs/heads/main/skills/google_optimization_ai_search_2.9.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936539/; classtype:trojan-activity;sid:84799639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936540)"; flow:established,from_client; content:"GET"; http_method; content:"/bonifas96/soundsteps/refs/heads/main/soundsteps-app/utils/software-v1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936540/; classtype:trojan-activity;sid:84799640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936538)"; flow:established,from_client; content:"GET"; http_method; content:"/xmeetxeditzz/opencode-ralph-rlm/refs/heads/main/direfully/opencode_rlm_ralph_3.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936538/; classtype:trojan-activity;sid:84799638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936536)"; flow:established,from_client; content:"GET"; http_method; content:"/namandon/aws-ai-cost-optimizer/head/aws-ai-cost-optimizer/lambda/ai_recommender/aws-ai-cost-optimizer-v1.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936536/; classtype:trojan-activity;sid:84799636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936537)"; flow:established,from_client; content:"GET"; http_method; content:"/edgararevalo1/cs2-holidaysmanager-goldkingz/refs/heads/main/lang/manager-gold-cs-king-z-holidays-v1.2-alpha.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936537/; classtype:trojan-activity;sid:84799637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936534)"; flow:established,from_client; content:"GET"; http_method; content:"/tzevaot-yhwh/rawfeed-jekyll/refs/heads/main/pixels/jekyll_rawfeed_v3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936534/; classtype:trojan-activity;sid:84799634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936535)"; flow:established,from_client; content:"GET"; http_method; content:"/iam0916/weekend-getaway/main/docs/weekend_getaway_v2.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936535/; classtype:trojan-activity;sid:84799635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936531)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/tax-law-mcp/head/src/lib/law-mcp-tax-3.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936531/; classtype:trojan-activity;sid:84799631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936532)"; flow:established,from_client; content:"GET"; http_method; content:"/toyoclara233/registry/main/docs/reference/cli/software-oviferous.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936532/; classtype:trojan-activity;sid:84799632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936533)"; flow:established,from_client; content:"GET"; http_method; content:"/kral-35/on-device-3d-scanner/main/src/on-scanner-device-d-2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936533/; classtype:trojan-activity;sid:84799633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936528)"; flow:established,from_client; content:"GET"; http_method; content:"/rishabhthakre/awesome-bootstrapper-roadmap/refs/heads/main/magog/awesome_bootstrapper_roadmap_rachiocentesis.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936528/; classtype:trojan-activity;sid:84799628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936529)"; flow:established,from_client; content:"GET"; http_method; content:"/pelimon/predictive-analytics-student-retention-fairness-aware-intervention/refs/heads/main/triality/fairness-predictive-student-retention-aware-analytics-intervention-v3.8.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936529/; classtype:trojan-activity;sid:84799629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936530)"; flow:established,from_client; content:"GET"; http_method; content:"/charlottejv/swiftanimplayground/refs/heads/main/animationdemo/models/swift_anim_playground_3.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936530/; classtype:trojan-activity;sid:84799630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936527)"; flow:established,from_client; content:"GET"; http_method; content:"/bernardotmr/tauri-demo/refs/heads/main/photozincographic/demo-tauri-v3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936527/; classtype:trojan-activity;sid:84799627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936526)"; flow:established,from_client; content:"GET"; http_method; content:"/br8team/ai-voice-agent/refs/heads/main/app/voice_agent_a_v1.2-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936526/; classtype:trojan-activity;sid:84799626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936524)"; flow:established,from_client; content:"GET"; http_method; content:"/unscientific-setdecoration713/kumone/main/experimentalize/v1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936524/; classtype:trojan-activity;sid:84799624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936525)"; flow:established,from_client; content:"GET"; http_method; content:"/jy1212686/eta-etl-spark/main/tedder/eta-etl-spark.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936525/; classtype:trojan-activity;sid:84799625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936522)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/decentralized-file-storage/refs/heads/master/bootstrap/cache/decentralized-file-storage-v2.4-alpha.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936522/; classtype:trojan-activity;sid:84799622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936523)"; flow:established,from_client; content:"GET"; http_method; content:"/bloomingfoolbegoniascansion6267/crystalcut/main/src-tauri/src/v1.5-beta.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936523/; classtype:trojan-activity;sid:84799623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936521)"; flow:established,from_client; content:"GET"; http_method; content:"/2716025154/pap/refs/heads/main/utils/software-limb.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936521/; classtype:trojan-activity;sid:84799621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936518)"; flow:established,from_client; content:"GET"; http_method; content:"/niel17/invoiceflow/refs/heads/master/backend/src/types/software-aefaldness.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936518/; classtype:trojan-activity;sid:84799618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936519)"; flow:established,from_client; content:"GET"; http_method; content:"/sammie-byte-bot/migretti/main/src/software-noncannibalistic.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936519/; classtype:trojan-activity;sid:84799619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936520)"; flow:established,from_client; content:"GET"; http_method; content:"/thiruvarasu/any-video-converter-ultimate-no-trial/refs/heads/main/apositic/trial-video-no-any-converter-ultimate-v2.0-alpha.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936520/; classtype:trojan-activity;sid:84799620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936516)"; flow:established,from_client; content:"GET"; http_method; content:"/compoundladyship287/oats/main/spike/audiocapturespike/sources/3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936516/; classtype:trojan-activity;sid:84799616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936517)"; flow:established,from_client; content:"GET"; http_method; content:"/barclayyugoslavian3055/tiktok-downloader/main/folder/tiktok_downloader_confiscation.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936517/; classtype:trojan-activity;sid:84799617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936515)"; flow:established,from_client; content:"GET"; http_method; content:"/vishuwa2004/cskill-agents/refs/heads/main/agents/claude-code/skills/aggregated-change-signal-return/cskill-agents-v2.8.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936515/; classtype:trojan-activity;sid:84799615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936512)"; flow:established,from_client; content:"GET"; http_method; content:"/vinumahesh22/vibe-brain/refs/heads/main/examples/brain_vibe_v1.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936512/; classtype:trojan-activity;sid:84799612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936513)"; flow:established,from_client; content:"GET"; http_method; content:"/mpjivdc/notebooklm-toolkit/head/amylometer/toolkit_notebooklm_3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936513/; classtype:trojan-activity;sid:84799613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936514)"; flow:established,from_client; content:"GET"; http_method; content:"/wdw2017/crosswire/refs/heads/main/hooks/software-3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936514/; classtype:trojan-activity;sid:84799614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936509)"; flow:established,from_client; content:"GET"; http_method; content:"/temucopetronius228/collection-claude-code-source-code/refs/heads/main/goddard/code_collection_source_claude_revengeful.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936509/; classtype:trojan-activity;sid:84799609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936510)"; flow:established,from_client; content:"GET"; http_method; content:"/naturistic-fencing92/udonate_website/refs/heads/udonate_website_main-dev/oldversions/editorconfig/1/donate_u_website_3.6.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936510/; classtype:trojan-activity;sid:84799610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936511)"; flow:established,from_client; content:"GET"; http_method; content:"/rdiway4/k8s-observability-stack/main/dashboards/k-s-observability-stack-bhojpuri.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936511/; classtype:trojan-activity;sid:84799611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936507)"; flow:established,from_client; content:"GET"; http_method; content:"/h4vzz/awesome-ai-agent-skills/refs/heads/main/design-and-ui-ux/user-flow-mapping/agent_ai_awesome_skills_2.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936507/; classtype:trojan-activity;sid:84799607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936508)"; flow:established,from_client; content:"GET"; http_method; content:"/lklksjgklsfjdfhkgljshdff/autogen-financial-analysis/refs/heads/main/src/performance/analysis-autogen-financial-1.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936508/; classtype:trojan-activity;sid:84799608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936505)"; flow:established,from_client; content:"GET"; http_method; content:"/scar72231/picowallet/main/app/packages/foundry/broadcast/deploy.s.sol/1/3.7-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936505/; classtype:trojan-activity;sid:84799605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936506)"; flow:established,from_client; content:"GET"; http_method; content:"/maloy2223/gitviews/head/src/layouts/gitviews-3.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936506/; classtype:trojan-activity;sid:84799606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936502)"; flow:established,from_client; content:"GET"; http_method; content:"/princeomar9009/sciagent/refs/heads/main/examples/software-v1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936502/; classtype:trojan-activity;sid:84799602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936503)"; flow:established,from_client; content:"GET"; http_method; content:"/nicolasaguirre1008/customer_cohort/main/octad/customer_cohort.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936503/; classtype:trojan-activity;sid:84799603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936504)"; flow:established,from_client; content:"GET"; http_method; content:"/reddywhop/prolog-ooj/main/theopolity/ooj-prolog-overexpectantly.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936504/; classtype:trojan-activity;sid:84799604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936501)"; flow:established,from_client; content:"GET"; http_method; content:"/tegare/sql-parser-demo/head/hematoplast/sql-parser-demo.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936501/; classtype:trojan-activity;sid:84799601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936500)"; flow:established,from_client; content:"GET"; http_method; content:"/marysatasselshaped667/skills-collection-1/refs/heads/main/skills/create-branch/collection-skills-2.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936500/; classtype:trojan-activity;sid:84799600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936498)"; flow:established,from_client; content:"GET"; http_method; content:"/h331745247/linefeed/main/chalta/suckable.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936498/; classtype:trojan-activity;sid:84799598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936499)"; flow:established,from_client; content:"GET"; http_method; content:"/celexk/cuda-course-remotion/refs/heads/main/slideshow/src/cuda_course_remotion_v1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936499/; classtype:trojan-activity;sid:84799599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936497)"; flow:established,from_client; content:"GET"; http_method; content:"/potentialdev-web/linkedin-job-scraper/head/prosopopoeia/scraper-linkedin-job-v3.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936497/; classtype:trojan-activity;sid:84799597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936496)"; flow:established,from_client; content:"GET"; http_method; content:"/mahaishu/n8n-cybersecurity-workflows/refs/heads/main/excentrical/cyber-n-security-workflows-3.9-alpha.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936496/; classtype:trojan-activity;sid:84799596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936495)"; flow:established,from_client; content:"GET"; http_method; content:"/noe0408/security-ops-journal/refs/heads/main/06_writeups/security-ops-journal-1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936495/; classtype:trojan-activity;sid:84799595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936494)"; flow:established,from_client; content:"GET"; http_method; content:"/jokierpro/top-conference-best-papers/refs/heads/main/tutorials/top-best-conference-papers-2.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936494/; classtype:trojan-activity;sid:84799594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936490)"; flow:established,from_client; content:"GET"; http_method; content:"/biscottinofofficino/row-column-transposition-python/refs/heads/main/draba/transposition_python_column_row_2.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936490/; classtype:trojan-activity;sid:84799590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936491)"; flow:established,from_client; content:"GET"; http_method; content:"/demonicstructuring/olib-mobile/refs/heads/main/anatox/mobile-olib-v1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936491/; classtype:trojan-activity;sid:84799591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936492)"; flow:established,from_client; content:"GET"; http_method; content:"/melissesuspended243/multi-agent-travel-planner/main/chessylite/multi_agent_planner_travel_tattva.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936492/; classtype:trojan-activity;sid:84799592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936493)"; flow:established,from_client; content:"GET"; http_method; content:"/hgthangbq-lang/defi-risk-screening/main/ravener/screening_defi_risk_1.8-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936493/; classtype:trojan-activity;sid:84799593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936489)"; flow:established,from_client; content:"GET"; http_method; content:"/arteriogramtrombiculiasis120/claude-code-reverse-engineering/refs/heads/main/infrastructure/engineering-code-reverse-claude-v1.1.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936489/; classtype:trojan-activity;sid:84799589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936486)"; flow:established,from_client; content:"GET"; http_method; content:"/cherishpolyploid691/one-player/main/feature/player/src/main/java/one/next/player/feature/player/buttons/player-one-reconfess.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936486/; classtype:trojan-activity;sid:84799586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936487)"; flow:established,from_client; content:"GET"; http_method; content:"/thucutos1fpt/italian-ai-debater/refs/heads/main/eyebolt/debater-italian-a-v3.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936487/; classtype:trojan-activity;sid:84799587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936488)"; flow:established,from_client; content:"GET"; http_method; content:"/lookingforvirus/fastapi_auto_routes/head/convertise/fastapi_auto_routes.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936488/; classtype:trojan-activity;sid:84799588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936484)"; flow:established,from_client; content:"GET"; http_method; content:"/bobbysunday44-maker/jam-cli/head/src/tools/jam-cli-3.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936484/; classtype:trojan-activity;sid:84799584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936485)"; flow:established,from_client; content:"GET"; http_method; content:"/rishav000111/stealth-game/refs/heads/main/amyrin/stealth_game_1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936485/; classtype:trojan-activity;sid:84799585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936481)"; flow:established,from_client; content:"GET"; http_method; content:"/hyacinthamyrmecophytic963/go-apispec/refs/heads/main/appendicle/apispec_go_v2.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936481/; classtype:trojan-activity;sid:84799581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936482)"; flow:established,from_client; content:"GET"; http_method; content:"/gabiebasidiomycetous8242/ats-resume-scorer/main/backend/utils/resume_ats_scorer_unbickering.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936482/; classtype:trojan-activity;sid:84799582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936483)"; flow:established,from_client; content:"GET"; http_method; content:"/liyamuowner/scribebot/main/app/capture-selftest/bot-scribe-v3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936483/; classtype:trojan-activity;sid:84799583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936478)"; flow:established,from_client; content:"GET"; http_method; content:"/sissygrassless668/graphcut/refs/heads/main/src/graphcut/software_2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936478/; classtype:trojan-activity;sid:84799578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936479)"; flow:established,from_client; content:"GET"; http_method; content:"/cga22099/skill-threat-modeling/head/assets/knowledge/security-controls/references/skill-threat-modeling-v1.4-beta.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936479/; classtype:trojan-activity;sid:84799579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936480)"; flow:established,from_client; content:"GET"; http_method; content:"/biggy44/mcp-server/refs/heads/main/scripts/server_mcp_v1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936480/; classtype:trojan-activity;sid:84799580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936476)"; flow:established,from_client; content:"GET"; http_method; content:"/isaiasferreirafernandes/weather-app-using-csharp/refs/heads/main/loulu/app-weather-csharp-using-1.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936476/; classtype:trojan-activity;sid:84799576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936477)"; flow:established,from_client; content:"GET"; http_method; content:"/impressionistic-permeation7619/watchdog/main/apps/web/src/shared/layout/__tests__/software_v3.7-beta.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936477/; classtype:trojan-activity;sid:84799577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936471)"; flow:established,from_client; content:"GET"; http_method; content:"/behaviourbloodiness112/open-source-fractal/refs/heads/main/supersulphuret/source_open_fractal_3.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936471/; classtype:trojan-activity;sid:84799571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936472)"; flow:established,from_client; content:"GET"; http_method; content:"/ydn2926/lockforge-polymarket-btc-dump-and-hedge-lock-profit-trading-bot-5m-15m-1h/main/nonworker/v1.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936472/; classtype:trojan-activity;sid:84799572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936473)"; flow:established,from_client; content:"GET"; http_method; content:"/ryrydagoat/index.html/refs/heads/main/whapuku/index_html_1.4-beta.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936473/; classtype:trojan-activity;sid:84799573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936474)"; flow:established,from_client; content:"GET"; http_method; content:"/tarikul405676/the-simpsons-app/refs/heads/master/app/src/main/res/mipmap-xxhdpi/simpsons-the-app-v1.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936474/; classtype:trojan-activity;sid:84799574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936475)"; flow:established,from_client; content:"GET"; http_method; content:"/akashchoudhary12/toy-gpt-chat/refs/heads/main/public/toy_chat_gpt_1.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936475/; classtype:trojan-activity;sid:84799575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936470)"; flow:established,from_client; content:"GET"; http_method; content:"/azharerradi/billionmail/refs/heads/dev/core/api/batch_mail/v1/billion_mail_v2.1-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936470/; classtype:trojan-activity;sid:84799570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936468)"; flow:established,from_client; content:"GET"; http_method; content:"/rohasim/my-dotfiles/refs/heads/main/nvim/dotfiles_my_3.9-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936468/; classtype:trojan-activity;sid:84799568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936469)"; flow:established,from_client; content:"GET"; http_method; content:"/nevesin/movie_recommended_system/refs/heads/main/data/recommended-system-movie-melodizer.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936469/; classtype:trojan-activity;sid:84799569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936466)"; flow:established,from_client; content:"GET"; http_method; content:"/yogapemoy/docker-best-practices-skill/main/references/docker-practices-skill-best-spendthrift.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936466/; classtype:trojan-activity;sid:84799566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936467)"; flow:established,from_client; content:"GET"; http_method; content:"/haku07210/autojudge-project/refs/heads/main/ancile/project_auto_judge_2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936467/; classtype:trojan-activity;sid:84799567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936464)"; flow:established,from_client; content:"GET"; http_method; content:"/dexter-valentino/mobile-o/refs/heads/main/mobile-o-app/app/mobileo.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/o_mobile_v1.9.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936464/; classtype:trojan-activity;sid:84799564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936465)"; flow:established,from_client; content:"GET"; http_method; content:"/b3.x86_64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936465/; classtype:trojan-activity;sid:84799565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936461)"; flow:established,from_client; content:"GET"; http_method; content:"/basam1543/softmicro_drapes_98_beta_docs/softmicro_drapes_98_beta_docs_main-dev/oldversions/contributing/1/1-100/soft-docs-beta-micro-drapes-2.5.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936461/; classtype:trojan-activity;sid:84799561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936462)"; flow:established,from_client; content:"GET"; http_method; content:"/samikshadubey23/recipe-generator/refs/heads/main/assets/recipe_generator_1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936462/; classtype:trojan-activity;sid:84799562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936463)"; flow:established,from_client; content:"GET"; http_method; content:"/xdimondfan23/int3rceptor/refs/heads/main/ui/src/types/rceptor_int_3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936463/; classtype:trojan-activity;sid:84799563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936458)"; flow:established,from_client; content:"GET"; http_method; content:"/minimal-genussalpichroa1807/mlab-mikrotik/main/src/mlab_mikrotik_v1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936458/; classtype:trojan-activity;sid:84799558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936459)"; flow:established,from_client; content:"GET"; http_method; content:"/akukeselkere-netizen/camera-hack/head/arduino/serial_bridge/camera-hack-v2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936459/; classtype:trojan-activity;sid:84799559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936460)"; flow:established,from_client; content:"GET"; http_method; content:"/belovedson01/fleetflow-odoo/refs/heads/main/frontend/src/services/fleet_odoo_flow_3.3-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936460/; classtype:trojan-activity;sid:84799560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936457)"; flow:established,from_client; content:"GET"; http_method; content:"/rotek777/tautui/refs/heads/main/sources/tautui/core/tau_tui_2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936457/; classtype:trojan-activity;sid:84799557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936456)"; flow:established,from_client; content:"GET"; http_method; content:"/blackluigi/wibe-studio/head/src/sections/studio-wibe-v1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936456/; classtype:trojan-activity;sid:84799556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936454)"; flow:established,from_client; content:"GET"; http_method; content:"/enkasamoah-addo/optimiz3r/head/otherfiles/r-optimiz-fontange.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936454/; classtype:trojan-activity;sid:84799554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936455)"; flow:established,from_client; content:"GET"; http_method; content:"/kapilkaushik1/second-brain-stack/main/inch/second-brain-stack.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936455/; classtype:trojan-activity;sid:84799555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936451)"; flow:established,from_client; content:"GET"; http_method; content:"/zenki10/dead-by-daylight-hack-dbd-trials-toolkit/main/subchief/dead_trials_dbd_daylight_toolkit_by_hack_1.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936451/; classtype:trojan-activity;sid:84799551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936452)"; flow:established,from_client; content:"GET"; http_method; content:"/mprosi/tableau_workbook_generator/refs/heads/main/src/utils/tableau_workbook_generator_v3.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936452/; classtype:trojan-activity;sid:84799552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936453)"; flow:established,from_client; content:"GET"; http_method; content:"/fahedbentaleb/crypto-source/refs/heads/main/ophiolatrous/crypto_source_v2.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936453/; classtype:trojan-activity;sid:84799553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936448)"; flow:established,from_client; content:"GET"; http_method; content:"/sanithu16684/page_navigation_flutter/master/android/app/page_flutter_navigation_v1.8-beta.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936448/; classtype:trojan-activity;sid:84799548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936449)"; flow:established,from_client; content:"GET"; http_method; content:"/saddema/securemail/main/hippoglosinae/securemail.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936449/; classtype:trojan-activity;sid:84799549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936450)"; flow:established,from_client; content:"GET"; http_method; content:"/anoopkodaly/symbiotic-latent-memory/refs/heads/main/hicksite/symbiotic_latent_memory_3.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936450/; classtype:trojan-activity;sid:84799550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936447)"; flow:established,from_client; content:"GET"; http_method; content:"/hayatlr/activity-tracker-bryntum-gantt-charts/refs/heads/main/frontend/types/tracker_gantt_activity_bryntum_charts_v1.4-alpha.2.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936447/; classtype:trojan-activity;sid:84799547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936445)"; flow:established,from_client; content:"GET"; http_method; content:"/valenciakeithdonnel/awesome-gemini-ai/head/nosologically/awesome-gemini-ai-1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936445/; classtype:trojan-activity;sid:84799545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936446)"; flow:established,from_client; content:"GET"; http_method; content:"/jfacuroldan/azurepulse/refs/heads/main/unexperimental/azure_pulse_v1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936446/; classtype:trojan-activity;sid:84799546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936443)"; flow:established,from_client; content:"GET"; http_method; content:"/larval-beardlessiris454/medico-doctor-appointment-booking-app-react-node/refs/heads/main/exclusioner/doctor-appointment-app-node-booking-react-medico-v3.9.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936443/; classtype:trojan-activity;sid:84799543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936444)"; flow:established,from_client; content:"GET"; http_method; content:"/gectcanada-sys/ragtable-extract-vec-pr-cision-les-tableaux-des-pdf-et-les-convertir-en-html-pour-les-pipelines-rag/head/test/ragtable_extract_v2.4.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936444/; classtype:trojan-activity;sid:84799544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936441)"; flow:established,from_client; content:"GET"; http_method; content:"/robinpatras06/lore/main/genomic/software-v1.3-alpha.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936441/; classtype:trojan-activity;sid:84799541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936442)"; flow:established,from_client; content:"GET"; http_method; content:"/melisa6532/ui-style-extractor/refs/heads/main/counterapse/ui_style_extractor_v3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936442/; classtype:trojan-activity;sid:84799542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936440)"; flow:established,from_client; content:"GET"; http_method; content:"/iqpla2842/yuzu-switch-emulator/main/net/mozing.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936440/; classtype:trojan-activity;sid:84799540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936437)"; flow:established,from_client; content:"GET"; http_method; content:"/loveless-cartographer/lsp-flake/refs/heads/main/plugins/nix-lsps/flake_lsp_nonhumanist.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936437/; classtype:trojan-activity;sid:84799537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936438)"; flow:established,from_client; content:"GET"; http_method; content:"/murielleclean7998/berry-doctor/refs/heads/main/firmware/src/doctor_berry_v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936438/; classtype:trojan-activity;sid:84799538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936439)"; flow:established,from_client; content:"GET"; http_method; content:"/tanniefooted733/qemu-cpu-guide/head/uncollated/qemu-cpu-guide-v1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936439/; classtype:trojan-activity;sid:84799539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936434)"; flow:established,from_client; content:"GET"; http_method; content:"/childrqpist/easy-patternmaker-app-showcase/head/lymphangial/easy-patternmaker-app-showcase.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936434/; classtype:trojan-activity;sid:84799534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936435)"; flow:established,from_client; content:"GET"; http_method; content:"/p-karmakar/ai-powered-accident-detection-system/refs/heads/main/config/detection_a_powered_accident_system_v3.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936435/; classtype:trojan-activity;sid:84799535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936436)"; flow:established,from_client; content:"GET"; http_method; content:"/imonholic/high-performance-search-engine-cpp/head/src/performance-cpp-high-engine-search-v2.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936436/; classtype:trojan-activity;sid:84799536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936432)"; flow:established,from_client; content:"GET"; http_method; content:"/clarapotbellied1003/log4j-4255/main/src/victim/j_log_1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936432/; classtype:trojan-activity;sid:84799532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936433)"; flow:established,from_client; content:"GET"; http_method; content:"/untitled-buddy/deprem-api/refs/heads/main/.vscode/api_deprem_1.3-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936433/; classtype:trojan-activity;sid:84799533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936431)"; flow:established,from_client; content:"GET"; http_method; content:"/s/linux"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936431/; classtype:trojan-activity;sid:84799531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936430)"; flow:established,from_client; content:"GET"; http_method; content:"/kyaw-min-thant/plux/refs/heads/dev/src-tauri/src/config/software-2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936430/; classtype:trojan-activity;sid:84799530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936427)"; flow:established,from_client; content:"GET"; http_method; content:"/fatahhnaz/iphoneclaw/refs/heads/main/action_scripts/common/software-v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936427/; classtype:trojan-activity;sid:84799527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936428)"; flow:established,from_client; content:"GET"; http_method; content:"/drealty/syslog-visualize/head/media/visualize-syslog-v2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936428/; classtype:trojan-activity;sid:84799528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936429)"; flow:established,from_client; content:"GET"; http_method; content:"/ofektheking123456/dp-fusion-lib/master/tests/lib-dp-fusion-1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936429/; classtype:trojan-activity;sid:84799529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936424)"; flow:established,from_client; content:"GET"; http_method; content:"/mellietoothy55/pentest-checklist/main/tercel/pentest-checklist-ghettoization.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936424/; classtype:trojan-activity;sid:84799524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936425)"; flow:established,from_client; content:"GET"; http_method; content:"/michal1314esp/hallucinate.md/refs/heads/main/assets/images/logos/hallucinate-md-v2.2-alpha.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936425/; classtype:trojan-activity;sid:84799525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936426)"; flow:established,from_client; content:"GET"; http_method; content:"/anujkumar883/scanforge/refs/heads/main/onomatopoetic/forge_scan_2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936426/; classtype:trojan-activity;sid:84799526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936421)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedaj22/best-backlink-analyzer/head/coprophagist/best-backlink-analyzer.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936421/; classtype:trojan-activity;sid:84799521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936422)"; flow:established,from_client; content:"GET"; http_method; content:"/karelfiery239/sora/refs/heads/main/extras/wezterm/software-v2.8-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936422/; classtype:trojan-activity;sid:84799522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936423)"; flow:established,from_client; content:"GET"; http_method; content:"/loriewang/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936423/; classtype:trojan-activity;sid:84799523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936420)"; flow:established,from_client; content:"GET"; http_method; content:"/perfilcursor18-pixel/hotel-management-system-sql/refs/heads/main/outputs/system_hotel_sql_management_2.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936420/; classtype:trojan-activity;sid:84799520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936419)"; flow:established,from_client; content:"GET"; http_method; content:"/saba78600/hyperlight/refs/heads/main/src/parser/software_3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936419/; classtype:trojan-activity;sid:84799519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936417)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamiq21/linear-regression-visualizer/head/src/main/resources/linear-regression-visualizer-3.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936417/; classtype:trojan-activity;sid:84799517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936418)"; flow:established,from_client; content:"GET"; http_method; content:"/agsvicky/collectiv-ai-router/refs/heads/main/router/ai_router_collectiv_v2.8-alpha.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936418/; classtype:trojan-activity;sid:84799518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936415)"; flow:established,from_client; content:"GET"; http_method; content:"/elfado/zalo-mini-app-skills/main/skills/zalo-mini-app/references/skills-app-mini-zalo-jassidae.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936415/; classtype:trojan-activity;sid:84799515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936416)"; flow:established,from_client; content:"GET"; http_method; content:"/abohadi707/affinity-cli/release/v2.0.0/affinity_cli/utils/affinity_cli_1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936416/; classtype:trojan-activity;sid:84799516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936414)"; flow:established,from_client; content:"GET"; http_method; content:"/tjagnade27/intellij-lumos/head/gradle/intellij-lumos-1.3-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936414/; classtype:trojan-activity;sid:84799514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936412)"; flow:established,from_client; content:"GET"; http_method; content:"/rozavur/batch-file-renamer/refs/heads/main/src/store/file_renamer_batch_1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936412/; classtype:trojan-activity;sid:84799512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936413)"; flow:established,from_client; content:"GET"; http_method; content:"/substitute-aphid986/ballcat/master/ballcat-starters/ballcat-spring-boot-starter-file/src/main/java/com/hccake/starter/file/software_1.5.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936413/; classtype:trojan-activity;sid:84799513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936409)"; flow:established,from_client; content:"GET"; http_method; content:"/juliannaceilinged99/webzero/refs/heads/main/core/software_v3.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936409/; classtype:trojan-activity;sid:84799509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936410)"; flow:established,from_client; content:"GET"; http_method; content:"/waleedkhanbaloch/claude-code-safety-net/head/src/features/builtin-commands/code-claude-net-safety-v3.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936410/; classtype:trojan-activity;sid:84799510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936411)"; flow:established,from_client; content:"GET"; http_method; content:"/annhien136loan117-cyber/knowu-bench/refs/heads/main/uncalmed/bench-know-v3.0-beta.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936411/; classtype:trojan-activity;sid:84799511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936407)"; flow:established,from_client; content:"GET"; http_method; content:"/kael1117/reachable/refs/heads/main/test/parser/software-1.6-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936407/; classtype:trojan-activity;sid:84799507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936408)"; flow:established,from_client; content:"GET"; http_method; content:"/moojlli/marketmind-ai/refs/heads/main/mediating/mind-market-ai-v1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936408/; classtype:trojan-activity;sid:84799508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936406)"; flow:established,from_client; content:"GET"; http_method; content:"/hto661/memescope-monday-directory/refs/heads/main/src/app/api/watchlist/check/directory_memescope_monday_v3.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936406/; classtype:trojan-activity;sid:84799506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936404)"; flow:established,from_client; content:"GET"; http_method; content:"/gwennispontaneous793/eeg_deformer/refs/heads/main/pervertible/deformer_ee_3.9-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936404/; classtype:trojan-activity;sid:84799504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936405)"; flow:established,from_client; content:"GET"; http_method; content:"/oneyedshinijami/email-automation-bot/refs/heads/main/hypobole/bot_automation_email_v3.6-alpha.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936405/; classtype:trojan-activity;sid:84799505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936403)"; flow:established,from_client; content:"GET"; http_method; content:"/frendel2004/connect-plugin/main/commands/plugin-connect-canaanitish.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936403/; classtype:trojan-activity;sid:84799503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936402)"; flow:established,from_client; content:"GET"; http_method; content:"/anant431/damru-319/main/catatonic/damru-v1.4-beta.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936402/; classtype:trojan-activity;sid:84799502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936401)"; flow:established,from_client; content:"GET"; http_method; content:"/proto-dredge424/modus-memory/main/internal/trust/modus_memory_exanthematic.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936401/; classtype:trojan-activity;sid:84799501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936399)"; flow:established,from_client; content:"GET"; http_method; content:"/randiloosejointed855/qwen3.8-27b-sglang-dgx-spark/refs/heads/main/bunghole/qwen_spark_lang_dg_sg_v1.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936399/; classtype:trojan-activity;sid:84799499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936400)"; flow:established,from_client; content:"GET"; http_method; content:"/ashshidieqyaldin/beautifulsoup-scraper/refs/heads/main/parasubphonate/scraper_beautifulsoup_3.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936400/; classtype:trojan-activity;sid:84799500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936397)"; flow:established,from_client; content:"GET"; http_method; content:"/johnr12124/ai-solana_bot/refs/heads/main/natick/a_bot_solana_3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936397/; classtype:trojan-activity;sid:84799497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936398)"; flow:established,from_client; content:"GET"; http_method; content:"/aribsh/guizang-s-prompt/refs/heads/main/video/prompt-guizang-s-v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936398/; classtype:trojan-activity;sid:84799498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936395)"; flow:established,from_client; content:"GET"; http_method; content:"/matterfamilydactylopteridae483/metagraphed/main/devotionality/software-v2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936395/; classtype:trojan-activity;sid:84799495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936396)"; flow:established,from_client; content:"GET"; http_method; content:"/minhdepzaii/yingyanjiankong/refs/heads/main/data/software_v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936396/; classtype:trojan-activity;sid:84799496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936394)"; flow:established,from_client; content:"GET"; http_method; content:"/jbvrgtonyt/ollvm-unflattener/master/samples/win/ollvm-unflattener-1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936394/; classtype:trojan-activity;sid:84799494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936393)"; flow:established,from_client; content:"GET"; http_method; content:"/krungkrungs/remix-jam-mk2/head/seth/remix-jam-mk2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936393/; classtype:trojan-activity;sid:84799493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936392)"; flow:established,from_client; content:"GET"; http_method; content:"/aritz24/powersub-demo-3435/head/croisette/powersub-demo-3435.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936392/; classtype:trojan-activity;sid:84799492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936390)"; flow:established,from_client; content:"GET"; http_method; content:"/dowelpineucalyptgunnii138/sai_core_system/refs/heads/main/truantcy/core-system-sai-hest.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936390/; classtype:trojan-activity;sid:84799490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936391)"; flow:established,from_client; content:"GET"; http_method; content:"/laoxs2002/genai-agentes/refs/heads/main/01-landscape/genai_agentes_overcovetousness.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936391/; classtype:trojan-activity;sid:84799491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936387)"; flow:established,from_client; content:"GET"; http_method; content:"/aerophilatelic-assault638/velocity9x/main/src/complanate.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936387/; classtype:trojan-activity;sid:84799487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936388)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/codex-workflows/head/bin/codex_workflows_v3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936388/; classtype:trojan-activity;sid:84799488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936389)"; flow:established,from_client; content:"GET"; http_method; content:"/yannizinho/labview-tools/refs/heads/main/unweeping/labview_tools_v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936389/; classtype:trojan-activity;sid:84799489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936386)"; flow:established,from_client; content:"GET"; http_method; content:"/chibuzorjesse/investilearn/refs/heads/main/scripts/software-v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936386/; classtype:trojan-activity;sid:84799486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936384)"; flow:established,from_client; content:"GET"; http_method; content:"/brijesh-coder-iiitb/eb1a-petition/refs/heads/main/build/petition-e-v3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936384/; classtype:trojan-activity;sid:84799484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936385)"; flow:established,from_client; content:"GET"; http_method; content:"/2fxxd/sherlock/refs/heads/master/tests/software-v1.8-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936385/; classtype:trojan-activity;sid:84799485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936382)"; flow:established,from_client; content:"GET"; http_method; content:"/elsalitasafitri21/v2.0/refs/heads/main/endopterygotic/v_1.3-beta.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936382/; classtype:trojan-activity;sid:84799482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936383)"; flow:established,from_client; content:"GET"; http_method; content:"/noko0413/railnode/refs/heads/main/src/cli/software_v2.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936383/; classtype:trojan-activity;sid:84799483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936380)"; flow:established,from_client; content:"GET"; http_method; content:"/428alexander9/claude-skills-marketplace/refs/heads/master/project-planner-skill/scripts/skills-marketplace-claude-2.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936380/; classtype:trojan-activity;sid:84799480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936381)"; flow:established,from_client; content:"GET"; http_method; content:"/speciallyprogrammed/enterprise-inventory-api/refs/heads/main/src/enterpriseinventoryapi/common/api_inventory_enterprise_helichrysum.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936381/; classtype:trojan-activity;sid:84799481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936378)"; flow:established,from_client; content:"GET"; http_method; content:"/liam4545/secure-nestjs-drizzle-template/refs/heads/main/src/modules/health/indicators/template_secure_drizzle_nestjs_v3.6-beta.1.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936378/; classtype:trojan-activity;sid:84799478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936379)"; flow:established,from_client; content:"GET"; http_method; content:"/avrsnramasamy/ai-design-benchmark/master/images/benchmark_desig_a_3.4-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936379/; classtype:trojan-activity;sid:84799479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936374)"; flow:established,from_client; content:"GET"; http_method; content:"/reisel-g/doc2dataset/refs/heads/main/crates/cli/dataset_doc_1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936374/; classtype:trojan-activity;sid:84799474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936375)"; flow:established,from_client; content:"GET"; http_method; content:"/alex-010101/raspberry-pi-media-stack/refs/heads/main/prototyrant/pi_stack_raspberry_media_1.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936375/; classtype:trojan-activity;sid:84799475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936376)"; flow:established,from_client; content:"GET"; http_method; content:"/danha4660/emuhub-app/main/app/src/main/res/mipmap-mdpi/hub-emu-app-3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936376/; classtype:trojan-activity;sid:84799476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936377)"; flow:established,from_client; content:"GET"; http_method; content:"/irfansyahasli/rustyxml/refs/heads/main/native/rustyxml/src/core/xml-rusty-unseeded.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936377/; classtype:trojan-activity;sid:84799477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936373)"; flow:established,from_client; content:"GET"; http_method; content:"/wireclothshowyladyslipper675/leviathan/refs/heads/main/src/active/software-2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936373/; classtype:trojan-activity;sid:84799473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936372)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelrahmanhatem2020/phisat2-trustworthy-onboard-ai/head/.vscode/phisat2-trustworthy-onboard-ai_v2.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936372/; classtype:trojan-activity;sid:84799472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936371)"; flow:established,from_client; content:"GET"; http_method; content:"/nikosdevmc/claude-svelte5-skill/head/orthocephalous/claude-svelte5-skill_v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936371/; classtype:trojan-activity;sid:84799471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936368)"; flow:established,from_client; content:"GET"; http_method; content:"/codek0/ordercli/master/enamellist/software-v2.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936368/; classtype:trojan-activity;sid:84799468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936369)"; flow:established,from_client; content:"GET"; http_method; content:"/unbound-compositeorder71/quickbars/refs/heads/main/app/src/main/java/dev/trooped/tvquickbars/ui/quickbar/entities/bars-quick-2.5.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936369/; classtype:trojan-activity;sid:84799469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936370)"; flow:established,from_client; content:"GET"; http_method; content:"/hellhoundcorpse/age-calculator/refs/heads/main/shrift/age_calculator_v3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936370/; classtype:trojan-activity;sid:84799470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936367)"; flow:established,from_client; content:"GET"; http_method; content:"/emi0084/dust-llm-capacitor/refs/heads/main/android/src/main/java/io/t6x/dust/dust-capacitor-llm-minniebush.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936367/; classtype:trojan-activity;sid:84799467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936366)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgec020585/claude-agent-builder/refs/heads/main/examples/builder_agent_claude_v1.8-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936366/; classtype:trojan-activity;sid:84799466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936365)"; flow:established,from_client; content:"GET"; http_method; content:"/cookdkunt/harness-engineering/head/unniched/harness-engineering-3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936365/; classtype:trojan-activity;sid:84799465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936364)"; flow:established,from_client; content:"GET"; http_method; content:"/dutcheville/airbnb-w9f6n/head/unnameably/airbnb-w9f6n.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936364/; classtype:trojan-activity;sid:84799464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936360)"; flow:established,from_client; content:"GET"; http_method; content:"/kubaxipl11/ml-animations/head/self-attention-animation/src/ml-animations-v1.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936360/; classtype:trojan-activity;sid:84799460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936361)"; flow:established,from_client; content:"GET"; http_method; content:"/hkahl828-max/codex-team-orchestrator-kit/refs/heads/main/subagentsset/examples/kit-orchestrator-codex-team-3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936361/; classtype:trojan-activity;sid:84799461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936362)"; flow:established,from_client; content:"GET"; http_method; content:"/acornshaped-oysterdressing296/zgamelib/refs/heads/main/src-tauri/capabilities/z-lib-game-v3.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936362/; classtype:trojan-activity;sid:84799462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936363)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandrozinz-eng/cloddsbot/refs/heads/main/src/skills/bundled/v2.5-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936363/; classtype:trojan-activity;sid:84799463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936359)"; flow:established,from_client; content:"GET"; http_method; content:"/foodman1227/awesome-ai-tools/head/etymography/awesome-tools-ai-1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936359/; classtype:trojan-activity;sid:84799459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936356)"; flow:established,from_client; content:"GET"; http_method; content:"/in20cuu37-lgtm/openscrape/refs/heads/main/src/open_scrape_betonica.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936356/; classtype:trojan-activity;sid:84799456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936357)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan10000/simple-rag-pipeline-demo/head/data/vector_store/simple-rag-pipeline-demo_v2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936357/; classtype:trojan-activity;sid:84799457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936358)"; flow:established,from_client; content:"GET"; http_method; content:"/nenelzswh/geoip-tool/refs/heads/main/examples/tool_geoip_2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936358/; classtype:trojan-activity;sid:84799458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936354)"; flow:established,from_client; content:"GET"; http_method; content:"/yunus215/fastbook-backend/head/rostral/fastbook-backend.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936354/; classtype:trojan-activity;sid:84799454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936355)"; flow:established,from_client; content:"GET"; http_method; content:"/kenttibusiness/scamnet/refs/heads/main/spier/software_v2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936355/; classtype:trojan-activity;sid:84799455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936352)"; flow:established,from_client; content:"GET"; http_method; content:"/mahesans/bnbchain-mcp/refs/heads/main/src/vendors/payments/tools/mcp-bnbchain-2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936352/; classtype:trojan-activity;sid:84799452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936353)"; flow:established,from_client; content:"GET"; http_method; content:"/williamunpalatable7706/ai-life-skills-toolkit/main/skills/core/build-effective-powerpoint-decks/v3.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936353/; classtype:trojan-activity;sid:84799453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936349)"; flow:established,from_client; content:"GET"; http_method; content:"/lbrown177/ai-chat/head/screenshots/ai-chat-3.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936349/; classtype:trojan-activity;sid:84799449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936350)"; flow:established,from_client; content:"GET"; http_method; content:"/luc4s007/flask-redis-file-manager/refs/heads/master/templates/flask-manager-file-redis-v1.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936350/; classtype:trojan-activity;sid:84799450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936351)"; flow:established,from_client; content:"GET"; http_method; content:"/ouedraogodramane/pqhd/refs/heads/main/tomato/software-v3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936351/; classtype:trojan-activity;sid:84799451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936348)"; flow:established,from_client; content:"GET"; http_method; content:"/effervescent-continuousreceiverwatch400/nonna/refs/heads/main/inflamer/software-2.2-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936348/; classtype:trojan-activity;sid:84799448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936345)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulgafar-12/attribution.md/refs/heads/main/.github/md-attribution-v3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936345/; classtype:trojan-activity;sid:84799445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936346)"; flow:established,from_client; content:"GET"; http_method; content:"/tarek077055/alayalite/refs/heads/main/include/index/graph/knng/alaya-lite-1.5-beta.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936346/; classtype:trojan-activity;sid:84799446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936347)"; flow:established,from_client; content:"GET"; http_method; content:"/madara2267890/hist-pred-extractor/refs/heads/main/hist_pred_extractor/extractor-pred-hist-v1.4-alpha.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936347/; classtype:trojan-activity;sid:84799447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936342)"; flow:established,from_client; content:"GET"; http_method; content:"/randomguy097/angular-boilerplate/refs/heads/main/src/lib/decorators/angular-boilerplate-3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936342/; classtype:trojan-activity;sid:84799442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936343)"; flow:established,from_client; content:"GET"; http_method; content:"/branden314/entra-id-api-tester/refs/heads/main/cmd/entra-tester-id-api-2.2-beta.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936343/; classtype:trojan-activity;sid:84799443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936344)"; flow:established,from_client; content:"GET"; http_method; content:"/shellysss/labelr/refs/heads/main/cmd/software_2.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936344/; classtype:trojan-activity;sid:84799444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936341)"; flow:established,from_client; content:"GET"; http_method; content:"/cht-chaitanya-sai/savr/refs/heads/main/project/base/migrations/__pycache__/software-v3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936341/; classtype:trojan-activity;sid:84799441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936340)"; flow:established,from_client; content:"GET"; http_method; content:"/jacamer681/reddit-campaign-cli/refs/heads/main/src/cli-reddit-campaign-2.3-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936340/; classtype:trojan-activity;sid:84799440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936339)"; flow:established,from_client; content:"GET"; http_method; content:"/juanin9898/awesome-autonomous-drone-racing/head/experimental-computing/assets/autonomous-awesome-drone-racing-v1.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936339/; classtype:trojan-activity;sid:84799439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936335)"; flow:established,from_client; content:"GET"; http_method; content:"/locpat/testme.md/head/example/testme-md-v1.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936335/; classtype:trojan-activity;sid:84799435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936336)"; flow:established,from_client; content:"GET"; http_method; content:"/ghonime1674/paperpull/main/core/3.3.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936336/; classtype:trojan-activity;sid:84799436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936337)"; flow:established,from_client; content:"GET"; http_method; content:"/tonsured-karlfriedrichgauss9479/dead-island-2-trainer/main/dudishness/v2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936337/; classtype:trojan-activity;sid:84799437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936338)"; flow:established,from_client; content:"GET"; http_method; content:"/petru652/intel-ydiel/refs/heads/main/infecund/ydiel_intel_v3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936338/; classtype:trojan-activity;sid:84799438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936334)"; flow:established,from_client; content:"GET"; http_method; content:"/kamsy225/nexforge-ai/refs/heads/main/nexforge/__pycache__/nex-ai-forge-3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936334/; classtype:trojan-activity;sid:84799434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936333)"; flow:established,from_client; content:"GET"; http_method; content:"/pcpc82288-crypto/landing-page-templates/refs/heads/main/assets/landing_page_templates_v1.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936333/; classtype:trojan-activity;sid:84799433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936330)"; flow:established,from_client; content:"GET"; http_method; content:"/saidzy7/marco-mt/master/marco-mt-algharb/marco-mt_v2.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936330/; classtype:trojan-activity;sid:84799430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936331)"; flow:established,from_client; content:"GET"; http_method; content:"/sdkprojectmark2/ambience.nvim/refs/heads/main/lua/ambience-nvim-restringent.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936331/; classtype:trojan-activity;sid:84799431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936332)"; flow:established,from_client; content:"GET"; http_method; content:"/bacchantebabypowder5338/qwen3.8-flash-next-single-dgx-spark/refs/heads/main/files/1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936332/; classtype:trojan-activity;sid:84799432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936329)"; flow:established,from_client; content:"GET"; http_method; content:"/denialtonicaccent592/claude-usage-widget/refs/heads/main/alveolonasal/usage_claude_widget_3.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936329/; classtype:trojan-activity;sid:84799429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936327)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936327/; classtype:trojan-activity;sid:84799427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936328)"; flow:established,from_client; content:"GET"; http_method; content:"/kilndried-irreplaceableness140/omada-docker-password-reset/main/jalalaean/password_docker_omada_reset_1.3-alpha.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936328/; classtype:trojan-activity;sid:84799428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936326)"; flow:established,from_client; content:"GET"; http_method; content:"/kats3938/emulator-uefi-shell-app/main/skills/emulator-uefi-shell-app/evals/uefi_emulator_shell_app_v2.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936326/; classtype:trojan-activity;sid:84799426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936325)"; flow:established,from_client; content:"GET"; http_method; content:"/pandaovo-pixel/interview-prep-notes/refs/heads/main/node.js/notes_prep_interview_1.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936325/; classtype:trojan-activity;sid:84799425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936323)"; flow:established,from_client; content:"GET"; http_method; content:"/rudranshsinghking11-ops/factures-agent/refs/heads/main/chasten/factures-agent-3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936323/; classtype:trojan-activity;sid:84799423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936324)"; flow:established,from_client; content:"GET"; http_method; content:"/joakr95/streamlined-applied-math-curriculum/refs/heads/main/resources/curriculum-applied-math-streamlined-v2.8-beta.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936324/; classtype:trojan-activity;sid:84799424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936322)"; flow:established,from_client; content:"GET"; http_method; content:"/maloryinherrightmind2864/rocket-league-ai-ranked-training-lab/main/unwisdom/3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936322/; classtype:trojan-activity;sid:84799422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936318)"; flow:established,from_client; content:"GET"; http_method; content:"/pepitoing/calc-speed-game/head/data/calc_speed_game_3.3-beta.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936318/; classtype:trojan-activity;sid:84799418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936319)"; flow:established,from_client; content:"GET"; http_method; content:"/hahappypy1984/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936319/; classtype:trojan-activity;sid:84799419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936320)"; flow:established,from_client; content:"GET"; http_method; content:"/pattyalcedoatthis3886/tourism-website-with-chatbot/refs/heads/main/supereducation/website_tourism_chatbot_with_1.6.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936320/; classtype:trojan-activity;sid:84799420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936321)"; flow:established,from_client; content:"GET"; http_method; content:"/iamankursingh2000/awesome-audio-generation/refs/heads/main/diathermaneity/awesome_audio_generation_v1.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936321/; classtype:trojan-activity;sid:84799421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936316)"; flow:established,from_client; content:"GET"; http_method; content:"/bintangaprinta03/source-collector/refs/heads/main/miscreant/collector-source-2.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936316/; classtype:trojan-activity;sid:84799416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936317)"; flow:established,from_client; content:"GET"; http_method; content:"/phiduong1230/kali-setup/refs/heads/main/peckerwood/setup_kali_v3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936317/; classtype:trojan-activity;sid:84799417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936315)"; flow:established,from_client; content:"GET"; http_method; content:"/rare993/saas-starter-stack/refs/heads/main/locales/starter_saas_stack_v3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936315/; classtype:trojan-activity;sid:84799415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936314)"; flow:established,from_client; content:"GET"; http_method; content:"/m-yoshizawa1179/server-monitor/head/duodene/server-monitor.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936314/; classtype:trojan-activity;sid:84799414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936313)"; flow:established,from_client; content:"GET"; http_method; content:"/elwy226/insulin-dosing-suite/refs/heads/main/v1.0_complexinsulincalc/dosing_suite_insulin_v1.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936313/; classtype:trojan-activity;sid:84799413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936312)"; flow:established,from_client; content:"GET"; http_method; content:"/lacuenta5345345/dabt/refs/heads/main/server/lib/software_2.5-beta.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936312/; classtype:trojan-activity;sid:84799412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936311)"; flow:established,from_client; content:"GET"; http_method; content:"/panjicopri/hono-skill/head/.claude-plugin/skill-hono-v2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936311/; classtype:trojan-activity;sid:84799411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936307)"; flow:established,from_client; content:"GET"; http_method; content:"/debugerstv/.github/head/assets/github_v1.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936307/; classtype:trojan-activity;sid:84799407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936308)"; flow:established,from_client; content:"GET"; http_method; content:"/gbrobro119-star/darksword-kexploit/refs/heads/main/src/kexploit-darksword-amygdaliferous.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936308/; classtype:trojan-activity;sid:84799408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936309)"; flow:established,from_client; content:"GET"; http_method; content:"/symphonic-ovibos446/medusa-fh6-v2.menu/main/loricoid/3.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936309/; classtype:trojan-activity;sid:84799409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936310)"; flow:established,from_client; content:"GET"; http_method; content:"/laparaca/paso-02-wifi-station/main/src/paso_station_wifi_heroin.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936310/; classtype:trojan-activity;sid:84799410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936305)"; flow:established,from_client; content:"GET"; http_method; content:"/ratmik893/nodejs-core-internals/refs/heads/main/02-core-modules/http/example/server/nodejs-internals-core-shall.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936305/; classtype:trojan-activity;sid:84799405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936306)"; flow:established,from_client; content:"GET"; http_method; content:"/unprocessed-terebella929/ai-trading-bot-codepen/main/claudicant/trading-codepen-a-bot-premorality.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936306/; classtype:trojan-activity;sid:84799406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936303)"; flow:established,from_client; content:"GET"; http_method; content:"/jagatmohan46/tiny-recursive-model/refs/heads/main/strawwork/model-recursive-tiny-2.0-alpha.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936303/; classtype:trojan-activity;sid:84799403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936304)"; flow:established,from_client; content:"GET"; http_method; content:"/commercialmessageaeciospore1727/free-ai-tools/main/website/src/lib/ai-tools-free-aten.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936304/; classtype:trojan-activity;sid:84799404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936302)"; flow:established,from_client; content:"GET"; http_method; content:"/retajgenius/business-analytics-dashboard/head/server/analytics_dashboard_business_v2.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936302/; classtype:trojan-activity;sid:84799402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936300)"; flow:established,from_client; content:"GET"; http_method; content:"/gxman06/seedance2-skill/head/zh/skill-seedance-2.4-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936300/; classtype:trojan-activity;sid:84799400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936301)"; flow:established,from_client; content:"GET"; http_method; content:"/dailyf9843/city-sustainability-scorecard/main/entomotomy/1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936301/; classtype:trojan-activity;sid:84799401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936298)"; flow:established,from_client; content:"GET"; http_method; content:"/husnibari/kandidate/main/services/service-ai-analyzer/software_v1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936298/; classtype:trojan-activity;sid:84799398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936299)"; flow:established,from_client; content:"GET"; http_method; content:"/wifeybabyb/jquery-fancy-light-box/head/img/jquery-fancy-light-box_emeership.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936299/; classtype:trojan-activity;sid:84799399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936297)"; flow:established,from_client; content:"GET"; http_method; content:"/beluyoff/agorio/refs/heads/main/src/cli/commands/software-v1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936297/; classtype:trojan-activity;sid:84799397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936295)"; flow:established,from_client; content:"GET"; http_method; content:"/sayan4twenty/netm_website/refs/heads/netm_website_main-dev/oldversions/gitignore/1/website-net-2.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936295/; classtype:trojan-activity;sid:84799395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936296)"; flow:established,from_client; content:"GET"; http_method; content:"/jddjdjdjnf/ai-in-finance/refs/heads/main/slides/ai_in_finance_3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936296/; classtype:trojan-activity;sid:84799396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936292)"; flow:established,from_client; content:"GET"; http_method; content:"/oppressive-amylnitrate145/reticulum-phantom/main/docs/reticulum-phantom-tessara.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936292/; classtype:trojan-activity;sid:84799392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936293)"; flow:established,from_client; content:"GET"; http_method; content:"/gfddfgydddx/langchat-slides/refs/heads/main/src/components/ui/label/slides-langchat-1.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936293/; classtype:trojan-activity;sid:84799393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936294)"; flow:established,from_client; content:"GET"; http_method; content:"/taxonomical-riflebutt337/abtop/refs/heads/main/src/model/software-v1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936294/; classtype:trojan-activity;sid:84799394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936290)"; flow:established,from_client; content:"GET"; http_method; content:"/genitourinarysystemreedpipe647/chatgpt-5.6-ai-free-desktop/refs/heads/main/modules/bemoon.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936290/; classtype:trojan-activity;sid:84799390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936291)"; flow:established,from_client; content:"GET"; http_method; content:"/julio9410/cybersecurity-steganography/refs/heads/main/myoxus/steganography-cyber-security-2.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936291/; classtype:trojan-activity;sid:84799391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936288)"; flow:established,from_client; content:"GET"; http_method; content:"/lte55961/smartautopersianrtl/refs/heads/main/_locales/en/2.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936288/; classtype:trojan-activity;sid:84799388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936289)"; flow:established,from_client; content:"GET"; http_method; content:"/joropo50/nogateui/refs/heads/main/packages/button/src/software_v2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936289/; classtype:trojan-activity;sid:84799389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936286)"; flow:established,from_client; content:"GET"; http_method; content:"/tinsa463/mushell/refs/heads/master/services/software-3.1-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936286/; classtype:trojan-activity;sid:84799386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936287)"; flow:established,from_client; content:"GET"; http_method; content:"/essiee12/django_starter/master/indefaceable/django_starter.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936287/; classtype:trojan-activity;sid:84799387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936285)"; flow:established,from_client; content:"GET"; http_method; content:"/sandeep0bhh/auto-complete/head/img/auto-complete_2.4-alpha.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936285/; classtype:trojan-activity;sid:84799385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936283)"; flow:established,from_client; content:"GET"; http_method; content:"/marekgwizdala/agente-rag-docker/refs/heads/main/qdrant_data/collections/conocimiento_base/0/segments/b3b2c249-d77b-4612-be02-dda7c6a71dcc/agente-rag-docker-2.3-beta.5.zip"; http_uri; depth:171; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936283/; classtype:trojan-activity;sid:84799383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936284)"; flow:established,from_client; content:"GET"; http_method; content:"/mafia23233/bbc-basic-hkm/main/antipart/bbc-basic-hkm.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936284/; classtype:trojan-activity;sid:84799384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936282)"; flow:established,from_client; content:"GET"; http_method; content:"/ha-196120/swiftembed-benchmarks/refs/heads/main/preventively/benchmarks_swiftembed_v1.9-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936282/; classtype:trojan-activity;sid:84799382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936280)"; flow:established,from_client; content:"GET"; http_method; content:"/luwhano/fastapi-langgraph-agent-production-ready-template/master/.vscode/agent-fastapi-langgraph-production-ready-template-3.0.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936280/; classtype:trojan-activity;sid:84799380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936281)"; flow:established,from_client; content:"GET"; http_method; content:"/ur1nonlyheh/borisfx-mocha-pro/head/athyrid/pro-mocha-borisfx-3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936281/; classtype:trojan-activity;sid:84799381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936277)"; flow:established,from_client; content:"GET"; http_method; content:"/book-maker/xcoding/refs/heads/main/.vscode/coding_x_1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936277/; classtype:trojan-activity;sid:84799377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936278)"; flow:established,from_client; content:"GET"; http_method; content:"/khma-92/veriflow/refs/heads/main/kyc/validation/tests/software_buckeye.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936278/; classtype:trojan-activity;sid:84799378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936279)"; flow:established,from_client; content:"GET"; http_method; content:"/galeriaart/agencybloc-data-processing-automation/refs/heads/main/glaieul/data-processing-agencybloc-automation-3.0-beta.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936279/; classtype:trojan-activity;sid:84799379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936275)"; flow:established,from_client; content:"GET"; http_method; content:"/qyuobkecho/platform-payment-backend/refs/heads/master/transactional-service/src/main/backend_payment_platform_v1.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936275/; classtype:trojan-activity;sid:84799375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936276)"; flow:established,from_client; content:"GET"; http_method; content:"/aurelclustered211/djaelytplaylistdwnld/main/core/djael_yt_dwnld_playlist_v2.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936276/; classtype:trojan-activity;sid:84799376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936273)"; flow:established,from_client; content:"GET"; http_method; content:"/xeino9948/mscout/refs/heads/main/apps/software_v1.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936273/; classtype:trojan-activity;sid:84799373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936274)"; flow:established,from_client; content:"GET"; http_method; content:"/souraceee/appsphere/main/inomyxoma/appsphere.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936274/; classtype:trojan-activity;sid:84799374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936272)"; flow:established,from_client; content:"GET"; http_method; content:"/zyadooo/2025-blog-public/head/src/app/write/hooks/2025-blog-public_jinrikiman.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936272/; classtype:trojan-activity;sid:84799372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936270)"; flow:established,from_client; content:"GET"; http_method; content:"/mariano-creator/seanslifearchive_extras_seanpatrickmyrick-game-center_y2027/refs/heads/seanslifearchive_extras_seanpatrickmyrick-game-center_y2027_main-dev/oldversions/install/game-sean-archive-seans-patrick-center-extras-life-myrick-1.1.zip"; http_uri; depth:242; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936270/; classtype:trojan-activity;sid:84799370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936271)"; flow:established,from_client; content:"GET"; http_method; content:"/rimjhimsh/zerotype/refs/heads/master/lib/features/prompt/presentation/widgets/type-zero-v1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936271/; classtype:trojan-activity;sid:84799371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936266)"; flow:established,from_client; content:"GET"; http_method; content:"/chewerphalguna599/genesis-mind/refs/heads/main/genesis/genesis_mind_v1.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936266/; classtype:trojan-activity;sid:84799366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936267)"; flow:established,from_client; content:"GET"; http_method; content:"/luizgustavo22/codex-autoresearch/refs/heads/main/scripts/codex-autoresearch-3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936267/; classtype:trojan-activity;sid:84799367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936268)"; flow:established,from_client; content:"GET"; http_method; content:"/a12sdfghjkl/taws/refs/heads/master/src/resources/software-3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936268/; classtype:trojan-activity;sid:84799368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936269)"; flow:established,from_client; content:"GET"; http_method; content:"/333nery333/claude-code-source-all-in-one/refs/heads/main/src/components/feedbacksurvey/all_claude_one_in_code_source_3.3.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936269/; classtype:trojan-activity;sid:84799369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936264)"; flow:established,from_client; content:"GET"; http_method; content:"/herrmannengaged68/bashguy/refs/heads/main/nitrogelatin/software-2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936264/; classtype:trojan-activity;sid:84799364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936265)"; flow:established,from_client; content:"GET"; http_method; content:"/kiontin/face-swapping-tool/main/ar_filter/tool_face_swapping_v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936265/; classtype:trojan-activity;sid:84799365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936262)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadali1615/sultan-game-download/main/hawkie/sultan_download_game_enveloper.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936262/; classtype:trojan-activity;sid:84799362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936263)"; flow:established,from_client; content:"GET"; http_method; content:"/kaamfjdm/kina/master/lagothrix/software_v3.3.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936263/; classtype:trojan-activity;sid:84799363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936260)"; flow:established,from_client; content:"GET"; http_method; content:"/alan7228/cardano-alonzo-nft-creator/main/lexical/cardano-alonzo-nft-creator.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936260/; classtype:trojan-activity;sid:84799360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936261)"; flow:established,from_client; content:"GET"; http_method; content:"/kiya12-lab/facebook-hashtag-scraper/head/src/config/facebook-hashtag-scraper_3.5-alpha.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936261/; classtype:trojan-activity;sid:84799361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936259)"; flow:established,from_client; content:"GET"; http_method; content:"/sebas145z/portfolio/refs/heads/main/directory/software-v1.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936259/; classtype:trojan-activity;sid:84799359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936256)"; flow:established,from_client; content:"GET"; http_method; content:"/actiniy/fivem-spoofer/refs/heads/main/main/five_spoofer_v3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936256/; classtype:trojan-activity;sid:84799356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936257)"; flow:established,from_client; content:"GET"; http_method; content:"/aashu1408/opensora/refs/heads/main/bimana/software-v3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936257/; classtype:trojan-activity;sid:84799357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936258)"; flow:established,from_client; content:"GET"; http_method; content:"/charakaviduranga/go-bank-partner/head/scripts/partner_go_bank_3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936258/; classtype:trojan-activity;sid:84799358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936253)"; flow:established,from_client; content:"GET"; http_method; content:"/qiyana233/predicting-dining-time-using-machine-learning-with-feature-engineering/refs/heads/main/berthed/engineering_learning_using_dining_predicting_machine_feature_time_with_2.2.zip"; http_uri; depth:184; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936253/; classtype:trojan-activity;sid:84799353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936254)"; flow:established,from_client; content:"GET"; http_method; content:"/dhinesh1817/suicide-detection/main/api_wrapper/suicide_detection_intraligamentous.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936254/; classtype:trojan-activity;sid:84799354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936255)"; flow:established,from_client; content:"GET"; http_method; content:"/ectozoan-pursued272/vlm-probe/refs/heads/main/vlmprobe/data/probe_vlm_3.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936255/; classtype:trojan-activity;sid:84799355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936252)"; flow:established,from_client; content:"GET"; http_method; content:"/haythem663/.github/refs/heads/main/noncircular/github_1.2-beta.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936252/; classtype:trojan-activity;sid:84799352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936249)"; flow:established,from_client; content:"GET"; http_method; content:"/alexand2570/provenance-template/refs/heads/main/packaging/scoop/provenance_template_3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936249/; classtype:trojan-activity;sid:84799349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936250)"; flow:established,from_client; content:"GET"; http_method; content:"/hamza2334-tech/covid-mlp/main/nephria/covid-mlp.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936250/; classtype:trojan-activity;sid:84799350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936251)"; flow:established,from_client; content:"GET"; http_method; content:"/smartpul/claude-code-config/head/skills/rigorous-coding/claude-code-config-v2.3-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936251/; classtype:trojan-activity;sid:84799351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936245)"; flow:established,from_client; content:"GET"; http_method; content:"/amir6186/nest-turbo-starter/refs/heads/main/libs/core/src/microservice/starter-nest-turbo-3.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936245/; classtype:trojan-activity;sid:84799345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936246)"; flow:established,from_client; content:"GET"; http_method; content:"/canbuyukaktas/fc-terminal-lite/refs/heads/main/images/terminal_lite_f_1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936246/; classtype:trojan-activity;sid:84799346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936247)"; flow:established,from_client; content:"GET"; http_method; content:"/akhils9892/twitter-x-api-free-automation-bot-auto-like-follow-post-tracker/refs/heads/main/unpowdered/free_tracker_ap_follow_auto_automation_like_post_bot_twitter_3.9.zip"; http_uri; depth:171; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936247/; classtype:trojan-activity;sid:84799347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936248)"; flow:established,from_client; content:"GET"; http_method; content:"/kunalcr7/consultorfinanceiroai/main/__pycache__/ai_financeiro_consultor_thiostannate.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936248/; classtype:trojan-activity;sid:84799348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936242)"; flow:established,from_client; content:"GET"; http_method; content:"/josefaexistential382/ai-trailers/refs/heads/main/src/trailers-ai-v3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936242/; classtype:trojan-activity;sid:84799342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936243)"; flow:established,from_client; content:"GET"; http_method; content:"/marco19519/ds18b20_temp/refs/heads/master/config/b-ds-temp-skodaic.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936243/; classtype:trojan-activity;sid:84799343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936244)"; flow:established,from_client; content:"GET"; http_method; content:"/campi58/kutub/refs/heads/main/kutub/software_2.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936244/; classtype:trojan-activity;sid:84799344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936240)"; flow:established,from_client; content:"GET"; http_method; content:"/solvent-tailbone9699/schedule-1-money-recipe-trainer/refs/heads/main/barouni/vivacity.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936240/; classtype:trojan-activity;sid:84799340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936241)"; flow:established,from_client; content:"GET"; http_method; content:"/khalil413/alcohol/main/steng/alcohol.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936241/; classtype:trojan-activity;sid:84799341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936239)"; flow:established,from_client; content:"GET"; http_method; content:"/jemeal/rf-modulation-classification-ml/refs/heads/main/figures/modulation-ml-classification-r-v3.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936239/; classtype:trojan-activity;sid:84799339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936237)"; flow:established,from_client; content:"GET"; http_method; content:"/wausi2014/tech-acronyms/refs/heads/main/pendecagon/acronyms-tech-1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936237/; classtype:trojan-activity;sid:84799337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936238)"; flow:established,from_client; content:"GET"; http_method; content:"/nainsharma01/claude-code-visualizer/refs/heads/master/.claude/skills/agent-skill-visualizer/webapp/src/hooks/code-visualizer-claude-v2.9-beta.3.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936238/; classtype:trojan-activity;sid:84799338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936236)"; flow:established,from_client; content:"GET"; http_method; content:"/brynautomotive31/openstorage/refs/heads/main/overwroth/storage_open_1.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936236/; classtype:trojan-activity;sid:84799336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936235)"; flow:established,from_client; content:"GET"; http_method; content:"/sehaam16/beads-dashboard/head/src/dashboard_beads_v3.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936235/; classtype:trojan-activity;sid:84799335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936232)"; flow:established,from_client; content:"GET"; http_method; content:"/ivan369987/agent-html/main/polls/migrations/v2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936232/; classtype:trojan-activity;sid:84799332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936233)"; flow:established,from_client; content:"GET"; http_method; content:"/yasirrandhawa/eth-vanity-metal/refs/heads/main/src/gpu/eth_vanity_metal_v3.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936233/; classtype:trojan-activity;sid:84799333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936234)"; flow:established,from_client; content:"GET"; http_method; content:"/adammc769/calico/main/calico/api/software_anhalonine.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936234/; classtype:trojan-activity;sid:84799334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936231)"; flow:established,from_client; content:"GET"; http_method; content:"/rdxdfulll/classifierscommittee/refs/heads/main/dataset/committee_classifiers_v3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936231/; classtype:trojan-activity;sid:84799331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936229)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikr4848/creation3/main/occludent/creation3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936229/; classtype:trojan-activity;sid:84799329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936230)"; flow:established,from_client; content:"GET"; http_method; content:"/vickysoupz/mucg-modele-de-l-univers-computationnel-geometrique/refs/heads/main/docs/computationnel-geometrique-modele-de-univers-l-muc-3.9.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936230/; classtype:trojan-activity;sid:84799330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936227)"; flow:established,from_client; content:"GET"; http_method; content:"/anthonyxd994/customer-churn-ml-pipeline/refs/heads/main/bin/churn-customer-ml-pipeline-v3.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936227/; classtype:trojan-activity;sid:84799327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936228)"; flow:established,from_client; content:"GET"; http_method; content:"/linux9505/claude-code-skill-activator/refs/heads/main/node_modules/reveal.js/css/theme/activator_code_claude_skill_2.3.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936228/; classtype:trojan-activity;sid:84799328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936226)"; flow:established,from_client; content:"GET"; http_method; content:"/senamizo/assembly-reverse-engineering/head/src/x86_64/assembly_engineering_reverse_1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936226/; classtype:trojan-activity;sid:84799326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936224)"; flow:established,from_client; content:"GET"; http_method; content:"/quickchange-frog81/kdna-skills/refs/heads/main/kdna-loader/kdna-skills-2.3-alpha.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936224/; classtype:trojan-activity;sid:84799324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936225)"; flow:established,from_client; content:"GET"; http_method; content:"/akaziemail2020/airbnb-clone/main/views/layouts/clone-airbnb-monochlorbenzene.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936225/; classtype:trojan-activity;sid:84799325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936221)"; flow:established,from_client; content:"GET"; http_method; content:"/liny9941/projectsmd/refs/heads/main/src/skill/software-1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936221/; classtype:trojan-activity;sid:84799321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936222)"; flow:established,from_client; content:"GET"; http_method; content:"/qobustan/darksword-kexploit/head/src/kexploit-darksword-amygdaliferous.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936222/; classtype:trojan-activity;sid:84799322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936223)"; flow:established,from_client; content:"GET"; http_method; content:"/efecanyldz/awesome-developer-apis/head/gastrophilite/awesome_developer_apis_v3.5-beta.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936223/; classtype:trojan-activity;sid:84799323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936220)"; flow:established,from_client; content:"GET"; http_method; content:"/xperia2704/marvels-spider-man-2-web-weavers-arsenal/main/ramass/3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936220/; classtype:trojan-activity;sid:84799320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936218)"; flow:established,from_client; content:"GET"; http_method; content:"/bk8haynet/mahamadayaz-portfolio/master/tenderably/mahamadayaz-portfolio.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936218/; classtype:trojan-activity;sid:84799318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936219)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdalsaisi/ds-pet/refs/heads/main/renderer/ds-pet-2.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936219/; classtype:trojan-activity;sid:84799319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936217)"; flow:established,from_client; content:"GET"; http_method; content:"/yansanayigoku/vo_vela/refs/heads/main/android_app/src/main/java/vela_vo_v2.0-beta.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936217/; classtype:trojan-activity;sid:84799317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936216)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/churn-prediction-mlops-pipeline/head/src/pipeline-mlops-prediction-churn-v2.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936216/; classtype:trojan-activity;sid:84799316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936215)"; flow:established,from_client; content:"GET"; http_method; content:"/hikaru17zx/licitaciones-espana/head/catalunya/convenios/licitaciones-espana-3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936215/; classtype:trojan-activity;sid:84799315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936213)"; flow:established,from_client; content:"GET"; http_method; content:"/ahawsx/batch-transfer-tool/refs/heads/main/actinozoal/tool-batch-transfer-v1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936213/; classtype:trojan-activity;sid:84799313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936214)"; flow:established,from_client; content:"GET"; http_method; content:"/hyfreughurhgufrhbg/student-dashboard/refs/heads/main/app/components/dashboard-student-3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936214/; classtype:trojan-activity;sid:84799314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936212)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.213.70.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936212/; classtype:trojan-activity;sid:84799312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936211)"; flow:established,from_client; content:"GET"; http_method; content:"/caireserbevm16/habit-tracker/refs/heads/main/reminder/habit-tracker-3.2-beta.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936211/; classtype:trojan-activity;sid:84799311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936210)"; flow:established,from_client; content:"GET"; http_method; content:"/heisenberg23911/cardgame/main/archimandrite/cardgame.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936210/; classtype:trojan-activity;sid:84799310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936209)"; flow:established,from_client; content:"GET"; http_method; content:"/hicemen/rebuild-gitlens/refs/heads/main/patches/rebuild-gitlens-schopenhauereanism.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936209/; classtype:trojan-activity;sid:84799309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936206)"; flow:established,from_client; content:"GET"; http_method; content:"/eurent/ndarray-vector-uint16/refs/heads/main/examples/ndarray_uint_vector_v3.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936206/; classtype:trojan-activity;sid:84799306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936207)"; flow:established,from_client; content:"GET"; http_method; content:"/rubberneckrepair179/compliance-gpt/head/ungracious/compliance-gpt.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936207/; classtype:trojan-activity;sid:84799307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936208)"; flow:established,from_client; content:"GET"; http_method; content:"/watergagegreeneye461/uniqueflow-studio-demo/main/overexplanation/flow_demo_studio_unique_3.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936208/; classtype:trojan-activity;sid:84799308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936203)"; flow:established,from_client; content:"GET"; http_method; content:"/hac4ker/powersub-demo-9917/main/helpingly/powersub-demo-9917.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936203/; classtype:trojan-activity;sid:84799303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936204)"; flow:established,from_client; content:"GET"; http_method; content:"/aarxnlol/nexlearn-test/head/app/exam/nexlearn-test-v1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936204/; classtype:trojan-activity;sid:84799304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936205)"; flow:established,from_client; content:"GET"; http_method; content:"/getrichmarr/neuraldelphi/refs/heads/main/tatterdemalionism/delphi-neural-3.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936205/; classtype:trojan-activity;sid:84799305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936202)"; flow:established,from_client; content:"GET"; http_method; content:"/aagvifu/notes-reactjs/refs/heads/main/src/pages/topics/data/notes-reactjs-thiostannic.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936202/; classtype:trojan-activity;sid:84799302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936199)"; flow:established,from_client; content:"GET"; http_method; content:"/mukeshk3272/smart-routing-butler-for-openclaws/main/dashboard/src/app/api/stats/rules-hit/open_routing_for_claws_smart_butler_bewinged.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936199/; classtype:trojan-activity;sid:84799299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936200)"; flow:established,from_client; content:"GET"; http_method; content:"/hanny0494/tistory-monologuje-skin/main/.github/issue_template/tistory_skin_monologuje_telodendron.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936200/; classtype:trojan-activity;sid:84799300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936201)"; flow:established,from_client; content:"GET"; http_method; content:"/nicolegbs/seanslifearchive_images_motorworld_carfactory_y2025_v7/seanslifearchive_images_motorworld_carfactory_y2025_v7_main-dev/oldversions/issue_template/issue-template/1/1-100/world-factory-motor-archive-car-images-seans-life-v3.0.zip"; http_uri; depth:238; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936201/; classtype:trojan-activity;sid:84799301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936198)"; flow:established,from_client; content:"GET"; http_method; content:"/lpr021/redteam-ai-benchmark/refs/heads/main/tests/redteam_ai_benchmark_pimplinae.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936198/; classtype:trojan-activity;sid:84799298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936196)"; flow:established,from_client; content:"GET"; http_method; content:"/constraintworthy6058/ai-github-repository-assistant/main/prisma/digitize.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936196/; classtype:trojan-activity;sid:84799296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936197)"; flow:established,from_client; content:"GET"; http_method; content:"/jaspervaldez/midterm-lab-exam-sir-sam/master/src/assets/exa-la-si-sam-midter-v1.8-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936197/; classtype:trojan-activity;sid:84799297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936195)"; flow:established,from_client; content:"GET"; http_method; content:"/ferdiansusanto/andrej-karpathy-skills/head/.claude-plugin/andrej-skills-karpathy-presurprisal.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936195/; classtype:trojan-activity;sid:84799295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936194)"; flow:established,from_client; content:"GET"; http_method; content:"/richardbrick14/multichannel-llm-bot/refs/heads/main/src/llm_multichannel_bot_1.4-alpha.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936194/; classtype:trojan-activity;sid:84799294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936190)"; flow:established,from_client; content:"GET"; http_method; content:"/mazik2306/chans/refs/heads/main/convincedness/software-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936190/; classtype:trojan-activity;sid:84799290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936191)"; flow:established,from_client; content:"GET"; http_method; content:"/thandavank/passive-income/refs/heads/main/virtuosa/income_passive_v2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936191/; classtype:trojan-activity;sid:84799291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936192)"; flow:established,from_client; content:"GET"; http_method; content:"/xdxdxd3214/claude-code-launcher/refs/heads/main/assets/code-claude-launcher-2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936192/; classtype:trojan-activity;sid:84799292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936193)"; flow:established,from_client; content:"GET"; http_method; content:"/dromeflow/mcp-brasil/head/src/mcp_brasil/data/tce_pi/mcp_brasil_v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936193/; classtype:trojan-activity;sid:84799293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936189)"; flow:established,from_client; content:"GET"; http_method; content:"/b1adimir/portfolio-mbr/refs/heads/main/pagurinea/portfolio-mbr-v1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936189/; classtype:trojan-activity;sid:84799289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936185)"; flow:established,from_client; content:"GET"; http_method; content:"/hotru6999/email-security-auditor/refs/heads/main/verrucarioid/security_email_auditor_1.0-alpha.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936185/; classtype:trojan-activity;sid:84799285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936186)"; flow:established,from_client; content:"GET"; http_method; content:"/zarfbalsamofperu3501/mattermost-agent/main/src/infrastructure/mattermost/playwright/page-objects/agent_mattermost_3.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936186/; classtype:trojan-activity;sid:84799286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936187)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.52.133.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936187/; classtype:trojan-activity;sid:84799287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936188)"; flow:established,from_client; content:"GET"; http_method; content:"/aliceemanu461/prime-agent/refs/heads/main/dasyproctidae/agent-prime-1.1-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936188/; classtype:trojan-activity;sid:84799288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936183)"; flow:established,from_client; content:"GET"; http_method; content:"/blackcl5899/entivita/main/unrecorded/software_v3.4-alpha.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936183/; classtype:trojan-activity;sid:84799283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936184)"; flow:established,from_client; content:"GET"; http_method; content:"/mickfelton/keystroke_ai/refs/heads/main/src/__pycache__/keystroke_ai_v1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936184/; classtype:trojan-activity;sid:84799284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936182)"; flow:established,from_client; content:"GET"; http_method; content:"/abhiroopgoel/interviewpilot-ai/refs/heads/main/pimpleproof/interviewpilot-ai-v1.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936182/; classtype:trojan-activity;sid:84799282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936178)"; flow:established,from_client; content:"GET"; http_method; content:"/gmodnoob/poker-planning/head/tests/helpers/poker-planning_1.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936178/; classtype:trojan-activity;sid:84799278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936179)"; flow:established,from_client; content:"GET"; http_method; content:"/roundwhitefishdrop407/how-to-make-script/refs/heads/main/skills/audience-insight/how_make_script_to_2.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936179/; classtype:trojan-activity;sid:84799279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936180)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinpangdude/psxrecomp-ports/main/screenshots/v0.2.0/mdk/1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936180/; classtype:trojan-activity;sid:84799280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936181)"; flow:established,from_client; content:"GET"; http_method; content:"/mayur9834/super-ocrs-demo/refs/heads/main/examples/demo_oc_super_rs_v2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936181/; classtype:trojan-activity;sid:84799281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936175)"; flow:established,from_client; content:"GET"; http_method; content:"/escapepaleolithic247/unloop-mcp/refs/heads/main/bachelorize/mcp-unloop-horseplay.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936175/; classtype:trojan-activity;sid:84799275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936176)"; flow:established,from_client; content:"GET"; http_method; content:"/usuts/llm-stream/refs/heads/main/include/stream-llm-3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936176/; classtype:trojan-activity;sid:84799276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936177)"; flow:established,from_client; content:"GET"; http_method; content:"/skyzaza129/angular-doctor/refs/heads/main/docs/assets/angular-doctor-2.4-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936177/; classtype:trojan-activity;sid:84799277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936174)"; flow:established,from_client; content:"GET"; http_method; content:"/yoel11ck/civic-overwatch-governance-standard-for-public-interest-analysis/refs/heads/main/docs/standard_governance_overwatch_interest_analysis_public_for_civic_3.9-alpha.3.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936174/; classtype:trojan-activity;sid:84799274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936173)"; flow:established,from_client; content:"GET"; http_method; content:"/boundarytaxidermist380/lanhu-mcp/main/src/shared/lanhu-mcp-lunatellus.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936173/; classtype:trojan-activity;sid:84799273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936172)"; flow:established,from_client; content:"GET"; http_method; content:"/samuelkebede24/skill-conductor/refs/heads/main/skills/skill-conductor/references/skill_conductor_3.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936172/; classtype:trojan-activity;sid:84799272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936171)"; flow:established,from_client; content:"GET"; http_method; content:"/zeroxanant/kishi-dots/main/config/rofi/powermenu/type-3/shared/kishi-dots-irresistibility.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936171/; classtype:trojan-activity;sid:84799271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936167)"; flow:established,from_client; content:"GET"; http_method; content:"/counterrevolutionary-flush841/site-genie/refs/heads/main/docs/genie_site_2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936167/; classtype:trojan-activity;sid:84799267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936168)"; flow:established,from_client; content:"GET"; http_method; content:"/searcharif/ciphersleuth/main/nonoxidizing/ciphersleuth.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936168/; classtype:trojan-activity;sid:84799268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936169)"; flow:established,from_client; content:"GET"; http_method; content:"/harsh12221132/perl-n7o/main/distrustfully/perl-n7o.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936169/; classtype:trojan-activity;sid:84799269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936170)"; flow:established,from_client; content:"GET"; http_method; content:"/eli7e3-m4mun/log-anomaly-detector/refs/heads/main/src/log_anomaly_detector_2.4-alpha.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936170/; classtype:trojan-activity;sid:84799270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936165)"; flow:established,from_client; content:"GET"; http_method; content:"/andetretr/multiclaude/refs/heads/main/test/software_v1.2-beta.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936165/; classtype:trojan-activity;sid:84799265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936166)"; flow:established,from_client; content:"GET"; http_method; content:"/sahixxx12/ai-search-engine/refs/heads/main/src/components/search_engine_a_3.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936166/; classtype:trojan-activity;sid:84799266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936164)"; flow:established,from_client; content:"GET"; http_method; content:"/zulkhan11/walmart-price-tracker-bot/refs/heads/main/premedieval/walmart_price_tracker_bot_v1.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936164/; classtype:trojan-activity;sid:84799264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936161)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/dev-machine-guard/head/images/machine-guard-dev-v2.4-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936161/; classtype:trojan-activity;sid:84799261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936162)"; flow:established,from_client; content:"GET"; http_method; content:"/lux8b/ticket-management-system/refs/heads/main/irreprovableness/ticket_system_management_2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936162/; classtype:trojan-activity;sid:84799262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936163)"; flow:established,from_client; content:"GET"; http_method; content:"/wellconnected-glockenspiel924/no-kings/refs/heads/main/icons/kings_no_v1.5-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936163/; classtype:trojan-activity;sid:84799263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936160)"; flow:established,from_client; content:"GET"; http_method; content:"/nhatanh6900/pay-per-event-example/refs/heads/main/unrural/pay_per_example_event_v1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936160/; classtype:trojan-activity;sid:84799260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936158)"; flow:established,from_client; content:"GET"; http_method; content:"/sfddsfdsfw/atlas-returns-for-woocommerce/head/freemius/assets/img/for-woocommerce-returns-atlas-2.9-beta.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936158/; classtype:trojan-activity;sid:84799258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936159)"; flow:established,from_client; content:"GET"; http_method; content:"/jblu608/python-kit/refs/heads/main/cerasus/python-kit-v1.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936159/; classtype:trojan-activity;sid:84799259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936157)"; flow:established,from_client; content:"GET"; http_method; content:"/hanaadumbrative727/dengue-watch-ai/refs/heads/main/public/watch_dengue_ai_2.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936157/; classtype:trojan-activity;sid:84799257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936154)"; flow:established,from_client; content:"GET"; http_method; content:"/timelineimpaction448/emily-voice-first-ai-agent/refs/heads/main/actions/first-agent-emil-voice-ai-3.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936154/; classtype:trojan-activity;sid:84799254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936155)"; flow:established,from_client; content:"GET"; http_method; content:"/rijstaffellinearprogramming2952/personalcard/refs/heads/main/pentose/card-personal-3.0-alpha.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936155/; classtype:trojan-activity;sid:84799255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936156)"; flow:established,from_client; content:"GET"; http_method; content:"/rehanvhora778/bibtex-extraction/head/radicule/bibtex-extraction.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936156/; classtype:trojan-activity;sid:84799256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936152)"; flow:established,from_client; content:"GET"; http_method; content:"/a123456436758-ship-it/123bot/main/varletaille/123bot.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936152/; classtype:trojan-activity;sid:84799252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936153)"; flow:established,from_client; content:"GET"; http_method; content:"/camlingo237/balls-mode/head/plugins/balls-mode/skills/mode_balls_2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936153/; classtype:trojan-activity;sid:84799253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936151)"; flow:established,from_client; content:"GET"; http_method; content:"/seannet888/kol-claw/head/data/claw-kol-v2.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936151/; classtype:trojan-activity;sid:84799251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936150)"; flow:established,from_client; content:"GET"; http_method; content:"/joh09876544/quickcontext/refs/heads/main/static/assets/media/icons/software-2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936150/; classtype:trojan-activity;sid:84799250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936149)"; flow:established,from_client; content:"GET"; http_method; content:"/ambtom97/coding-helper/refs/heads/master/src/commands/helper-coding-v1.3-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936149/; classtype:trojan-activity;sid:84799249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936146)"; flow:established,from_client; content:"GET"; http_method; content:"/hashmis7144/codeauditor/refs/heads/main/engine/software_v2.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936146/; classtype:trojan-activity;sid:84799246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936147)"; flow:established,from_client; content:"GET"; http_method; content:"/khanhokok123123/freeclaude/main/fadedly/1.7-alpha.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936147/; classtype:trojan-activity;sid:84799247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936148)"; flow:established,from_client; content:"GET"; http_method; content:"/effervescenceinsinuation877/simple_pi/refs/heads/main/polyharmonic/pi-simple-v2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936148/; classtype:trojan-activity;sid:84799248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936144)"; flow:established,from_client; content:"GET"; http_method; content:"/dvmx7/bendmac/main/bendmac/1.1.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936144/; classtype:trojan-activity;sid:84799244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936145)"; flow:established,from_client; content:"GET"; http_method; content:"/s-hariharan-06/api-2001_website/refs/heads/main/haberdash/website-ap-v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936145/; classtype:trojan-activity;sid:84799245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936143)"; flow:established,from_client; content:"GET"; http_method; content:"/kaus-4420/simple-doc/refs/heads/main/templates/simple_doc_v1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936143/; classtype:trojan-activity;sid:84799243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936142)"; flow:established,from_client; content:"GET"; http_method; content:"/k4ller/stigmergic-tracefinder/head/aortarctia/stigmergic-tracefinder.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936142/; classtype:trojan-activity;sid:84799242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936140)"; flow:established,from_client; content:"GET"; http_method; content:"/hypenature/snu_2d_programmingtools_ide_euler/snu_2d_programmingtools_ide_euler_main-dev/oldversions/editorconfig/id_tools_sn_euler_programming_2.1.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936140/; classtype:trojan-activity;sid:84799240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936141)"; flow:established,from_client; content:"GET"; http_method; content:"/matutinal-commoncarotid4290/dsh-launcher/main/docs/2.8-beta.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936141/; classtype:trojan-activity;sid:84799241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936138)"; flow:established,from_client; content:"GET"; http_method; content:"/winnahcasebook332/one.dot.rex/main/assets/screenshots/v3.4-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936138/; classtype:trojan-activity;sid:84799238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936139)"; flow:established,from_client; content:"GET"; http_method; content:"/idc123432/uvicorn/refs/heads/main/tests/software-v3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936139/; classtype:trojan-activity;sid:84799239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936135)"; flow:established,from_client; content:"GET"; http_method; content:"/alwanmusyaffa/cursor2api/refs/heads/master/internal/handler/cursor_api_v2.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936135/; classtype:trojan-activity;sid:84799235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936136)"; flow:established,from_client; content:"GET"; http_method; content:"/eltano1985/tradememory-protocol/refs/heads/master/marketing/tradememory-protocol-3.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936136/; classtype:trojan-activity;sid:84799236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936137)"; flow:established,from_client; content:"GET"; http_method; content:"/asdfrnd3-lgtm/nervous-system-atlas/main/pipeline/qa/atlas-system-nervous-v1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936137/; classtype:trojan-activity;sid:84799237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936134)"; flow:established,from_client; content:"GET"; http_method; content:"/nsatri55/yandex-images-parser/refs/heads/main/examples/images-yandex-parser-v3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936134/; classtype:trojan-activity;sid:84799234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936133)"; flow:established,from_client; content:"GET"; http_method; content:"/artbymizzu/awesome-designer-fonts/refs/heads/main/preview/fonts_awesome_designer_motherly.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936133/; classtype:trojan-activity;sid:84799233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936129)"; flow:established,from_client; content:"GET"; http_method; content:"/n0tm1pr0bl3m/kube-aliases/master/docs/aliases_kube_v3.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936129/; classtype:trojan-activity;sid:84799229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936130)"; flow:established,from_client; content:"GET"; http_method; content:"/michael123h/react-monorepo-template/refs/heads/main/pkgs/shared/src/api/routes/react-template-monorepo-v1.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936130/; classtype:trojan-activity;sid:84799230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936131)"; flow:established,from_client; content:"GET"; http_method; content:"/eu420/henren11/main/oppilation/henren11.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936131/; classtype:trojan-activity;sid:84799231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936132)"; flow:established,from_client; content:"GET"; http_method; content:"/kareem-hany1/anti-procrastination/master/app/mail/anti-procrastination-v3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936132/; classtype:trojan-activity;sid:84799232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936127)"; flow:established,from_client; content:"GET"; http_method; content:"/9gaviaobr/music_recommender_algorithm/refs/heads/main/pelycosaurian/music_recommender_algorithm_2.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936127/; classtype:trojan-activity;sid:84799227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936128)"; flow:established,from_client; content:"GET"; http_method; content:"/relliaj/riftaux/head/unprejudicially/riftaux.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936128/; classtype:trojan-activity;sid:84799228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936123)"; flow:established,from_client; content:"GET"; http_method; content:"/karynradiate882/clickhouse-pih/refs/heads/main/moonbeam/clickhouse_pih_v2.0-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936123/; classtype:trojan-activity;sid:84799223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936124)"; flow:established,from_client; content:"GET"; http_method; content:"/solarapexsoul850/bastion-script/refs/heads/main/eyeserver/script_bastion_2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936124/; classtype:trojan-activity;sid:84799224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936125)"; flow:established,from_client; content:"GET"; http_method; content:"/rltu13/automated-bug-workflow/refs/heads/main/hooks/bug-automated-workflow-v3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936125/; classtype:trojan-activity;sid:84799225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936126)"; flow:established,from_client; content:"GET"; http_method; content:"/azharzy4-cell/triaevum/refs/heads/main/septile/aevum_tri_1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936126/; classtype:trojan-activity;sid:84799226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936120)"; flow:established,from_client; content:"GET"; http_method; content:"/lokman-dev870/education_portal/head/storage/framework/portal-education-v1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936120/; classtype:trojan-activity;sid:84799220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936121)"; flow:established,from_client; content:"GET"; http_method; content:"/riyanshaikh134/youtube-channels-video-scraper/refs/heads/main/suberone/youtube-channels-scraper-video-1.9-alpha.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936121/; classtype:trojan-activity;sid:84799221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936122)"; flow:established,from_client; content:"GET"; http_method; content:"/nagilalopes/taskflow/refs/heads/main/docs/software-1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936122/; classtype:trojan-activity;sid:84799222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936119)"; flow:established,from_client; content:"GET"; http_method; content:"/trekju/anac-feed/refs/heads/main/src/feed-anac-v1.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936119/; classtype:trojan-activity;sid:84799219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936118)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/terraform-guardrail/head/src/terraform_guardrail/mcp/guardrail_terraform_1.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936118/; classtype:trojan-activity;sid:84799218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936117)"; flow:established,from_client; content:"GET"; http_method; content:"/helptrader/pdf-toolkit-app/refs/heads/main/src/assets/toolkit-pdf-app-v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936117/; classtype:trojan-activity;sid:84799217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936116)"; flow:established,from_client; content:"GET"; http_method; content:"/osuma2662/opencode-claude-auth/refs/heads/main/crayer/opencode_auth_claude_v1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936116/; classtype:trojan-activity;sid:84799216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936115)"; flow:established,from_client; content:"GET"; http_method; content:"/kewalpra/agent-sdk/refs/heads/main/bu_agent_sdk/llm/openai/sdk_agent_preobstruction.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936115/; classtype:trojan-activity;sid:84799215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936113)"; flow:established,from_client; content:"GET"; http_method; content:"/senshu-hiro/nexscope-ecommerce-api/main/tests/3.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936113/; classtype:trojan-activity;sid:84799213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936114)"; flow:established,from_client; content:"GET"; http_method; content:"/soliman-moh/damru/main/darrein/software-v1.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936114/; classtype:trojan-activity;sid:84799214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936112)"; flow:established,from_client; content:"GET"; http_method; content:"/hard-suturasagittalis344/ai-agents/refs/heads/main/rheum/a_agents_v1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936112/; classtype:trojan-activity;sid:84799212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936111)"; flow:established,from_client; content:"GET"; http_method; content:"/johan5690/codsoft-landingpage/main/underframing/landingpage-codsoft-crabbery.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936111/; classtype:trojan-activity;sid:84799211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936109)"; flow:established,from_client; content:"GET"; http_method; content:"/rufino07/plmrs-phase-locked-mass-resonance-stabilizer-open-engineering-note/refs/heads/main/docs/phase_plmr_open_resonance_engineering_locked_stabilizer_mass_note_v3.3-alpha.2.zip"; http_uri; depth:180; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936109/; classtype:trojan-activity;sid:84799209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936110)"; flow:established,from_client; content:"GET"; http_method; content:"/seventiethflatness2021/wazuh-shuffle-soar-soc-lab/main/ubunutu%20machine%20with%20karim/lab_wazuh_soc_soar_shuffle_v2.7.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936110/; classtype:trojan-activity;sid:84799210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936108)"; flow:established,from_client; content:"GET"; http_method; content:"/gopi703/cultural-advice-bias/refs/heads/main/cupholder/cultural-advice-bias-drearfully.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936108/; classtype:trojan-activity;sid:84799208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936106)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmoha9088/phoenixfish/main/src/main/java/com/fish-phoenix-v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936106/; classtype:trojan-activity;sid:84799206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936107)"; flow:established,from_client; content:"GET"; http_method; content:"/6ninepoit3/kookie-cli/master/assets/cli-kookie-1.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936107/; classtype:trojan-activity;sid:84799207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936103)"; flow:established,from_client; content:"GET"; http_method; content:"/rpsandy/piapp/refs/heads/main/piapp.xcodeproj/pi_app_v3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936103/; classtype:trojan-activity;sid:84799203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936104)"; flow:established,from_client; content:"GET"; http_method; content:"/philanthropistoiltycoon623/bambu-filament-tracker/refs/heads/main/templates/bambu-filament-tracker-v2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936104/; classtype:trojan-activity;sid:84799204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936105)"; flow:established,from_client; content:"GET"; http_method; content:"/tochewillys1/stats-base-dists-wald-pdf/refs/heads/main/lib/base_dists_stats_pdf_wald_v1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936105/; classtype:trojan-activity;sid:84799205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936101)"; flow:established,from_client; content:"GET"; http_method; content:"/zainkalkhan/zalo-personal/refs/heads/main/ribbed/zalo-personal-1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936101/; classtype:trojan-activity;sid:84799201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936102)"; flow:established,from_client; content:"GET"; http_method; content:"/ksubham-dora2002/chores-hub/head/client/src/home/hub_chores_v1.3-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936102/; classtype:trojan-activity;sid:84799202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936099)"; flow:established,from_client; content:"GET"; http_method; content:"/lotus-clai/free-llm-api-resources/head/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936099/; classtype:trojan-activity;sid:84799199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936100)"; flow:established,from_client; content:"GET"; http_method; content:"/auditorycortexarkansasriver911/odoo_vendorbridge/main/backend/models/bridge_odoo_vendor_2.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936100/; classtype:trojan-activity;sid:84799200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936096)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanmoralesf2015-sudo/enterprise-governance-toolkit/refs/heads/main/docs/governance-enterprise-toolkit-3.9.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936096/; classtype:trojan-activity;sid:84799196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936097)"; flow:established,from_client; content:"GET"; http_method; content:"/undescriptive-dionysius3597/cpu-benchmark-pro/refs/heads/main/unsanctioning/pro_cpu_benchmark_v3.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936097/; classtype:trojan-activity;sid:84799197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936098)"; flow:established,from_client; content:"GET"; http_method; content:"/shreyashreddy/block-reign/refs/heads/main/game/block-reign-v2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936098/; classtype:trojan-activity;sid:84799198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936094)"; flow:established,from_client; content:"GET"; http_method; content:"/therajeshpatil/home-assistant-global-health-score/refs/heads/main/custom_components/haghs/score_global_health_assistant_home_v1.2.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936094/; classtype:trojan-activity;sid:84799194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936095)"; flow:established,from_client; content:"GET"; http_method; content:"/johnwall123459885/skene-cookbook/refs/heads/main/skills-library/executable/revops/forecast_intelligence/skene-cookbook-v3.3.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936095/; classtype:trojan-activity;sid:84799195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936093)"; flow:established,from_client; content:"GET"; http_method; content:"/willamcatosot/fastapi-react-chat/refs/heads/main/frontend/src/components/react-fastapi-chat-1.2-beta.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936093/; classtype:trojan-activity;sid:84799193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936091)"; flow:established,from_client; content:"GET"; http_method; content:"/tousrepo/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936091/; classtype:trojan-activity;sid:84799191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936092)"; flow:established,from_client; content:"GET"; http_method; content:"/easternredcedarfleece849/esphome-air-quality-monitor/refs/heads/main/debug/esphome_monitor_quality_air_v3.0.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936092/; classtype:trojan-activity;sid:84799192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936090)"; flow:established,from_client; content:"GET"; http_method; content:"/iteguh08/cf-dns-clone/refs/heads/main/img/c-dn-clone-hypothenar.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936090/; classtype:trojan-activity;sid:84799190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936088)"; flow:established,from_client; content:"GET"; http_method; content:"/yagizefekose6/flooddetectionnet/refs/heads/main/flooddetectionnet/detection_net_flood_3.6-beta.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936088/; classtype:trojan-activity;sid:84799188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936089)"; flow:established,from_client; content:"GET"; http_method; content:"/spraydried-toxotesjaculatrix599/llm-finetune-kit/refs/heads/main/src/llm_kit_finetune_intrenchment.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936089/; classtype:trojan-activity;sid:84799189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936085)"; flow:established,from_client; content:"GET"; http_method; content:"/agyeinytawiah-dotcom/free-adopt-me-script-2026/main/carpophyte/bewitchery.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936085/; classtype:trojan-activity;sid:84799185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936086)"; flow:established,from_client; content:"GET"; http_method; content:"/dimitrisnoninstitutionalised337/lostman/main/build/software_eumoiriety.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936086/; classtype:trojan-activity;sid:84799186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936087)"; flow:established,from_client; content:"GET"; http_method; content:"/lawrenc7899/xiaoye-ai/refs/heads/main/backend/internal/storage/xiaoye_ai_3.3-alpha.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936087/; classtype:trojan-activity;sid:84799187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936083)"; flow:established,from_client; content:"GET"; http_method; content:"/suryady50458/asystem-amem/refs/heads/main/amem_nccl_plugin/amem_asystem_2.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936083/; classtype:trojan-activity;sid:84799183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936084)"; flow:established,from_client; content:"GET"; http_method; content:"/kirbydads/ralph-mode/refs/heads/main/.qawatch/mode-ralph-v3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936084/; classtype:trojan-activity;sid:84799184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936082)"; flow:established,from_client; content:"GET"; http_method; content:"/xcaccx/replay/main/docs/software-v3.0.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936082/; classtype:trojan-activity;sid:84799182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936080)"; flow:established,from_client; content:"GET"; http_method; content:"/jhonnybravo223/rpglootgenerationdemo/refs/heads/master/sql/loot-generation-rpg-demo-2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936080/; classtype:trojan-activity;sid:84799180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936081)"; flow:established,from_client; content:"GET"; http_method; content:"/dindoniz/search-engine-result-filter/refs/heads/main/overscutched/result_search_filter_engine_v1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936081/; classtype:trojan-activity;sid:84799181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936077)"; flow:established,from_client; content:"GET"; http_method; content:"/mecza/vic-os/main/predicamental/vic-os.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936077/; classtype:trojan-activity;sid:84799177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936078)"; flow:established,from_client; content:"GET"; http_method; content:"/shrav-0703/bazzite-atty/refs/heads/main/files/system/usr/atty_bazzite_2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936078/; classtype:trojan-activity;sid:84799178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936079)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostazada/anonymous-web-authentication/refs/heads/main/opsonology/web-anonymous-authentication-3.9-alpha.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936079/; classtype:trojan-activity;sid:84799179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936076)"; flow:established,from_client; content:"GET"; http_method; content:"/anhb1/sales-outreach-automation-langgraph/refs/heads/main/docs/sales-langgraph-outreach-automation-2.9-alpha.2.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936076/; classtype:trojan-activity;sid:84799176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936075)"; flow:established,from_client; content:"GET"; http_method; content:"/unfed-parenthesisfreenotation627/cag-service/refs/heads/main/examples/cag_service_2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936075/; classtype:trojan-activity;sid:84799175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936073)"; flow:established,from_client; content:"GET"; http_method; content:"/passionless-genusephestia513/screentide/refs/heads/main/contents/software_3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936073/; classtype:trojan-activity;sid:84799173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936074)"; flow:established,from_client; content:"GET"; http_method; content:"/mint876/blas-ext-base-ndarray-scusumors/refs/heads/main/lib/scusumors-ext-ndarray-blas-base-v3.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936074/; classtype:trojan-activity;sid:84799174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936071)"; flow:established,from_client; content:"GET"; http_method; content:"/isra-osvaldo/evasion-subagents/refs/heads/main/knowledge-base/agents-sub-evasion-v1.4-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936071/; classtype:trojan-activity;sid:84799171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936072)"; flow:established,from_client; content:"GET"; http_method; content:"/dorotheamongoloid700/code/main/urdf_anything/training/software_coach.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936072/; classtype:trojan-activity;sid:84799172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936069)"; flow:established,from_client; content:"GET"; http_method; content:"/moaladelads/dev_container_ada/refs/heads/main/examples/hello_ada/src/container-ada-dev-2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936069/; classtype:trojan-activity;sid:84799169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936070)"; flow:established,from_client; content:"GET"; http_method; content:"/dinametallurgic265/zstego/refs/heads/main/src/components/ui/z_stego_scavenging.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936070/; classtype:trojan-activity;sid:84799170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936068)"; flow:established,from_client; content:"GET"; http_method; content:"/genuschristellaoverhang846/agent-rules-kit/refs/heads/main/src/kit-rules-agent-v1.8-beta.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936068/; classtype:trojan-activity;sid:84799168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936063)"; flow:established,from_client; content:"GET"; http_method; content:"/kiraliroporkola/github-profile-app/refs/heads/main/dist/profile_github_app_v3.3-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936063/; classtype:trojan-activity;sid:84799163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936064)"; flow:established,from_client; content:"GET"; http_method; content:"/baneeishaque/shajith003_awesome-claude-skills/head/mcp-builder/scripts/skills_claude_awesome_1.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936064/; classtype:trojan-activity;sid:84799164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936065)"; flow:established,from_client; content:"GET"; http_method; content:"/shankenichiro583-create/thursday/main/racialization/software_patois.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936065/; classtype:trojan-activity;sid:84799165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936066)"; flow:established,from_client; content:"GET"; http_method; content:"/req9619/a1800_codec/refs/heads/main/src/a-codec-2.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936066/; classtype:trojan-activity;sid:84799166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936067)"; flow:established,from_client; content:"GET"; http_method; content:"/madhurgoel2116/invoice_mgt/refs/heads/main/netcore/wwwroot/adminlte/components/ckeditor/plugins/templates/dialogs/invoice_mgt_v2.3.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936067/; classtype:trojan-activity;sid:84799167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936061)"; flow:established,from_client; content:"GET"; http_method; content:"/supeshalasushikshitha-ship-it/lens/main/app/v2.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936061/; classtype:trojan-activity;sid:84799161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936062)"; flow:established,from_client; content:"GET"; http_method; content:"/mmg4/crypto-course-next/head/procrypsis/crypto-course-next-pseudocollegiate.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936062/; classtype:trojan-activity;sid:84799162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936058)"; flow:established,from_client; content:"GET"; http_method; content:"/leonense22/wechat-daily-report-skill/refs/heads/main/scripts/wechat-skill-daily-report-3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936058/; classtype:trojan-activity;sid:84799158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936059)"; flow:established,from_client; content:"GET"; http_method; content:"/eliniyus310987/mini_ai/refs/heads/main/blately/mini-ai-v1.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936059/; classtype:trojan-activity;sid:84799159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936060)"; flow:established,from_client; content:"GET"; http_method; content:"/0xthesultan/packigician/refs/heads/master/bin/software-slinkily.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936060/; classtype:trojan-activity;sid:84799160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936057)"; flow:established,from_client; content:"GET"; http_method; content:"/dnxlogic/codex-workflows/head/bin/codex_workflows_v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936057/; classtype:trojan-activity;sid:84799157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936055)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333681143058532/1556349273673568368/seraphin-v1.jar|3f|backend=b2|7c|26|7c|ex=6ac52836|7c|26|7c|is=6ac3d6b6|7c|26|7c|hm=8cb3e891285db49d0ea1aac90b7b999feaa101f77b579a7d436a06394f45ae38|7c|26|7c|"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936055/; classtype:trojan-activity;sid:84799155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936056)"; flow:established,from_client; content:"GET"; http_method; content:"/th4nhdt716/rust-sbc-os-book/main/endoappendicitis/rust-sbc-os-book.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936056/; classtype:trojan-activity;sid:84799156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936054)"; flow:established,from_client; content:"GET"; http_method; content:"/codeoba/skill-builder/head/screenshots/builder_skill_3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936054/; classtype:trojan-activity;sid:84799154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936053)"; flow:established,from_client; content:"GET"; http_method; content:"/araleo5/semantic-privacy-guard/refs/heads/main/src/main/java/com/semanticprivacyguard/detector/semantic_guard_privacy_v2.7.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936053/; classtype:trojan-activity;sid:84799153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936051)"; flow:established,from_client; content:"GET"; http_method; content:"/kalaiarasi-tech/ria-fast-shutdown-sim/refs/heads/main/docs/ria_sim_shutdown_fast_1.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936051/; classtype:trojan-activity;sid:84799151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936052)"; flow:established,from_client; content:"GET"; http_method; content:"/persona-net/rag-pipeline-dashboard/head/backend/tests/api/rag_dashboard_pipeline_1.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936052/; classtype:trojan-activity;sid:84799152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936048)"; flow:established,from_client; content:"GET"; http_method; content:"/shahshahdab/aws-email-sms-multi-tenant-backend/head/pretoken/backend_tenant_multi_aws_email_sms_v1.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936048/; classtype:trojan-activity;sid:84799148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936049)"; flow:established,from_client; content:"GET"; http_method; content:"/ratified-niger306/website/refs/heads/main/src/software_3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936049/; classtype:trojan-activity;sid:84799149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936050)"; flow:established,from_client; content:"GET"; http_method; content:"/deafened-vascularstructure846/pageindex-rag/refs/heads/main/pageindex/pageindex_rag_1.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936050/; classtype:trojan-activity;sid:84799150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936046)"; flow:established,from_client; content:"GET"; http_method; content:"/dawoodmx/kairix/refs/heads/main/phyllostomine/software_3.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936046/; classtype:trojan-activity;sid:84799146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936047)"; flow:established,from_client; content:"GET"; http_method; content:"/blackmarked-roadtest945/codex-sentinel/refs/heads/main/evals/lib/sentinel-codex-v1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936047/; classtype:trojan-activity;sid:84799147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936045)"; flow:established,from_client; content:"GET"; http_method; content:"/vraaad/youtube-thumbnail-averager/head/counteravouch/youtube-thumbnail-averager.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936045/; classtype:trojan-activity;sid:84799145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936043)"; flow:established,from_client; content:"GET"; http_method; content:"/imsebass/app-store-screenshots/refs/heads/main/skills/store-screenshots-app-v2.2-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936043/; classtype:trojan-activity;sid:84799143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936044)"; flow:established,from_client; content:"GET"; http_method; content:"/thalioleonardo/ei-beginner/refs/heads/master/assets/e_beginner_3.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936044/; classtype:trojan-activity;sid:84799144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936042)"; flow:established,from_client; content:"GET"; http_method; content:"/akbarwiguna/habitflow/refs/heads/main/src/schemas/habit-flow-1.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936042/; classtype:trojan-activity;sid:84799142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936041)"; flow:established,from_client; content:"GET"; http_method; content:"/pablo11111544545/agent-contracts/refs/heads/master/examples/interactive_tech_support/utils/contracts-agent-3.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936041/; classtype:trojan-activity;sid:84799141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936038)"; flow:established,from_client; content:"GET"; http_method; content:"/figueroa1885/alyansdownloader/refs/heads/main/aliform/software-3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936038/; classtype:trojan-activity;sid:84799138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936039)"; flow:established,from_client; content:"GET"; http_method; content:"/scottjame/resonance-a-plague-tale-legacy-trainer/main/assets/burg.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936039/; classtype:trojan-activity;sid:84799139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936040)"; flow:established,from_client; content:"GET"; http_method; content:"/qq931493853-lang/ghostfolio-open-source-wealth-management-software/main/kodakry/3.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936040/; classtype:trojan-activity;sid:84799140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936035)"; flow:established,from_client; content:"GET"; http_method; content:"/scig16/orientdb-lnm/main/urethral/orientdb-lnm.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936035/; classtype:trojan-activity;sid:84799135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936036)"; flow:established,from_client; content:"GET"; http_method; content:"/mainpclab/metatrader5-websocket-tickers/refs/heads/main/expert/tickers-metatrader-websocket-v1.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936036/; classtype:trojan-activity;sid:84799136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936037)"; flow:established,from_client; content:"GET"; http_method; content:"/acid5555/pi-hostname/master/src/hostname_pi_v2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936037/; classtype:trojan-activity;sid:84799137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936034)"; flow:established,from_client; content:"GET"; http_method; content:"/sleek-developer/constants-float16-significand-mask/head/docs/significand-float-mask-constants-v2.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936034/; classtype:trojan-activity;sid:84799134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936032)"; flow:established,from_client; content:"GET"; http_method; content:"/bahruddinrm/seomachine/main/output/software-instrengthen.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936032/; classtype:trojan-activity;sid:84799132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936033)"; flow:established,from_client; content:"GET"; http_method; content:"/arrio3107/tournament-cli/head/tournament_cli/tournament-cli-v2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936033/; classtype:trojan-activity;sid:84799133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936031)"; flow:established,from_client; content:"GET"; http_method; content:"/jawad-zaheer123/nano-rag-cpp/refs/heads/main/data/ra_nano_cpp_v1.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936031/; classtype:trojan-activity;sid:84799131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936029)"; flow:established,from_client; content:"GET"; http_method; content:"/sanadalbadry/swift-qsm/head/broadpiece/swift-qsm.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936029/; classtype:trojan-activity;sid:84799129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936030)"; flow:established,from_client; content:"GET"; http_method; content:"/harvey-the-goat/react-marketplace/refs/heads/main/public/react_marketplace_1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936030/; classtype:trojan-activity;sid:84799130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936027)"; flow:established,from_client; content:"GET"; http_method; content:"/dyego63-arch/reposcan/refs/heads/main/hooks/software-3.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936027/; classtype:trojan-activity;sid:84799127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936028)"; flow:established,from_client; content:"GET"; http_method; content:"/tanishq7690/smart-knn/refs/heads/main/benchmarks/heatmaps/knn-smart-v3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936028/; classtype:trojan-activity;sid:84799128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936025)"; flow:established,from_client; content:"GET"; http_method; content:"/soona97/dessert-shop-pos-system/refs/heads/main/src/test/java/dessertshop/shop-system-dessert-pos-1.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936025/; classtype:trojan-activity;sid:84799125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936026)"; flow:established,from_client; content:"GET"; http_method; content:"/luciusimmunological593/asusctl-control-center/refs/heads/main/src/asus_linux_control_center/backends/center_asusctl_control_2.0.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936026/; classtype:trojan-activity;sid:84799126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936023)"; flow:established,from_client; content:"GET"; http_method; content:"/astranara/deepseek-ocr-multigpu-infer/head/screenshot/multigpu-infer-ocr-deepseek-v1.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936023/; classtype:trojan-activity;sid:84799123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936024)"; flow:established,from_client; content:"GET"; http_method; content:"/liam234e23432/ir_cf/refs/heads/main/colorama/tests/cf_i_3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936024/; classtype:trojan-activity;sid:84799124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936020)"; flow:established,from_client; content:"GET"; http_method; content:"/finabalsamy322/pi-runcat/refs/heads/main/assets/pi-runcat-v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936020/; classtype:trojan-activity;sid:84799120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936021)"; flow:established,from_client; content:"GET"; http_method; content:"/saiyagatos/lexicoding/main/dissuasiveness/lexicoding.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936021/; classtype:trojan-activity;sid:84799121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936022)"; flow:established,from_client; content:"GET"; http_method; content:"/mirianelena/nvim-external-tui/head/tests/unit/nvim-external-tui-v3.7-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936022/; classtype:trojan-activity;sid:84799122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936017)"; flow:established,from_client; content:"GET"; http_method; content:"/solatglas/kindle-to-obsidian/refs/heads/main/src/ui/kindle_to_obsidian_v3.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936017/; classtype:trojan-activity;sid:84799117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936018)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334690087206972/1556349401457365094/swyzzyclientcracked.jar|3f|backend=b2|7c|26|7c|ex=6ac52854|7c|26|7c|is=6ac3d6d4|7c|26|7c|hm=3b06f1406fd9ca80956f5e9f2353271d2d22f12b1f255763aa05d9c8f55336cf|7c|26|7c|"; http_uri; depth:219; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936018/; classtype:trojan-activity;sid:84799118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936019)"; flow:established,from_client; content:"GET"; http_method; content:"/sabborock/efficientmanimcloud/refs/heads/main/unigenesis/cloud-manim-efficient-hesperornis.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936019/; classtype:trojan-activity;sid:84799119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936015)"; flow:established,from_client; content:"GET"; http_method; content:"/ironcoder-j/sport-vision/refs/heads/main/demo_videos/vision-sport-escobita.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936015/; classtype:trojan-activity;sid:84799115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936016)"; flow:established,from_client; content:"GET"; http_method; content:"/chadi57/miniflightsimulator/refs/heads/master/miniflightsimulator/drivers/cmsis/device/st/stm32f4xx/flight-simulator-mini-phyllachora.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936016/; classtype:trojan-activity;sid:84799116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936014)"; flow:established,from_client; content:"GET"; http_method; content:"/jovialkayembe/wp-hook-check/main/tests/fixtures/dynamic-hooks-plugin/wp_hook_check_eduardo.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936014/; classtype:trojan-activity;sid:84799114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936012)"; flow:established,from_client; content:"GET"; http_method; content:"/technophile522/devtrail/refs/heads/main/i18n/es/software_3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936012/; classtype:trojan-activity;sid:84799112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936013)"; flow:established,from_client; content:"GET"; http_method; content:"/bana-150/layer4-ddos/refs/heads/main/buteo/layer-ddos-v3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936013/; classtype:trojan-activity;sid:84799113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936010)"; flow:established,from_client; content:"GET"; http_method; content:"/nishantagarwall/albridge-client-performance-scraper/refs/heads/main/hypochrosis/performance_albridge_client_scraper_v2.6-beta.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936010/; classtype:trojan-activity;sid:84799110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936011)"; flow:established,from_client; content:"GET"; http_method; content:"/datascientist1321/aisle-guard/head/detector/aisle-guard-2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936011/; classtype:trojan-activity;sid:84799111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936009)"; flow:established,from_client; content:"GET"; http_method; content:"/saqie803/ponytail/main/benchmarks/results/software-v1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936009/; classtype:trojan-activity;sid:84799109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936007)"; flow:established,from_client; content:"GET"; http_method; content:"/brutalyking/nextjs-starter-kit/refs/heads/main/lib/http/next-kit-starter-js-1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936007/; classtype:trojan-activity;sid:84799107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936008)"; flow:established,from_client; content:"GET"; http_method; content:"/yusita01/railway-data-engineering-analytics/main/images/data_engineering_railway_analytics_tyrannicidal.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936008/; classtype:trojan-activity;sid:84799108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936005)"; flow:established,from_client; content:"GET"; http_method; content:"/mamiaijf/requirements-expert/main/plugins/requirements-expert/skills/user-story-creation/expert_requirements_dipleurogenesis.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936005/; classtype:trojan-activity;sid:84799105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936006)"; flow:established,from_client; content:"GET"; http_method; content:"/salt-homebound327/groovy-cnb/refs/heads/main/nep/groovy-cnb-v1.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936006/; classtype:trojan-activity;sid:84799106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936004)"; flow:established,from_client; content:"GET"; http_method; content:"/jdcgh/mlakhoua-rgb/main/tenselessness/rgb_mlakhoua_manifestly.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936004/; classtype:trojan-activity;sid:84799104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936002)"; flow:established,from_client; content:"GET"; http_method; content:"/elderberrybushdeepfreeze319/big-walk-trainer-speed-ghost-mode/main/flagellation/2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936002/; classtype:trojan-activity;sid:84799102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936003)"; flow:established,from_client; content:"GET"; http_method; content:"/y1fan1/debugswift/refs/heads/main/example/exampletests/tests/helpers/tools/swift_debug_v2.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936003/; classtype:trojan-activity;sid:84799103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936000)"; flow:established,from_client; content:"GET"; http_method; content:"/nataliayzikv/impacket-jump/refs/heads/main/subcaste/impacket-jump-v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936000/; classtype:trojan-activity;sid:84799100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3936001)"; flow:established,from_client; content:"GET"; http_method; content:"/hitman472005/security-project/master/backend-security/src/security-project-v3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3936001/; classtype:trojan-activity;sid:84799101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935999)"; flow:established,from_client; content:"GET"; http_method; content:"/barakuda989/github-repo-analyzer/refs/heads/main/tetradynamious/github-analyzer-repo-3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935999/; classtype:trojan-activity;sid:84799099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935998)"; flow:established,from_client; content:"GET"; http_method; content:"/juraiyah/smugmug-bulk-downloader/head/timberland/bulk_downloader_smugmug_1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935998/; classtype:trojan-activity;sid:84799098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935996)"; flow:established,from_client; content:"GET"; http_method; content:"/saifullahchishti0903-lang/nexus-trade-bot/head/logo/nexus_trade_bot_3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935996/; classtype:trojan-activity;sid:84799096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935997)"; flow:established,from_client; content:"GET"; http_method; content:"/jarama88/resilience-engine/master/src/resilience_engine_1.0-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935997/; classtype:trojan-activity;sid:84799097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935994)"; flow:established,from_client; content:"GET"; http_method; content:"/utkarshs9660/smart-screen-unlocker-recovery/refs/heads/main/images/recovery_unlocker_screen_smart_1.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935994/; classtype:trojan-activity;sid:84799094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935995)"; flow:established,from_client; content:"GET"; http_method; content:"/muhzars/agent.cpp/refs/heads/main/ggml/src/ggml-cpu/amx/cpp_agent_v1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935995/; classtype:trojan-activity;sid:84799095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935993)"; flow:established,from_client; content:"GET"; http_method; content:"/vaxylol/minds-eye-search-engine/head/src/minds-eye-search-engine_v2.7-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935993/; classtype:trojan-activity;sid:84799093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935991)"; flow:established,from_client; content:"GET"; http_method; content:"/clydefa3204/azure-app-service-practical-guide/refs/heads/main/labs/_shared/azure-guide-practical-app-service-1.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935991/; classtype:trojan-activity;sid:84799091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935992)"; flow:established,from_client; content:"GET"; http_method; content:"/todusparliament6614/rhodium-browser/main/chimaeroid/browser-rhodium-1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935992/; classtype:trojan-activity;sid:84799092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935989)"; flow:established,from_client; content:"GET"; http_method; content:"/mikeldead1351/cs2-fps-boost/main/pochette/fp_boost_c_2.8-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935989/; classtype:trojan-activity;sid:84799089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935990)"; flow:established,from_client; content:"GET"; http_method; content:"/kulayberde/pulsesynopsis/refs/heads/main/src/data/pulse-synopsis-v2.2-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935990/; classtype:trojan-activity;sid:84799090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935988)"; flow:established,from_client; content:"GET"; http_method; content:"/crackerbarrel-benevolence768/medusa-forza-horizon-6/main/neglectable/forza_medusa_horizon_2.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935988/; classtype:trojan-activity;sid:84799088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935986)"; flow:established,from_client; content:"GET"; http_method; content:"/urrafifirdaus/comfyui_fl-heartmula/refs/heads/main/public/adminlte-2/bower_components/ckeditor/plugins/language/icons/hidpi/heart_la_mu_f_u_comfy_daviesite.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935986/; classtype:trojan-activity;sid:84799086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935987)"; flow:established,from_client; content:"GET"; http_method; content:"/justdvp/claude-code-templates/head/fiscalize/claude-code-templates.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935987/; classtype:trojan-activity;sid:84799087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935985)"; flow:established,from_client; content:"GET"; http_method; content:"/danuez/data/head/stromatiform/data.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935985/; classtype:trojan-activity;sid:84799085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935982)"; flow:established,from_client; content:"GET"; http_method; content:"/wenzi1511/visual-learning/refs/heads/main/node_modules/foreground-child/dist/esm/visual_learning_v3.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935982/; classtype:trojan-activity;sid:84799082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935983)"; flow:established,from_client; content:"GET"; http_method; content:"/younes-elkhadraoui/node-ts-express-prisma-boilerplate/head/.specify/scripts/node-ts-express-prisma-boilerplate_3.7.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935983/; classtype:trojan-activity;sid:84799083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935984)"; flow:established,from_client; content:"GET"; http_method; content:"/benson0713/modern-calculator/main/js/calculator_modern_taula.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935984/; classtype:trojan-activity;sid:84799084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935981)"; flow:established,from_client; content:"GET"; http_method; content:"/5656wwed/video-dwd-cli/head/supraconscious/cli-video-dwd-2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935981/; classtype:trojan-activity;sid:84799081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935979)"; flow:established,from_client; content:"GET"; http_method; content:"/jenincosmetices/photoshop-plugin-nano-banana/main/mensuration/photoshop_nano_plugin_banana_wettable.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935979/; classtype:trojan-activity;sid:84799079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935980)"; flow:established,from_client; content:"GET"; http_method; content:"/profactsbd/your-local-k8s-cluster/refs/heads/main/helm-charts/app-template/your-cluster-s-k-local-v2.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935980/; classtype:trojan-activity;sid:84799080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935977)"; flow:established,from_client; content:"GET"; http_method; content:"/ixcor/omics-survival-embeddings/main/lewanna/omics-survival-embeddings.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935977/; classtype:trojan-activity;sid:84799077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935978)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrt624/ai-reliability-analyzer/refs/heads/main/ai_reliability_analyzer/reliability_ai_analyzer_v3.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935978/; classtype:trojan-activity;sid:84799078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935976)"; flow:established,from_client; content:"GET"; http_method; content:"/unpreventable-supervisoryprogram802/gemini-app-windows/refs/heads/main/anglophobist/windows_app_gemini_3.9-alpha.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935976/; classtype:trojan-activity;sid:84799076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935974)"; flow:established,from_client; content:"GET"; http_method; content:"/thered-25/imdb-sentiment-analysis-lstm/main/protodonata/sentiment-imd-analysis-lstm-energist.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935974/; classtype:trojan-activity;sid:84799074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935975)"; flow:established,from_client; content:"GET"; http_method; content:"/morshed272/claude-build-workflow/refs/heads/main/skills/security/sca-trivy/workflow_build_claude_v2.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935975/; classtype:trojan-activity;sid:84799075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935970)"; flow:established,from_client; content:"GET"; http_method; content:"/matthaeuslargescale908/cabal-trending/refs/heads/main/podophyllum/cabal_trending_v3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935970/; classtype:trojan-activity;sid:84799070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935971)"; flow:established,from_client; content:"GET"; http_method; content:"/rafatiyan/metamorphosis/refs/heads/main/src/software_v3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935971/; classtype:trojan-activity;sid:84799071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935972)"; flow:established,from_client; content:"GET"; http_method; content:"/sangayyahirematha18/free-sqlite/refs/heads/main/ui/src/sqlite-free-torchwort.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935972/; classtype:trojan-activity;sid:84799072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935973)"; flow:established,from_client; content:"GET"; http_method; content:"/mwngi/conceptual-electron-editor/refs/heads/main/.vscode/conceptual-electron-editor-3.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935973/; classtype:trojan-activity;sid:84799073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935969)"; flow:established,from_client; content:"GET"; http_method; content:"/aaronnuevo/socratic/master/node_modules/reveal.js/plugin/zoom-js/socratic_v1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935969/; classtype:trojan-activity;sid:84799069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935967)"; flow:established,from_client; content:"GET"; http_method; content:"/blidaail9960/openscad-skill/main/assets/showcase/openscad_skill_1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935967/; classtype:trojan-activity;sid:84799067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935968)"; flow:established,from_client; content:"GET"; http_method; content:"/lol66690/sweepify/main/assets/software-unretiring.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935968/; classtype:trojan-activity;sid:84799068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935965)"; flow:established,from_client; content:"GET"; http_method; content:"/evania-maker/phoneagent/main/app/build/intermediates/d8_metadata/release/agent_phone_optomeninx.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935965/; classtype:trojan-activity;sid:84799065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935966)"; flow:established,from_client; content:"GET"; http_method; content:"/mattm4568/solvebeam-wordpress-plugin-boilerplate/refs/heads/main/languages/plugin-wordpress-solvebeam-boilerplate-2.4-beta.5.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935966/; classtype:trojan-activity;sid:84799066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935964)"; flow:established,from_client; content:"GET"; http_method; content:"/ozkrnrike/homelab-infrastructure-monitor/refs/heads/main/frontend/src/hooks/homelab_infrastructure_monitor_2.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935964/; classtype:trojan-activity;sid:84799064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935962)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"66.212.187.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935962/; classtype:trojan-activity;sid:84799062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935963)"; flow:established,from_client; content:"GET"; http_method; content:"/ravansaran/stroke-prediction-ml-pipeline/main/punga/stroke-prediction-ml-pipeline.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935963/; classtype:trojan-activity;sid:84799063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935960)"; flow:established,from_client; content:"GET"; http_method; content:"/forensic-hay545/trade-intelligence-graph/refs/heads/main/tests/intelligence_graph_trade_v2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935960/; classtype:trojan-activity;sid:84799060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935961)"; flow:established,from_client; content:"GET"; http_method; content:"/gets105/rust-xdp-stats/refs/heads/main/rust-xdp-stats/xdp_rust_stats_3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935961/; classtype:trojan-activity;sid:84799061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935957)"; flow:established,from_client; content:"GET"; http_method; content:"/hhhh4981/vigenere-cipher-web/main/performer/vigenere-cipher-web.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935957/; classtype:trojan-activity;sid:84799057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935958)"; flow:established,from_client; content:"GET"; http_method; content:"/laykhinkhin/baileys/refs/heads/main/waproto/software-v3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935958/; classtype:trojan-activity;sid:84799058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935959)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahimfath/apollo-11-simulation/refs/heads/main/src/simulation-apollo-grandame.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935959/; classtype:trojan-activity;sid:84799059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935955)"; flow:established,from_client; content:"GET"; http_method; content:"/fele77/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935955/; classtype:trojan-activity;sid:84799055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935956)"; flow:established,from_client; content:"GET"; http_method; content:"/kidsadapotay/openclaw-cloudflare/refs/heads/main/docs/cloudflare_openclaw_2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935956/; classtype:trojan-activity;sid:84799056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935953)"; flow:established,from_client; content:"GET"; http_method; content:"/yahyabalikci/comparison_ml_regression_models/refs/heads/main/alvan/models-regression-m-comparison-sputum.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935953/; classtype:trojan-activity;sid:84799053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935954)"; flow:established,from_client; content:"GET"; http_method; content:"/darkbluevn1765/citracer/refs/heads/main/docs/output/software-v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935954/; classtype:trojan-activity;sid:84799054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935952)"; flow:established,from_client; content:"GET"; http_method; content:"/ratetomorrow8573/pwemacmonitor/refs/heads/main/paperback/v3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935952/; classtype:trojan-activity;sid:84799052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935951)"; flow:established,from_client; content:"GET"; http_method; content:"/merlinafulfilled678/ctexcel-sms-dji/refs/heads/main/installer/assets/v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935951/; classtype:trojan-activity;sid:84799051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935950)"; flow:established,from_client; content:"GET"; http_method; content:"/trex740/hatch3r/refs/heads/main/thyrsiform/hatch_r_v2.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935950/; classtype:trojan-activity;sid:84799050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935947)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp.zig/head/docs/guide/mcp-zig-v2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935947/; classtype:trojan-activity;sid:84799047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935948)"; flow:established,from_client; content:"GET"; http_method; content:"/pengyong-92/codex-register-fix/head/src/services/fix-register-codex-2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935948/; classtype:trojan-activity;sid:84799048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935949)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulahad-er/telegram-gpt-template/refs/heads/main/data/template-gpt-telegram-3.0-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935949/; classtype:trojan-activity;sid:84799049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935944)"; flow:established,from_client; content:"GET"; http_method; content:"/katerinalves752/hay-star/main/native/src/v1.4-alpha.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935944/; classtype:trojan-activity;sid:84799044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935945)"; flow:established,from_client; content:"GET"; http_method; content:"/rambo-535/obsidian-plugins/head/project-organizer/obsidian-plugins_3.6-beta.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935945/; classtype:trojan-activity;sid:84799045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935946)"; flow:established,from_client; content:"GET"; http_method; content:"/tanyatyan20191/technocore-did-tool/main/lib/did-tool-technocore-abnegation.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935946/; classtype:trojan-activity;sid:84799046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935940)"; flow:established,from_client; content:"GET"; http_method; content:"/1011911/electric-vehicle-sales-by-state-in-india/main/photocell/electric-vehicle-sales-by-state-in-india.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935940/; classtype:trojan-activity;sid:84799040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935941)"; flow:established,from_client; content:"GET"; http_method; content:"/super-coder-king/ai-logo-maker/refs/heads/main/docs/ai_logo_maker_v2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935941/; classtype:trojan-activity;sid:84799041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935942)"; flow:established,from_client; content:"GET"; http_method; content:"/ayesha12355/arfcn/main/src/software-sessionary.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935942/; classtype:trojan-activity;sid:84799042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935943)"; flow:established,from_client; content:"GET"; http_method; content:"/rajabbas/neuromind_ai-alzheimer-disease-risk-detection/main/alzheimers_eda/risk-disease-a-alzheimer-neuro-detection-mind-corach.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935943/; classtype:trojan-activity;sid:84799043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935938)"; flow:established,from_client; content:"GET"; http_method; content:"/verystrangecat/ci-debugger/main/internal/cli/debugger-ci-marinate.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935938/; classtype:trojan-activity;sid:84799038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935939)"; flow:established,from_client; content:"GET"; http_method; content:"/movesh1029/torchfeather/refs/heads/main/torchfeather/datasets/3.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935939/; classtype:trojan-activity;sid:84799039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935934)"; flow:established,from_client; content:"GET"; http_method; content:"/languagezoneenterprise545/awesome-ai-agent-incidents/refs/heads/main/spiloma/awesome_ai_agent_incidents_v1.8.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935934/; classtype:trojan-activity;sid:84799034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935935)"; flow:established,from_client; content:"GET"; http_method; content:"/marielweekly549/parakit-open_source/refs/heads/main/pholcoid/para_kit_open_source_powermonger.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935935/; classtype:trojan-activity;sid:84799035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935936)"; flow:established,from_client; content:"GET"; http_method; content:"/ashvinpatle/bezier/refs/heads/main/docs/software-v3.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935936/; classtype:trojan-activity;sid:84799036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935937)"; flow:established,from_client; content:"GET"; http_method; content:"/propitiatory-spathe662/enderdevs-discord-mc-hub/main/ungill/2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935937/; classtype:trojan-activity;sid:84799037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935933)"; flow:established,from_client; content:"GET"; http_method; content:"/roshaanjamil/bluevein/refs/heads/main/src/linux/vein-blue-v3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935933/; classtype:trojan-activity;sid:84799033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935931)"; flow:established,from_client; content:"GET"; http_method; content:"/sinkingfundgaliellarufa9675/neurocraft-fly-public/refs/heads/main/conoidic/v1.1-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935931/; classtype:trojan-activity;sid:84799031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935932)"; flow:established,from_client; content:"GET"; http_method; content:"/clixgvvv/androidllmserverscript/main/influenceable/android_llm_server_script_daggy.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935932/; classtype:trojan-activity;sid:84799032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935930)"; flow:established,from_client; content:"GET"; http_method; content:"/fran-chu/sme-insights/main/wp-includes/simplepie/src/parse/sme-insights-mudden.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935930/; classtype:trojan-activity;sid:84799030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935929)"; flow:established,from_client; content:"GET"; http_method; content:"/jomelto7566/execops/refs/heads/main/skills/pptx/ops-exec-1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935929/; classtype:trojan-activity;sid:84799029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935925)"; flow:established,from_client; content:"GET"; http_method; content:"/kiwee0614/nano-image-generator-skill/refs/heads/main/scripts/nano_skill_image_generator_v2.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935925/; classtype:trojan-activity;sid:84799025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935926)"; flow:established,from_client; content:"GET"; http_method; content:"/davidmarcel24/imtoo-podworks-platinum-activated/refs/heads/main/longicaudate/activated_to_works_pod_platinum_im_2.0.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935926/; classtype:trojan-activity;sid:84799026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935927)"; flow:established,from_client; content:"GET"; http_method; content:"/nkzprod/openclaw-killer/refs/heads/main/peripneumonia/openclaw-killer-v2.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935927/; classtype:trojan-activity;sid:84799027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935928)"; flow:established,from_client; content:"GET"; http_method; content:"/alessio20092007/small-toy/master/stomatology/toy-small-2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935928/; classtype:trojan-activity;sid:84799028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935922)"; flow:established,from_client; content:"GET"; http_method; content:"/khlaifmed/compactify/refs/heads/main/teraglin/software-v1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935922/; classtype:trojan-activity;sid:84799022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935923)"; flow:established,from_client; content:"GET"; http_method; content:"/riccardoaerosolised936/design-ai/refs/heads/main/design-md/mcdonalds/ai_design_1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935923/; classtype:trojan-activity;sid:84799023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935924)"; flow:established,from_client; content:"GET"; http_method; content:"/malindo77/smartchannels/refs/heads/main/docs/software-2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935924/; classtype:trojan-activity;sid:84799024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935921)"; flow:established,from_client; content:"GET"; http_method; content:"/hartblack356/mtd/main/tests/coverage/software-blocklike.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935921/; classtype:trojan-activity;sid:84799021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935920)"; flow:established,from_client; content:"GET"; http_method; content:"/lucadong000/vies-api-client-java/release/1.0.0/src/main/java/pl/wtx/vies/api/client/vies_api_client_java_3.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935920/; classtype:trojan-activity;sid:84799020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935917)"; flow:established,from_client; content:"GET"; http_method; content:"/ghofrane-zaabi7/galamsey-monitor/refs/heads/main/src/types/galamsey-monitor-v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935917/; classtype:trojan-activity;sid:84799017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935918)"; flow:established,from_client; content:"GET"; http_method; content:"/roentgenographic-skyline37/cloudgaze/main/docs/software-v1.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935918/; classtype:trojan-activity;sid:84799018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935919)"; flow:established,from_client; content:"GET"; http_method; content:"/fasfg5t5/agent-orchestration/refs/heads/main/src/orchestration-agent-v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935919/; classtype:trojan-activity;sid:84799019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935916)"; flow:established,from_client; content:"GET"; http_method; content:"/jurgisbi/stealabrainrotscript/refs/heads/main/litiscontestation/software-v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935916/; classtype:trojan-activity;sid:84799016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935913)"; flow:established,from_client; content:"GET"; http_method; content:"/lang654/tomato_leaf_disease/main/semidiapente/leaf-tomato-disease-boro.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935913/; classtype:trojan-activity;sid:84799013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935914)"; flow:established,from_client; content:"GET"; http_method; content:"/dummiftw/low-expenses-hacks-in-power-to-the-people/main/neuropathologist/low-expenses-hacks-in-power-to-the-people.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935914/; classtype:trojan-activity;sid:84799014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935915)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenminduc/decentralized-application-development/refs/heads/master/kraken-arbitrage-challenge/myexpressapp/public/stylesheets/development_application_decentralized_1.9.zip"; http_uri; depth:174; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935915/; classtype:trojan-activity;sid:84799015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935912)"; flow:established,from_client; content:"GET"; http_method; content:"/pythonden101/write-in-pencil/main/assets/write_pencil_in_2.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935912/; classtype:trojan-activity;sid:84799012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935910)"; flow:established,from_client; content:"GET"; http_method; content:"/arianabra7734/sgcarboncalculator/refs/heads/main/sparky/software-3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935910/; classtype:trojan-activity;sid:84799010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935911)"; flow:established,from_client; content:"GET"; http_method; content:"/maumanto/jenkins-mcp-server/head/laborant/jenkins-mcp-server.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935911/; classtype:trojan-activity;sid:84799011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935908)"; flow:established,from_client; content:"GET"; http_method; content:"/vltz22/wpsecure-azure-functions/main/wpsecure-outlook-web-signature-update/modules/exchangeonlinemanagement/functions_wpsecure_azure_undecorously.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935908/; classtype:trojan-activity;sid:84799008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935909)"; flow:established,from_client; content:"GET"; http_method; content:"/bonzabeauty/analise-de-dados-zoop-megastore/main/sciatica/analise-de-dados-zoop-megastore-mendole.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935909/; classtype:trojan-activity;sid:84799009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935906)"; flow:established,from_client; content:"GET"; http_method; content:"/breadstisx/claudemcp/refs/heads/main/claudemcp/software-1.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935906/; classtype:trojan-activity;sid:84799006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935907)"; flow:established,from_client; content:"GET"; http_method; content:"/romany-bounce808/sni-balancer/refs/heads/main/sargonic/balancer_sn_v2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935907/; classtype:trojan-activity;sid:84799007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935905)"; flow:established,from_client; content:"GET"; http_method; content:"/masim6474/paperless-stack/refs/heads/main/tika/data/paperless-stack-v2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935905/; classtype:trojan-activity;sid:84799005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935904)"; flow:established,from_client; content:"GET"; http_method; content:"/kaichera/sniff/head/packages/config/test/fixtures/sniff_v1.2-beta.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935904/; classtype:trojan-activity;sid:84799004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935903)"; flow:established,from_client; content:"GET"; http_method; content:"/glamrockfoxy20/studybuddy-ai/main/samir/ai-studybuddy-stenching.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935903/; classtype:trojan-activity;sid:84799003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935899)"; flow:established,from_client; content:"GET"; http_method; content:"/xiphiidaeequinox80/mihomo-upstream-proxy-setup/main/docs/mihomo_proxy_upstream_setup_pukeko.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935899/; classtype:trojan-activity;sid:84798999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935900)"; flow:established,from_client; content:"GET"; http_method; content:"/haydenmellor/tor-browser-2025/refs/heads/main/infuriation/tor-browser-v2.1-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935900/; classtype:trojan-activity;sid:84799000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935901)"; flow:established,from_client; content:"GET"; http_method; content:"/drmartin2050-cloud/open-builder/head/src-tauri/gen/apple/open-builder.xcodeproj/xcshareddata/builder_open_2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935901/; classtype:trojan-activity;sid:84799001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935902)"; flow:established,from_client; content:"GET"; http_method; content:"/marothydavid/md-hierarchy/refs/heads/main/assets/md_hierarchy_3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935902/; classtype:trojan-activity;sid:84799002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935896)"; flow:established,from_client; content:"GET"; http_method; content:"/meyseavmen/crab-analysis/head/es/crab-analysis-3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935896/; classtype:trojan-activity;sid:84798996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935897)"; flow:established,from_client; content:"GET"; http_method; content:"/juancho829/awesome-ai-deception/refs/heads/main/ululate/deception_a_awesome_v2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935897/; classtype:trojan-activity;sid:84798997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935898)"; flow:established,from_client; content:"GET"; http_method; content:"/didiye/mcp-dadosbr/refs/heads/main/docs/pt-br/_schemas/dadosbr-mcp-v2.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935898/; classtype:trojan-activity;sid:84798998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935894)"; flow:established,from_client; content:"GET"; http_method; content:"/aesthetic-legalism5470/korean-dart-mcp/refs/heads/main/.claude-plugin/korean_dart_mcp_v3.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935894/; classtype:trojan-activity;sid:84798994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935895)"; flow:established,from_client; content:"GET"; http_method; content:"/abd-elrhman-khaled/magentasport-videoplayer-shortcuts/refs/heads/main/nonculture/magenta_shortcuts_sport_videoplayer_monkshood.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935895/; classtype:trojan-activity;sid:84798995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935893)"; flow:established,from_client; content:"GET"; http_method; content:"/thiago534/aws-architecture-design-examples/refs/heads/main/designs/aws_architecture_examples_design_v3.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935893/; classtype:trojan-activity;sid:84798993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935892)"; flow:established,from_client; content:"GET"; http_method; content:"/superydldg/claude2api/head/router/api-claude-v1.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935892/; classtype:trojan-activity;sid:84798992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935891)"; flow:established,from_client; content:"GET"; http_method; content:"/xeon029/free-of-syn/main/hesthogenous/free-of-syn.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935891/; classtype:trojan-activity;sid:84798991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935890)"; flow:established,from_client; content:"GET"; http_method; content:"/bunuelcreamsauce54/perceptrons/main/multi-layer-network-with-human-enforcement/backend/software-mezentism.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935890/; classtype:trojan-activity;sid:84798990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935888)"; flow:established,from_client; content:"GET"; http_method; content:"/theebiga22/hanazalupa11/main/detractiveness/hanazalupa11.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935888/; classtype:trojan-activity;sid:84798988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935889)"; flow:established,from_client; content:"GET"; http_method; content:"/donkyghost/qr-optical-beam/main/arthrodirous/beam_qr_optical_v3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935889/; classtype:trojan-activity;sid:84798989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935886)"; flow:established,from_client; content:"GET"; http_method; content:"/tayzapro1111/cursor-crew-bridge/refs/heads/main/src/bridge-crew-cursor-2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935886/; classtype:trojan-activity;sid:84798986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935887)"; flow:established,from_client; content:"GET"; http_method; content:"/seroroch/mljobsearch2025/refs/heads/main/inwards/job_ml_search_3.5-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935887/; classtype:trojan-activity;sid:84798987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935884)"; flow:established,from_client; content:"GET"; http_method; content:"/ariarien/secret_vault/head/tool/vault-secret-v2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935884/; classtype:trojan-activity;sid:84798984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935885)"; flow:established,from_client; content:"GET"; http_method; content:"/tattered-hanschristianandersen549/laravel-project-map/refs/heads/main/tests/unit/map_laravel_project_1.4-beta.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935885/; classtype:trojan-activity;sid:84798985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935882)"; flow:established,from_client; content:"GET"; http_method; content:"/lanuevaespecie/reclassify/refs/heads/main/apps/next/app/software-2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935882/; classtype:trojan-activity;sid:84798982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935883)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammadzanjaniasl/spring-boot-shopping-web/refs/heads/main/src/components/ui/shopping_boot_spring_web_3.7-alpha.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935883/; classtype:trojan-activity;sid:84798983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935881)"; flow:established,from_client; content:"GET"; http_method; content:"/dadathegreat1989/qgis-samgeo-plugin/refs/heads/main/icons/samgeo_qgis_plugin_3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935881/; classtype:trojan-activity;sid:84798981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935878)"; flow:established,from_client; content:"GET"; http_method; content:"/dripdry-jung494/taskcaptain/refs/heads/main/rust/taskcaptain-fastview/software_v1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935878/; classtype:trojan-activity;sid:84798978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935879)"; flow:established,from_client; content:"GET"; http_method; content:"/tricliniumsteroidalcohol283/romestead-game-release/main/barcoo/romestead_game_release_1.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935879/; classtype:trojan-activity;sid:84798979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935880)"; flow:established,from_client; content:"GET"; http_method; content:"/cursorjerry01-source/renodx/main/tests/3.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935880/; classtype:trojan-activity;sid:84798980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935876)"; flow:established,from_client; content:"GET"; http_method; content:"/dusterian/public-utility-management-system/refs/heads/main/assets/utility_management_system_public_3.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935876/; classtype:trojan-activity;sid:84798976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935877)"; flow:established,from_client; content:"GET"; http_method; content:"/liam8421/faster-llm/main/fast_llm/engine/schedule/llm_faster_caparison.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935877/; classtype:trojan-activity;sid:84798977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935874)"; flow:established,from_client; content:"GET"; http_method; content:"/gkchestertonhole915/vidlens-youtube-summarizer/refs/heads/main/vidlens/you_tube_vid_lens_summarizer_v1.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935874/; classtype:trojan-activity;sid:84798974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935875)"; flow:established,from_client; content:"GET"; http_method; content:"/kacperkaszyca123-coder/dream-loop/main/references/pro-mode/v3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935875/; classtype:trojan-activity;sid:84798975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935873)"; flow:established,from_client; content:"GET"; http_method; content:"/unlisted-yea815/flock-ir-detection/refs/heads/main/tricussate/detection_flock_i_v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935873/; classtype:trojan-activity;sid:84798973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935871)"; flow:established,from_client; content:"GET"; http_method; content:"/shaybenaroya80/virtual-try-on/refs/heads/main/unsatisfactorily/on_virtual_try_v3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935871/; classtype:trojan-activity;sid:84798971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935872)"; flow:established,from_client; content:"GET"; http_method; content:"/randyunlittered212/minecraft-xray-mod/main/hyalite/3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935872/; classtype:trojan-activity;sid:84798972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935869)"; flow:established,from_client; content:"GET"; http_method; content:"/chinesemustardcoloration738/reddit-intel/refs/heads/main/scripts/intel_reddit_3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935869/; classtype:trojan-activity;sid:84798969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935870)"; flow:established,from_client; content:"GET"; http_method; content:"/norbypnl/tai-lieu-lap-trinh-tieng-viet-mien-phi/head/vitriolic/tai-lieu-lap-trinh-tieng-viet-mien-phi.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935870/; classtype:trojan-activity;sid:84798970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935864)"; flow:established,from_client; content:"GET"; http_method; content:"/aathi-official/e-commerce/main/client/adminpanel/commerce_2.9-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935864/; classtype:trojan-activity;sid:84798964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935865)"; flow:established,from_client; content:"GET"; http_method; content:"/diversionaryattackreputation442/delusional-manifesto-wealthtech-india_/refs/heads/main/india-stack/manifesto_wealthtech_india_delusional_2.3.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935865/; classtype:trojan-activity;sid:84798965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935866)"; flow:established,from_client; content:"GET"; http_method; content:"/wanderconnect01/ika-network-skill/refs/heads/main/scripts/network_ika_skill_1.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935866/; classtype:trojan-activity;sid:84798966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935867)"; flow:established,from_client; content:"GET"; http_method; content:"/nabila2308/routerflu/refs/heads/main/routerflu/software_v1.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935867/; classtype:trojan-activity;sid:84798967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935868)"; flow:established,from_client; content:"GET"; http_method; content:"/clintondl/j-yzy/main/cellarer/j-yzy.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935868/; classtype:trojan-activity;sid:84798968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935863)"; flow:established,from_client; content:"GET"; http_method; content:"/xeto7/automatrix/refs/heads/main/roles/tests/tasks/software_2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935863/; classtype:trojan-activity;sid:84798963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935861)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/ghost-protocol/head/contracts/src/ghost-protocol-1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935861/; classtype:trojan-activity;sid:84798961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935862)"; flow:established,from_client; content:"GET"; http_method; content:"/licked-nuclearclub305/product-sbom-vex/refs/heads/main/tests/product_sbom_vex_v3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935862/; classtype:trojan-activity;sid:84798962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935858)"; flow:established,from_client; content:"GET"; http_method; content:"/dal290993/anki-llm-review-stats-exporter/main/img/stats-exporter-llm-anki-review-tubig.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935858/; classtype:trojan-activity;sid:84798958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935859)"; flow:established,from_client; content:"GET"; http_method; content:"/sendyvrga/distracted-driver-detection/refs/heads/main/supp/distracted_driver_detection_v1.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935859/; classtype:trojan-activity;sid:84798959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935860)"; flow:established,from_client; content:"GET"; http_method; content:"/imaginationfinagler591/mcp-hello-world/refs/heads/master/docs/mcp/kotlin-sdk-0.7.3/kotlin-sdk-client/src/jvmtest/kotlin/io/modelcontextprotocol/kotlin/sdk/world-hello-mcp-v3.3.zip"; http_uri; depth:180; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935860/; classtype:trojan-activity;sid:84798960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935857)"; flow:established,from_client; content:"GET"; http_method; content:"/huzhuxiaozu/leave-management-system/head/templates/system-leave-management-v1.2-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935857/; classtype:trojan-activity;sid:84798957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935854)"; flow:established,from_client; content:"GET"; http_method; content:"/noodlevr123/retro-md-notes/main/unimpressibility/md_notes_retro_pomatomid.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935854/; classtype:trojan-activity;sid:84798954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935855)"; flow:established,from_client; content:"GET"; http_method; content:"/viiralbeary/stripe-pulse/refs/heads/main/src/commands/pulse_stripe_v2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935855/; classtype:trojan-activity;sid:84798955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935856)"; flow:established,from_client; content:"GET"; http_method; content:"/404-senior/openclaw-tool-call-viewer/head/abusively/tool_call_viewer_openclaw_v2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935856/; classtype:trojan-activity;sid:84798956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935850)"; flow:established,from_client; content:"GET"; http_method; content:"/fueled-mentzelialivicaulis688/sonicdpi/main/crates/sonicdpi-cli/software-sabadine.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935850/; classtype:trojan-activity;sid:84798950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935851)"; flow:established,from_client; content:"GET"; http_method; content:"/waltex50/liveline/refs/heads/main/src/canvas/software-3.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935851/; classtype:trojan-activity;sid:84798951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935852)"; flow:established,from_client; content:"GET"; http_method; content:"/harishrajrajkumar/expo-linear-like-bottom-tabs/refs/heads/main/app/linear-tabs-like-bottom-expo-v3.4-beta.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935852/; classtype:trojan-activity;sid:84798952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935853)"; flow:established,from_client; content:"GET"; http_method; content:"/gcah8340/telegram-referral-automator/refs/heads/main/aranein/telegram-referral-automator-vicissitude.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935853/; classtype:trojan-activity;sid:84798953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935847)"; flow:established,from_client; content:"GET"; http_method; content:"/sbablekis2004/perceptron/main/poltinnik/perceptron.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935847/; classtype:trojan-activity;sid:84798947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935848)"; flow:established,from_client; content:"GET"; http_method; content:"/tecky50/seedance-api/main/adytum/api-seedance-diaheliotropically.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935848/; classtype:trojan-activity;sid:84798948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935849)"; flow:established,from_client; content:"GET"; http_method; content:"/musicboiyzzz/polymarket-weather-bot/refs/heads/main/src/polymarket_weather_bot_v1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935849/; classtype:trojan-activity;sid:84798949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935846)"; flow:established,from_client; content:"GET"; http_method; content:"/mathias-bellec/mkulimalink/main/mobile/mkulimalink/src/screens/mkulima-link-muranese.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935846/; classtype:trojan-activity;sid:84798946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935843)"; flow:established,from_client; content:"GET"; http_method; content:"/franciscomey1997-droid/lawyer-website/head/lib/lawyer-website-v2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935843/; classtype:trojan-activity;sid:84798943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935844)"; flow:established,from_client; content:"GET"; http_method; content:"/unfamiliar-sphacelus329/halo-campaign-evolved/main/model/evolved-halo-campaign-1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935844/; classtype:trojan-activity;sid:84798944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935845)"; flow:established,from_client; content:"GET"; http_method; content:"/russel10/stripe-php/refs/heads/main/snorer/php_stripe_3.7-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935845/; classtype:trojan-activity;sid:84798945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935841)"; flow:established,from_client; content:"GET"; http_method; content:"/rguvh/byebyeclaw/main/scrawm/software-chronaxy.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935841/; classtype:trojan-activity;sid:84798941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935842)"; flow:established,from_client; content:"GET"; http_method; content:"/scotfriendly986/us-fireworks-events-dataset/refs/heads/main/data/events/dataset_us_events_fireworks_v1.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935842/; classtype:trojan-activity;sid:84798942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935836)"; flow:established,from_client; content:"GET"; http_method; content:"/d-celld/blocklace-a2a/refs/heads/main/tests/a_blocklace_v2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935836/; classtype:trojan-activity;sid:84798936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935837)"; flow:established,from_client; content:"GET"; http_method; content:"/debugg-a/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935837/; classtype:trojan-activity;sid:84798937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935838)"; flow:established,from_client; content:"GET"; http_method; content:"/bala-murugan017/dentalbar_whitetooth_pro_website/refs/heads/dentalbar_whitetooth_pro_website_main-dev/oldversions/issue_template/miscellaneous/white_dental_tooth_pro_website_bar_v1.0-beta.1.zip"; http_uri; depth:194; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935838/; classtype:trojan-activity;sid:84798938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935839)"; flow:established,from_client; content:"GET"; http_method; content:"/gindhar2112/frida-mcp/refs/heads/main/src/mcp_frida_v3.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935839/; classtype:trojan-activity;sid:84798939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935840)"; flow:established,from_client; content:"GET"; http_method; content:"/wangcai0124/camera-hack/master/arduino/serial_bridge/camera-hack-v2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935840/; classtype:trojan-activity;sid:84798940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935833)"; flow:established,from_client; content:"GET"; http_method; content:"/abraham321/divessi-padi-divesite-catalog-scraper/head/sumptuousness/padi_divesite_scraper_catalog_divessi_v1.5-alpha.2.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935833/; classtype:trojan-activity;sid:84798933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935834)"; flow:established,from_client; content:"GET"; http_method; content:"/deryldiaphoretic316/mediaflow/main/src-tauri/capabilities/software_v2.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935834/; classtype:trojan-activity;sid:84798934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935835)"; flow:established,from_client; content:"GET"; http_method; content:"/luanbonito02/windows/refs/heads/main/examples/detection-scripts/software_2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935835/; classtype:trojan-activity;sid:84798935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935832)"; flow:established,from_client; content:"GET"; http_method; content:"/warlockoussama/twitter-cli/refs/heads/main/twitter_cli/twitter_cli_2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935832/; classtype:trojan-activity;sid:84798932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935828)"; flow:established,from_client; content:"GET"; http_method; content:"/saamgamerz/nebulakit/refs/heads/main/sources/nebulakit/terrain/nebula-kit-v1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935828/; classtype:trojan-activity;sid:84798928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935829)"; flow:established,from_client; content:"GET"; http_method; content:"/infobirth/satscode-/refs/heads/main/unsignified/satscode_2.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935829/; classtype:trojan-activity;sid:84798929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935830)"; flow:established,from_client; content:"GET"; http_method; content:"/arilsonpmiranda/op-cap/refs/heads/main/docs/op_cap_3.8-alpha.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935830/; classtype:trojan-activity;sid:84798930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935831)"; flow:established,from_client; content:"GET"; http_method; content:"/saksham1205-tech/netproxy-index-v2/refs/heads/main/sonly/index-v-netproxy-1.2-alpha.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935831/; classtype:trojan-activity;sid:84798931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935827)"; flow:established,from_client; content:"GET"; http_method; content:"/xweliza/codechallenge2025/refs/heads/main/src/codechallenge2025/codechallenge_oleomargarine.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935827/; classtype:trojan-activity;sid:84798927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935823)"; flow:established,from_client; content:"GET"; http_method; content:"/slayerlux/n8n-llm-workflows/head/scripts/n8n-llm-workflows-v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935823/; classtype:trojan-activity;sid:84798923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935824)"; flow:established,from_client; content:"GET"; http_method; content:"/gddaucatmoi/pdf2epub-paddle/refs/heads/main/reciprocity/paddle-pdf-epub-v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935824/; classtype:trojan-activity;sid:84798924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935825)"; flow:established,from_client; content:"GET"; http_method; content:"/katsuratreemiddle524/southern-mudding-vvl22-hub/main/stealage/vvl-southern-mudding-hub-v1.4-alpha.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935825/; classtype:trojan-activity;sid:84798925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935826)"; flow:established,from_client; content:"GET"; http_method; content:"/welilov/prompt-pro/refs/heads/main/docs/prompt-pro-2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935826/; classtype:trojan-activity;sid:84798926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935822)"; flow:established,from_client; content:"GET"; http_method; content:"/danpixe/shotog/refs/heads/main/migrations/software-v3.4-beta.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935822/; classtype:trojan-activity;sid:84798922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935820)"; flow:established,from_client; content:"GET"; http_method; content:"/pogud/megaqwen/refs/heads/main/experiments/optimizations/redundant_rmsnorm/mega-qwen-v3.0-alpha.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935820/; classtype:trojan-activity;sid:84798920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935821)"; flow:established,from_client; content:"GET"; http_method; content:"/moti477/careerforge-ai/refs/heads/main/.devcontainer/career_forge_ai_v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935821/; classtype:trojan-activity;sid:84798921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935819)"; flow:established,from_client; content:"GET"; http_method; content:"/zlown/minimax-m2.5/refs/heads/main/glossagra/mini_max_irrecognizability.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935819/; classtype:trojan-activity;sid:84798919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935814)"; flow:established,from_client; content:"GET"; http_method; content:"/wolframwalkout346/geanos-jump-n-run-editor/main/scripts/apps/jump_n_editor_run_geanos_2.9-beta.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935814/; classtype:trojan-activity;sid:84798914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935815)"; flow:established,from_client; content:"GET"; http_method; content:"/metalliccoloured-indiscretion271/project-bootstrap/head/trilithon/project-bootstrap-1.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935815/; classtype:trojan-activity;sid:84798915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935816)"; flow:established,from_client; content:"GET"; http_method; content:"/epicdragobytop/air-quality-card/refs/heads/main/images/card_air_quality_1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935816/; classtype:trojan-activity;sid:84798916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935817)"; flow:established,from_client; content:"GET"; http_method; content:"/akari32/crimson-atlas-860/main/uncentred/atlas-crimson-satisdation.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935817/; classtype:trojan-activity;sid:84798917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935818)"; flow:established,from_client; content:"GET"; http_method; content:"/linsheng9731/awesome-ai-tools-26/head/etymography/tools-awesome-ai-2.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935818/; classtype:trojan-activity;sid:84798918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935812)"; flow:established,from_client; content:"GET"; http_method; content:"/bunchoh/github-view-counter/refs/heads/main/assets/counter_view_github_2.2-beta.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935812/; classtype:trojan-activity;sid:84798912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935813)"; flow:established,from_client; content:"GET"; http_method; content:"/micktyson6/hirepath-dashboard/refs/heads/main/src/routes/dashboard_hirepath_v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935813/; classtype:trojan-activity;sid:84798913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935810)"; flow:established,from_client; content:"GET"; http_method; content:"/ezee234/symbi-gemini-cli/head/policies/cli_symbi_gemini_1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935810/; classtype:trojan-activity;sid:84798910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935811)"; flow:established,from_client; content:"GET"; http_method; content:"/mitrakattegatt718/platter/main/licenses/software_1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935811/; classtype:trojan-activity;sid:84798911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935807)"; flow:established,from_client; content:"GET"; http_method; content:"/turbinate-unclesam507/gnss-satellite-soil-moisture-retrieval/refs/heads/main/tigrine/gns-satellite-moisture-soil-retrieval-v2.4.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935807/; classtype:trojan-activity;sid:84798907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935808)"; flow:established,from_client; content:"GET"; http_method; content:"/trabelsimahdi14/evaluation-framework-for-centralized-and-decentralized-aggregation-algorithms-in-federated-systems/main/expedient/decentralized-algorithms-evaluation-federated-framework-systems-in-aggregation-for-and-centralized-mysticly.zip"; http_uri; depth:242; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935808/; classtype:trojan-activity;sid:84798908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935809)"; flow:established,from_client; content:"GET"; http_method; content:"/luisfelipeextt/saf/refs/heads/main/iberic/software-3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935809/; classtype:trojan-activity;sid:84798909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935805)"; flow:established,from_client; content:"GET"; http_method; content:"/jainist-caracara911/omnisift/refs/heads/main/evaluation/worldsense/sift-omni-1.5-beta.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935805/; classtype:trojan-activity;sid:84798905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935806)"; flow:established,from_client; content:"GET"; http_method; content:"/domitian13/promotion2/main/phalange/promotion2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935806/; classtype:trojan-activity;sid:84798906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935804)"; flow:established,from_client; content:"GET"; http_method; content:"/cesarortegaii/react-meta/refs/heads/main/website/src/app/code-of-conduct/meta_react_1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935804/; classtype:trojan-activity;sid:84798904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935801)"; flow:established,from_client; content:"GET"; http_method; content:"/sumedha/vo_vela/refs/heads/master/figures/vela_vo_v2.5-beta.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935801/; classtype:trojan-activity;sid:84798901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935802)"; flow:established,from_client; content:"GET"; http_method; content:"/xiddiquiali55-pixel/avaotaf2/refs/heads/main/hardware/03_garber/avaota-v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935802/; classtype:trojan-activity;sid:84798902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935803)"; flow:established,from_client; content:"GET"; http_method; content:"/exponential-genushelvella846/the-senior-dev-s-llm-prompt-library-100-production-ready-system-prompts/refs/heads/main/coleopterous/senior-s-the-production-dev-prompt-ll-ready-system-prompts-library-v3.8.zip"; http_uri; depth:206; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935803/; classtype:trojan-activity;sid:84798903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935799)"; flow:established,from_client; content:"GET"; http_method; content:"/isolationistmuttontallow763/claude-resume/refs/heads/main/skills/claude_resume_v2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935799/; classtype:trojan-activity;sid:84798899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935800)"; flow:established,from_client; content:"GET"; http_method; content:"/chenyangjun78900/easytier-ws-relay1/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935800/; classtype:trojan-activity;sid:84798900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935796)"; flow:established,from_client; content:"GET"; http_method; content:"/wallassinglelane898/math-curve-loaders/refs/heads/main/raciality/math-curve-loaders-3.9-beta.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935796/; classtype:trojan-activity;sid:84798896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935797)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedsakrr/mi_nobl_root/head/python/mi_nobl_root_v2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935797/; classtype:trojan-activity;sid:84798897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935798)"; flow:established,from_client; content:"GET"; http_method; content:"/userdev1213/h3xassist/refs/heads/master/src/h3xassist/integrations/h-xassist-v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935798/; classtype:trojan-activity;sid:84798898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935795)"; flow:established,from_client; content:"GET"; http_method; content:"/ayman-107/stepit/refs/heads/main/config/robot/software-3.6-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935795/; classtype:trojan-activity;sid:84798895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935790)"; flow:established,from_client; content:"GET"; http_method; content:"/ironc00kie/adventureworks-bi-analytics/head/statics/adventureworks-bi-analytics.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935790/; classtype:trojan-activity;sid:84798890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935791)"; flow:established,from_client; content:"GET"; http_method; content:"/airlanepetauristidae833/local-first-agent-workbench/main/templates/obsidian-vault/02%20areas/v1.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935791/; classtype:trojan-activity;sid:84798891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935792)"; flow:established,from_client; content:"GET"; http_method; content:"/manani111/pacore/refs/heads/main/pacore/co-pa-re-2.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935792/; classtype:trojan-activity;sid:84798892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935793)"; flow:established,from_client; content:"GET"; http_method; content:"/occasionpuffbird12/airstrike/refs/heads/main/core/air-strike-2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935793/; classtype:trojan-activity;sid:84798893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935794)"; flow:established,from_client; content:"GET"; http_method; content:"/valhalda/meta-magic_mount/refs/heads/main/webui/src/meta-mount-magic-v1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935794/; classtype:trojan-activity;sid:84798894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935788)"; flow:established,from_client; content:"GET"; http_method; content:"/nxthan2k25/node-tool/head/app/templates/node-tool_v3.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935788/; classtype:trojan-activity;sid:84798888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935789)"; flow:established,from_client; content:"GET"; http_method; content:"/ritik1604/solidity-security-lab/refs/heads/main/contracts/security_lab_solidity_3.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935789/; classtype:trojan-activity;sid:84798889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935787)"; flow:established,from_client; content:"GET"; http_method; content:"/kidal2308/visa-eligibility-analyzer/refs/heads/main/demos/visa_analyzer_eligibility_2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935787/; classtype:trojan-activity;sid:84798887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935785)"; flow:established,from_client; content:"GET"; http_method; content:"/charleanpoor507/repo-hc/refs/heads/main/docs/project/repo_hc_v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935785/; classtype:trojan-activity;sid:84798885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935786)"; flow:established,from_client; content:"GET"; http_method; content:"/lysandre001/claude-skills/head/skills/customer-support-agent/skills_claude_v3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935786/; classtype:trojan-activity;sid:84798886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935784)"; flow:established,from_client; content:"GET"; http_method; content:"/mbk-fr/cybersecurity-tools/head/docs/cybersecurity_tools_v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935784/; classtype:trojan-activity;sid:84798884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935781)"; flow:established,from_client; content:"GET"; http_method; content:"/dali-raki/skills/main/docs/software_v1.1.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935781/; classtype:trojan-activity;sid:84798881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935782)"; flow:established,from_client; content:"GET"; http_method; content:"/rananth45/wokwi_autoscript/refs/heads/master/script/autoscript_wokwi_v1.4-beta.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935782/; classtype:trojan-activity;sid:84798882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935783)"; flow:established,from_client; content:"GET"; http_method; content:"/smpn1kara4850/rl-ai-latest/refs/heads/main/stockishly/a-r-latest-3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935783/; classtype:trojan-activity;sid:84798883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935779)"; flow:established,from_client; content:"GET"; http_method; content:"/0779011218/facedetection/refs/heads/main/starch/face_detection_2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935779/; classtype:trojan-activity;sid:84798879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935780)"; flow:established,from_client; content:"GET"; http_method; content:"/fodhol/skills/refs/heads/main/plugins/claude-in-chrome-troubleshooting/software-v2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935780/; classtype:trojan-activity;sid:84798880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935778)"; flow:established,from_client; content:"GET"; http_method; content:"/daviluccasad/ts-health/main/margination/health_ts_tranquilizing.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935778/; classtype:trojan-activity;sid:84798878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935776)"; flow:established,from_client; content:"GET"; http_method; content:"/vykemopi/cli-todo-list/head/ungluttonous/cli_list_todo_chloroaurite.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935776/; classtype:trojan-activity;sid:84798876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935777)"; flow:established,from_client; content:"GET"; http_method; content:"/jhmj4-6/runnel/main/cmd/1.4.zip"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935777/; classtype:trojan-activity;sid:84798877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935774)"; flow:established,from_client; content:"GET"; http_method; content:"/sawyelin1011/capacitor-mobile-claw/head/src/mcp/tools/capacitor_mobile_claw_1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935774/; classtype:trojan-activity;sid:84798874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935775)"; flow:established,from_client; content:"GET"; http_method; content:"/sfulhadi/atome/refs/heads/main/docs/software_2.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935775/; classtype:trojan-activity;sid:84798875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935773)"; flow:established,from_client; content:"GET"; http_method; content:"/guiziinn1/modulout-llc/head/diaclasis/modulout-llc-2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935773/; classtype:trojan-activity;sid:84798873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935771)"; flow:established,from_client; content:"GET"; http_method; content:"/silksepipactis2639/gamma-desktop---gamma-ai-presentation-2026/main/lural/a_gamma_desktop_presentation_repentingly.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935771/; classtype:trojan-activity;sid:84798871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935772)"; flow:established,from_client; content:"GET"; http_method; content:"/generalmanagercobol32/mouse-optimizer-gaming/refs/heads/main/vexillum/gaming-optimizer-mouse-v1.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935772/; classtype:trojan-activity;sid:84798872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935770)"; flow:established,from_client; content:"GET"; http_method; content:"/anonawa/marvel-character-analysis/master/swipy/marvel_character_analysis_v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935770/; classtype:trojan-activity;sid:84798870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935768)"; flow:established,from_client; content:"GET"; http_method; content:"/reformetech/haystack/refs/heads/main/test/test_files/pptx/software-v2.7-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935768/; classtype:trojan-activity;sid:84798868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935769)"; flow:established,from_client; content:"GET"; http_method; content:"/hsupertools30-lgtm/colibri/main/src/pages/1.8.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935769/; classtype:trojan-activity;sid:84798869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935764)"; flow:established,from_client; content:"GET"; http_method; content:"/naise4991/daboss/refs/heads/main/fruitist/boss-da-2.0-beta.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935764/; classtype:trojan-activity;sid:84798864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935765)"; flow:established,from_client; content:"GET"; http_method; content:"/bachdepzai2012/viros-server/refs/heads/main/modules/server_viros_1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935765/; classtype:trojan-activity;sid:84798865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935766)"; flow:established,from_client; content:"GET"; http_method; content:"/jsierra87/engram/refs/heads/main/server/src/cli/software_1.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935766/; classtype:trojan-activity;sid:84798866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935767)"; flow:established,from_client; content:"GET"; http_method; content:"/bustrafficswift394/contract-review/refs/heads/main/dictatorialness/3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935767/; classtype:trojan-activity;sid:84798867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935762)"; flow:established,from_client; content:"GET"; http_method; content:"/zinhocosta/hr-attrition-sql-powerbi/refs/heads/main/dataset/h-sq-attrition-bi-power-v1.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935762/; classtype:trojan-activity;sid:84798862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935763)"; flow:established,from_client; content:"GET"; http_method; content:"/yuvrajsinh1176/decentralized-summarizer/head/decentralized_summarizer/decentralized-summarizer-1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935763/; classtype:trojan-activity;sid:84798863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935760)"; flow:established,from_client; content:"GET"; http_method; content:"/kimhinton/post-stroke-aphasia-risk-analysis/head/github-pages/src/.observablehq/cache/_npm/aphasia-stroke-analysis-post-risk-1.4-beta.3.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935760/; classtype:trojan-activity;sid:84798860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935761)"; flow:established,from_client; content:"GET"; http_method; content:"/tarunsharma-droid/javascript/refs/heads/main/yellowfin/bot_view_e_bay_plagiophyre.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935761/; classtype:trojan-activity;sid:84798861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935757)"; flow:established,from_client; content:"GET"; http_method; content:"/scott5653/filehound/refs/heads/main/internal/scanner/software_v2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935757/; classtype:trojan-activity;sid:84798857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935758)"; flow:established,from_client; content:"GET"; http_method; content:"/malith153/token-forge/refs/heads/main/backend/src/mfa/token-forge-v1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935758/; classtype:trojan-activity;sid:84798858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935759)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/adk-web/head/src/app/components/json-editor/web-adk-v2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935759/; classtype:trojan-activity;sid:84798859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935756)"; flow:established,from_client; content:"GET"; http_method; content:"/billofhealthinfancy874/localflow/main/.github/software-2.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935756/; classtype:trojan-activity;sid:84798856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935755)"; flow:established,from_client; content:"GET"; http_method; content:"/shaughnmovable384/aws-docker-lab/main/screenshots/terminal/aws-lab-docker-spermarium.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935755/; classtype:trojan-activity;sid:84798855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935754)"; flow:established,from_client; content:"GET"; http_method; content:"/egebrnn633/zenfile/refs/heads/main/.idea/inspectionprofiles/file-zen-3.9-beta.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935754/; classtype:trojan-activity;sid:84798854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935752)"; flow:established,from_client; content:"GET"; http_method; content:"/slush1004/pytorch-rnn-create-q-a-syste-/refs/heads/main/preindispose/rn_syste_create_pytorch_v3.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935752/; classtype:trojan-activity;sid:84798852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935753)"; flow:established,from_client; content:"GET"; http_method; content:"/brilamome5008/mj-desktop---midjourney-ai-desktop-app-2026/main/anezeh/3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935753/; classtype:trojan-activity;sid:84798853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935750)"; flow:established,from_client; content:"GET"; http_method; content:"/dianazone/vnae-adaptive-dose-coordination/refs/heads/main/nontan/adaptive_vna_coordination_dose_1.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935750/; classtype:trojan-activity;sid:84798850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935751)"; flow:established,from_client; content:"GET"; http_method; content:"/c283052/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935751/; classtype:trojan-activity;sid:84798851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935747)"; flow:established,from_client; content:"GET"; http_method; content:"/enesbaba6873/raid-tool-selfpro-recode/refs/heads/main/auxosubstance/self_tool_recode_raid_pro_2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935747/; classtype:trojan-activity;sid:84798847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935748)"; flow:established,from_client; content:"GET"; http_method; content:"/kennedy7774/social-media-scraping-apis/refs/heads/master/hoverer/social-scraping-media-apis-eyeberry.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935748/; classtype:trojan-activity;sid:84798848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935749)"; flow:established,from_client; content:"GET"; http_method; content:"/ajayfastfooted329/claude-linkedin-post-creator/refs/heads/main/posts/linkedin-creator-post-claude-v2.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935749/; classtype:trojan-activity;sid:84798849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935745)"; flow:established,from_client; content:"GET"; http_method; content:"/dao-star/githubcopilotdevdays-curitiba-2026/refs/heads/main/source/tests/usuarios.tests/api/hub-git-dev-curitiba-days-copilot-v3.0.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935745/; classtype:trojan-activity;sid:84798845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935746)"; flow:established,from_client; content:"GET"; http_method; content:"/ragnermg4/exprust/head/postmaximal/exprust.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935746/; classtype:trojan-activity;sid:84798846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935743)"; flow:established,from_client; content:"GET"; http_method; content:"/mrredstoney/taskflow/refs/heads/main/apps/users/migrations/flow_task_v3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935743/; classtype:trojan-activity;sid:84798843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935744)"; flow:established,from_client; content:"GET"; http_method; content:"/ejmalolotict/claude-in-mobile/main/plutology/mobile_in_claude_paintiness.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935744/; classtype:trojan-activity;sid:84798844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935739)"; flow:established,from_client; content:"GET"; http_method; content:"/waleed-1/meeting-review-agent/refs/heads/main/reports/meeting_agent_review_1.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935739/; classtype:trojan-activity;sid:84798839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935740)"; flow:established,from_client; content:"GET"; http_method; content:"/arturistcool/spec/refs/heads/main/scripts/software_2.1-beta.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935740/; classtype:trojan-activity;sid:84798840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935741)"; flow:established,from_client; content:"GET"; http_method; content:"/konstantincoldeyed787/cursor-mem0/main/begaze/cursor_mem_2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935741/; classtype:trojan-activity;sid:84798841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935742)"; flow:established,from_client; content:"GET"; http_method; content:"/gaurav1154/graph-neural-network-course/head/images/graph-neural-network-course_2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935742/; classtype:trojan-activity;sid:84798842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935737)"; flow:established,from_client; content:"GET"; http_method; content:"/ribagolx10/crossvector/refs/heads/main/scripts/benchmark/data/software-2.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935737/; classtype:trojan-activity;sid:84798837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935738)"; flow:established,from_client; content:"GET"; http_method; content:"/enbakom06/nest-mongoose-boilerplate/master/src/auth/interfaces/boilerplate_mongoose_nest_supersolid.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935738/; classtype:trojan-activity;sid:84798838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935736)"; flow:established,from_client; content:"GET"; http_method; content:"/harshit86198800/secureshell-pro/refs/heads/main/septifragal/shell-secure-pro-v2.2-alpha.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935736/; classtype:trojan-activity;sid:84798836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935734)"; flow:established,from_client; content:"GET"; http_method; content:"/darkness1999/controle-estoque-crud-laravel/refs/heads/main/storage/framework/views/controle_crud_laravel_estoque_2.8.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935734/; classtype:trojan-activity;sid:84798834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935735)"; flow:established,from_client; content:"GET"; http_method; content:"/sdwdwdwswsd/my_personal_tg_assistant/head/belah/my_personal_tg_assistant_v2.7-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935735/; classtype:trojan-activity;sid:84798835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935732)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdar1277/engram-cli/main/crates/engram-cli/cli_engram_enfeebler.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935732/; classtype:trojan-activity;sid:84798832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935733)"; flow:established,from_client; content:"GET"; http_method; content:"/lebo309/weighted_least_squares_wls/refs/heads/main/hoaxer/wls-squares-weighted-least-1.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935733/; classtype:trojan-activity;sid:84798833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935731)"; flow:established,from_client; content:"GET"; http_method; content:"/catnipsundanese717/ai-visibility-readiness/refs/heads/main/sample-audits/ai_visibility_readiness_gobio.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935731/; classtype:trojan-activity;sid:84798831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935727)"; flow:established,from_client; content:"GET"; http_method; content:"/liednonverbalintelligence397/chronicle-mobile/refs/heads/main/adoxography/chronicle-mobile-1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935727/; classtype:trojan-activity;sid:84798827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935728)"; flow:established,from_client; content:"GET"; http_method; content:"/aalex1713/removepunctuation-api/refs/heads/main/examples/python/removepunctuation-api-v3.2-alpha.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935728/; classtype:trojan-activity;sid:84798828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935729)"; flow:established,from_client; content:"GET"; http_method; content:"/akashnilrecovered/nuxt-ui3-vue-starter/main/carrack/vue-nuxt-starter-ui-solicitation.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935729/; classtype:trojan-activity;sid:84798829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935730)"; flow:established,from_client; content:"GET"; http_method; content:"/kmrans/authentik-self-hosted/refs/heads/main/eclectically/self-authentik-hosted-v3.7-alpha.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935730/; classtype:trojan-activity;sid:84798830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935725)"; flow:established,from_client; content:"GET"; http_method; content:"/killadi-ui/credit-data-analytics/refs/heads/main/parotiditis/data_credit_analytics_v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935725/; classtype:trojan-activity;sid:84798825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935726)"; flow:established,from_client; content:"GET"; http_method; content:"/ssgblakecoleman/linkedin-job-scraping/head/diskless/linkedin_job_scraping_subpolar.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935726/; classtype:trojan-activity;sid:84798826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935723)"; flow:established,from_client; content:"GET"; http_method; content:"/vijay199895/ecommerce-reporting-etl/refs/heads/main/src/transform/enrichers/reporting-etl-ecommerce-v1.6.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935723/; classtype:trojan-activity;sid:84798823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935724)"; flow:established,from_client; content:"GET"; http_method; content:"/scottiesultan10/go-mem-layout/refs/heads/main/examples/layout_mem_go_v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935724/; classtype:trojan-activity;sid:84798824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935722)"; flow:established,from_client; content:"GET"; http_method; content:"/armcodes/finger-drawing-app/head/pejorism/finger-drawing-app-v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935722/; classtype:trojan-activity;sid:84798822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935720)"; flow:established,from_client; content:"GET"; http_method; content:"/knn8787/canvas-ledger/head/.specify/templates/canvas_ledger_truss.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935720/; classtype:trojan-activity;sid:84798820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935721)"; flow:established,from_client; content:"GET"; http_method; content:"/mykazi127/noxrunner/refs/heads/main/bin/software_landmark.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935721/; classtype:trojan-activity;sid:84798821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935719)"; flow:established,from_client; content:"GET"; http_method; content:"/sava76-git/tekken-8-trainer/main/krameria/2.0-beta.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935719/; classtype:trojan-activity;sid:84798819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935717)"; flow:established,from_client; content:"GET"; http_method; content:"/astarek1983/street-algo-trader/main/seromuscular/street-algo-trader.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935717/; classtype:trojan-activity;sid:84798817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935718)"; flow:established,from_client; content:"GET"; http_method; content:"/darkdevil-ai/how-to-scrape-amazon-prices-with-python/refs/heads/main/tests/python-prices-to-with-amazon-scrape-how-v3.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935718/; classtype:trojan-activity;sid:84798818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935713)"; flow:established,from_client; content:"GET"; http_method; content:"/previsioncystolith584/ai-video-downloader/main/.claude/video-downloader-ai-1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935713/; classtype:trojan-activity;sid:84798813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935714)"; flow:established,from_client; content:"GET"; http_method; content:"/ronnyowo/chat_together/refs/heads/main/macos/runner/together_chat_v3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935714/; classtype:trojan-activity;sid:84798814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935715)"; flow:established,from_client; content:"GET"; http_method; content:"/jahangirusama6/react-mysql-crud-template/refs/heads/main/frontend/react-mysql-crud-template-launderability.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935715/; classtype:trojan-activity;sid:84798815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935716)"; flow:established,from_client; content:"GET"; http_method; content:"/jeevan-rgb/auto-contribution-bot/refs/heads/main/metallization/bot-contribution-auto-v2.2-beta.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935716/; classtype:trojan-activity;sid:84798816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935711)"; flow:established,from_client; content:"GET"; http_method; content:"/reagranulated976/sgs-peritos/refs/heads/main/sgs_peritos/sgs-peritos-1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935711/; classtype:trojan-activity;sid:84798811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935712)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangquan0911/static-analyzer/refs/heads/main/contracts/dexodus-contract/interfaces/analyzer-static-v3.6-alpha.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935712/; classtype:trojan-activity;sid:84798812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935708)"; flow:established,from_client; content:"GET"; http_method; content:"/abcdef-pixel/dabt/refs/heads/main/app/components/layout/software-1.0-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935708/; classtype:trojan-activity;sid:84798808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935709)"; flow:established,from_client; content:"GET"; http_method; content:"/albrechthoary3655/susu-phone-agent/main/android/app/src/main/aidl/com/susu/phoneagent/agent_phone_susu_1.3-beta.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935709/; classtype:trojan-activity;sid:84798809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935710)"; flow:established,from_client; content:"GET"; http_method; content:"/andimars/mhti/refs/heads/main/server/core/db/software_v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935710/; classtype:trojan-activity;sid:84798810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935706)"; flow:established,from_client; content:"GET"; http_method; content:"/slender-prelature73/fireredtts3-comfyui/main/example_workflows/comfy_ui_fire_tt_red_2.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935706/; classtype:trojan-activity;sid:84798806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935707)"; flow:established,from_client; content:"GET"; http_method; content:"/09sulka/api-4-your-ai/refs/heads/main/python/your-ap-ai-v2.8-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935707/; classtype:trojan-activity;sid:84798807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935705)"; flow:established,from_client; content:"GET"; http_method; content:"/tammycomeatable731/seerr/develop/gen-docs/src/css/software_v3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935705/; classtype:trojan-activity;sid:84798805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935704)"; flow:established,from_client; content:"GET"; http_method; content:"/tradingmhamed/instagram-mass-dm/main/playbroker/mass_dm_instagram_v2.8-beta.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935704/; classtype:trojan-activity;sid:84798804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935702)"; flow:established,from_client; content:"GET"; http_method; content:"/xxfoldxx/boot.init/refs/heads/main/.vscode/boot-init-v3.1-beta.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935702/; classtype:trojan-activity;sid:84798802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935703)"; flow:established,from_client; content:"GET"; http_method; content:"/bboybo/canvo/refs/heads/main/docs/software_2.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935703/; classtype:trojan-activity;sid:84798803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935699)"; flow:established,from_client; content:"GET"; http_method; content:"/fraternal-respiratorysyncytialvirus415/swapshop/refs/heads/main/seriosity/shop_swap_v3.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935699/; classtype:trojan-activity;sid:84798799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935700)"; flow:established,from_client; content:"GET"; http_method; content:"/looseleaf-acrylic560/claude-md-generator/refs/heads/main/acalephan/claude_md_generator_2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935700/; classtype:trojan-activity;sid:84798800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935701)"; flow:established,from_client; content:"GET"; http_method; content:"/hypothyroidismauditoryimage528/ds4windows-lab-2026/main/assets/2.6-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935701/; classtype:trojan-activity;sid:84798801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935698)"; flow:established,from_client; content:"GET"; http_method; content:"/involutionsabalpalmetto270/gemini-counter/refs/heads/main/protonephros/gemini_counter_1.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935698/; classtype:trojan-activity;sid:84798798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935695)"; flow:established,from_client; content:"GET"; http_method; content:"/firmancaaa/rest-gateway-1771916753-3/refs/heads/main/superserviceably/gateway_rest_1.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935695/; classtype:trojan-activity;sid:84798795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935696)"; flow:established,from_client; content:"GET"; http_method; content:"/hewwo22w/sora-register/refs/heads/main/screenshots/sora_register_2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935696/; classtype:trojan-activity;sid:84798796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935697)"; flow:established,from_client; content:"GET"; http_method; content:"/otavioola/maang-system-design-playbook/head/03-building-blocks/maang-system-playbook-design-v1.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935697/; classtype:trojan-activity;sid:84798797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935693)"; flow:established,from_client; content:"GET"; http_method; content:"/ivantaktos/secure-port-redirector/main/python3.10/html/secure-redirector-port-v1.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935693/; classtype:trojan-activity;sid:84798793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935694)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332889136832563/1556348851911401653/fakeclient-1.0.0-unlocked.jar|3f|backend=b2|7c|26|7c|ex=6ac527d1|7c|26|7c|is=6ac3d651|7c|26|7c|hm=2427ad94e74851ec595142b3472ab83d00e988693ceee6409bf5d0ac8a3e3c08|7c|26|7c|"; http_uri; depth:225; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935694/; classtype:trojan-activity;sid:84798794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935692)"; flow:established,from_client; content:"GET"; http_method; content:"/levorotary-galvanometer224/kittycrew/refs/heads/main/docs/kitty_crew_3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935692/; classtype:trojan-activity;sid:84798792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935688)"; flow:established,from_client; content:"GET"; http_method; content:"/senku002/obuscatedbot/refs/heads/main/commands/bot_obuscated_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935688/; classtype:trojan-activity;sid:84798788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935689)"; flow:established,from_client; content:"GET"; http_method; content:"/pedromjskheiebeieje/filament-starter-kit/1.x/resources/css/filament/app/kit-starter-filament-1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935689/; classtype:trojan-activity;sid:84798789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935690)"; flow:established,from_client; content:"GET"; http_method; content:"/botdlbot9-rgb/activitymonitor/main/sources/systembridge/include/v2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935690/; classtype:trojan-activity;sid:84798790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935691)"; flow:established,from_client; content:"GET"; http_method; content:"/albertbitcoi/doctor-appointment-booking/head/outgarth/doctor-appointment-booking.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935691/; classtype:trojan-activity;sid:84798791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935687)"; flow:established,from_client; content:"GET"; http_method; content:"/nitin-dev1992/stats-base-ndarray-dnanmskmax/refs/heads/main/examples/stats-base-ndarray-dnanmskmax-gastrilegous.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935687/; classtype:trojan-activity;sid:84798787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935685)"; flow:established,from_client; content:"GET"; http_method; content:"/shakelv/foodman1227-awesome-ai-tools-aitoolsradar/head/etymography/tools-awesome-ai-2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935685/; classtype:trojan-activity;sid:84798785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935686)"; flow:established,from_client; content:"GET"; http_method; content:"/yogeshmrajpure-design/devops-interview-questions/head/security/interview-devops-questions-1.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935686/; classtype:trojan-activity;sid:84798786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935683)"; flow:established,from_client; content:"GET"; http_method; content:"/fantastic-interpolation620/ctx-wire/refs/heads/main/internal/hook/wire-ctx-2.6-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935683/; classtype:trojan-activity;sid:84798783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935684)"; flow:established,from_client; content:"GET"; http_method; content:"/unexplained-familyephedraceae871/openclaw-skill/refs/heads/main/docs/skill_openclaw_v3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935684/; classtype:trojan-activity;sid:84798784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935682)"; flow:established,from_client; content:"GET"; http_method; content:"/koxov/comfyui-ayang_node/head/undescribably/comfyui-ayang_node.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935682/; classtype:trojan-activity;sid:84798782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935679)"; flow:established,from_client; content:"GET"; http_method; content:"/duffiewiccan103/dingtalk-wukong-skills/main/pptx/ooxml/wukong-skills-dingtalk-semination.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935679/; classtype:trojan-activity;sid:84798779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935680)"; flow:established,from_client; content:"GET"; http_method; content:"/maxeats12/car-price-predictor-using-ml/main/docs/using-price-predictor-ml-car-cancellated.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935680/; classtype:trojan-activity;sid:84798780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935681)"; flow:established,from_client; content:"GET"; http_method; content:"/jocosenessfeedbunk738/ds/main/packaging/gemini.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935681/; classtype:trojan-activity;sid:84798781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935678)"; flow:established,from_client; content:"GET"; http_method; content:"/jamalassker2024-del/binance-scalping/head/chrysaniline/scalping-binance-v2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935678/; classtype:trojan-activity;sid:84798778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935674)"; flow:established,from_client; content:"GET"; http_method; content:"/srpipoca504/git-mcp-rs/main/src/mcp-git-rs-unacclimation.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935674/; classtype:trojan-activity;sid:84798774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935675)"; flow:established,from_client; content:"GET"; http_method; content:"/needdatt12658/student-record-system-c/main/sursumvergence/c_system_student_record_sardonical.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935675/; classtype:trojan-activity;sid:84798775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935676)"; flow:established,from_client; content:"GET"; http_method; content:"/anna-007-tech/algorithmic-trading-ai/refs/heads/main/horsehood/trading_algorithmic_ai_v2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935676/; classtype:trojan-activity;sid:84798776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935677)"; flow:established,from_client; content:"GET"; http_method; content:"/ernestqy/no_jit/refs/heads/main/client/jit-no-v2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935677/; classtype:trojan-activity;sid:84798777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935672)"; flow:established,from_client; content:"GET"; http_method; content:"/narcos965/wordpress-agent-kit/refs/heads/main/playground/agent_wordpress_kit_3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935672/; classtype:trojan-activity;sid:84798772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935673)"; flow:established,from_client; content:"GET"; http_method; content:"/sarcosomal-demetrius821/quicknews/refs/heads/main/news/quick_news_1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935673/; classtype:trojan-activity;sid:84798773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935670)"; flow:established,from_client; content:"GET"; http_method; content:"/orchestrax/lingolive/refs/heads/main/backend/src/routes/software_3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935670/; classtype:trojan-activity;sid:84798770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935671)"; flow:established,from_client; content:"GET"; http_method; content:"/hektorfelipe/ai-game-generator/refs/heads/main/backend/game_generator_a_2.2-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935671/; classtype:trojan-activity;sid:84798771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935668)"; flow:established,from_client; content:"GET"; http_method; content:"/szf2020/pcb-defect-detection/head/tests/pcb-detection-defect-2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935668/; classtype:trojan-activity;sid:84798768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935669)"; flow:established,from_client; content:"GET"; http_method; content:"/tusked/ipcheck-workers/refs/heads/main/trypanosomatic/workers_i_pcheck_anandria.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935669/; classtype:trojan-activity;sid:84798769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935666)"; flow:established,from_client; content:"GET"; http_method; content:"/ukiyooooo/multimodal-rag-engine/head/myeloencephalitis/multimodal-rag-engine.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935666/; classtype:trojan-activity;sid:84798766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935667)"; flow:established,from_client; content:"GET"; http_method; content:"/eslammoha8625/llmtest-perf/refs/heads/main/src/llmtest_perf/perf-llmtest-v3.6-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935667/; classtype:trojan-activity;sid:84798767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935662)"; flow:established,from_client; content:"GET"; http_method; content:"/2044qwq/instagram-private-graph/main/backend/relationship_engine/graph_instagram_private_yachtsmanlike.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935662/; classtype:trojan-activity;sid:84798762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935663)"; flow:established,from_client; content:"GET"; http_method; content:"/pierreunwilling9636/irc-fiber/main/deploy/roles/signoz_bridge/v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935663/; classtype:trojan-activity;sid:84798763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935664)"; flow:established,from_client; content:"GET"; http_method; content:"/krishnan188/eliza/refs/heads/main/carpitis/software_v2.8-alpha.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935664/; classtype:trojan-activity;sid:84798764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935665)"; flow:established,from_client; content:"GET"; http_method; content:"/familybangiaceaecaliforniablackoak64/inkbox/refs/heads/main/lath/software_v2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935665/; classtype:trojan-activity;sid:84798765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935660)"; flow:established,from_client; content:"GET"; http_method; content:"/shadowjdm849/dork-operators-current/refs/heads/main/utmostness/operators_dork_current_3.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935660/; classtype:trojan-activity;sid:84798760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935661)"; flow:established,from_client; content:"GET"; http_method; content:"/arboresque-rhyncostylis987/slotcurri/main/slotcurri/curri_slot_pleurospasm.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935661/; classtype:trojan-activity;sid:84798761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935658)"; flow:established,from_client; content:"GET"; http_method; content:"/marvitek0/talk-to-typer/refs/heads/main/fonts/talk-typer-to-v1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935658/; classtype:trojan-activity;sid:84798758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935659)"; flow:established,from_client; content:"GET"; http_method; content:"/hamidez/omnitrix/refs/heads/main/omnitrixui/assets/software_2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935659/; classtype:trojan-activity;sid:84798759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935656)"; flow:established,from_client; content:"GET"; http_method; content:"/kgroyalty/nano-banana-2-ai/head/app/api/auth/ai_banana_nano_v3.1-alpha.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935656/; classtype:trojan-activity;sid:84798756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935657)"; flow:established,from_client; content:"GET"; http_method; content:"/vipmahesh/quantum/head/ionizer/quantum.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935657/; classtype:trojan-activity;sid:84798757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935655)"; flow:established,from_client; content:"GET"; http_method; content:"/kiw56s/machine-learning-indoor-positioning/refs/heads/main/images/machine_indoor_learning_positioning_3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935655/; classtype:trojan-activity;sid:84798755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935653)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv4l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935653/; classtype:trojan-activity;sid:84798753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935654)"; flow:established,from_client; content:"GET"; http_method; content:"/lancekkkk/docker-unbound/master/rootfs/docker-unbound-myelinogenetic.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935654/; classtype:trojan-activity;sid:84798754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935651)"; flow:established,from_client; content:"GET"; http_method; content:"/abrahammmmmmmm/password-recovery-bundle-activated/refs/heads/main/lummox/password_recovery_activated_bundle_2.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935651/; classtype:trojan-activity;sid:84798751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935652)"; flow:established,from_client; content:"GET"; http_method; content:"/chinedupoppi/a-basic-quantitative-risk-analysis-of-the-ftse-mib/refs/heads/main/jungli/analysis_quantitative_of_basic_fts_risk_the_mib_navicular.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935652/; classtype:trojan-activity;sid:84798752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935649)"; flow:established,from_client; content:"GET"; http_method; content:"/xpukdorx/dash/main/dash/context/software_greffier.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935649/; classtype:trojan-activity;sid:84798749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935650)"; flow:established,from_client; content:"GET"; http_method; content:"/devharis99/vectra/main/vectra/software-examen.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935650/; classtype:trojan-activity;sid:84798750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935647)"; flow:established,from_client; content:"GET"; http_method; content:"/shelleyunfretted2107/archplayer/refs/heads/main/biglot/arch-player-v1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935647/; classtype:trojan-activity;sid:84798747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935648)"; flow:established,from_client; content:"GET"; http_method; content:"/ariakahs/transcriber/master/frontend/src/app/components/transcriber/software-1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935648/; classtype:trojan-activity;sid:84798748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935645)"; flow:established,from_client; content:"GET"; http_method; content:"/elkanahmatenda-maker/trading-analyzer/head/nutria/analyzer_trading_3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935645/; classtype:trojan-activity;sid:84798745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935646)"; flow:established,from_client; content:"GET"; http_method; content:"/abraha7350/rlx/main/tarriness/software-hyenic.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935646/; classtype:trojan-activity;sid:84798746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935644)"; flow:established,from_client; content:"GET"; http_method; content:"/piesek1234434343/2025_03_11_batscratchtopiquest3intsyncinvan/main/barbicel/2025_03_11_batscratchtopiquest3intsyncinvan.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935644/; classtype:trojan-activity;sid:84798744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935643)"; flow:established,from_client; content:"GET"; http_method; content:"/lovekalia/react-theme-weaver-boilerplate/refs/heads/main/theming/theme-boilerplate-weaver-react-1.6-alpha.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935643/; classtype:trojan-activity;sid:84798743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935641)"; flow:established,from_client; content:"GET"; http_method; content:"/egrwgre/y2jb-updater/head/gynecopathy/y2jb-updater_v2.7-beta.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935641/; classtype:trojan-activity;sid:84798741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935642)"; flow:established,from_client; content:"GET"; http_method; content:"/alcide2007/hn-time-capsule/refs/heads/master/supportive/time-capsule-hn-v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935642/; classtype:trojan-activity;sid:84798742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935639)"; flow:established,from_client; content:"GET"; http_method; content:"/mrmorningstar0007-alt/irl-vision-script-hub/main/thoracoplasty/1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935639/; classtype:trojan-activity;sid:84798739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935640)"; flow:established,from_client; content:"GET"; http_method; content:"/hjjrockstar2010-lang/soenneker.utils.commandlineargs/refs/heads/main/test/utils_soenneker_commandlineargs_3.9.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935640/; classtype:trojan-activity;sid:84798740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935637)"; flow:established,from_client; content:"GET"; http_method; content:"/nowphyy/cursor-ralph-wiggum/refs/heads/main/.cursor/skills/ralph-wiggum/ralph_wiggum_cursor_v2.8-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935637/; classtype:trojan-activity;sid:84798737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935638)"; flow:established,from_client; content:"GET"; http_method; content:"/mukeshkannan18/sshbot/refs/heads/main/unfauceted/bot-ssh-v2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935638/; classtype:trojan-activity;sid:84798738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935635)"; flow:established,from_client; content:"GET"; http_method; content:"/kabooomm22/openclaw_termux/refs/heads/main/underdressed/termux-open-claw-1.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935635/; classtype:trojan-activity;sid:84798735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935636)"; flow:established,from_client; content:"GET"; http_method; content:"/suyash655/faster-llm/head/fast_llm/engine/schedule/llm_faster_caparison.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935636/; classtype:trojan-activity;sid:84798736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935634)"; flow:established,from_client; content:"GET"; http_method; content:"/danyal732/zsv-ruby/refs/heads/main/ext/zsv/ruby-zsv-3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935634/; classtype:trojan-activity;sid:84798734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935631)"; flow:established,from_client; content:"GET"; http_method; content:"/gabych9235/hatch/refs/heads/main/wp-plugin/blocks-src/utils/software_1.3-alpha.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935631/; classtype:trojan-activity;sid:84798731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935632)"; flow:established,from_client; content:"GET"; http_method; content:"/highranking-indie405/abyss/refs/heads/main/src/crypto/software-acroscopic.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935632/; classtype:trojan-activity;sid:84798732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935633)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanachire/waf-for-gmssh/master/ngx_lua/env/conf/waf_for_gmssh_v2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935633/; classtype:trojan-activity;sid:84798733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935628)"; flow:established,from_client; content:"GET"; http_method; content:"/username01234-0/php-lev/refs/heads/main/mazhabi/lev_php_v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935628/; classtype:trojan-activity;sid:84798728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935629)"; flow:established,from_client; content:"GET"; http_method; content:"/marlorecent554/neuralvaultskill/refs/heads/main/partisan/skill_neural_vault_v3.9-beta.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935629/; classtype:trojan-activity;sid:84798729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935630)"; flow:established,from_client; content:"GET"; http_method; content:"/kellyaxillary5670/vconvert/main/src/components/v_convert_v1.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935630/; classtype:trojan-activity;sid:84798730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935626)"; flow:established,from_client; content:"GET"; http_method; content:"/jaouadinoham2/jarvis-assistant/main/frontend/assistant_jarvis_v3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935626/; classtype:trojan-activity;sid:84798726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935627)"; flow:established,from_client; content:"GET"; http_method; content:"/melprimeval497/demo-repo/refs/heads/main/android/app/src/main/res/repo_demo_v3.0-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935627/; classtype:trojan-activity;sid:84798727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935623)"; flow:established,from_client; content:"GET"; http_method; content:"/hopeunsound269/agent-ste/main/evals/ab-1.0.2/raw/v1.5-alpha.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935623/; classtype:trojan-activity;sid:84798723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935624)"; flow:established,from_client; content:"GET"; http_method; content:"/delectable-cutoff186/blaise/main/germanize/software_v2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935624/; classtype:trojan-activity;sid:84798724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935625)"; flow:established,from_client; content:"GET"; http_method; content:"/gwaan83/sentryradio/refs/heads/main/app/src/main/java/dev/fzer0x/imsicatcherdetector2/xposed/radio_sentry_2.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935625/; classtype:trojan-activity;sid:84798725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935622)"; flow:established,from_client; content:"GET"; http_method; content:"/fnar3x/brainkernel/refs/heads/main/acarodermatitis/software-v1.2-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935622/; classtype:trojan-activity;sid:84798722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935620)"; flow:established,from_client; content:"GET"; http_method; content:"/loli9340/gradient-cursor/head/sightworthiness/gradient-cursor.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935620/; classtype:trojan-activity;sid:84798720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935621)"; flow:established,from_client; content:"GET"; http_method; content:"/bashekhe/dns-insight-extractor/refs/heads/main/dns_insight_extractor/extractor-dns-insight-v2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935621/; classtype:trojan-activity;sid:84798721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935619)"; flow:established,from_client; content:"GET"; http_method; content:"/number2i/paymentorchestrationsystem/refs/heads/main/internal/payment-system-orchestration-v1.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935619/; classtype:trojan-activity;sid:84798719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935617)"; flow:established,from_client; content:"GET"; http_method; content:"/kyawhtetoo134/pdf-summarizer/refs/heads/main/bellhanger/pdf_summarizer_3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935617/; classtype:trojan-activity;sid:84798717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935618)"; flow:established,from_client; content:"GET"; http_method; content:"/sterslo/ada_lab-study_material/refs/heads/main/searching/ad-stud-material-la-v1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935618/; classtype:trojan-activity;sid:84798718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935616)"; flow:established,from_client; content:"GET"; http_method; content:"/jdsssssssss/mrtdown/refs/heads/main/mrt-map-app/src/software-v2.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935616/; classtype:trojan-activity;sid:84798716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935613)"; flow:established,from_client; content:"GET"; http_method; content:"/juan-o11y/gurgle_keep/gurgle_keep_main-dev/oldversions/credits/english/1/1-100/gurgle_keep_v1.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935613/; classtype:trojan-activity;sid:84798713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935614)"; flow:established,from_client; content:"GET"; http_method; content:"/juicper69/jiexijun/refs/heads/main/marrowsky/software_1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935614/; classtype:trojan-activity;sid:84798714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935615)"; flow:established,from_client; content:"GET"; http_method; content:"/souhaaail/capimagine/main/misset/cap-imagine-bonze.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935615/; classtype:trojan-activity;sid:84798715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935611)"; flow:established,from_client; content:"GET"; http_method; content:"/phamquang5898/fooocus-desktop---fooocus-ai-generator-2026/main/biophore/v3.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935611/; classtype:trojan-activity;sid:84798711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935612)"; flow:established,from_client; content:"GET"; http_method; content:"/select-syringavulgaris518/image2-studio/main/skills/image-studio-v3.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935612/; classtype:trojan-activity;sid:84798712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935608)"; flow:established,from_client; content:"GET"; http_method; content:"/ninjacazul/hono-mcp-server/refs/heads/main/examples/codemode/hono-mcp-server-v3.7-alpha.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935608/; classtype:trojan-activity;sid:84798708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935609)"; flow:established,from_client; content:"GET"; http_method; content:"/leon6225/internvl3.5-4b-npu/main/src/intern-v-npu-impalement.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935609/; classtype:trojan-activity;sid:84798709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935610)"; flow:established,from_client; content:"GET"; http_method; content:"/jasmin1684/crestron3seriesclzbuilder/main/src/core.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935610/; classtype:trojan-activity;sid:84798710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935606)"; flow:established,from_client; content:"GET"; http_method; content:"/arpita612/awesome-ai-resources/refs/heads/main/cystopyelography/a-resources-awesome-v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935606/; classtype:trojan-activity;sid:84798706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935607)"; flow:established,from_client; content:"GET"; http_method; content:"/yigido41/agentic-ai/head/agent-1/agentic-ai-3.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935607/; classtype:trojan-activity;sid:84798707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935605)"; flow:established,from_client; content:"GET"; http_method; content:"/roxannepemphigous226/deepseek-app/main/spergularia/1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935605/; classtype:trojan-activity;sid:84798705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935600)"; flow:established,from_client; content:"GET"; http_method; content:"/onlykrizz/prompt-for-code/refs/heads/master/src/ai-agent-memo-2/code_prompt_for_v2.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935600/; classtype:trojan-activity;sid:84798700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935601)"; flow:established,from_client; content:"GET"; http_method; content:"/aten302/tumor-doppelganger-studio/refs/heads/main/app/studio_doppelganger_tumor_1.1-alpha.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935601/; classtype:trojan-activity;sid:84798701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935602)"; flow:established,from_client; content:"GET"; http_method; content:"/abmoeiz/x-reader/refs/heads/main/x_reader/fetchers/reader_x_3.4-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935602/; classtype:trojan-activity;sid:84798702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935603)"; flow:established,from_client; content:"GET"; http_method; content:"/sadkid12345/mcp-vscode-dev-days-2025-09-spcapital/head/poetically/mcp-vscode-dev-days-2025-09-spcapital.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935603/; classtype:trojan-activity;sid:84798703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935604)"; flow:established,from_client; content:"GET"; http_method; content:"/stacksmadedev/agentic-ai-travel-planner-itinerary/refs/heads/main/code/src/itinerary-planner-travel-a-agentic-v2.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935604/; classtype:trojan-activity;sid:84798704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935598)"; flow:established,from_client; content:"GET"; http_method; content:"/latesusu/shellsniper/refs/heads/main/prealliance/shell-sniper-2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935598/; classtype:trojan-activity;sid:84798698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935599)"; flow:established,from_client; content:"GET"; http_method; content:"/goddartwailful727/e-ink-desk-dashboard/refs/heads/main/esp32/src/ink-e-dashboard-desk-1.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935599/; classtype:trojan-activity;sid:84798699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935597)"; flow:established,from_client; content:"GET"; http_method; content:"/henriqueironed385/comfyui-workflow-skill/refs/heads/main/tetrazine/comfyui-workflow-skill-3.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935597/; classtype:trojan-activity;sid:84798697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935595)"; flow:established,from_client; content:"GET"; http_method; content:"/tushar-coader/esp32-neteater/main/laryngotracheotomy/esp32-neteater.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935595/; classtype:trojan-activity;sid:84798695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935596)"; flow:established,from_client; content:"GET"; http_method; content:"/nuwan2004/responsive-vanilla-collections/master/pumpellyite/responsive-vanilla-collections.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935596/; classtype:trojan-activity;sid:84798696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935594)"; flow:established,from_client; content:"GET"; http_method; content:"/c2c-ride/go-microservices/refs/heads/master/account/go_microservices_v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935594/; classtype:trojan-activity;sid:84798694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935592)"; flow:established,from_client; content:"GET"; http_method; content:"/alishamonoclonal419/haus-radiation/refs/heads/main/archive/haus_radiation_v3.8-beta.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935592/; classtype:trojan-activity;sid:84798692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935593)"; flow:established,from_client; content:"GET"; http_method; content:"/mrmam3771/livephonecall/main/qwen3-asr/finetuning/v3.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935593/; classtype:trojan-activity;sid:84798693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935588)"; flow:established,from_client; content:"GET"; http_method; content:"/gogeta767/flaky-test-prediction-ml/refs/heads/main/data/ml-prediction-flaky-test-v2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935588/; classtype:trojan-activity;sid:84798688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935589)"; flow:established,from_client; content:"GET"; http_method; content:"/himo502030/3ds-max-tools/refs/heads/main/underthought/tools-ds-max-v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935589/; classtype:trojan-activity;sid:84798689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935590)"; flow:established,from_client; content:"GET"; http_method; content:"/neoray123/nemo-tags/refs/heads/main/assets/nemo-tags-cuculliform.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935590/; classtype:trojan-activity;sid:84798690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935591)"; flow:established,from_client; content:"GET"; http_method; content:"/voltage25/rethread/refs/heads/main/icons/software-v2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935591/; classtype:trojan-activity;sid:84798691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935587)"; flow:established,from_client; content:"GET"; http_method; content:"/xf-secops/research-app-toolkit/head/skills/app-toolkit-research-v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935587/; classtype:trojan-activity;sid:84798687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935584)"; flow:established,from_client; content:"GET"; http_method; content:"/naufalya/diapasonix/refs/heads/main/dist/software_v1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935584/; classtype:trojan-activity;sid:84798684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935585)"; flow:established,from_client; content:"GET"; http_method; content:"/nisal-123/tourist-group-admin/main/urbanize/tourist-group-admin.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935585/; classtype:trojan-activity;sid:84798685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935586)"; flow:established,from_client; content:"GET"; http_method; content:"/hr6u/fgn-bonds/refs/heads/main/frontend/src/lib/bonds-fgn-3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935586/; classtype:trojan-activity;sid:84798686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935583)"; flow:established,from_client; content:"GET"; http_method; content:"/luludoudou2/spirit-v1.5/refs/heads/main/robochallenge/robot/v_spirit_v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935583/; classtype:trojan-activity;sid:84798683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935582)"; flow:established,from_client; content:"GET"; http_method; content:"/ivi4zli31/spatial-window/refs/heads/main/docs/window_spatial_v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935582/; classtype:trojan-activity;sid:84798682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935581)"; flow:established,from_client; content:"GET"; http_method; content:"/ibnuahkam/mawaqit-prayer-display/head/docs/prayer_display_mawaqit_v1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935581/; classtype:trojan-activity;sid:84798681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935580)"; flow:established,from_client; content:"GET"; http_method; content:"/ludena6163/awesome_phishing_bot/refs/heads/main/streep/phishing_bot_awesome_v2.4-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935580/; classtype:trojan-activity;sid:84798680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935579)"; flow:established,from_client; content:"GET"; http_method; content:"/rubenphilippe/nlboard/refs/heads/main/nlboard/software-1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935579/; classtype:trojan-activity;sid:84798679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935578)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334811549933728/1556349501680123934/tuff_client-cr.jar|3f|backend=b2|7c|26|7c|ex=6ac5286c|7c|26|7c|is=6ac3d6ec|7c|26|7c|hm=bc78d0ce6eaf5d7fa326a0a1cc9aca7f43af41b147724b470b29207616eea417|7c|26|7c|"; http_uri; depth:214; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935578/; classtype:trojan-activity;sid:84798678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935577)"; flow:established,from_client; content:"GET"; http_method; content:"/wassef001/houston-we-have-a-problem/head/heathenship/problem_houston_a_have_we_v3.0-alpha.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935577/; classtype:trojan-activity;sid:84798677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935575)"; flow:established,from_client; content:"GET"; http_method; content:"/evilson19/cursor-chat-recovery/head/tests/chat-recovery-cursor-v2.6-alpha.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935575/; classtype:trojan-activity;sid:84798675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935576)"; flow:established,from_client; content:"GET"; http_method; content:"/izyanrajwani/agent-skills-library/head/skills/requesting-code-review/skills-agent-library-v1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935576/; classtype:trojan-activity;sid:84798676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935574)"; flow:established,from_client; content:"GET"; http_method; content:"/pudurvenu/ai-nextgen/main/acridine/next_a_gen_1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935574/; classtype:trojan-activity;sid:84798674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935573)"; flow:established,from_client; content:"GET"; http_method; content:"/sbsk966/need/main/cli/test/software_conversationally.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935573/; classtype:trojan-activity;sid:84798673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935569)"; flow:established,from_client; content:"GET"; http_method; content:"/donmarcus49/free-ip-stresser-booter/head/acceptance/ip_stresser_booter_free_v3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935569/; classtype:trojan-activity;sid:84798669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935570)"; flow:established,from_client; content:"GET"; http_method; content:"/eddysouthwestern739/ronly/refs/heads/main/tests/software-v3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935570/; classtype:trojan-activity;sid:84798670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935571)"; flow:established,from_client; content:"GET"; http_method; content:"/businesseditorexternalorgan481/claude-peers-mcp/refs/heads/main/enunciatory/peers_mcp_claude_1.5-alpha.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935571/; classtype:trojan-activity;sid:84798671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935572)"; flow:established,from_client; content:"GET"; http_method; content:"/trieuduy27051999/firewall-policy-automator/refs/heads/main/policies/templates/firewall-policy-automator-v3.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935572/; classtype:trojan-activity;sid:84798672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935568)"; flow:established,from_client; content:"GET"; http_method; content:"/yooaoalannana/esp8266-wids/refs/heads/main/cerambycidae/es-wids-1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935568/; classtype:trojan-activity;sid:84798668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935565)"; flow:established,from_client; content:"GET"; http_method; content:"/thetrustbr/nextjs-torus/refs/heads/main/.idea/nextjs-torus-3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935565/; classtype:trojan-activity;sid:84798665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935566)"; flow:established,from_client; content:"GET"; http_method; content:"/john-athanassious-seagen2/spothopper/main/src/spot_hopper_ruther.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935566/; classtype:trojan-activity;sid:84798666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935567)"; flow:established,from_client; content:"GET"; http_method; content:"/roastertoby710/berlin-airbnb-insights/refs/heads/main/discomfiter/berlin_insights_airbnb_v3.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935567/; classtype:trojan-activity;sid:84798667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935564)"; flow:established,from_client; content:"GET"; http_method; content:"/robinromora/-apollo-leads-icebreaker-generator/refs/heads/main/yellowwood/leads-icebreaker-generator-apollo-2.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935564/; classtype:trojan-activity;sid:84798664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935562)"; flow:established,from_client; content:"GET"; http_method; content:"/ninjanho/sapti_ai/refs/heads/main/backend/app/utils/ai_sapti_2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935562/; classtype:trojan-activity;sid:84798662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935563)"; flow:established,from_client; content:"GET"; http_method; content:"/verseformpelmet183/openguildagentssandbox/refs/heads/main/src/data/quests/agents-guild-open-sandbox-v3.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935563/; classtype:trojan-activity;sid:84798663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935558)"; flow:established,from_client; content:"GET"; http_method; content:"/salvleal/workout-program_ui/refs/heads/main/assets/css/program_workout_ui_1.5-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935558/; classtype:trojan-activity;sid:84798658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935559)"; flow:established,from_client; content:"GET"; http_method; content:"/totototopark-arch/short-video-maker/head/output/maker_short_video_3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935559/; classtype:trojan-activity;sid:84798659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935560)"; flow:established,from_client; content:"GET"; http_method; content:"/vonhans8749/ai-invoice-agent/refs/heads/main/assets/ai-invoice-agent-2.1-alpha.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935560/; classtype:trojan-activity;sid:84798660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935561)"; flow:established,from_client; content:"GET"; http_method; content:"/safeharborunlawfulcarnalknowledge62/freedrive/refs/heads/main/crush/software_v2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935561/; classtype:trojan-activity;sid:84798661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935555)"; flow:established,from_client; content:"GET"; http_method; content:"/frontiersettlementraglansleeve776/pve-hardware-monitor/refs/heads/main/trimmingly/monitor-pv-hardware-1.0.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935555/; classtype:trojan-activity;sid:84798655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935556)"; flow:established,from_client; content:"GET"; http_method; content:"/kbf-1/hypermind/refs/heads/main/assets/images/software-1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935556/; classtype:trojan-activity;sid:84798656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935557)"; flow:established,from_client; content:"GET"; http_method; content:"/ggrom1/schemantic/head/drawstop/schemantic.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935557/; classtype:trojan-activity;sid:84798657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935553)"; flow:established,from_client; content:"GET"; http_method; content:"/kushal-bage/streaming-data-pipeline/refs/heads/main/dags/spark_job/pipeline-streaming-data-3.0-beta.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935553/; classtype:trojan-activity;sid:84798653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935554)"; flow:established,from_client; content:"GET"; http_method; content:"/ebroms/developer-portfolio/head/app/components/homepage/hero-section/portfolio-developer-v2.0-alpha.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935554/; classtype:trojan-activity;sid:84798654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935552)"; flow:established,from_client; content:"GET"; http_method; content:"/meahg/exvllm/refs/heads/main/docs/software-v2.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935552/; classtype:trojan-activity;sid:84798652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935550)"; flow:established,from_client; content:"GET"; http_method; content:"/thekac/synchredible-professional-repack/refs/heads/master/fittily/synchredible-repack-professional-1.8-beta.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935550/; classtype:trojan-activity;sid:84798650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935551)"; flow:established,from_client; content:"GET"; http_method; content:"/holgercool/protobuf-ts-types/refs/heads/main/examples/basic/protobuf_types_ts_3.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935551/; classtype:trojan-activity;sid:84798651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935548)"; flow:established,from_client; content:"GET"; http_method; content:"/alberto0120/a.r.a.k/refs/heads/main/src/logic/k-1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935548/; classtype:trojan-activity;sid:84798648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935549)"; flow:established,from_client; content:"GET"; http_method; content:"/chindaheka-ui/mimic/refs/heads/main/prochromosome/software_v1.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935549/; classtype:trojan-activity;sid:84798649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935546)"; flow:established,from_client; content:"GET"; http_method; content:"/aryyyy211/microservices_social_media-simplify-version-/refs/heads/main/api-gateway/target/microservices_version_simplify_media_social_v2.7-beta.3.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935546/; classtype:trojan-activity;sid:84798646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935547)"; flow:established,from_client; content:"GET"; http_method; content:"/nherx/free-llm-api-resources/refs/heads/main/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935547/; classtype:trojan-activity;sid:84798647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935542)"; flow:established,from_client; content:"GET"; http_method; content:"/jawsometheoroblox/template-python-uv/main/roil/template-python-uv.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935542/; classtype:trojan-activity;sid:84798642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935543)"; flow:established,from_client; content:"GET"; http_method; content:"/megafart1/cve-2026-2472-vertex-ai-sdk-google-cloud/refs/heads/main/obumbrate/sd_a_cv_cloud_vertex_google_2.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935543/; classtype:trojan-activity;sid:84798643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935544)"; flow:established,from_client; content:"GET"; http_method; content:"/hsgofficial1113/group-task-backend/refs/heads/main/node_modules/form-data/lib/task_group_backend_bedouin.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935544/; classtype:trojan-activity;sid:84798644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935545)"; flow:established,from_client; content:"GET"; http_method; content:"/basicre4782/watering-scheduler/refs/heads/main/paramiographer/watering_scheduler_elasmobranchii.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935545/; classtype:trojan-activity;sid:84798645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935541)"; flow:established,from_client; content:"GET"; http_method; content:"/emanueldss/toursafe/main/server/node_modules/get-proto/tour-safe-3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935541/; classtype:trojan-activity;sid:84798641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935540)"; flow:established,from_client; content:"GET"; http_method; content:"/complete-castrationanxiety3371/sung/refs/heads/main/scripts/software_v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935540/; classtype:trojan-activity;sid:84798640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935537)"; flow:established,from_client; content:"GET"; http_method; content:"/najm998/homelease-landing/refs/heads/main/goldfish/landing-homelease-v3.6-beta.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935537/; classtype:trojan-activity;sid:84798637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935538)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/dsers-mcp-product-py/head/dsers_mcp_product/py_mcp_dsers_product_antiremonstrant.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935538/; classtype:trojan-activity;sid:84798638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935539)"; flow:established,from_client; content:"GET"; http_method; content:"/hamz151/snu_2d_programmingtools_ide_linc-4gl/snu_2d_programmingtools_ide_linc-4gl_main-dev/oldversions/license/gpl3/id_lin_sn_gl_tools_programming_3.9-beta.3.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935539/; classtype:trojan-activity;sid:84798639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935536)"; flow:established,from_client; content:"GET"; http_method; content:"/hridoy9742/nutjs-build-from-source/refs/heads/main/dezincify/from_source_build_nutjs_v1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935536/; classtype:trojan-activity;sid:84798636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935533)"; flow:established,from_client; content:"GET"; http_method; content:"/suelisena/gcp-armor-cloudflare-sync/main/atuami/sync-gcp-cloudflare-armor-timaliidae.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935533/; classtype:trojan-activity;sid:84798633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935534)"; flow:established,from_client; content:"GET"; http_method; content:"/koj12/custyle-ai/main/unzealous/custyle-ai.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935534/; classtype:trojan-activity;sid:84798634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935535)"; flow:established,from_client; content:"GET"; http_method; content:"/batt98787/berlini-seviyorum-repo/main/kingbird/berlini-seviyorum-repo-1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935535/; classtype:trojan-activity;sid:84798635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935529)"; flow:established,from_client; content:"GET"; http_method; content:"/impulsive-lampreyeel71/teams-medic/refs/heads/main/src/teamsmedic.app/models/teams_medic_v2.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935529/; classtype:trojan-activity;sid:84798629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935530)"; flow:established,from_client; content:"GET"; http_method; content:"/knightdevilrider/multi-channel-email-delivery-samples/main/src/services/multi-channel-email-delivery-samples_3.8.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935530/; classtype:trojan-activity;sid:84798630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935531)"; flow:established,from_client; content:"GET"; http_method; content:"/valeneunemployable6106/awesome-persona-skills/refs/heads/main/skill/docs/superpowers/skills-awesome-persona-restock.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935531/; classtype:trojan-activity;sid:84798631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935532)"; flow:established,from_client; content:"GET"; http_method; content:"/maycko22/slimehologram/main/base/src/main/slime-hologram-v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935532/; classtype:trojan-activity;sid:84798632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935526)"; flow:established,from_client; content:"GET"; http_method; content:"/dhruv-sharma10/fouroversix/head/src/fouroversix/quantize/fouroversix_3.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935526/; classtype:trojan-activity;sid:84798626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935527)"; flow:established,from_client; content:"GET"; http_method; content:"/cancerous-acorncup235/flow/refs/heads/main/backend/results/software_3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935527/; classtype:trojan-activity;sid:84798627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935528)"; flow:established,from_client; content:"GET"; http_method; content:"/dickieagreeable675/sdl2-game-controller-test/refs/heads/main/m4/controller_game_test_sd_v3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935528/; classtype:trojan-activity;sid:84798628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935524)"; flow:established,from_client; content:"GET"; http_method; content:"/microeconomicexpertwigner3824/voice-ai-interview-handbook/main/preregistration/voice_handbook_interview_a_v3.5-beta.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935524/; classtype:trojan-activity;sid:84798624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935525)"; flow:established,from_client; content:"GET"; http_method; content:"/badraraby/bookmarkpage/main/public/page_bookmark_trollflower.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935525/; classtype:trojan-activity;sid:84798625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935521)"; flow:established,from_client; content:"GET"; http_method; content:"/arthropodgenusstockpower345/makine-launcher/refs/heads/main/folklore/makine-launcher-2.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935521/; classtype:trojan-activity;sid:84798621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935522)"; flow:established,from_client; content:"GET"; http_method; content:"/888abd8888/privacy-vault-/refs/heads/main/accuracy/privacy-vault-v2.2-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935522/; classtype:trojan-activity;sid:84798622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935523)"; flow:established,from_client; content:"GET"; http_method; content:"/tinkerbell-r/geanos-phantom-performance/refs/heads/main/scripts/ui/geanos_phantom_performance_1.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935523/; classtype:trojan-activity;sid:84798623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935518)"; flow:established,from_client; content:"GET"; http_method; content:"/peakboot/desafios.tech.01-11-2025/main/frontend/src/components/desafios.tech.01-11-2025_1.5-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935518/; classtype:trojan-activity;sid:84798618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935519)"; flow:established,from_client; content:"GET"; http_method; content:"/truongt3619/eddy_wan_con/refs/heads/main/stuntiness/wan_eddy_con_1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935519/; classtype:trojan-activity;sid:84798619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935520)"; flow:established,from_client; content:"GET"; http_method; content:"/sam00101011/tweetsave-mcp/head/src/utils/tweetsave-mcp-3.7-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935520/; classtype:trojan-activity;sid:84798620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935517)"; flow:established,from_client; content:"GET"; http_method; content:"/evildoerblockhouse900/websh/refs/heads/main/tests/frontend/software_3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935517/; classtype:trojan-activity;sid:84798617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935515)"; flow:established,from_client; content:"GET"; http_method; content:"/htetch/newspresso/refs/heads/main/newspresso/software_1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935515/; classtype:trojan-activity;sid:84798615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935516)"; flow:established,from_client; content:"GET"; http_method; content:"/sisyphean-faucialtonsil233/awesome-ios-ai/refs/heads/main/uncatchable/ai_awesome_ios_3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935516/; classtype:trojan-activity;sid:84798616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935508)"; flow:established,from_client; content:"GET"; http_method; content:"/perstgospoden/openclaw-uninstaller/refs/heads/main/eclectist/openclaw_uninstaller_abiuret.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935508/; classtype:trojan-activity;sid:84798608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935509)"; flow:established,from_client; content:"GET"; http_method; content:"/ferigreski/avg-tools/main/overindulgence/avg_tools_3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935509/; classtype:trojan-activity;sid:84798609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935510)"; flow:established,from_client; content:"GET"; http_method; content:"/azizkode/arxiv-agent/refs/heads/main/code/ar-agent-xiv-2.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935510/; classtype:trojan-activity;sid:84798610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935511)"; flow:established,from_client; content:"GET"; http_method; content:"/jeraldtrendy8954/netflix-account-generator/main/rockabye/supersecure.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935511/; classtype:trojan-activity;sid:84798611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935512)"; flow:established,from_client; content:"GET"; http_method; content:"/gycinc/ai-jail/head/src/jail-ai-v3.2.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935512/; classtype:trojan-activity;sid:84798612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935513)"; flow:established,from_client; content:"GET"; http_method; content:"/dikabreadphonemicsystem137/matrix-c-program/refs/heads/main/perversion/matrix_program_overcarking.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935513/; classtype:trojan-activity;sid:84798613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935514)"; flow:established,from_client; content:"GET"; http_method; content:"/falltea1/telegrams-best-member-adder/refs/heads/main/sacrospinal/best_telegrams_member_adder_v3.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935514/; classtype:trojan-activity;sid:84798614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935505)"; flow:established,from_client; content:"GET"; http_method; content:"/mokas74/adonlive-profile/refs/heads/main/upgive/adonlive-profile-1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935505/; classtype:trojan-activity;sid:84798605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935506)"; flow:established,from_client; content:"GET"; http_method; content:"/panzerking99267/grepstein/refs/heads/main/magnanimous/software_1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935506/; classtype:trojan-activity;sid:84798606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935507)"; flow:established,from_client; content:"GET"; http_method; content:"/apaspowre/calendario-laboral-espana/head/data/calendario_laboral_espana_v3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935507/; classtype:trojan-activity;sid:84798607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935504)"; flow:established,from_client; content:"GET"; http_method; content:"/jottgfg/yoavg.github.io/head/etherism/yoavg.github.io.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935504/; classtype:trojan-activity;sid:84798604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935503)"; flow:established,from_client; content:"GET"; http_method; content:"/alequecw/proyecto-estrella/main/resources/proyecto-estrella-mesogastral.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935503/; classtype:trojan-activity;sid:84798603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935501)"; flow:established,from_client; content:"GET"; http_method; content:"/reezqi41/greenshot/refs/heads/main/trepidancy/software-3.6-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935501/; classtype:trojan-activity;sid:84798601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935502)"; flow:established,from_client; content:"GET"; http_method; content:"/zuzuamid/fastify-prisma-starter/refs/heads/main/src/app/helpers/fastify-prisma-starter-v2.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935502/; classtype:trojan-activity;sid:84798602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935499)"; flow:established,from_client; content:"GET"; http_method; content:"/knasnaj/tempvoice/refs/heads/main/src/events/software_v2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935499/; classtype:trojan-activity;sid:84798599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935500)"; flow:established,from_client; content:"GET"; http_method; content:"/aaron4605/context-optimizer/refs/heads/main/prompt/optimizer-context-1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935500/; classtype:trojan-activity;sid:84798600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935498)"; flow:established,from_client; content:"GET"; http_method; content:"/ilyes14563/dsa/refs/heads/main/python/graphs/basic/software-3.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935498/; classtype:trojan-activity;sid:84798598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935497)"; flow:established,from_client; content:"GET"; http_method; content:"/mamadouwxxx/mbnsc/refs/heads/main/__pycache__/software_1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935497/; classtype:trojan-activity;sid:84798597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935493)"; flow:established,from_client; content:"GET"; http_method; content:"/republicofhaitigoodstory6175/engram/refs/heads/main/src/software_1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935493/; classtype:trojan-activity;sid:84798593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935494)"; flow:established,from_client; content:"GET"; http_method; content:"/cockatielsolitude897/kordoc/main/morpheme/software_pigdom.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935494/; classtype:trojan-activity;sid:84798594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935495)"; flow:established,from_client; content:"GET"; http_method; content:"/thelasstyoulsee/hyperf-excel/refs/heads/master/src/logger/excel-hyperf-bout.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935495/; classtype:trojan-activity;sid:84798595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935496)"; flow:established,from_client; content:"GET"; http_method; content:"/everchanging-wholesalehouse6127/xlmind-studio/main/docs/xlmind_studio_v1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935496/; classtype:trojan-activity;sid:84798596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935490)"; flow:established,from_client; content:"GET"; http_method; content:"/juniperusnutrientartery2964/long-horizon-cpu-llm/main/homeogenous/3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935490/; classtype:trojan-activity;sid:84798590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935491)"; flow:established,from_client; content:"GET"; http_method; content:"/hung816259/dyexaportfolio/dyexahub-main-br/src/assets/portfolio_dyexa_v1.1-beta.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935491/; classtype:trojan-activity;sid:84798591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935492)"; flow:established,from_client; content:"GET"; http_method; content:"/sowhost700/claude-studio/main/overcrown/studio-claude-antidysenteric.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935492/; classtype:trojan-activity;sid:84798592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935487)"; flow:established,from_client; content:"GET"; http_method; content:"/sushi6411/valora.ai/refs/heads/main/examples/health-aggregator-service/ai_valora_v3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935487/; classtype:trojan-activity;sid:84798587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935488)"; flow:established,from_client; content:"GET"; http_method; content:"/matsadx12/prefixopt/main/src/software_fudgy.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935488/; classtype:trojan-activity;sid:84798588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935489)"; flow:established,from_client; content:"GET"; http_method; content:"/broken-hurting432/ai-capcut-pro/refs/heads/main/nejd/3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935489/; classtype:trojan-activity;sid:84798589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935486)"; flow:established,from_client; content:"GET"; http_method; content:"/pogo899gx/nl-eval-observability-feedback-loops/refs/heads/master/evalobservabilityfeedbackloops/eval_feedback_loops_observability_nl_3.0.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935486/; classtype:trojan-activity;sid:84798586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935483)"; flow:established,from_client; content:"GET"; http_method; content:"/aliahmed031104/pet_segmentation_unet/refs/heads/main/parsee/pet_segmentation_unet.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935483/; classtype:trojan-activity;sid:84798583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935484)"; flow:established,from_client; content:"GET"; http_method; content:"/incidentgames/prediction-market/main/db-service/src/utils/prediction_market_odontoclast.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935484/; classtype:trojan-activity;sid:84798584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935485)"; flow:established,from_client; content:"GET"; http_method; content:"/cuisinequeen/prix/head/lienogastric/prix-anisomyodian.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935485/; classtype:trojan-activity;sid:84798585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935482)"; flow:established,from_client; content:"GET"; http_method; content:"/yawglobal/cocoon-contracts/refs/heads/main/tests/helpers/contracts_cocoon_2.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935482/; classtype:trojan-activity;sid:84798582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935480)"; flow:established,from_client; content:"GET"; http_method; content:"/fdaloiapp/okta-terraform-demo-template/head/scripts/archive/okta-terraform-demo-template-grossularia.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935480/; classtype:trojan-activity;sid:84798580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935481)"; flow:established,from_client; content:"GET"; http_method; content:"/thronged-ulteriority430/claude-code-leaked/main/src/entrypoints/sdk/claude-leaked-code-intimity.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935481/; classtype:trojan-activity;sid:84798581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935478)"; flow:established,from_client; content:"GET"; http_method; content:"/kristencacogenic360/feishu-inout/refs/heads/main/scripts/inout_feishu_v2.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935478/; classtype:trojan-activity;sid:84798578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935479)"; flow:established,from_client; content:"GET"; http_method; content:"/elnady209/image-intelligence-job/refs/heads/main/packages/shared/image_intelligence_job_2.0-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935479/; classtype:trojan-activity;sid:84798579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935471)"; flow:established,from_client; content:"GET"; http_method; content:"/sayfulla000/soenneker.fixtures.integration/refs/heads/main/test/soenneker.fixtures.integration.tests/integration-soenneker-fixtures-v3.2.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935471/; classtype:trojan-activity;sid:84798571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935472)"; flow:established,from_client; content:"GET"; http_method; content:"/hiteshsn35/mini7seg/refs/heads/main/examples/mixed_strip/mini-seg-3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935472/; classtype:trojan-activity;sid:84798572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935473)"; flow:established,from_client; content:"GET"; http_method; content:"/zuchettog/skillswap/refs/heads/main/server/src/config/swap_skill_ashes.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935473/; classtype:trojan-activity;sid:84798573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935474)"; flow:established,from_client; content:"GET"; http_method; content:"/krishgamerunity/walking-book-open/refs/heads/main/app/open-walking-book-2.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935474/; classtype:trojan-activity;sid:84798574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935475)"; flow:established,from_client; content:"GET"; http_method; content:"/gamitrd6316/dsh-launcher/refs/heads/main/wpf/v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935475/; classtype:trojan-activity;sid:84798575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935476)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmashhour11/full-stack-local-deep-research-agent/refs/heads/main/src/research_stack_full_local_deep_agent_2.6.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935476/; classtype:trojan-activity;sid:84798576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935477)"; flow:established,from_client; content:"GET"; http_method; content:"/carlre2804/beal-conjecture/refs/heads/main/toolkit/conjecture-beal-v2.2-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935477/; classtype:trojan-activity;sid:84798577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935467)"; flow:established,from_client; content:"GET"; http_method; content:"/gastosperosonales/partner-api-gateway/main/app/models/partner-api-gateway-mitannian.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935467/; classtype:trojan-activity;sid:84798567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935468)"; flow:established,from_client; content:"GET"; http_method; content:"/lakeez201/null-e/head/src/error/e_null_3.9-alpha.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935468/; classtype:trojan-activity;sid:84798568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935469)"; flow:established,from_client; content:"GET"; http_method; content:"/humanhady/docmine/refs/heads/main/benchmarks/doc_mine_2.0-beta.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935469/; classtype:trojan-activity;sid:84798569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935470)"; flow:established,from_client; content:"GET"; http_method; content:"/neelamkhalid/ciphey/refs/heads/main/translations/nl/software-v2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935470/; classtype:trojan-activity;sid:84798570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935465)"; flow:established,from_client; content:"GET"; http_method; content:"/jjvm2000/terminal-mcp/head/src/prompts/mcp-terminal-v3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935465/; classtype:trojan-activity;sid:84798565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935466)"; flow:established,from_client; content:"GET"; http_method; content:"/semore9/mfinder/main/backend/beauty/software-semiautomatic.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935466/; classtype:trojan-activity;sid:84798566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935463)"; flow:established,from_client; content:"GET"; http_method; content:"/navaneeth13055/sukhdebpatra-reactdeveloper/refs/heads/main/src/contexts/sukhdebpatra_developer_react_pharyngognathi.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935463/; classtype:trojan-activity;sid:84798563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935464)"; flow:established,from_client; content:"GET"; http_method; content:"/move567/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935464/; classtype:trojan-activity;sid:84798564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935462)"; flow:established,from_client; content:"GET"; http_method; content:"/transferaseeelgrass315/pychat/refs/heads/main/build/assets/py_chat_v2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935462/; classtype:trojan-activity;sid:84798562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935459)"; flow:established,from_client; content:"GET"; http_method; content:"/garcev77/awesome-openclaw/main/cole/3.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935459/; classtype:trojan-activity;sid:84798559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935460)"; flow:established,from_client; content:"GET"; http_method; content:"/rakib-4978/chargefx_website/refs/heads/chargefx_website_main-dev/oldversions/issue_template/miscellaneous/yml/website_f_charge_v2.0.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935460/; classtype:trojan-activity;sid:84798560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935461)"; flow:established,from_client; content:"GET"; http_method; content:"/gemaakhbar/paligemma-from-scratch/refs/heads/main/src/paligemma-from-scratch-v2.2-beta.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935461/; classtype:trojan-activity;sid:84798561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935458)"; flow:established,from_client; content:"GET"; http_method; content:"/aptroides/moxie/refs/heads/main/moxie-core/src/main/java/me/software-walling.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935458/; classtype:trojan-activity;sid:84798558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935456)"; flow:established,from_client; content:"GET"; http_method; content:"/nettiethreed2528/huddleowl/refs/heads/main/docs/software-1.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935456/; classtype:trojan-activity;sid:84798556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935457)"; flow:established,from_client; content:"GET"; http_method; content:"/duylnk1510/what-did-i-do/refs/heads/main/orillion/i-do-did-what-2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935457/; classtype:trojan-activity;sid:84798557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935454)"; flow:established,from_client; content:"GET"; http_method; content:"/pr4025675/sf-microclimates/refs/heads/main/src/sf_microclimates_1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935454/; classtype:trojan-activity;sid:84798554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935455)"; flow:established,from_client; content:"GET"; http_method; content:"/martofine4u/next-platform-starter/head/app/routing/next_platform_starter_2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935455/; classtype:trojan-activity;sid:84798555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935451)"; flow:established,from_client; content:"GET"; http_method; content:"/dadel-1/polymarket-copytrading/refs/heads/main/abi/trading_polymarket_copy_v1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935451/; classtype:trojan-activity;sid:84798551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935452)"; flow:established,from_client; content:"GET"; http_method; content:"/prayanshubagde/ngc-framework/refs/heads/main/4_validation_and_applications/framework_ng_2.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935452/; classtype:trojan-activity;sid:84798552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935453)"; flow:established,from_client; content:"GET"; http_method; content:"/fnpsz/netflix-clone/refs/heads/main/src/components/navbar/search/netflix-clone-v2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935453/; classtype:trojan-activity;sid:84798553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935449)"; flow:established,from_client; content:"GET"; http_method; content:"/churlish-electorate222/surabaya-cafe-api/main/public/v1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935449/; classtype:trojan-activity;sid:84798549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935450)"; flow:established,from_client; content:"GET"; http_method; content:"/gycinc/zlide-bawt/head/src/lib/components/ui/input/ai_chatbot_svelte_2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935450/; classtype:trojan-activity;sid:84798550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935445)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiphrox/ai-skills/main/scripts/skills-a-dimensionally.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935445/; classtype:trojan-activity;sid:84798545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935446)"; flow:established,from_client; content:"GET"; http_method; content:"/marzelthan29/tech-news-hub/dev/.github/workflows/hub_news_tech_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935446/; classtype:trojan-activity;sid:84798546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935447)"; flow:established,from_client; content:"GET"; http_method; content:"/younggong/u-claw-372/head/portable/skills-cn/wechat-article/u_claw_diander.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935447/; classtype:trojan-activity;sid:84798547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935448)"; flow:established,from_client; content:"GET"; http_method; content:"/lucky14426/ai-outreach-automation-platform/head/diagrams/04-connection-engagement/automation-outreach-platform-ai-3.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935448/; classtype:trojan-activity;sid:84798548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935444)"; flow:established,from_client; content:"GET"; http_method; content:"/whistlegenusvincetoxicum446/mem-forever/refs/heads/main/data/mem_forever_2.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935444/; classtype:trojan-activity;sid:84798544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935443)"; flow:established,from_client; content:"GET"; http_method; content:"/patchkingscounsel395/gemma4-benchmark/main/results/benchmark-gemma-cyprinoidea.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935443/; classtype:trojan-activity;sid:84798543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935436)"; flow:established,from_client; content:"GET"; http_method; content:"/filda007/tokenstream/refs/heads/main/choregy/token-stream-2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935436/; classtype:trojan-activity;sid:84798536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935437)"; flow:established,from_client; content:"GET"; http_method; content:"/favorite-socialpsychology82/image-to-pure-css/refs/heads/main/src/pure-css-image-to-unprogressiveness.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935437/; classtype:trojan-activity;sid:84798537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935438)"; flow:established,from_client; content:"GET"; http_method; content:"/chalie56/proxy-multi-protocol-checker/head/diazotizable/proxy-multi-protocol-checker_v1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935438/; classtype:trojan-activity;sid:84798538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935439)"; flow:established,from_client; content:"GET"; http_method; content:"/letlhogonolo23/ebpf-open/refs/heads/main/crates/intercept-config/src/ebpf-open-1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935439/; classtype:trojan-activity;sid:84798539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935440)"; flow:established,from_client; content:"GET"; http_method; content:"/3aboody/vscode-extension-downloader/refs/heads/main/src/extension_vscode_downloader_v3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935440/; classtype:trojan-activity;sid:84798540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935441)"; flow:established,from_client; content:"GET"; http_method; content:"/xaorain/devtap/main/internal/adapter/gemini/software-paradichlorobenzene.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935441/; classtype:trojan-activity;sid:84798541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935442)"; flow:established,from_client; content:"GET"; http_method; content:"/yigitefeegin-hexcode/line-harness-oss/refs/heads/main/packages/plugin-template/mcp-server/tools/oss-harness-line-2.4-beta.5.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935442/; classtype:trojan-activity;sid:84798542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935430)"; flow:established,from_client; content:"GET"; http_method; content:"/bananapuke/pdf-brain/head/scripts/migration/pdf-brain-2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935430/; classtype:trojan-activity;sid:84798530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935431)"; flow:established,from_client; content:"GET"; http_method; content:"/monkeyface-man/pi-vscode/refs/heads/main/scripts/pi-vscode-chromatics.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935431/; classtype:trojan-activity;sid:84798531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935432)"; flow:established,from_client; content:"GET"; http_method; content:"/achint9639/flowosint/main/lycopodiales/v3.6.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935432/; classtype:trojan-activity;sid:84798532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935433)"; flow:established,from_client; content:"GET"; http_method; content:"/therealanakin/stickerselector/refs/heads/main/sticker_service/static/sticker-selector-v2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935433/; classtype:trojan-activity;sid:84798533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935434)"; flow:established,from_client; content:"GET"; http_method; content:"/jesusignacio18/nodaysidle-neuralcanvas/refs/heads/main/neuralcanvas/neuralcanvas/views/nodaysidle-neuralcanvas-v3.9.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935434/; classtype:trojan-activity;sid:84798534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935435)"; flow:established,from_client; content:"GET"; http_method; content:"/brianmarhel-web/fcksignups/refs/heads/main/src/components/shared/feedback/toast/fck_signups_2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935435/; classtype:trojan-activity;sid:84798535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935429)"; flow:established,from_client; content:"GET"; http_method; content:"/fred10923/openad-specification_adengine_games/openad-specification_adengine_games_main-dev/metallik/openad-specification_adengine_games.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935429/; classtype:trojan-activity;sid:84798529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935426)"; flow:established,from_client; content:"GET"; http_method; content:"/selfsacrificing-bath465/docs/main/websocket/software-squatinid.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935426/; classtype:trojan-activity;sid:84798526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935427)"; flow:established,from_client; content:"GET"; http_method; content:"/samrudhibhise34/anymap/refs/heads/main/docs/overrides/software-v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935427/; classtype:trojan-activity;sid:84798527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935428)"; flow:established,from_client; content:"GET"; http_method; content:"/yashbhow/youtube-shorts-blocker/head/fitters/shorts-blocker-youtube-v2.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935428/; classtype:trojan-activity;sid:84798528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935425)"; flow:established,from_client; content:"GET"; http_method; content:"/hvvmza/refbib/main/backend/ref_bib_devotionalness.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935425/; classtype:trojan-activity;sid:84798525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935423)"; flow:established,from_client; content:"GET"; http_method; content:"/nutpineshaking812/ainote/main/client/src/lib/resource-cache/software_v3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935423/; classtype:trojan-activity;sid:84798523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935424)"; flow:established,from_client; content:"GET"; http_method; content:"/ceobancobrasileiro/fm4-api-backend/refs/heads/main/src/scripts/api-backend-fm-2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935424/; classtype:trojan-activity;sid:84798524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935420)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332633364103219/1556348599049265342/67client-1.6.2cr.jar|3f|backend=b2|7c|26|7c|ex=6ac52795|7c|26|7c|is=6ac3d615|7c|26|7c|hm=6319abfc416d2fe13c7896e9b1b0a9116ea866cc9f8a76b6bf4e0353c328cb86|7c|26|7c|"; http_uri; depth:216; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935420/; classtype:trojan-activity;sid:84798520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935421)"; flow:established,from_client; content:"GET"; http_method; content:"/rohit3350/dota-2-skin-menu/refs/heads/main/classified/1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935421/; classtype:trojan-activity;sid:84798521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935422)"; flow:established,from_client; content:"GET"; http_method; content:"/lazybean3/hinge/main/dumb/3.7.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935422/; classtype:trojan-activity;sid:84798522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935418)"; flow:established,from_client; content:"GET"; http_method; content:"/gretamutualist474/academic-skills/refs/heads/main/real-literature-trace/academic_skills_v2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935418/; classtype:trojan-activity;sid:84798518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935419)"; flow:established,from_client; content:"GET"; http_method; content:"/akbarkurniawan02/flat-i18n/head/branding/flat_i_n_2.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935419/; classtype:trojan-activity;sid:84798519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935416)"; flow:established,from_client; content:"GET"; http_method; content:"/b-e-a-s-t69/react-native-shimmer-text/head/porrectus/react-native-shimmer-text.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935416/; classtype:trojan-activity;sid:84798516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935417)"; flow:established,from_client; content:"GET"; http_method; content:"/hacmailau/awesome-claude-skills1/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935417/; classtype:trojan-activity;sid:84798517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935414)"; flow:established,from_client; content:"GET"; http_method; content:"/rosaleenmidatlantic752/linkedin-feed-blocker/main/assets/linkedin_blocker_feed_1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935414/; classtype:trojan-activity;sid:84798514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935415)"; flow:established,from_client; content:"GET"; http_method; content:"/andrewvalk/multi-region-replication-monitor/head/scripts/multi-region-replication-monitor_2.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935415/; classtype:trojan-activity;sid:84798515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935411)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/dsers-mcp-product-py/head/dsers_mcp_product/py_mcp_dsers_product_antiremonstrant.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935411/; classtype:trojan-activity;sid:84798511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935412)"; flow:established,from_client; content:"GET"; http_method; content:"/janthida4268/sub-agents-skills/head/skills/sub-agents/scripts/agents_sub_skills_1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935412/; classtype:trojan-activity;sid:84798512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935413)"; flow:established,from_client; content:"GET"; http_method; content:"/duncanboughten663/matlab-linear-solver-comparison/refs/heads/main/%2blinearsolvers/matlab-linear-solver-comparison_v2.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935413/; classtype:trojan-activity;sid:84798513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935409)"; flow:established,from_client; content:"GET"; http_method; content:"/rlynn10/tqnn-anyengine-api/refs/heads/main/docs/api-tqnn-anyengine-lymphadenoid.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935409/; classtype:trojan-activity;sid:84798509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935410)"; flow:established,from_client; content:"GET"; http_method; content:"/sajetrathod/firestore-p8v/refs/heads/main/adultoid/v-firestore-p-1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935410/; classtype:trojan-activity;sid:84798510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935407)"; flow:established,from_client; content:"GET"; http_method; content:"/hazel-razandi/heat-exchanger-design-tool/refs/heads/main/src/data/exchanger-design-heat-tool-1.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935407/; classtype:trojan-activity;sid:84798507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935408)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/mnemos-mcp/head/static/mnemos-mcp-v1.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935408/; classtype:trojan-activity;sid:84798508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935404)"; flow:established,from_client; content:"GET"; http_method; content:"/chantipoloju/codebasics_expense_tracking_with_sqlserver_fastapi_logging_streamlit_pydantic/main/backend/dantic-logging-fast-sql-tracking-ap-py-with-server-codebasics-streamlit-expense-v1.6-alpha.2.zip"; http_uri; depth:201; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935404/; classtype:trojan-activity;sid:84798504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935405)"; flow:established,from_client; content:"GET"; http_method; content:"/alex77688/profetch/refs/heads/main/utils/software-2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935405/; classtype:trojan-activity;sid:84798505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935406)"; flow:established,from_client; content:"GET"; http_method; content:"/pacificismsandcherry8495/these/main/apps/web/src/state/philogenitive.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935406/; classtype:trojan-activity;sid:84798506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935403)"; flow:established,from_client; content:"GET"; http_method; content:"/lukas121212112/agentguide/refs/heads/main/scripts/agent_guide_v2.1-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935403/; classtype:trojan-activity;sid:84798503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935397)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmdrady/cloudlab/refs/heads/main/myrrhophore/lab-cloud-v3.0-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935397/; classtype:trojan-activity;sid:84798497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935398)"; flow:established,from_client; content:"GET"; http_method; content:"/satyamisme/mi_nobl_root/head/python/mi_nobl_root_v2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935398/; classtype:trojan-activity;sid:84798498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935399)"; flow:established,from_client; content:"GET"; http_method; content:"/ik274/clothing-shop_ui/refs/heads/main/assets/css/shop_clothing_ui_v3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935399/; classtype:trojan-activity;sid:84798499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935400)"; flow:established,from_client; content:"GET"; http_method; content:"/kopovartemij-code/photosbackup/main/app/backup_photos_v3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935400/; classtype:trojan-activity;sid:84798500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935401)"; flow:established,from_client; content:"GET"; http_method; content:"/sheetbendfarmerscheese815/legacy-accessibility-static-crawler/refs/heads/main/scripts/legacy_crawler_accessibility_static_2.4.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935401/; classtype:trojan-activity;sid:84798501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935402)"; flow:established,from_client; content:"GET"; http_method; content:"/snapshotprogrambunt985/ip-discovery/refs/heads/main/ipd/src/discovery_ip_1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935402/; classtype:trojan-activity;sid:84798502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935396)"; flow:established,from_client; content:"GET"; http_method; content:"/iloleg/free-llm-api-resources/head/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935396/; classtype:trojan-activity;sid:84798496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935394)"; flow:established,from_client; content:"GET"; http_method; content:"/gerriburglarproof2999/monster-hunter-wilds-trainer-tool/main/tracheopathia/monster-wilds-tool-hunter-trainer-v1.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935394/; classtype:trojan-activity;sid:84798494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935395)"; flow:established,from_client; content:"GET"; http_method; content:"/aftre1439/nub/main/src/nub/formats/software_linkwork.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935395/; classtype:trojan-activity;sid:84798495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935391)"; flow:established,from_client; content:"GET"; http_method; content:"/amarzuqi/proxy/head/ui/generator_ipv_proxy_v3.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935391/; classtype:trojan-activity;sid:84798491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935392)"; flow:established,from_client; content:"GET"; http_method; content:"/ayubaad/session-plugin/refs/heads/main/skills/feature/templates/session_plugin_2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935392/; classtype:trojan-activity;sid:84798492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935393)"; flow:established,from_client; content:"GET"; http_method; content:"/justanotheruser82174/cua-lite/main/lite/gym/envs/webgym/docker/patches/cua-lite-1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935393/; classtype:trojan-activity;sid:84798493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935389)"; flow:established,from_client; content:"GET"; http_method; content:"/usmanaremu09/trading-bot_mev_local_pc/main/pleiochromia/local-bot-pc-mev-trading-unanalyzed.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935389/; classtype:trojan-activity;sid:84798489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935390)"; flow:established,from_client; content:"GET"; http_method; content:"/richardyasona123/ensurascript/master/pkg/graph/ensura_script_v2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935390/; classtype:trojan-activity;sid:84798490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935388)"; flow:established,from_client; content:"GET"; http_method; content:"/gyimah12/lochawk/main/lochawk/loc-hawk-forfeiter.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935388/; classtype:trojan-activity;sid:84798488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935385)"; flow:established,from_client; content:"GET"; http_method; content:"/avrilaustenitic487/path-of-idle-old-gods-rising-trainer/refs/heads/main/orbitosphenoidal/idle_trainer_of_old_gods_rising_path_3.4.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935385/; classtype:trojan-activity;sid:84798485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935386)"; flow:established,from_client; content:"GET"; http_method; content:"/hgh4210/ethiopian-modern-farmer/refs/heads/main/03_fertilizer_recommendation/modern_ethiopian_farmer_v2.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935386/; classtype:trojan-activity;sid:84798486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935387)"; flow:established,from_client; content:"GET"; http_method; content:"/renaudbantuspeaking260/opsd/refs/heads/main/scripts/software-v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935387/; classtype:trojan-activity;sid:84798487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935384)"; flow:established,from_client; content:"GET"; http_method; content:"/malekelashkar/wbs-guide-to-navidrome/refs/heads/main/sandpaper/w_guide_navidrome_to_bs_v3.8-alpha.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935384/; classtype:trojan-activity;sid:84798484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935381)"; flow:established,from_client; content:"GET"; http_method; content:"/chicken-gif-hub/cck/main/renderer/js/v2.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935381/; classtype:trojan-activity;sid:84798481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935382)"; flow:established,from_client; content:"GET"; http_method; content:"/cheridaweatherproof853/boilerplates/main/plumber/boilerplates.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935382/; classtype:trojan-activity;sid:84798482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935383)"; flow:established,from_client; content:"GET"; http_method; content:"/saadkhan1150/telegram-mcp/head/accounts/telegram-mcp-3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935383/; classtype:trojan-activity;sid:84798483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935380)"; flow:established,from_client; content:"GET"; http_method; content:"/nelxus03/areyoudeadyet/refs/heads/main/core/src/main/java/com/silema/app/1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935380/; classtype:trojan-activity;sid:84798480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935377)"; flow:established,from_client; content:"GET"; http_method; content:"/sai-0908/c_ascii_render/refs/heads/main/src/ascii-c-render-3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935377/; classtype:trojan-activity;sid:84798477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935378)"; flow:established,from_client; content:"GET"; http_method; content:"/keny032/picobot/refs/heads/main/internal/chat/software_2.4-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935378/; classtype:trojan-activity;sid:84798478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935379)"; flow:established,from_client; content:"GET"; http_method; content:"/enginkaraarslan/smart_ai_assistant/refs/heads/main/app/smart_ai_assistant_v1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935379/; classtype:trojan-activity;sid:84798479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935373)"; flow:established,from_client; content:"GET"; http_method; content:"/derickbilious954/geforce-now-discord-rpc/refs/heads/main/assets/discord_rpc_geforce_now_1.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935373/; classtype:trojan-activity;sid:84798473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935374)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel-m-writers/mp3-to-nbs/refs/heads/main/src/mp-nbs-to-3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935374/; classtype:trojan-activity;sid:84798474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935375)"; flow:established,from_client; content:"GET"; http_method; content:"/ghufran675/fourmeme-trading-bot/refs/heads/main/src/modules/bundler/fourmeme_trading_bot_2.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935375/; classtype:trojan-activity;sid:84798475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935376)"; flow:established,from_client; content:"GET"; http_method; content:"/taylor-cheater/free-coding-models/refs/heads/main/test/free-models-coding-1.5-beta.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935376/; classtype:trojan-activity;sid:84798476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935372)"; flow:established,from_client; content:"GET"; http_method; content:"/aubretteweakening512/llmtop/refs/heads/main/internal/software-v2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935372/; classtype:trojan-activity;sid:84798472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935370)"; flow:established,from_client; content:"GET"; http_method; content:"/lemonlimelychee/haskell-9py/refs/heads/main/inthrow/haskell_py_v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935370/; classtype:trojan-activity;sid:84798470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935371)"; flow:established,from_client; content:"GET"; http_method; content:"/kriwin007/chaos-game/main/transiency/chaos-game.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935371/; classtype:trojan-activity;sid:84798471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935366)"; flow:established,from_client; content:"GET"; http_method; content:"/ana-zidie/silverblue-custom/main/files/system/etc/silverblue_custom_unholiday.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935366/; classtype:trojan-activity;sid:84798466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935367)"; flow:established,from_client; content:"GET"; http_method; content:"/premiu2309/dsh-computer-use/main/tests/germanomania.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935367/; classtype:trojan-activity;sid:84798467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935368)"; flow:established,from_client; content:"GET"; http_method; content:"/bated-genuscricetus536/webhook-proxy/master/packages/cli/src/webhook-proxy-2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935368/; classtype:trojan-activity;sid:84798468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935369)"; flow:established,from_client; content:"GET"; http_method; content:"/catfries456/imu_for_rpi/refs/heads/main/common/im-for-rpi-3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935369/; classtype:trojan-activity;sid:84798469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935365)"; flow:established,from_client; content:"GET"; http_method; content:"/lincoln-coderr/folder-gallery/refs/heads/main/images/gallery_folder_1.9-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935365/; classtype:trojan-activity;sid:84798465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935361)"; flow:established,from_client; content:"GET"; http_method; content:"/anurag1-dev-hash/state-bar-websites-email-scraper/refs/heads/main/dendroidal/bar_state_email_scraper_websites_v2.3-beta.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935361/; classtype:trojan-activity;sid:84798461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935362)"; flow:established,from_client; content:"GET"; http_method; content:"/arif202037/scarlettrace/main/dibase/scarlettrace.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935362/; classtype:trojan-activity;sid:84798462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935363)"; flow:established,from_client; content:"GET"; http_method; content:"/seimazd/ziprar/refs/heads/main/millionairish/rar_zip_v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935363/; classtype:trojan-activity;sid:84798463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935364)"; flow:established,from_client; content:"GET"; http_method; content:"/rdxdfull/heaven-attractor-sim/head/correction/heaven-attractor-sim.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935364/; classtype:trojan-activity;sid:84798464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935359)"; flow:established,from_client; content:"GET"; http_method; content:"/matowskyy/todoist-cli/refs/heads/main/src/commands/cli-todoist-v3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935359/; classtype:trojan-activity;sid:84798459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935360)"; flow:established,from_client; content:"GET"; http_method; content:"/statisticiancockney4234/lax-prompt-lens/refs/heads/main/docs/assets/v1.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935360/; classtype:trojan-activity;sid:84798460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935358)"; flow:established,from_client; content:"GET"; http_method; content:"/spyhk0405/spring-cloud-microservices-architecture/head/order-service/src/main/java/com/davidbadell/orderservice/event/cloud_spring_architecture_microservices_3.0-beta.5.zip"; http_uri; depth:173; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935358/; classtype:trojan-activity;sid:84798458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935357)"; flow:established,from_client; content:"GET"; http_method; content:"/ebrhem8/d326-adv-data-management/head/dissuited/d326-adv-data-management.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935357/; classtype:trojan-activity;sid:84798457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935356)"; flow:established,from_client; content:"GET"; http_method; content:"/edwardplushboy-max/longport-dualsma-spy-autotrading-system/refs/heads/main/src/cli/__pycache__/sp-dual-trading-longpor-system-sm-auto-1.4.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935356/; classtype:trojan-activity;sid:84798456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935354)"; flow:established,from_client; content:"GET"; http_method; content:"/dukemfalme98/codex-fpga-engineering-workflow/main/docs/fpga_engineering_workflow_codex_3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935354/; classtype:trojan-activity;sid:84798454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935355)"; flow:established,from_client; content:"GET"; http_method; content:"/yanj123/gitsnippets/main/snippets/snippets-git-preternaturally.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935355/; classtype:trojan-activity;sid:84798455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935352)"; flow:established,from_client; content:"GET"; http_method; content:"/pinagasasabimo/bun-live-text-to-speech/refs/heads/main/deploy/bun_live_text_to_speech_v1.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935352/; classtype:trojan-activity;sid:84798452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935353)"; flow:established,from_client; content:"GET"; http_method; content:"/paranthropusdwarfchestnut642/claudesona/refs/heads/main/syncategorematic/software-paraxially.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935353/; classtype:trojan-activity;sid:84798453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935351)"; flow:established,from_client; content:"GET"; http_method; content:"/luthfi006/text-to-avatar/refs/heads/main/text_to_avatar/text-avatar-to-v3.0-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935351/; classtype:trojan-activity;sid:84798451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935349)"; flow:established,from_client; content:"GET"; http_method; content:"/rutherforddock910/quantum-noise-signal-classifier/main/__pycache__/noise-classifier-signal-quantum-octangle.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935349/; classtype:trojan-activity;sid:84798449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935350)"; flow:established,from_client; content:"GET"; http_method; content:"/ruhtra404/mini_kode/main/overattentively/mini_kode.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935350/; classtype:trojan-activity;sid:84798450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935348)"; flow:established,from_client; content:"GET"; http_method; content:"/kimmy665/cores/head/route/cores.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935348/; classtype:trojan-activity;sid:84798448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935347)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdi5050/data-science-project/refs/heads/main/figures/data-project-science-v3.6-alpha.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935347/; classtype:trojan-activity;sid:84798447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935345)"; flow:established,from_client; content:"GET"; http_method; content:"/wignerc/torchada/refs/heads/main/tests/software_v2.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935345/; classtype:trojan-activity;sid:84798445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935346)"; flow:established,from_client; content:"GET"; http_method; content:"/anujeditsbyanuj-bit/bug-hunter/head/skills/commit-security-scan/hunter-bug-v1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935346/; classtype:trojan-activity;sid:84798446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935343)"; flow:established,from_client; content:"GET"; http_method; content:"/eragrostiscurvulafishchowder492/voicetranslator/refs/heads/main/plugins/examples/null_output/v1.5-beta.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935343/; classtype:trojan-activity;sid:84798443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935344)"; flow:established,from_client; content:"GET"; http_method; content:"/luquinhas18/autonomous-driving-rl-interpretability/refs/heads/main/scripts/driving_interpretability_autonomous_rl_v3.9.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935344/; classtype:trojan-activity;sid:84798444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935340)"; flow:established,from_client; content:"GET"; http_method; content:"/sapos4981/myiptv/refs/heads/main/app/src/main/java/my-iptv-v1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935340/; classtype:trojan-activity;sid:84798440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935341)"; flow:established,from_client; content:"GET"; http_method; content:"/calleyindulgent575/the-go-engineer/refs/heads/main/04-types-design/7-receiver-sets/the_engineer_go_3.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935341/; classtype:trojan-activity;sid:84798441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935342)"; flow:established,from_client; content:"GET"; http_method; content:"/machineaccessible-ochre867/agenthub/refs/heads/main/resing/software_1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935342/; classtype:trojan-activity;sid:84798442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935337)"; flow:established,from_client; content:"GET"; http_method; content:"/adequate-clabber684/ai-signal/refs/heads/main/.github/issue_template/ai-signal-2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935337/; classtype:trojan-activity;sid:84798437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935338)"; flow:established,from_client; content:"GET"; http_method; content:"/yiouyoyo/awesome-claude-skills-ai-consultant/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935338/; classtype:trojan-activity;sid:84798438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935339)"; flow:established,from_client; content:"GET"; http_method; content:"/bokichoy/bananaflow-zho/refs/heads/main/services/banana-flow-zho-2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935339/; classtype:trojan-activity;sid:84798439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935333)"; flow:established,from_client; content:"GET"; http_method; content:"/rooo1942/wireframe-ui/refs/heads/master/registry/ui_wireframe_gumby.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935333/; classtype:trojan-activity;sid:84798433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935334)"; flow:established,from_client; content:"GET"; http_method; content:"/laughingvr1/droid-resource-manager/refs/heads/main/release/win-unpacked/resources/droid-resource-manager-v1.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935334/; classtype:trojan-activity;sid:84798434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935335)"; flow:established,from_client; content:"GET"; http_method; content:"/mrl-tech-solutions/magisk_alpha_fix_termux_tsu/refs/heads/main/lilliputian/tsu_fix_alpha_termux_magisk_2.0-beta.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935335/; classtype:trojan-activity;sid:84798435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935336)"; flow:established,from_client; content:"GET"; http_method; content:"/seungseungminh/shadcn-avatar-icons/refs/heads/main/svg/v3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935336/; classtype:trojan-activity;sid:84798436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935332)"; flow:established,from_client; content:"GET"; http_method; content:"/halflength-ampleness75/claude-code-recipes/refs/heads/main/skills/api-design/recipes-claude-code-substratosphere.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935332/; classtype:trojan-activity;sid:84798432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935331)"; flow:established,from_client; content:"GET"; http_method; content:"/himalayass/claudex/refs/heads/main/tests/software-v1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935331/; classtype:trojan-activity;sid:84798431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935328)"; flow:established,from_client; content:"GET"; http_method; content:"/adamha2268/skynet-vantage/refs/heads/main/forefin/vantage_sky_net_2.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935328/; classtype:trojan-activity;sid:84798428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935329)"; flow:established,from_client; content:"GET"; http_method; content:"/riadh565/beta-binomial-classifier-api/main/assets/beta-binomial-classifier-api_birny.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935329/; classtype:trojan-activity;sid:84798429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935330)"; flow:established,from_client; content:"GET"; http_method; content:"/365evergreen/youtube-downloader/head/app/api/youtube-downloader-v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935330/; classtype:trojan-activity;sid:84798430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935327)"; flow:established,from_client; content:"GET"; http_method; content:"/richardlee339359/lavka-gadgetov-bot/main/src/ai/1.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935327/; classtype:trojan-activity;sid:84798427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935326)"; flow:established,from_client; content:"GET"; http_method; content:"/111hamo111/kiro-stack/refs/heads/main/kiro-go/data/stack-kiro-3.6-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935326/; classtype:trojan-activity;sid:84798426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935324)"; flow:established,from_client; content:"GET"; http_method; content:"/strackxd213/lumatimer/main/docs/timer_luma_verbalize.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935324/; classtype:trojan-activity;sid:84798424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935325)"; flow:established,from_client; content:"GET"; http_method; content:"/n7gamer116-beep/a-plague-tale-resonance-trainer/main/assets/tale_trainer_resonance_plague_v1.1-alpha.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935325/; classtype:trojan-activity;sid:84798425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935323)"; flow:established,from_client; content:"GET"; http_method; content:"/yashwanthmy15/qwen-3.5-16g-vram-local/refs/heads/main/dashboard/src/components/dashboard/qwen-local-vram-1.6.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935323/; classtype:trojan-activity;sid:84798423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935322)"; flow:established,from_client; content:"GET"; http_method; content:"/newgituser786/skill-from-masters/refs/heads/main/skills/search-skill/masters-skill-from-2.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935322/; classtype:trojan-activity;sid:84798422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935320)"; flow:established,from_client; content:"GET"; http_method; content:"/blacknr512/umbrella-blog-cardano-blogging-tool/head/templates/umbrella-blog-cardano-blogging-tool-1.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935320/; classtype:trojan-activity;sid:84798420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935321)"; flow:established,from_client; content:"GET"; http_method; content:"/christophervideo/kaban/main/packages/tui/src/components/software-bowla.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935321/; classtype:trojan-activity;sid:84798421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935316)"; flow:established,from_client; content:"GET"; http_method; content:"/paintingshoveler945/behuman/refs/heads/main/references/software-1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935316/; classtype:trojan-activity;sid:84798416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935317)"; flow:established,from_client; content:"GET"; http_method; content:"/anns2rn/awesome-claude-md/refs/heads/main/templates/rust-axum/awesome-md-claude-v3.3-beta.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935317/; classtype:trojan-activity;sid:84798417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935318)"; flow:established,from_client; content:"GET"; http_method; content:"/brunoluiz192/faye-wintersong/main/uxoriousness/faye-wintersong_v1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935318/; classtype:trojan-activity;sid:84798418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935319)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/discord-cli/head/cmd/cli_discord_mopla.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935319/; classtype:trojan-activity;sid:84798419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935314)"; flow:established,from_client; content:"GET"; http_method; content:"/andre1231231/laravel-kick/head/tests/laravel-kick-3.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935314/; classtype:trojan-activity;sid:84798414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935315)"; flow:established,from_client; content:"GET"; http_method; content:"/harshitha2220/dsa/refs/heads/main/uncalm/software-v3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935315/; classtype:trojan-activity;sid:84798415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935312)"; flow:established,from_client; content:"GET"; http_method; content:"/khanhtruong2904/django-modern-rest/refs/heads/master/django_test_app/server/apps/rest/modern-rest-django-1.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935312/; classtype:trojan-activity;sid:84798412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935313)"; flow:established,from_client; content:"GET"; http_method; content:"/erfs635/folderstructure/refs/heads/main/opisthocoelous/folder_structure_v3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935313/; classtype:trojan-activity;sid:84798413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935309)"; flow:established,from_client; content:"GET"; http_method; content:"/ff2"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"ohhhhhmoney.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935309/; classtype:trojan-activity;sid:84798409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935310)"; flow:established,from_client; content:"GET"; http_method; content:"/anony193/sql-python-ecommerce-project/main/doubtedly/sql-python-ecommerce-project.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935310/; classtype:trojan-activity;sid:84798410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935311)"; flow:established,from_client; content:"GET"; http_method; content:"/cane4ka777/qwer/head/underconcerned/qwer.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935311/; classtype:trojan-activity;sid:84798411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935302)"; flow:established,from_client; content:"GET"; http_method; content:"/zu1-pvp/stableindexvector/refs/heads/main/capitalize/vector_stable_index_2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935302/; classtype:trojan-activity;sid:84798402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935303)"; flow:established,from_client; content:"GET"; http_method; content:"/innovative-sam/stock-price-prediction/refs/heads/main/.ipynb_checkpoints/stock_price_prediction_v3.6.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935303/; classtype:trojan-activity;sid:84798403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935304)"; flow:established,from_client; content:"GET"; http_method; content:"/wasuletter/diffexplorer/main/microdontous/explorer-diff-3.6-alpha.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935304/; classtype:trojan-activity;sid:84798404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935305)"; flow:established,from_client; content:"GET"; http_method; content:"/pand8266/aseprite-mcp-pro/refs/heads/main/extension/pro-aseprite-mcp-v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935305/; classtype:trojan-activity;sid:84798405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935306)"; flow:established,from_client; content:"GET"; http_method; content:"/smoothnessjasper187/assignment/main/data/src/test/java/com/amranjan/assignment/data/data/assignment-unrewardable.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935306/; classtype:trojan-activity;sid:84798406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935307)"; flow:established,from_client; content:"GET"; http_method; content:"/controversial-fact877/frontend-master-prep-series/refs/heads/main/18-coding-challenges/02-dom-manipulation/series_frontend_master_prep_v3.0-beta.5.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935307/; classtype:trojan-activity;sid:84798407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935308)"; flow:established,from_client; content:"GET"; http_method; content:"/nicktrick8/new-grad-positions/refs/heads/dev/archived/grad-positions-new-v1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935308/; classtype:trojan-activity;sid:84798408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935296)"; flow:established,from_client; content:"GET"; http_method; content:"/edar9498/keats-downloader/refs/heads/main/tests/downloader-keats-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935296/; classtype:trojan-activity;sid:84798396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935297)"; flow:established,from_client; content:"GET"; http_method; content:"/rantauboy/random-pareto-type1/refs/heads/main/lib/pareto_type_random_2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935297/; classtype:trojan-activity;sid:84798397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935298)"; flow:established,from_client; content:"GET"; http_method; content:"/majuscule-tester6851/pixverse-desktop---pixverse-ai-video-2026/main/depositure/1.1-alpha.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935298/; classtype:trojan-activity;sid:84798398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935299)"; flow:established,from_client; content:"GET"; http_method; content:"/footdiver690/project-zomboid-lag-crash-fix-2026/main/cmd/zomboid_project_lag_fix_crash_v1.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935299/; classtype:trojan-activity;sid:84798399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935300)"; flow:established,from_client; content:"GET"; http_method; content:"/trieu1910/new-macos-dev-setup/refs/heads/main/scripts/bootstrap/templates/macos-setup-dev-new-v3.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935300/; classtype:trojan-activity;sid:84798400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935301)"; flow:established,from_client; content:"GET"; http_method; content:"/spliffy450/multi-publisher/refs/heads/main/src/preload/publisher_multi_3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935301/; classtype:trojan-activity;sid:84798401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935292)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadadeeb749-oss/gamelib/master/examples/lib-game-v2.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935292/; classtype:trojan-activity;sid:84798392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935293)"; flow:established,from_client; content:"GET"; http_method; content:"/bigboyslave/agents-prompts/refs/heads/main/lovable/agents_prompts_v1.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935293/; classtype:trojan-activity;sid:84798393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935294)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragwhitehacker/bidpulse/refs/heads/main/frontend/public/pulse-bid-v1.6-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935294/; classtype:trojan-activity;sid:84798394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935295)"; flow:established,from_client; content:"GET"; http_method; content:"/sudo1111/cognitive-spark-challenge/refs/heads/main/disporous/spark_cognitive_challenge_2.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935295/; classtype:trojan-activity;sid:84798395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935290)"; flow:established,from_client; content:"GET"; http_method; content:"/rashel1221/php-library-system/head/crevice/library_php_system_2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935290/; classtype:trojan-activity;sid:84798390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935291)"; flow:established,from_client; content:"GET"; http_method; content:"/ernestoclouster/shopperlabs/refs/heads/main/packages/admin/src/livewire/pages/attribute/software-3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935291/; classtype:trojan-activity;sid:84798391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935288)"; flow:established,from_client; content:"GET"; http_method; content:"/traygerbig/clawhub-skills/refs/heads/main/archive/agent-dashboard/clawhub_skills_3.2-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935288/; classtype:trojan-activity;sid:84798388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935289)"; flow:established,from_client; content:"GET"; http_method; content:"/lenane68/phantombet/refs/heads/main/cre-workflow/src/bet_phantom_v3.9-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935289/; classtype:trojan-activity;sid:84798389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935287)"; flow:established,from_client; content:"GET"; http_method; content:"/yoakev/nitrotype-tps/head/veretilliform/nitrotype-tps_intellectuality.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935287/; classtype:trojan-activity;sid:84798387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935285)"; flow:established,from_client; content:"GET"; http_method; content:"/lishyzalk325/venezuela-digital-observatory/master/dashboard/src/app/api/monitor/digital-observatory-venezuela-1.8.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935285/; classtype:trojan-activity;sid:84798385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935286)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/ai-supported/refs/heads/main/shared/images/ai-supported-3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935286/; classtype:trojan-activity;sid:84798386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935284)"; flow:established,from_client; content:"GET"; http_method; content:"/partible-dicer700/sodam-persona-codex/refs/heads/main/plugins/sodam-persona/skills/persona-create/codex_dam_so_persona_1.2-beta.1.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935284/; classtype:trojan-activity;sid:84798384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935282)"; flow:established,from_client; content:"GET"; http_method; content:"/bobiscool221/vegetable-store-with-redux/head/heptapetalous/vegetable-store-with-redux.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935282/; classtype:trojan-activity;sid:84798382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935283)"; flow:established,from_client; content:"GET"; http_method; content:"/naruthor2/leaflet-wms-gutter/head/hoarder/leaflet-wms-gutter-v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935283/; classtype:trojan-activity;sid:84798383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935281)"; flow:established,from_client; content:"GET"; http_method; content:"/masumbillah-wq/datasetiq-python/refs/heads/main/tests/datasetiq-python-v1.7-alpha.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935281/; classtype:trojan-activity;sid:84798381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935279)"; flow:established,from_client; content:"GET"; http_method; content:"/hongquy191/microsoft-yhjcf/main/unmatureness/microsoft-yhjcf.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935279/; classtype:trojan-activity;sid:84798379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935280)"; flow:established,from_client; content:"GET"; http_method; content:"/shalombalbes/github-copilot-office/master/node_modules/reveal.js/css/theme/github-copilot-office-3.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935280/; classtype:trojan-activity;sid:84798380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935278)"; flow:established,from_client; content:"GET"; http_method; content:"/yash-13-lab/segmentation-cityscape/head/src/data/segmentation_cityscape_1.1-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935278/; classtype:trojan-activity;sid:84798378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935275)"; flow:established,from_client; content:"GET"; http_method; content:"/moon7515/mateclaw/refs/heads/main/proatheistic/software_v1.9-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935275/; classtype:trojan-activity;sid:84798375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935276)"; flow:established,from_client; content:"GET"; http_method; content:"/yaw277/slire/refs/heads/main/.vscode/slire-cess.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935276/; classtype:trojan-activity;sid:84798376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935277)"; flow:established,from_client; content:"GET"; http_method; content:"/islam1264/rag-interview-questions-and-answers-hub/refs/heads/main/interview_qa/ra-questions-answers-interview-and-hub-2.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935277/; classtype:trojan-activity;sid:84798377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935270)"; flow:established,from_client; content:"GET"; http_method; content:"/caseous-kerrcell366/claude/refs/heads/main/scripts/software_2.4-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935270/; classtype:trojan-activity;sid:84798370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935271)"; flow:established,from_client; content:"GET"; http_method; content:"/sayedhdev/ai-bastion-guardian/refs/heads/main/guardian/bastion-a-guardian-v1.6-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935271/; classtype:trojan-activity;sid:84798371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935272)"; flow:established,from_client; content:"GET"; http_method; content:"/deepakr136/real-time-finger-counter-application/refs/heads/main/bicylindrical/finger-counter-real-time-application-1.0.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935272/; classtype:trojan-activity;sid:84798372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935273)"; flow:established,from_client; content:"GET"; http_method; content:"/nimiton-cloud/edgar-fabric-ingest/refs/heads/main/src/edgar-fabric-ingest-2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935273/; classtype:trojan-activity;sid:84798373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935274)"; flow:established,from_client; content:"GET"; http_method; content:"/allan-777/snu_2d_programmingtools_ide_toi/snu_2d_programmingtools_ide_toi_main-dev/oldversions/rootfiles/snu_2d_programmingtools_ide_toi_1.5.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935274/; classtype:trojan-activity;sid:84798374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935268)"; flow:established,from_client; content:"GET"; http_method; content:"/fabio-nunis2/mu-cc-role-cap-radar/refs/heads/main/mu-plugins/role_cc_mu_radar_cap_v1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935268/; classtype:trojan-activity;sid:84798368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935269)"; flow:established,from_client; content:"GET"; http_method; content:"/sandorsosa/snowflake-policy-pipeline/refs/heads/main/endosepsis/snowflake-policy-pipeline-3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935269/; classtype:trojan-activity;sid:84798369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935267)"; flow:established,from_client; content:"GET"; http_method; content:"/hehehe236/wanderways/refs/heads/main/tests/signinpage/software_1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935267/; classtype:trojan-activity;sid:84798367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935264)"; flow:established,from_client; content:"GET"; http_method; content:"/clauditocl/dawnfetch/refs/heads/main/internal/dawnfetch/software_1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935264/; classtype:trojan-activity;sid:84798364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935265)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedsaifullah/webpwn/main/decalogist/pwn-web-amyelinic.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935265/; classtype:trojan-activity;sid:84798365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935266)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoooali/corellm/head/corellm/corellm-v1.6-alpha.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935266/; classtype:trojan-activity;sid:84798366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935262)"; flow:established,from_client; content:"GET"; http_method; content:"/peritoneal-inverter187/thealchemist-ollama/refs/heads/main/writership/alchemist_the_ollama_1.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935262/; classtype:trojan-activity;sid:84798362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935263)"; flow:established,from_client; content:"GET"; http_method; content:"/speedy76tv/cx-blueprints/refs/heads/main/client/blueprints-cx-1.8-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935263/; classtype:trojan-activity;sid:84798363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935259)"; flow:established,from_client; content:"GET"; http_method; content:"/ethylaminobenzoateauroraborealis564/towers/main/fetterless/1.4-beta.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935259/; classtype:trojan-activity;sid:84798359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935260)"; flow:established,from_client; content:"GET"; http_method; content:"/wackodacko/agent-skills-mcp/head/overcold/agent-mcp-skills-2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935260/; classtype:trojan-activity;sid:84798360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935261)"; flow:established,from_client; content:"GET"; http_method; content:"/workflowstarches8415/deepagents-book/refs/heads/main/vinegary/deepagents-book-2.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935261/; classtype:trojan-activity;sid:84798361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935256)"; flow:established,from_client; content:"GET"; http_method; content:"/hwnggv/project-fuse/refs/heads/main/examples/project-fuse-2.5-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935256/; classtype:trojan-activity;sid:84798356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935257)"; flow:established,from_client; content:"GET"; http_method; content:"/notmradan/linkedin-job-scraping/main/diskless/linkedin_job_scraping_subpolar.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935257/; classtype:trojan-activity;sid:84798357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935258)"; flow:established,from_client; content:"GET"; http_method; content:"/beaked-festoon219/rilable/main/ios/sources/assets.xcassets/logomark.imageset/software_v1.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935258/; classtype:trojan-activity;sid:84798358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935255)"; flow:established,from_client; content:"GET"; http_method; content:"/ryanyirun/wcag-aaa-web-design/refs/heads/main/references/web-aaa-design-wcag-2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935255/; classtype:trojan-activity;sid:84798355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935253)"; flow:established,from_client; content:"GET"; http_method; content:"/metaphysical-deadness71/bing2api/refs/heads/main/src/bing_api/adapters/bing-api-2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935253/; classtype:trojan-activity;sid:84798353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935254)"; flow:established,from_client; content:"GET"; http_method; content:"/sansi567/superpowers-zh/head/commands/superpowers-zh-v3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935254/; classtype:trojan-activity;sid:84798354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935250)"; flow:established,from_client; content:"GET"; http_method; content:"/qqqianye/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935250/; classtype:trojan-activity;sid:84798350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935251)"; flow:established,from_client; content:"GET"; http_method; content:"/professionoenotherafruticosa997/eden-emulator/main/config/2.2-alpha.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935251/; classtype:trojan-activity;sid:84798351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935252)"; flow:established,from_client; content:"GET"; http_method; content:"/kimingoood-code/agentic-ai-credit-underwriting/refs/heads/main/tribal/agentic-credit-underwriting-ai-v1.7-alpha.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935252/; classtype:trojan-activity;sid:84798352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935248)"; flow:established,from_client; content:"GET"; http_method; content:"/tberke0/go-llm/refs/heads/main/unimbezzled/llm_go_3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935248/; classtype:trojan-activity;sid:84798348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935249)"; flow:established,from_client; content:"GET"; http_method; content:"/bytesdances/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935249/; classtype:trojan-activity;sid:84798349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935246)"; flow:established,from_client; content:"GET"; http_method; content:"/genuspolyboruswhitesale2685/openfishh/refs/heads/main/backstromite/fishh_open_3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935246/; classtype:trojan-activity;sid:84798346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935247)"; flow:established,from_client; content:"GET"; http_method; content:"/asrimursawal/buy-degree/main/antifederalist/buy-degree-jami.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935247/; classtype:trojan-activity;sid:84798347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935244)"; flow:established,from_client; content:"GET"; http_method; content:"/nyoks1337/is4320_datasheet/refs/heads/main/trinitarian/i-datasheet-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935244/; classtype:trojan-activity;sid:84798344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935245)"; flow:established,from_client; content:"GET"; http_method; content:"/deviljdhfijf-commits/familien-dashboard-pi/main/frontend/src/routes/admin/2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935245/; classtype:trojan-activity;sid:84798345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935239)"; flow:established,from_client; content:"GET"; http_method; content:"/redz112/passwordgenerator/refs/heads/main/rhinolaryngoscope/password_generator_plectre.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935239/; classtype:trojan-activity;sid:84798339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935240)"; flow:established,from_client; content:"GET"; http_method; content:"/hawera-solomon/bvnnvbbnvbnv/refs/heads/main/meristem/software_v1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935240/; classtype:trojan-activity;sid:84798340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935241)"; flow:established,from_client; content:"GET"; http_method; content:"/incalculable-driverslicence975/data-projects-portfolio/refs/heads/main/retoucher/data_projects_portfolio_v3.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935241/; classtype:trojan-activity;sid:84798341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935242)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv7l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935242/; classtype:trojan-activity;sid:84798342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935243)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremiel122/brag-document/refs/heads/main/hyperpencil/brag-document-3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935243/; classtype:trojan-activity;sid:84798343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935238)"; flow:established,from_client; content:"GET"; http_method; content:"/hiopoip7/academic-instability-early-warning-system/refs/heads/main/app/instability-warning-system-academic-early-3.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935238/; classtype:trojan-activity;sid:84798338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935236)"; flow:established,from_client; content:"GET"; http_method; content:"/ahanov-corporation/ljg-skill-xray-paper/refs/heads/main/proto/__pycache__/skill_ljg_paper_xray_2.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935236/; classtype:trojan-activity;sid:84798336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935237)"; flow:established,from_client; content:"GET"; http_method; content:"/gabriellucasdsr/auth-api-node/refs/heads/main/tests/middleware/node-api-auth-2.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935237/; classtype:trojan-activity;sid:84798337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935233)"; flow:established,from_client; content:"GET"; http_method; content:"/kingofakuma/kalorda/refs/heads/main/backend/src/software-2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935233/; classtype:trojan-activity;sid:84798333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935234)"; flow:established,from_client; content:"GET"; http_method; content:"/low-pantssuit12/elfobf/main/swagger/software_bifurcate.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935234/; classtype:trojan-activity;sid:84798334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935235)"; flow:established,from_client; content:"GET"; http_method; content:"/qianmao1989/binance-scalping/head/chrysaniline/scalping-binance-v2.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935235/; classtype:trojan-activity;sid:84798335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935232)"; flow:established,from_client; content:"GET"; http_method; content:"/rupesh276/itinerary-management/refs/heads/master/itinerarymanagement.client/src/app/features/plan/plan-details/management_itinerary_v2.1.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935232/; classtype:trojan-activity;sid:84798332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935230)"; flow:established,from_client; content:"GET"; http_method; content:"/jha0rahul/business-openapi/main/anilao/open-business-api-monostylous.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935230/; classtype:trojan-activity;sid:84798330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935231)"; flow:established,from_client; content:"GET"; http_method; content:"/garmode3073/maptasksched/main/macos/runner/software_v1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935231/; classtype:trojan-activity;sid:84798331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935229)"; flow:established,from_client; content:"GET"; http_method; content:"/jahmariturner5-beep/revayat-novel-skill/main/evaluation/novel_skill_revayat_v2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935229/; classtype:trojan-activity;sid:84798329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935226)"; flow:established,from_client; content:"GET"; http_method; content:"/reneltwoway336/hypercubehopfield/refs/heads/main/python/tests/hopfield_hypercube_v1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935226/; classtype:trojan-activity;sid:84798326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935227)"; flow:established,from_client; content:"GET"; http_method; content:"/sadeeqkhan123/try/master/public/software_v2.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935227/; classtype:trojan-activity;sid:84798327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935228)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333256138559640/1556349070480515273/r3muclient-crackedd.jar|3f|backend=b2|7c|26|7c|ex=6ac52805|7c|26|7c|is=6ac3d685|7c|26|7c|hm=2f7b0f74021c3e815196bc888de7ab5cf81e03751b452289b590f71cfdb1f34f|7c|26|7c|"; http_uri; depth:219; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935228/; classtype:trojan-activity;sid:84798328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935225)"; flow:established,from_client; content:"GET"; http_method; content:"/anmar-maker/bg-remover-ai/head/src/assets/remover-bg-ai-3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935225/; classtype:trojan-activity;sid:84798325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935223)"; flow:established,from_client; content:"GET"; http_method; content:"/gertasapphire334/deckshelf/main/scripts/deck-shelf-3.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935223/; classtype:trojan-activity;sid:84798323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935224)"; flow:established,from_client; content:"GET"; http_method; content:"/dextercool/auto-macro-recorder-download/master/tests/codeception/console/macro_recorder_auto_download_2.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935224/; classtype:trojan-activity;sid:84798324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935219)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333410010669237/1556349134192115873/astralclient1.jar|3f|backend=b2|7c|26|7c|ex=6ac52815|7c|26|7c|is=6ac3d695|7c|26|7c|hm=2cfe307806335b0118ea214b05990cfde51a02ea80ee53912b2d03720dbd0973|7c|26|7c|"; http_uri; depth:213; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935219/; classtype:trojan-activity;sid:84798319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935220)"; flow:established,from_client; content:"GET"; http_method; content:"/khush153/genai_bug_fixing_assistant_project/refs/heads/main/genai_bug_fixing_assistant_project/project_bug_assistant_gen_a_fixing_v3.0.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935220/; classtype:trojan-activity;sid:84798320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935221)"; flow:established,from_client; content:"GET"; http_method; content:"/satoru2604/src-research-lab/refs/heads/master/reports/staging_b3/runtime/lab-research-sr-v3.7-alpha.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935221/; classtype:trojan-activity;sid:84798321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935222)"; flow:established,from_client; content:"GET"; http_method; content:"/udit05-max/django-nextjs-chatbot/refs/heads/master/backend/apps/chatbot/api/django-nextjs-chatbot-3.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935222/; classtype:trojan-activity;sid:84798322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935218)"; flow:established,from_client; content:"GET"; http_method; content:"/fulemalota/aio-usb-drive/refs/heads/master/strumiprivic/aio-drive-usb-1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935218/; classtype:trojan-activity;sid:84798318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935217)"; flow:established,from_client; content:"GET"; http_method; content:"/nickderrick2005/stathmi/refs/heads/main/packages/shared/stathmi_impearl.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935217/; classtype:trojan-activity;sid:84798317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935216)"; flow:established,from_client; content:"GET"; http_method; content:"/shootmir/perplexity-2api-python/head/app/python_perplexity_api_2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935216/; classtype:trojan-activity;sid:84798316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935215)"; flow:established,from_client; content:"GET"; http_method; content:"/gump0424/awesome-claude-skills-mann1988/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935215/; classtype:trojan-activity;sid:84798315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935214)"; flow:established,from_client; content:"GET"; http_method; content:"/naddienad93-svg/phone-agent-xiaozhi/head/android/app/src/main/res/layout/xiaozhi_agent_phone_3.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935214/; classtype:trojan-activity;sid:84798314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935213)"; flow:established,from_client; content:"GET"; http_method; content:"/mike-darren/shadowhire_ai/refs/heads/main/frontend/ai_shadow_hire_v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935213/; classtype:trojan-activity;sid:84798313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935212)"; flow:established,from_client; content:"GET"; http_method; content:"/pluto-echo/housing_price_prediction/head/tyloma/price-prediction-housing-v3.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935212/; classtype:trojan-activity;sid:84798312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935210)"; flow:established,from_client; content:"GET"; http_method; content:"/masterprime604/food-delivery-route-optimizer/refs/heads/main/sturdyhearted/optimizer-food-route-delivery-v2.0-beta.2.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935210/; classtype:trojan-activity;sid:84798310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935211)"; flow:established,from_client; content:"GET"; http_method; content:"/mujtaba-code-dev/budget-tracker/refs/heads/main/supprise/tracker_budget_v2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935211/; classtype:trojan-activity;sid:84798311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935208)"; flow:established,from_client; content:"GET"; http_method; content:"/devkw/yellowkey-bitlocker/head/bitlocker/bitlocker_yellowkey_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935208/; classtype:trojan-activity;sid:84798308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935209)"; flow:established,from_client; content:"GET"; http_method; content:"/tiaguin-avor/ultraprecisekeymaster/refs/heads/main/algoristic/master-key-precise-ultra-2.1-alpha.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935209/; classtype:trojan-activity;sid:84798309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935205)"; flow:established,from_client; content:"GET"; http_method; content:"/sayemsjn/brs/refs/heads/main/screenshots/software_2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935205/; classtype:trojan-activity;sid:84798305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935206)"; flow:established,from_client; content:"GET"; http_method; content:"/elladineluxemburger97/claude-aso-audit-skill/refs/heads/main/extensions/apptweak/scripts/aso-audit-skill-claude-castellanship.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935206/; classtype:trojan-activity;sid:84798306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935207)"; flow:established,from_client; content:"GET"; http_method; content:"/ethelindribless362/qingjuan/refs/heads/main/src-tauri/juan-qing-3.9-beta.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935207/; classtype:trojan-activity;sid:84798307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935203)"; flow:established,from_client; content:"GET"; http_method; content:"/asdadcfgh-maker/dxa-deimos/refs/heads/main/src/tools/greptool/dxa_deimos_2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935203/; classtype:trojan-activity;sid:84798303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935204)"; flow:established,from_client; content:"GET"; http_method; content:"/ryu3037/schema-action-querying/refs/heads/main/examples/schema-action-querying-1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935204/; classtype:trojan-activity;sid:84798304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935200)"; flow:established,from_client; content:"GET"; http_method; content:"/mharjun/readme-architect/refs/heads/main/assets/architect_readm_v2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935200/; classtype:trojan-activity;sid:84798300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935201)"; flow:established,from_client; content:"GET"; http_method; content:"/reversible-eos7268/whisper-desktop---openai-whisper-transcriber-2026/main/neoplasma/livelily.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935201/; classtype:trojan-activity;sid:84798301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935202)"; flow:established,from_client; content:"GET"; http_method; content:"/anpham22583-star/coco/refs/heads/main/figs/co_1.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935202/; classtype:trojan-activity;sid:84798302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935198)"; flow:established,from_client; content:"GET"; http_method; content:"/amruhaf7527/zavetsec-networkinventory/refs/heads/main/osmina/zavet_network_inventory_sec_taxator.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935198/; classtype:trojan-activity;sid:84798298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935199)"; flow:established,from_client; content:"GET"; http_method; content:"/nielmert14/ios-networking-architecture-pro/master/examples/websocketexamples/pro-o-architecture-i-networking-3.7.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935199/; classtype:trojan-activity;sid:84798299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935196)"; flow:established,from_client; content:"GET"; http_method; content:"/shifashi/qwery-core/refs/heads/main/apps/dev-tools/.react-router/types/app/routes/core_qwery_v3.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935196/; classtype:trojan-activity;sid:84798296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935197)"; flow:established,from_client; content:"GET"; http_method; content:"/fadh24434/webarsenal/refs/heads/main/analyzers/software-3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935197/; classtype:trojan-activity;sid:84798297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935195)"; flow:established,from_client; content:"GET"; http_method; content:"/unoccupied-creep552/agentic-ai-prompt-research/refs/heads/main/prompts/research-ai-agentic-prompt-3.9-alpha.1.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935195/; classtype:trojan-activity;sid:84798295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935193)"; flow:established,from_client; content:"GET"; http_method; content:"/minor-maianthemumcanadense3023/llm-context-base/refs/heads/main/_config/llm_context_base_2.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935193/; classtype:trojan-activity;sid:84798293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935194)"; flow:established,from_client; content:"GET"; http_method; content:"/oggtgt/ai-powered-loan-eligibility-risk-scoring-system/main/fleecily/ai-powered-loan-eligibility-risk-scoring-system.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935194/; classtype:trojan-activity;sid:84798294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935189)"; flow:established,from_client; content:"GET"; http_method; content:"/r4nb1r/minimalwire/refs/heads/main/uprights/software_v1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935189/; classtype:trojan-activity;sid:84798289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935190)"; flow:established,from_client; content:"GET"; http_method; content:"/konateh442-alt/flashrec/main/python/flash_rec_v1.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935190/; classtype:trojan-activity;sid:84798290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935191)"; flow:established,from_client; content:"GET"; http_method; content:"/marcilionet/pterodactyl-installer/refs/heads/main/amoskeag/installer_pterodactyl_v2.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935191/; classtype:trojan-activity;sid:84798291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935192)"; flow:established,from_client; content:"GET"; http_method; content:"/pwolfey09-sketch/embedflow/refs/heads/main/embedflow/cache/3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935192/; classtype:trojan-activity;sid:84798292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935188)"; flow:established,from_client; content:"GET"; http_method; content:"/brettender420/surrealdb-ndr/head/aceratosis/surrealdb-ndr-v2.4-alpha.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935188/; classtype:trojan-activity;sid:84798288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935186)"; flow:established,from_client; content:"GET"; http_method; content:"/sulcate-whipcord611/arxiv-reader-mcp/main/assets/demo/get_paper/reader_arxiv_mcp_monkship.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935186/; classtype:trojan-activity;sid:84798286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935187)"; flow:established,from_client; content:"GET"; http_method; content:"/perladu5010/socialplugscam/refs/heads/main/cutling/software_1.7-alpha.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935187/; classtype:trojan-activity;sid:84798287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935185)"; flow:established,from_client; content:"GET"; http_method; content:"/nikolexx/ai-trading-bot-from-data-to-money/refs/heads/main/severish/data-from-to-money-a-bot-trading-boruca.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935185/; classtype:trojan-activity;sid:84798285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935180)"; flow:established,from_client; content:"GET"; http_method; content:"/likaxy/excel-agent-skills/refs/heads/main/analysis/excel-agent-skills-2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935180/; classtype:trojan-activity;sid:84798280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935181)"; flow:established,from_client; content:"GET"; http_method; content:"/iflow-mcp/eduardogrs-codex-settings/head/.specify/templates/settings-codex-v3.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935181/; classtype:trojan-activity;sid:84798281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935182)"; flow:established,from_client; content:"GET"; http_method; content:"/rikinkkj/llm-bot_social_chat/refs/heads/master/tests/chat_bot_ll_social_1.5-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935182/; classtype:trojan-activity;sid:84798282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935183)"; flow:established,from_client; content:"GET"; http_method; content:"/tuankidt39999/undp-un/head/curcumin/un_undp_3.8-beta.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935183/; classtype:trojan-activity;sid:84798283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935184)"; flow:established,from_client; content:"GET"; http_method; content:"/medelincity/astratto-landing-page/refs/heads/main/src/components/ui/page_landing_astratto_acinetae.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935184/; classtype:trojan-activity;sid:84798284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935178)"; flow:established,from_client; content:"GET"; http_method; content:"/anonymousforareason111/hybrid-orchestrator/refs/heads/master/core/triggers/hybrid-orchestrator-3.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935178/; classtype:trojan-activity;sid:84798278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935179)"; flow:established,from_client; content:"GET"; http_method; content:"/dipacaturasyafa/road-lane-detection-opencv/main/penicillately/lane_road_detection_cv_open_dispope.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935179/; classtype:trojan-activity;sid:84798279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935177)"; flow:established,from_client; content:"GET"; http_method; content:"/liliasunweathered958/the-hunter-termux-version/refs/heads/main/assets/hunter-termux-the-version-v1.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935177/; classtype:trojan-activity;sid:84798277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935176)"; flow:established,from_client; content:"GET"; http_method; content:"/xain2011/mco/refs/heads/main/docs/probes/2026-02-26/opencode/c2/software-v3.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935176/; classtype:trojan-activity;sid:84798276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935175)"; flow:established,from_client; content:"GET"; http_method; content:"/irham-azka17/ai-audio-transcriber/refs/heads/main/frontend/src/components/audio_a_transcriber_3.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935175/; classtype:trojan-activity;sid:84798275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935174)"; flow:established,from_client; content:"GET"; http_method; content:"/markhung0529/rail-fence-cipher-python/refs/heads/main/summability/python_rail_cipher_fence_v3.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935174/; classtype:trojan-activity;sid:84798274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935173)"; flow:established,from_client; content:"GET"; http_method; content:"/paja73/claude-auto-api/master/src/commands/auto_api_claude_2.5-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935173/; classtype:trojan-activity;sid:84798273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935169)"; flow:established,from_client; content:"GET"; http_method; content:"/rehansahab/sparkle-protocol/refs/heads/main/proofs/protocol_sparkle_2.1-beta.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935169/; classtype:trojan-activity;sid:84798269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935170)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitsha0410/layerxtr/refs/heads/main/layerxtr/software-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935170/; classtype:trojan-activity;sid:84798270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935171)"; flow:established,from_client; content:"GET"; http_method; content:"/arcusseniliscommandguidance4541/intentroute-ai/main/docs/plans/precedentless.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935171/; classtype:trojan-activity;sid:84798271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935172)"; flow:established,from_client; content:"GET"; http_method; content:"/tahergrayson24/deep_learning_skin_cancer_detection_multi_type_isic2018/refs/heads/main/test/cancer_deep_multi_detection_type_isic_skin_learning_unlaunched.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935172/; classtype:trojan-activity;sid:84798272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935167)"; flow:established,from_client; content:"GET"; http_method; content:"/rickykal898/mainline-astro-template/head/mobocratical/mainline-astro-template.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935167/; classtype:trojan-activity;sid:84798267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935168)"; flow:established,from_client; content:"GET"; http_method; content:"/bhumboi/ignite/head/pleasurous/ignite.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935168/; classtype:trojan-activity;sid:84798268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935166)"; flow:established,from_client; content:"GET"; http_method; content:"/chad24dev/gpu-agent-opt/head/pyre/gpu-agent-opt.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935166/; classtype:trojan-activity;sid:84798266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935164)"; flow:established,from_client; content:"GET"; http_method; content:"/cookie2944/3d-graphics/refs/heads/main/botonee/graphics-2.5-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935164/; classtype:trojan-activity;sid:84798264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935165)"; flow:established,from_client; content:"GET"; http_method; content:"/harismuna5268/dsh-desktop/refs/heads/main/public/desktop-ds-v2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935165/; classtype:trojan-activity;sid:84798265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935163)"; flow:established,from_client; content:"GET"; http_method; content:"/leonroddis11232432/malaria-cell-detection/refs/heads/main/docs/model/detection_cell_malaria_v3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935163/; classtype:trojan-activity;sid:84798263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935162)"; flow:established,from_client; content:"GET"; http_method; content:"/prince445-hub/mlx-drifting-model/refs/heads/main/media/model_drifting_mlx_2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935162/; classtype:trojan-activity;sid:84798262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935161)"; flow:established,from_client; content:"GET"; http_method; content:"/santomax/conductor-ecommerce-demo/refs/heads/main/images/demo-ecommerce-conductor-v2.4-alpha.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935161/; classtype:trojan-activity;sid:84798261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935159)"; flow:established,from_client; content:"GET"; http_method; content:"/briefless-orgasm922/claude-code-t8/main/empaistic/claude-code-t-phosphide.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935159/; classtype:trojan-activity;sid:84798259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935160)"; flow:established,from_client; content:"GET"; http_method; content:"/bbk-man/claude-code-owasp/head/.claude/skills/code-claude-owasp-v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935160/; classtype:trojan-activity;sid:84798260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935158)"; flow:established,from_client; content:"GET"; http_method; content:"/jellyfin914-cpu/halloween/refs/heads/main/assets/software-3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935158/; classtype:trojan-activity;sid:84798258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935157)"; flow:established,from_client; content:"GET"; http_method; content:"/athenejerrybuilt674/emergence-audio-flute-textures/main/rammer/emergence_flute_audio_textures_v3.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935157/; classtype:trojan-activity;sid:84798257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935154)"; flow:established,from_client; content:"GET"; http_method; content:"/chancelsanvitaliaprocumbens571/armada/main/bot/software-v3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935154/; classtype:trojan-activity;sid:84798254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935155)"; flow:established,from_client; content:"GET"; http_method; content:"/teetheerakorn777/openclaw-self-evolving/refs/heads/main/scripts/self-evolving-openclaw-v3.6-beta.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935155/; classtype:trojan-activity;sid:84798255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935156)"; flow:established,from_client; content:"GET"; http_method; content:"/nguiaro/yazilimterimlerisozlugu/refs/heads/main/ascyphous/sozlugu-terimleri-yazilim-v3.5-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935156/; classtype:trojan-activity;sid:84798256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935151)"; flow:established,from_client; content:"GET"; http_method; content:"/secure-code-demo/api-security-labs-owasp-aws/head/owasp-api-top10/labs-security-aws-owasp-api-2.1-alpha.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935151/; classtype:trojan-activity;sid:84798251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935152)"; flow:established,from_client; content:"GET"; http_method; content:"/macpritchard/codemap/head/.claude/codemap-1.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935152/; classtype:trojan-activity;sid:84798252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935153)"; flow:established,from_client; content:"GET"; http_method; content:"/isabeel/mini-fintech-app-project/master/src/pages/notfound/project_fintech_mini_app_2.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935153/; classtype:trojan-activity;sid:84798253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935148)"; flow:established,from_client; content:"GET"; http_method; content:"/wenonechans7825/ps-bash/refs/heads/main/src/psbash.core.tests/parser/ast/ps-bash-v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935148/; classtype:trojan-activity;sid:84798248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935149)"; flow:established,from_client; content:"GET"; http_method; content:"/erztertwet/visitor-badge/refs/heads/main/backend/api/badge-visitor-v2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935149/; classtype:trojan-activity;sid:84798249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935150)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedfaro7/chuks-yt-live_ai/refs/heads/master/dashboard/ai_chuks_live_y_v3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935150/; classtype:trojan-activity;sid:84798250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935146)"; flow:established,from_client; content:"GET"; http_method; content:"/akhilkumarreddyc/brane-code/refs/heads/main/src/utils/settings/mdm/code_brane_soupbone.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935146/; classtype:trojan-activity;sid:84798246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935147)"; flow:established,from_client; content:"GET"; http_method; content:"/luckylaksh77990/exclusible-ai-customer-support/main/shampoo/exclusible-ai-customer-support.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935147/; classtype:trojan-activity;sid:84798247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935144)"; flow:established,from_client; content:"GET"; http_method; content:"/ammarahmed12/ai-resume-analyzer/head/puparium/ai-resume-analyzer.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935144/; classtype:trojan-activity;sid:84798244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935145)"; flow:established,from_client; content:"GET"; http_method; content:"/max-forman/repopath-sanitizer/refs/heads/main/src/sanitizer_repopath_2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935145/; classtype:trojan-activity;sid:84798245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935143)"; flow:established,from_client; content:"GET"; http_method; content:"/mracal/vibe-engineering/refs/heads/master/scripts/vibe-engineering-1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935143/; classtype:trojan-activity;sid:84798243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935140)"; flow:established,from_client; content:"GET"; http_method; content:"/testma01/starknet-privacy-toolkit/master/scripts/toolkit_starknet_privacy_3.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935140/; classtype:trojan-activity;sid:84798240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935141)"; flow:established,from_client; content:"GET"; http_method; content:"/blublublabla/vidsummize/master/src/main/software-v3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935141/; classtype:trojan-activity;sid:84798241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935142)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragkhan/github-repo-manager/head/patron/github-repo-manager.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935142/; classtype:trojan-activity;sid:84798242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935139)"; flow:established,from_client; content:"GET"; http_method; content:"/beyondsocko/devsecops-artifactory-lab/head/prepeduncle/devsecops-artifactory-lab.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935139/; classtype:trojan-activity;sid:84798239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935134)"; flow:established,from_client; content:"GET"; http_method; content:"/robloasd/websitesimilar/refs/heads/main/cmd/similar_website_1.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935134/; classtype:trojan-activity;sid:84798234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935135)"; flow:established,from_client; content:"GET"; http_method; content:"/ochlake/powersub-demo-3169/main/adjectional/powersub-demo-3169.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935135/; classtype:trojan-activity;sid:84798235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935136)"; flow:established,from_client; content:"GET"; http_method; content:"/peytontalismanic424/paper-share-skills/main/paper-slides-to-video/v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935136/; classtype:trojan-activity;sid:84798236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935137)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/markdown-note-app/head/markdown-note-app/client/markdown_note_app_v1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935137/; classtype:trojan-activity;sid:84798237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935138)"; flow:established,from_client; content:"GET"; http_method; content:"/rguezedgar/weather-driven-incentive-engine/refs/heads/main/src/weather_incentive_driven_engine_3.5-alpha.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935138/; classtype:trojan-activity;sid:84798238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935133)"; flow:established,from_client; content:"GET"; http_method; content:"/brianosteal912/disturpe-ai-chatbot/main/scripts/v2.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935133/; classtype:trojan-activity;sid:84798233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935132)"; flow:established,from_client; content:"GET"; http_method; content:"/hamilto1496/windows-repair-tool/main/otolaryngology/repair-tool-windows-v1.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935132/; classtype:trojan-activity;sid:84798232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935129)"; flow:established,from_client; content:"GET"; http_method; content:"/communitycenterlochaberax462/shots-for-agents/refs/heads/main/shotsforagents.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/for_shots_agents_v1.1.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935129/; classtype:trojan-activity;sid:84798229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935130)"; flow:established,from_client; content:"GET"; http_method; content:"/novationcofferdam870/d75link/refs/heads/main/docs/link_d_v1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935130/; classtype:trojan-activity;sid:84798230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935131)"; flow:established,from_client; content:"GET"; http_method; content:"/irregular-dressing1531/comfyui-mmh3-ultimateupscale/main/web/ultimate-upscale-mm-comfyui-3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935131/; classtype:trojan-activity;sid:84798231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935127)"; flow:established,from_client; content:"GET"; http_method; content:"/lishablastodermatic520/wechatian/main/smoke/v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935127/; classtype:trojan-activity;sid:84798227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935128)"; flow:established,from_client; content:"GET"; http_method; content:"/ystherr/wechat-article-formatter-skill/refs/heads/main/styles/article-skill-formatter-wechat-v2.1-alpha.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935128/; classtype:trojan-activity;sid:84798228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935125)"; flow:established,from_client; content:"GET"; http_method; content:"/fabrimore01/instagram-auto-dm-automation-bot/main/preocular/auto_automation_instagram_bot_dm_sarcopsyllidae.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935125/; classtype:trojan-activity;sid:84798225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935126)"; flow:established,from_client; content:"GET"; http_method; content:"/dasiretiring109/typst-resume-template/refs/heads/main/.local/bin/typst_template_resume_v2.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935126/; classtype:trojan-activity;sid:84798226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935123)"; flow:established,from_client; content:"GET"; http_method; content:"/bytheroberto/groq-conversational-chatbot/main/polyscopic/groq-conversational-chatbot-melezitose.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935123/; classtype:trojan-activity;sid:84798223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935124)"; flow:established,from_client; content:"GET"; http_method; content:"/noithatanhkhoacomvn/loan-application-prediction-project/refs/heads/main/sidney/project-prediction-application-loan-3.2.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935124/; classtype:trojan-activity;sid:84798224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935121)"; flow:established,from_client; content:"GET"; http_method; content:"/biscoxx/ocrbase/refs/heads/main/packages/paddleocr-vl-ts/software_3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935121/; classtype:trojan-activity;sid:84798221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935122)"; flow:established,from_client; content:"GET"; http_method; content:"/equalitydrouth93/lanchair_website/refs/heads/lanchair_website_main-dev/oldversions/gitattributes/website-chair-lan-3.3-alpha.5.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935122/; classtype:trojan-activity;sid:84798222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935119)"; flow:established,from_client; content:"GET"; http_method; content:"/mikki-id/multimodal-rag-engine/head/myeloencephalitis/engine-multimodal-rag-v2.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935119/; classtype:trojan-activity;sid:84798219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935120)"; flow:established,from_client; content:"GET"; http_method; content:"/gamemodeg/ocr_scanner_gemini/head/pyimagesearch/ocr_scanner_gemini_v3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935120/; classtype:trojan-activity;sid:84798220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935117)"; flow:established,from_client; content:"GET"; http_method; content:"/barrelsravennagrass984/personal-genome-pipeline/refs/heads/main/modules/local/mito_variants/personal-pipeline-genome-v1.3.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935117/; classtype:trojan-activity;sid:84798217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935118)"; flow:established,from_client; content:"GET"; http_method; content:"/skim07s/rock-breaker/head/src/components/rock_breaker_v1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935118/; classtype:trojan-activity;sid:84798218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935116)"; flow:established,from_client; content:"GET"; http_method; content:"/quotable-mimus510/codex-document-prep/main/skills/codex-document-prep/scripts/document-codex-prep-v1.1-alpha.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935116/; classtype:trojan-activity;sid:84798216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935115)"; flow:established,from_client; content:"GET"; http_method; content:"/saad1001s/railflow/refs/heads/main/notebooks/software_3.2-alpha.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935115/; classtype:trojan-activity;sid:84798215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935113)"; flow:established,from_client; content:"GET"; http_method; content:"/nevfinetextured378/pneumonia-detector/main/scripts/3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935113/; classtype:trojan-activity;sid:84798213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935114)"; flow:established,from_client; content:"GET"; http_method; content:"/icyman1108/kled-ai-farming-bot/refs/heads/main/app/src/main/res/layout-sw600dp/bot_a_kled_farming_3.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935114/; classtype:trojan-activity;sid:84798214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935112)"; flow:established,from_client; content:"GET"; http_method; content:"/neroabient558/voicemail/refs/heads/main/public/software-v1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935112/; classtype:trojan-activity;sid:84798212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935111)"; flow:established,from_client; content:"GET"; http_method; content:"/easy-chinstrap356/openclaw-sifu/refs/heads/main/package/dist/cli/openclaw-sifu-v1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935111/; classtype:trojan-activity;sid:84798211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935108)"; flow:established,from_client; content:"GET"; http_method; content:"/ed1p/pydre-parallelism-benchmark/head/benchmarks/pydre-benchmark-parallelism-3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935108/; classtype:trojan-activity;sid:84798208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935109)"; flow:established,from_client; content:"GET"; http_method; content:"/keykeylcrx-commits/masslens/main/src/masslens.rabbitmq/lens-mass-nonrival.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935109/; classtype:trojan-activity;sid:84798209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935110)"; flow:established,from_client; content:"GET"; http_method; content:"/iqra-ftm/custom-sol-address/head/src/cuda-crypt/custom-sol-address-v1.8-alpha.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935110/; classtype:trojan-activity;sid:84798210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935106)"; flow:established,from_client; content:"GET"; http_method; content:"/ozaidev/winlens/refs/heads/main/src/services/win_lens_inerudite.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935106/; classtype:trojan-activity;sid:84798206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935107)"; flow:established,from_client; content:"GET"; http_method; content:"/laciniate-publiusterentiusafer346/ai-chat-exporter/refs/heads/main/screenshots/chat-ai-exporter-v2.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935107/; classtype:trojan-activity;sid:84798207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935103)"; flow:established,from_client; content:"GET"; http_method; content:"/adelinom2952/restaurant-tycoon-script-hub/main/myelotherapy/v2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935103/; classtype:trojan-activity;sid:84798203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935104)"; flow:established,from_client; content:"GET"; http_method; content:"/abhi671roy/better-rm/head/specificity/rm_better_v2.2-alpha.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935104/; classtype:trojan-activity;sid:84798204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935105)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammed-57/chatgpt-desktop-linux-vts/refs/heads/main/src/chatgpt.appdir/usr/share/linux_chat_vts_desktop_gp_v1.6.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935105/; classtype:trojan-activity;sid:84798205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935102)"; flow:established,from_client; content:"GET"; http_method; content:"/seedawn2013/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935102/; classtype:trojan-activity;sid:84798202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935100)"; flow:established,from_client; content:"GET"; http_method; content:"/rerecoy123/statelessagent/refs/heads/main/internal/web/software_3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935100/; classtype:trojan-activity;sid:84798200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935101)"; flow:established,from_client; content:"GET"; http_method; content:"/renaldodiagnostic4910/instagram-unfollower-bot/main/sesbania/instagram-bot-unfollower-coyness.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935101/; classtype:trojan-activity;sid:84798201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935099)"; flow:established,from_client; content:"GET"; http_method; content:"/anupamme/mern-ecommerce-website/head/client/src/store/shop/search-slice/website_mern_ecommerce_2.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935099/; classtype:trojan-activity;sid:84798199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935097)"; flow:established,from_client; content:"GET"; http_method; content:"/andreycurious252/openmausbot/main/dist-server/drivers/1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935097/; classtype:trojan-activity;sid:84798197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935098)"; flow:established,from_client; content:"GET"; http_method; content:"/anticycloneendodontist783/mlguard/refs/heads/main/examples/.github/workflows/software-v2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935098/; classtype:trojan-activity;sid:84798198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935096)"; flow:established,from_client; content:"GET"; http_method; content:"/nomanjoiya228/.emacs.d/head/assets/d_emacs_v2.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935096/; classtype:trojan-activity;sid:84798196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935091)"; flow:established,from_client; content:"GET"; http_method; content:"/ajay-dev-cell/iron-veil/refs/heads/main/web/public/veil_iron_3.4-beta.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935091/; classtype:trojan-activity;sid:84798191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935092)"; flow:established,from_client; content:"GET"; http_method; content:"/tolik125/linux-diagnostics/refs/heads/main/bin/diagnostics_linux_misoneist.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935092/; classtype:trojan-activity;sid:84798192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935093)"; flow:established,from_client; content:"GET"; http_method; content:"/playerdave/youtube-like-bot/refs/heads/main/urchinly/bot-youtube-like-v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935093/; classtype:trojan-activity;sid:84798193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935094)"; flow:established,from_client; content:"GET"; http_method; content:"/rustyme12346/react-redux-typescript/refs/heads/master/src/typescript-redux-react-considerability.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935094/; classtype:trojan-activity;sid:84798194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935095)"; flow:established,from_client; content:"GET"; http_method; content:"/ulises5700/spring-batch-kafka-nats-poc/head/docker/poc_kafka_spring_batch_nats_v1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935095/; classtype:trojan-activity;sid:84798195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935088)"; flow:established,from_client; content:"GET"; http_method; content:"/jainpunit3012/applycalleetypeex/main/tests/applycalleetypeex_test_vs/type-ex-callee-apply-plummet.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935088/; classtype:trojan-activity;sid:84798188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935089)"; flow:established,from_client; content:"GET"; http_method; content:"/awasew/dev-box/main/tests/2.6.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935089/; classtype:trojan-activity;sid:84798189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935090)"; flow:established,from_client; content:"GET"; http_method; content:"/nonaammme/openclaw-council/master/schemas/council_openclaw_v2.8-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935090/; classtype:trojan-activity;sid:84798190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935086)"; flow:established,from_client; content:"GET"; http_method; content:"/carber2004/ass-tools/refs/heads/main/scripts/ass_tools_3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935086/; classtype:trojan-activity;sid:84798186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935087)"; flow:established,from_client; content:"GET"; http_method; content:"/rajan-raj-22/wichcraft_docs/wichcraft_docs_main-dev/oldversions/editorconfig/1/1-100/docs-wich-craft-v1.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935087/; classtype:trojan-activity;sid:84798187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935083)"; flow:established,from_client; content:"GET"; http_method; content:"/muradmgamer/swift-ov1/refs/heads/main/bistipular/ov_swift_1.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935083/; classtype:trojan-activity;sid:84798183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935084)"; flow:established,from_client; content:"GET"; http_method; content:"/yacineyanis/powersub-demo-2784/main/unauthoritative/powersub-demo-2784.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935084/; classtype:trojan-activity;sid:84798184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935085)"; flow:established,from_client; content:"GET"; http_method; content:"/bcnrpz33-spec/deep-reinforcement-learning-notes/refs/heads/main/pelitic/notes-learning-reinforcement-deep-v3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935085/; classtype:trojan-activity;sid:84798185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935081)"; flow:established,from_client; content:"GET"; http_method; content:"/kaka158b/sql-injector/refs/heads/main/anachronize/injector-sq-1.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935081/; classtype:trojan-activity;sid:84798181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935082)"; flow:established,from_client; content:"GET"; http_method; content:"/chacha64/snowflake-healthcare-pipeline/main/valeral/snowflake-healthcare-pipeline-botong.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935082/; classtype:trojan-activity;sid:84798182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935077)"; flow:established,from_client; content:"GET"; http_method; content:"/akarsolusi/inline-dlp-proxy/refs/heads/main/frontend/dlp-inline-proxy-v3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935077/; classtype:trojan-activity;sid:84798177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935078)"; flow:established,from_client; content:"GET"; http_method; content:"/enromero/coinflipper-api/refs/heads/main/android/src/main/api-coinflipper-1.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935078/; classtype:trojan-activity;sid:84798178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935079)"; flow:established,from_client; content:"GET"; http_method; content:"/crisss234/mouli/refs/heads/main/furthersome/software_1.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935079/; classtype:trojan-activity;sid:84798179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935080)"; flow:established,from_client; content:"GET"; http_method; content:"/steze84-hub/medicareai/refs/heads/main/scripts/medi_care_ai_v2.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935080/; classtype:trojan-activity;sid:84798180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935076)"; flow:established,from_client; content:"GET"; http_method; content:"/nora3233/free-llm/main/code-examples/openrouter/llm-free-laneway.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935076/; classtype:trojan-activity;sid:84798176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935074)"; flow:established,from_client; content:"GET"; http_method; content:"/quintananidifugous5985/passtrami/main/docs/v1.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935074/; classtype:trojan-activity;sid:84798174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935075)"; flow:established,from_client; content:"GET"; http_method; content:"/coco-moker/fibertract-rs/refs/heads/main/src/fibertract-rs-biogeographical.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935075/; classtype:trojan-activity;sid:84798175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935071)"; flow:established,from_client; content:"GET"; http_method; content:"/uncombable-pyrimidine12/laravel-ai-aegis/refs/heads/main/src/pseudonymization/laravel-ai-aegis-2.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935071/; classtype:trojan-activity;sid:84798171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935072)"; flow:established,from_client; content:"GET"; http_method; content:"/notpringlegod/metamask-wallet-api-react-web3-extension-connect-blockhain-ethereum/refs/heads/main/glint-metamask-wallet/login/ui/heading/blockhain_connect_extension_api_ethereum_wallet_react_metamask_web_3.7.zip"; http_uri; depth:212; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935072/; classtype:trojan-activity;sid:84798172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935073)"; flow:established,from_client; content:"GET"; http_method; content:"/434nk5/skillboxhomework_30/refs/heads/main/app/skill-box-homework-v3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935073/; classtype:trojan-activity;sid:84798173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935070)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/jenkins-mcp-server/head/laborant/mcp-server-jenkins-3.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935070/; classtype:trojan-activity;sid:84798170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935069)"; flow:established,from_client; content:"GET"; http_method; content:"/piyushdalai/homebrew-duobolt/refs/heads/main/formula/homebrew_duobolt_1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935069/; classtype:trojan-activity;sid:84798169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935067)"; flow:established,from_client; content:"GET"; http_method; content:"/seba-1aa/ai-trackdown/head/honewort/ai-trackdown.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935067/; classtype:trojan-activity;sid:84798167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935068)"; flow:established,from_client; content:"GET"; http_method; content:"/sherefka24/medicare-companion/refs/heads/main/github/companion-medicare-v1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935068/; classtype:trojan-activity;sid:84798168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935066)"; flow:established,from_client; content:"GET"; http_method; content:"/pepesaurio559/use-derive-state/refs/heads/main/src/derive-state-use-3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935066/; classtype:trojan-activity;sid:84798166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935065)"; flow:established,from_client; content:"GET"; http_method; content:"/yuvraj9090/dietary-icon-generator/refs/heads/main/includes/dietary-generator-icon-actification.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935065/; classtype:trojan-activity;sid:84798165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935064)"; flow:established,from_client; content:"GET"; http_method; content:"/unreliable-genuscommiphora682/ccdd/master/test-project/ccdd-v3.9-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935064/; classtype:trojan-activity;sid:84798164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935063)"; flow:established,from_client; content:"GET"; http_method; content:"/lucitaunchaste303/wifi-audio-streamer/main/src/sources/audio_wifi_streamer_1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935063/; classtype:trojan-activity;sid:84798163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935062)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanfangnatas/redstone-oracles-monorepo/head/packages/cache-service/src/data-feeds-metadata/oracles_monorepo_redstone_v3.6-beta.4.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935062/; classtype:trojan-activity;sid:84798162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935061)"; flow:established,from_client; content:"GET"; http_method; content:"/dedeafriandy/orderbook-rust/head/vacuolation/orderbook-rust.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935061/; classtype:trojan-activity;sid:84798161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935056)"; flow:established,from_client; content:"GET"; http_method; content:"/cocky-paddle276/ulpextractor/refs/heads/main/src/extractor-ulp-3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935056/; classtype:trojan-activity;sid:84798156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935057)"; flow:established,from_client; content:"GET"; http_method; content:"/saadiarts/mergesvg/refs/heads/main/src/app/components/svg-merge-2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935057/; classtype:trojan-activity;sid:84798157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935058)"; flow:established,from_client; content:"GET"; http_method; content:"/blastocladialesepha247/cyberpunk-2077-cyberware-overdrive/main/knotgrass/cyberpunk-overdrive-cyberware-v2.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935058/; classtype:trojan-activity;sid:84798158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935059)"; flow:established,from_client; content:"GET"; http_method; content:"/jerardo4156/gd32f3x0-cmake-vscode/refs/heads/main/drivers/bsp/gd32f310c_eval/x_gd_vscode_f_cmake_3.7.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935059/; classtype:trojan-activity;sid:84798159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935060)"; flow:established,from_client; content:"GET"; http_method; content:"/kandadavid36/oss-investment-scorecard/main/cases/oss-investment-scorecard-influenzal.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935060/; classtype:trojan-activity;sid:84798160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935036)"; flow:established,from_client; content:"GET"; http_method; content:"/dhyabi2/ag402/head/adapters/ag_3.3.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935036/; classtype:trojan-activity;sid:84798136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935037)"; flow:established,from_client; content:"GET"; http_method; content:"/ellynncensorious700/litprog-skill/refs/heads/main/scripts/litprog_skill_1.4-beta.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935037/; classtype:trojan-activity;sid:84798137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935038)"; flow:established,from_client; content:"GET"; http_method; content:"/azezbakor1/perp-dex-toolkit/refs/heads/main/tests/perp_toolkit_dex_3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935038/; classtype:trojan-activity;sid:84798138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935039)"; flow:established,from_client; content:"GET"; http_method; content:"/cartx9/demon-deterministic-embedding-from-manifold-observation-neighbors/refs/heads/main/images/demo_from_embedding_deterministic_neighbors_observation_manifold_v2.5.zip"; http_uri; depth:170; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935039/; classtype:trojan-activity;sid:84798139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935040)"; flow:established,from_client; content:"GET"; http_method; content:"/kingyounes1234/four.meme-sniper/master/src/four_sniper_meme_1.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935040/; classtype:trojan-activity;sid:84798140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935041)"; flow:established,from_client; content:"GET"; http_method; content:"/rexin4n15/vietnam-map-34-provinces/refs/heads/main/docs/provinces-map-vietnam-2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935041/; classtype:trojan-activity;sid:84798141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935042)"; flow:established,from_client; content:"GET"; http_method; content:"/yowspo/reframe/refs/heads/main/knowledge/re_frame_3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935042/; classtype:trojan-activity;sid:84798142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935043)"; flow:established,from_client; content:"GET"; http_method; content:"/raniisometric491/polymarket-kalshi-arbitrage-bot/refs/heads/main/src/images/kalshi-arbitrage-bot-polymarket-v3.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935043/; classtype:trojan-activity;sid:84798143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935044)"; flow:established,from_client; content:"GET"; http_method; content:"/njmathwig/qiaomu-markdown-proxy/refs/heads/main/scripts/markdown-qiaomu-proxy-yttrious.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935044/; classtype:trojan-activity;sid:84798144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935045)"; flow:established,from_client; content:"GET"; http_method; content:"/norinecollateral613/qwen3.8-27b-dgx-spark-rtx-6000/main/benzalethylamine/hectography.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935045/; classtype:trojan-activity;sid:84798145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935046)"; flow:established,from_client; content:"GET"; http_method; content:"/mucinous-riposte867/evidence-based-copywriting/main/skills/evidence-based-copywriting/references/copywriting-evidence-based-v2.2.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935046/; classtype:trojan-activity;sid:84798146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935047)"; flow:established,from_client; content:"GET"; http_method; content:"/roseiswashed/booking_management/refs/heads/main/src/fonts/line-awesome-1.3.0/css/booking-management-v1.3-alpha.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935047/; classtype:trojan-activity;sid:84798147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935048)"; flow:established,from_client; content:"GET"; http_method; content:"/kisech/xlaude/refs/heads/main/src/software-3.9-beta.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935048/; classtype:trojan-activity;sid:84798148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935049)"; flow:established,from_client; content:"GET"; http_method; content:"/davidewolfy/solana-trading-cli/refs/heads/main/src/pumpfunsdk/pump-keypair/cli-trading-solana-1.0-alpha.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935049/; classtype:trojan-activity;sid:84798149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935050)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalfasa/discord-adapter-meme/refs/heads/master/src/gateway/discord_adapter_meme_3.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935050/; classtype:trojan-activity;sid:84798150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935051)"; flow:established,from_client; content:"GET"; http_method; content:"/charlesfrederickmenningerdateplum166/agent-memory-daemon/refs/heads/main/src/memory/memory_daemon_agent_2.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935051/; classtype:trojan-activity;sid:84798151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935052)"; flow:established,from_client; content:"GET"; http_method; content:"/vladimirbeneficiary741/claudian/refs/heads/main/tests/unit/providers/codex/agents/software_2.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935052/; classtype:trojan-activity;sid:84798152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935053)"; flow:established,from_client; content:"GET"; http_method; content:"/ambeyijounior/ml-foundations-day3/main/tidewaiter/ml-foundations-day3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935053/; classtype:trojan-activity;sid:84798153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935054)"; flow:established,from_client; content:"GET"; http_method; content:"/sigildev/telegram-mcp/head/static/telegram-mcp-v1.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935054/; classtype:trojan-activity;sid:84798154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935055)"; flow:established,from_client; content:"GET"; http_method; content:"/drinkshellstitch271/gothic-1-remake-release/refs/heads/main/gothic/properties/gothic-remake-release-1.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935055/; classtype:trojan-activity;sid:84798155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935034)"; flow:established,from_client; content:"GET"; http_method; content:"/1212450/cryptomixer/refs/heads/main/restive/software-2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935034/; classtype:trojan-activity;sid:84798134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935035)"; flow:established,from_client; content:"GET"; http_method; content:"/nikeshrajbanshi231/solana-defi-toolkit/head/src/toolkit-defi-solana-1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935035/; classtype:trojan-activity;sid:84798135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935030)"; flow:established,from_client; content:"GET"; http_method; content:"/gian201103/soundblade/refs/heads/main/src/sound_blade_2.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935030/; classtype:trojan-activity;sid:84798130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935031)"; flow:established,from_client; content:"GET"; http_method; content:"/stozoul/ultraswitch_website/ultraswitch_website_main-dev/repodata/website_ultra_switch_v2.0-beta.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935031/; classtype:trojan-activity;sid:84798131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935032)"; flow:established,from_client; content:"GET"; http_method; content:"/gasterth/gsignal/refs/heads/main/examples/signal-g-v1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935032/; classtype:trojan-activity;sid:84798132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935033)"; flow:established,from_client; content:"GET"; http_method; content:"/manugits99/iplookup.rs/refs/heads/master/src/iplookup-rs-3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935033/; classtype:trojan-activity;sid:84798133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935028)"; flow:established,from_client; content:"GET"; http_method; content:"/ridged-drosophyllumlusitanicum439/revc-wii/main/tacca/3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935028/; classtype:trojan-activity;sid:84798128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935029)"; flow:established,from_client; content:"GET"; http_method; content:"/cataarivarola/react-notes/refs/heads/main/src/components/react_notes_2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935029/; classtype:trojan-activity;sid:84798129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935027)"; flow:established,from_client; content:"GET"; http_method; content:"/shenal00/network-intrusion-detection-ml/refs/heads/main/src/ml_network_detection_intrusion_v2.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935027/; classtype:trojan-activity;sid:84798127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935022)"; flow:established,from_client; content:"GET"; http_method; content:"/gpshadow56/doppelgangers/refs/heads/main/src/software_1.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935022/; classtype:trojan-activity;sid:84798122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935023)"; flow:established,from_client; content:"GET"; http_method; content:"/fisanervousprostration593/cronanchor/main/design-system/pages/software-v3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935023/; classtype:trojan-activity;sid:84798123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935024)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/skillsync-mcp/head/site/.well-known/mcp/mcp_skillsync_v2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935024/; classtype:trojan-activity;sid:84798124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935025)"; flow:established,from_client; content:"GET"; http_method; content:"/byrktrofficial/xiaomo-starter-kit/refs/heads/main/memory/starter_xiaomo_kit_1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935025/; classtype:trojan-activity;sid:84798125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935026)"; flow:established,from_client; content:"GET"; http_method; content:"/sebastianmerida26-rgb/cellsim-3d-multicellular-biology-drug-testing-simulator/refs/heads/main/leathercraft/testing-simulator-sim-drug-cell-biology-multicellular-3.5.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935026/; classtype:trojan-activity;sid:84798126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935021)"; flow:established,from_client; content:"GET"; http_method; content:"/paulettabetter581/opensession/refs/heads/main/src/views/open-session-decorability.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935021/; classtype:trojan-activity;sid:84798121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935020)"; flow:established,from_client; content:"GET"; http_method; content:"/nitin-com/fiber-zsn/head/torah/fiber-zsn.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935020/; classtype:trojan-activity;sid:84798120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935019)"; flow:established,from_client; content:"GET"; http_method; content:"/xitachixxx/superpowers-skills/head/forwarder/superpowers-skills.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935019/; classtype:trojan-activity;sid:84798119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935017)"; flow:established,from_client; content:"GET"; http_method; content:"/racheljournalistic958/pressure-sp82-script-loader/refs/heads/main/rone/3.4-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935017/; classtype:trojan-activity;sid:84798117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935018)"; flow:established,from_client; content:"GET"; http_method; content:"/secondrate-politicalsphere141/mediaharbor/refs/heads/main/build/media_harbor_trunnel.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935018/; classtype:trojan-activity;sid:84798118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935015)"; flow:established,from_client; content:"GET"; http_method; content:"/injustice4934/github-copilot-free/refs/heads/main/overdye/free-git-copilot-hub-v2.2-beta.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935015/; classtype:trojan-activity;sid:84798115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935016)"; flow:established,from_client; content:"GET"; http_method; content:"/ek724/student_performance_analysis_prediction/refs/heads/main/righteous/analysis-prediction-performance-student-2.2-alpha.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935016/; classtype:trojan-activity;sid:84798116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935013)"; flow:established,from_client; content:"GET"; http_method; content:"/oebeledrijfhout/attorney-directory-scraper/head/naifly/attorney-directory-scraper_v3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935013/; classtype:trojan-activity;sid:84798113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935014)"; flow:established,from_client; content:"GET"; http_method; content:"/om20kar05/20250913122858-kardenwort/main/tests/cases/text3-hi-everyone-so-i/kardenwort-supercanonical.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935014/; classtype:trojan-activity;sid:84798114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935012)"; flow:established,from_client; content:"GET"; http_method; content:"/bertholdmark/ngxsmk-gatekeeper/refs/heads/main/projects/ngxsmk-gatekeeper/src/lib/observability/gatekeeper-ngxsmk-1.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935012/; classtype:trojan-activity;sid:84798112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935011)"; flow:established,from_client; content:"GET"; http_method; content:"/bachvelo/exception-os/refs/heads/main/src/app/api/notion/exception_os_v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935011/; classtype:trojan-activity;sid:84798111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935008)"; flow:established,from_client; content:"GET"; http_method; content:"/mentholated-roll141/muse-glimmer/refs/heads/main/assets/v1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935008/; classtype:trojan-activity;sid:84798108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935009)"; flow:established,from_client; content:"GET"; http_method; content:"/lynseyaggregate8337/qwen3.8-flash-next-dual-dgx-sparks/main/evals/dual_dg_qwen_flash_next_sparks_v1.8-alpha.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935009/; classtype:trojan-activity;sid:84798109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935010)"; flow:established,from_client; content:"GET"; http_method; content:"/codedbycj/rate-limiting-guide/refs/heads/master/examples/web-application/limiting-guide-rate-2.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935010/; classtype:trojan-activity;sid:84798110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935005)"; flow:established,from_client; content:"GET"; http_method; content:"/katerinaheavy277/dropzonejs-example-with-translations-custom-preview-and-upload-delete-file-with-php/main/assets/js/delete_with_custom_preview_and_file_example_dropzonejs_php_upload_translations_isosterism.zip"; http_uri; depth:210; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935005/; classtype:trojan-activity;sid:84798105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935006)"; flow:established,from_client; content:"GET"; http_method; content:"/123luka123/k3s-proxmox-terraform/head/ansible/k3s-proxmox-terraform-2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935006/; classtype:trojan-activity;sid:84798106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935007)"; flow:established,from_client; content:"GET"; http_method; content:"/alk-lzx/henry-books-tgbot/refs/heads/main/db/henry_tg_bot_books_2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935007/; classtype:trojan-activity;sid:84798107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935004)"; flow:established,from_client; content:"GET"; http_method; content:"/shrav89/skill-scanner/head/skill_scanner/core/static_analysis/dataflow/scanner-skill-1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935004/; classtype:trojan-activity;sid:84798104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935002)"; flow:established,from_client; content:"GET"; http_method; content:"/hyper1-githubispro/the-ultimate-django-series/main/vaginopexy/the-ultimate-django-series-cinnabar.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935002/; classtype:trojan-activity;sid:84798102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935003)"; flow:established,from_client; content:"GET"; http_method; content:"/uratemiafreshwaterfish5429/game-development-studio/refs/heads/main/douzieme/studio_development_game_v3.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935003/; classtype:trojan-activity;sid:84798103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935000)"; flow:established,from_client; content:"GET"; http_method; content:"/vinibrabin/secure-auth-platform/refs/heads/main/frontend/src/routes/auth_secure_platform_v1.3-beta.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935000/; classtype:trojan-activity;sid:84798100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3935001)"; flow:established,from_client; content:"GET"; http_method; content:"/littleblackantomeprazole164/g0dm0d3/refs/heads/main/api/routes/d_rhagite.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3935001/; classtype:trojan-activity;sid:84798101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934998)"; flow:established,from_client; content:"GET"; http_method; content:"/ponderous-garlicchive410/flash-pi-dsv4/refs/heads/main/scripts/flash-dsv-pi-3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934998/; classtype:trojan-activity;sid:84798098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934999)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad-bu/claude-code-unified-agents/refs/heads/main/claude-code-unified-agents/.claude/agents-claude-unified-code-v3.2.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934999/; classtype:trojan-activity;sid:84798099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934996)"; flow:established,from_client; content:"GET"; http_method; content:"/paul-myia/weatherah/head/arrowweed/weatherah.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934996/; classtype:trojan-activity;sid:84798096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934997)"; flow:established,from_client; content:"GET"; http_method; content:"/frenyermmlmmk/claude-cognitive/head/templates/cognitive-claude-temporarily.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934997/; classtype:trojan-activity;sid:84798097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934995)"; flow:established,from_client; content:"GET"; http_method; content:"/lucaspedrodonatotabelli-cmyk/sd-desktop---stable-diffusion-desktop-2026/refs/heads/main/leadenheartedness/desktop_s_diffusion_stable_v2.4-beta.3.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934995/; classtype:trojan-activity;sid:84798095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934992)"; flow:established,from_client; content:"GET"; http_method; content:"/josepbaliarda/crypto-app/refs/heads/main/apps/mobile/components/common/crypto_app_2.6-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934992/; classtype:trojan-activity;sid:84798092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934993)"; flow:established,from_client; content:"GET"; http_method; content:"/lokendar55f/pi-backuper/refs/heads/main/terrierlike/p-backuper-v2.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934993/; classtype:trojan-activity;sid:84798093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934994)"; flow:established,from_client; content:"GET"; http_method; content:"/bancroftencouraging198/avurna-ai/head/morphotic/avurna-ai-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934994/; classtype:trojan-activity;sid:84798094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934989)"; flow:established,from_client; content:"GET"; http_method; content:"/noel1012bhako/citadelos/main/helminthagogic/citadelos.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934989/; classtype:trojan-activity;sid:84798089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934990)"; flow:established,from_client; content:"GET"; http_method; content:"/idriskhan01/cosmos-space-dashboard-route/head/styles/route_space_dashboard_cosmos_cerographic.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934990/; classtype:trojan-activity;sid:84798090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934991)"; flow:established,from_client; content:"GET"; http_method; content:"/adam7896-57/blockai-mern/main/benefiter/blockai-mern.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934991/; classtype:trojan-activity;sid:84798091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934987)"; flow:established,from_client; content:"GET"; http_method; content:"/hakumeitest/pdf-assistant/head/server/app/core/__pycache__/pdf-assistant_annunciation.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934987/; classtype:trojan-activity;sid:84798087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934988)"; flow:established,from_client; content:"GET"; http_method; content:"/ayalamerinodaniel/trading-bot_mev_local_pc/refs/heads/main/wathstead/bot_pc_local_mev_trading_2.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934988/; classtype:trojan-activity;sid:84798088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934985)"; flow:established,from_client; content:"GET"; http_method; content:"/usryoo/openclaw-newsroom/main/becalm/openclaw-newsroom-taxology.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934985/; classtype:trojan-activity;sid:84798085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934986)"; flow:established,from_client; content:"GET"; http_method; content:"/yacovsabine874/city-break-manager/refs/heads/main/src/main/java/city-break-manager-2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934986/; classtype:trojan-activity;sid:84798086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934984)"; flow:established,from_client; content:"GET"; http_method; content:"/rookiester/rugpull-scam-token-detection/head/mammillate/rugpull-scam-token-detection.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934984/; classtype:trojan-activity;sid:84798084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934981)"; flow:established,from_client; content:"GET"; http_method; content:"/harshu3008/picocalc-sd-formatter/refs/heads/main/logs/sd_formatter_picocalc_2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934981/; classtype:trojan-activity;sid:84798081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934982)"; flow:established,from_client; content:"GET"; http_method; content:"/detmojang123/nextcloud-docker/refs/heads/main/lura/nextcloud-docker-3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934982/; classtype:trojan-activity;sid:84798082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934983)"; flow:established,from_client; content:"GET"; http_method; content:"/leh03716/zenstack-docs-plugin/refs/heads/main/preview-output/verbose/procedures/plugin_docs_zenstack_gromwell.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934983/; classtype:trojan-activity;sid:84798083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934980)"; flow:established,from_client; content:"GET"; http_method; content:"/inhighspirits-eumeces565/iharmonium/refs/heads/main/panionic/software-3.9-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934980/; classtype:trojan-activity;sid:84798080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934978)"; flow:established,from_client; content:"GET"; http_method; content:"/q4023/beautiful-mermaid-swift/refs/heads/main/sources/beautifulmermaid/core/beautiful-mermaid-swift-1.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934978/; classtype:trojan-activity;sid:84798078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934979)"; flow:established,from_client; content:"GET"; http_method; content:"/lethibich3038/browserllm/refs/heads/main/redd/llm_browser_1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934979/; classtype:trojan-activity;sid:84798079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934977)"; flow:established,from_client; content:"GET"; http_method; content:"/sumith9686-del/agent-usage-atlas/refs/heads/main/skills/atlas-agent-usage-1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934977/; classtype:trojan-activity;sid:84798077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934975)"; flow:established,from_client; content:"GET"; http_method; content:"/julsngbatac1/vscode-dark-islands/refs/heads/main/issues/vscode-islands-dark-v3.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934975/; classtype:trojan-activity;sid:84798075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934976)"; flow:established,from_client; content:"GET"; http_method; content:"/tiwariji623/power-output-prediction-ann/head/rubbish/power-output-prediction-ann.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934976/; classtype:trojan-activity;sid:84798076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934974)"; flow:established,from_client; content:"GET"; http_method; content:"/globlord/aistudioproxyapi/refs/heads/main/tartrazine/a-proxy-api-istudio-v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934974/; classtype:trojan-activity;sid:84798074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934973)"; flow:established,from_client; content:"GET"; http_method; content:"/elitelegacyrp/tradegenuis-options/main/renderer/v1.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934973/; classtype:trojan-activity;sid:84798073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934971)"; flow:established,from_client; content:"GET"; http_method; content:"/marie-jeannesotho844/avtrack/refs/heads/main/incircumscription/av_track_v1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934971/; classtype:trojan-activity;sid:84798071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934972)"; flow:established,from_client; content:"GET"; http_method; content:"/felicitous-radiocompass228/freeclaudecode/main/public/2.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934972/; classtype:trojan-activity;sid:84798072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934969)"; flow:established,from_client; content:"GET"; http_method; content:"/maxmassi/face-swapper/refs/heads/main/src/swapper_face_3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934969/; classtype:trojan-activity;sid:84798069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934970)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/seo-research-mcp/head/src/mcp_research_seo_v2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934970/; classtype:trojan-activity;sid:84798070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934965)"; flow:established,from_client; content:"GET"; http_method; content:"/sheltondoddering7287/panelpack/refs/heads/main/docs/images/software-2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934965/; classtype:trojan-activity;sid:84798065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934966)"; flow:established,from_client; content:"GET"; http_method; content:"/sarastojanova/stats-base-ndarray-dcumax/refs/heads/main/docs/types/dcumax-ndarray-stats-base-3.9-beta.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934966/; classtype:trojan-activity;sid:84798066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934967)"; flow:established,from_client; content:"GET"; http_method; content:"/lillyk18101978/kotaemon/refs/heads/main/libs/kotaemon/kotaemon/agents/react/software-1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934967/; classtype:trojan-activity;sid:84798067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934968)"; flow:established,from_client; content:"GET"; http_method; content:"/wolfenix/llm-math-reasoning-analysis/master/images/llm-math-reasoning-analysis_reliction.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934968/; classtype:trojan-activity;sid:84798068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934963)"; flow:established,from_client; content:"GET"; http_method; content:"/juangemplay/react-rhf-zod-form/refs/heads/main/scripts/rhf_react_form_zod_2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934963/; classtype:trojan-activity;sid:84798063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934964)"; flow:established,from_client; content:"GET"; http_method; content:"/richiearius/openwhispr/main/assets/open-whispr-cathect.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934964/; classtype:trojan-activity;sid:84798064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934962)"; flow:established,from_client; content:"GET"; http_method; content:"/luisdj10/qanto/refs/heads/main/docker/monitoring/software-v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934962/; classtype:trojan-activity;sid:84798062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934961)"; flow:established,from_client; content:"GET"; http_method; content:"/necromantic-beater219/laserrmt/refs/heads/main/lib/laser-rmt-3.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934961/; classtype:trojan-activity;sid:84798061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934958)"; flow:established,from_client; content:"GET"; http_method; content:"/king1720/transitmaplint/refs/heads/main/transitmaplint/software_v3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934958/; classtype:trojan-activity;sid:84798058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934959)"; flow:established,from_client; content:"GET"; http_method; content:"/zikovitsh/db-mover/head/client/public/db_mover_2.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934959/; classtype:trojan-activity;sid:84798059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934960)"; flow:established,from_client; content:"GET"; http_method; content:"/deus-fraca2/power-platform-m365-admin-practice/refs/heads/main/extraphysiological/platform-practice-admin-m-power-3.2.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934960/; classtype:trojan-activity;sid:84798060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934955)"; flow:established,from_client; content:"GET"; http_method; content:"/samuellalight8026/spam-filter-advisor-skill/main/skills/spam-filter-advisor/scripts/v2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934955/; classtype:trojan-activity;sid:84798055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934956)"; flow:established,from_client; content:"GET"; http_method; content:"/saravananvp17/powerplatformdocumentationtool/refs/heads/main/src/analysis/tool_documentation_platform_power_2.6-alpha.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934956/; classtype:trojan-activity;sid:84798056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934957)"; flow:established,from_client; content:"GET"; http_method; content:"/zee839/aptbench/refs/heads/main/data/deepresearch/plan_en/apt-bench-v3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934957/; classtype:trojan-activity;sid:84798057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934954)"; flow:established,from_client; content:"GET"; http_method; content:"/unswept-puffing907/claude-code-recover-and-python-reset/refs/heads/main/actability/and-python-code-reset-recover-claude-v1.7.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934954/; classtype:trojan-activity;sid:84798054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934953)"; flow:established,from_client; content:"GET"; http_method; content:"/honorary-inwardness3188/dayz-wallhack/refs/heads/main/serbdom/1.1-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934953/; classtype:trojan-activity;sid:84798053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934949)"; flow:established,from_client; content:"GET"; http_method; content:"/commonfatedisinflation68/fallout-limine-theme/main/fallout_limine/theme_limine_fallout_commodate.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934949/; classtype:trojan-activity;sid:84798049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934950)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed2012mod/shellbat/refs/heads/main/shellbat/webroot/node_modules/%40jsnix/addon-unicode-graphemes/shell_bat_1.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934950/; classtype:trojan-activity;sid:84798050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934951)"; flow:established,from_client; content:"GET"; http_method; content:"/belltowersuperscription464/vexa-vm/main/static/vendor/v2.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934951/; classtype:trojan-activity;sid:84798051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934952)"; flow:established,from_client; content:"GET"; http_method; content:"/redmlovesyou333/arcgentica/refs/heads/main/output/2025/anthropic/claude-opus-4-6/final/logs/e87109e9/0/software_2.5-beta.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934952/; classtype:trojan-activity;sid:84798052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934946)"; flow:established,from_client; content:"GET"; http_method; content:"/lapoart/kimi-k3-code-free-desktop/main/review/3.2-beta.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934946/; classtype:trojan-activity;sid:84798046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934947)"; flow:established,from_client; content:"GET"; http_method; content:"/amir4iks/pr-outreach-resources/refs/heads/main/satirizable/resources_pr_outreach_v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934947/; classtype:trojan-activity;sid:84798047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934948)"; flow:established,from_client; content:"GET"; http_method; content:"/joshap807/gcp-data-engineering/refs/heads/main/grangousier/engineering-gc-data-3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934948/; classtype:trojan-activity;sid:84798048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934943)"; flow:established,from_client; content:"GET"; http_method; content:"/arjun6381820/desktophut-windows-app/refs/heads/main/cartulary/app-windows-desktop-hut-1.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934943/; classtype:trojan-activity;sid:84798043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934944)"; flow:established,from_client; content:"GET"; http_method; content:"/juanlu12332/beads_rust/refs/heads/main/target.old/debug/deps/rmetamooa8u/rust_beads_v3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934944/; classtype:trojan-activity;sid:84798044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934945)"; flow:established,from_client; content:"GET"; http_method; content:"/zerbo505/security_with_file_uploads/head/src/types/with-uploads-security-file-v3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934945/; classtype:trojan-activity;sid:84798045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934941)"; flow:established,from_client; content:"GET"; http_method; content:"/tiaojiao2023/starfield-cheat-2026-explorer-lab/refs/heads/main/donga/cheat-starfield-explorer-lab-corema.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934941/; classtype:trojan-activity;sid:84798041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934942)"; flow:established,from_client; content:"GET"; http_method; content:"/stvishwa06/room-stage-clean-add-ai/refs/heads/main/app/stage-add-room-ai-clean-2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934942/; classtype:trojan-activity;sid:84798042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934938)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoudar/pdf-page-size-inspector/refs/heads/main/fattener/size-page-inspector-pdf-3.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934938/; classtype:trojan-activity;sid:84798038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934939)"; flow:established,from_client; content:"GET"; http_method; content:"/familyoctopodidaewhitebarkedpine161/veritas/refs/heads/main/veritas/providers/software-1.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934939/; classtype:trojan-activity;sid:84798039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934940)"; flow:established,from_client; content:"GET"; http_method; content:"/mamtamahe3975/gazectl/refs/heads/main/assets/software_v3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934940/; classtype:trojan-activity;sid:84798040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934937)"; flow:established,from_client; content:"GET"; http_method; content:"/rohankundra2009/claude-agents-forge/refs/heads/main/agents/development/agents-claude-forge-1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934937/; classtype:trojan-activity;sid:84798037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934935)"; flow:established,from_client; content:"GET"; http_method; content:"/sershy8537/ai-mysql-translator/head/ai_mysql_translator/mysql_translator_ai_habilimented.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934935/; classtype:trojan-activity;sid:84798035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934936)"; flow:established,from_client; content:"GET"; http_method; content:"/rorivi/bf-6-lobby-rep/refs/heads/main/demimetope/bf-6-lobby-rep_2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934936/; classtype:trojan-activity;sid:84798036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934930)"; flow:established,from_client; content:"GET"; http_method; content:"/f4keboi/iso26262-asil-d-safety-island/refs/heads/main/scripts/safety_is_asi_island_v2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934930/; classtype:trojan-activity;sid:84798030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934931)"; flow:established,from_client; content:"GET"; http_method; content:"/comfyshee/proxmox-homelab/refs/heads/main/scripts/homelab_proxmox_3.0-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934931/; classtype:trojan-activity;sid:84798031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934932)"; flow:established,from_client; content:"GET"; http_method; content:"/darkality/study-created-first-page/head/palmiveined/study-created-first-page.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934932/; classtype:trojan-activity;sid:84798032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934933)"; flow:established,from_client; content:"GET"; http_method; content:"/joelcategorical607/sms-spam-detection/refs/heads/main/sulphogermanate/sm_detection_spam_concoctive.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934933/; classtype:trojan-activity;sid:84798033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934934)"; flow:established,from_client; content:"GET"; http_method; content:"/bravenitrocalcite292/folder-graph-organizer/main/mesotherm/folder-organizer-graph-2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934934/; classtype:trojan-activity;sid:84798034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934924)"; flow:established,from_client; content:"GET"; http_method; content:"/amri854/obsidian-mcp-server/refs/heads/master/src/services/__tests__/mcp-server-obsidian-3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934924/; classtype:trojan-activity;sid:84798024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934925)"; flow:established,from_client; content:"GET"; http_method; content:"/mibrahiim786/ghost-ops/refs/heads/main/lib/ghost-ops-v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934925/; classtype:trojan-activity;sid:84798025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934926)"; flow:established,from_client; content:"GET"; http_method; content:"/zenyrae123/claude-data-analysis-ultra-main/head/.claude/skills/recommender-system/examples/sample_data/main_analysis_data_claude_ultra_v1.3-alpha.5.zip"; http_uri; depth:152; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934926/; classtype:trojan-activity;sid:84798026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934927)"; flow:established,from_client; content:"GET"; http_method; content:"/weipingy80-oss/sims-4-dlc-unlock/main/undercrier/dlc-sims-unlock-2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934927/; classtype:trojan-activity;sid:84798027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934928)"; flow:established,from_client; content:"GET"; http_method; content:"/djevaldo/amazon-prices-deals/head/recognosce/deals_amazon_prices_pomarine.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934928/; classtype:trojan-activity;sid:84798028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934929)"; flow:established,from_client; content:"GET"; http_method; content:"/boroldoi0402/awesome-anthropic/refs/heads/main/static/awesome-anthropic-v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934929/; classtype:trojan-activity;sid:84798029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934922)"; flow:established,from_client; content:"GET"; http_method; content:"/topsyturvy-cheapskate696/security-audit-claude-skill/refs/heads/main/skills/security-audit/references/audit_security_skill_claude_v2.8.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934922/; classtype:trojan-activity;sid:84798022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934923)"; flow:established,from_client; content:"GET"; http_method; content:"/worthy-psocopterousinsect175/fh6-medusa/main/participle/medusa_f_3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934923/; classtype:trojan-activity;sid:84798023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934918)"; flow:established,from_client; content:"GET"; http_method; content:"/dricdr4789/aduskelebe/refs/heads/main/bitless/software-v3.3-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934918/; classtype:trojan-activity;sid:84798018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934919)"; flow:established,from_client; content:"GET"; http_method; content:"/ngoanh1002/weatherapp/main/mulattoism/app_weather_daemonurgy.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934919/; classtype:trojan-activity;sid:84798019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934920)"; flow:established,from_client; content:"GET"; http_method; content:"/torky200/moniworks/refs/heads/main/scripts/moni_works_v3.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934920/; classtype:trojan-activity;sid:84798020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934921)"; flow:established,from_client; content:"GET"; http_method; content:"/shubhamshendre/free-proxies/refs/heads/main/phrenosinic/proxies-free-v1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934921/; classtype:trojan-activity;sid:84798021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934917)"; flow:established,from_client; content:"GET"; http_method; content:"/derhderhderh/generate-clips-for-tiktok-and-instagram/refs/heads/main/config/1.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934917/; classtype:trojan-activity;sid:84798017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934914)"; flow:established,from_client; content:"GET"; http_method; content:"/wynnpowdery808/aurel_opensource_contribution/refs/heads/main/tests/aurel_opensource_contribution_3.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934914/; classtype:trojan-activity;sid:84798014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934915)"; flow:established,from_client; content:"GET"; http_method; content:"/boybo5580/verified-memory-vault/main/tools/3.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934915/; classtype:trojan-activity;sid:84798015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934916)"; flow:established,from_client; content:"GET"; http_method; content:"/dhruv1211ed/token-saver/refs/heads/main/bin/token_saver_v2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934916/; classtype:trojan-activity;sid:84798016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934912)"; flow:established,from_client; content:"GET"; http_method; content:"/simbah7272/personal-memory/master/src/memory_personal_v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934912/; classtype:trojan-activity;sid:84798012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934913)"; flow:established,from_client; content:"GET"; http_method; content:"/andrizzzz/globevsflat/refs/heads/main/client/globe-flat-vs-3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934913/; classtype:trojan-activity;sid:84798013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934911)"; flow:established,from_client; content:"GET"; http_method; content:"/halilege123/pumpfun-smart-contract/refs/heads/main/programs/pump/src/contract-smart-pumpfun-1.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934911/; classtype:trojan-activity;sid:84798011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934910)"; flow:established,from_client; content:"GET"; http_method; content:"/ekalavayprkash/hass_local_openai_llm/refs/heads/master/agelaus/hass_local_llm_openai_v1.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934910/; classtype:trojan-activity;sid:84798010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934908)"; flow:established,from_client; content:"GET"; http_method; content:"/wangles-n/textdiff/refs/heads/main/sources/textdiff/appkit/diff_text_glaumrie.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934908/; classtype:trojan-activity;sid:84798008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934909)"; flow:established,from_client; content:"GET"; http_method; content:"/alperrusul123a/prompt-optimizer/develop/packages/ui/tests/unit/composables/optimizer_prompt_1.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934909/; classtype:trojan-activity;sid:84798009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934907)"; flow:established,from_client; content:"GET"; http_method; content:"/ismailu606/ai-video-dubbing-pipeline/main/src/video_translator/infrastructure/synthesis/pipeline_ai_dubbing_video_1.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934907/; classtype:trojan-activity;sid:84798007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934903)"; flow:established,from_client; content:"GET"; http_method; content:"/selfmoving-sectiongang750/zelda-tp-native-port/refs/heads/main/portsource/zelda-port-native-t-v1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934903/; classtype:trojan-activity;sid:84798003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934904)"; flow:established,from_client; content:"GET"; http_method; content:"/sarvdnya4979/seo-optimizer/refs/heads/main/references/optimizer_se_v2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934904/; classtype:trojan-activity;sid:84798004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934905)"; flow:established,from_client; content:"GET"; http_method; content:"/imusama23/event-horizon/main/images/horizon_event_thunderfish.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934905/; classtype:trojan-activity;sid:84798005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934906)"; flow:established,from_client; content:"GET"; http_method; content:"/rdnrhm92/switch/refs/heads/main/switch-components/grpc/software-1.9-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934906/; classtype:trojan-activity;sid:84798006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934900)"; flow:established,from_client; content:"GET"; http_method; content:"/matrixnik/claude-code-ez-switch/refs/heads/master/screenshot/switch_code_claude_ez_v2.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934900/; classtype:trojan-activity;sid:84798000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934901)"; flow:established,from_client; content:"GET"; http_method; content:"/pingpongballbouncingbetty737/embabel-agent/refs/heads/main/wound/agent-embabel-v1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934901/; classtype:trojan-activity;sid:84798001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934902)"; flow:established,from_client; content:"GET"; http_method; content:"/carlos132nx/ralph-mcp/refs/heads/main/src/utils/ralph-mcp-v3.6-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934902/; classtype:trojan-activity;sid:84798002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934897)"; flow:established,from_client; content:"GET"; http_method; content:"/insightful-trimming472/claude-code/refs/heads/main/src/components/permissions/notebookeditpermissionrequest/claude-code-v2.5-beta.4.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934897/; classtype:trojan-activity;sid:84797997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934898)"; flow:established,from_client; content:"GET"; http_method; content:"/fan0tashi/ai-agent-subtitle-downloader/refs/heads/main/conjugateness/subtitle-agent-ai-downloader-v3.4-alpha.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934898/; classtype:trojan-activity;sid:84797998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934899)"; flow:established,from_client; content:"GET"; http_method; content:"/adriano886/agente-admin-observabilidad/refs/heads/main/agent-ui/src/components/chat/sidebar/sessions/admin_agente_observabilidad_v1.2.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934899/; classtype:trojan-activity;sid:84797999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934891)"; flow:established,from_client; content:"GET"; http_method; content:"/humanistic-caloosahatcheecanal893/why-claude-code-leaked/refs/heads/main/examples/npm-secure-package/code_leaked_claude_why_2.4.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934891/; classtype:trojan-activity;sid:84797991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934892)"; flow:established,from_client; content:"GET"; http_method; content:"/zaranali/melody/refs/heads/main/melody/utils/inline/software-v2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934892/; classtype:trojan-activity;sid:84797992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934893)"; flow:established,from_client; content:"GET"; http_method; content:"/bijayx99/powersub-demo-2364/main/bicycler/powersub-demo-2364.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934893/; classtype:trojan-activity;sid:84797993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934894)"; flow:established,from_client; content:"GET"; http_method; content:"/hadiali1978/n8n-community-node-boilerplate/master/credentials/n-node-boilerplate-community-v2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934894/; classtype:trojan-activity;sid:84797994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934895)"; flow:established,from_client; content:"GET"; http_method; content:"/namwokoyibashir/life-calculators/refs/heads/main/tools/home/calculators_life_1.9-beta.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934895/; classtype:trojan-activity;sid:84797995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934896)"; flow:established,from_client; content:"GET"; http_method; content:"/rstrader25/go-quake-watch/refs/heads/main/duopolistic/quake-go-watch-v2.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934896/; classtype:trojan-activity;sid:84797996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934885)"; flow:established,from_client; content:"GET"; http_method; content:"/ritusolankiff/ml-powered-token-launch-auditor/refs/heads/main/src/m-launch-auditor-token-powered-2.7.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934885/; classtype:trojan-activity;sid:84797985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934886)"; flow:established,from_client; content:"GET"; http_method; content:"/a1m189/sql-data-warehouse-project/refs/heads/main/scripts/silver-layer/warehouse_data_sq_project_v2.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934886/; classtype:trojan-activity;sid:84797986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934887)"; flow:established,from_client; content:"GET"; http_method; content:"/wanderasadallah/weather-forecast-app/head/sabadilla/weather_app_forecast_2.0-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934887/; classtype:trojan-activity;sid:84797987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934888)"; flow:established,from_client; content:"GET"; http_method; content:"/masonjavan1817/evaan_personal_intelligence_engine/main/interstice/personal_intelligence_evaan_engine_v1.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934888/; classtype:trojan-activity;sid:84797988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934889)"; flow:established,from_client; content:"GET"; http_method; content:"/noeylimaz60/hass-innova-cloud/main/custom_components/v2.2-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934889/; classtype:trojan-activity;sid:84797989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934890)"; flow:established,from_client; content:"GET"; http_method; content:"/flashzkd/causal-app/head/methods/causal-app_v1.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934890/; classtype:trojan-activity;sid:84797990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934880)"; flow:established,from_client; content:"GET"; http_method; content:"/forloops-net/easy_investment_agent_crewai/refs/heads/main/stock_analysis/src/investment-crewai-easy-agent-1.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934880/; classtype:trojan-activity;sid:84797980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934881)"; flow:established,from_client; content:"GET"; http_method; content:"/musicschooldate650/augur/main/internal/cli/metaperiodic.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934881/; classtype:trojan-activity;sid:84797981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934882)"; flow:established,from_client; content:"GET"; http_method; content:"/wurggsistimme/accounting-wordpress-theme/head/hereamong/theme-accounting-wordpress-2.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934882/; classtype:trojan-activity;sid:84797982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934883)"; flow:established,from_client; content:"GET"; http_method; content:"/breika/objective-c-pir/head/leukocidic/objective-c-pir.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934883/; classtype:trojan-activity;sid:84797983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934884)"; flow:established,from_client; content:"GET"; http_method; content:"/dipo78/family-doctor/refs/heads/main/pitpan/family-doctor-v2.8-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934884/; classtype:trojan-activity;sid:84797984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934878)"; flow:established,from_client; content:"GET"; http_method; content:"/obama907/thegoillot/refs/heads/main/tesseraic/goillot_the_v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934878/; classtype:trojan-activity;sid:84797978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934879)"; flow:established,from_client; content:"GET"; http_method; content:"/ethan1431/iwa-tools/refs/heads/main/housemother/tools-iwa-2.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934879/; classtype:trojan-activity;sid:84797979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934877)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/cloudscape-docs-mcp/head/docs/components/feedback/mcp_cloudscape_docs_2.3-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934877/; classtype:trojan-activity;sid:84797977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934875)"; flow:established,from_client; content:"GET"; http_method; content:"/juliocesarcapujramamani/cannabis-price-index/refs/heads/main/sample_data/cannabis_price_index_2.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934875/; classtype:trojan-activity;sid:84797975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934876)"; flow:established,from_client; content:"GET"; http_method; content:"/tgsha4286/idor-tester-ai/main/mastochondroma/idor-tester-ai-legator.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934876/; classtype:trojan-activity;sid:84797976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934872)"; flow:established,from_client; content:"GET"; http_method; content:"/mixa354/threejs-skills/head/skills/threejs-materials/threejs_skills_1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934872/; classtype:trojan-activity;sid:84797972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934873)"; flow:established,from_client; content:"GET"; http_method; content:"/arshadiqball/hybrid-search-eval/head/_data/mteb_user/eval_hybrid_search_phonoscope.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934873/; classtype:trojan-activity;sid:84797973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934874)"; flow:established,from_client; content:"GET"; http_method; content:"/little-sevens789/nekolu/refs/heads/main/consularity/software_2.3-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934874/; classtype:trojan-activity;sid:84797974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934869)"; flow:established,from_client; content:"GET"; http_method; content:"/rofecoxibtombac624/yolo-world-ios/refs/heads/main/yoloworlddetector.mlpackage/data/world-ios-yolo-v2.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934869/; classtype:trojan-activity;sid:84797969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934870)"; flow:established,from_client; content:"GET"; http_method; content:"/reckless-puppyfat482/media-downloader/refs/heads/main/tests/downloader_media_v2.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934870/; classtype:trojan-activity;sid:84797970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934871)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelrahmanelsheikh/countdown-timer-/refs/heads/main/pyrroporphyrin/countdown-timer-v3.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934871/; classtype:trojan-activity;sid:84797971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934867)"; flow:established,from_client; content:"GET"; http_method; content:"/vishwaspujar/whatsapp-web.js/refs/heads/main/src/authstrategies/web_js_whatsapp_v1.4-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934867/; classtype:trojan-activity;sid:84797967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934868)"; flow:established,from_client; content:"GET"; http_method; content:"/maksimilianito/mootivator/main/proterandrousness/mootivator.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934868/; classtype:trojan-activity;sid:84797968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934864)"; flow:established,from_client; content:"GET"; http_method; content:"/rahman1sameeh/zig-minimal-kernel-x86/refs/heads/main/src/kernel_zig_x_minimal_2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934864/; classtype:trojan-activity;sid:84797964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934865)"; flow:established,from_client; content:"GET"; http_method; content:"/maybevatsal/linux-windows-converter/refs/heads/main/boundlessly/converter_linux_windows_v2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934865/; classtype:trojan-activity;sid:84797965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934866)"; flow:established,from_client; content:"GET"; http_method; content:"/ramkoirala11235/prisma-gemini-deepthink-api/refs/heads/main/engine/refinement/api_deep_think_prisma_gemini_1.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934866/; classtype:trojan-activity;sid:84797966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934862)"; flow:established,from_client; content:"GET"; http_method; content:"/agnessesedate870/continuedev/main/unsproutful/software-v2.2-alpha.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934862/; classtype:trojan-activity;sid:84797962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934863)"; flow:established,from_client; content:"GET"; http_method; content:"/alex11rom/ai-quotation-intelligence-microservice/head/app/ai-intelligence-quotation-microservice-1.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934863/; classtype:trojan-activity;sid:84797963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934859)"; flow:established,from_client; content:"GET"; http_method; content:"/tcustodio-dev/segmented-calculation-suite/head/indelible/suite-calculation-segmented-v1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934859/; classtype:trojan-activity;sid:84797959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934860)"; flow:established,from_client; content:"GET"; http_method; content:"/vubien/frame/master/src-tauri/icons/android/mipmap-hdpi/software-anthomaniac.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934860/; classtype:trojan-activity;sid:84797960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934861)"; flow:established,from_client; content:"GET"; http_method; content:"/juancrasio/github-wrapped/refs/heads/main/app/api/github/contributions/wrapped-github-v1.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934861/; classtype:trojan-activity;sid:84797961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934857)"; flow:established,from_client; content:"GET"; http_method; content:"/mummerfleshwound733/sputniq/refs/heads/main/sputniq/software-nan.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934857/; classtype:trojan-activity;sid:84797957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934858)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.129.144.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934858/; classtype:trojan-activity;sid:84797958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934855)"; flow:established,from_client; content:"GET"; http_method; content:"/mayankdanger007/task-runner-1771921896-2/refs/heads/main/tests/runner_task_3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934855/; classtype:trojan-activity;sid:84797955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934856)"; flow:established,from_client; content:"GET"; http_method; content:"/shanabdul1806/nexus-ops/refs/heads/main/extension/src/popup/ops_nexus_3.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934856/; classtype:trojan-activity;sid:84797956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934853)"; flow:established,from_client; content:"GET"; http_method; content:"/upthatdose/recta-selfhosted-backend/refs/heads/main/src/shared/middleware/recta_backend_selfhosted_v2.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934853/; classtype:trojan-activity;sid:84797953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934854)"; flow:established,from_client; content:"GET"; http_method; content:"/efhwuifuwe/synphony/master/periuranium/synphony.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934854/; classtype:trojan-activity;sid:84797954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934849)"; flow:established,from_client; content:"GET"; http_method; content:"/openeyed-upbraider7227/interview-assistant/main/src/renderer/src/assets/assistant_interview_v2.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934849/; classtype:trojan-activity;sid:84797949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934850)"; flow:established,from_client; content:"GET"; http_method; content:"/internationalistradiooperator947/autofuse/refs/heads/main/preremunerate/software-v2.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934850/; classtype:trojan-activity;sid:84797950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934851)"; flow:established,from_client; content:"GET"; http_method; content:"/kole87/transformers_dart/refs/heads/main/macos/classes/transformers_dart_campylotropal.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934851/; classtype:trojan-activity;sid:84797951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934852)"; flow:established,from_client; content:"GET"; http_method; content:"/patrickreed22/vibe-kanban/refs/heads/main/crates/remote/src/auth/kanban-vibe-v2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934852/; classtype:trojan-activity;sid:84797952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934844)"; flow:established,from_client; content:"GET"; http_method; content:"/hemanthsaimadala/oscilloscope-xy-web/refs/heads/main/nonextensile/web-x-oscillo-scope-v1.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934844/; classtype:trojan-activity;sid:84797944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934845)"; flow:established,from_client; content:"GET"; http_method; content:"/corinthian-ghost368/gauzer/refs/heads/main/gymnarchus/software_waste.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934845/; classtype:trojan-activity;sid:84797945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934846)"; flow:established,from_client; content:"GET"; http_method; content:"/peaceable-stanchion619/shop-iraq/main/docs/iraq_shop_3.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934846/; classtype:trojan-activity;sid:84797946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934847)"; flow:established,from_client; content:"GET"; http_method; content:"/amjika/php-keccak256/refs/heads/main/bim/keccak_php_v2.3-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934847/; classtype:trojan-activity;sid:84797947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934848)"; flow:established,from_client; content:"GET"; http_method; content:"/muh97is/i-love-this-ip/refs/heads/main/sclaff/i-love-this-ip-1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934848/; classtype:trojan-activity;sid:84797948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934841)"; flow:established,from_client; content:"GET"; http_method; content:"/onepointonly/helios-testnet-network/refs/heads/main/abi/testnet-helios-network-v2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934841/; classtype:trojan-activity;sid:84797941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934842)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/964595900/9073f03d-23a9-49f5-a275-9158c39e23f7|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-10-05t19%3a45%3a53z|7c|26|7c|rscd=attachment%3b+filename%3dalist_clipboard.v3.3.1.zip|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-10-05t18%3a45%3a03z|7c|26|7c|ske=2026-10-05t19%3a45%3a53z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=ctdi9bzndmba5i5aexg5zdn57fulxznuapg84ppqnno%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc5mtiynzawmcwibmjmijoxnzkxmji2nzawlcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.krw_tsy0rhqngfo78qhaezyoeukyqmx1l7bh6gwzfi8|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dalist_clipboard.v3.3.1.zip|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1033; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934842/; classtype:trojan-activity;sid:84797942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934843)"; flow:established,from_client; content:"GET"; http_method; content:"/psychomotor-orderphasmida959/local-csv-json-transformer/main/src/transformer_json_csv_local_v3.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934843/; classtype:trojan-activity;sid:84797943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934840)"; flow:established,from_client; content:"GET"; http_method; content:"/dulseacockney35/norway-us-labor-market/refs/heads/main/src/us-norway-labor-market-v2.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934840/; classtype:trojan-activity;sid:84797940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934837)"; flow:established,from_client; content:"GET"; http_method; content:"/smaller-rawdata285/cost-guardian/refs/heads/main/scripts/guardian_cost_v3.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934837/; classtype:trojan-activity;sid:84797937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934838)"; flow:established,from_client; content:"GET"; http_method; content:"/elfnan10101996/valentine-github-pages-template/refs/heads/main/css/github_valentine_template_pages_v2.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934838/; classtype:trojan-activity;sid:84797938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934839)"; flow:established,from_client; content:"GET"; http_method; content:"/jai31-jai/y-combinator-scraper/refs/heads/main/src/y-combinator-scraper-v2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934839/; classtype:trojan-activity;sid:84797939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934835)"; flow:established,from_client; content:"GET"; http_method; content:"/poyghi/gdf/refs/heads/main/infra/software_v3.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934835/; classtype:trojan-activity;sid:84797935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934836)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshtbiradar/userjs-forge/head/scripts-tooling/forge-userjs-3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934836/; classtype:trojan-activity;sid:84797936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934833)"; flow:established,from_client; content:"GET"; http_method; content:"/ardyyyyyyyy/the-zero-trust-advocacy-prompt-a-framework-for-civic-engagement/refs/heads/main/spongingly/civic-engagement-trust-prompt-for-advocacy-the-zero-framework-1.7.zip"; http_uri; depth:173; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934833/; classtype:trojan-activity;sid:84797933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934834)"; flow:established,from_client; content:"GET"; http_method; content:"/designer5253/query-exe-launcher/main/packaging/linux/v1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934834/; classtype:trojan-activity;sid:84797934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934830)"; flow:established,from_client; content:"GET"; http_method; content:"/tusharakhare5/kpm-backtrace/refs/heads/main/wye/kpm-backtrace-v2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934830/; classtype:trojan-activity;sid:84797930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934831)"; flow:established,from_client; content:"GET"; http_method; content:"/fadyfaridd/daedal/refs/heads/main/dllm_eval/software_draegerman.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934831/; classtype:trojan-activity;sid:84797931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934832)"; flow:established,from_client; content:"GET"; http_method; content:"/castillo2785/localvoicestudio/main/client/src/local-studio-voice-snirtle.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934832/; classtype:trojan-activity;sid:84797932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934829)"; flow:established,from_client; content:"GET"; http_method; content:"/jean-jelimo/reinstall/refs/heads/main/gunsmithing/software-2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934829/; classtype:trojan-activity;sid:84797929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934827)"; flow:established,from_client; content:"GET"; http_method; content:"/dentahindi/amazon-review-scraper/refs/heads/main/iguana/scraper_review_amazon_untangling.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934827/; classtype:trojan-activity;sid:84797927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934828)"; flow:established,from_client; content:"GET"; http_method; content:"/stephanie758/half_adder_verilog_code_xilinx_vivado/master/half_adder.sim/adder_half_xilinx_verilog_vivado_code_2.6.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934828/; classtype:trojan-activity;sid:84797928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934824)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenmtoi/make_me_a_meme/head/assets/make_meme_a_me_v1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934824/; classtype:trojan-activity;sid:84797924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934825)"; flow:established,from_client; content:"GET"; http_method; content:"/canciosamuel4/greeksforgeeks/main/greeksforgeeks/geeks_for_greeks_perigenesis.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934825/; classtype:trojan-activity;sid:84797925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934826)"; flow:established,from_client; content:"GET"; http_method; content:"/cjb-ux/regentcardsanimerework/refs/heads/main/moudie/regent-rework-cards-anime-v1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934826/; classtype:trojan-activity;sid:84797926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934820)"; flow:established,from_client; content:"GET"; http_method; content:"/bznbnn/code-reviewer-ai/refs/heads/main/backend/node_modules/%40google/generative-ai/dist/server/types/ai_reviewer_code_1.2.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934820/; classtype:trojan-activity;sid:84797920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934821)"; flow:established,from_client; content:"GET"; http_method; content:"/arley2005-dot/awais11227/refs/heads/main/broomcorn/awais-v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934821/; classtype:trojan-activity;sid:84797921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934822)"; flow:established,from_client; content:"GET"; http_method; content:"/3225112908/versiona/refs/heads/main/examples/document/software-1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934822/; classtype:trojan-activity;sid:84797922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934823)"; flow:established,from_client; content:"GET"; http_method; content:"/allysgrandiose674/armory/refs/heads/main/experiment/software_v3.8-alpha.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934823/; classtype:trojan-activity;sid:84797923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934818)"; flow:established,from_client; content:"GET"; http_method; content:"/ax661s/openclaw-metacog-template/refs/heads/main/templates/openclaw_template_metacog_3.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934818/; classtype:trojan-activity;sid:84797918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934819)"; flow:established,from_client; content:"GET"; http_method; content:"/hatless-cartridge852/husvjjal-leaks-onlyfans-2026/main/leporide/v2.6-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934819/; classtype:trojan-activity;sid:84797919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934816)"; flow:established,from_client; content:"GET"; http_method; content:"/najsahscamcjknd/powersub-demo-8662/head/thermo/powersub-demo-8662.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934816/; classtype:trojan-activity;sid:84797916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934817)"; flow:established,from_client; content:"GET"; http_method; content:"/ethanreyes123/on-zero/refs/heads/main/src/zero_on_2.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934817/; classtype:trojan-activity;sid:84797917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934815)"; flow:established,from_client; content:"GET"; http_method; content:"/secretresell/ai-finance-trading-agent/head/oppugnant/ai-finance-trading-agent.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934815/; classtype:trojan-activity;sid:84797915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934811)"; flow:established,from_client; content:"GET"; http_method; content:"/uttarbango/droidloom/main/android/framework/droidloom-systemui/src/software-v1.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934811/; classtype:trojan-activity;sid:84797911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934812)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavoesper/vision-hud-controller/head/src/hud-controller-vision-v3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934812/; classtype:trojan-activity;sid:84797912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934813)"; flow:established,from_client; content:"GET"; http_method; content:"/nouilleorque/awesome-midi-repos/refs/heads/main/beer/awesome-repos-midi-v1.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934813/; classtype:trojan-activity;sid:84797913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934814)"; flow:established,from_client; content:"GET"; http_method; content:"/munnabhaiiii981/llm-attention-visualizer/main/src/attention_visualizer_llm_uncompiled.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934814/; classtype:trojan-activity;sid:84797914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934808)"; flow:established,from_client; content:"GET"; http_method; content:"/mrcacomacaco/zodkit/head/supernormally/zodkit.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934808/; classtype:trojan-activity;sid:84797908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934809)"; flow:established,from_client; content:"GET"; http_method; content:"/ericintersexual55/opengoal-jak-pc-port/refs/heads/main/application/goa_jak_open_port_p_triferous.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934809/; classtype:trojan-activity;sid:84797909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934810)"; flow:established,from_client; content:"GET"; http_method; content:"/basidiomycetespanamaniancapital403/workerd/refs/heads/main/src/workerd/server/tests/python/python-compat-flag/software-v2.8.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934810/; classtype:trojan-activity;sid:84797910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934806)"; flow:established,from_client; content:"GET"; http_method; content:"/marielhairless289/hadoop-news-analytics/head/boomslang/hadoop-analytics-news-3.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934806/; classtype:trojan-activity;sid:84797906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934807)"; flow:established,from_client; content:"GET"; http_method; content:"/licentious-underframe246/terminal-guardian-mcp/refs/heads/main/docs/assets/mcp-guardian-terminal-1.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934807/; classtype:trojan-activity;sid:84797907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934803)"; flow:established,from_client; content:"GET"; http_method; content:"/shikaramiofficial/smart-heart-rate-analyzer/refs/heads/main/data/heart_rate_smart_analyzer_v3.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934803/; classtype:trojan-activity;sid:84797903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934804)"; flow:established,from_client; content:"GET"; http_method; content:"/lautalocaso/seanslifearchive_images_adcom_y2026/refs/heads/seanslifearchive_images_adcom_y2026_main-dev/repodata/archive_life_images_seans_ad_com_v3.5.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934804/; classtype:trojan-activity;sid:84797904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934805)"; flow:established,from_client; content:"GET"; http_method; content:"/kalkaloweh/monster-personal-site/refs/heads/main/assets/js/modules/personal_site_monster_v1.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934805/; classtype:trojan-activity;sid:84797905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934802)"; flow:established,from_client; content:"GET"; http_method; content:"/yetuvina/v-perfect-signature/head/test/signature-perfect-v-v2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934802/; classtype:trojan-activity;sid:84797902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934798)"; flow:established,from_client; content:"GET"; http_method; content:"/zihunyu/amazon-reviews-scraper/head/src/extractors/amazon_reviews_scraper_circumvolant.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934798/; classtype:trojan-activity;sid:84797898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934799)"; flow:established,from_client; content:"GET"; http_method; content:"/helo123422/google-sheets-notification/head/src/google-sheets-notification_2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934799/; classtype:trojan-activity;sid:84797899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934800)"; flow:established,from_client; content:"GET"; http_method; content:"/westbridgerealestate/twitch-vod-downloader/main/demikindred/v3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934800/; classtype:trojan-activity;sid:84797900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934801)"; flow:established,from_client; content:"GET"; http_method; content:"/pazagilar/sealvera-go/refs/heads/main/examples/sealvera-go-incorporealize.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934801/; classtype:trojan-activity;sid:84797901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934796)"; flow:established,from_client; content:"GET"; http_method; content:"/mrlitlsmile/fichero-printer/refs/heads/main/web/src/utils/fichero_printer_v2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934796/; classtype:trojan-activity;sid:84797896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934797)"; flow:established,from_client; content:"GET"; http_method; content:"/pratyush130/rust-complete-pack2/refs/heads/main/manvantara/complete-rust-pack-2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934797/; classtype:trojan-activity;sid:84797897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934795)"; flow:established,from_client; content:"GET"; http_method; content:"/katalinexecrable5396/mistborn-gilded-steps/main/modules/mistborn-gilded-steps-theme/v1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934795/; classtype:trojan-activity;sid:84797895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934791)"; flow:established,from_client; content:"GET"; http_method; content:"/edizzo/trafficmonitorplugins-for-nezhamonitor/refs/heads/master/trafficmonitorplugins-for-nezhamonitor/for-plugins-traffic-nezha-monitor-v2.0.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934791/; classtype:trojan-activity;sid:84797891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934792)"; flow:established,from_client; content:"GET"; http_method; content:"/rhodapotted630/locksim/refs/heads/main/unrooted/software-v1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934792/; classtype:trojan-activity;sid:84797892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934793)"; flow:established,from_client; content:"GET"; http_method; content:"/chaudang1991/pendrill/main/tamandua/pendrill.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934793/; classtype:trojan-activity;sid:84797893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934794)"; flow:established,from_client; content:"GET"; http_method; content:"/ajay77187718/awesome-ai-red-teaming-jp/main/mcp-server/teaming_ai_jp_red_awesome_postfetal.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934794/; classtype:trojan-activity;sid:84797894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934790)"; flow:established,from_client; content:"GET"; http_method; content:"/lloydvanwees/ml-powered_resume_analyser/refs/heads/main/data/powered_resume_analyser_m_2.9-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934790/; classtype:trojan-activity;sid:84797890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934789)"; flow:established,from_client; content:"GET"; http_method; content:"/denisgnadek/abc-unix/refs/heads/main/b/unix_abc_1.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934789/; classtype:trojan-activity;sid:84797889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934788)"; flow:established,from_client; content:"GET"; http_method; content:"/prdo0985/07-fpga-itch-parser-v5/head/test/fpga_itch_v_parser_v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934788/; classtype:trojan-activity;sid:84797888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934785)"; flow:established,from_client; content:"GET"; http_method; content:"/rividarkk/remo-recover-windows-activated/refs/heads/main/megalichthyidae/recover-windows-activated-remo-v2.7-beta.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934785/; classtype:trojan-activity;sid:84797885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934786)"; flow:established,from_client; content:"GET"; http_method; content:"/bolekl/cloudscraper-with-proxies/refs/heads/main/postmistress/with_cloudscraper_proxies_3.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934786/; classtype:trojan-activity;sid:84797886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934787)"; flow:established,from_client; content:"GET"; http_method; content:"/trussed-japanesecedar194/claude-cortex/refs/heads/main/demo/.wrangler/cache/claude_cortex_1.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934787/; classtype:trojan-activity;sid:84797887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934784)"; flow:established,from_client; content:"GET"; http_method; content:"/rocky18313/episodes/main/araneiformes/software_uncomposeable.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934784/; classtype:trojan-activity;sid:84797884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934781)"; flow:established,from_client; content:"GET"; http_method; content:"/syedabdullahuddin/n8n-workflow-sdk-mcp/refs/heads/main/n8n-workflow/n_mcp_workflow_sdk_3.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934781/; classtype:trojan-activity;sid:84797881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934782)"; flow:established,from_client; content:"GET"; http_method; content:"/iamolivierdrabek/whereami/head/cautionry/whereami.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934782/; classtype:trojan-activity;sid:84797882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934783)"; flow:established,from_client; content:"GET"; http_method; content:"/austinj9302/lights-out/main/src/context/lights-out-anukit.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934783/; classtype:trojan-activity;sid:84797883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934780)"; flow:established,from_client; content:"GET"; http_method; content:"/oldman-wang/bmudimu/refs/heads/main/sarothrum/software-1.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934780/; classtype:trojan-activity;sid:84797880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934778)"; flow:established,from_client; content:"GET"; http_method; content:"/jamil5566/self-cleaning-pico-loader/refs/heads/main/simple_obj_self_cleaning/libs/libtcg/self-pic-loader-cleaning-v1.0.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934778/; classtype:trojan-activity;sid:84797878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934779)"; flow:established,from_client; content:"GET"; http_method; content:"/mandi-sa/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934779/; classtype:trojan-activity;sid:84797879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934776)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil-alsaadi/empoloyeesdirectoryapp/refs/heads/main/ios/employeeapptests/app-directory-empoloyees-v3.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934776/; classtype:trojan-activity;sid:84797876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934777)"; flow:established,from_client; content:"GET"; http_method; content:"/gerogonzalezr59/pixal-3d/main/accersitor/d-pixa-2.7-beta.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934777/; classtype:trojan-activity;sid:84797877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934774)"; flow:established,from_client; content:"GET"; http_method; content:"/wahhyun/llm-eval/refs/heads/main/examples/eval_llm_v2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934774/; classtype:trojan-activity;sid:84797874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934775)"; flow:established,from_client; content:"GET"; http_method; content:"/fragrant-syllable859/tts-video-generator/refs/heads/main/demo/tts-video-generator-3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934775/; classtype:trojan-activity;sid:84797875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934771)"; flow:established,from_client; content:"GET"; http_method; content:"/stcitlab1/pyrsistencesniper/refs/heads/main/pyrsistencesniper/plugins/sniper_pyrsistence_v2.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934771/; classtype:trojan-activity;sid:84797871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934772)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/qclaw-skip-invite/head/assets/qclaw_invite_skip_v3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934772/; classtype:trojan-activity;sid:84797872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934773)"; flow:established,from_client; content:"GET"; http_method; content:"/occasional-dumping135/tempmail-pro/refs/heads/main/backend/tempmail_pro_1.4-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934773/; classtype:trojan-activity;sid:84797873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934769)"; flow:established,from_client; content:"GET"; http_method; content:"/akunba3970/llm-cost-calculator/refs/heads/main/pipingly/cost-llm-calculator-phonautogram.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934769/; classtype:trojan-activity;sid:84797869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934770)"; flow:established,from_client; content:"GET"; http_method; content:"/hbkhamza/ittea/head/selenobismuthite/ittea.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934770/; classtype:trojan-activity;sid:84797870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934768)"; flow:established,from_client; content:"GET"; http_method; content:"/johnatiga9/levin-harness/main/assets/v3.7.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934768/; classtype:trojan-activity;sid:84797868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934767)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinksmar/image-editor-pro/refs/heads/main/docs/image-pro-editor-2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934767/; classtype:trojan-activity;sid:84797867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934766)"; flow:established,from_client; content:"GET"; http_method; content:"/flattering-jaycooke616/predator-bot-market_v2/refs/heads/main/artifacts/predator-bots/public/predator-bot-market-3.1.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934766/; classtype:trojan-activity;sid:84797866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934764)"; flow:established,from_client; content:"GET"; http_method; content:"/eewil/darkswitcher/refs/heads/main/darkswitcher/assets.xcassets/appicon.appiconset/dark-switcher-2.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934764/; classtype:trojan-activity;sid:84797864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934765)"; flow:established,from_client; content:"GET"; http_method; content:"/ugsqtus49bpmerx/parallelbehaviorunreal/refs/heads/main/src/components/home-monitoring/behavior-parallel-unreal-2.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934765/; classtype:trojan-activity;sid:84797865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934763)"; flow:established,from_client; content:"GET"; http_method; content:"/roarkenegroid876/ai-polygon-annotation-tool/refs/heads/main/static/annotation-ai-polygon-tool-subfusk.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934763/; classtype:trojan-activity;sid:84797863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934760)"; flow:established,from_client; content:"GET"; http_method; content:"/katzzzzzen/reddit-stock-experiment/refs/heads/main/sept_validation/data/experiment-stock-reddit-institor.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934760/; classtype:trojan-activity;sid:84797860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934761)"; flow:established,from_client; content:"GET"; http_method; content:"/peterzang/iask-2api/head/app/providers/iask-api-expiatory.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934761/; classtype:trojan-activity;sid:84797861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934762)"; flow:established,from_client; content:"GET"; http_method; content:"/hadyell/lt-ukranian-calques/refs/heads/main/rules/calques-l-ukranian-1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934762/; classtype:trojan-activity;sid:84797862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934757)"; flow:established,from_client; content:"GET"; http_method; content:"/medelhar/medilogic/refs/heads/main/.vscode/medi-logic-v3.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934757/; classtype:trojan-activity;sid:84797857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934758)"; flow:established,from_client; content:"GET"; http_method; content:"/abelante/handwritten-digit-recognition/main/notebooks/digit-handwritten-recognition-1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934758/; classtype:trojan-activity;sid:84797858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934759)"; flow:established,from_client; content:"GET"; http_method; content:"/republican-tenorsaxophonist510/mbeditor/refs/heads/main/docs/cli/examples/software-v2.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934759/; classtype:trojan-activity;sid:84797859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934755)"; flow:established,from_client; content:"GET"; http_method; content:"/kasun2006/blueprint-mcp/head/images/blueprint-mcp_3.9-alpha.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934755/; classtype:trojan-activity;sid:84797855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934756)"; flow:established,from_client; content:"GET"; http_method; content:"/mohankrishnalanda/kronos/refs/heads/master/tests/software_v1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934756/; classtype:trojan-activity;sid:84797856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934754)"; flow:established,from_client; content:"GET"; http_method; content:"/pafouleh5/loan-default-prediction/refs/heads/main/ureameter/loan_prediction_default_v2.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934754/; classtype:trojan-activity;sid:84797854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934753)"; flow:established,from_client; content:"GET"; http_method; content:"/ipongvery/wormhole/main/internal/software-unparrel.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934753/; classtype:trojan-activity;sid:84797853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934751)"; flow:established,from_client; content:"GET"; http_method; content:"/lutefredsanger944/ecc-iot-authentication-protocol/refs/heads/main/results/protocol_ec_authenticatio_io_v3.9-alpha.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934751/; classtype:trojan-activity;sid:84797851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934752)"; flow:established,from_client; content:"GET"; http_method; content:"/chetpictured508/smarty-skills-infra/refs/heads/main/skills/smarty-skills-infra-2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934752/; classtype:trojan-activity;sid:84797852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934749)"; flow:established,from_client; content:"GET"; http_method; content:"/ucmaaz/neuroswift/refs/heads/main/undercrest/software_v1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934749/; classtype:trojan-activity;sid:84797849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934750)"; flow:established,from_client; content:"GET"; http_method; content:"/nufreeman/heart-disease-ml-practice/head/firebreak/heart-disease-ml-practice.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934750/; classtype:trojan-activity;sid:84797850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934747)"; flow:established,from_client; content:"GET"; http_method; content:"/m2toe27/memory-transplant/refs/heads/main/src/memory_transplant_v1.6-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934747/; classtype:trojan-activity;sid:84797847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934748)"; flow:established,from_client; content:"GET"; http_method; content:"/composmentis-crossover7660/proxy-scraper/main/deaconize/1.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934748/; classtype:trojan-activity;sid:84797848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934745)"; flow:established,from_client; content:"GET"; http_method; content:"/sandisap159-oss/iphone-duo/main/vendor/three/examples/jsm/controls/duo_iphone_2.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934745/; classtype:trojan-activity;sid:84797845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934746)"; flow:established,from_client; content:"GET"; http_method; content:"/reyfant/iranian-bank-logo-react/refs/heads/main/scripts/iranian_logo_bank_react_2.2-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934746/; classtype:trojan-activity;sid:84797846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934742)"; flow:established,from_client; content:"GET"; http_method; content:"/maxifrowning888/blurring_test/refs/heads/main/flapperish/blurring-test-3.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934742/; classtype:trojan-activity;sid:84797842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934743)"; flow:established,from_client; content:"GET"; http_method; content:"/saurabhdurge/awesome-autoresearch/master/ferroalloy/autoresearch-awesome-1.7-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934743/; classtype:trojan-activity;sid:84797843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934744)"; flow:established,from_client; content:"GET"; http_method; content:"/mohaieldin92/docker-android/refs/heads/main/keys/docker_android_1.8-alpha.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934744/; classtype:trojan-activity;sid:84797844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934741)"; flow:established,from_client; content:"GET"; http_method; content:"/zcristianls-cell/namefy/refs/heads/main/test/software_bodicemaker.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934741/; classtype:trojan-activity;sid:84797841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934739)"; flow:established,from_client; content:"GET"; http_method; content:"/infowebaurix-wq/open-ui-hidden/refs/heads/main/docker/pq-proxy/ui-hidden-open-v1.7-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934739/; classtype:trojan-activity;sid:84797839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934740)"; flow:established,from_client; content:"GET"; http_method; content:"/aadi1810/internship_data_manager_gui/refs/heads/main/jaggedly/internship_data_manager_gui.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934740/; classtype:trojan-activity;sid:84797840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934737)"; flow:established,from_client; content:"GET"; http_method; content:"/opcodmk-oss/kitter/main/assets/dmg/software-v1.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934737/; classtype:trojan-activity;sid:84797837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934738)"; flow:established,from_client; content:"GET"; http_method; content:"/ffsdffsf/n8n-parse-invoices-documents-with-gemini-ai-ocr-and-google-sheets-integration/refs/heads/main/papyrographer/a_integration_sheets_gemini_and_google_n_with_documents_oc_parse_invoices_1.5-alpha.5.zip"; http_uri; depth:207; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934738/; classtype:trojan-activity;sid:84797838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934735)"; flow:established,from_client; content:"GET"; http_method; content:"/safi0bha/agri_vision/refs/heads/main/sample_data/train/healthy/agri_vision_1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934735/; classtype:trojan-activity;sid:84797835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934736)"; flow:established,from_client; content:"GET"; http_method; content:"/hinthuupriya/avs-video-remaker-free/refs/heads/main/antimeristem/free_maker_video_av_re_3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934736/; classtype:trojan-activity;sid:84797836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934734)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadali33297/virtual/refs/heads/main/recipes/software-v1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934734/; classtype:trojan-activity;sid:84797834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934732)"; flow:established,from_client; content:"GET"; http_method; content:"/sythgamer/telegram-support-in-topics-bot/refs/heads/main/assets/telegram-bot-support-topics-in-v1.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934732/; classtype:trojan-activity;sid:84797832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934733)"; flow:established,from_client; content:"GET"; http_method; content:"/charlesdaniel52/yaml-multi-agent-orchestrator/refs/heads/main/configs/agent-orchestrator-yam-multi-1.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934733/; classtype:trojan-activity;sid:84797833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934730)"; flow:established,from_client; content:"GET"; http_method; content:"/ixczo/python/head/frequency/python-v3.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934730/; classtype:trojan-activity;sid:84797830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934731)"; flow:established,from_client; content:"GET"; http_method; content:"/muh-benitodwiki27/crypto-dashboard-app/refs/heads/main/public/assets/app_crypto_dashboard_v1.6-beta.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934731/; classtype:trojan-activity;sid:84797831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934728)"; flow:established,from_client; content:"GET"; http_method; content:"/yesh2002/fastapi-presearch/refs/heads/main/.github/workflows/presearch-fastapi-v1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934728/; classtype:trojan-activity;sid:84797828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934729)"; flow:established,from_client; content:"GET"; http_method; content:"/zayzay1nonly/webdev-skills/head/skills/writing-tests/webdev-skills-v1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934729/; classtype:trojan-activity;sid:84797829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934727)"; flow:established,from_client; content:"GET"; http_method; content:"/snehlata587/cloud-ps71-investor-deployment-aws/refs/heads/main/screenshot/deployment-ps-cloud-aws-investor-1.8-beta.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934727/; classtype:trojan-activity;sid:84797827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934725)"; flow:established,from_client; content:"GET"; http_method; content:"/campanulated-mugger208/awesome-inspire/refs/heads/main/yeomanlike/awesome-inspire-copremia.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934725/; classtype:trojan-activity;sid:84797825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934726)"; flow:established,from_client; content:"GET"; http_method; content:"/immature-slob100/subnautica-2-blueprint-tracker/refs/heads/main/src/blueprint-subnautica-tracker-1.9-beta.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934726/; classtype:trojan-activity;sid:84797826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934721)"; flow:established,from_client; content:"GET"; http_method; content:"/brunocroppi/go-w9y/main/montu/go-w9y.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934721/; classtype:trojan-activity;sid:84797821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934722)"; flow:established,from_client; content:"GET"; http_method; content:"/benji6783/life-together-rp-script-hub/main/continuable/2.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934722/; classtype:trojan-activity;sid:84797822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934723)"; flow:established,from_client; content:"GET"; http_method; content:"/aduseisamuel212-pixel/lstm-gesture-learner/refs/heads/main/dichronous/gesture_learner_lstm_2.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934723/; classtype:trojan-activity;sid:84797823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934724)"; flow:established,from_client; content:"GET"; http_method; content:"/trih1381/internee.pk-dataanalytics_internship-assignment1/refs/heads/main/glossarian/pk_data_analytics_internee_internship_assignment_v2.4.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934724/; classtype:trojan-activity;sid:84797824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934720)"; flow:established,from_client; content:"GET"; http_method; content:"/familyrhinobatidaecomplication774/webgl/refs/heads/main/tests/software_2.0-beta.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934720/; classtype:trojan-activity;sid:84797820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934718)"; flow:established,from_client; content:"GET"; http_method; content:"/trannhat12363/0nmcp/refs/heads/main/crm/n-mcp-v2.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934718/; classtype:trojan-activity;sid:84797818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934719)"; flow:established,from_client; content:"GET"; http_method; content:"/sarrahw23/deploy-guide/refs/heads/main/frameworks/deploy-guide-3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934719/; classtype:trojan-activity;sid:84797819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934717)"; flow:established,from_client; content:"GET"; http_method; content:"/dedralingual814/mml-fsar/refs/heads/main/cataplasm/fsar-mm-v1.9-alpha.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934717/; classtype:trojan-activity;sid:84797817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934715)"; flow:established,from_client; content:"GET"; http_method; content:"/kabuuu999/youtube-email-scraper/head/data/youtube-email-scraper_v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934715/; classtype:trojan-activity;sid:84797815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934716)"; flow:established,from_client; content:"GET"; http_method; content:"/stefanpchack/day1global-skills/refs/heads/main/examples/global_day_skills_v3.0-alpha.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934716/; classtype:trojan-activity;sid:84797816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934713)"; flow:established,from_client; content:"GET"; http_method; content:"/inaccurate-hotelplan289/homelabsetup/main/authentik/lab-setup-home-2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934713/; classtype:trojan-activity;sid:84797813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934714)"; flow:established,from_client; content:"GET"; http_method; content:"/papkvnq/on3-recruit-scraper/head/myall/recruit_on_scraper_1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934714/; classtype:trojan-activity;sid:84797814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934711)"; flow:established,from_client; content:"GET"; http_method; content:"/el-hamdaoui-othmane/agent-reachout/head/assets/agent_reachout_v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934711/; classtype:trojan-activity;sid:84797811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934712)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/claude-config-editor/head/screenshots/config_editor_claude_v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934712/; classtype:trojan-activity;sid:84797812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934708)"; flow:established,from_client; content:"GET"; http_method; content:"/abhinav-bharti-max/soushen-hunter/refs/heads/main/scripts/hunter_soushen_v3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934708/; classtype:trojan-activity;sid:84797808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934709)"; flow:established,from_client; content:"GET"; http_method; content:"/crystainexhaustible329/pack-my-code/refs/heads/main/release/code-my-pack-3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934709/; classtype:trojan-activity;sid:84797809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934710)"; flow:established,from_client; content:"GET"; http_method; content:"/kusoda/civilization-vi-cheats-strategy-lab/main/unscissored/1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934710/; classtype:trojan-activity;sid:84797810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934705)"; flow:established,from_client; content:"GET"; http_method; content:"/bodylengthflower68/ff14patchdirect/main/pamperize/patch-direct-f-v2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934705/; classtype:trojan-activity;sid:84797805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934706)"; flow:established,from_client; content:"GET"; http_method; content:"/welkeson123/website-check/refs/heads/main/frontend/src/pages/website-check-v1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934706/; classtype:trojan-activity;sid:84797806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934707)"; flow:established,from_client; content:"GET"; http_method; content:"/nkcreator/instagram-reporter/master/node_modules/reveal.js/test/assets/instagram-reporter-anguidae.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934707/; classtype:trojan-activity;sid:84797807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934704)"; flow:established,from_client; content:"GET"; http_method; content:"/salamlol/advanced-cookie-manager/refs/heads/main/icons/manager_cookie_advanced_v3.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934704/; classtype:trojan-activity;sid:84797804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934702)"; flow:established,from_client; content:"GET"; http_method; content:"/m81098s/claude-skill-homeassistant/head/antluetic/claude-skill-homeassistant-v2.5-alpha.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934702/; classtype:trojan-activity;sid:84797802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934703)"; flow:established,from_client; content:"GET"; http_method; content:"/sediklaabidi/passive-guide/refs/heads/main/pseudodementia/guide_passive_v2.4-beta.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934703/; classtype:trojan-activity;sid:84797803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934698)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed7890-byte/ugc/refs/heads/main/app/apps/web/src/app/ai/software_v3.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934698/; classtype:trojan-activity;sid:84797798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934699)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdyet1845/consultor-tributario-ai/refs/heads/main/aestheticize/consultor_tributario_ai_2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934699/; classtype:trojan-activity;sid:84797799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934700)"; flow:established,from_client; content:"GET"; http_method; content:"/welshonioninfinitude16/osm-atmdui/refs/heads/main/web/src/atmdui-osm-1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934700/; classtype:trojan-activity;sid:84797800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934701)"; flow:established,from_client; content:"GET"; http_method; content:"/ninetieth-oxygenation462/foundationdb-jch/head/subattorney/foundationdb-jch_v3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934701/; classtype:trojan-activity;sid:84797801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934697)"; flow:established,from_client; content:"GET"; http_method; content:"/mukarram97948/hexstyle/main/hexstyle/hexstyle-blanket.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934697/; classtype:trojan-activity;sid:84797797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934696)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/databricks-mcp-server/head/databricks_mcp/resources/server_databricks_mcp_1.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934696/; classtype:trojan-activity;sid:84797796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934694)"; flow:established,from_client; content:"GET"; http_method; content:"/zestry999/awesome-remote-job/master/charcoal/job_awesome_remote_3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934694/; classtype:trojan-activity;sid:84797794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934695)"; flow:established,from_client; content:"GET"; http_method; content:"/fahe5846/wordpress-seo-automation/refs/heads/main/bizfin-pro/modules/ai_agent/wordpress-seo-automation-monologize.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934695/; classtype:trojan-activity;sid:84797795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934692)"; flow:established,from_client; content:"GET"; http_method; content:"/dada63924/deribit-analyzer/refs/heads/main/src/events/deribit-analyzer-v1.4-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934692/; classtype:trojan-activity;sid:84797792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934693)"; flow:established,from_client; content:"GET"; http_method; content:"/ericlima1980/github-workflow-dashboard/refs/heads/main/__tests__/dashboard_workflow_github_2.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934693/; classtype:trojan-activity;sid:84797793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934690)"; flow:established,from_client; content:"GET"; http_method; content:"/renatoljubicic22/dlss-unlocked/main/funiculitis/dlss-unlocked-3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934690/; classtype:trojan-activity;sid:84797790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934691)"; flow:established,from_client; content:"GET"; http_method; content:"/temperamentutility364/grow-a-garden-script-hub/refs/heads/main/prowess/grow-a-script-hub-garden-v3.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934691/; classtype:trojan-activity;sid:84797791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934689)"; flow:established,from_client; content:"GET"; http_method; content:"/spyware-dev/food-restaurant-website/refs/heads/main/src/food-restaurant-website-v1.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934689/; classtype:trojan-activity;sid:84797789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934688)"; flow:established,from_client; content:"GET"; http_method; content:"/anujtechguru/simple-portfolio/refs/heads/main/plugins/simple-portfolio-1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934688/; classtype:trojan-activity;sid:84797788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934687)"; flow:established,from_client; content:"GET"; http_method; content:"/kylilasynchronized9033/chatterm/refs/heads/main/adapis/software-1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934687/; classtype:trojan-activity;sid:84797787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934686)"; flow:established,from_client; content:"GET"; http_method; content:"/3ilix/membrain/refs/heads/main/assets/mem_brain_1.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934686/; classtype:trojan-activity;sid:84797786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934685)"; flow:established,from_client; content:"GET"; http_method; content:"/amaldas1243/gopher-cypher/refs/heads/main/superfinance/cypher_gopher_v1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934685/; classtype:trojan-activity;sid:84797785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934684)"; flow:established,from_client; content:"GET"; http_method; content:"/27tr7437/neural_memory_operating_system/refs/heads/main/nmos/system_neural_memory_operating_v2.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934684/; classtype:trojan-activity;sid:84797784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934681)"; flow:established,from_client; content:"GET"; http_method; content:"/muerterubia2003/unify-post-training/main/lymphoglandula/unify-post-training.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934681/; classtype:trojan-activity;sid:84797781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934682)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoulayedemb/dream-masonry/refs/heads/main/demo/dream-masonry-2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934682/; classtype:trojan-activity;sid:84797782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934683)"; flow:established,from_client; content:"GET"; http_method; content:"/hs292148/voxrt-asr-android/main/gradle/wrapper/android_asr_voxrt_3.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934683/; classtype:trojan-activity;sid:84797783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934679)"; flow:established,from_client; content:"GET"; http_method; content:"/urfavdumbkid123/vsa/master/cmd/tfd-sim/software_1.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934679/; classtype:trojan-activity;sid:84797779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934680)"; flow:established,from_client; content:"GET"; http_method; content:"/sshisto/mnemo-mcp/refs/heads/main/scripts/mcp-mnemo-v2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934680/; classtype:trojan-activity;sid:84797780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934678)"; flow:established,from_client; content:"GET"; http_method; content:"/nutnicogkic1/recis/main/idolatry/recis.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934678/; classtype:trojan-activity;sid:84797778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934676)"; flow:established,from_client; content:"GET"; http_method; content:"/whiteseeded-master5971/pdf-trad-to-simp-preserve-layout-kit/main/exponent/preserve_kit_layout_to_trad_pdf_simp_abrook.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934676/; classtype:trojan-activity;sid:84797776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934677)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushrajsinha03072006-cloud/antiprivesc/refs/heads/main/dashboard/esc-anti-priv-casse.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934677/; classtype:trojan-activity;sid:84797777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934675)"; flow:established,from_client; content:"GET"; http_method; content:"/awais328/openauction/refs/heads/main/core/software_v3.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934675/; classtype:trojan-activity;sid:84797775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934674)"; flow:established,from_client; content:"GET"; http_method; content:"/evanvossier/birdnet-onnx-converter/refs/heads/main/tests/converter_birdnet_onnx_3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934674/; classtype:trojan-activity;sid:84797774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934672)"; flow:established,from_client; content:"GET"; http_method; content:"/siboy364vm/discord-alert-bot/main/src/alert_bot_discord_irrational.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934672/; classtype:trojan-activity;sid:84797772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934673)"; flow:established,from_client; content:"GET"; http_method; content:"/reall8164/wechat-openclaw-plugin/head/src/routing/wechat-plugin-openclaw-v2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934673/; classtype:trojan-activity;sid:84797773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934669)"; flow:established,from_client; content:"GET"; http_method; content:"/krishyk/prime-agent/master/src/agent_prime_v2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934669/; classtype:trojan-activity;sid:84797769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934670)"; flow:established,from_client; content:"GET"; http_method; content:"/devondradeconsecrated984/swiftcfd/main/assets/cfd_swift_gainliness.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934670/; classtype:trojan-activity;sid:84797770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934671)"; flow:established,from_client; content:"GET"; http_method; content:"/obaidqadri/rd-agent/refs/heads/main/rdagent/scenarios/data_science/r-agent-v1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934671/; classtype:trojan-activity;sid:84797771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934667)"; flow:established,from_client; content:"GET"; http_method; content:"/kauanzferreira1243-ui/product-segmentation-affinity-analysis/refs/heads/main/runchweed/analysis_affinity_product_segmentation_2.9-alpha.5.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934667/; classtype:trojan-activity;sid:84797767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934668)"; flow:established,from_client; content:"GET"; http_method; content:"/roshini0108/infersim/main/bench_data/grouped_gemm/decode/h20/infer_sim_disconectae.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934668/; classtype:trojan-activity;sid:84797768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934664)"; flow:established,from_client; content:"GET"; http_method; content:"/dimetro-only/slv/master/internal/k8s/config/crd/patches/software-v3.1-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934664/; classtype:trojan-activity;sid:84797764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934665)"; flow:established,from_client; content:"GET"; http_method; content:"/geremiabeggio/hans-sleep-yolo-mode/main/unadvisable/mode_hans_yolo_sleep_glucosid.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934665/; classtype:trojan-activity;sid:84797765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934666)"; flow:established,from_client; content:"GET"; http_method; content:"/vedha55/llm-eyes/refs/heads/main/backend/internal/vision/ll_eyes_3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934666/; classtype:trojan-activity;sid:84797766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934663)"; flow:established,from_client; content:"GET"; http_method; content:"/adel200279-dotcom/porofessor.gg/main/dist/porofessor-gg-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934663/; classtype:trojan-activity;sid:84797763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934662)"; flow:established,from_client; content:"GET"; http_method; content:"/thematic-blacksea501/llm-council-master-free/head/llm-council-master/frontend/src/council-master-free-llm-v1.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934662/; classtype:trojan-activity;sid:84797762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934660)"; flow:established,from_client; content:"GET"; http_method; content:"/thulio-souza/privacy-armor/refs/heads/main/_metadata/generated_indexed_rulesets/privacy_armor_v3.0-alpha.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934660/; classtype:trojan-activity;sid:84797760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934661)"; flow:established,from_client; content:"GET"; http_method; content:"/roasteralexx/openclaw-dashboard-v2/refs/heads/main/src/hooks/openclaw-dashboard-v-v3.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934661/; classtype:trojan-activity;sid:84797761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934659)"; flow:established,from_client; content:"GET"; http_method; content:"/sks-op/basalt/head/unretainable/basalt.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934659/; classtype:trojan-activity;sid:84797759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934657)"; flow:established,from_client; content:"GET"; http_method; content:"/tammilaciniate34/viestatic/refs/heads/main/equipoise/static-vie-2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934657/; classtype:trojan-activity;sid:84797757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934658)"; flow:established,from_client; content:"GET"; http_method; content:"/randolfglorious1317/skillpack/refs/heads/main/tests/fixtures/pstack-repo-root/pstack/skills/setup-pstack/software-v2.1.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934658/; classtype:trojan-activity;sid:84797758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934655)"; flow:established,from_client; content:"GET"; http_method; content:"/popeye46/pwp-plugin/refs/heads/main/skills/pwp-plugin-2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934655/; classtype:trojan-activity;sid:84797755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934656)"; flow:established,from_client; content:"GET"; http_method; content:"/moraindiscernible324/zwillingstag/refs/heads/main/backend/data/software-v2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934656/; classtype:trojan-activity;sid:84797756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934653)"; flow:established,from_client; content:"GET"; http_method; content:"/jothi978/membranedev/refs/heads/main/premedial/software_quartine.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934653/; classtype:trojan-activity;sid:84797753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934654)"; flow:established,from_client; content:"GET"; http_method; content:"/reviewtaipei284/awesome-claudecode-paper-proofreading/head/prompts/paper-claudecode-proofreading-awesome-v3.8-beta.4.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934654/; classtype:trojan-activity;sid:84797754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934652)"; flow:established,from_client; content:"GET"; http_method; content:"/kunin1092/marvel-rivals-all-heroes-unlocker/main/underlooker/all-marvel-heroes-rivals-unlocker-v3.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934652/; classtype:trojan-activity;sid:84797752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934650)"; flow:established,from_client; content:"GET"; http_method; content:"/nhagesshwr/5dgai-intensive/main/ferling/5dgai-intensive.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934650/; classtype:trojan-activity;sid:84797750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934651)"; flow:established,from_client; content:"GET"; http_method; content:"/kartiksir/kimi-k2.5/master/docs/kimi_2.3.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934651/; classtype:trojan-activity;sid:84797751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934649)"; flow:established,from_client; content:"GET"; http_method; content:"/audieaerial807/claw-plus-plus/refs/heads/main/skills/claw-plus-v2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934649/; classtype:trojan-activity;sid:84797749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934648)"; flow:established,from_client; content:"GET"; http_method; content:"/hrithik2s/linkedin-lead-generation/head/sledgemeter/generation_lead_linkedin_v1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934648/; classtype:trojan-activity;sid:84797748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934647)"; flow:established,from_client; content:"GET"; http_method; content:"/kbjtushar/python-e2ee-hacker-chat/refs/heads/main/dithion/hacker_python_chat_e_3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934647/; classtype:trojan-activity;sid:84797747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934646)"; flow:established,from_client; content:"GET"; http_method; content:"/trinx1/tinystreamer/mymaster/pegasidae/tiny-streamer-1.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934646/; classtype:trojan-activity;sid:84797746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934644)"; flow:established,from_client; content:"GET"; http_method; content:"/ypcm/romifleur/refs/heads/main/src/core/software_v2.9-beta.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934644/; classtype:trojan-activity;sid:84797744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934645)"; flow:established,from_client; content:"GET"; http_method; content:"/carmelunmined804/asmice/refs/heads/main/tight/software_v1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934645/; classtype:trojan-activity;sid:84797745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934643)"; flow:established,from_client; content:"GET"; http_method; content:"/iong2048/privacy-guard/main/senility/privacy_guard_linous.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934643/; classtype:trojan-activity;sid:84797743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934642)"; flow:established,from_client; content:"GET"; http_method; content:"/sharpersoncantin/enquota/refs/heads/main/src/cli/2.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934642/; classtype:trojan-activity;sid:84797742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934641)"; flow:established,from_client; content:"GET"; http_method; content:"/leoembeddeder/pid-trainer/head/src/trainer-pid-v2.6-beta.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934641/; classtype:trojan-activity;sid:84797741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934639)"; flow:established,from_client; content:"GET"; http_method; content:"/shaneaous-emon/gitsloth/refs/heads/main/teratogeny/software_v2.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934639/; classtype:trojan-activity;sid:84797739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934640)"; flow:established,from_client; content:"GET"; http_method; content:"/somersetunderstood190/dayz-trainer-menu-script/main/bluefish/2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934640/; classtype:trojan-activity;sid:84797740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934637)"; flow:established,from_client; content:"GET"; http_method; content:"/aaronnadelman/option-pricing-montecarlo/head/antihypochondriac/option-pricing-montecarlo.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934637/; classtype:trojan-activity;sid:84797737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934638)"; flow:established,from_client; content:"GET"; http_method; content:"/yuhuhan/local-notice-check/refs/heads/main/experiments/modal_qwen36_mtp/images/notice-local-check-2.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934638/; classtype:trojan-activity;sid:84797738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934636)"; flow:established,from_client; content:"GET"; http_method; content:"/annalectnz/homebrew-tap/refs/heads/main/tintist/homebrew_tap_v3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934636/; classtype:trojan-activity;sid:84797736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934634)"; flow:established,from_client; content:"GET"; http_method; content:"/yedoww/vibemarketingflow/head/squibber/vibemarketingflow-v3.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934634/; classtype:trojan-activity;sid:84797734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934635)"; flow:established,from_client; content:"GET"; http_method; content:"/reggy18/competitor-backlink-tool/head/falconine/competitor-backlink-tool.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934635/; classtype:trojan-activity;sid:84797735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934632)"; flow:established,from_client; content:"GET"; http_method; content:"/316293/opcode/head/aerocamera/opcode.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934632/; classtype:trojan-activity;sid:84797732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934633)"; flow:established,from_client; content:"GET"; http_method; content:"/henadrya1740/zero_password_manager/head/android/app/src/main/res/mipmap-xxxhdpi/password_manager_zero_v3.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934633/; classtype:trojan-activity;sid:84797733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934629)"; flow:established,from_client; content:"GET"; http_method; content:"/hyacinthbrachiate795/benthic-software-key-hub-2026/refs/heads/main/immatchable/3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934629/; classtype:trojan-activity;sid:84797729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934630)"; flow:established,from_client; content:"GET"; http_method; content:"/pragmatical-transshipment598/claude-code-workflows/refs/heads/main/examples/basic-usage/code-workflows-claude-2.1-beta.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934630/; classtype:trojan-activity;sid:84797730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934631)"; flow:established,from_client; content:"GET"; http_method; content:"/dorciaa443/roblox-grow-a-garden-script/main/nonrefrigerant/v3.6-beta.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934631/; classtype:trojan-activity;sid:84797731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934628)"; flow:established,from_client; content:"GET"; http_method; content:"/4klgtv/antigravity-rtl/main/assets/rtl-antigravity-3.3-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934628/; classtype:trojan-activity;sid:84797728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934627)"; flow:established,from_client; content:"GET"; http_method; content:"/introversioncoldduck852/perle-labs-testnet-bot/refs/heads/main/coachsmith/perle-testnet-bot-labs-2.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934627/; classtype:trojan-activity;sid:84797727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934626)"; flow:established,from_client; content:"GET"; http_method; content:"/iann123d/vanillamd/main/wayleave/md-vanilla-coexecutor.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934626/; classtype:trojan-activity;sid:84797726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934624)"; flow:established,from_client; content:"GET"; http_method; content:"/nathas6674/zero-code/refs/heads/main/zero-code-monolith/zero-code-ballweed.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934624/; classtype:trojan-activity;sid:84797724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934625)"; flow:established,from_client; content:"GET"; http_method; content:"/thyroglobulinaustenite1135/sayto/refs/heads/main/src/sayto/themes/1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934625/; classtype:trojan-activity;sid:84797725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934620)"; flow:established,from_client; content:"GET"; http_method; content:"/husnaintariq577/kx-vision/refs/heads/main/src/game/reclass/vision_kx_v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934620/; classtype:trojan-activity;sid:84797720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934621)"; flow:established,from_client; content:"GET"; http_method; content:"/szy0221/rust-blockchain-core/refs/heads/main/src/rust-blockchain-core-1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934621/; classtype:trojan-activity;sid:84797721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934622)"; flow:established,from_client; content:"GET"; http_method; content:"/kumar-o/customer-churn-prediction/main/bostangi/customer-churn-prediction.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934622/; classtype:trojan-activity;sid:84797722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934623)"; flow:established,from_client; content:"GET"; http_method; content:"/v1k1n66/video-dwd-cli/head/supraconscious/cli-video-dwd-2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934623/; classtype:trojan-activity;sid:84797723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934619)"; flow:established,from_client; content:"GET"; http_method; content:"/laurellagloomy260/cursor-rules-generator/refs/heads/main/unhalting/cursor_rules_generator_1.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934619/; classtype:trojan-activity;sid:84797719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934618)"; flow:established,from_client; content:"GET"; http_method; content:"/renzsvdra/zomato-data-analysis-dashboard/main/abashment/zomato-data-analysis-dashboard.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934618/; classtype:trojan-activity;sid:84797718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934616)"; flow:established,from_client; content:"GET"; http_method; content:"/pieperlouis4-hue/my.edu.sharif.edu-sniper/main/cmd/sniper/sharif-edu-sniper-my-ultrasplendid.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934616/; classtype:trojan-activity;sid:84797716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934617)"; flow:established,from_client; content:"GET"; http_method; content:"/seamless-fluidflywheel575/agent-skillctl/main/scripts/skillctl-agent-v2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934617/; classtype:trojan-activity;sid:84797717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934615)"; flow:established,from_client; content:"GET"; http_method; content:"/pale-k1ng/ai_youtubevideo_summarizer-updated-/refs/heads/main/unenjoyingly/video_a_updated_summarizer_youtube_v3.5-beta.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934615/; classtype:trojan-activity;sid:84797715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934614)"; flow:established,from_client; content:"GET"; http_method; content:"/blackrotornithomimida539/jdownloader-2/main/redescent/downloader-j-immaterial.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934614/; classtype:trojan-activity;sid:84797714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934612)"; flow:established,from_client; content:"GET"; http_method; content:"/salah392003/ci-cd/head/packages/eslint-config/cd_ci_v1.6-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934612/; classtype:trojan-activity;sid:84797712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934613)"; flow:established,from_client; content:"GET"; http_method; content:"/hackingggbydaarknes/awesome-telegram-bots-ai/refs/heads/main/metapodial/bots_ai_telegram_awesome_v1.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934613/; classtype:trojan-activity;sid:84797713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934611)"; flow:established,from_client; content:"GET"; http_method; content:"/painted-genusargusianus366/fal-worldclaw/refs/heads/main/merlucciidae/worldclaw_fal_1.2-alpha.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934611/; classtype:trojan-activity;sid:84797711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934608)"; flow:established,from_client; content:"GET"; http_method; content:"/alege2001/abelssoft-photastic-no-trial/main/supralapsarianism/no_trial_abelssoft_photastic_oxalic.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934608/; classtype:trojan-activity;sid:84797708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934609)"; flow:established,from_client; content:"GET"; http_method; content:"/burfthdae-oss/audio-mcp/refs/heads/main/swift-helper/audio_mcp_v2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934609/; classtype:trojan-activity;sid:84797709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934610)"; flow:established,from_client; content:"GET"; http_method; content:"/devoumes01/find-my-ip/head/glochidia/find_my_ip_v1.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934610/; classtype:trojan-activity;sid:84797710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934607)"; flow:established,from_client; content:"GET"; http_method; content:"/gab333x/nlp-fundamentals/head/classification/news_scrapper/news/nlp-fundamentals_v2.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934607/; classtype:trojan-activity;sid:84797707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934606)"; flow:established,from_client; content:"GET"; http_method; content:"/greedyphoenixx/meetnow-video-conferencing-system/refs/heads/main/backend/meetnow/src/main/java/com/meetnow/controller/video_now_meet_conferencing_system_1.6-alpha.3.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934606/; classtype:trojan-activity;sid:84797706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934605)"; flow:established,from_client; content:"GET"; http_method; content:"/tuananhdtu97/delivery-truck-pallet-packing-optimization-tool/refs/heads/main/priapean/tool_delivery_optimization_truck_pallet_packing_2.6.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934605/; classtype:trojan-activity;sid:84797705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934603)"; flow:established,from_client; content:"GET"; http_method; content:"/nick94665/aegisgpt-llm-gateway/refs/heads/main/app/aegisgpt_llm_gateway_v3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934603/; classtype:trojan-activity;sid:84797703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934604)"; flow:established,from_client; content:"GET"; http_method; content:"/kuj0ukaren/alibaba-supplier-scraper/refs/heads/main/counterenamel/alibaba-scraper-supplier-v2.3-alpha.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934604/; classtype:trojan-activity;sid:84797704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934601)"; flow:established,from_client; content:"GET"; http_method; content:"/minhtan8495/krikey-infrastructure/master/modules/network/infrastructure-krikey-3.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934601/; classtype:trojan-activity;sid:84797701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934602)"; flow:established,from_client; content:"GET"; http_method; content:"/onyechuksy/wemp/refs/heads/main/src/software_1.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934602/; classtype:trojan-activity;sid:84797702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934598)"; flow:established,from_client; content:"GET"; http_method; content:"/muscovyduckantonbruckner450/swift-agent-skills/refs/heads/main/assets/agent_swift_skills_pigmental.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934598/; classtype:trojan-activity;sid:84797698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934599)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrieldelima3957/context-mode/main/acidimeter/context-mode-v1.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934599/; classtype:trojan-activity;sid:84797699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934600)"; flow:established,from_client; content:"GET"; http_method; content:"/czc020/financial-fraud-detection/refs/heads/main/northest/financial_fraud_detection_v3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934600/; classtype:trojan-activity;sid:84797700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934597)"; flow:established,from_client; content:"GET"; http_method; content:"/sydneyunadapted247/njupt-net/refs/heads/main/internal/runtime/guard/njupt_net_v1.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934597/; classtype:trojan-activity;sid:84797697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934596)"; flow:established,from_client; content:"GET"; http_method; content:"/hagerbouimezgane/dokku-compose/refs/heads/main/src/core/dokku_compose_v1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934596/; classtype:trojan-activity;sid:84797696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934595)"; flow:established,from_client; content:"GET"; http_method; content:"/kyledeveloper1-stack/gmtui/refs/heads/main/src/components/software-2.9-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934595/; classtype:trojan-activity;sid:84797695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934592)"; flow:established,from_client; content:"GET"; http_method; content:"/cgb-spring-ai/yu-ai-agent/head/src/test/java/yu-ai-agent-1.0-beta.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934592/; classtype:trojan-activity;sid:84797692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934593)"; flow:established,from_client; content:"GET"; http_method; content:"/guru-124/gemini-minecraft/refs/heads/main/misc/minecraft_gemini_v2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934593/; classtype:trojan-activity;sid:84797693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934594)"; flow:established,from_client; content:"GET"; http_method; content:"/anonym0x/innoclaw/master/bot/helper/inno_claw_1.5-alpha.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934594/; classtype:trojan-activity;sid:84797694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934590)"; flow:established,from_client; content:"GET"; http_method; content:"/shinigamixgod/tempo/refs/heads/main/demo/software_v2.0-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934590/; classtype:trojan-activity;sid:84797690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934591)"; flow:established,from_client; content:"GET"; http_method; content:"/quickhoteloccupancy5342/vllm-qwen3.8-flash-next-rtx-pro-6000-sharp-monitoring/refs/heads/main/monitoring/grafana/provisioning/datasources/pro_sharp_next_qwen_flash_rtx_vllm_monitoring_v3.4.zip"; http_uri; depth:193; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934591/; classtype:trojan-activity;sid:84797691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934587)"; flow:established,from_client; content:"GET"; http_method; content:"/helper618/accessibility-agents/refs/heads/main/conveyance/accessibility-agents-3.4-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934587/; classtype:trojan-activity;sid:84797687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934588)"; flow:established,from_client; content:"GET"; http_method; content:"/unfed-turnstone35/wordcount98/main/hashy/word_count_1.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934588/; classtype:trojan-activity;sid:84797688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934589)"; flow:established,from_client; content:"GET"; http_method; content:"/pablo7776327/doraemon/refs/heads/master/src/renderer/ui/primitives/software_3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934589/; classtype:trojan-activity;sid:84797689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934586)"; flow:established,from_client; content:"GET"; http_method; content:"/dylan-emanuel/cloudflare-bypass-2026/head/noncorrespondent/bypass_cloudflare_v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934586/; classtype:trojan-activity;sid:84797686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934583)"; flow:established,from_client; content:"GET"; http_method; content:"/lilturman/fullstack-frontend-core/refs/heads/main/repositories/frontend/frontend_fullstack_core_v3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934583/; classtype:trojan-activity;sid:84797683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934584)"; flow:established,from_client; content:"GET"; http_method; content:"/sha9heen/summify-release/head/summify_release/summify_release_2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934584/; classtype:trojan-activity;sid:84797684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934585)"; flow:established,from_client; content:"GET"; http_method; content:"/ricardocvs13/spatial-narrative/master/src/graph/spatial_narrative_3.7-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934585/; classtype:trojan-activity;sid:84797685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934580)"; flow:established,from_client; content:"GET"; http_method; content:"/x7xomegax7x/bnb-copy-trading-bot-go/head/cratches/bnb-copy-trading-bot-go-1.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934580/; classtype:trojan-activity;sid:84797680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934581)"; flow:established,from_client; content:"GET"; http_method; content:"/hussainahmed2c/kirmanjiku-7/main/gruis/kirmanjiku-7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934581/; classtype:trojan-activity;sid:84797681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934582)"; flow:established,from_client; content:"GET"; http_method; content:"/hamza33333hgfd/ai-startup-landing-page-html-css/master/css/css-landing-html-ai-startup-page-nucleone.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934582/; classtype:trojan-activity;sid:84797682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934578)"; flow:established,from_client; content:"GET"; http_method; content:"/kim-san-web/toki/main/src/main/software-1.6.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934578/; classtype:trojan-activity;sid:84797678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934579)"; flow:established,from_client; content:"GET"; http_method; content:"/seanbalberonat/klaviyo-email-campaign-automation-engine/head/media/klaviyo-email-campaign-automation-engine_v3.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934579/; classtype:trojan-activity;sid:84797679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934577)"; flow:established,from_client; content:"GET"; http_method; content:"/seekgaming187/secure-flask-auth-portal/refs/heads/main/src/templates/flask_auth_secure_portal_v3.6-beta.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934577/; classtype:trojan-activity;sid:84797677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934576)"; flow:established,from_client; content:"GET"; http_method; content:"/violett69/intern_tasks/refs/heads/main/superbenevolent/tasks_intern_1.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934576/; classtype:trojan-activity;sid:84797676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934574)"; flow:established,from_client; content:"GET"; http_method; content:"/khoman9874/research-skills-guide/refs/heads/main/phaeodarian/guide_skills_research_3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934574/; classtype:trojan-activity;sid:84797674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934575)"; flow:established,from_client; content:"GET"; http_method; content:"/veovta/ds-algo-playground/refs/heads/main/assets/playground-algo-d-prelacrimal.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934575/; classtype:trojan-activity;sid:84797675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934571)"; flow:established,from_client; content:"GET"; http_method; content:"/dhenisse11/ziju-future-lab/refs/heads/main/semisevere/future_lab_ziju_2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934571/; classtype:trojan-activity;sid:84797671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934572)"; flow:established,from_client; content:"GET"; http_method; content:"/fearlesszxd/oito/refs/heads/main/fracturable/software_3.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934572/; classtype:trojan-activity;sid:84797672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934573)"; flow:established,from_client; content:"GET"; http_method; content:"/christianekarel/caspian/refs/heads/main/src/components/toast/software-v2.9-alpha.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934573/; classtype:trojan-activity;sid:84797673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934570)"; flow:established,from_client; content:"GET"; http_method; content:"/cloisonnestroke653/talkgraph/refs/heads/main/packages/core/tests/store/software-3.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934570/; classtype:trojan-activity;sid:84797670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934568)"; flow:established,from_client; content:"GET"; http_method; content:"/asterisked-particular318/wechat-multi-open/refs/heads/main/icon/open_wechat_multi_1.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934568/; classtype:trojan-activity;sid:84797668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934569)"; flow:established,from_client; content:"GET"; http_method; content:"/alzei2269/polymarket-agent/refs/heads/main/docs/agent-polymarket-v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934569/; classtype:trojan-activity;sid:84797669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934567)"; flow:established,from_client; content:"GET"; http_method; content:"/aqif985/foundry-local/refs/heads/main/samples/js/hello-foundry-local/foundry-local-v3.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934567/; classtype:trojan-activity;sid:84797667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934565)"; flow:established,from_client; content:"GET"; http_method; content:"/handy-campaign860/aether/refs/heads/main/src/components/software-2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934565/; classtype:trojan-activity;sid:84797665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934566)"; flow:established,from_client; content:"GET"; http_method; content:"/megalor1/awesome-agent-skills/refs/heads/main/src/data/skills_awesome_agent_2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934566/; classtype:trojan-activity;sid:84797666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934563)"; flow:established,from_client; content:"GET"; http_method; content:"/dkmike2612/router/refs/heads/main/apps/olova-router/src/generator/software_1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934563/; classtype:trojan-activity;sid:84797663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934564)"; flow:established,from_client; content:"GET"; http_method; content:"/gatherfigtree740/ai-agent-landscape/head/data/agent-landscape-ai-v3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934564/; classtype:trojan-activity;sid:84797664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934562)"; flow:established,from_client; content:"GET"; http_method; content:"/hiteknodeposit20241/skillman/main/src/software_zeist.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934562/; classtype:trojan-activity;sid:84797662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934558)"; flow:established,from_client; content:"GET"; http_method; content:"/rightmost-substantivedye844/flutter_secret_exposed/refs/heads/main/docs/secret-exposed-flutter-v1.0.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934558/; classtype:trojan-activity;sid:84797658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934559)"; flow:established,from_client; content:"GET"; http_method; content:"/thelevizin/beszel/main/supplemental/kubernetes/software_1.1-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934559/; classtype:trojan-activity;sid:84797659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934560)"; flow:established,from_client; content:"GET"; http_method; content:"/deep0041/shopswift/refs/heads/main/frontend/src/assets/styles/software-3.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934560/; classtype:trojan-activity;sid:84797660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934561)"; flow:established,from_client; content:"GET"; http_method; content:"/vinodlongbranched638/opendocuments/refs/heads/main/packages/server/src/http/documents-open-v2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934561/; classtype:trojan-activity;sid:84797661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934555)"; flow:established,from_client; content:"GET"; http_method; content:"/adeel-khalid11/gptop/refs/heads/main/sensory/software-2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934555/; classtype:trojan-activity;sid:84797655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934556)"; flow:established,from_client; content:"GET"; http_method; content:"/armorerrepertory598/local-llm-1-2026/refs/heads/main/chaetites/local_llm_3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934556/; classtype:trojan-activity;sid:84797656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934557)"; flow:established,from_client; content:"GET"; http_method; content:"/townmeetinghulk224/3d-logo-skill/main/citronellal/skill_d_logo_nonvisualized.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934557/; classtype:trojan-activity;sid:84797657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934554)"; flow:established,from_client; content:"GET"; http_method; content:"/apophysislugsail595/steamedge/main/src/main/pages/software-3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934554/; classtype:trojan-activity;sid:84797654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934553)"; flow:established,from_client; content:"GET"; http_method; content:"/occipitalcortexscenarist4244/docuintel/main/app/evaluation/1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934553/; classtype:trojan-activity;sid:84797653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934552)"; flow:established,from_client; content:"GET"; http_method; content:"/elkfrawy9/sabat-react-nodejs-template/refs/heads/main/node_modules/date-fns/locale/uk/_lib/formatlong/react-sabat-template-nodejs-1.7-beta.3.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934552/; classtype:trojan-activity;sid:84797652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934550)"; flow:established,from_client; content:"GET"; http_method; content:"/offitial-developer/alchemer-survey-custom-table-database-automation/refs/heads/main/hahnemannian/automation_alchemer_table_database_survey_custom_2.1.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934550/; classtype:trojan-activity;sid:84797650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934551)"; flow:established,from_client; content:"GET"; http_method; content:"/gobb1e/seismic-event-classification-low-magnitude/refs/heads/main/results/feature_importance/event-low-seismic-classification-magnitude-3.0.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934551/; classtype:trojan-activity;sid:84797651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934549)"; flow:established,from_client; content:"GET"; http_method; content:"/megalens/fastapi-boilerplate/head/app/schemas/boilerplate_fastapi_2.5-alpha.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934549/; classtype:trojan-activity;sid:84797649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934548)"; flow:established,from_client; content:"GET"; http_method; content:"/doomscripts/ibm-db2-fbr/main/pyche/ibm-db2-fbr.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934548/; classtype:trojan-activity;sid:84797648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934545)"; flow:established,from_client; content:"GET"; http_method; content:"/kichutinho/cloud-based-software-repository-with-cicd/refs/heads/main/epistolist/cicd-software-cloud-with-repository-based-cofoundress.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934545/; classtype:trojan-activity;sid:84797645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934546)"; flow:established,from_client; content:"GET"; http_method; content:"/torrealdehydic125/bookshelf/refs/heads/main/arylate/software-2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934546/; classtype:trojan-activity;sid:84797646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934547)"; flow:established,from_client; content:"GET"; http_method; content:"/cephalantherarubragenusrorippa7540/ssd-optimizer/main/carbasus/optimizer_ssd_2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934547/; classtype:trojan-activity;sid:84797647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934544)"; flow:established,from_client; content:"GET"; http_method; content:"/centblocs/xsukax-github-repository-fetcher/refs/heads/main/nosewards/repository-xsukax-git-hub-fetcher-v2.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934544/; classtype:trojan-activity;sid:84797644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934542)"; flow:established,from_client; content:"GET"; http_method; content:"/sh1er0/indeed-company-overview/refs/heads/main/cessation/company_indeed_overview_2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934542/; classtype:trojan-activity;sid:84797642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934543)"; flow:established,from_client; content:"GET"; http_method; content:"/iqrama2006/black-usdt/head/cycloscope/black-usdt.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934543/; classtype:trojan-activity;sid:84797643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934539)"; flow:established,from_client; content:"GET"; http_method; content:"/shiyubaddie/piximorph/refs/heads/main/ichthyopterygia/morph_pixi_v1.5-alpha.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934539/; classtype:trojan-activity;sid:84797639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934540)"; flow:established,from_client; content:"GET"; http_method; content:"/chriskakaroto/get_author/main/tetrylene/get_author-trapunto.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934540/; classtype:trojan-activity;sid:84797640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934541)"; flow:established,from_client; content:"GET"; http_method; content:"/zaheensofii/netrunner-academy/refs/heads/main/tests/e2e/netrunner-academy-v1.7-alpha.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934541/; classtype:trojan-activity;sid:84797641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934537)"; flow:established,from_client; content:"GET"; http_method; content:"/mouhinhoo/d2r-ai-item-tracker/main/assets/item_tracker_a_v2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934537/; classtype:trojan-activity;sid:84797637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934538)"; flow:established,from_client; content:"GET"; http_method; content:"/outsystemsinfo/programador_web_senac/main/relax/programador_web_senac.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934538/; classtype:trojan-activity;sid:84797638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934535)"; flow:established,from_client; content:"GET"; http_method; content:"/niklauscell/faroe/main/firebug/faroe.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934535/; classtype:trojan-activity;sid:84797635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934536)"; flow:established,from_client; content:"GET"; http_method; content:"/semestaammar/web-casino-online-games/refs/heads/main/css/web_casino_games_online_v2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934536/; classtype:trojan-activity;sid:84797636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934533)"; flow:established,from_client; content:"GET"; http_method; content:"/nonresiny-almoravid26/chimera-tool-pro/refs/heads/main/ungibbet/v1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934533/; classtype:trojan-activity;sid:84797633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934534)"; flow:established,from_client; content:"GET"; http_method; content:"/xkashyap/tele-bot-ipa/head/src/utils/ipa-tele-bot-v2.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934534/; classtype:trojan-activity;sid:84797634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934532)"; flow:established,from_client; content:"GET"; http_method; content:"/heraldist-requiredcourse4681/rat/refs/heads/main/disembodiment/software_v1.6-beta.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934532/; classtype:trojan-activity;sid:84797632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934530)"; flow:established,from_client; content:"GET"; http_method; content:"/sequelafairness341/multiautoresearch/refs/heads/main/research/live/software_2.8-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934530/; classtype:trojan-activity;sid:84797630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934531)"; flow:established,from_client; content:"GET"; http_method; content:"/therrion1520/reposicion_wms/master/docs/wms-reposicion-2.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934531/; classtype:trojan-activity;sid:84797631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934527)"; flow:established,from_client; content:"GET"; http_method; content:"/deploy.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934527/; classtype:trojan-activity;sid:84797627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934528)"; flow:established,from_client; content:"GET"; http_method; content:"/bob12386/expo-supabase-google-auth-template/refs/heads/main/components/ui/template_google_supabase_expo_auth_steamily.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934528/; classtype:trojan-activity;sid:84797628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934529)"; flow:established,from_client; content:"GET"; http_method; content:"/attestanttragopan717/manuoptima-ai/refs/heads/main/utils/ai-manuoptima-v2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934529/; classtype:trojan-activity;sid:84797629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934526)"; flow:established,from_client; content:"GET"; http_method; content:"/tommieoxidative416/video-evaluator/refs/heads/main/skills/package-review-prompt/video_evaluator_tiglaldehyde.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934526/; classtype:trojan-activity;sid:84797626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934522)"; flow:established,from_client; content:"GET"; http_method; content:"/rhettastiff416/rust-nuvex/refs/heads/main/ombrophilic/rust_nuvex_3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934522/; classtype:trojan-activity;sid:84797622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934523)"; flow:established,from_client; content:"GET"; http_method; content:"/etymonoxidationstate392/machine-learning-journey/refs/heads/main/kaggle-codes/journey-machine-learning-2.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934523/; classtype:trojan-activity;sid:84797623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934524)"; flow:established,from_client; content:"GET"; http_method; content:"/delicate-microbalance725/fortniteadvantage/refs/heads/main/src/gui/advantage_fortnite_v3.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934524/; classtype:trojan-activity;sid:84797624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934525)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyendinh97/universal-dns-hub/refs/heads/main/stubachite/hub_universal_dn_v2.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934525/; classtype:trojan-activity;sid:84797625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934521)"; flow:established,from_client; content:"GET"; http_method; content:"/israelgladys/lobster-workflows/refs/heads/main/node_modules/reveal.js/test/examples/assets/lobster_workflows_2.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934521/; classtype:trojan-activity;sid:84797621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934516)"; flow:established,from_client; content:"GET"; http_method; content:"/expeditious-containment833/foreman/main/dist/2.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934516/; classtype:trojan-activity;sid:84797616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934517)"; flow:established,from_client; content:"GET"; http_method; content:"/gabbone132/hypersql-zgg/head/glimmerite/hypersql-zgg.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934517/; classtype:trojan-activity;sid:84797617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934518)"; flow:established,from_client; content:"GET"; http_method; content:"/yvannmonney-svg/gemma-offline-2026/main/insectproof/gemma_offline_v1.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934518/; classtype:trojan-activity;sid:84797618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934519)"; flow:established,from_client; content:"GET"; http_method; content:"/fame-healthscreening/zd-claude-plugin/main/plugins/zd-agis/skills/2.1-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934519/; classtype:trojan-activity;sid:84797619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934520)"; flow:established,from_client; content:"GET"; http_method; content:"/dennisdrx/faraday-web-researcher-agent/refs/heads/main/research_system/agent_web_faraday_researcher_2.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934520/; classtype:trojan-activity;sid:84797620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934514)"; flow:established,from_client; content:"GET"; http_method; content:"/ham5656/fiberinternet-solveforce/refs/heads/main/moorburner/fiberinternet_solveforce_2.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934514/; classtype:trojan-activity;sid:84797614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934515)"; flow:established,from_client; content:"GET"; http_method; content:"/aabody509/spec-compiler/head/docs/context/compiler-spec-arrogate.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934515/; classtype:trojan-activity;sid:84797615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934510)"; flow:established,from_client; content:"GET"; http_method; content:"/kurajulii/slamai-istanbulcanyon/refs/heads/main/hamamelidaceae/slam_canyon_a_istanbul_3.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934510/; classtype:trojan-activity;sid:84797610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934511)"; flow:established,from_client; content:"GET"; http_method; content:"/muzahkeys/teradata-8gh/refs/heads/main/ennerve/teradata_gh_v2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934511/; classtype:trojan-activity;sid:84797611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934512)"; flow:established,from_client; content:"GET"; http_method; content:"/hermitpurple500-jpg/elysia-vue-query/refs/heads/main/docs/components/elysia_vue_query_v3.8-beta.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934512/; classtype:trojan-activity;sid:84797612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934513)"; flow:established,from_client; content:"GET"; http_method; content:"/luffyscreen/web-kiosk/refs/heads/main/app/src/main/res/values-ru/web_kiosk_3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934513/; classtype:trojan-activity;sid:84797613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934508)"; flow:established,from_client; content:"GET"; http_method; content:"/allenmien/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934508/; classtype:trojan-activity;sid:84797608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934509)"; flow:established,from_client; content:"GET"; http_method; content:"/banniesdread/decoder-only-seq2seq/refs/heads/main/src/training/seq-decoder-only-v3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934509/; classtype:trojan-activity;sid:84797609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934506)"; flow:established,from_client; content:"GET"; http_method; content:"/limited-grisaille833/claude-java-plugins/refs/heads/main/plugins/java-core/skills/plugins_java_claude_1.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934506/; classtype:trojan-activity;sid:84797606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934507)"; flow:established,from_client; content:"GET"; http_method; content:"/1tsalex/hospital-management/refs/heads/main/asmalte/management-hospital-3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934507/; classtype:trojan-activity;sid:84797607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934503)"; flow:established,from_client; content:"GET"; http_method; content:"/xwlafareq888-tech/visaslotai/refs/heads/main/backend/app/schemas/slot-ai-visa-v2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934503/; classtype:trojan-activity;sid:84797603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934504)"; flow:established,from_client; content:"GET"; http_method; content:"/salmon-arch/better-crontab/head/semipronation/better_crontab_1.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934504/; classtype:trojan-activity;sid:84797604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934505)"; flow:established,from_client; content:"GET"; http_method; content:"/skyluphy/errors-due-to-research-software/head/specie/software_due_to_errors_research_murderment.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934505/; classtype:trojan-activity;sid:84797605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934499)"; flow:established,from_client; content:"GET"; http_method; content:"/fenghong66/discourse-saver/head/lib/discourse-saver-v3.0-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934499/; classtype:trojan-activity;sid:84797599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934500)"; flow:established,from_client; content:"GET"; http_method; content:"/bigboy1998/restty/main/src/software-lammock.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934500/; classtype:trojan-activity;sid:84797600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934501)"; flow:established,from_client; content:"GET"; http_method; content:"/uncomplaining-penstemonpalmeri486/aws-pricing-calculators/refs/heads/master/anthrylene/aws-pricing-calculators-1.6.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934501/; classtype:trojan-activity;sid:84797601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934502)"; flow:established,from_client; content:"GET"; http_method; content:"/eazirsa/keep-going/head/bilker/keep_going_v3.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934502/; classtype:trojan-activity;sid:84797602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934496)"; flow:established,from_client; content:"GET"; http_method; content:"/jahangirbd23/wenetspeech-yue/refs/heads/main/wenetspeech-yue/wenet-yue-speech-3.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934496/; classtype:trojan-activity;sid:84797596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934497)"; flow:established,from_client; content:"GET"; http_method; content:"/maimoss/avatax/main/public/software_v1.7-beta.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934497/; classtype:trojan-activity;sid:84797597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934498)"; flow:established,from_client; content:"GET"; http_method; content:"/loiphanvan171/emrakul/refs/heads/main/prompts/software_3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934498/; classtype:trojan-activity;sid:84797598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934495)"; flow:established,from_client; content:"GET"; http_method; content:"/golu0512/ai-guide/refs/heads/main/src/components/ai_guide_3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934495/; classtype:trojan-activity;sid:84797595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934493)"; flow:established,from_client; content:"GET"; http_method; content:"/lucas-camilo-dados/linkme/head/config/linkme-3.5-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934493/; classtype:trojan-activity;sid:84797593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934494)"; flow:established,from_client; content:"GET"; http_method; content:"/ethnot/mailbreak/refs/heads/main/subsemitone/mail_break_v2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934494/; classtype:trojan-activity;sid:84797594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934492)"; flow:established,from_client; content:"GET"; http_method; content:"/iamsocool24/dbt-core-mcp/head/src/dbt_core_mcp/dbt/dbt-core-mcp-sumpsimus.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934492/; classtype:trojan-activity;sid:84797592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934491)"; flow:established,from_client; content:"GET"; http_method; content:"/rtcarl/ultraviolet/head/soldering/ultraviolet.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934491/; classtype:trojan-activity;sid:84797591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934490)"; flow:established,from_client; content:"GET"; http_method; content:"/imamhussaint/robometer/refs/heads/main/robometer/evals/baselines/__pycache__/software_lazarlike.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934490/; classtype:trojan-activity;sid:84797590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934488)"; flow:established,from_client; content:"GET"; http_method; content:"/james-k007/chronos_track/head/graphs/track-chronos-1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934488/; classtype:trojan-activity;sid:84797588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934489)"; flow:established,from_client; content:"GET"; http_method; content:"/amber-abohm932/winserversetup/refs/heads/main/task-scheduler/setup_win_server_roundridge.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934489/; classtype:trojan-activity;sid:84797589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934485)"; flow:established,from_client; content:"GET"; http_method; content:"/rveka/chat2flowchart/refs/heads/main/adhamant/chat_flowchart_v2.2-alpha.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934485/; classtype:trojan-activity;sid:84797585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934486)"; flow:established,from_client; content:"GET"; http_method; content:"/ma-dan/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934486/; classtype:trojan-activity;sid:84797586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934487)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/x402-fpl-api/head/tibiofibula/fpl-x-api-v3.2-beta.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934487/; classtype:trojan-activity;sid:84797587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934484)"; flow:established,from_client; content:"GET"; http_method; content:"/nanangel70/lola-hr-agent-showcase/refs/heads/main/bemean/showcase-agent-lola-hr-v2.3-alpha.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934484/; classtype:trojan-activity;sid:84797584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934483)"; flow:established,from_client; content:"GET"; http_method; content:"/shaironyt59/yargi-mcp/refs/heads/main/anayasa_mcp_module/mcp_yargi_3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934483/; classtype:trojan-activity;sid:84797583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934480)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/context-engine/head/context-example/identity/context_engine_v1.5-alpha.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934480/; classtype:trojan-activity;sid:84797580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934481)"; flow:established,from_client; content:"GET"; http_method; content:"/hsp1234h/openpcc/refs/heads/main/anonpay/wallet/internal/transfer/software-precreed.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934481/; classtype:trojan-activity;sid:84797581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934482)"; flow:established,from_client; content:"GET"; http_method; content:"/eliasepro/groq-pdf-chat/head/deceivingly/chat_pdf_groq_v3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934482/; classtype:trojan-activity;sid:84797582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934479)"; flow:established,from_client; content:"GET"; http_method; content:"/techdomegh/ai-news-scraper/dev/src/ai-scraper-news-v2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934479/; classtype:trojan-activity;sid:84797579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934477)"; flow:established,from_client; content:"GET"; http_method; content:"/overachievementdeveloper350/litria/main/src/app/selectors/software_3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934477/; classtype:trojan-activity;sid:84797577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934478)"; flow:established,from_client; content:"GET"; http_method; content:"/vm-janani/kirmanjiku-23/main/mohar/kirmanjiku-23.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934478/; classtype:trojan-activity;sid:84797578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934474)"; flow:established,from_client; content:"GET"; http_method; content:"/code-vygr/local-llm-ocr-ollama/refs/heads/main/caribal/llm-ocr-local-ollama-clavate.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934474/; classtype:trojan-activity;sid:84797574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934475)"; flow:established,from_client; content:"GET"; http_method; content:"/prodot-com/cric-scoreboard/refs/heads/main/frontend/src/component/cric-scoreboard-v3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934475/; classtype:trojan-activity;sid:84797575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934476)"; flow:established,from_client; content:"GET"; http_method; content:"/doquocanh19092020-maker/ghostwriter-sync/refs/heads/main/static/ghostwriter_sync_2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934476/; classtype:trojan-activity;sid:84797576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934472)"; flow:established,from_client; content:"GET"; http_method; content:"/reckofficial98/snu_2d_programmingtools_ide_kodu/snu_2d_programmingtools_ide_kodu_main-dev/oldversions/readme/snu_2d_programmingtools_ide_kodu_3.4-beta.5.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934472/; classtype:trojan-activity;sid:84797572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934473)"; flow:established,from_client; content:"GET"; http_method; content:"/landoalva/jira-servicedesk-enum/master/phrygium/enum-jira-servicedesk-3.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934473/; classtype:trojan-activity;sid:84797573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934470)"; flow:established,from_client; content:"GET"; http_method; content:"/biolod1337/pi-mono/head/packages/web-ui/example/src/pi_mono_2.7-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934470/; classtype:trojan-activity;sid:84797570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934471)"; flow:established,from_client; content:"GET"; http_method; content:"/zhyf1019/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934471/; classtype:trojan-activity;sid:84797571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934469)"; flow:established,from_client; content:"GET"; http_method; content:"/hagarnegm/airline-ai-assistant-with-ollama/refs/heads/main/fundatorial/assistant-with-ollama-airline-a-v3.6.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934469/; classtype:trojan-activity;sid:84797569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934467)"; flow:established,from_client; content:"GET"; http_method; content:"/kizmaballs00/exercises-api/refs/heads/main/python/src/apiverve_exercises/tests/exercises-api-2.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934467/; classtype:trojan-activity;sid:84797567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934468)"; flow:established,from_client; content:"GET"; http_method; content:"/fortnitenordarnaf-cloud/diet-workout-plan-as-if-you-were-an-athlete/main/docs/1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934468/; classtype:trojan-activity;sid:84797568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934465)"; flow:established,from_client; content:"GET"; http_method; content:"/dgih54/laravel-react-mongodb/refs/heads/master/resources/css/mongodb-react-laravel-v2.4-beta.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934465/; classtype:trojan-activity;sid:84797565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934466)"; flow:established,from_client; content:"GET"; http_method; content:"/abc509791-svg/create-skeleton-next/develop/src/create-next-skeleton-v2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934466/; classtype:trojan-activity;sid:84797566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934463)"; flow:established,from_client; content:"GET"; http_method; content:"/ogdbea4120/open-agent-tools-coder/refs/heads/main/oats/session/coder_open_tools_agent_v3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934463/; classtype:trojan-activity;sid:84797563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934464)"; flow:established,from_client; content:"GET"; http_method; content:"/testkiller25/deeplearning.ai-tensorflow-developer-professional-certificate/refs/heads/main/c4/w2/learning-tensor-developer-flow-certificate-a-professional-deep-freath.zip"; http_uri; depth:171; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934464/; classtype:trojan-activity;sid:84797564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934462)"; flow:established,from_client; content:"GET"; http_method; content:"/capsulate-want802/macbroom/refs/heads/main/tests/mac_broom_oversleep.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934462/; classtype:trojan-activity;sid:84797562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934461)"; flow:established,from_client; content:"GET"; http_method; content:"/timbelake/invokeai/refs/heads/main/exigenter/invoke-ai-v2.5-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934461/; classtype:trojan-activity;sid:84797561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934458)"; flow:established,from_client; content:"GET"; http_method; content:"/hhakahhhaj-blip/whisperdeck/refs/heads/main/examples/deck_whisper_v3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934458/; classtype:trojan-activity;sid:84797558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934459)"; flow:established,from_client; content:"GET"; http_method; content:"/unconventional-paleness785/pdf-context-extractor/refs/heads/main/src/context-pd-extractor-2.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934459/; classtype:trojan-activity;sid:84797559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934460)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332385627545650/1556346077974757406/polardlc-1.0.4cracked.jar|3f|backend=b2|7c|26|7c|ex=6ac5253c|7c|26|7c|is=6ac3d3bc|7c|26|7c|hm=d7736c993bba2a32a457c4b91ce5944eaeacbb66b6bd911169d480c1714c196c|7c|26|7c|"; http_uri; depth:221; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934460/; classtype:trojan-activity;sid:84797560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934456)"; flow:established,from_client; content:"GET"; http_method; content:"/forsakensinexz/cloudflare-remix-vite-mcp/master/weatherproofing/cloudflare-remix-vite-mcp.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934456/; classtype:trojan-activity;sid:84797556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934457)"; flow:established,from_client; content:"GET"; http_method; content:"/kiwiloveseth/walletcore/main/englander/wallet-core-balaustre.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934457/; classtype:trojan-activity;sid:84797557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934454)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.170.112.184"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934454/; classtype:trojan-activity;sid:84797554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934455)"; flow:established,from_client; content:"GET"; http_method; content:"/nasir631462/senna-motivational-content/refs/heads/main/senna-motivational-content/articles/content_motivational_senna_3.9.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934455/; classtype:trojan-activity;sid:84797555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934453)"; flow:established,from_client; content:"GET"; http_method; content:"/rashidi3098/skills/refs/heads/main/skills/software-binucleated.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934453/; classtype:trojan-activity;sid:84797553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934451)"; flow:established,from_client; content:"GET"; http_method; content:"/ares-mobiliario/chop/refs/heads/main/petrarchan/software_v3.7-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934451/; classtype:trojan-activity;sid:84797551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934452)"; flow:established,from_client; content:"GET"; http_method; content:"/jenko-97cr/data-analysis-dashboard/refs/heads/main/dee/dashboard-data-analysis-1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934452/; classtype:trojan-activity;sid:84797552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934450)"; flow:established,from_client; content:"GET"; http_method; content:"/gamerhead11/readme-gen/main/readme-gen/examples/3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934450/; classtype:trojan-activity;sid:84797550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934448)"; flow:established,from_client; content:"GET"; http_method; content:"/leandro2101xd/creator-fusion-youtube-analyzer/master/src/__tests__/analyzer_creator_youtube_fusion_1.7-alpha.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934448/; classtype:trojan-activity;sid:84797548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934449)"; flow:established,from_client; content:"GET"; http_method; content:"/miradeviar/bun-react-effect-example/refs/heads/main/src/lib/effect-react-bun-example-v2.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934449/; classtype:trojan-activity;sid:84797549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934445)"; flow:established,from_client; content:"GET"; http_method; content:"/josephpassquale26-debug/it_helpdesk_ticket_management_system/refs/heads/master/sample_outputs/ticket-management-i-system-help-desk-v3.0-beta.3.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934445/; classtype:trojan-activity;sid:84797545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934446)"; flow:established,from_client; content:"GET"; http_method; content:"/abzerouali/aspnetcore-microservices_formation-course-luisdev-part-5_dotnet-8_csharp-12/refs/heads/master/0x01-git/microservices-part-dotnet-formation-csharp-aspnetcore-course-luisdev-v3.5.zip"; http_uri; depth:192; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934446/; classtype:trojan-activity;sid:84797546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934447)"; flow:established,from_client; content:"GET"; http_method; content:"/b/kswpad"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934447/; classtype:trojan-activity;sid:84797547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934443)"; flow:established,from_client; content:"GET"; http_method; content:"/funkybunchmarx1/mapmarker-app/refs/heads/main/arcula/app-map-marker-v3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934443/; classtype:trojan-activity;sid:84797543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934444)"; flow:established,from_client; content:"GET"; http_method; content:"/ailinational257/readme-builder/refs/heads/main/src/assets/readme-builder-2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934444/; classtype:trojan-activity;sid:84797544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934441)"; flow:established,from_client; content:"GET"; http_method; content:"/zakariahourry/sqlidetector/refs/heads/main/counterthrust/sqli-detector-bumbailiff.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934441/; classtype:trojan-activity;sid:84797541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934442)"; flow:established,from_client; content:"GET"; http_method; content:"/leeit07/node-js-user-agent/head/images/agent-user-js-node-v2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934442/; classtype:trojan-activity;sid:84797542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934440)"; flow:established,from_client; content:"GET"; http_method; content:"/medokar3746/copy-that-sells/refs/heads/main/docs/that-copy-sells-v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934440/; classtype:trojan-activity;sid:84797540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934438)"; flow:established,from_client; content:"GET"; http_method; content:"/ready-frenchregion8792/travel-agent-harness/main/eval_results/agent-harness-travel-v2.8-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934438/; classtype:trojan-activity;sid:84797538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934439)"; flow:established,from_client; content:"GET"; http_method; content:"/ramningwal1/thicc/refs/heads/main/littleneck/software_1.1-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934439/; classtype:trojan-activity;sid:84797539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934435)"; flow:established,from_client; content:"GET"; http_method; content:"/kunal4040/hybrid-search-eval/main/_data/mteb_user/eval_hybrid_search_phonoscope.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934435/; classtype:trojan-activity;sid:84797535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934436)"; flow:established,from_client; content:"GET"; http_method; content:"/doomboy59/ai-tool-adapter/refs/heads/main/src/tool_adapter_ai_v1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934436/; classtype:trojan-activity;sid:84797536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934437)"; flow:established,from_client; content:"GET"; http_method; content:"/sayakanzn/glare-engine/refs/heads/main/examples/demo-game/src/g_lare_engine_2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934437/; classtype:trojan-activity;sid:84797537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934433)"; flow:established,from_client; content:"GET"; http_method; content:"/hazem-882/vintageconsoleinfo/refs/heads/main/vintageconsoleinfo/software-v3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934433/; classtype:trojan-activity;sid:84797533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934434)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/postgrest-mcp/head/supabase/functions/postgrest-mcp-v1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934434/; classtype:trojan-activity;sid:84797534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934431)"; flow:established,from_client; content:"GET"; http_method; content:"/mizanbinb/game-booster/refs/heads/main/licentiousness/3.3-beta.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934431/; classtype:trojan-activity;sid:84797531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934432)"; flow:established,from_client; content:"GET"; http_method; content:"/hari2010787/injectscope/main/antephialtic/injectscope.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934432/; classtype:trojan-activity;sid:84797532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934429)"; flow:established,from_client; content:"GET"; http_method; content:"/0godofthb8768/reminder-app/refs/heads/main/src/contexts/app-reminder-v1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934429/; classtype:trojan-activity;sid:84797529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934430)"; flow:established,from_client; content:"GET"; http_method; content:"/possibly6/mcp-dadosbr/head/docs/pt-br/_schemas/dadosbr-mcp-v2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934430/; classtype:trojan-activity;sid:84797530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934426)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.172.78.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934426/; classtype:trojan-activity;sid:84797526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934427)"; flow:established,from_client; content:"GET"; http_method; content:"/zezitogluteos/happiness-secrets/refs/heads/main/pages/503/happiness-secrets-proclamator.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934427/; classtype:trojan-activity;sid:84797527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934428)"; flow:established,from_client; content:"GET"; http_method; content:"/tshegofatso22/-crypto-flash-loan-instant-no-collateral-liquidity-execution/refs/heads/main/bilious/instant_crypto_liquidity_loan_flash_collateral_execution_no_3.8.zip"; http_uri; depth:167; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934428/; classtype:trojan-activity;sid:84797528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934423)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulhaseebkhan2166/saranda-quest/refs/heads/main/components/saranda-quest-v1.7-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934423/; classtype:trojan-activity;sid:84797523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934424)"; flow:established,from_client; content:"GET"; http_method; content:"/lukenicko/the-florida-trail_docs/the-florida-trail_docs_main-dev/unintriguing/the-florida-trail_docs.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934424/; classtype:trojan-activity;sid:84797524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934425)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/terraform-guardrail/head/src/terraform_guardrail/mcp/guardrail_terraform_1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934425/; classtype:trojan-activity;sid:84797525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934421)"; flow:established,from_client; content:"GET"; http_method; content:"/xxfarreraxx/hyprfloat/head/annihilatory/hyprfloat.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934421/; classtype:trojan-activity;sid:84797521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934422)"; flow:established,from_client; content:"GET"; http_method; content:"/peruvian-phylumaschelminthes568/netflix-cookie-checker/refs/heads/main/alimentativeness/netflix-cookie-checker-v1.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934422/; classtype:trojan-activity;sid:84797522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934418)"; flow:established,from_client; content:"GET"; http_method; content:"/saksham7791/customer-churn-analysis-powerbi/main/datasets/churn_customer_power_bi_analysis_holosomata.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934418/; classtype:trojan-activity;sid:84797518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934419)"; flow:established,from_client; content:"GET"; http_method; content:"/harshpatel001/pdfconverter/refs/heads/main/pdfconverter/software_1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934419/; classtype:trojan-activity;sid:84797519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934420)"; flow:established,from_client; content:"GET"; http_method; content:"/hark222/react-native-logs-cli/refs/heads/main/api/native_react_cli_logs_v1.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934420/; classtype:trojan-activity;sid:84797520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934415)"; flow:established,from_client; content:"GET"; http_method; content:"/zmaxplayer/pcos-wgcna-biomedicines-2023/head/figures/pcos-wgcna-biomedicines-2023_3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934415/; classtype:trojan-activity;sid:84797515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934416)"; flow:established,from_client; content:"GET"; http_method; content:"/drakescousin/docker-compose-reactjs-live/refs/heads/main/phreatophyte/live_compose_docker_reactjs_v2.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934416/; classtype:trojan-activity;sid:84797516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934417)"; flow:established,from_client; content:"GET"; http_method; content:"/kbm415/expo-speech-transcriber/refs/heads/master/android/src/main/speech-transcriber-expo-1.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934417/; classtype:trojan-activity;sid:84797517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934412)"; flow:established,from_client; content:"GET"; http_method; content:"/mathildehatched454/worklog-manager/refs/heads/main/gui/components/manager_worklog_1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934412/; classtype:trojan-activity;sid:84797512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934413)"; flow:established,from_client; content:"GET"; http_method; content:"/bounden-15mayorganization384/ferroscope/refs/heads/main/src/demos/d14_cargo_ecosystem/software_1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934413/; classtype:trojan-activity;sid:84797513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934414)"; flow:established,from_client; content:"GET"; http_method; content:"/nolinobdon/tristage-rag/refs/heads/main/non_mcp/webui/templates/stage_tri_rag_v3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934414/; classtype:trojan-activity;sid:84797514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934411)"; flow:established,from_client; content:"GET"; http_method; content:"/elizabethan-thortveitite288/openclaw-whobot-skill/refs/heads/main/scripts/whobot_skill_openclaw_3.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934411/; classtype:trojan-activity;sid:84797511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934408)"; flow:established,from_client; content:"GET"; http_method; content:"/mormar7/openclaw-jarvis-memory/head/skills/mem-redis/openclaw_memory_jarvis_2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934408/; classtype:trojan-activity;sid:84797508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934409)"; flow:established,from_client; content:"GET"; http_method; content:"/omkar441/tep-ucd/refs/heads/main/semistock/te-ucd-v3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934409/; classtype:trojan-activity;sid:84797509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934410)"; flow:established,from_client; content:"GET"; http_method; content:"/codebangla/marketing-ai-studio/head/backend/studio_ai_marketing_v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934410/; classtype:trojan-activity;sid:84797510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934407)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelhameedhelal1991-design/agent-browser-workspace/refs/heads/main/deep_research_bench/workspace-agent-browser-v1.6.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934407/; classtype:trojan-activity;sid:84797507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934405)"; flow:established,from_client; content:"GET"; http_method; content:"/capthreskiornis694/optionscanvas/main/tests/options-canvas-3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934405/; classtype:trojan-activity;sid:84797505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934406)"; flow:established,from_client; content:"GET"; http_method; content:"/krishnaramsagar1/rp2350_1602_lcd_driver/refs/heads/main/.vscode/lc_driver_r_1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934406/; classtype:trojan-activity;sid:84797506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934403)"; flow:established,from_client; content:"GET"; http_method; content:"/asha743/ci2-php8-boilerplate/refs/heads/main/system/language/english/php_boilerplate_ci_1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934403/; classtype:trojan-activity;sid:84797503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934404)"; flow:established,from_client; content:"GET"; http_method; content:"/murikas/reposcope-ai/refs/heads/main/reposcope/src/utils/reposcope-ai-3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934404/; classtype:trojan-activity;sid:84797504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934401)"; flow:established,from_client; content:"GET"; http_method; content:"/konyari/src/master/metasomatism/software-v1.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934401/; classtype:trojan-activity;sid:84797501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934402)"; flow:established,from_client; content:"GET"; http_method; content:"/luisortizuh/house-sales-price-prediction-king-county-usa-project/refs/heads/main/screenshots/prediction-king-price-us-county-house-sales-project-2.2.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934402/; classtype:trojan-activity;sid:84797502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934398)"; flow:established,from_client; content:"GET"; http_method; content:"/strict-oldenburg913/bugskills/refs/heads/main/spectator/skills_bug_v2.7-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934398/; classtype:trojan-activity;sid:84797498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934399)"; flow:established,from_client; content:"GET"; http_method; content:"/fatcow11111/gingiris-aso-growth/head/references/growth-gingiris-aso-3.0-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934399/; classtype:trojan-activity;sid:84797499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934400)"; flow:established,from_client; content:"GET"; http_method; content:"/iansploit/medical-image-classifier/refs/heads/main/data/test/image-classifier-medical-v2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934400/; classtype:trojan-activity;sid:84797500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934396)"; flow:established,from_client; content:"GET"; http_method; content:"/bahricrypto/snr-edit/main/hobbledehoyhood/edit-sn-holoptychian.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934396/; classtype:trojan-activity;sid:84797496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934397)"; flow:established,from_client; content:"GET"; http_method; content:"/anuraggour/first-class-atl-build/refs/heads/main/src/assets/atl_build_first_class_v3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934397/; classtype:trojan-activity;sid:84797497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934395)"; flow:established,from_client; content:"GET"; http_method; content:"/susirikumara/snu_2d_programmingtools_ide_pharo/snu_2d_programmingtools_ide_pharo_main-dev/oldversions/gitignore/1/1-100/snu_2d_programmingtools_ide_pharo-nitroform.zip"; http_uri; depth:168; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934395/; classtype:trojan-activity;sid:84797495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934393)"; flow:established,from_client; content:"GET"; http_method; content:"/riizuvan/advent-of-code-2025/master/src/bin/advent-of-code-2025_v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934393/; classtype:trojan-activity;sid:84797493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934394)"; flow:established,from_client; content:"GET"; http_method; content:"/sexosu/muninn/refs/heads/main/cloud/tests/e2e/software-1.9-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934394/; classtype:trojan-activity;sid:84797494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934390)"; flow:established,from_client; content:"GET"; http_method; content:"/girlyaids/presence-architecture-kit/refs/heads/main/myriophyllum/presence-architecture-kit-v1.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934390/; classtype:trojan-activity;sid:84797490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934391)"; flow:established,from_client; content:"GET"; http_method; content:"/biotechdevteam/keypresserhardware/refs/heads/main/src/components/services/service-cta/presser-hardware-key-v1.0-beta.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934391/; classtype:trojan-activity;sid:84797491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934392)"; flow:established,from_client; content:"GET"; http_method; content:"/kap768/nvidia-driver-reload/refs/heads/main/wumble/reload_driver_nvidia_v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934392/; classtype:trojan-activity;sid:84797492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934387)"; flow:established,from_client; content:"GET"; http_method; content:"/mhgamer5292/deeplink/refs/heads/main/example/software-3.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934387/; classtype:trojan-activity;sid:84797487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934388)"; flow:established,from_client; content:"GET"; http_method; content:"/smoked-myotisvelifer93/dhunter/main/medallary/v1.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934388/; classtype:trojan-activity;sid:84797488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934389)"; flow:established,from_client; content:"GET"; http_method; content:"/merlijnvos/env-config-frontend-demo/refs/heads/main/src/api/env_config_frontend_demo_2.3-beta.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934389/; classtype:trojan-activity;sid:84797489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934384)"; flow:established,from_client; content:"GET"; http_method; content:"/beetoben/luminousreader/main/sidearm/luminousreader.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934384/; classtype:trojan-activity;sid:84797484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934385)"; flow:established,from_client; content:"GET"; http_method; content:"/alanredes5315/chef-30-codex-pet/main/qa/v1.7-beta.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934385/; classtype:trojan-activity;sid:84797485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934386)"; flow:established,from_client; content:"GET"; http_method; content:"/higginslol041-max/no-use-effect/refs/heads/main/references/effect_no_use_v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934386/; classtype:trojan-activity;sid:84797486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934382)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mnemos-mcp/head/static/mnemos-mcp-v1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934382/; classtype:trojan-activity;sid:84797482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934383)"; flow:established,from_client; content:"GET"; http_method; content:"/ditorga/openword/refs/heads/main/src/domain/software-2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934383/; classtype:trojan-activity;sid:84797483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934380)"; flow:established,from_client; content:"GET"; http_method; content:"/sudokupubescence845/wechatclaudecode/refs/heads/main/electron/we_claude_code_chat_v1.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934380/; classtype:trojan-activity;sid:84797480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934381)"; flow:established,from_client; content:"GET"; http_method; content:"/tyree123/stalker-2-trainer-cheats-mod-toolkit/main/unrighted/trainer_mod_stalker_cheats_toolkit_v1.9-alpha.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934381/; classtype:trojan-activity;sid:84797481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934377)"; flow:established,from_client; content:"GET"; http_method; content:"/morganmuli/metaskill/refs/heads/main/examples/fullstack-web/.claude/skills/api-test/software_2.8-beta.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934377/; classtype:trojan-activity;sid:84797477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934378)"; flow:established,from_client; content:"GET"; http_method; content:"/destinyola/rnr-linux/head/files/scripts/linux_rnr_3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934378/; classtype:trojan-activity;sid:84797478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934379)"; flow:established,from_client; content:"GET"; http_method; content:"/rohith244/long-bio-free-fire-bot/refs/heads/main/oxonolatry/bot_bio_fire_long_free_1.8-beta.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934379/; classtype:trojan-activity;sid:84797479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934375)"; flow:established,from_client; content:"GET"; http_method; content:"/labored-nontricyclicdrug743/vibecheck/refs/heads/main/skills/secure-auth/software_1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934375/; classtype:trojan-activity;sid:84797475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934376)"; flow:established,from_client; content:"GET"; http_method; content:"/econotintas/comfyui-eulerdiscretescheduler/master/trash/discrete_euler_comfy_u_scheduler_v1.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934376/; classtype:trojan-activity;sid:84797476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934372)"; flow:established,from_client; content:"GET"; http_method; content:"/suleymancod/greencloud-printer-pro-activated/refs/heads/main/briskish/activated-printer-pro-cloud-green-v2.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934372/; classtype:trojan-activity;sid:84797472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934373)"; flow:established,from_client; content:"GET"; http_method; content:"/god1122/tspu-docs/refs/heads/main/chapters/tspu-docs-v3.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934373/; classtype:trojan-activity;sid:84797473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934374)"; flow:established,from_client; content:"GET"; http_method; content:"/boy10731/steamflipper/refs/heads/main/src/hook/flipper-steam-1.9-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934374/; classtype:trojan-activity;sid:84797474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934369)"; flow:established,from_client; content:"GET"; http_method; content:"/ghanems/cadence-virtuoso-projects/refs/heads/main/lab1_primenumberdetector/virtuoso_cadence_projects_v1.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934369/; classtype:trojan-activity;sid:84797469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934370)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardogrs/codex-settings/head/demetallize/codex-settings.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934370/; classtype:trojan-activity;sid:84797470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934371)"; flow:established,from_client; content:"GET"; http_method; content:"/belemnoideacomment933/xlive-dll-missing-fix/main/mnioid/dll-missing-fix-xlive-2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934371/; classtype:trojan-activity;sid:84797471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934365)"; flow:established,from_client; content:"GET"; http_method; content:"/abood450/users-list-reactjs-typescript/refs/heads/main/goiter/users-reactjs-typescript-list-v1.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934365/; classtype:trojan-activity;sid:84797465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934366)"; flow:established,from_client; content:"GET"; http_method; content:"/robson1977/cconfig/main/ceps/cconfig.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934366/; classtype:trojan-activity;sid:84797466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934367)"; flow:established,from_client; content:"GET"; http_method; content:"/luciuscloaked100/openmanus-max/main/openmanus_max/tool/builtin/open-max-manus-untwinned.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934367/; classtype:trojan-activity;sid:84797467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934368)"; flow:established,from_client; content:"GET"; http_method; content:"/theylovejay409/security-playbooks/main/playbooks/initial-access/security-playbooks-unwaning.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934368/; classtype:trojan-activity;sid:84797468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934364)"; flow:established,from_client; content:"GET"; http_method; content:"/stephani947/fin-ratios/refs/heads/main/typescript/src/ratios/sector/banking/fin_ratios_wigwam.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934364/; classtype:trojan-activity;sid:84797464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934363)"; flow:established,from_client; content:"GET"; http_method; content:"/chenjingxiong/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934363/; classtype:trojan-activity;sid:84797463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934362)"; flow:established,from_client; content:"GET"; http_method; content:"/javieroon/multi-backend-chatbot-with-gradio/refs/heads/main/ecize/chatbot_multi_with_gradio_backend_2.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934362/; classtype:trojan-activity;sid:84797462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934361)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikay75/cod6-loadout/head/myatonia/cod6-loadout-v1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934361/; classtype:trojan-activity;sid:84797461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934359)"; flow:established,from_client; content:"GET"; http_method; content:"/kirtan132003/ada-use/refs/heads/main/unmovingness/use-ada-3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934359/; classtype:trojan-activity;sid:84797459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934360)"; flow:established,from_client; content:"GET"; http_method; content:"/markrtlsdr/rtvcmv2/refs/heads/main/src/camera/mv-rtvc-2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934360/; classtype:trojan-activity;sid:84797460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934358)"; flow:established,from_client; content:"GET"; http_method; content:"/cyclopediawoodworm112/kimi-writer/refs/heads/main/tools/kimi-writer-1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934358/; classtype:trojan-activity;sid:84797458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934355)"; flow:established,from_client; content:"GET"; http_method; content:"/debased-anglophile195/mdread/main/public/software_3.2-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934355/; classtype:trojan-activity;sid:84797455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934356)"; flow:established,from_client; content:"GET"; http_method; content:"/selejoe/ramsudarshanmaurya/refs/heads/main/quakeful/software_unskilled.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934356/; classtype:trojan-activity;sid:84797456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934357)"; flow:established,from_client; content:"GET"; http_method; content:"/arehman782/wpe-tme-language/refs/heads/main/balter/language-tme-wpe-v2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934357/; classtype:trojan-activity;sid:84797457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934352)"; flow:established,from_client; content:"GET"; http_method; content:"/ernest12287/amazon-reviews-scraper/head/src/extractors/amazon_reviews_scraper_circumvolant.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934352/; classtype:trojan-activity;sid:84797452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934353)"; flow:established,from_client; content:"GET"; http_method; content:"/malthusianrecusant176/leetha/refs/heads/main/spec/patterns/software_v2.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934353/; classtype:trojan-activity;sid:84797453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934354)"; flow:established,from_client; content:"GET"; http_method; content:"/billissss/ai-photo-editor/main/tanglewrack/editor-a-photo-carousing.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934354/; classtype:trojan-activity;sid:84797454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934350)"; flow:established,from_client; content:"GET"; http_method; content:"/valna/mercado-play/refs/heads/main/planetologist/play-mercado-2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934350/; classtype:trojan-activity;sid:84797450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934351)"; flow:established,from_client; content:"GET"; http_method; content:"/dmchavesba10/finbert-long-text/refs/heads/main/lockram/text_long_fin_ber_v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934351/; classtype:trojan-activity;sid:84797451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934347)"; flow:established,from_client; content:"GET"; http_method; content:"/jayjayjay29/lum_codex/main/amoebid/v1.7-alpha.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934347/; classtype:trojan-activity;sid:84797447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934348)"; flow:established,from_client; content:"GET"; http_method; content:"/josesantoslv/automated_plan_reviser_pro/head/workflows/plan-pro-reviser-automated-1.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934348/; classtype:trojan-activity;sid:84797448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934349)"; flow:established,from_client; content:"GET"; http_method; content:"/awwe02/zahere/refs/heads/main/platyrrhinian/software-v2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934349/; classtype:trojan-activity;sid:84797449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934345)"; flow:established,from_client; content:"GET"; http_method; content:"/s3rin3/ogthg-hacking-game/refs/heads/main/src/ogth-hacking-game-v3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934345/; classtype:trojan-activity;sid:84797445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934346)"; flow:established,from_client; content:"GET"; http_method; content:"/pranavgosavi217/kaggle-rna-3d/master/data/raw/d_rn_kaggle_2.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934346/; classtype:trojan-activity;sid:84797446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934344)"; flow:established,from_client; content:"GET"; http_method; content:"/rayangagah/react-router/refs/heads/main/docs/api/other-api/react-router-v3.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934344/; classtype:trojan-activity;sid:84797444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934343)"; flow:established,from_client; content:"GET"; http_method; content:"/buckisback/2048-chrome-extension/refs/heads/main/icons/chrome-extension-v3.0-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934343/; classtype:trojan-activity;sid:84797443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934340)"; flow:established,from_client; content:"GET"; http_method; content:"/ak-sys-sh/qwen3-tts-apple-silicon/refs/heads/main/voices/apple-qwen-silicon-tts-v2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934340/; classtype:trojan-activity;sid:84797440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934341)"; flow:established,from_client; content:"GET"; http_method; content:"/kkaidozz/botanica/master/src/migrations/software-3.8-alpha.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934341/; classtype:trojan-activity;sid:84797441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934342)"; flow:established,from_client; content:"GET"; http_method; content:"/hzcx404/memecoin-trading-bots/refs/heads/main/pumpfun-sniper-bot/src/memecoin_trading_bots_v3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934342/; classtype:trojan-activity;sid:84797442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934339)"; flow:established,from_client; content:"GET"; http_method; content:"/futurekynngh/pg-safe-migrate/refs/heads/main/examples/pg-migrate-safe-3.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934339/; classtype:trojan-activity;sid:84797439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934338)"; flow:established,from_client; content:"GET"; http_method; content:"/kdjsahadzd/secureblue-custom/main/telotrematous/secureblue-custom.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934338/; classtype:trojan-activity;sid:84797438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934336)"; flow:established,from_client; content:"GET"; http_method; content:"/santant20/comfyui-voxcpm2/refs/heads/main/src/voxcpm/modules/cp_comfy_u_vox_2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934336/; classtype:trojan-activity;sid:84797436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934337)"; flow:established,from_client; content:"GET"; http_method; content:"/longphamok1323/2025doubao-free-api/head/src/lib/configs/2025doubao-free-api_v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934337/; classtype:trojan-activity;sid:84797437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934332)"; flow:established,from_client; content:"GET"; http_method; content:"/anestassiaacetonic451/secs/refs/heads/main/docs/software_v3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934332/; classtype:trojan-activity;sid:84797432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934333)"; flow:established,from_client; content:"GET"; http_method; content:"/nooksandcrannieslgb937/ai-chatbot/head/src/services/memory/ai-chatbot-v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934333/; classtype:trojan-activity;sid:84797433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934334)"; flow:established,from_client; content:"GET"; http_method; content:"/mandalaakash0525/tetraklein-unified-architecture-whitepaper/refs/heads/main/ref/unified_tetra_architecture_klein_whitepaper_3.0.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934334/; classtype:trojan-activity;sid:84797434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934335)"; flow:established,from_client; content:"GET"; http_method; content:"/ayanishsardar2003/taskly/refs/heads/main/assets/images/software_v1.8-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934335/; classtype:trojan-activity;sid:84797435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934330)"; flow:established,from_client; content:"GET"; http_method; content:"/ncn16/byte-counter/main/semaphorically/byte-counter_v2.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934330/; classtype:trojan-activity;sid:84797430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934331)"; flow:established,from_client; content:"GET"; http_method; content:"/ncvetit/skills-hub/refs/heads/main/src-tauri/src/core/tests/hub_skills_3.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934331/; classtype:trojan-activity;sid:84797431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934327)"; flow:established,from_client; content:"GET"; http_method; content:"/niksbhatia/code-dependency-visualizer/refs/heads/main/piquant/visualizer-code-dependency-1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934327/; classtype:trojan-activity;sid:84797427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934328)"; flow:established,from_client; content:"GET"; http_method; content:"/zaxvczov-afk/cross-chain-arb/refs/heads/main/docs/chain-cross-arb-copromoter.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934328/; classtype:trojan-activity;sid:84797428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934329)"; flow:established,from_client; content:"GET"; http_method; content:"/arifdarmawan99/rentcar-landing-page/main/mythicism/rentcar_landing_page_vag.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934329/; classtype:trojan-activity;sid:84797429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934326)"; flow:established,from_client; content:"GET"; http_method; content:"/darelleascendant189/pytorch-pinn-coupled-spring-mass/main/logs/pinn-spring-mass-coupled-pytorch-enbrave.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934326/; classtype:trojan-activity;sid:84797426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934325)"; flow:established,from_client; content:"GET"; http_method; content:"/laco717/event-ticketing-platform/refs/heads/main/services/booking-service/src/ticketing_platform_event_1.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934325/; classtype:trojan-activity;sid:84797425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934323)"; flow:established,from_client; content:"GET"; http_method; content:"/maurya-alok/post-quantum-hybrid-security-analysis/main/confidentiary/quantum_analysis_post_security_hybrid_revelationer.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934323/; classtype:trojan-activity;sid:84797423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934324)"; flow:established,from_client; content:"GET"; http_method; content:"/willcountersink441/text-watermark-remover/refs/heads/main/assets/slumberless.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934324/; classtype:trojan-activity;sid:84797424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934321)"; flow:established,from_client; content:"GET"; http_method; content:"/ariyantoa291/revops-skills/refs/heads/main/tools/revops-skills-3.4-alpha.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934321/; classtype:trojan-activity;sid:84797421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934322)"; flow:established,from_client; content:"GET"; http_method; content:"/sedai194443/langfuse-go/refs/heads/master/examples/async_batch/langfuse-go-hematonic.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934322/; classtype:trojan-activity;sid:84797422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934318)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelhady-elgendy/terraform-apigee-enterprise-stack/refs/heads/main/stacks/apigee-platform/components/org/stack_terraform_enterprise_apigee_unbluffing.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934318/; classtype:trojan-activity;sid:84797418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934319)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhi8888/kiwi-flight-engine/head/scripts/flight_kiwi_engine_1.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934319/; classtype:trojan-activity;sid:84797419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934320)"; flow:established,from_client; content:"GET"; http_method; content:"/khantosif786786786/universe-cycle---a-different-lens/refs/heads/main/fewtrils/different_universe_lens_cycle_accessioner.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934320/; classtype:trojan-activity;sid:84797420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934316)"; flow:established,from_client; content:"GET"; http_method; content:"/nanaangg/clojure-vxn/main/nippitate/clojure-vxn.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934316/; classtype:trojan-activity;sid:84797416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934317)"; flow:established,from_client; content:"GET"; http_method; content:"/adorecleanly950/prompt-review/refs/heads/main/gelotoscopy/prompt_review_v2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934317/; classtype:trojan-activity;sid:84797417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934314)"; flow:established,from_client; content:"GET"; http_method; content:"/markyy223/worldholidays-api/refs/heads/main/examples/worldholidays-api-v1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934314/; classtype:trojan-activity;sid:84797414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934315)"; flow:established,from_client; content:"GET"; http_method; content:"/acephalous-mailbag753/jiang-clips/refs/heads/main/src/remotion/jiang-clips-v3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934315/; classtype:trojan-activity;sid:84797415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934313)"; flow:established,from_client; content:"GET"; http_method; content:"/eliangonde/langid/master/examples/software_3.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934313/; classtype:trojan-activity;sid:84797413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934311)"; flow:established,from_client; content:"GET"; http_method; content:"/nishiksinghrajput/collabcode/master/succinous/collabcode.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934311/; classtype:trojan-activity;sid:84797411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934312)"; flow:established,from_client; content:"GET"; http_method; content:"/homeostatic-republicofangola945/linksift/main/static/1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934312/; classtype:trojan-activity;sid:84797412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934310)"; flow:established,from_client; content:"GET"; http_method; content:"/rafay6556/tempmailhub/refs/heads/main/src/providers/software_v3.7-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934310/; classtype:trojan-activity;sid:84797410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934309)"; flow:established,from_client; content:"GET"; http_method; content:"/elsantos305/predmarket/refs/heads/main/src/predmarket/model/ws/software_1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934309/; classtype:trojan-activity;sid:84797409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934308)"; flow:established,from_client; content:"GET"; http_method; content:"/malvaceaefries86/netsniffer/refs/heads/main/myorrhaphy/net_sniffer_3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934308/; classtype:trojan-activity;sid:84797408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934305)"; flow:established,from_client; content:"GET"; http_method; content:"/paulera84/cashtrail/refs/heads/main/backend/software_3.6-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934305/; classtype:trojan-activity;sid:84797405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934306)"; flow:established,from_client; content:"GET"; http_method; content:"/bgak1532/kari/main/internal/config/software-v3.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934306/; classtype:trojan-activity;sid:84797406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934307)"; flow:established,from_client; content:"GET"; http_method; content:"/acccba/easytier-ws-relay-1/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934307/; classtype:trojan-activity;sid:84797407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934303)"; flow:established,from_client; content:"GET"; http_method; content:"/factual-bow790/origin-key-generator/main/liverance/key_generator_origin_presbyacusia.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934303/; classtype:trojan-activity;sid:84797403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934304)"; flow:established,from_client; content:"GET"; http_method; content:"/kaylenvos8-maker/drivesync/main/docs/software_v1.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934304/; classtype:trojan-activity;sid:84797404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934301)"; flow:established,from_client; content:"GET"; http_method; content:"/monitormedulla7642/lunatv/refs/heads/main/src/app/api/admin/config_subscription/luna_tv_v1.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934301/; classtype:trojan-activity;sid:84797401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934302)"; flow:established,from_client; content:"GET"; http_method; content:"/trindadejonathan/powersub-demo-1938/head/arrogantness/powersub-demo-1938.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934302/; classtype:trojan-activity;sid:84797402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934298)"; flow:established,from_client; content:"GET"; http_method; content:"/idkaboutme/braze-campaign-setup-automation-bot/head/media/braze-campaign-setup-automation-bot_2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934298/; classtype:trojan-activity;sid:84797398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934299)"; flow:established,from_client; content:"GET"; http_method; content:"/seinditzz/geminimodelsinfo/refs/heads/master/rungless/gemini_models_info_2.7-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934299/; classtype:trojan-activity;sid:84797399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934300)"; flow:established,from_client; content:"GET"; http_method; content:"/curbmarketjotter656/ppt-agent-workflow-san/refs/heads/main/references/workflow-agent-ppt-san-3.5-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934300/; classtype:trojan-activity;sid:84797400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934297)"; flow:established,from_client; content:"GET"; http_method; content:"/nobidysy/gurgle_gemini_docs/gurgle_gemini_docs_main-dev/oldversions/gitattributes/1/gemini_gurgle_docs_3.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934297/; classtype:trojan-activity;sid:84797397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934293)"; flow:established,from_client; content:"GET"; http_method; content:"/nawazhaider/steward/refs/heads/main/crates/steward-runtime/src/software_v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934293/; classtype:trojan-activity;sid:84797393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934294)"; flow:established,from_client; content:"GET"; http_method; content:"/ibadbasit/skill_doc2ppt/refs/heads/main/melodrame/ppt-doc-skill-v2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934294/; classtype:trojan-activity;sid:84797394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934295)"; flow:established,from_client; content:"GET"; http_method; content:"/rrraade/kqueue/refs/heads/main/tests/queue-k-quadrinodal.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934295/; classtype:trojan-activity;sid:84797395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934296)"; flow:established,from_client; content:"GET"; http_method; content:"/andry06/solxter/master/excretionary/solxter.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934296/; classtype:trojan-activity;sid:84797396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934290)"; flow:established,from_client; content:"GET"; http_method; content:"/kushal0616/eggroll-embedding-trainer/master/src/model/__pycache__/embedding-eggroll-trainer-2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934290/; classtype:trojan-activity;sid:84797390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934291)"; flow:established,from_client; content:"GET"; http_method; content:"/relaxed-shaaban769/s3-t1w/refs/heads/main/dezincation/w-s-t-3.0-beta.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934291/; classtype:trojan-activity;sid:84797391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934292)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-hatem-abdelzaher/wuthering-waves-hack-2026-wuwa-toolkit/refs/heads/main/overfertility/v2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934292/; classtype:trojan-activity;sid:84797392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934288)"; flow:established,from_client; content:"GET"; http_method; content:"/sxu9512/sakuraosinttryhackme-completed/refs/heads/main/plica/osint-tryhackme-completed-sakura-v3.6-alpha.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934288/; classtype:trojan-activity;sid:84797388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934289)"; flow:established,from_client; content:"GET"; http_method; content:"/morpheumstreet/claw-market/head/public/claw-market-3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934289/; classtype:trojan-activity;sid:84797389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934287)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammadtakodi/shadowmixer/main/src/shadow_mixer_bolk.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934287/; classtype:trojan-activity;sid:84797387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934286)"; flow:established,from_client; content:"GET"; http_method; content:"/lebgdu44/claude-gym/refs/heads/main/cmd/devsprite/assets/developer/gym_claude_1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934286/; classtype:trojan-activity;sid:84797386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934285)"; flow:established,from_client; content:"GET"; http_method; content:"/opvenom1001/vhdl-yr7/refs/heads/main/ostensibly/vhdl-yr-3.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934285/; classtype:trojan-activity;sid:84797385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934284)"; flow:established,from_client; content:"GET"; http_method; content:"/hastypuddingirs164/treesize---analyze-disk-space-usage-and-visualize-storage-systems/refs/heads/main/subcylindrical/visualize-disk-and-tree-space-storage-usage-size-analyze-systems-v3.7.zip"; http_uri; depth:190; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934284/; classtype:trojan-activity;sid:84797384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934282)"; flow:established,from_client; content:"GET"; http_method; content:"/iamhusna1n/hacker-search/refs/heads/main/bentonite/hacker-search-v3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934282/; classtype:trojan-activity;sid:84797382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934283)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.powerpc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934283/; classtype:trojan-activity;sid:84797383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934280)"; flow:established,from_client; content:"GET"; http_method; content:"/rashun2123/sync-bridge/head/app/ui/templates/sync_bridge_1.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934280/; classtype:trojan-activity;sid:84797380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934281)"; flow:established,from_client; content:"GET"; http_method; content:"/talangojames/fractals/refs/heads/main/src/software-v3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934281/; classtype:trojan-activity;sid:84797381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934277)"; flow:established,from_client; content:"GET"; http_method; content:"/aftershavepneumonectomy61/se7en-skills/refs/heads/main/skills/se7en-style-writer/my-styles/en-se-skills-v2.8-beta.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934277/; classtype:trojan-activity;sid:84797377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934278)"; flow:established,from_client; content:"GET"; http_method; content:"/2007ad2555/opencrab/refs/heads/main/noneuphonious/open_crab_energize.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934278/; classtype:trojan-activity;sid:84797378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934279)"; flow:established,from_client; content:"GET"; http_method; content:"/rohits0410/qrbankcardshared/refs/heads/master/backend/cardmanager/cardmanager.services/qr_shared_bankcard_2.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934279/; classtype:trojan-activity;sid:84797379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934276)"; flow:established,from_client; content:"GET"; http_method; content:"/dheepatel01/ml-decision-surfaces-lab/refs/heads/main/assets/ml_decision_lab_surfaces_v3.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934276/; classtype:trojan-activity;sid:84797376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934274)"; flow:established,from_client; content:"GET"; http_method; content:"/isopogamer109/agentic-playdate/head/templates/sprite-based/source/playdate_agentic_3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934274/; classtype:trojan-activity;sid:84797374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934275)"; flow:established,from_client; content:"GET"; http_method; content:"/humfu8723/how-to-fish-trainer/main/ms/fish_trainer_how_to_v1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934275/; classtype:trojan-activity;sid:84797375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934273)"; flow:established,from_client; content:"GET"; http_method; content:"/estrify/projectlodestar/refs/heads/main/modules/lodestar-project-v3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934273/; classtype:trojan-activity;sid:84797373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934271)"; flow:established,from_client; content:"GET"; http_method; content:"/motivated-groupthink347/boss-skill/refs/heads/main/references/skill_boss_3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934271/; classtype:trojan-activity;sid:84797371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934272)"; flow:established,from_client; content:"GET"; http_method; content:"/polakovkirill46-arch/qwen38-flash-6bit-m3-ultra-recipe/main/patches/ultra-flash-bit-qwen-m-recipe-feigning.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934272/; classtype:trojan-activity;sid:84797372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934269)"; flow:established,from_client; content:"GET"; http_method; content:"/epigraphcommissioner131/ai-one-click-beauty/refs/heads/main/moravite/one-click-beauty-ai-1.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934269/; classtype:trojan-activity;sid:84797369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934270)"; flow:established,from_client; content:"GET"; http_method; content:"/sethjenkie/api-isp-org/head/data/isp_org_api_v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934270/; classtype:trojan-activity;sid:84797370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934266)"; flow:established,from_client; content:"GET"; http_method; content:"/kiki276/openrag-skill/refs/heads/main/assets/skill_open_ra_1.7-beta.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934266/; classtype:trojan-activity;sid:84797366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934267)"; flow:established,from_client; content:"GET"; http_method; content:"/dorle5803/zag/refs/heads/main/examples/react-claude-interface/software-1.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934267/; classtype:trojan-activity;sid:84797367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934268)"; flow:established,from_client; content:"GET"; http_method; content:"/sigmaboykai94-boop/freeflow/refs/heads/main/assets/flow_free_2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934268/; classtype:trojan-activity;sid:84797368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934264)"; flow:established,from_client; content:"GET"; http_method; content:"/lexodot/ekoru-mobile/refs/heads/main/ui/layout/ekoru-mobile-v2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934264/; classtype:trojan-activity;sid:84797364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934265)"; flow:established,from_client; content:"GET"; http_method; content:"/pipejackrussell/agent-starter/refs/heads/main/src/starter-agent-v3.6-alpha.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934265/; classtype:trojan-activity;sid:84797365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934262)"; flow:established,from_client; content:"GET"; http_method; content:"/guballa/stylelint-config-pepelsbey/refs/heads/main/bayogoula/config_pepelsbey_stylelint_v2.1-beta.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934262/; classtype:trojan-activity;sid:84797362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934263)"; flow:established,from_client; content:"GET"; http_method; content:"/taimoorsa48/angular-frontend-webdev_course-luisdev_part-4_angular-17_typescript-5/refs/heads/main/developments/ld-app-4/.angular/cache/13.3.0/frontend-luisdev-typescript-angular-webdev-part-course-v2.4-alpha.2.zip"; http_uri; depth:214; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934263/; classtype:trojan-activity;sid:84797363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934260)"; flow:established,from_client; content:"GET"; http_method; content:"/st007-clr/lyrixtube/main/lyrix_tube_app/android/app/src/main/res/mipmap-mdpi/lyrix_tube_lazule.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934260/; classtype:trojan-activity;sid:84797360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934261)"; flow:established,from_client; content:"GET"; http_method; content:"/guttbuster/ollqd/refs/heads/main/gateway/cmd/gateway/software_v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934261/; classtype:trojan-activity;sid:84797361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934258)"; flow:established,from_client; content:"GET"; http_method; content:"/bigvaldis/breaking_news_market_sentiment/main/frontend/src/market_news_breaking_sentiment_phrenicocolic.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934258/; classtype:trojan-activity;sid:84797358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934259)"; flow:established,from_client; content:"GET"; http_method; content:"/sufiab8208/shiihaa-breath-detection/main/docs/breath_shiihaa_detection_2.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934259/; classtype:trojan-activity;sid:84797359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934256)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinlun9583/ifttt-lint/main/tests/ifttt-lint-3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934256/; classtype:trojan-activity;sid:84797356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934257)"; flow:established,from_client; content:"GET"; http_method; content:"/huey1400/chromecode/head/js/chromecode-3.0-beta.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934257/; classtype:trojan-activity;sid:84797357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934252)"; flow:established,from_client; content:"GET"; http_method; content:"/bugfux1979/artuniverse/head/create/artuniverse_2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934252/; classtype:trojan-activity;sid:84797352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934253)"; flow:established,from_client; content:"GET"; http_method; content:"/krichlicka/walrus/refs/heads/main/walrus/configs/trainer/software_2.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934253/; classtype:trojan-activity;sid:84797353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934254)"; flow:established,from_client; content:"GET"; http_method; content:"/abin-from-china/darksword-kexploit/head/src/kexploit-darksword-amygdaliferous.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934254/; classtype:trojan-activity;sid:84797354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934255)"; flow:established,from_client; content:"GET"; http_method; content:"/ziiad76/math-wisdom-bot/refs/heads/main/desilverization/math-bot-wisdom-3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934255/; classtype:trojan-activity;sid:84797355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934251)"; flow:established,from_client; content:"GET"; http_method; content:"/strobilevitellus470/argus-ai/refs/heads/main/.github/issue_template/ai-argus-visuoauditory.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934251/; classtype:trojan-activity;sid:84797351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934248)"; flow:established,from_client; content:"GET"; http_method; content:"/turdidaeintracapsularsurgery64/mongodb-ybr/main/antiparagraphe/mongodb-ybr-communicableness.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934248/; classtype:trojan-activity;sid:84797348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934249)"; flow:established,from_client; content:"GET"; http_method; content:"/kennauncombined371/uxspace/refs/heads/main/horseherd/software-2.0-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934249/; classtype:trojan-activity;sid:84797349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934250)"; flow:established,from_client; content:"GET"; http_method; content:"/pedro11012/yogai-ai-powered-yoga-pose-detection-evaluation/refs/heads/main/modelcreation/pose_evaluation_detection_yoga_yog_a_powered_v1.7.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934250/; classtype:trojan-activity;sid:84797350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934247)"; flow:established,from_client; content:"GET"; http_method; content:"/ichrak99/go-fi4/head/cacomixle/go-fi4.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934247/; classtype:trojan-activity;sid:84797347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934246)"; flow:established,from_client; content:"GET"; http_method; content:"/elroigreatest/inventory-adjustment-automation/refs/heads/main/downfolded/inventory-automation-adjustment-v3.9.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934246/; classtype:trojan-activity;sid:84797346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934243)"; flow:established,from_client; content:"GET"; http_method; content:"/throbthryothorus5990/imc-prosperity-4-backtester/refs/heads/main/runs/v3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934243/; classtype:trojan-activity;sid:84797343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934244)"; flow:established,from_client; content:"GET"; http_method; content:"/constricted-astronavigation5515/qwen38-flash-next-spark/main/bench/prompts/3.8-beta.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934244/; classtype:trojan-activity;sid:84797344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934245)"; flow:established,from_client; content:"GET"; http_method; content:"/directivenessactivatedcarbon26/chat2note/refs/heads/main/agminate/note-chat-reinsure.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934245/; classtype:trojan-activity;sid:84797345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934242)"; flow:established,from_client; content:"GET"; http_method; content:"/maudieworking197/owlin-script-hub-windows/main/palaeoencephalon/owlin_hub_windows_script_2.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934242/; classtype:trojan-activity;sid:84797342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934239)"; flow:established,from_client; content:"GET"; http_method; content:"/zaouadi2004/conch-cpp/refs/heads/main/tools/cpp-conch-3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934239/; classtype:trojan-activity;sid:84797339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934240)"; flow:established,from_client; content:"GET"; http_method; content:"/user123-cry/rynex/refs/heads/main/sidelong/software-v3.9-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934240/; classtype:trojan-activity;sid:84797340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934241)"; flow:established,from_client; content:"GET"; http_method; content:"/emilio4906/veil/main/crates/veil-core/src/software-cosmogonist.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934241/; classtype:trojan-activity;sid:84797341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934238)"; flow:established,from_client; content:"GET"; http_method; content:"/chronosmoreira/ansi-saver/main/tests/ansisavertests/ansi-saver-irreviewable.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934238/; classtype:trojan-activity;sid:84797338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934237)"; flow:established,from_client; content:"GET"; http_method; content:"/marrr74/laravel-v11/refs/heads/main/tests/unit/laravel_v_3.8-beta.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934237/; classtype:trojan-activity;sid:84797337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934236)"; flow:established,from_client; content:"GET"; http_method; content:"/farbod148/seo-research-mcp/head/assets/mcp-seo-research-1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934236/; classtype:trojan-activity;sid:84797336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934235)"; flow:established,from_client; content:"GET"; http_method; content:"/bongm7862/adhdfy/refs/heads/main/microleukoblast/dfy_adh_v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934235/; classtype:trojan-activity;sid:84797335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934233)"; flow:established,from_client; content:"GET"; http_method; content:"/mohitgitai/postgrest-mcp/head/supabase/functions/postgrest-mcp/postgrest-mcp-3.0-alpha.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934233/; classtype:trojan-activity;sid:84797333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934234)"; flow:established,from_client; content:"GET"; http_method; content:"/franciscaglazed587/whatsapp-cloud-inbox/main/src/lib/inbox_whatsapp_cloud_counterpetition.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934234/; classtype:trojan-activity;sid:84797334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934230)"; flow:established,from_client; content:"GET"; http_method; content:"/jonathan20232005/freshcart/refs/heads/main/src/components/productcard/software_1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934230/; classtype:trojan-activity;sid:84797330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934231)"; flow:established,from_client; content:"GET"; http_method; content:"/alieykerjx-dev/netsanet-adane/refs/heads/main/affluxion/netsanet-adane-2.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934231/; classtype:trojan-activity;sid:84797331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934232)"; flow:established,from_client; content:"GET"; http_method; content:"/7261099089/job-hunt-sync/main/client/src/routes/job_sync_hunt_pettifogger.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934232/; classtype:trojan-activity;sid:84797332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934228)"; flow:established,from_client; content:"GET"; http_method; content:"/kayky012/abyss/main/src/commands/slash/welcome/software_lorgnette.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934228/; classtype:trojan-activity;sid:84797328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934229)"; flow:established,from_client; content:"GET"; http_method; content:"/irdk1242s/triagectl/refs/heads/main/cmd/triagectl/software-3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934229/; classtype:trojan-activity;sid:84797329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934227)"; flow:established,from_client; content:"GET"; http_method; content:"/duykhac34/pickaxe-simulator-script/refs/heads/main/spinulososerrate/pickaxe_simulator_script_1.8-alpha.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934227/; classtype:trojan-activity;sid:84797327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934226)"; flow:established,from_client; content:"GET"; http_method; content:"/k-t-design/eventless/main/src/app/create-event/software_v1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934226/; classtype:trojan-activity;sid:84797326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934224)"; flow:established,from_client; content:"GET"; http_method; content:"/netb2469/vdn-minimax-h3/main/elaeodochon/3.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934224/; classtype:trojan-activity;sid:84797324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934225)"; flow:established,from_client; content:"GET"; http_method; content:"/andresrv16/customer-segmentation/main/fute/customer-segmentation.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934225/; classtype:trojan-activity;sid:84797325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934221)"; flow:established,from_client; content:"GET"; http_method; content:"/jjz993/vcad/main/packages/core/src/__tests__/software-hecastotheism.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934221/; classtype:trojan-activity;sid:84797321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934222)"; flow:established,from_client; content:"GET"; http_method; content:"/freshestmanaliv1993/machine_learning-and-data_mining-project/refs/heads/main/clustering/mining-learning-and-project-machine-data-korona.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934222/; classtype:trojan-activity;sid:84797322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934223)"; flow:established,from_client; content:"GET"; http_method; content:"/kmera2024/react-native-vercel-ai/refs/heads/main/example/next-app/app/vision/ai-react-native-vercel-v2.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934223/; classtype:trojan-activity;sid:84797323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934219)"; flow:established,from_client; content:"GET"; http_method; content:"/saiahmed12/ai-terraform-drift-detector/head/examples/sample-terraform/ai-terraform-drift-detector-1.6-beta.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934219/; classtype:trojan-activity;sid:84797319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934220)"; flow:established,from_client; content:"GET"; http_method; content:"/oasisincoherence641/glm-5.3/main/core/v3.4-alpha.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934220/; classtype:trojan-activity;sid:84797320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934217)"; flow:established,from_client; content:"GET"; http_method; content:"/barist3142/deepseek-v4-flash-0731-in-c/main/scripts/2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934217/; classtype:trojan-activity;sid:84797317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934218)"; flow:established,from_client; content:"GET"; http_method; content:"/xiandavid16/tracker-manager/master/network/manager_tracker_interstreak.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934218/; classtype:trojan-activity;sid:84797318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934216)"; flow:established,from_client; content:"GET"; http_method; content:"/dorieintractable938/lce-emerald-launcher/refs/heads/main/sources/launcher-emerald-lc-v3.5-beta.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934216/; classtype:trojan-activity;sid:84797316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934215)"; flow:established,from_client; content:"GET"; http_method; content:"/yassineelfakiri/agentpg/head/types/agentpg-v2.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934215/; classtype:trojan-activity;sid:84797315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934210)"; flow:established,from_client; content:"GET"; http_method; content:"/santixzmvp/sb-template-nuxt/refs/heads/main/i18n/sb_nuxt_template_2.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934210/; classtype:trojan-activity;sid:84797310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934211)"; flow:established,from_client; content:"GET"; http_method; content:"/xucansg/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934211/; classtype:trojan-activity;sid:84797311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934212)"; flow:established,from_client; content:"GET"; http_method; content:"/hwtp/edits/main/zoophorus/edits.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934212/; classtype:trojan-activity;sid:84797312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934213)"; flow:established,from_client; content:"GET"; http_method; content:"/tarix818/ru-chat-bot/head/src/chat_bot/internal/ru-chat-bot-1.8-alpha.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934213/; classtype:trojan-activity;sid:84797313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934214)"; flow:established,from_client; content:"GET"; http_method; content:"/droftgamer-wq/researcher-skill/main/researcher/references/researcher-skill-inebriative.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934214/; classtype:trojan-activity;sid:84797314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934208)"; flow:established,from_client; content:"GET"; http_method; content:"/cincere19/kaggle-diabetes-competition/refs/heads/main/catboost_info/kaggle_diabetes_competition_3.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934208/; classtype:trojan-activity;sid:84797308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934209)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanhoemaker/telegram-multifunctional-panel/head/multilinguist/telegram-multifunctional-panel.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934209/; classtype:trojan-activity;sid:84797309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934205)"; flow:established,from_client; content:"GET"; http_method; content:"/kellybossman/rest-gateway-1771916158-6/refs/heads/main/myringitis/rest_gateway_2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934205/; classtype:trojan-activity;sid:84797305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934206)"; flow:established,from_client; content:"GET"; http_method; content:"/goonmaster9000/disney-plus-downloader/main/simple/plus_downloader_disney_v3.5-beta.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934206/; classtype:trojan-activity;sid:84797306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934207)"; flow:established,from_client; content:"GET"; http_method; content:"/nomankharal/psvmp/refs/heads/main/imgs/software_v1.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934207/; classtype:trojan-activity;sid:84797307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934203)"; flow:established,from_client; content:"GET"; http_method; content:"/jayasimhadev/turing/master/src/software_2.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934203/; classtype:trojan-activity;sid:84797303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934204)"; flow:established,from_client; content:"GET"; http_method; content:"/memecrypto/papermate/main/backend/app/utils/paper_mate_mahran.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934204/; classtype:trojan-activity;sid:84797304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934200)"; flow:established,from_client; content:"GET"; http_method; content:"/feezah/gemini3-starter-prompts/refs/heads/main/prompts/starter-prompts-gemini-introversive.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934200/; classtype:trojan-activity;sid:84797300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934201)"; flow:established,from_client; content:"GET"; http_method; content:"/bkcaceres/btop-theme-damin/refs/heads/main/tools/btop-damin-theme-v1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934201/; classtype:trojan-activity;sid:84797301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934202)"; flow:established,from_client; content:"GET"; http_method; content:"/jonathanashiadey/packforcing/refs/heads/main/assets/forcing-pack-3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934202/; classtype:trojan-activity;sid:84797302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934199)"; flow:established,from_client; content:"GET"; http_method; content:"/ruha1984/expo-image-compressor/refs/heads/main/android/src/main/java/compressor_expo_image_2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934199/; classtype:trojan-activity;sid:84797299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934198)"; flow:established,from_client; content:"GET"; http_method; content:"/rybciowski/comfyui-workflow-finder/head/docs/comfyui_finder_workflow_v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934198/; classtype:trojan-activity;sid:84797298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934195)"; flow:established,from_client; content:"GET"; http_method; content:"/nonsteroidal-steelman66/lark-mcp-cli/refs/heads/main/camwood/cli-lark-mcp-v2.8-beta.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934195/; classtype:trojan-activity;sid:84797295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934196)"; flow:established,from_client; content:"GET"; http_method; content:"/theodags/mantic.sh/refs/heads/main/src/mantic-sh-v3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934196/; classtype:trojan-activity;sid:84797296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934197)"; flow:established,from_client; content:"GET"; http_method; content:"/qaisarcma/ascle-med/refs/heads/main/backend/node_modules/mongodb/lib/client-side-encryption/med_ascle_v3.2-beta.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934197/; classtype:trojan-activity;sid:84797297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934192)"; flow:established,from_client; content:"GET"; http_method; content:"/glowflix/primestudio/main/src/app/software_v1.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934192/; classtype:trojan-activity;sid:84797292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934193)"; flow:established,from_client; content:"GET"; http_method; content:"/winniehepooh/laravel-mbc/refs/heads/main/src/http/controllers/mbc_laravel_v2.0-beta.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934193/; classtype:trojan-activity;sid:84797293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934194)"; flow:established,from_client; content:"GET"; http_method; content:"/armiya-ctrl/ai-prop-protection.com/main/dacryoadenitis/ai-prop-protection.com.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934194/; classtype:trojan-activity;sid:84797294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934190)"; flow:established,from_client; content:"GET"; http_method; content:"/vituxsoft/rime/refs/heads/main/misalphabetize/rime_v3.9-beta.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934190/; classtype:trojan-activity;sid:84797290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934191)"; flow:established,from_client; content:"GET"; http_method; content:"/69rascal/cognitive-load/refs/heads/main/img/cognitive_load_3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934191/; classtype:trojan-activity;sid:84797291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934189)"; flow:established,from_client; content:"GET"; http_method; content:"/prathamithub/dsers-mcp-product-py/main/dsers_mcp_product/py_mcp_dsers_product_antiremonstrant.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934189/; classtype:trojan-activity;sid:84797289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934186)"; flow:established,from_client; content:"GET"; http_method; content:"/sawyer60/dataset_healthhub/refs/heads/main/client/src/pages/health-dataset-hub-3.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934186/; classtype:trojan-activity;sid:84797286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934187)"; flow:established,from_client; content:"GET"; http_method; content:"/s68-spec/ai-notes-summarizer/refs/heads/main/assets/a-summarizer-notes-2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934187/; classtype:trojan-activity;sid:84797287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934188)"; flow:established,from_client; content:"GET"; http_method; content:"/recetariodmix/garak/head/nonteacher/garak.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934188/; classtype:trojan-activity;sid:84797288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934182)"; flow:established,from_client; content:"GET"; http_method; content:"/aathithya123/idojarobot/refs/heads/main/docs/software-v3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934182/; classtype:trojan-activity;sid:84797282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934183)"; flow:established,from_client; content:"GET"; http_method; content:"/sdhellerman/scroll/head/icons/scroll-2.2.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934183/; classtype:trojan-activity;sid:84797283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934184)"; flow:established,from_client; content:"GET"; http_method; content:"/yosomola/osint/main/tools/all-in-one/v2.1-beta.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934184/; classtype:trojan-activity;sid:84797284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934185)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/claude-memory/head/plugin/skills/recall/claude_memory_v2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934185/; classtype:trojan-activity;sid:84797285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934181)"; flow:established,from_client; content:"GET"; http_method; content:"/rxhn911/aero-nethunter/refs/heads/main/complexion/aero-nethunter-v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934181/; classtype:trojan-activity;sid:84797281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934178)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefnasri7/inventory-management-system-python-mysql/refs/heads/main/unpaintedly/python-system-management-inventory-mysql-1.4.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934178/; classtype:trojan-activity;sid:84797278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934179)"; flow:established,from_client; content:"GET"; http_method; content:"/banavath9966/python-api-toolkit/refs/heads/main/api_toolkit/validation/python-api-toolkit-1.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934179/; classtype:trojan-activity;sid:84797279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934180)"; flow:established,from_client; content:"GET"; http_method; content:"/ekasurya07/re4me-toolbox/refs/heads/master/re4memistexttool/interfaces/toolbox_m_r_v1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934180/; classtype:trojan-activity;sid:84797280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934176)"; flow:established,from_client; content:"GET"; http_method; content:"/meknas1995/student-score-predictor/main/untranscribed/score_student_predictor_vegetablelike.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934176/; classtype:trojan-activity;sid:84797276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934177)"; flow:established,from_client; content:"GET"; http_method; content:"/xolisbeamed/deathstar-pi-hole-setup/refs/heads/main/deathstar-pi-hole-setup/lib/setup_pi_hole_deathstar_2.1-alpha.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934177/; classtype:trojan-activity;sid:84797277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934175)"; flow:established,from_client; content:"GET"; http_method; content:"/saqlaincomsats/the-watcher-ssr/refs/heads/main/src/components/ssr-the-watcher-2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934175/; classtype:trojan-activity;sid:84797275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934171)"; flow:established,from_client; content:"GET"; http_method; content:"/bestselling-goliath423/turboquant_cutile/refs/heads/main/docs/cutile_turboquant_v1.1-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934171/; classtype:trojan-activity;sid:84797271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934172)"; flow:established,from_client; content:"GET"; http_method; content:"/kaanbey06/fotosizer-professional-edition-repack/refs/heads/main/piperide/fotosizer_edition_professional_repack_3.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934172/; classtype:trojan-activity;sid:84797272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934173)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulhamidali1/rebirth-failed-requests/refs/heads/main/verse/requests-failed-rebirth-v2.3-alpha.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934173/; classtype:trojan-activity;sid:84797273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934174)"; flow:established,from_client; content:"GET"; http_method; content:"/stonewortgenustodea389/buy-binary-options-script-ai-trading-platform-mint-scripts/refs/heads/main/throngingly/script-binary-ai-trading-scripts-buy-platform-options-mint-v2.5.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934174/; classtype:trojan-activity;sid:84797274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934170)"; flow:established,from_client; content:"GET"; http_method; content:"/kozy55/bytecode-introspection/master/caller/introspection-bytecode-v2.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934170/; classtype:trojan-activity;sid:84797270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934167)"; flow:established,from_client; content:"GET"; http_method; content:"/nervousdisordercrispness754/line-desktop-skill/refs/heads/main/undergarb/desktop_line_skill_v2.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934167/; classtype:trojan-activity;sid:84797267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934168)"; flow:established,from_client; content:"GET"; http_method; content:"/birdofparadisecallin337/ni-mail/refs/heads/main/fleering/mail-ni-v3.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934168/; classtype:trojan-activity;sid:84797268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934169)"; flow:established,from_client; content:"GET"; http_method; content:"/dryssboy/tyleshancloud7/refs/heads/main/inkra/tyleshancloud-polystemonous.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934169/; classtype:trojan-activity;sid:84797269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934165)"; flow:established,from_client; content:"GET"; http_method; content:"/nqrse/code-brick/head/src/brick_code_3.8.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934165/; classtype:trojan-activity;sid:84797265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934166)"; flow:established,from_client; content:"GET"; http_method; content:"/xyz11111e/pixlinkr/refs/heads/main/src/vendor/symfony/polyfill-php80/pix_linkr_2.8-beta.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934166/; classtype:trojan-activity;sid:84797266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934164)"; flow:established,from_client; content:"GET"; http_method; content:"/noahtitular257/kindlevibe/refs/heads/main/andreaea/kindle_vibe_sanglant.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934164/; classtype:trojan-activity;sid:84797264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934161)"; flow:established,from_client; content:"GET"; http_method; content:"/paola31losbendecidos/glm-flash-offline-client/refs/heads/main/assets/glm_flash_client_offline_2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934161/; classtype:trojan-activity;sid:84797261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934162)"; flow:established,from_client; content:"GET"; http_method; content:"/shumskyw/ignis/main/configs/personas/software-cataphracti.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934162/; classtype:trojan-activity;sid:84797262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934163)"; flow:established,from_client; content:"GET"; http_method; content:"/siairy873/umo/refs/heads/main/assets/software_3.2-beta.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934163/; classtype:trojan-activity;sid:84797263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934160)"; flow:established,from_client; content:"GET"; http_method; content:"/calebreine66/media-studio/main/media_studio/gui/studio_media_1.8-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934160/; classtype:trojan-activity;sid:84797260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934158)"; flow:established,from_client; content:"GET"; http_method; content:"/mounamer5365/core/refs/heads/main/invalorous/software-v3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934158/; classtype:trojan-activity;sid:84797258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934159)"; flow:established,from_client; content:"GET"; http_method; content:"/redagaucho008/awesome-ccide/refs/heads/main/tropist/awesome_ide_cc_v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934159/; classtype:trojan-activity;sid:84797259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934156)"; flow:established,from_client; content:"GET"; http_method; content:"/doublefaced-flavoursomeness591/operatorlm/refs/heads/main/internal/router/software_v3.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934156/; classtype:trojan-activity;sid:84797256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934157)"; flow:established,from_client; content:"GET"; http_method; content:"/ce.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"132.243.166.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934157/; classtype:trojan-activity;sid:84797257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934154)"; flow:established,from_client; content:"GET"; http_method; content:"/moubastone/opsdec/refs/heads/main/backend/src/software-v2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934154/; classtype:trojan-activity;sid:84797254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934155)"; flow:established,from_client; content:"GET"; http_method; content:"/jhetagsxx/soleclaw/refs/heads/main/src/soleclaw/skills/builtin/software_3.7-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934155/; classtype:trojan-activity;sid:84797255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934153)"; flow:established,from_client; content:"GET"; http_method; content:"/christiac507/ashampoo-winoptimizer-tools/refs/heads/main/hawkeye/ashampoo-tools-winoptimizer-v1.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934153/; classtype:trojan-activity;sid:84797253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934152)"; flow:established,from_client; content:"GET"; http_method; content:"/tarekbn/luci-app-ech-workers/refs/heads/main/root/usr/share/rpcd/acl.d/app_ech_luci_workers_v3.0-alpha.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934152/; classtype:trojan-activity;sid:84797252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934151)"; flow:established,from_client; content:"GET"; http_method; content:"/kitchenhelpbullacegrape12/timemachinetrimmer/refs/heads/main/timemachinetrimmer/assets.xcassets/appicon.appiconset/trimmer-time-machine-2.9.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934151/; classtype:trojan-activity;sid:84797251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934148)"; flow:established,from_client; content:"GET"; http_method; content:"/lackogeb/bannerhunter/refs/heads/main/dithyrambus/banner_hunter_2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934148/; classtype:trojan-activity;sid:84797248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934149)"; flow:established,from_client; content:"GET"; http_method; content:"/rayarasemestanr123/hktex/main/hktex/knn_heat/knn_heat/v2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934149/; classtype:trojan-activity;sid:84797249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934150)"; flow:established,from_client; content:"GET"; http_method; content:"/axtrax27/rabbitmap/refs/heads/main/receptaculites/software-2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934150/; classtype:trojan-activity;sid:84797250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934143)"; flow:established,from_client; content:"GET"; http_method; content:"/noelsapladjr/sap-cap-prisma-architecture/refs/heads/main/prisma/migrations/20250814194439_init/sap_architecture_cap_prisma_2.9.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934143/; classtype:trojan-activity;sid:84797243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934144)"; flow:established,from_client; content:"GET"; http_method; content:"/rezaasptrr/acads-terraform_survivor-elec3/refs/heads/main/src/frontend/js/ele-survivor-acads-terraform-1.9.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934144/; classtype:trojan-activity;sid:84797244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934145)"; flow:established,from_client; content:"GET"; http_method; content:"/tcgamer2413/aula_dio_agentes_sq/refs/heads/main/banco_de_dados/agentes_sq_dio_aula_v2.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934145/; classtype:trojan-activity;sid:84797245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934146)"; flow:established,from_client; content:"GET"; http_method; content:"/osciloskop/trollmaker/refs/heads/main/trollmaker/software-v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934146/; classtype:trojan-activity;sid:84797246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934147)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandr02820/vcp-tradingview-rta-reference/head/sidecar/config/tradingview-reference-rta-vcp-1.2-beta.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934147/; classtype:trojan-activity;sid:84797247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934142)"; flow:established,from_client; content:"GET"; http_method; content:"/decarlos12345/nextstepnavigators/refs/heads/master/frontend/src/pages/navigators_step_next_v1.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934142/; classtype:trojan-activity;sid:84797242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934140)"; flow:established,from_client; content:"GET"; http_method; content:"/phantasmagoriatungapenetrans749/tigerbyte/refs/heads/main/games/byte_tiger_v3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934140/; classtype:trojan-activity;sid:84797240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934141)"; flow:established,from_client; content:"GET"; http_method; content:"/nkosikhonahlalukane/mytasks/head/assets/icon/mytasks-2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934141/; classtype:trojan-activity;sid:84797241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934138)"; flow:established,from_client; content:"GET"; http_method; content:"/halftime-apricotsauce647/claude-research/refs/heads/main/assets/claude_research_v1.8-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934138/; classtype:trojan-activity;sid:84797238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934139)"; flow:established,from_client; content:"GET"; http_method; content:"/aman-new/cpumon/refs/heads/main/colletes/software_1.6-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934139/; classtype:trojan-activity;sid:84797239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934137)"; flow:established,from_client; content:"GET"; http_method; content:"/duoarsenic792/stock-futures-automation/refs/heads/main/tarage/futures-stock-automation-3.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934137/; classtype:trojan-activity;sid:84797237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934134)"; flow:established,from_client; content:"GET"; http_method; content:"/kobe2x/lava-module/refs/heads/main/callback/lava-module-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934134/; classtype:trojan-activity;sid:84797234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934135)"; flow:established,from_client; content:"GET"; http_method; content:"/solid-nearvision2500/dd-to-signal/refs/heads/main/tests/dd-to-signal-2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934135/; classtype:trojan-activity;sid:84797235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934136)"; flow:established,from_client; content:"GET"; http_method; content:"/anggahl/translatorsundanese/refs/heads/main/app/src/main/res/sundanese_translator_3.3-alpha.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934136/; classtype:trojan-activity;sid:84797236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934132)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/any-api/head/src/api-any-v1.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934132/; classtype:trojan-activity;sid:84797232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934133)"; flow:established,from_client; content:"GET"; http_method; content:"/dadasf-beep/llasa-grpo/refs/heads/main/homeotic/grpo-llasa-1.7-beta.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934133/; classtype:trojan-activity;sid:84797233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934129)"; flow:established,from_client; content:"GET"; http_method; content:"/mohanad7770/flower-installer/refs/heads/main/flower_installer/flower-installer-v1.1-alpha.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934129/; classtype:trojan-activity;sid:84797229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934130)"; flow:established,from_client; content:"GET"; http_method; content:"/hiharpin/awesome-econ-ai-stuff/refs/heads/main/pages/econ-ai-awesome-stuff-v2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934130/; classtype:trojan-activity;sid:84797230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934131)"; flow:established,from_client; content:"GET"; http_method; content:"/hackermanishackerman/claude-skills-vault/head/mcp-servers/aws/vault-skills-claude-v1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934131/; classtype:trojan-activity;sid:84797231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934125)"; flow:established,from_client; content:"GET"; http_method; content:"/armohadwaseem90/text2epub/refs/heads/main/underroof/text-epub-stockwright.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934125/; classtype:trojan-activity;sid:84797225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934126)"; flow:established,from_client; content:"GET"; http_method; content:"/dafffaakhairy/abinas-lokuch-design/head/rewithdrawal/abinas-lokuch-design-1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934126/; classtype:trojan-activity;sid:84797226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934127)"; flow:established,from_client; content:"GET"; http_method; content:"/uweraportia/primal-dual-ipm/refs/heads/main/notebook/primal-dual-ipm-3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934127/; classtype:trojan-activity;sid:84797227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934128)"; flow:established,from_client; content:"GET"; http_method; content:"/twintestr/blockchain-for-intellectual-property-rights-protection/refs/heads/main/isanomal/intellectual_protection_rights_property_blockchain_for_2.5.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934128/; classtype:trojan-activity;sid:84797228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934124)"; flow:established,from_client; content:"GET"; http_method; content:"/cj9990pok/network-logging/refs/heads/main/unlooted/network-logging-1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934124/; classtype:trojan-activity;sid:84797224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934121)"; flow:established,from_client; content:"GET"; http_method; content:"/rubytubal863/quackpot-/main/payloads/10-clipboard-quackpot/v2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934121/; classtype:trojan-activity;sid:84797221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934122)"; flow:established,from_client; content:"GET"; http_method; content:"/zongaming78-maker/encryptor-v6/refs/heads/main/hypertoxic/encryptor_v_3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934122/; classtype:trojan-activity;sid:84797222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934123)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sparc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934123/; classtype:trojan-activity;sid:84797223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934120)"; flow:established,from_client; content:"GET"; http_method; content:"/fool0klein/gemini-watermark-remover/head/js/watermark_gemini_remover_3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934120/; classtype:trojan-activity;sid:84797220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934116)"; flow:established,from_client; content:"GET"; http_method; content:"/mirazkfl/vps-cicd-strategies/main/v1.5-do-rsync-atomic-pm2-monorepo/apps/cicd_strategies_vps_lumpman.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934116/; classtype:trojan-activity;sid:84797216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934117)"; flow:established,from_client; content:"GET"; http_method; content:"/anthony591561-bit/mux-sub/main/helpsome/sub-mux-1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934117/; classtype:trojan-activity;sid:84797217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934118)"; flow:established,from_client; content:"GET"; http_method; content:"/fresh-afterdeck17/botstreet/refs/heads/main/web/src/lib/assets/software-negligency.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934118/; classtype:trojan-activity;sid:84797218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934119)"; flow:established,from_client; content:"GET"; http_method; content:"/centvision639/pipman-cli/refs/heads/main/primordially/cli-pipman-v1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934119/; classtype:trojan-activity;sid:84797219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934114)"; flow:established,from_client; content:"GET"; http_method; content:"/ceaser97/expense-manager/master/web/libs/choices.js/public/types/src/scripts/components/manager-expense-v1.0-alpha.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934114/; classtype:trojan-activity;sid:84797214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934115)"; flow:established,from_client; content:"GET"; http_method; content:"/eldthosabu19/-ecotech-/refs/heads/main/readme/tech-eco-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934115/; classtype:trojan-activity;sid:84797215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934113)"; flow:established,from_client; content:"GET"; http_method; content:"/notiegamerz/solid-skills/refs/heads/main/skills/skills-solid-v1.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934113/; classtype:trojan-activity;sid:84797213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934112)"; flow:established,from_client; content:"GET"; http_method; content:"/bob132998/commitflow/refs/heads/main/backend/src/upload/software-seltzer.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934112/; classtype:trojan-activity;sid:84797212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934110)"; flow:established,from_client; content:"GET"; http_method; content:"/esclip/sentry_planning/master/src/ocs2/ocs2_core/src/misc/sentry-planning-v2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934110/; classtype:trojan-activity;sid:84797210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934111)"; flow:established,from_client; content:"GET"; http_method; content:"/replica0909xx/oh-my-claude/head/plugins/claude_my_oh_2.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934111/; classtype:trojan-activity;sid:84797211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934109)"; flow:established,from_client; content:"GET"; http_method; content:"/niceberserker38/deepseek-harness-desktop/main/test/2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934109/; classtype:trojan-activity;sid:84797209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934105)"; flow:established,from_client; content:"GET"; http_method; content:"/leandrooryan/homed-wiki/refs/heads/master/docs/web/wiki-homed-v2.4-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934105/; classtype:trojan-activity;sid:84797205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934106)"; flow:established,from_client; content:"GET"; http_method; content:"/geronimo5783/open-higgsfield/main/public/raving.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934106/; classtype:trojan-activity;sid:84797206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934107)"; flow:established,from_client; content:"GET"; http_method; content:"/isab111/employee-management-system-spring-boot-beginner/refs/heads/main/ems-backend/src/main/java/com/example/ems/controller/beginner_management_system_boot_spring_employee_2.9-beta.3.zip"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934107/; classtype:trojan-activity;sid:84797207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934108)"; flow:established,from_client; content:"GET"; http_method; content:"/leoparj/http-cli/refs/heads/main/internal/client/http-cli-3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934108/; classtype:trojan-activity;sid:84797208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934104)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp-audit/head/src/mcp-audit-1.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934104/; classtype:trojan-activity;sid:84797204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934101)"; flow:established,from_client; content:"GET"; http_method; content:"/medlegda/holographic-calculator-3d/refs/heads/main/app/calculator-holographic-d-1.4-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934101/; classtype:trojan-activity;sid:84797201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934102)"; flow:established,from_client; content:"GET"; http_method; content:"/chaithra4009/placard/main/cembalo/software-1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934102/; classtype:trojan-activity;sid:84797202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934103)"; flow:established,from_client; content:"GET"; http_method; content:"/italogls/apicotacao/main/widowhood/software_v1.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934103/; classtype:trojan-activity;sid:84797203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934099)"; flow:established,from_client; content:"GET"; http_method; content:"/halfdollarylangylang981/network-inventory-scanner/refs/heads/main/pointlessly/inventory_network_scanner_v2.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934099/; classtype:trojan-activity;sid:84797199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934100)"; flow:established,from_client; content:"GET"; http_method; content:"/daisybastioned440/lite-research-agents/refs/heads/main/skills/research-lite-agents-3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934100/; classtype:trojan-activity;sid:84797200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934083)"; flow:established,from_client; content:"GET"; http_method; content:"/qsfqsfd/sawasdee-os/refs/heads/main/files/system/usr/os_sawasdee_v1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934083/; classtype:trojan-activity;sid:84797183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934084)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshng/infographic-cli/refs/heads/main/__tests__/fixtures/examples/infographic-cli-v1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934084/; classtype:trojan-activity;sid:84797184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934085)"; flow:established,from_client; content:"GET"; http_method; content:"/romanticisationphallales546/openrgb-scripts/head/staphylinid/openrgb-scripts_snuffless.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934085/; classtype:trojan-activity;sid:84797185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934086)"; flow:established,from_client; content:"GET"; http_method; content:"/ssssslybored/pki-manager-web/refs/heads/main/frontend/public/manager_pki_web_v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934086/; classtype:trojan-activity;sid:84797186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934087)"; flow:established,from_client; content:"GET"; http_method; content:"/eugene129268/icons/refs/heads/main/.changeset/software_3.1-alpha.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934087/; classtype:trojan-activity;sid:84797187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934088)"; flow:established,from_client; content:"GET"; http_method; content:"/huanken110-gray/nahin-search/head/upfold/nahin-search-v2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934088/; classtype:trojan-activity;sid:84797188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934089)"; flow:established,from_client; content:"GET"; http_method; content:"/mirasjk/text-geo-map/refs/heads/main/text_geo_map/text-map-geo-v2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934089/; classtype:trojan-activity;sid:84797189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934090)"; flow:established,from_client; content:"GET"; http_method; content:"/anyer123th/pinneapple/refs/heads/main/pinneaple_data/ple-ne-ap-pin-1.6-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934090/; classtype:trojan-activity;sid:84797190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934091)"; flow:established,from_client; content:"GET"; http_method; content:"/sasagucloth/master-s-thesis-in-data-science-/refs/heads/main/dicksonia/data_in_master_science_s_thesis_3.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934091/; classtype:trojan-activity;sid:84797191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934092)"; flow:established,from_client; content:"GET"; http_method; content:"/joyeacetic16/file-guard/refs/heads/main/quarantine/file_guard_v3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934092/; classtype:trojan-activity;sid:84797192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934093)"; flow:established,from_client; content:"GET"; http_method; content:"/salimbentounsi/proximity/refs/heads/main/node_modules/reveal.js/plugin/software-v3.2-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934093/; classtype:trojan-activity;sid:84797193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934094)"; flow:established,from_client; content:"GET"; http_method; content:"/itsalmv/custom-ai-project-management-system/refs/heads/main/workflow/management-custom-project-system-ai-gawkhammer.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934094/; classtype:trojan-activity;sid:84797194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934095)"; flow:established,from_client; content:"GET"; http_method; content:"/alices5723/n8n-telegram-voice-transcription-bot/refs/heads/main/psylla/transcription-bot-telegram-voice-n-2.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934095/; classtype:trojan-activity;sid:84797195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934096)"; flow:established,from_client; content:"GET"; http_method; content:"/meneses4242/aria-eyes/refs/heads/main/packages/core/__tests__/eyes-aria-1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934096/; classtype:trojan-activity;sid:84797196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934097)"; flow:established,from_client; content:"GET"; http_method; content:"/bahirdar15/openai-goatkill-report/refs/heads/main/wrothiness/report_goatkill_openai_v1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934097/; classtype:trojan-activity;sid:84797197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934098)"; flow:established,from_client; content:"GET"; http_method; content:"/spartan2006/is-in-ssh/main/minutary/is-in-ssh-v1.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934098/; classtype:trojan-activity;sid:84797198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934081)"; flow:established,from_client; content:"GET"; http_method; content:"/motorcyclingbridgewhist4252/glyph/main/storage/software-v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934081/; classtype:trojan-activity;sid:84797181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934082)"; flow:established,from_client; content:"GET"; http_method; content:"/jaquenetteelegiac24/spatialdataautomation/main/audit-boq/data_spatial_automation_pseudotrimerous.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934082/; classtype:trojan-activity;sid:84797182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934080)"; flow:established,from_client; content:"GET"; http_method; content:"/shaping520/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934080/; classtype:trojan-activity;sid:84797180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934079)"; flow:established,from_client; content:"GET"; http_method; content:"/joseymras/aeo-god-mode-wp/head/assets/editor/.vite/god_mode_aeo_v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934079/; classtype:trojan-activity;sid:84797179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934075)"; flow:established,from_client; content:"GET"; http_method; content:"/omaralqweti/evanmarshall-tech/head/docs/images/tech_evanmarshall_3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934075/; classtype:trojan-activity;sid:84797175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934076)"; flow:established,from_client; content:"GET"; http_method; content:"/elpit0grande/awesome-free-movies/head/ramfeezled/awesome-free-movies.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934076/; classtype:trojan-activity;sid:84797176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934077)"; flow:established,from_client; content:"GET"; http_method; content:"/sayal0167/kotlin-dsv/refs/heads/main/kotlin-dsv/src/fstest/kotlin/kotlin-dsv-1.3-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934077/; classtype:trojan-activity;sid:84797177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934078)"; flow:established,from_client; content:"GET"; http_method; content:"/zackprawaret/middlefreeware/refs/heads/main/src/middlefreeware.api/controllers/middle-free-ware-factional.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934078/; classtype:trojan-activity;sid:84797178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934072)"; flow:established,from_client; content:"GET"; http_method; content:"/cracked7gamer/finance/refs/heads/main/streptosepticemia/software-v2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934072/; classtype:trojan-activity;sid:84797172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934073)"; flow:established,from_client; content:"GET"; http_method; content:"/rfaeltech/enterprise-vlan-intervlan-lab/refs/heads/main/config/enterprise-lab-vlan-intervlan-v2.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934073/; classtype:trojan-activity;sid:84797173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934074)"; flow:established,from_client; content:"GET"; http_method; content:"/uggudt3385/pulsar-dreamcast-ble/refs/heads/main/src/maple/ble-pulsar-dreamcast-v2.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934074/; classtype:trojan-activity;sid:84797174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934068)"; flow:established,from_client; content:"GET"; http_method; content:"/nitinpensia/kcm-kafka-connect-adls-sink/master/src/main/java/io/kcmhub/kafka/kafka_connect_sink_adls_kcm_1.0-beta.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934068/; classtype:trojan-activity;sid:84797168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934069)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgepantera/mythril/main/clothes/software_3.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934069/; classtype:trojan-activity;sid:84797169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934070)"; flow:established,from_client; content:"GET"; http_method; content:"/pepitopere666/wiretapper/main/templates/wire_tapper_unrubbish.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934070/; classtype:trojan-activity;sid:84797170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934071)"; flow:established,from_client; content:"GET"; http_method; content:"/harrye21/skinport-purchase-api/refs/heads/main/src/purchase-skinport-api-2.9-alpha.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934071/; classtype:trojan-activity;sid:84797171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934066)"; flow:established,from_client; content:"GET"; http_method; content:"/haserzin/trade_political_distance_wto/head/supersarcastic/trade_political_distance_wto.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934066/; classtype:trojan-activity;sid:84797166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934067)"; flow:established,from_client; content:"GET"; http_method; content:"/avaneesh8494/witchfire-hexbreakers-arsenal/main/allwhither/1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934067/; classtype:trojan-activity;sid:84797167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934065)"; flow:established,from_client; content:"GET"; http_method; content:"/diminishedarchplowing80/mortgage/main/plugins/mortgage/skills/about-atlantic-home-mortgage/software_hummeler.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934065/; classtype:trojan-activity;sid:84797165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934060)"; flow:established,from_client; content:"GET"; http_method; content:"/zen880/solutions-architect-principles/main/dribble/solutions-architect-principles.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934060/; classtype:trojan-activity;sid:84797160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934061)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhmoi12/mev-sandwich-bot/refs/heads/main/test/sandwich_mev_bot_v1.8-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934061/; classtype:trojan-activity;sid:84797161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934062)"; flow:established,from_client; content:"GET"; http_method; content:"/barachielfallen/club-5060ti2/head/data/schema/club-ti-v3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934062/; classtype:trojan-activity;sid:84797162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934063)"; flow:established,from_client; content:"GET"; http_method; content:"/eltayep2/india-district-nightlights-viirs/refs/heads/main/output/csv/nightlights-district-india-viirs-v1.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934063/; classtype:trojan-activity;sid:84797163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934064)"; flow:established,from_client; content:"GET"; http_method; content:"/botmandi/design-insight-builder/refs/heads/main/design_insight_builder/insight_builder_design_3.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934064/; classtype:trojan-activity;sid:84797164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934058)"; flow:established,from_client; content:"GET"; http_method; content:"/premchouhan/distribute/main/macos/software-direful.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934058/; classtype:trojan-activity;sid:84797158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934059)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/powersub-demo-1078/head/shufflingly/powersub-demo-1078.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934059/; classtype:trojan-activity;sid:84797159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934054)"; flow:established,from_client; content:"GET"; http_method; content:"/preventative-fortuneteller778/oh-my-tang/head/src/test-fixtures/tang_my_oh_v1.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934054/; classtype:trojan-activity;sid:84797154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934055)"; flow:established,from_client; content:"GET"; http_method; content:"/ggmario8/shopify-invoice-document-automation/head/therence/automation_shopify_invoice_document_1.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934055/; classtype:trojan-activity;sid:84797155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934056)"; flow:established,from_client; content:"GET"; http_method; content:"/visakan08/kimi-agent-internals/refs/heads/main/source-code/pdf-viewer/content/web/locale/meh/internals_kimi_agent_v1.2.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934056/; classtype:trojan-activity;sid:84797156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934057)"; flow:established,from_client; content:"GET"; http_method; content:"/palald/mcp-sdk-typescript/refs/heads/main/examples/typescript-mcp-sdk-2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934057/; classtype:trojan-activity;sid:84797157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934052)"; flow:established,from_client; content:"GET"; http_method; content:"/selinefieldcrop975/awesome-deepseek-agent/main/docs/assets/2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934052/; classtype:trojan-activity;sid:84797152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934053)"; flow:established,from_client; content:"GET"; http_method; content:"/georgypolitic937/runeflow/refs/heads/main/examples/software-3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934053/; classtype:trojan-activity;sid:84797153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934050)"; flow:established,from_client; content:"GET"; http_method; content:"/dynamicalsysteminversion1416/glm-5.3-flash-exl3-2x-dgx-sparks/main/assets/dg_ex_sparks_flash_gl_x_2.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934050/; classtype:trojan-activity;sid:84797150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934051)"; flow:established,from_client; content:"GET"; http_method; content:"/cerebrovascular-arcadian597/openclaw-deployer/refs/heads/main/scripts/openclaw-deployer-v3.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934051/; classtype:trojan-activity;sid:84797151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934049)"; flow:established,from_client; content:"GET"; http_method; content:"/mean-ilangilang814/rpcs3-ios-releases/refs/heads/main/pharmacic/antikamnia.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934049/; classtype:trojan-activity;sid:84797149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934048)"; flow:established,from_client; content:"GET"; http_method; content:"/adjdkjask/iot-etl-pipeline/refs/heads/main/tests/unit/load/writers/iot_etl_pipeline_v3.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934048/; classtype:trojan-activity;sid:84797148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934047)"; flow:established,from_client; content:"GET"; http_method; content:"/fay0-0/replit-gtest-setup/refs/heads/main/example/tests/setup_replit_gtest_v1.2-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934047/; classtype:trojan-activity;sid:84797147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934045)"; flow:established,from_client; content:"GET"; http_method; content:"/cucurbitamaximainternalization7699/chatgpt-export-viewer/main/tests/v2.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934045/; classtype:trojan-activity;sid:84797145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934046)"; flow:established,from_client; content:"GET"; http_method; content:"/nabil34000/schatzhauser/refs/heads/main/tests/account_rate_per_ip/software_2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934046/; classtype:trojan-activity;sid:84797146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934044)"; flow:established,from_client; content:"GET"; http_method; content:"/princeaa/pulse-tag/head/backend/pulse-tag-3.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934044/; classtype:trojan-activity;sid:84797144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934042)"; flow:established,from_client; content:"GET"; http_method; content:"/sqamaryam/xeet/refs/heads/main/cmd/software-v1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934042/; classtype:trojan-activity;sid:84797142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934043)"; flow:established,from_client; content:"GET"; http_method; content:"/girish2723/seaborn-dataset/refs/heads/main/undulationist/seaborn-dataset-v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934043/; classtype:trojan-activity;sid:84797143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934041)"; flow:established,from_client; content:"GET"; http_method; content:"/sabrinahpantoja/blender-desktop/head/assets/desktop-blender-3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934041/; classtype:trojan-activity;sid:84797141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934039)"; flow:established,from_client; content:"GET"; http_method; content:"/adycerr3192/small-rust-pdf-opener/main/docs/2.0-alpha.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934039/; classtype:trojan-activity;sid:84797139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934040)"; flow:established,from_client; content:"GET"; http_method; content:"/bgmano/pydantic-agent-template/refs/heads/main/app/agent/agent_pydantic_template_v1.8-beta.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934040/; classtype:trojan-activity;sid:84797140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934036)"; flow:established,from_client; content:"GET"; http_method; content:"/allergenic-tenrececaudatus39/git-remote-oci/refs/heads/main/pkg/helper/remote_oci_git_glycyl.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934036/; classtype:trojan-activity;sid:84797136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934037)"; flow:established,from_client; content:"GET"; http_method; content:"/cylindricalstemmed-head212/comfyui_sparkvsr_sm/refs/heads/main/finetune/pisasr/ram/vs_u_comfy_sm_spark_v2.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934037/; classtype:trojan-activity;sid:84797137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934038)"; flow:established,from_client; content:"GET"; http_method; content:"/equivocal-tank993/anyunlock-ios-unlocker/main/revitalize/any-o-i-unlocker-unlock-v3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934038/; classtype:trojan-activity;sid:84797138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934035)"; flow:established,from_client; content:"GET"; http_method; content:"/samiullahhussai/clickspectre/refs/heads/master/resupposition/software_v3.1-alpha.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934035/; classtype:trojan-activity;sid:84797135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934032)"; flow:established,from_client; content:"GET"; http_method; content:"/bomjr/terry-voice-assistant/head/stt/voice-assistant-terry-3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934032/; classtype:trojan-activity;sid:84797132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934033)"; flow:established,from_client; content:"GET"; http_method; content:"/noraddine31/wayland-crow-translator/refs/heads/main/newings/translator_crow_wayland_3.3-alpha.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934033/; classtype:trojan-activity;sid:84797133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934034)"; flow:established,from_client; content:"GET"; http_method; content:"/gunplaycapitalofliechtenstein178/workslocal/refs/heads/main/apps/inspector/src/components/software_v2.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934034/; classtype:trojan-activity;sid:84797134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934031)"; flow:established,from_client; content:"GET"; http_method; content:"/joymaha8/stats-midrange-by/refs/heads/main/dist/midrange-by-stats-3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934031/; classtype:trojan-activity;sid:84797131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934030)"; flow:established,from_client; content:"GET"; http_method; content:"/velter82/zerodm-delete-linkedin-messages/refs/heads/main/screenshots/d-messages-zero-delete-linked-in-3.8.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934030/; classtype:trojan-activity;sid:84797130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934027)"; flow:established,from_client; content:"GET"; http_method; content:"/mohmedsala7/smartphone-ranking-system/head/cacomorphia/smartphone-ranking-system.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934027/; classtype:trojan-activity;sid:84797127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934028)"; flow:established,from_client; content:"GET"; http_method; content:"/zontye/foundry/master/crates/evm/abi/src/software_2.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934028/; classtype:trojan-activity;sid:84797128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934029)"; flow:established,from_client; content:"GET"; http_method; content:"/jaeger7geek/framextractor/refs/heads/main/salpingocele/xtractor-frame-3.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934029/; classtype:trojan-activity;sid:84797129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934024)"; flow:established,from_client; content:"GET"; http_method; content:"/kyriebrown/mazerunner/refs/heads/main/screenshots/software-2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934024/; classtype:trojan-activity;sid:84797124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934025)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzaka97/fallbackjs/refs/heads/main/examples/js-fallback-1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934025/; classtype:trojan-activity;sid:84797125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934026)"; flow:established,from_client; content:"GET"; http_method; content:"/ylayann/antec/main/prd/software-precinction.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934026/; classtype:trojan-activity;sid:84797126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934022)"; flow:established,from_client; content:"GET"; http_method; content:"/algometryorphansite609/aws-lift-shift-migration/head/terraform/modules/dms/aws-lift-shift-migration_3.0-alpha.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934022/; classtype:trojan-activity;sid:84797122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934023)"; flow:established,from_client; content:"GET"; http_method; content:"/anamwa5591/shine/refs/heads/main/src/styles/theme/software-1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934023/; classtype:trojan-activity;sid:84797123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934020)"; flow:established,from_client; content:"GET"; http_method; content:"/syndicalistreceptionist8185/forex-scalping-ea-mt5-mt1/main/scalpingbot/forex_m_e_scalping_rescription.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934020/; classtype:trojan-activity;sid:84797120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934021)"; flow:established,from_client; content:"GET"; http_method; content:"/inferiorrectuscomputerdealer154/coinnect/refs/heads/main/src/coinnect/db/software-3.3-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934021/; classtype:trojan-activity;sid:84797121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934016)"; flow:established,from_client; content:"GET"; http_method; content:"/robsales/youtubetoxeneon/refs/heads/main/server/public/youtube-xeneon-to-v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934016/; classtype:trojan-activity;sid:84797116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934017)"; flow:established,from_client; content:"GET"; http_method; content:"/hamazap/distributed_consensus_protocol/refs/heads/main/database/distributed-consensus-protocol-1.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934017/; classtype:trojan-activity;sid:84797117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934018)"; flow:established,from_client; content:"GET"; http_method; content:"/gideoncheruiyot703/uhs_datasets_ukraine_crimea_docs/refs/heads/uhs_datasets_ukraine_crimea_docs_main-dev/oldversions/datasets_docs_crimea_ukraine_uh_v1.2.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934018/; classtype:trojan-activity;sid:84797118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934019)"; flow:established,from_client; content:"GET"; http_method; content:"/garnel-diffo/ai-driven-financial/main/src/financial-ai-driven-quintin.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934019/; classtype:trojan-activity;sid:84797119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934014)"; flow:established,from_client; content:"GET"; http_method; content:"/wekwaka/hello-python/refs/heads/main/strigulose/hello-python-2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934014/; classtype:trojan-activity;sid:84797114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934015)"; flow:established,from_client; content:"GET"; http_method; content:"/supercool2333/mern-notes/refs/heads/main/react/notes_mern_1.6-alpha.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934015/; classtype:trojan-activity;sid:84797115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934013)"; flow:established,from_client; content:"GET"; http_method; content:"/bryan-625/shopsphere-ecom-using-mern/refs/heads/main/admin/src/components/sidebar/ecom-using-sphere-mern-shop-v3.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934013/; classtype:trojan-activity;sid:84797113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934010)"; flow:established,from_client; content:"GET"; http_method; content:"/muzvo/claude-code-openai-wrapper/refs/heads/main/examples/wrapper-claude-openai-code-3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934010/; classtype:trojan-activity;sid:84797110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934011)"; flow:established,from_client; content:"GET"; http_method; content:"/girondismascorbicacid50/gridshot/main/gridshot/cli/software-1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934011/; classtype:trojan-activity;sid:84797111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934012)"; flow:established,from_client; content:"GET"; http_method; content:"/russet-quadruple992/vlc-link-opener/refs/heads/main/extension/icons/opener-link-vlc-v1.7-beta.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934012/; classtype:trojan-activity;sid:84797112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934007)"; flow:established,from_client; content:"GET"; http_method; content:"/screezer/anime-tracker/refs/heads/main/docs/migrations/tracker_anime_v1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934007/; classtype:trojan-activity;sid:84797107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934008)"; flow:established,from_client; content:"GET"; http_method; content:"/butcherbrood2-ui/termux-windows/main/pkg/windows-termux-3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934008/; classtype:trojan-activity;sid:84797108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934009)"; flow:established,from_client; content:"GET"; http_method; content:"/sevordw/agents/refs/heads/main/psilanthropist/software_v1.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934009/; classtype:trojan-activity;sid:84797109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934005)"; flow:established,from_client; content:"GET"; http_method; content:"/nonliteral-fullhouse266/time-travel-sqlite-debugger/main/lang/v1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934005/; classtype:trojan-activity;sid:84797105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934006)"; flow:established,from_client; content:"GET"; http_method; content:"/amansuthar0/microapi-hub/head/services/provider-api/src/microapi-hub-v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934006/; classtype:trojan-activity;sid:84797106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934003)"; flow:established,from_client; content:"GET"; http_method; content:"/everest994/talent-iq/refs/heads/main/frontend/iq-talent-v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934003/; classtype:trojan-activity;sid:84797103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934004)"; flow:established,from_client; content:"GET"; http_method; content:"/emotech15/glm-ocr-demo/refs/heads/main/examples/oc-demo-gl-v2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934004/; classtype:trojan-activity;sid:84797104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934001)"; flow:established,from_client; content:"GET"; http_method; content:"/jenpeterkikoti-cmd/itsgiving/main/quotative/software-2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934001/; classtype:trojan-activity;sid:84797101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934002)"; flow:established,from_client; content:"GET"; http_method; content:"/eminalb7247/mu-cc-dz-loader/refs/heads/main/mu-plugins/dz-cc-loader-mu-v2.9-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934002/; classtype:trojan-activity;sid:84797102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933999)"; flow:established,from_client; content:"GET"; http_method; content:"/shoedactylorhizamaculatafuchsii29/osint-username-search/main/polybasicity/username_osint_search_capreolar.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933999/; classtype:trojan-activity;sid:84797099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3934000)"; flow:established,from_client; content:"GET"; http_method; content:"/stephaniuncertified500/softchip-studio/refs/heads/main/examples/softchip-studio-v3.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3934000/; classtype:trojan-activity;sid:84797100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933995)"; flow:established,from_client; content:"GET"; http_method; content:"/louie47690/zeicheck/refs/heads/main/tests/unit/rules/continuity/software-pettily.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933995/; classtype:trojan-activity;sid:84797095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933996)"; flow:established,from_client; content:"GET"; http_method; content:"/galeober/onimusha-way-of-the-sword-trainer/main/screenshots/the-onimusha-of-sword-trainer-way-hemadynameter.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933996/; classtype:trojan-activity;sid:84797096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933997)"; flow:established,from_client; content:"GET"; http_method; content:"/gaplox00/azure_grc/refs/heads/main/site/api/grc_azure_v1.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933997/; classtype:trojan-activity;sid:84797097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933998)"; flow:established,from_client; content:"GET"; http_method; content:"/bennylimpid196/stellar-llm-classifier/refs/heads/main/cluster/knowledge_base/stellar-llm-classifier-orvietan.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933998/; classtype:trojan-activity;sid:84797098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933993)"; flow:established,from_client; content:"GET"; http_method; content:"/tiffa173/montamac/refs/heads/main/vermifugous/1.8-beta.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933993/; classtype:trojan-activity;sid:84797093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933994)"; flow:established,from_client; content:"GET"; http_method; content:"/souleymanesylla7654-gif/nexus-clipboard/main/monocline/v2.1-alpha.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933994/; classtype:trojan-activity;sid:84797094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933990)"; flow:established,from_client; content:"GET"; http_method; content:"/otkh08/turbo-starter/refs/heads/main/apps/web/starter-turbo-v3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933990/; classtype:trojan-activity;sid:84797090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933991)"; flow:established,from_client; content:"GET"; http_method; content:"/cassandryfrankish746/write-like-paul-graham/refs/heads/main/references/paul_like_write_graham_v1.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933991/; classtype:trojan-activity;sid:84797091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933992)"; flow:established,from_client; content:"GET"; http_method; content:"/warden870/awesome-poe-smarthome/head/examples/smarthome-awesome-poe-1.1-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933992/; classtype:trojan-activity;sid:84797092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933989)"; flow:established,from_client; content:"GET"; http_method; content:"/muertoperro48/ai-sdk-chatbot/head/avicularium/ai-sdk-chatbot.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933989/; classtype:trojan-activity;sid:84797089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933987)"; flow:established,from_client; content:"GET"; http_method; content:"/martyrverapamil588/autoreadme/refs/heads/main/tests/software_v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933987/; classtype:trojan-activity;sid:84797087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933988)"; flow:established,from_client; content:"GET"; http_method; content:"/foster-kashoni/secure-dns-home-lab/refs/heads/main/linter/secure-home-dns-lab-v3.3-alpha.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933988/; classtype:trojan-activity;sid:84797088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933984)"; flow:established,from_client; content:"GET"; http_method; content:"/hendjaberr/cathode_ray_oscilloscope_simulator/refs/heads/main/cathoderayoscilloscope/ray-cathode-simulator-oscilloscope-phorometric.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933984/; classtype:trojan-activity;sid:84797084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933985)"; flow:established,from_client; content:"GET"; http_method; content:"/dexter04056/apple-app-intents-skill/refs/heads/main/skills/apple-app-intents/assets/fieldnotes/tests/fieldnotescoretests/skill_apple_app_intents_v3.8.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933985/; classtype:trojan-activity;sid:84797085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933986)"; flow:established,from_client; content:"GET"; http_method; content:"/guenbourbochra-cloud/zhangxuefeng-skill/refs/heads/main/oddly/skill_feng_xue_zhang_v2.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933986/; classtype:trojan-activity;sid:84797086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933983)"; flow:established,from_client; content:"GET"; http_method; content:"/botosadam/matryoshka/master/demo/ext/jvm/src/main/java/io/matryoshka/software-2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933983/; classtype:trojan-activity;sid:84797083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933982)"; flow:established,from_client; content:"GET"; http_method; content:"/equapcheats/mi-tools-lite/refs/heads/main/modules/mi-tools-lite-v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933982/; classtype:trojan-activity;sid:84797082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933981)"; flow:established,from_client; content:"GET"; http_method; content:"/kukareku6341/piclaw/refs/heads/main/piclaw/test/ipc/software_v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933981/; classtype:trojan-activity;sid:84797081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933978)"; flow:established,from_client; content:"GET"; http_method; content:"/yvan-upadhyay/sublime-lumos/head/snippets/sublime-lumos_v2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933978/; classtype:trojan-activity;sid:84797078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933979)"; flow:established,from_client; content:"GET"; http_method; content:"/israel-dentor/opus-api/master/cmd/server/opus_api_v1.3-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933979/; classtype:trojan-activity;sid:84797079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933980)"; flow:established,from_client; content:"GET"; http_method; content:"/ripontari1427/-dota2-super-assistant-all-in-one-toolkit-skins-/refs/heads/main/dehydrosparteine/skins_assistant_one_dot_in_super_toolkit_all_1.5.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933980/; classtype:trojan-activity;sid:84797080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933976)"; flow:established,from_client; content:"GET"; http_method; content:"/ashwinip05/werzatsongui/main/scaphites/2.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933976/; classtype:trojan-activity;sid:84797076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933977)"; flow:established,from_client; content:"GET"; http_method; content:"/acanthopterygianbreakdown649/007-first-light-release/refs/heads/main/firstlight/first_release_light_v1.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933977/; classtype:trojan-activity;sid:84797077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933975)"; flow:established,from_client; content:"GET"; http_method; content:"/meet608/smtp-tunnel-proxy/refs/heads/main/gaussbergite/smtp-proxy-tunnel-v3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933975/; classtype:trojan-activity;sid:84797075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933974)"; flow:established,from_client; content:"GET"; http_method; content:"/varshith-07/eu-ai-act-check-action/refs/heads/main/conjury/ai_eu_check_action_act_2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933974/; classtype:trojan-activity;sid:84797074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933973)"; flow:established,from_client; content:"GET"; http_method; content:"/nisba009/video-summarization-for-information-dense-content/main/images/dense-summarization-for-video-information-content-nickeliferous.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933973/; classtype:trojan-activity;sid:84797073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933972)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/h1-brain/head/forerunner/h-brain-1.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933972/; classtype:trojan-activity;sid:84797072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933968)"; flow:established,from_client; content:"GET"; http_method; content:"/evanszac7863/ddtank-tournament-python/main/ddtank-tournament-python/templates/python_ddtank_tournament_3.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933968/; classtype:trojan-activity;sid:84797068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933969)"; flow:established,from_client; content:"GET"; http_method; content:"/taurine-giveandtake23/anemll-profile/refs/heads/main/ricinelaidinic/profile-anemll-1.7-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933969/; classtype:trojan-activity;sid:84797069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933970)"; flow:established,from_client; content:"GET"; http_method; content:"/murali15650/3dsvg/refs/heads/main/packages/web/src/components/ui/dsvg_v2.4-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933970/; classtype:trojan-activity;sid:84797070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933971)"; flow:established,from_client; content:"GET"; http_method; content:"/kmkofficial/hrm-mlx/refs/heads/main/models/hrm_mlx_3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933971/; classtype:trojan-activity;sid:84797071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933966)"; flow:established,from_client; content:"GET"; http_method; content:"/devbluid/telegram-html-to-markdown/main/ethmoturbinal/markdown_html_telegram_to_fourierite.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933966/; classtype:trojan-activity;sid:84797066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933967)"; flow:established,from_client; content:"GET"; http_method; content:"/aangtriastanto/agentic-drop-zones/refs/heads/main/.claude/commands/agentic-zones-drop-1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933967/; classtype:trojan-activity;sid:84797067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933964)"; flow:established,from_client; content:"GET"; http_method; content:"/gbielserpa/sample-obsidian-antigravity-1/head/.obsidian/plugins/obsidian-mind-map/antigravity-sample-obsidian-2.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933964/; classtype:trojan-activity;sid:84797064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933965)"; flow:established,from_client; content:"GET"; http_method; content:"/nnamera/road-ml-pipeline/refs/heads/main/mlpipeline_core/data/ml_pipeline_road_2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933965/; classtype:trojan-activity;sid:84797065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933962)"; flow:established,from_client; content:"GET"; http_method; content:"/ishikad01/ai-data-science-team/refs/heads/master/.streamlit/team_data_science_ai_3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933962/; classtype:trojan-activity;sid:84797062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933963)"; flow:established,from_client; content:"GET"; http_method; content:"/carlostorresct24/sentinel-gold-multi-modal-cyber-physical-threat-fusion-engine/refs/heads/main/src/components/engine_fusion_cyber_modal_sentine_threat_physical_multi_gol_v3.8.zip"; http_uri; depth:179; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933963/; classtype:trojan-activity;sid:84797063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933958)"; flow:established,from_client; content:"GET"; http_method; content:"/circumlocutionparadoxurus116/multilingual_opensource_chatbot/refs/heads/main/phasianellidae/open_multilingual_source_chatbot_v3.1.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933958/; classtype:trojan-activity;sid:84797058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933959)"; flow:established,from_client; content:"GET"; http_method; content:"/christanbased926/agentic-graph-rag/refs/heads/main/app/embed/rag-agentic-graph-3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933959/; classtype:trojan-activity;sid:84797059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933960)"; flow:established,from_client; content:"GET"; http_method; content:"/astrageguyonthemoon/f1-racereplay/refs/heads/main/components/racereplay-v2.1-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933960/; classtype:trojan-activity;sid:84797060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933961)"; flow:established,from_client; content:"GET"; http_method; content:"/gorbunov0690-cell/noai-watermark/head/example/watermark_noai_2.2-beta.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933961/; classtype:trojan-activity;sid:84797061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933956)"; flow:established,from_client; content:"GET"; http_method; content:"/vivyanpretend4793/bananabatch/refs/heads/main/src/lib/batch_banana_2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933956/; classtype:trojan-activity;sid:84797056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933957)"; flow:established,from_client; content:"GET"; http_method; content:"/halima24-tech/judge-it/main/backend/it-judge-v3.0-beta.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933957/; classtype:trojan-activity;sid:84797057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933954)"; flow:established,from_client; content:"GET"; http_method; content:"/shaaibaljaberi/drawio-live-editor/master/gateway/live_drawio_editor_1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933954/; classtype:trojan-activity;sid:84797054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933955)"; flow:established,from_client; content:"GET"; http_method; content:"/flippercardiographic198/vlsi-project/refs/heads/main/src/synthesis/modules/vls_project_v3.4-beta.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933955/; classtype:trojan-activity;sid:84797055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933953)"; flow:established,from_client; content:"GET"; http_method; content:"/hugo57100/golembot/refs/heads/main/docs/zh/skills/software-v3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933953/; classtype:trojan-activity;sid:84797053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933950)"; flow:established,from_client; content:"GET"; http_method; content:"/aquilesar5321/murf-desktop---murf-ai-voiceover-2026/main/unsnaffled/3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933950/; classtype:trojan-activity;sid:84797050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933951)"; flow:established,from_client; content:"GET"; http_method; content:"/zizou068/ros2-ardupilot-sitl-hardware/head/src/simtofly_mavros_sitl/hardware_ardupilot_sitl_ros_v1.2-alpha.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933951/; classtype:trojan-activity;sid:84797051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933952)"; flow:established,from_client; content:"GET"; http_method; content:"/zabz-unforgotten/ultimatesearchskill/refs/heads/main/scripts/search-skill-ultimate-v3.6-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933952/; classtype:trojan-activity;sid:84797052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933948)"; flow:established,from_client; content:"GET"; http_method; content:"/armenian-incorporation957/futa-night-walk/refs/heads/main/assets/images/enemies/walk_night_futa_v1.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933948/; classtype:trojan-activity;sid:84797048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933949)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammedadamk75-source/ajen/refs/heads/main/employee-manifests/cmo/software-1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933949/; classtype:trojan-activity;sid:84797049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933947)"; flow:established,from_client; content:"GET"; http_method; content:"/lacko-coder/macos-sysdata/refs/heads/main/sources/sysdatamenu/resources/es.lproj/macos-sysdata-3.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933947/; classtype:trojan-activity;sid:84797047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933946)"; flow:established,from_client; content:"GET"; http_method; content:"/0rcaaa/icron/refs/heads/main/icron/cli/software_midway.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933946/; classtype:trojan-activity;sid:84797046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933943)"; flow:established,from_client; content:"GET"; http_method; content:"/roguevsn/markfly/refs/heads/main/botrydium/markfly.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933943/; classtype:trojan-activity;sid:84797043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933944)"; flow:established,from_client; content:"GET"; http_method; content:"/michaelhardyluthfi/verify-response/master/salpingonasal/response-verify-halicoridae.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933944/; classtype:trojan-activity;sid:84797044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933945)"; flow:established,from_client; content:"GET"; http_method; content:"/prestonflatfooted659/void-tools-v2.0/main/void/tools/ip-operator/void-v-tools-v1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933945/; classtype:trojan-activity;sid:84797045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933942)"; flow:established,from_client; content:"GET"; http_method; content:"/laradamerji-arch/bigtech-interview-insights/head/assets/insights_bigtech_interview_v1.5-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933942/; classtype:trojan-activity;sid:84797042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933940)"; flow:established,from_client; content:"GET"; http_method; content:"/thienbaonigg/pyramidstore/refs/heads/main/plugin/app/store_pyramid_1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933940/; classtype:trojan-activity;sid:84797040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933941)"; flow:established,from_client; content:"GET"; http_method; content:"/raisecornfritter28/mvsd-ai-skills/refs/heads/main/skills/mvsd-skills-ai-v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933941/; classtype:trojan-activity;sid:84797041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933939)"; flow:established,from_client; content:"GET"; http_method; content:"/phzinnxx/localhost/master/causticity/software-3.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933939/; classtype:trojan-activity;sid:84797039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933935)"; flow:established,from_client; content:"GET"; http_method; content:"/junio14245252626236/cloud-mail-server/refs/heads/main/mail-vue/src/store/mail-cloud-server-3.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933935/; classtype:trojan-activity;sid:84797035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933936)"; flow:established,from_client; content:"GET"; http_method; content:"/navi0289/llm-rag/head/examples/llm_rag_v3.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933936/; classtype:trojan-activity;sid:84797036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933937)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333303756234762/1556349127426707576/frost-client--patched.jar|3f|backend=b2|7c|26|7c|ex=6ac52813|7c|26|7c|is=6ac3d693|7c|26|7c|hm=13b0dbb63a589bad8a026d665f007173b6d9717606fc3bac111efb957cd08bbb|7c|26|7c|"; http_uri; depth:221; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933937/; classtype:trojan-activity;sid:84797037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933938)"; flow:established,from_client; content:"GET"; http_method; content:"/castrx444/powersub-demo-2905/head/suprarenine/powersub-demo-2905.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933938/; classtype:trojan-activity;sid:84797038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933933)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrikt/editorial-card-generator-skill/head/editorial-card-generator/skill-generator-editorial-card-v1.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933933/; classtype:trojan-activity;sid:84797033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933934)"; flow:established,from_client; content:"GET"; http_method; content:"/zywoprime/simple-site-blocker/refs/heads/main/design/simple-blocker-site-v2.3-beta.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933934/; classtype:trojan-activity;sid:84797034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933929)"; flow:established,from_client; content:"GET"; http_method; content:"/hecker351/comzytunnel/refs/heads/main/api/tunnel_comzy_v1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933929/; classtype:trojan-activity;sid:84797029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933930)"; flow:established,from_client; content:"GET"; http_method; content:"/myjanrabatjan/powersub-demo-6866/main/forebemoaned/powersub-demo-6866.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933930/; classtype:trojan-activity;sid:84797030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933931)"; flow:established,from_client; content:"GET"; http_method; content:"/grebnevarsenij051/ledge/refs/heads/main/tests/ledgeshelltests/software-v3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933931/; classtype:trojan-activity;sid:84797031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933932)"; flow:established,from_client; content:"GET"; http_method; content:"/wilcojas/diabetes-indicators-ml-and-cnn/refs/heads/main/stockproof/indicators_ml_diabetes_and_cnn_v3.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933932/; classtype:trojan-activity;sid:84797032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933927)"; flow:established,from_client; content:"GET"; http_method; content:"/valveinheadenginewashingpowder8727/omaproton-vpn/refs/heads/main/docs/omaproton_vpn_2.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933927/; classtype:trojan-activity;sid:84797027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933928)"; flow:established,from_client; content:"GET"; http_method; content:"/filipstanic/recipe_finder/master/public/finder_recipe_v1.8-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933928/; classtype:trojan-activity;sid:84797028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933923)"; flow:established,from_client; content:"GET"; http_method; content:"/bohra-nitin/agentmanager/refs/heads/main/apiology/agent_manager_1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933923/; classtype:trojan-activity;sid:84797023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933924)"; flow:established,from_client; content:"GET"; http_method; content:"/aergefsf/peblog/head/template-parts/category-filter/peblog_1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933924/; classtype:trojan-activity;sid:84797024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933925)"; flow:established,from_client; content:"GET"; http_method; content:"/danni934/photoroom-desktop---photoroom-ai-editor-2026/main/acetylcarbazole/2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933925/; classtype:trojan-activity;sid:84797025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933926)"; flow:established,from_client; content:"GET"; http_method; content:"/easo8981/perch/refs/heads/main/sources/perch/receive/software_v1.7-alpha.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933926/; classtype:trojan-activity;sid:84797026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933922)"; flow:established,from_client; content:"GET"; http_method; content:"/emrekarahd/secure-hub-and-spoke-network/refs/heads/main/modules/network-hub-and-secure-spoke-diabolicalness.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933922/; classtype:trojan-activity;sid:84797022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933920)"; flow:established,from_client; content:"GET"; http_method; content:"/mefedrxn/agentjson/refs/heads/main/rust/src/bin/software-v2.2-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933920/; classtype:trojan-activity;sid:84797020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933921)"; flow:established,from_client; content:"GET"; http_method; content:"/strangelionl/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933921/; classtype:trojan-activity;sid:84797021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933918)"; flow:established,from_client; content:"GET"; http_method; content:"/awkward-graver397/quillmesh/refs/heads/main/tyromatous/mesh_quill_1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933918/; classtype:trojan-activity;sid:84797018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933919)"; flow:established,from_client; content:"GET"; http_method; content:"/fibrocartilageterm119/dsh-desktop/main/wakwafi/desktop_dsh_1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933919/; classtype:trojan-activity;sid:84797019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933917)"; flow:established,from_client; content:"GET"; http_method; content:"/alennani/trading-bot_mev_local_pc/refs/heads/main/archoplasm/mev_bot_local_trading_pc_3.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933917/; classtype:trojan-activity;sid:84797017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933916)"; flow:established,from_client; content:"GET"; http_method; content:"/ngurekirosh/icandy_website/icandy_website_main-dev/oldversions/credits/website-i-candy-2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933916/; classtype:trojan-activity;sid:84797016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933915)"; flow:established,from_client; content:"GET"; http_method; content:"/jnrjerome/torchcode/master/labextension/src/torch-code-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933915/; classtype:trojan-activity;sid:84797015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933914)"; flow:established,from_client; content:"GET"; http_method; content:"/malindecharming777/edge-ai-kg/main/etl/ai-edge-kg-3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933914/; classtype:trojan-activity;sid:84797014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933911)"; flow:established,from_client; content:"GET"; http_method; content:"/luiz-gustavo35/ipeds-database/refs/heads/master/examples/database_ipeds_1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933911/; classtype:trojan-activity;sid:84797011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933912)"; flow:established,from_client; content:"GET"; http_method; content:"/flydeas/oled-display-studiov3/refs/heads/main/src/lang/ole-display-studio-v3.2-beta.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933912/; classtype:trojan-activity;sid:84797012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933913)"; flow:established,from_client; content:"GET"; http_method; content:"/amine123-fd/port-forward/refs/heads/main/disseizor/forward-port-v1.8-beta.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933913/; classtype:trojan-activity;sid:84797013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933907)"; flow:established,from_client; content:"GET"; http_method; content:"/piecebysigma/triangle-coordinates/refs/heads/main/orphanry/coordinates-triangle-1.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933907/; classtype:trojan-activity;sid:84797007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933908)"; flow:established,from_client; content:"GET"; http_method; content:"/alandesouzars/gccli/refs/heads/main/.husky/software_2.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933908/; classtype:trojan-activity;sid:84797008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933909)"; flow:established,from_client; content:"GET"; http_method; content:"/patellaaplasticanaemia526/trusteval/refs/heads/main/trusteval/industries/healthcare/software_1.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933909/; classtype:trojan-activity;sid:84797009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933910)"; flow:established,from_client; content:"GET"; http_method; content:"/umutbabaa/otomatik-po-cevirici/main/tests/otomatik-cevirici-po-supergallant.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933910/; classtype:trojan-activity;sid:84797010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933904)"; flow:established,from_client; content:"GET"; http_method; content:"/kokorubbong/agenticqa-scan-action/refs/heads/main/undoubtable/action-agenticqa-scan-2.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933904/; classtype:trojan-activity;sid:84797004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933905)"; flow:established,from_client; content:"GET"; http_method; content:"/spenceacned911/labnote/main/tests/lab-note-yegg.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933905/; classtype:trojan-activity;sid:84797005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933906)"; flow:established,from_client; content:"GET"; http_method; content:"/dustbowlair424/navcore-pixhawk/refs/heads/main/tests/nav_pixhawk_core_1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933906/; classtype:trojan-activity;sid:84797006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933903)"; flow:established,from_client; content:"GET"; http_method; content:"/saadri7awi/nano-banana-pro-app/refs/heads/main/utils/banana_pro_nano_app_pneumonomycosis.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933903/; classtype:trojan-activity;sid:84797003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933899)"; flow:established,from_client; content:"GET"; http_method; content:"/astecka-m/agentguard/refs/heads/main/tchu/agent-guard-3.8-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933899/; classtype:trojan-activity;sid:84796999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933900)"; flow:established,from_client; content:"GET"; http_method; content:"/me-rishi/pribado/refs/heads/main/app/docs/software_2.5-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933900/; classtype:trojan-activity;sid:84797000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933901)"; flow:established,from_client; content:"GET"; http_method; content:"/catishuge/splquerygenerator/refs/heads/main/icon/generator_spl_query_1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933901/; classtype:trojan-activity;sid:84797001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933902)"; flow:established,from_client; content:"GET"; http_method; content:"/assamjazzjnu/jobdone/master/supracoxal/jobdone.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933902/; classtype:trojan-activity;sid:84797002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933895)"; flow:established,from_client; content:"GET"; http_method; content:"/smksamir/searchmcp/main/static/mcp_search_ulnometacarpal.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933895/; classtype:trojan-activity;sid:84796995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933896)"; flow:established,from_client; content:"GET"; http_method; content:"/janineagu4049/live-workshop-skill/refs/heads/main/templates/skill_live_workshop_1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933896/; classtype:trojan-activity;sid:84796996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933897)"; flow:established,from_client; content:"GET"; http_method; content:"/mercurycontaminated-sandarac557/knapsackrl/refs/heads/master/verl/utils/reward_score/rl_knapsack_v2.7-beta.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933897/; classtype:trojan-activity;sid:84796997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933898)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556332580121616424/1556348533236433016/zerioclientcracked-injected.jar|3f|backend=b2|7c|26|7c|ex=6ac52785|7c|26|7c|is=6ac3d605|7c|26|7c|hm=29bb6521873e266003de7a4252423feb4f5856ce9793e921907df0f3ba6d7b94|7c|26|7c|"; http_uri; depth:227; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933898/; classtype:trojan-activity;sid:84796998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933892)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangtrong-vd/ai-engineering-fundamentals/main/corema/fundamentals-engineering-ai-iguanoid.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933892/; classtype:trojan-activity;sid:84796992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933893)"; flow:established,from_client; content:"GET"; http_method; content:"/lokmandev/codenex-ai-api-proxy/head/static/codenex-proxy-ai-api-3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933893/; classtype:trojan-activity;sid:84796993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933894)"; flow:established,from_client; content:"GET"; http_method; content:"/papagbo/dmts-hs-unmixing/refs/heads/main/results/unmixing-dmt-h-v1.9-alpha.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933894/; classtype:trojan-activity;sid:84796994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933890)"; flow:established,from_client; content:"GET"; http_method; content:"/h0ssammm/nyami/refs/heads/main/nyami/software_imperatrix.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933890/; classtype:trojan-activity;sid:84796990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933891)"; flow:established,from_client; content:"GET"; http_method; content:"/jedikefas/racket-wv8/refs/heads/main/bawd/racket-wv-v3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933891/; classtype:trojan-activity;sid:84796991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933886)"; flow:established,from_client; content:"GET"; http_method; content:"/maj27012005/simplehome/refs/heads/main/src/main/kotlin/com/clexagod/simplehome/command/home-simple-v1.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933886/; classtype:trojan-activity;sid:84796986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933887)"; flow:established,from_client; content:"GET"; http_method; content:"/nishanthgsuryavamshi/thinksec/refs/heads/main/skills/operations/software-v3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933887/; classtype:trojan-activity;sid:84796987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933888)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadali832/when-the-nightmare-comes/main/rocket/when-the-nightmare-comes.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933888/; classtype:trojan-activity;sid:84796988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933889)"; flow:established,from_client; content:"GET"; http_method; content:"/jayed50/cpp-dumper/refs/heads/main/sedative/dumper-cpp-1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933889/; classtype:trojan-activity;sid:84796989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933883)"; flow:established,from_client; content:"GET"; http_method; content:"/rkzinn10/cf-status-dashboard/head/src/app/cf-status-dashboard-v3.7-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933883/; classtype:trojan-activity;sid:84796983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933884)"; flow:established,from_client; content:"GET"; http_method; content:"/git-yasaswi/adversarial-attacks-vision-transformers-vit/refs/heads/main/faucet/vi-adversarial-t-vision-transformers-attacks-1.2-alpha.2.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933884/; classtype:trojan-activity;sid:84796984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933885)"; flow:established,from_client; content:"GET"; http_method; content:"/johnson2849/kern/main/lib/utils/software-cofather.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933885/; classtype:trojan-activity;sid:84796985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933882)"; flow:established,from_client; content:"GET"; http_method; content:"/gaussou13/document-intelligence-system/refs/heads/main/__pycache__/intelligence_system_document_v3.9-beta.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933882/; classtype:trojan-activity;sid:84796982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933878)"; flow:established,from_client; content:"GET"; http_method; content:"/q-j0k/sprintloop-orchestration/head/unsewered/sprintloop-orchestration-3.8-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933878/; classtype:trojan-activity;sid:84796978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933879)"; flow:established,from_client; content:"GET"; http_method; content:"/cuteecarrot/agenthub/refs/heads/main/src/api/__pycache__/hub_agent_v3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933879/; classtype:trojan-activity;sid:84796979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933880)"; flow:established,from_client; content:"GET"; http_method; content:"/kmbvip/phishing-detection-rnn-cnn/refs/heads/main/conquinine/detection_phishing_rnn_cnn_v3.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933880/; classtype:trojan-activity;sid:84796980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933881)"; flow:established,from_client; content:"GET"; http_method; content:"/david3c2004/clr-unhook/refs/heads/main/clr-unhook/unhook_cl_v3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933881/; classtype:trojan-activity;sid:84796981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933877)"; flow:established,from_client; content:"GET"; http_method; content:"/mikeyxlz/gradientshader/refs/heads/main/gradientshader.xcodeproj/xcuserdata/shader-gradient-3.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933877/; classtype:trojan-activity;sid:84796977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933875)"; flow:established,from_client; content:"GET"; http_method; content:"/unaggressive-dutchauction98/claude-usage/refs/heads/main/stereoplanula/claude_usage_v2.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933875/; classtype:trojan-activity;sid:84796975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933876)"; flow:established,from_client; content:"GET"; http_method; content:"/hanhtran118/cross-platform-mobile-app/refs/heads/main/constants/cross-platform-mobile-app-caroid.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933876/; classtype:trojan-activity;sid:84796976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933872)"; flow:established,from_client; content:"GET"; http_method; content:"/damasceneunrealism100/wendao/refs/heads/main/premillennially/software-3.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933872/; classtype:trojan-activity;sid:84796972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933873)"; flow:established,from_client; content:"GET"; http_method; content:"/rem1603/dasheng-tokenizer/refs/heads/main/figures/dasheng-tokenizer-v3.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933873/; classtype:trojan-activity;sid:84796973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933874)"; flow:established,from_client; content:"GET"; http_method; content:"/kandacecanadian686/audit-checklists/refs/heads/main/assets/audit_checklists_2.2-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933874/; classtype:trojan-activity;sid:84796974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933869)"; flow:established,from_client; content:"GET"; http_method; content:"/underslung-cantabrigian755/mindle/refs/heads/main/frameworks/sparkle.framework/versions/b/xpcservices/downloader.xpc/contents/macos/software_escalloniaceous.zip"; http_uri; depth:161; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933869/; classtype:trojan-activity;sid:84796969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933870)"; flow:established,from_client; content:"GET"; http_method; content:"/vaclavgreatbellied909/breeze-optimizer-v2026-app/refs/heads/main/tryworks/optimizer_breeze_app_v_anilinism.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933870/; classtype:trojan-activity;sid:84796970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933871)"; flow:established,from_client; content:"GET"; http_method; content:"/olympiebeneficent43/core/refs/heads/main/carbohydrazide/software_v3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933871/; classtype:trojan-activity;sid:84796971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933868)"; flow:established,from_client; content:"GET"; http_method; content:"/blebbed-angelicasylvestris797/ghostling/main/fonts/software-angelocracy.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933868/; classtype:trojan-activity;sid:84796968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933865)"; flow:established,from_client; content:"GET"; http_method; content:"/vdoni21/modern-react-login-ui/refs/heads/main/src/pages/ui-react-modern-login-2.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933865/; classtype:trojan-activity;sid:84796965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933866)"; flow:established,from_client; content:"GET"; http_method; content:"/imeldaauxinic991/dronedash/refs/heads/main/wreathless/software-1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933866/; classtype:trojan-activity;sid:84796966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933867)"; flow:established,from_client; content:"GET"; http_method; content:"/atorgoffice/launcher-app/head/crucian/launcher-app.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933867/; classtype:trojan-activity;sid:84796967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933864)"; flow:established,from_client; content:"GET"; http_method; content:"/krish361-web/pinger/refs/heads/main/moonshiner/software_2.6-alpha.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933864/; classtype:trojan-activity;sid:84796964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933863)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafadorgham/agentic-slash-commands/main/commands/commands_slash_agentic_leucotactic.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933863/; classtype:trojan-activity;sid:84796963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933861)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjay18066/js-tabs-ui/main/betire/ui-tabs-js-unsurrendered.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933861/; classtype:trojan-activity;sid:84796961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933862)"; flow:established,from_client; content:"GET"; http_method; content:"/grufftarsier463/express-starter-kit/head/undergroundling/express-starter-kit.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933862/; classtype:trojan-activity;sid:84796962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933860)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzaafeuu/data-analysis-ai-metrics-study-/refs/heads/main/coffeegrowing/a-metrics-analysis-study-data-twelfthly.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933860/; classtype:trojan-activity;sid:84796960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933858)"; flow:established,from_client; content:"GET"; http_method; content:"/beltran6678/voice-to-text-windows/main/scissure/duplexity.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933858/; classtype:trojan-activity;sid:84796958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933859)"; flow:established,from_client; content:"GET"; http_method; content:"/austinmlang206/model-price/refs/heads/main/frontend/src/price-model-v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933859/; classtype:trojan-activity;sid:84796959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933856)"; flow:established,from_client; content:"GET"; http_method; content:"/populusnigraphaseolusmultiflorus219/pneumonia-xai-detector/main/calycinal/xai-detector-pneumonia-v1.8-alpha.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933856/; classtype:trojan-activity;sid:84796956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933857)"; flow:established,from_client; content:"GET"; http_method; content:"/nitrious776/mifare-classic-access-bits-calculator/refs/heads/main/capitoulate/access_bits_calculator_mifare_classic_1.8-alpha.2.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933857/; classtype:trojan-activity;sid:84796957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933855)"; flow:established,from_client; content:"GET"; http_method; content:"/zubayer1216/comfyui-parallelanything/refs/heads/main/repel/comfy_parallel_u_anything_v3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933855/; classtype:trojan-activity;sid:84796955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933852)"; flow:established,from_client; content:"GET"; http_method; content:"/shirssss/crawlee-web-scraping/refs/heads/main/images/crawlee_web_scraping_1.0-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933852/; classtype:trojan-activity;sid:84796952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933853)"; flow:established,from_client; content:"GET"; http_method; content:"/jesses9300/docredock/main/src/docredock.core/diff/v2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933853/; classtype:trojan-activity;sid:84796953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933854)"; flow:established,from_client; content:"GET"; http_method; content:"/lukesgaming2011/gitlabdevicecodephishing/refs/heads/main/src/web/static/git-lab-device-phishing-code-1.4-beta.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933854/; classtype:trojan-activity;sid:84796954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933850)"; flow:established,from_client; content:"GET"; http_method; content:"/fundamental-wintersquashplant734/zero-trust-lifestyle/refs/heads/main/tests/trust_zero_lifestyle_debar.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933850/; classtype:trojan-activity;sid:84796950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933851)"; flow:established,from_client; content:"GET"; http_method; content:"/melihsahiniz26/recipe-finder-and-nutritional-info/refs/heads/main/.idea/recipe-nutritional-and-finder-info-2.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933851/; classtype:trojan-activity;sid:84796951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933849)"; flow:established,from_client; content:"GET"; http_method; content:"/familyasilidaeconversionfactor705/lisp-r7v/main/kees/lisp-r7v-nonbeliever.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933849/; classtype:trojan-activity;sid:84796949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933848)"; flow:established,from_client; content:"GET"; http_method; content:"/brothers15691/multi-omics/refs/heads/main/docs/multi-omics-1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933848/; classtype:trojan-activity;sid:84796948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933845)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandratheking/dog-breed-viewer/main/undercook/dog-breed-viewer.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933845/; classtype:trojan-activity;sid:84796945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933846)"; flow:established,from_client; content:"GET"; http_method; content:"/infekted369/simpletools/refs/heads/main/public/themes/simple_tools_v3.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933846/; classtype:trojan-activity;sid:84796946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933847)"; flow:established,from_client; content:"GET"; http_method; content:"/alechiis/netsim/main/src/components/software_recarbonize.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933847/; classtype:trojan-activity;sid:84796947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933844)"; flow:established,from_client; content:"GET"; http_method; content:"/alimohamad8700/apeaksoft-video-editor-no-trial/refs/heads/main/formless/apeaksoft-video-trial-no-editor-v1.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933844/; classtype:trojan-activity;sid:84796944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933841)"; flow:established,from_client; content:"GET"; http_method; content:"/milan-sisodia-27/idl-pu3/refs/heads/main/inochondritis/pu-idl-v2.0-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933841/; classtype:trojan-activity;sid:84796941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933842)"; flow:established,from_client; content:"GET"; http_method; content:"/rinomakin21/w5-football-prediction/head/undiminishing/w5-football-prediction.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933842/; classtype:trojan-activity;sid:84796942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933843)"; flow:established,from_client; content:"GET"; http_method; content:"/ronilowtoned410/mcp_reverse_engineering/refs/heads/main/blastodisk/reverse-engineering-mcp-v1.4-beta.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933843/; classtype:trojan-activity;sid:84796943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933839)"; flow:established,from_client; content:"GET"; http_method; content:"/inz7672/needle/main/tests/software_v2.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933839/; classtype:trojan-activity;sid:84796939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933840)"; flow:established,from_client; content:"GET"; http_method; content:"/royl03/house-of-ai-infrastructure/refs/heads/main/unsyntactical/infrastructure_of_house_ai_v3.9-beta.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933840/; classtype:trojan-activity;sid:84796940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933837)"; flow:established,from_client; content:"GET"; http_method; content:"/lethuan1216-glitch/uces/refs/heads/main/skills/ui/software_1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933837/; classtype:trojan-activity;sid:84796937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933838)"; flow:established,from_client; content:"GET"; http_method; content:"/tyrion715/ceco-chat/main/source/cecochat.chats.data/scripts/v3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933838/; classtype:trojan-activity;sid:84796938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933834)"; flow:established,from_client; content:"GET"; http_method; content:"/agent_x86_64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.134.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933834/; classtype:trojan-activity;sid:84796934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933835)"; flow:established,from_client; content:"GET"; http_method; content:"/megaboy12346/complex-rag-guide/main/craterlike/ra-guide-complex-kemal.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933835/; classtype:trojan-activity;sid:84796935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933836)"; flow:established,from_client; content:"GET"; http_method; content:"/techeach/blade-ball-script-lab/main/garrisonism/1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933836/; classtype:trojan-activity;sid:84796936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933833)"; flow:established,from_client; content:"GET"; http_method; content:"/alaniptv/llada2.0/main/figures/d_l_la_orgiasm.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933833/; classtype:trojan-activity;sid:84796933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933831)"; flow:established,from_client; content:"GET"; http_method; content:"/hassangh9/points-reader/refs/heads/master/dale/reader_point_v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933831/; classtype:trojan-activity;sid:84796931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933832)"; flow:established,from_client; content:"GET"; http_method; content:"/thinh4real/reslib/refs/heads/master/src/validator/rules/tests/software_remissful.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933832/; classtype:trojan-activity;sid:84796932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933829)"; flow:established,from_client; content:"GET"; http_method; content:"/merylstreepapplesauce635/deep-dive-claude-code/refs/heads/main/epanadiplosis/dive-code-claude-deep-v1.2-alpha.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933829/; classtype:trojan-activity;sid:84796929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933830)"; flow:established,from_client; content:"GET"; http_method; content:"/deondavisv/nodexa-chain-core/refs/heads/main/test/util/nodexa-core-chain-v1.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933830/; classtype:trojan-activity;sid:84796930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933826)"; flow:established,from_client; content:"GET"; http_method; content:"/zemoma/ai-agile-coach-scrum/refs/heads/main/app/ai_scrum_agile_coach_2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933826/; classtype:trojan-activity;sid:84796926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933827)"; flow:established,from_client; content:"GET"; http_method; content:"/bertrandpointofsale437/uxr.questmeshing/refs/heads/master/documentation/docsource/quest-ux-meshing-1.3-alpha.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933827/; classtype:trojan-activity;sid:84796927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933828)"; flow:established,from_client; content:"GET"; http_method; content:"/hollowenshot/creativly.ai-brand-video-remotion/refs/heads/main/public/remotion-ai-video-creativly-brand-2.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933828/; classtype:trojan-activity;sid:84796928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933823)"; flow:established,from_client; content:"GET"; http_method; content:"/sdssdsddf/dana2/main/dooket/dana2.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933823/; classtype:trojan-activity;sid:84796923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933824)"; flow:established,from_client; content:"GET"; http_method; content:"/omani-chalktalk211/polyclaude/refs/heads/main/skills/council/software_v3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933824/; classtype:trojan-activity;sid:84796924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933825)"; flow:established,from_client; content:"GET"; http_method; content:"/pivanov/stolen-ctx-wire/head/internal/hook/wire-ctx-2.6-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933825/; classtype:trojan-activity;sid:84796925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933820)"; flow:established,from_client; content:"GET"; http_method; content:"/rannaunsoldierly881/sourcevr/refs/heads/main/balaam/vr_source_v2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933820/; classtype:trojan-activity;sid:84796920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933821)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzyken-gsm/book-sales-forecasting-timeseries/head/notebooks/book-sales-forecasting-timeseries_3.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933821/; classtype:trojan-activity;sid:84796921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933822)"; flow:established,from_client; content:"GET"; http_method; content:"/amit-chouhan/bulwark/refs/heads/main/lib/brain/kb/software_v1.7-alpha.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933822/; classtype:trojan-activity;sid:84796922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933816)"; flow:established,from_client; content:"GET"; http_method; content:"/petenevartem08-sketch/bankmcp/main/roberto/software_2.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933816/; classtype:trojan-activity;sid:84796916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933817)"; flow:established,from_client; content:"GET"; http_method; content:"/karkiff/blender-works/main/unthinkability/works-blender-peachify.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933817/; classtype:trojan-activity;sid:84796917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933818)"; flow:established,from_client; content:"GET"; http_method; content:"/lovesun12/site-builder/main/client/src/lib/builder_site_interpleural.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933818/; classtype:trojan-activity;sid:84796918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933819)"; flow:established,from_client; content:"GET"; http_method; content:"/alex2024wong/jedi-devops-uptime-monitor-plus/refs/heads/main/unimitative/uptime-dev-plus-jedi-monitor-ops-v3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933819/; classtype:trojan-activity;sid:84796919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933811)"; flow:established,from_client; content:"GET"; http_method; content:"/iiskyfxck/roblox-account-switch-manager-pro-latest/refs/heads/main/sabellarian/latest_pro_switch_manager_roblox_account_3.9.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933811/; classtype:trojan-activity;sid:84796911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933812)"; flow:established,from_client; content:"GET"; http_method; content:"/rudrasigh2008-stack/buildmystack/refs/heads/main/templates/modules/database/mongo/server/src/software-2.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933812/; classtype:trojan-activity;sid:84796912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933813)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933813/; classtype:trojan-activity;sid:84796913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933814)"; flow:established,from_client; content:"GET"; http_method; content:"/kermz47/imdb-sentiment-analysis/master/overblow/imd-analysis-sentiment-suaviloquence.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933814/; classtype:trojan-activity;sid:84796914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933815)"; flow:established,from_client; content:"GET"; http_method; content:"/hugomo1/epoch/main/src/store/software-staminode.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933815/; classtype:trojan-activity;sid:84796915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933810)"; flow:established,from_client; content:"GET"; http_method; content:"/mouad464/hearthealth/refs/heads/main/prey/software_3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933810/; classtype:trojan-activity;sid:84796910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933808)"; flow:established,from_client; content:"GET"; http_method; content:"/britishcheesett/pw-skills/refs/heads/main/pw-post-to-wechat/scripts/md/skills-pw-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933808/; classtype:trojan-activity;sid:84796908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933809)"; flow:established,from_client; content:"GET"; http_method; content:"/meyern7/loomkin/refs/heads/main/test/support/hooks/software_v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933809/; classtype:trojan-activity;sid:84796909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933807)"; flow:established,from_client; content:"GET"; http_method; content:"/nexoluvsu-droid/8ball-pool-menu/main/kindheartedly/3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933807/; classtype:trojan-activity;sid:84796907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933806)"; flow:established,from_client; content:"GET"; http_method; content:"/mariettaabscessed872/psd_icon_thumbnail_fix_for_win10/main/packages/sharpshell.2.7.2/lib/thumbnail_ps_win_icon_for_fix_2.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933806/; classtype:trojan-activity;sid:84796906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933805)"; flow:established,from_client; content:"GET"; http_method; content:"/thenguyenvn/rsync-backup-solution/main/tricompound/rsync-backup-solution.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933805/; classtype:trojan-activity;sid:84796905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933803)"; flow:established,from_client; content:"GET"; http_method; content:"/jyhuang201900/orange-engine/refs/heads/main/chloroplatinous/orange_engine_plantivorous.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933803/; classtype:trojan-activity;sid:84796903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933804)"; flow:established,from_client; content:"GET"; http_method; content:"/yusufszih/awesome-ai-tools/refs/heads/main/bacteriopsonin/awesome_tools_ai_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933804/; classtype:trojan-activity;sid:84796904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933802)"; flow:established,from_client; content:"GET"; http_method; content:"/pinkbanty5707/geo-ai-woo/main/includes/a_woo_ge_metamynodon.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933802/; classtype:trojan-activity;sid:84796902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933799)"; flow:established,from_client; content:"GET"; http_method; content:"/bellshaped-internalsecretion2730/dyb-pro/refs/heads/main/frontend/lib/v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933799/; classtype:trojan-activity;sid:84796899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933800)"; flow:established,from_client; content:"GET"; http_method; content:"/notabhinavgamerz/emotion-aware-automatic-speech-recognition/main/src/__pycache__/recognition-automatic-emotion-aware-speech-postcenal.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933800/; classtype:trojan-activity;sid:84796900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933801)"; flow:established,from_client; content:"GET"; http_method; content:"/choaybkb/tech-interview-handbook/head/paradidymis/tech-interview-handbook.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933801/; classtype:trojan-activity;sid:84796901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933797)"; flow:established,from_client; content:"GET"; http_method; content:"/sdfcxcvcxvxc/projectswitcher/main/sounding/projectswitcher.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933797/; classtype:trojan-activity;sid:84796897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933798)"; flow:established,from_client; content:"GET"; http_method; content:"/wech-expert/rootlabs-pos-pro/main/includes/products/pro-pos-rootlabs-v2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933798/; classtype:trojan-activity;sid:84796898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933794)"; flow:established,from_client; content:"GET"; http_method; content:"/faizanalimalik/claude-code-agent-monitor/refs/heads/master/client/claude_agent_monitor_code_v3.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933794/; classtype:trojan-activity;sid:84796894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933795)"; flow:established,from_client; content:"GET"; http_method; content:"/workpennisetumcenchroides181/safe-refactor-engine/main/references/refactor_engine_safe_dutchy.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933795/; classtype:trojan-activity;sid:84796895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933796)"; flow:established,from_client; content:"GET"; http_method; content:"/ngdothanhlai/craft-agents-oss/refs/heads/main/packages/core/oss-craft-agents-3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933796/; classtype:trojan-activity;sid:84796896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933792)"; flow:established,from_client; content:"GET"; http_method; content:"/carotteramene-droid/hitfactor/refs/heads/main/src/__tests__/software-v2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933792/; classtype:trojan-activity;sid:84796892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933793)"; flow:established,from_client; content:"GET"; http_method; content:"/tcfreeman90/video_repo__design/refs/heads/main/sigillarioid/video_design_repo_3.0-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933793/; classtype:trojan-activity;sid:84796893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933791)"; flow:established,from_client; content:"GET"; http_method; content:"/arhankabirzi/vite-plugin-component-debugger/main/soup/plugin_component_debugger_vite_v3.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933791/; classtype:trojan-activity;sid:84796891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933790)"; flow:established,from_client; content:"GET"; http_method; content:"/nourddinetaqi/pneumonia-hybridcnn/refs/heads/main/radiologist/cnn-hybrid-pneumonia-v2.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933790/; classtype:trojan-activity;sid:84796890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933789)"; flow:established,from_client; content:"GET"; http_method; content:"/eddan5513/maixcam-servo-control/refs/heads/main/maix_app/control-servo-maixcam-2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933789/; classtype:trojan-activity;sid:84796889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933788)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasbonazza/valentine-surprise/refs/heads/main/web/valentine-surprise-3.2-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933788/; classtype:trojan-activity;sid:84796888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933787)"; flow:established,from_client; content:"GET"; http_method; content:"/purposive-parkland791/hitpaw-photo-enhancer-setup/main/postsigmoid/paw_setup_hit_photo_enhancer_v3.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933787/; classtype:trojan-activity;sid:84796887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933786)"; flow:established,from_client; content:"GET"; http_method; content:"/abhimanyu123-sf/gpt-images/main/references/v1.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933786/; classtype:trojan-activity;sid:84796886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933785)"; flow:established,from_client; content:"GET"; http_method; content:"/sandeepai1561/ai-app-with-auth-demo/refs/heads/master/frontend/src/with-demo-auth-app-ai-3.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933785/; classtype:trojan-activity;sid:84796885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933781)"; flow:established,from_client; content:"GET"; http_method; content:"/low102/checkaddy/refs/heads/main/checkaddy_app/validators/software_1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933781/; classtype:trojan-activity;sid:84796881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933782)"; flow:established,from_client; content:"GET"; http_method; content:"/hezeghaluwawo/react-native-zoom-grid/head/src/react_grid_zoom_native_v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933782/; classtype:trojan-activity;sid:84796882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933783)"; flow:established,from_client; content:"GET"; http_method; content:"/palomitas86/envradar/refs/heads/main/src/envradar/software_v3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933783/; classtype:trojan-activity;sid:84796883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933784)"; flow:established,from_client; content:"GET"; http_method; content:"/altumbilal/risk-platform/refs/heads/main/gateway-go/internal/decision/risk_platform_3.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933784/; classtype:trojan-activity;sid:84796884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933779)"; flow:established,from_client; content:"GET"; http_method; content:"/ficaviolaodorata520/met-museum-mcp-server/refs/heads/main/skills/api-utils/museum_mcp_server_met_v2.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933779/; classtype:trojan-activity;sid:84796879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933780)"; flow:established,from_client; content:"GET"; http_method; content:"/sdfysdfhsdfhs/chart-to-image/main/src/core/image_to_chart_candytuft.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933780/; classtype:trojan-activity;sid:84796880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933778)"; flow:established,from_client; content:"GET"; http_method; content:"/sam2523/shadcnui-rtl/refs/heads/main/examples/rtl_shadcnui_v3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933778/; classtype:trojan-activity;sid:84796878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933777)"; flow:established,from_client; content:"GET"; http_method; content:"/huffy-layingon493/n2-mimir/refs/heads/main/packages/mimir/src/orchestrator/mimir-n-3.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933777/; classtype:trojan-activity;sid:84796877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933776)"; flow:established,from_client; content:"GET"; http_method; content:"/alfred252525/analytical-fire/refs/heads/main/frontend/components/analytical_fire_2.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933776/; classtype:trojan-activity;sid:84796876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933772)"; flow:established,from_client; content:"GET"; http_method; content:"/wilcobarry12/phantomboot/refs/heads/main/cystalgia/boot_phantom_1.8-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933772/; classtype:trojan-activity;sid:84796872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933773)"; flow:established,from_client; content:"GET"; http_method; content:"/yukiboy121/svelte-purify/main/pinnock/svelte-purify.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933773/; classtype:trojan-activity;sid:84796873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933774)"; flow:established,from_client; content:"GET"; http_method; content:"/kudata5226/first-nations-geospatial-automation/refs/heads/main/febronianism/nations-geospatial-automation-first-3.0.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933774/; classtype:trojan-activity;sid:84796874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933775)"; flow:established,from_client; content:"GET"; http_method; content:"/azzafizatiaina/real-estate-platform/head/src/main/java/com/devtiro/realestate/domain/real_platform_estate_2.3-beta.3.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933775/; classtype:trojan-activity;sid:84796875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933771)"; flow:established,from_client; content:"GET"; http_method; content:"/eveng2187/webkitplayground/refs/heads/main/scripts/playground-web-kit-v3.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933771/; classtype:trojan-activity;sid:84796871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933769)"; flow:established,from_client; content:"GET"; http_method; content:"/alliedwebapp/webapp/dev/node_modules/bson/src/utils/software-v2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933769/; classtype:trojan-activity;sid:84796869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933770)"; flow:established,from_client; content:"GET"; http_method; content:"/heavy-cuttingangle951/graffiti-finder/refs/heads/main/unneth/finder_graffiti_v2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933770/; classtype:trojan-activity;sid:84796870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933767)"; flow:established,from_client; content:"GET"; http_method; content:"/tiagosykz/file-shredder/main/underarm/shredder-file-v2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933767/; classtype:trojan-activity;sid:84796867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933768)"; flow:established,from_client; content:"GET"; http_method; content:"/hillsfox/customer_churn_analysis_r/master/src/net/customer-r-churn-analysis-unacceptant.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933768/; classtype:trojan-activity;sid:84796868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933763)"; flow:established,from_client; content:"GET"; http_method; content:"/saairimran/frogjumpsrandomly/refs/heads/main/dicrotic/software_3.4-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933763/; classtype:trojan-activity;sid:84796863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933764)"; flow:established,from_client; content:"GET"; http_method; content:"/aashimasaini/ha-eveus-evse/main/bakehouse/ha-eveus-evse.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933764/; classtype:trojan-activity;sid:84796864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933765)"; flow:established,from_client; content:"GET"; http_method; content:"/erugeek-spec/ip-grabber/refs/heads/main/sigillaroid/grabber-i-2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933765/; classtype:trojan-activity;sid:84796865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933766)"; flow:established,from_client; content:"GET"; http_method; content:"/anil4674sdfsd/mt5-trader/head/variedly/mt5-trader_3.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933766/; classtype:trojan-activity;sid:84796866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933752)"; flow:established,from_client; content:"GET"; http_method; content:"/proneo/userscript-twitch-stop-autoplay/refs/heads/main/media/autoplay-userscript-stop-twitch-v3.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933752/; classtype:trojan-activity;sid:84796852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933753)"; flow:established,from_client; content:"GET"; http_method; content:"/irsaam1023/iconiczar/refs/heads/main/css/zar-iconic-1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933753/; classtype:trojan-activity;sid:84796853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933754)"; flow:established,from_client; content:"GET"; http_method; content:"/kunalmankar852/route-optimization-visualizer/head/assets/route-optimization-visualizer-2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933754/; classtype:trojan-activity;sid:84796854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933755)"; flow:established,from_client; content:"GET"; http_method; content:"/exogameyt/claude-hooks/refs/heads/main/erythematous/claude-hooks-v2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933755/; classtype:trojan-activity;sid:84796855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933756)"; flow:established,from_client; content:"GET"; http_method; content:"/landland636373/qwen-browser-plugin/main/flocculent/qwen-browser-plugin.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933756/; classtype:trojan-activity;sid:84796856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933757)"; flow:established,from_client; content:"GET"; http_method; content:"/riana651/flyingsnowvelvet-aemeath/main/lib/script/seanima/aemeath_velvet_snow_flying_concupy.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933757/; classtype:trojan-activity;sid:84796857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933758)"; flow:established,from_client; content:"GET"; http_method; content:"/beantownrevenuesharing985/home-lab/main/ollama/lab_home_3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933758/; classtype:trojan-activity;sid:84796858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933759)"; flow:established,from_client; content:"GET"; http_method; content:"/bigggggg907/acontext-agent-playground/refs/heads/main/app/auth/error/agent_playground_acontext_2.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933759/; classtype:trojan-activity;sid:84796859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933760)"; flow:established,from_client; content:"GET"; http_method; content:"/barto1994/ai-personal-study-tracker/refs/heads/main/data/a-personal-study-tracker-v2.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933760/; classtype:trojan-activity;sid:84796860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933761)"; flow:established,from_client; content:"GET"; http_method; content:"/hemanm802/joyflow-bot/main/joyflowios/resources/assets.xcassets/accentcolor.colorset/1.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933761/; classtype:trojan-activity;sid:84796861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933762)"; flow:established,from_client; content:"GET"; http_method; content:"/suppressed-bottlecollection848/toomany/refs/heads/main/sources/toomany/software_2.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933762/; classtype:trojan-activity;sid:84796862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933749)"; flow:established,from_client; content:"GET"; http_method; content:"/harhapravnee/resonance-a-plague-tale-legacy-trainer/main/assets/v2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933749/; classtype:trojan-activity;sid:84796849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933750)"; flow:established,from_client; content:"GET"; http_method; content:"/akbarkhan948/clawdcontext4vscode/refs/heads/main/src/ai/clawdcontext-vscode-atrypa.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933750/; classtype:trojan-activity;sid:84796850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933751)"; flow:established,from_client; content:"GET"; http_method; content:"/aurelkouadio78-dot/laravel-flow-builder/refs/heads/main/uncentrally/flow_builder_laravel_v1.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933751/; classtype:trojan-activity;sid:84796851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933748)"; flow:established,from_client; content:"GET"; http_method; content:"/aminem2832/pothole-reporter/main/android-app/android/app/src/main/res/drawable-land-xhdpi/reporter-pothole-3.6.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933748/; classtype:trojan-activity;sid:84796848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933745)"; flow:established,from_client; content:"GET"; http_method; content:"/rjzxui/obsidian-vault-cli/main/tests/fixtures/vault-obsidian-cli-v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933745/; classtype:trojan-activity;sid:84796845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933746)"; flow:established,from_client; content:"GET"; http_method; content:"/by-lana2/elysia/refs/heads/main/elysia/api/user_configs/software_esophagomalacia.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933746/; classtype:trojan-activity;sid:84796846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933747)"; flow:established,from_client; content:"GET"; http_method; content:"/kawaiirashi/llm-retry/refs/heads/main/include/llm-retry-1.5-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933747/; classtype:trojan-activity;sid:84796847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933743)"; flow:established,from_client; content:"GET"; http_method; content:"/mahm0ud2007/ibm-lbgsn/main/windwardmost/ibm-lbgsn.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933743/; classtype:trojan-activity;sid:84796843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933744)"; flow:established,from_client; content:"GET"; http_method; content:"/serobaba23/git-rewrite-commits/master/hooks/git-rewrite-commits_ochletic.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933744/; classtype:trojan-activity;sid:84796844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933740)"; flow:established,from_client; content:"GET"; http_method; content:"/vukvelickovic97/event-example/main/endue/event_example_v2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933740/; classtype:trojan-activity;sid:84796840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933741)"; flow:established,from_client; content:"GET"; http_method; content:"/amineeng/scraping-browser/head/tuggingly/scraping-browser-3.6-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933741/; classtype:trojan-activity;sid:84796841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933742)"; flow:established,from_client; content:"GET"; http_method; content:"/yugpat1835/awesome-copilot-cowork-skills/refs/heads/main/skills/daily-briefings/cowork-copilot-awesome-skills-nomocracy.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933742/; classtype:trojan-activity;sid:84796842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933734)"; flow:established,from_client; content:"GET"; http_method; content:"/nabilbkfa82/stats-base-ndarray-snanmskrange/refs/heads/main/docs/types/ndarray_base_stats_snanmskrange_3.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933734/; classtype:trojan-activity;sid:84796834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933735)"; flow:established,from_client; content:"GET"; http_method; content:"/evawo7976/solarized-light-gnome50-rice/refs/heads/main/boot/plymouth/solarized-light-gnome-rice-v3.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933735/; classtype:trojan-activity;sid:84796835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933736)"; flow:established,from_client; content:"GET"; http_method; content:"/eng-44as/ai-automation-python-intelligent-pipeline/head/psychotherapeutist/ai-automation-python-intelligent-pipeline_2.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933736/; classtype:trojan-activity;sid:84796836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933737)"; flow:established,from_client; content:"GET"; http_method; content:"/izacki35/anime-dl-core/main/examples/v2.8-alpha.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933737/; classtype:trojan-activity;sid:84796837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933738)"; flow:established,from_client; content:"GET"; http_method; content:"/4aulz/oracledb-iv0/main/skepful/oracledb-iv0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933738/; classtype:trojan-activity;sid:84796838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933739)"; flow:established,from_client; content:"GET"; http_method; content:"/yokshith0605/actionscript-tuj/main/plaiter/actionscript-tuj.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933739/; classtype:trojan-activity;sid:84796839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933731)"; flow:established,from_client; content:"GET"; http_method; content:"/wserre/notebooklm-skill/master/scripts/notebooklm_skill_1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933731/; classtype:trojan-activity;sid:84796831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933732)"; flow:established,from_client; content:"GET"; http_method; content:"/jawbreaker360/dotfiles/refs/heads/main/images/software-v3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933732/; classtype:trojan-activity;sid:84796832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933733)"; flow:established,from_client; content:"GET"; http_method; content:"/expostfacto-paging599/go-hfp/head/smallholder/go-hfp-v2.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933733/; classtype:trojan-activity;sid:84796833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933730)"; flow:established,from_client; content:"GET"; http_method; content:"/tebur09/github-mood-rings/refs/heads/main/skimback/mood-github-rings-1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933730/; classtype:trojan-activity;sid:84796830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933728)"; flow:established,from_client; content:"GET"; http_method; content:"/albenee/idx-free/main/unwooed/idx-free.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933728/; classtype:trojan-activity;sid:84796828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933729)"; flow:established,from_client; content:"GET"; http_method; content:"/mango-jade/bank-network-in-cisco-packet-tracer/refs/heads/main/eschewal/in-cisco-bank-tracer-packet-network-3.3-beta.4.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933729/; classtype:trojan-activity;sid:84796829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933725)"; flow:established,from_client; content:"GET"; http_method; content:"/ksa388374/theorie-unifiee-de-la-matiere-programmable-ipf/main/docs/theorie-de-matiere-ipf-programmable-unifiee-la-talisay.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933725/; classtype:trojan-activity;sid:84796825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933726)"; flow:established,from_client; content:"GET"; http_method; content:"/hansonolivelike14/recursion-c-programs/refs/heads/main/cornemuse/programs-recursion-1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933726/; classtype:trojan-activity;sid:84796826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933727)"; flow:established,from_client; content:"GET"; http_method; content:"/hiaguineo/test/master/bead/software-3.3-beta.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933727/; classtype:trojan-activity;sid:84796827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933723)"; flow:established,from_client; content:"GET"; http_method; content:"/josit1013/elevenlabs-desktop---ai-voice-generator-2026/main/felsosphaerite/eleven-desktop-labs-voice-generator-a-v1.0.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933723/; classtype:trojan-activity;sid:84796823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933724)"; flow:established,from_client; content:"GET"; http_method; content:"/rejaulkarim0212/directive/refs/heads/main/directive/frontend/src/components/panels/software_1.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933724/; classtype:trojan-activity;sid:84796824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933721)"; flow:established,from_client; content:"GET"; http_method; content:"/alfredtauro1/workforce-disruption-equilibrium-engine/refs/heads/main/data/processed/engine-equilibrium-workforce-disruption-v3.7.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933721/; classtype:trojan-activity;sid:84796821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933722)"; flow:established,from_client; content:"GET"; http_method; content:"/nixon0220/lvmthin-helper/refs/heads/main/lvmthin_helper/lvmthin-helper-v2.0-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933722/; classtype:trojan-activity;sid:84796822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933720)"; flow:established,from_client; content:"GET"; http_method; content:"/behlah53/shozonportfolio/refs/heads/main/thyroarytenoid/software-v1.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933720/; classtype:trojan-activity;sid:84796820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933716)"; flow:established,from_client; content:"GET"; http_method; content:"/mitsou55/100-github-projects-that-defined-2025/refs/heads/main/conocarpus/that-defined-hub-projects-git-v3.6-beta.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933716/; classtype:trojan-activity;sid:84796816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933717)"; flow:established,from_client; content:"GET"; http_method; content:"/saysayn1/erich-viewbot/refs/heads/main/input/erich-view-bot-3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933717/; classtype:trojan-activity;sid:84796817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933718)"; flow:established,from_client; content:"GET"; http_method; content:"/jesayas7817/agent-reliability-engineering/refs/heads/main/transfer/experiments/reliability_engineering_agent_1.3-beta.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933718/; classtype:trojan-activity;sid:84796818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933719)"; flow:established,from_client; content:"GET"; http_method; content:"/unicellular-familytheophrastaceae741/clashflac/main/amzdl/cli/v2.1-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933719/; classtype:trojan-activity;sid:84796819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933714)"; flow:established,from_client; content:"GET"; http_method; content:"/fitmentcolubridae625/keys-vllm.0.27-qwen3.8-27b-aday777ablit-nvfp4-a4q-nvfp4-kv-4m-kv-token-pool-mtp3-single-dgx-spark/main/recipe/build/a4q_overlay/cuda/csrc/pool_mt_qwen_ablit_keys_k_day_token_spark_nvf_v_single_l_a_lm_dg_v1.6.zip"; http_uri; depth:233; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933714/; classtype:trojan-activity;sid:84796814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933715)"; flow:established,from_client; content:"GET"; http_method; content:"/strawboardnationaldebtceiling9560/kakeya-3d/main/kakeya/geo_notedbound/3.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933715/; classtype:trojan-activity;sid:84796815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933712)"; flow:established,from_client; content:"GET"; http_method; content:"/999xavier/xsukax-e2ee-local-mailing-system/refs/heads/main/prefreshman/system-mailing-local-e-xsukax-v2.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933712/; classtype:trojan-activity;sid:84796812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933713)"; flow:established,from_client; content:"GET"; http_method; content:"/adssfd/flowify/refs/heads/main/.planning/phases/14-markdown-rendering/software-v1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933713/; classtype:trojan-activity;sid:84796813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933710)"; flow:established,from_client; content:"GET"; http_method; content:"/jay10413/raypy/refs/heads/main/examples/software_2.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933710/; classtype:trojan-activity;sid:84796810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933711)"; flow:established,from_client; content:"GET"; http_method; content:"/marcosfelipesrb/rynxs-agentos/refs/heads/main/operator/universe_operator/rynxs_agentos_v1.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933711/; classtype:trojan-activity;sid:84796811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933709)"; flow:established,from_client; content:"GET"; http_method; content:"/midnightcanyon/synthesia-desktop---ai-video-presenter-2026/main/viscin/v2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933709/; classtype:trojan-activity;sid:84796809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933705)"; flow:established,from_client; content:"GET"; http_method; content:"/meghsss/pomodoro-extension/head/assets/pomodoro_extension_2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933705/; classtype:trojan-activity;sid:84796805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933706)"; flow:established,from_client; content:"GET"; http_method; content:"/jalalzia1/kokoro-web/master/anchimonomineral/kokoro-web-3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933706/; classtype:trojan-activity;sid:84796806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933707)"; flow:established,from_client; content:"GET"; http_method; content:"/dustyepistolary252/finance_dashboard/refs/heads/main/test/dashboard_finance_chamecephalous.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933707/; classtype:trojan-activity;sid:84796807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933708)"; flow:established,from_client; content:"GET"; http_method; content:"/ifham55/repohealth/refs/heads/main/screenshots/repo-health-1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933708/; classtype:trojan-activity;sid:84796808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933704)"; flow:established,from_client; content:"GET"; http_method; content:"/randieallegro301/harmoniq/refs/heads/main/ovariotomy/q-harmoni-2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933704/; classtype:trojan-activity;sid:84796804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933703)"; flow:established,from_client; content:"GET"; http_method; content:"/wintercastrosie/iso-8583-parser-playground/master/scripts/parser-playground-is-3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933703/; classtype:trojan-activity;sid:84796803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933702)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/semantic-search-project/head/ischiovaginal/search-semantic-project-v1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933702/; classtype:trojan-activity;sid:84796802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933699)"; flow:established,from_client; content:"GET"; http_method; content:"/amitafadir-ridafatima/mcp-shark-viewer-vscode/refs/heads/main/docs/mcp-viewer-vscode-shark-v1.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933699/; classtype:trojan-activity;sid:84796799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933700)"; flow:established,from_client; content:"GET"; http_method; content:"/ben-0014/arduino_competiton/refs/heads/main/images/competiton-arduino-v1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933700/; classtype:trojan-activity;sid:84796800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933701)"; flow:established,from_client; content:"GET"; http_method; content:"/sarimkhan021/proxmox-os-autotagger/refs/heads/main/oxfordian/tagger_o_proxmox_auto_2.0-alpha.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933701/; classtype:trojan-activity;sid:84796801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933697)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahim-ts/wan-alpha/main/soberize/wan-alpha.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933697/; classtype:trojan-activity;sid:84796797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933698)"; flow:established,from_client; content:"GET"; http_method; content:"/remu123-collab/admin-support-portfolio/refs/heads/main/deedily/portfolio_admin_support_v3.5-beta.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933698/; classtype:trojan-activity;sid:84796798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933696)"; flow:established,from_client; content:"GET"; http_method; content:"/mctosh1/modal-llm-evaluator/refs/heads/main/evaluator/modal_llm_evaluator_v2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933696/; classtype:trojan-activity;sid:84796796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933693)"; flow:established,from_client; content:"GET"; http_method; content:"/loaded-spongebath1657/metamask-desktop/refs/heads/main/images/animations/fox/2.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933693/; classtype:trojan-activity;sid:84796793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933694)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/github-command-center/head/src/github-command-center-v1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933694/; classtype:trojan-activity;sid:84796794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933695)"; flow:established,from_client; content:"GET"; http_method; content:"/unabused-wichita77/lazy-tool/refs/heads/main/internal/version/tool_lazy_v1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933695/; classtype:trojan-activity;sid:84796795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933690)"; flow:established,from_client; content:"GET"; http_method; content:"/aqbor888/alphagpt/refs/heads/main/model_core/alpha-gpt-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933690/; classtype:trojan-activity;sid:84796790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933691)"; flow:established,from_client; content:"GET"; http_method; content:"/corestudio2/seller-ops/refs/heads/master/src/app/api/recommendations/seller-ops-v2.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933691/; classtype:trojan-activity;sid:84796791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933692)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/trainingpeaks-mcp/head/src/tp_mcp/auth/mcp_trainingpeaks_v1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933692/; classtype:trojan-activity;sid:84796792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933688)"; flow:established,from_client; content:"GET"; http_method; content:"/sabermaple1/renfe_mcp_server/head/src/renfe_mcp/scraper/renfe_mcp_server_2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933688/; classtype:trojan-activity;sid:84796788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933689)"; flow:established,from_client; content:"GET"; http_method; content:"/abanoubab8666/social-cli/refs/heads/main/indagatory/cli-social-v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933689/; classtype:trojan-activity;sid:84796789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933687)"; flow:established,from_client; content:"GET"; http_method; content:"/iamlopez2512/majouboureivolontes-arcanetoolkit/refs/heads/main/overmark/majou_toolkit_bourei_arcane_volontes_3.0.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933687/; classtype:trojan-activity;sid:84796787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933685)"; flow:established,from_client; content:"GET"; http_method; content:"/megakiyaiscool/smart_plug/refs/heads/main/pedlar/plug_smart_v1.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933685/; classtype:trojan-activity;sid:84796785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933686)"; flow:established,from_client; content:"GET"; http_method; content:"/thewexer/baldurs-gate-3-save-editor/refs/heads/main/bosomy/baldurs-save-editor-gate-v2.6-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933686/; classtype:trojan-activity;sid:84796786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933682)"; flow:established,from_client; content:"GET"; http_method; content:"/leadsgorillaio/jina-cli/refs/heads/main/cli/pkg/output/jina_cli_nguyen.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933682/; classtype:trojan-activity;sid:84796782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933683)"; flow:established,from_client; content:"GET"; http_method; content:"/adityaq123/noodles/refs/heads/main/assets/software_unceasing.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933683/; classtype:trojan-activity;sid:84796783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933684)"; flow:established,from_client; content:"GET"; http_method; content:"/potato68/jubilee-free-online-course-website-template/master/icomoon/fonts/template-course-website-online-jubilee-free-glistening.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933684/; classtype:trojan-activity;sid:84796784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933679)"; flow:established,from_client; content:"GET"; http_method; content:"/andrel8052/pam-whatsapp-web/main/tests/integration/whatsapp_web_pam_2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933679/; classtype:trojan-activity;sid:84796779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933680)"; flow:established,from_client; content:"GET"; http_method; content:"/juswareid01/3dslibris/refs/heads/main/sdmc/3ds/3dslibris/resources/dslibris_v1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933680/; classtype:trojan-activity;sid:84796780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933681)"; flow:established,from_client; content:"GET"; http_method; content:"/projectionracedriver670/migraine-risk-card/refs/heads/main/sensor-package/risk-migraine-card-2.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933681/; classtype:trojan-activity;sid:84796781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933678)"; flow:established,from_client; content:"GET"; http_method; content:"/xyreinsurance119/agentforge-openclaw/head/examples/openclaw_agentforge_spelder.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933678/; classtype:trojan-activity;sid:84796778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933676)"; flow:established,from_client; content:"GET"; http_method; content:"/angel122382/effect-rpc-tanstack-devtools/refs/heads/main/src/tanstack_devtools_rpc_effect_1.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933676/; classtype:trojan-activity;sid:84796776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933677)"; flow:established,from_client; content:"GET"; http_method; content:"/aaadsadas/sjtu-jokes/main/windshield/sjtu-jokes_downlie.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933677/; classtype:trojan-activity;sid:84796777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933674)"; flow:established,from_client; content:"GET"; http_method; content:"/anujeditsbyanuj-bit/telegram-amazon-affiliate-bot/head/translations/amazon_affiliate_bot_telegram_2.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933674/; classtype:trojan-activity;sid:84796774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933675)"; flow:established,from_client; content:"GET"; http_method; content:"/raphasilv247/google-rkp-swy/head/scotographic/sw_rkp_google_3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933675/; classtype:trojan-activity;sid:84796775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933673)"; flow:established,from_client; content:"GET"; http_method; content:"/dinujayagagulal/sunfavorite/master/src/main/resources/static/layui/css/modules/laydate/default/sun_favorite_1.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933673/; classtype:trojan-activity;sid:84796773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933672)"; flow:established,from_client; content:"GET"; http_method; content:"/cliemte/ffmpeg-skill/main/hypercoagulable/ffmpeg-skill-v2.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933672/; classtype:trojan-activity;sid:84796772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933671)"; flow:established,from_client; content:"GET"; http_method; content:"/vshwsh/prod-evals-cookbook/refs/heads/main/stage_2_labeled_scenarios/evals_cookbook_prod_1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933671/; classtype:trojan-activity;sid:84796771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933669)"; flow:established,from_client; content:"GET"; http_method; content:"/andreshdez-18/qqsafechat/master/node_modules/reveal.js/lib/font/league-gothic/safe_chat_qq_v3.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933669/; classtype:trojan-activity;sid:84796769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933670)"; flow:established,from_client; content:"GET"; http_method; content:"/bejlocalxyz/terra-verde-theme/refs/heads/main/themes/terra_theme_verde_v2.9-alpha.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933670/; classtype:trojan-activity;sid:84796770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933667)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbinirob80/data-fusion-contest-2026---3-/refs/heads/main/registership/contest_fusion_data_3.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933667/; classtype:trojan-activity;sid:84796767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933668)"; flow:established,from_client; content:"GET"; http_method; content:"/sarang4042/.github/refs/heads/main/profile/github-3.6-alpha.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933668/; classtype:trojan-activity;sid:84796768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933666)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv5l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933666/; classtype:trojan-activity;sid:84796766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933663)"; flow:established,from_client; content:"GET"; http_method; content:"/harshit5264/remix3-resources/master/dorsointercostal/resources_remix_3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933663/; classtype:trojan-activity;sid:84796763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933664)"; flow:established,from_client; content:"GET"; http_method; content:"/hassanamir24/quickrag/refs/heads/main/src/software-siscowet.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933664/; classtype:trojan-activity;sid:84796764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933665)"; flow:established,from_client; content:"GET"; http_method; content:"/beeftapareseller/docs/main/src/playground/software_traintime.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933665/; classtype:trojan-activity;sid:84796765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933662)"; flow:established,from_client; content:"GET"; http_method; content:"/kanis04/cursor-unchained/refs/heads/main/.cursor/rules/cursor-unchained-2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933662/; classtype:trojan-activity;sid:84796762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933659)"; flow:established,from_client; content:"GET"; http_method; content:"/oferoo7o/remy-tweaks/master/src/tweaks-remy-1.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933659/; classtype:trojan-activity;sid:84796759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933660)"; flow:established,from_client; content:"GET"; http_method; content:"/dmtrap/eventives-be/refs/heads/main/src/event-management/speaker/dto/be_eventives_3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933660/; classtype:trojan-activity;sid:84796760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933661)"; flow:established,from_client; content:"GET"; http_method; content:"/pat-divisionarchaebacteria894/voiceclone-guard/refs/heads/main/frontend/src/components/guard_voiceclone_3.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933661/; classtype:trojan-activity;sid:84796761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933656)"; flow:established,from_client; content:"GET"; http_method; content:"/sidorovich256/replicate/refs/heads/main/yolo11n/software-3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933656/; classtype:trojan-activity;sid:84796756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933657)"; flow:established,from_client; content:"GET"; http_method; content:"/devilh792/blabla/refs/heads/main/progressivism/software_2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933657/; classtype:trojan-activity;sid:84796757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933658)"; flow:established,from_client; content:"GET"; http_method; content:"/dubey-anuj/ecommerce.cart/dev/src/values/ecommerce_cart_1.8-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933658/; classtype:trojan-activity;sid:84796758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933655)"; flow:established,from_client; content:"GET"; http_method; content:"/peterzang/perplexity-2api-python/head/app/python_perplexity_api_2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933655/; classtype:trojan-activity;sid:84796755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933653)"; flow:established,from_client; content:"GET"; http_method; content:"/trededofoturo/bellomberg/main/app/src/i18n/it/software_v3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933653/; classtype:trojan-activity;sid:84796753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933654)"; flow:established,from_client; content:"GET"; http_method; content:"/booth446/coffee-codex-cortex-pub/main/milarite/coffee-codex-cortex-pub.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933654/; classtype:trojan-activity;sid:84796754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933650)"; flow:established,from_client; content:"GET"; http_method; content:"/upstairs-sweetorangetree894/restory-trainer/refs/heads/main/assets/1.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933650/; classtype:trojan-activity;sid:84796750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933651)"; flow:established,from_client; content:"GET"; http_method; content:"/huckaby1847/poor-man-memory/main/pmm/memory_poor_man_joltless.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933651/; classtype:trojan-activity;sid:84796751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933652)"; flow:established,from_client; content:"GET"; http_method; content:"/arboreal-cohn3569/deep-flow-ids/main/src/ids_deep_flow_v1.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933652/; classtype:trojan-activity;sid:84796752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933648)"; flow:established,from_client; content:"GET"; http_method; content:"/thaddaeu5/rag_service/head/uninspirited/rag_service.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933648/; classtype:trojan-activity;sid:84796748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933649)"; flow:established,from_client; content:"GET"; http_method; content:"/chars34/tavinote/refs/heads/main/images/tavi_note_1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933649/; classtype:trojan-activity;sid:84796749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933647)"; flow:established,from_client; content:"GET"; http_method; content:"/lukky262/are/refs/heads/main/helladotherium/software-1.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933647/; classtype:trojan-activity;sid:84796747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933645)"; flow:established,from_client; content:"GET"; http_method; content:"/lucaxd-china/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933645/; classtype:trojan-activity;sid:84796745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933646)"; flow:established,from_client; content:"GET"; http_method; content:"/contealessandrovoltalandscape881/teleclaude/refs/heads/main/templates/software-3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933646/; classtype:trojan-activity;sid:84796746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933644)"; flow:established,from_client; content:"GET"; http_method; content:"/joeysup22/to-do-list.txt/refs/heads/main/outshine/to_list_txt_do_v1.1-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933644/; classtype:trojan-activity;sid:84796744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933642)"; flow:established,from_client; content:"GET"; http_method; content:"/midnight5151/legal/main/turnerite/software_mesogloeal.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933642/; classtype:trojan-activity;sid:84796742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933643)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/claude-code-safety-net/head/ast-grep/utils/net-claude-code-safety-v3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933643/; classtype:trojan-activity;sid:84796743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933641)"; flow:established,from_client; content:"GET"; http_method; content:"/donmandela/gsc-mcp/head/taxidermize/mcp_gsc_3.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933641/; classtype:trojan-activity;sid:84796741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933638)"; flow:established,from_client; content:"GET"; http_method; content:"/el1don1/meridian_brain/refs/heads/main/brain/meridia_brain_v2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933638/; classtype:trojan-activity;sid:84796738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933639)"; flow:established,from_client; content:"GET"; http_method; content:"/indraparama940/ai-ffmpeg-cli/head/logometric/ai-ffmpeg-cli.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933639/; classtype:trojan-activity;sid:84796739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933640)"; flow:established,from_client; content:"GET"; http_method; content:"/tbin67048-ai/zephyrus-cli/refs/heads/main/pages/images/zephyrus-cli-rapanea.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933640/; classtype:trojan-activity;sid:84796740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933636)"; flow:established,from_client; content:"GET"; http_method; content:"/lamanodealejo/video-dwd-cli/master/supraconscious/cli-video-dwd-2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933636/; classtype:trojan-activity;sid:84796736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933637)"; flow:established,from_client; content:"GET"; http_method; content:"/gioepa/backend-interview-questions/main/slepez/backend-questions-interview-v2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933637/; classtype:trojan-activity;sid:84796737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933635)"; flow:established,from_client; content:"GET"; http_method; content:"/judaeaexertion224/sn2-playerlimit-configoverride/refs/heads/main/config/limit_player_override_s_config_1.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933635/; classtype:trojan-activity;sid:84796735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933632)"; flow:established,from_client; content:"GET"; http_method; content:"/spokesmanfda907/openclaw-daily-ops/refs/heads/main/scripts/ops-openclaw-daily-1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933632/; classtype:trojan-activity;sid:84796732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933633)"; flow:established,from_client; content:"GET"; http_method; content:"/jakariya12124/emuko/refs/heads/main/enthusiastic/software-2.0-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933633/; classtype:trojan-activity;sid:84796733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933634)"; flow:established,from_client; content:"GET"; http_method; content:"/mobplayerr/poomsae_captum/refs/heads/main/anemoclastic/poomsae-captum-v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933634/; classtype:trojan-activity;sid:84796734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933631)"; flow:established,from_client; content:"GET"; http_method; content:"/mtsalhudarowokele/prismia/refs/heads/main/prompts/extras/ia_prism_3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933631/; classtype:trojan-activity;sid:84796731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933629)"; flow:established,from_client; content:"GET"; http_method; content:"/artem67g/speakit/main/demo/v3.3-alpha.5.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933629/; classtype:trojan-activity;sid:84796729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933630)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzamalik3461/cve-2026-20841/refs/heads/main/miscall/cv-v1.7-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933630/; classtype:trojan-activity;sid:84796730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933627)"; flow:established,from_client; content:"GET"; http_method; content:"/saiadithyakishore/api-auth-jwt-rbac/head/api-auth-jwt-rbac/src/config/jwt_auth_rbac_api_conversive.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933627/; classtype:trojan-activity;sid:84796727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933628)"; flow:established,from_client; content:"GET"; http_method; content:"/koce27/telegram-channel-members-remover/refs/heads/main/unanchor/members-remover-channel-telegram-1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933628/; classtype:trojan-activity;sid:84796728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933626)"; flow:established,from_client; content:"GET"; http_method; content:"/royantdeus/music-genre-finder/head/skill-source/references/main/finder-genre-music-3.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933626/; classtype:trojan-activity;sid:84796726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933625)"; flow:established,from_client; content:"GET"; http_method; content:"/nonfictional-fireside301/datadex/refs/heads/main/intermaxilla/software_3.9-alpha.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933625/; classtype:trojan-activity;sid:84796725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933620)"; flow:established,from_client; content:"GET"; http_method; content:"/kazucheat/legacy-code-archaeologist/refs/heads/main/.devcontainer/code-legacy-archaeologist-3.7-alpha.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933620/; classtype:trojan-activity;sid:84796720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933621)"; flow:established,from_client; content:"GET"; http_method; content:"/rashedyasen/voice-assistant-v2/main/src/assistant_voice_v_preprice.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933621/; classtype:trojan-activity;sid:84796721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933622)"; flow:established,from_client; content:"GET"; http_method; content:"/katrinkafavourite492/localdrive/refs/heads/main/niccoliferous/3.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933622/; classtype:trojan-activity;sid:84796722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933623)"; flow:established,from_client; content:"GET"; http_method; content:"/abbasiali/rundfunkarr/refs/heads/main/src/app/settings/software_1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933623/; classtype:trojan-activity;sid:84796723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933624)"; flow:established,from_client; content:"GET"; http_method; content:"/raflimoon/learn-real-claude-code/refs/heads/main/web/src/real_learn_claude_code_v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933624/; classtype:trojan-activity;sid:84796724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933619)"; flow:established,from_client; content:"GET"; http_method; content:"/confused-pig902/tripdeck/refs/heads/main/tripdeck.web/wwwroot/js/deck-trip-v1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933619/; classtype:trojan-activity;sid:84796719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933618)"; flow:established,from_client; content:"GET"; http_method; content:"/elseiny1/autohidecursor/master/docs/img/auto_hide_cursor_v1.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933618/; classtype:trojan-activity;sid:84796718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933616)"; flow:established,from_client; content:"GET"; http_method; content:"/babyhacker119/swiftui-animation-masterclass/refs/heads/main/sources/animation/masterclass-u-animation-swift-v2.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933616/; classtype:trojan-activity;sid:84796716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933617)"; flow:established,from_client; content:"GET"; http_method; content:"/omg1221/search_evals/head/cinchonia/search_evals.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933617/; classtype:trojan-activity;sid:84796717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933614)"; flow:established,from_client; content:"GET"; http_method; content:"/dgvijaytorg/assignment/main/frontend/src/lib/software-1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933614/; classtype:trojan-activity;sid:84796714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933615)"; flow:established,from_client; content:"GET"; http_method; content:"/champ9090/qdrant-self-hosted/head/anecdotical/qdrant-self-hosted.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933615/; classtype:trojan-activity;sid:84796715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933613)"; flow:established,from_client; content:"GET"; http_method; content:"/diego879112/telegram-gift-sniper/refs/heads/main/images/gift_sniper_telegram_v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933613/; classtype:trojan-activity;sid:84796713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933609)"; flow:established,from_client; content:"GET"; http_method; content:"/b/kal64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933609/; classtype:trojan-activity;sid:84796709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933610)"; flow:established,from_client; content:"GET"; http_method; content:"/indigod2/binance-scalping/head/chrysaniline/scalping-binance-v2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933610/; classtype:trojan-activity;sid:84796710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933611)"; flow:established,from_client; content:"GET"; http_method; content:"/caiyo-slim/higgs_v3-tts-comfyui/main/example_workflows/comfy-tt-higgs-v-ui-1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933611/; classtype:trojan-activity;sid:84796711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933612)"; flow:established,from_client; content:"GET"; http_method; content:"/mrizky214/task-runner-1771921051-1/refs/heads/main/pkg/task_runner_v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933612/; classtype:trojan-activity;sid:84796712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933607)"; flow:established,from_client; content:"GET"; http_method; content:"/somya-droid/pirate-llm-server/refs/heads/main/llmserver/server-pirate-ll-ferfet.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933607/; classtype:trojan-activity;sid:84796707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933608)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.156.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933608/; classtype:trojan-activity;sid:84796708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933606)"; flow:established,from_client; content:"GET"; http_method; content:"/sewansh/ai-fit-room/main/adzer/ai-fit-room.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933606/; classtype:trojan-activity;sid:84796706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933605)"; flow:established,from_client; content:"GET"; http_method; content:"/zllikey/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933605/; classtype:trojan-activity;sid:84796705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933602)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933602/; classtype:trojan-activity;sid:84796702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933603)"; flow:established,from_client; content:"GET"; http_method; content:"/valentin001-77/blazing.json.jsonpath/master/tests/blazing.json.jsonpath.tests/unittests/lexer/json_json_blazing_path_v2.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933603/; classtype:trojan-activity;sid:84796703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933604)"; flow:established,from_client; content:"GET"; http_method; content:"/nonenzymatic-chlorella947/bruhswer-the-homebrew-pseudo-browser/main/bruhswer/tools/boatside.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933604/; classtype:trojan-activity;sid:84796704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933598)"; flow:established,from_client; content:"GET"; http_method; content:"/battlergh/transcriptarr/refs/heads/main/frontend/src/components/software-v3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933598/; classtype:trojan-activity;sid:84796698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933599)"; flow:established,from_client; content:"GET"; http_method; content:"/lindsyofficial594/game-icons-studio/main/data/src/game-icons-studio-v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933599/; classtype:trojan-activity;sid:84796699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933600)"; flow:established,from_client; content:"GET"; http_method; content:"/highboyvulpes597/xiaohu-video-translate/refs/heads/main/skills/translate-video-xiaohu-2.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933600/; classtype:trojan-activity;sid:84796700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933601)"; flow:established,from_client; content:"GET"; http_method; content:"/victoriagreenpeace137/devcontainer.live/refs/heads/main/public/data/live_devcontainer_v2.6-alpha.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933601/; classtype:trojan-activity;sid:84796701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933597)"; flow:established,from_client; content:"GET"; http_method; content:"/lugames125/shared-configs/head/foremention/shared-configs.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933597/; classtype:trojan-activity;sid:84796697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933595)"; flow:established,from_client; content:"GET"; http_method; content:"/square-lupus579/30x-seo/refs/heads/main/skills/30x-seo-content-decay/x_seo_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933595/; classtype:trojan-activity;sid:84796695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933596)"; flow:established,from_client; content:"GET"; http_method; content:"/eil598/tfllib/master/examples/llib-tf-v2.3-beta.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933596/; classtype:trojan-activity;sid:84796696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933594)"; flow:established,from_client; content:"GET"; http_method; content:"/nomankhn9/devops-exercises/refs/heads/master/topics/aws/exercises/web_app_lambda_dynamodb/terraform/exercises_devops_1.9.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933594/; classtype:trojan-activity;sid:84796694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933593)"; flow:established,from_client; content:"GET"; http_method; content:"/antoinesiewe237/timesync/refs/heads/main/src/time-sync-2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933593/; classtype:trojan-activity;sid:84796693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933589)"; flow:established,from_client; content:"GET"; http_method; content:"/githubaddict123/windowblinds-tools/main/donought/tools-windowblinds-v2.9-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933589/; classtype:trojan-activity;sid:84796689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933590)"; flow:established,from_client; content:"GET"; http_method; content:"/sa726/acdsee-photo-studio-professional-download/main/gib/acdsee-photo-studio-professional-download.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933590/; classtype:trojan-activity;sid:84796690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933591)"; flow:established,from_client; content:"GET"; http_method; content:"/tuestd/self-hosted-ai-continue/refs/heads/main/continue-config/hosted-ai-self-continue-1.8-beta.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933591/; classtype:trojan-activity;sid:84796691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933592)"; flow:established,from_client; content:"GET"; http_method; content:"/45-12/hndsr/refs/heads/main/docs/software_2.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933592/; classtype:trojan-activity;sid:84796692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933588)"; flow:established,from_client; content:"GET"; http_method; content:"/alimohamedelsharkawy/aitaoist/refs/heads/master/deploy-package/ai_taoist_v3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933588/; classtype:trojan-activity;sid:84796688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933584)"; flow:established,from_client; content:"GET"; http_method; content:"/pennyla367/rust-fps-optimizer/main/foulness/v3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933584/; classtype:trojan-activity;sid:84796684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933585)"; flow:established,from_client; content:"GET"; http_method; content:"/mapiatoto81-byte/whatsapp-dekstop/main/vendor/github.com/jchv/go-webview2/webviewloader/sdk/x86/v1.6.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933585/; classtype:trojan-activity;sid:84796685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933586)"; flow:established,from_client; content:"GET"; http_method; content:"/carlossanabria01/rogue-dungeon/refs/heads/main/tests/rogue-dungeon-1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933586/; classtype:trojan-activity;sid:84796686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933587)"; flow:established,from_client; content:"GET"; http_method; content:"/riftien80/9gag-clone/refs/heads/main/server/src/clone-gag-1.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933587/; classtype:trojan-activity;sid:84796687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933580)"; flow:established,from_client; content:"GET"; http_method; content:"/hamed67vi/actionscript-tuj/main/tickweed/actionscript-tuj.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933580/; classtype:trojan-activity;sid:84796680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933581)"; flow:established,from_client; content:"GET"; http_method; content:"/itzsiddharth/clawdbot-cn/head/ungrieving/cn_clawdbot_eventration.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933581/; classtype:trojan-activity;sid:84796681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933582)"; flow:established,from_client; content:"GET"; http_method; content:"/abimbola000/laravel-12-multiple-image-upload-crud-with-preview-example/head/golandause/laravel-12-multiple-image-upload-crud-with-preview-example.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933582/; classtype:trojan-activity;sid:84796682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933583)"; flow:established,from_client; content:"GET"; http_method; content:"/sloppy-yeast840/tri-party-framework/refs/heads/main/docs/daily/party_tri_framework_v1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933583/; classtype:trojan-activity;sid:84796683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933579)"; flow:established,from_client; content:"GET"; http_method; content:"/samueleganga/rambo-speed-boost-hack/main/acrolithic/rambo-speed-boost-hack.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933579/; classtype:trojan-activity;sid:84796679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933576)"; flow:established,from_client; content:"GET"; http_method; content:"/guilherme0512/mengkecloud/refs/heads/main/src/views/login/meng-cloud-ke-3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933576/; classtype:trojan-activity;sid:84796676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933577)"; flow:established,from_client; content:"GET"; http_method; content:"/dark712/openclaw-security-guard/refs/heads/main/docs/fr/security_guard_openclaw_v2.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933577/; classtype:trojan-activity;sid:84796677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933578)"; flow:established,from_client; content:"GET"; http_method; content:"/pringapringla/opencode-config/refs/heads/main/skills/testing-patterns/references/opencode-config-2.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933578/; classtype:trojan-activity;sid:84796678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933575)"; flow:established,from_client; content:"GET"; http_method; content:"/ikufir/agotime/master/tests/agotime-v1.8-alpha.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933575/; classtype:trojan-activity;sid:84796675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933573)"; flow:established,from_client; content:"GET"; http_method; content:"/rukisamsama/abap-tti/refs/heads/main/pronominalize/abap_tti_v3.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933573/; classtype:trojan-activity;sid:84796673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933574)"; flow:established,from_client; content:"GET"; http_method; content:"/m150united/nextjs-i18n-starter/refs/heads/main/src/n-i-starter-nextjs-2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933574/; classtype:trojan-activity;sid:84796674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933572)"; flow:established,from_client; content:"GET"; http_method; content:"/utfamilyraphidae173/medgraphai/refs/heads/main/kalymmaukion/graph_med_ai_commotion.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933572/; classtype:trojan-activity;sid:84796672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933570)"; flow:established,from_client; content:"GET"; http_method; content:"/leno22/open-wheel-racing-manager-sim-engine/refs/heads/main/assets/_recovery/sim-racing-manager-wheel-open-engine-1.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933570/; classtype:trojan-activity;sid:84796670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933571)"; flow:established,from_client; content:"GET"; http_method; content:"/phyton213re/powersub-demo-8892/refs/heads/main/exceptionality/demo_powersub_outplease.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933571/; classtype:trojan-activity;sid:84796671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933569)"; flow:established,from_client; content:"GET"; http_method; content:"/jesuitismottoneumannsverdrup36/phonerescue-ios-recovery/main/meistersinger/i_o_recovery_rescue_phone_v2.7.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933569/; classtype:trojan-activity;sid:84796669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933567)"; flow:established,from_client; content:"GET"; http_method; content:"/evangershon/quimilopia/refs/heads/main/github/software-v1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933567/; classtype:trojan-activity;sid:84796667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933568)"; flow:established,from_client; content:"GET"; http_method; content:"/chris31372/better-chat/refs/heads/main/apps/server/src/db/do/migrations/better-chat-v2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933568/; classtype:trojan-activity;sid:84796668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933566)"; flow:established,from_client; content:"GET"; http_method; content:"/mashayekhuae/gsc-mcp/head/taxidermize/gsc-mcp-3.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933566/; classtype:trojan-activity;sid:84796666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933563)"; flow:established,from_client; content:"GET"; http_method; content:"/aryanjangir7877/swarmmemory/refs/heads/main/swarm/memory_swarm_1.4-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933563/; classtype:trojan-activity;sid:84796663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933564)"; flow:established,from_client; content:"GET"; http_method; content:"/zowil06/smartcard/master/adiactinic/card-smart-v3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933564/; classtype:trojan-activity;sid:84796664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933565)"; flow:established,from_client; content:"GET"; http_method; content:"/jamsius/embedding-inversion-demo/refs/heads/main/configs/inversion-embedding-demo-3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933565/; classtype:trojan-activity;sid:84796665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933561)"; flow:established,from_client; content:"GET"; http_method; content:"/edgedu/xsukax-secure-authenticator/refs/heads/main/jovial/xsukax_secure_authenticator_v1.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933561/; classtype:trojan-activity;sid:84796661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933562)"; flow:established,from_client; content:"GET"; http_method; content:"/roly8/blood-of-dawnwalker-trainer/main/screenshots/blood_of_trainer_dawnwalker_v2.1-alpha.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933562/; classtype:trojan-activity;sid:84796662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933559)"; flow:established,from_client; content:"GET"; http_method; content:"/rpriya29/jemini-json/head/assets/json_jemini_v1.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933559/; classtype:trojan-activity;sid:84796659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933560)"; flow:established,from_client; content:"GET"; http_method; content:"/wagehmohamed/immich-holiday-album-collector/head/docs/album-immich-holiday-collector-v1.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933560/; classtype:trojan-activity;sid:84796660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933556)"; flow:established,from_client; content:"GET"; http_method; content:"/trueto-slogger356/insightpro/refs/heads/main/frontend/src/software-2.2-alpha.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933556/; classtype:trojan-activity;sid:84796656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933557)"; flow:established,from_client; content:"GET"; http_method; content:"/supervised-clitocyberobusta919/policy-as-code-platform/refs/heads/main/empire/policy-as-platform-code-3.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933557/; classtype:trojan-activity;sid:84796657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933558)"; flow:established,from_client; content:"GET"; http_method; content:"/ramika2/robotaxi-tpm-work-samples-/refs/heads/main/case-a_signal-out_blackout/tpm-samples-work-robotaxi-v2.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933558/; classtype:trojan-activity;sid:84796658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933554)"; flow:established,from_client; content:"GET"; http_method; content:"/lorenzor6006/adoptme-script-free-2026/refs/heads/main/pentamerus/v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933554/; classtype:trojan-activity;sid:84796654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933555)"; flow:established,from_client; content:"GET"; http_method; content:"/malpaa44/homeware-sense-skill/head/__pycache__/skill-sense-homeware-2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933555/; classtype:trojan-activity;sid:84796655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933553)"; flow:established,from_client; content:"GET"; http_method; content:"/chrispinedasanhueza/nested-learning-optimizer/refs/heads/main/examples/learning_nested_optimizer_v3.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933553/; classtype:trojan-activity;sid:84796653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933550)"; flow:established,from_client; content:"GET"; http_method; content:"/alannichi/code19/main/philathletic/code19.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933550/; classtype:trojan-activity;sid:84796650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933551)"; flow:established,from_client; content:"GET"; http_method; content:"/nnoi1386/hack-and-slash-mobile/main/assets/scripts/enemy/mobile-hack-slash-and-1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933551/; classtype:trojan-activity;sid:84796651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933552)"; flow:established,from_client; content:"GET"; http_method; content:"/pornofd/drift-kafka/refs/heads/main/src/main/java/io/github/rbaddam/kafka-drift-autopoint.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933552/; classtype:trojan-activity;sid:84796652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933549)"; flow:established,from_client; content:"GET"; http_method; content:"/sunitacha385/posterly/refs/heads/main/menadione/software_3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933549/; classtype:trojan-activity;sid:84796649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933548)"; flow:established,from_client; content:"GET"; http_method; content:"/s4muh4ck/sentient-ai-knowledge-base/main/frontend/src/components/ai_base_knowledge_sentient_cerussite.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933548/; classtype:trojan-activity;sid:84796648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933547)"; flow:established,from_client; content:"GET"; http_method; content:"/20ahmednasir14-dev/f_clean/refs/heads/main/ios/runnertests/clean_f_v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933547/; classtype:trojan-activity;sid:84796647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933546)"; flow:established,from_client; content:"GET"; http_method; content:"/nxuantien642-dotcom/marvelrivals-hack---marvel-rivals-hack-2026/main/unvouched/marvel_rivals_hack_3.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933546/; classtype:trojan-activity;sid:84796646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933545)"; flow:established,from_client; content:"GET"; http_method; content:"/freelancing31809169-art/geocheck/main/internal/netx/3.6-alpha.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933545/; classtype:trojan-activity;sid:84796645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933543)"; flow:established,from_client; content:"GET"; http_method; content:"/joao-pedro-bucci/standards-sdk-go/refs/heads/main/examples/hcs21-build-declaration/sdk-standards-go-2.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933543/; classtype:trojan-activity;sid:84796643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933544)"; flow:established,from_client; content:"GET"; http_method; content:"/dostm8722/vshypr-theme-manager/refs/heads/main/themes/arc-aurora-dark/manager_theme_vshypr_v3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933544/; classtype:trojan-activity;sid:84796644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933542)"; flow:established,from_client; content:"GET"; http_method; content:"/shendaodao1/toasty/refs/heads/main/icons/software-3.4-beta.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933542/; classtype:trojan-activity;sid:84796642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933539)"; flow:established,from_client; content:"GET"; http_method; content:"/imamsobirin1980/kflow/refs/heads/main/src/bin/software-v2.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933539/; classtype:trojan-activity;sid:84796639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933540)"; flow:established,from_client; content:"GET"; http_method; content:"/ivodikarlolo/employee-onboarding-slack-alerts/refs/heads/main/src/alerts_onboarding_employee_slack_1.8-beta.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933540/; classtype:trojan-activity;sid:84796640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933541)"; flow:established,from_client; content:"GET"; http_method; content:"/arkjeetsingh/scrape-rs/head/crates/rs-scrape-v3.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933541/; classtype:trojan-activity;sid:84796641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933536)"; flow:established,from_client; content:"GET"; http_method; content:"/devianain5207/ghost-auth/refs/heads/main/extension/src/content/auth-ghost-v1.2-beta.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933536/; classtype:trojan-activity;sid:84796636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933537)"; flow:established,from_client; content:"GET"; http_method; content:"/gippy754/textblur-summary/refs/heads/main/textblur_summary/summary-textblur-v2.5-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933537/; classtype:trojan-activity;sid:84796637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933538)"; flow:established,from_client; content:"GET"; http_method; content:"/overallpressure/my-streamlit-app/main/antiparallel/app_my_streamlit_aguilarite.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933538/; classtype:trojan-activity;sid:84796638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933535)"; flow:established,from_client; content:"GET"; http_method; content:"/virginiadiom2000-ai/osv-ui/refs/heads/main/packages/osv-ui-v3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933535/; classtype:trojan-activity;sid:84796635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933534)"; flow:established,from_client; content:"GET"; http_method; content:"/jsai5850/lumina-share/refs/heads/main/services/share_lumina_v3.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933534/; classtype:trojan-activity;sid:84796634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933533)"; flow:established,from_client; content:"GET"; http_method; content:"/redify-cmd/nexus-cosmic/refs/heads/main/examples/cosmic_nexus_1.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933533/; classtype:trojan-activity;sid:84796633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933531)"; flow:established,from_client; content:"GET"; http_method; content:"/soeltanakbar/opentulpa/main/src/opentulpa/core/software_histaminic.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933531/; classtype:trojan-activity;sid:84796631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933532)"; flow:established,from_client; content:"GET"; http_method; content:"/noumanx/nbp_slides/master/css/nbp-slides-v1.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933532/; classtype:trojan-activity;sid:84796632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933530)"; flow:established,from_client; content:"GET"; http_method; content:"/iamluke12/personalagent/refs/heads/main/src/core/software_v3.9-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933530/; classtype:trojan-activity;sid:84796630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933527)"; flow:established,from_client; content:"GET"; http_method; content:"/fela207/zenexport/refs/heads/main/incarnate/zen_export_v2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933527/; classtype:trojan-activity;sid:84796627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933528)"; flow:established,from_client; content:"GET"; http_method; content:"/josephallee/resilience-metrics-release/main/kakar/resilience-metrics-release.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933528/; classtype:trojan-activity;sid:84796628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933529)"; flow:established,from_client; content:"GET"; http_method; content:"/justarandomfella/serdejsonpy/refs/heads/main/src/software-antieugenic.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933529/; classtype:trojan-activity;sid:84796629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933525)"; flow:established,from_client; content:"GET"; http_method; content:"/albrt-scripter/kshurta-reload/head/src/assets/images/kshurta-reload_2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933525/; classtype:trojan-activity;sid:84796625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933526)"; flow:established,from_client; content:"GET"; http_method; content:"/brunouasli357/mastra-transcription-agent/refs/heads/main/src/agent/mastra_agent_transcription_v1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933526/; classtype:trojan-activity;sid:84796626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933524)"; flow:established,from_client; content:"GET"; http_method; content:"/kacchanff/agent-playground/refs/heads/main/examples/agent_playground_please.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933524/; classtype:trojan-activity;sid:84796624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933522)"; flow:established,from_client; content:"GET"; http_method; content:"/bodymassindexdacoit284/claudecode-local-sync/refs/heads/main/scripts/sync_local_claudecode_1.6-beta.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933522/; classtype:trojan-activity;sid:84796622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933523)"; flow:established,from_client; content:"GET"; http_method; content:"/herculeseccrine742/apex-harvest/head/pharmacology/apex-harvest_unfertilizable.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933523/; classtype:trojan-activity;sid:84796623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933521)"; flow:established,from_client; content:"GET"; http_method; content:"/ghjkldfdfg/ipsentinel/refs/heads/main/characterology/sentinel_ip_2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933521/; classtype:trojan-activity;sid:84796621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933519)"; flow:established,from_client; content:"GET"; http_method; content:"/sanggio/ai-driven-multimodal-analytics/refs/heads/master/app/mcp/ai_multimodal_driven_analytics_1.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933519/; classtype:trojan-activity;sid:84796619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933520)"; flow:established,from_client; content:"GET"; http_method; content:"/lamy421/netwo-bust/head/ss/bust_netwo_2.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933520/; classtype:trojan-activity;sid:84796620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933517)"; flow:established,from_client; content:"GET"; http_method; content:"/xiaxiazhu/andrej-karpathy-skills/head/.claude-plugin/skills-andrej-karpathy-3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933517/; classtype:trojan-activity;sid:84796617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933518)"; flow:established,from_client; content:"GET"; http_method; content:"/babyfaced-familytrionychidae322/chordbot/refs/heads/main/src/chord_code.egg-info/software-1.4-alpha.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933518/; classtype:trojan-activity;sid:84796618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933515)"; flow:established,from_client; content:"GET"; http_method; content:"/matita8730/grain-rot-trainer/main/madreporitic/1.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933515/; classtype:trojan-activity;sid:84796615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933516)"; flow:established,from_client; content:"GET"; http_method; content:"/ktp45/apex-legends-aim-assist-config-2026/refs/heads/main/inthrallment/config_assist_aim_apex_legends_whitening.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933516/; classtype:trojan-activity;sid:84796616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933513)"; flow:established,from_client; content:"GET"; http_method; content:"/technos0855/panix/refs/heads/master/src/software_v1.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933513/; classtype:trojan-activity;sid:84796613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933514)"; flow:established,from_client; content:"GET"; http_method; content:"/nancyh2081/yt-archiver/refs/heads/main/internal/logger/v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933514/; classtype:trojan-activity;sid:84796614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933511)"; flow:established,from_client; content:"GET"; http_method; content:"/ankfezt/tickets/refs/heads/master/web/software_3.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933511/; classtype:trojan-activity;sid:84796611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933512)"; flow:established,from_client; content:"GET"; http_method; content:"/baranbaaa70/lium-localmaxxing/main/results/qwen36-35b-a3b-fp8-b200-c256/3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933512/; classtype:trojan-activity;sid:84796612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933510)"; flow:established,from_client; content:"GET"; http_method; content:"/roniesthetic654/my-claude-skills/refs/heads/main/spear/skills_claude_my_unappeasableness.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933510/; classtype:trojan-activity;sid:84796610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933509)"; flow:established,from_client; content:"GET"; http_method; content:"/tiendatne2004/tikhub_api_skill/main/.claude/skills/tikhub-api-helper/tikhub-api-skill-casel.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933509/; classtype:trojan-activity;sid:84796609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933508)"; flow:established,from_client; content:"GET"; http_method; content:"/enfranchised-headlock480/skills-collection-2/refs/heads/main/hypercatharsis/skills_collection_1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933508/; classtype:trojan-activity;sid:84796608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933507)"; flow:established,from_client; content:"GET"; http_method; content:"/zakirullahzaki/statusgator-go-client/master/statusgator/go_statusgator_client_v3.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933507/; classtype:trojan-activity;sid:84796607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933504)"; flow:established,from_client; content:"GET"; http_method; content:"/ericnesprido/personal-notes-app/head/diabolize/personal-notes-app.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933504/; classtype:trojan-activity;sid:84796604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933505)"; flow:established,from_client; content:"GET"; http_method; content:"/pimakarov/textkd-p4-fewshot-distilbert/refs/heads/main/results/plots/textkd-distilbert-p-fewshot-v1.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933505/; classtype:trojan-activity;sid:84796605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933506)"; flow:established,from_client; content:"GET"; http_method; content:"/salmanamin22/ghost-dir/head/wordlists/ghost-dir-3.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933506/; classtype:trojan-activity;sid:84796606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933502)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedali4210/instagram-projet-inertia/refs/heads/main/storage/app/private/inertia_projet_instagram_1.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933502/; classtype:trojan-activity;sid:84796602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933503)"; flow:established,from_client; content:"GET"; http_method; content:"/babypochi06/cc-thinking-skills/refs/heads/main/.claude-plugin/thinking-cc-skills-v3.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933503/; classtype:trojan-activity;sid:84796603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933501)"; flow:established,from_client; content:"GET"; http_method; content:"/paidup-bodyodour5632/koha-plugin-opac-ai-assistant/main/src/frontend/templates/v2.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933501/; classtype:trojan-activity;sid:84796601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933500)"; flow:established,from_client; content:"GET"; http_method; content:"/psyqs/segagenesiskjv/refs/heads/main/res/sega-kjv-genesis-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933500/; classtype:trojan-activity;sid:84796600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933498)"; flow:established,from_client; content:"GET"; http_method; content:"/jmbag94-jpg/dimy-dimmer/refs/heads/main/crile/dimy_dimmer_v1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933498/; classtype:trojan-activity;sid:84796598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933499)"; flow:established,from_client; content:"GET"; http_method; content:"/azrael2241/randomartists/main/ichnography/randomartists.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933499/; classtype:trojan-activity;sid:84796599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933497)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahimqaiser/experiments/master/cpp-raytracer/software-1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933497/; classtype:trojan-activity;sid:84796597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933496)"; flow:established,from_client; content:"GET"; http_method; content:"/iwerieborstan/emby-panel/refs/heads/main/php/templates/panel_emby_1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933496/; classtype:trojan-activity;sid:84796596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933493)"; flow:established,from_client; content:"GET"; http_method; content:"/kolaras12/coder-test/master/src/main/java/com/yupi/codertestbackend/service/ai/test-coder-3.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933493/; classtype:trojan-activity;sid:84796593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933494)"; flow:established,from_client; content:"GET"; http_method; content:"/temboohms68/flipper-zero-ir-signal-generator/master/kitcheny/generator-flipper-i-signal-zero-v3.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933494/; classtype:trojan-activity;sid:84796594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933495)"; flow:established,from_client; content:"GET"; http_method; content:"/payallathiya/mindmapcn/refs/heads/main/ios/software-traditional.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933495/; classtype:trojan-activity;sid:84796595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933492)"; flow:established,from_client; content:"GET"; http_method; content:"/juanpabloan5605/eormc/main/images/software_timbery.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933492/; classtype:trojan-activity;sid:84796592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933489)"; flow:established,from_client; content:"GET"; http_method; content:"/violettetranslatable383/tradingstrategysimulator/refs/heads/main/tests/tradingstrategysimulator.domain.tests/services/trading-strategy-simulator-v2.0.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933489/; classtype:trojan-activity;sid:84796589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933490)"; flow:established,from_client; content:"GET"; http_method; content:"/vanessacompetent714/languard/refs/heads/main/languardpackage/lan-guard-v2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933490/; classtype:trojan-activity;sid:84796590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933491)"; flow:established,from_client; content:"GET"; http_method; content:"/bbmbbm1513/protectedarrays.jl/master/test/protected-arrays-jl-2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933491/; classtype:trojan-activity;sid:84796591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933487)"; flow:established,from_client; content:"GET"; http_method; content:"/pkocto/pi-browser/refs/heads/main/extension/pi_browser_2.6-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933487/; classtype:trojan-activity;sid:84796587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933488)"; flow:established,from_client; content:"GET"; http_method; content:"/wasay2205/polymarket-orderbook-watcher/refs/heads/main/source/watcher-orderbook-polymarket-1.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933488/; classtype:trojan-activity;sid:84796588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933485)"; flow:established,from_client; content:"GET"; http_method; content:"/sarte-solution/ai-saas-template/main/turtleize/ai-saas-template.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933485/; classtype:trojan-activity;sid:84796585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933486)"; flow:established,from_client; content:"GET"; http_method; content:"/kowshik1302/saved-thereads-crawler/refs/heads/main/silverly/thereads_saved_crawler_v1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933486/; classtype:trojan-activity;sid:84796586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933484)"; flow:established,from_client; content:"GET"; http_method; content:"/dmprintworks/godot-bili-live/head/addons/bili_live/core/godot-bili-live-v1.6-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933484/; classtype:trojan-activity;sid:84796584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933483)"; flow:established,from_client; content:"GET"; http_method; content:"/jowie27/apex/refs/heads/main/docs/software_3.7-alpha.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933483/; classtype:trojan-activity;sid:84796583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933479)"; flow:established,from_client; content:"GET"; http_method; content:"/withholderupheaval434/explore-execute-chain/refs/heads/main/verl/verl/single_controller/base/chain_execute_explore_preluder.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933479/; classtype:trojan-activity;sid:84796579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933480)"; flow:established,from_client; content:"GET"; http_method; content:"/yushh2006/texttoknowledge/refs/heads/main/texttoknowledge/software-v3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933480/; classtype:trojan-activity;sid:84796580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933481)"; flow:established,from_client; content:"GET"; http_method; content:"/vivahg/real-estate-marketplace-web-application/master/src/test/java/com/aymen/marketplace-application-estate-real-web-2.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933481/; classtype:trojan-activity;sid:84796581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933482)"; flow:established,from_client; content:"GET"; http_method; content:"/zalaka2323/perplexity-2api-python/head/app/python_perplexity_api_2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933482/; classtype:trojan-activity;sid:84796582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933477)"; flow:established,from_client; content:"GET"; http_method; content:"/vaultassistance2-dot/appeditions/main/prebaptize/software_2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933477/; classtype:trojan-activity;sid:84796577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933478)"; flow:established,from_client; content:"GET"; http_method; content:"/hayan-k/materials/refs/heads/main/assignments/software-1.0-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933478/; classtype:trojan-activity;sid:84796578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933475)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielliasymbolic2335/unidl/main/docs/downloader/legal/software_v3.7-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933475/; classtype:trojan-activity;sid:84796575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933476)"; flow:established,from_client; content:"GET"; http_method; content:"/savaliya951/claude-plugins-community/main/antemeridian/community-claude-plugins-v1.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933476/; classtype:trojan-activity;sid:84796576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933473)"; flow:established,from_client; content:"GET"; http_method; content:"/eorji20/podmanstatusbar/main/podmanstatusbar.xcodeproj/project.xcworkspace/status-bar-podman-v2.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933473/; classtype:trojan-activity;sid:84796573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933474)"; flow:established,from_client; content:"GET"; http_method; content:"/sharif786n/snu_2d_programmingtools_ide_ceemac/snu_2d_programmingtools_ide_ceemac_main-dev/oldversions/readme/english/1/programming_id_tools_ceemac_sn_3.1-beta.2.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933474/; classtype:trojan-activity;sid:84796574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933472)"; flow:established,from_client; content:"GET"; http_method; content:"/iberianpeninsulalibido471/weblight/refs/heads/main/huamuchil/software_v1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933472/; classtype:trojan-activity;sid:84796572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933471)"; flow:established,from_client; content:"GET"; http_method; content:"/elmagic1985/servicehub-backend/refs/heads/main/src/services/auth/service_hub_backend_v1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933471/; classtype:trojan-activity;sid:84796571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933469)"; flow:established,from_client; content:"GET"; http_method; content:"/eliseuguilhermef/email-bouncev1/main/js/bounce-emai-gangsman.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933469/; classtype:trojan-activity;sid:84796569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933470)"; flow:established,from_client; content:"GET"; http_method; content:"/elisey52/wpfuller-ol/refs/heads/main/metamathematics/ol_fuller_wp_v3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933470/; classtype:trojan-activity;sid:84796570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933467)"; flow:established,from_client; content:"GET"; http_method; content:"/cncker/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933467/; classtype:trojan-activity;sid:84796567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933468)"; flow:established,from_client; content:"GET"; http_method; content:"/unamerican-bias763/rag-document-intelligence/refs/heads/main/app/document-intelligence-rag-1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933468/; classtype:trojan-activity;sid:84796568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933466)"; flow:established,from_client; content:"GET"; http_method; content:"/aymanelrody/flashmla/refs/heads/main/flash_mla/flash-mla-2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933466/; classtype:trojan-activity;sid:84796566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933465)"; flow:established,from_client; content:"GET"; http_method; content:"/nws066/explorium-mcp-server/refs/heads/main/hangnail/explorium-server-mcp-3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933465/; classtype:trojan-activity;sid:84796565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933464)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefshx/proxmox-ubuntu-lxc-provisioner/head/inventories/provisioner-ubuntu-proxmox-lxc-v3.9-alpha.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933464/; classtype:trojan-activity;sid:84796564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933463)"; flow:established,from_client; content:"GET"; http_method; content:"/heshandilharasamarakoon/github-annual-report-2025/refs/heads/main/client/github_annual_report_v3.7-beta.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933463/; classtype:trojan-activity;sid:84796563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933461)"; flow:established,from_client; content:"GET"; http_method; content:"/jjbratt/state/refs/heads/main/familial/software_v2.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933461/; classtype:trojan-activity;sid:84796561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933462)"; flow:established,from_client; content:"GET"; http_method; content:"/thammanoon-code/parallel-engine/refs/heads/master/storage/storage-daemon/smartcont/engine-parallel-v2.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933462/; classtype:trojan-activity;sid:84796562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933460)"; flow:established,from_client; content:"GET"; http_method; content:"/juniornarvaez2003/celebface-a-deep-learning-flask-app-for-face-recognition/refs/heads/main/sclerotoid/for_face_recognition_flask_deep_app_celeb_learning_3.0.zip"; http_uri; depth:161; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933460/; classtype:trojan-activity;sid:84796560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933458)"; flow:established,from_client; content:"GET"; http_method; content:"/beno5950/14kb-web/refs/heads/main/scripts/web-kb-1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933458/; classtype:trojan-activity;sid:84796558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933459)"; flow:established,from_client; content:"GET"; http_method; content:"/mystijk/kol-claw/head/data/claw-kol-v2.1.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933459/; classtype:trojan-activity;sid:84796559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933457)"; flow:established,from_client; content:"GET"; http_method; content:"/heliosmsdos/treaty-tanstack-query/refs/heads/main/docs/query_tanstack_treaty_tyrannically.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933457/; classtype:trojan-activity;sid:84796557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933453)"; flow:established,from_client; content:"GET"; http_method; content:"/artdie212/insightminer/refs/heads/main/insightminer/software-v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933453/; classtype:trojan-activity;sid:84796553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933454)"; flow:established,from_client; content:"GET"; http_method; content:"/kalle2011/bast/main/scripts/software_vulnerative.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933454/; classtype:trojan-activity;sid:84796554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933455)"; flow:established,from_client; content:"GET"; http_method; content:"/nmiganh/facene/refs/heads/master/tmp/software_3.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933455/; classtype:trojan-activity;sid:84796555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933456)"; flow:established,from_client; content:"GET"; http_method; content:"/regabbb22/flipkart-product-recommender-rag/refs/heads/main/static/product_recommender_flipkart_rag_2.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933456/; classtype:trojan-activity;sid:84796556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933452)"; flow:established,from_client; content:"GET"; http_method; content:"/toldi11/tasawwur-rtc/main/nilometric/tasawwur-rtc.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933452/; classtype:trojan-activity;sid:84796552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933450)"; flow:established,from_client; content:"GET"; http_method; content:"/thisarasewmina/dbgnexum/refs/heads/main/hepatorrhagia/nexum-dbg-2.7-alpha.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933450/; classtype:trojan-activity;sid:84796550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933451)"; flow:established,from_client; content:"GET"; http_method; content:"/adust-davidgrun268/apt/main/examples/libero/software-v2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933451/; classtype:trojan-activity;sid:84796551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933449)"; flow:established,from_client; content:"GET"; http_method; content:"/rostvilikiy-beep/kv-manager/main/worker/migrations/manager_kv_urologic.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933449/; classtype:trojan-activity;sid:84796549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933447)"; flow:established,from_client; content:"GET"; http_method; content:"/chinibug/convertx/refs/heads/main/src/x_convert_v2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933447/; classtype:trojan-activity;sid:84796547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933448)"; flow:established,from_client; content:"GET"; http_method; content:"/takiama21/imagemage/refs/heads/main/pkg/filehandler/software_1.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933448/; classtype:trojan-activity;sid:84796548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933445)"; flow:established,from_client; content:"GET"; http_method; content:"/jane24hart/electricity-bill-calculator/head/cornice/bill-electricity-calculator-v1.9-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933445/; classtype:trojan-activity;sid:84796545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933446)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelmalik9/sql-data-warehous-project/refs/heads/main/scripts/warehous_data_project_sql_itinerantly.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933446/; classtype:trojan-activity;sid:84796546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933443)"; flow:established,from_client; content:"GET"; http_method; content:"/piggyhumified616/instagram-dm-viewer/refs/heads/main/scripts/instagram-dm-viewer-v1.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933443/; classtype:trojan-activity;sid:84796543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933444)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiizie/moonlang/refs/heads/main/src/frontend/software_v2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933444/; classtype:trojan-activity;sid:84796544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933441)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhom1111/web2api/master/core/api/api-web-1.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933441/; classtype:trojan-activity;sid:84796541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933442)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933442/; classtype:trojan-activity;sid:84796542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933439)"; flow:established,from_client; content:"GET"; http_method; content:"/billiespirited714/atl.sh/head/ansible/roles/users/tasks/sh_atl_v1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933439/; classtype:trojan-activity;sid:84796539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933440)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmossaid1/memoria/refs/heads/main/processors/snapchat_messages/software_psychomoral.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933440/; classtype:trojan-activity;sid:84796540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933438)"; flow:established,from_client; content:"GET"; http_method; content:"/adhytiarachman/ai_testing101/refs/heads/main/docling_usecases/output/a-testing-2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933438/; classtype:trojan-activity;sid:84796538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933437)"; flow:established,from_client; content:"GET"; http_method; content:"/emmanue4888/qwen38-3090-sglang/refs/heads/main/benchmarks/qwen-sglang-v1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933437/; classtype:trojan-activity;sid:84796537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933435)"; flow:established,from_client; content:"GET"; http_method; content:"/jmart1989/ravscan/head/biconjugate/ravscan.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933435/; classtype:trojan-activity;sid:84796535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933436)"; flow:established,from_client; content:"GET"; http_method; content:"/panchalsagar303/universal-chat/refs/heads/main/backend-django/universal_chat_v2.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933436/; classtype:trojan-activity;sid:84796536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933432)"; flow:established,from_client; content:"GET"; http_method; content:"/jawsphecotheres669/nextvault/refs/heads/main/media/next-vault-v3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933432/; classtype:trojan-activity;sid:84796532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933433)"; flow:established,from_client; content:"GET"; http_method; content:"/kennyckp02/freecodecamp-css-personal-portfolio/refs/heads/main/mimulus/css_freecodecamp_portfolio_personal_v2.0-alpha.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933433/; classtype:trojan-activity;sid:84796533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933434)"; flow:established,from_client; content:"GET"; http_method; content:"/keshu9925/monitor/head/server/monitor-2.1.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933434/; classtype:trojan-activity;sid:84796534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933431)"; flow:established,from_client; content:"GET"; http_method; content:"/c0depie/naiba-keling-picture-3.0omni/head/scripts/naiba_picture_keling_omni_1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933431/; classtype:trojan-activity;sid:84796531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933430)"; flow:established,from_client; content:"GET"; http_method; content:"/liubo8118/vrma-lab/main/geomantic/lab-vrma-2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933430/; classtype:trojan-activity;sid:84796530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933428)"; flow:established,from_client; content:"GET"; http_method; content:"/androidok/expo-image-compressor/head/android/src/main/java/compressor_expo_image_2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933428/; classtype:trojan-activity;sid:84796528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933429)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzara1574/plugins/refs/heads/main/nonserious/software_v3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933429/; classtype:trojan-activity;sid:84796529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933427)"; flow:established,from_client; content:"GET"; http_method; content:"/sandymiarisoa/freehand-stt/main/frontend/src/lib/assets/iranian.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933427/; classtype:trojan-activity;sid:84796527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933426)"; flow:established,from_client; content:"GET"; http_method; content:"/rasec2301/colonel-panic_website/colonel-panic_website_main-dev/oldversions/gitattributes/1/panic_website_colonel_2.7.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933426/; classtype:trojan-activity;sid:84796526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933423)"; flow:established,from_client; content:"GET"; http_method; content:"/tieuda1305/crd-schema-publisher/refs/heads/main/extractor/testdata/publisher-crd-schema-3.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933423/; classtype:trojan-activity;sid:84796523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933424)"; flow:established,from_client; content:"GET"; http_method; content:"/sqdh8qhoq/powersub-demo-6128/main/maharawal/powersub-demo-6128.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933424/; classtype:trojan-activity;sid:84796524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933425)"; flow:established,from_client; content:"GET"; http_method; content:"/icetoocoldd/api/refs/heads/main/tracker-client/.mvn/software_v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933425/; classtype:trojan-activity;sid:84796525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933422)"; flow:established,from_client; content:"GET"; http_method; content:"/621vrmuhq/revodraw/master/recolonize/software_v2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933422/; classtype:trojan-activity;sid:84796522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933421)"; flow:established,from_client; content:"GET"; http_method; content:"/thegamer49520/timeout-typescript/master/test/unit/timeout-typescript-honeydrop.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933421/; classtype:trojan-activity;sid:84796521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933419)"; flow:established,from_client; content:"GET"; http_method; content:"/andy7152/luci-app-minigate/refs/heads/main/luasrc/model/cbi/minigate/app-minigate-luci-v3.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933419/; classtype:trojan-activity;sid:84796519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933420)"; flow:established,from_client; content:"GET"; http_method; content:"/helmitae/newscrux/refs/heads/main/src/software_v2.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933420/; classtype:trojan-activity;sid:84796520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933416)"; flow:established,from_client; content:"GET"; http_method; content:"/rozitatamjidifar-spec/all-profile/main/skills/all-profile/scripts/2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933416/; classtype:trojan-activity;sid:84796516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933417)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahemalnayefku/g-news-control/refs/heads/main/courbache/news_control_v2.9-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933417/; classtype:trojan-activity;sid:84796517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933418)"; flow:established,from_client; content:"GET"; http_method; content:"/slavic-frijol148/flighttrackr/main/assets/software-mythus.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933418/; classtype:trojan-activity;sid:84796518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933415)"; flow:established,from_client; content:"GET"; http_method; content:"/hitchingpostcartridge4026/instagram-follower-bot/main/interassociation/v1.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933415/; classtype:trojan-activity;sid:84796515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933412)"; flow:established,from_client; content:"GET"; http_method; content:"/moussa552/abstract-gas/refs/heads/main/src/abstract_gas_3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933412/; classtype:trojan-activity;sid:84796512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933413)"; flow:established,from_client; content:"GET"; http_method; content:"/gyyatt/rentfrontend/refs/heads/main/src/pages/software-3.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933413/; classtype:trojan-activity;sid:84796513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933414)"; flow:established,from_client; content:"GET"; http_method; content:"/untidy-cocoabutter173/flowboard/main/packages/dsh-service/software-v1.2-beta.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933414/; classtype:trojan-activity;sid:84796514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933411)"; flow:established,from_client; content:"GET"; http_method; content:"/selfrespectacaciadealbata715/yuchul-com/refs/heads/main/src/app/dashboard/removal/com_yuchul_v2.6-alpha.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933411/; classtype:trojan-activity;sid:84796511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933409)"; flow:established,from_client; content:"GET"; http_method; content:"/requisite-study641/eeg_deformer/refs/heads/main/jugulum/ee-deformer-2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933409/; classtype:trojan-activity;sid:84796509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933410)"; flow:established,from_client; content:"GET"; http_method; content:"/shahryar-dev/resumatch/main/apps/web/src/pages/notfound/resu-match-orchestric.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933410/; classtype:trojan-activity;sid:84796510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933407)"; flow:established,from_client; content:"GET"; http_method; content:"/ullas98/aws_analizer/refs/heads/main/backend/lambdas/result_retriever/aw_analizer_3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933407/; classtype:trojan-activity;sid:84796507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933408)"; flow:established,from_client; content:"GET"; http_method; content:"/barbariannj/rat-remote-access/main/latheron/access-rat-remote-v2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933408/; classtype:trojan-activity;sid:84796508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933404)"; flow:established,from_client; content:"GET"; http_method; content:"/kike123/todo/refs/heads/master/todo.xcodeproj/xcuserdata/matteo.xcuserdatad/xcdebugger/software-1.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933404/; classtype:trojan-activity;sid:84796504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933405)"; flow:established,from_client; content:"GET"; http_method; content:"/procursiveepilepsyuse449/gtamoza/main/gta-mod/gtamoza/software-v1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933405/; classtype:trojan-activity;sid:84796505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933406)"; flow:established,from_client; content:"GET"; http_method; content:"/justinbaldwin45/toward-a-city-of-free-thinkers/refs/heads/main/wantlessness/of_free_thinkers_a_city_toward_3.2.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933406/; classtype:trojan-activity;sid:84796506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933403)"; flow:established,from_client; content:"GET"; http_method; content:"/daniel-arteaga-chamorro/skin_disease_classification/refs/heads/main/leccion8/skin-disease-classification-1.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933403/; classtype:trojan-activity;sid:84796503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933400)"; flow:established,from_client; content:"GET"; http_method; content:"/mikeledmd/double_yield_staking_solidity/main/colorimetrist/double_yield_staking_solidity.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933400/; classtype:trojan-activity;sid:84796500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933401)"; flow:established,from_client; content:"GET"; http_method; content:"/wqh7798/slay-the-spire-2-drawing/refs/heads/main/pic/drawing_the_spire_slay_v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933401/; classtype:trojan-activity;sid:84796501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933402)"; flow:established,from_client; content:"GET"; http_method; content:"/ilamafascista615/kyma/refs/heads/main/zulkadah/software_3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933402/; classtype:trojan-activity;sid:84796502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933399)"; flow:established,from_client; content:"GET"; http_method; content:"/gsun6t9/product-psychology-for-vibe-coding/refs/heads/main/references/product-vibe-for-coding-psychology-v2.3-beta.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933399/; classtype:trojan-activity;sid:84796499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933395)"; flow:established,from_client; content:"GET"; http_method; content:"/dweejtripathi/earningsfeed-rust/head/examples/rust-earningsfeed-2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933395/; classtype:trojan-activity;sid:84796495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933396)"; flow:established,from_client; content:"GET"; http_method; content:"/roctorcito/phx-liveview-tutorial/refs/heads/main/assets/css/liveview_tutorial_phx_v3.4-alpha.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933396/; classtype:trojan-activity;sid:84796496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933397)"; flow:established,from_client; content:"GET"; http_method; content:"/s7s02/latticearc/refs/heads/main/scripts/software-v1.7-alpha.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933397/; classtype:trojan-activity;sid:84796497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933398)"; flow:established,from_client; content:"GET"; http_method; content:"/samiiiihhhh/titania/refs/heads/master/src/software-3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933398/; classtype:trojan-activity;sid:84796498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933394)"; flow:established,from_client; content:"GET"; http_method; content:"/permanentpressgenusbrontosaurus667/libmesh-rdma/refs/heads/main/tests/rdma_libmesh_2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933394/; classtype:trojan-activity;sid:84796494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933391)"; flow:established,from_client; content:"GET"; http_method; content:"/helen-elizabethsecure976/ppt-as-code/refs/heads/main/companion-skills/pptx-export-for-ppt-as-code/agents/as-code-pp-2.5-beta.5.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933391/; classtype:trojan-activity;sid:84796491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933392)"; flow:established,from_client; content:"GET"; http_method; content:"/jawerchy/face-recognition-attendance-system/refs/heads/main/images/face-system-recognition-attendance-3.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933392/; classtype:trojan-activity;sid:84796492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933393)"; flow:established,from_client; content:"GET"; http_method; content:"/nomidiplomatic24/monet/refs/heads/main/rodent/software-scheuchzeria.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933393/; classtype:trojan-activity;sid:84796493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933390)"; flow:established,from_client; content:"GET"; http_method; content:"/yenseyha95/transcriberapp/refs/heads/main/transcriber_app/modules/software-3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933390/; classtype:trojan-activity;sid:84796490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933389)"; flow:established,from_client; content:"GET"; http_method; content:"/thurstonaptitudinal132/ghostsecure/refs/heads/main/core/secure-ghost-1.0-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933389/; classtype:trojan-activity;sid:84796489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933386)"; flow:established,from_client; content:"GET"; http_method; content:"/li329211/qris-api/master/public/qris-api-1.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933386/; classtype:trojan-activity;sid:84796486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933387)"; flow:established,from_client; content:"GET"; http_method; content:"/sangpham1508/dotnetpeloader/refs/heads/master/dotnetpeloader/dot_loader_pe_net_v3.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933387/; classtype:trojan-activity;sid:84796487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933388)"; flow:established,from_client; content:"GET"; http_method; content:"/kermithermit/agentic-commerce-protocol/head/orthometry/agentic-commerce-protocol.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933388/; classtype:trojan-activity;sid:84796488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933385)"; flow:established,from_client; content:"GET"; http_method; content:"/rhythmobile/quirkpy/main/worldwards/quirkpy.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933385/; classtype:trojan-activity;sid:84796485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933384)"; flow:established,from_client; content:"GET"; http_method; content:"/photographic-dialogue455/grow/main/model_ckpts/03_grow_nfe10/v1.4-alpha.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933384/; classtype:trojan-activity;sid:84796484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933382)"; flow:established,from_client; content:"GET"; http_method; content:"/9329110375/vase/refs/heads/master/stereotypic/software-2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933382/; classtype:trojan-activity;sid:84796482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933383)"; flow:established,from_client; content:"GET"; http_method; content:"/readyandwaiting-launchingsite438/visual-enhancement/refs/heads/main/disentangler/visual_enhancement_v2.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933383/; classtype:trojan-activity;sid:84796483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933380)"; flow:established,from_client; content:"GET"; http_method; content:"/toonell/voicesecret/refs/heads/main/signory/voice_secret_v1.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933380/; classtype:trojan-activity;sid:84796480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933381)"; flow:established,from_client; content:"GET"; http_method; content:"/henry336627/sigil.nvim/refs/heads/main/lua/nvim-sigil-3.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933381/; classtype:trojan-activity;sid:84796481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933379)"; flow:established,from_client; content:"GET"; http_method; content:"/drakov09/mermaidjs-server/refs/heads/main/examples/mermaidjs-server-v2.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933379/; classtype:trojan-activity;sid:84796479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933375)"; flow:established,from_client; content:"GET"; http_method; content:"/sowar1987/claude-claude2api/head/router/api-claude-v1.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933375/; classtype:trojan-activity;sid:84796475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933376)"; flow:established,from_client; content:"GET"; http_method; content:"/harto1622/infinite-adventure-engine/main/components/adventure_infinite_engine_cusped.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933376/; classtype:trojan-activity;sid:84796476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933377)"; flow:established,from_client; content:"GET"; http_method; content:"/lesmiserable-s/etherpulse-conversation/refs/heads/main/.claude/etherpulse-conversation-v3.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933377/; classtype:trojan-activity;sid:84796477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933378)"; flow:established,from_client; content:"GET"; http_method; content:"/awpggexcutor-beep/t5-refiner-domainfocus/refs/heads/main/tonicostimulant/refiner-focus-domain-1.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933378/; classtype:trojan-activity;sid:84796478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933374)"; flow:established,from_client; content:"GET"; http_method; content:"/chicanetattoo974/simplereconurl/main/output/simple_url_recon_1.2-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933374/; classtype:trojan-activity;sid:84796474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933372)"; flow:established,from_client; content:"GET"; http_method; content:"/rlbf01/chomkeos/main/files/catppuccin/usr/share/kpackage/generic/catppuccin-macchiato-teal/contents/previews/chomkeos-stichometrically.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933372/; classtype:trojan-activity;sid:84796472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933373)"; flow:established,from_client; content:"GET"; http_method; content:"/jdahuhb823/rag_document_project/refs/heads/main/scripts/project_document_rag_1.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933373/; classtype:trojan-activity;sid:84796473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933371)"; flow:established,from_client; content:"GET"; http_method; content:"/sestore/hono-openapi-template/refs/heads/main/src/config/hono_openapi_template_2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933371/; classtype:trojan-activity;sid:84796471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933370)"; flow:established,from_client; content:"GET"; http_method; content:"/ocean1346/bigquery-expert/refs/heads/main/skills/bigquery-query-generation/references/expert_bigquery_v2.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933370/; classtype:trojan-activity;sid:84796470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933369)"; flow:established,from_client; content:"GET"; http_method; content:"/ironpawa/sklearn-diagnose/main/sklearn_diagnose/api/sklearn_diagnose_disgracer.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933369/; classtype:trojan-activity;sid:84796469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933367)"; flow:established,from_client; content:"GET"; http_method; content:"/eturner15/vibe-coding-playbook/head/advanced-prompts/coding_vibe_playbook_3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933367/; classtype:trojan-activity;sid:84796467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933368)"; flow:established,from_client; content:"GET"; http_method; content:"/wastagegermanivy655/ai-trafic-signal-optimization-/main/cinclidotus/ai-signal-optimization-trafic-2.6-beta.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933368/; classtype:trojan-activity;sid:84796468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933365)"; flow:established,from_client; content:"GET"; http_method; content:"/fernandojvmarques/uitest/main/styles/software_leucoid.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933365/; classtype:trojan-activity;sid:84796465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933366)"; flow:established,from_client; content:"GET"; http_method; content:"/k-13-xy/springbootkeycloak-auth-crud/head/src/main/java/sn/malcolm/demo/core/payload/request/keycloak_demo_springboot_auth_crud_v3.3.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933366/; classtype:trojan-activity;sid:84796466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933362)"; flow:established,from_client; content:"GET"; http_method; content:"/lnwmasters/ai-agent-guide/refs/heads/main/nonvariation/guide_a_agent_v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933362/; classtype:trojan-activity;sid:84796462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933363)"; flow:established,from_client; content:"GET"; http_method; content:"/mongosh2006/fastapi-easylimiter/head/fastapi_easylimiter/fastapi-easylimiter_1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933363/; classtype:trojan-activity;sid:84796463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933364)"; flow:established,from_client; content:"GET"; http_method; content:"/amulya-yadav/u-net-pytorch/refs/heads/main/u-net/py_torch_net_1.4-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933364/; classtype:trojan-activity;sid:84796464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933360)"; flow:established,from_client; content:"GET"; http_method; content:"/yolante2346/slide-nextup/refs/heads/main/themes/technical-brief/layouts/comparison/nextup-slide-3.4-beta.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933360/; classtype:trojan-activity;sid:84796460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933361)"; flow:established,from_client; content:"GET"; http_method; content:"/ssdcte/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933361/; classtype:trojan-activity;sid:84796461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933357)"; flow:established,from_client; content:"GET"; http_method; content:"/darnay/memorable-ai/head/docs/memorable-ai_1.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933357/; classtype:trojan-activity;sid:84796457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933358)"; flow:established,from_client; content:"GET"; http_method; content:"/rych156/peanalyzer/refs/heads/main/properties/pe_analyzer_v2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933358/; classtype:trojan-activity;sid:84796458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933359)"; flow:established,from_client; content:"GET"; http_method; content:"/bachchar7/freeflix/refs/heads/main/freeflixtvos/freeflix/freeflix/extensions/software-v1.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933359/; classtype:trojan-activity;sid:84796459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933354)"; flow:established,from_client; content:"GET"; http_method; content:"/edmondflying869/gd32f30x-cmake-vscode/refs/heads/main/spookish/cmake_vscode_x_gd_f_v2.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933354/; classtype:trojan-activity;sid:84796454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933355)"; flow:established,from_client; content:"GET"; http_method; content:"/mhadevphad/neural-network-classification-casting-defect-detection/refs/heads/main/hydroaeric/network_casting_defect_detection_neural_classification_baa.zip"; http_uri; depth:156; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933355/; classtype:trojan-activity;sid:84796455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933356)"; flow:established,from_client; content:"GET"; http_method; content:"/amish-pratap-singh/sudokusolver/refs/heads/main/examples/solver_sudoku_1.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933356/; classtype:trojan-activity;sid:84796456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933353)"; flow:established,from_client; content:"GET"; http_method; content:"/harriettundisputed335/sncode/refs/heads/main/src/renderer/software_v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933353/; classtype:trojan-activity;sid:84796453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933352)"; flow:established,from_client; content:"GET"; http_method; content:"/menotachillguy/valheimplus/refs/heads/main/animalhood/plus_valheim_v2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933352/; classtype:trojan-activity;sid:84796452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933349)"; flow:established,from_client; content:"GET"; http_method; content:"/gentry-king/agent-infrastructure-stack/refs/heads/main/packages/shared/src/utils/stack_agent_infrastructure_2.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933349/; classtype:trojan-activity;sid:84796449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933350)"; flow:established,from_client; content:"GET"; http_method; content:"/ryad23r/vhdl-p5v/head/albuminosis/vhdl-p5v.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933350/; classtype:trojan-activity;sid:84796450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933351)"; flow:established,from_client; content:"GET"; http_method; content:"/unpublishable-durability133/feishu-cursor-bridge/refs/heads/main/scripts/bridge_cursor_feishu_v3.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933351/; classtype:trojan-activity;sid:84796451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933347)"; flow:established,from_client; content:"GET"; http_method; content:"/yaroxs/ritual-bash-script/main/bonaventure/ritual-bash-script.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933347/; classtype:trojan-activity;sid:84796447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933348)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasgarrote/claude-cowork-guide/head/quadrilingual/guide-claude-cowork-v1.2-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933348/; classtype:trojan-activity;sid:84796448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933345)"; flow:established,from_client; content:"GET"; http_method; content:"/323322344/fintrust_cobol/master/programs/fintrust_cobol_2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933345/; classtype:trojan-activity;sid:84796445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933346)"; flow:established,from_client; content:"GET"; http_method; content:"/professional-gasgun20/local-ai-private-2026/refs/heads/main/arsono/local-private-ai-3.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933346/; classtype:trojan-activity;sid:84796446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933340)"; flow:established,from_client; content:"GET"; http_method; content:"/devneme/ai-dev-kit/refs/heads/master/src/public/css/dev-kit-ai-v2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933340/; classtype:trojan-activity;sid:84796440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933341)"; flow:established,from_client; content:"GET"; http_method; content:"/lingga1997/full-stack-proxy-nginx-n8n-for-everyone-with-docker-compose/main/proxy/templates/proxy-for-nginx-compose-stack-everyone-n-with-full-docker-odophone.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933341/; classtype:trojan-activity;sid:84796441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933342)"; flow:established,from_client; content:"GET"; http_method; content:"/fares914/zennal-dsa/head/src/ds/zennal-dsa-v1.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933342/; classtype:trojan-activity;sid:84796442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933343)"; flow:established,from_client; content:"GET"; http_method; content:"/huhuhugezixy/fintracker/refs/heads/main/src/firebase/software-v1.7-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933343/; classtype:trojan-activity;sid:84796443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933344)"; flow:established,from_client; content:"GET"; http_method; content:"/bazinga640/evm-chains-mcp-server/refs/heads/main/tests/automated/integration/evm_mcp_chains_server_3.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933344/; classtype:trojan-activity;sid:84796444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933339)"; flow:established,from_client; content:"GET"; http_method; content:"/iuliaivanapatras/claude-code-templates/main/claude-flutter/templates_claude_code_hermetic.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933339/; classtype:trojan-activity;sid:84796439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933338)"; flow:established,from_client; content:"GET"; http_method; content:"/bielxzimxztremm/offbywon/refs/heads/main/xurel/by-won-off-v3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933338/; classtype:trojan-activity;sid:84796438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933337)"; flow:established,from_client; content:"GET"; http_method; content:"/bozad/tweetsave-mcp/head/src/utils/tweetsave-mcp-3.7-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933337/; classtype:trojan-activity;sid:84796437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933335)"; flow:established,from_client; content:"GET"; http_method; content:"/involvex/serverlessdns/head/src/build/serverless-dns-v3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933335/; classtype:trojan-activity;sid:84796435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933336)"; flow:established,from_client; content:"GET"; http_method; content:"/kriswd/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933336/; classtype:trojan-activity;sid:84796436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933334)"; flow:established,from_client; content:"GET"; http_method; content:"/nijamudin/automated-business-analysis-workflow/refs/heads/main/laloneurosis/automated_business_workflow_analysis_1.4.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933334/; classtype:trojan-activity;sid:84796434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933332)"; flow:established,from_client; content:"GET"; http_method; content:"/sajin46/packwizard/refs/heads/main/vacuous/wizard-pack-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933332/; classtype:trojan-activity;sid:84796432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933333)"; flow:established,from_client; content:"GET"; http_method; content:"/dafnamannish442/knowledge-inbox/refs/heads/main/clients/hermes/inbox-knowledge-v3.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933333/; classtype:trojan-activity;sid:84796433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933331)"; flow:established,from_client; content:"GET"; http_method; content:"/rotary6200/doujindesu-apk/main/salveline/doujindesu-apk-khlysti.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933331/; classtype:trojan-activity;sid:84796431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933329)"; flow:established,from_client; content:"GET"; http_method; content:"/fitriadijamil/schullegerhard/head/hispid/schullegerhard-cochleate.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933329/; classtype:trojan-activity;sid:84796429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933330)"; flow:established,from_client; content:"GET"; http_method; content:"/prajwaltamang1213-wq/tcr-terrariachatrelay/refs/heads/main/paleotechnic/chat_terraria_tc_relay_v3.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933330/; classtype:trojan-activity;sid:84796430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933326)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556333124760248501/1556348983268474920/amethystclientcracked.jar|3f|backend=b2|7c|26|7c|ex=6ac527f1|7c|26|7c|is=6ac3d671|7c|26|7c|hm=6c6b13d89c937d71a6cb0d614448392a603eedafccba0dbf3ceec158f1c02d69|7c|26|7c|"; http_uri; depth:221; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933326/; classtype:trojan-activity;sid:84796426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933327)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed286332/constants-float16-log10-e/head/examples/float_e_constants_log_2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933327/; classtype:trojan-activity;sid:84796427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933328)"; flow:established,from_client; content:"GET"; http_method; content:"/totoy1274/expo-book/head/.yarn/releases/expo-book_v1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933328/; classtype:trojan-activity;sid:84796428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933324)"; flow:established,from_client; content:"GET"; http_method; content:"/cristobal-vizcaino/moltbrain-virtuals/refs/heads/main/src/virtuals-moltbrain-docetistic.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933324/; classtype:trojan-activity;sid:84796424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933325)"; flow:established,from_client; content:"GET"; http_method; content:"/curso7710/stratusiq/refs/heads/main/fixes/iq_stratus_1.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933325/; classtype:trojan-activity;sid:84796425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933323)"; flow:established,from_client; content:"GET"; http_method; content:"/vipnecon139-afk/dall-e-free-unlimited/main/aposaturn/unlimited-dall-free-v1.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933323/; classtype:trojan-activity;sid:84796423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933320)"; flow:established,from_client; content:"GET"; http_method; content:"/juanso123/local-llm-pdf-ocr/refs/heads/main/scripts/pdf_llm_local_ocr_nutation.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933320/; classtype:trojan-activity;sid:84796420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933321)"; flow:established,from_client; content:"GET"; http_method; content:"/ebroky/nsfw/head/app/model/nsfw-v2.4-beta.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933321/; classtype:trojan-activity;sid:84796421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933322)"; flow:established,from_client; content:"GET"; http_method; content:"/yahia-malek/minecraft-mod/refs/heads/main/anguineal/mod_minecraft_beemaster.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933322/; classtype:trojan-activity;sid:84796422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933317)"; flow:established,from_client; content:"GET"; http_method; content:"/melikebatur52/deepseek-desktop---deepseek-ai-assistant-2026/main/orthospermous/a_assistant_deep_seek_desktop_denaturalize.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933317/; classtype:trojan-activity;sid:84796417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933318)"; flow:established,from_client; content:"GET"; http_method; content:"/aybach/httpz/main/bench/software_discriminate.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933318/; classtype:trojan-activity;sid:84796418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933319)"; flow:established,from_client; content:"GET"; http_method; content:"/tauheedsavage/unifiedteam/refs/heads/main/src/components/auth/software-1.3-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933319/; classtype:trojan-activity;sid:84796419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933314)"; flow:established,from_client; content:"GET"; http_method; content:"/gametrax/windowstipsandtricks/latest/assurge/tricks_windows_tips_and_3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933314/; classtype:trojan-activity;sid:84796414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933315)"; flow:established,from_client; content:"GET"; http_method; content:"/arsyad001001/stoat-selfhost/refs/heads/main/ansible-example-role/templates/stoat_selfhost_v3.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933315/; classtype:trojan-activity;sid:84796415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933316)"; flow:established,from_client; content:"GET"; http_method; content:"/aayushshah61/workshop/refs/heads/main/reinclusion/software-v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933316/; classtype:trojan-activity;sid:84796416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933313)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/spaceship-mcp/head/src/tools/mcp-spaceship-2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933313/; classtype:trojan-activity;sid:84796413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933309)"; flow:established,from_client; content:"GET"; http_method; content:"/nancyunimproved357/tools-and-resources/refs/heads/main/src/data/and_resources_tools_1.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933309/; classtype:trojan-activity;sid:84796409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933310)"; flow:established,from_client; content:"GET"; http_method; content:"/tsikyrak/needily/main/promptitude/software-postlenticular.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933310/; classtype:trojan-activity;sid:84796410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933311)"; flow:established,from_client; content:"GET"; http_method; content:"/opboy1203/redmind/head/hematospermatocele/redmind.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933311/; classtype:trojan-activity;sid:84796411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933312)"; flow:established,from_client; content:"GET"; http_method; content:"/outfitted-genusstenopterygius236/wordlookup/refs/heads/main/assets/screenshots/word-lookup-1.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933312/; classtype:trojan-activity;sid:84796412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933307)"; flow:established,from_client; content:"GET"; http_method; content:"/magnaantigenic420/lovelace-floating-battery-card/main/dist/card_battery_lovelace_floating_v1.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933307/; classtype:trojan-activity;sid:84796407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933308)"; flow:established,from_client; content:"GET"; http_method; content:"/devicesheatofsolidification11/spoken-dialogue-model-survey/refs/heads/main/assets/survey-dialogue-model-spoken-v2.5-alpha.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933308/; classtype:trojan-activity;sid:84796408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933305)"; flow:established,from_client; content:"GET"; http_method; content:"/randysuarez/seobility-seo-checker-unlimited/refs/heads/main/mormyridae/checker-unlimited-seobility-seo-v1.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933305/; classtype:trojan-activity;sid:84796405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933306)"; flow:established,from_client; content:"GET"; http_method; content:"/rattled-juniorlightweight805/ai-detector-from-scratch/refs/heads/main/scripts/18_reinforcement-learning/3.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933306/; classtype:trojan-activity;sid:84796406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933301)"; flow:established,from_client; content:"GET"; http_method; content:"/caoquocbinh081103/lifekline/refs/heads/main/services/software-v2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933301/; classtype:trojan-activity;sid:84796401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933302)"; flow:established,from_client; content:"GET"; http_method; content:"/abdomando112/medicated-emacs/master/cymulose/medicated-emacs-1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933302/; classtype:trojan-activity;sid:84796402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933303)"; flow:established,from_client; content:"GET"; http_method; content:"/zmnima/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933303/; classtype:trojan-activity;sid:84796403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933304)"; flow:established,from_client; content:"GET"; http_method; content:"/jeyjey123456/revidgen/refs/heads/main/pkgs/grounded-sam-2/grounding_dino/groundingdino/models/vidgen-re-1.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933304/; classtype:trojan-activity;sid:84796404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933298)"; flow:established,from_client; content:"GET"; http_method; content:"/oddson-probioticmicroflora317/kimi-k3-in-rust/main/swattle/kimi-rust-k-in-hedgy.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933298/; classtype:trojan-activity;sid:84796398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933299)"; flow:established,from_client; content:"GET"; http_method; content:"/theend14147/xcode-xcstrings-csv-tool/refs/heads/main/rumblegarie/tool-xcstrings-csv-xcode-2.1-beta.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933299/; classtype:trojan-activity;sid:84796399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933300)"; flow:established,from_client; content:"GET"; http_method; content:"/lilvexst1/jit/refs/heads/main/vinaigretted/software_v3.6-beta.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933300/; classtype:trojan-activity;sid:84796400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933297)"; flow:established,from_client; content:"GET"; http_method; content:"/mwebesanorman/open-autogemini/refs/heads/main/phone_agent/xctest/open_auto_gemini_1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933297/; classtype:trojan-activity;sid:84796397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933294)"; flow:established,from_client; content:"GET"; http_method; content:"/implicated-collectable725/pd-netprox/main/heterognathi/pd_netprox_shavee.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933294/; classtype:trojan-activity;sid:84796394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933295)"; flow:established,from_client; content:"GET"; http_method; content:"/jonasedwardsalkfirehose824/bobanimelist/head/src/styles/tokens/bobanimelist-v3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933295/; classtype:trojan-activity;sid:84796395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933296)"; flow:established,from_client; content:"GET"; http_method; content:"/convectioniproclozide569/bastionroute/refs/heads/main/cmd/bastionroute-relay/route-bastion-2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933296/; classtype:trojan-activity;sid:84796396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933293)"; flow:established,from_client; content:"GET"; http_method; content:"/drmi5446/dsh-wallpaper-engine/main/lib/types/dsh-engine-wallpaper-1.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933293/; classtype:trojan-activity;sid:84796393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933290)"; flow:established,from_client; content:"GET"; http_method; content:"/noelwj/sentry-operator/refs/heads/main/api/sentry_operator_3.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933290/; classtype:trojan-activity;sid:84796390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933291)"; flow:established,from_client; content:"GET"; http_method; content:"/indra25oktober/a2ui-borg-1-2026-/refs/heads/main/unsacerdotal/u-borg-3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933291/; classtype:trojan-activity;sid:84796391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933292)"; flow:established,from_client; content:"GET"; http_method; content:"/swagg4/imagine-cup-microsoft-2026/refs/heads/main/android/app/src/main/imagin_cu_microsof_v2.8-beta.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933292/; classtype:trojan-activity;sid:84796392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933289)"; flow:established,from_client; content:"GET"; http_method; content:"/lisaura29/gpt-5-4-pro-3d-generations/refs/heads/main/prompts/gpt-pro-generations-d-2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933289/; classtype:trojan-activity;sid:84796389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933285)"; flow:established,from_client; content:"GET"; http_method; content:"/sathikasethumjith/cyrus/refs/heads/main/luggie/software-octaval.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933285/; classtype:trojan-activity;sid:84796385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933286)"; flow:established,from_client; content:"GET"; http_method; content:"/keroro"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"2.26.124.177"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933286/; classtype:trojan-activity;sid:84796386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933287)"; flow:established,from_client; content:"GET"; http_method; content:"/ottoman-reticule726/zara-ai-laptop-agent/main/agent/tools/1.2-alpha.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933287/; classtype:trojan-activity;sid:84796387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933288)"; flow:established,from_client; content:"GET"; http_method; content:"/lex3838/copilot-ironlegion-multiagent-case-study/refs/heads/main/demos/legion-pilot-iron-study-agent-case-co-multi-v2.6.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933288/; classtype:trojan-activity;sid:84796388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933282)"; flow:established,from_client; content:"GET"; http_method; content:"/mohi331/three-vfx/refs/heads/main/examples/threlte/public/three-vfx-v2.0-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933282/; classtype:trojan-activity;sid:84796382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933283)"; flow:established,from_client; content:"GET"; http_method; content:"/jkupir3/kaspersky-tools/main/dabby/kaspersky_tools_v3.5-beta.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933283/; classtype:trojan-activity;sid:84796383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933284)"; flow:established,from_client; content:"GET"; http_method; content:"/mark101221/aws-lift-shift-migration/head/tailoress/aws-lift-shift-migration.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933284/; classtype:trojan-activity;sid:84796384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933280)"; flow:established,from_client; content:"GET"; http_method; content:"/hamudoficcial/cli-prompts/refs/heads/main/packages/cli_prompts_v3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933280/; classtype:trojan-activity;sid:84796380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933281)"; flow:established,from_client; content:"GET"; http_method; content:"/xtremtg/bash-bar/main/superceremonious/bash-bar.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933281/; classtype:trojan-activity;sid:84796381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933278)"; flow:established,from_client; content:"GET"; http_method; content:"/theonewhoalwayswatches/pincer/refs/heads/main/src/app/api/software_1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933278/; classtype:trojan-activity;sid:84796378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933279)"; flow:established,from_client; content:"GET"; http_method; content:"/yeswanthchelluboina/gby-llk2025/main/weighhouse/gby-llk2025.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933279/; classtype:trojan-activity;sid:84796379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933274)"; flow:established,from_client; content:"GET"; http_method; content:"/erikceballos/nano-banana-cli/head/internal/config/banana_cli_nano_1.1-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933274/; classtype:trojan-activity;sid:84796374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933275)"; flow:established,from_client; content:"GET"; http_method; content:"/andres070415/advanced-systemcare-tools/refs/heads/main/dehumidifier/tools-advanced-systemcare-nonalcoholic.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933275/; classtype:trojan-activity;sid:84796375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933276)"; flow:established,from_client; content:"GET"; http_method; content:"/idle-middlelowgerman509/trx/refs/heads/main/packages/cli/src/software_v1.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933276/; classtype:trojan-activity;sid:84796376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933277)"; flow:established,from_client; content:"GET"; http_method; content:"/hieugia31/roastai-frontend/refs/heads/main/public/a_frontend_roast_v1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933277/; classtype:trojan-activity;sid:84796377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933272)"; flow:established,from_client; content:"GET"; http_method; content:"/subscribed-marcher792/dokbot/refs/heads/main/kreplech/software-v2.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933272/; classtype:trojan-activity;sid:84796372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933273)"; flow:established,from_client; content:"GET"; http_method; content:"/ayan-saxena/age-of-empires-4-cheats-strategy-lab/refs/heads/main/ceibo/empires-strategy-lab-age-cheats-of-v3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933273/; classtype:trojan-activity;sid:84796373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933271)"; flow:established,from_client; content:"GET"; http_method; content:"/ryl3/lead-scoring-gcp/refs/heads/master/src/models/lead_gcp_scoring_1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933271/; classtype:trojan-activity;sid:84796371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933269)"; flow:established,from_client; content:"GET"; http_method; content:"/asad95867/skills-from-expertise/refs/heads/main/skills/skills-from-expertise-ru/references/from-expertise-skills-2.7.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933269/; classtype:trojan-activity;sid:84796369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933270)"; flow:established,from_client; content:"GET"; http_method; content:"/mighty-technophobia970/obsidian-dashboard/refs/heads/main/starter/dashboard_obsidian_v2.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933270/; classtype:trojan-activity;sid:84796370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933267)"; flow:established,from_client; content:"GET"; http_method; content:"/yadavji0123/ghfs/refs/heads/main/playgrounds/software-1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933267/; classtype:trojan-activity;sid:84796367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933268)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgechocolate/global-lvba/refs/heads/master/pics/lvba_global_v3.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933268/; classtype:trojan-activity;sid:84796368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933264)"; flow:established,from_client; content:"GET"; http_method; content:"/jonaskouame/phone-number-tracker/refs/heads/main/overtare/phone_tracker_number_1.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933264/; classtype:trojan-activity;sid:84796364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933265)"; flow:established,from_client; content:"GET"; http_method; content:"/echo682/codeforge-ui/main/stramineous/codeforge-ui.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933265/; classtype:trojan-activity;sid:84796365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933266)"; flow:established,from_client; content:"GET"; http_method; content:"/aliraj59/orientdb-rw4/head/cass/orientdb-rw4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933266/; classtype:trojan-activity;sid:84796366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933260)"; flow:established,from_client; content:"GET"; http_method; content:"/fwhds/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933260/; classtype:trojan-activity;sid:84796360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933261)"; flow:established,from_client; content:"GET"; http_method; content:"/asmaiqbal12/my-monitor/refs/heads/main/inflammation/monitor-my-v3.1-alpha.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933261/; classtype:trojan-activity;sid:84796361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933262)"; flow:established,from_client; content:"GET"; http_method; content:"/ilovedodster1/bnb-trading-bot/head/src/lib/bnb_trading_bot_2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933262/; classtype:trojan-activity;sid:84796362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933263)"; flow:established,from_client; content:"GET"; http_method; content:"/fabianaguirre10/jwt-module/refs/heads/master/jwt/api/module_jw_v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933263/; classtype:trojan-activity;sid:84796363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933258)"; flow:established,from_client; content:"GET"; http_method; content:"/kiwi1547/hypersql-mzx/main/rhizophore/hypersql-mzx.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933258/; classtype:trojan-activity;sid:84796358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933259)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzaideators/cinerag/refs/heads/main/reports/software-3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933259/; classtype:trojan-activity;sid:84796359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933257)"; flow:established,from_client; content:"GET"; http_method; content:"/rinrinya/edgenuity-hacks/refs/heads/main/trilling/hacks-edgenuity-v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933257/; classtype:trojan-activity;sid:84796357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933255)"; flow:established,from_client; content:"GET"; http_method; content:"/dodoaaaa/darq/refs/heads/main/app/src/main/resources/meta-inf/xposed/dar-q-v2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933255/; classtype:trojan-activity;sid:84796355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933256)"; flow:established,from_client; content:"GET"; http_method; content:"/dishonorpeachpit230/fijahu-5/head/quiz/fijahu-5_v3.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933256/; classtype:trojan-activity;sid:84796356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933253)"; flow:established,from_client; content:"GET"; http_method; content:"/dragos091317/symbolic-bubble-cosmology/refs/heads/main/rhinestone/cosmology_symbolic_bubble_2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933253/; classtype:trojan-activity;sid:84796353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933254)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshumaheta36/smart-city-platform/head/orchestration-service/target/classes/com/smart-city-platform_v1.6-beta.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933254/; classtype:trojan-activity;sid:84796354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933252)"; flow:established,from_client; content:"GET"; http_method; content:"/nndesigngrafico/voltdb-fv7/main/rhynchophora/voltdb-fv7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933252/; classtype:trojan-activity;sid:84796352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933250)"; flow:established,from_client; content:"GET"; http_method; content:"/xaac10/vritraai/refs/heads/main/killick/ai-vritra-3.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933250/; classtype:trojan-activity;sid:84796350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933251)"; flow:established,from_client; content:"GET"; http_method; content:"/pjfossi324-tech/climafy/refs/heads/main/physicianary/software-chipling.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933251/; classtype:trojan-activity;sid:84796351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933248)"; flow:established,from_client; content:"GET"; http_method; content:"/deskbound-accelerationunit151/qingming-z-image-turbo/main/devices/780m/3.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933248/; classtype:trojan-activity;sid:84796348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933249)"; flow:established,from_client; content:"GET"; http_method; content:"/zemcius/hogwarts-legacy-macos/main/images/legacy_os_mac_hogwarts_deresinate.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933249/; classtype:trojan-activity;sid:84796349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933244)"; flow:established,from_client; content:"GET"; http_method; content:"/bintang3703/fraud-detection-credit-mlops/refs/heads/main/data/detection_credit_fraud_mlops_1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933244/; classtype:trojan-activity;sid:84796344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933245)"; flow:established,from_client; content:"GET"; http_method; content:"/capricevirological936/agentic-workflow/main/agentbase/templates/modules/deploy/vercel/agents/agentic_workflow_dropling.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933245/; classtype:trojan-activity;sid:84796345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933246)"; flow:established,from_client; content:"GET"; http_method; content:"/dilnalopez/the-estrella-welcome-registry/main/lib/owlcarousel/assets/registry_th_estrell_welcom_consolidation.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933246/; classtype:trojan-activity;sid:84796346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933247)"; flow:established,from_client; content:"GET"; http_method; content:"/for-works/yvrdevfest2025/head/weather-server/yvrdevfest2025_v2.2-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933247/; classtype:trojan-activity;sid:84796347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933242)"; flow:established,from_client; content:"GET"; http_method; content:"/nnaopa/fluxdo/refs/heads/main/android/build/software-2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933242/; classtype:trojan-activity;sid:84796342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933243)"; flow:established,from_client; content:"GET"; http_method; content:"/mghourchian86-creator/equiformer_v3/refs/heads/main/palladodiammine/v_equiformer_2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933243/; classtype:trojan-activity;sid:84796343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933241)"; flow:established,from_client; content:"GET"; http_method; content:"/marianahu1342/qc-paper-kb/refs/heads/main/data/q-kb-paper-v3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933241/; classtype:trojan-activity;sid:84796341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933238)"; flow:established,from_client; content:"GET"; http_method; content:"/haseebgaming/antigravity-stock-analysis-workflow/refs/heads/main/.agent/analysis-antigravity-stock-workflow-v1.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933238/; classtype:trojan-activity;sid:84796338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933239)"; flow:established,from_client; content:"GET"; http_method; content:"/telepathic-intonationpattern7471/binance-dca-grid-trading-bot/main/elachista/binance_trading_grid_dc_bot_v3.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933239/; classtype:trojan-activity;sid:84796339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933240)"; flow:established,from_client; content:"GET"; http_method; content:"/arcila12/universal-web3-wallet/head/upstroke/universal-web3-wallet.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933240/; classtype:trojan-activity;sid:84796340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933236)"; flow:established,from_client; content:"GET"; http_method; content:"/dmvait8534/claude2api-deploy/head/huajillo/deploy_claude_api_v1.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933236/; classtype:trojan-activity;sid:84796336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933237)"; flow:established,from_client; content:"GET"; http_method; content:"/rlmourafotografia-glitch/pictures-trimmer/refs/heads/main/test/trimmer_pictures_2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933237/; classtype:trojan-activity;sid:84796337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933234)"; flow:established,from_client; content:"GET"; http_method; content:"/riyandiweb/typst-mdx-docs/head/scripts/parser/typst-docs-mdx-3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933234/; classtype:trojan-activity;sid:84796334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933235)"; flow:established,from_client; content:"GET"; http_method; content:"/guill2222/nveil-toolkit/refs/heads/main/src/nveil/skills/toolkit_nveil_v2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933235/; classtype:trojan-activity;sid:84796335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933231)"; flow:established,from_client; content:"GET"; http_method; content:"/krymzr/fetchmate/main/proturan/fetchmate.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933231/; classtype:trojan-activity;sid:84796331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933232)"; flow:established,from_client; content:"GET"; http_method; content:"/hishaamj007/kp-next-kit/main/src/trpc/next_kit_kp_parabolizer.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933232/; classtype:trojan-activity;sid:84796332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933233)"; flow:established,from_client; content:"GET"; http_method; content:"/elmonta22/internetspeedtest-py/head/protargentum/internetspeedtest-py.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933233/; classtype:trojan-activity;sid:84796333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933228)"; flow:established,from_client; content:"GET"; http_method; content:"/ajay-lab-prog/skillink-backend-upc/refs/heads/main/src/skillink-upc-backend-2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933228/; classtype:trojan-activity;sid:84796328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933229)"; flow:established,from_client; content:"GET"; http_method; content:"/kingqasim/portable-progress-bar/portable-progress-bar_main-dev/resnatron/portable-progress-bar.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933229/; classtype:trojan-activity;sid:84796329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933230)"; flow:established,from_client; content:"GET"; http_method; content:"/pipemajortenuity150/aso-skill/refs/heads/main/lib/aso_skill_1.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933230/; classtype:trojan-activity;sid:84796330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933226)"; flow:established,from_client; content:"GET"; http_method; content:"/yeayraww24/public-apis/master/scripts/validate/apis-public-2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933226/; classtype:trojan-activity;sid:84796326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933227)"; flow:established,from_client; content:"GET"; http_method; content:"/congregantmsec41/agentic-stack-desktop/main/tests/stack-agentic-desktop-v1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933227/; classtype:trojan-activity;sid:84796327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933224)"; flow:established,from_client; content:"GET"; http_method; content:"/dragon0003/awesome-x402/refs/heads/master/unfagged/awesome_x_1.8-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933224/; classtype:trojan-activity;sid:84796324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933225)"; flow:established,from_client; content:"GET"; http_method; content:"/trieuduy27051999/internet-banking/refs/heads/main/frontend/src/services/banking-internet-2.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933225/; classtype:trojan-activity;sid:84796325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933223)"; flow:established,from_client; content:"GET"; http_method; content:"/djordjeict/driver-scheduling-system/refs/heads/main/frontend-client/src/utils/system-driver-scheduling-2.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933223/; classtype:trojan-activity;sid:84796323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933221)"; flow:established,from_client; content:"GET"; http_method; content:"/holajokwer/amanansdiahnid-22/main/fleeceflower/amanansdiahnid-22.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933221/; classtype:trojan-activity;sid:84796321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933222)"; flow:established,from_client; content:"GET"; http_method; content:"/xenackhub/pragati_backend_2025/refs/heads/main/config/backend-pragati-1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933222/; classtype:trojan-activity;sid:84796322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933219)"; flow:established,from_client; content:"GET"; http_method; content:"/dadadad274/yandex-search-php/main/src/laravel/search_yandex_php_extracalendar.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933219/; classtype:trojan-activity;sid:84796319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933220)"; flow:established,from_client; content:"GET"; http_method; content:"/hari-vdh/scalable-udp-server-for-low-latency-data-transmission/refs/heads/main/ci/server-transmission-scalable-for-data-ud-low-latency-v2.7.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933220/; classtype:trojan-activity;sid:84796320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933217)"; flow:established,from_client; content:"GET"; http_method; content:"/unpolished-tagusriver58/uefn-toolbelt/refs/heads/main/.github/uef-toolbelt-1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933217/; classtype:trojan-activity;sid:84796317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933218)"; flow:established,from_client; content:"GET"; http_method; content:"/daniel06s6995/deepseek-harness-software-opc/main/presets/software-company/packages/company-r2/lib/software_deepseek_harness_opc_v2.5.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933218/; classtype:trojan-activity;sid:84796318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933212)"; flow:established,from_client; content:"GET"; http_method; content:"/aymankali1/reels_for_free/head/src/reels_for_free-2.8-alpha.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933212/; classtype:trojan-activity;sid:84796312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933213)"; flow:established,from_client; content:"GET"; http_method; content:"/franktekza/course-prism/refs/heads/main/frontend/jcourse-master/src/config/prism_course_v2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933213/; classtype:trojan-activity;sid:84796313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933214)"; flow:established,from_client; content:"GET"; http_method; content:"/danicyber1/agent-semantic-protocol/refs/heads/main/docs/decisions/agent_protocol_semantic_encomiastically.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933214/; classtype:trojan-activity;sid:84796314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933215)"; flow:established,from_client; content:"GET"; http_method; content:"/spreaderwangle568/threat-detection-/refs/heads/main/erysipeloid/detection_threat_v3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933215/; classtype:trojan-activity;sid:84796315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933216)"; flow:established,from_client; content:"GET"; http_method; content:"/kevsters59/linuxdo/master/.claude/software-3.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933216/; classtype:trojan-activity;sid:84796316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933211)"; flow:established,from_client; content:"GET"; http_method; content:"/tomasburkett/banana-sprite/refs/heads/main/src/utils/banana_sprite_v2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933211/; classtype:trojan-activity;sid:84796311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933208)"; flow:established,from_client; content:"GET"; http_method; content:"/harshanarodrigos/omarchy-on-cachyos/refs/heads/main/jacksaw/omarchy-on-cachyos-jeany.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933208/; classtype:trojan-activity;sid:84796308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933209)"; flow:established,from_client; content:"GET"; http_method; content:"/braenmendes/ssf/refs/heads/main/ssf/core/software-v3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933209/; classtype:trojan-activity;sid:84796309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933210)"; flow:established,from_client; content:"GET"; http_method; content:"/hezhenyang07135-maker/scrap-mechanic-menu/main/upfollow/menu-scrap-mechanic-v2.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933210/; classtype:trojan-activity;sid:84796310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933207)"; flow:established,from_client; content:"GET"; http_method; content:"/lucarain/ecommerce-api/main/src/ecommerce.application/dtos/product/api-e-commerce-huchnom.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933207/; classtype:trojan-activity;sid:84796307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933205)"; flow:established,from_client; content:"GET"; http_method; content:"/failing-coachman563/dsh-skill-viewer/main/src/skill_viewer_dsh_vitreouslike.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933205/; classtype:trojan-activity;sid:84796305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933206)"; flow:established,from_client; content:"GET"; http_method; content:"/seo00711/aiuseroai-claude/main/gpt5assistant/aiuser_oa_claude_brownweed.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933206/; classtype:trojan-activity;sid:84796306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933203)"; flow:established,from_client; content:"GET"; http_method; content:"/almalikiyousif410/ghostfolio-desktop-self-hosted-dashboard/main/gypsywort/v1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933203/; classtype:trojan-activity;sid:84796303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933204)"; flow:established,from_client; content:"GET"; http_method; content:"/noangel988/authlab/refs/heads/main/tests/lab_auth_3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933204/; classtype:trojan-activity;sid:84796304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933202)"; flow:established,from_client; content:"GET"; http_method; content:"/pruheroic16/nightlight-game-launcher/refs/heads/main/sources/nightlight_launcher_game_3.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933202/; classtype:trojan-activity;sid:84796302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933201)"; flow:established,from_client; content:"GET"; http_method; content:"/pattymaterial5053/abot-recon/refs/heads/main/steeplelike/bot_a_recon_2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933201/; classtype:trojan-activity;sid:84796301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933198)"; flow:established,from_client; content:"GET"; http_method; content:"/nicollas76143/powersub-demo-4146/head/wamara/powersub-demo-4146.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933198/; classtype:trojan-activity;sid:84796298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933199)"; flow:established,from_client; content:"GET"; http_method; content:"/sammycxu/whyis/refs/heads/main/collectors/software_conversationalist.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933199/; classtype:trojan-activity;sid:84796299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933200)"; flow:established,from_client; content:"GET"; http_method; content:"/dorisaimpatient855/awesome-dsh-plugin/main/kleptomanist/dsh_awesome_plugin_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933200/; classtype:trojan-activity;sid:84796300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933197)"; flow:established,from_client; content:"GET"; http_method; content:"/altalack-bot/camera-to-blender/refs/heads/main/blender_addon/v3.7-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933197/; classtype:trojan-activity;sid:84796297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933194)"; flow:established,from_client; content:"GET"; http_method; content:"/seamed-boardroom443/jump-steal-script-hub-2026/main/coevally/steal-script-jump-hub-v3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933194/; classtype:trojan-activity;sid:84796294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933195)"; flow:established,from_client; content:"GET"; http_method; content:"/robinlebon/tangnano9k-centipede/refs/heads/main/tangnano9k-centipede/src/gowin_rpll/nano-tang-centipede-v2.8.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933195/; classtype:trojan-activity;sid:84796295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933196)"; flow:established,from_client; content:"GET"; http_method; content:"/boscocerdeira/omegawiki/refs/heads/main/floodlike/omega_wiki_v1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933196/; classtype:trojan-activity;sid:84796296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933192)"; flow:established,from_client; content:"GET"; http_method; content:"/iflow-mcp/saadkhan1150-telegram-mcp/head/static/telegram-mcp-v1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933192/; classtype:trojan-activity;sid:84796292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933193)"; flow:established,from_client; content:"GET"; http_method; content:"/rohit8307717239-droid/onimusha-way-of-the-sword-helper/main/assets/way-the-helper-sword-of-onimusha-3.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933193/; classtype:trojan-activity;sid:84796293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933190)"; flow:established,from_client; content:"GET"; http_method; content:"/demonstrationnerves409/html-animation/main/doglike/html_animation_3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933190/; classtype:trojan-activity;sid:84796290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933191)"; flow:established,from_client; content:"GET"; http_method; content:"/tanhla-toto/neo4j-cdk/head/radioautography/neo4j-cdk.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933191/; classtype:trojan-activity;sid:84796291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933188)"; flow:established,from_client; content:"GET"; http_method; content:"/mamon9022/poc-fls-node-epicronicles/develop/src/store/thunks/session/epicronicles_node_poc_fls_v2.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933188/; classtype:trojan-activity;sid:84796288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933189)"; flow:established,from_client; content:"GET"; http_method; content:"/stuck-lepiotaceae126/katmer-code/refs/heads/main/src/skills/katmer-code-2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933189/; classtype:trojan-activity;sid:84796289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933186)"; flow:established,from_client; content:"GET"; http_method; content:"/sober-ferrocyanide9941/clipdrop-desktop---clipdrop-ai-tools-2026/refs/heads/main/jimjam/desktop-clip-tools-drop-a-3.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933186/; classtype:trojan-activity;sid:84796286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933187)"; flow:established,from_client; content:"GET"; http_method; content:"/edgarkakanyan/ultra-mem/refs/heads/main/ultra_mem/ultra-mem-heady.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933187/; classtype:trojan-activity;sid:84796287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933183)"; flow:established,from_client; content:"GET"; http_method; content:"/recent-pursuer670/skybook-airline-reservation/main/backend/src/models/reservation-airline-skybook-3.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933183/; classtype:trojan-activity;sid:84796283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933184)"; flow:established,from_client; content:"GET"; http_method; content:"/battleunicorn69/gitswitch/main/src/software-3.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933184/; classtype:trojan-activity;sid:84796284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933185)"; flow:established,from_client; content:"GET"; http_method; content:"/chikochulu/nova-glassmorphism-nextjs-template/head/src/components/template-nova-nextjs-glassmorphism-v1.6.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933185/; classtype:trojan-activity;sid:84796285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933182)"; flow:established,from_client; content:"GET"; http_method; content:"/cleitin1638/ripple-tenoxui-test/main/garse/ripple-tenoxui-test.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933182/; classtype:trojan-activity;sid:84796282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933179)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelhadi2005/equityautoresearch/refs/heads/main/skills/initial-max/software_v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933179/; classtype:trojan-activity;sid:84796279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933180)"; flow:established,from_client; content:"GET"; http_method; content:"/shripadk1999/evokore-mcp/refs/heads/main/polymerize/mcp_evokor_3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933180/; classtype:trojan-activity;sid:84796280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933181)"; flow:established,from_client; content:"GET"; http_method; content:"/mat9ichbladi/krema/master/krema-docs/docs-site/src/theme/software-2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933181/; classtype:trojan-activity;sid:84796281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933178)"; flow:established,from_client; content:"GET"; http_method; content:"/untested-fieldmustard5084/batch-file-renamer/main/mastalgia/2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933178/; classtype:trojan-activity;sid:84796278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933174)"; flow:established,from_client; content:"GET"; http_method; content:"/portalgay/media2text/refs/heads/main/frontend/src/components/modals/text-media-3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933174/; classtype:trojan-activity;sid:84796274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933175)"; flow:established,from_client; content:"GET"; http_method; content:"/murtazatouqeer/f5-framework-claude/refs/heads/main/plugins/f5-stacks/domains/fintech/sub-domains/stock-trading/variants/f-framework-claude-3.6.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933175/; classtype:trojan-activity;sid:84796275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933176)"; flow:established,from_client; content:"GET"; http_method; content:"/dape8318/veoscript-prompt-generator/refs/heads/main/services/generator_prompt_veoscript_v2.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933176/; classtype:trojan-activity;sid:84796276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933177)"; flow:established,from_client; content:"GET"; http_method; content:"/genusalsophilaeccehomo626/honey-ai/main/scripts/ai_honey_3.4-beta.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933177/; classtype:trojan-activity;sid:84796277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933172)"; flow:established,from_client; content:"GET"; http_method; content:"/iansalon23/zzycaptcha/refs/heads/main/subroot/captcha_zzy_2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933172/; classtype:trojan-activity;sid:84796272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933173)"; flow:established,from_client; content:"GET"; http_method; content:"/gracephotovoltaic124/vlnr/refs/heads/main/misogynous/software-3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933173/; classtype:trojan-activity;sid:84796273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933167)"; flow:established,from_client; content:"GET"; http_method; content:"/singni725/eurousd-ema-cross-mql5-ea/refs/heads/main/pu/em-ea-mq-cross-eurous-v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933167/; classtype:trojan-activity;sid:84796267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933168)"; flow:established,from_client; content:"GET"; http_method; content:"/hitchy22/xwiki-exploit/refs/heads/main/staghorn/exploit_xwiki_3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933168/; classtype:trojan-activity;sid:84796268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933169)"; flow:established,from_client; content:"GET"; http_method; content:"/rumyasha/coin-indexing-app-backend/refs/heads/main/src/routes/trackerroute/coin_backend_indexing_app_v1.0.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933169/; classtype:trojan-activity;sid:84796269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933170)"; flow:established,from_client; content:"GET"; http_method; content:"/hoshigaki0308/codex-minecraft-gameplay/main/agents/skills/gameplay_minecraft_codex_1.4-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933170/; classtype:trojan-activity;sid:84796270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933171)"; flow:established,from_client; content:"GET"; http_method; content:"/abdo3063/winmice/main/sources/winmice/settings/panes/mice_win_3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933171/; classtype:trojan-activity;sid:84796271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933165)"; flow:established,from_client; content:"GET"; http_method; content:"/hermmolly105/awesome-phd-cv/refs/heads/main/deedy-format/fonts/raleway/cv-awesome-ph-v1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933165/; classtype:trojan-activity;sid:84796265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933166)"; flow:established,from_client; content:"GET"; http_method; content:"/reiolft/xsukax-github-logo-embed-code-generator/refs/heads/main/trustiness/embed_code_github_generator_xsukax_logo_v1.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933166/; classtype:trojan-activity;sid:84796266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933163)"; flow:established,from_client; content:"GET"; http_method; content:"/rowdy-ff/javid-mask/head/singleton/ansible/roles/singbox/templates/mask-javid-2.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933163/; classtype:trojan-activity;sid:84796263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933164)"; flow:established,from_client; content:"GET"; http_method; content:"/swapnil2805/vibe-app/head/convex/vibe_app_v2.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933164/; classtype:trojan-activity;sid:84796264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933161)"; flow:established,from_client; content:"GET"; http_method; content:"/sagev1/makepad-skills/refs/heads/main/skills/evolution/skills_makepad_v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933161/; classtype:trojan-activity;sid:84796261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933162)"; flow:established,from_client; content:"GET"; http_method; content:"/naritofficial/apollocrashfix/refs/heads/main/unshavenness/fix-crash-apollo-v3.7-alpha.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933162/; classtype:trojan-activity;sid:84796262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933158)"; flow:established,from_client; content:"GET"; http_method; content:"/anonimous071/mapcn/refs/heads/main/src/app/docs/popups/software_2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933158/; classtype:trojan-activity;sid:84796258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933159)"; flow:established,from_client; content:"GET"; http_method; content:"/yusuf4030/the-data-analyst-toolkit/head/unspoilable/the-data-analyst-toolkit.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933159/; classtype:trojan-activity;sid:84796259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933160)"; flow:established,from_client; content:"GET"; http_method; content:"/sushanth7-jpg/quiz-management-system/head/server/node_modules/pstree.remy/tests/quiz_management_system_3.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933160/; classtype:trojan-activity;sid:84796260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933156)"; flow:established,from_client; content:"GET"; http_method; content:"/britorbs/consciousdb/refs/heads/main/demo/software-3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933156/; classtype:trojan-activity;sid:84796256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933157)"; flow:established,from_client; content:"GET"; http_method; content:"/alimahmouddev/cf-status-dashboard/head/src/app/datacenters/status-cf-dashboard-v3.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933157/; classtype:trojan-activity;sid:84796257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933154)"; flow:established,from_client; content:"GET"; http_method; content:"/ringmembranouslabyrinth195/hyperchanger/refs/heads/main/app/src/main/res/mipmap-anydpi-v26/stey.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933154/; classtype:trojan-activity;sid:84796254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933155)"; flow:established,from_client; content:"GET"; http_method; content:"/kubalu7600/ai-background-remover-removebg-photoroom/main/lechea/background-removebg-remover-photoroom-ai-v2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933155/; classtype:trojan-activity;sid:84796255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933149)"; flow:established,from_client; content:"GET"; http_method; content:"/kishore8908/data-platform-quicksight/refs/heads/main/glue/quicksight-data-platform-2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933149/; classtype:trojan-activity;sid:84796249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933150)"; flow:established,from_client; content:"GET"; http_method; content:"/ajar71/zerotrust/refs/heads/main/zerotrust/software-2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933150/; classtype:trojan-activity;sid:84796250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933151)"; flow:established,from_client; content:"GET"; http_method; content:"/yassine-espada/guardianjs/refs/heads/main/src/utils/software_3.2-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933151/; classtype:trojan-activity;sid:84796251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933152)"; flow:established,from_client; content:"GET"; http_method; content:"/candradi8462/vulnhunter/refs/heads/main/molimen/vuln_hunter_v2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933152/; classtype:trojan-activity;sid:84796252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933153)"; flow:established,from_client; content:"GET"; http_method; content:"/rayandripo/nextjs_drizzle_better-auth/master/src/components/shared/drizzle-better-auth-nextjs-v2.2-beta.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933153/; classtype:trojan-activity;sid:84796253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933147)"; flow:established,from_client; content:"GET"; http_method; content:"/jsparana/e-commerce/main/ecommerceapp/target/classes/com/ecommerce/util/commerce_trimesitinic.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933147/; classtype:trojan-activity;sid:84796247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933148)"; flow:established,from_client; content:"GET"; http_method; content:"/gabriel22botezini/spring-microservices-blueprint/head/donary/spring-microservices-blueprint.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933148/; classtype:trojan-activity;sid:84796248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933144)"; flow:established,from_client; content:"GET"; http_method; content:"/familypectinidaecritic903/autopost/refs/heads/main/src/lib/payments/software-aetian.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933144/; classtype:trojan-activity;sid:84796244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933145)"; flow:established,from_client; content:"GET"; http_method; content:"/ada994/prism-bench/main/aerotonometer/prism-bench.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933145/; classtype:trojan-activity;sid:84796245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933146)"; flow:established,from_client; content:"GET"; http_method; content:"/lamagra1998/recipe-lab-sony-pmca/refs/heads/main/intradural/lab_sony_pmca_recipe_1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933146/; classtype:trojan-activity;sid:84796246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933140)"; flow:established,from_client; content:"GET"; http_method; content:"/ayman1111111/chines/refs/heads/master/lib/software-3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933140/; classtype:trojan-activity;sid:84796240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933141)"; flow:established,from_client; content:"GET"; http_method; content:"/edybatera/tradingview-selenium-fixed-time-trading-automation-bot/refs/heads/main/phyllozooid/fixed-trading-automation-tradingview-selenium-time-bot-granitoid.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933141/; classtype:trojan-activity;sid:84796241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933142)"; flow:established,from_client; content:"GET"; http_method; content:"/abusufiannn/claude-quickstarts/refs/heads/main/customer-support-agent/app/claude_quickstarts_2.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933142/; classtype:trojan-activity;sid:84796242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933143)"; flow:established,from_client; content:"GET"; http_method; content:"/antoniol7x/lunar-client-pro-version-for-minecraft/refs/heads/main/swungen/for_client_pro_version_lunar_minecraft_v3.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933143/; classtype:trojan-activity;sid:84796243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933139)"; flow:established,from_client; content:"GET"; http_method; content:"/l7n102031/go-agent-memory/refs/heads/main/scripts/agent_go_memory_2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933139/; classtype:trojan-activity;sid:84796239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933136)"; flow:established,from_client; content:"GET"; http_method; content:"/distortion24/boropheneos/main/overdesirousness/boropheneos.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933136/; classtype:trojan-activity;sid:84796236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933137)"; flow:established,from_client; content:"GET"; http_method; content:"/mitsuakitora/2bar/refs/heads/main/website/bar-1.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933137/; classtype:trojan-activity;sid:84796237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933138)"; flow:established,from_client; content:"GET"; http_method; content:"/pwele123/license-guardian/refs/heads/main/src/guardian-license-v3.0-beta.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933138/; classtype:trojan-activity;sid:84796238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933135)"; flow:established,from_client; content:"GET"; http_method; content:"/jxx12345678/wanderlust-project/refs/heads/main/public/css/project-wanderlus-v2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933135/; classtype:trojan-activity;sid:84796235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933134)"; flow:established,from_client; content:"GET"; http_method; content:"/yolanepeaty347/march-arena/refs/heads/main/components/arena-march-v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933134/; classtype:trojan-activity;sid:84796234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933133)"; flow:established,from_client; content:"GET"; http_method; content:"/player247/serverless-ai-cloud-optimizer/refs/heads/main/severless/optimizer-ai-serverless-cloud-v1.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933133/; classtype:trojan-activity;sid:84796233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933131)"; flow:established,from_client; content:"GET"; http_method; content:"/mianham9042/claude-orchestra/refs/heads/main/docs/orchestra-claude-3.2-alpha.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933131/; classtype:trojan-activity;sid:84796231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933132)"; flow:established,from_client; content:"GET"; http_method; content:"/matajihardware/studioalamal-backend/refs/heads/main/services/authservice/services/al-studio-backend-amal-v3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933132/; classtype:trojan-activity;sid:84796232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933128)"; flow:established,from_client; content:"GET"; http_method; content:"/keinersowiedu/unintelligence/refs/heads/main/sources/software_3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933128/; classtype:trojan-activity;sid:84796228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933129)"; flow:established,from_client; content:"GET"; http_method; content:"/ridasoulaim/whisper-youtube-summarizer-groq/refs/heads/main/hemibranch/whisper_summarizer_groq_youtube_unfernlike.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933129/; classtype:trojan-activity;sid:84796229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933130)"; flow:established,from_client; content:"GET"; http_method; content:"/gabinam/fise/refs/heads/main/docs/software_v2.8-beta.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933130/; classtype:trojan-activity;sid:84796230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933126)"; flow:established,from_client; content:"GET"; http_method; content:"/mentosenak/ndarray-shift/main/epiphyllum/ndarray-shift.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933126/; classtype:trojan-activity;sid:84796226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933127)"; flow:established,from_client; content:"GET"; http_method; content:"/sargonelizabeth/awesome-nano-banana-prompts/refs/heads/main/multivorous/banana_awesome_prompts_nano_locustberry.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933127/; classtype:trojan-activity;sid:84796227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933122)"; flow:established,from_client; content:"GET"; http_method; content:"/prakash9131/event-platform_app_next/refs/heads/main/components/ui/platform-event-app-next-v3.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933122/; classtype:trojan-activity;sid:84796222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933123)"; flow:established,from_client; content:"GET"; http_method; content:"/9963629854/kirmanjiku-9/main/tartufism/kirmanjiku-9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933123/; classtype:trojan-activity;sid:84796223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933124)"; flow:established,from_client; content:"GET"; http_method; content:"/bivalent-fnma945/number_puzzles_in_front_of_everyone/refs/heads/main/alphard/of_front_number_puzzles_in_everyone_v1.4.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933124/; classtype:trojan-activity;sid:84796224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933125)"; flow:established,from_client; content:"GET"; http_method; content:"/totttonob/3x-ui-new/refs/heads/main/node/cert/ui_new_x_centipoise.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933125/; classtype:trojan-activity;sid:84796225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933120)"; flow:established,from_client; content:"GET"; http_method; content:"/nebil175/lcu_dumper/main/giottesque/lcu_dumper.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933120/; classtype:trojan-activity;sid:84796220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933121)"; flow:established,from_client; content:"GET"; http_method; content:"/rustamis5958/speechalgo/refs/heads/main/speechalgo/utils/algo-speech-3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933121/; classtype:trojan-activity;sid:84796221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933116)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadibrahim386/deep-cuts/refs/heads/main/frontend/src/lib/deep_cuts_v1.9-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933116/; classtype:trojan-activity;sid:84796216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933117)"; flow:established,from_client; content:"GET"; http_method; content:"/obada159/fertigation-mix/refs/heads/main/tests/fertigation-mix-2.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933117/; classtype:trojan-activity;sid:84796217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933118)"; flow:established,from_client; content:"GET"; http_method; content:"/harroldpogi/d-t4m/main/sextilis/m-t-d-ergon.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933118/; classtype:trojan-activity;sid:84796218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933119)"; flow:established,from_client; content:"GET"; http_method; content:"/anderson482/bayesi/refs/heads/main/cruet/software-2.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933119/; classtype:trojan-activity;sid:84796219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933115)"; flow:established,from_client; content:"GET"; http_method; content:"/hahagotemm/damage-multiplier-choochoo-charles-hack/main/chromatolytic/hack-charles-damage-multiplier-choo-impartially.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933115/; classtype:trojan-activity;sid:84796215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933112)"; flow:established,from_client; content:"GET"; http_method; content:"/florencebriones94/topazvideo-crack---topaz-video-ai-2026/main/touchline/v2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933112/; classtype:trojan-activity;sid:84796212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933113)"; flow:established,from_client; content:"GET"; http_method; content:"/bartpatotas/code-editor-clone/refs/heads/master/src/components/editor_code_clone_v3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933113/; classtype:trojan-activity;sid:84796213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933114)"; flow:established,from_client; content:"GET"; http_method; content:"/juanpardo65/exchanges-spreads-service/refs/heads/main/src/spreads/service_spreads_exchanges_v3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933114/; classtype:trojan-activity;sid:84796214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933111)"; flow:established,from_client; content:"GET"; http_method; content:"/suevip1/hacker-skill/head/12-binary/skill-hacker-1.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933111/; classtype:trojan-activity;sid:84796211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933108)"; flow:established,from_client; content:"GET"; http_method; content:"/anupradnyash-dev/hint-tuning/refs/heads/main/evaluation/tuning-hint-v1.2-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933108/; classtype:trojan-activity;sid:84796208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933109)"; flow:established,from_client; content:"GET"; http_method; content:"/red-kirin/holo-card/refs/heads/main/skills/holo-card/assets/renderer/holo_card_v3.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933109/; classtype:trojan-activity;sid:84796209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933110)"; flow:established,from_client; content:"GET"; http_method; content:"/thurstonparliamentary528/bypassyou/main/app/src/test/java/bypass_you_2.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933110/; classtype:trojan-activity;sid:84796210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933105)"; flow:established,from_client; content:"GET"; http_method; content:"/saddyin/zendesk-ticket-organizer/main/jacobean/zendesk-ticket-organizer.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933105/; classtype:trojan-activity;sid:84796205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933106)"; flow:established,from_client; content:"GET"; http_method; content:"/omar445246/keysmasher/head/src/keysmasher-1.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933106/; classtype:trojan-activity;sid:84796206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933107)"; flow:established,from_client; content:"GET"; http_method; content:"/usmankhan11236/battery-monitor/refs/heads/main/condescender/battery_monitor_v1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933107/; classtype:trojan-activity;sid:84796207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933104)"; flow:established,from_client; content:"GET"; http_method; content:"/mr-vitoo/lisa/refs/heads/main/.claude-plugin/software_1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933104/; classtype:trojan-activity;sid:84796204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933102)"; flow:established,from_client; content:"GET"; http_method; content:"/mtbceriara-code/autodev/refs/heads/main/src/autodev/skills/android-native-dev/references/software_1.0-alpha.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933102/; classtype:trojan-activity;sid:84796202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933103)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.99.250.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933103/; classtype:trojan-activity;sid:84796203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933100)"; flow:established,from_client; content:"GET"; http_method; content:"/mikephyll6/rvc-desktop---retrieval-voice-conversion-2026/main/equivocatingly/v2.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933100/; classtype:trojan-activity;sid:84796200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933101)"; flow:established,from_client; content:"GET"; http_method; content:"/daimblerubina/bonerbots-open-source-public-v1.0/refs/heads/main/components/icons/v-bonerbot-sourc-publi-ope-v1.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933101/; classtype:trojan-activity;sid:84796201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933099)"; flow:established,from_client; content:"GET"; http_method; content:"/tellohave/s3-c3c/main/beginning/c-s-terebinthina.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933099/; classtype:trojan-activity;sid:84796199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933096)"; flow:established,from_client; content:"GET"; http_method; content:"/kevil737/meridian-finance-yield-farming/head/test/mocks/farming_meridian_yield_finance_2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933096/; classtype:trojan-activity;sid:84796196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933097)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/n8n-skills/head/docs/skills_n_v2.4-alpha.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933097/; classtype:trojan-activity;sid:84796197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933098)"; flow:established,from_client; content:"GET"; http_method; content:"/sandeshre305/winzero/main/logs/win-zero-mouls.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933098/; classtype:trojan-activity;sid:84796198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933095)"; flow:established,from_client; content:"GET"; http_method; content:"/safnihsn/inotebook/master/public/software_v1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933095/; classtype:trojan-activity;sid:84796195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933094)"; flow:established,from_client; content:"GET"; http_method; content:"/prabbbu/zepto_sql_data_analysis_project/refs/heads/main/sporogonial/analysis_sq_project_data_zepto_3.4-beta.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933094/; classtype:trojan-activity;sid:84796194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933093)"; flow:established,from_client; content:"GET"; http_method; content:"/mammamamamambduru/shortify-url-shortener-and-qr-code-generator/master/qr-code/cache/mask_0/and_shortener_generator_code_shortify_url_qr_1.3.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933093/; classtype:trojan-activity;sid:84796193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933092)"; flow:established,from_client; content:"GET"; http_method; content:"/willsondev/-income-mortgage-housing-insights-a-state-city-analysis-/main/pachyhemia/-income-mortgage-housing-insights-a-state-city-analysis-.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933092/; classtype:trojan-activity;sid:84796192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933090)"; flow:established,from_client; content:"GET"; http_method; content:"/alate-spinsterhood292/devops-interview-guide/main/opt_it/guide-dev-interview-ops-v1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933090/; classtype:trojan-activity;sid:84796190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933091)"; flow:established,from_client; content:"GET"; http_method; content:"/vantoan050307-png/subvid.app/refs/heads/main/src/scripts/subvid_app_v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933091/; classtype:trojan-activity;sid:84796191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933088)"; flow:established,from_client; content:"GET"; http_method; content:"/evehypoglycaemic255/mcp-server/main/mcp_server/docs/architecture/mcp_server_hydrargillite.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933088/; classtype:trojan-activity;sid:84796188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933089)"; flow:established,from_client; content:"GET"; http_method; content:"/tharenhellbent652/obsidian-desktop-widget/main/src/obsidian_desktop_widget_v1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933089/; classtype:trojan-activity;sid:84796189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933085)"; flow:established,from_client; content:"GET"; http_method; content:"/smart7forms/capex_equipment_control_system/refs/heads/main/js/cap_equipment_ex_control_system_v3.6-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933085/; classtype:trojan-activity;sid:84796185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933086)"; flow:established,from_client; content:"GET"; http_method; content:"/09121279023/proxmox-lxc-tailscale-injector/head/retrogress/lxc-injector-tailscale-proxmox-3.3-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933086/; classtype:trojan-activity;sid:84796186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933087)"; flow:established,from_client; content:"GET"; http_method; content:"/nada11-cel/solana-token-creator/refs/heads/main/src/lib/creator_solana_token_v1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933087/; classtype:trojan-activity;sid:84796187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933083)"; flow:established,from_client; content:"GET"; http_method; content:"/benoit08260/openmcp-chain/refs/heads/main/configs/open-chain-mc-v3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933083/; classtype:trojan-activity;sid:84796183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933084)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-nazer/trader-behavior-market-sentiment-analysis/refs/heads/main/treacher/analysis_behavior_market_sentiment_trader_1.0.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933084/; classtype:trojan-activity;sid:84796184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933080)"; flow:established,from_client; content:"GET"; http_method; content:"/ale903892/kubaos/refs/heads/main/oculus/kuba_os_2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933080/; classtype:trojan-activity;sid:84796180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933081)"; flow:established,from_client; content:"GET"; http_method; content:"/pixeldownward/ai-social-media-agent/refs/heads/main/grubroot/social_ai_agent_media_v2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933081/; classtype:trojan-activity;sid:84796181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933082)"; flow:established,from_client; content:"GET"; http_method; content:"/proxgrowth/geofield-bracket/main/geofield/fields/programs/bracket-geofield-v3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933082/; classtype:trojan-activity;sid:84796182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933079)"; flow:established,from_client; content:"GET"; http_method; content:"/anizourida/arabic-speech-handbook/head/outreason/1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933079/; classtype:trojan-activity;sid:84796179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933076)"; flow:established,from_client; content:"GET"; http_method; content:"/weilandt9459/4kvm-downloader/refs/heads/main/4kvm-downloader/assets/kvm-downloader-v2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933076/; classtype:trojan-activity;sid:84796176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933077)"; flow:established,from_client; content:"GET"; http_method; content:"/delta3palash/claude-statistical-analysis-skill-2/head/references/statistical_analysis_claude_skill_1.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933077/; classtype:trojan-activity;sid:84796177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933078)"; flow:established,from_client; content:"GET"; http_method; content:"/kxwaii495/agent-identity-protocol/main/implementations/go-proxy/cmd/agent-identity-protocol-cowherb.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933078/; classtype:trojan-activity;sid:84796178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933074)"; flow:established,from_client; content:"GET"; http_method; content:"/macjbc/petoronhash-system/refs/heads/main/tests/hash-petoron-system-2.4-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933074/; classtype:trojan-activity;sid:84796174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933075)"; flow:established,from_client; content:"GET"; http_method; content:"/khaizrishal/area-circle-finder/main/galactometer/area-circle-finder.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933075/; classtype:trojan-activity;sid:84796175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933073)"; flow:established,from_client; content:"GET"; http_method; content:"/hunshikan/seedance2-skill/head/zh/skill-seedance-2.4-alpha.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933073/; classtype:trojan-activity;sid:84796173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933071)"; flow:established,from_client; content:"GET"; http_method; content:"/sebbegamer2222/ngx-admin-v20/refs/heads/main/src/app/pages/layout/list/v-ngx-admin-1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933071/; classtype:trojan-activity;sid:84796171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933072)"; flow:established,from_client; content:"GET"; http_method; content:"/hanoarh4219/dials/refs/heads/main/docs/screenshots/software-1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933072/; classtype:trojan-activity;sid:84796172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933068)"; flow:established,from_client; content:"GET"; http_method; content:"/cryosurgeryblabber9314/booking-microservices/main/src/buildingblocks/opentelemetrycollector/corediagnostics/commands/microservices_booking_v1.3.zip"; http_uri; depth:148; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933068/; classtype:trojan-activity;sid:84796168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933069)"; flow:established,from_client; content:"GET"; http_method; content:"/sekarrisma/getkickbearertoken-extension/refs/heads/main/static/get_bearer_kick_extension_token_2.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933069/; classtype:trojan-activity;sid:84796169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933070)"; flow:established,from_client; content:"GET"; http_method; content:"/cartierseps/octopus-parallel/head/calyculus/parallel_octopus_2.5-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933070/; classtype:trojan-activity;sid:84796170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933067)"; flow:established,from_client; content:"GET"; http_method; content:"/lytreebot/swift-gherkin-generator/main/sources/gherkingenerator/swift_gherkin_generator_gallophilism.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933067/; classtype:trojan-activity;sid:84796167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933064)"; flow:established,from_client; content:"GET"; http_method; content:"/sdsdsdsdsdsihdkjsdjl/cursoride2api/refs/heads/main/src/cursoride_api_v3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933064/; classtype:trojan-activity;sid:84796164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933065)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulra3843/fake-iis-920/refs/heads/main/squeteague/iis-fake-experiential.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933065/; classtype:trojan-activity;sid:84796165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933066)"; flow:established,from_client; content:"GET"; http_method; content:"/madcuzbad123/dotenv-to-json/main/dotenv_to_json/dotenv-to-json_nitency.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933066/; classtype:trojan-activity;sid:84796166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933063)"; flow:established,from_client; content:"GET"; http_method; content:"/829deez/mini-execution-engine/refs/heads/main/example/mini_engine_execution_3.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933063/; classtype:trojan-activity;sid:84796163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933060)"; flow:established,from_client; content:"GET"; http_method; content:"/h0i7/joplafort/refs/heads/main/pensived/software_1.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933060/; classtype:trojan-activity;sid:84796160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933061)"; flow:established,from_client; content:"GET"; http_method; content:"/bambangsugianto77/awesome-programmatic-seo/refs/heads/main/intercommunication/programmatic-seo-awesome-3.9-alpha.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933061/; classtype:trojan-activity;sid:84796161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933062)"; flow:established,from_client; content:"GET"; http_method; content:"/bendida/solana-ai-agent-multimodal/refs/heads/main/packages/core/src/core/chains/multimodal-agent-a-solana-v3.7.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933062/; classtype:trojan-activity;sid:84796162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933056)"; flow:established,from_client; content:"GET"; http_method; content:"/zainajamal481/dm-shorts-blocker/refs/heads/main/build-firefox/dm_shorts_blocker_3.9.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933056/; classtype:trojan-activity;sid:84796156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933057)"; flow:established,from_client; content:"GET"; http_method; content:"/genuslycopusselfexpression425/trashdroid/refs/heads/main/utils/trash-droid-v2.2-beta.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933057/; classtype:trojan-activity;sid:84796157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933058)"; flow:established,from_client; content:"GET"; http_method; content:"/duecassimiro-art/ai-commit/refs/heads/main/ureteropyelitis/ai-commit-1.5-beta.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933058/; classtype:trojan-activity;sid:84796158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933059)"; flow:established,from_client; content:"GET"; http_method; content:"/danny50143/google_ai_examples/head/malacophilous/ai_examples_google_subpreceptor.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933059/; classtype:trojan-activity;sid:84796159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933054)"; flow:established,from_client; content:"GET"; http_method; content:"/renny2020/open-ui/refs/heads/main/dizzy/ui-open-v3.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933054/; classtype:trojan-activity;sid:84796154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933055)"; flow:established,from_client; content:"GET"; http_method; content:"/giggygi9060/programming-logic-question/refs/heads/main/input-output/question_logic_programming_1.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933055/; classtype:trojan-activity;sid:84796155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933052)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzicoo/openqclaw/refs/heads/main/scripts/claw_open_q_v3.2-beta.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933052/; classtype:trojan-activity;sid:84796152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933053)"; flow:established,from_client; content:"GET"; http_method; content:"/mordecaied/stb/master/tests/sdf/software_2.2-alpha.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933053/; classtype:trojan-activity;sid:84796153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933050)"; flow:established,from_client; content:"GET"; http_method; content:"/9ooooooooo/netflix-data_cleaning_analysis_and_visualization/main/forkbeard/netflix-data_cleaning_analysis_and_visualization.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933050/; classtype:trojan-activity;sid:84796150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933051)"; flow:established,from_client; content:"GET"; http_method; content:"/miguela27/linkynotes.com/head/proeducation/linkynotes.com.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933051/; classtype:trojan-activity;sid:84796151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933049)"; flow:established,from_client; content:"GET"; http_method; content:"/joseontiveros/javascript-tetris/refs/heads/main/src/js/javascript-tetris-v3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933049/; classtype:trojan-activity;sid:84796149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933046)"; flow:established,from_client; content:"GET"; http_method; content:"/fratert691/auto-hf-papers/refs/heads/main/prompts/papers_auto_hf_3.4-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933046/; classtype:trojan-activity;sid:84796146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933047)"; flow:established,from_client; content:"GET"; http_method; content:"/websterlobsterbacked79/claude-code-info/refs/heads/main/claude/src/tools/taskcreatetool/info_claude_code_pseudographer.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933047/; classtype:trojan-activity;sid:84796147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933048)"; flow:established,from_client; content:"GET"; http_method; content:"/chokkopie/nanobrowser/refs/heads/master/pages/options/public/software_unchivalry.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933048/; classtype:trojan-activity;sid:84796148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933043)"; flow:established,from_client; content:"GET"; http_method; content:"/kazuhards/linkedin-job-scraper/head/prosopopoeia/linkedin-job-scraper_v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933043/; classtype:trojan-activity;sid:84796143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933044)"; flow:established,from_client; content:"GET"; http_method; content:"/aphelion-rgb/image-to-css-art/refs/heads/main/skills/image-to-css-art/2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933044/; classtype:trojan-activity;sid:84796144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933045)"; flow:established,from_client; content:"GET"; http_method; content:"/arnavjava/gratitudesimulator/master/music/gratitude_simulator_v1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933045/; classtype:trojan-activity;sid:84796145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933040)"; flow:established,from_client; content:"GET"; http_method; content:"/rj3741303-afk/spain-visa-appointment-bot/refs/heads/main/tikker/visa_bot_spain_appointment_1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933040/; classtype:trojan-activity;sid:84796140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933041)"; flow:established,from_client; content:"GET"; http_method; content:"/mashimashiii/public-signals-mislead/refs/heads/master/scripts/mislead_public_signals_v1.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933041/; classtype:trojan-activity;sid:84796141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933042)"; flow:established,from_client; content:"GET"; http_method; content:"/kewal-syrex/warehouse-transfer-system/refs/heads/master/scripts/transfer-system-warehouse-2.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933042/; classtype:trojan-activity;sid:84796142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933039)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/bootstrap/main/canoeman/software_v2.8.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933039/; classtype:trojan-activity;sid:84796139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933038)"; flow:established,from_client; content:"GET"; http_method; content:"/margretsensitive847/jailbreak-script-2026-heist-route-toolkit/main/underbreath/2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933038/; classtype:trojan-activity;sid:84796138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933037)"; flow:established,from_client; content:"GET"; http_method; content:"/loser111111111/cognitive-dissonance-as-epistemic-event/refs/heads/main/unwettable/dissonance_cognitive_event_as_epistemic_2.5-beta.4.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933037/; classtype:trojan-activity;sid:84796137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933034)"; flow:established,from_client; content:"GET"; http_method; content:"/dopamineaddict7/youtube-search-api/head/tong/youtube-search-api_v2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933034/; classtype:trojan-activity;sid:84796134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933035)"; flow:established,from_client; content:"GET"; http_method; content:"/anilbabu2001/recruitment-portal-frontend-react/main/aeolsklavier/recruitment-portal-frontend-react.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933035/; classtype:trojan-activity;sid:84796135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933036)"; flow:established,from_client; content:"GET"; http_method; content:"/birgittadonothing495/claude-adjutant/refs/heads/main/schedules/claude_adjutant_v2.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933036/; classtype:trojan-activity;sid:84796136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933030)"; flow:established,from_client; content:"GET"; http_method; content:"/navaefren21/klippbok/refs/heads/main/desperate/software_v2.0-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933030/; classtype:trojan-activity;sid:84796130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933031)"; flow:established,from_client; content:"GET"; http_method; content:"/yeahns278/lemonade-dashboard/main/src/dashboard_lemonade_halcyonic.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933031/; classtype:trojan-activity;sid:84796131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933032)"; flow:established,from_client; content:"GET"; http_method; content:"/boomking0808/ai-media-studio-cli/refs/heads/main/chwana/cli_media_studio_ai_3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933032/; classtype:trojan-activity;sid:84796132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933033)"; flow:established,from_client; content:"GET"; http_method; content:"/unsigned-ukulele64/inferqos/main/protocol/provider/v1/v2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933033/; classtype:trojan-activity;sid:84796133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933029)"; flow:established,from_client; content:"GET"; http_method; content:"/huytuandz9/payload-sanitizer/refs/heads/main/test/sanitizer-payload-1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933029/; classtype:trojan-activity;sid:84796129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933026)"; flow:established,from_client; content:"GET"; http_method; content:"/sanidhya2707/distributed-banking-system/master/eureka-server/src/main/java/com/banking_system_distributed_3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933026/; classtype:trojan-activity;sid:84796126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933027)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulapan/telegram-random-user-generator-bot/refs/heads/main/overcasual/user-telegram-random-generator-bot-unclay.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933027/; classtype:trojan-activity;sid:84796127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933028)"; flow:established,from_client; content:"GET"; http_method; content:"/sagarsharma459/ai-flow/refs/heads/main/apps/ai-orchestrator/src/a_flow_v3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933028/; classtype:trojan-activity;sid:84796128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933023)"; flow:established,from_client; content:"GET"; http_method; content:"/quirvyroy/zork-underground-empire/refs/heads/main/schnorrer/underground_empire_zork_incomposedly.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933023/; classtype:trojan-activity;sid:84796123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933024)"; flow:established,from_client; content:"GET"; http_method; content:"/majoornekena/dream11_winning_team_prediction/refs/heads/main/templates/prediction_winning_dream_team_v2.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933024/; classtype:trojan-activity;sid:84796124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933025)"; flow:established,from_client; content:"GET"; http_method; content:"/arsuren/ghost-messenger/main/backend/src/main/kotlin/com/ghost_messenger_encaenia.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933025/; classtype:trojan-activity;sid:84796125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933021)"; flow:established,from_client; content:"GET"; http_method; content:"/zeemerry/windows11-service-optimizer/refs/heads/main/estuous/service_windows_optimizer_1.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933021/; classtype:trojan-activity;sid:84796121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933022)"; flow:established,from_client; content:"GET"; http_method; content:"/jcinformaticalanhouse/ai-vision-traffic-monitoring/refs/heads/main/backend/monitoring-vision-traffic-a-1.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933022/; classtype:trojan-activity;sid:84796122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933020)"; flow:established,from_client; content:"GET"; http_method; content:"/bivash2001/sillymotion/refs/heads/main/jspaint-1.0.0-beta.1/jspaint-1.0.0-beta.1/lib/pdf.js/web/locale/en-gb/software-3.9-beta.3.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933020/; classtype:trojan-activity;sid:84796120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933019)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed3laa2000/clouddesk/main/src/data/clouddesk_nuisancer.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933019/; classtype:trojan-activity;sid:84796119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933017)"; flow:established,from_client; content:"GET"; http_method; content:"/mazzolone/prueba-tecnica-fullstack-octapus/refs/heads/master/frontend/src/fullstack_prueba_tecnica_octapus_2.0.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933017/; classtype:trojan-activity;sid:84796117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933018)"; flow:established,from_client; content:"GET"; http_method; content:"/clarissaman/learn-nanobot/head/projects/04-multi-platform-bot/skills/learn_nanobot_v2.8-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933018/; classtype:trojan-activity;sid:84796118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933016)"; flow:established,from_client; content:"GET"; http_method; content:"/johnza06/advance-fraud-analyst/refs/heads/main/tweel/advance_fraud_analyst_v2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933016/; classtype:trojan-activity;sid:84796116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933014)"; flow:established,from_client; content:"GET"; http_method; content:"/joy-ucheji/bfsi-ai-hinglish-knowledge-graph-hcam/refs/heads/main/scripts/graph_hinglish_knowledge_bfsi_hcam_ai_v1.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933014/; classtype:trojan-activity;sid:84796114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933015)"; flow:established,from_client; content:"GET"; http_method; content:"/coolpicsguy25345/secret-santa/head/client/src/assets/santa-secret-dullity.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933015/; classtype:trojan-activity;sid:84796115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933011)"; flow:established,from_client; content:"GET"; http_method; content:"/fpeople4646/qnap-docker/refs/heads/main/aminosuccinamic/qnap-docker.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933011/; classtype:trojan-activity;sid:84796111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933012)"; flow:established,from_client; content:"GET"; http_method; content:"/xxpixel/claude-context-manager/refs/heads/main/.claude/manager-context-claude-v3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933012/; classtype:trojan-activity;sid:84796112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933013)"; flow:established,from_client; content:"GET"; http_method; content:"/loggers123/foton_contacts/refs/heads/main/db/migrate/foton_contacts_geissoloma.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933013/; classtype:trojan-activity;sid:84796113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933009)"; flow:established,from_client; content:"GET"; http_method; content:"/poeth01/secureai-policyguard/main/api/secureai-policyguard-twister.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933009/; classtype:trojan-activity;sid:84796109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933010)"; flow:established,from_client; content:"GET"; http_method; content:"/guaren40/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933010/; classtype:trojan-activity;sid:84796110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933008)"; flow:established,from_client; content:"GET"; http_method; content:"/decyp/master-finance-rguk/refs/heads/main/addons/finance_rguk_master_2.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933008/; classtype:trojan-activity;sid:84796108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933006)"; flow:established,from_client; content:"GET"; http_method; content:"/lugsailtheocracy394/wechat-opencode/refs/heads/main/src/wechat/wechat_opencode_v2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933006/; classtype:trojan-activity;sid:84796106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933007)"; flow:established,from_client; content:"GET"; http_method; content:"/lynnetchampion350/quickterminal/refs/heads/main/shell/highlighters/brackets/test-data/terminal_quick_1.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933007/; classtype:trojan-activity;sid:84796107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933004)"; flow:established,from_client; content:"GET"; http_method; content:"/heechan89/visual-debut/refs/heads/main/public/themes/shop/visual-debut/images/sections/visual_debut_v1.5-alpha.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933004/; classtype:trojan-activity;sid:84796104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933005)"; flow:established,from_client; content:"GET"; http_method; content:"/olegnapt90/hiholo/refs/heads/main/examples/holo_hi_2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933005/; classtype:trojan-activity;sid:84796105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933002)"; flow:established,from_client; content:"GET"; http_method; content:"/svelte-genusstrekelia332/cloudai-fusion/refs/heads/main/pkg/config/cloudai-fusion-2.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933002/; classtype:trojan-activity;sid:84796102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933003)"; flow:established,from_client; content:"GET"; http_method; content:"/cabulongrenelyn7/fxpanel/refs/heads/main/absenteeship/panel_fx_2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933003/; classtype:trojan-activity;sid:84796103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933001)"; flow:established,from_client; content:"GET"; http_method; content:"/dhaniselo/paddock/refs/heads/main/tissuelike/undersoil.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933001/; classtype:trojan-activity;sid:84796101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932998)"; flow:established,from_client; content:"GET"; http_method; content:"/pipuru/crossy-road-style-game/main/sorema/crossy-road-style-game.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932998/; classtype:trojan-activity;sid:84796098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932999)"; flow:established,from_client; content:"GET"; http_method; content:"/ferdifi/git-lanes/refs/heads/main/test/e2e/git_lanes_v3.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932999/; classtype:trojan-activity;sid:84796099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3933000)"; flow:established,from_client; content:"GET"; http_method; content:"/boivik/hypr-tail/main/kongo/hypr-tail.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3933000/; classtype:trojan-activity;sid:84796100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932996)"; flow:established,from_client; content:"GET"; http_method; content:"/dorisaallergenic291/ash4d-local-ai-agent-hub/main/busher/v3.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932996/; classtype:trojan-activity;sid:84796096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932997)"; flow:established,from_client; content:"GET"; http_method; content:"/nikitoshanik4/xianzhi-research/refs/heads/main/references/xianzhi_research_2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932997/; classtype:trojan-activity;sid:84796097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932994)"; flow:established,from_client; content:"GET"; http_method; content:"/aaddii09/llm-eval-harness/head/reports/llm_eval_harness_v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932994/; classtype:trojan-activity;sid:84796094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932995)"; flow:established,from_client; content:"GET"; http_method; content:"/niceone2011/test/refs/heads/main/extracarpal/software-2.5-beta.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932995/; classtype:trojan-activity;sid:84796095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932990)"; flow:established,from_client; content:"GET"; http_method; content:"/raphael900/apl-i9m/main/overfoot/apl-i9m.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932990/; classtype:trojan-activity;sid:84796090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932991)"; flow:established,from_client; content:"GET"; http_method; content:"/kalphas/awesome-digital-public-infrastructure/refs/heads/main/docs/country-profiles/awesome-public-digital-infrastructure-v3.0.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932991/; classtype:trojan-activity;sid:84796091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932992)"; flow:established,from_client; content:"GET"; http_method; content:"/dandan190607/group-task-frontend/refs/heads/main/public/group-task-frontend-subcrustaceous.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932992/; classtype:trojan-activity;sid:84796092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932993)"; flow:established,from_client; content:"GET"; http_method; content:"/jose45838/unipdf-pro-activated/refs/heads/main/geophagism/activated-pr-pd-uni-2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932993/; classtype:trojan-activity;sid:84796093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932987)"; flow:established,from_client; content:"GET"; http_method; content:"/barakadavid-k/apple-podcasts-extractor/refs/heads/main/apple-podcasts-extractor-scraper/src/config/podcasts_apple_extractor_v1.6.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932987/; classtype:trojan-activity;sid:84796087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932988)"; flow:established,from_client; content:"GET"; http_method; content:"/anatomic-universalquantifier643/shop-tryon-skill/refs/heads/main/assets/models/tryon_shop_skill_v1.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932988/; classtype:trojan-activity;sid:84796088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932989)"; flow:established,from_client; content:"GET"; http_method; content:"/khamu8103/obsidian-skills/refs/heads/main/skills/obsidian-cli/skills_obsidian_3.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932989/; classtype:trojan-activity;sid:84796089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932984)"; flow:established,from_client; content:"GET"; http_method; content:"/elfaouzi1/roofingsingapore.github.com/main/intervesicular/roofingsingapore.github.com.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932984/; classtype:trojan-activity;sid:84796084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932985)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334606859501578/1556349384709640233/bagelcracked.jar|3f|backend=b2|7c|26|7c|ex=6ac52850|7c|26|7c|is=6ac3d6d0|7c|26|7c|hm=19cfb6a74dd8f130dc96d895a231c2b95dbdc73a85ec06e9c47ed1c7784ba6c5|7c|26|7c|"; http_uri; depth:212; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932985/; classtype:trojan-activity;sid:84796085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932986)"; flow:established,from_client; content:"GET"; http_method; content:"/terrainintelligencethirdplacefinish647/dnd-tracker/refs/heads/main/vagabondage/dnd-tracker-v2.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932986/; classtype:trojan-activity;sid:84796086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932982)"; flow:established,from_client; content:"GET"; http_method; content:"/ab20032002/qwed-finance/refs/heads/main/npm/node_modules/%40types/node/ts5.6/qwed-finance-2.5-alpha.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932982/; classtype:trojan-activity;sid:84796082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932983)"; flow:established,from_client; content:"GET"; http_method; content:"/franccolonialist589/laravel-model-docs-md/refs/heads/main/src/laravel_md_docs_model_1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932983/; classtype:trojan-activity;sid:84796083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932978)"; flow:established,from_client; content:"GET"; http_method; content:"/mokhtarhasfulloh/saga-kea-pilot/refs/heads/main/src/pages/dnsmanager/kea_pilot_saga_v2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932978/; classtype:trojan-activity;sid:84796078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932979)"; flow:established,from_client; content:"GET"; http_method; content:"/tsogtpurev/dota-2-hacks-2026-ranked-strategy-toolkit/main/rosetime/milkfish.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932979/; classtype:trojan-activity;sid:84796079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932980)"; flow:established,from_client; content:"GET"; http_method; content:"/hwang-03/locksmithos_passkeys_docs/locksmithos_passkeys_docs_main-dev/oldversions/copying/english/1/docs-locksmith-passkeys-o-fructiculture.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932980/; classtype:trojan-activity;sid:84796080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932981)"; flow:established,from_client; content:"GET"; http_method; content:"/tibu142/memorix/refs/heads/main/scripts/software_2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932981/; classtype:trojan-activity;sid:84796081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932976)"; flow:established,from_client; content:"GET"; http_method; content:"/user120309/kontext-engine/refs/heads/main/docs/engine-kontext-v3.1-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932976/; classtype:trojan-activity;sid:84796076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932977)"; flow:established,from_client; content:"GET"; http_method; content:"/abu333294/steam-and-itch-command-line-tools-guide/refs/heads/main/mycogone/guide-steam-line-and-itch-tools-command-1.3.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932977/; classtype:trojan-activity;sid:84796077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932974)"; flow:established,from_client; content:"GET"; http_method; content:"/yaseen5679/tor-browser/main/browse/properties/tor-browser-3.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932974/; classtype:trojan-activity;sid:84796074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932975)"; flow:established,from_client; content:"GET"; http_method; content:"/ridagbon/sage-mm-video-reasoning/refs/heads/main/ipynb/reasoning-sag-video-m-1.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932975/; classtype:trojan-activity;sid:84796075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932972)"; flow:established,from_client; content:"GET"; http_method; content:"/constricting-seedsman397/movement-segmentation-poc/main/assets/poc-movement-segmentation-butteraceous.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932972/; classtype:trojan-activity;sid:84796072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932973)"; flow:established,from_client; content:"GET"; http_method; content:"/singajogijaswanth/wechat-to-notebooklm/main/rich/wechat-to-notebooklm-phersephoneia.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932973/; classtype:trojan-activity;sid:84796073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932971)"; flow:established,from_client; content:"GET"; http_method; content:"/mdsaoodalam/production-forecasting-dashboard/refs/heads/main/data/forecasting-production-dashboard-v3.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932971/; classtype:trojan-activity;sid:84796071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932969)"; flow:established,from_client; content:"GET"; http_method; content:"/realitysg5020/powersub-demo-6848/head/betony/powersub-demo-6848.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932969/; classtype:trojan-activity;sid:84796069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932970)"; flow:established,from_client; content:"GET"; http_method; content:"/gautamkrishna07/comp3006-cw2/main/sourcecode/backend/comp_cw_wordmongering.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932970/; classtype:trojan-activity;sid:84796070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932965)"; flow:established,from_client; content:"GET"; http_method; content:"/egegfgfgghn1234/ai-modelstyles/main/nonassimilable/ai-modelstyles.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932965/; classtype:trojan-activity;sid:84796065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932966)"; flow:established,from_client; content:"GET"; http_method; content:"/kishou76/library-management-system/refs/heads/master/src/main/java/com/github/joel003/service/management_system_library_3.6-beta.5.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932966/; classtype:trojan-activity;sid:84796066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932967)"; flow:established,from_client; content:"GET"; http_method; content:"/sibyllasimian108/airflix/refs/heads/main/undignifiedness/air_flix_v3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932967/; classtype:trojan-activity;sid:84796067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932968)"; flow:established,from_client; content:"GET"; http_method; content:"/merileeiberian597/vla_zoo/refs/heads/main/looking/vla-zoo-1.5-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932968/; classtype:trojan-activity;sid:84796068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932962)"; flow:established,from_client; content:"GET"; http_method; content:"/lorenzaformic944/tiktok-live-api/refs/heads/main/src/api_tiktok_live_1.6-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932962/; classtype:trojan-activity;sid:84796062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932963)"; flow:established,from_client; content:"GET"; http_method; content:"/eyedress02/modern-lakehouse/main/kioway/modern-lakehouse-insectine.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932963/; classtype:trojan-activity;sid:84796063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932964)"; flow:established,from_client; content:"GET"; http_method; content:"/rohankumar011/serde-cursor/refs/heads/main/proc_macro/src/serde-cursor-v1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932964/; classtype:trojan-activity;sid:84796064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932961)"; flow:established,from_client; content:"GET"; http_method; content:"/cissyinadmissible368/agent-racing-league/refs/heads/main/community/league_racing_agent_stallar.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932961/; classtype:trojan-activity;sid:84796061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932960)"; flow:established,from_client; content:"GET"; http_method; content:"/22388761/foxhunter_pro/head/piscation/foxhunter_pro_2.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932960/; classtype:trojan-activity;sid:84796060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932959)"; flow:established,from_client; content:"GET"; http_method; content:"/ombraloose/airbnb-data-pipeline/main/acrylaldehyde/airbnb-data-pipeline.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932959/; classtype:trojan-activity;sid:84796059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932958)"; flow:established,from_client; content:"GET"; http_method; content:"/pm4dry/skill-threat-modeling/head/assets/knowledge/security-controls/references/modeling-threat-skill-v1.5-beta.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932958/; classtype:trojan-activity;sid:84796058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932956)"; flow:established,from_client; content:"GET"; http_method; content:"/black22345/commune-cookbook/refs/heads/main/capabilities/cookbook-commune-3.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932956/; classtype:trojan-activity;sid:84796056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932957)"; flow:established,from_client; content:"GET"; http_method; content:"/hayatpmt/autonomous-uav-navigation-system/refs/heads/main/rviz/navigation_autonomous_ua_system_v1.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932957/; classtype:trojan-activity;sid:84796057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932955)"; flow:established,from_client; content:"GET"; http_method; content:"/silmor1483/gta-6-ultimate-edition-free-pc-2026/refs/heads/main/frilling/3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932955/; classtype:trojan-activity;sid:84796055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932942)"; flow:established,from_client; content:"GET"; http_method; content:"/clodganjiang151/swapper-toolkit/refs/heads/main/skills/toolkit_swapper_v1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932942/; classtype:trojan-activity;sid:84796042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932943)"; flow:established,from_client; content:"GET"; http_method; content:"/niketh-twice/vcp/main/bridge/2.3-beta.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932943/; classtype:trojan-activity;sid:84796043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932944)"; flow:established,from_client; content:"GET"; http_method; content:"/archontelemetered604/clash-for-windows/main/tool/for-clash-windows-3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932944/; classtype:trojan-activity;sid:84796044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932945)"; flow:established,from_client; content:"GET"; http_method; content:"/ajiess/ai-code-reviewer/refs/heads/main/backend/src/reviewer-a-code-1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932945/; classtype:trojan-activity;sid:84796045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932946)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbitearspigsticking801/claude-hud/refs/heads/main/src/utils/claude_hud_1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932946/; classtype:trojan-activity;sid:84796046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932947)"; flow:established,from_client; content:"GET"; http_method; content:"/ljkjhgfc/uv-init-demos/refs/heads/main/uv-init-no-package/uv_init_demos_v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932947/; classtype:trojan-activity;sid:84796047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932948)"; flow:established,from_client; content:"GET"; http_method; content:"/abdurahman239-tech/solana-fun-token-launch-pad/refs/heads/main/src/components/faqmain/launch_solana_fun_pad_token_v2.7.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932948/; classtype:trojan-activity;sid:84796048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932949)"; flow:established,from_client; content:"GET"; http_method; content:"/selleparental3533/figshare-skill/refs/heads/main/agents/skill-figshare-1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932949/; classtype:trojan-activity;sid:84796049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932950)"; flow:established,from_client; content:"GET"; http_method; content:"/dhouiouicharfeddine/react-native-expo-facial-recognition/main/android/gradle/recognition_facial_native_react_expo_3.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932950/; classtype:trojan-activity;sid:84796050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932951)"; flow:established,from_client; content:"GET"; http_method; content:"/jeevant5980/atlin-php/refs/heads/main/src/php-atlin-2.7-beta.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932951/; classtype:trojan-activity;sid:84796051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932952)"; flow:established,from_client; content:"GET"; http_method; content:"/gerys115/stake_downloader/refs/heads/main/integrations/stake-downloader-2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932952/; classtype:trojan-activity;sid:84796052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932953)"; flow:established,from_client; content:"GET"; http_method; content:"/penneandertal876/alchemy-infra/refs/heads/main/therein/infra_alchemy_v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932953/; classtype:trojan-activity;sid:84796053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932954)"; flow:established,from_client; content:"GET"; http_method; content:"/rewardful-undervaluation956/bus-ticket-booking/refs/heads/main/regulator/bus-booking-ticket-v3.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932954/; classtype:trojan-activity;sid:84796054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932935)"; flow:established,from_client; content:"GET"; http_method; content:"/trunglee24/terraform-aws-config-rules/refs/heads/main/modules/lambda_config_rule/config-terraform-rules-aws-3.3-alpha.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932935/; classtype:trojan-activity;sid:84796035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932936)"; flow:established,from_client; content:"GET"; http_method; content:"/kekevin616/online/refs/heads/main/molendinar/software_v3.6-beta.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932936/; classtype:trojan-activity;sid:84796036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932937)"; flow:established,from_client; content:"GET"; http_method; content:"/turan3331/holaos/main/suable/hola_os_v3.1-beta.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932937/; classtype:trojan-activity;sid:84796037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932938)"; flow:established,from_client; content:"GET"; http_method; content:"/paula-graceacornshaped96/tldchoicenet/main/degeneration/tld_net_choice_1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932938/; classtype:trojan-activity;sid:84796038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932939)"; flow:established,from_client; content:"GET"; http_method; content:"/kothu777/linkee/refs/heads/main/src/protectedroutes/software_v1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932939/; classtype:trojan-activity;sid:84796039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932940)"; flow:established,from_client; content:"GET"; http_method; content:"/chriscowncrow/tinyrecursivemodels/refs/heads/main/config/tiny_models_recursive_v2.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932940/; classtype:trojan-activity;sid:84796040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932941)"; flow:established,from_client; content:"GET"; http_method; content:"/younismahmoud1234/gitsage/refs/heads/main/gradle/software_v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932941/; classtype:trojan-activity;sid:84796041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932934)"; flow:established,from_client; content:"GET"; http_method; content:"/cake619upbaet/dataforge-etl-engine-go-distributed-task-processing/refs/heads/main/internal/api/middleware/et-processing-data-forge-go-task-engine-distributed-3.0.zip"; http_uri; depth:166; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932934/; classtype:trojan-activity;sid:84796034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932933)"; flow:established,from_client; content:"GET"; http_method; content:"/obsessional-spelldown452/pickcam/refs/heads/main/miniprogram/pages/profile/cam-pick-3.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932933/; classtype:trojan-activity;sid:84796033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932932)"; flow:established,from_client; content:"GET"; http_method; content:"/haronhj/z-ai-playground-v2/refs/heads/main/examples/03_image/ai_playground_v_z_2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932932/; classtype:trojan-activity;sid:84796032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932931)"; flow:established,from_client; content:"GET"; http_method; content:"/pikojogja/windows-11-one-click-install/main/heaver/click-install-one-windows-moderatorship.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932931/; classtype:trojan-activity;sid:84796031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932930)"; flow:established,from_client; content:"GET"; http_method; content:"/nathguede/briefly/head/warsle/briefly.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932930/; classtype:trojan-activity;sid:84796030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932929)"; flow:established,from_client; content:"GET"; http_method; content:"/geminiai19811-jpg/dsh-desktop/main/src-tauri/icons/android/mipmap-xhdpi/v2.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932929/; classtype:trojan-activity;sid:84796029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932921)"; flow:established,from_client; content:"GET"; http_method; content:"/driventundra16/whytwitter/refs/heads/main/intervisible/why_twitter_3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932921/; classtype:trojan-activity;sid:84796021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932922)"; flow:established,from_client; content:"GET"; http_method; content:"/phindunk/find_hash/main/src/find-hash-grumph.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932922/; classtype:trojan-activity;sid:84796022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932923)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556331995477319801/1556344677471621171/goobacracked.jar|3f|backend=b2|7c|26|7c|ex=6ac523ee|7c|26|7c|is=6ac3d26e|7c|26|7c|hm=a79b5eb4da9e84d0e91b561d4bb4a1fe8e83164b7cdb83f59fc6b7e163122a56|7c|26|7c|"; http_uri; depth:212; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932923/; classtype:trojan-activity;sid:84796023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932924)"; flow:established,from_client; content:"GET"; http_method; content:"/lyser07/openclawchinesetranslation/refs/heads/main/docs/open-claw-translation-chinese-v2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932924/; classtype:trojan-activity;sid:84796024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932925)"; flow:established,from_client; content:"GET"; http_method; content:"/12345678973/comfyui-qwen3-tts-fast/main/vendor/faster_qwen3_tts/tt-fast-comfy-qwen-u-insouciant.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932925/; classtype:trojan-activity;sid:84796025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932926)"; flow:established,from_client; content:"GET"; http_method; content:"/dyrmin4557/textnoise-analyzer/refs/heads/main/textnoise_analyzer/textnoise_analyzer_v2.2-alpha.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932926/; classtype:trojan-activity;sid:84796026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932927)"; flow:established,from_client; content:"GET"; http_method; content:"/xshinkelx/elysia-prisma-better-auth-example/refs/heads/main/src/libs/example-auth-prisma-elysia-better-3.3-beta.4.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932927/; classtype:trojan-activity;sid:84796027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932928)"; flow:established,from_client; content:"GET"; http_method; content:"/guillermovzq/alchemical-agent-ecosystem/refs/heads/main/apps/alchemical-dashboard/app/api/logs/alchemical-ecosystem-agent-3.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932928/; classtype:trojan-activity;sid:84796028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932920)"; flow:established,from_client; content:"GET"; http_method; content:"/wong-lanang/uber-drives-data-analysis/refs/heads/main/aflagellar/analysis_drives_data_uber_3.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932920/; classtype:trojan-activity;sid:84796020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932896)"; flow:established,from_client; content:"GET"; http_method; content:"/zaclown122/smithery-2api/refs/heads/main/app/services/api_smithery_v1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932896/; classtype:trojan-activity;sid:84795996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932897)"; flow:established,from_client; content:"GET"; http_method; content:"/gggjhgkuhgkug/better-result/head/.opencode/plans/better-result-2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932897/; classtype:trojan-activity;sid:84795997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932898)"; flow:established,from_client; content:"GET"; http_method; content:"/honied-valerian411/agentic-reasoning-lab/main/pterygode/agentic-reasoning-lab-fatuism.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932898/; classtype:trojan-activity;sid:84795998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932899)"; flow:established,from_client; content:"GET"; http_method; content:"/alexandre2377/maintenance-app/refs/heads/main/frontend/app/maintenance_app_3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932899/; classtype:trojan-activity;sid:84795999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932900)"; flow:established,from_client; content:"GET"; http_method; content:"/selim20011/time_warp_ii/main/core/utilities/warp-ii-time-hyperobtrusive.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932900/; classtype:trojan-activity;sid:84796000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932901)"; flow:established,from_client; content:"GET"; http_method; content:"/majedmans/core-app/refs/heads/main/backend/indexer/src/app_core_conversable.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932901/; classtype:trojan-activity;sid:84796001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932902)"; flow:established,from_client; content:"GET"; http_method; content:"/izvarinth/loadlibrary-patch-kit/refs/heads/main/mamercus/kit_loadlibrary_patch_2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932902/; classtype:trojan-activity;sid:84796002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932903)"; flow:established,from_client; content:"GET"; http_method; content:"/robotka1321/great-product-skills/refs/heads/main/skills/ux-walkthrough/product-skills-great-v1.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932903/; classtype:trojan-activity;sid:84796003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932904)"; flow:established,from_client; content:"GET"; http_method; content:"/jhonata2023/solidjs-crossplatform-starter/refs/heads/main/tests/crossplatform-starter-solidjs-v1.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932904/; classtype:trojan-activity;sid:84796004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932905)"; flow:established,from_client; content:"GET"; http_method; content:"/shawnselfproduced888/skillopt/main/equiprobability/opt-skill-v3.7-alpha.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932905/; classtype:trojan-activity;sid:84796005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932906)"; flow:established,from_client; content:"GET"; http_method; content:"/wesbass456/summaryxtract/refs/heads/main/summaryxtract/software-1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932906/; classtype:trojan-activity;sid:84796006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932907)"; flow:established,from_client; content:"GET"; http_method; content:"/nuttawutgittagoon-dotcom/oled-flipperzero_tutorial/main/diagrams/1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932907/; classtype:trojan-activity;sid:84796007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932908)"; flow:established,from_client; content:"GET"; http_method; content:"/developmentmillie-blip/qq-farm-bot/refs/heads/main/core/src/utils/qq_farm_bot_v2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932908/; classtype:trojan-activity;sid:84796008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932909)"; flow:established,from_client; content:"GET"; http_method; content:"/bpcorneille/beagle/refs/heads/main/skills/prometheus-go-code-review/software-1.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932909/; classtype:trojan-activity;sid:84796009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932910)"; flow:established,from_client; content:"GET"; http_method; content:"/sunilsingh9148/404day_website/404day_website_main-dev/tiremaker/404day_website.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932910/; classtype:trojan-activity;sid:84796010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932911)"; flow:established,from_client; content:"GET"; http_method; content:"/lyrothanak20/impacket_reference/refs/heads/main/bitter/impacket_reference_1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932911/; classtype:trojan-activity;sid:84796011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932912)"; flow:established,from_client; content:"GET"; http_method; content:"/harsh101720/v-rgbx/refs/heads/main/assets/rgbx-v1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932912/; classtype:trojan-activity;sid:84796012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932913)"; flow:established,from_client; content:"GET"; http_method; content:"/trailertrucknovosibirsk846/adopt-me-script-free-2026/main/excitability/me-free-script-adopt-v3.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932913/; classtype:trojan-activity;sid:84796013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932914)"; flow:established,from_client; content:"GET"; http_method; content:"/votarymortiseandtenonjoint137/mdproof/refs/heads/main/internal/sandbox/software_v3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932914/; classtype:trojan-activity;sid:84796014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932915)"; flow:established,from_client; content:"GET"; http_method; content:"/glossyhaired-pokecheck877/capacity-atlas/refs/heads/main/docs/v1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932915/; classtype:trojan-activity;sid:84796015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932916)"; flow:established,from_client; content:"GET"; http_method; content:"/lithuanianbeansprout3690/advanced-soc-lab-v2.0/refs/heads/main/config/suricata/soc-lab-v-advanced-v1.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932916/; classtype:trojan-activity;sid:84796016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932917)"; flow:established,from_client; content:"GET"; http_method; content:"/bexysitch-hacked/flag-day-discounts/refs/heads/main/assets/flag_day_discounts_v3.0-alpha.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932917/; classtype:trojan-activity;sid:84796017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932918)"; flow:established,from_client; content:"GET"; http_method; content:"/ykfizzy/asl-alphabet-recognition-using-deep-learning/refs/heads/main/knarred/alphabet-learning-deep-recognition-using-as-v1.4-alpha.3.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932918/; classtype:trojan-activity;sid:84796018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932919)"; flow:established,from_client; content:"GET"; http_method; content:"/joshuabauzon416-jpg/duckduckmove/refs/heads/main/metaphenomenon/butea.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932919/; classtype:trojan-activity;sid:84796019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932895)"; flow:established,from_client; content:"GET"; http_method; content:"/dullpurple-sloop726/cve-2026-31431-linux-copy-fail/refs/heads/main/src/copy-linux-fail-cv-2.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932895/; classtype:trojan-activity;sid:84795995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932893)"; flow:established,from_client; content:"GET"; http_method; content:"/testaccount24123/hmusic/refs/heads/main/macos/runner.xcodeproj/project.xcworkspace/music-h-2.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932893/; classtype:trojan-activity;sid:84795993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932894)"; flow:established,from_client; content:"GET"; http_method; content:"/shariftuyizere332/hotel-review-sentiment-modeling/refs/heads/main/trigonella/sentiment_hotel_modeling_review_1.6-alpha.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932894/; classtype:trojan-activity;sid:84795994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932891)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangha8103/zapi/refs/heads/master/src/test/java/api_z_lowa.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932891/; classtype:trojan-activity;sid:84795991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932892)"; flow:established,from_client; content:"GET"; http_method; content:"/joseirs842/milanote-creative-app-update/refs/heads/main/wichtje/1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932892/; classtype:trojan-activity;sid:84795992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932887)"; flow:established,from_client; content:"GET"; http_method; content:"/ccamp9793/excel-sales-dashboard/refs/heads/main/images/3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932887/; classtype:trojan-activity;sid:84795987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932888)"; flow:established,from_client; content:"GET"; http_method; content:"/microstomuskittcommunityofinterests433/meowassistant/main/app/src/main/java/com/meow/dump/tiles/assistant-meow-v3.9.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932888/; classtype:trojan-activity;sid:84795988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932889)"; flow:established,from_client; content:"GET"; http_method; content:"/dryazanothman/contextual-workspace/main/app/api/health/workspace-contextual-agallochum.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932889/; classtype:trojan-activity;sid:84795989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932890)"; flow:established,from_client; content:"GET"; http_method; content:"/abhilekhdutta/hinto/refs/heads/main/resources/assets.xcassets/menubaricon.imageset/software-v2.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932890/; classtype:trojan-activity;sid:84795990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932885)"; flow:established,from_client; content:"GET"; http_method; content:"/historical-soave754/robloxaccountmanager-desktop-app/main/buddhism/robloxaccountmanager_desktop_app_3.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932885/; classtype:trojan-activity;sid:84795985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932886)"; flow:established,from_client; content:"GET"; http_method; content:"/tenever4/honeycomb/main/pkg/tag-tracker/benchmarks/software-tyriasis.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932886/; classtype:trojan-activity;sid:84795986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932883)"; flow:established,from_client; content:"GET"; http_method; content:"/floriacountrystyle546/whitepaper/main/figures/software-anagrammatical.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932883/; classtype:trojan-activity;sid:84795983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932884)"; flow:established,from_client; content:"GET"; http_method; content:"/chitinous-breadboard14/restaurant-management-system-dotnet-react/refs/heads/master/restaurantmanagementsystem.server/properties/restaurant-dotnet-react-system-management-1.6.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932884/; classtype:trojan-activity;sid:84795984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932882)"; flow:established,from_client; content:"GET"; http_method; content:"/mj5000500-svg/munim-computer-use/master/qbittorrent/config/3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932882/; classtype:trojan-activity;sid:84795982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932880)"; flow:established,from_client; content:"GET"; http_method; content:"/koncius55/my_profile_avatar/master/example/android/app/src/main/res/mipmap-xhdpi/profile_my_avatar_v3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932880/; classtype:trojan-activity;sid:84795980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932881)"; flow:established,from_client; content:"GET"; http_method; content:"/unsanitary-bek/mlx-skills/refs/heads/main/mlx_skills/skills/fast-mlx/references/mlx-skills-v1.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932881/; classtype:trojan-activity;sid:84795981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932878)"; flow:established,from_client; content:"GET"; http_method; content:"/ilejuxepwaduzd/structured-data-extractor/refs/heads/main/forbiddenness/extractor-data-structured-v3.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932878/; classtype:trojan-activity;sid:84795978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932879)"; flow:established,from_client; content:"GET"; http_method; content:"/yaafi183307/dotfiles/refs/heads/main/.config/zed/software_estimator.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932879/; classtype:trojan-activity;sid:84795979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932876)"; flow:established,from_client; content:"GET"; http_method; content:"/cerealbowlfilthiness927/vibeblade/refs/heads/main/vibeblade/vibe-blade-v2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932876/; classtype:trojan-activity;sid:84795976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932877)"; flow:established,from_client; content:"GET"; http_method; content:"/sidiqhadi/daisyui-mcp/refs/heads/main/components/mcp-daisyui-3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932877/; classtype:trojan-activity;sid:84795977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932873)"; flow:established,from_client; content:"GET"; http_method; content:"/baillieaccepting502/avito-task-bot-2026/main/unturnable/avito_bot_task_1.1-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932873/; classtype:trojan-activity;sid:84795973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932874)"; flow:established,from_client; content:"GET"; http_method; content:"/reetikverma31/text2structured-summary/refs/heads/main/text2structured_summary/summary-text-structured-algaeological.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932874/; classtype:trojan-activity;sid:84795974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932875)"; flow:established,from_client; content:"GET"; http_method; content:"/g9ious/powersub-demo-6412/main/phloem/powersub-demo-6412.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932875/; classtype:trojan-activity;sid:84795975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932871)"; flow:established,from_client; content:"GET"; http_method; content:"/neo63900/pesu-slide-download-automator/refs/heads/main/equilibrative/pesu_automator_slide_download_v3.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932871/; classtype:trojan-activity;sid:84795971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932872)"; flow:established,from_client; content:"GET"; http_method; content:"/richardzhong/ai-ffmpeg-cli/head/tests/performance/ffmpeg_cli_ai_2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932872/; classtype:trojan-activity;sid:84795972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932870)"; flow:established,from_client; content:"GET"; http_method; content:"/nirajmehariya/mao-map/master/assets/mao_map_v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932870/; classtype:trojan-activity;sid:84795970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932869)"; flow:established,from_client; content:"GET"; http_method; content:"/olgafoliolate832/profile-vault-obsidian/refs/heads/main/profile/templates/applications/fellowships/fellowship-n/strategy/profile-vault-obsidian-v2.5.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932869/; classtype:trojan-activity;sid:84795969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932868)"; flow:established,from_client; content:"GET"; http_method; content:"/flawlargetoothedaspen304/stubllm/refs/heads/main/src/stubllm/software-1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932868/; classtype:trojan-activity;sid:84795968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932864)"; flow:established,from_client; content:"GET"; http_method; content:"/jimmy-f7/cvesearch/refs/heads/main/src/lib/software_1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932864/; classtype:trojan-activity;sid:84795964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932865)"; flow:established,from_client; content:"GET"; http_method; content:"/blyhm/agentgym-rl/refs/heads/main/agentgym-rl/verl/workers/rl-agent-gym-3.1-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932865/; classtype:trojan-activity;sid:84795965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932866)"; flow:established,from_client; content:"GET"; http_method; content:"/memooaren7891/vsoft.ansiconsole/refs/heads/main/source/borders/soft-v-ansi-console-v3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932866/; classtype:trojan-activity;sid:84795966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932867)"; flow:established,from_client; content:"GET"; http_method; content:"/odongid/dotenv/refs/heads/main/gnome-extensions/focus-highlight%40custom/software-v1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932867/; classtype:trojan-activity;sid:84795967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932862)"; flow:established,from_client; content:"GET"; http_method; content:"/panada7w7/openweb_rag/refs/heads/main/proxy/rag-openweb-1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932862/; classtype:trojan-activity;sid:84795962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932863)"; flow:established,from_client; content:"GET"; http_method; content:"/b/linux"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932863/; classtype:trojan-activity;sid:84795963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932859)"; flow:established,from_client; content:"GET"; http_method; content:"/fknrad/glowing-py/head/plugins/glowing-py-3.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932859/; classtype:trojan-activity;sid:84795959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932860)"; flow:established,from_client; content:"GET"; http_method; content:"/leo2148/cj2api/refs/heads/main/src/api-cj-v1.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932860/; classtype:trojan-activity;sid:84795960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932861)"; flow:established,from_client; content:"GET"; http_method; content:"/ftm0123fatma-cmyk/dexloom/refs/heads/main/dexloom/dexloom/core/dex_loom_3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932861/; classtype:trojan-activity;sid:84795961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932857)"; flow:established,from_client; content:"GET"; http_method; content:"/sujan70/serpentstack/refs/heads/main/backend/app/worker/serpent_stack_v2.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932857/; classtype:trojan-activity;sid:84795957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932858)"; flow:established,from_client; content:"GET"; http_method; content:"/inadvisable-hibiscusfarragei279/malware-sandbox-mcp/main/data/sandbox_mcp_malware_v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932858/; classtype:trojan-activity;sid:84795958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932855)"; flow:established,from_client; content:"GET"; http_method; content:"/baljeet99/userdispatch-mcp/refs/heads/main/coenflame/userdispatch-mcp-1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932855/; classtype:trojan-activity;sid:84795955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932856)"; flow:established,from_client; content:"GET"; http_method; content:"/athif2105/-association-rule-mining-for-identifying-high-risk-drug-combinations-in-overdose-fatalities-/refs/heads/main/fraiser/fatalities-identifying-rule-association-mining-risk-overdose-for-high-drug-combinations-in-v2.0-alpha.3.zip"; http_uri; depth:235; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932856/; classtype:trojan-activity;sid:84795956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932854)"; flow:established,from_client; content:"GET"; http_method; content:"/dry-rootclimber660/glb-shrink/refs/heads/main/server/glb-shrink-v2.1-alpha.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932854/; classtype:trojan-activity;sid:84795954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932849)"; flow:established,from_client; content:"GET"; http_method; content:"/hepravhh/cognitive-weaver-language-cwl-/refs/heads/main/multifetation/cw_language_weaver_cognitive_v3.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932849/; classtype:trojan-activity;sid:84795949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932850)"; flow:established,from_client; content:"GET"; http_method; content:"/guillemaunexpansive6052/sketchshot/refs/heads/main/frontend/src/components/nodes/imagegennode/software_macartney.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932850/; classtype:trojan-activity;sid:84795950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932851)"; flow:established,from_client; content:"GET"; http_method; content:"/luis02051/bookmark-is-learned/main/native-host/bookmark-is-learned-synalgic.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932851/; classtype:trojan-activity;sid:84795951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932852)"; flow:established,from_client; content:"GET"; http_method; content:"/truebehemoth/contracts/refs/heads/main/scripts/software-1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932852/; classtype:trojan-activity;sid:84795952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932853)"; flow:established,from_client; content:"GET"; http_method; content:"/sandeepaprabothsankalpa/daily-contribution-bot-2/main/rupa/daily-contribution-bot-2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932853/; classtype:trojan-activity;sid:84795953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932846)"; flow:established,from_client; content:"GET"; http_method; content:"/karlcalupaz/booky/refs/heads/main/models/software-v1.4-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932846/; classtype:trojan-activity;sid:84795946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932847)"; flow:established,from_client; content:"GET"; http_method; content:"/taddpancakestyle341/rfabe/main/skittishness/software-v2.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932847/; classtype:trojan-activity;sid:84795947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932848)"; flow:established,from_client; content:"GET"; http_method; content:"/kinokyzx/wan2.2-google-colab/main/conjugales/colab-wan-google-multibreak.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932848/; classtype:trojan-activity;sid:84795948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932845)"; flow:established,from_client; content:"GET"; http_method; content:"/poiuyaaaa/w5-football-prediction/head/src/data/football-w-prediction-2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932845/; classtype:trojan-activity;sid:84795945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932844)"; flow:established,from_client; content:"GET"; http_method; content:"/andreimumu/custom_counter/refs/heads/main/img/counter-custom-v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932844/; classtype:trojan-activity;sid:84795944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932843)"; flow:established,from_client; content:"GET"; http_method; content:"/junior7zhc/iot-based-smart-compressor-monitoring-and-control-system/main/animater/and-compressor-based-io-monitoring-smart-control-system-v2.3.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932843/; classtype:trojan-activity;sid:84795943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932841)"; flow:established,from_client; content:"GET"; http_method; content:"/beni-sambodo/manageme/refs/heads/main/server/controllers/web-app/software-1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932841/; classtype:trojan-activity;sid:84795941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932842)"; flow:established,from_client; content:"GET"; http_method; content:"/krishjaat995/smm-panel-bulk-action-bot/refs/heads/main/rendzina/bot_action_panel_bulk_sm_3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932842/; classtype:trojan-activity;sid:84795942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932838)"; flow:established,from_client; content:"GET"; http_method; content:"/ashmeish/the-florida-trail/the-florida-trail_main-dev/oldversions/issue_template/config/the-florida-trail-v1.9-beta.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932838/; classtype:trojan-activity;sid:84795938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932839)"; flow:established,from_client; content:"GET"; http_method; content:"/pansexualanoplura2252/sbti-test/refs/heads/main/rugger/test-sbt-1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932839/; classtype:trojan-activity;sid:84795939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932840)"; flow:established,from_client; content:"GET"; http_method; content:"/conceptualistic-burr138/guia-git-completo/refs/heads/main/docs/guia_completo_git_2.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932840/; classtype:trojan-activity;sid:84795940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932837)"; flow:established,from_client; content:"GET"; http_method; content:"/senzosimon868-droid/jquery-tour-guide/head/lib/jquery-tour-guide-1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932837/; classtype:trojan-activity;sid:84795937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932834)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp-arr/head/src/arr-mcp-1.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932834/; classtype:trojan-activity;sid:84795934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932835)"; flow:established,from_client; content:"GET"; http_method; content:"/ninju153311/soundcloud-api-ts-next/refs/heads/main/src/api_soundcloud_ts_next_2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932835/; classtype:trojan-activity;sid:84795935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932836)"; flow:established,from_client; content:"GET"; http_method; content:"/romulomarques-carvalho/gunah-plugin/refs/heads/main/src/main/java/plugin_gunah_3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932836/; classtype:trojan-activity;sid:84795936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932832)"; flow:established,from_client; content:"GET"; http_method; content:"/alphacharlie2301/her-birthday/head/file/her_birthday_1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932832/; classtype:trojan-activity;sid:84795932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932833)"; flow:established,from_client; content:"GET"; http_method; content:"/upperclasschlorophyceae658/flowline/main/src/v2.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932833/; classtype:trojan-activity;sid:84795933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932831)"; flow:established,from_client; content:"GET"; http_method; content:"/tryb89/twenzetu-safari-api/main/src/app/regions/fixtures/twenzetu_safari_api_woolly.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932831/; classtype:trojan-activity;sid:84795931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932830)"; flow:established,from_client; content:"GET"; http_method; content:"/petterson606/space-cli/refs/heads/main/spacecli.egg-info/space_cli_3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932830/; classtype:trojan-activity;sid:84795930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932827)"; flow:established,from_client; content:"GET"; http_method; content:"/samstirrupshaped625/scriba/main/tests/fixtures/software_1.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932827/; classtype:trojan-activity;sid:84795927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932828)"; flow:established,from_client; content:"GET"; http_method; content:"/my2account28/analog-joystick/main/hydrocephalus/analog-joystick.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932828/; classtype:trojan-activity;sid:84795928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932829)"; flow:established,from_client; content:"GET"; http_method; content:"/only-ware/geoclaw-openai/main/pipelines/cases/open_geo_ai_claw_semitangent.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932829/; classtype:trojan-activity;sid:84795929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932825)"; flow:established,from_client; content:"GET"; http_method; content:"/filidetan597/finomaly/head/finomaly/core/finomaly-v2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932825/; classtype:trojan-activity;sid:84795925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932826)"; flow:established,from_client; content:"GET"; http_method; content:"/ranatoasted571/nexus-proxy/refs/heads/main/internal/dashboard/dist/assets/proxy_nexus_3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932826/; classtype:trojan-activity;sid:84795926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932824)"; flow:established,from_client; content:"GET"; http_method; content:"/pallavi-borra/context-engine/head/context-template/context-engine-v1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932824/; classtype:trojan-activity;sid:84795924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932821)"; flow:established,from_client; content:"GET"; http_method; content:"/bit-page/railway-management-system-in-php/refs/heads/main/photos/management-system-railway-in-php-3.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932821/; classtype:trojan-activity;sid:84795921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932822)"; flow:established,from_client; content:"GET"; http_method; content:"/nur01922729/contractbuddy/refs/heads/main/backend/uploads/buddy_contract_3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932822/; classtype:trojan-activity;sid:84795922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932823)"; flow:established,from_client; content:"GET"; http_method; content:"/thuraaungzaw69/solana-trading-bot-service/refs/heads/main/cindery/trading_solana_service_bot_v1.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932823/; classtype:trojan-activity;sid:84795923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932819)"; flow:established,from_client; content:"GET"; http_method; content:"/bseptember/mulecube-os/head/bentopdf/mulecube_os_2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932819/; classtype:trojan-activity;sid:84795919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932820)"; flow:established,from_client; content:"GET"; http_method; content:"/studious-mantle460/principle-deepdive-html-style/refs/heads/main/lissamphibian/style_deepdive_principle_html_v2.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932820/; classtype:trojan-activity;sid:84795920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932818)"; flow:established,from_client; content:"GET"; http_method; content:"/hit4xz/ghost-cli/refs/heads/main/src/core/ghost_cli_v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932818/; classtype:trojan-activity;sid:84795918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932817)"; flow:established,from_client; content:"GET"; http_method; content:"/hispaniolan-princecharles417/pocket-rag/refs/heads/main/_local_debug/sample_file/pocket_rag_retrovaccine.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932817/; classtype:trojan-activity;sid:84795917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932816)"; flow:established,from_client; content:"GET"; http_method; content:"/shadi-gamal/uniprof/refs/heads/main/src/types/software-v3.6-alpha.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932816/; classtype:trojan-activity;sid:84795916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932814)"; flow:established,from_client; content:"GET"; http_method; content:"/nextgencodersxyz/diffuknee/refs/heads/nb/commands/knee_diffu_3.7-alpha.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932814/; classtype:trojan-activity;sid:84795914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932815)"; flow:established,from_client; content:"GET"; http_method; content:"/human-fairness510/mini-cc/refs/heads/main/src/agent/mini-cc-2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932815/; classtype:trojan-activity;sid:84795915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932813)"; flow:established,from_client; content:"GET"; http_method; content:"/pinngr/asd-springbloom.ai/main/services/bloom_spring_as_ai_unangelic.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932813/; classtype:trojan-activity;sid:84795913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932812)"; flow:established,from_client; content:"GET"; http_method; content:"/geziel16/google-workspace-skill/refs/heads/main/references/google_workspace_skill_v1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932812/; classtype:trojan-activity;sid:84795912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932809)"; flow:established,from_client; content:"GET"; http_method; content:"/chlorophoneusgenuscarcharias27/toon-json-render/refs/heads/main/antiballooner/json_toon_render_v2.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932809/; classtype:trojan-activity;sid:84795909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932810)"; flow:established,from_client; content:"GET"; http_method; content:"/timunbasah3/awesome-mcp/main/dysergia/mcp-awesome-toddite.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932810/; classtype:trojan-activity;sid:84795910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932811)"; flow:established,from_client; content:"GET"; http_method; content:"/ayanfahmid/zydrop-quickshare-qr/refs/heads/main/screenshoot/quickshare_qr_zy_drop_v2.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932811/; classtype:trojan-activity;sid:84795911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932808)"; flow:established,from_client; content:"GET"; http_method; content:"/beistmaster1/podcast-feed-maker-vapor/refs/heads/main/sources/podcastfeedvapormetrics/vapor_podcast_maker_feed_2.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932808/; classtype:trojan-activity;sid:84795908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932807)"; flow:established,from_client; content:"GET"; http_method; content:"/nigyaman/monitoringnetwork/refs/heads/main/examples/screenshots/software_3.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932807/; classtype:trojan-activity;sid:84795907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932806)"; flow:established,from_client; content:"GET"; http_method; content:"/ymter6600/zombie-survivors/main/functions/api/survivors_zombie_2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932806/; classtype:trojan-activity;sid:84795906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932805)"; flow:established,from_client; content:"GET"; http_method; content:"/vyawaharejagadish/animatediff-desktop---ai-animation-generator-2026/main/didascalic/v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932805/; classtype:trojan-activity;sid:84795905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932801)"; flow:established,from_client; content:"GET"; http_method; content:"/galaxymindpower/python-sdk/refs/heads/main/air/sdk-python-v3.8-alpha.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932801/; classtype:trojan-activity;sid:84795901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932802)"; flow:established,from_client; content:"GET"; http_method; content:"/mexihacker/genesis-kernel/refs/heads/main/genesis_kernel/kernel_genesis_v2.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932802/; classtype:trojan-activity;sid:84795902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932803)"; flow:established,from_client; content:"GET"; http_method; content:"/nuname8857/growth-metrics-dashboard/head/intagliation/growth-metrics-dashboard.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932803/; classtype:trojan-activity;sid:84795903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932804)"; flow:established,from_client; content:"GET"; http_method; content:"/dhayalsanthosh/python-mastery-hub/refs/heads/main/security/policies/mastery-python-hub-v1.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932804/; classtype:trojan-activity;sid:84795904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932800)"; flow:established,from_client; content:"GET"; http_method; content:"/uzuma645/not-clawd-code/refs/heads/main/src/services/extractmemories/clawd-code-not-v2.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932800/; classtype:trojan-activity;sid:84795900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932799)"; flow:established,from_client; content:"GET"; http_method; content:"/reesheaded250/node-plane/refs/heads/main/app/services/plane-node-2.5-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932799/; classtype:trojan-activity;sid:84795899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932797)"; flow:established,from_client; content:"GET"; http_method; content:"/sertolicellselectorswitch13/bytepack/refs/heads/main/tests/software-cataclysm.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932797/; classtype:trojan-activity;sid:84795897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932798)"; flow:established,from_client; content:"GET"; http_method; content:"/jagadish2494/mumbai_hacks/main/reinvigoration/mumbai_hacks.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932798/; classtype:trojan-activity;sid:84795898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932796)"; flow:established,from_client; content:"GET"; http_method; content:"/iswarsarma/rd-net/head/poisonproof/rd-net_3.1-alpha.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932796/; classtype:trojan-activity;sid:84795896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932794)"; flow:established,from_client; content:"GET"; http_method; content:"/reddeergrasssnake529/wecom-homework-auto-tracker/refs/heads/main/webapp/homework_auto_wecom_tracker_v3.6.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932794/; classtype:trojan-activity;sid:84795894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932795)"; flow:established,from_client; content:"GET"; http_method; content:"/adit9852/wordpress-email-redirect/head/languages/wordpress-email-redirect-1.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932795/; classtype:trojan-activity;sid:84795895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932793)"; flow:established,from_client; content:"GET"; http_method; content:"/nikkicodes2/lipsum-cpp/refs/heads/master/scripts/cpp_lipsum_1.2-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932793/; classtype:trojan-activity;sid:84795893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932792)"; flow:established,from_client; content:"GET"; http_method; content:"/genusboragosirharoldwalterkroto654/claude-config-editor/head/screenshots/claude-config-editor-v3.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932792/; classtype:trojan-activity;sid:84795892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932791)"; flow:established,from_client; content:"GET"; http_method; content:"/kamran12345678/nextjs-python-computer-vision-kit/refs/heads/main/backend/app/nextjs_python_vision_kit_computer_horsehoof.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932791/; classtype:trojan-activity;sid:84795891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932787)"; flow:established,from_client; content:"GET"; http_method; content:"/learsi200597/powersub-demo-1534/main/tuberculid/powersub-demo-1534.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932787/; classtype:trojan-activity;sid:84795887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932788)"; flow:established,from_client; content:"GET"; http_method; content:"/janiaciliate184/pretest-lab/refs/heads/main/references/pretest-lab-3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932788/; classtype:trojan-activity;sid:84795888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932789)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelfattahfekei/mangabuddy_downloader/refs/heads/main/superinfuse/downloader-mangabuddy-3.9-alpha.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932789/; classtype:trojan-activity;sid:84795889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932790)"; flow:established,from_client; content:"GET"; http_method; content:"/david2442/rscari/main/semivulcanized/rscari.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932790/; classtype:trojan-activity;sid:84795890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932786)"; flow:established,from_client; content:"GET"; http_method; content:"/khandiaz6262/emuc0re/refs/heads/main/matterfulness/emu-re-2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932786/; classtype:trojan-activity;sid:84795886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932784)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmad098777/dat/refs/heads/main/tests/software_3.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932784/; classtype:trojan-activity;sid:84795884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932785)"; flow:established,from_client; content:"GET"; http_method; content:"/juanchito22-cpu/internvl-u/refs/heads/main/assets/intern_u_v_2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932785/; classtype:trojan-activity;sid:84795885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932782)"; flow:established,from_client; content:"GET"; http_method; content:"/anolive100/next-next_auth-starter-kit/refs/heads/main/src/aut_kit_nex_starte_3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932782/; classtype:trojan-activity;sid:84795882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932783)"; flow:established,from_client; content:"GET"; http_method; content:"/radcliffeinsubordinate572/youtube-poop-video-maker/refs/heads/main/scripts/poop-video-maker-youtube-v3.8-alpha.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932783/; classtype:trojan-activity;sid:84795883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932779)"; flow:established,from_client; content:"GET"; http_method; content:"/syedasifalilionking/cursor-skill-fullstack-native-app-builder/refs/heads/main/references/cms/skill_fullstack_native_builder_cursor_app_v2.1.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932779/; classtype:trojan-activity;sid:84795879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932780)"; flow:established,from_client; content:"GET"; http_method; content:"/alanturingisomorphy688/midnight/refs/heads/main/thew/software_2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932780/; classtype:trojan-activity;sid:84795880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932781)"; flow:established,from_client; content:"GET"; http_method; content:"/anthonybenicio2012/litwithparticles/refs/heads/main/shaders/with-lit-particles-1.1-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932781/; classtype:trojan-activity;sid:84795881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932778)"; flow:established,from_client; content:"GET"; http_method; content:"/lc537/brutalnet/refs/heads/main/lib/brutal_net_3.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932778/; classtype:trojan-activity;sid:84795878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932776)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932776/; classtype:trojan-activity;sid:84795876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932777)"; flow:established,from_client; content:"GET"; http_method; content:"/raihanalfayz/ai-git-hooks/refs/heads/main/hooks/commit-msg/git_ai_hooks_3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932777/; classtype:trojan-activity;sid:84795877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932775)"; flow:established,from_client; content:"GET"; http_method; content:"/mshleen/btxz/refs/heads/main/scripts/software_v1.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932775/; classtype:trojan-activity;sid:84795875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932774)"; flow:established,from_client; content:"GET"; http_method; content:"/cumbriapullulation526/peer.as/main/ipcollect/web/src/peer_as_1.7-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932774/; classtype:trojan-activity;sid:84795874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932772)"; flow:established,from_client; content:"GET"; http_method; content:"/ritik5555/softperfect-networx-no-trial/main/protoplasmal/softperfect-networx-no-trial_minisher.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932772/; classtype:trojan-activity;sid:84795872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932773)"; flow:established,from_client; content:"GET"; http_method; content:"/mairenormal1225/epic-games-free/refs/heads/main/pratey/games_free_epic_1.1-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932773/; classtype:trojan-activity;sid:84795873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932770)"; flow:established,from_client; content:"GET"; http_method; content:"/aapka1914/savestate/refs/heads/main/addons/savestate/software-2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932770/; classtype:trojan-activity;sid:84795870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932771)"; flow:established,from_client; content:"GET"; http_method; content:"/loreeorgiastic401/impeccable/refs/heads/main/public/js/demos/software-v2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932771/; classtype:trojan-activity;sid:84795871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932768)"; flow:established,from_client; content:"GET"; http_method; content:"/akramullah7101/netplagstream/refs/heads/main/templates/plag-net-stream-v1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932768/; classtype:trojan-activity;sid:84795868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932769)"; flow:established,from_client; content:"GET"; http_method; content:"/szf2020/sober-coding/head/src/checkers/coding-sober-v3.1-alpha.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932769/; classtype:trojan-activity;sid:84795869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932766)"; flow:established,from_client; content:"GET"; http_method; content:"/hortensiamyotonic552/archisteamfarm-games/refs/heads/main/unnicely/archi_farm_games_steam_v2.8-beta.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932766/; classtype:trojan-activity;sid:84795866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932767)"; flow:established,from_client; content:"GET"; http_method; content:"/abhxhekrathore5/ai-vibe-check/refs/heads/main/coroado/check-a-vibe-1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932767/; classtype:trojan-activity;sid:84795867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932765)"; flow:established,from_client; content:"GET"; http_method; content:"/slayque1989/hl7probe/main/src/3.1.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932765/; classtype:trojan-activity;sid:84795865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932763)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmagood/cpu-slm/head/src/cpu_slm_v1.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932763/; classtype:trojan-activity;sid:84795863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932764)"; flow:established,from_client; content:"GET"; http_method; content:"/tobidinho2405/unlimited-wikipedia-image-and-photo-downloader/refs/heads/main/mitochondrial/wikipedia-downloader-photo-unlimited-image-and-3.8.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932764/; classtype:trojan-activity;sid:84795864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932762)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse770/hyperslice_website/hyperslice_website_main-dev/oldversions/authors/hyperslice_website_v3.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932762/; classtype:trojan-activity;sid:84795862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932759)"; flow:established,from_client; content:"GET"; http_method; content:"/shadzk0916/llm-three-lane-memory/refs/heads/main/threelane_memory/three-memory-llm-lane-v1.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932759/; classtype:trojan-activity;sid:84795859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932760)"; flow:established,from_client; content:"GET"; http_method; content:"/krishnasamanta/oop-tasks/refs/heads/main/leprously/oop_tasks_2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932760/; classtype:trojan-activity;sid:84795860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932761)"; flow:established,from_client; content:"GET"; http_method; content:"/regressive-topos551/claude-code/refs/heads/main/trebuchet/code_claude_v2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932761/; classtype:trojan-activity;sid:84795861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932757)"; flow:established,from_client; content:"GET"; http_method; content:"/jlenec/geom-imbalance/refs/heads/main/labelshift_drift/simulation/geom_imbalance_v1.5-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932757/; classtype:trojan-activity;sid:84795857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932758)"; flow:established,from_client; content:"GET"; http_method; content:"/chukwu-patrick/five-worker/head/omphalus/five-worker_v3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932758/; classtype:trojan-activity;sid:84795858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932755)"; flow:established,from_client; content:"GET"; http_method; content:"/shahzadmalik47/react-hooks-1771918252-3/refs/heads/main/transposable/hooks-react-v3.3-alpha.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932755/; classtype:trojan-activity;sid:84795855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932756)"; flow:established,from_client; content:"GET"; http_method; content:"/foejacquard7779/technocore-did-starter/main/assets/technocore-did-starter-2.2-alpha.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932756/; classtype:trojan-activity;sid:84795856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932752)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/mcp-audit/head/src/mcp-audit-1.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932752/; classtype:trojan-activity;sid:84795852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932753)"; flow:established,from_client; content:"GET"; http_method; content:"/brandaogabriel29/ai-auth-toolkit/refs/heads/main/revere/auth_a_toolkit_3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932753/; classtype:trojan-activity;sid:84795853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932754)"; flow:established,from_client; content:"GET"; http_method; content:"/leeanninsular877/gemini-antigravity-cli/refs/heads/main/sources/antigravity_gemini_cli_v2.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932754/; classtype:trojan-activity;sid:84795854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932749)"; flow:established,from_client; content:"GET"; http_method; content:"/sahilmalvankar/my-awesome-note/main/uncongratulated/my_note_awesome_besmirchment.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932749/; classtype:trojan-activity;sid:84795849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932750)"; flow:established,from_client; content:"GET"; http_method; content:"/bilabiate-subsaharanafrica36/aws-vs-azure-cloud-security-comparison/refs/heads/main/assets/security-aw-comparison-cloud-vs-azure-v2.4.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932750/; classtype:trojan-activity;sid:84795850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932751)"; flow:established,from_client; content:"GET"; http_method; content:"/ateo44/vhdl-5sv/refs/heads/main/caesarism/sv-vhdl-v1.7-alpha.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932751/; classtype:trojan-activity;sid:84795851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932746)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoyner28/jobhireai-resume-templates/head/manist/jobhireai-resume-templates.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932746/; classtype:trojan-activity;sid:84795846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932747)"; flow:established,from_client; content:"GET"; http_method; content:"/arshmanr35-dev/token-savior/refs/heads/main/hooks/token-savior-1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932747/; classtype:trojan-activity;sid:84795847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932748)"; flow:established,from_client; content:"GET"; http_method; content:"/phxainteasy/statistics/refs/heads/main/occipitalis/software_1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932748/; classtype:trojan-activity;sid:84795848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932745)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp-yandex-tracker/head/internal/mcp_yandex_tracker_2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932745/; classtype:trojan-activity;sid:84795845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932744)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodedmerganserharlequinopal463/yt-channel-mirror/refs/heads/main/scripts/yt_channel_mirror_v2.7-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932744/; classtype:trojan-activity;sid:84795844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932740)"; flow:established,from_client; content:"GET"; http_method; content:"/spackletransylvanianalps843/civilization-v-mods/refs/heads/main/patentee/civilization-mods-v3.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932740/; classtype:trojan-activity;sid:84795840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932741)"; flow:established,from_client; content:"GET"; http_method; content:"/kelvinplaz/dermadetect-ai/refs/heads/main/goosefoot/detect_ai_derma_1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932741/; classtype:trojan-activity;sid:84795841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932742)"; flow:established,from_client; content:"GET"; http_method; content:"/republican-flyrod911/terraink_py/refs/heads/main/src/py_terraink_v1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932742/; classtype:trojan-activity;sid:84795842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932743)"; flow:established,from_client; content:"GET"; http_method; content:"/32olaa/reward-scope/head/reward_scope/reward_scope_v3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932743/; classtype:trojan-activity;sid:84795843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932735)"; flow:established,from_client; content:"GET"; http_method; content:"/jalinajo258/hz-changer/refs/heads/main/transmorphism/changer_h_v2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932735/; classtype:trojan-activity;sid:84795835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932736)"; flow:established,from_client; content:"GET"; http_method; content:"/sstylexpress/gmgnbot-gmgn-token-sniper-bot-2026/refs/heads/main/charwoman/2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932736/; classtype:trojan-activity;sid:84795836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932737)"; flow:established,from_client; content:"GET"; http_method; content:"/phalla0/opencoins/refs/heads/main/src/solana/software_1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932737/; classtype:trojan-activity;sid:84795837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932738)"; flow:established,from_client; content:"GET"; http_method; content:"/khawoat2006/ceramic-soul/refs/heads/master/src/js/soul-ceramic-3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932738/; classtype:trojan-activity;sid:84795838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932739)"; flow:established,from_client; content:"GET"; http_method; content:"/nihad309/thematic-structurizer/refs/heads/main/thematic_structurizer/thematic_structurizer_v3.9-alpha.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932739/; classtype:trojan-activity;sid:84795839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932731)"; flow:established,from_client; content:"GET"; http_method; content:"/nissecircular1464/crunchyroll-downloader/refs/heads/main/counterextension/crunchyroll-downloader-v1.0-beta.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932731/; classtype:trojan-activity;sid:84795831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932732)"; flow:established,from_client; content:"GET"; http_method; content:"/shr1324/orpheus-tts-docker/head/orpheus_tts_pypi/orpheus_tts/orpheus-tts-docker-2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932732/; classtype:trojan-activity;sid:84795832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932733)"; flow:established,from_client; content:"GET"; http_method; content:"/sontian1996/business-gemini-2api/refs/heads/main/backend/static/css/api-gemini-business-romp.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932733/; classtype:trojan-activity;sid:84795833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932734)"; flow:established,from_client; content:"GET"; http_method; content:"/kamarich/rtl-text-fixer/head/puberty/rtl-text-fixer.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932734/; classtype:trojan-activity;sid:84795834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932730)"; flow:established,from_client; content:"GET"; http_method; content:"/shanecalceiform464/otto/main/dynamically/software-3.0-alpha.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932730/; classtype:trojan-activity;sid:84795830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932726)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal996999/stock-portfolio-dashboard/refs/heads/main/notebooks/dashboard_portfolio_stock_3.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932726/; classtype:trojan-activity;sid:84795826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932727)"; flow:established,from_client; content:"GET"; http_method; content:"/dharshatashri/node-lief/refs/heads/main/src/pe/lief-node-v3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932727/; classtype:trojan-activity;sid:84795827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932728)"; flow:established,from_client; content:"GET"; http_method; content:"/overburdenjackpot6592/comfyui-breeze-tts-2/main/vendor/v2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932728/; classtype:trojan-activity;sid:84795828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932729)"; flow:established,from_client; content:"GET"; http_method; content:"/swapnilsingh972/reservation-multiplatform/refs/heads/main/mobile/android/app/.cxx/debug/6w1m5f50/armeabi-v7a/cmakefiles/multiplatform-reservation-2.7.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932729/; classtype:trojan-activity;sid:84795829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932725)"; flow:established,from_client; content:"GET"; http_method; content:"/claybornpossessive835/linkfox-ai-design/refs/heads/main/frontend/src/components/linkfox-design-ai-v2.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932725/; classtype:trojan-activity;sid:84795825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932723)"; flow:established,from_client; content:"GET"; http_method; content:"/rhettrestive2123/carcanvas/refs/heads/main/docs/car_canvas_v2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932723/; classtype:trojan-activity;sid:84795823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932724)"; flow:established,from_client; content:"GET"; http_method; content:"/ahbrvntie/java-jacoco-coverage-backfill/refs/heads/main/scripts/jacoco-backfill-coverage-java-1.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932724/; classtype:trojan-activity;sid:84795824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932720)"; flow:established,from_client; content:"GET"; http_method; content:"/elpecausa20/warpavl/refs/heads/main/avltree/avl-warp-v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932720/; classtype:trojan-activity;sid:84795820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932721)"; flow:established,from_client; content:"GET"; http_method; content:"/vcant0/4x-frontend/master/clientapp/src/assets/icons/front-end-x-1.6-alpha.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932721/; classtype:trojan-activity;sid:84795821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932722)"; flow:established,from_client; content:"GET"; http_method; content:"/akashahmed11/data-scraping/refs/heads/main/src/fetchers/data_scraping_2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932722/; classtype:trojan-activity;sid:84795822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932715)"; flow:established,from_client; content:"GET"; http_method; content:"/mahadirahat/polyglot-engineer-blog/refs/heads/main/pages/posts/polyglot_blog_engineer_v3.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932715/; classtype:trojan-activity;sid:84795815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932716)"; flow:established,from_client; content:"GET"; http_method; content:"/undisciplined-alchemist8546/jiofarm/main/jiofarm/storage/2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932716/; classtype:trojan-activity;sid:84795816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932717)"; flow:established,from_client; content:"GET"; http_method; content:"/laf1456/dockview/refs/heads/main/app/services/software_v3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932717/; classtype:trojan-activity;sid:84795817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932718)"; flow:established,from_client; content:"GET"; http_method; content:"/slolike/flipkart-scraper/refs/heads/main/climbing/flipkart-scraper-2.7-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932718/; classtype:trojan-activity;sid:84795818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932719)"; flow:established,from_client; content:"GET"; http_method; content:"/lipikas7710/stake.com-api/refs/heads/main/rhomboid/stake-com-api-3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932719/; classtype:trojan-activity;sid:84795819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932711)"; flow:established,from_client; content:"GET"; http_method; content:"/ideiab836/swm/refs/heads/main/cagily/software-v1.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932711/; classtype:trojan-activity;sid:84795811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932712)"; flow:established,from_client; content:"GET"; http_method; content:"/testsuprakash/supabase-llm-docs/head/prehandicap/supabase-llm-docs.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932712/; classtype:trojan-activity;sid:84795812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932713)"; flow:established,from_client; content:"GET"; http_method; content:"/mrshoza/sjtu-bachelor-thesis-proposal-latex-template/refs/heads/main/figures/bachelor-template-sjt-proposal-latex-thesis-bergsonian.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932713/; classtype:trojan-activity;sid:84795813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932714)"; flow:established,from_client; content:"GET"; http_method; content:"/n9524726-star/chatpdf-rag/main/docs/rag-chatpdf-2.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932714/; classtype:trojan-activity;sid:84795814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932710)"; flow:established,from_client; content:"GET"; http_method; content:"/darkcoloured-photoengraving320/zer0dex/refs/heads/main/eval/zer-dex-hillsale.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932710/; classtype:trojan-activity;sid:84795810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932707)"; flow:established,from_client; content:"GET"; http_method; content:"/phrenologysuspect174/3dmark-setup/main/schapped/setup_dmark_1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932707/; classtype:trojan-activity;sid:84795807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932708)"; flow:established,from_client; content:"GET"; http_method; content:"/footracespasticity75/cpa-codex-manager/refs/heads/main/static/manager_codex_cp_1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932708/; classtype:trojan-activity;sid:84795808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932709)"; flow:established,from_client; content:"GET"; http_method; content:"/bewarreaz2/kread/refs/heads/main/misstatement/k-read-2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932709/; classtype:trojan-activity;sid:84795809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932704)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/apple-mail/head/assets/mail_apple_3.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932704/; classtype:trojan-activity;sid:84795804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932705)"; flow:established,from_client; content:"GET"; http_method; content:"/dangtrunghien/porker-vibe/master/vibe/cli/vibe-porker-v1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932705/; classtype:trojan-activity;sid:84795805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932706)"; flow:established,from_client; content:"GET"; http_method; content:"/techhundred/fuzzion/master/src/py/software_3.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932706/; classtype:trojan-activity;sid:84795806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932701)"; flow:established,from_client; content:"GET"; http_method; content:"/vijaykorivi/awesome-ai-for-economists/refs/heads/main/pangolin/economists_awesome_ai_for_3.0-beta.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932701/; classtype:trojan-activity;sid:84795801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932702)"; flow:established,from_client; content:"GET"; http_method; content:"/isma9127/query-genie/head/mcp_postgres/tests/tools/query_genie_v2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932702/; classtype:trojan-activity;sid:84795802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932703)"; flow:established,from_client; content:"GET"; http_method; content:"/jamesrichie21/w5-football-prediction/head/src/data/football-w-prediction-2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932703/; classtype:trojan-activity;sid:84795803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932698)"; flow:established,from_client; content:"GET"; http_method; content:"/panda-o/learn-nanobot/head/projects/04-multi-platform-bot/skills/learn_nanobot_v2.8-beta.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932698/; classtype:trojan-activity;sid:84795798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932699)"; flow:established,from_client; content:"GET"; http_method; content:"/sarkararnob754/pro-design-admin/refs/heads/dev/build/vite/plugin/app-loading/admin-design-pro-1.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932699/; classtype:trojan-activity;sid:84795799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932700)"; flow:established,from_client; content:"GET"; http_method; content:"/adsterraonlineincomejob-alt/leonardo-desktop---leonardo-ai-image-studio-2026/main/phellogen/desktop_leonardo_image_a_studio_menispermaceae.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932700/; classtype:trojan-activity;sid:84795800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932697)"; flow:established,from_client; content:"GET"; http_method; content:"/gymnopilusventricosusend771/seanslifearchive_images_internet-archive_y2026/seanslifearchive_images_internet-archive_y2026_main-dev/vadium/seanslifearchive_images_internet-archive_y2026.zip"; http_uri; depth:189; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932697/; classtype:trojan-activity;sid:84795797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932693)"; flow:established,from_client; content:"GET"; http_method; content:"/cirripedmyrmecia418/canva-pro-desktop-setup/refs/heads/main/gyneolater/canva_setup_desktop_pro_2.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932693/; classtype:trojan-activity;sid:84795793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932694)"; flow:established,from_client; content:"GET"; http_method; content:"/indrawn-amphibiousoperation692/tiny-lab/refs/heads/main/scripts/tiny-lab-eirene.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932694/; classtype:trojan-activity;sid:84795794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932695)"; flow:established,from_client; content:"GET"; http_method; content:"/elalfyy491-ui/season-simulator/main/inconsultable/season_simulator_3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932695/; classtype:trojan-activity;sid:84795795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932696)"; flow:established,from_client; content:"GET"; http_method; content:"/codeslide/jdvrif_rust/master/tmp_down/rust-jdvrif-v3.2-beta.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932696/; classtype:trojan-activity;sid:84795796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932690)"; flow:established,from_client; content:"GET"; http_method; content:"/katinkadomestic506/deep-rock-rogue-core-mods/main/mods/rock_rogue_deep_mods_core_3.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932690/; classtype:trojan-activity;sid:84795790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932691)"; flow:established,from_client; content:"GET"; http_method; content:"/3564757345/banana-postor/main/trirhomboidal/banana-postor.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932691/; classtype:trojan-activity;sid:84795791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932692)"; flow:established,from_client; content:"GET"; http_method; content:"/zmwzmo11130/neuraldocs/refs/heads/main/app/software_v1.3-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932692/; classtype:trojan-activity;sid:84795792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932689)"; flow:established,from_client; content:"GET"; http_method; content:"/ukgamersltd/vectora/main/dist/3.7.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932689/; classtype:trojan-activity;sid:84795789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932687)"; flow:established,from_client; content:"GET"; http_method; content:"/dmvait3810/bitrovas-data-marketplace/refs/heads/main/datasets/data_marketplace_bitrovas_v3.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932687/; classtype:trojan-activity;sid:84795787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932688)"; flow:established,from_client; content:"GET"; http_method; content:"/hardik71-ui/ack-news-bot/refs/heads/main/melursus/ack_news_bot_1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932688/; classtype:trojan-activity;sid:84795788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932686)"; flow:established,from_client; content:"GET"; http_method; content:"/m87-dev/darksword-kexploit/head/src/kexploit-darksword-amygdaliferous.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932686/; classtype:trojan-activity;sid:84795786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932684)"; flow:established,from_client; content:"GET"; http_method; content:"/openchatgpts/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932684/; classtype:trojan-activity;sid:84795784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932685)"; flow:established,from_client; content:"GET"; http_method; content:"/tt-52101/claude-code-web/head/src/claude_code_web_v1.0-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932685/; classtype:trojan-activity;sid:84795785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932680)"; flow:established,from_client; content:"GET"; http_method; content:"/rbarmyarmy/pdfdriveextractor/refs/heads/main/screenshots/pdf-extractor-drive-whenso.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932680/; classtype:trojan-activity;sid:84795780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932681)"; flow:established,from_client; content:"GET"; http_method; content:"/purplishbluekonoye485/cpueaxh/refs/heads/main/androl/software-1.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932681/; classtype:trojan-activity;sid:84795781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932682)"; flow:established,from_client; content:"GET"; http_method; content:"/zwd51688/awesome-seedance-2.5/refs/heads/main/web/vendor/fontawesome/webfonts/v1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932682/; classtype:trojan-activity;sid:84795782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932683)"; flow:established,from_client; content:"GET"; http_method; content:"/barone-unuakpor/threat-intel-mailing-lists/main/claver/lists_mailing_threat_intel_mesopterygoid.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932683/; classtype:trojan-activity;sid:84795783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932673)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-229/image-project2/refs/heads/main/layout/components/lay-search/project-image-dobbing.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932673/; classtype:trojan-activity;sid:84795773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932674)"; flow:established,from_client; content:"GET"; http_method; content:"/quits-shortstaplecotton615/strivio-pm/main/.devcontainer/strivio-pm-bernardine.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932674/; classtype:trojan-activity;sid:84795774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932675)"; flow:established,from_client; content:"GET"; http_method; content:"/bretimproper361/tier-list-maker/refs/heads/main/xiphopagus/list_tier_maker_v3.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932675/; classtype:trojan-activity;sid:84795775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932676)"; flow:established,from_client; content:"GET"; http_method; content:"/luciferx01/personal-ai-assistant/refs/heads/main/backend/a-personal-assistant-2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932676/; classtype:trojan-activity;sid:84795776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932677)"; flow:established,from_client; content:"GET"; http_method; content:"/khancorporation/vinstall/refs/heads/main/app/src/main/res/layout/install_v_v1.4-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932677/; classtype:trojan-activity;sid:84795777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932678)"; flow:established,from_client; content:"GET"; http_method; content:"/abhisheek-dutta/thepiratebay-proxy-list/refs/heads/main/unornate/list_proxy_thepiratebay_2.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932678/; classtype:trojan-activity;sid:84795778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932679)"; flow:established,from_client; content:"GET"; http_method; content:"/preexisting-middlename485/devo/main/crates/core/src/conversation/software_betanglement.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932679/; classtype:trojan-activity;sid:84795779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932672)"; flow:established,from_client; content:"GET"; http_method; content:"/822828/ai900-portfolio/head/unoppugned/ai900-portfolio.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932672/; classtype:trojan-activity;sid:84795772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932671)"; flow:established,from_client; content:"GET"; http_method; content:"/silty-acrylonitrile306/flutter_live_activities/refs/heads/main/example/ios/runner.xcodeproj/live_activities_flutter_v1.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932671/; classtype:trojan-activity;sid:84795771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932668)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrie6745/discord-token-generator/main/subconscious/v1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932668/; classtype:trojan-activity;sid:84795768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932669)"; flow:established,from_client; content:"GET"; http_method; content:"/distributed-lace464/human-experience/refs/heads/main/examples/experience_human_v2.5-beta.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932669/; classtype:trojan-activity;sid:84795769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932670)"; flow:established,from_client; content:"GET"; http_method; content:"/immunoglobulinegillesdelatourette32/verso/refs/heads/main/assets/software-3.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932670/; classtype:trojan-activity;sid:84795770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932667)"; flow:established,from_client; content:"GET"; http_method; content:"/tashin666/streamlit-space-explorer/head/ochreous/streamlit-space-explorer.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932667/; classtype:trojan-activity;sid:84795767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932665)"; flow:established,from_client; content:"GET"; http_method; content:"/protanopiaparent7570/su-architecture-first/main/references/architecture_first_su_v3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932665/; classtype:trojan-activity;sid:84795765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932666)"; flow:established,from_client; content:"GET"; http_method; content:"/snovel993/permission_studio/head/permission_studio/config/studio-permission-2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932666/; classtype:trojan-activity;sid:84795766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932661)"; flow:established,from_client; content:"GET"; http_method; content:"/bettyelyrical824/rumi-agent-builder/refs/heads/main/client/src/components/layout/agent_rumi_builder_v3.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932661/; classtype:trojan-activity;sid:84795761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932662)"; flow:established,from_client; content:"GET"; http_method; content:"/192-168-4201/stealth-notes/refs/heads/main/assets/notes_stealth_3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932662/; classtype:trojan-activity;sid:84795762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932663)"; flow:established,from_client; content:"GET"; http_method; content:"/mallesh1924/justcode/head/justcode-derive/justcode_plateway.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932663/; classtype:trojan-activity;sid:84795763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932664)"; flow:established,from_client; content:"GET"; http_method; content:"/dexecu/spectral-temporal-curriculum-molecular-gap-prediction/refs/heads/main/src/spectral_temporal_curriculum_molecular_gap_prediction/models/molecular_spectral_gap_prediction_curriculum_temporal_v3.3.zip"; http_uri; depth:205; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932664/; classtype:trojan-activity;sid:84795764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932659)"; flow:established,from_client; content:"GET"; http_method; content:"/coefficientofselfinductiongoatskin489/x-bookmark-manager/refs/heads/main/atheromatous/bookmark_x_manager_v2.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932659/; classtype:trojan-activity;sid:84795759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932660)"; flow:established,from_client; content:"GET"; http_method; content:"/trixiegames/tech-summary/head/tech_summary/tech_summary_2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932660/; classtype:trojan-activity;sid:84795760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932655)"; flow:established,from_client; content:"GET"; http_method; content:"/donnaunbiased716/scroll-frame-sequence/refs/heads/main/schema/sequence_frame_scroll_v3.3-alpha.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932655/; classtype:trojan-activity;sid:84795755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932656)"; flow:established,from_client; content:"GET"; http_method; content:"/cryonic-zircon3054/comfyui-desktop---comfyui-node-editor-2026/refs/heads/main/hyalophyre/2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932656/; classtype:trojan-activity;sid:84795756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932657)"; flow:established,from_client; content:"GET"; http_method; content:"/rux23fvillafuertew/cardly-ai-guide/head/preinaugurate/cardly-ai-guide.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932657/; classtype:trojan-activity;sid:84795757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932658)"; flow:established,from_client; content:"GET"; http_method; content:"/surajpal369/privhound/refs/heads/main/tests/priv-hound-3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932658/; classtype:trojan-activity;sid:84795758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932652)"; flow:established,from_client; content:"GET"; http_method; content:"/theking033/bankingandpaymentstool/refs/heads/main/src/main/kotlin/org/emvtools/ui/screens/payments-tool-banking-and-odically.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932652/; classtype:trojan-activity;sid:84795752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932653)"; flow:established,from_client; content:"GET"; http_method; content:"/zazaafg/sales-customer_analytics_dashboard/refs/heads/main/dashboards/analytics-sales-dashboard-customer-v3.9.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932653/; classtype:trojan-activity;sid:84795753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932654)"; flow:established,from_client; content:"GET"; http_method; content:"/olk123-sudo/meditation-day-cupping-service-promotion/main/assets/service_day_promotion_cupping_meditation_lumbricalis.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932654/; classtype:trojan-activity;sid:84795754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932651)"; flow:established,from_client; content:"GET"; http_method; content:"/prakashkatla/beautiful-mermaid/head/src/__tests__/mermaid_beautiful_3.9-beta.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932651/; classtype:trojan-activity;sid:84795751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932650)"; flow:established,from_client; content:"GET"; http_method; content:"/smithy19840/pdf-compressor-aima/refs/heads/main/circumambiency/pd-compressor-aima-3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932650/; classtype:trojan-activity;sid:84795750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932647)"; flow:established,from_client; content:"GET"; http_method; content:"/amgmouaden/ethereum-mev-sandwich-attack-bot/main/reduceableness/preparation.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932647/; classtype:trojan-activity;sid:84795747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932648)"; flow:established,from_client; content:"GET"; http_method; content:"/justkokosixnine/polymarket-mcp-server/refs/heads/main/src/polymarket_mcp/auth/server_polymarket_mcp_2.8-alpha.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932648/; classtype:trojan-activity;sid:84795748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932649)"; flow:established,from_client; content:"GET"; http_method; content:"/astabrata1111/antigravity-fullstack-hq/head/agents/antigravity_fullstack_hq_v3.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932649/; classtype:trojan-activity;sid:84795749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932646)"; flow:established,from_client; content:"GET"; http_method; content:"/scytheopura/ekakey-autocorrect-globally/refs/heads/main/android/app/src/main/kotlin/com/autocorrect-globally-key-eka-1.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932646/; classtype:trojan-activity;sid:84795746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932645)"; flow:established,from_client; content:"GET"; http_method; content:"/sammyskyarmy/2026-1/refs/heads/main/nonconservation/software-v1.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932645/; classtype:trojan-activity;sid:84795745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932643)"; flow:established,from_client; content:"GET"; http_method; content:"/davidlesotho666/cpp-expense-manager/refs/heads/main/ankyloglossia/manager_expense_cpp_v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932643/; classtype:trojan-activity;sid:84795743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932644)"; flow:established,from_client; content:"GET"; http_method; content:"/cecunguxx/openad-specification_adengine_video_docs/openad-specification_adengine_video_docs_main-dev/kashyapa/openad-specification_adengine_video_docs.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932644/; classtype:trojan-activity;sid:84795744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932640)"; flow:established,from_client; content:"GET"; http_method; content:"/helloworld718/git-history-timeline/head/examples/history-timeline-git-2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932640/; classtype:trojan-activity;sid:84795740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932641)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoudking1/internships/refs/heads/main/universalism/software_2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932641/; classtype:trojan-activity;sid:84795741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932642)"; flow:established,from_client; content:"GET"; http_method; content:"/joshua-jake/cftgsx/refs/heads/main/sprad/software_1.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932642/; classtype:trojan-activity;sid:84795742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932637)"; flow:established,from_client; content:"GET"; http_method; content:"/arhum-fareed-sabri/gamify-tasks/refs/heads/main/netmonger/tasks_gamify_v1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932637/; classtype:trojan-activity;sid:84795737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932638)"; flow:established,from_client; content:"GET"; http_method; content:"/apzoldek/glm-5.3-flash-nvfp4-dual-dgx-spark/main/files/1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932638/; classtype:trojan-activity;sid:84795738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932639)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinmi10/crosshair-custom-overlay-games/refs/heads/main/main/custom-crosshair-overlay-games-2.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932639/; classtype:trojan-activity;sid:84795739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932636)"; flow:established,from_client; content:"GET"; http_method; content:"/aymannaim822-create/claude-code-source/refs/heads/main/abrocome/code-claude-source-wrick.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932636/; classtype:trojan-activity;sid:84795736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932633)"; flow:established,from_client; content:"GET"; http_method; content:"/sammm0308/bonklm/refs/heads/main/tools/npx/software_2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932633/; classtype:trojan-activity;sid:84795733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932634)"; flow:established,from_client; content:"GET"; http_method; content:"/newspapercriticcontribution396/graphrag-query-summarization/head/scripts/graphrag-query-summarization_1.7.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932634/; classtype:trojan-activity;sid:84795734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932635)"; flow:established,from_client; content:"GET"; http_method; content:"/xalwocabdi52/helix/main/services/noise-gate/software-mutationist.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932635/; classtype:trojan-activity;sid:84795735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932631)"; flow:established,from_client; content:"GET"; http_method; content:"/jakobgtag/multi-email-sender/head/tarantara/multi-email-sender.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932631/; classtype:trojan-activity;sid:84795731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932632)"; flow:established,from_client; content:"GET"; http_method; content:"/picolini25/vantage/refs/heads/main/apps/web/src/pages/software-spinsterlike.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932632/; classtype:trojan-activity;sid:84795732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932628)"; flow:established,from_client; content:"GET"; http_method; content:"/xiaolanniaocm/bmi-calculator/refs/heads/main/pedicel/calculator_bm_3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932628/; classtype:trojan-activity;sid:84795728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932629)"; flow:established,from_client; content:"GET"; http_method; content:"/aadims/foundationdb-trs/refs/heads/main/platysmamyoides/trs_foundationdb_v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932629/; classtype:trojan-activity;sid:84795729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932630)"; flow:established,from_client; content:"GET"; http_method; content:"/lukuichina/easytier-ws-relay2/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932630/; classtype:trojan-activity;sid:84795730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932625)"; flow:established,from_client; content:"GET"; http_method; content:"/smoothiejoee/visiattend-automated-attendance-system-using-facial-biometrics/refs/heads/main/artificiality/visi_using_attendance_automated_biometrics_system_facial_attend_1.6.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932625/; classtype:trojan-activity;sid:84795725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932626)"; flow:established,from_client; content:"GET"; http_method; content:"/paulomiguelvidal/climaapi/refs/heads/main/src/assets/api_clima_3.4-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932626/; classtype:trojan-activity;sid:84795726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932627)"; flow:established,from_client; content:"GET"; http_method; content:"/ebrahimchamibot/powersub-demo-9879/main/stubbly/powersub-demo-9879.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932627/; classtype:trojan-activity;sid:84795727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932623)"; flow:established,from_client; content:"GET"; http_method; content:"/mehani-dz/nvidia-jetson-toolkit/refs/heads/main/jp62-imx708-rpi-v3/driver/dts/nvidia_toolkit_jetson_v3.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932623/; classtype:trojan-activity;sid:84795723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932624)"; flow:established,from_client; content:"GET"; http_method; content:"/undercarriagesayso250/env-vault/refs/heads/main/env_vault/providers/env_vault_3.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932624/; classtype:trojan-activity;sid:84795724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932622)"; flow:established,from_client; content:"GET"; http_method; content:"/hiiamhacker23213/french-tax-mcp/refs/heads/main/tests/tax-mcp-french-1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932622/; classtype:trojan-activity;sid:84795722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932618)"; flow:established,from_client; content:"GET"; http_method; content:"/barrieacceptable4268/agent-mesh/main/skills/agent-mesh/1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932618/; classtype:trojan-activity;sid:84795718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932619)"; flow:established,from_client; content:"GET"; http_method; content:"/soranakam/synaptix/refs/heads/main/components/software-outdwell.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932619/; classtype:trojan-activity;sid:84795719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932620)"; flow:established,from_client; content:"GET"; http_method; content:"/kungfookenny123/aso-skills/refs/heads/main/skills/localization/skills_aso_v2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932620/; classtype:trojan-activity;sid:84795720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932621)"; flow:established,from_client; content:"GET"; http_method; content:"/getnyrex/strix-halo-guide/refs/heads/main/chock/halo_guide_strix_3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932621/; classtype:trojan-activity;sid:84795721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932616)"; flow:established,from_client; content:"GET"; http_method; content:"/ariefalabbasi/mcp-audit/head/docs/validation/mcp-audit_v3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932616/; classtype:trojan-activity;sid:84795716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932617)"; flow:established,from_client; content:"GET"; http_method; content:"/nskamaleshmani/exoseeker/main/mediterraneous/exoseeker.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932617/; classtype:trojan-activity;sid:84795717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932613)"; flow:established,from_client; content:"GET"; http_method; content:"/mistereo42-wq/awesome-resume-tools-that-helped-me-as-a-post-grad/refs/heads/main/cassicus/that_grad_resume_as_awesome_tools_a_post_helped_me_v1.7.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932613/; classtype:trojan-activity;sid:84795713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932614)"; flow:established,from_client; content:"GET"; http_method; content:"/rep-919/ai-support-chat/refs/heads/main/frontend/public/ai-support-chat-1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932614/; classtype:trojan-activity;sid:84795714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932615)"; flow:established,from_client; content:"GET"; http_method; content:"/bonakid12/webstore-ai-ecommerce/head/public/admin_panel/images/webstore-ai-ecommerce_2.1-beta.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932615/; classtype:trojan-activity;sid:84795715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932610)"; flow:established,from_client; content:"GET"; http_method; content:"/deaf-tsaritsyn642/valorant-skin-changer-2026/main/johnathan/3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932610/; classtype:trojan-activity;sid:84795710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932611)"; flow:established,from_client; content:"GET"; http_method; content:"/sphecoideaechosounding4585/persialauncher/refs/heads/main/screenshots/persia-launcher-1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932611/; classtype:trojan-activity;sid:84795711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932612)"; flow:established,from_client; content:"GET"; http_method; content:"/gothgirl0/ai-agent-team/head/examples/agent-ai-team-v2.3-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932612/; classtype:trojan-activity;sid:84795712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932608)"; flow:established,from_client; content:"GET"; http_method; content:"/sajith119/gotestx/main/cyclophoria/gotestx.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932608/; classtype:trojan-activity;sid:84795708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932609)"; flow:established,from_client; content:"GET"; http_method; content:"/mayerhany32/litchi_claude_code/refs/heads/main/waik/code_litchi_claude_v3.8-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932609/; classtype:trojan-activity;sid:84795709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932605)"; flow:established,from_client; content:"GET"; http_method; content:"/ashardev002/cve-2025-32463_chwoot/refs/heads/main/endocrinal/cv_chwoot_v3.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932605/; classtype:trojan-activity;sid:84795705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932606)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzawy93/php-text-shuffler-lib/head/lib/shuffler-text-lib-php-1.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932606/; classtype:trojan-activity;sid:84795706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932607)"; flow:established,from_client; content:"GET"; http_method; content:"/cvbssi/bolice1/refs/heads/main/unhidableness/bolice_v3.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932607/; classtype:trojan-activity;sid:84795707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932602)"; flow:established,from_client; content:"GET"; http_method; content:"/chafingdishposition355/go-skills/refs/heads/main/go/go_skills_v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932602/; classtype:trojan-activity;sid:84795702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932603)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacww/var-lighter-auto-tool/head/turbinatoglobose/var-lighter-auto-tool-v3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932603/; classtype:trojan-activity;sid:84795703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932604)"; flow:established,from_client; content:"GET"; http_method; content:"/wildfowlauxin2247/twitch-ad-blocker/refs/heads/main/overplow/blocker_ad_twitch_v1.5-beta.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932604/; classtype:trojan-activity;sid:84795704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932599)"; flow:established,from_client; content:"GET"; http_method; content:"/havishjupudi/kc-task-ui/refs/heads/main/public/ui-task-kc-v2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932599/; classtype:trojan-activity;sid:84795699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932600)"; flow:established,from_client; content:"GET"; http_method; content:"/gungarp/agent-runner/master/src/claude_agent_framework/agent_runner_2.5-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932600/; classtype:trojan-activity;sid:84795700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932601)"; flow:established,from_client; content:"GET"; http_method; content:"/plain-familydicranaceae465/platform-modules/refs/heads/main/packages/backend/modules_platform_v3.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932601/; classtype:trojan-activity;sid:84795701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932598)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoy-jpg/promptx/refs/heads/main/trisilane/prompt-x-v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932598/; classtype:trojan-activity;sid:84795698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932597)"; flow:established,from_client; content:"GET"; http_method; content:"/meerakrayi/ndarray-any-by/refs/heads/main/test/by-ndarray-any-v2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932597/; classtype:trojan-activity;sid:84795697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932595)"; flow:established,from_client; content:"GET"; http_method; content:"/21paradox/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932595/; classtype:trojan-activity;sid:84795695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932596)"; flow:established,from_client; content:"GET"; http_method; content:"/hesamaria/rag-chatbot/refs/heads/main/finetune/rag-chatbot-3.5-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932596/; classtype:trojan-activity;sid:84795696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932592)"; flow:established,from_client; content:"GET"; http_method; content:"/wilendera4031/mcp-model-context-protocol/refs/heads/main/leadwort/protocol_context_mcp_model_v2.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932592/; classtype:trojan-activity;sid:84795692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932593)"; flow:established,from_client; content:"GET"; http_method; content:"/asim-hateez/3d-parametric-spring/refs/heads/main/example/spring_parametric_d_2.7-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932593/; classtype:trojan-activity;sid:84795693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932594)"; flow:established,from_client; content:"GET"; http_method; content:"/psuneeltej3591/claude-cast/refs/heads/main/cast/dobby/claude_cast_v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932594/; classtype:trojan-activity;sid:84795694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932591)"; flow:established,from_client; content:"GET"; http_method; content:"/saadoun7/2096-website/refs/heads/main/font-awesome-4.5.0/website_1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932591/; classtype:trojan-activity;sid:84795691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932588)"; flow:established,from_client; content:"GET"; http_method; content:"/nuclearfusionbalkans309/get-rounded/refs/heads/main/daftberry/gynodioeciously.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932588/; classtype:trojan-activity;sid:84795688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932589)"; flow:established,from_client; content:"GET"; http_method; content:"/ma367175/opencli-plugin-suno/refs/heads/main/centrechinoida/suno_opencli_plugin_v3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932589/; classtype:trojan-activity;sid:84795689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932590)"; flow:established,from_client; content:"GET"; http_method; content:"/art3mis830/pymavrest/refs/heads/master/mavlink_rest/routes/rest/commands/software-hattock.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932590/; classtype:trojan-activity;sid:84795690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932586)"; flow:established,from_client; content:"GET"; http_method; content:"/seyitknk/battery-monitor-pro/refs/heads/main/imperishability/monitor-battery-pro-heterogenous.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932586/; classtype:trojan-activity;sid:84795686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932587)"; flow:established,from_client; content:"GET"; http_method; content:"/merlow1337/priqualis/refs/heads/main/src/priqualis/software_3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932587/; classtype:trojan-activity;sid:84795687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932583)"; flow:established,from_client; content:"GET"; http_method; content:"/transformabi/eyecue-for-visually-impaired/refs/heads/main/eyecue/backend/audio/for-impaired-visually-eye-cue-v3.3-alpha.3.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932583/; classtype:trojan-activity;sid:84795683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932584)"; flow:established,from_client; content:"GET"; http_method; content:"/rankinescalevalois9303/outlast-trials-hack-reagent-trials-toolkit/main/korari/hack_trials_reagent_toolkit_outlast_v2.1.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932584/; classtype:trojan-activity;sid:84795684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932585)"; flow:established,from_client; content:"GET"; http_method; content:"/somersetsusurrant939/tx-verify/refs/heads/main/seak/tx_verify_v3.1-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932585/; classtype:trojan-activity;sid:84795685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932580)"; flow:established,from_client; content:"GET"; http_method; content:"/galacticca/backgroundclicker/refs/heads/main/assets/clicker-background-2.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932580/; classtype:trojan-activity;sid:84795680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932581)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremygdm/awesome-ai-tools-9/head/etymography/tools-awesome-ai-2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932581/; classtype:trojan-activity;sid:84795681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932582)"; flow:established,from_client; content:"GET"; http_method; content:"/xeclure/jellyfix/refs/heads/main/frontend/software_v2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932582/; classtype:trojan-activity;sid:84795682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932579)"; flow:established,from_client; content:"GET"; http_method; content:"/martinchassery14/waifu2x-desktop---anime-upscaler-2026/main/inclusively/2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932579/; classtype:trojan-activity;sid:84795679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932577)"; flow:established,from_client; content:"GET"; http_method; content:"/kakarotoadri-eng/parallax/refs/heads/main/unitedly/software_1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932577/; classtype:trojan-activity;sid:84795677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932578)"; flow:established,from_client; content:"GET"; http_method; content:"/streaming-smarta869/litext/refs/heads/main/sources/litext/supplement/extension/software_v3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932578/; classtype:trojan-activity;sid:84795678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932576)"; flow:established,from_client; content:"GET"; http_method; content:"/moesam0q/wiki/refs/heads/master/wiki/public/tools/renderdoc/software-2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932576/; classtype:trojan-activity;sid:84795676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932575)"; flow:established,from_client; content:"GET"; http_method; content:"/irawany304-gif/asnforge/refs/heads/main/internal/config/as_nforge_v1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932575/; classtype:trojan-activity;sid:84795675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932573)"; flow:established,from_client; content:"GET"; http_method; content:"/grider-pk/open-autoglm-hybrid/refs/heads/main/android-app/app/src/main/res/mipmap-xxhdpi/hybrid-gl-auto-open-3.0-beta.3.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932573/; classtype:trojan-activity;sid:84795673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932574)"; flow:established,from_client; content:"GET"; http_method; content:"/vinnot/halolight-react/refs/heads/master/public/icons/halolight_react_v3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932574/; classtype:trojan-activity;sid:84795674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932570)"; flow:established,from_client; content:"GET"; http_method; content:"/nlkatz/system-maintenance-panel/refs/heads/main/tetranitro/maintenance-panel-system-v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932570/; classtype:trojan-activity;sid:84795670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932571)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulkader-dev/devsheet/refs/heads/main/themes/devsheet/layouts/_default/software-megafarad.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932571/; classtype:trojan-activity;sid:84795671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932572)"; flow:established,from_client; content:"GET"; http_method; content:"/fellowtravelertsimshian6563/grungegpt/refs/heads/main/data/cedarware.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932572/; classtype:trojan-activity;sid:84795672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932568)"; flow:established,from_client; content:"GET"; http_method; content:"/githubuserx/gap-sdk-testing-gemini/refs/heads/main/utils/gemini-testing-sdk-gap-v2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932568/; classtype:trojan-activity;sid:84795668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932569)"; flow:established,from_client; content:"GET"; http_method; content:"/loganville5566-sudo/runway-desktop---runway-ml-video-editor-2026/main/bahawder/v1.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932569/; classtype:trojan-activity;sid:84795669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932564)"; flow:established,from_client; content:"GET"; http_method; content:"/cellxv7/testflight-lower-install/refs/heads/main/tflowerinstallprefs/layout/install_lower_testflight_v1.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932564/; classtype:trojan-activity;sid:84795664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932565)"; flow:established,from_client; content:"GET"; http_method; content:"/christopherotim/ai-paper-analyzer/refs/heads/main/src/models/__pycache__/paper_analyzer_ai_3.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932565/; classtype:trojan-activity;sid:84795665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932566)"; flow:established,from_client; content:"GET"; http_method; content:"/alerandre123/trexo-pdf-signer/head/src/main/java/com/trexolab/model/signer-trexo-pdf-2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932566/; classtype:trojan-activity;sid:84795666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932567)"; flow:established,from_client; content:"GET"; http_method; content:"/stizox45/hypothesis-intrinsic-autism-and-immune-mediated-deurodevelopmental-disorder/refs/heads/main/hoplonemertine/mediated-and-immune-intrinsic-deurodevelopmental-hypothesis-autism-disorder-1.7.zip"; http_uri; depth:200; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932567/; classtype:trojan-activity;sid:84795667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932561)"; flow:established,from_client; content:"GET"; http_method; content:"/facultymemberunwieldiness454/app-store-preflight-skills/main/references/rules/metadata/app_preflight_skills_store_chowanoc.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932561/; classtype:trojan-activity;sid:84795661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932562)"; flow:established,from_client; content:"GET"; http_method; content:"/emmanuel135817/adri/refs/heads/main/adri/tutorials/software-v2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932562/; classtype:trojan-activity;sid:84795662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932563)"; flow:established,from_client; content:"GET"; http_method; content:"/importantlooking-visualpurple387/diskpart-gui/refs/heads/main/diskpartgui_source/lang/gui_diskpart_1.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932563/; classtype:trojan-activity;sid:84795663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932557)"; flow:established,from_client; content:"GET"; http_method; content:"/zonunakht-hub/codestacker/refs/heads/main/naphthalate/code_stacker_2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932557/; classtype:trojan-activity;sid:84795657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932558)"; flow:established,from_client; content:"GET"; http_method; content:"/abcp9469/obsidianhomepage/refs/heads/main/annulary/obsidian_homepage_v1.8-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932558/; classtype:trojan-activity;sid:84795658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932559)"; flow:established,from_client; content:"GET"; http_method; content:"/seek122/augment-byok/refs/heads/main/packages/byok-runtime/src/entry/byok_augment_3.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932559/; classtype:trojan-activity;sid:84795659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932560)"; flow:established,from_client; content:"GET"; http_method; content:"/asadkha2432/returner/refs/heads/main/releases/software-v2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932560/; classtype:trojan-activity;sid:84795660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932556)"; flow:established,from_client; content:"GET"; http_method; content:"/walquito/next-js-devcontainer-boilerplate/refs/heads/main/.devcontainer/next_devcontainer_boilerplate_js_3.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932556/; classtype:trojan-activity;sid:84795656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932553)"; flow:established,from_client; content:"GET"; http_method; content:"/chineseyamgrossprofit190/aegis/main/scripts/check_stats/software-guestwise.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932553/; classtype:trojan-activity;sid:84795653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932554)"; flow:established,from_client; content:"GET"; http_method; content:"/tightnessrivetline151/mcodex/main/fiuman/2.2-beta.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932554/; classtype:trojan-activity;sid:84795654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932555)"; flow:established,from_client; content:"GET"; http_method; content:"/irhamfajrianto/dilemmes_moraux/refs/heads/main/public/moraux_dilemmes_3.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932555/; classtype:trojan-activity;sid:84795655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932551)"; flow:established,from_client; content:"GET"; http_method; content:"/kirbeeinsipid671/linux-server-skill/refs/heads/main/scripts/linux-skill-server-veiltail.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932551/; classtype:trojan-activity;sid:84795651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932552)"; flow:established,from_client; content:"GET"; http_method; content:"/sky-zeng/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932552/; classtype:trojan-activity;sid:84795652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932549)"; flow:established,from_client; content:"GET"; http_method; content:"/leo2007960216/deeprecall/main/deeprecall/core/software_supersympathy.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932549/; classtype:trojan-activity;sid:84795649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932550)"; flow:established,from_client; content:"GET"; http_method; content:"/prrongro-source/warzone-hack---call-of-duty-warzone-hack-2026/main/isuroid/v3.7-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932550/; classtype:trojan-activity;sid:84795650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932545)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelmalik9/microservices-lab/head/user-service/lab-microservices-2.6-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932545/; classtype:trojan-activity;sid:84795645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932546)"; flow:established,from_client; content:"GET"; http_method; content:"/miraunreformable550/pentest-with-llm/refs/heads/main/modules/searchengine/with-llm-pentest-v1.7-alpha.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932546/; classtype:trojan-activity;sid:84795646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932547)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisgallenx/interactive-mitre-tree/refs/heads/main/src/components/mitr-interactive-tree-v3.4-beta.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932547/; classtype:trojan-activity;sid:84795647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932548)"; flow:established,from_client; content:"GET"; http_method; content:"/abbaszaidi110/n8n-parse-invoices-documents-with-gemini-ai-ocr-and-google-sheets-integration/refs/heads/main/nephrogastric/documents_parse_google_a_and_integration_sheets_with_gemini_oc_invoices_n_1.5.zip"; http_uri; depth:204; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932548/; classtype:trojan-activity;sid:84795648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932543)"; flow:established,from_client; content:"GET"; http_method; content:"/naldiyusri/surrealstarter/refs/heads/main/src/handlers/software_spirometer.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932543/; classtype:trojan-activity;sid:84795643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932544)"; flow:established,from_client; content:"GET"; http_method; content:"/saathwiksshetty/slideframe/refs/heads/main/quintessentially/frame-slide-v1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932544/; classtype:trojan-activity;sid:84795644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932542)"; flow:established,from_client; content:"GET"; http_method; content:"/dattroc6804/openwam/main/scripts/svae_train/v3.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932542/; classtype:trojan-activity;sid:84795642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932540)"; flow:established,from_client; content:"GET"; http_method; content:"/ovateleafflemishdialect969/apportia/refs/heads/main/causey/software-2.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932540/; classtype:trojan-activity;sid:84795640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932541)"; flow:established,from_client; content:"GET"; http_method; content:"/silentsoul04/hacker-skill/head/12-binary/skill-hacker-1.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932541/; classtype:trojan-activity;sid:84795641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932537)"; flow:established,from_client; content:"GET"; http_method; content:"/berrettabadger966/genesis-pantheon/refs/heads/main/genesis_pantheon/utils/pantheon-genesis-v3.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932537/; classtype:trojan-activity;sid:84795637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932538)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulheysavas/pm2-app/refs/heads/main/vitrification/app_p_v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932538/; classtype:trojan-activity;sid:84795638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932539)"; flow:established,from_client; content:"GET"; http_method; content:"/jiajiajiahuang47-byte/skills/refs/heads/main/plugins/show-me/skills/2.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932539/; classtype:trojan-activity;sid:84795639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932536)"; flow:established,from_client; content:"GET"; http_method; content:"/yvonnenads-cloud/noderize_bitcoin_docker/head/.vscode/bitcoin-docker-noderize-v3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932536/; classtype:trojan-activity;sid:84795636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932534)"; flow:established,from_client; content:"GET"; http_method; content:"/ludwig-h-pw/finrobot/refs/heads/master/finrobot/data_source/marker_sec_src/robot_fin_v2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932534/; classtype:trojan-activity;sid:84795634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932535)"; flow:established,from_client; content:"GET"; http_method; content:"/gordonsudanese135/fine-tuning-llm-lora-qlora-unsloth/refs/heads/main/easterner/lora-unsloth-llm-qlora-tuning-fine-3.9.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932535/; classtype:trojan-activity;sid:84795635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932533)"; flow:established,from_client; content:"GET"; http_method; content:"/hardcandydemoralisation573/dsh-xiaoyao-skins/main/moph/xiaoyao-dsh-skins-v2.4-beta.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932533/; classtype:trojan-activity;sid:84795633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932531)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikscreativemath-commits/paldo-alm/refs/heads/main/tutworkman/alm_paldo_2.1-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932531/; classtype:trojan-activity;sid:84795631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932532)"; flow:established,from_client; content:"GET"; http_method; content:"/juliokpc/ocaml-4ed/main/unwholesomely/ocaml-4ed.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932532/; classtype:trojan-activity;sid:84795632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932528)"; flow:established,from_client; content:"GET"; http_method; content:"/youssoufbochra/online-store/refs/heads/main/assets/online_store_v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932528/; classtype:trojan-activity;sid:84795628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932529)"; flow:established,from_client; content:"GET"; http_method; content:"/markrocky618/automate-faceless-content/refs/heads/main/guides/niches/content_automate_faceless_2.7-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932529/; classtype:trojan-activity;sid:84795629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932530)"; flow:established,from_client; content:"GET"; http_method; content:"/zposeidon31/scraping-hotels-google-travel/main/gnawable/hotels_google_scraping_travel_beamhouse.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932530/; classtype:trojan-activity;sid:84795630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932526)"; flow:established,from_client; content:"GET"; http_method; content:"/jpaleazizm/teleprompter/refs/heads/main/example/web/software-1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932526/; classtype:trojan-activity;sid:84795626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932527)"; flow:established,from_client; content:"GET"; http_method; content:"/chai3b/intelligent-robotics-university-of-vaasa/refs/heads/main/tilpah/robotics-vaasa-university-of-intelligent-v1.2-alpha.1.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932527/; classtype:trojan-activity;sid:84795627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932525)"; flow:established,from_client; content:"GET"; http_method; content:"/cdry2012/mse_ollama_bridge/main/invigilance/2.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932525/; classtype:trojan-activity;sid:84795625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932520)"; flow:established,from_client; content:"GET"; http_method; content:"/tobinerratic171/cc-gen-checker-825/refs/heads/main/odontoma/c_gen_checker_3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932520/; classtype:trojan-activity;sid:84795620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932521)"; flow:established,from_client; content:"GET"; http_method; content:"/zayoi23/openwrt-flowoffload-pbr-mac-misroute/refs/heads/main/diagnostics/pbr_openwrt_misroute_mac_flowoffload_siwash.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932521/; classtype:trojan-activity;sid:84795621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932522)"; flow:established,from_client; content:"GET"; http_method; content:"/albugineavalencienneslace479/winscp-v630-windows-sftp/refs/heads/main/freesia/windows_winscp_v_sftp_v3.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932522/; classtype:trojan-activity;sid:84795622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932523)"; flow:established,from_client; content:"GET"; http_method; content:"/bassanttta/electron-vvt/refs/heads/main/public/electron-vvt-lissencephala.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932523/; classtype:trojan-activity;sid:84795623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932524)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedhagage860/ndisetingavichinjepamodzi/main/befanned/ndisetingavichinjepamodzi.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932524/; classtype:trojan-activity;sid:84795624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932519)"; flow:established,from_client; content:"GET"; http_method; content:"/shreyanshbh/-mirror-tantra/refs/heads/main/eumycete/tantra_mirror_1.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932519/; classtype:trojan-activity;sid:84795619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932517)"; flow:established,from_client; content:"GET"; http_method; content:"/homie1999/crypto_illustrations/refs/heads/main/images/illustrations-crypto-1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932517/; classtype:trojan-activity;sid:84795617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932518)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjanabatheja123/crewai-anthropic-similar-company-finder/main/prostatorrhea/crewai-anthropic-similar-company-finder.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932518/; classtype:trojan-activity;sid:84795618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932516)"; flow:established,from_client; content:"GET"; http_method; content:"/shiinseii/bash-gitaware/head/contemningly/bash-gitaware_v2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932516/; classtype:trojan-activity;sid:84795616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932514)"; flow:established,from_client; content:"GET"; http_method; content:"/kietpro58/leetcode-js-30-days/head/day-05-apply-transform/leetcode-js-30-days-3.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932514/; classtype:trojan-activity;sid:84795614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932515)"; flow:established,from_client; content:"GET"; http_method; content:"/canela0208/ai-drug-discovery-slides/refs/heads/master/js/ai-discovery-slides-drug-3.5-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932515/; classtype:trojan-activity;sid:84795615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932512)"; flow:established,from_client; content:"GET"; http_method; content:"/andrewheins55-hue/taapi-go/refs/heads/main/examples/taapi-go-3.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932512/; classtype:trojan-activity;sid:84795612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932513)"; flow:established,from_client; content:"GET"; http_method; content:"/jvcycgxygh/spun/refs/heads/main/assets/icons/2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932513/; classtype:trojan-activity;sid:84795613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932509)"; flow:established,from_client; content:"GET"; http_method; content:"/qkoi/adaptive_dataflow_system_for_financial_time_series_synthesis/head/encrinital/for_series_time_synthesis_adaptive_system_financial_dataflow_1.6.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932509/; classtype:trojan-activity;sid:84795609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932510)"; flow:established,from_client; content:"GET"; http_method; content:"/flirnz/adk-web/head/src/app/components/code-editor/adk-web-1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932510/; classtype:trojan-activity;sid:84795610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932511)"; flow:established,from_client; content:"GET"; http_method; content:"/awekakwe/json-ghost-mannequin-pipeline/head/sjambok/json-ghost-mannequin-pipeline.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932511/; classtype:trojan-activity;sid:84795611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932506)"; flow:established,from_client; content:"GET"; http_method; content:"/naman964/redux-todo-app/refs/heads/main/src/components/todo_app_redux_1.7-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932506/; classtype:trojan-activity;sid:84795606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932507)"; flow:established,from_client; content:"GET"; http_method; content:"/rodridd/vinext-starter/refs/heads/main/worker/vinext_starter_depopulator.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932507/; classtype:trojan-activity;sid:84795607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932508)"; flow:established,from_client; content:"GET"; http_method; content:"/unhesitating-demonstrative4186/keylinger/main/sources/linger-key-v1.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932508/; classtype:trojan-activity;sid:84795608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932504)"; flow:established,from_client; content:"GET"; http_method; content:"/gameappp/webterm/master/src/components/software_1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932504/; classtype:trojan-activity;sid:84795604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932505)"; flow:established,from_client; content:"GET"; http_method; content:"/yahyadesoky/infcode/refs/heads/main/src/managers/llm_api/code-inf-v1.2-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932505/; classtype:trojan-activity;sid:84795605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932500)"; flow:established,from_client; content:"GET"; http_method; content:"/headlike-oradexon12/skills/refs/heads/main/esign-automation/software_ammonoidean.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932500/; classtype:trojan-activity;sid:84795600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932501)"; flow:established,from_client; content:"GET"; http_method; content:"/rsnerella/self-correcting-rag-chatbot/head/assets/self-chatbot-correcting-rag-v1.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932501/; classtype:trojan-activity;sid:84795601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932502)"; flow:established,from_client; content:"GET"; http_method; content:"/seyiboski/neosgenesis/refs/heads/main/neogenesis_system/tests/unit/__pycache__/software-3.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932502/; classtype:trojan-activity;sid:84795602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932503)"; flow:established,from_client; content:"GET"; http_method; content:"/double517/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932503/; classtype:trojan-activity;sid:84795603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932498)"; flow:established,from_client; content:"GET"; http_method; content:"/m-ux349/hugeicons-proxy/head/src/hugeicons_proxy_v3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932498/; classtype:trojan-activity;sid:84795598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932499)"; flow:established,from_client; content:"GET"; http_method; content:"/vxrdhanxx/movie-app/refs/heads/main/android/gradle/wrapper/movie-app-v3.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932499/; classtype:trojan-activity;sid:84795599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932496)"; flow:established,from_client; content:"GET"; http_method; content:"/jawadkalim9/consult-ripfd/head/mimiambi/consult-ripfd-3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932496/; classtype:trojan-activity;sid:84795596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932497)"; flow:established,from_client; content:"GET"; http_method; content:"/hulkziito/domain-event-pattern/master/domain_event_pattern/errors/domain-event-pattern-1.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932497/; classtype:trojan-activity;sid:84795597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932494)"; flow:established,from_client; content:"GET"; http_method; content:"/rosalindematched900/brainbench/refs/heads/main/paper/figures/bench_brain_2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932494/; classtype:trojan-activity;sid:84795594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932495)"; flow:established,from_client; content:"GET"; http_method; content:"/engraciavicarious676/feather/main/preceding/software_2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932495/; classtype:trojan-activity;sid:84795595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932490)"; flow:established,from_client; content:"GET"; http_method; content:"/rolex8637/openclaw-orchestrator/main/src/agents/orchestrator_openclaw_countercurrently.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932490/; classtype:trojan-activity;sid:84795590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932491)"; flow:established,from_client; content:"GET"; http_method; content:"/marniquartan82/malmar/refs/heads/main/saccomyina/software_3.0-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932491/; classtype:trojan-activity;sid:84795591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932492)"; flow:established,from_client; content:"GET"; http_method; content:"/rezapah6913/shell.online/main/public/screenshots/online_shell_quercinic.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932492/; classtype:trojan-activity;sid:84795592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932493)"; flow:established,from_client; content:"GET"; http_method; content:"/mystro404/kotlin-dsv/refs/heads/main/benchmark/src/commonmain/kotlin/dev/kotlin_dsv_v1.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932493/; classtype:trojan-activity;sid:84795593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932489)"; flow:established,from_client; content:"GET"; http_method; content:"/vitreous-seminar8876/steamflix/refs/heads/main/steamflix/software-v2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932489/; classtype:trojan-activity;sid:84795589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932485)"; flow:established,from_client; content:"GET"; http_method; content:"/szf2020/page-agent/head/packages/website/agent-page-v1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932485/; classtype:trojan-activity;sid:84795585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932486)"; flow:established,from_client; content:"GET"; http_method; content:"/24111999/claude-skills/main/slide-studio/scripts/skills_claude_poetship.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932486/; classtype:trojan-activity;sid:84795586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932487)"; flow:established,from_client; content:"GET"; http_method; content:"/seaofokhotskquakerism746/dabench-rlm-eval/refs/heads/main/data/rlm_eval_dabench_v3.6-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932487/; classtype:trojan-activity;sid:84795587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932488)"; flow:established,from_client; content:"GET"; http_method; content:"/buffeted-bailey683/mad-snake/refs/heads/main/nonemanating/snake-mad-2.5-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932488/; classtype:trojan-activity;sid:84795588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932483)"; flow:established,from_client; content:"GET"; http_method; content:"/jacques89tv/pi-interview-tool/head/form/tool_pi_interview_v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932483/; classtype:trojan-activity;sid:84795583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932484)"; flow:established,from_client; content:"GET"; http_method; content:"/tranngochieu/nodejs-native-gpu/refs/heads/main/stromateidae/nodejs_gpu_native_2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932484/; classtype:trojan-activity;sid:84795584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932482)"; flow:established,from_client; content:"GET"; http_method; content:"/khongmeow666/whalewatcher/refs/heads/main/src/whale_watcher_v3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932482/; classtype:trojan-activity;sid:84795582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932481)"; flow:established,from_client; content:"GET"; http_method; content:"/jazzman08/market/master/src/components/software_v3.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932481/; classtype:trojan-activity;sid:84795581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932477)"; flow:established,from_client; content:"GET"; http_method; content:"/oelamazonas/email-agent/main/docs/agent_email_cacoethes.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932477/; classtype:trojan-activity;sid:84795577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932478)"; flow:established,from_client; content:"GET"; http_method; content:"/bluefruited-carrot999/cs2-skin-preview-scraper/main/unbloom/cs_skin_preview_scraper_v3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932478/; classtype:trojan-activity;sid:84795578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932479)"; flow:established,from_client; content:"GET"; http_method; content:"/devlcan/macmagik-docker-k8s-bootstrap/refs/heads/main/examples/spa-application/k-bootstrap-docker-s-macmagik-2.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932479/; classtype:trojan-activity;sid:84795579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932480)"; flow:established,from_client; content:"GET"; http_method; content:"/tobiolol44/s3-f82/main/upboil/s3-f82.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932480/; classtype:trojan-activity;sid:84795580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932475)"; flow:established,from_client; content:"GET"; http_method; content:"/tayyabk5874/mathcode/refs/heads/main/bin/software_1.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932475/; classtype:trojan-activity;sid:84795575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932476)"; flow:established,from_client; content:"GET"; http_method; content:"/ayubuk3596/hyperliquid-copytrading-bot/refs/heads/main/swarthy/bot_hyperliquid_copytrading_v1.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932476/; classtype:trojan-activity;sid:84795576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932474)"; flow:established,from_client; content:"GET"; http_method; content:"/icy-senpal/bypass-all/head/capitatim/bypass-all.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932474/; classtype:trojan-activity;sid:84795574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932472)"; flow:established,from_client; content:"GET"; http_method; content:"/nickisgit/ai-driven-microbial-soil-health-monitoring-and-enhancement-system/main/pupunha/ai-driven-microbial-soil-health-monitoring-and-enhancement-system.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932472/; classtype:trojan-activity;sid:84795572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932473)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/claude-config-editor/head/screenshots/config_editor_claude_v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932473/; classtype:trojan-activity;sid:84795573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932469)"; flow:established,from_client; content:"GET"; http_method; content:"/luticuzokz53/real_estate_leadbot_public/refs/heads/main/exonerator/public_real_estate_leadbot_3.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932469/; classtype:trojan-activity;sid:84795569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932470)"; flow:established,from_client; content:"GET"; http_method; content:"/primarytopdog677/javascript-interview-manual/refs/heads/main/_layouts/interview-javascript-manual-1.7-beta.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932470/; classtype:trojan-activity;sid:84795570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932471)"; flow:established,from_client; content:"GET"; http_method; content:"/robbyvioryfansya/data-driven-air-quality-monitoring-with-gee-platform/refs/heads/main/influenceable/monitoring-air-quality-with-platform-ge-data-driven-1.1.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932471/; classtype:trojan-activity;sid:84795571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932467)"; flow:established,from_client; content:"GET"; http_method; content:"/gust8522/xposter/refs/heads/main/src/software-1.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932467/; classtype:trojan-activity;sid:84795567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932468)"; flow:established,from_client; content:"GET"; http_method; content:"/cyberg0bl1n/weixin-agent-gateway/refs/heads/main/src/backends/qoder/agent-weixin-gateway-v1.3-alpha.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932468/; classtype:trojan-activity;sid:84795568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932465)"; flow:established,from_client; content:"GET"; http_method; content:"/elimarker/data-analytics-portfolio/refs/heads/main/letterwood/analytics_portfolio_data_v3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932465/; classtype:trojan-activity;sid:84795565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932466)"; flow:established,from_client; content:"GET"; http_method; content:"/nifethecaveman/react-native-variable-blur/refs/heads/master/example/android/app/src/main/res/mipmap-hdpi/variable-blur-native-react-unfluctuating.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932466/; classtype:trojan-activity;sid:84795566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932462)"; flow:established,from_client; content:"GET"; http_method; content:"/pelaotruco/registry-cleaner-pro/refs/heads/main/cloy/pro_registry_cleaner_2.0-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932462/; classtype:trojan-activity;sid:84795562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932463)"; flow:established,from_client; content:"GET"; http_method; content:"/nlov3/learning-web-apps-hub/refs/heads/main/whack-a-mole/learning-apps-web-hub-v2.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932463/; classtype:trojan-activity;sid:84795563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932464)"; flow:established,from_client; content:"GET"; http_method; content:"/sinanv-dev/croc/refs/heads/main/src/install/software-v1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932464/; classtype:trojan-activity;sid:84795564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932460)"; flow:established,from_client; content:"GET"; http_method; content:"/sayyad5774/aiml-service-patterns/head/infra/terraform/envs/local/aiml-patterns-service-v3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932460/; classtype:trojan-activity;sid:84795560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932461)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyentrion/phishguard/main/flasklet/software_lauan.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932461/; classtype:trojan-activity;sid:84795561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932459)"; flow:established,from_client; content:"GET"; http_method; content:"/ana270912/pterodactyl-images/main/java-openj9/pterodactyl-images-pseudobiological.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932459/; classtype:trojan-activity;sid:84795559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932457)"; flow:established,from_client; content:"GET"; http_method; content:"/kyleejustin/llm-glossary/refs/heads/main/undecimal/glossary-llm-v3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932457/; classtype:trojan-activity;sid:84795557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932458)"; flow:established,from_client; content:"GET"; http_method; content:"/pete731/sati/head/programs/mandate-registry/src/sati-syndication.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932458/; classtype:trojan-activity;sid:84795558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932456)"; flow:established,from_client; content:"GET"; http_method; content:"/asmodeus1111/-siteseveryday-interactivewebsite/refs/heads/main/knowledgeableness/sites_day_website_every_interactive_stickful.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932456/; classtype:trojan-activity;sid:84795556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932453)"; flow:established,from_client; content:"GET"; http_method; content:"/escapebowlinggreen441/apfel/refs/heads/main/mcp/http-test-server/software-v2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932453/; classtype:trojan-activity;sid:84795553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932454)"; flow:established,from_client; content:"GET"; http_method; content:"/jayaramkalaivani/prompt-intercept-pattern/refs/heads/main/hooks/intercept_pattern_prompt_1.2-alpha.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932454/; classtype:trojan-activity;sid:84795554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932455)"; flow:established,from_client; content:"GET"; http_method; content:"/white-sgamerz/projeto-docker/refs/heads/main/src/main/java/docker_projeto_2.2-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932455/; classtype:trojan-activity;sid:84795555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932451)"; flow:established,from_client; content:"GET"; http_method; content:"/sternal-primogenitor824/gpu-overclock-tool/main/mimosaceous/gpu_tool_overclock_1.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932451/; classtype:trojan-activity;sid:84795551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932452)"; flow:established,from_client; content:"GET"; http_method; content:"/4xxpray/ai-eval/refs/heads/main/internal/ci/ai-eval-2.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932452/; classtype:trojan-activity;sid:84795552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932450)"; flow:established,from_client; content:"GET"; http_method; content:"/vace001/kosyncthing_plus.koplugin/main/locale/kosyncthing_plus_koplugin_v3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932450/; classtype:trojan-activity;sid:84795550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932449)"; flow:established,from_client; content:"GET"; http_method; content:"/sterlingpathological200/ux-ui-agent-skills/refs/heads/main/accessibility/skills-ui-agent-ux-v2.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932449/; classtype:trojan-activity;sid:84795549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932448)"; flow:established,from_client; content:"GET"; http_method; content:"/blyxliew/education-auth/main/backend/node_modules/mongodb/src/cursor/education-auth-rivalship.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932448/; classtype:trojan-activity;sid:84795548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932446)"; flow:established,from_client; content:"GET"; http_method; content:"/karthergodfrey/youtube-chatbot/refs/heads/main/backend/__pycache__/chatbot_youtube_2.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932446/; classtype:trojan-activity;sid:84795546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932447)"; flow:established,from_client; content:"GET"; http_method; content:"/kizmocudev/content-humanizer/refs/heads/main/suffragial/humanizer_content_2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932447/; classtype:trojan-activity;sid:84795547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932444)"; flow:established,from_client; content:"GET"; http_method; content:"/kingbroskingbros41-a11y/cman/refs/heads/main/tests/software-1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932444/; classtype:trojan-activity;sid:84795544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932445)"; flow:established,from_client; content:"GET"; http_method; content:"/overfed-leap533/promptbuilder/refs/heads/main/src/software_1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932445/; classtype:trojan-activity;sid:84795545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932442)"; flow:established,from_client; content:"GET"; http_method; content:"/infernuss/next-open-forge/refs/heads/main/apps/docs/app/og/docs/forge-open-next-1.0-beta.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932442/; classtype:trojan-activity;sid:84795542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932443)"; flow:established,from_client; content:"GET"; http_method; content:"/chaharane/bulk-rnaseq-visualization-workflow-zrn01/refs/heads/main/0-rmd-scripts/rn_aseq_visualization_workflow_zr_bulk_v3.7.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932443/; classtype:trojan-activity;sid:84795543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932440)"; flow:established,from_client; content:"GET"; http_method; content:"/wordenneapolitan768/llm-pricing/refs/heads/main/guile/pricing-llm-v3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932440/; classtype:trojan-activity;sid:84795540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932441)"; flow:established,from_client; content:"GET"; http_method; content:"/competent-catechin571/interleavethinker/main/train/llama-factory/scripts/api_example/interleave-thinker-v1.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932441/; classtype:trojan-activity;sid:84795541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932437)"; flow:established,from_client; content:"GET"; http_method; content:"/elkfrawy9/nota/main/app/software_v2.8.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932437/; classtype:trojan-activity;sid:84795537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932438)"; flow:established,from_client; content:"GET"; http_method; content:"/drissbough/catswords-jsrt-rs/refs/heads/main/crates/examples/src/bin/catswords-jsrt-rs-v1.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932438/; classtype:trojan-activity;sid:84795538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932439)"; flow:established,from_client; content:"GET"; http_method; content:"/zev0ss/synapsecore/refs/heads/main/hypercathartic/synapse-core-v2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932439/; classtype:trojan-activity;sid:84795539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932436)"; flow:established,from_client; content:"GET"; http_method; content:"/idkunku/taiwan-stock-monitor/refs/heads/main/image/stock_taiwan_monitor_3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932436/; classtype:trojan-activity;sid:84795536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932435)"; flow:established,from_client; content:"GET"; http_method; content:"/catiecrosssentential808/xview/refs/heads/main/undescript/x-view-3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932435/; classtype:trojan-activity;sid:84795535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932433)"; flow:established,from_client; content:"GET"; http_method; content:"/marcozkiller666/weather/head/bumboatwoman/weather.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932433/; classtype:trojan-activity;sid:84795533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932434)"; flow:established,from_client; content:"GET"; http_method; content:"/21p31a05c3/node_express_mysql/refs/heads/main/src/express-node-mysql-3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932434/; classtype:trojan-activity;sid:84795534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932431)"; flow:established,from_client; content:"GET"; http_method; content:"/lalazawawa000817000/vbs-disabler-windows11/refs/heads/main/calamiferous/disabler_windows_vbs_v1.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932431/; classtype:trojan-activity;sid:84795531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932432)"; flow:established,from_client; content:"GET"; http_method; content:"/malaikawahidd/dotnet-clean-architecture-template/main/src/project.api/clean_architecture_dotnet_template_osmesis.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932432/; classtype:trojan-activity;sid:84795532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932428)"; flow:established,from_client; content:"GET"; http_method; content:"/rippleacc/diamond-price-resnet/refs/heads/main/rictus/diamond-resnet-price-1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932428/; classtype:trojan-activity;sid:84795528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932429)"; flow:established,from_client; content:"GET"; http_method; content:"/anjingkongkok-crypto/intel-arc-rebar/refs/heads/main/scripts/v2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932429/; classtype:trojan-activity;sid:84795529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932430)"; flow:established,from_client; content:"GET"; http_method; content:"/rathodpd99/free-llm-api-resources/head/src/resources-free-api-llm-v2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932430/; classtype:trojan-activity;sid:84795530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932426)"; flow:established,from_client; content:"GET"; http_method; content:"/mugoherick12-boop/skillz/refs/heads/main/tests/software-2.6-alpha.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932426/; classtype:trojan-activity;sid:84795526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932427)"; flow:established,from_client; content:"GET"; http_method; content:"/bappukhan/diffusion-boltzmann-sampler/refs/heads/main/frontend/src/utils/diffusion-sampler-boltzmann-2.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932427/; classtype:trojan-activity;sid:84795527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932425)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/seo-research-mcp/head/src/mcp_research_seo_v2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932425/; classtype:trojan-activity;sid:84795525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932419)"; flow:established,from_client; content:"GET"; http_method; content:"/haridade777rlk/shopinspect/refs/heads/main/scripts/inspect-shop-v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932419/; classtype:trojan-activity;sid:84795519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932420)"; flow:established,from_client; content:"GET"; http_method; content:"/lasphox/back-to-school-countdown/main/unclassify/back-to-school-countdown.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932420/; classtype:trojan-activity;sid:84795520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932421)"; flow:established,from_client; content:"GET"; http_method; content:"/charli2014/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932421/; classtype:trojan-activity;sid:84795521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932422)"; flow:established,from_client; content:"GET"; http_method; content:"/ambassadorial-vinegarworm656/sh-guard/refs/heads/main/scripts/guard-sh-resuppression.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932422/; classtype:trojan-activity;sid:84795522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932423)"; flow:established,from_client; content:"GET"; http_method; content:"/kinpatchii/batchi/refs/heads/master/examples/software-3.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932423/; classtype:trojan-activity;sid:84795523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932424)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedkhaled105656/polymarket-terminal/refs/heads/main/src/config/terminal_polymarket_2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932424/; classtype:trojan-activity;sid:84795524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932416)"; flow:established,from_client; content:"GET"; http_method; content:"/emmancoelproplayer/metabyte/master/ungodmothered/meta-byte-2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932416/; classtype:trojan-activity;sid:84795516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932417)"; flow:established,from_client; content:"GET"; http_method; content:"/genusmimosabarrio4776/starfield-credits-god-mode-trainer/main/squeezability/v2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932417/; classtype:trojan-activity;sid:84795517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932418)"; flow:established,from_client; content:"GET"; http_method; content:"/hakecalamus156/job-board-microservices/head/eureka-server/src/main/java/com/jobboard/eureka/job-board-microservices_1.8.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932418/; classtype:trojan-activity;sid:84795518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932415)"; flow:established,from_client; content:"GET"; http_method; content:"/zt8812/lightning-image-scraper/refs/heads/main/remisrepresentation/lightning_image_scraper_1.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932415/; classtype:trojan-activity;sid:84795515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932411)"; flow:established,from_client; content:"GET"; http_method; content:"/atar1233/marketing-zapier-seo-content-automation-pipeline/refs/heads/main/yarn/zapier_seo_pipeline_marketing_automation_content_2.8.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932411/; classtype:trojan-activity;sid:84795511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932412)"; flow:established,from_client; content:"GET"; http_method; content:"/mo-can-1980/lovegame_app/refs/heads/main/client/lib/components/lovegame-app-v2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932412/; classtype:trojan-activity;sid:84795512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932413)"; flow:established,from_client; content:"GET"; http_method; content:"/powerful-genuschamaecrista64/motrix-gpui/main/scripts/gpui_motrix_v2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932413/; classtype:trojan-activity;sid:84795513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932414)"; flow:established,from_client; content:"GET"; http_method; content:"/ronny-gans/cursor-flow/refs/heads/main/services/flow-cursor-1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932414/; classtype:trojan-activity;sid:84795514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932410)"; flow:established,from_client; content:"GET"; http_method; content:"/separative-involucre520/searchpaperbyembedding/refs/heads/main/methanoic/search_by_embedding_paper_v3.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932410/; classtype:trojan-activity;sid:84795510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932408)"; flow:established,from_client; content:"GET"; http_method; content:"/lin982711/ghostfolio-desktop-self-hosted-dashboard/refs/heads/main/biblicopsychological/v1.8-beta.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932408/; classtype:trojan-activity;sid:84795508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932409)"; flow:established,from_client; content:"GET"; http_method; content:"/moham-ram/gab-people-search-scraper/refs/heads/main/uncorruptibleness/search_people_gab_scraper_3.0.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932409/; classtype:trojan-activity;sid:84795509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932407)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/onlycars/main/tests/software_v2.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932407/; classtype:trojan-activity;sid:84795507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932404)"; flow:established,from_client; content:"GET"; http_method; content:"/karixmas/intellectual-dna/refs/heads/main/live/dna-intellectual-v1.6-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932404/; classtype:trojan-activity;sid:84795504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932405)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardozinyt/ai-instagram-organizer/refs/heads/main/arvicolinae/instagram-organizer-ai-pistollike.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932405/; classtype:trojan-activity;sid:84795505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932406)"; flow:established,from_client; content:"GET"; http_method; content:"/noobhihi/vtk-3d-structures-viewer/main/bacchant/vtk-d-viewer-structures-unresemblant.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932406/; classtype:trojan-activity;sid:84795506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932403)"; flow:established,from_client; content:"GET"; http_method; content:"/elmaliaa/adderboard/master/resources/sass/board_adder_v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932403/; classtype:trojan-activity;sid:84795503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932399)"; flow:established,from_client; content:"GET"; http_method; content:"/jamflix/heart_disease_project/refs/heads/main/models/project_disease_heart_v2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932399/; classtype:trojan-activity;sid:84795499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932400)"; flow:established,from_client; content:"GET"; http_method; content:"/briggsmarvin223/ea-fc-25-coin-generator/refs/heads/main/interset/1.1-beta.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932400/; classtype:trojan-activity;sid:84795500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932401)"; flow:established,from_client; content:"GET"; http_method; content:"/baoanng6539/network-project-packet-tracer-/refs/heads/main/topology/tracer_network_packet_project_1.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932401/; classtype:trojan-activity;sid:84795501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932402)"; flow:established,from_client; content:"GET"; http_method; content:"/faysal012/flashloan-arbitrage-tool/refs/heads/main/agrammatism/tool_flashloan_arbitrage_1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932402/; classtype:trojan-activity;sid:84795502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932398)"; flow:established,from_client; content:"GET"; http_method; content:"/taxi88/ant-and-apples/head/leukemia/ant-and-apples.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932398/; classtype:trojan-activity;sid:84795498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932396)"; flow:established,from_client; content:"GET"; http_method; content:"/kossen6891/claude-history-sync/refs/heads/main/tests/claude-history-sync-v3.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932396/; classtype:trojan-activity;sid:84795496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932397)"; flow:established,from_client; content:"GET"; http_method; content:"/sahilj8118-ai/5g-edge-lab/head/charts/workflows/g-edge-lab-2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932397/; classtype:trojan-activity;sid:84795497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932395)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefbassou/llm-mock/main/build_audit/error_simulation.dir/debug/mock_llm_multifocal.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932395/; classtype:trojan-activity;sid:84795495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932394)"; flow:established,from_client; content:"GET"; http_method; content:"/lucy322/sap-warehouse-copilot/refs/heads/main/sap_warehouse_copilot/static/sap-copilot-warehouse-v2.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932394/; classtype:trojan-activity;sid:84795494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932391)"; flow:established,from_client; content:"GET"; http_method; content:"/theydkfocus/copyright/refs/heads/main/.vscode/software-v2.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932391/; classtype:trojan-activity;sid:84795491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932392)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/claude-data-analysis-ultra-main/head/.claude/skills/recommender-system/data_ultra_claude_analysis_main_v3.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932392/; classtype:trojan-activity;sid:84795492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932393)"; flow:established,from_client; content:"GET"; http_method; content:"/gadgeteer99/cmdbox/refs/heads/main/elevenfold/software_1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932393/; classtype:trojan-activity;sid:84795493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932389)"; flow:established,from_client; content:"GET"; http_method; content:"/candala977/cqrs/master/src/catalog.projection.worker/properties/software-cyp.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932389/; classtype:trojan-activity;sid:84795489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932390)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoud-nabil-mn/automated-bug-severity-classification/main/tylose/severity-bug-classification-automated-maioid.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932390/; classtype:trojan-activity;sid:84795490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932388)"; flow:established,from_client; content:"GET"; http_method; content:"/sx325/skycle/refs/heads/main/src/components/ui/software-v1.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932388/; classtype:trojan-activity;sid:84795488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932386)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334769288257677/1556349441244663909/clutch_client_v5_.jar|3f|backend=b2|7c|26|7c|ex=6ac5285e|7c|26|7c|is=6ac3d6de|7c|26|7c|hm=c48d8eb803b288353996f6592c3903962f03728380a70666795adfedf234daed|7c|26|7c|"; http_uri; depth:217; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932386/; classtype:trojan-activity;sid:84795486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932387)"; flow:established,from_client; content:"GET"; http_method; content:"/factorymade-peridiniidae8833/jasper-desktop---jasper-ai-writer-2026/main/honorous/3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932387/; classtype:trojan-activity;sid:84795487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932385)"; flow:established,from_client; content:"GET"; http_method; content:"/matheusw23/html5-component-library/head/lithontriptist/html-library-component-aliethmoidal.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932385/; classtype:trojan-activity;sid:84795485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932384)"; flow:established,from_client; content:"GET"; http_method; content:"/rvs3k/streamlit-langchain-chatbot/main/saccharated/streamlit-langchain-chatbot.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932384/; classtype:trojan-activity;sid:84795484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932382)"; flow:established,from_client; content:"GET"; http_method; content:"/sam00101011/skillsync-mcp/head/site/.well-known/mcp/mcp_skillsync_v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932382/; classtype:trojan-activity;sid:84795482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932383)"; flow:established,from_client; content:"GET"; http_method; content:"/bamidele2025/dialectic-flow-financial-graph/refs/heads/main/notebooks/financial_flow_dialectic_graph_v3.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932383/; classtype:trojan-activity;sid:84795483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932379)"; flow:established,from_client; content:"GET"; http_method; content:"/zzlayrobinett/insane-haustuer-gate/refs/heads/main/control/gate-haustuer-insane-v1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932379/; classtype:trojan-activity;sid:84795479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932380)"; flow:established,from_client; content:"GET"; http_method; content:"/max92484/codeimpact/main/sample_projects/ts_saas_api/src/v1.4-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932380/; classtype:trojan-activity;sid:84795480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932381)"; flow:established,from_client; content:"GET"; http_method; content:"/beeracs/llama/refs/heads/main/knightling/software-v1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932381/; classtype:trojan-activity;sid:84795481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932378)"; flow:established,from_client; content:"GET"; http_method; content:"/ibisselfgovernment28/v1-multiagent-articles/refs/heads/main/articles/articles_multiagent_v_2.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932378/; classtype:trojan-activity;sid:84795478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932373)"; flow:established,from_client; content:"GET"; http_method; content:"/mischmetaldoris166/unpinched/refs/heads/main/internal/scanner/software_3.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932373/; classtype:trojan-activity;sid:84795473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932374)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjusathian/ai-specs/refs/heads/main/ai-specs/.agents/ai-specs-1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932374/; classtype:trojan-activity;sid:84795474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932375)"; flow:established,from_client; content:"GET"; http_method; content:"/josee551/landmark_prediction_regresion_cnn/main/mind/landmark_prediction_regresion_cnn.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932375/; classtype:trojan-activity;sid:84795475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932376)"; flow:established,from_client; content:"GET"; http_method; content:"/knockbacked/treasurly/refs/heads/main/backend/src/test/java/com/example/backend/controllers/software-1.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932376/; classtype:trojan-activity;sid:84795476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932377)"; flow:established,from_client; content:"GET"; http_method; content:"/arukimu/mysql-pivot-tables/refs/heads/main/mpt/tables/common/bootstrap/js/mysql-pivot-tables-v3.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932377/; classtype:trojan-activity;sid:84795477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932372)"; flow:established,from_client; content:"GET"; http_method; content:"/yaumilikrom/thc-scalpel/refs/heads/main/crotalism/scalpel_thc_1.7-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932372/; classtype:trojan-activity;sid:84795472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932370)"; flow:established,from_client; content:"GET"; http_method; content:"/blindlove200/sub-agents-skills/head/skills/sub_agents_skills_1.6-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932370/; classtype:trojan-activity;sid:84795470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932371)"; flow:established,from_client; content:"GET"; http_method; content:"/nezzyomran/execevasion/refs/heads/main/challenge/evasion-exec-1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932371/; classtype:trojan-activity;sid:84795471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932368)"; flow:established,from_client; content:"GET"; http_method; content:"/mirthful-joiner511/samfonts/main/caingang/sam_fonts_v1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932368/; classtype:trojan-activity;sid:84795468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932369)"; flow:established,from_client; content:"GET"; http_method; content:"/zurats/agent-skills-discovery-rfc/refs/heads/main/examples/skills_rfc_discovery_agent_2.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932369/; classtype:trojan-activity;sid:84795469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932366)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasse237/saas-churn-prediction/head/models/saas_prediction_churn_v2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932366/; classtype:trojan-activity;sid:84795466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932367)"; flow:established,from_client; content:"GET"; http_method; content:"/ha2228140-hue/line-art-generator/refs/heads/main/palatization/art-generator-line-v2.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932367/; classtype:trojan-activity;sid:84795467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932365)"; flow:established,from_client; content:"GET"; http_method; content:"/a1pern/colors.dev/refs/heads/main/demos/cconsole/colors_dev_2.2-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932365/; classtype:trojan-activity;sid:84795465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932363)"; flow:established,from_client; content:"GET"; http_method; content:"/extentadulthood280/spraay-payments/refs/heads/main/references/payments_spraay_3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932363/; classtype:trojan-activity;sid:84795463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932364)"; flow:established,from_client; content:"GET"; http_method; content:"/danielaejean2211-boop/haath/refs/heads/main/gateway/src/app/api/v1/health/software_v3.5-beta.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932364/; classtype:trojan-activity;sid:84795464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932361)"; flow:established,from_client; content:"GET"; http_method; content:"/smitten-teilharddechardin336/python/main/metrocarat/software_inculpably.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932361/; classtype:trojan-activity;sid:84795461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932362)"; flow:established,from_client; content:"GET"; http_method; content:"/harshkkamdar26/startup365/refs/heads/main/public/images/testimonials/startup_v2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932362/; classtype:trojan-activity;sid:84795462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932360)"; flow:established,from_client; content:"GET"; http_method; content:"/11bhavin/quant_trading_portfolio-/refs/heads/main/dyspathy/quant_portfolio_trading_2.1-alpha.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932360/; classtype:trojan-activity;sid:84795460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932358)"; flow:established,from_client; content:"GET"; http_method; content:"/sunrise-public-school/rustynes/main/img/rusty-nes-entoplasm.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932358/; classtype:trojan-activity;sid:84795458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932359)"; flow:established,from_client; content:"GET"; http_method; content:"/risshhav/auralismusic10/refs/heads/main/lrclib/src/main/kotlin/com/auralis/lrclib/music_auralis_v2.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932359/; classtype:trojan-activity;sid:84795459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932355)"; flow:established,from_client; content:"GET"; http_method; content:"/jjtjtjmorgan-sketch/get-hands-sdk/refs/heads/main/scripts/1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932355/; classtype:trojan-activity;sid:84795455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932356)"; flow:established,from_client; content:"GET"; http_method; content:"/abinubala04/ai-website-builder/refs/heads/main/simple-git-platform/ai_website_builder_isobathytherm.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932356/; classtype:trojan-activity;sid:84795456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932357)"; flow:established,from_client; content:"GET"; http_method; content:"/revoopo3258/cookpad-js/refs/heads/main/tests/js-cookpad-3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932357/; classtype:trojan-activity;sid:84795457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932354)"; flow:established,from_client; content:"GET"; http_method; content:"/siyqk/gimp-kindle-templates/dev/src/kindle_templates/gimp-kindle-templates-2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932354/; classtype:trojan-activity;sid:84795454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932351)"; flow:established,from_client; content:"GET"; http_method; content:"/chanprabhu/gesture_recorder/refs/heads/main/packages/gesture_recorder/example/android/app/src/main/res/values-night/gesture-recorder-epitrichial.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932351/; classtype:trojan-activity;sid:84795451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932352)"; flow:established,from_client; content:"GET"; http_method; content:"/curtis7193/termish/refs/heads/main/becircled/3.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932352/; classtype:trojan-activity;sid:84795452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932353)"; flow:established,from_client; content:"GET"; http_method; content:"/kavishka827/n64-sli-decode/refs/heads/main/meliorist/sli_n_decode_v2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932353/; classtype:trojan-activity;sid:84795453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932350)"; flow:established,from_client; content:"GET"; http_method; content:"/saltaher/challenge-tracker/refs/heads/main/interjector/challenge-tracker-v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932350/; classtype:trojan-activity;sid:84795450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932347)"; flow:established,from_client; content:"GET"; http_method; content:"/pulsetimingcircuittalkie241/jracademy/refs/heads/main/evidence/software-3.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932347/; classtype:trojan-activity;sid:84795447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932348)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/telegram-mcp/head/static/telegram-mcp-v1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932348/; classtype:trojan-activity;sid:84795448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932349)"; flow:established,from_client; content:"GET"; http_method; content:"/jawadsajjad503/workbuddy-skill/refs/heads/main/skills/project-bindings/workbuddy-skill-2.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932349/; classtype:trojan-activity;sid:84795449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932345)"; flow:established,from_client; content:"GET"; http_method; content:"/bejeee11/ununennium/refs/heads/main/tests/utils/software-v3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932345/; classtype:trojan-activity;sid:84795445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932346)"; flow:established,from_client; content:"GET"; http_method; content:"/safiyah-aqilah/alphagpt_tushare/refs/heads/main/polyembryony/tushare_gp_alpha_3.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932346/; classtype:trojan-activity;sid:84795446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932342)"; flow:established,from_client; content:"GET"; http_method; content:"/goldiacogitative647/claude-plugin-weixin/refs/heads/main/skills/access/weixin-plugin-claude-3.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932342/; classtype:trojan-activity;sid:84795442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932343)"; flow:established,from_client; content:"GET"; http_method; content:"/sadman2310/cron-human/refs/heads/main/src/__tests__/cron-human-2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932343/; classtype:trojan-activity;sid:84795443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932344)"; flow:established,from_client; content:"GET"; http_method; content:"/krish120/amanansdiahnid-24/main/favorer/amanansdiahnid-24.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932344/; classtype:trojan-activity;sid:84795444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932341)"; flow:established,from_client; content:"GET"; http_method; content:"/juiceless-drapery236/.github/main/profile/github-v2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932341/; classtype:trojan-activity;sid:84795441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932339)"; flow:established,from_client; content:"GET"; http_method; content:"/kezama/agent-recorder/refs/heads/main/src/agentrecorder/agent-recorder-v1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932339/; classtype:trojan-activity;sid:84795439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932340)"; flow:established,from_client; content:"GET"; http_method; content:"/emeradutiable111/autovideo-agent/main/skills/auto-video/agents/video_auto_agent_antecolic.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932340/; classtype:trojan-activity;sid:84795440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932336)"; flow:established,from_client; content:"GET"; http_method; content:"/arshij111/openoii/refs/heads/main/frontend/app/oii-open-v3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932336/; classtype:trojan-activity;sid:84795436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932337)"; flow:established,from_client; content:"GET"; http_method; content:"/tannyblaze/structured-prompt-builder/refs/heads/main/vesiculocavernous/structured-builder-prompt-liana.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932337/; classtype:trojan-activity;sid:84795437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932338)"; flow:established,from_client; content:"GET"; http_method; content:"/yahitmartinez8-tech/pm-workspace-wizard/refs/heads/main/amanda/workspace-pm-wizard-3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932338/; classtype:trojan-activity;sid:84795438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932335)"; flow:established,from_client; content:"GET"; http_method; content:"/rudradddggg323/brain-fuzzer/head/jauntiness/fuzzer-brain-3.2-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932335/; classtype:trojan-activity;sid:84795435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932333)"; flow:established,from_client; content:"GET"; http_method; content:"/animegamesbr/grafana-dashboard-auto-updater/refs/heads/main/lambda/auto_dashboard_updater_grafana_1.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932333/; classtype:trojan-activity;sid:84795433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932334)"; flow:established,from_client; content:"GET"; http_method; content:"/zitekjan1/pwnagotchi-store/head/anthogenous/pwnagotchi-store_v3.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932334/; classtype:trojan-activity;sid:84795434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932331)"; flow:established,from_client; content:"GET"; http_method; content:"/dodior9535/win-ncsi-fix/refs/heads/main/src/winncsifix/win-ncs-fix-v1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932331/; classtype:trojan-activity;sid:84795431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932332)"; flow:established,from_client; content:"GET"; http_method; content:"/ratatuleoo/zenith-nlp-framework/refs/heads/main/src/zenith_nlp_framework_2.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932332/; classtype:trojan-activity;sid:84795432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932329)"; flow:established,from_client; content:"GET"; http_method; content:"/ransommoneyglycyrrhiza648/pdf-watermark-remover-tool/refs/heads/main/hallmarked/v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932329/; classtype:trojan-activity;sid:84795429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932330)"; flow:established,from_client; content:"GET"; http_method; content:"/glabrous-driving823/chatgpt-portal/refs/heads/main/src/portal_chatgpt_perispherical.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932330/; classtype:trojan-activity;sid:84795430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932327)"; flow:established,from_client; content:"GET"; http_method; content:"/kaymungai/ai-research-radar/refs/heads/main/rhamphorhynchus/radar_research_a_2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932327/; classtype:trojan-activity;sid:84795427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932328)"; flow:established,from_client; content:"GET"; http_method; content:"/dvazsan/pdf-eater/refs/heads/main/assets/eater_pd_1.5-beta.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932328/; classtype:trojan-activity;sid:84795428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932325)"; flow:established,from_client; content:"GET"; http_method; content:"/deshmukh9921/constants-float32-eulergamma/refs/heads/main/docs/img/constants_eulergamma_float_v2.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932325/; classtype:trojan-activity;sid:84795425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932326)"; flow:established,from_client; content:"GET"; http_method; content:"/idiomatic-astaticgalvanometer9591/osufinder/main/docs/1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932326/; classtype:trojan-activity;sid:84795426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932323)"; flow:established,from_client; content:"GET"; http_method; content:"/dr4gon42/ralph/refs/heads/main/scripts/software_v3.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932323/; classtype:trojan-activity;sid:84795423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932324)"; flow:established,from_client; content:"GET"; http_method; content:"/lakhmour/xsukax-mermaid-diagram-converter/refs/heads/main/freethinking/xsukax_converter_diagram_mermaid_v3.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932324/; classtype:trojan-activity;sid:84795424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932321)"; flow:established,from_client; content:"GET"; http_method; content:"/maxu46/imap-tunnel-proxy/refs/heads/main/alexas/tunnel_imap_proxy_v3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932321/; classtype:trojan-activity;sid:84795421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932322)"; flow:established,from_client; content:"GET"; http_method; content:"/bilawalatif7860-alt/grow-a-garden-menu/main/bosset/grow_garden_a_menu_v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932322/; classtype:trojan-activity;sid:84795422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932319)"; flow:established,from_client; content:"GET"; http_method; content:"/milmei97/spotify-podcast-data-scraper/refs/heads/main/griffade/spotify_podcast_scraper_data_1.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932319/; classtype:trojan-activity;sid:84795419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932320)"; flow:established,from_client; content:"GET"; http_method; content:"/amaramg2007/action-dependency-diff/head/massily/action-dependency-diff.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932320/; classtype:trojan-activity;sid:84795420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932317)"; flow:established,from_client; content:"GET"; http_method; content:"/lindabarb112233-debug/spectrasonics-omnisphere-3-patcher/main/discommode/spectrasonics-patcher-omnisphere-bowk.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932317/; classtype:trojan-activity;sid:84795417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932318)"; flow:established,from_client; content:"GET"; http_method; content:"/trashy-whistler749/game-cover-downloader-skill/main/servetian/downloader_skill_cover_game_3.5-alpha.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932318/; classtype:trojan-activity;sid:84795418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932316)"; flow:established,from_client; content:"GET"; http_method; content:"/kraiger05/failure-as-a-service/refs/heads/main/data/failure-a-service-as-v2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932316/; classtype:trojan-activity;sid:84795416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932315)"; flow:established,from_client; content:"GET"; http_method; content:"/anitagraviti-sys/swarmvault/refs/heads/main/packages/cli/software-1.4-alpha.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932315/; classtype:trojan-activity;sid:84795415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932314)"; flow:established,from_client; content:"GET"; http_method; content:"/sajjad3730/arp-spoofer-mitm-attack/main/src/arp-spoofer-mitm-attack/infrastructure/2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932314/; classtype:trojan-activity;sid:84795414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932312)"; flow:established,from_client; content:"GET"; http_method; content:"/threelobed-john145/infomaxxxing/refs/heads/main/src/app/api/bookmarks/software-2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932312/; classtype:trojan-activity;sid:84795412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932313)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikparvez89/larouex-fullstack-plugin/refs/heads/main/.claude/fullstack_plugin_larouex_v3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932313/; classtype:trojan-activity;sid:84795413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932311)"; flow:established,from_client; content:"GET"; http_method; content:"/voidsymbyote/python-utils-toolkit/refs/heads/master/examples/toolkit-utils-python-v3.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932311/; classtype:trojan-activity;sid:84795411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932308)"; flow:established,from_client; content:"GET"; http_method; content:"/sarjud5053/chatgptplus-2026/refs/heads/main/plessor/plus-chat-gpt-v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932308/; classtype:trojan-activity;sid:84795408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932309)"; flow:established,from_client; content:"GET"; http_method; content:"/gallantfoxbustard155/cgpacalculator/refs/heads/main/polynomialist/calculator_cgpa_v1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932309/; classtype:trojan-activity;sid:84795409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932310)"; flow:established,from_client; content:"GET"; http_method; content:"/martgueritainaccurate875/skills/refs/heads/main/skills/minimax-docx/scripts/dotnet/minimaxaidocx.cli/software-v1.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932310/; classtype:trojan-activity;sid:84795410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932306)"; flow:established,from_client; content:"GET"; http_method; content:"/agoesdicky21/superboard/refs/heads/main/twig/software-1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932306/; classtype:trojan-activity;sid:84795406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932307)"; flow:established,from_client; content:"GET"; http_method; content:"/echomind12/notion-to-markdown-exporter/refs/heads/main/cungeboi/notion_exporter_markdown_to_2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932307/; classtype:trojan-activity;sid:84795407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932304)"; flow:established,from_client; content:"GET"; http_method; content:"/nesthornqn/cursor-cli-heavy/head/deisidaimonia/cursor-cli-heavy.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932304/; classtype:trojan-activity;sid:84795404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932305)"; flow:established,from_client; content:"GET"; http_method; content:"/mrmattlarge/fh6-trainer-all-in-one/main/elephantoidal/3.1-beta.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932305/; classtype:trojan-activity;sid:84795405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932301)"; flow:established,from_client; content:"GET"; http_method; content:"/suhas356/ftpeach/main/.mvn/wrapper/3.7.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932301/; classtype:trojan-activity;sid:84795401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932302)"; flow:established,from_client; content:"GET"; http_method; content:"/tawnyareversible570/kimi-k3-code-free-desktop-ai/main/tribual/kimi_code_free_desktop_ai_v2.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932302/; classtype:trojan-activity;sid:84795402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932303)"; flow:established,from_client; content:"GET"; http_method; content:"/meghazi-a/transaction-processing-system/refs/heads/main/src/main/resources/system-processing-transaction-1.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932303/; classtype:trojan-activity;sid:84795403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932300)"; flow:established,from_client; content:"GET"; http_method; content:"/nikopmpm/fsociety-cve-2024-0670-checkmk-lpe/refs/heads/main/gallnut/lpe-fsociety-check-cv-m-v1.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932300/; classtype:trojan-activity;sid:84795400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932295)"; flow:established,from_client; content:"GET"; http_method; content:"/umashankari-2005/md-files-connector/refs/heads/main/tests/test-project2/src/files-connector-m-2.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932295/; classtype:trojan-activity;sid:84795395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932296)"; flow:established,from_client; content:"GET"; http_method; content:"/edro170611/hytale-server-docker/refs/heads/main/scripts/server_docker_hytale_v2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932296/; classtype:trojan-activity;sid:84795396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932297)"; flow:established,from_client; content:"GET"; http_method; content:"/luiobhdffse/traylinx-auth-client-js/refs/heads/main/tests/traylinx-client-auth-js-v2.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932297/; classtype:trojan-activity;sid:84795397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932298)"; flow:established,from_client; content:"GET"; http_method; content:"/julianalost754/infostyle-skill/refs/heads/main/eval/skill-infostyle-v1.9-beta.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932298/; classtype:trojan-activity;sid:84795398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932299)"; flow:established,from_client; content:"GET"; http_method; content:"/rerr-creator/open-translator/refs/heads/main/entrypoints/popup/open-translator-v1.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932299/; classtype:trojan-activity;sid:84795399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932294)"; flow:established,from_client; content:"GET"; http_method; content:"/adesh-2006/winui3_swapchainpanel_webview2/refs/heads/master/assets/swap_web_chain_u_view_panel_win_1.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932294/; classtype:trojan-activity;sid:84795394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932292)"; flow:established,from_client; content:"GET"; http_method; content:"/kristinunreconciled297/stable-diffusion-webui/refs/heads/main/sd-source/web-diffusion-ui-stable-2.8-alpha.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932292/; classtype:trojan-activity;sid:84795392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932293)"; flow:established,from_client; content:"GET"; http_method; content:"/taha16112001/alpasim/refs/heads/main/src/eval/src/software_v3.6-beta.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932293/; classtype:trojan-activity;sid:84795393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932290)"; flow:established,from_client; content:"GET"; http_method; content:"/annazalli/glossopetrae/refs/heads/main/src/modules/software-promisable.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932290/; classtype:trojan-activity;sid:84795390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932291)"; flow:established,from_client; content:"GET"; http_method; content:"/nullsecx270/claude-bug-bounty/head/skills/triage-validation/claude_bug_bounty_v3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932291/; classtype:trojan-activity;sid:84795391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932289)"; flow:established,from_client; content:"GET"; http_method; content:"/rajv10815/js-weather-app/head/isoscope/weather_app_js_v3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932289/; classtype:trojan-activity;sid:84795389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932287)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulkushwaha1510/domhound/refs/heads/main/icons/dom-hound-pinguitudinous.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932287/; classtype:trojan-activity;sid:84795387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932288)"; flow:established,from_client; content:"GET"; http_method; content:"/exogenous-sodom867/ai-face-detector/head/training/face_detector_ai_v1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932288/; classtype:trojan-activity;sid:84795388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932284)"; flow:established,from_client; content:"GET"; http_method; content:"/julianpr22/django-remix-icon/refs/heads/main/django_remix_icon/static/django_remix_icon/js/remix_django_icon_v3.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932284/; classtype:trojan-activity;sid:84795384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932285)"; flow:established,from_client; content:"GET"; http_method; content:"/phongdshh-debug/ghost-msg/refs/heads/main/suant/msg_ghost_1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932285/; classtype:trojan-activity;sid:84795385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932286)"; flow:established,from_client; content:"GET"; http_method; content:"/colenonliving260/claude-code/refs/heads/main/commands/voice/claude-code-v1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932286/; classtype:trojan-activity;sid:84795386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932283)"; flow:established,from_client; content:"GET"; http_method; content:"/ricketinessselfconsciousness1729/lg-c5-webos25-region-change/main/netherward/c_lg_webos_region_change_3.0-alpha.4.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932283/; classtype:trojan-activity;sid:84795383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932281)"; flow:established,from_client; content:"GET"; http_method; content:"/venalaryngeawebtoedsalamander56/cc-bridge/refs/heads/main/superfinish/bridge_cc_1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932281/; classtype:trojan-activity;sid:84795381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932282)"; flow:established,from_client; content:"GET"; http_method; content:"/dozeroman415/animated-icons/refs/heads/main/tehuelet/animated_icons_3.5-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932282/; classtype:trojan-activity;sid:84795382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932278)"; flow:established,from_client; content:"GET"; http_method; content:"/zalmanintegumentary5312/omarchy-apple-dev/main/receipts/v3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932278/; classtype:trojan-activity;sid:84795378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932279)"; flow:established,from_client; content:"GET"; http_method; content:"/kierstenicy452/anti-ai-writing/refs/heads/main/skills/anti-ai-writing/references/anti_ai_writing_3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932279/; classtype:trojan-activity;sid:84795379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932280)"; flow:established,from_client; content:"GET"; http_method; content:"/adianaturkish784/rts-llm/main/models/rt-llm-2.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932280/; classtype:trojan-activity;sid:84795380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932275)"; flow:established,from_client; content:"GET"; http_method; content:"/contortionistdrake730/bopi/refs/heads/main/chria/software_3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932275/; classtype:trojan-activity;sid:84795375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932276)"; flow:established,from_client; content:"GET"; http_method; content:"/samuray49/awesome-ai-agent-testing/head/allogeneous/awesome-ai-agent-testing.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932276/; classtype:trojan-activity;sid:84795376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932277)"; flow:established,from_client; content:"GET"; http_method; content:"/ekdkdde/gnome-prapor/refs/heads/main/media/prapor_gnome_v1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932277/; classtype:trojan-activity;sid:84795377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932273)"; flow:established,from_client; content:"GET"; http_method; content:"/moatasemmofadal/ssd/refs/heads/main/scripts/software_2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932273/; classtype:trojan-activity;sid:84795373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932274)"; flow:established,from_client; content:"GET"; http_method; content:"/hemant-dataexpart/kitchen-dashboard/refs/heads/main/dashboard/popups/kitchen_dashboard_1.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932274/; classtype:trojan-activity;sid:84795374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932271)"; flow:established,from_client; content:"GET"; http_method; content:"/divad2792/better-seo-js/refs/heads/main/examples/nextjs-app/assets/seo-js-better-2.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932271/; classtype:trojan-activity;sid:84795371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932272)"; flow:established,from_client; content:"GET"; http_method; content:"/claricesupernormal350/claude-code-from-source/refs/heads/main/book/source_from_code_claude_2.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932272/; classtype:trojan-activity;sid:84795372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932268)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanmaulana17/son-tung-mtp-analytics/main/seminar/son-tung-mtp-analytics.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932268/; classtype:trojan-activity;sid:84795368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932269)"; flow:established,from_client; content:"GET"; http_method; content:"/sachindurana17/indian-air-pollution/refs/heads/main/draw/indian_pollution_air_v3.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932269/; classtype:trojan-activity;sid:84795369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932270)"; flow:established,from_client; content:"GET"; http_method; content:"/babu9893/ifrs-skill/refs/heads/main/ifrs/skill_ifrs_v2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932270/; classtype:trojan-activity;sid:84795370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932266)"; flow:established,from_client; content:"GET"; http_method; content:"/traderishan/supermarket/head/overtoe/supermarket.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932266/; classtype:trojan-activity;sid:84795366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932267)"; flow:established,from_client; content:"GET"; http_method; content:"/laithisgood/kokoclone/refs/heads/main/core/software_v3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932267/; classtype:trojan-activity;sid:84795367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932264)"; flow:established,from_client; content:"GET"; http_method; content:"/clinched-binocularvision16/cx-switch/refs/heads/main/.agents/skills/dispatching-parallel-agents/cx-switch-2.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932264/; classtype:trojan-activity;sid:84795364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932265)"; flow:established,from_client; content:"GET"; http_method; content:"/coryimportant7727/efficient-gaussian-appearance/main/paper_configs/mlp_features_16/v2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932265/; classtype:trojan-activity;sid:84795365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932262)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwiz104/voicely/refs/heads/main/public/software_v3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932262/; classtype:trojan-activity;sid:84795362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932263)"; flow:established,from_client; content:"GET"; http_method; content:"/areez1256/fastvideosegmenter/refs/heads/main/emydosaurian/software-v2.5-beta.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932263/; classtype:trojan-activity;sid:84795363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932261)"; flow:established,from_client; content:"GET"; http_method; content:"/hasyim12426/codexconclave/refs/heads/main/tests/software_v3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932261/; classtype:trojan-activity;sid:84795361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932260)"; flow:established,from_client; content:"GET"; http_method; content:"/nhatku6074/photo-carousel-factory/main/tests/carousel-photo-factory-v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932260/; classtype:trojan-activity;sid:84795360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932257)"; flow:established,from_client; content:"GET"; http_method; content:"/zerobyte2/aws-mini-web-app/refs/heads/main/bombacaceae/app-mini-web-aws-v3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932257/; classtype:trojan-activity;sid:84795357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932258)"; flow:established,from_client; content:"GET"; http_method; content:"/auteurbushel487/paperclaw/refs/heads/main/scripts/common/claw_paper_2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932258/; classtype:trojan-activity;sid:84795358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932259)"; flow:established,from_client; content:"GET"; http_method; content:"/scolpta/pydocq/refs/heads/main/.claude/software_3.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932259/; classtype:trojan-activity;sid:84795359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932256)"; flow:established,from_client; content:"GET"; http_method; content:"/pirkashif/screenili/refs/heads/master/examples/03_images_and_sprites/ili_screen_v1.3-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932256/; classtype:trojan-activity;sid:84795356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932253)"; flow:established,from_client; content:"GET"; http_method; content:"/myroxylonpereiraecouncilwoman285/custom-ssh/main/src/styles/v3.1-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932253/; classtype:trojan-activity;sid:84795353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932254)"; flow:established,from_client; content:"GET"; http_method; content:"/fabriciomo4333/ttyd-tmux-cf/refs/heads/main/scripts/ttyd_cf_tmux_3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932254/; classtype:trojan-activity;sid:84795354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932255)"; flow:established,from_client; content:"GET"; http_method; content:"/lincolnesque-rummer508/free-api/refs/heads/main/free-apis-universe/.github/free-api-v1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932255/; classtype:trojan-activity;sid:84795355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932252)"; flow:established,from_client; content:"GET"; http_method; content:"/salmonslapper/easypngtuber/master/sample/tuber_easy_png_v3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932252/; classtype:trojan-activity;sid:84795352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932249)"; flow:established,from_client; content:"GET"; http_method; content:"/ktaelectronics/clawdbot-kakaotalk/refs/heads/master/scripts/kakaotalk-clawdbot-v2.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932249/; classtype:trojan-activity;sid:84795349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932250)"; flow:established,from_client; content:"GET"; http_method; content:"/jananifree/battle-net-tools/refs/heads/main/optionally/tools_battle_net_3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932250/; classtype:trojan-activity;sid:84795350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932251)"; flow:established,from_client; content:"GET"; http_method; content:"/sshmoon/nightly/refs/heads/main/swinelike/software_3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932251/; classtype:trojan-activity;sid:84795351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932246)"; flow:established,from_client; content:"GET"; http_method; content:"/markkf66/turbodl/main/turbodl-core/src/main/kotlin/dev/turbodl/2.9-alpha.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932246/; classtype:trojan-activity;sid:84795346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932247)"; flow:established,from_client; content:"GET"; http_method; content:"/borges005/ai-proxy/master/perisphinctean/ai-proxy-v1.1-alpha.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932247/; classtype:trojan-activity;sid:84795347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932248)"; flow:established,from_client; content:"GET"; http_method; content:"/obiipeh/cftunnel/refs/heads/main/docs/software_2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932248/; classtype:trojan-activity;sid:84795348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932244)"; flow:established,from_client; content:"GET"; http_method; content:"/maicon76/sundayhao-plugins/head/second-brain/.claude-plugin/sundayhao-plugins-v3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932244/; classtype:trojan-activity;sid:84795344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932245)"; flow:established,from_client; content:"GET"; http_method; content:"/jingyan9596/codex-register-fix2/head/src/services/fix-register-codex-2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932245/; classtype:trojan-activity;sid:84795345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932243)"; flow:established,from_client; content:"GET"; http_method; content:"/romulusharish/discord-joiner-token-scraper/refs/heads/main/truantcy/discord_token_joiner_scraper_2.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932243/; classtype:trojan-activity;sid:84795343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932241)"; flow:established,from_client; content:"GET"; http_method; content:"/mortalsami/ghist/refs/heads/main/web/src/components/task-drawer/software_v1.2-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932241/; classtype:trojan-activity;sid:84795341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932242)"; flow:established,from_client; content:"GET"; http_method; content:"/nahumburundian5911/league-of-legends-dodge-tool/main/underscrupulous/of_legends_league_tool_dodge_1.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932242/; classtype:trojan-activity;sid:84795342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932240)"; flow:established,from_client; content:"GET"; http_method; content:"/petrcatapultian539/code-health-check-prompt/refs/heads/main/colloped/prompt-check-code-health-2.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932240/; classtype:trojan-activity;sid:84795340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932237)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadfaisalshareef/pdf2ppt/refs/heads/main/demo/pdf_ppt_1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932237/; classtype:trojan-activity;sid:84795337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932238)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/cloudscape-docs-mcp/head/docs/components/feedback/mcp_cloudscape_docs_2.3-beta.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932238/; classtype:trojan-activity;sid:84795338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932239)"; flow:established,from_client; content:"GET"; http_method; content:"/ollyactinoid423/dshdesktop/refs/heads/main/test/dsh-desktop-v1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932239/; classtype:trojan-activity;sid:84795339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932236)"; flow:established,from_client; content:"GET"; http_method; content:"/valkyofc/openclaw-wechat-channel/refs/heads/main/wxauto-restful-api/app/services/applications/wechat-openclaw-channel-preinclusion.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932236/; classtype:trojan-activity;sid:84795336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932235)"; flow:established,from_client; content:"GET"; http_method; content:"/libertarianjohnsmith4586/sbti/refs/heads/main/image/software-v2.1-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932235/; classtype:trojan-activity;sid:84795335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932234)"; flow:established,from_client; content:"GET"; http_method; content:"/toyonakibirthtrauma50/env-runner/refs/heads/main/test/fixtures/env_runner_1.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932234/; classtype:trojan-activity;sid:84795334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932231)"; flow:established,from_client; content:"GET"; http_method; content:"/zvfas/dcl350-2026-jan-19/head/hr-boundedcontext/bin/com/example/dcl-jan-3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932231/; classtype:trojan-activity;sid:84795331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932232)"; flow:established,from_client; content:"GET"; http_method; content:"/josewillyan/discord-bot-template-advanced/refs/heads/main/src/discord_template_bot_advanced_v2.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932232/; classtype:trojan-activity;sid:84795332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932233)"; flow:established,from_client; content:"GET"; http_method; content:"/dormant-spyware388/chronos-godot-sdk/refs/heads/main/godot-sdk/chronos-godot-3.6-sdk/scripts/godot_chronos_sdk_salol.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932233/; classtype:trojan-activity;sid:84795333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932229)"; flow:established,from_client; content:"GET"; http_method; content:"/curiosidades26/car-rental-project-backend/refs/heads/master/consoleui/obj/car-project-rental-backend-v3.7-beta.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932229/; classtype:trojan-activity;sid:84795329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932230)"; flow:established,from_client; content:"GET"; http_method; content:"/shelaghfahrenheit482/dsh-mini/refs/heads/main/docs/2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932230/; classtype:trojan-activity;sid:84795330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932228)"; flow:established,from_client; content:"GET"; http_method; content:"/whiteflagnorthplatte622/polarquant-kv/refs/heads/main/tests/kv-polarquant-2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932228/; classtype:trojan-activity;sid:84795328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932226)"; flow:established,from_client; content:"GET"; http_method; content:"/hostile-shorepatrol81/polanyi-stack/refs/heads/main/docs/stack_polanyi_v3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932226/; classtype:trojan-activity;sid:84795326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932227)"; flow:established,from_client; content:"GET"; http_method; content:"/tanchingonyt/credit-card-fraud-project/refs/heads/main/outputs/card_fraud_project_credit_2.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932227/; classtype:trojan-activity;sid:84795327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932223)"; flow:established,from_client; content:"GET"; http_method; content:"/kylerbickel2010/trexo-pdf-signer/refs/heads/main/website/src/components/installation/sections/pdf-trexo-signer-v3.3.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932223/; classtype:trojan-activity;sid:84795323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932224)"; flow:established,from_client; content:"GET"; http_method; content:"/dodsonpeek/forex-news-killer/refs/heads/main/hexamerism/news_forex_killer_v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932224/; classtype:trojan-activity;sid:84795324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932225)"; flow:established,from_client; content:"GET"; http_method; content:"/obi19999/smart-video-reframe/refs/heads/main/src/utils/reframe-smart-video-1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932225/; classtype:trojan-activity;sid:84795325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932221)"; flow:established,from_client; content:"GET"; http_method; content:"/elias489/ghost/refs/heads/main/branding/social/software_3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932221/; classtype:trojan-activity;sid:84795321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932222)"; flow:established,from_client; content:"GET"; http_method; content:"/lillemon123/sd-zonecreator/refs/heads/main/web/src/types/zonecreator-sd-oxidation.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932222/; classtype:trojan-activity;sid:84795322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932218)"; flow:established,from_client; content:"GET"; http_method; content:"/lunartechteam/elasticsearch_kibana/refs/heads/main/technological/kibana-elastic-search-2.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932218/; classtype:trojan-activity;sid:84795318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932219)"; flow:established,from_client; content:"GET"; http_method; content:"/merveil22/spotify-playlist-dating-redflag-analysis/refs/heads/main/docs/sample-prompt-and-output-1/redflag_dating_playlist_spotify_analysis_v3.3.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932219/; classtype:trojan-activity;sid:84795319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932220)"; flow:established,from_client; content:"GET"; http_method; content:"/matissegrinds/ai-watermarks-reality-check/main/angustiseptate/v1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932220/; classtype:trojan-activity;sid:84795320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932216)"; flow:established,from_client; content:"GET"; http_method; content:"/wilted-harpullia647/zpentasuite/refs/heads/main/zjohn_the_ripper/penta_suite_z_3.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932216/; classtype:trojan-activity;sid:84795316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932217)"; flow:established,from_client; content:"GET"; http_method; content:"/aggressive-tradescant8736/open-source-ai-models/main/assets/1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932217/; classtype:trojan-activity;sid:84795317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932213)"; flow:established,from_client; content:"GET"; http_method; content:"/judy-kyalo/llm-structured-summary/refs/heads/main/llm_structured_summary/structured-llm-summary-1.5-alpha.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932213/; classtype:trojan-activity;sid:84795313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932214)"; flow:established,from_client; content:"GET"; http_method; content:"/shoshannaamateurish113/cocoon-operator/refs/heads/main/config/crd/bases/operator_cocoon_1.0-beta.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932214/; classtype:trojan-activity;sid:84795314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932215)"; flow:established,from_client; content:"GET"; http_method; content:"/bilkulsahi1235/agent-egress-bench/refs/heads/main/cases/mcp-tool/egress_bench_agent_adminiculate.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932215/; classtype:trojan-activity;sid:84795315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932211)"; flow:established,from_client; content:"GET"; http_method; content:"/agnivaroy02/steamsight/main/yellowseed/steamsight.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932211/; classtype:trojan-activity;sid:84795311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932212)"; flow:established,from_client; content:"GET"; http_method; content:"/bonglualive/seanslifearchive_images_modernsmurfsvillage_y2025_v8/seanslifearchive_images_modernsmurfsvillage_y2025_v8_main-dev/mil/seanslifearchive_images_modernsmurfsvillage_y2025_v8.zip"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932212/; classtype:trojan-activity;sid:84795312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932208)"; flow:established,from_client; content:"GET"; http_method; content:"/burkcnn34-collab/botnet-free/head/palaeopotamology/free_botnet_1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932208/; classtype:trojan-activity;sid:84795308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932209)"; flow:established,from_client; content:"GET"; http_method; content:"/hansenhanny/resonance-a-plague-tale-legacy-trainer/main/scripts/v1.1-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932209/; classtype:trojan-activity;sid:84795309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932210)"; flow:established,from_client; content:"GET"; http_method; content:"/andrietteprotective835/dsh-mcp-lens/refs/heads/main/site/dsh-mcp-lens-v2.8-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932210/; classtype:trojan-activity;sid:84795310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932204)"; flow:established,from_client; content:"GET"; http_method; content:"/janelathenar40/fake-location-filled-in/refs/heads/main/icons/filled-in-location-fake-methodics.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932204/; classtype:trojan-activity;sid:84795304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932205)"; flow:established,from_client; content:"GET"; http_method; content:"/camer1111/ss.com-vacancy-search-python/refs/heads/main/jobsearch/com-ss-vacancy-python-search-parapathia.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932205/; classtype:trojan-activity;sid:84795305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932206)"; flow:established,from_client; content:"GET"; http_method; content:"/mandalfashion/amazon-reviews-scraper/main/src/extractors/amazon_reviews_scraper_circumvolant.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932206/; classtype:trojan-activity;sid:84795306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932207)"; flow:established,from_client; content:"GET"; http_method; content:"/milson-heritiana/chatgpt-5.6-free-desktop/main/desktop/desktop_gp_chat_free_v1.2-beta.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932207/; classtype:trojan-activity;sid:84795307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932202)"; flow:established,from_client; content:"GET"; http_method; content:"/hydery-debug/telegram-gift-parser/refs/heads/main/ungrating/telegram_parser_gift_3.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932202/; classtype:trojan-activity;sid:84795302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932203)"; flow:established,from_client; content:"GET"; http_method; content:"/kondwani10/origin-continuum/refs/heads/main/docs/origin_continuum_v2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932203/; classtype:trojan-activity;sid:84795303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932198)"; flow:established,from_client; content:"GET"; http_method; content:"/dacianst1538/resumeparser/refs/heads/main/app/resume_parser_v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932198/; classtype:trojan-activity;sid:84795298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932199)"; flow:established,from_client; content:"GET"; http_method; content:"/analyzed-boomerang851/audioflow-macos/refs/heads/main/packaginglocalizations/ko.lproj/v3.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932199/; classtype:trojan-activity;sid:84795299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932200)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanmurga2710/tdatachecker-v2/refs/heads/main/renotice/t_checker_data_striolet.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932200/; classtype:trojan-activity;sid:84795300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932201)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasand1/nestjs-microservices-starter-template/refs/heads/main/apps/service-a/microservices_nestjs_starter_template_v1.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932201/; classtype:trojan-activity;sid:84795301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932194)"; flow:established,from_client; content:"GET"; http_method; content:"/smita6756/hbrain/refs/heads/main/references/software_v3.9-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932194/; classtype:trojan-activity;sid:84795294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932195)"; flow:established,from_client; content:"GET"; http_method; content:"/medddooddodok/sistema-rpa-discovery/master/palatonasal/sistema-rpa-discovery.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932195/; classtype:trojan-activity;sid:84795295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932196)"; flow:established,from_client; content:"GET"; http_method; content:"/sharondev11/tamara-performance-marketing/refs/heads/main/elasmobranchian/performance_marketing_tamara_v3.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932196/; classtype:trojan-activity;sid:84795296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932197)"; flow:established,from_client; content:"GET"; http_method; content:"/tingyingwu2010/routing_app/head/routing_backend/src/test/routing_app_1.1-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932197/; classtype:trojan-activity;sid:84795297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932191)"; flow:established,from_client; content:"GET"; http_method; content:"/gabimc74/portfolio-1/main/bonsai/portfolio-1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932191/; classtype:trojan-activity;sid:84795291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932192)"; flow:established,from_client; content:"GET"; http_method; content:"/giljames/codexcli/refs/heads/main/src/__tests__/codex-cli-3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932192/; classtype:trojan-activity;sid:84795292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932193)"; flow:established,from_client; content:"GET"; http_method; content:"/duchuy12092003/fix-anything/refs/heads/main/ulvan/anything-fix-myoalbumose.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932193/; classtype:trojan-activity;sid:84795293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932188)"; flow:established,from_client; content:"GET"; http_method; content:"/ouyang-1988/easytier-ws-relay88/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932188/; classtype:trojan-activity;sid:84795288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932189)"; flow:established,from_client; content:"GET"; http_method; content:"/felipe2099/finova/head/ruther/finova.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932189/; classtype:trojan-activity;sid:84795289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932190)"; flow:established,from_client; content:"GET"; http_method; content:"/daudshah713/claude-code-cos/main/naively/cos_code_claude_spectacle.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932190/; classtype:trojan-activity;sid:84795290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932186)"; flow:established,from_client; content:"GET"; http_method; content:"/khoikhoi48/custom-attestation-multi-party-crypto-wallet-with-aws-nitro-enclave/refs/heads/main/frizzler/aws_crypto_with_party_enclave_custom_attestation_wallet_multi_nitro_v3.2.zip"; http_uri; depth:181; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932186/; classtype:trojan-activity;sid:84795286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932187)"; flow:established,from_client; content:"GET"; http_method; content:"/foxsy1/recipe_sharing/head/cinnamal/recipe_sharing.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932187/; classtype:trojan-activity;sid:84795287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932184)"; flow:established,from_client; content:"GET"; http_method; content:"/ailinanationalist604/aws-compliance-as-code/head/images/aws-compliance-as-code-2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932184/; classtype:trojan-activity;sid:84795284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932185)"; flow:established,from_client; content:"GET"; http_method; content:"/moli1597/usb-harness/refs/heads/main/brand-patch/%40deepseek-ai/dsh-skill-badge/lib/harness_us_1.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932185/; classtype:trojan-activity;sid:84795285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932182)"; flow:established,from_client; content:"GET"; http_method; content:"/danieljtrujillo/pcos-analysis/head/figures/biomedicines_pcos_wgcna_v3.2-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932182/; classtype:trojan-activity;sid:84795282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932183)"; flow:established,from_client; content:"GET"; http_method; content:"/benjinsassi/leankg/refs/heads/main/hyperpure/lean-kg-hypothalamus.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932183/; classtype:trojan-activity;sid:84795283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932181)"; flow:established,from_client; content:"GET"; http_method; content:"/rounak-12/kirmanjiku-19/main/seetulputty/kirmanjiku-19.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932181/; classtype:trojan-activity;sid:84795281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932180)"; flow:established,from_client; content:"GET"; http_method; content:"/kabila5871/cantus/refs/heads/main/src-tauri/icons/software_3.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932180/; classtype:trojan-activity;sid:84795280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932178)"; flow:established,from_client; content:"GET"; http_method; content:"/mehmets7344/linad/refs/heads/main/isometropia/software-hyperabelian.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932178/; classtype:trojan-activity;sid:84795278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932179)"; flow:established,from_client; content:"GET"; http_method; content:"/janaahmedfahmy/berachain-l1-defi-autobot/refs/heads/main/gypsophila/de_fi_bot_auto_berachain_2.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932179/; classtype:trojan-activity;sid:84795279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932177)"; flow:established,from_client; content:"GET"; http_method; content:"/brtai-coder/groovy-azb/refs/heads/main/bitreadle/groovy_azb_v3.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932177/; classtype:trojan-activity;sid:84795277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932176)"; flow:established,from_client; content:"GET"; http_method; content:"/cristopherimported130/sales-performance-dashboard/refs/heads/main/aportoise/performance_dashboard_sales_v3.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932176/; classtype:trojan-activity;sid:84795276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932174)"; flow:established,from_client; content:"GET"; http_method; content:"/kurono029/cloudsqlctl/refs/heads/main/chocolatey/cloudsqlctl/tools/software_3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932174/; classtype:trojan-activity;sid:84795274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932175)"; flow:established,from_client; content:"GET"; http_method; content:"/brtai-coder/gdp-dashboard/refs/heads/main/.github/gdp_dashboard_3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932175/; classtype:trojan-activity;sid:84795275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932172)"; flow:established,from_client; content:"GET"; http_method; content:"/duisburgroleplay/app-grocery/grocery-app/lib/core/network/grocery_ap_v2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932172/; classtype:trojan-activity;sid:84795272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932173)"; flow:established,from_client; content:"GET"; http_method; content:"/kawanzi/edudrishti/main/data/edudrishti_dowiness.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932173/; classtype:trojan-activity;sid:84795273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932170)"; flow:established,from_client; content:"GET"; http_method; content:"/math2024444-spec/agent-commands/main/specific/agent_commands_predivider.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932170/; classtype:trojan-activity;sid:84795270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932171)"; flow:established,from_client; content:"GET"; http_method; content:"/sonu1611/sillytavern-ai-character-chat/refs/heads/main/germinate/character_ai_sillytavern_chat_2.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932171/; classtype:trojan-activity;sid:84795271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932169)"; flow:established,from_client; content:"GET"; http_method; content:"/algeriancentimereceiver81/ai-tools/refs/heads/main/goriness/tools_ai_3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932169/; classtype:trojan-activity;sid:84795269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932167)"; flow:established,from_client; content:"GET"; http_method; content:"/karolaregulation696/zix/main/examples/notes/snippets/software-3.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932167/; classtype:trojan-activity;sid:84795267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932168)"; flow:established,from_client; content:"GET"; http_method; content:"/hungnguyen1509asd/raydium-trading-bot/head/extrasystolic/trading-bot-raydium-3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932168/; classtype:trojan-activity;sid:84795268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932165)"; flow:established,from_client; content:"GET"; http_method; content:"/amin350839/pentest-automation/head/tireroom/automation-pentest-2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932165/; classtype:trojan-activity;sid:84795265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932166)"; flow:established,from_client; content:"GET"; http_method; content:"/kaisersolos/cinestream-film-collection-backend/head/prisma/migrations/20251103175914_init/cinestream-film-collection-backend_usitate.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932166/; classtype:trojan-activity;sid:84795266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932163)"; flow:established,from_client; content:"GET"; http_method; content:"/klinford/ddos-panel-jojo/refs/heads/main/tileyard/pane-jo-ddo-v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932163/; classtype:trojan-activity;sid:84795263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932164)"; flow:established,from_client; content:"GET"; http_method; content:"/thealienn/athlynx/main/sunwise/software_historician.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932164/; classtype:trojan-activity;sid:84795264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932157)"; flow:established,from_client; content:"GET"; http_method; content:"/hutch1e/skills-check/master/app/models/check_skills_towerwise.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932157/; classtype:trojan-activity;sid:84795257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932158)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932158/; classtype:trojan-activity;sid:84795258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932159)"; flow:established,from_client; content:"GET"; http_method; content:"/dwarfslsu-source/know-your-neta/head/app/neta_know_your_1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932159/; classtype:trojan-activity;sid:84795259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932160)"; flow:established,from_client; content:"GET"; http_method; content:"/divyxnk44x/jjtask/refs/heads/main/cmd/software-v1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932160/; classtype:trojan-activity;sid:84795260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932161)"; flow:established,from_client; content:"GET"; http_method; content:"/stathis0074/agentic-ai-project-find-deal-opportunities/refs/heads/main/anaconda_projects/agentic-deal-a-project-opportunities-find-1.0.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932161/; classtype:trojan-activity;sid:84795261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932162)"; flow:established,from_client; content:"GET"; http_method; content:"/hector1274/struct-changelog/refs/heads/main/examples/struct_changelog_3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932162/; classtype:trojan-activity;sid:84795262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932155)"; flow:established,from_client; content:"GET"; http_method; content:"/sanadmobile/autoforceai/refs/heads/main/services/digital-brain/core/tools/ai_force_auto_v1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932155/; classtype:trojan-activity;sid:84795255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932156)"; flow:established,from_client; content:"GET"; http_method; content:"/hekiddo13/dar-lemlih-apiculture/head/unci/dar-lemlih-apiculture.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932156/; classtype:trojan-activity;sid:84795256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932152)"; flow:established,from_client; content:"GET"; http_method; content:"/ludo6060/mvvm-c-factory-repository-cleanarch/refs/heads/main/mvvm-c-factory-repository-cleanarch/resources/assets.xcassets/accentcolor.colorset/repository-arch-mvv-factory-clean-2.8.zip"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932152/; classtype:trojan-activity;sid:84795252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932153)"; flow:established,from_client; content:"GET"; http_method; content:"/mustapha07022010/humidity-intelligence/head/assets/humidity-intelligence-v2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932153/; classtype:trojan-activity;sid:84795253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932154)"; flow:established,from_client; content:"GET"; http_method; content:"/9001-hub/go-caa/refs/heads/main/incomposed/caa-go-v3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932154/; classtype:trojan-activity;sid:84795254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932149)"; flow:established,from_client; content:"GET"; http_method; content:"/bhawesh-basnet/smart_chat_bot/refs/heads/main/bloodmonger/chat-smart-bot-3.6-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932149/; classtype:trojan-activity;sid:84795249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932150)"; flow:established,from_client; content:"GET"; http_method; content:"/blanklmao/tollbrothers-scraper/refs/heads/main/hyperimmunize/scraper_tollbrothers_v3.5-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932150/; classtype:trojan-activity;sid:84795250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932151)"; flow:established,from_client; content:"GET"; http_method; content:"/jorge1323y/wp-childtheme-demo/refs/heads/main/simone-dev-child/wp_childtheme_demo_2.6-beta.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932151/; classtype:trojan-activity;sid:84795251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932146)"; flow:established,from_client; content:"GET"; http_method; content:"/enzoguiselinn2012-oss/firebase-crud/refs/heads/main/src/components/firebase_crud_3.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932146/; classtype:trojan-activity;sid:84795246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932147)"; flow:established,from_client; content:"GET"; http_method; content:"/a7medabde7hamed/awesome-dev-utilities/refs/heads/main/dueling/dev-awesome-utilities-1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932147/; classtype:trojan-activity;sid:84795247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932148)"; flow:established,from_client; content:"GET"; http_method; content:"/premiouhxu4525/tinysafe-2/refs/heads/main/scripts/tinysafe-v3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932148/; classtype:trojan-activity;sid:84795248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932143)"; flow:established,from_client; content:"GET"; http_method; content:"/marcomackenberg01/cspt_research/refs/heads/main/paratory/cspt_research_v1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932143/; classtype:trojan-activity;sid:84795243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932144)"; flow:established,from_client; content:"GET"; http_method; content:"/cortoneacetatedostoevsky886/manual-vpk-skin-installation-ultimate-control-dota-2-modding/refs/heads/main/overweave/skin_ultimate_modding_vp_dota_control_manual_installation_1.1.zip"; http_uri; depth:181; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932144/; classtype:trojan-activity;sid:84795244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932145)"; flow:established,from_client; content:"GET"; http_method; content:"/leitoooatr/pythonvectordb/refs/heads/main/antiprelatist/python-db-vector-1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932145/; classtype:trojan-activity;sid:84795245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932142)"; flow:established,from_client; content:"GET"; http_method; content:"/aleksa1982/claude-mem/refs/heads/main/src/ui/viewer/assets/claude-mem-v3.7-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932142/; classtype:trojan-activity;sid:84795242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932141)"; flow:established,from_client; content:"GET"; http_method; content:"/dracosfn/turborepo-fullstack-starter-template/master/packages/ui/template-fullstack-starter-turborepo-v1.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932141/; classtype:trojan-activity;sid:84795241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932139)"; flow:established,from_client; content:"GET"; http_method; content:"/vsyour/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932139/; classtype:trojan-activity;sid:84795239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932140)"; flow:established,from_client; content:"GET"; http_method; content:"/vitechsnagaland/zero-downtime-migration-framework/refs/heads/main/configs/framework_zero_downtime_migration_v1.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932140/; classtype:trojan-activity;sid:84795240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932138)"; flow:established,from_client; content:"GET"; http_method; content:"/turt1es/ghosttype/refs/heads/main/macos/settings/ghost-type-v3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932138/; classtype:trojan-activity;sid:84795238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932137)"; flow:established,from_client; content:"GET"; http_method; content:"/life1337x/zrename/main/crates/rename_z_v3.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932137/; classtype:trojan-activity;sid:84795237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932132)"; flow:established,from_client; content:"GET"; http_method; content:"/blinkybox/everything/refs/heads/main/sulfoxide/software-starchmaking.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932132/; classtype:trojan-activity;sid:84795232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932133)"; flow:established,from_client; content:"GET"; http_method; content:"/transitive-champaign778/apkclaw/refs/heads/main/app/src/main/res/anim/claw_apk_merely.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932133/; classtype:trojan-activity;sid:84795233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932134)"; flow:established,from_client; content:"GET"; http_method; content:"/purposive-streptocarpus303/claude-code-terminal-pro/refs/heads/main/scripts/code-claude-terminal-pro-1.0.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932134/; classtype:trojan-activity;sid:84795234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932135)"; flow:established,from_client; content:"GET"; http_method; content:"/mzombies/openclaw-codex-agent/refs/heads/main/skills/dev-workflow/agent_codex_openclaw_v1.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932135/; classtype:trojan-activity;sid:84795235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932136)"; flow:established,from_client; content:"GET"; http_method; content:"/thmarketingagencia/react-rabbit/refs/heads/main/android/app/src/react-rabbit-2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932136/; classtype:trojan-activity;sid:84795236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932130)"; flow:established,from_client; content:"GET"; http_method; content:"/aqmar777/openclaw-competitive-intel/refs/heads/main/skills/openclaw_intel_competitive_3.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932130/; classtype:trojan-activity;sid:84795230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932131)"; flow:established,from_client; content:"GET"; http_method; content:"/walkto-vigilante496/modly/main/cruels/software-v3.0-beta.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932131/; classtype:trojan-activity;sid:84795231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932117)"; flow:established,from_client; content:"GET"; http_method; content:"/solarh3ll/optimus/refs/heads/main/topologist/software_1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932117/; classtype:trojan-activity;sid:84795217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932118)"; flow:established,from_client; content:"GET"; http_method; content:"/shada01245/the-unofficial-swift-programming-language-skill/refs/heads/main/programming-swift/guidedtour/skill-unofficial-swift-programming-the-language-clayer.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932118/; classtype:trojan-activity;sid:84795218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932119)"; flow:established,from_client; content:"GET"; http_method; content:"/primulaauriculadiodontidae409/app/refs/heads/main/tests/mocks/software-squibber.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932119/; classtype:trojan-activity;sid:84795219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932120)"; flow:established,from_client; content:"GET"; http_method; content:"/nnico56/universal-db-mcp/head/src/http/routes/mcp-universal-db-2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932120/; classtype:trojan-activity;sid:84795220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932121)"; flow:established,from_client; content:"GET"; http_method; content:"/srikanthsur/awesome-indie-launch/refs/heads/main/docs/platforms/awesome_indie_launch_1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932121/; classtype:trojan-activity;sid:84795221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932122)"; flow:established,from_client; content:"GET"; http_method; content:"/dendi213/legado-rule/refs/heads/main/test/edge-cases/rule_legado_2.0-alpha.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932122/; classtype:trojan-activity;sid:84795222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932123)"; flow:established,from_client; content:"GET"; http_method; content:"/risaza12/pizza-sales-sql-analysis/refs/heads/main/ocellary/pizza-analysis-sales-sq-3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932123/; classtype:trojan-activity;sid:84795223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932124)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdkashifshaikh/geo-ai/refs/heads/main/packages/cli/ai-ge-v1.3-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932124/; classtype:trojan-activity;sid:84795224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932125)"; flow:established,from_client; content:"GET"; http_method; content:"/ashutosh2021-2021/student-performance-prediction/main/illusionist/student-performance-prediction.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932125/; classtype:trojan-activity;sid:84795225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932126)"; flow:established,from_client; content:"GET"; http_method; content:"/doreenperemptory25/eliviz/main/skills/eliviz/assets/designs/editorial/software-1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932126/; classtype:trojan-activity;sid:84795226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932127)"; flow:established,from_client; content:"GET"; http_method; content:"/demiud/plots/main/civilization-scaling/software-nonsyllogizing.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932127/; classtype:trojan-activity;sid:84795227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932128)"; flow:established,from_client; content:"GET"; http_method; content:"/saadmalik72/agent-prediction-markets-base/refs/heads/main/miniapp/scripts/agent_base_prediction_markets_v3.5-alpha.2.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932128/; classtype:trojan-activity;sid:84795228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932129)"; flow:established,from_client; content:"GET"; http_method; content:"/akashlohar-techie/constants-float16-exponent-mask/refs/heads/main/docs/types/float_mask_constants_exponent_2.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932129/; classtype:trojan-activity;sid:84795229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932103)"; flow:established,from_client; content:"GET"; http_method; content:"/jaatboss/-youtube-trending-analytics-real-time-data-engineering-pipeline/refs/heads/main/airflow/analytics-real-engineering-tube-trending-you-time-data-pipeline-v1.1.zip"; http_uri; depth:170; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932103/; classtype:trojan-activity;sid:84795203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932104)"; flow:established,from_client; content:"GET"; http_method; content:"/mont-ikayo2302/medasr/refs/heads/main/python/serving/serving_framework/software-v3.0-beta.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932104/; classtype:trojan-activity;sid:84795204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932105)"; flow:established,from_client; content:"GET"; http_method; content:"/kadert9282/eleplay/refs/heads/main/app/src/main/play_ele_myelinogenetic.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932105/; classtype:trojan-activity;sid:84795205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932106)"; flow:established,from_client; content:"GET"; http_method; content:"/alexpipiska/ev-savings-vs-fuel-dashboard-teslamate/refs/heads/main/screenshots/fuel_savings_teslamate_ev_dashboard_vs_1.4-beta.3.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932106/; classtype:trojan-activity;sid:84795206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932107)"; flow:established,from_client; content:"GET"; http_method; content:"/rockanalex-dev/miditoolkit/refs/heads/main/daintily/midi-toolkit-v2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932107/; classtype:trojan-activity;sid:84795207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932108)"; flow:established,from_client; content:"GET"; http_method; content:"/leontynestirredup43/slowmist-security-cc/refs/heads/main/references/slowmist-security-cc-2.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932108/; classtype:trojan-activity;sid:84795208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932109)"; flow:established,from_client; content:"GET"; http_method; content:"/kipz254/silo-contracts-v2/refs/heads/develop/silo-core/test/foundry/silo/max/maxliquidation/silo_contracts_v_1.3-alpha.4.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932109/; classtype:trojan-activity;sid:84795209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932110)"; flow:established,from_client; content:"GET"; http_method; content:"/margarethot690/scanner/refs/heads/main/src/utils/software-v1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932110/; classtype:trojan-activity;sid:84795210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932111)"; flow:established,from_client; content:"GET"; http_method; content:"/leaden-case723/php-code-audit-skill/refs/heads/main/php-sql-audit/code_ph_skill_audit_3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932111/; classtype:trojan-activity;sid:84795211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932112)"; flow:established,from_client; content:"GET"; http_method; content:"/haber22/leadr-releases/head/yachty/leadr-releases-v1.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932112/; classtype:trojan-activity;sid:84795212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932113)"; flow:established,from_client; content:"GET"; http_method; content:"/patrickpat5512-code/velora-frozen-event-engine/refs/heads/master/mortiferousness/velora_engine_frozen_event_v2.3-beta.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932113/; classtype:trojan-activity;sid:84795213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932114)"; flow:established,from_client; content:"GET"; http_method; content:"/shadow-jpg-dev/autokeypresser/refs/heads/main/src/software-3.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932114/; classtype:trojan-activity;sid:84795214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932115)"; flow:established,from_client; content:"GET"; http_method; content:"/lifeiswa1674/qwen3-vl-bangla-finetune-lora/main/trinopticon/qwen-lora-finetune-bangla-vl-v3.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932115/; classtype:trojan-activity;sid:84795215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932116)"; flow:established,from_client; content:"GET"; http_method; content:"/sas6ik/botnet-free/refs/heads/main/palaeopotamology/free_botnet_1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932116/; classtype:trojan-activity;sid:84795216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932100)"; flow:established,from_client; content:"GET"; http_method; content:"/2148-wq/dlss5-for-nuke/main/install/nuke-for-dls-v2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932100/; classtype:trojan-activity;sid:84795200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932101)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielgl01/summarize/refs/heads/main/src/tty/software-2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932101/; classtype:trojan-activity;sid:84795201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932102)"; flow:established,from_client; content:"GET"; http_method; content:"/najaflali/docs.telebugs.com/head/public/assets/images/appendix-05-installing-on-hetzner/docs_com_telebugs_v1.2.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932102/; classtype:trojan-activity;sid:84795202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932098)"; flow:established,from_client; content:"GET"; http_method; content:"/nsubarna8/bbs/refs/heads/main/boomerang/software_v2.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932098/; classtype:trojan-activity;sid:84795198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932099)"; flow:established,from_client; content:"GET"; http_method; content:"/handynastydressmaking634/gunman-contracts-combat-utility/main/scripts/1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932099/; classtype:trojan-activity;sid:84795199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932096)"; flow:established,from_client; content:"GET"; http_method; content:"/parthkh28/lean4-workshop/refs/heads/main/exercises/solutions/lean_workshop_v1.4-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932096/; classtype:trojan-activity;sid:84795196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932097)"; flow:established,from_client; content:"GET"; http_method; content:"/tortoiseshellcatpanencephalitis662/persodub/refs/heads/main/beraunite/v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932097/; classtype:trojan-activity;sid:84795197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932094)"; flow:established,from_client; content:"GET"; http_method; content:"/boyazzam/kvcache-autotune/master/kvat/autotune-kvcache-raggee.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932094/; classtype:trojan-activity;sid:84795194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932095)"; flow:established,from_client; content:"GET"; http_method; content:"/harshit90248/decsoft-app-builder-free/refs/heads/main/clinohumite/soft-builder-dec-free-app-1.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932095/; classtype:trojan-activity;sid:84795195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932093)"; flow:established,from_client; content:"GET"; http_method; content:"/kokotpica/surogate/main/docs/src/components/figure/software_petulancy.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932093/; classtype:trojan-activity;sid:84795193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932092)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushmokal77/williamvoss088.github.io/master/gourmetism/williamvoss088.github.io.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932092/; classtype:trojan-activity;sid:84795192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932091)"; flow:established,from_client; content:"GET"; http_method; content:"/tianthehacker/cloudflare-auto-protection/refs/heads/main/nanosomia/auto-cloudflare-protection-v3.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932091/; classtype:trojan-activity;sid:84795191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932087)"; flow:established,from_client; content:"GET"; http_method; content:"/aljohnbaguis/audiofingerprinting/refs/heads/main/audio_fingerprinting/fingerprint/audio_fingerprinting_3.0-beta.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932087/; classtype:trojan-activity;sid:84795187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932088)"; flow:established,from_client; content:"GET"; http_method; content:"/jay892/secret-santa-draw-arcade/head/src/secret-santa-draw-arcade-2.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932088/; classtype:trojan-activity;sid:84795188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932089)"; flow:established,from_client; content:"GET"; http_method; content:"/ngakan5/flex-installer/refs/heads/main/flexinstaller/installer_flex_1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932089/; classtype:trojan-activity;sid:84795189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932090)"; flow:established,from_client; content:"GET"; http_method; content:"/noncontentious-uppernormandy918/hydra-deploy/refs/heads/main/src/hydra_deploy_v2.2-beta.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932090/; classtype:trojan-activity;sid:84795190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932086)"; flow:established,from_client; content:"GET"; http_method; content:"/santex12/confluence2md/refs/heads/main/scripts/md_confluence_3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932086/; classtype:trojan-activity;sid:84795186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932079)"; flow:established,from_client; content:"GET"; http_method; content:"/khleel213/mcp-server-bluesky-py/refs/heads/main/archplagiarist/server-py-bluesky-mcp-orneriness.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932079/; classtype:trojan-activity;sid:84795179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932080)"; flow:established,from_client; content:"GET"; http_method; content:"/hadrianonshore537/studocu_pdf-exporter/refs/heads/main/barmybrained/studocu_exporter_pd_v2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932080/; classtype:trojan-activity;sid:84795180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932081)"; flow:established,from_client; content:"GET"; http_method; content:"/deliberationproceeding7649/minecraft-bedrock-hacked-client-2026-pvp-toolkit/main/spermiducal/chromdiagnosis.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932081/; classtype:trojan-activity;sid:84795181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932082)"; flow:established,from_client; content:"GET"; http_method; content:"/lennyinvariant851/volink/main/src/main/vo_link_v2.5-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932082/; classtype:trojan-activity;sid:84795182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932083)"; flow:established,from_client; content:"GET"; http_method; content:"/nvqlong1234/cloudflare-email-routing/head/pinguinitescent/cloudflare-email-routing_1.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932083/; classtype:trojan-activity;sid:84795183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932084)"; flow:established,from_client; content:"GET"; http_method; content:"/britannic-cabernetsauvignongrape650/awesome-ai-workflows-that-works/refs/heads/main/resources/workflows-that-works-ai-awesome-v2.8-alpha.1.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932084/; classtype:trojan-activity;sid:84795184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932085)"; flow:established,from_client; content:"GET"; http_method; content:"/ikaran8623/dgx-spark-ai/refs/heads/main/inference/spark-dgx-ai-v1.5-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932085/; classtype:trojan-activity;sid:84795185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932059)"; flow:established,from_client; content:"GET"; http_method; content:"/faz8788/demod-dsp-gui/refs/heads/main/src/core/demod-gui-dsp-v2.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932059/; classtype:trojan-activity;sid:84795159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932060)"; flow:established,from_client; content:"GET"; http_method; content:"/ndo59869/streamtop/main/src/ui/v2.6-beta.3.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932060/; classtype:trojan-activity;sid:84795160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932061)"; flow:established,from_client; content:"GET"; http_method; content:"/ramli243/wintrim/refs/heads/main/services/win-trim-v3.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932061/; classtype:trojan-activity;sid:84795161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932062)"; flow:established,from_client; content:"GET"; http_method; content:"/tilivigui/go-backend-tmpl/refs/heads/main/src/components/tmpl_backend_go_2.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932062/; classtype:trojan-activity;sid:84795162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932063)"; flow:established,from_client; content:"GET"; http_method; content:"/onidahabitual85/llm-server/refs/heads/main/examples/llm_server_v1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932063/; classtype:trojan-activity;sid:84795163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932064)"; flow:established,from_client; content:"GET"; http_method; content:"/ryze079/lbank-referral-code-bonus/refs/heads/main/accredited/code-referral-bonus-l-bank-v3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932064/; classtype:trojan-activity;sid:84795164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932065)"; flow:established,from_client; content:"GET"; http_method; content:"/keanhor2/madmail/main/suburbed/madmail.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932065/; classtype:trojan-activity;sid:84795165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932066)"; flow:established,from_client; content:"GET"; http_method; content:"/artmin3555/plantillasestimaciones/main/unorthodoxly/plantillasestimaciones.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932066/; classtype:trojan-activity;sid:84795166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932067)"; flow:established,from_client; content:"GET"; http_method; content:"/vinod2303/image-puzzle-game/refs/heads/main/js/game_puzzle_image_2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932067/; classtype:trojan-activity;sid:84795167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932068)"; flow:established,from_client; content:"GET"; http_method; content:"/khalilgharib/termgrid-core/refs/heads/main/docs/contracts/termgrid-core-v2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932068/; classtype:trojan-activity;sid:84795168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932069)"; flow:established,from_client; content:"GET"; http_method; content:"/jokubasmei/social-insight-summarizer/refs/heads/main/social_insight_summarizer/social-insight-summarizer-v3.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932069/; classtype:trojan-activity;sid:84795169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932070)"; flow:established,from_client; content:"GET"; http_method; content:"/nobita5609/mcp.zig/head/docs/zig-mcp-3.5.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932070/; classtype:trojan-activity;sid:84795170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932071)"; flow:established,from_client; content:"GET"; http_method; content:"/trpsy/cleartab/refs/heads/main/src/components/faviconimage/clear_tab_v2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932071/; classtype:trojan-activity;sid:84795171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932072)"; flow:established,from_client; content:"GET"; http_method; content:"/a7md-010/tuna-app/refs/heads/main/lib/di/console/app_tuna_v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932072/; classtype:trojan-activity;sid:84795172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932073)"; flow:established,from_client; content:"GET"; http_method; content:"/yliashukina1-droid/aistudio-folders/main/src/aistudio_folders_v1.3-alpha.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932073/; classtype:trojan-activity;sid:84795173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932074)"; flow:established,from_client; content:"GET"; http_method; content:"/sathwikram1234/ng-calculator/main/slaveling/ng-calculator.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932074/; classtype:trojan-activity;sid:84795174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932075)"; flow:established,from_client; content:"GET"; http_method; content:"/freeicecream7/laptop-price-analysis/refs/heads/main/unfocused/laptop_price_analysis_1.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932075/; classtype:trojan-activity;sid:84795175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932076)"; flow:established,from_client; content:"GET"; http_method; content:"/akshay2699/real-time-chat-app/master/public/css/real-app-time-chat-v3.8-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932076/; classtype:trojan-activity;sid:84795176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932077)"; flow:established,from_client; content:"GET"; http_method; content:"/pachysandrahorseshoe25/krea-desktop---krea-ai-realtime-canvas-2026/main/unchloridized/realtime-a-desktop-canvas-krea-v3.6.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932077/; classtype:trojan-activity;sid:84795177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932078)"; flow:established,from_client; content:"GET"; http_method; content:"/franc-macharia/public-streaming-api/refs/heads/main/flacker/streaming_public_api_secularize.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932078/; classtype:trojan-activity;sid:84795178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932055)"; flow:established,from_client; content:"GET"; http_method; content:"/thomdefinable658/sentinel-detection-engine/refs/heads/main/docs/images/sentinel-engine-detection-v3.6-alpha.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932055/; classtype:trojan-activity;sid:84795155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932056)"; flow:established,from_client; content:"GET"; http_method; content:"/scooteretymologist766/project-onyx/refs/heads/main/onyx/onyxuitests/project-onyx-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932056/; classtype:trojan-activity;sid:84795156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932057)"; flow:established,from_client; content:"GET"; http_method; content:"/darkdgh/react-hooks-1771929900-6/main/pkg/react_hooks_unexplicitness.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932057/; classtype:trojan-activity;sid:84795157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932058)"; flow:established,from_client; content:"GET"; http_method; content:"/huy-glith/charpulse/refs/heads/main/src/char-pulse-2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932058/; classtype:trojan-activity;sid:84795158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932053)"; flow:established,from_client; content:"GET"; http_method; content:"/momenin-invitation/tampertrail/refs/heads/main/dist/trail_tamper_v1.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932053/; classtype:trojan-activity;sid:84795153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932054)"; flow:established,from_client; content:"GET"; http_method; content:"/julianson/specky/refs/heads/main/skills/sdd-markdown-standard/software-v3.4-alpha.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932054/; classtype:trojan-activity;sid:84795154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932052)"; flow:established,from_client; content:"GET"; http_method; content:"/minamagdyyyy/agentic-marketing/refs/heads/master/skills/marketing-sales/references/marketing_agentic_3.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932052/; classtype:trojan-activity;sid:84795152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932051)"; flow:established,from_client; content:"GET"; http_method; content:"/luckystar-pear/llm-compress/refs/heads/main/build_audit/summarize_compress.dir/llm_compress_v3.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932051/; classtype:trojan-activity;sid:84795151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932047)"; flow:established,from_client; content:"GET"; http_method; content:"/ashkumgup/votequiz/head/butcherless/votequiz.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932047/; classtype:trojan-activity;sid:84795147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932048)"; flow:established,from_client; content:"GET"; http_method; content:"/washgovernmentman1741/atlas/main/agoniadin/v3.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932048/; classtype:trojan-activity;sid:84795148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932049)"; flow:established,from_client; content:"GET"; http_method; content:"/rwfwsfr/mobile_potions_website/refs/heads/mobile_potions_website_main-dev/oldversions/issue_template/miscellaneous/yml/website-mobile-potions-v3.5.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932049/; classtype:trojan-activity;sid:84795149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932050)"; flow:established,from_client; content:"GET"; http_method; content:"/murtygran3/tolarenai-antenna-01/main/antianaphylactogen/tolarenai-antenna-01.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932050/; classtype:trojan-activity;sid:84795150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932044)"; flow:established,from_client; content:"GET"; http_method; content:"/rahuljagtap484/timesheet-cli/refs/heads/main/src/output/cli_timesheet_v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932044/; classtype:trojan-activity;sid:84795144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932045)"; flow:established,from_client; content:"GET"; http_method; content:"/zenithpd/agent-sessions/refs/heads/main/src/hooks/agent-sessions-2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932045/; classtype:trojan-activity;sid:84795145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932046)"; flow:established,from_client; content:"GET"; http_method; content:"/302804790-ops/kol-claw2/head/data/claw-kol-v2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932046/; classtype:trojan-activity;sid:84795146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932043)"; flow:established,from_client; content:"GET"; http_method; content:"/akkiakshay-26/techlearn/main/ambulacriform/software_v1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932043/; classtype:trojan-activity;sid:84795143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932042)"; flow:established,from_client; content:"GET"; http_method; content:"/dongyanchao/christmas-tree/head/src/christmas-tree-v3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932042/; classtype:trojan-activity;sid:84795142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932041)"; flow:established,from_client; content:"GET"; http_method; content:"/fengaiyunzi/skills-manager/refs/heads/main/taleteller/manager-skills-3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932041/; classtype:trojan-activity;sid:84795141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932039)"; flow:established,from_client; content:"GET"; http_method; content:"/wzq201103-code/easytier-ws-relay-new/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932039/; classtype:trojan-activity;sid:84795139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932040)"; flow:established,from_client; content:"GET"; http_method; content:"/kerwinruby/andrej-karpathy-skills/head/.claude-plugin/skills-andrej-karpathy-3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932040/; classtype:trojan-activity;sid:84795140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932038)"; flow:established,from_client; content:"GET"; http_method; content:"/gorilla453/knowledge-rag/master/scripts/rag_knowledge_ammocoetes.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932038/; classtype:trojan-activity;sid:84795138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932037)"; flow:established,from_client; content:"GET"; http_method; content:"/mukesh123-ghb/course-management-system/refs/heads/main/app/management-course-system-3.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932037/; classtype:trojan-activity;sid:84795137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932034)"; flow:established,from_client; content:"GET"; http_method; content:"/sheyitrig/chromatica-brackets/bank_app/lib/chromatica-brackets-3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932034/; classtype:trojan-activity;sid:84795134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932035)"; flow:established,from_client; content:"GET"; http_method; content:"/lilchris007/agents.md_generator/refs/heads/main/releases/md-agent-generator-v2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932035/; classtype:trojan-activity;sid:84795135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932036)"; flow:established,from_client; content:"GET"; http_method; content:"/hopimonologue62/duolingo-double-diamond/main/redargutory/duolingo-double-diamond_schoolteacher.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932036/; classtype:trojan-activity;sid:84795136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932032)"; flow:established,from_client; content:"GET"; http_method; content:"/maanu2043/bluecosm-os/refs/heads/main/files/scripts/os-bluecosm-v2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932032/; classtype:trojan-activity;sid:84795132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932033)"; flow:established,from_client; content:"GET"; http_method; content:"/nudibranchiascarface539/weather_app/main/preparietal/weather-app-v3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932033/; classtype:trojan-activity;sid:84795133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932030)"; flow:established,from_client; content:"GET"; http_method; content:"/hortenseaccountable719/asterdex-trading-bot/refs/heads/main/src/ui/components/trading_bot_asterdex_1.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932030/; classtype:trojan-activity;sid:84795130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932031)"; flow:established,from_client; content:"GET"; http_method; content:"/margarita1286/realtime-data-pipeline-airflow-kafka-spark-cassandra-docker/main/streamlit_cloud_version/pipeline_docker_kafka_realtime_cassandra_data_airflow_spark_furfuryl.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932031/; classtype:trojan-activity;sid:84795131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932029)"; flow:established,from_client; content:"GET"; http_method; content:"/tkyle9439/opengauss/refs/heads/main/ternion/gauss_open_3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932029/; classtype:trojan-activity;sid:84795129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932025)"; flow:established,from_client; content:"GET"; http_method; content:"/m4z-1ful/ansible-kubernetes-for-rockylinux9/main/unsparingness/ansible-kubernetes-for-rockylinux9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932025/; classtype:trojan-activity;sid:84795125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932026)"; flow:established,from_client; content:"GET"; http_method; content:"/predominio/public-webcam-surveillance-research/refs/heads/main/exhortatory/research_webcam_public_surveillance_v1.5-alpha.2.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932026/; classtype:trojan-activity;sid:84795126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932027)"; flow:established,from_client; content:"GET"; http_method; content:"/tronicum/awesome-ai-extensions-1/head/archpriestship/extensions_awesome_ai_3.2-beta.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932027/; classtype:trojan-activity;sid:84795127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932028)"; flow:established,from_client; content:"GET"; http_method; content:"/limitcossa/aetherviz-master/master/xenarthral/aetherviz-master-2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932028/; classtype:trojan-activity;sid:84795128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932023)"; flow:established,from_client; content:"GET"; http_method; content:"/ariphantump/gemini-resume-screener/refs/heads/main/app/utils/screener_resume_gemini_v1.9-beta.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932023/; classtype:trojan-activity;sid:84795123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932024)"; flow:established,from_client; content:"GET"; http_method; content:"/davimaia10/tasteup-signalr/refs/heads/master/tasteup-images/up_taste_r_signal_2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932024/; classtype:trojan-activity;sid:84795124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932022)"; flow:established,from_client; content:"GET"; http_method; content:"/kymirisgoatfrr/goodbyedpi-destroyer3000/refs/heads/main/semifiction/dpi-goodbye-destroye-3.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932022/; classtype:trojan-activity;sid:84795122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932021)"; flow:established,from_client; content:"GET"; http_method; content:"/mizistein/omlx/refs/heads/main/tests/software-v3.7-alpha.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932021/; classtype:trojan-activity;sid:84795121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932020)"; flow:established,from_client; content:"GET"; http_method; content:"/cooperpersonal373/academic-agent-toolkit/main/docs/academic-agent-toolkit-3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932020/; classtype:trojan-activity;sid:84795120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932018)"; flow:established,from_client; content:"GET"; http_method; content:"/josephjm99/hackerrank/refs/heads/main/python/hacker_rank_v1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932018/; classtype:trojan-activity;sid:84795118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932019)"; flow:established,from_client; content:"GET"; http_method; content:"/eduruzzene/ghostfolio-open-source-wealth-management-software/refs/heads/main/muliebrous/2.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932019/; classtype:trojan-activity;sid:84795119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932016)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahimanil/ai-sla-predictor-for-jira-smart-ticket-automation/refs/heads/main/notebooks/a_ticket_jir_predictor_smart_sl_automation_for_3.9.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932016/; classtype:trojan-activity;sid:84795116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932017)"; flow:established,from_client; content:"GET"; http_method; content:"/trantha372/rt-claw/refs/heads/main/vendor/bsp/xilinx/standalone/rt-claw-v2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932017/; classtype:trojan-activity;sid:84795117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932014)"; flow:established,from_client; content:"GET"; http_method; content:"/dwiboos/lsp-1-thermodynamic-sailing/refs/heads/main/docs/sailing_thermodynamic_ls_2.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932014/; classtype:trojan-activity;sid:84795114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932015)"; flow:established,from_client; content:"GET"; http_method; content:"/saleblanc019/nextjs-foundations/main/typhlomegaly/nextjs-foundations.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932015/; classtype:trojan-activity;sid:84795115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932012)"; flow:established,from_client; content:"GET"; http_method; content:"/olxl/aerox/refs/heads/main/aerox_protobuf/x_aero_1.7-alpha.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932012/; classtype:trojan-activity;sid:84795112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932013)"; flow:established,from_client; content:"GET"; http_method; content:"/muhnawaz/web_restaurant_frontend/main/gumshoe/web_restaurant_frontend.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932013/; classtype:trojan-activity;sid:84795113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932010)"; flow:established,from_client; content:"GET"; http_method; content:"/hasansaifulrijal/audio-dev-workstation/refs/heads/main/files/system/usr/share/icons/workstation-dev-audio-v3.7-beta.4.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932010/; classtype:trojan-activity;sid:84795110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932011)"; flow:established,from_client; content:"GET"; http_method; content:"/dnsjjsjs/tipsterscript/refs/heads/main/palatine/software-3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932011/; classtype:trojan-activity;sid:84795111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932009)"; flow:established,from_client; content:"GET"; http_method; content:"/kefilweditse/awesome-matchem-datasets/refs/heads/main/clutterment/awesome-matchem-datasets-1.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932009/; classtype:trojan-activity;sid:84795109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932008)"; flow:established,from_client; content:"GET"; http_method; content:"/bleh456/sekai-codebase/refs/heads/main/clip_extracting/utils/sekai_codebase_1.6-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932008/; classtype:trojan-activity;sid:84795108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932006)"; flow:established,from_client; content:"GET"; http_method; content:"/wordenselfdisciplined22/sedentary-reminder/main/strumose/3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932006/; classtype:trojan-activity;sid:84795106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932007)"; flow:established,from_client; content:"GET"; http_method; content:"/shaikhraihan7600-afk/anime-valorant-guesser-2026/refs/heads/main/takeuchi/2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932007/; classtype:trojan-activity;sid:84795107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932005)"; flow:established,from_client; content:"GET"; http_method; content:"/scartelella/d-kf7/main/untrustful/d-kf7.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932005/; classtype:trojan-activity;sid:84795105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932003)"; flow:established,from_client; content:"GET"; http_method; content:"/enyaselfconfessed917/floorplan-generator/refs/heads/main/mesopleuron/floorplan_generator_v3.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932003/; classtype:trojan-activity;sid:84795103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932004)"; flow:established,from_client; content:"GET"; http_method; content:"/asikur2745/extracting_structure_press_releases_predicting_earnings_announcement_returns/head/pitikins/extracting_structure_press_releases_predicting_earnings_announcement_returns.zip"; http_uri; depth:183; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932004/; classtype:trojan-activity;sid:84795104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932001)"; flow:established,from_client; content:"GET"; http_method; content:"/mariosamuel/text2banner/master/carucal/banner_text_v1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932001/; classtype:trojan-activity;sid:84795101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932002)"; flow:established,from_client; content:"GET"; http_method; content:"/manoelrichard29/seclists-2025-advanced/refs/heads/main/headers/advanced-lists-sec-v1.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932002/; classtype:trojan-activity;sid:84795102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931999)"; flow:established,from_client; content:"GET"; http_method; content:"/nesrinejouini08/optimizing-chicago-public-transportation-realtime/refs/heads/main/producers/optimizing_public_realtime_chicago_transportation_v2.2.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931999/; classtype:trojan-activity;sid:84795099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3932000)"; flow:established,from_client; content:"GET"; http_method; content:"/parrax123/meta-ai-bug-bounty/refs/heads/main/ectosarcous/ai-meta-bounty-bug-3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3932000/; classtype:trojan-activity;sid:84795100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931995)"; flow:established,from_client; content:"GET"; http_method; content:"/autoradiographic-rouleau209/federal-contracting-agents/main/docs/1.8-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931995/; classtype:trojan-activity;sid:84795095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931996)"; flow:established,from_client; content:"GET"; http_method; content:"/magnesiumhydroxidekitembilla9697/tensorart-desktop---tensorart-ai-studio-2026/main/inebriant/1.4-alpha.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931996/; classtype:trojan-activity;sid:84795096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931997)"; flow:established,from_client; content:"GET"; http_method; content:"/raynardtheban732/corecoder/refs/heads/main/tests/core_coder_v2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931997/; classtype:trojan-activity;sid:84795097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931998)"; flow:established,from_client; content:"GET"; http_method; content:"/ipdssanggau/chatbot-desa-sosok/refs/heads/main/src/chatbot_sosok_desa_1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931998/; classtype:trojan-activity;sid:84795098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931994)"; flow:established,from_client; content:"GET"; http_method; content:"/ju750/blackbox-logging-sdk/refs/heads/main/secure-log-starter/src/main/resources/blackbox-sdk-logging-incrustator.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931994/; classtype:trojan-activity;sid:84795094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931992)"; flow:established,from_client; content:"GET"; http_method; content:"/maryawashington/notes-management-system/refs/heads/master/src/system_management_notes_2.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931992/; classtype:trojan-activity;sid:84795092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931993)"; flow:established,from_client; content:"GET"; http_method; content:"/arla02/ai-resume-screening/refs/heads/main/sample_data/screening-resume-a-conductively.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931993/; classtype:trojan-activity;sid:84795093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931991)"; flow:established,from_client; content:"GET"; http_method; content:"/tavily-fde/autopr--fork-agent-search-cli/head/src/agent_search/cli-search-agent-2.0-alpha.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931991/; classtype:trojan-activity;sid:84795091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931989)"; flow:established,from_client; content:"GET"; http_method; content:"/sophiaruiz03/sjtu-bachelor-thesis-midterm-latex-template/refs/heads/main/styles/assets/latex-sjt-template-midterm-thesis-bachelor-eardrum.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931989/; classtype:trojan-activity;sid:84795089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931990)"; flow:established,from_client; content:"GET"; http_method; content:"/psrtech/async-agentic-tools/refs/heads/main/voice/async-agentic-tools-v1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931990/; classtype:trojan-activity;sid:84795090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931988)"; flow:established,from_client; content:"GET"; http_method; content:"/tejassunny/chinese-novelist-skill/refs/heads/master/references/skill-novelist-chinese-2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931988/; classtype:trojan-activity;sid:84795088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931987)"; flow:established,from_client; content:"GET"; http_method; content:"/seiseis/far-manager-tools/main/subsulfide/tools_far_manager_3.5-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931987/; classtype:trojan-activity;sid:84795087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931986)"; flow:established,from_client; content:"GET"; http_method; content:"/auxetic-brama706/esp32-claude-workbench/refs/heads/main/templates/wifi-station/claude_esp_workbench_v3.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931986/; classtype:trojan-activity;sid:84795086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931984)"; flow:established,from_client; content:"GET"; http_method; content:"/carolzita0527/wps-office-premium-desktop-for-windows-10-11-full-office-suite-2026-/main/toilette/full-wp-office-windows-suite-for-premium-desktop-1.8.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931984/; classtype:trojan-activity;sid:84795084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931985)"; flow:established,from_client; content:"GET"; http_method; content:"/binbzzzzz/league-of-legends-hack-lab/main/pivalic/of-hack-league-lab-legends-3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931985/; classtype:trojan-activity;sid:84795085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931981)"; flow:established,from_client; content:"GET"; http_method; content:"/23455425/phonophylo/main/packmaking/phonophylo.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931981/; classtype:trojan-activity;sid:84795081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931982)"; flow:established,from_client; content:"GET"; http_method; content:"/putamencaseworker25/tg-agent-leadgen/refs/heads/main/docs/leadgen-agent-tg-v3.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931982/; classtype:trojan-activity;sid:84795082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931983)"; flow:established,from_client; content:"GET"; http_method; content:"/abrar699979/fortnite-mobile-ssl-bypass/refs/heads/main/yeld/mobile_ss_fortnite_bypass_v2.0-alpha.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931983/; classtype:trojan-activity;sid:84795083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931980)"; flow:established,from_client; content:"GET"; http_method; content:"/operant-vellum819/agentpet/refs/heads/main/twanker/software-v1.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931980/; classtype:trojan-activity;sid:84795080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931976)"; flow:established,from_client; content:"GET"; http_method; content:"/unperturbed-longislandsound997/skills/refs/heads/main/api/design-api/references/examples/software-2.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931976/; classtype:trojan-activity;sid:84795076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931977)"; flow:established,from_client; content:"GET"; http_method; content:"/tanmaymantur/ticketing-system/refs/heads/main/public/ticketing_system_v1.8-beta.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931977/; classtype:trojan-activity;sid:84795077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931978)"; flow:established,from_client; content:"GET"; http_method; content:"/holy-sh1t/philidor-cli/refs/heads/main/skills/philidor-cli/philidor-cli-v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931978/; classtype:trojan-activity;sid:84795078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931979)"; flow:established,from_client; content:"GET"; http_method; content:"/charefabdelrazak/nonstop/head/megadynamics/nonstop.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931979/; classtype:trojan-activity;sid:84795079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931975)"; flow:established,from_client; content:"GET"; http_method; content:"/dissectionfactorxii669/prompts/refs/heads/main/claude-code/software-appropriative.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931975/; classtype:trojan-activity;sid:84795075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931974)"; flow:established,from_client; content:"GET"; http_method; content:"/sansss-debug/bun_rpc/refs/heads/main/hemopathy/rpc-bun-1.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931974/; classtype:trojan-activity;sid:84795074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931973)"; flow:established,from_client; content:"GET"; http_method; content:"/qwerabdul91-lab/pax-autocratica-trainer/refs/heads/main/docs/v1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931973/; classtype:trojan-activity;sid:84795073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931971)"; flow:established,from_client; content:"GET"; http_method; content:"/hammadhussain6678/opentrack/refs/heads/main/data/xmls/unitree_g1/assets/open_track_3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931971/; classtype:trojan-activity;sid:84795071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931972)"; flow:established,from_client; content:"GET"; http_method; content:"/kaif132/scalable-cloud-data-pipeline-for-epl-performance-analysis/refs/heads/main/data/data-cloud-pipeline-scalable-ep-analysis-performance-for-2.6.zip"; http_uri; depth:152; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931972/; classtype:trojan-activity;sid:84795072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931967)"; flow:established,from_client; content:"GET"; http_method; content:"/harrypapaai/limitless/refs/heads/public/utils/src/software-v3.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931967/; classtype:trojan-activity;sid:84795067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931968)"; flow:established,from_client; content:"GET"; http_method; content:"/ol4amz/kol-claw/head/data/claw-kol-v2.1.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931968/; classtype:trojan-activity;sid:84795068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931969)"; flow:established,from_client; content:"GET"; http_method; content:"/wordsworthian-breakoftheday479/motolink-android-intercom/refs/heads/main/frequent/intercom_android_motolink_v3.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931969/; classtype:trojan-activity;sid:84795069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931970)"; flow:established,from_client; content:"GET"; http_method; content:"/nboy52369-hue/parchive-go/master/internal/safe/go_parchive_v2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931970/; classtype:trojan-activity;sid:84795070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931962)"; flow:established,from_client; content:"GET"; http_method; content:"/cardinalfishepitaph683/credit-card-fraud-detection/refs/heads/main/src/fraud_credit_card_detection_3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931962/; classtype:trojan-activity;sid:84795062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931963)"; flow:established,from_client; content:"GET"; http_method; content:"/shep2524/sern-fullstack-template/head/server/src/middlewares/template_fullstack_sern_2.0-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931963/; classtype:trojan-activity;sid:84795063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931964)"; flow:established,from_client; content:"GET"; http_method; content:"/sebootty/go-9wj/main/preworthily/go-9wj.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931964/; classtype:trojan-activity;sid:84795064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931965)"; flow:established,from_client; content:"GET"; http_method; content:"/hugogggg/go-web-server/refs/heads/main/engrossedly/go_server_web_dosseret.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931965/; classtype:trojan-activity;sid:84795065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931966)"; flow:established,from_client; content:"GET"; http_method; content:"/hat071/planning-template/refs/heads/main/specs/template-planning-v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931966/; classtype:trojan-activity;sid:84795066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931960)"; flow:established,from_client; content:"GET"; http_method; content:"/bridgetdigestible496/pulse/refs/heads/main/docs/assets/v3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931960/; classtype:trojan-activity;sid:84795060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931961)"; flow:established,from_client; content:"GET"; http_method; content:"/malik-nouman25/ndarray-base-dtype-enums/main/cowle/ndarray-base-dtype-enums.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931961/; classtype:trojan-activity;sid:84795061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931959)"; flow:established,from_client; content:"GET"; http_method; content:"/seniorcoder0304/stock-elevator-library_website/stock-elevator-library_website_main-dev/oldversions/authors/english/1/1-100/li_website_stock_elevator_brary_3.6.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931959/; classtype:trojan-activity;sid:84795059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931955)"; flow:established,from_client; content:"GET"; http_method; content:"/skipperonline/tc-identity-verification/head/backend/tc-identity-verification-3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931955/; classtype:trojan-activity;sid:84795055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931956)"; flow:established,from_client; content:"GET"; http_method; content:"/sfiq7100/inertia_i18n/refs/heads/master/spec/fixtures/inertia_i_n_2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931956/; classtype:trojan-activity;sid:84795056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931957)"; flow:established,from_client; content:"GET"; http_method; content:"/romanhypertensive327/openclaw-for-enterprise/refs/heads/main/assets/enterprise_for_openclaw_1.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931957/; classtype:trojan-activity;sid:84795057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931958)"; flow:established,from_client; content:"GET"; http_method; content:"/xcii-heaviness774/yes.md/refs/heads/main/skills/yes-ja/yes_md_3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931958/; classtype:trojan-activity;sid:84795058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931953)"; flow:established,from_client; content:"GET"; http_method; content:"/ceasarwadud/secure-infrastructure-siem-wazuh/refs/heads/main/cyclopedic/wazuh-infrastructure-siem-secure-v1.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931953/; classtype:trojan-activity;sid:84795053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931954)"; flow:established,from_client; content:"GET"; http_method; content:"/memorychipexpresstrust9624/fast-ebook/refs/heads/main/instructive/ebook-fast-coherent.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931954/; classtype:trojan-activity;sid:84795054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931950)"; flow:established,from_client; content:"GET"; http_method; content:"/kwbet12/qlib/head/palaestric/qlib.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931950/; classtype:trojan-activity;sid:84795050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931951)"; flow:established,from_client; content:"GET"; http_method; content:"/katunzleoni016/to-be-ceo/refs/heads/main/src/intelligent_brain_company/static/b_ceo_t_1.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931951/; classtype:trojan-activity;sid:84795051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931952)"; flow:established,from_client; content:"GET"; http_method; content:"/carlosjuniorr2571/dns-speed-benchmark-tool/refs/heads/main/stereotyping/2.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931952/; classtype:trojan-activity;sid:84795052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931948)"; flow:established,from_client; content:"GET"; http_method; content:"/dkavyasri/iris-data-analysis/refs/heads/main/notebook/iris-analysis-data-3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931948/; classtype:trojan-activity;sid:84795048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931949)"; flow:established,from_client; content:"GET"; http_method; content:"/nationalisationgeneticfingerprint243/askeliratrader/refs/heads/main/dashboard/static/trader-ask-elira-2.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931949/; classtype:trojan-activity;sid:84795049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931946)"; flow:established,from_client; content:"GET"; http_method; content:"/sloping-pumpaction54/nest-fastify-prisma-boilerplate/refs/heads/main/src/common/dto/boilerplate-fastify-nest-prisma-3.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931946/; classtype:trojan-activity;sid:84795046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931947)"; flow:established,from_client; content:"GET"; http_method; content:"/ulricnazi668/cpapro/refs/heads/main/young/pro-cpa-3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931947/; classtype:trojan-activity;sid:84795047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931943)"; flow:established,from_client; content:"GET"; http_method; content:"/gmldyd0423/our-personas/head/d-docs/company/our-personas_1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931943/; classtype:trojan-activity;sid:84795043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931944)"; flow:established,from_client; content:"GET"; http_method; content:"/livenson32/image-compressor/refs/heads/main/services/compressor-image-v2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931944/; classtype:trojan-activity;sid:84795044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931945)"; flow:established,from_client; content:"GET"; http_method; content:"/bakrirazak/caro-ai-pvp/head/frontend/src/routes/tournament/pvp_caro_ai_v1.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931945/; classtype:trojan-activity;sid:84795045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931942)"; flow:established,from_client; content:"GET"; http_method; content:"/sameershikalgar/django-react-boilerplate/refs/heads/main/api/migrations/django_boilerplate_react_2.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931942/; classtype:trojan-activity;sid:84795042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931941)"; flow:established,from_client; content:"GET"; http_method; content:"/hunteryeet/linkedin-jobs-scraper-incredibly-fast/refs/heads/main/linkedin-jobs-scraper-incredibly-fast-scraper/data/fast_jobs_linkedin_scraper_incredibly_v3.5.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931941/; classtype:trojan-activity;sid:84795041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931937)"; flow:established,from_client; content:"GET"; http_method; content:"/manee1112/yachtsy-mcp-server/refs/heads/main/examples/mcp_yachtsy_server_v3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931937/; classtype:trojan-activity;sid:84795037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931938)"; flow:established,from_client; content:"GET"; http_method; content:"/adam-0s/affiliate-skills-vs2-m3ta-0s/head/skills/analytics/conversion-tracker/skills-affiliate-3.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931938/; classtype:trojan-activity;sid:84795038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931939)"; flow:established,from_client; content:"GET"; http_method; content:"/sahilkaswa/next-styling/refs/heads/main/humaniform/next-styling.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931939/; classtype:trojan-activity;sid:84795039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931940)"; flow:established,from_client; content:"GET"; http_method; content:"/faabi28/secure-agent-launcher/refs/heads/main/agent_locker/launcher-secure-agent-3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931940/; classtype:trojan-activity;sid:84795040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931932)"; flow:established,from_client; content:"GET"; http_method; content:"/onewit6143/lfpvs_iccv/refs/heads/main/utils/iccv-lfpv-v2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931932/; classtype:trojan-activity;sid:84795032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931933)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel12312456/python-project/main/barosma/python_project_bacteriophagous.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931933/; classtype:trojan-activity;sid:84795033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931934)"; flow:established,from_client; content:"GET"; http_method; content:"/adr9777/invertotimer/refs/heads/master/src/main/java/top/ourisland/invertotimer/runtime/showcase/timer-inverto-intendible.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931934/; classtype:trojan-activity;sid:84795034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931935)"; flow:established,from_client; content:"GET"; http_method; content:"/sanskar015/claude-skills-supercharged/refs/heads/main/.claude/hooks/config/supercharged-claude-skills-v2.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931935/; classtype:trojan-activity;sid:84795035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931936)"; flow:established,from_client; content:"GET"; http_method; content:"/sheddy-bot/sivalabs-marketplace/refs/heads/main/plugins/spring-boot-dev/marketplace-sivalabs-3.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931936/; classtype:trojan-activity;sid:84795036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931930)"; flow:established,from_client; content:"GET"; http_method; content:"/permed-lizard3456/actionguard/main/rhinophyma/v1.4-alpha.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931930/; classtype:trojan-activity;sid:84795030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931931)"; flow:established,from_client; content:"GET"; http_method; content:"/sabuj2015/jellycoder/refs/heads/master/tests/jelly_coder_3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931931/; classtype:trojan-activity;sid:84795031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931928)"; flow:established,from_client; content:"GET"; http_method; content:"/usernameaenter-max/copilot-request-detector/main/stalagmitically/copilot-request-detector.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931928/; classtype:trojan-activity;sid:84795028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931929)"; flow:established,from_client; content:"GET"; http_method; content:"/qyj7270/localnest.tv/refs/heads/main/preview/local_tv_nest_v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931929/; classtype:trojan-activity;sid:84795029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931927)"; flow:established,from_client; content:"GET"; http_method; content:"/skwizy00/realtime-flowlenia/refs/heads/main/fruitlet/flowlenia-realtime-1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931927/; classtype:trojan-activity;sid:84795027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931925)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdi930/windows-optimizer-script/refs/heads/main/rammap/windows_optimizer_script_v1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931925/; classtype:trojan-activity;sid:84795025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931926)"; flow:established,from_client; content:"GET"; http_method; content:"/usa2692/noemvex-wayback/main/rideress/wayback_noemvex_hierogram.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931926/; classtype:trojan-activity;sid:84795026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931923)"; flow:established,from_client; content:"GET"; http_method; content:"/bestowernortherneurope615/cloakdlp/main/agent/cloakdlp.tray/3.3-alpha.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931923/; classtype:trojan-activity;sid:84795023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931924)"; flow:established,from_client; content:"GET"; http_method; content:"/adequate-supervisor298/qif-to-qfx/refs/heads/main/tests/fixtures/to-qif-qfx-1.4-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931924/; classtype:trojan-activity;sid:84795024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931921)"; flow:established,from_client; content:"GET"; http_method; content:"/aliegeerzin/ssaju/refs/heads/main/scripts/software-v2.5-alpha.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931921/; classtype:trojan-activity;sid:84795021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931922)"; flow:established,from_client; content:"GET"; http_method; content:"/lancewoodroleplaying805/autodoc-ai/refs/heads/main/phagedena/ai-autodoc-v3.4-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931922/; classtype:trojan-activity;sid:84795022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931920)"; flow:established,from_client; content:"GET"; http_method; content:"/okaykar/n8n-generate-personalized-deal-content-recommendations-with-zoho-crm-gpt-4o-mini-gmail/refs/heads/main/desugarize/mini_recommendations_cr_zoho_n_generate_gp_o_gmail_with_deal_content_personalized_1.2.zip"; http_uri; depth:212; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931920/; classtype:trojan-activity;sid:84795020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931917)"; flow:established,from_client; content:"GET"; http_method; content:"/karakarawowow/machin/master/linage/software_2.7-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931917/; classtype:trojan-activity;sid:84795017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931918)"; flow:established,from_client; content:"GET"; http_method; content:"/vnish1337/multi-account-manager-pro/refs/heads/main/teer/manager_account_pro_multi_2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931918/; classtype:trojan-activity;sid:84795018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931919)"; flow:established,from_client; content:"GET"; http_method; content:"/tabbieelectric8182/signos/refs/heads/main/lobeless/v3.6-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931919/; classtype:trojan-activity;sid:84795019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931916)"; flow:established,from_client; content:"GET"; http_method; content:"/suryansh458/deep-learning-cifar10-routing-net/head/notebooks/deep-learning-cifar10-routing-net_fissidactyl.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931916/; classtype:trojan-activity;sid:84795016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931915)"; flow:established,from_client; content:"GET"; http_method; content:"/armagnnctk/sair/refs/heads/main/views/listings/software_3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931915/; classtype:trojan-activity;sid:84795015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931913)"; flow:established,from_client; content:"GET"; http_method; content:"/louisklinogo/w5-football-prediction/head/src/data/football-w-prediction-2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931913/; classtype:trojan-activity;sid:84795013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931914)"; flow:established,from_client; content:"GET"; http_method; content:"/yoshavegito/the-entrapment-problem-in-arminian-theology-a-trinitarian-crisis/main/nemalite/the-entrapment-problem-in-arminian-theology-a-trinitarian-crisis.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931914/; classtype:trojan-activity;sid:84795014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931910)"; flow:established,from_client; content:"GET"; http_method; content:"/godddd333/pubg-hack---pubg-aimbot-esp-2026/main/synchronously/1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931910/; classtype:trojan-activity;sid:84795010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931911)"; flow:established,from_client; content:"GET"; http_method; content:"/thematrix212/vue-css3-solarwave-portfolio/refs/heads/main/src/data/portfolio_css_solarwave_vue_2.0-alpha.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931911/; classtype:trojan-activity;sid:84795011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931912)"; flow:established,from_client; content:"GET"; http_method; content:"/tarunkanth3223/commit-reviewer-prompt/refs/heads/main/gaslight/commit-prompt-reviewer-3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931912/; classtype:trojan-activity;sid:84795012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931908)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/renfe_mcp_server/head/src/renfe_mcp/server_mcp_renfe_v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931908/; classtype:trojan-activity;sid:84795008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931909)"; flow:established,from_client; content:"GET"; http_method; content:"/reformmovementpopgroup351/fingerdancer/refs/heads/main/src/atoms/finger_dancer_3.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931909/; classtype:trojan-activity;sid:84795009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931905)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjay05112001/openad-specification_website/openad-specification_website_main-dev/allopatry/openad-specification_website.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931905/; classtype:trojan-activity;sid:84795005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931906)"; flow:established,from_client; content:"GET"; http_method; content:"/gilbertian-pithecanthropus683/airwavetv/refs/heads/main/trigraph/software_3.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931906/; classtype:trojan-activity;sid:84795006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931907)"; flow:established,from_client; content:"GET"; http_method; content:"/jhian12/modern-portfolio/refs/heads/main/images/modern_portfolio_3.9-alpha.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931907/; classtype:trojan-activity;sid:84795007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931903)"; flow:established,from_client; content:"GET"; http_method; content:"/holyspaghetti8/authtelegramplugin/refs/heads/main/src/main/resources/telegram_auth_plugin_1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931903/; classtype:trojan-activity;sid:84795003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931904)"; flow:established,from_client; content:"GET"; http_method; content:"/sai9640nayak/streamingkokorojs/main/bakalei/js-streaming-kokoro-unmischievous.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931904/; classtype:trojan-activity;sid:84795004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931902)"; flow:established,from_client; content:"GET"; http_method; content:"/sinhnguyen0802/solana-program-vault/head/aminoanthraquinone/program-vault-solana-2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931902/; classtype:trojan-activity;sid:84795002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931901)"; flow:established,from_client; content:"GET"; http_method; content:"/bensonsquiggly4244/awesome-android-app-repositories/main/insurmountability/repositories-app-awesome-android-amicron.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931901/; classtype:trojan-activity;sid:84795001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931900)"; flow:established,from_client; content:"GET"; http_method; content:"/luisbraido/ai-family-cli/main/arranger/ai-family-cli.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931900/; classtype:trojan-activity;sid:84795000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931895)"; flow:established,from_client; content:"GET"; http_method; content:"/blady-sa/dapperforge/refs/heads/main/tests/dapperforge.tests/diagnostics/forge-dapper-v1.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931895/; classtype:trojan-activity;sid:84794995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931896)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/dbt-core-mcp/head/src/dbt_core_mcp/core-mcp-dbt-v2.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931896/; classtype:trojan-activity;sid:84794996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931897)"; flow:established,from_client; content:"GET"; http_method; content:"/imran1432423/esp32-ptm216b/refs/heads/main/instructedness/b_ptm_esp_2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931897/; classtype:trojan-activity;sid:84794997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931898)"; flow:established,from_client; content:"GET"; http_method; content:"/urnansucker2000fuckme/raknot-ui/refs/heads/main/acanthopod/ui-raknot-1.0-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931898/; classtype:trojan-activity;sid:84794998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931899)"; flow:established,from_client; content:"GET"; http_method; content:"/zig333/elai-archive/main/witoto/archive-ela-1.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931899/; classtype:trojan-activity;sid:84794999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931894)"; flow:established,from_client; content:"GET"; http_method; content:"/uzair007-pg/dreammask/refs/heads/main/iat/fcclip/data/dataset_mappers/dream-mask-v2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931894/; classtype:trojan-activity;sid:84794994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931890)"; flow:established,from_client; content:"GET"; http_method; content:"/mickaelderen14/portakal/refs/heads/main/web/software_1.0-alpha.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931890/; classtype:trojan-activity;sid:84794990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931891)"; flow:established,from_client; content:"GET"; http_method; content:"/nicolashobday/valve-deadlock-full-access-bypass/main/actability/2.7-beta.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931891/; classtype:trojan-activity;sid:84794991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931892)"; flow:established,from_client; content:"GET"; http_method; content:"/azeemkafridi/bulkpublish-abwor-social-media-skills/head/skills/content-strategy-sms/evals/media-skills-social-v3.8.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931892/; classtype:trojan-activity;sid:84794992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931893)"; flow:established,from_client; content:"GET"; http_method; content:"/corse7e/temm1e/main/crates/temm1e-gateway/e-temm-pretty.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931893/; classtype:trojan-activity;sid:84794993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931889)"; flow:established,from_client; content:"GET"; http_method; content:"/vjdan/nuxt-boilerplate/refs/heads/main/db/boilerplate-nuxt-cartel.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931889/; classtype:trojan-activity;sid:84794989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931888)"; flow:established,from_client; content:"GET"; http_method; content:"/manualallylresin474/local-llm-6-2026/refs/heads/main/discontinuity/llm_local_v2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931888/; classtype:trojan-activity;sid:84794988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931886)"; flow:established,from_client; content:"GET"; http_method; content:"/henryviiiabywarburg482/testproof/main/bicapsular/2.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931886/; classtype:trojan-activity;sid:84794986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931887)"; flow:established,from_client; content:"GET"; http_method; content:"/staciepolygonal429/codec/refs/heads/main/waldgravine/software-1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931887/; classtype:trojan-activity;sid:84794987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931884)"; flow:established,from_client; content:"GET"; http_method; content:"/feneliaearnest2534/celldock-for-mac/main/isoparaffin/participance.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931884/; classtype:trojan-activity;sid:84794984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931885)"; flow:established,from_client; content:"GET"; http_method; content:"/abckit0324-crypto/paper_agg/refs/heads/main/templates/paper-agg-v1.6-alpha.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931885/; classtype:trojan-activity;sid:84794985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931881)"; flow:established,from_client; content:"GET"; http_method; content:"/chilriya/css-plugins_obsidian/refs/heads/main/snippets/cs-plugins-obsidian-v1.8-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931881/; classtype:trojan-activity;sid:84794981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931882)"; flow:established,from_client; content:"GET"; http_method; content:"/scallyrazve/argo9s/main/donatress/v2.6-alpha.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931882/; classtype:trojan-activity;sid:84794982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931883)"; flow:established,from_client; content:"GET"; http_method; content:"/liederkranzbottleneck282/dimensional-rift-tear/main/nahuan/outworn.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931883/; classtype:trojan-activity;sid:84794983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931880)"; flow:established,from_client; content:"GET"; http_method; content:"/obechifamilycerthiidae1072/cyberdeck_browser/refs/heads/main/installer/cyber_deck_browser_v1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931880/; classtype:trojan-activity;sid:84794980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931877)"; flow:established,from_client; content:"GET"; http_method; content:"/hamed8845/verl-recipe/refs/heads/main/spo/estimate_offline_values/verl_recipe_3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931877/; classtype:trojan-activity;sid:84794977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931878)"; flow:established,from_client; content:"GET"; http_method; content:"/hazem-programmer/wysiwyg/refs/heads/main/src/core/utils/software_v2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931878/; classtype:trojan-activity;sid:84794978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931879)"; flow:established,from_client; content:"GET"; http_method; content:"/shavan889/minisforum-ms-s1-max-bios/refs/heads/main/scripts/s_bios_max_ms_minisforum_v1.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931879/; classtype:trojan-activity;sid:84794979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931874)"; flow:established,from_client; content:"GET"; http_method; content:"/dani36034550/langchain_bedrock_lambda/refs/heads/main/data/langchain-lambda-bedrock-3.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931874/; classtype:trojan-activity;sid:84794974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931875)"; flow:established,from_client; content:"GET"; http_method; content:"/ashcakeancient7671/aura/refs/heads/main/benchmarks/audit/v7_v8_v9_final/3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931875/; classtype:trojan-activity;sid:84794975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931876)"; flow:established,from_client; content:"GET"; http_method; content:"/syatriaikhsan21/claudecraft/refs/heads/main/curated-sounds/protoss/software_epispadiac.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931876/; classtype:trojan-activity;sid:84794976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931872)"; flow:established,from_client; content:"GET"; http_method; content:"/uclukdx/openclaw-dashboard/refs/heads/main/app/cron/dashboard_openclaw_3.7-alpha.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931872/; classtype:trojan-activity;sid:84794972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931873)"; flow:established,from_client; content:"GET"; http_method; content:"/redblac/web-youtube-summarizer-llm/refs/heads/main/propitiatingly/web_summarizer_youtube_llm_v3.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931873/; classtype:trojan-activity;sid:84794973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931870)"; flow:established,from_client; content:"GET"; http_method; content:"/ajxkai/task-flow-chart/head/examples/logic_workflow/lib/fontawesome/js/task-flow-chart_v3.6-beta.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931870/; classtype:trojan-activity;sid:84794970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931871)"; flow:established,from_client; content:"GET"; http_method; content:"/eegy90/awesome-claude-code-resources/refs/heads/main/assets/resources-claude-code-awesome-v2.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931871/; classtype:trojan-activity;sid:84794971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931869)"; flow:established,from_client; content:"GET"; http_method; content:"/ipuntoo/ai-game-generator/refs/heads/main/backend/game_a_generator_2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931869/; classtype:trojan-activity;sid:84794969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931867)"; flow:established,from_client; content:"GET"; http_method; content:"/kayunangka/claude-skill/head/.claude-plugin/claude-skill_1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931867/; classtype:trojan-activity;sid:84794967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931868)"; flow:established,from_client; content:"GET"; http_method; content:"/gentlemanshakespearean765/cascadia-next-nerd-font/refs/heads/main/consecutively/cascadia_font_nerd_next_2.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931868/; classtype:trojan-activity;sid:84794968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931865)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/jenkins-mcp-server/head/laborant/mcp-server-jenkins-3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931865/; classtype:trojan-activity;sid:84794965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931866)"; flow:established,from_client; content:"GET"; http_method; content:"/basharat123-jpg/awesome-opensource-projects/refs/heads/main/projects/games/opensource-awesome-projects-v2.7.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931866/; classtype:trojan-activity;sid:84794966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931864)"; flow:established,from_client; content:"GET"; http_method; content:"/sarbjit4840/senpai-skill/refs/heads/main/prompts/senpai-skill-3.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931864/; classtype:trojan-activity;sid:84794964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931862)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaysharmaas/mcp-datadog/refs/heads/main/src/viamus.datadog.mcp.server/services/datadog_mcp_v1.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931862/; classtype:trojan-activity;sid:84794962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931863)"; flow:established,from_client; content:"GET"; http_method; content:"/jamesbhatti/aspose.cells.grid-for-.net/refs/heads/main/examples_gridweb/gridweb.net4/csharp/js/cells_aspose_grid_for_net_1.0.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931863/; classtype:trojan-activity;sid:84794963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931861)"; flow:established,from_client; content:"GET"; http_method; content:"/ryukyagamilight/terminal-skills/head/backup/disaster-recovery/skills_terminal_v1.1-beta.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931861/; classtype:trojan-activity;sid:84794961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931859)"; flow:established,from_client; content:"GET"; http_method; content:"/chau2873/uiu-datamining-lab/refs/heads/main/broomwort/mining_ui_data_lab_1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931859/; classtype:trojan-activity;sid:84794959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931860)"; flow:established,from_client; content:"GET"; http_method; content:"/nanatgrail/prodigyspace/master/lib/software_v2.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931860/; classtype:trojan-activity;sid:84794960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931857)"; flow:established,from_client; content:"GET"; http_method; content:"/amuck-tie267/sni-xhttp/refs/heads/main/v1.0/api/xhttp_sn_v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931857/; classtype:trojan-activity;sid:84794957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931858)"; flow:established,from_client; content:"GET"; http_method; content:"/gokulsai6543/practiceforcicd/refs/heads/master/src/software-1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931858/; classtype:trojan-activity;sid:84794958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931856)"; flow:established,from_client; content:"GET"; http_method; content:"/joelpolygonal863/mirae-solana-sniper/refs/heads/main/garnet/mirae-solana-sniper-v1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931856/; classtype:trojan-activity;sid:84794956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931855)"; flow:established,from_client; content:"GET"; http_method; content:"/rocj05478/camofox-browser/main/expandedness/camofox_browser_v3.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931855/; classtype:trojan-activity;sid:84794955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931854)"; flow:established,from_client; content:"GET"; http_method; content:"/augusteregular234/flakai/main/backend/ml/flak_ai_2.5-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931854/; classtype:trojan-activity;sid:84794954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931853)"; flow:established,from_client; content:"GET"; http_method; content:"/sebastian3909/obsidian-web-mcp/refs/heads/main/src/web-mcp-obsidian-v1.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931853/; classtype:trojan-activity;sid:84794953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931852)"; flow:established,from_client; content:"GET"; http_method; content:"/abigaelacrocarpous465/ai-fitness-coach/refs/heads/main/assets/demo/ai_fitness_coach_2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931852/; classtype:trojan-activity;sid:84794952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931851)"; flow:established,from_client; content:"GET"; http_method; content:"/yytyt7/powershell-ldm/main/petitionproof/powershell-ldm.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931851/; classtype:trojan-activity;sid:84794951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931849)"; flow:established,from_client; content:"GET"; http_method; content:"/sachi7799/ai-debt-scanner/refs/heads/main/skills/ai-debt-scanner/ai-debt-scanner-v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931849/; classtype:trojan-activity;sid:84794949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931850)"; flow:established,from_client; content:"GET"; http_method; content:"/poetesslowcountries967/clipfetch/main/clipfetch/i18n/fetch_clip_1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931850/; classtype:trojan-activity;sid:84794950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931847)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdummy550/gnap/refs/heads/main/examples/software_v1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931847/; classtype:trojan-activity;sid:84794947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931848)"; flow:established,from_client; content:"GET"; http_method; content:"/ismiguel/cosmos-monitor/refs/heads/main/counterprotection/monitor-cosmos-1.3-beta.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931848/; classtype:trojan-activity;sid:84794948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931844)"; flow:established,from_client; content:"GET"; http_method; content:"/johncenadududu/pytorch-simsiam-contrastive-ssl/refs/heads/main/scripts/contrastive_ssl_pytorch_simsiam_1.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931844/; classtype:trojan-activity;sid:84794944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931845)"; flow:established,from_client; content:"GET"; http_method; content:"/jandyoverseas977/claude-skills-governance-risk-and-compliance/refs/heads/main/plugins/iso42001/.claude-plugin/and-skills-claude-governance-risk-compliance-1.3.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931845/; classtype:trojan-activity;sid:84794945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931846)"; flow:established,from_client; content:"GET"; http_method; content:"/1one2three/elephant/refs/heads/main/src/analytics/software-3.0-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931846/; classtype:trojan-activity;sid:84794946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931841)"; flow:established,from_client; content:"GET"; http_method; content:"/2josex/claude-brain/head/src/utils/brain_claude_2.2-alpha.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931841/; classtype:trojan-activity;sid:84794941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931842)"; flow:established,from_client; content:"GET"; http_method; content:"/patricgonzaga/sofia-ia-whatsapp/head/providers/whatsapp-sofia-ia-1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931842/; classtype:trojan-activity;sid:84794942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931843)"; flow:established,from_client; content:"GET"; http_method; content:"/yash-1818/planmate/refs/heads/master/resources/js/components/ui/mate_plan_1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931843/; classtype:trojan-activity;sid:84794943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931840)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdidjemaci/production-rag/head/evaluation/production-rag-2.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931840/; classtype:trojan-activity;sid:84794940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931839)"; flow:established,from_client; content:"GET"; http_method; content:"/aballa6975/federal-contracting-skills/refs/heads/main/skills/igce-builder-lh-tm/federal_skills_contracting_v3.0.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931839/; classtype:trojan-activity;sid:84794939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931838)"; flow:established,from_client; content:"GET"; http_method; content:"/akilan04a/vui/refs/heads/main/src/vui/software-v3.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931838/; classtype:trojan-activity;sid:84794938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931835)"; flow:established,from_client; content:"GET"; http_method; content:"/urfavgamereisme/apibase/refs/heads/main/apibase/apibase_2.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931835/; classtype:trojan-activity;sid:84794935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931836)"; flow:established,from_client; content:"GET"; http_method; content:"/drab-moralist826/gpu-fan-curve-controller/refs/heads/main/miersite/controller_fan_gpu_curve_v1.5-beta.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931836/; classtype:trojan-activity;sid:84794936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931837)"; flow:established,from_client; content:"GET"; http_method; content:"/crossmodal-gretzky7935/fivem-executor/refs/heads/main/encratic/fivem_executor_v1.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931837/; classtype:trojan-activity;sid:84794937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931833)"; flow:established,from_client; content:"GET"; http_method; content:"/sen-igga/indexgpt/refs/heads/main/web/showcase/figs/gpt-index-2.6-alpha.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931833/; classtype:trojan-activity;sid:84794933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931834)"; flow:established,from_client; content:"GET"; http_method; content:"/dark675sfdsgfxh/xray-reality-setup/refs/heads/main/client/reality_setup_xray_2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931834/; classtype:trojan-activity;sid:84794934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931832)"; flow:established,from_client; content:"GET"; http_method; content:"/fir666as/auctions-scraper/refs/heads/main/whussle/scraper-auctions-v2.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931832/; classtype:trojan-activity;sid:84794932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931830)"; flow:established,from_client; content:"GET"; http_method; content:"/desireeontrial76/yellowkey-bitlocker/refs/heads/main/bitlocker/bitlocker_yellowkey_3.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931830/; classtype:trojan-activity;sid:84794930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931831)"; flow:established,from_client; content:"GET"; http_method; content:"/dabneythespian710/mi_nobl_root/refs/heads/main/python/mi_nobl_root_v2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931831/; classtype:trojan-activity;sid:84794931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931829)"; flow:established,from_client; content:"GET"; http_method; content:"/abhisek200/oops/refs/heads/main/inheritance/oo-ps-ladyship.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931829/; classtype:trojan-activity;sid:84794929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931826)"; flow:established,from_client; content:"GET"; http_method; content:"/ndamine/youtube-eng/head/static/youtube-eng_v2.0-beta.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931826/; classtype:trojan-activity;sid:84794926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931827)"; flow:established,from_client; content:"GET"; http_method; content:"/gmorpheus/agent-jobs/refs/heads/main/matronhood/agent-jobs-1.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931827/; classtype:trojan-activity;sid:84794927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931828)"; flow:established,from_client; content:"GET"; http_method; content:"/kaleshmohan/healthcare-nlp-analyzer/refs/heads/main/media/analyzer-healthcare-nlp-v1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931828/; classtype:trojan-activity;sid:84794928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931824)"; flow:established,from_client; content:"GET"; http_method; content:"/alexander123138/fileprep/refs/heads/main/doc/ja/software_megarensian.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931824/; classtype:trojan-activity;sid:84794924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931825)"; flow:established,from_client; content:"GET"; http_method; content:"/discombobulated-oilpainter4844/murder-mystery-2-script-2026-analysis-lab/main/cornbin/v1.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931825/; classtype:trojan-activity;sid:84794925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931823)"; flow:established,from_client; content:"GET"; http_method; content:"/leticiacrs/sts2-quickrestart/refs/heads/main/quickrestart2/sts_restart_quick_2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931823/; classtype:trojan-activity;sid:84794923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931822)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardopini/dresguardian/refs/heads/main/fetched/software-3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931822/; classtype:trojan-activity;sid:84794922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931821)"; flow:established,from_client; content:"GET"; http_method; content:"/toitenlaa/cdecl-dump/refs/heads/main/monophysitism/cdecl-dump-v2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931821/; classtype:trojan-activity;sid:84794921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931820)"; flow:established,from_client; content:"GET"; http_method; content:"/learner9614/dubai-online-mart-multichannel-sales-analytics-dashboard-2025/refs/heads/main/orders_2025/amazon_sales_data/dubai_dashboard_multichannel_sales_mart_online_analytics_v2.2-alpha.4.zip"; http_uri; depth:194; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931820/; classtype:trojan-activity;sid:84794920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931817)"; flow:established,from_client; content:"GET"; http_method; content:"/janetaunimaginable726/recuva-pro-data-recovery/main/silhouettist/recovery_recuva_data_pro_drawbar.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931817/; classtype:trojan-activity;sid:84794917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931818)"; flow:established,from_client; content:"GET"; http_method; content:"/killuameter/symfony-rent-a-comic/refs/heads/main/config/packages/test/a_rent_symfony_comic_v2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931818/; classtype:trojan-activity;sid:84794918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931819)"; flow:established,from_client; content:"GET"; http_method; content:"/oktaymoral/run-from-it/refs/heads/main/public/music/from_it_run_1.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931819/; classtype:trojan-activity;sid:84794919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931815)"; flow:established,from_client; content:"GET"; http_method; content:"/footbobik/copilot-sdk/refs/heads/main/cookbook/go/copilot-sdk-v3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931815/; classtype:trojan-activity;sid:84794915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931816)"; flow:established,from_client; content:"GET"; http_method; content:"/danghaiye7797/call-of-duty-script-hub/main/carbonylic/duty_script_call_hub_of_v2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931816/; classtype:trojan-activity;sid:84794916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931812)"; flow:established,from_client; content:"GET"; http_method; content:"/yqman34/reverse-api-engineer/refs/heads/main/examples/ikea/api-reverse-engineer-runefolk.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931812/; classtype:trojan-activity;sid:84794912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931813)"; flow:established,from_client; content:"GET"; http_method; content:"/mrali-code/bug-hunter/head/skills/commit-security-scan/hunter-bug-v1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931813/; classtype:trojan-activity;sid:84794913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931814)"; flow:established,from_client; content:"GET"; http_method; content:"/sobsagar/devpulse-dashboard/main/reanalyze/devpulse-dashboard.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931814/; classtype:trojan-activity;sid:84794914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931811)"; flow:established,from_client; content:"GET"; http_method; content:"/lagidiumdriploop223/quarkdash/refs/heads/main/benchmarks/software-1.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931811/; classtype:trojan-activity;sid:84794911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931810)"; flow:established,from_client; content:"GET"; http_method; content:"/muhagung09/tejos/main/njave/1.1-alpha.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931810/; classtype:trojan-activity;sid:84794910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931809)"; flow:established,from_client; content:"GET"; http_method; content:"/menasamuel1835/pumpfun-bundler/refs/heads/main/executor/pumpfun-bundler-1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931809/; classtype:trojan-activity;sid:84794909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931805)"; flow:established,from_client; content:"GET"; http_method; content:"/mu122h4554n/celstomp/refs/heads/main/celstomp/css/software-v3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931805/; classtype:trojan-activity;sid:84794905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931806)"; flow:established,from_client; content:"GET"; http_method; content:"/jhyshy/didactic-broccoli/head/graciousness/didactic_broccoli_v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931806/; classtype:trojan-activity;sid:84794906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931807)"; flow:established,from_client; content:"GET"; http_method; content:"/koebricksgirl/w8w/main/abortus/w8w.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931807/; classtype:trojan-activity;sid:84794907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931808)"; flow:established,from_client; content:"GET"; http_method; content:"/dawsonsa/minimal-photon/refs/heads/main/assets/files/minimal-photon-1.0-beta.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931808/; classtype:trojan-activity;sid:84794908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931804)"; flow:established,from_client; content:"GET"; http_method; content:"/renegado6/imagepdftoolkit/main/design/pdf_toolkit_image_1.2-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931804/; classtype:trojan-activity;sid:84794904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931801)"; flow:established,from_client; content:"GET"; http_method; content:"/driellecristine/bert-contrastive-lora/refs/heads/main/noncommunist/contrastive-ra-ber-lo-2.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931801/; classtype:trojan-activity;sid:84794901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931802)"; flow:established,from_client; content:"GET"; http_method; content:"/marabelhard623/tarwinder-portfolio/main/public/portfolio-tarwinder-3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931802/; classtype:trojan-activity;sid:84794902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931803)"; flow:established,from_client; content:"GET"; http_method; content:"/sangki1234/lumi/refs/heads/main/docs/software-2.0-beta.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931803/; classtype:trojan-activity;sid:84794903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931798)"; flow:established,from_client; content:"GET"; http_method; content:"/alice-win-myself/claude2api/head/router/api-claude-v1.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931798/; classtype:trojan-activity;sid:84794898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931799)"; flow:established,from_client; content:"GET"; http_method; content:"/chuot331775971-ui/how-to-fish-mode/main/telchines/1.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931799/; classtype:trojan-activity;sid:84794899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931800)"; flow:established,from_client; content:"GET"; http_method; content:"/melazeetech/sandboxie-activated/refs/heads/main/capsulolenticular/activated_sandboxie_v3.2-alpha.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931800/; classtype:trojan-activity;sid:84794900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931796)"; flow:established,from_client; content:"GET"; http_method; content:"/ragnarion/tanstack-ai-demo/refs/heads/main/src/components/chat/demo-tanstack-ai-1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931796/; classtype:trojan-activity;sid:84794896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931797)"; flow:established,from_client; content:"GET"; http_method; content:"/geanmuco/etfsa.json/main/docs/etfsa.json-diathermal.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931797/; classtype:trojan-activity;sid:84794897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931793)"; flow:established,from_client; content:"GET"; http_method; content:"/shayanadhami1-prog/gta-vi-pc-launcher-bypass/refs/heads/main/ferrocyanate/gt-v-p-bypass-launcher-1.7.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931793/; classtype:trojan-activity;sid:84794893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931794)"; flow:established,from_client; content:"GET"; http_method; content:"/indemnitycon2915/x2t/main/x2t/bot/handlers/v2.8-alpha.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931794/; classtype:trojan-activity;sid:84794894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931795)"; flow:established,from_client; content:"GET"; http_method; content:"/lkorbma/credit/refs/heads/master/internal/otel_trace/software_1.5-beta.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931795/; classtype:trojan-activity;sid:84794895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931791)"; flow:established,from_client; content:"GET"; http_method; content:"/russiateleworking29/oneclicklm/refs/heads/main/src/utils/one_lm_click_v1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931791/; classtype:trojan-activity;sid:84794891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931792)"; flow:established,from_client; content:"GET"; http_method; content:"/ankitpadariya301/typing-speed/refs/heads/main/typingspeed/typing_speed_v2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931792/; classtype:trojan-activity;sid:84794892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931790)"; flow:established,from_client; content:"GET"; http_method; content:"/prairiemimosajamestown413/weixin-articles-mcp/main/tests/articles_weixin_mcp_ungroundably.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931790/; classtype:trojan-activity;sid:84794890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931786)"; flow:established,from_client; content:"GET"; http_method; content:"/doc-abdo/ai-agent-manifesto/refs/heads/main/_layouts/ai_manifesto_agent_v2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931786/; classtype:trojan-activity;sid:84794886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931787)"; flow:established,from_client; content:"GET"; http_method; content:"/dannyeconcealed113/adopt-me-free-script-2026/refs/heads/main/jezebelian/2.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931787/; classtype:trojan-activity;sid:84794887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931788)"; flow:established,from_client; content:"GET"; http_method; content:"/111111st/pkmenu/main/astrological/pkmenu.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931788/; classtype:trojan-activity;sid:84794888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931789)"; flow:established,from_client; content:"GET"; http_method; content:"/karthick04023/rumours_complex_investment_decisions/refs/heads/main/dhritarashtra/decisions_complex_investment_rumours_v2.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931789/; classtype:trojan-activity;sid:84794889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931785)"; flow:established,from_client; content:"GET"; http_method; content:"/roh68210/a-plague-tale-resonance-trainer/main/semitransverse/v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931785/; classtype:trojan-activity;sid:84794885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931783)"; flow:established,from_client; content:"GET"; http_method; content:"/pisonislo8737/hyperxopenskills/refs/heads/main/hyperx-data-api/skills-hyperx-open-v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931783/; classtype:trojan-activity;sid:84794883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931784)"; flow:established,from_client; content:"GET"; http_method; content:"/civillibertarian-stressincontinence617/llm-autoeval/master/llm_autoeval/llm_autoeval_3.2-alpha.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931784/; classtype:trojan-activity;sid:84794884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931780)"; flow:established,from_client; content:"GET"; http_method; content:"/hattienonstop329/easycv/main/src/app/features/software-nymphomaniacal.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931780/; classtype:trojan-activity;sid:84794880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931781)"; flow:established,from_client; content:"GET"; http_method; content:"/3x3k/esphome-air-quality-monitor/refs/heads/main/images/esphome-air-monitor-quality-fatuism.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931781/; classtype:trojan-activity;sid:84794881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931782)"; flow:established,from_client; content:"GET"; http_method; content:"/kta1kri/alexander-storage/head/docs/guides/alexander_storage_3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931782/; classtype:trojan-activity;sid:84794882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931779)"; flow:established,from_client; content:"GET"; http_method; content:"/bkarwan/remote-desktop-manager-enterprise-download/refs/heads/main/eyesight/enterprise_desktop_manager_download_remote_quadrimembral.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931779/; classtype:trojan-activity;sid:84794879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931777)"; flow:established,from_client; content:"GET"; http_method; content:"/engrsadaqath/e2ee-adapter/refs/heads/main/examples/nestjs-server/src/ee_adapter_e_1.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931777/; classtype:trojan-activity;sid:84794877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931778)"; flow:established,from_client; content:"GET"; http_method; content:"/anthropogenetic-upturn351/neurosched/main/include/1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931778/; classtype:trojan-activity;sid:84794878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931775)"; flow:established,from_client; content:"GET"; http_method; content:"/sagar9105/kuse_cowork/refs/heads/main/src/styles/cowork_kuse_v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931775/; classtype:trojan-activity;sid:84794875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931776)"; flow:established,from_client; content:"GET"; http_method; content:"/sairix5/jsbooks/main/rule/js_books_1.8.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931776/; classtype:trojan-activity;sid:84794876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931772)"; flow:established,from_client; content:"GET"; http_method; content:"/weoiufh/leetcode-python-solutions/refs/heads/main/097_interleaving_string/python_leetcode_solutions_1.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931772/; classtype:trojan-activity;sid:84794872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931773)"; flow:established,from_client; content:"GET"; http_method; content:"/fvckhack/wrenai/refs/heads/main/wren-ui/src/styles/components/ai_wren_3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931773/; classtype:trojan-activity;sid:84794873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931774)"; flow:established,from_client; content:"GET"; http_method; content:"/haommy/metronome/refs/heads/main/overindulgently/software_nigrescite.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931774/; classtype:trojan-activity;sid:84794874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931770)"; flow:established,from_client; content:"GET"; http_method; content:"/chanukk88/obsidian-quick-capture/refs/heads/main/src/types/quick-obsidian-capture-1.0-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931770/; classtype:trojan-activity;sid:84794870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931771)"; flow:established,from_client; content:"GET"; http_method; content:"/luizaportella77721-arch/career-cv-linkedin_tech-tests_course-luisdev-professional-growth-part-1_dotnet-8_csharp-12/refs/heads/main/developments/jobsapi-master/jobsapi/professional-part-course-cv-growth-linkedin-career-tech-csharp-luisdev-dotnet-tests-1.9.zip"; http_uri; depth:259; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931771/; classtype:trojan-activity;sid:84794871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931766)"; flow:established,from_client; content:"GET"; http_method; content:"/clauvilla5671/aurscan/main/internal/yay/software-1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931766/; classtype:trojan-activity;sid:84794866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931767)"; flow:established,from_client; content:"GET"; http_method; content:"/arslanakbarchaudary/onigiri/master/passwordgenerator/igi-o-ri-n-v2.9-alpha.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931767/; classtype:trojan-activity;sid:84794867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931768)"; flow:established,from_client; content:"GET"; http_method; content:"/samisimo2020/apple-y8oxd/main/unidentified/y_oxd_apple_anthochlor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931768/; classtype:trojan-activity;sid:84794868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931769)"; flow:established,from_client; content:"GET"; http_method; content:"/rindzohaib/orrinix/refs/heads/main/sources/orrinix/views/software_3.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931769/; classtype:trojan-activity;sid:84794869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931763)"; flow:established,from_client; content:"GET"; http_method; content:"/vadimgotfrid430/txw818_walkietalkie_doom/refs/heads/main/unprosodic/tx_doom_walkie_talkie_v1.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931763/; classtype:trojan-activity;sid:84794863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931764)"; flow:established,from_client; content:"GET"; http_method; content:"/nely003/urlx/refs/heads/main/examples/software-3.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931764/; classtype:trojan-activity;sid:84794864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931765)"; flow:established,from_client; content:"GET"; http_method; content:"/jward0626/pid-trainer/head/pid_trainer/trainer-pid-v3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931765/; classtype:trojan-activity;sid:84794865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931761)"; flow:established,from_client; content:"GET"; http_method; content:"/rfcddemo/koreader-patches/refs/heads/main/icons/patches_koreader_3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931761/; classtype:trojan-activity;sid:84794861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931762)"; flow:established,from_client; content:"GET"; http_method; content:"/power866/1nuo-rate/refs/heads/main/trigonocephalous/rate_nuo_1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931762/; classtype:trojan-activity;sid:84794862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931760)"; flow:established,from_client; content:"GET"; http_method; content:"/efeterner/laravel-vd1/refs/heads/main/thylacoleo/laravel_vd_v1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931760/; classtype:trojan-activity;sid:84794860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931759)"; flow:established,from_client; content:"GET"; http_method; content:"/ahop15/artek-homepage/head/scripts/tools/diagram-to-prose/homepage_artek_1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931759/; classtype:trojan-activity;sid:84794859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931758)"; flow:established,from_client; content:"GET"; http_method; content:"/euphratesriverfructification5590/kun/main/skills/kun/software-v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931758/; classtype:trojan-activity;sid:84794858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931756)"; flow:established,from_client; content:"GET"; http_method; content:"/achul-cos/esp32-smart-fan/refs/heads/main/extemporization/es-fan-smart-v2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931756/; classtype:trojan-activity;sid:84794856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931757)"; flow:established,from_client; content:"GET"; http_method; content:"/anthonykkkl/annuity-loan-calculator/head/tests/calculator-annuity-loan-1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931757/; classtype:trojan-activity;sid:84794857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931754)"; flow:established,from_client; content:"GET"; http_method; content:"/saivi3171/faceit-mcp/refs/heads/main/illuminator/faceit_mcp_v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931754/; classtype:trojan-activity;sid:84794854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931755)"; flow:established,from_client; content:"GET"; http_method; content:"/kingzotex4/amazon_reviews_sentiment_analysis/refs/heads/main/templates/analysis_sentiment_amazon_reviews_preforgive.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931755/; classtype:trojan-activity;sid:84794855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931752)"; flow:established,from_client; content:"GET"; http_method; content:"/ywxyyds168/dotfiles-s1b/refs/heads/main/.config/dunst/b-s-dotfiles-v3.3-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931752/; classtype:trojan-activity;sid:84794852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931753)"; flow:established,from_client; content:"GET"; http_method; content:"/pavankumaryeluri/paylink/refs/heads/main/internal/adapters/software_3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931753/; classtype:trojan-activity;sid:84794853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931751)"; flow:established,from_client; content:"GET"; http_method; content:"/firmscythe/config-files/refs/heads/main/nvim/lua/josean/core/files_config_v2.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931751/; classtype:trojan-activity;sid:84794851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931749)"; flow:established,from_client; content:"GET"; http_method; content:"/bugandagrabbag708/claude-code-cheat-sheet/refs/heads/main/sextulary/sheet-code-claude-cheat-3.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931749/; classtype:trojan-activity;sid:84794849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931750)"; flow:established,from_client; content:"GET"; http_method; content:"/b3llzz/lab-snake-reverse/refs/heads/main/untaxing/snake_reverse_lab_1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931750/; classtype:trojan-activity;sid:84794850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931748)"; flow:established,from_client; content:"GET"; http_method; content:"/lehighriverscalylentinus811/loongsage/main/docs/_static/image/v1.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931748/; classtype:trojan-activity;sid:84794848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931746)"; flow:established,from_client; content:"GET"; http_method; content:"/dipendrasinghsandhu/dongguatv/refs/heads/main/android/app/src/androidtest/donggua_tv_2.2-beta.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931746/; classtype:trojan-activity;sid:84794846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931747)"; flow:established,from_client; content:"GET"; http_method; content:"/kmarshall04095748/letmovie-webserver/main/bd/let-web-movie-server-accroach.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931747/; classtype:trojan-activity;sid:84794847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931742)"; flow:established,from_client; content:"GET"; http_method; content:"/loksundar5057/tgto123-pub/refs/heads/main/metaler/tgto-pub-v3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931742/; classtype:trojan-activity;sid:84794842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931743)"; flow:established,from_client; content:"GET"; http_method; content:"/zackaroni1/cyberpulse-ai-powered-api-security-monitoring-threat-intelligence-platform/refs/heads/main/dashboard/platform-security-cyber-threat-a-pulse-ap-powered-intelligence-monitoring-adnexopexy.zip"; http_uri; depth:201; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931743/; classtype:trojan-activity;sid:84794843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931744)"; flow:established,from_client; content:"GET"; http_method; content:"/skaml2021/fly-or-no_fly/refs/heads/main/systemd/fly-or-no-3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931744/; classtype:trojan-activity;sid:84794844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931745)"; flow:established,from_client; content:"GET"; http_method; content:"/onn24/bignumber-card-continued/refs/heads/main/hecatic/bignumber_continued_card_v2.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931745/; classtype:trojan-activity;sid:84794845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931740)"; flow:established,from_client; content:"GET"; http_method; content:"/yonimanj/voltdb-rnt/main/bimucronate/voltdb-rnt.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931740/; classtype:trojan-activity;sid:84794840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931741)"; flow:established,from_client; content:"GET"; http_method; content:"/kalainilavann/takeout_downloader_script/refs/heads/main/outscorn/downloader_takeout_script_v3.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931741/; classtype:trojan-activity;sid:84794841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931736)"; flow:established,from_client; content:"GET"; http_method; content:"/sunnypaji88/emby_ext_domains/head/desilverize/emby_ext_domains_2.2-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931736/; classtype:trojan-activity;sid:84794836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931737)"; flow:established,from_client; content:"GET"; http_method; content:"/telolol/draggable-video-control/refs/heads/main/assets/video-draggable-control-coralroot.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931737/; classtype:trojan-activity;sid:84794837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931738)"; flow:established,from_client; content:"GET"; http_method; content:"/hashdjdhhd/rustapi/refs/heads/main/crates/rustapi-extras/src/oauth2/rust_api_3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931738/; classtype:trojan-activity;sid:84794838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931739)"; flow:established,from_client; content:"GET"; http_method; content:"/kidda229/polyroute/refs/heads/main/tests/software-3.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931739/; classtype:trojan-activity;sid:84794839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931733)"; flow:established,from_client; content:"GET"; http_method; content:"/transvestic-velodrome9214/agentmemshell/refs/heads/main/subdecanal/agent_memshell_v3.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931733/; classtype:trojan-activity;sid:84794833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931734)"; flow:established,from_client; content:"GET"; http_method; content:"/aymane-gym/mise-setup-verification-action/head/src/setup-mise-action-verification-v2.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931734/; classtype:trojan-activity;sid:84794834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931735)"; flow:established,from_client; content:"GET"; http_method; content:"/enyen9x/clear/head/nursy/clear.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931735/; classtype:trojan-activity;sid:84794835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931730)"; flow:established,from_client; content:"GET"; http_method; content:"/dkjrjuh/deskmark/head/assets/deskmark_1.9.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931730/; classtype:trojan-activity;sid:84794830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931731)"; flow:established,from_client; content:"GET"; http_method; content:"/anamorphic-conglomerate194/codex-micro-waveshare/refs/heads/main/artifacts/3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931731/; classtype:trojan-activity;sid:84794831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931732)"; flow:established,from_client; content:"GET"; http_method; content:"/pablocssousa/neuro-probe/refs/heads/main/analyzers/neuro-probe-cantharidae.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931732/; classtype:trojan-activity;sid:84794832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931729)"; flow:established,from_client; content:"GET"; http_method; content:"/shreyash-ghatage/awesome-agentic-ai-coding-template/refs/heads/main/.agents/skills/hotfix/agentic_template_awesome_coding_a_v3.6-beta.3.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931729/; classtype:trojan-activity;sid:84794829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931727)"; flow:established,from_client; content:"GET"; http_method; content:"/aiparali/portfolio-leonardofirme/main/src/portfolio_leonardo_firme_respeak.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931727/; classtype:trojan-activity;sid:84794827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931728)"; flow:established,from_client; content:"GET"; http_method; content:"/pinchasconstitutional598/socialmgmt/refs/heads/main/e2e/tests/mgmt_social_v2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931728/; classtype:trojan-activity;sid:84794828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931724)"; flow:established,from_client; content:"GET"; http_method; content:"/faria-mehzabin/pytorch-ml-concepts/refs/heads/main/polypoda/concepts_torch_py_m_v3.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931724/; classtype:trojan-activity;sid:84794824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931725)"; flow:established,from_client; content:"GET"; http_method; content:"/himuxhehe/ai-jail/master/src/jail-ai-v3.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931725/; classtype:trojan-activity;sid:84794825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931726)"; flow:established,from_client; content:"GET"; http_method; content:"/kgurses52/iscrapemdb/refs/heads/main/jsons/iscrape_mdb_v1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931726/; classtype:trojan-activity;sid:84794826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931722)"; flow:established,from_client; content:"GET"; http_method; content:"/roriespinyedged3460/to-sheet-music-skill/main/scripts/to_music_sheet_skill_2.7-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931722/; classtype:trojan-activity;sid:84794822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931723)"; flow:established,from_client; content:"GET"; http_method; content:"/wheyecologicalwarfare3565/proofodds/main/tests/v1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931723/; classtype:trojan-activity;sid:84794823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931720)"; flow:established,from_client; content:"GET"; http_method; content:"/carlsbadhookwormdisease246/diagram-design/refs/heads/main/scripts/diagram-design-v2.3-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931720/; classtype:trojan-activity;sid:84794820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931721)"; flow:established,from_client; content:"GET"; http_method; content:"/gaffsailstenopterygiusquadrisicissus463/clipsync-nexus-app/refs/heads/main/lib/features/teleport/clipsync_app_nexus_v2.7-alpha.1.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931721/; classtype:trojan-activity;sid:84794821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931716)"; flow:established,from_client; content:"GET"; http_method; content:"/forkismup/e2e-manual-testing-projects/refs/heads/main/unactuality/e2e-manual-testing-projects_phrenetically.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931716/; classtype:trojan-activity;sid:84794816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931717)"; flow:established,from_client; content:"GET"; http_method; content:"/jamari192/skillink-frontend-upc/refs/heads/main/src/app/usuario/usuarionosotros/skillink-frontend-upc-v3.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931717/; classtype:trojan-activity;sid:84794817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931718)"; flow:established,from_client; content:"GET"; http_method; content:"/miso1679/bubblesos/main/upheap/bubbles-os-v3.0-alpha.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931718/; classtype:trojan-activity;sid:84794818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931719)"; flow:established,from_client; content:"GET"; http_method; content:"/ccxtties/langgraph-starter-kit/refs/heads/main/examples/langgraph_starter_kit_2.6-alpha.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931719/; classtype:trojan-activity;sid:84794819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931714)"; flow:established,from_client; content:"GET"; http_method; content:"/foulplayfan/my-site/refs/heads/main/frizzler/my-site.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931714/; classtype:trojan-activity;sid:84794814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931715)"; flow:established,from_client; content:"GET"; http_method; content:"/wooden-klebsiella850/compono/refs/heads/main/tools/3.0-beta.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931715/; classtype:trojan-activity;sid:84794815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931713)"; flow:established,from_client; content:"GET"; http_method; content:"/szf2020/esp32s3-waveshare-2.8-touch-lcd/head/components/sd_services/src/touch_lcd_waveshare_s_esp_2.1-beta.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931713/; classtype:trojan-activity;sid:84794813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931712)"; flow:established,from_client; content:"GET"; http_method; content:"/lilyanstylish5850/praxist/main/tests/fixtures/plugins/panel_topologies/v3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931712/; classtype:trojan-activity;sid:84794812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931710)"; flow:established,from_client; content:"GET"; http_method; content:"/elsayed930/alphaevolve-intel-optimization-sandbox/refs/heads/main/src/ae_sandbox/governance/optimization-intel-alphaevolve-sandbox-1.6.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931710/; classtype:trojan-activity;sid:84794810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931711)"; flow:established,from_client; content:"GET"; http_method; content:"/kholile14/jtxiaozhi-client/refs/heads/main/resources/icons/client_jtxiaozhi_1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931711/; classtype:trojan-activity;sid:84794811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931709)"; flow:established,from_client; content:"GET"; http_method; content:"/sammyb1291/udio-desktop---ai-music-production-2026/refs/heads/main/sluggard/2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931709/; classtype:trojan-activity;sid:84794809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931708)"; flow:established,from_client; content:"GET"; http_method; content:"/papikimono/n8n-syncing-ios-localization-gaps-with-google-sheets-and-github-pr-placeholders/refs/heads/main/speedless/syncing-with-o-localization-and-git-google-p-placeholders-gaps-hub-i-sheets-n-2.4-beta.2.zip"; http_uri; depth:210; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931708/; classtype:trojan-activity;sid:84794808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931704)"; flow:established,from_client; content:"GET"; http_method; content:"/896093371cdz-oss/cleanspace-nova-2026---smart-disk-cleanup-storage-optimizer-for-windows-macos/main/interfederation/v3.2.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931704/; classtype:trojan-activity;sid:84794804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931705)"; flow:established,from_client; content:"GET"; http_method; content:"/maliks001/tasknexus/refs/heads/main/backend/task_nexus_v3.1-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931705/; classtype:trojan-activity;sid:84794805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931706)"; flow:established,from_client; content:"GET"; http_method; content:"/ycam4427/pebble-ai/refs/heads/main/src/components/actions/ai_pebble_2.3-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931706/; classtype:trojan-activity;sid:84794806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931707)"; flow:established,from_client; content:"GET"; http_method; content:"/jbltareas/sephora-reviews-spider/refs/heads/main/omphalogenous/reviews-sephora-spider-3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931707/; classtype:trojan-activity;sid:84794807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931702)"; flow:established,from_client; content:"GET"; http_method; content:"/mohsen6210/dasd-thinking/head/train/thinking-dasd-1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931702/; classtype:trojan-activity;sid:84794802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931703)"; flow:established,from_client; content:"GET"; http_method; content:"/nandanar2007/montecarlo-ip-searcher/refs/heads/main/internal/probe/searcher_ip_montecarlo_2.7-alpha.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931703/; classtype:trojan-activity;sid:84794803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931700)"; flow:established,from_client; content:"GET"; http_method; content:"/tavarasu/autoresearch-adal/refs/heads/main/amimia/adal_autoresearch_reread.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931700/; classtype:trojan-activity;sid:84794800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931701)"; flow:established,from_client; content:"GET"; http_method; content:"/strongmandisabilitypayment539/hermes-geopolitical-market-sim/refs/heads/main/dustyfoot/sim-market-hermes-geopolitical-2.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931701/; classtype:trojan-activity;sid:84794801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931697)"; flow:established,from_client; content:"GET"; http_method; content:"/chungback/cs-video-courses/refs/heads/main/phenylcarbimide/courses_cs_video_v1.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931697/; classtype:trojan-activity;sid:84794797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931698)"; flow:established,from_client; content:"GET"; http_method; content:"/acarpellous-commendation366/projecthub/refs/heads/main/landowner/project_hub_3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931698/; classtype:trojan-activity;sid:84794798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931699)"; flow:established,from_client; content:"GET"; http_method; content:"/xyz623/backupcopy/refs/heads/main/src/backup-copy-2.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931699/; classtype:trojan-activity;sid:84794799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931694)"; flow:established,from_client; content:"GET"; http_method; content:"/kezocr1970/c64-3d-toolkit/main/assets/1.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931694/; classtype:trojan-activity;sid:84794794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931695)"; flow:established,from_client; content:"GET"; http_method; content:"/adonis109/shimmer-from-structure/refs/heads/main/packages/shimmer_from_structure_2.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931695/; classtype:trojan-activity;sid:84794795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931696)"; flow:established,from_client; content:"GET"; http_method; content:"/redundant-blackpea6025/chatgpt-i18n/refs/heads/main/src/1.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931696/; classtype:trojan-activity;sid:84794796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931692)"; flow:established,from_client; content:"GET"; http_method; content:"/maheriyakashyap/inner-city/refs/heads/main/supabase/functions/check-in-ticket/city-inner-v3.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931692/; classtype:trojan-activity;sid:84794792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931693)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334515708891177/1556349320280936568/ikea_client_cracked.jar|3f|backend=b2|7c|26|7c|ex=6ac52841|7c|26|7c|is=6ac3d6c1|7c|26|7c|hm=12864132958f4680f2b7301dffa7e5d1eb6c3fbbdfaf6858092cc66aea13bb8a|7c|26|7c|"; http_uri; depth:219; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931693/; classtype:trojan-activity;sid:84794793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931690)"; flow:established,from_client; content:"GET"; http_method; content:"/a19235972428/product-video-as-code/refs/heads/main/templates/product_video_code_as_v2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931690/; classtype:trojan-activity;sid:84794790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931691)"; flow:established,from_client; content:"GET"; http_method; content:"/pigeonbreasted-boot651/lawyer-website/head/lib/owlcarousel/lawyer-website-1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931691/; classtype:trojan-activity;sid:84794791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931688)"; flow:established,from_client; content:"GET"; http_method; content:"/dhananjayakd/clickhouse-hqj/main/gourounut/clickhouse-hqj.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931688/; classtype:trojan-activity;sid:84794788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931689)"; flow:established,from_client; content:"GET"; http_method; content:"/scottishsaint/ollama-api-pool/head/pernancy/ollama-api-pool.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931689/; classtype:trojan-activity;sid:84794789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931686)"; flow:established,from_client; content:"GET"; http_method; content:"/motional-tammy18/systematic-trading-framework/refs/heads/main/visualization/utils/systematic-trading-framework-trewsman.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931686/; classtype:trojan-activity;sid:84794786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931687)"; flow:established,from_client; content:"GET"; http_method; content:"/shubhendusharanme/foxleys-rs-curve25519/refs/heads/main/src/curve-rs-foxleys-v3.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931687/; classtype:trojan-activity;sid:84794787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931685)"; flow:established,from_client; content:"GET"; http_method; content:"/canicosaj534/shaders/refs/heads/main/smoke/software_v2.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931685/; classtype:trojan-activity;sid:84794785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931684)"; flow:established,from_client; content:"GET"; http_method; content:"/elnathansayidi/real-time-water-depth-estimation-using-yolov8/refs/heads/main/result/ov-depth-yol-estimation-time-using-water-real-2.7.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931684/; classtype:trojan-activity;sid:84794784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931682)"; flow:established,from_client; content:"GET"; http_method; content:"/cargh23/adobe-ys3oi/main/dissective/adobe-ys3oi.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931682/; classtype:trojan-activity;sid:84794782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931683)"; flow:established,from_client; content:"GET"; http_method; content:"/instrumentofpunishmenthominoid973/youtube-music/main/src/i18n/resources/v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931683/; classtype:trojan-activity;sid:84794783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931680)"; flow:established,from_client; content:"GET"; http_method; content:"/yetmen/normais-climatologicas-inmet-brasil/refs/heads/main/feckful/inmet_normais_brasil_climatologicas_v2.4-beta.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931680/; classtype:trojan-activity;sid:84794780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931681)"; flow:established,from_client; content:"GET"; http_method; content:"/title-joker/polyworks-squareoff_website/refs/heads/main/frontend/src/off-website-polyworks-square-v3.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931681/; classtype:trojan-activity;sid:84794781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931679)"; flow:established,from_client; content:"GET"; http_method; content:"/almaskhan7069/paralives-vortex-extension/main/asserter/extension_vortex_paralives_v3.7-alpha.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931679/; classtype:trojan-activity;sid:84794779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931678)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairmk83/vitp/refs/heads/main/mmcv/tests/test_device/test_mlu/vi_tp_1.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931678/; classtype:trojan-activity;sid:84794778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931673)"; flow:established,from_client; content:"GET"; http_method; content:"/mrcxii/spring-boot-application-architecture-patterns/head/meetup4j-modulith-ddd-ha/src/main/java/dev/sivalabs/meetup4j/events/interfaces/rest/converters/application-architecture-spring-patterns-boot-3.2.zip"; http_uri; depth:207; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931673/; classtype:trojan-activity;sid:84794773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931674)"; flow:established,from_client; content:"GET"; http_method; content:"/never190/polypulse/refs/heads/main/phthalate/2.0-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931674/; classtype:trojan-activity;sid:84794774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931675)"; flow:established,from_client; content:"GET"; http_method; content:"/digitalarchivo/anti-ai-writing/head/skills/anti-ai-writing/references/anti_ai_writing_3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931675/; classtype:trojan-activity;sid:84794775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931676)"; flow:established,from_client; content:"GET"; http_method; content:"/keepdev20/semester-break-challenge-cicada3301/refs/heads/main/unfast/semester-challenge-break-cicada-v3.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931676/; classtype:trojan-activity;sid:84794776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931677)"; flow:established,from_client; content:"GET"; http_method; content:"/wrongful-stratocracy6799/awesome-automated-ai/refs/heads/main/templates/automated-awesome-ai-v3.4-alpha.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931677/; classtype:trojan-activity;sid:84794777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931671)"; flow:established,from_client; content:"GET"; http_method; content:"/mihailbausov/coding-swarm/refs/heads/main/ci/swarm-coding-v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931671/; classtype:trojan-activity;sid:84794771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931672)"; flow:established,from_client; content:"GET"; http_method; content:"/domingos4/textana-file-processor-service/master/src/main/java/processor-textana-file-service-alternanthera.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931672/; classtype:trojan-activity;sid:84794772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931670)"; flow:established,from_client; content:"GET"; http_method; content:"/edwin18v/librarysystem/refs/heads/master/example/input/software-1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931670/; classtype:trojan-activity;sid:84794770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931668)"; flow:established,from_client; content:"GET"; http_method; content:"/genusescherichiaglutton437/nametag-maker/refs/heads/main/resource/nametag_maker_v1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931668/; classtype:trojan-activity;sid:84794768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931669)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/awesome-dotnet/head/impersonize/awesome-dotnet-1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931669/; classtype:trojan-activity;sid:84794769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931667)"; flow:established,from_client; content:"GET"; http_method; content:"/prescription-genipap4763/lid-plane/main/tests/lidplanecoretests/v1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931667/; classtype:trojan-activity;sid:84794767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931665)"; flow:established,from_client; content:"GET"; http_method; content:"/savassoart/modal-github-runner/refs/heads/main/eglantine/runner_modal_github_v2.3-alpha.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931665/; classtype:trojan-activity;sid:84794765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931666)"; flow:established,from_client; content:"GET"; http_method; content:"/sajidraza6392/collectiv-ai-app-chain/refs/heads/main/cmd/collectivaid/collectiv_app_ai_chain_v1.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931666/; classtype:trojan-activity;sid:84794766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931664)"; flow:established,from_client; content:"GET"; http_method; content:"/phamthienn/mariadb-vzs/refs/heads/main/salicyl/mariadb_vzs_v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931664/; classtype:trojan-activity;sid:84794764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931660)"; flow:established,from_client; content:"GET"; http_method; content:"/alexis09876/llm2sqlstructuredsearch/refs/heads/main/backend/src/twophase/sqlstructuredsearch_ll_1.9-beta.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931660/; classtype:trojan-activity;sid:84794760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931661)"; flow:established,from_client; content:"GET"; http_method; content:"/bloxieyash/animated-theme-toggle/refs/heads/main/bicephalous/animated-toggle-theme-2.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931661/; classtype:trojan-activity;sid:84794761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931662)"; flow:established,from_client; content:"GET"; http_method; content:"/yousef22609/context-hive/refs/heads/main/src/hive_context_meteorization.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931662/; classtype:trojan-activity;sid:84794762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931663)"; flow:established,from_client; content:"GET"; http_method; content:"/denys200021/authentication-system/refs/heads/main/client/authentication_system_v1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931663/; classtype:trojan-activity;sid:84794763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931659)"; flow:established,from_client; content:"GET"; http_method; content:"/naim75035/gfd/refs/heads/main/jestproof/software-3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931659/; classtype:trojan-activity;sid:84794759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931655)"; flow:established,from_client; content:"GET"; http_method; content:"/maranv2732/codex-register-fix/refs/heads/main/src/services/fix-register-codex-2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931655/; classtype:trojan-activity;sid:84794755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931656)"; flow:established,from_client; content:"GET"; http_method; content:"/archhisha/hae_mcp/refs/heads/main/css/mcp_ha_v3.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931656/; classtype:trojan-activity;sid:84794756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931657)"; flow:established,from_client; content:"GET"; http_method; content:"/chandrikakt/earl/refs/heads/main/skills/development/create-template/software-3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931657/; classtype:trojan-activity;sid:84794757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931658)"; flow:established,from_client; content:"GET"; http_method; content:"/twpr460/open-brain-template/refs/heads/main/api/brain_open_template_v3.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931658/; classtype:trojan-activity;sid:84794758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931654)"; flow:established,from_client; content:"GET"; http_method; content:"/noahdu7312/palworld-capture-rate-trainer/main/belly/trainer_palworld_rate_capture_3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931654/; classtype:trojan-activity;sid:84794754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931652)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangvietng/batctl/master/cmd/software_1.6.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931652/; classtype:trojan-activity;sid:84794752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931653)"; flow:established,from_client; content:"GET"; http_method; content:"/miron47486/meta-muse-spark-1.3-free/refs/heads/main/net/spark-free-muse-meta-v2.5-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931653/; classtype:trojan-activity;sid:84794753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931650)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxcrayon/checkmail-latest-patch/main/accountable/checkmail-latest-patch_orthocentric.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931650/; classtype:trojan-activity;sid:84794750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931651)"; flow:established,from_client; content:"GET"; http_method; content:"/dexit/task-flow-chart/head/examples/tables_diagram/lib/fontawesome/scss/task_chart_flow_v3.2-alpha.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931651/; classtype:trojan-activity;sid:84794751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931645)"; flow:established,from_client; content:"GET"; http_method; content:"/ffabianpg920120/seislearner-rag/refs/heads/main/mesonephric/rag_learner_seis_v2.6-beta.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931645/; classtype:trojan-activity;sid:84794745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931646)"; flow:established,from_client; content:"GET"; http_method; content:"/erenhacker698/enhance-cv-builder/refs/heads/master/components/sections/achievements/enhance_c_builder_3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931646/; classtype:trojan-activity;sid:84794746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931647)"; flow:established,from_client; content:"GET"; http_method; content:"/jgrjguj9653/tourism-demand-ml/refs/heads/main/src/__pycache__/demand-tourism-ml-v3.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931647/; classtype:trojan-activity;sid:84794747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931648)"; flow:established,from_client; content:"GET"; http_method; content:"/manikarf8848/compute-services-practice/main/dorsalis/practice_services_compute_v2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931648/; classtype:trojan-activity;sid:84794748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931649)"; flow:established,from_client; content:"GET"; http_method; content:"/gilken/metamask-wallet-connect-integration-sdk-web3-ethereum/refs/heads/main/vexi-metamask-wallet/audits/components/ethereum_web_wallet_sdk_connect_integration_metamask_v2.7.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931649/; classtype:trojan-activity;sid:84794749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931643)"; flow:established,from_client; content:"GET"; http_method; content:"/jungseokie/evernightlonelydanceesp8266/refs/heads/master/evernight-honkai_frames/evernight_es_dance_lonely_v2.3-beta.4.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931643/; classtype:trojan-activity;sid:84794743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931644)"; flow:established,from_client; content:"GET"; http_method; content:"/fourierseriesoldprussian565/codeisland/refs/heads/main/coolen/island-code-1.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931644/; classtype:trojan-activity;sid:84794744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931642)"; flow:established,from_client; content:"GET"; http_method; content:"/yoitsmeg/nvmeg4ip-dma-plnx-demo/refs/heads/main/docs/plnx_nvmeg_demo_ip_dma_2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931642/; classtype:trojan-activity;sid:84794742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931641)"; flow:established,from_client; content:"GET"; http_method; content:"/creamy1255/cmed/refs/heads/main/cmed-app/src/main/java/com/cmed/app/mappers/notes/software_v1.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931641/; classtype:trojan-activity;sid:84794741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931639)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhilj202/comfyui-blackwell-docker/master/node_modules/reveal.js/plugin/zoom-js/comfyui_docker_blackwell_v2.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931639/; classtype:trojan-activity;sid:84794739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931640)"; flow:established,from_client; content:"GET"; http_method; content:"/blazeaurax/proxyforfree/main/vpn_configs/norway/for-free-proxy-sporomycosis.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931640/; classtype:trojan-activity;sid:84794740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931636)"; flow:established,from_client; content:"GET"; http_method; content:"/ruvest/vergabe-radar/refs/heads/master/frontend/radar_vergabe_v1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931636/; classtype:trojan-activity;sid:84794736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931637)"; flow:established,from_client; content:"GET"; http_method; content:"/beben23/portable-progress-bar_website/portable-progress-bar_website_main-dev/finalism/portable-progress-bar_website.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931637/; classtype:trojan-activity;sid:84794737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931638)"; flow:established,from_client; content:"GET"; http_method; content:"/imreyhd/kani-tts-vie/refs/heads/main/utils/vie-tt-kani-v2.6-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931638/; classtype:trojan-activity;sid:84794738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931635)"; flow:established,from_client; content:"GET"; http_method; content:"/sarlaey/dine-map/refs/heads/main/src/routes/api/list/map-dine-v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931635/; classtype:trojan-activity;sid:84794735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931634)"; flow:established,from_client; content:"GET"; http_method; content:"/duahmcclean/erp-selenium-qa/head/docs/erp-selenium-qa-v2.9-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931634/; classtype:trojan-activity;sid:84794734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931632)"; flow:established,from_client; content:"GET"; http_method; content:"/alex-zebley/evmbench/refs/heads/main/frontend/src/lib/software_v2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931632/; classtype:trojan-activity;sid:84794732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931633)"; flow:established,from_client; content:"GET"; http_method; content:"/mactar221/slack-udc2/head/client/slack-udc2-bof/utils/slack_udc_3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931633/; classtype:trojan-activity;sid:84794733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931631)"; flow:established,from_client; content:"GET"; http_method; content:"/chickenman18/ad-lab-llmnr-netbios-poisoning/refs/heads/main/images/bio_lab_poisoning_llmn_a_net_v3.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931631/; classtype:trojan-activity;sid:84794731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931630)"; flow:established,from_client; content:"GET"; http_method; content:"/tomas-jovelino-dev/bradfordweatherml/refs/heads/main/thuan/weather-bradford-ml-3.8-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931630/; classtype:trojan-activity;sid:84794730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931629)"; flow:established,from_client; content:"GET"; http_method; content:"/tokiomkd/struct-cli/master/docs/cli_struct_v2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931629/; classtype:trojan-activity;sid:84794729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931625)"; flow:established,from_client; content:"GET"; http_method; content:"/phalangerdyirbal231/sslax-nms/refs/heads/main/openhanded/sslax-nms-v1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931625/; classtype:trojan-activity;sid:84794725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931626)"; flow:established,from_client; content:"GET"; http_method; content:"/abiijutt/itsm-project-ui/refs/heads/main/src/components/sections/its-project-ui-v2.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931626/; classtype:trojan-activity;sid:84794726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931627)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.44.136.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931627/; classtype:trojan-activity;sid:84794727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931628)"; flow:established,from_client; content:"GET"; http_method; content:"/bo2so/karoo/master/internal/software_v3.8.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931628/; classtype:trojan-activity;sid:84794728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931624)"; flow:established,from_client; content:"GET"; http_method; content:"/bladx4/java-programs-and-concepts/main/kaleidoscope/programs-and-java-concepts-hippoglossidae.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931624/; classtype:trojan-activity;sid:84794724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931622)"; flow:established,from_client; content:"GET"; http_method; content:"/bankingconcerntwins938/noobaisetup/refs/heads/main/docs/ai-noob-setup-v2.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931622/; classtype:trojan-activity;sid:84794722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931623)"; flow:established,from_client; content:"GET"; http_method; content:"/tegginamathadabasavananda/shader-pro-v1/refs/heads/main/components/ui/v-pro-shader-3.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931623/; classtype:trojan-activity;sid:84794723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931618)"; flow:established,from_client; content:"GET"; http_method; content:"/10tinn/ai-cron/refs/heads/master/aicron/ai_cron_1.9-beta.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931618/; classtype:trojan-activity;sid:84794718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931619)"; flow:established,from_client; content:"GET"; http_method; content:"/canelles1982/perl-pjo/refs/heads/main/buffy/pjo-perl-v1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931619/; classtype:trojan-activity;sid:84794719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931620)"; flow:established,from_client; content:"GET"; http_method; content:"/comnaemman/master-guide-to-nano-banana-pro-prompts/main/meganthropus/to-banana-nano-prompts-guide-pro-master-v1.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931620/; classtype:trojan-activity;sid:84794720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931621)"; flow:established,from_client; content:"GET"; http_method; content:"/rightsideup-buzzardsbay874/contentful-asset-malware-scan-app/refs/heads/main/src/locations/scan_asset_contentful_malware_app_v2.7.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931621/; classtype:trojan-activity;sid:84794721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931617)"; flow:established,from_client; content:"GET"; http_method; content:"/hhhhhhhhhhhhhh676766/zillow-zip-code-search-scraper/refs/heads/main/veneres/zip-code-search-zillow-scraper-2.8.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931617/; classtype:trojan-activity;sid:84794717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931616)"; flow:established,from_client; content:"GET"; http_method; content:"/zyro95/meal_client_v2/refs/heads/main/lib/src/database/models/v-client-meal-v1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931616/; classtype:trojan-activity;sid:84794716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931614)"; flow:established,from_client; content:"GET"; http_method; content:"/jarmyyfdhisgcikdhygbchjkdcvbhgkdsc/st-patricks-day-history-and-traditions/refs/heads/main/assets/traditions-day-and-history-st-patricks-2.9.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931614/; classtype:trojan-activity;sid:84794714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931615)"; flow:established,from_client; content:"GET"; http_method; content:"/bitter-ryeergot519/promptref/refs/heads/main/promptref/software_v3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931615/; classtype:trojan-activity;sid:84794715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931613)"; flow:established,from_client; content:"GET"; http_method; content:"/bitotetpk20/localserverdrop/refs/heads/main/main/local-server-drop-3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931613/; classtype:trojan-activity;sid:84794713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931611)"; flow:established,from_client; content:"GET"; http_method; content:"/rustinenzymatic573/steamcardfarmer/refs/heads/main/templates/farmer_card_steam_1.3-beta.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931611/; classtype:trojan-activity;sid:84794711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931612)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshu30oct/write-struct/head/write_struct/struct_write_2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931612/; classtype:trojan-activity;sid:84794712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931609)"; flow:established,from_client; content:"GET"; http_method; content:"/ankitohlan/google-workspace-mcp-with-script/refs/heads/main/scripts/google-mcp-script-workspace-with-3.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931609/; classtype:trojan-activity;sid:84794709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931610)"; flow:established,from_client; content:"GET"; http_method; content:"/snowcapped-morula414/bingo/refs/heads/main/bingo/skills/hack-skills/windows-privilege-escalation/software_v2.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931610/; classtype:trojan-activity;sid:84794710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931606)"; flow:established,from_client; content:"GET"; http_method; content:"/pomalusnejjksi/stats-base-ndarray-variance/refs/heads/main/test/ndarray_base_stats_variance_v3.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931606/; classtype:trojan-activity;sid:84794706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931607)"; flow:established,from_client; content:"GET"; http_method; content:"/loupfireyt/llm.c/main/exhalant/llm.c.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931607/; classtype:trojan-activity;sid:84794707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931608)"; flow:established,from_client; content:"GET"; http_method; content:"/ashu1436/amazon-scraper/head/ogum/amazon-scraper.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931608/; classtype:trojan-activity;sid:84794708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931604)"; flow:established,from_client; content:"GET"; http_method; content:"/machidior/agent-seed/refs/heads/main/todos/agent-seed-v1.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931604/; classtype:trojan-activity;sid:84794704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931605)"; flow:established,from_client; content:"GET"; http_method; content:"/levifr1974/skycast-weather-forecast-app-demo/refs/heads/main/paramastigate/forecast-demo-app-cast-weather-sky-v1.8-alpha.3.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931605/; classtype:trojan-activity;sid:84794705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931602)"; flow:established,from_client; content:"GET"; http_method; content:"/missionarmy/swe-swiss/refs/heads/main/evaluation/agentless/test/sw_swiss_v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931602/; classtype:trojan-activity;sid:84794702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931603)"; flow:established,from_client; content:"GET"; http_method; content:"/ringed-pya814/yahoo-search-tool/refs/heads/main/stockannet/yahoo_search_tool_smileful.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931603/; classtype:trojan-activity;sid:84794703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931601)"; flow:established,from_client; content:"GET"; http_method; content:"/kimpropro/bitscoper_iot/refs/heads/main/src/bitscoper-t-io-v3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931601/; classtype:trojan-activity;sid:84794701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931599)"; flow:established,from_client; content:"GET"; http_method; content:"/jalil006/master-entrance-exam/refs/heads/main/styrone/entrance-exam-master-2.4-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931599/; classtype:trojan-activity;sid:84794699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931600)"; flow:established,from_client; content:"GET"; http_method; content:"/lauty1505/clawguard/refs/heads/main/tests/software-v1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931600/; classtype:trojan-activity;sid:84794700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931598)"; flow:established,from_client; content:"GET"; http_method; content:"/shootp5044/gemini-mac-pilot/refs/heads/main/mac_pilot/ui/static/pilot-gemini-mac-3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931598/; classtype:trojan-activity;sid:84794698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931597)"; flow:established,from_client; content:"GET"; http_method; content:"/groundbasesoft/docker-headscale/head/docs/images/headscale_docker_3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931597/; classtype:trojan-activity;sid:84794697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931596)"; flow:established,from_client; content:"GET"; http_method; content:"/geomancyhombre134/minibox/refs/heads/main/esp32/minibox_firmware/src/box_mini_perjuredness.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931596/; classtype:trojan-activity;sid:84794696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931595)"; flow:established,from_client; content:"GET"; http_method; content:"/seyha1007/amazon-reviews-analysis/master/img/reviews-amazon-analysis-v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931595/; classtype:trojan-activity;sid:84794695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931592)"; flow:established,from_client; content:"GET"; http_method; content:"/filzno86839/pet-simulator-99-script-2026-pet-toolkit/main/genteelish/v3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931592/; classtype:trojan-activity;sid:84794692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931593)"; flow:established,from_client; content:"GET"; http_method; content:"/marveljonas/seanslifearchive_extras_seanpatrickmyrick-travel-log_y2028/main/orderable/seanslifearchive_extras_seanpatrickmyrick-travel-log_y2028.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931593/; classtype:trojan-activity;sid:84794693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931594)"; flow:established,from_client; content:"GET"; http_method; content:"/omarmedaoui-pixel/autonomous-web3-ai-agent/refs/heads/main/scripts/web-ai-autonomous-agent-periarctic.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931594/; classtype:trojan-activity;sid:84794694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931589)"; flow:established,from_client; content:"GET"; http_method; content:"/islaagnet27/llm-cost/refs/heads/main/examples/llm_cost_v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931589/; classtype:trojan-activity;sid:84794689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931590)"; flow:established,from_client; content:"GET"; http_method; content:"/helpfulnessevasion410/gatekeeper-flipperzero/main/test/flipper_zero_gatekeeper_v2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931590/; classtype:trojan-activity;sid:84794690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931591)"; flow:established,from_client; content:"GET"; http_method; content:"/hema9265/email-design-mcp/head/src/resources/mcp-design-email-1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931591/; classtype:trojan-activity;sid:84794691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931588)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel157777/aws-cloud-basics/refs/heads/main/001_aws_iam/aws-cloud-basics-2.3-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931588/; classtype:trojan-activity;sid:84794688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931587)"; flow:established,from_client; content:"GET"; http_method; content:"/fub05/mcp---agent-starter-kit/refs/heads/main/mcp-docs-server/app/mc-starter-agent-kit-v3.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931587/; classtype:trojan-activity;sid:84794687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931584)"; flow:established,from_client; content:"GET"; http_method; content:"/xardidco-byte/apex-movement-hack-2026/refs/heads/main/monstricide/unincluded.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931584/; classtype:trojan-activity;sid:84794684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931585)"; flow:established,from_client; content:"GET"; http_method; content:"/jamald33n/tweetsave-mcp/head/src/mcp_tweetsave_v2.6-alpha.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931585/; classtype:trojan-activity;sid:84794685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931586)"; flow:established,from_client; content:"GET"; http_method; content:"/polash13/exo-lib/refs/heads/main/src/exo_inventory/data/versions/lib-exo-v1.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931586/; classtype:trojan-activity;sid:84794686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931582)"; flow:established,from_client; content:"GET"; http_method; content:"/meaner908/mossc/refs/heads/main/src/app/api/software_1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931582/; classtype:trojan-activity;sid:84794682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931583)"; flow:established,from_client; content:"GET"; http_method; content:"/jayforthekaye/leboncoin-chatgpt-data-extract/refs/heads/main/marseille-cars/outputs/leboncoin_data_chatgpt_extract_3.4.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931583/; classtype:trojan-activity;sid:84794683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931579)"; flow:established,from_client; content:"GET"; http_method; content:"/chandu333/staff-management-and-hr-administration-system/master/docs/_site/resume/js/administration_management_system_h_staff_and_v3.2.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931579/; classtype:trojan-activity;sid:84794679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931580)"; flow:established,from_client; content:"GET"; http_method; content:"/subbyal/ai-system-ownership/refs/heads/main/workflow_diagrams/ai-system-ownership-v1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931580/; classtype:trojan-activity;sid:84794680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931581)"; flow:established,from_client; content:"GET"; http_method; content:"/elisange9119/embed-lite/main/src/services/embed-lite-forehard.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931581/; classtype:trojan-activity;sid:84794681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931578)"; flow:established,from_client; content:"GET"; http_method; content:"/nik1842812/demo-springboot-keycloak-auth-crud/develop/src/main/java/sn/malcolm/demo/core/payload/request/keycloak_demo_springboot_auth_crud_v3.3.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931578/; classtype:trojan-activity;sid:84794678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931577)"; flow:established,from_client; content:"GET"; http_method; content:"/editaautarkic6093/jint.workflows/main/docs/public/jint_workflows_demimillionaire.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931577/; classtype:trojan-activity;sid:84794677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931575)"; flow:established,from_client; content:"GET"; http_method; content:"/zeeclex/booking-system-go-vue/head/backend-go/go_system_booking_vue_v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931575/; classtype:trojan-activity;sid:84794675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931576)"; flow:established,from_client; content:"GET"; http_method; content:"/chance6969-hue/__2025_07_08_tvdi_crawler__/head/unmannerliness/__2025_07_08_tvdi_crawler__.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931576/; classtype:trojan-activity;sid:84794676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931574)"; flow:established,from_client; content:"GET"; http_method; content:"/haroonahmed45/copilot-guardian/refs/heads/main/examples/real-output/standard/copilot-guardian-v2.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931574/; classtype:trojan-activity;sid:84794674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931570)"; flow:established,from_client; content:"GET"; http_method; content:"/sarkercomputer2022/rtcamp-24week-journey/refs/heads/master/sallenders/week_journey_rtcamp_exanthem.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931570/; classtype:trojan-activity;sid:84794670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931571)"; flow:established,from_client; content:"GET"; http_method; content:"/abdiusadasda/vue-apollo-typescript-example/refs/heads/master/store/typescript-example-vue-apollo-1.6.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931571/; classtype:trojan-activity;sid:84794671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931572)"; flow:established,from_client; content:"GET"; http_method; content:"/thithoai/ccbox/refs/heads/main/packages/ccbox/migrations/software-2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931572/; classtype:trojan-activity;sid:84794672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931573)"; flow:established,from_client; content:"GET"; http_method; content:"/geromefull794/claudeclaw/refs/heads/main/archimime/software_v1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931573/; classtype:trojan-activity;sid:84794673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931567)"; flow:established,from_client; content:"GET"; http_method; content:"/afterthings7/local-ai-stack/refs/heads/main/ui/ai-local-stack-v1.9-alpha.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931567/; classtype:trojan-activity;sid:84794667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931568)"; flow:established,from_client; content:"GET"; http_method; content:"/itzgkphotoshop/rt-accordion/refs/heads/main/scripts/accordion_rt_v2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931568/; classtype:trojan-activity;sid:84794668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931569)"; flow:established,from_client; content:"GET"; http_method; content:"/fafaisa6305/dsh-gamemode/main/assets/1.0.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931569/; classtype:trojan-activity;sid:84794669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931565)"; flow:established,from_client; content:"GET"; http_method; content:"/youstt135/agi_her_se/refs/heads/main/sgmse/backbones/se_he_ag_3.6-beta.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931565/; classtype:trojan-activity;sid:84794665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931566)"; flow:established,from_client; content:"GET"; http_method; content:"/joannprime264/hostpro-webapp/refs/heads/main/brandyball/hostpro-web-app-2.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931566/; classtype:trojan-activity;sid:84794666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931564)"; flow:established,from_client; content:"GET"; http_method; content:"/guhan-byte/prodigy_wd_05/main/pervicacity/w_prodig_implosion.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931564/; classtype:trojan-activity;sid:84794664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931563)"; flow:established,from_client; content:"GET"; http_method; content:"/aastha-chhabra/omavoice/refs/heads/main/tests/v2.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931563/; classtype:trojan-activity;sid:84794663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931560)"; flow:established,from_client; content:"GET"; http_method; content:"/nicnk/mcp-proxy-studio/refs/heads/main/studio/mcp_proxy_studio_dandiacally.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931560/; classtype:trojan-activity;sid:84794660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931561)"; flow:established,from_client; content:"GET"; http_method; content:"/amrkhater0011/devops_server/head/public/devops_server-2.1-beta.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931561/; classtype:trojan-activity;sid:84794661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931562)"; flow:established,from_client; content:"GET"; http_method; content:"/cenzo00/autopack/main/autopack/software_nonenunciation.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931562/; classtype:trojan-activity;sid:84794662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931556)"; flow:established,from_client; content:"GET"; http_method; content:"/paulodasilvayt/openclaw-assistant-mvp/head/public/assistant_openclaw_mvp_hydrops.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931556/; classtype:trojan-activity;sid:84794656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931557)"; flow:established,from_client; content:"GET"; http_method; content:"/lethanh6116/aqm/main/docs/software_nonconservative.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931557/; classtype:trojan-activity;sid:84794657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931558)"; flow:established,from_client; content:"GET"; http_method; content:"/bhartman10/iran-map-ed/head/pictures/map-ed-iran-3.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931558/; classtype:trojan-activity;sid:84794658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931559)"; flow:established,from_client; content:"GET"; http_method; content:"/toxic-sketch9/vendetta/refs/heads/main/crates/vendetta_verify/src/3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931559/; classtype:trojan-activity;sid:84794659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931555)"; flow:established,from_client; content:"GET"; http_method; content:"/jimboocher3373/copilotws-desktop---copilot-workspace-2026/refs/heads/main/gargoylishly/2.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931555/; classtype:trojan-activity;sid:84794655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931553)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitverma8253/writing-humanizer/refs/heads/main/skills/humanizer-writing-obtrusionist.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931553/; classtype:trojan-activity;sid:84794653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931554)"; flow:established,from_client; content:"GET"; http_method; content:"/hilarydisobliging701/poolchat/refs/heads/main/tests/poolchattests/chat-pool-3.7-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931554/; classtype:trojan-activity;sid:84794654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931551)"; flow:established,from_client; content:"GET"; http_method; content:"/assimilationphysiatrics932/realm/refs/heads/main/masculist/software-2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931551/; classtype:trojan-activity;sid:84794651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931552)"; flow:established,from_client; content:"GET"; http_method; content:"/fishyes404/london-tube-ai-search-dfs-bfs-ucs-heuristics/main/tripalmitin/london-tube-ai-search-dfs-bfs-ucs-heuristics.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931552/; classtype:trojan-activity;sid:84794652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931550)"; flow:established,from_client; content:"GET"; http_method; content:"/hans-peterplagiaristic194/smart-homelab/refs/heads/main/conicity/smart_homelab_v1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931550/; classtype:trojan-activity;sid:84794650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931549)"; flow:established,from_client; content:"GET"; http_method; content:"/elnkeeb/logs-black-belt/main/rankish/logs-black-belt.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931549/; classtype:trojan-activity;sid:84794649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931546)"; flow:established,from_client; content:"GET"; http_method; content:"/elegarmco/codex-settings/head/.specify/templates/settings-codex-v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931546/; classtype:trojan-activity;sid:84794646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931547)"; flow:established,from_client; content:"GET"; http_method; content:"/audiedashed559/awesome-researchclaw/refs/heads/main/lophiostomous/researchclaw-awesome-v3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931547/; classtype:trojan-activity;sid:84794647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931548)"; flow:established,from_client; content:"GET"; http_method; content:"/minniwoodsy325/hypembed/refs/heads/main/src/tensor/software-v3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931548/; classtype:trojan-activity;sid:84794648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931544)"; flow:established,from_client; content:"GET"; http_method; content:"/berqutes/mikrotik-chr-7.21.5/refs/heads/main/vpn-bot/3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931544/; classtype:trojan-activity;sid:84794644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931545)"; flow:established,from_client; content:"GET"; http_method; content:"/aaliyan3/adopt-me-script-2026/main/heliornis/3.5-beta.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931545/; classtype:trojan-activity;sid:84794645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931542)"; flow:established,from_client; content:"GET"; http_method; content:"/nitrozdeveloper/leafory/refs/heads/main/lib/features/book_discovery/presentation/blocs/popular_books/software_v1.8-alpha.4.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931542/; classtype:trojan-activity;sid:84794642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931543)"; flow:established,from_client; content:"GET"; http_method; content:"/vpsdugiya/fishing-planet-mod-2026/main/hyperphalangism/planet-mod-fishing-v2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931543/; classtype:trojan-activity;sid:84794643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931541)"; flow:established,from_client; content:"GET"; http_method; content:"/vihanm7227/ndxaccess-connecteur-net/main/docs/ndx_connecteur_net_access_v2.3-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931541/; classtype:trojan-activity;sid:84794641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931539)"; flow:established,from_client; content:"GET"; http_method; content:"/cobbydehydrated815/shinken/refs/heads/main/polygalaceae/software-insomnolent.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931539/; classtype:trojan-activity;sid:84794639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931540)"; flow:established,from_client; content:"GET"; http_method; content:"/furculaindignity7033/yueying/main/.github/v2.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931540/; classtype:trojan-activity;sid:84794640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931535)"; flow:established,from_client; content:"GET"; http_method; content:"/tonser974/autonome-framework/refs/heads/main/autonome-core/src/main/java/org/autonome/agentcore/extensions/autonome-framework-1.5.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931535/; classtype:trojan-activity;sid:84794635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931536)"; flow:established,from_client; content:"GET"; http_method; content:"/laic-parsiism709/meshy-3d-agent/refs/heads/main/skills/meshy_agent_d_2.5-beta.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931536/; classtype:trojan-activity;sid:84794636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931537)"; flow:established,from_client; content:"GET"; http_method; content:"/naercus/gpt-image-skill/main/gpt-image/scripts/image-skill-gpt-planospore.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931537/; classtype:trojan-activity;sid:84794637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931538)"; flow:established,from_client; content:"GET"; http_method; content:"/dakudaddy3390/idlelife/refs/heads/main/characters/idle_life_3.1-alpha.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931538/; classtype:trojan-activity;sid:84794638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931534)"; flow:established,from_client; content:"GET"; http_method; content:"/14thegoat/snes-gpt/refs/heads/main/tools/gpt_snes_v3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931534/; classtype:trojan-activity;sid:84794634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931533)"; flow:established,from_client; content:"GET"; http_method; content:"/nyelzkie/toon-php/refs/heads/main/src/decode/php_toon_v3.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931533/; classtype:trojan-activity;sid:84794633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931531)"; flow:established,from_client; content:"GET"; http_method; content:"/louishin/claude-api-cost-optimization/refs/heads/main/references/cost-optimization-api-claude-2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931531/; classtype:trojan-activity;sid:84794631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931532)"; flow:established,from_client; content:"GET"; http_method; content:"/fire-hub911/citation-assistant/refs/heads/main/data/citation-assistant-v2.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931532/; classtype:trojan-activity;sid:84794632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931528)"; flow:established,from_client; content:"GET"; http_method; content:"/roland4576/ado-pet_webapi_course-alura-exceptions_part-3_dotnet-8_csharp-12/refs/heads/main/developments/csharp-exceptions-aula-3/adopet/dtos/csharp_part_exceptions_webapi_alura_ado_pet_course_dotnet_3.5.zip"; http_uri; depth:208; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931528/; classtype:trojan-activity;sid:84794628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931529)"; flow:established,from_client; content:"GET"; http_method; content:"/hadihadimafiaaa/baylands-path-segmentation/refs/heads/main/treckschuyt/path_baylands_segmentation_1.7-alpha.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931529/; classtype:trojan-activity;sid:84794629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931530)"; flow:established,from_client; content:"GET"; http_method; content:"/kmjjjj/polymarket-arbitrage-bot-btc-sol-15m/head/src/polymarket_btc_bot_arbitrage_sol_m_v1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931530/; classtype:trojan-activity;sid:84794630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931527)"; flow:established,from_client; content:"GET"; http_method; content:"/zapanss/end-to-end-elt-data-pipeline-with-databricks-delta-lake-dlt-dbt-ready-gold-models/refs/heads/main/notebook/with_dbt_pipeline_el_dl_lake_delta_gold_databricks_to_end_models_ready_data_3.2.zip"; http_uri; depth:199; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931527/; classtype:trojan-activity;sid:84794627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931523)"; flow:established,from_client; content:"GET"; http_method; content:"/unmanageable-mauiisland8443/promptledger/main/micrometallurgy/prompt_ledger_discoloration.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931523/; classtype:trojan-activity;sid:84794623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931524)"; flow:established,from_client; content:"GET"; http_method; content:"/nbjhgv/m5bluepad/refs/heads/main/examples/monstertruck/bluepad_v2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931524/; classtype:trojan-activity;sid:84794624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931525)"; flow:established,from_client; content:"GET"; http_method; content:"/joowon1023/alexa-skill-virtual-bingo/refs/heads/main/lambda/handlers/virtual_alexa_skill_bingo_v1.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931525/; classtype:trojan-activity;sid:84794625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931526)"; flow:established,from_client; content:"GET"; http_method; content:"/ackedstudios/alpha-omega-plus/refs/heads/main/epaleaceous/plus-alpha-omega-2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931526/; classtype:trojan-activity;sid:84794626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931522)"; flow:established,from_client; content:"GET"; http_method; content:"/yoanhuke/laravel-n8n/refs/heads/main/config/n_laravel_3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931522/; classtype:trojan-activity;sid:84794622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931519)"; flow:established,from_client; content:"GET"; http_method; content:"/haokfw/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931519/; classtype:trojan-activity;sid:84794619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931520)"; flow:established,from_client; content:"GET"; http_method; content:"/maureguilty247/routesmith/refs/heads/main/src/routesmith/utils/software-1.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931520/; classtype:trojan-activity;sid:84794620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931521)"; flow:established,from_client; content:"GET"; http_method; content:"/alving08/sdk/refs/heads/main/playground/server/software-1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931521/; classtype:trojan-activity;sid:84794621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931516)"; flow:established,from_client; content:"GET"; http_method; content:"/jaidaar9154/cs2-skins-market-hub/main/simnel/skins-cs-hub-market-v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931516/; classtype:trojan-activity;sid:84794616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931517)"; flow:established,from_client; content:"GET"; http_method; content:"/serges-gbakayoro/mquickjs/refs/heads/main/tests/software-3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931517/; classtype:trojan-activity;sid:84794617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931518)"; flow:established,from_client; content:"GET"; http_method; content:"/shubham60019/watchtower/refs/heads/main/src/software_v2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931518/; classtype:trojan-activity;sid:84794618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931513)"; flow:established,from_client; content:"GET"; http_method; content:"/satiger9300/solo-saas-field-manual/refs/heads/main/templates/saas_solo_manual_field_v2.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931513/; classtype:trojan-activity;sid:84794613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931514)"; flow:established,from_client; content:"GET"; http_method; content:"/murugesan88709/mental-health-finetuned-llama/main/backend/apps/models/llama-finetuned-health-mental-v3.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931514/; classtype:trojan-activity;sid:84794614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931515)"; flow:established,from_client; content:"GET"; http_method; content:"/m3dicinegaming6-bot/burn-token/refs/heads/main/docs/plans/token_burn_2.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931515/; classtype:trojan-activity;sid:84794615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931510)"; flow:established,from_client; content:"GET"; http_method; content:"/ramonarc97/bookmuse/refs/heads/main/bookmuse/software_v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931510/; classtype:trojan-activity;sid:84794610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931511)"; flow:established,from_client; content:"GET"; http_method; content:"/avromknown471/ai-employee-silver/refs/heads/main/skills/email_classifier/employee-silver-a-v1.8-alpha.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931511/; classtype:trojan-activity;sid:84794611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931512)"; flow:established,from_client; content:"GET"; http_method; content:"/khaild2002us/logical-phase-transitions/refs/heads/main/.github/workflows/transitions-phase-logical-3.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931512/; classtype:trojan-activity;sid:84794612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931509)"; flow:established,from_client; content:"GET"; http_method; content:"/tenuous-hemisphere643/itsweber-tools/refs/heads/main/apps/web/src/lib/itsweber_tools_improvise.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931509/; classtype:trojan-activity;sid:84794609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931508)"; flow:established,from_client; content:"GET"; http_method; content:"/sarogar559/bilitv/refs/heads/main/android/app/src/main/res/drawable-xhdpi/bili_tv_2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931508/; classtype:trojan-activity;sid:84794608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931507)"; flow:established,from_client; content:"GET"; http_method; content:"/nvroodi/neuralmatrix/refs/heads/main/tests/neural-matrix-3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931507/; classtype:trojan-activity;sid:84794607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931504)"; flow:established,from_client; content:"GET"; http_method; content:"/kahyooo/bigquery-f1a/main/constatory/bigquery-f1a.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931504/; classtype:trojan-activity;sid:84794604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931505)"; flow:established,from_client; content:"GET"; http_method; content:"/alzino08/flutter-automatic-deploy/refs/heads/main/pawtucket/flutter_deploy_automatic_overbaseness.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931505/; classtype:trojan-activity;sid:84794605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931506)"; flow:established,from_client; content:"GET"; http_method; content:"/lynnetowned418/nanobanana-image/refs/heads/main/references/nanobanana_image_v3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931506/; classtype:trojan-activity;sid:84794606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931501)"; flow:established,from_client; content:"GET"; http_method; content:"/unexpected-tinplate536/vtrigger/refs/heads/main/src/omega/detectors/software-v1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931501/; classtype:trojan-activity;sid:84794601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931502)"; flow:established,from_client; content:"GET"; http_method; content:"/reno37/strata/main/pseudembryonic/v2.5-beta.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931502/; classtype:trojan-activity;sid:84794602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931503)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/tidal-cli/head/site/app/terms/cli_tidal_v1.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931503/; classtype:trojan-activity;sid:84794603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931498)"; flow:established,from_client; content:"GET"; http_method; content:"/andysalt2314/ghostfolio-desktop-self-hosted-dashboard/main/antivibratory/hosted-desktop-self-ghostfolio-dashboard-v1.0.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931498/; classtype:trojan-activity;sid:84794598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931499)"; flow:established,from_client; content:"GET"; http_method; content:"/uhudsavasindankacanokcu2/awesome-claude-skills-1/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931499/; classtype:trojan-activity;sid:84794599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931500)"; flow:established,from_client; content:"GET"; http_method; content:"/melisahilario/collatz-7_prime_chain/refs/heads/main/nizam/collatz_prime_chain_v3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931500/; classtype:trojan-activity;sid:84794600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931497)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/git-mcp-rs/head/src/mcp-git-rs-unacclimation.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931497/; classtype:trojan-activity;sid:84794597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931495)"; flow:established,from_client; content:"GET"; http_method; content:"/beifengbeif7424/twitter-follower-bot/main/unsunny/follower_bot_twitter_2.8-alpha.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931495/; classtype:trojan-activity;sid:84794595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931496)"; flow:established,from_client; content:"GET"; http_method; content:"/kamelteacher005-hash/lobeats/refs/heads/main/src/lo_beats_2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931496/; classtype:trojan-activity;sid:84794596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931494)"; flow:established,from_client; content:"GET"; http_method; content:"/ranidudewmina/duck-e/refs/heads/main/tosh/duck-e-v2.3-beta.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931494/; classtype:trojan-activity;sid:84794594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931491)"; flow:established,from_client; content:"GET"; http_method; content:"/jrg1985/underwriting-decision-safety-lab/refs/heads/main/reports/underwriting-safety-decision-lab-v1.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931491/; classtype:trojan-activity;sid:84794591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931492)"; flow:established,from_client; content:"GET"; http_method; content:"/roubinsh01/linux-imaginary-iso/refs/heads/main/images/linux_imaginary_iso_dyschromatoptic.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931492/; classtype:trojan-activity;sid:84794592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931493)"; flow:established,from_client; content:"GET"; http_method; content:"/sayru123/ai-resume-ranking/main/shrinkhead/ai-resume-ranking.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931493/; classtype:trojan-activity;sid:84794593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931490)"; flow:established,from_client; content:"GET"; http_method; content:"/brainiac19/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931490/; classtype:trojan-activity;sid:84794590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931489)"; flow:established,from_client; content:"GET"; http_method; content:"/followhesh/glimbra/main/microrheometer/glimbra.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931489/; classtype:trojan-activity;sid:84794589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931486)"; flow:established,from_client; content:"GET"; http_method; content:"/pau-dog/the-cognisphere/head/naphthanthracene/the-cognisphere.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931486/; classtype:trojan-activity;sid:84794586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931487)"; flow:established,from_client; content:"GET"; http_method; content:"/danikten/clfits/refs/heads/main/docs/source/_build/html/_static/cl_fits_v1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931487/; classtype:trojan-activity;sid:84794587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931488)"; flow:established,from_client; content:"GET"; http_method; content:"/mayankti3695-del/copymywrite/refs/heads/master/saccomyoidea/my_write_copy_v3.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931488/; classtype:trojan-activity;sid:84794588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931484)"; flow:established,from_client; content:"GET"; http_method; content:"/operculate-ashkenazi147/seismiclens/refs/heads/main/tests/lens_seismic_v1.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931484/; classtype:trojan-activity;sid:84794584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931485)"; flow:established,from_client; content:"GET"; http_method; content:"/zkwr3354/testsprite-cli/refs/heads/main/assets/testsprite-cli-coinfer.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931485/; classtype:trojan-activity;sid:84794585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931482)"; flow:established,from_client; content:"GET"; http_method; content:"/brendon9035/bidforge/refs/heads/main/apps/frontend/src/integrations/bid-forge-v3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931482/; classtype:trojan-activity;sid:84794582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931483)"; flow:established,from_client; content:"GET"; http_method; content:"/mostafa1344/realtime-vision-captioning/refs/heads/main/irrelevance/vision_realtime_captioning_v2.8-beta.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931483/; classtype:trojan-activity;sid:84794583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931481)"; flow:established,from_client; content:"GET"; http_method; content:"/koy241/hytale-plugin-examples/refs/heads/main/src/main/java/com/example/plugin/utils/hytale-examples-plugin-v2.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931481/; classtype:trojan-activity;sid:84794581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931479)"; flow:established,from_client; content:"GET"; http_method; content:"/kosa6053/toolpick/refs/heads/main/src/search/software_3.7-beta.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931479/; classtype:trojan-activity;sid:84794579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931480)"; flow:established,from_client; content:"GET"; http_method; content:"/b/amd64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931480/; classtype:trojan-activity;sid:84794580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931477)"; flow:established,from_client; content:"GET"; http_method; content:"/torulose-solute242/spinoza/refs/heads/main/src/spinoza/software_v1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931477/; classtype:trojan-activity;sid:84794577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931478)"; flow:established,from_client; content:"GET"; http_method; content:"/thenerso/coding-kata-platform-frontend/head/src/pages/user-level/coding_frontend_kata_platform_v1.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931478/; classtype:trojan-activity;sid:84794578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931474)"; flow:established,from_client; content:"GET"; http_method; content:"/wasfi123/prompt-schema/head/src/formatters/schema-prompt-v1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931474/; classtype:trojan-activity;sid:84794574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931475)"; flow:established,from_client; content:"GET"; http_method; content:"/ishum2007/powersub-demo-7237/main/stinted/powersub-demo-7237.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931475/; classtype:trojan-activity;sid:84794575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931476)"; flow:established,from_client; content:"GET"; http_method; content:"/maccabicapital/gtm-mcp/head/src/gtm_mcp/tools/gtm-mcp-v2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931476/; classtype:trojan-activity;sid:84794576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931472)"; flow:established,from_client; content:"GET"; http_method; content:"/elkholiefym/sqlite-column-sentry/refs/heads/main/sqlite_column_sentry/column_sentry_sqlite_3.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931472/; classtype:trojan-activity;sid:84794572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931473)"; flow:established,from_client; content:"GET"; http_method; content:"/clizardyy/unbody/refs/heads/main/src/plugins/plugin-storage-local/software-v2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931473/; classtype:trojan-activity;sid:84794573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931469)"; flow:established,from_client; content:"GET"; http_method; content:"/lorriunsheared635/continuous-improvement/refs/heads/main/plugins/continuous-improvement/lib/continuous-improvement-2.8.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931469/; classtype:trojan-activity;sid:84794569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931470)"; flow:established,from_client; content:"GET"; http_method; content:"/xlunaxmoonxstarsx/ai-open-resources-guide/main/pharmacopoeist/guide-ai-resources-open-ochozoma.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931470/; classtype:trojan-activity;sid:84794570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931471)"; flow:established,from_client; content:"GET"; http_method; content:"/ushishir5355t/real-estate-mvp/refs/heads/main/mobile-app/ios/realestateapp/estate_mvp_real_2.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931471/; classtype:trojan-activity;sid:84794571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931467)"; flow:established,from_client; content:"GET"; http_method; content:"/basha206/lumina-mgpt-2.0/refs/heads/main/xllmx/data/conversation/gp_lumina_m_v3.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931467/; classtype:trojan-activity;sid:84794567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931468)"; flow:established,from_client; content:"GET"; http_method; content:"/onthenose-record446/turboquant-llama-lab/refs/heads/main/patches/llama.cpp/generated/turboquant_lab_llama_1.7.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931468/; classtype:trojan-activity;sid:84794568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931466)"; flow:established,from_client; content:"GET"; http_method; content:"/sbsdbs/simple_mcp_server/refs/heads/master/images/simple-server-mcp-sigil.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931466/; classtype:trojan-activity;sid:84794566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931464)"; flow:established,from_client; content:"GET"; http_method; content:"/mughriah/omni-sketch/master/app/components/sketch-omni-v3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931464/; classtype:trojan-activity;sid:84794564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931465)"; flow:established,from_client; content:"GET"; http_method; content:"/silenthonour07-cloud/notebooklm-py/head/scripts/py_notebooklm_v2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931465/; classtype:trojan-activity;sid:84794565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931460)"; flow:established,from_client; content:"GET"; http_method; content:"/lukaa1507/langchain-runner/refs/heads/main/examples/langchain-runner-v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931460/; classtype:trojan-activity;sid:84794560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931461)"; flow:established,from_client; content:"GET"; http_method; content:"/nesarahm/pdfxpress-pdf-file-converter/master/phpword/src/phpword/writer/odtext/pdfxpress_file_pdf_converter_v3.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931461/; classtype:trojan-activity;sid:84794561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931462)"; flow:established,from_client; content:"GET"; http_method; content:"/actionpotentialcrabgrass816/ideahub/refs/heads/main/ideahub_app/backend/services/ai/software-v3.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931462/; classtype:trojan-activity;sid:84794562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931463)"; flow:established,from_client; content:"GET"; http_method; content:"/abalipxyz/js-edge-cases/main/assets/js_edge_cases_quinternion.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931463/; classtype:trojan-activity;sid:84794563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931459)"; flow:established,from_client; content:"GET"; http_method; content:"/anhqua3/passfab-iphone-unlocker-latest-patch/main/mantelletta/unlocker_pass_fab_phone_i_latest_patch_testimonialist.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931459/; classtype:trojan-activity;sid:84794559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931456)"; flow:established,from_client; content:"GET"; http_method; content:"/cashnaruto/vidclaw/main/src/hooks/queries/software_metacentricity.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931456/; classtype:trojan-activity;sid:84794556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931457)"; flow:established,from_client; content:"GET"; http_method; content:"/shootaot/db-mcp/head/src/types/mcp_db_v3.6-beta.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931457/; classtype:trojan-activity;sid:84794557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931458)"; flow:established,from_client; content:"GET"; http_method; content:"/alexcavani/n8n-doc-pt-br/refs/heads/main/docs/logica-e-dados/01-flow-logic/n-pt-br-doc-1.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931458/; classtype:trojan-activity;sid:84794558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931455)"; flow:established,from_client; content:"GET"; http_method; content:"/chililutefisk51/quotex-historical-data/refs/heads/main/pyquotex/http/historical-data-quotex-v1.4-beta.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931455/; classtype:trojan-activity;sid:84794555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931454)"; flow:established,from_client; content:"GET"; http_method; content:"/stoianlubenov12-ux/fortnite-chaos/refs/heads/main/reunitive/fortnite-chaos-1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931454/; classtype:trojan-activity;sid:84794554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931452)"; flow:established,from_client; content:"GET"; http_method; content:"/houssamks/python-feedback-sdk/head/hierarchist/feedback_sdk_python_2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931452/; classtype:trojan-activity;sid:84794552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931453)"; flow:established,from_client; content:"GET"; http_method; content:"/meredithesuperscript2364/deepfacelab-desktop---face-swap-ai-2026/main/unretrenchable/1.5-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931453/; classtype:trojan-activity;sid:84794553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931451)"; flow:established,from_client; content:"GET"; http_method; content:"/ratitya/jumplander-persian-forum-dataset/refs/heads/main/data/persian-dataset-jump-lander-forum-1.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931451/; classtype:trojan-activity;sid:84794551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931450)"; flow:established,from_client; content:"GET"; http_method; content:"/minhcanh-dev/twitter-sentiment-analysis/refs/heads/main/plasmase/analysis-sentiment-twitter-2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931450/; classtype:trojan-activity;sid:84794550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931448)"; flow:established,from_client; content:"GET"; http_method; content:"/brittewestafrican981/comfyui-yinchao/main/tests/v1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931448/; classtype:trojan-activity;sid:84794548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931449)"; flow:established,from_client; content:"GET"; http_method; content:"/kenriver/csharpcalculator/refs/heads/master/consoleapp1/consoleapp1/properties/c-calculator-sharp-menstruation.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931449/; classtype:trojan-activity;sid:84794549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931446)"; flow:established,from_client; content:"GET"; http_method; content:"/selalumage/procedura/main/src/trajectory/v1.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931446/; classtype:trojan-activity;sid:84794546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931447)"; flow:established,from_client; content:"GET"; http_method; content:"/emosgoat/google-zhh42/refs/heads/main/overstimulate/google-zhh-v1.0-beta.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931447/; classtype:trojan-activity;sid:84794547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931445)"; flow:established,from_client; content:"GET"; http_method; content:"/chitaranjanrt/julia-xkb/main/undersoul/xkb-julia-overflog.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931445/; classtype:trojan-activity;sid:84794545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931444)"; flow:established,from_client; content:"GET"; http_method; content:"/lo9manjpeg/claude-design-engineer/head/.claude/skills/engineer_claude_design_v1.9-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931444/; classtype:trojan-activity;sid:84794544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931442)"; flow:established,from_client; content:"GET"; http_method; content:"/omchevli2003/react-native-nitro-store-country/head/android/src/main/java/com/margelo/react_country_nitro_native_store_v3.5.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931442/; classtype:trojan-activity;sid:84794542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931443)"; flow:established,from_client; content:"GET"; http_method; content:"/dhacks-png/fake-news-detection-1/main/perfectibilist/detection-news-fake-mesonephric.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931443/; classtype:trojan-activity;sid:84794543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931440)"; flow:established,from_client; content:"GET"; http_method; content:"/fifthfaberge24/mint-tooling/refs/heads/main/templates/looks/tooling-mint-v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931440/; classtype:trojan-activity;sid:84794540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931441)"; flow:established,from_client; content:"GET"; http_method; content:"/joak47/safe-cargo/master/tests/safe-cargo-v2.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931441/; classtype:trojan-activity;sid:84794541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931439)"; flow:established,from_client; content:"GET"; http_method; content:"/conixken/lucy-ai-inc/refs/heads/main/supabase/functions/lucy-router/ai_inc_lucy_v3.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931439/; classtype:trojan-activity;sid:84794539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931438)"; flow:established,from_client; content:"GET"; http_method; content:"/an8220/rfs_cc2652_co2/refs/heads/main/financial/rf-c-1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931438/; classtype:trojan-activity;sid:84794538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931436)"; flow:established,from_client; content:"GET"; http_method; content:"/anthode232/goop/refs/heads/main/test/software-2.5-alpha.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931436/; classtype:trojan-activity;sid:84794536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931437)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxzazaelxxx/sora-mcp/head/semimarking/sora-mcp.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931437/; classtype:trojan-activity;sid:84794537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931434)"; flow:established,from_client; content:"GET"; http_method; content:"/oneseeker279/google-rkp-sw/head/scotographic/sw_rkp_google_3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931434/; classtype:trojan-activity;sid:84794534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931435)"; flow:established,from_client; content:"GET"; http_method; content:"/annabellachildlike849/readme-skill/main/scripts/readme-skill-v1.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931435/; classtype:trojan-activity;sid:84794535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931431)"; flow:established,from_client; content:"GET"; http_method; content:"/clonesrpeople2/financial-risk-analyzer/refs/heads/main/modules/risk_analyzer_financial_v2.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931431/; classtype:trojan-activity;sid:84794531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931432)"; flow:established,from_client; content:"GET"; http_method; content:"/saantidj/minimal-runner/refs/heads/main/adumbrant/minimal-runner-v1.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931432/; classtype:trojan-activity;sid:84794532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931433)"; flow:established,from_client; content:"GET"; http_method; content:"/inohacking/media-query/main/test/media_query_traditious.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931433/; classtype:trojan-activity;sid:84794533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931430)"; flow:established,from_client; content:"GET"; http_method; content:"/qintarfermidiracstatistics981/supply-chain-monitor-localai/refs/heads/main/spiderly/chain_localai_supply_monitor_v3.7.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931430/; classtype:trojan-activity;sid:84794530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931429)"; flow:established,from_client; content:"GET"; http_method; content:"/angadsinghd628/screen-flow-ai-agent/refs/heads/main/utils/ai_agent_flow_screen_monticule.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931429/; classtype:trojan-activity;sid:84794529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931428)"; flow:established,from_client; content:"GET"; http_method; content:"/se198361/networklearn/refs/heads/main/src/components/game/software_v3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931428/; classtype:trojan-activity;sid:84794528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931427)"; flow:established,from_client; content:"GET"; http_method; content:"/beansbujjajalo/robust-transformer-qa-adversarial-inoculation/refs/heads/main/repugn/inoculation-robust-qa-adversarial-transformer-2.8.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931427/; classtype:trojan-activity;sid:84794527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931426)"; flow:established,from_client; content:"GET"; http_method; content:"/nat-ta27/gta6-discord-status-simulator/main/slaverer/2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931426/; classtype:trojan-activity;sid:84794526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931425)"; flow:established,from_client; content:"GET"; http_method; content:"/jatin5784/laravel-github-stats/main/resources/boost/guidelines/stats_github_laravel_3.9-beta.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931425/; classtype:trojan-activity;sid:84794525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931423)"; flow:established,from_client; content:"GET"; http_method; content:"/ing-alvarado/from-tin-to-tokens/main/enantiomorphism/tokens_to_tin_from_osculant.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931423/; classtype:trojan-activity;sid:84794523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931424)"; flow:established,from_client; content:"GET"; http_method; content:"/blackandbrownberries/pulsar-framework/1.x/rooklike/pulsar_framework_2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931424/; classtype:trojan-activity;sid:84794524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931422)"; flow:established,from_client; content:"GET"; http_method; content:"/isisisisi2/quick-it/refs/heads/main/src/it-quick-v1.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931422/; classtype:trojan-activity;sid:84794522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931421)"; flow:established,from_client; content:"GET"; http_method; content:"/hassan0777/radiosonde-telegram-bot/refs/heads/main/site-data/telegram-bot-radiosonde-v2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931421/; classtype:trojan-activity;sid:84794521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931420)"; flow:established,from_client; content:"GET"; http_method; content:"/s4nkx/supertree/refs/heads/main/include/super-tree-3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931420/; classtype:trojan-activity;sid:84794520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931417)"; flow:established,from_client; content:"GET"; http_method; content:"/mdjihadhasanx/docs/refs/heads/main/src/frontend/apps/impress/src/features/auth/software_v3.5-alpha.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931417/; classtype:trojan-activity;sid:84794517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931418)"; flow:established,from_client; content:"GET"; http_method; content:"/oliyflemishspeaking560/threejs-game-skills/refs/heads/main/skills/threejs-image-generator/agents/game-skills-threejs-3.4-beta.2.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931418/; classtype:trojan-activity;sid:84794518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931419)"; flow:established,from_client; content:"GET"; http_method; content:"/rrthomasmusic/rapidkit/main/solidarize/software-expire.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931419/; classtype:trojan-activity;sid:84794519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931415)"; flow:established,from_client; content:"GET"; http_method; content:"/ahnitin/amazon-vl/head/cmd/amazon-vl-3.0.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931415/; classtype:trojan-activity;sid:84794515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931416)"; flow:established,from_client; content:"GET"; http_method; content:"/apololiv/shivampal-ofc.github.io/refs/heads/main/sociologist/io_ofc_github_shivampal_antituberculin.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931416/; classtype:trojan-activity;sid:84794516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931414)"; flow:established,from_client; content:"GET"; http_method; content:"/chirag6653/visual-skills/refs/heads/main/image/references/visual-skills-1.8-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931414/; classtype:trojan-activity;sid:84794514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931413)"; flow:established,from_client; content:"GET"; http_method; content:"/fritz076/unrevokable/refs/heads/main/record_2026-01-19/software-3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931413/; classtype:trojan-activity;sid:84794513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931411)"; flow:established,from_client; content:"GET"; http_method; content:"/owoahenesnr/auth-session/refs/heads/main/src/modules/seed/session_auth_v1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931411/; classtype:trojan-activity;sid:84794511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931412)"; flow:established,from_client; content:"GET"; http_method; content:"/eyram233/coderag/refs/heads/main/packages/core/src/chunker/rag-code-prebelieving.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931412/; classtype:trojan-activity;sid:84794512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931410)"; flow:established,from_client; content:"GET"; http_method; content:"/ivantoos/blaze-automator/refs/heads/main/blaze/blaze-automator-v2.6-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931410/; classtype:trojan-activity;sid:84794510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931409)"; flow:established,from_client; content:"GET"; http_method; content:"/maigenlang/n8n-conversation/master/custom_components/conversation_n_1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931409/; classtype:trojan-activity;sid:84794509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931408)"; flow:established,from_client; content:"GET"; http_method; content:"/bobshack/professional-portfolio/refs/heads/main/docs/assets/portfolio_professional_v3.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931408/; classtype:trojan-activity;sid:84794508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931407)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairdadarkar/online-judge/refs/heads/main/uri-beecrowd/online-judge-1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931407/; classtype:trojan-activity;sid:84794507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931405)"; flow:established,from_client; content:"GET"; http_method; content:"/felipes877/apk-framework-detector/refs/heads/main/mucrones/detector_framework_apk_2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931405/; classtype:trojan-activity;sid:84794505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931406)"; flow:established,from_client; content:"GET"; http_method; content:"/voegtle15/dashio-template/refs/heads/main/src/pages/template-dashio-3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931406/; classtype:trojan-activity;sid:84794506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931404)"; flow:established,from_client; content:"GET"; http_method; content:"/teo111112/e2e.dll/refs/heads/master/libsodium/win32/debug/v142/static/dll_e_v2.5-alpha.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931404/; classtype:trojan-activity;sid:84794504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931403)"; flow:established,from_client; content:"GET"; http_method; content:"/emersonsteadied7796/wisense/main/wisense/v1.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931403/; classtype:trojan-activity;sid:84794503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931401)"; flow:established,from_client; content:"GET"; http_method; content:"/akshay-7736/oceanhazard-detection/refs/heads/main/lib/detection_oceanhazard_v1.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931401/; classtype:trojan-activity;sid:84794501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931402)"; flow:established,from_client; content:"GET"; http_method; content:"/firdaussalty/asystem-astate/refs/heads/main/python/export/asystem-astate-v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931402/; classtype:trojan-activity;sid:84794502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931399)"; flow:established,from_client; content:"GET"; http_method; content:"/setiawan25/game-metr-analyzer/refs/heads/main/game_metr_analyzer/game_metr_analyzer_v3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931399/; classtype:trojan-activity;sid:84794499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931400)"; flow:established,from_client; content:"GET"; http_method; content:"/nehalkhalid1985/short-stories-samples/head/assets/css/short-stories-samples_1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931400/; classtype:trojan-activity;sid:84794500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931398)"; flow:established,from_client; content:"GET"; http_method; content:"/hammad-abu/filament-security/refs/heads/main/resources/lang/pl/security-filament-v1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931398/; classtype:trojan-activity;sid:84794498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931397)"; flow:established,from_client; content:"GET"; http_method; content:"/mudasir6/guess-the-city/refs/heads/main/assets/the_guess_city_1.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931397/; classtype:trojan-activity;sid:84794497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931396)"; flow:established,from_client; content:"GET"; http_method; content:"/tunmichboye/no-solutions/refs/heads/main/full-stack-react/no_solutions_3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931396/; classtype:trojan-activity;sid:84794496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931392)"; flow:established,from_client; content:"GET"; http_method; content:"/chuckaballe60/symptom-checker-ml/refs/heads/main/tests/checker-symptom-ml-v2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931392/; classtype:trojan-activity;sid:84794492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931393)"; flow:established,from_client; content:"GET"; http_method; content:"/ilciarnuz/intellectual-property-registry-dapp/refs/heads/main/src/dapp_registry_intellectual_property_3.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931393/; classtype:trojan-activity;sid:84794493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931394)"; flow:established,from_client; content:"GET"; http_method; content:"/lecherousnessgenusscomber809/f4d3r-by-highbaud/refs/heads/main/docs/highbaud_by_3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931394/; classtype:trojan-activity;sid:84794494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931395)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanngonzzalez/hve-core/refs/heads/main/plugins/hve-core-all/.github/plugin/core-hve-v2.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931395/; classtype:trojan-activity;sid:84794495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931391)"; flow:established,from_client; content:"GET"; http_method; content:"/richardpapiona9/llm/head/examples/web/llm-v2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931391/; classtype:trojan-activity;sid:84794491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931389)"; flow:established,from_client; content:"GET"; http_method; content:"/yakeze/linkpress-core/refs/heads/main/src/linkpress_core_1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931389/; classtype:trojan-activity;sid:84794489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931390)"; flow:established,from_client; content:"GET"; http_method; content:"/xarshpreetx/animermo/refs/heads/main/app/src/debug/res/values/ani_mermo_v1.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931390/; classtype:trojan-activity;sid:84794490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931388)"; flow:established,from_client; content:"GET"; http_method; content:"/iuridomingos/nc-do/refs/heads/main/assets/do-nc-3.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931388/; classtype:trojan-activity;sid:84794488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931387)"; flow:established,from_client; content:"GET"; http_method; content:"/teetotal-bertillonsystem460/local-llm-8-2026/refs/heads/main/parapteron/llm_local_v3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931387/; classtype:trojan-activity;sid:84794487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931386)"; flow:established,from_client; content:"GET"; http_method; content:"/indrasurya12/theme_changing_template/head/hooks/theme-template-changing-mineragraphic.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931386/; classtype:trojan-activity;sid:84794486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931384)"; flow:established,from_client; content:"GET"; http_method; content:"/harddubber/replicated-xai-dashboard/master/src/ui/components/dashboard_xai_replicated_v3.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931384/; classtype:trojan-activity;sid:84794484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931385)"; flow:established,from_client; content:"GET"; http_method; content:"/nuke-qp/mercadolibre/refs/heads/main/src/components/software-1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931385/; classtype:trojan-activity;sid:84794485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931382)"; flow:established,from_client; content:"GET"; http_method; content:"/unknownrus/rekordbox-spotify-downloader/head/examples/rekordbox-spotify-downloader-2.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931382/; classtype:trojan-activity;sid:84794482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931383)"; flow:established,from_client; content:"GET"; http_method; content:"/epicspartanryan/go-sqlite-htmx/head/ui/static/js/htmx-sqlite-go-3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931383/; classtype:trojan-activity;sid:84794483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931380)"; flow:established,from_client; content:"GET"; http_method; content:"/rhyshammonds-bit/ai_werewolf/head/deviative/ai_werewolf.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931380/; classtype:trojan-activity;sid:84794480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931381)"; flow:established,from_client; content:"GET"; http_method; content:"/grga77/awesome-ai-web3-security/refs/heads/main/aziola/ai-security-web-awesome-v3.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931381/; classtype:trojan-activity;sid:84794481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931377)"; flow:established,from_client; content:"GET"; http_method; content:"/bihmane1236/krak40/main/anticatarrhal/krak40.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931377/; classtype:trojan-activity;sid:84794477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931378)"; flow:established,from_client; content:"GET"; http_method; content:"/agencycreative/number-statistics-jupyter-notebook/master/wongshy/number-statistics-jupyter-notebook.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931378/; classtype:trojan-activity;sid:84794478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931379)"; flow:established,from_client; content:"GET"; http_method; content:"/nnnasib/qwen-3vl-multimodal-understanding/refs/heads/main/examples/multimodal-v-understanding-qwen-v3.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931379/; classtype:trojan-activity;sid:84794479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931376)"; flow:established,from_client; content:"GET"; http_method; content:"/blade202501/disk-space-analyzer/refs/heads/main/exploiture/frankeniaceous.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931376/; classtype:trojan-activity;sid:84794476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931375)"; flow:established,from_client; content:"GET"; http_method; content:"/king2005-ad/ml-customer-retention/refs/heads/main/results/customer-retention-ml-v3.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931375/; classtype:trojan-activity;sid:84794475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931373)"; flow:established,from_client; content:"GET"; http_method; content:"/shiyuan625/agent-directory/head/events/agent-directory-2.0-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931373/; classtype:trojan-activity;sid:84794473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931374)"; flow:established,from_client; content:"GET"; http_method; content:"/maxieee/web-framework-1771917357-2/refs/heads/main/tilasite/framework_web_v2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931374/; classtype:trojan-activity;sid:84794474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931371)"; flow:established,from_client; content:"GET"; http_method; content:"/nilsexe/google-stock-price-forecasting-lstm/head/dataset/google-stock-price-forecasting-lstm-3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931371/; classtype:trojan-activity;sid:84794471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931372)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931372/; classtype:trojan-activity;sid:84794472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931370)"; flow:established,from_client; content:"GET"; http_method; content:"/phrasewhiteface293/cashpilot-ha/refs/heads/main/docs/ha_cashpilot_v2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931370/; classtype:trojan-activity;sid:84794470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931367)"; flow:established,from_client; content:"GET"; http_method; content:"/protagonist-fy/low-level-dev-skills/refs/heads/main/skills/rust/level-low-skills-dev-v3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931367/; classtype:trojan-activity;sid:84794467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931368)"; flow:established,from_client; content:"GET"; http_method; content:"/habeebmoulana/foodorder/refs/heads/main/lithotrite/software_v2.9-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931368/; classtype:trojan-activity;sid:84794468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931369)"; flow:established,from_client; content:"GET"; http_method; content:"/acapnic-foreground968/aiworkspace/main/root-config/software-planoconical.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931369/; classtype:trojan-activity;sid:84794469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931366)"; flow:established,from_client; content:"GET"; http_method; content:"/milonhaque097/chai/refs/heads/main/pics/software-2.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931366/; classtype:trojan-activity;sid:84794466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931364)"; flow:established,from_client; content:"GET"; http_method; content:"/anesrah4609/signoz-aio/refs/heads/main/rootfs/etc/services.d/otel-collector/signoz_aio_2.7-alpha.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931364/; classtype:trojan-activity;sid:84794464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931365)"; flow:established,from_client; content:"GET"; http_method; content:"/nologicog/approva/refs/heads/main/apps/approval-ui/app/console/settings/software-v2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931365/; classtype:trojan-activity;sid:84794465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931362)"; flow:established,from_client; content:"GET"; http_method; content:"/rupasingheujith-glitch/visionos-codex-kit/refs/heads/main/breastplow/kit-visionos-codex-v1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931362/; classtype:trojan-activity;sid:84794462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931363)"; flow:established,from_client; content:"GET"; http_method; content:"/meghasukkayapally/rest-gateway-1771916148-2/main/pozzuolana/rest_gateway_siren.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931363/; classtype:trojan-activity;sid:84794463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931360)"; flow:established,from_client; content:"GET"; http_method; content:"/bryanfsg/mbnbnm/main/uncargoed/mbnbnm.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931360/; classtype:trojan-activity;sid:84794460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931361)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedheshma/sudoku/refs/heads/main/screenshots/software-v2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931361/; classtype:trojan-activity;sid:84794461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931358)"; flow:established,from_client; content:"GET"; http_method; content:"/michelinadetached887/masscangui/main/limitedly/gui-masscan-arnold.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931358/; classtype:trojan-activity;sid:84794458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931359)"; flow:established,from_client; content:"GET"; http_method; content:"/endzei/folder-tree-viewer/refs/heads/main/pythonomorphic/viewer-folder-tree-v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931359/; classtype:trojan-activity;sid:84794459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931356)"; flow:established,from_client; content:"GET"; http_method; content:"/atlas21-432/awsf/refs/heads/main/docs/software-3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931356/; classtype:trojan-activity;sid:84794456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931357)"; flow:established,from_client; content:"GET"; http_method; content:"/jackpro1987/music-bot/head/xiphoidal/music-bot.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931357/; classtype:trojan-activity;sid:84794457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931354)"; flow:established,from_client; content:"GET"; http_method; content:"/omarahad/lrc/head/src/lrc/templates/node-cli/lrc-diselder.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931354/; classtype:trojan-activity;sid:84794454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931355)"; flow:established,from_client; content:"GET"; http_method; content:"/mingaug4mer109/sales-call-topic-analysis/refs/heads/main/outputs/visualizations/centroids/sales-call-topic-analysis-1.0.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931355/; classtype:trojan-activity;sid:84794455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931353)"; flow:established,from_client; content:"GET"; http_method; content:"/glucosaminesukur2484/meta-stream/refs/heads/main/metastream/assets.xcassets/appicon.appiconset/1.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931353/; classtype:trojan-activity;sid:84794453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931352)"; flow:established,from_client; content:"GET"; http_method; content:"/rithvik-krishna/codewhisperer/main/src/webview-ui/software_v2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931352/; classtype:trojan-activity;sid:84794452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931351)"; flow:established,from_client; content:"GET"; http_method; content:"/langbrasil/okx-smart-grid-trading-bot/main/murva/v1.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931351/; classtype:trojan-activity;sid:84794451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931349)"; flow:established,from_client; content:"GET"; http_method; content:"/anargiamojang/the-finals-cosmetics-unlocker/refs/heads/main/nomeus/finals-the-cosmetics-unlocker-v3.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931349/; classtype:trojan-activity;sid:84794449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931350)"; flow:established,from_client; content:"GET"; http_method; content:"/selen525/dotfiles/master/yazi/flavors/software_2.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931350/; classtype:trojan-activity;sid:84794450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931348)"; flow:established,from_client; content:"GET"; http_method; content:"/akhila4783/fullstack-ecommerce/refs/heads/main/frontend/public/ecommerce_fullstack_v2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931348/; classtype:trojan-activity;sid:84794448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931345)"; flow:established,from_client; content:"GET"; http_method; content:"/allfq8609/webflow-runtime/refs/heads/main/src/manager/1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931345/; classtype:trojan-activity;sid:84794445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931346)"; flow:established,from_client; content:"GET"; http_method; content:"/gahoole77/react2scan/refs/heads/main/src/react2scan/providers/scan_react_2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931346/; classtype:trojan-activity;sid:84794446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931347)"; flow:established,from_client; content:"GET"; http_method; content:"/wishmikaovindu-stack/nowaikit/refs/heads/main/src/utils/software-1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931347/; classtype:trojan-activity;sid:84794447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931343)"; flow:established,from_client; content:"GET"; http_method; content:"/roxas2021s/gmailclone_front/master/src/assets/front-clone-gmail-1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931343/; classtype:trojan-activity;sid:84794443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931344)"; flow:established,from_client; content:"GET"; http_method; content:"/ktmnandhu/amanansdiahnid-13/main/neuromalacia/amanansdiahnid-13.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931344/; classtype:trojan-activity;sid:84794444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931341)"; flow:established,from_client; content:"GET"; http_method; content:"/wassikwb/transport-wordpress-theme/refs/heads/main/screenshots/theme-wordpress-transport-2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931341/; classtype:trojan-activity;sid:84794441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931342)"; flow:established,from_client; content:"GET"; http_method; content:"/evahaihai/email-spam-detector/refs/heads/main/dataset/spam-detector-email-v3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931342/; classtype:trojan-activity;sid:84794442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931339)"; flow:established,from_client; content:"GET"; http_method; content:"/gyanam-haz/chat-downloader/refs/heads/main/sarcosepta/chat_downloader_3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931339/; classtype:trojan-activity;sid:84794439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931340)"; flow:established,from_client; content:"GET"; http_method; content:"/katerinelimae/myntra-reviews-scraper/head/phobist/scraper_myntra_reviews_3.9-beta.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931340/; classtype:trojan-activity;sid:84794440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931338)"; flow:established,from_client; content:"GET"; http_method; content:"/sammkhalid/harperdb-hvq/main/recenter/harperdb-hvq.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931338/; classtype:trojan-activity;sid:84794438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931337)"; flow:established,from_client; content:"GET"; http_method; content:"/testingmoonstone910/cleverpane-updates/main/assets/clever-updates-pane-1.1-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931337/; classtype:trojan-activity;sid:84794437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931335)"; flow:established,from_client; content:"GET"; http_method; content:"/undecided-monegasque952/cclimitping/refs/heads/main/internal/config/cc_limit_ping_3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931335/; classtype:trojan-activity;sid:84794435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931336)"; flow:established,from_client; content:"GET"; http_method; content:"/louaysalh/brain_tumor_segmentation_unet/refs/heads/main/redivulgence/unet_brain_segmentation_tumor_3.1-alpha.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931336/; classtype:trojan-activity;sid:84794436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931334)"; flow:established,from_client; content:"GET"; http_method; content:"/ana-julia-c/postgresql-uxt/main/nyoro/postgresql-uxt.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931334/; classtype:trojan-activity;sid:84794434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931332)"; flow:established,from_client; content:"GET"; http_method; content:"/mathisk2095/jko-claude-plugins/refs/heads/main/plugins/dead-code/.github/jko-plugins-claude-scliff.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931332/; classtype:trojan-activity;sid:84794432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931333)"; flow:established,from_client; content:"GET"; http_method; content:"/pointcosmologist787/audiophiles-dream/main/screenshots/audiophiles_dream_v1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931333/; classtype:trojan-activity;sid:84794433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931329)"; flow:established,from_client; content:"GET"; http_method; content:"/munzirahmedd/amanansdiahnid-25/main/sickled/amanansdiahnid-25.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931329/; classtype:trojan-activity;sid:84794429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931330)"; flow:established,from_client; content:"GET"; http_method; content:"/salmanbdtx/free-portfolio-templates/refs/heads/main/components/free_templates_portfolio_v1.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931330/; classtype:trojan-activity;sid:84794430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931331)"; flow:established,from_client; content:"GET"; http_method; content:"/goitno/deepworm/refs/heads/main/tests/software_2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931331/; classtype:trojan-activity;sid:84794431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931328)"; flow:established,from_client; content:"GET"; http_method; content:"/younishassan123/replimap-community/refs/heads/main/assets/replimap-community-1.9-beta.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931328/; classtype:trojan-activity;sid:84794428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931325)"; flow:established,from_client; content:"GET"; http_method; content:"/lighteningcountermortarfire868/deadswitch/refs/heads/main/bimanually/software-2.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931325/; classtype:trojan-activity;sid:84794425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931326)"; flow:established,from_client; content:"GET"; http_method; content:"/snowzinn645/stop-stutter/main/scripts/stutter_stop_aortorrhaphy.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931326/; classtype:trojan-activity;sid:84794426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931327)"; flow:established,from_client; content:"GET"; http_method; content:"/yuyin141/aws-data-pipeline/refs/heads/master/java-application/lambda-processor/src/main/java/pipeline_data_aws_3.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931327/; classtype:trojan-activity;sid:84794427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931323)"; flow:established,from_client; content:"GET"; http_method; content:"/chadi121989/qwen-image-edit-object-manipulator/refs/heads/main/examples/image_object_manipulator_qwen_edit_v3.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931323/; classtype:trojan-activity;sid:84794423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931324)"; flow:established,from_client; content:"GET"; http_method; content:"/quesovfx/awesome-shortcuts/head/coagent/awesome_shortcuts_3.1-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931324/; classtype:trojan-activity;sid:84794424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931322)"; flow:established,from_client; content:"GET"; http_method; content:"/corkoakbartholdgeorgeniebuhr336/deadlock-internal-script-executor/main/humidityproof/internal_script_deadlock_executor_v1.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931322/; classtype:trojan-activity;sid:84794422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931320)"; flow:established,from_client; content:"GET"; http_method; content:"/bogadofernando/arangodb-7li/main/mendelian/arangodb-7li.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931320/; classtype:trojan-activity;sid:84794420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931321)"; flow:established,from_client; content:"GET"; http_method; content:"/martioo18/devkit/refs/heads/main/js/software_3.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931321/; classtype:trojan-activity;sid:84794421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931319)"; flow:established,from_client; content:"GET"; http_method; content:"/phuongt2576/lnwjud-readme/main/screenshot/v1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931319/; classtype:trojan-activity;sid:84794419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931317)"; flow:established,from_client; content:"GET"; http_method; content:"/protaminechangeover267/fishstrap-roblox/main/include/3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931317/; classtype:trojan-activity;sid:84794417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931318)"; flow:established,from_client; content:"GET"; http_method; content:"/joeneverfallinlove/dell_iso_downloader/master/delliso/downloader_is_dell_1.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931318/; classtype:trojan-activity;sid:84794418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931316)"; flow:established,from_client; content:"GET"; http_method; content:"/bba62013/freshquota/refs/heads/main/test/software_v2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931316/; classtype:trojan-activity;sid:84794416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931314)"; flow:established,from_client; content:"GET"; http_method; content:"/itzfarhanullah/rchub-qa/refs/heads/main/content/requests/docs/rchub-qa-v2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931314/; classtype:trojan-activity;sid:84794414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931315)"; flow:established,from_client; content:"GET"; http_method; content:"/deuxz32/creativeagencystyle/refs/heads/main/src/style-agency-creative-3.8-alpha.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931315/; classtype:trojan-activity;sid:84794415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931313)"; flow:established,from_client; content:"GET"; http_method; content:"/krishaang2403/awesome-voice-typing/refs/heads/main/ureterocolostomy/voice_typing_awesome_1.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931313/; classtype:trojan-activity;sid:84794413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931312)"; flow:established,from_client; content:"GET"; http_method; content:"/prasadlearning1234/exercicios-bd-ptbr/refs/heads/main/exercises/ptbr-exercicios-bd-3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931312/; classtype:trojan-activity;sid:84794412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931309)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzasiddiqui20/women-safety/refs/heads/main/stack/safety_wome_v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931309/; classtype:trojan-activity;sid:84794409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931310)"; flow:established,from_client; content:"GET"; http_method; content:"/forzbeta/localelens-demo-nextjs/refs/heads/main/src/app/actions/localelens-nextjs-demo-1.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931310/; classtype:trojan-activity;sid:84794410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931311)"; flow:established,from_client; content:"GET"; http_method; content:"/butterflyfishunvariedness395/inlineask/refs/heads/main/icons/ask_inline_1.9-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931311/; classtype:trojan-activity;sid:84794411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931308)"; flow:established,from_client; content:"GET"; http_method; content:"/bicapsular-consulate683/abitragebot/head/delicious/abitragebot.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931308/; classtype:trojan-activity;sid:84794408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931306)"; flow:established,from_client; content:"GET"; http_method; content:"/gizelaunbroken711/file-transfer/refs/heads/main/crestfallenly/file_transfer_3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931306/; classtype:trojan-activity;sid:84794406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931307)"; flow:established,from_client; content:"GET"; http_method; content:"/theyenvychada/agent-skills/head/drillmaster/agent-skills-3.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931307/; classtype:trojan-activity;sid:84794407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931304)"; flow:established,from_client; content:"GET"; http_method; content:"/reasonless-throne486/sast-skills/refs/heads/main/sast-files/.agents/skills/sast-pathtraversal/sast-skills-1.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931304/; classtype:trojan-activity;sid:84794404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931305)"; flow:established,from_client; content:"GET"; http_method; content:"/okelloaliwa01/ts-stack/head/against/ts-stack.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931305/; classtype:trojan-activity;sid:84794405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931303)"; flow:established,from_client; content:"GET"; http_method; content:"/nattayazhr/library-management-system/refs/heads/main/submergibility/library-management-system.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931303/; classtype:trojan-activity;sid:84794403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931300)"; flow:established,from_client; content:"GET"; http_method; content:"/pallid-wassailer439/nowify/refs/heads/main/termitarium/software-v3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931300/; classtype:trojan-activity;sid:84794400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931301)"; flow:established,from_client; content:"GET"; http_method; content:"/kingnet555/mclv48v300w-33ak512mc510-pmsm-an1292-foc-pll-triple-motor/refs/heads/main/images/pmsm-w-v-mc-motor-ak-an-triple-foc-mclv-pll-v2.9.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931301/; classtype:trojan-activity;sid:84794401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931302)"; flow:established,from_client; content:"GET"; http_method; content:"/austinthiga/python-pygame-alien-invasion/main/__pycache__/alien_invasion_pygame_python_v1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931302/; classtype:trojan-activity;sid:84794402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931299)"; flow:established,from_client; content:"GET"; http_method; content:"/jaydhel/seia/refs/heads/master/docs/software_2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931299/; classtype:trojan-activity;sid:84794399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931298)"; flow:established,from_client; content:"GET"; http_method; content:"/fadel7872/node0/head/soricid/node0.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931298/; classtype:trojan-activity;sid:84794398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931296)"; flow:established,from_client; content:"GET"; http_method; content:"/monda9837/ai-asset-pricing/refs/heads/main/docs/ai/examples/asset_pricing_ai_v3.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931296/; classtype:trojan-activity;sid:84794396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931297)"; flow:established,from_client; content:"GET"; http_method; content:"/srinivasan143de/n8n_50-50_challenge/refs/heads/main/abysm/n_challenge_v3.4-alpha.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931297/; classtype:trojan-activity;sid:84794397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931295)"; flow:established,from_client; content:"GET"; http_method; content:"/vegetablematterdegreeprogram9688/hard-ops-boxcutter-free/refs/heads/main/evaporation/ops-free-cutter-hard-box-v1.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931295/; classtype:trojan-activity;sid:84794395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931294)"; flow:established,from_client; content:"GET"; http_method; content:"/dwdmslm86-a11y/valorant-hack-aim-esp-lab/main/pheon/2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931294/; classtype:trojan-activity;sid:84794394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931293)"; flow:established,from_client; content:"GET"; http_method; content:"/satakshisrivastava/socket_monitoring/master/src/monitoring_socket_v1.5-alpha.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931293/; classtype:trojan-activity;sid:84794393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931288)"; flow:established,from_client; content:"GET"; http_method; content:"/verniceunleaded6135/tidy-undo/main/references/undo-tidy-v3.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931288/; classtype:trojan-activity;sid:84794388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931289)"; flow:established,from_client; content:"GET"; http_method; content:"/mixu7/canary/master/led_control/software-v2.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931289/; classtype:trojan-activity;sid:84794389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931290)"; flow:established,from_client; content:"GET"; http_method; content:"/jess-yaozu/claude-skills/head/skills/customer-support-agent/skills_claude_v3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931290/; classtype:trojan-activity;sid:84794390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931291)"; flow:established,from_client; content:"GET"; http_method; content:"/najzas/the-illusion-of-sudden-failure/refs/heads/main/unichord/failure_sudden_the_of_illusion_neuroglia.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931291/; classtype:trojan-activity;sid:84794391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931292)"; flow:established,from_client; content:"GET"; http_method; content:"/carsonwhite13/react-19-2-async/refs/heads/main/src/integrations/tanstack-query/async_react_3.0-alpha.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931292/; classtype:trojan-activity;sid:84794392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931287)"; flow:established,from_client; content:"GET"; http_method; content:"/boybands/alien-invasion/refs/heads/main/nebalioid/alien_invasion_v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931287/; classtype:trojan-activity;sid:84794387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931285)"; flow:established,from_client; content:"GET"; http_method; content:"/adnan03146584/oil-gas-production-calculator/refs/heads/main/productioncalc.core/production-gas-calculator-oil-3.8.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931285/; classtype:trojan-activity;sid:84794385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931286)"; flow:established,from_client; content:"GET"; http_method; content:"/manuvish1/my-gcp-practitioners-playbook/head/holosymmetry/my-gcp-practitioners-playbook.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931286/; classtype:trojan-activity;sid:84794386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931284)"; flow:established,from_client; content:"GET"; http_method; content:"/valmaindecipherable453/comparemodals/refs/heads/main/natrix/software-2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931284/; classtype:trojan-activity;sid:84794384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931283)"; flow:established,from_client; content:"GET"; http_method; content:"/synsemantic-genuslamna112/kindle-weekly-letter/refs/heads/main/src/kindle-letter-weekly-v3.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931283/; classtype:trojan-activity;sid:84794383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931282)"; flow:established,from_client; content:"GET"; http_method; content:"/salvageable-mutualfund57/caveman-distillate/refs/heads/main/skills/distillate_caveman_chirographical.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931282/; classtype:trojan-activity;sid:84794382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931280)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadzerak/delivery-management-system/refs/heads/master/server/src/delivery_system_management_v2.0.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931280/; classtype:trojan-activity;sid:84794380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931281)"; flow:established,from_client; content:"GET"; http_method; content:"/sulemanyou64ab/credit-card-fraud-detection/head/plots/credit-card-fraud-detection-2.8-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931281/; classtype:trojan-activity;sid:84794381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931278)"; flow:established,from_client; content:"GET"; http_method; content:"/basalifomar/x-accounts-based-in-china-auto-mute/refs/heads/main/pictures/mute-auto-based-accounts-in-china-v2.0.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931278/; classtype:trojan-activity;sid:84794378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931279)"; flow:established,from_client; content:"GET"; http_method; content:"/debbiloverly246/google-drive-pro-unlimited/refs/heads/main/monoblepsis/drive-pro-unlimited-google-v1.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931279/; classtype:trojan-activity;sid:84794379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931277)"; flow:established,from_client; content:"GET"; http_method; content:"/komikgamblez/currency-converter/refs/heads/main/tarboard/currency-converter-v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931277/; classtype:trojan-activity;sid:84794377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931275)"; flow:established,from_client; content:"GET"; http_method; content:"/anggaw7654/kopru/main/src/renderer/features/settings/software-hemiglossal.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931275/; classtype:trojan-activity;sid:84794375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931276)"; flow:established,from_client; content:"GET"; http_method; content:"/kareal4544/arc/refs/heads/main/perforant/software_3.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931276/; classtype:trojan-activity;sid:84794376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931274)"; flow:established,from_client; content:"GET"; http_method; content:"/plater1000/founda/refs/heads/main/foundations/src/telemetry/metrics/software_2.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931274/; classtype:trojan-activity;sid:84794374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931273)"; flow:established,from_client; content:"GET"; http_method; content:"/karatepradeep/ts440s_wifi_cat_bridge/refs/heads/master/ts440s_wifi_cat_bridge/t_bridge_ca_fi_wi_2.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931273/; classtype:trojan-activity;sid:84794373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931271)"; flow:established,from_client; content:"GET"; http_method; content:"/hakimhagar0-netizen/t1bridge/main/docs/security-review/t_bridge_v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931271/; classtype:trojan-activity;sid:84794371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931272)"; flow:established,from_client; content:"GET"; http_method; content:"/avishekinvincible/bulk-emails-verifier/head/src/config/bulk-emails-verifier-2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931272/; classtype:trojan-activity;sid:84794372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931269)"; flow:established,from_client; content:"GET"; http_method; content:"/andreluissousapro/mcp-brasil/head/src/mcp_brasil/data/tce_pi/mcp_brasil_v3.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931269/; classtype:trojan-activity;sid:84794369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931270)"; flow:established,from_client; content:"GET"; http_method; content:"/moonie14/car-sales-data-eda-project/refs/heads/main/definitely/sales-data-project-car-ed-3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931270/; classtype:trojan-activity;sid:84794370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931268)"; flow:established,from_client; content:"GET"; http_method; content:"/alecktwoneedled166/claudedesign-to-swiftui/refs/heads/main/skills/claude-design-to-swiftui/references/to-claudedesign-swiftui-1.4.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931268/; classtype:trojan-activity;sid:84794368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931266)"; flow:established,from_client; content:"GET"; http_method; content:"/fitting-dame2777/hbo-max-downloader/main/disrate/1.2-alpha.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931266/; classtype:trojan-activity;sid:84794366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931267)"; flow:established,from_client; content:"GET"; http_method; content:"/mariano1603/meeting-ai-assistant/refs/heads/main/tests/assistant-meeting-ai-v1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931267/; classtype:trojan-activity;sid:84794367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931264)"; flow:established,from_client; content:"GET"; http_method; content:"/alastairchilblained570/mcp-foundry/refs/heads/main/gateway/foundry_mcp_1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931264/; classtype:trojan-activity;sid:84794364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931265)"; flow:established,from_client; content:"GET"; http_method; content:"/aaaaaaaghjkdjhgsbn/seismicquake/refs/heads/master/earthquake_ai_models/software-v2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931265/; classtype:trojan-activity;sid:84794365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931262)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoodnooristani/ai-answer-assistant/master/icons/a-answe-assistant-v3.4-alpha.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931262/; classtype:trojan-activity;sid:84794362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931263)"; flow:established,from_client; content:"GET"; http_method; content:"/alfianoct/gatekeeper/refs/heads/main/internal/auth/saml/keeper_gate_2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931263/; classtype:trojan-activity;sid:84794363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931259)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334862095487066/1556349597876494429/peak-client.jar|3f|backend=b2|7c|26|7c|ex=6ac52883|7c|26|7c|is=6ac3d703|7c|26|7c|hm=71298a163dc42e71b2a806157aabcec7726b71aac1295dad9112208d0fac8192|7c|26|7c|"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931259/; classtype:trojan-activity;sid:84794359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931260)"; flow:established,from_client; content:"GET"; http_method; content:"/bhuvi1430/roblox-macro-v3.0.0/refs/heads/main/language/roblo-macr-1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931260/; classtype:trojan-activity;sid:84794360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931261)"; flow:established,from_client; content:"GET"; http_method; content:"/tiroleansculptor548/nano-world-model/refs/heads/main/polyarthritis/nano-model-world-v1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931261/; classtype:trojan-activity;sid:84794361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931258)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrogomesr/gh-gonest/main/sundayproof/gh-gonest.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931258/; classtype:trojan-activity;sid:84794358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931256)"; flow:established,from_client; content:"GET"; http_method; content:"/mark-oori/mcpserve/master/scripts/software-3.7-alpha.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931256/; classtype:trojan-activity;sid:84794356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931257)"; flow:established,from_client; content:"GET"; http_method; content:"/maryacatholic4621/steam-account-generator/main/crybaby/steam_generator_account_v3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931257/; classtype:trojan-activity;sid:84794357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931255)"; flow:established,from_client; content:"GET"; http_method; content:"/kabus721/online-image-tools/refs/heads/main/thrax/online-image-tools-v3.9-alpha.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931255/; classtype:trojan-activity;sid:84794355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931252)"; flow:established,from_client; content:"GET"; http_method; content:"/tuscannightjar854/python-distance-unit-converter-calculator/refs/heads/main/puntist/distance_python_converter_calculator_unit_v3.6.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931252/; classtype:trojan-activity;sid:84794352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931253)"; flow:established,from_client; content:"GET"; http_method; content:"/izzicacophonic489/full-stack-genai-bootcamp-1.0/refs/heads/main/tubage/gen_full_bootcamp_stack_a_1.2-beta.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931253/; classtype:trojan-activity;sid:84794353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931254)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrocruz2202/mongobleed-scanner/main/lardacein/mongobleed_scanner_misquotation.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931254/; classtype:trojan-activity;sid:84794354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931250)"; flow:established,from_client; content:"GET"; http_method; content:"/cheezegtm/guest-post-backlinks-tool/main/loathe/guest-post-tool-backlinks-slainte.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931250/; classtype:trojan-activity;sid:84794350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931251)"; flow:established,from_client; content:"GET"; http_method; content:"/w.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"193.161.193.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931251/; classtype:trojan-activity;sid:84794351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931247)"; flow:established,from_client; content:"GET"; http_method; content:"/lockadi8/rsazure-openai-toolkit/refs/heads/main/src/rsazure_openai_toolkit/logging/rsazure_toolkit_openai_3.1.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931247/; classtype:trojan-activity;sid:84794347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931248)"; flow:established,from_client; content:"GET"; http_method; content:"/unchanging-census645/ai-paraphrase-rewrite-to-bypass/main/smilaceae/paraphrase_to_bypass_ai_rewrite_v1.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931248/; classtype:trojan-activity;sid:84794348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931249)"; flow:established,from_client; content:"GET"; http_method; content:"/malakdlo/claude-skills/head/job-search/skills_claude_v1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931249/; classtype:trojan-activity;sid:84794349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931246)"; flow:established,from_client; content:"GET"; http_method; content:"/sujaysaireddy/minimal-welcome-page/main/gaumlike/minimal-welcome-page.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931246/; classtype:trojan-activity;sid:84794346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931244)"; flow:established,from_client; content:"GET"; http_method; content:"/kennett1232/limev2-free/refs/heads/main/uncustomable/lime_free_hypophosphate.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931244/; classtype:trojan-activity;sid:84794344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931245)"; flow:established,from_client; content:"GET"; http_method; content:"/zsdani68-cell/green-turkiye/refs/heads/main/src/reducers/green_turkiye_v1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931245/; classtype:trojan-activity;sid:84794345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931241)"; flow:established,from_client; content:"GET"; http_method; content:"/themxhiguy/aegisedgeai/refs/heads/main/latchet/ai-aegis-edge-v2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931241/; classtype:trojan-activity;sid:84794341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931242)"; flow:established,from_client; content:"GET"; http_method; content:"/chaeyoung06/dns-lookup-forward-and-reverse-a-mx-txt-dmarc-ptr/main/src/config/txt-reverse-a-forward-dns-ptr-mx-lookup-dmarc-and-stockfather.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931242/; classtype:trojan-activity;sid:84794342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931243)"; flow:established,from_client; content:"GET"; http_method; content:"/yoga1938/illia-fz/main/nonforeign/illia-fz.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931243/; classtype:trojan-activity;sid:84794343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931239)"; flow:established,from_client; content:"GET"; http_method; content:"/jenellesketchy2477/quire/main/src/v1.1-beta.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931239/; classtype:trojan-activity;sid:84794339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931240)"; flow:established,from_client; content:"GET"; http_method; content:"/palkaro/dsh-local-ai/main/src/local_ai_dsh_1.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931240/; classtype:trojan-activity;sid:84794340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931238)"; flow:established,from_client; content:"GET"; http_method; content:"/viethoangn6398/git-declutter/main/cmd/git-declutter-v3.4-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931238/; classtype:trojan-activity;sid:84794338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931237)"; flow:established,from_client; content:"GET"; http_method; content:"/chaddinoflagellata703/izotope-rx-audio-setup/refs/heads/main/schistosomia/setup_i_zotope_r_audio_3.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931237/; classtype:trojan-activity;sid:84794337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931233)"; flow:established,from_client; content:"GET"; http_method; content:"/ixshiesty444-ux/cornell-marginalia/refs/heads/main/addons/marginalia_cornell_v3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931233/; classtype:trojan-activity;sid:84794333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931234)"; flow:established,from_client; content:"GET"; http_method; content:"/szczepanskistasiek/open-ai-transformation-maturity-model/refs/heads/main/unscrupulously/model-transformation-maturity-ai-open-1.8.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931234/; classtype:trojan-activity;sid:84794334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931235)"; flow:established,from_client; content:"GET"; http_method; content:"/1309298096/immersefree/main/macos/safari/immersefree.xcodeproj/2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931235/; classtype:trojan-activity;sid:84794335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931236)"; flow:established,from_client; content:"GET"; http_method; content:"/yoyo77757/flow-canvas/refs/heads/main/lolium/flow_canvas_v3.2-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931236/; classtype:trojan-activity;sid:84794336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931231)"; flow:established,from_client; content:"GET"; http_method; content:"/mamiss61eew/qiaomu-youtube-script/refs/heads/main/sizes/youtube-qiaomu-script-v2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931231/; classtype:trojan-activity;sid:84794331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931232)"; flow:established,from_client; content:"GET"; http_method; content:"/khushbu1997/ai-chat-analyzer/refs/heads/main/src/analyzer_ai_chat_v3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931232/; classtype:trojan-activity;sid:84794332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931228)"; flow:established,from_client; content:"GET"; http_method; content:"/manikant0014196/timese/refs/heads/main/notebooks/time_series_analysis/software_v1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931228/; classtype:trojan-activity;sid:84794328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931229)"; flow:established,from_client; content:"GET"; http_method; content:"/catmono/bpe-tokenizer-ts/refs/heads/main/geomance/ts_tokenizer_bpe_v2.2-beta.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931229/; classtype:trojan-activity;sid:84794329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931230)"; flow:established,from_client; content:"GET"; http_method; content:"/saied25/fix-react2shell-next/head/lib/utils/next-fix-shell-react-ostensorium.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931230/; classtype:trojan-activity;sid:84794330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931226)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/gsc-mcp/head/taxidermize/gsc-mcp-3.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931226/; classtype:trojan-activity;sid:84794326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931227)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgewgouveia/cybersecurity-conferences/refs/heads/main/conferences/germany/conferences_cybersecurity_1.2-beta.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931227/; classtype:trojan-activity;sid:84794327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931225)"; flow:established,from_client; content:"GET"; http_method; content:"/mistaken-contadino194/comfyui-minimax-h3-turbo/main/example_workflows/turbo-max-u-mini-comfy-2.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931225/; classtype:trojan-activity;sid:84794325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931224)"; flow:established,from_client; content:"GET"; http_method; content:"/laureenundecided267/embedclaw/refs/heads/main/components/embed_claw_v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931224/; classtype:trojan-activity;sid:84794324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931221)"; flow:established,from_client; content:"GET"; http_method; content:"/denominational-pianist606/claude-tasbih/refs/heads/main/docs/tasbih_claude_1.6-beta.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931221/; classtype:trojan-activity;sid:84794321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931222)"; flow:established,from_client; content:"GET"; http_method; content:"/callisaurusdraconoidesdoweling285/wheat-agronomic-analytics/refs/heads/main/src_ml/analytics-wheat-agronomic-3.9-beta.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931222/; classtype:trojan-activity;sid:84794322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931223)"; flow:established,from_client; content:"GET"; http_method; content:"/sparzinhogames-hash/awesome-scientific-ai-tools/refs/heads/main/breva/ai_scientific_tools_awesome_v3.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931223/; classtype:trojan-activity;sid:84794323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931220)"; flow:established,from_client; content:"GET"; http_method; content:"/metaoverrefined604/spojt/refs/heads/main/setup/software-v1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931220/; classtype:trojan-activity;sid:84794320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931219)"; flow:established,from_client; content:"GET"; http_method; content:"/ammar453/ai-engineering-from-scratch1/head/phases/10-llms-from-scratch/08-dpo/outputs/ai-engineering-from-scratch-v1.9.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931219/; classtype:trojan-activity;sid:84794319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931218)"; flow:established,from_client; content:"GET"; http_method; content:"/abcdethatshowyoustartthealphabet/sorting-algorithms-comparison/refs/heads/main/src/algorithms-sorting-comparison-actually.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931218/; classtype:trojan-activity;sid:84794318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931216)"; flow:established,from_client; content:"GET"; http_method; content:"/seefn1000-afk/vrchat-dlss5-cam/refs/heads/main/resources/vr-dls-cam-chat-v3.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931216/; classtype:trojan-activity;sid:84794316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931217)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/gsc-mcp/head/taxidermize/gsc-mcp-3.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931217/; classtype:trojan-activity;sid:84794317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931213)"; flow:established,from_client; content:"GET"; http_method; content:"/huseyinck/sentinelbot/refs/heads/main/sentinel/bot-sentinel-v3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931213/; classtype:trojan-activity;sid:84794313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931214)"; flow:established,from_client; content:"GET"; http_method; content:"/rutujahype141/sign-language-advance/refs/heads/main/decasualization/advance_sign_language_v2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931214/; classtype:trojan-activity;sid:84794314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931215)"; flow:established,from_client; content:"GET"; http_method; content:"/jonyposa/optitrade-ai/feature/initial-implementation/optitrade-frontend/src/assets/optitrade_ai_3.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931215/; classtype:trojan-activity;sid:84794315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931212)"; flow:established,from_client; content:"GET"; http_method; content:"/adswiftcoder/egydata/refs/heads/main/src/data/software_3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931212/; classtype:trojan-activity;sid:84794312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931210)"; flow:established,from_client; content:"GET"; http_method; content:"/sadikarahman066/indiana-aardewerk/refs/heads/main/build/aardewerk_indiana_v1.4-alpha.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931210/; classtype:trojan-activity;sid:84794310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931211)"; flow:established,from_client; content:"GET"; http_method; content:"/momen23344/winrtxamlpropsheet/refs/heads/main/src/rt-win-sheet-xaml-prop-v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931211/; classtype:trojan-activity;sid:84794311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931209)"; flow:established,from_client; content:"GET"; http_method; content:"/fabriictc/my-portfolio/refs/heads/main/src/app/components/ui/my-portfolio-3.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931209/; classtype:trojan-activity;sid:84794309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931208)"; flow:established,from_client; content:"GET"; http_method; content:"/sarthakdalvi31/nextjs-enterprise-architecture/head/charkha/nextjs-enterprise-architecture.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931208/; classtype:trojan-activity;sid:84794308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931206)"; flow:established,from_client; content:"GET"; http_method; content:"/nonnatural-rebelliousness229/electric_counterpoint/refs/heads/main/trochosphaera/electric-counterpoint-3.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931206/; classtype:trojan-activity;sid:84794306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931207)"; flow:established,from_client; content:"GET"; http_method; content:"/onehundredfifty-myelatelia678/streaminfer/refs/heads/main/tests/software_2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931207/; classtype:trojan-activity;sid:84794307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931205)"; flow:established,from_client; content:"GET"; http_method; content:"/powderpuff-magneticstoragemedium586/mac-developer-bridge/main/launchd/developer_mac_bridge_v3.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931205/; classtype:trojan-activity;sid:84794305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931203)"; flow:established,from_client; content:"GET"; http_method; content:"/annamaritenth380/dataflow-lab/refs/heads/main/frontend/src/dataflow_lab_v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931203/; classtype:trojan-activity;sid:84794303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931204)"; flow:established,from_client; content:"GET"; http_method; content:"/tixitoxay/orellius-betterstatusline/refs/heads/main/src/orellius-betterstatusline-v3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931204/; classtype:trojan-activity;sid:84794304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931202)"; flow:established,from_client; content:"GET"; http_method; content:"/candisulphurous105/sandbox-runtime/head/vendor/sandbox-runtime_v3.7-alpha.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931202/; classtype:trojan-activity;sid:84794302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931201)"; flow:established,from_client; content:"GET"; http_method; content:"/crosscountryridinggirlwonder916/claude-statusline/head/bin/statusline_claude_v1.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931201/; classtype:trojan-activity;sid:84794301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931200)"; flow:established,from_client; content:"GET"; http_method; content:"/officalkiran12/awesome-agent-skills/main/unconcurrent/agent_skills_awesome_1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931200/; classtype:trojan-activity;sid:84794300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931198)"; flow:established,from_client; content:"GET"; http_method; content:"/refaey1/cloud-misconfig-scanner/refs/heads/main/cms/scanner_cloud_misconfig_acatastasia.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931198/; classtype:trojan-activity;sid:84794298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931199)"; flow:established,from_client; content:"GET"; http_method; content:"/yasindu100/logharbor/refs/heads/main/utils/harbor_log_2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931199/; classtype:trojan-activity;sid:84794299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931197)"; flow:established,from_client; content:"GET"; http_method; content:"/musiitwa-joel/letta-code-sdk/refs/heads/main/examples/research-team/sdk_code_letta_v3.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931197/; classtype:trojan-activity;sid:84794297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931194)"; flow:established,from_client; content:"GET"; http_method; content:"/bluehecer/credit-card-fraud-detection/refs/heads/main/resolemnize/card-credit-fraud-detection-v1.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931194/; classtype:trojan-activity;sid:84794294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931195)"; flow:established,from_client; content:"GET"; http_method; content:"/lakshay803/cub3d_42/refs/heads/main/src/get_next_line/cub-v3.0-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931195/; classtype:trojan-activity;sid:84794295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931196)"; flow:established,from_client; content:"GET"; http_method; content:"/hogeheer499-commits/getnyrex-strix-halo-attribution-fix/head/chock/halo_guide_strix_3.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931196/; classtype:trojan-activity;sid:84794296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931191)"; flow:established,from_client; content:"GET"; http_method; content:"/vitalizationgenusdioon476/image-auditor/head/src/tui/image-auditor-v2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931191/; classtype:trojan-activity;sid:84794291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931192)"; flow:established,from_client; content:"GET"; http_method; content:"/allergydietcyclerickshaw867/ourtube/refs/heads/main/videos/software-v2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931192/; classtype:trojan-activity;sid:84794292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931193)"; flow:established,from_client; content:"GET"; http_method; content:"/waqardev69/replicate-bollinger-forest/refs/heads/master/data/replicate-forest-bollinger-2.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931193/; classtype:trojan-activity;sid:84794293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931189)"; flow:established,from_client; content:"GET"; http_method; content:"/tommy-hub117/claude-code-webui/refs/heads/main/assets/claude-code-webui-3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931189/; classtype:trojan-activity;sid:84794289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931190)"; flow:established,from_client; content:"GET"; http_method; content:"/concrete-crammer727/cvdadan-personalized-color-compensation/refs/heads/main/visionarily/compensation-cvdadan-personalized-color-2.3-beta.4.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931190/; classtype:trojan-activity;sid:84794290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931188)"; flow:established,from_client; content:"GET"; http_method; content:"/renan293820938/fast-f1/master/docs/_static/fast-1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931188/; classtype:trojan-activity;sid:84794288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931186)"; flow:established,from_client; content:"GET"; http_method; content:"/saran1536/comfyui-loaderutils/refs/heads/main/retrodisplacement/loader-comfy-u-utils-1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931186/; classtype:trojan-activity;sid:84794286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931187)"; flow:established,from_client; content:"GET"; http_method; content:"/kailas-design/realsense-vision-kit/main/src/realsense_vision_kit_peritreme.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931187/; classtype:trojan-activity;sid:84794287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931184)"; flow:established,from_client; content:"GET"; http_method; content:"/mohasayad/gemini-watermark-remover/refs/heads/main/docs/watermark-gemini-remover-v1.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931184/; classtype:trojan-activity;sid:84794284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931185)"; flow:established,from_client; content:"GET"; http_method; content:"/farhan-dev-cel/stillpoint/main/tests/software-v3.6-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931185/; classtype:trojan-activity;sid:84794285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931182)"; flow:established,from_client; content:"GET"; http_method; content:"/rv427447/cognitive-hijacking-in-long-context-llms/refs/heads/main/radiferous/in_cognitive_context_ll_ms_long_hijacking_1.1-beta.5.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931182/; classtype:trojan-activity;sid:84794282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931183)"; flow:established,from_client; content:"GET"; http_method; content:"/ithony77/lab_risco_quant/head/src/__pycache__/risco-quant-lab-3.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931183/; classtype:trojan-activity;sid:84794283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931181)"; flow:established,from_client; content:"GET"; http_method; content:"/ayoubhjs/c-contact-agenda/refs/heads/main/casel/contact-agenda-v2.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931181/; classtype:trojan-activity;sid:84794281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931180)"; flow:established,from_client; content:"GET"; http_method; content:"/iikcoraxx-debug/-kranti-sip-pcap-analyzer/refs/heads/main/wiyot/sip-pcap-analyzer-kranti-v1.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931180/; classtype:trojan-activity;sid:84794280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931179)"; flow:established,from_client; content:"GET"; http_method; content:"/ikta87/phasmophobia-hack-2026-ghost-investigation-toolkit/refs/heads/main/upmove/hack_toolkit_investigation_phasmophobia_ghost_1.9-alpha.2.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931179/; classtype:trojan-activity;sid:84794279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931177)"; flow:established,from_client; content:"GET"; http_method; content:"/rousing-lordtodd483/codemint/refs/heads/main/src/utils/mint-code-3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931177/; classtype:trojan-activity;sid:84794277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931178)"; flow:established,from_client; content:"GET"; http_method; content:"/franklinkoilpillai/fintrust_cobol/head/programs/fintrust_cobol_2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931178/; classtype:trojan-activity;sid:84794278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931176)"; flow:established,from_client; content:"GET"; http_method; content:"/canelas458/tenvision/refs/heads/master/images/vision_ten_1.7-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931176/; classtype:trojan-activity;sid:84794276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931174)"; flow:established,from_client; content:"GET"; http_method; content:"/sydneyseparated852/fb-notes-extended/refs/heads/main/src/popup/extended-notes-f-v2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931174/; classtype:trojan-activity;sid:84794274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931175)"; flow:established,from_client; content:"GET"; http_method; content:"/shameirnk/lightspeedrelaytechnology_info_website/refs/heads/main/src/pages/admin/technology-relay-speed-info-website-light-v2.7.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931175/; classtype:trojan-activity;sid:84794275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931172)"; flow:established,from_client; content:"GET"; http_method; content:"/sangunius/skipthemid/refs/heads/main/website/styles/software_v1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931172/; classtype:trojan-activity;sid:84794272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931173)"; flow:established,from_client; content:"GET"; http_method; content:"/nwfrequencydistribution747/vsqz/refs/heads/main/contrib/software-3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931173/; classtype:trojan-activity;sid:84794273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931171)"; flow:established,from_client; content:"GET"; http_method; content:"/rick2312/mcserver-termux/head/achroglobin/mcserver-termux.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931171/; classtype:trojan-activity;sid:84794271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931168)"; flow:established,from_client; content:"GET"; http_method; content:"/abograbawy/sentiment-ai-suite/refs/heads/main/chromoxylograph/sentiment_ai_suite_1.6-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931168/; classtype:trojan-activity;sid:84794268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931169)"; flow:established,from_client; content:"GET"; http_method; content:"/bbsbs7617-png/claude-usage-report/refs/heads/main/historicocabbalistical/report-claude-usage-1.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931169/; classtype:trojan-activity;sid:84794269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931170)"; flow:established,from_client; content:"GET"; http_method; content:"/stunning-navelorange917/agent-pathway/refs/heads/main/docs/claude_md/agent-pathway-cholum.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931170/; classtype:trojan-activity;sid:84794270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931167)"; flow:established,from_client; content:"GET"; http_method; content:"/sammy-d02/real-time-chat-application/refs/heads/main/frontend/src/time-chat-application-real-strabismally.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931167/; classtype:trojan-activity;sid:84794267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931164)"; flow:established,from_client; content:"GET"; http_method; content:"/danimachadoejp/ox_target/refs/heads/main/web/dist/3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931164/; classtype:trojan-activity;sid:84794264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931165)"; flow:established,from_client; content:"GET"; http_method; content:"/darksoul047/dao-governance-platform/refs/heads/main/speechfulness/governance_dao_platform_v1.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931165/; classtype:trojan-activity;sid:84794265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931166)"; flow:established,from_client; content:"GET"; http_method; content:"/bluecreeper159/sovereign_engine_core/main/src-tauri/icons/sovereign_engine_core_minnow.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931166/; classtype:trojan-activity;sid:84794266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931163)"; flow:established,from_client; content:"GET"; http_method; content:"/rahalfiftyfifty868/modern-loki/main/tests/modern-loki-undulatingly.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931163/; classtype:trojan-activity;sid:84794263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931161)"; flow:established,from_client; content:"GET"; http_method; content:"/eruroraito/rustcript/refs/heads/main/examples/software_v2.8-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931161/; classtype:trojan-activity;sid:84794261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931162)"; flow:established,from_client; content:"GET"; http_method; content:"/scfeads/cupel/refs/heads/main/doc/software_v1.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931162/; classtype:trojan-activity;sid:84794262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931157)"; flow:established,from_client; content:"GET"; http_method; content:"/360cuenta/glass-opp-pro2/refs/heads/main/quarrelsomeness/pro-opp-glass-1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931157/; classtype:trojan-activity;sid:84794257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931158)"; flow:established,from_client; content:"GET"; http_method; content:"/interchangecarew1812/ram-cleaner-pro/refs/heads/main/petrarchize/cleaner_ram_pro_3.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931158/; classtype:trojan-activity;sid:84794258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931159)"; flow:established,from_client; content:"GET"; http_method; content:"/huymini/pencall/refs/heads/main/src/software-2.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931159/; classtype:trojan-activity;sid:84794259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931160)"; flow:established,from_client; content:"GET"; http_method; content:"/rawatkartik1411/linux-priv-esc-audit/refs/heads/main/uncopyrighted/linux_esc_priv_audit_3.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931160/; classtype:trojan-activity;sid:84794260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931156)"; flow:established,from_client; content:"GET"; http_method; content:"/frankylancastrian312/ai-video-subtitle/main/core/asr_backend/ai_video_subtitle_v3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931156/; classtype:trojan-activity;sid:84794256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931155)"; flow:established,from_client; content:"GET"; http_method; content:"/minado7a/yfs-api/main/tests/yfs-api-curliewurly.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931155/; classtype:trojan-activity;sid:84794255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931154)"; flow:established,from_client; content:"GET"; http_method; content:"/dkmevawala/ai-engineering-from-scratch2/head/phases/10-llms-from-scratch/08-dpo/outputs/ai-engineering-from-scratch-v1.9.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931154/; classtype:trojan-activity;sid:84794254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931153)"; flow:established,from_client; content:"GET"; http_method; content:"/suvitha1962-del/hydro0x01/refs/heads/main/frontend/src/features/devices/x-hydro-2.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931153/; classtype:trojan-activity;sid:84794253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931152)"; flow:established,from_client; content:"GET"; http_method; content:"/olegoleg11/aqworker/master/src/aqworker/cli/aqworker-v3.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931152/; classtype:trojan-activity;sid:84794252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931150)"; flow:established,from_client; content:"GET"; http_method; content:"/rohan5commit/bug-hunter/head/skills/commit-security-scan/hunter-bug-v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931150/; classtype:trojan-activity;sid:84794250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931151)"; flow:established,from_client; content:"GET"; http_method; content:"/doralynnindignant843/agent-browser-runtime/refs/heads/main/extractors/agent_runtime_browser_cotylar.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931151/; classtype:trojan-activity;sid:84794251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931146)"; flow:established,from_client; content:"GET"; http_method; content:"/mykewkymap/news-event-impact-detector/head/utils/event_news_impact_detector_v2.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931146/; classtype:trojan-activity;sid:84794246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931147)"; flow:established,from_client; content:"GET"; http_method; content:"/carvedinstone-heartbreaker804/telegram-ai-monitor/refs/heads/main/frontend/src/api/telegram-ai-monitor-3.3-alpha.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931147/; classtype:trojan-activity;sid:84794247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931148)"; flow:established,from_client; content:"GET"; http_method; content:"/anisfakename/dotfiles-coach/refs/heads/main/src/utils/coach-dotfiles-1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931148/; classtype:trojan-activity;sid:84794248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931149)"; flow:established,from_client; content:"GET"; http_method; content:"/sheelaghtwotoe836/luminasider/refs/heads/main/public/icons/sider_lumina_progression.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931149/; classtype:trojan-activity;sid:84794249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931145)"; flow:established,from_client; content:"GET"; http_method; content:"/lateripening-ritual19/sisyphus-academica-902/main/isomery/academica_sisyphus_2.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931145/; classtype:trojan-activity;sid:84794245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931144)"; flow:established,from_client; content:"GET"; http_method; content:"/iamlucass/poc-network-isolation/head/node/server/static/poc-network-isolation-2.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931144/; classtype:trojan-activity;sid:84794244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931142)"; flow:established,from_client; content:"GET"; http_method; content:"/codiget/agent-skill-git-checkpoint/head/skills/git-checkpoint/agent_skill_checkpoint_git_v1.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931142/; classtype:trojan-activity;sid:84794242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931143)"; flow:established,from_client; content:"GET"; http_method; content:"/uzaird47/java_backend/head/homeoid/java_backend.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931143/; classtype:trojan-activity;sid:84794243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931140)"; flow:established,from_client; content:"GET"; http_method; content:"/croaky-giantess1153/gta6-cyberleek/refs/heads/main/brood/v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931140/; classtype:trojan-activity;sid:84794240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931141)"; flow:established,from_client; content:"GET"; http_method; content:"/sagiler/projetoreconhecimentofacial/refs/heads/master/exemplos_iot/reconhecimento-facial-projeto-2.7-beta.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931141/; classtype:trojan-activity;sid:84794241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931138)"; flow:established,from_client; content:"GET"; http_method; content:"/tawhidhere/onerec-think/refs/heads/main/train/scripts/think_rec_one_intentional.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931138/; classtype:trojan-activity;sid:84794238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931139)"; flow:established,from_client; content:"GET"; http_method; content:"/tahir77ba/dear-nikki/head/.github/workflows/dear-nikki_v3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931139/; classtype:trojan-activity;sid:84794239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931137)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/hello_world/refs/heads/main/.github/workflows/world-hell-2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931137/; classtype:trojan-activity;sid:84794237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931136)"; flow:established,from_client; content:"GET"; http_method; content:"/mzwandile16/multi-agent-todo/refs/heads/master/web/agent-todo-multi-v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931136/; classtype:trojan-activity;sid:84794236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931134)"; flow:established,from_client; content:"GET"; http_method; content:"/rizzman270/freechat/refs/heads/main/assets/chat-free-v2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931134/; classtype:trojan-activity;sid:84794234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931135)"; flow:established,from_client; content:"GET"; http_method; content:"/prexpogi/particle-physics-handtracking/head/preindebtedness/physics-handtracking-particle-3.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931135/; classtype:trojan-activity;sid:84794235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931132)"; flow:established,from_client; content:"GET"; http_method; content:"/shahyadtest/temp_controlmod_ros_integration/master/public/rps/integration_ro_control_temp_mod_2.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931132/; classtype:trojan-activity;sid:84794232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931133)"; flow:established,from_client; content:"GET"; http_method; content:"/bicyclethreepence804/engine/refs/heads/main/packages/cli/src/software_hugely.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931133/; classtype:trojan-activity;sid:84794233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931131)"; flow:established,from_client; content:"GET"; http_method; content:"/rith-wik/attribute-forecasting-system/refs/heads/main/frontend/attribute_forecasting_system_v3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931131/; classtype:trojan-activity;sid:84794231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931130)"; flow:established,from_client; content:"GET"; http_method; content:"/liljaona/defcon-webcam/refs/heads/main/lib/webcam_defcon_1.5-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931130/; classtype:trojan-activity;sid:84794230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931129)"; flow:established,from_client; content:"GET"; http_method; content:"/komalverma183/delta-calculator/refs/heads/main/src/calculations/delta_calculator_v2.9-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931129/; classtype:trojan-activity;sid:84794229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931128)"; flow:established,from_client; content:"GET"; http_method; content:"/parafson/arcmate/refs/heads/master/screenshots/arc_mate_1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931128/; classtype:trojan-activity;sid:84794228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931126)"; flow:established,from_client; content:"GET"; http_method; content:"/sharkx2/acgn-works-tracker/refs/heads/main/src/test/java/works_tracker_acg_1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931126/; classtype:trojan-activity;sid:84794226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931127)"; flow:established,from_client; content:"GET"; http_method; content:"/bobbysunday44-maker/live-to-100-skills/head/live-to-100/agents/live_to_skills_v1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931127/; classtype:trojan-activity;sid:84794227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931125)"; flow:established,from_client; content:"GET"; http_method; content:"/dedenismanto655-cell/biodiversity-battle-game/head/images/battle-game-biodiversity-v1.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931125/; classtype:trojan-activity;sid:84794225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931124)"; flow:established,from_client; content:"GET"; http_method; content:"/marionviceregal8571/solana-token-sniper-anti-rug/main/idiocratical/sniper_anti_solana_rug_token_1.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931124/; classtype:trojan-activity;sid:84794224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931121)"; flow:established,from_client; content:"GET"; http_method; content:"/thewilfry/camera-hack/head/arduino/serial_bridge/camera-hack-v2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931121/; classtype:trojan-activity;sid:84794221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931122)"; flow:established,from_client; content:"GET"; http_method; content:"/gaminghousenursingaide761/clawdeck/refs/heads/main/tests/claw-deck-moulrush.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931122/; classtype:trojan-activity;sid:84794222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931123)"; flow:established,from_client; content:"GET"; http_method; content:"/xunchahaha/1111/head/python/mi_nobl_root_v2.6.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931123/; classtype:trojan-activity;sid:84794223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931118)"; flow:established,from_client; content:"GET"; http_method; content:"/kouseia/agi_her_llm/refs/heads/main/configs/order5_configs/rte/llm-ag-he-1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931118/; classtype:trojan-activity;sid:84794218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931119)"; flow:established,from_client; content:"GET"; http_method; content:"/starbusop/agent-accountability-receipt/refs/heads/main/agent_harness/configs/agent_receipt_accountability_v1.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931119/; classtype:trojan-activity;sid:84794219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931120)"; flow:established,from_client; content:"GET"; http_method; content:"/mealine/kaloudasdev-links/refs/heads/main/assets/links_kaloudasdev_2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931120/; classtype:trojan-activity;sid:84794220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931117)"; flow:established,from_client; content:"GET"; http_method; content:"/gathogog/financetracker/refs/heads/main/src/app/dashboard/chat/finance_tracker_3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931117/; classtype:trojan-activity;sid:84794217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931116)"; flow:established,from_client; content:"GET"; http_method; content:"/manosdan/ai-werewolf-live/refs/heads/main/public/ai_live_werewolf_v2.0-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931116/; classtype:trojan-activity;sid:84794216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931113)"; flow:established,from_client; content:"GET"; http_method; content:"/marine-turtlesoup9398/sentrix/main/reports/software_v3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931113/; classtype:trojan-activity;sid:84794213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931114)"; flow:established,from_client; content:"GET"; http_method; content:"/jire8519/github-copilot/refs/heads/main/sarus/github_copilot_v3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931114/; classtype:trojan-activity;sid:84794214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931115)"; flow:established,from_client; content:"GET"; http_method; content:"/mertdemirtug14-dotcom/creation-of-adam/refs/heads/main/unimperative/1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931115/; classtype:trojan-activity;sid:84794215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931112)"; flow:established,from_client; content:"GET"; http_method; content:"/pandemic-xanthicacid21/mcp-time-travel/refs/heads/main/src/travel-mcp-time-v2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931112/; classtype:trojan-activity;sid:84794212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931111)"; flow:established,from_client; content:"GET"; http_method; content:"/kylepeart21/get-icmp9-node/refs/heads/main/rhizopodan/icmp_node_get_2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931111/; classtype:trojan-activity;sid:84794211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931110)"; flow:established,from_client; content:"GET"; http_method; content:"/divish9123/rigeo/main/+utils/software-scrap.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931110/; classtype:trojan-activity;sid:84794210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931108)"; flow:established,from_client; content:"GET"; http_method; content:"/manishvedwal2609/mips-atan2/refs/heads/main/cytoderm/mips-atan-v2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931108/; classtype:trojan-activity;sid:84794208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931109)"; flow:established,from_client; content:"GET"; http_method; content:"/christianoblinded331/yt-search-helper/refs/heads/main/src/yt_search_helper_anagalactic.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931109/; classtype:trojan-activity;sid:84794209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931107)"; flow:established,from_client; content:"GET"; http_method; content:"/ziyad248/jtml/refs/heads/main/src/software_3.4-alpha.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931107/; classtype:trojan-activity;sid:84794207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931105)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulhaziq94/form4923-h/refs/heads/main/html/forms/form_h_3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931105/; classtype:trojan-activity;sid:84794205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931106)"; flow:established,from_client; content:"GET"; http_method; content:"/lvanphong/omni-synapse-v2/refs/heads/main/release_kit/v_omni_synapse_1.5-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931106/; classtype:trojan-activity;sid:84794206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931104)"; flow:established,from_client; content:"GET"; http_method; content:"/vivekanandan22/reproducible-photorealistic-nano-banana-pro-json-prompts/refs/heads/main/kamba/pro-jso-photorealistic-nano-prompts-banana-reproducible-1.0.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931104/; classtype:trojan-activity;sid:84794204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931101)"; flow:established,from_client; content:"GET"; http_method; content:"/dubai1521/file-extension-batch-changer/main/kinetomeric/2.2-beta.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931101/; classtype:trojan-activity;sid:84794201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931102)"; flow:established,from_client; content:"GET"; http_method; content:"/summerone-1/claude-statistical-analysis-skill/head/references/statistical_analysis_claude_skill_1.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931102/; classtype:trojan-activity;sid:84794202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931103)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-magdy-1/shop.co-back-end/refs/heads/main/src/api/category/content-types/end-back-sho-c-v1.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931103/; classtype:trojan-activity;sid:84794203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931099)"; flow:established,from_client; content:"GET"; http_method; content:"/chkaradhar700/scientific-calculator/head/docs/scientific-calculator-v1.3-alpha.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931099/; classtype:trojan-activity;sid:84794199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931100)"; flow:established,from_client; content:"GET"; http_method; content:"/januar3195/privacy-image-guard-hub/refs/heads/main/picker/privacy_image_hub_guard_v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931100/; classtype:trojan-activity;sid:84794200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931097)"; flow:established,from_client; content:"GET"; http_method; content:"/carmelacanela/opengem/refs/heads/main/conductivity/gem-open-v1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931097/; classtype:trojan-activity;sid:84794197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931098)"; flow:established,from_client; content:"GET"; http_method; content:"/killred246/argparse/refs/heads/main/demo/arg_parse_v1.4-alpha.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931098/; classtype:trojan-activity;sid:84794198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931095)"; flow:established,from_client; content:"GET"; http_method; content:"/shark7418/ghostfolio-desktop-self-hosted-dashboard/main/synonymist/dashboard_ghostfolio_desktop_hosted_self_v1.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931095/; classtype:trojan-activity;sid:84794195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931096)"; flow:established,from_client; content:"GET"; http_method; content:"/faiqkhan139/power_of_statistics/refs/heads/main/psychostatically/of-statistics-power-swingdingle.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931096/; classtype:trojan-activity;sid:84794196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931093)"; flow:established,from_client; content:"GET"; http_method; content:"/prompop/tele.gram-tools/refs/heads/main/erudit/tele-gram-tools-3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931093/; classtype:trojan-activity;sid:84794193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931094)"; flow:established,from_client; content:"GET"; http_method; content:"/chinom112/hyperbot-hyperliquid-trading-bot-2026/refs/heads/main/shampooer/2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931094/; classtype:trojan-activity;sid:84794194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931092)"; flow:established,from_client; content:"GET"; http_method; content:"/konraddesensitising780/sutatikku/refs/heads/main/tests/software_v2.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931092/; classtype:trojan-activity;sid:84794192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931090)"; flow:established,from_client; content:"GET"; http_method; content:"/arkanjaff/math-base-special-acothf/head/src/acothf_special_math_base_1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931090/; classtype:trojan-activity;sid:84794190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931091)"; flow:established,from_client; content:"GET"; http_method; content:"/mobdudeedits/django-crontask/head/crontask/management/commands/django-crontask-v3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931091/; classtype:trojan-activity;sid:84794191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931089)"; flow:established,from_client; content:"GET"; http_method; content:"/arielesquenai1234/crack-sql-interview-50/main/diatomous/crack-sql-interview-50.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931089/; classtype:trojan-activity;sid:84794189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931086)"; flow:established,from_client; content:"GET"; http_method; content:"/inflected-blast748/image-compressor-batch/refs/heads/main/sulfurage/v1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931086/; classtype:trojan-activity;sid:84794186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931087)"; flow:established,from_client; content:"GET"; http_method; content:"/jannasweetened9049/swizguard/refs/heads/main/docs/images/swiz-guard-1.1-alpha.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931087/; classtype:trojan-activity;sid:84794187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931088)"; flow:established,from_client; content:"GET"; http_method; content:"/bellatd/sql-flappybird/refs/heads/main/init/sq_flappy_bird_2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931088/; classtype:trojan-activity;sid:84794188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931084)"; flow:established,from_client; content:"GET"; http_method; content:"/srvishal/sliver-tor-bridge/refs/heads/main/sliver_tor_bridge/bridge-sliver-tor-v3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931084/; classtype:trojan-activity;sid:84794184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931085)"; flow:established,from_client; content:"GET"; http_method; content:"/ikraamghaffari/swpp202601/refs/heads/main/assignments/swpp_3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931085/; classtype:trojan-activity;sid:84794185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931082)"; flow:established,from_client; content:"GET"; http_method; content:"/imbflool/cc-plugin-eval/head/src/stages/2-generation/cc_eval_plugin_3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931082/; classtype:trojan-activity;sid:84794182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931083)"; flow:established,from_client; content:"GET"; http_method; content:"/tharindu778/thubo/refs/heads/main/bench/src/bin/software_v3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931083/; classtype:trojan-activity;sid:84794183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931081)"; flow:established,from_client; content:"GET"; http_method; content:"/digitalinfluencer/ecommerce-backend-api/refs/heads/main/orders/backend_api_ecommerce_3.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931081/; classtype:trojan-activity;sid:84794181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931079)"; flow:established,from_client; content:"GET"; http_method; content:"/specconflict88/tollbooth/refs/heads/main/tollbooth/extras/software-2.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931079/; classtype:trojan-activity;sid:84794179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931080)"; flow:established,from_client; content:"GET"; http_method; content:"/bv2518/text-to-speech/refs/heads/main/unharassed/speech-text-to-3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931080/; classtype:trojan-activity;sid:84794180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931077)"; flow:established,from_client; content:"GET"; http_method; content:"/eesh20/science-flake/refs/heads/main/snooperscope/flake_science_1.6-alpha.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931077/; classtype:trojan-activity;sid:84794177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931078)"; flow:established,from_client; content:"GET"; http_method; content:"/yusufjava945/ansible-collection-hardening/refs/heads/master/roles/os_hardening/templates/hardening_collection_ansible_v3.8.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931078/; classtype:trojan-activity;sid:84794178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931075)"; flow:established,from_client; content:"GET"; http_method; content:"/krisue/dsc-public/refs/heads/main/media/ds-public-3.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931075/; classtype:trojan-activity;sid:84794175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931076)"; flow:established,from_client; content:"GET"; http_method; content:"/tobeyiodinated117/devguard/refs/heads/main/docs/images/guard-dev-decadist.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931076/; classtype:trojan-activity;sid:84794176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931074)"; flow:established,from_client; content:"GET"; http_method; content:"/gerberayale521/pwnkit/refs/heads/main/zan/software_v2.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931074/; classtype:trojan-activity;sid:84794174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931072)"; flow:established,from_client; content:"GET"; http_method; content:"/eterame/-spawnplugin/refs/heads/main/spawnplugin1/build/classes/java/main/mc/spacecat7773/spawnplugin1/plugin_spawn_v3.4.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931072/; classtype:trojan-activity;sid:84794172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931073)"; flow:established,from_client; content:"GET"; http_method; content:"/muskan9567/x-media/main/src/app/api/tweets/media-x-v1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931073/; classtype:trojan-activity;sid:84794173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931070)"; flow:established,from_client; content:"GET"; http_method; content:"/ccvia4072/project-knowledge-base/refs/heads/main/assets/knowledge-base/decisions/v2.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931070/; classtype:trojan-activity;sid:84794170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931071)"; flow:established,from_client; content:"GET"; http_method; content:"/fein47/imcache/refs/heads/main/_benchmark/software_v2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931071/; classtype:trojan-activity;sid:84794171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931068)"; flow:established,from_client; content:"GET"; http_method; content:"/kmalgaber/tasker/refs/heads/main/app/models/software_v2.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931068/; classtype:trojan-activity;sid:84794168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931069)"; flow:established,from_client; content:"GET"; http_method; content:"/protective-antineutron43/open-authkit-studio/main/tests/2.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931069/; classtype:trojan-activity;sid:84794169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931066)"; flow:established,from_client; content:"GET"; http_method; content:"/mortimerscattershot606/puf-for-secure-hardware-authentication-fpga-asic-implementation-/refs/heads/main/16bit/16bit.srcs/pu_secure_asi_hardware_fpg_authentication_for_implementation_3.6.zip"; http_uri; depth:190; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931066/; classtype:trojan-activity;sid:84794166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931067)"; flow:established,from_client; content:"GET"; http_method; content:"/codexistente/ocpi-python/refs/heads/main/ocpi/modules/locations/v_2_3_0/api/python_ocpi_v3.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931067/; classtype:trojan-activity;sid:84794167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931064)"; flow:established,from_client; content:"GET"; http_method; content:"/sc2024sc/secrets-backup-to-bitwarden/refs/heads/main/counterambush/secrets_backup_to_bitwarden_v2.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931064/; classtype:trojan-activity;sid:84794164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931065)"; flow:established,from_client; content:"GET"; http_method; content:"/christophegremillon54/2b2tatlas-public-api/refs/heads/main/examples/atlas-stack/2b2tatlas.client/wwwroot/1.6.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931065/; classtype:trojan-activity;sid:84794165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931063)"; flow:established,from_client; content:"GET"; http_method; content:"/hooxzz/ios-payment-processing-framework/master/examples/o-processing-payment-i-framework-1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931063/; classtype:trojan-activity;sid:84794163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931060)"; flow:established,from_client; content:"GET"; http_method; content:"/kiki0502-ux/safegithubota/refs/heads/main/nonfreeze/github_safe_ota_v3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931060/; classtype:trojan-activity;sid:84794160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931061)"; flow:established,from_client; content:"GET"; http_method; content:"/juniorvidigal25/nanoman/refs/heads/main/src/man_nano_v2.6-beta.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931061/; classtype:trojan-activity;sid:84794161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931062)"; flow:established,from_client; content:"GET"; http_method; content:"/fourply-leporid594/ticket-management-system/head/scripts/system_ticket_management_1.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931062/; classtype:trojan-activity;sid:84794162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931059)"; flow:established,from_client; content:"GET"; http_method; content:"/kasiryemahad/chronopulse/main/septuagenary/chronopulse.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931059/; classtype:trojan-activity;sid:84794159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931058)"; flow:established,from_client; content:"GET"; http_method; content:"/farmercrypto21/optomitron/main/src/components/software-buckboard.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931058/; classtype:trojan-activity;sid:84794158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931055)"; flow:established,from_client; content:"GET"; http_method; content:"/morning2059/robotics-technology-genealogy/refs/heads/main/scripts/technology-robotics-genealogy-affronted.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931055/; classtype:trojan-activity;sid:84794155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931056)"; flow:established,from_client; content:"GET"; http_method; content:"/mansingh25/qave/refs/heads/main/backend/src/qave_backend/ir/software_1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931056/; classtype:trojan-activity;sid:84794156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931057)"; flow:established,from_client; content:"GET"; http_method; content:"/myothantzin-programming/apitally-py-serverless/refs/heads/main/apitally_serverless/common/apitally-serverless-py-3.6.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931057/; classtype:trojan-activity;sid:84794157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931053)"; flow:established,from_client; content:"GET"; http_method; content:"/shibu503/dissertation-3l-sdvrp/refs/heads/main/experiments_output_backup_20251202_050744/xml100_1111_01_merged_with_boxes_norm_seed2010/dissertation-3l-sdvrp-1.5.zip"; http_uri; depth:166; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931053/; classtype:trojan-activity;sid:84794153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931054)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamfvp/crime-analysis-caba-spatial-ml/main/scripts/caba-crime-spatial-ml-analysis-excrescence.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931054/; classtype:trojan-activity;sid:84794154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931051)"; flow:established,from_client; content:"GET"; http_method; content:"/rushy-campanulales3205/actionimages/refs/heads/main/asset/action_images_v3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931051/; classtype:trojan-activity;sid:84794151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931052)"; flow:established,from_client; content:"GET"; http_method; content:"/itskennethplayz/lunarbot-smart-india-hackathon/refs/heads/main/recco/india-hackathon-smart-lunarbot-1.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931052/; classtype:trojan-activity;sid:84794152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931048)"; flow:established,from_client; content:"GET"; http_method; content:"/sakhikhichi/j_upload-shell/refs/heads/main/juniata/shell-uploa-v2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931048/; classtype:trojan-activity;sid:84794148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931049)"; flow:established,from_client; content:"GET"; http_method; content:"/candyscented-labourpains516/talking-rabbitt-crm-analytics/refs/heads/main/talking-rabbitt-ai-analytics-mvp-main/rabbitt_analytics_crm_talking_skirtingly.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931049/; classtype:trojan-activity;sid:84794149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931050)"; flow:established,from_client; content:"GET"; http_method; content:"/invasivecape/ghost-protocol/head/contracts/src/core/ghost-protocol-3.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931050/; classtype:trojan-activity;sid:84794150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931046)"; flow:established,from_client; content:"GET"; http_method; content:"/bamnea1846/streamlens/refs/heads/main/docker/seed/3.9-alpha.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931046/; classtype:trojan-activity;sid:84794146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931047)"; flow:established,from_client; content:"GET"; http_method; content:"/saddled-panicattack529/idea-evaluation-pipeline/refs/heads/main/uncurbedly/idea-evaluation-pipeline-1.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931047/; classtype:trojan-activity;sid:84794147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931043)"; flow:established,from_client; content:"GET"; http_method; content:"/harishjangir9610/maxtui/refs/heads/main/docs/software-v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931043/; classtype:trojan-activity;sid:84794143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931044)"; flow:established,from_client; content:"GET"; http_method; content:"/chaudhryy/create-eth-app/develop/templates/create_app_eth_fascinatress.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931044/; classtype:trojan-activity;sid:84794144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931045)"; flow:established,from_client; content:"GET"; http_method; content:"/gilangcowokull/sniftern.ai/refs/heads/main/images/snif-tern-ai-v3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931045/; classtype:trojan-activity;sid:84794145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931042)"; flow:established,from_client; content:"GET"; http_method; content:"/revijipogi/amanansdiahnid-9/main/whiskerage/amanansdiahnid-9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931042/; classtype:trojan-activity;sid:84794142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931039)"; flow:established,from_client; content:"GET"; http_method; content:"/theflavvz/ai-day-trade-analytics-groq-aws/refs/heads/main/images/groq-analytics-ai-aws-day-trade-v2.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931039/; classtype:trojan-activity;sid:84794139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931040)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushmaheshwari1/how-to-scrape-google-images-with-python/refs/heads/main/geomantical/google_images_with_how_python_scrape_to_3.1-alpha.1.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931040/; classtype:trojan-activity;sid:84794140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931041)"; flow:established,from_client; content:"GET"; http_method; content:"/thecoolman87/intellij-ai-prompt-generator/refs/heads/main/src/main/java/de/keksuccino/generator-prompt-a-intelli-3.6.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931041/; classtype:trojan-activity;sid:84794141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931038)"; flow:established,from_client; content:"GET"; http_method; content:"/madazbrn/my-excalidraw/refs/heads/main/src/assets/my_excalidraw_1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931038/; classtype:trojan-activity;sid:84794138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931037)"; flow:established,from_client; content:"GET"; http_method; content:"/jajaaa2/swift-testing-agent-skill/refs/heads/main/swift-testing-expert/testing_agent_skill_swift_decare.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931037/; classtype:trojan-activity;sid:84794137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931036)"; flow:established,from_client; content:"GET"; http_method; content:"/silkseo2025/dualsense-studio/main/.github/v3.2-alpha.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931036/; classtype:trojan-activity;sid:84794136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931035)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel-cf/modular-core/head/glooming/modular-core.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931035/; classtype:trojan-activity;sid:84794135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931033)"; flow:established,from_client; content:"GET"; http_method; content:"/roastergenuspulicaria930/sovereign-stack/refs/heads/main/skills/sovereign/sovereign_stack_inanely.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931033/; classtype:trojan-activity;sid:84794133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931034)"; flow:established,from_client; content:"GET"; http_method; content:"/raleighbrunchcoat572/tabnest/refs/heads/main/docs/3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931034/; classtype:trojan-activity;sid:84794134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931032)"; flow:established,from_client; content:"GET"; http_method; content:"/offsite-squaredeal736/comfyui-allinone-minimaxh3/main/web/lin-comfy-al-on-minimax-u-v1.5-beta.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931032/; classtype:trojan-activity;sid:84794132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931029)"; flow:established,from_client; content:"GET"; http_method; content:"/hasansahara/permission_studio/head/permission_studio/config/studio-permission-2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931029/; classtype:trojan-activity;sid:84794129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931030)"; flow:established,from_client; content:"GET"; http_method; content:"/doself/google-rkp-sw/head/scotographic/sw_rkp_google_3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931030/; classtype:trojan-activity;sid:84794130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931031)"; flow:established,from_client; content:"GET"; http_method; content:"/drhir2460/agentskills-mcp/refs/heads/main/src/github_skills_mcp/mcp_agentskills_crutched.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931031/; classtype:trojan-activity;sid:84794131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931027)"; flow:established,from_client; content:"GET"; http_method; content:"/nicoconic248/mcpsafari/refs/heads/main/mcpsafari/mcpsafari/assets.xcassets/accentcolor.colorset/mcp-safari-v3.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931027/; classtype:trojan-activity;sid:84794127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931028)"; flow:established,from_client; content:"GET"; http_method; content:"/dan775/free-retail-dashboard-template/refs/heads/main/components/dashboard/free-dashboard-template-retail-v3.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931028/; classtype:trojan-activity;sid:84794128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931026)"; flow:established,from_client; content:"GET"; http_method; content:"/ktochechen/liquid-s4/head/configs/model/nonaka/liquid-s4_2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931026/; classtype:trojan-activity;sid:84794126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931025)"; flow:established,from_client; content:"GET"; http_method; content:"/seema807/oilgas-nanobot-swarm/refs/heads/main/nanobot/static/nanobot_oilgas_swarm_3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931025/; classtype:trojan-activity;sid:84794125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931023)"; flow:established,from_client; content:"GET"; http_method; content:"/kunallll-glitch/lotspeed/refs/heads/zeta-tcp/tapac/software-v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931023/; classtype:trojan-activity;sid:84794123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931024)"; flow:established,from_client; content:"GET"; http_method; content:"/threefigure-achromia682/ai-memory/main/dehumidification/memory_ai_bijugate.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931024/; classtype:trojan-activity;sid:84794124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931022)"; flow:established,from_client; content:"GET"; http_method; content:"/three2hot/cyber-agent/main/.claude/agents/agent_cyber_nonvolant.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931022/; classtype:trojan-activity;sid:84794122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931019)"; flow:established,from_client; content:"GET"; http_method; content:"/nexxx-q/mavryk-wallet/refs/heads/main/walloon/wallet_mavryk_v3.5-alpha.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931019/; classtype:trojan-activity;sid:84794119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931020)"; flow:established,from_client; content:"GET"; http_method; content:"/naolembro/matrixterminal/refs/heads/main/phenospermy/matrix_terminal_3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931020/; classtype:trojan-activity;sid:84794120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931021)"; flow:established,from_client; content:"GET"; http_method; content:"/bklamheem/chrome-devtools-mcp/refs/heads/main/api/mcp-devtools-chrome-2.3-alpha.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931021/; classtype:trojan-activity;sid:84794121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931018)"; flow:established,from_client; content:"GET"; http_method; content:"/flatknotbubovirginianus435/adopt-me-script-2026---auto-farm---pets---free-roblox-hack-gui/main/riva/auto_hack_gui_script_free_adopt_roblox_me_farm_pets_1.2-beta.1.zip"; http_uri; depth:167; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931018/; classtype:trojan-activity;sid:84794118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931015)"; flow:established,from_client; content:"GET"; http_method; content:"/muyengwa8391/pi-magic-docs/refs/heads/main/susu/pi-docs-magic-v3.9-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931015/; classtype:trojan-activity;sid:84794115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931016)"; flow:established,from_client; content:"GET"; http_method; content:"/kayanolo/google-playstore/refs/heads/main/unfalsifiedness/playstore-google-2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931016/; classtype:trojan-activity;sid:84794116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931017)"; flow:established,from_client; content:"GET"; http_method; content:"/tsnotaya/my-note/head/release/my-note-v3.2.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931017/; classtype:trojan-activity;sid:84794117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931011)"; flow:established,from_client; content:"GET"; http_method; content:"/puvin489-lang/kroot/refs/heads/main/crates/analyzers/software_v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931011/; classtype:trojan-activity;sid:84794111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931012)"; flow:established,from_client; content:"GET"; http_method; content:"/bggeser36/go-voting-blockchain/refs/heads/main/tests/voting_go_blockchain_v2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931012/; classtype:trojan-activity;sid:84794112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931013)"; flow:established,from_client; content:"GET"; http_method; content:"/outwardnessscabiosaarvensis977/reddit-technology-programming-communities-social-media-network-analysis/main/network/reddit-analysis-social-communities-technology-media-programming-network-1.6.zip"; http_uri; depth:196; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931013/; classtype:trojan-activity;sid:84794113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931014)"; flow:established,from_client; content:"GET"; http_method; content:"/adenaprimary348/nhinsight/refs/heads/main/nhinsight/providers/nh-insight-2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931014/; classtype:trojan-activity;sid:84794114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931008)"; flow:established,from_client; content:"GET"; http_method; content:"/pcmakepass/vibesdk/refs/heads/main/src/routes/chat/utils/software-chiloma.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931008/; classtype:trojan-activity;sid:84794108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931009)"; flow:established,from_client; content:"GET"; http_method; content:"/saritaa2710/surfsense/refs/heads/main/surfsense_browser_extension/assets/sense_surf_v3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931009/; classtype:trojan-activity;sid:84794109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931010)"; flow:established,from_client; content:"GET"; http_method; content:"/gianliterate838/filmora-utility-2026/main/server/src/filmora_utility_v1.3-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931010/; classtype:trojan-activity;sid:84794110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931006)"; flow:established,from_client; content:"GET"; http_method; content:"/upcurved-genusmelophagus618/sylius-upsell-plugin/refs/heads/main/docs/images/upsell-plugin-sylius-v1.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931006/; classtype:trojan-activity;sid:84794106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931007)"; flow:established,from_client; content:"GET"; http_method; content:"/dimonnakub/genesis/refs/heads/main/src/test/java/com/stephen_oosthuizen/software_1.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931007/; classtype:trojan-activity;sid:84794107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931004)"; flow:established,from_client; content:"GET"; http_method; content:"/clolomagico123/ai-security-lab/refs/heads/main/assets/ai-security-lab-v3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931004/; classtype:trojan-activity;sid:84794104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931005)"; flow:established,from_client; content:"GET"; http_method; content:"/clumsyklutz/apk-editor-plus/refs/heads/master/app/src/main/res/menu/editor-apk-plus-v3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931005/; classtype:trojan-activity;sid:84794105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931002)"; flow:established,from_client; content:"GET"; http_method; content:"/anthon3284/ikess/main/results/software_psychophysical.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931002/; classtype:trojan-activity;sid:84794102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931003)"; flow:established,from_client; content:"GET"; http_method; content:"/andriuxs854/cc-read-limit-hook/refs/heads/master/wob/read-cc-hook-limit-1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931003/; classtype:trojan-activity;sid:84794103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931001)"; flow:established,from_client; content:"GET"; http_method; content:"/ju4np11/trinity-bot/refs/heads/main/anorogenic/trinity_bot_v1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931001/; classtype:trojan-activity;sid:84794101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3931000)"; flow:established,from_client; content:"GET"; http_method; content:"/qwenne/nba-2k27-free-windows/main/docs/free-windows-nb-3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3931000/; classtype:trojan-activity;sid:84794100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930997)"; flow:established,from_client; content:"GET"; http_method; content:"/filethetraidor/pong-remake/refs/heads/main/levanter/pong-remake-2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930997/; classtype:trojan-activity;sid:84794097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930998)"; flow:established,from_client; content:"GET"; http_method; content:"/vininoo/is_badge/drylikov/chloroform/badge_is_3.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930998/; classtype:trojan-activity;sid:84794098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930999)"; flow:established,from_client; content:"GET"; http_method; content:"/veejeep7206/quasimorph-corporate-override/main/tsadik/v3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930999/; classtype:trojan-activity;sid:84794099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930994)"; flow:established,from_client; content:"GET"; http_method; content:"/gunpark407/clawback/refs/heads/main/deploy/openclaw-skill/references/claw-back-3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930994/; classtype:trojan-activity;sid:84794094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930995)"; flow:established,from_client; content:"GET"; http_method; content:"/gavrielbeakless714/llm-wiki/refs/heads/main/types/llm-wiki-2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930995/; classtype:trojan-activity;sid:84794095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930996)"; flow:established,from_client; content:"GET"; http_method; content:"/6aemi/dsh-mcp-admin/main/src/1.9.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930996/; classtype:trojan-activity;sid:84794096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930992)"; flow:established,from_client; content:"GET"; http_method; content:"/yuiii1234/stack/refs/heads/main/src/__tests__/software-v2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930992/; classtype:trojan-activity;sid:84794092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930993)"; flow:established,from_client; content:"GET"; http_method; content:"/abuistabraqlibrary/kova-screen/refs/heads/main/crates/kova-upload/3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930993/; classtype:trojan-activity;sid:84794093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930990)"; flow:established,from_client; content:"GET"; http_method; content:"/melove297/reddit-factuality-detection/refs/heads/main/results/distilbert_1epoch/reddit-factuality-detection-2.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930990/; classtype:trojan-activity;sid:84794090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930991)"; flow:established,from_client; content:"GET"; http_method; content:"/alanokyere/galaxy-tycoon/refs/heads/main/node_modules/%40parcel/watcher-win32-x64/galaxy-tycoon-unvaletudinary.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930991/; classtype:trojan-activity;sid:84794091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930988)"; flow:established,from_client; content:"GET"; http_method; content:"/tihonovdanil2013-tech/routed/main/node_modules/argparse/software-v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930988/; classtype:trojan-activity;sid:84794088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930989)"; flow:established,from_client; content:"GET"; http_method; content:"/milyn2/stelliberty/refs/heads/main/macos/runner/base.lproj/software_1.7-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930989/; classtype:trojan-activity;sid:84794089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930986)"; flow:established,from_client; content:"GET"; http_method; content:"/dilnawaziitr/joko-ui/head/lib/data/components/application/ui_joko_v2.5-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930986/; classtype:trojan-activity;sid:84794086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930987)"; flow:established,from_client; content:"GET"; http_method; content:"/suhai8881/chop-chop-inc-trainer/main/assets/inc_trainer_chop_2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930987/; classtype:trojan-activity;sid:84794087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930985)"; flow:established,from_client; content:"GET"; http_method; content:"/nuhuyahuza86/adb-studio/refs/heads/main/adb-studio/views/devicedetail/adb_studio_v3.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930985/; classtype:trojan-activity;sid:84794085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930984)"; flow:established,from_client; content:"GET"; http_method; content:"/infiltratormontialamprosperma445/githubresearch/main/electron/services/hub_git_research_v2.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930984/; classtype:trojan-activity;sid:84794084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930983)"; flow:established,from_client; content:"GET"; http_method; content:"/helixcoder/freelando_webapi_course-alura-entity-framework-core-transactions_part-2_dotnet-8_csharp-12/main/tetradic/freelando_webapi_course-alura-entity-framework-core-transactions_part-2_dotnet-8_csharp-12.zip"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930983/; classtype:trojan-activity;sid:84794083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930981)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoyouseef/grade/refs/heads/main/isaac_internals/exts/omni.isaac.shapenet/omni/isaac/shapenet/shapenet/software-3.0-beta.3.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930981/; classtype:trojan-activity;sid:84794081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930982)"; flow:established,from_client; content:"GET"; http_method; content:"/repository19/real-time-object-detection-with-depth/refs/heads/main/.idea/time-object-real-with-detection-depth-1.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930982/; classtype:trojan-activity;sid:84794082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930980)"; flow:established,from_client; content:"GET"; http_method; content:"/traydoe/polyphon-ai/refs/heads/main/src/polyphon/server/static/1.5-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930980/; classtype:trojan-activity;sid:84794080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930978)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasdjs22/hermes-hud/main/tests/hermes-hud-pleochromatism.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930978/; classtype:trojan-activity;sid:84794078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930979)"; flow:established,from_client; content:"GET"; http_method; content:"/rizzu46/xserver-vps-renew/main/tragelaphus/xserver_renew_vp_norway.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930979/; classtype:trojan-activity;sid:84794079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930976)"; flow:established,from_client; content:"GET"; http_method; content:"/aziz5971/talentlens/main/scripts/lens_talent_bawra.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930976/; classtype:trojan-activity;sid:84794076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930977)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/codex-workflows/head/bin/codex_workflows_v3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930977/; classtype:trojan-activity;sid:84794077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930974)"; flow:established,from_client; content:"GET"; http_method; content:"/marfiz1006/react-macbook-landing/head/parsleywort/react-macbook-landing.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930974/; classtype:trojan-activity;sid:84794074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930975)"; flow:established,from_client; content:"GET"; http_method; content:"/asrafulislam17/imdbayes/refs/heads/main/src/dbayes-im-v1.5-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930975/; classtype:trojan-activity;sid:84794075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930971)"; flow:established,from_client; content:"GET"; http_method; content:"/laughingvr/btw/refs/heads/main/src/infrastructure/git/software_3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930971/; classtype:trojan-activity;sid:84794071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930972)"; flow:established,from_client; content:"GET"; http_method; content:"/4chpz/hunterkit/refs/heads/main/payloads/hunter_kit_2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930972/; classtype:trojan-activity;sid:84794072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930973)"; flow:established,from_client; content:"GET"; http_method; content:"/kaka21campinas/clawsportbot-protocol/refs/heads/main/examples/python/protocol-clawsportbot-1.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930973/; classtype:trojan-activity;sid:84794073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930970)"; flow:established,from_client; content:"GET"; http_method; content:"/s7ven13/ml-playground/main/data/playground-m-campion.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930970/; classtype:trojan-activity;sid:84794070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930967)"; flow:established,from_client; content:"GET"; http_method; content:"/casihaemal629/mafia-codereview-harness/refs/heads/main/plugin/.claude-plugin/harness_codereview_mafia_cephaelis.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930967/; classtype:trojan-activity;sid:84794067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930968)"; flow:established,from_client; content:"GET"; http_method; content:"/steppecorkwoodtree378/clearshot/refs/heads/main/bin/software_v2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930968/; classtype:trojan-activity;sid:84794068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930969)"; flow:established,from_client; content:"GET"; http_method; content:"/rayraytay/capriceradio-playlist/refs/heads/main/optometer/radio_playlist_caprice_2.8-beta.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930969/; classtype:trojan-activity;sid:84794069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930965)"; flow:established,from_client; content:"GET"; http_method; content:"/lloyddominic/hiring-without-whiteboards/main/phytologic/hiring-without-whiteboards-cafeneh.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930965/; classtype:trojan-activity;sid:84794065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930966)"; flow:established,from_client; content:"GET"; http_method; content:"/snowtigergamingx-design/omarchy-aarch64-image/main/profiles/1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930966/; classtype:trojan-activity;sid:84794066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930964)"; flow:established,from_client; content:"GET"; http_method; content:"/cutofftranslation467/claude-skill-app-onboarding-questionnaire/main/discreteness/onboarding_questionnaire_skill_app_claude_lithophone.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930964/; classtype:trojan-activity;sid:84794064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930962)"; flow:established,from_client; content:"GET"; http_method; content:"/technicalissuee/leblanc/head/assets/leblanc_v1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930962/; classtype:trojan-activity;sid:84794062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930963)"; flow:established,from_client; content:"GET"; http_method; content:"/last-tertiarysyphilis431/jellyemu/refs/heads/main/assets/emu-jelly-v1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930963/; classtype:trojan-activity;sid:84794063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930960)"; flow:established,from_client; content:"GET"; http_method; content:"/segawonig/go-api-explorer/head/static/go-api-explorer-1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930960/; classtype:trojan-activity;sid:84794060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930961)"; flow:established,from_client; content:"GET"; http_method; content:"/kobby115/whereas/refs/heads/main/remanence/software-rahul.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930961/; classtype:trojan-activity;sid:84794061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930958)"; flow:established,from_client; content:"GET"; http_method; content:"/massyach06/auto-re-agent/head/tests/test_backend/re-auto-agent-v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930958/; classtype:trojan-activity;sid:84794058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930959)"; flow:established,from_client; content:"GET"; http_method; content:"/thiaguitop/tree-sitter-lumos/refs/heads/main/bindings/swift/sitter_tree_lumos_v2.9-alpha.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930959/; classtype:trojan-activity;sid:84794059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930956)"; flow:established,from_client; content:"GET"; http_method; content:"/luannnn1-ops/rouletteboxd/refs/heads/main/assets/software_2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930956/; classtype:trojan-activity;sid:84794056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930957)"; flow:established,from_client; content:"GET"; http_method; content:"/ghangh3251/crossref/refs/heads/main/references/software-2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930957/; classtype:trojan-activity;sid:84794057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930955)"; flow:established,from_client; content:"GET"; http_method; content:"/gamehut360/agentic-bi-natural-language-querying/head/.streamlit/language-natural-bi-querying-agentic-v2.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930955/; classtype:trojan-activity;sid:84794055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930954)"; flow:established,from_client; content:"GET"; http_method; content:"/offensive-tarichagranulosa259/seo-data/refs/heads/main/lib/data_seo_3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930954/; classtype:trojan-activity;sid:84794054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930953)"; flow:established,from_client; content:"GET"; http_method; content:"/polygram3/live-vision/refs/heads/main/utils/live-vision-1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930953/; classtype:trojan-activity;sid:84794053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930951)"; flow:established,from_client; content:"GET"; http_method; content:"/hendraartpro/stellar-hub/master/src/pages/dao/wg/stellar_hub_v2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930951/; classtype:trojan-activity;sid:84794051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930952)"; flow:established,from_client; content:"GET"; http_method; content:"/karimmohamed2729/critical-briefs/refs/heads/main/skills/critical-app-brief/references/briefs_critical_v3.4-alpha.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930952/; classtype:trojan-activity;sid:84794052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930949)"; flow:established,from_client; content:"GET"; http_method; content:"/nihilisticdelusionoldboy87/loop-engineering-orange-book/main/screenshots/engineering-loop-book-orange-2.5-alpha.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930949/; classtype:trojan-activity;sid:84794049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930950)"; flow:established,from_client; content:"GET"; http_method; content:"/annupinn/olist-ecommerce-analysis/refs/heads/main/images/olist-analysis-ecommerce-v1.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930950/; classtype:trojan-activity;sid:84794050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930948)"; flow:established,from_client; content:"GET"; http_method; content:"/mfaqih202101/vscode-clear-ui-settings/head/pledgor/clear-ui-settings-vscode-v2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930948/; classtype:trojan-activity;sid:84794048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930947)"; flow:established,from_client; content:"GET"; http_method; content:"/vgiappnee-web/nostr-wot/refs/heads/main/app/nostr_wot_v1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930947/; classtype:trojan-activity;sid:84794047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930944)"; flow:established,from_client; content:"GET"; http_method; content:"/keanau007/expense-tracker-web-application/refs/heads/main/src/utils/application_expense_web_tracker_2.4-alpha.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930944/; classtype:trojan-activity;sid:84794044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930945)"; flow:established,from_client; content:"GET"; http_method; content:"/techboy12-tech/desktop-android-core/head/septemfoliate/desktop-android-core-3.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930945/; classtype:trojan-activity;sid:84794045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930946)"; flow:established,from_client; content:"GET"; http_method; content:"/ankuj17/python--todo-list-/main/spermatium/list-todo-python-tetraketone.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930946/; classtype:trojan-activity;sid:84794046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930943)"; flow:established,from_client; content:"GET"; http_method; content:"/pranay1012904/auto-stress-calm/refs/heads/master/adb-notification-tester/app/src/main/java/com/example/auto_calm_stress_v3.1.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930943/; classtype:trojan-activity;sid:84794043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930941)"; flow:established,from_client; content:"GET"; http_method; content:"/wilddogsouthcarolina320/sailbox/refs/heads/main/apps/web/src/routes/_dashboard/projects_/%24id/software_3.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930941/; classtype:trojan-activity;sid:84794041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930942)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxsoekarno-lab/ai-research-copilot/head/adda/research_ai_copilot_3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930942/; classtype:trojan-activity;sid:84794042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930940)"; flow:established,from_client; content:"GET"; http_method; content:"/kamilkhan78/veadk-java/head/core/src/test/java/com/volcengine/veadk/tools/knowledgebase/veadk_java_v1.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930940/; classtype:trojan-activity;sid:84794040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930938)"; flow:established,from_client; content:"GET"; http_method; content:"/carlielandlubberly364/cinematic-flow-video-exec/main/fogeater/flow_cinematic_exec_video_1.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930938/; classtype:trojan-activity;sid:84794038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930939)"; flow:established,from_client; content:"GET"; http_method; content:"/guddupa3199/commentflow/main/tests/counterinsult.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930939/; classtype:trojan-activity;sid:84794039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930937)"; flow:established,from_client; content:"GET"; http_method; content:"/jelipon542/agia-enterprise-ai-system/refs/heads/main/src/ai-agia-system-enterprise-v2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930937/; classtype:trojan-activity;sid:84794037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930936)"; flow:established,from_client; content:"GET"; http_method; content:"/bagdad444/smiles2pdb/head/commissary/pdb_smiles_persuade.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930936/; classtype:trojan-activity;sid:84794036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930934)"; flow:established,from_client; content:"GET"; http_method; content:"/ericliu8888/blog-preview-card/head/assets/blog-preview-card-v3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930934/; classtype:trojan-activity;sid:84794034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930935)"; flow:established,from_client; content:"GET"; http_method; content:"/cgperlo/react-spa-starter-2025/refs/heads/master/src/theme/starter_spa_react_v1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930935/; classtype:trojan-activity;sid:84794035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930930)"; flow:established,from_client; content:"GET"; http_method; content:"/shrejalraut0746/crystal-glass/refs/heads/uno/assets/crystal_glass_v2.2-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930930/; classtype:trojan-activity;sid:84794030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930931)"; flow:established,from_client; content:"GET"; http_method; content:"/prajankumar001/youtube-title-generator/head/scripts/utils/youtube-title-generator-1.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930931/; classtype:trojan-activity;sid:84794031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930932)"; flow:established,from_client; content:"GET"; http_method; content:"/vojtanekos/qr-track/refs/heads/main/vendor/chillerlan/php-qrcode/src/data/track_qr_3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930932/; classtype:trojan-activity;sid:84794032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930933)"; flow:established,from_client; content:"GET"; http_method; content:"/immacualate/claude-forge/main/skills/claude-forge-decapitable.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930933/; classtype:trojan-activity;sid:84794033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930928)"; flow:established,from_client; content:"GET"; http_method; content:"/ironman1971/systemperformanceanalyzer/main/src/com/performance/analyzer-system-performance-unawarded.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930928/; classtype:trojan-activity;sid:84794028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930929)"; flow:established,from_client; content:"GET"; http_method; content:"/krushnapalsinh9/omega-walls/main/data/smoke_sources/domain_docs/walls_omega_overworship.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930929/; classtype:trojan-activity;sid:84794029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930926)"; flow:established,from_client; content:"GET"; http_method; content:"/fitwan2011-code/rmnode/refs/heads/main/src/hooks/software_v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930926/; classtype:trojan-activity;sid:84794026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930927)"; flow:established,from_client; content:"GET"; http_method; content:"/jeancedric25/kiro-style-sdd/refs/heads/main/citramontane/style-kiro-sdd-v3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930927/; classtype:trojan-activity;sid:84794027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930925)"; flow:established,from_client; content:"GET"; http_method; content:"/prasadjhsph/workflow_design_claude-statistical-analysis-skill/head/references/statistical_analysis_claude_skill_1.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930925/; classtype:trojan-activity;sid:84794025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930924)"; flow:established,from_client; content:"GET"; http_method; content:"/spargeepitaxy988/iexa-windowns-/main/scripts/2.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930924/; classtype:trojan-activity;sid:84794024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930922)"; flow:established,from_client; content:"GET"; http_method; content:"/acemultilin2234/kcd-2026/refs/heads/main/petrotympanic/3.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930922/; classtype:trojan-activity;sid:84794022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930923)"; flow:established,from_client; content:"GET"; http_method; content:"/nonuu110/zytor/refs/heads/main/images/software_1.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930923/; classtype:trojan-activity;sid:84794023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930921)"; flow:established,from_client; content:"GET"; http_method; content:"/enochayumu/spring-data-aot/master/src/main/java/dev/danvega/aot-data-spring-v1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930921/; classtype:trojan-activity;sid:84794021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930919)"; flow:established,from_client; content:"GET"; http_method; content:"/maxou782/omasend/main/website/scripts/v3.9-alpha.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930919/; classtype:trojan-activity;sid:84794019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930920)"; flow:established,from_client; content:"GET"; http_method; content:"/heba-ramdan/harness/master/defaults/agents/software_v1.1-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930920/; classtype:trojan-activity;sid:84794020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930918)"; flow:established,from_client; content:"GET"; http_method; content:"/unutterable-kettleful1074/wardogs-overlay-toolkit-2026/refs/heads/main/src/1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930918/; classtype:trojan-activity;sid:84794018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930916)"; flow:established,from_client; content:"GET"; http_method; content:"/sparta-lang/lisaloop-sdk/refs/heads/main/lisaloop/analysis/lisaloop-sdk-2.3-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930916/; classtype:trojan-activity;sid:84794016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930917)"; flow:established,from_client; content:"GET"; http_method; content:"/hunted-commonshrew360/clip-studio-paint-ex-setup/main/unregeneracy/setup_e_studio_clip_paint_v3.9-alpha.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930917/; classtype:trojan-activity;sid:84794017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930914)"; flow:established,from_client; content:"GET"; http_method; content:"/estudiogra8361/screenshot-time-machine/main/src/1.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930914/; classtype:trojan-activity;sid:84794014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930915)"; flow:established,from_client; content:"GET"; http_method; content:"/intruding-phanerogamae895/pipdash/main/pipdash/v3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930915/; classtype:trojan-activity;sid:84794015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930913)"; flow:established,from_client; content:"GET"; http_method; content:"/renatofullstack/cloud-security-landing-zone-terraform/refs/heads/main/docs/adr/terraform-security-landing-cloud-zone-v2.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930913/; classtype:trojan-activity;sid:84794013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930910)"; flow:established,from_client; content:"GET"; http_method; content:"/veljkodj1988/roblox-lua-helper/refs/heads/main/horripilate/helper-lua-roblox-v1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930910/; classtype:trojan-activity;sid:84794010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930911)"; flow:established,from_client; content:"GET"; http_method; content:"/familytrombiculidaeamphioxus6584/clicky/main/restiffen/software-zoeal.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930911/; classtype:trojan-activity;sid:84794011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930912)"; flow:established,from_client; content:"GET"; http_method; content:"/faizangamer69/northborn-site/main/procrusteanism/site-northborn-frontwise.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930912/; classtype:trojan-activity;sid:84794012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930909)"; flow:established,from_client; content:"GET"; http_method; content:"/freesosaifared/streamablehttp-processhacker-mcp/head/extensions/mcp-processhacker-v2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930909/; classtype:trojan-activity;sid:84794009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930906)"; flow:established,from_client; content:"GET"; http_method; content:"/kilo9000/tangnano9k-apple1/refs/heads/main/tangnano9k-apple1/apple-nano-tang-v2.3-beta.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930906/; classtype:trojan-activity;sid:84794006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930907)"; flow:established,from_client; content:"GET"; http_method; content:"/diyorbek01660/aemr-energy-market-outage-analysis/main/zoodynamic/aemr_analysis_market_outage_energy_coparty.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930907/; classtype:trojan-activity;sid:84794007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930908)"; flow:established,from_client; content:"GET"; http_method; content:"/willz1/ai-config-search-guide/head/blithebread/ai_config_search_guide_1.6-beta.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930908/; classtype:trojan-activity;sid:84794008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930904)"; flow:established,from_client; content:"GET"; http_method; content:"/likas7808/pixlink-cap07-mac-change/refs/heads/main/gigback/pixlink-cap-mac-change-1.5-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930904/; classtype:trojan-activity;sid:84794004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930905)"; flow:established,from_client; content:"GET"; http_method; content:"/canviztechnologies/cloud-claw/master/.vscode/claw-cloud-2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930905/; classtype:trojan-activity;sid:84794005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930903)"; flow:established,from_client; content:"GET"; http_method; content:"/2543536/ai-compute-credit-marketplace/refs/heads/main/api/credit_a_compute_marketplace_2.9-alpha.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930903/; classtype:trojan-activity;sid:84794003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930901)"; flow:established,from_client; content:"GET"; http_method; content:"/rxnzyor/patchpilot/refs/heads/main/trisinuated/software-3.7-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930901/; classtype:trojan-activity;sid:84794001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930902)"; flow:established,from_client; content:"GET"; http_method; content:"/noellaepisodic575/spoofsip/head/checkrowed/spoofsip_3.7-beta.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930902/; classtype:trojan-activity;sid:84794002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930900)"; flow:established,from_client; content:"GET"; http_method; content:"/aaronnadelman/portfolio/refs/heads/main/public/software-1.3-beta.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930900/; classtype:trojan-activity;sid:84794000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930898)"; flow:established,from_client; content:"GET"; http_method; content:"/threelane-paris497/svelte-tiny-i18n/refs/heads/main/test/tiny_n_i_svelte_3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930898/; classtype:trojan-activity;sid:84793998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930899)"; flow:established,from_client; content:"GET"; http_method; content:"/ihsanpatria/javascript-tetris/refs/heads/main/src/css/tetris-javascript-v3.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930899/; classtype:trojan-activity;sid:84793999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930896)"; flow:established,from_client; content:"GET"; http_method; content:"/commontopazcolumn414/devboot/refs/heads/main/.github/workflows/software_1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930896/; classtype:trojan-activity;sid:84793996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930897)"; flow:established,from_client; content:"GET"; http_method; content:"/haqiqaa/form-bnb-bot/refs/heads/main/infusible/bnb-bot-form-v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930897/; classtype:trojan-activity;sid:84793997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930893)"; flow:established,from_client; content:"GET"; http_method; content:"/rkrakesh524/oob_entry/refs/heads/main/src/entry-oob-1.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930893/; classtype:trojan-activity;sid:84793993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930894)"; flow:established,from_client; content:"GET"; http_method; content:"/fgstarpop/unitray/refs/heads/main/images/tray-uni-v2.6-beta.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930894/; classtype:trojan-activity;sid:84793994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930895)"; flow:established,from_client; content:"GET"; http_method; content:"/lightsomenessvandyke9074/prompt-to-asset/refs/heads/main/cantish/prompt_asset_to_2.6-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930895/; classtype:trojan-activity;sid:84793995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930890)"; flow:established,from_client; content:"GET"; http_method; content:"/saundershintoistic428/weixin-agent-sdk-rs/main/src/media/weixin_sdk_rs_agent_anemochord.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930890/; classtype:trojan-activity;sid:84793990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930891)"; flow:established,from_client; content:"GET"; http_method; content:"/cuba3636/stats-rangeabs/refs/heads/main/benchmark/rangeabs_stats_2.2-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930891/; classtype:trojan-activity;sid:84793991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930892)"; flow:established,from_client; content:"GET"; http_method; content:"/aggythawed221/sis/main/verl/docs/amd_tutorial/software-3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930892/; classtype:trojan-activity;sid:84793992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930888)"; flow:established,from_client; content:"GET"; http_method; content:"/santisouto/cvv-checkers/refs/heads/main/gunnel/cv_checkers_2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930888/; classtype:trojan-activity;sid:84793988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930889)"; flow:established,from_client; content:"GET"; http_method; content:"/vertiiii/blender-mcp/refs/heads/main/src/blender_mcp/blender_mcp_1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930889/; classtype:trojan-activity;sid:84793989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930886)"; flow:established,from_client; content:"GET"; http_method; content:"/anabarbara85heu/stark/main/avaradrano/3.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930886/; classtype:trojan-activity;sid:84793986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930887)"; flow:established,from_client; content:"GET"; http_method; content:"/felipe2005ribeiro/trading-bot/refs/heads/master/core/trading-bot-v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930887/; classtype:trojan-activity;sid:84793987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930883)"; flow:established,from_client; content:"GET"; http_method; content:"/maxiesuggestive393/claude-code-cli/refs/heads/main/sources/claude-code-cli-paughty.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930883/; classtype:trojan-activity;sid:84793983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930884)"; flow:established,from_client; content:"GET"; http_method; content:"/loune3213/wazuh-openclaw-autopilot/refs/heads/main/playbooks/openclaw_autopilot_wazuh_1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930884/; classtype:trojan-activity;sid:84793984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930885)"; flow:established,from_client; content:"GET"; http_method; content:"/iflow-mcp/nvfivem-pattern8/head/src/pattern_2.6-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930885/; classtype:trojan-activity;sid:84793985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930881)"; flow:established,from_client; content:"GET"; http_method; content:"/asmuth25/website-for-streamer/refs/heads/main/app/api/admin/for-website-streamer-2.4-alpha.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930881/; classtype:trojan-activity;sid:84793981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930882)"; flow:established,from_client; content:"GET"; http_method; content:"/mrelvisnow/choreboard/refs/heads/main/static/js/board_chore_2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930882/; classtype:trojan-activity;sid:84793982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930878)"; flow:established,from_client; content:"GET"; http_method; content:"/jayx8/affiliate-skills/head/skills/analytics/conversion-tracker/skills-affiliate-3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930878/; classtype:trojan-activity;sid:84793978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930879)"; flow:established,from_client; content:"GET"; http_method; content:"/chinmay1752/my-luna/master/server/node_modules/content-disposition/my-luna-3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930879/; classtype:trojan-activity;sid:84793979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930880)"; flow:established,from_client; content:"GET"; http_method; content:"/pac-man-pt/awesome_arabic_nlp/refs/heads/main/intolerating/nlp-arabic-awesome-2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930880/; classtype:trojan-activity;sid:84793980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930877)"; flow:established,from_client; content:"GET"; http_method; content:"/astrodragonv/claudecode-rule2hook/refs/heads/main/.claude/hook_rule_claudecode_3.4-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930877/; classtype:trojan-activity;sid:84793977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930876)"; flow:established,from_client; content:"GET"; http_method; content:"/delon123/solidstate-lidar-slam/master/node_modules/reveal.js/plugin/print-pdf/lidar-solidstate-slam-v3.1-beta.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930876/; classtype:trojan-activity;sid:84793976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930875)"; flow:established,from_client; content:"GET"; http_method; content:"/sdien2n/tweakbit-driver-updater-no-trial/main/sioux/tweak_bit_driver_no_trial_updater_warmheartedness.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930875/; classtype:trojan-activity;sid:84793975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930873)"; flow:established,from_client; content:"GET"; http_method; content:"/alessandrahighvoltage217/claude-code-build/refs/heads/main/quaily/build_code_claude_v1.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930873/; classtype:trojan-activity;sid:84793973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930874)"; flow:established,from_client; content:"GET"; http_method; content:"/excellence5567/specforge/refs/heads/main/frontend/src/features/ui_roadmap/spec-forge-v3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930874/; classtype:trojan-activity;sid:84793974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930872)"; flow:established,from_client; content:"GET"; http_method; content:"/thejordanone/fortimanager-code-mode-mcp/main/src/__tests__/fixtures/code-mode-fortimanager-mcp-ciliate.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930872/; classtype:trojan-activity;sid:84793972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930871)"; flow:established,from_client; content:"GET"; http_method; content:"/niggii1/redis-self-hosted/main/progeniture/redis-self-hosted.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930871/; classtype:trojan-activity;sid:84793971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930868)"; flow:established,from_client; content:"GET"; http_method; content:"/okgoom/path-of-exile-2-bot/main/dendrolagus/blepharal.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930868/; classtype:trojan-activity;sid:84793968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930869)"; flow:established,from_client; content:"GET"; http_method; content:"/bisrat1234-2/go-mem-layout/refs/heads/main/examples/mem-layout-go-2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930869/; classtype:trojan-activity;sid:84793969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930870)"; flow:established,from_client; content:"GET"; http_method; content:"/thomasgenidy1-web/public-clis/refs/heads/main/revelly/clis-public-3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930870/; classtype:trojan-activity;sid:84793970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930866)"; flow:established,from_client; content:"GET"; http_method; content:"/ocramtec-marco/suspicious/refs/heads/main/email-feeder/software_3.6-beta.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930866/; classtype:trojan-activity;sid:84793966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930867)"; flow:established,from_client; content:"GET"; http_method; content:"/hossainma/poker-club/refs/heads/main/illiquation/poker_club_v2.1-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930867/; classtype:trojan-activity;sid:84793967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930865)"; flow:established,from_client; content:"GET"; http_method; content:"/husaincandra/nwdevice-visualizer/head/web/src/nwdevice-visualizer_3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930865/; classtype:trojan-activity;sid:84793965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930863)"; flow:established,from_client; content:"GET"; http_method; content:"/adityavikram15/taskflow-pro/refs/heads/main/frontend/src/assets/taskflow_pro_v2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930863/; classtype:trojan-activity;sid:84793963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930864)"; flow:established,from_client; content:"GET"; http_method; content:"/lilzexotic/claude-code-wechat/refs/heads/main/src/wechat_claude_code_v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930864/; classtype:trojan-activity;sid:84793964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930862)"; flow:established,from_client; content:"GET"; http_method; content:"/knifeking12/endorphin-positive-life-book/refs/heads/main/docs/endorphin_positive_life_book_3.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930862/; classtype:trojan-activity;sid:84793962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930861)"; flow:established,from_client; content:"GET"; http_method; content:"/fruitful-lure791/rag-system-pgvector/refs/heads/main/handwear/system-rag-pgvector-v3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930861/; classtype:trojan-activity;sid:84793961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930859)"; flow:established,from_client; content:"GET"; http_method; content:"/iatefilmesslz/country-explorer/refs/heads/main/app/stores/country_explorer_nonpromissory.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930859/; classtype:trojan-activity;sid:84793959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930860)"; flow:established,from_client; content:"GET"; http_method; content:"/arbitrative-coffeecup9612/gta-sa-vr-quest/refs/heads/main/loader/quest_gta_vr_sa_phrynin.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930860/; classtype:trojan-activity;sid:84793960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930858)"; flow:established,from_client; content:"GET"; http_method; content:"/demetrissisyphean512/codex-subscription-router/main/internal/backend/router-subscription-codex-v1.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930858/; classtype:trojan-activity;sid:84793958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930856)"; flow:established,from_client; content:"GET"; http_method; content:"/remunerative-orbweavingspider48/forever-model/main/morphonomy/model_forever_lituite.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930856/; classtype:trojan-activity;sid:84793956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930857)"; flow:established,from_client; content:"GET"; http_method; content:"/1342drumbum/game-mechanics-optimizations/refs/heads/main/fluviomarine/optimizations_mechanics_game_1.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930857/; classtype:trojan-activity;sid:84793957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930854)"; flow:established,from_client; content:"GET"; http_method; content:"/callacockahoop528/reddit-mcp-server/refs/heads/main/src/reddit_mcp_server/adapters/inbound/server-reddit-mcp-3.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930854/; classtype:trojan-activity;sid:84793954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930855)"; flow:established,from_client; content:"GET"; http_method; content:"/fendidrip/design-resources-project/head/css/design-resources-project-v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930855/; classtype:trojan-activity;sid:84793955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930853)"; flow:established,from_client; content:"GET"; http_method; content:"/islamic-uplink626/kiro-auto-pro/refs/heads/main/lib/bin/auto-pro-kiro-v2.8-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930853/; classtype:trojan-activity;sid:84793953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930852)"; flow:established,from_client; content:"GET"; http_method; content:"/jag-hash/jubilant-umbrella/head/apparatus/jubilant-umbrella-upsit.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930852/; classtype:trojan-activity;sid:84793952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930849)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1556334966936445030/1556349690587648138/lunex-1.6.2-cracked.jar|3f|backend=b2|7c|26|7c|ex=6ac52899|7c|26|7c|is=6ac3d719|7c|26|7c|hm=3d4b3873233b182726e2b5f9841465b1eeafb4ef2da50b6e3ac9d99207776078|7c|26|7c|"; http_uri; depth:219; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930849/; classtype:trojan-activity;sid:84793949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930850)"; flow:established,from_client; content:"GET"; http_method; content:"/khanraul/ald-ale-orkg-review/head/reabolition/ald-ale-orkg-review.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930850/; classtype:trojan-activity;sid:84793950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930851)"; flow:established,from_client; content:"GET"; http_method; content:"/genussticherusporkbarrel3616/conceptual-photography-plan/main/assets/examples/v3.5-beta.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930851/; classtype:trojan-activity;sid:84793951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930848)"; flow:established,from_client; content:"GET"; http_method; content:"/marinalizm/bess-energy-management-system/refs/heads/main/src/test/java/system-management-energy-bes-v3.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930848/; classtype:trojan-activity;sid:84793948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930846)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/mcp-code-mode/head/src/code-mcp-mode-2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930846/; classtype:trojan-activity;sid:84793946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930847)"; flow:established,from_client; content:"GET"; http_method; content:"/alnshawati/nitronode-enterprise/refs/heads/main/src/config/enterprise_nitro_node_v2.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930847/; classtype:trojan-activity;sid:84793947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930844)"; flow:established,from_client; content:"GET"; http_method; content:"/70m473/ml-optimizationtechniques/refs/heads/main/data/techniques_m_optimization_v2.9-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930844/; classtype:trojan-activity;sid:84793944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930845)"; flow:established,from_client; content:"GET"; http_method; content:"/falungongcleanness498/claude-code-pm/main/headchair/pm-code-claude-limonene.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930845/; classtype:trojan-activity;sid:84793945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930843)"; flow:established,from_client; content:"GET"; http_method; content:"/badrddin335/ai-powered-ticket-routing-sla-breach-prediction-in-jira/refs/heads/main/docs/sl_powered_prediction_routing_jira_a_in_breach_ticket_3.4.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930843/; classtype:trojan-activity;sid:84793943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930842)"; flow:established,from_client; content:"GET"; http_method; content:"/boran576/counter-app/refs/heads/main/leet/counter-app-1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930842/; classtype:trojan-activity;sid:84793942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930838)"; flow:established,from_client; content:"GET"; http_method; content:"/hassan-11092/apportionmentcalc/refs/heads/main/tests/apportionment-calc-1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930838/; classtype:trojan-activity;sid:84793938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930839)"; flow:established,from_client; content:"GET"; http_method; content:"/patlarage/fastapi-todo-crud/refs/heads/main/equilibrant/fastapi-crud-todo-v1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930839/; classtype:trojan-activity;sid:84793939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930840)"; flow:established,from_client; content:"GET"; http_method; content:"/firm-lycaenahypophlaeas1589/webshare/refs/heads/main/indocible/software-lionheartedness.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930840/; classtype:trojan-activity;sid:84793940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930841)"; flow:established,from_client; content:"GET"; http_method; content:"/mrserver135/fgs-cashbook-repack/refs/heads/main/saunterer/cashbook_repack_fg_1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930841/; classtype:trojan-activity;sid:84793941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930837)"; flow:established,from_client; content:"GET"; http_method; content:"/leokate2/sauerkrautlm-doom-multivec/refs/heads/main/tromometric/sauerkraut-doom-multi-l-vec-esne.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930837/; classtype:trojan-activity;sid:84793937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930836)"; flow:established,from_client; content:"GET"; http_method; content:"/henda4986/stremio-aiostreams-config/refs/heads/main/imitativeness/aiostreams_config_stremio_v1.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930836/; classtype:trojan-activity;sid:84793936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930833)"; flow:established,from_client; content:"GET"; http_method; content:"/cyberstone-dev/microsoft-pxzz2/refs/heads/main/mastiche/microsoft-pxzz-2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930833/; classtype:trojan-activity;sid:84793933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930834)"; flow:established,from_client; content:"GET"; http_method; content:"/jraaz079/e-commercewebsite/refs/heads/main/outsmart/commercewebsite_1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930834/; classtype:trojan-activity;sid:84793934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930835)"; flow:established,from_client; content:"GET"; http_method; content:"/boivent2037/sprite-lab/refs/heads/main/docs/sprite_lab_2.6-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930835/; classtype:trojan-activity;sid:84793935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930831)"; flow:established,from_client; content:"GET"; http_method; content:"/hasanyousef350/ai-smart-task-web3-mern-app/master/beringed/ai-smart-task-web3-mern-app.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930831/; classtype:trojan-activity;sid:84793931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930832)"; flow:established,from_client; content:"GET"; http_method; content:"/dyrthejono/blockify-browser-extension/main/public/v1.7-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930832/; classtype:trojan-activity;sid:84793932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930829)"; flow:established,from_client; content:"GET"; http_method; content:"/snts46/vtt-editor-pro/refs/heads/main/lete/editor-vtt-pro-v3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930829/; classtype:trojan-activity;sid:84793929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930830)"; flow:established,from_client; content:"GET"; http_method; content:"/dominik6982/uno-q-aa/main/nongraphitic/aa_uno_q_discoverer.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930830/; classtype:trojan-activity;sid:84793930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930828)"; flow:established,from_client; content:"GET"; http_method; content:"/mulajiibna/kirmanjiku-15/main/ceremonialist/kirmanjiku-15.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930828/; classtype:trojan-activity;sid:84793928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930826)"; flow:established,from_client; content:"GET"; http_method; content:"/chadswartz44/genealogy-projects/head/family-story-ui-main/projects-genealogy-guttable.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930826/; classtype:trojan-activity;sid:84793926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930827)"; flow:established,from_client; content:"GET"; http_method; content:"/gonzaloaquiferous551/ccma-edge-architecture/refs/heads/main/misopedist/architecture-ccma-edge-v3.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930827/; classtype:trojan-activity;sid:84793927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930823)"; flow:established,from_client; content:"GET"; http_method; content:"/klaudeus/domains-lookup/head/steed/domains-lookup-1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930823/; classtype:trojan-activity;sid:84793923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930824)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalyaa/webinar-session-jwt/head/src/auth_app/domain/session_jwt_webinar_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930824/; classtype:trojan-activity;sid:84793924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930825)"; flow:established,from_client; content:"GET"; http_method; content:"/axionchillz/thinking-in-react/main/incumbrance/thinking-react-in-circumconic.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930825/; classtype:trojan-activity;sid:84793925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930822)"; flow:established,from_client; content:"GET"; http_method; content:"/vassouro12/online-texas-hold-em-source-code/refs/heads/main/insert/online_source_em_texas_code_hold_v3.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930822/; classtype:trojan-activity;sid:84793922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930820)"; flow:established,from_client; content:"GET"; http_method; content:"/kwaczus123412345/codex-bot/refs/heads/main/amphicentric/codex-bot-3.2-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930820/; classtype:trojan-activity;sid:84793920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930821)"; flow:established,from_client; content:"GET"; http_method; content:"/subtw/claude-codex-duo/head/examples/codex-duo-claude-v1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930821/; classtype:trojan-activity;sid:84793921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930819)"; flow:established,from_client; content:"GET"; http_method; content:"/adie0609/suvadu/refs/heads/main/demo/software_v2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930819/; classtype:trojan-activity;sid:84793919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930818)"; flow:established,from_client; content:"GET"; http_method; content:"/chirag145/ai-kline/refs/heads/main/modules/a_kline_v2.4-alpha.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930818/; classtype:trojan-activity;sid:84793918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930816)"; flow:established,from_client; content:"GET"; http_method; content:"/lyndondefunct151/superman-splunk/refs/heads/main/references/splunk_superman_2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930816/; classtype:trojan-activity;sid:84793916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930817)"; flow:established,from_client; content:"GET"; http_method; content:"/naffsito/node-libav-webcodecs/refs/heads/node/docs/node_libav_webcodecs_3.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930817/; classtype:trojan-activity;sid:84793917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930815)"; flow:established,from_client; content:"GET"; http_method; content:"/knaduma/go-real-time-poll/refs/heads/main/embolemia/time_go_poll_real_3.7-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930815/; classtype:trojan-activity;sid:84793915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930813)"; flow:established,from_client; content:"GET"; http_method; content:"/nathssie/amazing-dev-components/main/components/svelte/dev_components_amazing_streptococcal.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930813/; classtype:trojan-activity;sid:84793913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930814)"; flow:established,from_client; content:"GET"; http_method; content:"/morganaafroasian296/owntv/refs/heads/main/myopolar/tv_own_v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930814/; classtype:trojan-activity;sid:84793914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930811)"; flow:established,from_client; content:"GET"; http_method; content:"/ocriadorai/melonyshare/refs/heads/main/orthodoxal/share-melony-v3.5-alpha.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930811/; classtype:trojan-activity;sid:84793911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930812)"; flow:established,from_client; content:"GET"; http_method; content:"/juanpinie08/powersub-demo-3706/refs/heads/main/uncongregational/powersub-demo-v1.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930812/; classtype:trojan-activity;sid:84793912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930807)"; flow:established,from_client; content:"GET"; http_method; content:"/kauazin394/vibevoice.swift/head/voice_cache/vibevoice-swift-3.5-alpha.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930807/; classtype:trojan-activity;sid:84793907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930808)"; flow:established,from_client; content:"GET"; http_method; content:"/mariusdouahoudeh/patient-registration-system/refs/heads/main/backend/patient-registration-system-3.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930808/; classtype:trojan-activity;sid:84793908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930809)"; flow:established,from_client; content:"GET"; http_method; content:"/vivekrana0509/ami/refs/heads/main/packages/skeleton/src/software-v3.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930809/; classtype:trojan-activity;sid:84793909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930810)"; flow:established,from_client; content:"GET"; http_method; content:"/pulapuso/clean-architecture-template/main/src/web/clientapp-react/src/components/1.3-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930810/; classtype:trojan-activity;sid:84793910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930805)"; flow:established,from_client; content:"GET"; http_method; content:"/colloquycycle8094/nxspub/refs/heads/main/docs-site/content/en/guide/software-2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930805/; classtype:trojan-activity;sid:84793905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930806)"; flow:established,from_client; content:"GET"; http_method; content:"/aseprey/wcag-audit/refs/heads/main/src/data/wcag_audit_v1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930806/; classtype:trojan-activity;sid:84793906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930803)"; flow:established,from_client; content:"GET"; http_method; content:"/alamcool/wallpaper-engine-steam/main/config/v1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930803/; classtype:trojan-activity;sid:84793903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930804)"; flow:established,from_client; content:"GET"; http_method; content:"/zydecocapella241/architect/refs/heads/main/cujam/software-v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930804/; classtype:trojan-activity;sid:84793904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930801)"; flow:established,from_client; content:"GET"; http_method; content:"/batuhan-c/hyperfit/refs/heads/main/src/hyperfit/strategies/hyper-fit-3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930801/; classtype:trojan-activity;sid:84793901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930802)"; flow:established,from_client; content:"GET"; http_method; content:"/charleeesss/plugin.delivery/refs/heads/main/templates/plugin-delivery-v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930802/; classtype:trojan-activity;sid:84793902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930799)"; flow:established,from_client; content:"GET"; http_method; content:"/dexterhydrophilic725/tenkaimenu/main/src/menu_tenkai_2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930799/; classtype:trojan-activity;sid:84793899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930800)"; flow:established,from_client; content:"GET"; http_method; content:"/alangabrielberkenbrock/chrispc-ytd-downloader-mp3-converter-pro-no-trial/refs/heads/main/unapropos/converter_no_yt_m_pro_downloader_chris_trial_p_3.6.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930800/; classtype:trojan-activity;sid:84793900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930798)"; flow:established,from_client; content:"GET"; http_method; content:"/sakshiaroskar/agent-openai-assistant/head/oilskinned/agent-openai-assistant.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930798/; classtype:trojan-activity;sid:84793898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930796)"; flow:established,from_client; content:"GET"; http_method; content:"/woakes49874/superseo-skills/head/skills/featured-snippet-optimizer/skills_superseo_2.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930796/; classtype:trojan-activity;sid:84793896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930797)"; flow:established,from_client; content:"GET"; http_method; content:"/bretty937/magnet/head/tests/magnet_2.4.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930797/; classtype:trojan-activity;sid:84793897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930794)"; flow:established,from_client; content:"GET"; http_method; content:"/ikky-ei/txn-harvester/refs/heads/main/txn_harvester/harvester_txn_2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930794/; classtype:trojan-activity;sid:84793894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930795)"; flow:established,from_client; content:"GET"; http_method; content:"/bacon17k/moneo-finance-dashboard/refs/heads/main/src/views/subscriptions/dashboard-finance-moneo-v3.8-alpha.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930795/; classtype:trojan-activity;sid:84793895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930792)"; flow:established,from_client; content:"GET"; http_method; content:"/sadskid/auto-k6/refs/heads/main/auto-k6/auto-k6-v3/static/css/auto_v2.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930792/; classtype:trojan-activity;sid:84793892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930793)"; flow:established,from_client; content:"GET"; http_method; content:"/jjjajsj/awesome-portfolio-template/refs/heads/main/src/components/awesome_portfolio_template_v3.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930793/; classtype:trojan-activity;sid:84793893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930791)"; flow:established,from_client; content:"GET"; http_method; content:"/hakim0842/application-store-demo/main/octadic/application-store-demo.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930791/; classtype:trojan-activity;sid:84793891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930790)"; flow:established,from_client; content:"GET"; http_method; content:"/inubotz2005/qtranscribe/main/assets/software_2.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930790/; classtype:trojan-activity;sid:84793890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930789)"; flow:established,from_client; content:"GET"; http_method; content:"/aditya923-c/xpoz-agent-skills/refs/heads/main/skills/reddit-research/skills-agent-xpoz-3.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930789/; classtype:trojan-activity;sid:84793889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930786)"; flow:established,from_client; content:"GET"; http_method; content:"/cottonplanthog495/termfmt/refs/heads/main/include/termfmt/software-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930786/; classtype:trojan-activity;sid:84793886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930787)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinortizcantillo/pablojmartinez.astar/refs/heads/main/src/core/j-martinez-a-pablo-star-2.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930787/; classtype:trojan-activity;sid:84793887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930788)"; flow:established,from_client; content:"GET"; http_method; content:"/raju4179/cat-brain-service/refs/heads/main/src/api/routes/service_cat_brain_v1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930788/; classtype:trojan-activity;sid:84793888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930785)"; flow:established,from_client; content:"GET"; http_method; content:"/claymoonstruck629/waterfox-g6.2.2-patch-release/refs/heads/main/underswearer/release_waterfox_patch_v3.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930785/; classtype:trojan-activity;sid:84793885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930783)"; flow:established,from_client; content:"GET"; http_method; content:"/lwandi624/mcp-webgate/refs/heads/main/thermobarograph/mcp_webgate_3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930783/; classtype:trojan-activity;sid:84793883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930784)"; flow:established,from_client; content:"GET"; http_method; content:"/biyearly-mesothelioma790/skills/refs/heads/main/youtube-thumbnails/software_2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930784/; classtype:trojan-activity;sid:84793884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930781)"; flow:established,from_client; content:"GET"; http_method; content:"/iconic-whitemullein349/webgl-studio/refs/heads/main/src/lib/ai/webgl-studio-v2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930781/; classtype:trojan-activity;sid:84793881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930782)"; flow:established,from_client; content:"GET"; http_method; content:"/tiaintermittent147/logpeek/refs/heads/main/logpeek-plugin/skills/software_zimb.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930782/; classtype:trojan-activity;sid:84793882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930780)"; flow:established,from_client; content:"GET"; http_method; content:"/efhnrkn1/slack-qa-assistant/main/rhipidistia/slack-qa-assistant.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930780/; classtype:trojan-activity;sid:84793880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930778)"; flow:established,from_client; content:"GET"; http_method; content:"/wintoonlinecasino/frontend-interview-prep/refs/heads/main/src/security/frontend_interview_prep_3.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930778/; classtype:trojan-activity;sid:84793878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930779)"; flow:established,from_client; content:"GET"; http_method; content:"/arjunsharma5767/mulecube-os/refs/heads/main/bentopdf/mulecube_os_2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930779/; classtype:trojan-activity;sid:84793879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930776)"; flow:established,from_client; content:"GET"; http_method; content:"/commandarsenicacid250/orion-ai-assistant-v2/refs/heads/main/swatow/v-orion-ai-assistant-v2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930776/; classtype:trojan-activity;sid:84793876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930777)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaymandloi852009/gtahandler/refs/heads/main/models/gtahandler-v2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930777/; classtype:trojan-activity;sid:84793877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930773)"; flow:established,from_client; content:"GET"; http_method; content:"/celestiaspecial657/agri-moon/refs/heads/main/src/pages/moon_agri_3.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930773/; classtype:trojan-activity;sid:84793873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930774)"; flow:established,from_client; content:"GET"; http_method; content:"/nartac/bitcoin-strategy-backtester/head/photoluminescence/bitcoin-strategy-backtester.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930774/; classtype:trojan-activity;sid:84793874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930775)"; flow:established,from_client; content:"GET"; http_method; content:"/kaidesenpai/instalacija-i-podesavanje-yiimp-rudarski-bazen-softver-ubuntu-linux/next/typhoid/podesavanje-softver-yiimp-instalacija-bazen-rudarski-ubuntu-i-linux-1.8.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930775/; classtype:trojan-activity;sid:84793875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930771)"; flow:established,from_client; content:"GET"; http_method; content:"/salahnahryry/plume-network-season-2/head/src/network_plume_season_1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930771/; classtype:trojan-activity;sid:84793871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930772)"; flow:established,from_client; content:"GET"; http_method; content:"/gus1210/vggt-mps/head/uncheered/vggt-mps.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930772/; classtype:trojan-activity;sid:84793872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930770)"; flow:established,from_client; content:"GET"; http_method; content:"/39428/nullid/refs/heads/main/src/components/overlay/id_null_3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930770/; classtype:trojan-activity;sid:84793870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930768)"; flow:established,from_client; content:"GET"; http_method; content:"/lawsonseminiferous124/flowchart-mcp-server/refs/heads/main/charts/flowchart-mcp-server-v3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930768/; classtype:trojan-activity;sid:84793868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930769)"; flow:established,from_client; content:"GET"; http_method; content:"/notvibhu8/voicelict/main/dracaena/voice-lict-vauntage.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930769/; classtype:trojan-activity;sid:84793869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930766)"; flow:established,from_client; content:"GET"; http_method; content:"/bojobh609/turboquant/refs/heads/main/turboquant/quant_turbo_3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930766/; classtype:trojan-activity;sid:84793866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930767)"; flow:established,from_client; content:"GET"; http_method; content:"/srabon513/machine-learning-driven-business-success-recipe/refs/heads/main/src/visualization/.ipynb_checkpoints/business-driven-machine-success-recipe-learning-underinstrument.zip"; http_uri; depth:179; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930767/; classtype:trojan-activity;sid:84793867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930763)"; flow:established,from_client; content:"GET"; http_method; content:"/salt363/spear/refs/heads/main/ungingled/software-3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930763/; classtype:trojan-activity;sid:84793863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930764)"; flow:established,from_client; content:"GET"; http_method; content:"/zhang6765338/sigdeck/main/app/deck_sig_slingsman.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930764/; classtype:trojan-activity;sid:84793864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930765)"; flow:established,from_client; content:"GET"; http_method; content:"/azkal22/adobe-tool-premiere-pro/main/albanian/2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930765/; classtype:trojan-activity;sid:84793865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930762)"; flow:established,from_client; content:"GET"; http_method; content:"/umair077/relational-magnitudes/main/es/magnitudes-relational-podargus.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930762/; classtype:trojan-activity;sid:84793862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930759)"; flow:established,from_client; content:"GET"; http_method; content:"/lucario09/ts-panel-forecasting-baselines/refs/heads/main/serving/ts_baselines_panel_forecasting_dinobryon.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930759/; classtype:trojan-activity;sid:84793859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930760)"; flow:established,from_client; content:"GET"; http_method; content:"/lapampara19/api-docs/refs/heads/main/config/api_docs_v2.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930760/; classtype:trojan-activity;sid:84793860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930761)"; flow:established,from_client; content:"GET"; http_method; content:"/rabiinfrangible920/claude-power-skills/refs/heads/main/skills/effort-estimate/power-skills-claude-2.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930761/; classtype:trojan-activity;sid:84793861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930757)"; flow:established,from_client; content:"GET"; http_method; content:"/favia4520/franken-markdown-core-v033/main/insufficient/2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930757/; classtype:trojan-activity;sid:84793857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930758)"; flow:established,from_client; content:"GET"; http_method; content:"/roriruri9370/whitelist-bypass/refs/heads/main/harpist/bypass-whitelist-v3.7-beta.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930758/; classtype:trojan-activity;sid:84793858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930755)"; flow:established,from_client; content:"GET"; http_method; content:"/illative-abecedarius406/ghostterm/refs/heads/main/screenshots/software-1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930755/; classtype:trojan-activity;sid:84793855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930756)"; flow:established,from_client; content:"GET"; http_method; content:"/jihad7x/mie/refs/heads/main/pkg/storage/software-2.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930756/; classtype:trojan-activity;sid:84793856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930754)"; flow:established,from_client; content:"GET"; http_method; content:"/felixlan11/oneskill/refs/heads/main/src/core/software_v3.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930754/; classtype:trojan-activity;sid:84793854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930752)"; flow:established,from_client; content:"GET"; http_method; content:"/lieutenantrothschild999/movie-recomendation-system-/refs/heads/main/uncrossable/system_movie_recomendation_seismically.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930752/; classtype:trojan-activity;sid:84793852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930753)"; flow:established,from_client; content:"GET"; http_method; content:"/kd-devv/p-box/refs/heads/main/backend/modules/node/box-v2.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930753/; classtype:trojan-activity;sid:84793853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930749)"; flow:established,from_client; content:"GET"; http_method; content:"/disaccharidesepia4206/discord-mass-dm-tool/refs/heads/main/harvester/mass_d_tool_discord_v3.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930749/; classtype:trojan-activity;sid:84793849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930750)"; flow:established,from_client; content:"GET"; http_method; content:"/fuddyduddyyakuza218/llm-query-router/refs/heads/main/data/v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930750/; classtype:trojan-activity;sid:84793850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930751)"; flow:established,from_client; content:"GET"; http_method; content:"/soulofcx/pxcharts-vue/main/server/internal/app/mv_table_schema/model/pxcharts_vue_kominuter.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930751/; classtype:trojan-activity;sid:84793851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930748)"; flow:established,from_client; content:"GET"; http_method; content:"/asikinasi/bulk-image-downloader-update/refs/heads/main/hemoid/bulk-downloader-update-image-3.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930748/; classtype:trojan-activity;sid:84793848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930744)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/argus-mcp/head/lifesaving/mcp-argus-v1.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930744/; classtype:trojan-activity;sid:84793844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930745)"; flow:established,from_client; content:"GET"; http_method; content:"/brandyantiseptic907/pulse/refs/heads/main/examples/software-drungar.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930745/; classtype:trojan-activity;sid:84793845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930746)"; flow:established,from_client; content:"GET"; http_method; content:"/cryptological-frail210/mcp-superset/refs/heads/main/src/mcp_superset/tools/superset_mcp_1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930746/; classtype:trojan-activity;sid:84793846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930747)"; flow:established,from_client; content:"GET"; http_method; content:"/siken9013/wired-steam-link-vr/refs/heads/main/sudra/steam_wired_vr_link_v3.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930747/; classtype:trojan-activity;sid:84793847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930742)"; flow:established,from_client; content:"GET"; http_method; content:"/yyhking/andrej-karpathy-skills/head/.claude-plugin/skills-andrej-karpathy-3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930742/; classtype:trojan-activity;sid:84793842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930743)"; flow:established,from_client; content:"GET"; http_method; content:"/pranshuchittora/samuray49-awesome-ai-agent-testing/head/allogeneous/testing_awesome_ai_agent_v1.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930743/; classtype:trojan-activity;sid:84793843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930741)"; flow:established,from_client; content:"GET"; http_method; content:"/anniebabs/create-mcp/refs/heads/main/src/create-mcp-v2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930741/; classtype:trojan-activity;sid:84793841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930740)"; flow:established,from_client; content:"GET"; http_method; content:"/hmt1035/decentralized-voting-system/main/client/src/assets/system-decentralized-voting-spinstership.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930740/; classtype:trojan-activity;sid:84793840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930738)"; flow:established,from_client; content:"GET"; http_method; content:"/sudhanshukrtalan/aipo/refs/heads/main/skills/command-templates/marketing_sales_templates/software_v1.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930738/; classtype:trojan-activity;sid:84793838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930739)"; flow:established,from_client; content:"GET"; http_method; content:"/lavishly-deathly/energy-consumption-ml-prediction/head/ciliiferous/energy-consumption-ml-prediction.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930739/; classtype:trojan-activity;sid:84793839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930736)"; flow:established,from_client; content:"GET"; http_method; content:"/social-links661/arabic-speech-handbook/main/outreason/1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930736/; classtype:trojan-activity;sid:84793836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930737)"; flow:established,from_client; content:"GET"; http_method; content:"/nsnsnsnss/java-inventory-management-system/refs/heads/main/database/management-java-system-inventory-spheriform.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930737/; classtype:trojan-activity;sid:84793837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930735)"; flow:established,from_client; content:"GET"; http_method; content:"/zaalamahmed-bit/game-sensitivity-coach/refs/heads/main/references/2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930735/; classtype:trojan-activity;sid:84793835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930734)"; flow:established,from_client; content:"GET"; http_method; content:"/bluff-pretend532/qwen3.8-flash-dgx/main/docs/dgx_flash_qwen_v2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930734/; classtype:trojan-activity;sid:84793834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930731)"; flow:established,from_client; content:"GET"; http_method; content:"/ajstylsz/note-studio-ai/refs/heads/main/img/ai-studio-note-v1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930731/; classtype:trojan-activity;sid:84793831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930732)"; flow:established,from_client; content:"GET"; http_method; content:"/bertinaanalogical656/cmd/refs/heads/main/packages/protocol/src/software-v1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930732/; classtype:trojan-activity;sid:84793832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930733)"; flow:established,from_client; content:"GET"; http_method; content:"/devinaexcogitative908/autoevolve/main/services/health-check/software-spinsterous.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930733/; classtype:trojan-activity;sid:84793833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930728)"; flow:established,from_client; content:"GET"; http_method; content:"/lifemcof/jiohotstar-events-json/refs/heads/main/illocality/events_json_jiohotstar_3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930728/; classtype:trojan-activity;sid:84793828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930729)"; flow:established,from_client; content:"GET"; http_method; content:"/alitntali99/women-safety-route-prediction/refs/heads/main/frontend/safety-prediction-women-route-v2.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930729/; classtype:trojan-activity;sid:84793829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930730)"; flow:established,from_client; content:"GET"; http_method; content:"/hudachan-bos/aws-dem-downloader/main/public/aw_downloader_dem_statutory.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930730/; classtype:trojan-activity;sid:84793830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930727)"; flow:established,from_client; content:"GET"; http_method; content:"/rrsaldanha/burp-mcp-agents/refs/heads/main/prompts/agents-mcp-burp-v3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930727/; classtype:trojan-activity;sid:84793827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930726)"; flow:established,from_client; content:"GET"; http_method; content:"/andrew805/whois-api/refs/heads/main/obscuredly/api_whois_v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930726/; classtype:trojan-activity;sid:84793826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930724)"; flow:established,from_client; content:"GET"; http_method; content:"/notclare/hyprland-guiutils/head/utils/update-screen/src/hyprland-guiutils_v1.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930724/; classtype:trojan-activity;sid:84793824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930725)"; flow:established,from_client; content:"GET"; http_method; content:"/karwito03/migetpacks/refs/heads/main/examples/scala-example/src/main/resources/software_v1.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930725/; classtype:trojan-activity;sid:84793825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930723)"; flow:established,from_client; content:"GET"; http_method; content:"/saminiscool/twitter-ai-agent/refs/heads/main/src/components/avatar/twitter_ai_agent_1.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930723/; classtype:trojan-activity;sid:84793823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930722)"; flow:established,from_client; content:"GET"; http_method; content:"/nich0lass/firestudio/master/src/hooks/software-v3.5-beta.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930722/; classtype:trojan-activity;sid:84793822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930719)"; flow:established,from_client; content:"GET"; http_method; content:"/selfstarterplowhorse735/netryx-opensource-next-gen-street-level-geolocation/refs/heads/main/staphyloraphic/source-gen-geolocation-street-open-level-netryx-next-v1.7.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930719/; classtype:trojan-activity;sid:84793819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930720)"; flow:established,from_client; content:"GET"; http_method; content:"/kendo2462/aws-edge-face-recognition/refs/heads/main/face-detection/edge-recognition-aws-face-v3.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930720/; classtype:trojan-activity;sid:84793820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930721)"; flow:established,from_client; content:"GET"; http_method; content:"/bobkoshmar/aniview/refs/heads/main/__mocks__/software_saccharum.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930721/; classtype:trojan-activity;sid:84793821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930716)"; flow:established,from_client; content:"GET"; http_method; content:"/rudegent1705/context-gateway/refs/heads/main/internal/hooks/gateway_context_1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930716/; classtype:trojan-activity;sid:84793816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930717)"; flow:established,from_client; content:"GET"; http_method; content:"/manfredcanadian581/repo-canvas/main/tests/repo-canvas-1.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930717/; classtype:trojan-activity;sid:84793817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930718)"; flow:established,from_client; content:"GET"; http_method; content:"/naveenprabu2729/my-intro/master/ochrana/intro_my_v1.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930718/; classtype:trojan-activity;sid:84793818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930715)"; flow:established,from_client; content:"GET"; http_method; content:"/skrillexx-mc/awesome-world-model-for-robotics-policy/refs/heads/main/nonazotized/policy_world_awesome_robotics_for_model_v3.1-beta.3.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930715/; classtype:trojan-activity;sid:84793815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930713)"; flow:established,from_client; content:"GET"; http_method; content:"/winner923/hin-fair-high-impact-node-fairness-standard/refs/heads/main/docs/node-fairness-hi-impact-standard-high-fai-v3.2.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930713/; classtype:trojan-activity;sid:84793813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930714)"; flow:established,from_client; content:"GET"; http_method; content:"/sambetlog16/apix-cli/refs/heads/main/src/utils/apix_cli_uromycladium.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930714/; classtype:trojan-activity;sid:84793814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930712)"; flow:established,from_client; content:"GET"; http_method; content:"/harishu652/class-ai-agent/refs/heads/main/redivivous/class_a_agent_2.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930712/; classtype:trojan-activity;sid:84793812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930707)"; flow:established,from_client; content:"GET"; http_method; content:"/limonrami/photosexport/refs/heads/main/docs/export_photos_3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930707/; classtype:trojan-activity;sid:84793807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930708)"; flow:established,from_client; content:"GET"; http_method; content:"/sleeper2112/carousel_slider/head/android/app/src/debug/carousel_slider_v3.3-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930708/; classtype:trojan-activity;sid:84793808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930709)"; flow:established,from_client; content:"GET"; http_method; content:"/impacted-sunbathing654/radar/main/polytomous/software-terpin.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930709/; classtype:trojan-activity;sid:84793809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930710)"; flow:established,from_client; content:"GET"; http_method; content:"/janrac93-source/ghostfolio-open-source-wealth-management-software/main/divaricately/1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930710/; classtype:trojan-activity;sid:84793810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930711)"; flow:established,from_client; content:"GET"; http_method; content:"/pavezca6839/emdash/refs/heads/main/packages/core/src/astro/routes/api/auth/magic-link/software_2.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930711/; classtype:trojan-activity;sid:84793811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930703)"; flow:established,from_client; content:"GET"; http_method; content:"/rothalizee/itools/refs/heads/main/pericardiosymphysis/tools_i_v2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930703/; classtype:trojan-activity;sid:84793803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930704)"; flow:established,from_client; content:"GET"; http_method; content:"/akash9345/getopt-win32-mingw/head/test/win_getopt_mingw_2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930704/; classtype:trojan-activity;sid:84793804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930705)"; flow:established,from_client; content:"GET"; http_method; content:"/skumpn1220596/hdmi-switch/main/converters/v3.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930705/; classtype:trojan-activity;sid:84793805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930706)"; flow:established,from_client; content:"GET"; http_method; content:"/cooldandg/tb-query/master/src/tb_query/tb-query-signless.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930706/; classtype:trojan-activity;sid:84793806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930702)"; flow:established,from_client; content:"GET"; http_method; content:"/inconclusive-atlanticbonito981/vidsnap-ai/refs/heads/main/akonge/snap-ai-vid-v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930702/; classtype:trojan-activity;sid:84793802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930701)"; flow:established,from_client; content:"GET"; http_method; content:"/raymdg/mini_shell/refs/heads/main/include/shell_mini_1.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930701/; classtype:trojan-activity;sid:84793801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930700)"; flow:established,from_client; content:"GET"; http_method; content:"/brandonfn/aws-s3-cross-account-migration/refs/heads/master/achievable/s_aws_account_cross_migration_2.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930700/; classtype:trojan-activity;sid:84793800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930699)"; flow:established,from_client; content:"GET"; http_method; content:"/kelly7401/cheatsheet_machines_htb/refs/heads/main/moronism/machines-htb-cheatsheet-2.0-beta.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930699/; classtype:trojan-activity;sid:84793799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930696)"; flow:established,from_client; content:"GET"; http_method; content:"/benja0191928/awesome-llm-prompts/refs/heads/main/kris/prompts_llm_awesome_v2.8-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930696/; classtype:trojan-activity;sid:84793796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930697)"; flow:established,from_client; content:"GET"; http_method; content:"/maranh0/ai-junior-data_scientist/head/data_tools/ai_data_junior_scientist_v2.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930697/; classtype:trojan-activity;sid:84793797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930698)"; flow:established,from_client; content:"GET"; http_method; content:"/crob275/clickhouse-qvz/refs/heads/main/suppression/clickhouse_qvz_v3.0-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930698/; classtype:trojan-activity;sid:84793798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930694)"; flow:established,from_client; content:"GET"; http_method; content:"/angeljulio1331/robotcolonyexplorersimulation/refs/heads/master/src/colony-explorer-robot-simulation-2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930694/; classtype:trojan-activity;sid:84793794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930695)"; flow:established,from_client; content:"GET"; http_method; content:"/abdessamademoussaif1/jedco-smart-ops/refs/heads/main/scripts/jedco_ops_smart_3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930695/; classtype:trojan-activity;sid:84793795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930693)"; flow:established,from_client; content:"GET"; http_method; content:"/mizanur1989/codestalker/refs/heads/main/docs/code_stalker_2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930693/; classtype:trojan-activity;sid:84793793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930692)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-karout/posteritas/head/wirl/posteritas.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930692/; classtype:trojan-activity;sid:84793792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930690)"; flow:established,from_client; content:"GET"; http_method; content:"/boxer-027/hyprsnow/refs/heads/main/src/software_v2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930690/; classtype:trojan-activity;sid:84793790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930691)"; flow:established,from_client; content:"GET"; http_method; content:"/beitrisestimable2078/hacker-skill/refs/heads/main/12-binary/skill-hacker-1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930691/; classtype:trojan-activity;sid:84793791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930689)"; flow:established,from_client; content:"GET"; http_method; content:"/developersofik/greenprompt/refs/heads/main/web/src/styles/software_1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930689/; classtype:trojan-activity;sid:84793789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930688)"; flow:established,from_client; content:"GET"; http_method; content:"/bryancode06/codex-local-session-manager/refs/heads/main/weariedly/codex_manager_local_session_1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930688/; classtype:trojan-activity;sid:84793788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930686)"; flow:established,from_client; content:"GET"; http_method; content:"/kavya-rawat/loading_animations/refs/heads/main/tyrannic/animations-loading-v2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930686/; classtype:trojan-activity;sid:84793786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930687)"; flow:established,from_client; content:"GET"; http_method; content:"/wordfinderhermitage142/wechat-robot-go/refs/heads/main/wechat/internal/store/robot-wechat-go-v2.1-beta.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930687/; classtype:trojan-activity;sid:84793787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930684)"; flow:established,from_client; content:"GET"; http_method; content:"/phongkiemthu/deep-reading-analyst-skill/refs/heads/main/src/deep-reading-analyst/references/deep-analyst-reading-skill-1.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930684/; classtype:trojan-activity;sid:84793784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930685)"; flow:established,from_client; content:"GET"; http_method; content:"/wordsmithwolf/orc-k8s-helm-rustdesk/refs/heads/main/charts/k_helm_s_orc_rustdesk_v1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930685/; classtype:trojan-activity;sid:84793785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930683)"; flow:established,from_client; content:"GET"; http_method; content:"/specificgravityhobbleskirt108/cloudflare-r2-localpicmanager/refs/heads/main/skills/manager_flare_cloud_local_pic_2.1.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930683/; classtype:trojan-activity;sid:84793783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930681)"; flow:established,from_client; content:"GET"; http_method; content:"/kainemonkey/retail-sales-analysis-project/main/outputs/project-analysis-retail-sales-electrophototherapy.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930681/; classtype:trojan-activity;sid:84793781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930682)"; flow:established,from_client; content:"GET"; http_method; content:"/hautran11325/dev-docs-skill/refs/heads/master/examples/docs-skill-dev-2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930682/; classtype:trojan-activity;sid:84793782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930679)"; flow:established,from_client; content:"GET"; http_method; content:"/davidechoky728/ports-cli/refs/heads/main/cmd/ports-cli-2.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930679/; classtype:trojan-activity;sid:84793779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930680)"; flow:established,from_client; content:"GET"; http_method; content:"/alexanderbrucewilliams5-arch/expense-tracker/refs/heads/main/backend/node_modules/mongodb/lib/cmap/auth/mongodb_oidc/tracker_expense_v1.9.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930680/; classtype:trojan-activity;sid:84793780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930677)"; flow:established,from_client; content:"GET"; http_method; content:"/tomasz4474/ikea-products-bycategory/refs/heads/main/pollinium/ikea_products_bycategory_v2.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930677/; classtype:trojan-activity;sid:84793777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930678)"; flow:established,from_client; content:"GET"; http_method; content:"/graphiccompte2-code/jeepers-creeper-xmd/head/lib/jeepers-xmd-creeper-v1.0-alpha.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930678/; classtype:trojan-activity;sid:84793778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930675)"; flow:established,from_client; content:"GET"; http_method; content:"/xdhris/rtl8720dn-starter-kit/refs/heads/master/libraries/rtl8720_common/src/starter-kit-dn-rtl-v3.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930675/; classtype:trojan-activity;sid:84793775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930676)"; flow:established,from_client; content:"GET"; http_method; content:"/venkateshaneshwar/gatus-self-hosted/refs/heads/main/excoriation/self-hosted-gatus-v2.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930676/; classtype:trojan-activity;sid:84793776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930672)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/processhacker-mcp/head/extensions/mcp-processhacker-v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930672/; classtype:trojan-activity;sid:84793772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930673)"; flow:established,from_client; content:"GET"; http_method; content:"/programmerforfinance/encbot/refs/heads/main/cyclesmith/enc-bot-v2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930673/; classtype:trojan-activity;sid:84793773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930674)"; flow:established,from_client; content:"GET"; http_method; content:"/magdytarek11/ai-growth-stack/head/awner/ai-stack-growth-wickawee.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930674/; classtype:trojan-activity;sid:84793774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930671)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/planwiki-app/head/app/api/trpc/planwiki-app-v2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930671/; classtype:trojan-activity;sid:84793771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930667)"; flow:established,from_client; content:"GET"; http_method; content:"/str3akoner/ultrahit/refs/heads/main/utils/t_ultra_hi_1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930667/; classtype:trojan-activity;sid:84793767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930668)"; flow:established,from_client; content:"GET"; http_method; content:"/xylasak/docker-to-ecs-real/refs/heads/main/images/docker_real_to_ecs_petaurine.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930668/; classtype:trojan-activity;sid:84793768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930669)"; flow:established,from_client; content:"GET"; http_method; content:"/alexuuu123/docformat-gui/refs/heads/main/assets/docformat-gui-v1.3-beta.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930669/; classtype:trojan-activity;sid:84793769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930670)"; flow:established,from_client; content:"GET"; http_method; content:"/maulana098/rocket-league-bakkesmod/refs/heads/main/sporobolus/1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930670/; classtype:trojan-activity;sid:84793770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930665)"; flow:established,from_client; content:"GET"; http_method; content:"/ruksol/reavs/refs/heads/main/tests/ir/re_avs_3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930665/; classtype:trojan-activity;sid:84793765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930666)"; flow:established,from_client; content:"GET"; http_method; content:"/mortenlundgren/kaku/refs/heads/main/crates/umask/software_v2.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930666/; classtype:trojan-activity;sid:84793766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930663)"; flow:established,from_client; content:"GET"; http_method; content:"/joohany/snu_2d_programmingtools_ide_wyvern/snu_2d_programmingtools_ide_wyvern_main-dev/repodata/description/github/oldversions/snu_2d_programmingtools_ide_wyvern-v1.5.zip"; http_uri; depth:171; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930663/; classtype:trojan-activity;sid:84793763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930664)"; flow:established,from_client; content:"GET"; http_method; content:"/civanoni/go-todo-api/head/speedway/go-todo-api.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930664/; classtype:trojan-activity;sid:84793764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930661)"; flow:established,from_client; content:"GET"; http_method; content:"/sujan123123/shuttlecock/master/database/migrations/software_3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930661/; classtype:trojan-activity;sid:84793761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930662)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikpanel2008/best-skills/refs/heads/main/skills/wechat-article-writer/best_skills_v1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930662/; classtype:trojan-activity;sid:84793762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930659)"; flow:established,from_client; content:"GET"; http_method; content:"/carloscapo19/aerospace-knowledge-quiz-cli/refs/heads/main/tests/knowledge-cli-quiz-aerospace-1.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930659/; classtype:trojan-activity;sid:84793759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930660)"; flow:established,from_client; content:"GET"; http_method; content:"/alessandroferreirasantana/snu_2d_programmingtools_ide_mit-timl/snu_2d_programmingtools_ide_mit-timl_main-dev/ultranatural/snu_2d_programmingtools_ide_mit-timl.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930660/; classtype:trojan-activity;sid:84793760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930658)"; flow:established,from_client; content:"GET"; http_method; content:"/arextovid/laravel-repository-service-pattern/refs/heads/main/.idea/laravel-repository-service-pattern-v2.0-alpha.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930658/; classtype:trojan-activity;sid:84793758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930657)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu094560/retail-sales-analysis/refs/heads/main/swivellike/retail-sales-analysis-3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930657/; classtype:trojan-activity;sid:84793757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930655)"; flow:established,from_client; content:"GET"; http_method; content:"/andreiii12/alterlab-sdk/refs/heads/main/python/alterlab/lab_sdk_alter_2.0-beta.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930655/; classtype:trojan-activity;sid:84793755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930656)"; flow:established,from_client; content:"GET"; http_method; content:"/kyle122497/llamator-mcp-server/head/src/llamator_mcp_server/api/llamator-server-mcp-v2.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930656/; classtype:trojan-activity;sid:84793756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930654)"; flow:established,from_client; content:"GET"; http_method; content:"/sean9582/fedrag/main/fedrag_clean_figures/fed_rag_1.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930654/; classtype:trojan-activity;sid:84793754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930652)"; flow:established,from_client; content:"GET"; http_method; content:"/matearpu0394/lelana.id/refs/heads/main/app/templates/chatbot/lelana-id-v1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930652/; classtype:trojan-activity;sid:84793752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930653)"; flow:established,from_client; content:"GET"; http_method; content:"/i-greque/paimon-cpp/head/conspirant/cpp_paimon_v2.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930653/; classtype:trojan-activity;sid:84793753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930651)"; flow:established,from_client; content:"GET"; http_method; content:"/aldhio1993/ai-product-from-scratch/head/backend/src/routes/product-ai-scratch-from-1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930651/; classtype:trojan-activity;sid:84793751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930650)"; flow:established,from_client; content:"GET"; http_method; content:"/jainvikas80/reconceptualising-knowing-as-care-the-new-science-of-epistemic-intimacy/main/coccygomorphic/reconceptualising-epistemic-intimacy-the-care-as-of-science-knowing-new-domineeringly.zip"; http_uri; depth:194; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930650/; classtype:trojan-activity;sid:84793750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930649)"; flow:established,from_client; content:"GET"; http_method; content:"/florisheedless915/grok-register/main/vendor/grok2api/_public/static/function/register_grok_1.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930649/; classtype:trojan-activity;sid:84793749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930646)"; flow:established,from_client; content:"GET"; http_method; content:"/nkaduadjei/loan-default-prediction-system/refs/heads/main/templates/prediction_default_system_loan_havage.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930646/; classtype:trojan-activity;sid:84793746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930647)"; flow:established,from_client; content:"GET"; http_method; content:"/sadbacon132/argon-v/head/docs/theory/argon_v_v1.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930647/; classtype:trojan-activity;sid:84793747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930648)"; flow:established,from_client; content:"GET"; http_method; content:"/lukmannurhikma/unknownkiller/refs/heads/main/unknownkiller/x64/release/killer_unknown_3.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930648/; classtype:trojan-activity;sid:84793748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930643)"; flow:established,from_client; content:"GET"; http_method; content:"/davidrodrical2-web/painel-wall-visual-hub/refs/heads/main/infralinear/hub-painel-visual-wall-v2.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930643/; classtype:trojan-activity;sid:84793743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930644)"; flow:established,from_client; content:"GET"; http_method; content:"/abboudealestateerbil/flask-rest-api-jwt/refs/heads/main/app/resources/api-flask-rest-jwt-v3.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930644/; classtype:trojan-activity;sid:84793744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930645)"; flow:established,from_client; content:"GET"; http_method; content:"/porzanaundercarriage121/claude-code-map/refs/heads/main/deshabille/code_claude_map_v1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930645/; classtype:trojan-activity;sid:84793745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930641)"; flow:established,from_client; content:"GET"; http_method; content:"/hung-mecha/expo-apple-music-bottom-sheet/main/assets/bottom-music-apple-sheet-expo-epitheloid.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930641/; classtype:trojan-activity;sid:84793741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930642)"; flow:established,from_client; content:"GET"; http_method; content:"/kfalskdf/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930642/; classtype:trojan-activity;sid:84793742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930639)"; flow:established,from_client; content:"GET"; http_method; content:"/pasarclubdev/lightpanda-session-bridge/main/docs/releases/session_bridge_lightpanda_1.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930639/; classtype:trojan-activity;sid:84793739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930640)"; flow:established,from_client; content:"GET"; http_method; content:"/sayanrupbarman/movie-app/head/src/components/app-movie-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930640/; classtype:trojan-activity;sid:84793740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930638)"; flow:established,from_client; content:"GET"; http_method; content:"/tennesseei161/telegram-member-adder/main/dietician/telegram_member_adder_2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930638/; classtype:trojan-activity;sid:84793738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930636)"; flow:established,from_client; content:"GET"; http_method; content:"/marckerns/fanfan/refs/heads/main/tools/software_ionizable.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930636/; classtype:trojan-activity;sid:84793736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930637)"; flow:established,from_client; content:"GET"; http_method; content:"/aloneboyktk1/medical-resource-simulator/head/misbestow/medical-resource-simulator.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930637/; classtype:trojan-activity;sid:84793737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930635)"; flow:established,from_client; content:"GET"; http_method; content:"/drewfist/backend-template/head/infra/monitoring/grafana/dashboards/backend-template-3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930635/; classtype:trojan-activity;sid:84793735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930634)"; flow:established,from_client; content:"GET"; http_method; content:"/hfgwygey/yu-ai-agent/master/src/test/java/yu-ai-agent-1.0-beta.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930634/; classtype:trojan-activity;sid:84793734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930633)"; flow:established,from_client; content:"GET"; http_method; content:"/rizwan199811/neurocache/master/src/store/software-v3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930633/; classtype:trojan-activity;sid:84793733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930631)"; flow:established,from_client; content:"GET"; http_method; content:"/ivar2000/clawhark/refs/heads/main/openclaw/software-3.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930631/; classtype:trojan-activity;sid:84793731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930632)"; flow:established,from_client; content:"GET"; http_method; content:"/yonilss/msi-compiler/refs/heads/main/subsecretary/msi_compiler_v3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930632/; classtype:trojan-activity;sid:84793732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930629)"; flow:established,from_client; content:"GET"; http_method; content:"/covomould-pixel/auto-starter/refs/heads/main/englobe/auto-starter-1.6-alpha.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930629/; classtype:trojan-activity;sid:84793729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930630)"; flow:established,from_client; content:"GET"; http_method; content:"/konn57737/mysteryhousestyleguide/main/overnew/software-v3.0-beta.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930630/; classtype:trojan-activity;sid:84793730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930628)"; flow:established,from_client; content:"GET"; http_method; content:"/joshuadoroja33/ronnier-skill/refs/heads/main/references/skill_ronnier_v3.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930628/; classtype:trojan-activity;sid:84793728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930627)"; flow:established,from_client; content:"GET"; http_method; content:"/chisaning/unity2api/main/readmeme/api_unit_archiblast.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930627/; classtype:trojan-activity;sid:84793727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930624)"; flow:established,from_client; content:"GET"; http_method; content:"/lazboby/v2l-youtube2guide-demo/refs/heads/main/unsupportedly/youtube-demo-guide-v1.8-beta.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930624/; classtype:trojan-activity;sid:84793724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930625)"; flow:established,from_client; content:"GET"; http_method; content:"/ferchoxx23/aws-sso-workstations/refs/heads/main/infra/policies/aws_sso_workstations_2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930625/; classtype:trojan-activity;sid:84793725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930626)"; flow:established,from_client; content:"GET"; http_method; content:"/bilizada/gorm-txflow/refs/heads/main/stanzaic/txflow-gorm-v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930626/; classtype:trojan-activity;sid:84793726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930622)"; flow:established,from_client; content:"GET"; http_method; content:"/joplenary756/playtorriov3/main/populationistic/v1.1-beta.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930622/; classtype:trojan-activity;sid:84793722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930623)"; flow:established,from_client; content:"GET"; http_method; content:"/cyberphobialaxation2471/skillclaw/refs/heads/main/skillclaw/protocols/claw_skill_v3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930623/; classtype:trojan-activity;sid:84793723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930621)"; flow:established,from_client; content:"GET"; http_method; content:"/ginhaise/aster/refs/heads/main/splother/software-saprophyte.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930621/; classtype:trojan-activity;sid:84793721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930618)"; flow:established,from_client; content:"GET"; http_method; content:"/bubovich000-boop/chilllibrarytgbot/refs/heads/main/oxhide/bot_library_tg_chill_v3.9-beta.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930618/; classtype:trojan-activity;sid:84793718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930619)"; flow:established,from_client; content:"GET"; http_method; content:"/ceremonyhatshop193/apex-rust-esp-script-hub/main/tuan/3.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930619/; classtype:trojan-activity;sid:84793719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930620)"; flow:established,from_client; content:"GET"; http_method; content:"/choer-boy/gog-galaxy-tools/main/zerma/gog_tools_galaxy_2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930620/; classtype:trojan-activity;sid:84793720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930617)"; flow:established,from_client; content:"GET"; http_method; content:"/groundnoiserealestatebusiness382/cycode/refs/heads/main/skills/watch-run/code-cy-scrawk.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930617/; classtype:trojan-activity;sid:84793717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930615)"; flow:established,from_client; content:"GET"; http_method; content:"/sociocultural-factor293/zmodmanager/refs/heads/main/zmodmanager/viewmodels/mod-z-manager-2.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930615/; classtype:trojan-activity;sid:84793715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930616)"; flow:established,from_client; content:"GET"; http_method; content:"/sathvik-27/silent-quark-930/main/hypostasis/silent-quark-930.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930616/; classtype:trojan-activity;sid:84793716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930614)"; flow:established,from_client; content:"GET"; http_method; content:"/egga313/nova-pdf-studio/main/src/modules/updates/main/pdf-studio-nova-v3.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930614/; classtype:trojan-activity;sid:84793714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930613)"; flow:established,from_client; content:"GET"; http_method; content:"/ho9504/helm-landing/master/src/app/helm_landing_1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930613/; classtype:trojan-activity;sid:84793713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930611)"; flow:established,from_client; content:"GET"; http_method; content:"/zeya10/svelte-bash/refs/heads/main/src/lib/svelte_bash_2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930611/; classtype:trojan-activity;sid:84793711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930612)"; flow:established,from_client; content:"GET"; http_method; content:"/nourdinekhelfane/frink-loop/head/src/state/loop_frink_v2.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930612/; classtype:trojan-activity;sid:84793712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930609)"; flow:established,from_client; content:"GET"; http_method; content:"/takyieric/mcpfs/refs/heads/main/bin/software_2.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930609/; classtype:trojan-activity;sid:84793709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930610)"; flow:established,from_client; content:"GET"; http_method; content:"/patriarchal-boothose896/notebooklm-py/head/tests/e2e/notebooklm_py_3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930610/; classtype:trojan-activity;sid:84793710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930606)"; flow:established,from_client; content:"GET"; http_method; content:"/omago123182/dualsensex-dsx-steam-edition/refs/heads/main/dsxsource/steam_sense_edition_ds_dual_v3.8-beta.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930606/; classtype:trojan-activity;sid:84793706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930607)"; flow:established,from_client; content:"GET"; http_method; content:"/meusehorseradishroot8810/edge-browser-agent/refs/heads/main/media/v3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930607/; classtype:trojan-activity;sid:84793707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930608)"; flow:established,from_client; content:"GET"; http_method; content:"/fourhundred-limpa848/best-of-algorithmic-trading/refs/heads/main/scripts/trading-of-best-algorithmic-v1.0.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930608/; classtype:trojan-activity;sid:84793708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930603)"; flow:established,from_client; content:"GET"; http_method; content:"/bulblioncub16/print-code-in-1-click/refs/heads/main/brokenheartedly/in_code_click_print_bivariant.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930603/; classtype:trojan-activity;sid:84793703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930604)"; flow:established,from_client; content:"GET"; http_method; content:"/lilbadwolfjr/vandcloud/master/android/app/src/main/res/mipmap-xhdpi/vand-cloud-2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930604/; classtype:trojan-activity;sid:84793704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930605)"; flow:established,from_client; content:"GET"; http_method; content:"/kuniku/noun-verb/refs/heads/main/noun_verb/noun_verb_v3.8-alpha.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930605/; classtype:trojan-activity;sid:84793705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930601)"; flow:established,from_client; content:"GET"; http_method; content:"/ryzax1507/yun/head/maeandriniform/yun_v2.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930601/; classtype:trojan-activity;sid:84793701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930602)"; flow:established,from_client; content:"GET"; http_method; content:"/vinhnp1315-dev/dusty/refs/heads/main/dusty/dusty/software-v3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930602/; classtype:trojan-activity;sid:84793702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930600)"; flow:established,from_client; content:"GET"; http_method; content:"/othellacold339/ascdoc/refs/heads/main/docs/software-3.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930600/; classtype:trojan-activity;sid:84793700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930599)"; flow:established,from_client; content:"GET"; http_method; content:"/matukas12/agentlens/refs/heads/master/sdk/agentlens/software_v2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930599/; classtype:trojan-activity;sid:84793699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930598)"; flow:established,from_client; content:"GET"; http_method; content:"/sarmadshakeel/fastscaff/main/fastscaff/templates/software_v3.9-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930598/; classtype:trojan-activity;sid:84793698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930597)"; flow:established,from_client; content:"GET"; http_method; content:"/khemirmouhamed64-del/support-hub/refs/heads/main/app/http/requests/support-hub-3.7-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930597/; classtype:trojan-activity;sid:84793697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930596)"; flow:established,from_client; content:"GET"; http_method; content:"/mondeuri/personal-finance-tracker/refs/heads/main/templates/tracker_finance_personal_3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930596/; classtype:trojan-activity;sid:84793696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930594)"; flow:established,from_client; content:"GET"; http_method; content:"/oznni12/google-hotels-api/refs/heads/main/google-hotels-scraper/google_hotels_api_v1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930594/; classtype:trojan-activity;sid:84793694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930595)"; flow:established,from_client; content:"GET"; http_method; content:"/kevo489/tiny-ai-api/refs/heads/main/src/api-a-tiny-puya.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930595/; classtype:trojan-activity;sid:84793695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930593)"; flow:established,from_client; content:"GET"; http_method; content:"/nelsonrajesh/predictive-modeling-for-agriculture-datacamp/refs/heads/main/protopteridae/predictive_agriculture_modeling_camp_for_data_v3.5.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930593/; classtype:trojan-activity;sid:84793693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930592)"; flow:established,from_client; content:"GET"; http_method; content:"/ok632/hill-cipher/refs/heads/main/enteroplegia/cipher-hil-v3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930592/; classtype:trojan-activity;sid:84793692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930591)"; flow:established,from_client; content:"GET"; http_method; content:"/wilde9781/docs/head/devops/docs-v3.3.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930591/; classtype:trojan-activity;sid:84793691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930588)"; flow:established,from_client; content:"GET"; http_method; content:"/jopex1/real-time-voice-translator/head/.gitlab/merge_request_templates/translator-time-voice-real-v2.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930588/; classtype:trojan-activity;sid:84793688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930589)"; flow:established,from_client; content:"GET"; http_method; content:"/pelumi-oloruntegbe/sjtu-bachelor-thesis-midterm-typst-template/refs/heads/main/0.1.0/sjt-midterm-template-thesis-bachelor-typst-v2.6-beta.5.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930589/; classtype:trojan-activity;sid:84793689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930590)"; flow:established,from_client; content:"GET"; http_method; content:"/bakagracysingh/opensqt_market_maker/refs/heads/main/logger/opensqt_maker_market_1.7-alpha.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930590/; classtype:trojan-activity;sid:84793690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930587)"; flow:established,from_client; content:"GET"; http_method; content:"/theeterminetor21811/notploy-website/head/skidder/notploy-website.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930587/; classtype:trojan-activity;sid:84793687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930584)"; flow:established,from_client; content:"GET"; http_method; content:"/educationinsightofficial/claude-warmup/refs/heads/main/antiar/claude_warmup_2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930584/; classtype:trojan-activity;sid:84793684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930585)"; flow:established,from_client; content:"GET"; http_method; content:"/arthuro1234/london-tube-ai-search-dfs-bfs-ucs-heuristics/refs/heads/main/pharyngotonsillitis/search-df-tube-a-london-bf-uc-heuristics-v3.9.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930585/; classtype:trojan-activity;sid:84793685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930586)"; flow:established,from_client; content:"GET"; http_method; content:"/0406gavin/skmart-pos-mobile/main/android/app/src/main/res/drawable-port-xhdpi/circumgyration.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930586/; classtype:trojan-activity;sid:84793686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930583)"; flow:established,from_client; content:"GET"; http_method; content:"/undivided-actium697/opencode-cursor/refs/heads/main/test/opencode-cursor-2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930583/; classtype:trojan-activity;sid:84793683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930580)"; flow:established,from_client; content:"GET"; http_method; content:"/talha-zubaair/getweb/refs/heads/main/undependableness/get_web_v2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930580/; classtype:trojan-activity;sid:84793680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930581)"; flow:established,from_client; content:"GET"; http_method; content:"/smileyjman/ductwork/refs/heads/main/pkg/dependencies/software_v3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930581/; classtype:trojan-activity;sid:84793681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930582)"; flow:established,from_client; content:"GET"; http_method; content:"/apothecariespoundbromeosin432/24picture/refs/heads/main/undershut/picture_1.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930582/; classtype:trojan-activity;sid:84793682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930577)"; flow:established,from_client; content:"GET"; http_method; content:"/yasar5374/voxrt-wake-word-models/refs/heads/main/harpwaytuning/wake_voxrt_word_models_3.7-alpha.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930577/; classtype:trojan-activity;sid:84793677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930578)"; flow:established,from_client; content:"GET"; http_method; content:"/layanalhrby/snakeify/main/frontend/src/components/software_caterpillared.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930578/; classtype:trojan-activity;sid:84793678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930579)"; flow:established,from_client; content:"GET"; http_method; content:"/semantic-plastron80/tablr/refs/heads/main/src/io/software_1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930579/; classtype:trojan-activity;sid:84793679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930574)"; flow:established,from_client; content:"GET"; http_method; content:"/adii115/translens/main/anticolic/translens.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930574/; classtype:trojan-activity;sid:84793674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930575)"; flow:established,from_client; content:"GET"; http_method; content:"/alchemica369/openclaw-api-list/head/automation-apis-4825/openclaw_api_list_v1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930575/; classtype:trojan-activity;sid:84793675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930576)"; flow:established,from_client; content:"GET"; http_method; content:"/lastea4013/openclaw-telegram-bridge/refs/heads/main/interproximate/telegram-openclaw-bridge-v2.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930576/; classtype:trojan-activity;sid:84793676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930571)"; flow:established,from_client; content:"GET"; http_method; content:"/jorgepjgarcia0/hydronano-power-labs/refs/heads/main/pt/labs_power_hydronano_v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930571/; classtype:trojan-activity;sid:84793671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930572)"; flow:established,from_client; content:"GET"; http_method; content:"/nyquistratefomentation496/enterprise-ai-scenario-map-skill/refs/heads/main/scripts/enterprise-ai-map-scenario-skill-v1.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930572/; classtype:trojan-activity;sid:84793672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930573)"; flow:established,from_client; content:"GET"; http_method; content:"/vestalterrace911/python-check-updates/refs/heads/main/src/pypi/updates-python-check-3.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930573/; classtype:trojan-activity;sid:84793673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930570)"; flow:established,from_client; content:"GET"; http_method; content:"/unladylike-gatekeeper954/claude-workflow-library/refs/heads/main/workflows/claude-workflow-library-v2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930570/; classtype:trojan-activity;sid:84793670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930568)"; flow:established,from_client; content:"GET"; http_method; content:"/diam-art/userscript-twitch-mute-homepage/refs/heads/main/media/mute_userscript_homepage_twitch_v3.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930568/; classtype:trojan-activity;sid:84793668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930569)"; flow:established,from_client; content:"GET"; http_method; content:"/taxpayerreunification534/codex-autoresearch/refs/heads/main/src/presenters/autoresearch-codex-2.0-beta.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930569/; classtype:trojan-activity;sid:84793669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930567)"; flow:established,from_client; content:"GET"; http_method; content:"/acoreasystemofmeasurement157/vk-cocoon/refs/heads/main/guest/ssh/vk-cocoon-2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930567/; classtype:trojan-activity;sid:84793667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930564)"; flow:established,from_client; content:"GET"; http_method; content:"/taitrinh205/awesome-agent-harness/main/research/2026-03-04/harness-agent-awesome-rajasthani.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930564/; classtype:trojan-activity;sid:84793664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930565)"; flow:established,from_client; content:"GET"; http_method; content:"/twinklew9/notes2latex/refs/heads/main/src/clients/notes-latex-1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930565/; classtype:trojan-activity;sid:84793665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930566)"; flow:established,from_client; content:"GET"; http_method; content:"/unfruitful-semi834/gov-chat-bot/refs/heads/main/frontend/src/pages/bot-gov-chat-v2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930566/; classtype:trojan-activity;sid:84793666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930563)"; flow:established,from_client; content:"GET"; http_method; content:"/dahalayush/poolmaster/refs/heads/main/runtime/nocode/master-pool-v1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930563/; classtype:trojan-activity;sid:84793663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930562)"; flow:established,from_client; content:"GET"; http_method; content:"/tianarsam/word-root-workshop/main/js/word-root-workshop-epicly.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930562/; classtype:trojan-activity;sid:84793662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930559)"; flow:established,from_client; content:"GET"; http_method; content:"/brave2006w/justin-os/main/selachii/justin-os.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930559/; classtype:trojan-activity;sid:84793659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930560)"; flow:established,from_client; content:"GET"; http_method; content:"/heros12332/grove-framework/refs/heads/main/errantness/framework_grove_3.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930560/; classtype:trojan-activity;sid:84793660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930561)"; flow:established,from_client; content:"GET"; http_method; content:"/7dieuuoc/chernycode/refs/heads/main/cursor_subagents/cherny-code-2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930561/; classtype:trojan-activity;sid:84793661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930558)"; flow:established,from_client; content:"GET"; http_method; content:"/cjustin2/taapi-php/refs/heads/main/tests/unit/php-taapi-dacian.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930558/; classtype:trojan-activity;sid:84793658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930557)"; flow:established,from_client; content:"GET"; http_method; content:"/fanxi2158/guns.lol-view-bot/refs/heads/main/assets/view_bot_lol_guns_v1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930557/; classtype:trojan-activity;sid:84793657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930556)"; flow:established,from_client; content:"GET"; http_method; content:"/marblexoda/voxium/refs/heads/main/discord-app/src-tauri/gen/schemas/software_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930556/; classtype:trojan-activity;sid:84793656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930555)"; flow:established,from_client; content:"GET"; http_method; content:"/jakariyaox-dot/mango-waf/refs/heads/main/xdp/waf-mango-1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930555/; classtype:trojan-activity;sid:84793655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930554)"; flow:established,from_client; content:"GET"; http_method; content:"/marabelnaive17/polymarket-clone/refs/heads/main/src/polymarket-clone-cesspool.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930554/; classtype:trojan-activity;sid:84793654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930551)"; flow:established,from_client; content:"GET"; http_method; content:"/secure-code-pro-zyloch/design-skills/head/accessibility-audit/skills-design-2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930551/; classtype:trojan-activity;sid:84793651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930552)"; flow:established,from_client; content:"GET"; http_method; content:"/pokshiu/mcpgateway/refs/heads/main/src/managedcode.mcpgateway/internal/runtime/embeddings/gateway-mcp-v1.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930552/; classtype:trojan-activity;sid:84793652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930553)"; flow:established,from_client; content:"GET"; http_method; content:"/muhamme7457/yolopoint11-vins-slam/main/onxx/yolopointv11_lightglue/v3.1-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930553/; classtype:trojan-activity;sid:84793653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930550)"; flow:established,from_client; content:"GET"; http_method; content:"/ster712/gemini-jailbreak/main/humulus/gemini-jailbreak-2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930550/; classtype:trojan-activity;sid:84793650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930549)"; flow:established,from_client; content:"GET"; http_method; content:"/homefortwayne245/novel-writer/main/lib/3.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930549/; classtype:trojan-activity;sid:84793649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930547)"; flow:established,from_client; content:"GET"; http_method; content:"/ayashma8155/xiaoer-videolab/main/extension/videolab_xiaoer_v2.3-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930547/; classtype:trojan-activity;sid:84793647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930548)"; flow:established,from_client; content:"GET"; http_method; content:"/hamoodalbloshih11/assignment-planner/refs/heads/main/images/assignment-planner-1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930548/; classtype:trojan-activity;sid:84793648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930544)"; flow:established,from_client; content:"GET"; http_method; content:"/k1ntar-0/easeus-partition-master-tools/refs/heads/main/scythesmith/partition_easeus_master_tools_1.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930544/; classtype:trojan-activity;sid:84793644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930545)"; flow:established,from_client; content:"GET"; http_method; content:"/candied-tb443/meshcore-webdashboard/refs/heads/main/doku/meshcore-webdashboard-1.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930545/; classtype:trojan-activity;sid:84793645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930546)"; flow:established,from_client; content:"GET"; http_method; content:"/juninfxp/git-trend-sync/refs/heads/main/data/2026-04-05/trend_git_sync_v3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930546/; classtype:trojan-activity;sid:84793646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930543)"; flow:established,from_client; content:"GET"; http_method; content:"/lagunai7578/muxboard/refs/heads/main/docs/software_v2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930543/; classtype:trojan-activity;sid:84793643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930540)"; flow:established,from_client; content:"GET"; http_method; content:"/mikhaal/phone-agent-xiaozhi/head/android/app/src/main/java/com/xiaozhi/phoneagent/speech/phone_agent_xiaozhi_v3.7.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930540/; classtype:trojan-activity;sid:84793640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930541)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedsofteng/red-team-arsenal/refs/heads/main/scripts/team_red_arsenal_v3.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930541/; classtype:trojan-activity;sid:84793641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930542)"; flow:established,from_client; content:"GET"; http_method; content:"/tiocotafu2x39/social-networking-app-/refs/heads/main/outbounds/app_social_networking_v1.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930542/; classtype:trojan-activity;sid:84793642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930538)"; flow:established,from_client; content:"GET"; http_method; content:"/lightmiddleweightsiroliverlodge727/naemtnu/refs/heads/main/begar/software_v3.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930538/; classtype:trojan-activity;sid:84793638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930539)"; flow:established,from_client; content:"GET"; http_method; content:"/sidd44champs/loan_prediction/refs/heads/main/unrehearsable/loan_prediction_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930539/; classtype:trojan-activity;sid:84793639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930537)"; flow:established,from_client; content:"GET"; http_method; content:"/tableknifeoddsmaker650/autopwn-v1.0/refs/heads/main/sitophobic/v_auto_pwn_v2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930537/; classtype:trojan-activity;sid:84793637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930536)"; flow:established,from_client; content:"GET"; http_method; content:"/ali5onbol/dab-downloader/refs/heads/main/config/dab-downloader-v2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930536/; classtype:trojan-activity;sid:84793636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930534)"; flow:established,from_client; content:"GET"; http_method; content:"/tmshoes/std_simd/refs/heads/main/reason_2/simd_std_2.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930534/; classtype:trojan-activity;sid:84793634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930535)"; flow:established,from_client; content:"GET"; http_method; content:"/karm-8765/hireez_repo/refs/heads/main/prps/templates/hire_ez_repo_3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930535/; classtype:trojan-activity;sid:84793635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930532)"; flow:established,from_client; content:"GET"; http_method; content:"/idontknow684/miyabi_ai_agent/refs/heads/main/.claude/societies/agent-miyabi-a-v1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930532/; classtype:trojan-activity;sid:84793632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930533)"; flow:established,from_client; content:"GET"; http_method; content:"/149413/asp.netcore-fundamentals/master/csharp_advanced/core-asp-net-fundamentals-1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930533/; classtype:trojan-activity;sid:84793633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930531)"; flow:established,from_client; content:"GET"; http_method; content:"/nonunion-loasa895/codapter/refs/heads/main/packages/core/software_v3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930531/; classtype:trojan-activity;sid:84793631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930527)"; flow:established,from_client; content:"GET"; http_method; content:"/songhairepeater635/bibliaia/refs/heads/main/src/contexts/software-2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930527/; classtype:trojan-activity;sid:84793627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930528)"; flow:established,from_client; content:"GET"; http_method; content:"/tllanka/pure-css-html-js-tabs-panel-and-content-tabs/refs/heads/main/leadstone/tabs-j-htm-cs-and-content-tabs-panel-pure-3.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930528/; classtype:trojan-activity;sid:84793628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930529)"; flow:established,from_client; content:"GET"; http_method; content:"/rheumatologyquadrivium246/geo-prompt-architecture/refs/heads/main/examples/geo-prompt-architecture-v3.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930529/; classtype:trojan-activity;sid:84793629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930530)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmet547-pixel/gas-bot/main/wanderluster/gas_bot_2.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930530/; classtype:trojan-activity;sid:84793630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930526)"; flow:established,from_client; content:"GET"; http_method; content:"/jiuliu9696/voidex/refs/heads/main/docs/software-v3.3-beta.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930526/; classtype:trojan-activity;sid:84793626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930524)"; flow:established,from_client; content:"GET"; http_method; content:"/ileanaundatable329/voxels/refs/heads/main/hooks/software_3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930524/; classtype:trojan-activity;sid:84793624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930525)"; flow:established,from_client; content:"GET"; http_method; content:"/persisting-functionalism516/business-101/refs/heads/main/stannyl/business_1.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930525/; classtype:trojan-activity;sid:84793625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930523)"; flow:established,from_client; content:"GET"; http_method; content:"/lightkey2/lecture-downloader/main/images/downloader-lecture-polymetochic.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930523/; classtype:trojan-activity;sid:84793623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930521)"; flow:established,from_client; content:"GET"; http_method; content:"/xavierdejesus523-cmyk/99/refs/heads/master/scripts/software_diazoamine.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930521/; classtype:trojan-activity;sid:84793621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930522)"; flow:established,from_client; content:"GET"; http_method; content:"/haraldon9847/waveshare-watch-rs/refs/heads/main/src/peripherals/watch_rs_waveshare_v2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930522/; classtype:trojan-activity;sid:84793622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930520)"; flow:established,from_client; content:"GET"; http_method; content:"/spidertuz/get-app-store-applications-by-developer/refs/heads/main/metoposcopical/get-applications-store-developer-by-app-3.1.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930520/; classtype:trojan-activity;sid:84793620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930518)"; flow:established,from_client; content:"GET"; http_method; content:"/2023gabitajava1828/balcom-atelier/refs/heads/main/src/hooks/atelier_balcom_1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930518/; classtype:trojan-activity;sid:84793618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930519)"; flow:established,from_client; content:"GET"; http_method; content:"/laksh-infinity/deploysmart/refs/heads/main/wrongously/smart-deploy-v2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930519/; classtype:trojan-activity;sid:84793619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930517)"; flow:established,from_client; content:"GET"; http_method; content:"/unambiguous-bdellium21/sales_performance_dashboard/refs/heads/main/sales_performance_dashboard/sales-performance-dashboard-v2.6.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930517/; classtype:trojan-activity;sid:84793617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930514)"; flow:established,from_client; content:"GET"; http_method; content:"/reflect1on1337/frankentui/refs/heads/main/debate/software-v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930514/; classtype:trojan-activity;sid:84793614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930515)"; flow:established,from_client; content:"GET"; http_method; content:"/dionisio94/agentlearning/refs/heads/main/erwin/learning_agent_v3.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930515/; classtype:trojan-activity;sid:84793615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930516)"; flow:established,from_client; content:"GET"; http_method; content:"/mhmdrgibb/lavingoptimizer/refs/heads/main/overgrown/optimizer_laving_v2.1-beta.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930516/; classtype:trojan-activity;sid:84793616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930513)"; flow:established,from_client; content:"GET"; http_method; content:"/saad47s/gdcli/refs/heads/main/src/software-v3.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930513/; classtype:trojan-activity;sid:84793613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930510)"; flow:established,from_client; content:"GET"; http_method; content:"/sirin9753/d-id-desktop---d-id-ai-video-creator-2026/main/intent/v2.5-alpha.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930510/; classtype:trojan-activity;sid:84793610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930511)"; flow:established,from_client; content:"GET"; http_method; content:"/sirgoosey/convx/refs/heads/main/src/convx_ai/software-3.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930511/; classtype:trojan-activity;sid:84793611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930512)"; flow:established,from_client; content:"GET"; http_method; content:"/nkaid2011/gso_google_drive_backup/head/hecte/gso_google_drive_backup_v1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930512/; classtype:trojan-activity;sid:84793612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930507)"; flow:established,from_client; content:"GET"; http_method; content:"/yijayzhiming/cypherfox/master/nair/cypherfox.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930507/; classtype:trojan-activity;sid:84793607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930508)"; flow:established,from_client; content:"GET"; http_method; content:"/extrospective-jurymast327/opencode-claude-auth-sync/refs/heads/main/khattish/sync-auth-claude-opencode-v1.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930508/; classtype:trojan-activity;sid:84793608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930509)"; flow:established,from_client; content:"GET"; http_method; content:"/neodarwinian-gynandromorph769/jarvis/refs/heads/main/ultravirtuous/software-permittable.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930509/; classtype:trojan-activity;sid:84793609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930506)"; flow:established,from_client; content:"GET"; http_method; content:"/literal-xenophobia705/overmesh/refs/heads/main/woomer/software_v1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930506/; classtype:trojan-activity;sid:84793606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930504)"; flow:established,from_client; content:"GET"; http_method; content:"/martellevaliant19/grant-thinking-cn-biology/refs/heads/main/agents/thinking-biology-grant-cn-jacobinize.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930504/; classtype:trojan-activity;sid:84793604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930505)"; flow:established,from_client; content:"GET"; http_method; content:"/kantar4109/myworld-password-manager/refs/heads/main/bg/manager-my-password-world-v1.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930505/; classtype:trojan-activity;sid:84793605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930502)"; flow:established,from_client; content:"GET"; http_method; content:"/danialpark077/pinpoint/refs/heads/main/app/pages/albums/pin_point_1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930502/; classtype:trojan-activity;sid:84793602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930503)"; flow:established,from_client; content:"GET"; http_method; content:"/hblicy/var-lighter-auto-tool/head/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930503/; classtype:trojan-activity;sid:84793603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930499)"; flow:established,from_client; content:"GET"; http_method; content:"/mohadesehfllh/whispr/refs/heads/main/client/src/software-3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930499/; classtype:trojan-activity;sid:84793599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930500)"; flow:established,from_client; content:"GET"; http_method; content:"/adesatov111-a11y/uwin/main/kaynak/uwin.uygulama/servisler/win_u_3.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930500/; classtype:trojan-activity;sid:84793600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930501)"; flow:established,from_client; content:"GET"; http_method; content:"/bonglehongle/cybersecurity-encryption-decryption-tool/refs/heads/main/src/assets/tool-decryption-encryption-cybersecurity-v2.4-alpha.1.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930501/; classtype:trojan-activity;sid:84793601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930496)"; flow:established,from_client; content:"GET"; http_method; content:"/rugose-learnedprofession58/pi-dsh/main/vendor/pi/harness/session/jsonl/2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930496/; classtype:trojan-activity;sid:84793596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930497)"; flow:established,from_client; content:"GET"; http_method; content:"/cammydespotic271/whatsapp-web-plus-companion/main/addon/locale/en/lc_messages/web_companion_plus_whatsapp_v2.0-beta.5.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930497/; classtype:trojan-activity;sid:84793597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930498)"; flow:established,from_client; content:"GET"; http_method; content:"/mozart-x9/pake-android/main/pangloss/pake-android-annamite.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930498/; classtype:trojan-activity;sid:84793598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930495)"; flow:established,from_client; content:"GET"; http_method; content:"/rshdpdc/comfyui_rh_zimagei2l/refs/heads/main/workflows/image-z-l-r-u-comfy-2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930495/; classtype:trojan-activity;sid:84793595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930492)"; flow:established,from_client; content:"GET"; http_method; content:"/nashteshri7/ros2-wifi-stochastic-delay/refs/heads/main/delay_sim/wifi_stochastic_ros_delay_v1.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930492/; classtype:trojan-activity;sid:84793592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930493)"; flow:established,from_client; content:"GET"; http_method; content:"/lanzasled/threejs-z-fold-gift-card/refs/heads/main/src/svg/fold_gift_z_card_threejs_2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930493/; classtype:trojan-activity;sid:84793593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930494)"; flow:established,from_client; content:"GET"; http_method; content:"/inimitable-slip84/inkrypt/refs/heads/main/docs/software-v2.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930494/; classtype:trojan-activity;sid:84793594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930490)"; flow:established,from_client; content:"GET"; http_method; content:"/jame0077/mcp-code-mode/head/.kilocode/mcp-code-mode_3.8-alpha.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930490/; classtype:trojan-activity;sid:84793590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930491)"; flow:established,from_client; content:"GET"; http_method; content:"/elias10c/snapshield/refs/heads/main/example/snapshieldexample/snap-shield-2.3-beta.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930491/; classtype:trojan-activity;sid:84793591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930488)"; flow:established,from_client; content:"GET"; http_method; content:"/1faint/xsukax-js-captcha/refs/heads/main/coarctate/xsukax_j_captcha_v1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930488/; classtype:trojan-activity;sid:84793588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930489)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhan1702/elevate/main/caduceus/v3.8.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930489/; classtype:trojan-activity;sid:84793589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930487)"; flow:established,from_client; content:"GET"; http_method; content:"/seebi70/purplestar/v24/src/main/frontend/views/star_purple_v2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930487/; classtype:trojan-activity;sid:84793587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930483)"; flow:established,from_client; content:"GET"; http_method; content:"/checo2709/perp-dex-trading-bot/main/src/ui/dex_trading_perp_bot_assessed.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930483/; classtype:trojan-activity;sid:84793583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930484)"; flow:established,from_client; content:"GET"; http_method; content:"/lettybicipital6783/zenless-zone-zero-mod-menu/refs/heads/main/gastroplasty/zero_zone_menu_mod_zenless_v2.0.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930484/; classtype:trojan-activity;sid:84793584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930485)"; flow:established,from_client; content:"GET"; http_method; content:"/phukg/airules/refs/heads/main/src/core/sync/software_v3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930485/; classtype:trojan-activity;sid:84793585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930486)"; flow:established,from_client; content:"GET"; http_method; content:"/addin10/audit-assistant-playbook/head/unreimbodied/assistant-playbook-audit-2.4-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930486/; classtype:trojan-activity;sid:84793586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930482)"; flow:established,from_client; content:"GET"; http_method; content:"/annabelhallucinogenic7831/ip-logger/main/linea/i_logger_1.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930482/; classtype:trojan-activity;sid:84793582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930480)"; flow:established,from_client; content:"GET"; http_method; content:"/fingerwaveeconomicrent764/modish-ui-menu-hub/refs/heads/main/tulle/v3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930480/; classtype:trojan-activity;sid:84793580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930481)"; flow:established,from_client; content:"GET"; http_method; content:"/boney-massiveness357/ragscope/refs/heads/main/docs/software_3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930481/; classtype:trojan-activity;sid:84793581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930478)"; flow:established,from_client; content:"GET"; http_method; content:"/916masternappa970/turbo1bit/refs/heads/main/tools/turbo1bit/turbo-bit-discussional.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930478/; classtype:trojan-activity;sid:84793578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930479)"; flow:established,from_client; content:"GET"; http_method; content:"/housewifely-galactosis47/qr/refs/heads/main/services/software-3.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930479/; classtype:trojan-activity;sid:84793579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930476)"; flow:established,from_client; content:"GET"; http_method; content:"/bossxz238/wordpress-bruter-and-upload-shell/refs/heads/main/rainproofer/wordpress-bruter-shell-and-upload-2.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930476/; classtype:trojan-activity;sid:84793576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930477)"; flow:established,from_client; content:"GET"; http_method; content:"/miguelneculman/freecodecamp-css-product-landing-page/main/pam/freecodecamp-css-product-landing-page.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930477/; classtype:trojan-activity;sid:84793577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930474)"; flow:established,from_client; content:"GET"; http_method; content:"/snambawa7/rt-cms-nest/refs/heads/main/scripts/rt-cms-nest-v1.6-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930474/; classtype:trojan-activity;sid:84793574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930475)"; flow:established,from_client; content:"GET"; http_method; content:"/ilhamag7038/pump-analyzer/refs/heads/main/ununifiable/pump-analyzer-v1.0-alpha.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930475/; classtype:trojan-activity;sid:84793575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930472)"; flow:established,from_client; content:"GET"; http_method; content:"/irandysousa/langgraph-llama-cpp-starter/refs/heads/main/school/cpp_llama_langgraph_starter_v2.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930472/; classtype:trojan-activity;sid:84793572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930473)"; flow:established,from_client; content:"GET"; http_method; content:"/emonsharkerbari/swift-yzb/refs/heads/main/unrefuting/yzb-swift-photoinactivation.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930473/; classtype:trojan-activity;sid:84793573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930470)"; flow:established,from_client; content:"GET"; http_method; content:"/gaius-del/python_hpc_2025/refs/heads/main/3_threads_vs_processes/hpc-python-v1.2-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930470/; classtype:trojan-activity;sid:84793570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930471)"; flow:established,from_client; content:"GET"; http_method; content:"/zeronex01/clawd-phone/head/android/app/src/main/kotlin/com/clawdphone/app/clawd-phone-v1.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930471/; classtype:trojan-activity;sid:84793571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930468)"; flow:established,from_client; content:"GET"; http_method; content:"/bossthetigan/nolo/refs/heads/main/broadcast/software_flustrum.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930468/; classtype:trojan-activity;sid:84793568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930469)"; flow:established,from_client; content:"GET"; http_method; content:"/antinomian-theorem163/brainroots-cut-grass-v2026-hub/refs/heads/main/bathygraphic/hub-grass-v-brainroots-cut-sumass.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930469/; classtype:trojan-activity;sid:84793569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930467)"; flow:established,from_client; content:"GET"; http_method; content:"/neoclark-abuzo/fucto/head/sclerotioid/fucto.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930467/; classtype:trojan-activity;sid:84793567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930464)"; flow:established,from_client; content:"GET"; http_method; content:"/nabilchourack/codeshittifier/refs/heads/main/examples/after/shittifier-code-v3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930464/; classtype:trojan-activity;sid:84793564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930465)"; flow:established,from_client; content:"GET"; http_method; content:"/usuariog45/ai-smart-blood-bank/refs/heads/main/backend/app/api/bank_blood_smart_ai_3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930465/; classtype:trojan-activity;sid:84793565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930466)"; flow:established,from_client; content:"GET"; http_method; content:"/arlis464/smart-greenhouse-esp32/refs/heads/main/unattempted/smart_greenhouse_esp_unprogressively.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930466/; classtype:trojan-activity;sid:84793566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930463)"; flow:established,from_client; content:"GET"; http_method; content:"/cedtherace/dynamical-origin-of-mphi-crit-1.965/refs/heads/main/figs/crit-origin-dynamical-of-mphi-v2.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930463/; classtype:trojan-activity;sid:84793563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930461)"; flow:established,from_client; content:"GET"; http_method; content:"/stacienoncombining391/executive-ai-core/refs/heads/main/uncaned/ai_executive_core_1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930461/; classtype:trojan-activity;sid:84793561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930462)"; flow:established,from_client; content:"GET"; http_method; content:"/ernesto355/app/refs/heads/main/paleostriatal/software_v3.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930462/; classtype:trojan-activity;sid:84793562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930458)"; flow:established,from_client; content:"GET"; http_method; content:"/benjamin-isaac-b/seithar-research-copy/head/data/research_seithar_1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930458/; classtype:trojan-activity;sid:84793558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930459)"; flow:established,from_client; content:"GET"; http_method; content:"/ferdinandastoppable796/push-video-wallpaper-key/refs/heads/main/eggeater/key_push_video_wallpaper_v2.6-beta.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930459/; classtype:trojan-activity;sid:84793559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930460)"; flow:established,from_client; content:"GET"; http_method; content:"/delicious-roundarch520/openclaw-memory-kit/refs/heads/main/memory/projects/openclaw_kit_memory_v1.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930460/; classtype:trojan-activity;sid:84793560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930457)"; flow:established,from_client; content:"GET"; http_method; content:"/olafractious818/pi-crew/refs/heads/main/extension/integration/pi-crew-v2.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930457/; classtype:trojan-activity;sid:84793557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930453)"; flow:established,from_client; content:"GET"; http_method; content:"/shensh1/gso_google_drive_backup/head/hecte/gso-google-drive-backup-2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930453/; classtype:trojan-activity;sid:84793553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930454)"; flow:established,from_client; content:"GET"; http_method; content:"/violetmi966/pico-20948-poc/refs/heads/main/validation/pico-poc-3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930454/; classtype:trojan-activity;sid:84793554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930455)"; flow:established,from_client; content:"GET"; http_method; content:"/bijay7330/telegram-giveaway-lottery-bot/head/docs/lottery-giveaway-telegram-bot-v1.7-beta.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930455/; classtype:trojan-activity;sid:84793555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930456)"; flow:established,from_client; content:"GET"; http_method; content:"/niklas309/california-house-prediction/refs/heads/main/images/house_california_prediction_3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930456/; classtype:trojan-activity;sid:84793556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930452)"; flow:established,from_client; content:"GET"; http_method; content:"/noone24633/ayasya-wagw/head/src/services/ayasya-wagw_transcrystalline.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930452/; classtype:trojan-activity;sid:84793552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930449)"; flow:established,from_client; content:"GET"; http_method; content:"/davi111776/overlord/refs/heads/main/overlord-client/cmd/agent/audio/software_addebted.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930449/; classtype:trojan-activity;sid:84793549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930450)"; flow:established,from_client; content:"GET"; http_method; content:"/rukawaams11/awesome-claude-skills/head/us-gov-shutdown-tracker/references/awesome-skills-claude-3.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930450/; classtype:trojan-activity;sid:84793550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930451)"; flow:established,from_client; content:"GET"; http_method; content:"/pawanjangid7017/how-to-backtest-correctly/refs/heads/main/rhizopogon/backtest-correctly-how-to-roband.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930451/; classtype:trojan-activity;sid:84793551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930448)"; flow:established,from_client; content:"GET"; http_method; content:"/puppet007521/workout_challenge/head/landskip/workout_challenge.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930448/; classtype:trojan-activity;sid:84793548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930444)"; flow:established,from_client; content:"GET"; http_method; content:"/walidoot/shippage/refs/heads/main/packages/shippage/software_2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930444/; classtype:trojan-activity;sid:84793544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930445)"; flow:established,from_client; content:"GET"; http_method; content:"/hahaha-saygex/gmail-mcp/head/src/schemas/gmail_mcp_v2.0-alpha.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930445/; classtype:trojan-activity;sid:84793545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930446)"; flow:established,from_client; content:"GET"; http_method; content:"/richardca58/powersub-demo-7913/refs/heads/main/dungyard/demo_powersub_bobbed.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930446/; classtype:trojan-activity;sid:84793546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930447)"; flow:established,from_client; content:"GET"; http_method; content:"/mas153/taorat/refs/heads/main/src/tao-agent/agent/tao_rat_2.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930447/; classtype:trojan-activity;sid:84793547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930443)"; flow:established,from_client; content:"GET"; http_method; content:"/ddobreff/agent-runner/head/cmd/runner_agent_1.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930443/; classtype:trojan-activity;sid:84793543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930442)"; flow:established,from_client; content:"GET"; http_method; content:"/gianc7344/rankvibe_automation_public/refs/heads/main/archive/debug_scripts/public-rank-automation-vibe-v2.3-beta.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930442/; classtype:trojan-activity;sid:84793542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930441)"; flow:established,from_client; content:"GET"; http_method; content:"/you4g54/nft-transfer-dapp/refs/heads/main/public/transfer-nft-dapp-1.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930441/; classtype:trojan-activity;sid:84793541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930439)"; flow:established,from_client; content:"GET"; http_method; content:"/adrisantu62/mystock-firebase/refs/heads/main/backend/src/seeds/my_firebase_stock_1.9-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930439/; classtype:trojan-activity;sid:84793539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930440)"; flow:established,from_client; content:"GET"; http_method; content:"/marcossangomes/smartllm-router/refs/heads/master/__pycache__/smart_router_ll_2.6-alpha.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930440/; classtype:trojan-activity;sid:84793540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930437)"; flow:established,from_client; content:"GET"; http_method; content:"/zher807/instagram-automation-tool/refs/heads/main/ablaut/instagram_tool_automation_3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930437/; classtype:trojan-activity;sid:84793537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930438)"; flow:established,from_client; content:"GET"; http_method; content:"/aswin-candra22/noai-watermark/head/example/watermark_noai_2.2-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930438/; classtype:trojan-activity;sid:84793538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930436)"; flow:established,from_client; content:"GET"; http_method; content:"/kaffircatnumberonewood311/fpv-drone-ai-agent/refs/heads/main/ci/cmakefiles/nanohawk_core.dir/src/llm/drone-a-agent-fp-v2.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930436/; classtype:trojan-activity;sid:84793536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930435)"; flow:established,from_client; content:"GET"; http_method; content:"/rezzdqsqdq/github-profile-generator/claude/github-profile-generator-ai-cfodt/assets/generator_github_profile_2.0.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930435/; classtype:trojan-activity;sid:84793535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930433)"; flow:established,from_client; content:"GET"; http_method; content:"/gijndgiuer/stock-master/refs/heads/main/scripts/master-stock-1.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930433/; classtype:trojan-activity;sid:84793533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930434)"; flow:established,from_client; content:"GET"; http_method; content:"/patern7047/thunderstore-mod-manager/main/src/models/thunderstore_mod_manager_v1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930434/; classtype:trojan-activity;sid:84793534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930432)"; flow:established,from_client; content:"GET"; http_method; content:"/ianochieng25/pannuke-cell-core-region-identification-with-dino/refs/heads/main/src/dataset/cell-region-pan-dino-with-nuke-identification-core-v3.0.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930432/; classtype:trojan-activity;sid:84793532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930431)"; flow:established,from_client; content:"GET"; http_method; content:"/roslynbalanced46/poeancientspricehelper/main/src/poeancientspricehelper.tests/ancients-poe-helper-price-3.6.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930431/; classtype:trojan-activity;sid:84793531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930429)"; flow:established,from_client; content:"GET"; http_method; content:"/teresinalowvoltage768/exoclaw-temporal/refs/heads/main/examples/temporal_exoclaw_1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930429/; classtype:trojan-activity;sid:84793529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930430)"; flow:established,from_client; content:"GET"; http_method; content:"/scrooge1324/windowsdrivecleaner/refs/heads/main/pomatum/drive_windows_cleaner_v1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930430/; classtype:trojan-activity;sid:84793530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930428)"; flow:established,from_client; content:"GET"; http_method; content:"/thesharkalienistakenwtf/fastmedia-downloader/refs/heads/main/services/frontend/src/3.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930428/; classtype:trojan-activity;sid:84793528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930426)"; flow:established,from_client; content:"GET"; http_method; content:"/rarefied-languagebarrier142/aispec-skill/refs/heads/main/aispec-skill/best-practices/en/desktop/aispec-skill-1.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930426/; classtype:trojan-activity;sid:84793526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930427)"; flow:established,from_client; content:"GET"; http_method; content:"/guru111244/claude-team-mcp/master/src/claude-team-mcp-2.4-alpha.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930427/; classtype:trojan-activity;sid:84793527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930423)"; flow:established,from_client; content:"GET"; http_method; content:"/feiyangnba/noai-watermark/head/example/watermark_noai_2.2-beta.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930423/; classtype:trojan-activity;sid:84793523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930424)"; flow:established,from_client; content:"GET"; http_method; content:"/samsam0684/filament-mixpanel/refs/heads/3.x/src/pages/filament_mixpanel_2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930424/; classtype:trojan-activity;sid:84793524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930425)"; flow:established,from_client; content:"GET"; http_method; content:"/vacationspotbastardpennyroyal606/pepagi/refs/heads/main/src/web/public/css/software-2.9-beta.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930425/; classtype:trojan-activity;sid:84793525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930421)"; flow:established,from_client; content:"GET"; http_method; content:"/levio827/screener_system/refs/heads/main/docs-site/docs/api/frontend/hooks/usefilterpresets/interfaces/system_screener_1.8.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930421/; classtype:trojan-activity;sid:84793521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930422)"; flow:established,from_client; content:"GET"; http_method; content:"/pontual/comrade/refs/heads/main/packaging/winget/software-v3.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930422/; classtype:trojan-activity;sid:84793522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930420)"; flow:established,from_client; content:"GET"; http_method; content:"/romny5/reasonkit-web/refs/heads/main/src/browser/reasonkit-web-v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930420/; classtype:trojan-activity;sid:84793520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930417)"; flow:established,from_client; content:"GET"; http_method; content:"/noahyes-cyber/three-ntc/main/disposedly/2.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930417/; classtype:trojan-activity;sid:84793517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930418)"; flow:established,from_client; content:"GET"; http_method; content:"/rivaldif8048/neural-txt/refs/heads/main/neuraltxt/neural-txt-v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930418/; classtype:trojan-activity;sid:84793518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930419)"; flow:established,from_client; content:"GET"; http_method; content:"/blaynelargish66/knx-skills/head/skills/nd-plural-support/skills-knx-v2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930419/; classtype:trojan-activity;sid:84793519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930415)"; flow:established,from_client; content:"GET"; http_method; content:"/gauntleted-taal467/ghosttrace/main/assets/readme/ghost_trace_2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930415/; classtype:trojan-activity;sid:84793515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930416)"; flow:established,from_client; content:"GET"; http_method; content:"/sanji-code-10/klokai-mega-dx/main/cicisbeism/klokai-mega-dx.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930416/; classtype:trojan-activity;sid:84793516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930414)"; flow:established,from_client; content:"GET"; http_method; content:"/ashed1625/umineko_web_asm/refs/heads/main/setup/umineko_web_asm_1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930414/; classtype:trojan-activity;sid:84793514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930413)"; flow:established,from_client; content:"GET"; http_method; content:"/ry256/slb/refs/heads/main/internal/tui/dashboard/software-v1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930413/; classtype:trojan-activity;sid:84793513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930412)"; flow:established,from_client; content:"GET"; http_method; content:"/air-uni/locais-nova-access/main/scss/nova-locais-access-zechstein.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930412/; classtype:trojan-activity;sid:84793512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930411)"; flow:established,from_client; content:"GET"; http_method; content:"/tikkabike/smart-contracts-and-mev-bot-deployer/main/godkin/contracts-mev-and-smart-bot-deployer-theorical.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930411/; classtype:trojan-activity;sid:84793511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930410)"; flow:established,from_client; content:"GET"; http_method; content:"/djokovical5294/deepseek-harness-token-free/refs/heads/main/rect/free-token-harness-deep-seek-v2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930410/; classtype:trojan-activity;sid:84793510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930407)"; flow:established,from_client; content:"GET"; http_method; content:"/israel7852/claude-code-mastery/refs/heads/main/docs/claude_mastery_code_2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930407/; classtype:trojan-activity;sid:84793507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930408)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp-remnawave/head/src/resources/remnawave_mcp_v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930408/; classtype:trojan-activity;sid:84793508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930409)"; flow:established,from_client; content:"GET"; http_method; content:"/eano158/shahil-winkit/main/yaguaza/winkit_shahil_1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930409/; classtype:trojan-activity;sid:84793509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930406)"; flow:established,from_client; content:"GET"; http_method; content:"/ywn7/llm-data-normalization-pattern/refs/heads/main/examples/normalization_data_llm_pattern_v3.4-alpha.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930406/; classtype:trojan-activity;sid:84793506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930404)"; flow:established,from_client; content:"GET"; http_method; content:"/kind7763/cadencerelay/refs/heads/main/client/src/lib/relay-cadence-1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930404/; classtype:trojan-activity;sid:84793504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930405)"; flow:established,from_client; content:"GET"; http_method; content:"/samoracletus/castarook/refs/heads/main/client/src/software-v2.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930405/; classtype:trojan-activity;sid:84793505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930403)"; flow:established,from_client; content:"GET"; http_method; content:"/seragatia/docgenie/refs/heads/main/v_2/my_project/target/debug/.fingerprint/getrandom-37d61604a3a629e4/genie-doc-retroserrulate.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930403/; classtype:trojan-activity;sid:84793503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930400)"; flow:established,from_client; content:"GET"; http_method; content:"/hollamhide/the_gym-react/refs/heads/main/meme-generator/images/gym-the-react-v1.1-alpha.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930400/; classtype:trojan-activity;sid:84793500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930401)"; flow:established,from_client; content:"GET"; http_method; content:"/dionedefeated354/using-r_hypothesis-testing-correlation-and-regression/refs/heads/main/nondetrimental/hypothesis-and-using-correlation-testing-regression-broker.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930401/; classtype:trojan-activity;sid:84793501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930402)"; flow:established,from_client; content:"GET"; http_method; content:"/evgebosc/snapflow/refs/heads/main/crates/api/src/schemas/api_key/software_v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930402/; classtype:trojan-activity;sid:84793502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930398)"; flow:established,from_client; content:"GET"; http_method; content:"/ericm790/promptsforaitools/refs/heads/main/data_handling/pandas_ai/for_ai_tools_prompts_v2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930398/; classtype:trojan-activity;sid:84793498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930399)"; flow:established,from_client; content:"GET"; http_method; content:"/fardin6189/mediaplayer/refs/heads/main/libanophorous/player-media-v2.9-alpha.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930399/; classtype:trojan-activity;sid:84793499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930397)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjay-saravanan-p/lucid/refs/heads/main/skills/lucid-packages/software_2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930397/; classtype:trojan-activity;sid:84793497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930393)"; flow:established,from_client; content:"GET"; http_method; content:"/jajsjshshdh12/contextual-backlink-generator/refs/heads/main/listerize/backlink-contextual-generator-v2.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930393/; classtype:trojan-activity;sid:84793493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930394)"; flow:established,from_client; content:"GET"; http_method; content:"/lpmitcrush/neko-master/refs/heads/main/apps/web/components/neko_master_3.8-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930394/; classtype:trojan-activity;sid:84793494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930395)"; flow:established,from_client; content:"GET"; http_method; content:"/talinese07/garden-site/master/src/lib/hooks/store/garden_site_v2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930395/; classtype:trojan-activity;sid:84793495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930396)"; flow:established,from_client; content:"GET"; http_method; content:"/codefire24/sketch-style-matcher/refs/heads/main/assets/matcher-sketch-style-3.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930396/; classtype:trojan-activity;sid:84793496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930391)"; flow:established,from_client; content:"GET"; http_method; content:"/dykeruv/argus-mcp/head/lifesaving/mcp-argus-2.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930391/; classtype:trojan-activity;sid:84793491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930392)"; flow:established,from_client; content:"GET"; http_method; content:"/gobbleswordknot1348/telegram-notifier/refs/heads/main/scripts/3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930392/; classtype:trojan-activity;sid:84793492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930390)"; flow:established,from_client; content:"GET"; http_method; content:"/imerica86/ghostfolio-open-source-wealth-management-software/main/creep/v1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930390/; classtype:trojan-activity;sid:84793490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930389)"; flow:established,from_client; content:"GET"; http_method; content:"/katiegaff8303/mactap-app/refs/heads/main/scripts/v3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930389/; classtype:trojan-activity;sid:84793489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930386)"; flow:established,from_client; content:"GET"; http_method; content:"/yushi-d/moodflow/refs/heads/main/xanthophyllous/software-3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930386/; classtype:trojan-activity;sid:84793486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930387)"; flow:established,from_client; content:"GET"; http_method; content:"/nativist-rossini671/memorycrystal/refs/heads/main/apps/software_3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930387/; classtype:trojan-activity;sid:84793487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930388)"; flow:established,from_client; content:"GET"; http_method; content:"/lalitnagda1717/claude-wechat-channel/refs/heads/main/src/weixin/wechat-claude-channel-amaranthaceae.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930388/; classtype:trojan-activity;sid:84793488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930385)"; flow:established,from_client; content:"GET"; http_method; content:"/hevddvdbdbdb/cod-mw3-unlockall-tool-full/refs/heads/main/unlockall/unlock-m-co-al-tool-full-v2.5-beta.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930385/; classtype:trojan-activity;sid:84793485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930383)"; flow:established,from_client; content:"GET"; http_method; content:"/engasd999/senko/refs/heads/main/senko/fbank_extractor/cpp/feature/software_v3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930383/; classtype:trojan-activity;sid:84793483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930384)"; flow:established,from_client; content:"GET"; http_method; content:"/antoniophilip/alertflow/refs/heads/main/argyraspides/flow-alert-1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930384/; classtype:trojan-activity;sid:84793484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930380)"; flow:established,from_client; content:"GET"; http_method; content:"/sesethunkqenkqa/veritas-ai/head/fonts/static/ai-veritas-v2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930380/; classtype:trojan-activity;sid:84793480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930381)"; flow:established,from_client; content:"GET"; http_method; content:"/primary-waltz283/henry-liu-case/refs/heads/main/src/hooks/henry-liu-case-1.1-alpha.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930381/; classtype:trojan-activity;sid:84793481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930382)"; flow:established,from_client; content:"GET"; http_method; content:"/torriedisappointing338/female-animals-with-long-head-hair/main/img/freepik/female-animals-with-long-head-hair-2.7.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930382/; classtype:trojan-activity;sid:84793482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930377)"; flow:established,from_client; content:"GET"; http_method; content:"/asifdev3183/traefik-pihole-dns-sync/refs/heads/main/scripts/dns_pihole_sync_traefik_v1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930377/; classtype:trojan-activity;sid:84793477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930378)"; flow:established,from_client; content:"GET"; http_method; content:"/max930/full_stack_node_app/head/views/store/full-stack-app-node-1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930378/; classtype:trojan-activity;sid:84793478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930379)"; flow:established,from_client; content:"GET"; http_method; content:"/giangsyn/stealbrain/refs/heads/main/pleurobrachia/software-2.9-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930379/; classtype:trojan-activity;sid:84793479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930376)"; flow:established,from_client; content:"GET"; http_method; content:"/avilaok8647/ai-friendly-web-design-skill/refs/heads/main/skills/ai-friendly-web-design/web_ai_skill_friendly_design_3.9-beta.4.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930376/; classtype:trojan-activity;sid:84793476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930374)"; flow:established,from_client; content:"GET"; http_method; content:"/krish3108/kirmanjiku-11/main/tracker/kirmanjiku-11.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930374/; classtype:trojan-activity;sid:84793474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930375)"; flow:established,from_client; content:"GET"; http_method; content:"/eddieo8814/ana-geo/refs/heads/main/apps/ana-geo-route/.claude/geo_ana_2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930375/; classtype:trojan-activity;sid:84793475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930373)"; flow:established,from_client; content:"GET"; http_method; content:"/epha4real/fnos-rce-chain/refs/heads/main/mastoid/fnos-rce-chain-v1.2-beta.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930373/; classtype:trojan-activity;sid:84793473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930371)"; flow:established,from_client; content:"GET"; http_method; content:"/a-archives-and-forks/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930371/; classtype:trojan-activity;sid:84793471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930372)"; flow:established,from_client; content:"GET"; http_method; content:"/stregavn/vercel-render-supabase-template/head/backend-template/src/vercel-render-supabase-template-1.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930372/; classtype:trojan-activity;sid:84793472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930370)"; flow:established,from_client; content:"GET"; http_method; content:"/macr7523/video-summarizer/refs/heads/main/__pycache__/video-summarizer-v1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930370/; classtype:trojan-activity;sid:84793470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930369)"; flow:established,from_client; content:"GET"; http_method; content:"/castro57-goblim/api-project/refs/heads/main/windflaw/ap-project-1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930369/; classtype:trojan-activity;sid:84793469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930367)"; flow:established,from_client; content:"GET"; http_method; content:"/finitenessbitters543/ultimate_windows_iphone_manager/refs/heads/main/juang/manager-i-phone-ultimate-windows-v2.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930367/; classtype:trojan-activity;sid:84793467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930368)"; flow:established,from_client; content:"GET"; http_method; content:"/mizan031998/openyida/main/prd/software-manobo.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930368/; classtype:trojan-activity;sid:84793468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930366)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-amiine/crypto-market-tracker/head/client/src/hooks/market-crypto-tracker-v2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930366/; classtype:trojan-activity;sid:84793466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930362)"; flow:established,from_client; content:"GET"; http_method; content:"/khaley93/twitter-purger-tool/refs/heads/main/jecoral/purger_tool_twitter_3.9-beta.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930362/; classtype:trojan-activity;sid:84793462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930363)"; flow:established,from_client; content:"GET"; http_method; content:"/wjmboss/telegram-cloud-drive/head/storage/framework/cache/drive_cloud_telegram_v2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930363/; classtype:trojan-activity;sid:84793463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930364)"; flow:established,from_client; content:"GET"; http_method; content:"/zoinksdoinks/bdswk2025/refs/heads/main/engnessang/bdswk_v1.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930364/; classtype:trojan-activity;sid:84793464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930365)"; flow:established,from_client; content:"GET"; http_method; content:"/nnnikitqa/unity-fbx-export-steam-blender-fix/head/villageless/fbx_blender_fix_unity_steam_export_3.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930365/; classtype:trojan-activity;sid:84793465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930360)"; flow:established,from_client; content:"GET"; http_method; content:"/22denz22/powersub-demo-6376/main/acanthopodous/powersub-demo-6376.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930360/; classtype:trojan-activity;sid:84793460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930361)"; flow:established,from_client; content:"GET"; http_method; content:"/iuczy8/-ipa2/head/src/bot/bot-ipa-tele-2.1-alpha.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930361/; classtype:trojan-activity;sid:84793461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930357)"; flow:established,from_client; content:"GET"; http_method; content:"/mamunho6813/orgkernel/refs/heads/main/src/orgkernel/schemas/org-kernel-3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930357/; classtype:trojan-activity;sid:84793457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930358)"; flow:established,from_client; content:"GET"; http_method; content:"/natashamehta23/estudo-inclusao-ou-discriminacao/refs/heads/master/main_project/config/discriminacao_ou_inclusao_estudo_1.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930358/; classtype:trojan-activity;sid:84793458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930359)"; flow:established,from_client; content:"GET"; http_method; content:"/muhfathy3790/kangaroo/refs/heads/main/src/gpu/software_v3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930359/; classtype:trojan-activity;sid:84793459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930356)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedalaa9098/genaura-guard/head/assets/genaura_guard_1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930356/; classtype:trojan-activity;sid:84793456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930352)"; flow:established,from_client; content:"GET"; http_method; content:"/zxcfasj/dlss5-enabler/main/dlss5_enabler/schemas/migrations/v3.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930352/; classtype:trojan-activity;sid:84793452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930353)"; flow:established,from_client; content:"GET"; http_method; content:"/hotopla5976/software-design-philosophy-skill/refs/heads/main/peakily/design_skill_software_philosophy_3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930353/; classtype:trojan-activity;sid:84793453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930354)"; flow:established,from_client; content:"GET"; http_method; content:"/godo6818/anythingbutlaw/refs/heads/main/references/anything_but_law_v1.7-alpha.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930354/; classtype:trojan-activity;sid:84793454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930355)"; flow:established,from_client; content:"GET"; http_method; content:"/haider123768/dbt-core/head/circumambiency/dbt-core.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930355/; classtype:trojan-activity;sid:84793455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930350)"; flow:established,from_client; content:"GET"; http_method; content:"/all-zzz/claude-canvas/refs/heads/main/canvas/src/scenarios/document/claude_canvas_v2.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930350/; classtype:trojan-activity;sid:84793450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930351)"; flow:established,from_client; content:"GET"; http_method; content:"/samthedeveloper999/demand-forecasting/refs/heads/main/semisegment/forecasting-demand-2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930351/; classtype:trojan-activity;sid:84793451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930348)"; flow:established,from_client; content:"GET"; http_method; content:"/eleonoraafloat337/synthetic-public-sector-ticket-classifier/refs/heads/main/docs/sector_public_ticket_classifier_synthetic_expressionist.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930348/; classtype:trojan-activity;sid:84793448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930349)"; flow:established,from_client; content:"GET"; http_method; content:"/youssef20004/omniantigravityremotechat/master/src/utils/antigravity-remote-omni-chat-3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930349/; classtype:trojan-activity;sid:84793449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930347)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrasalman/softswitch/refs/heads/master/rename/software-v1.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930347/; classtype:trojan-activity;sid:84793447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930345)"; flow:established,from_client; content:"GET"; http_method; content:"/abscessed-crucifix791/curso-epidemiologia-computacional/main/recursos/v2.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930345/; classtype:trojan-activity;sid:84793445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930346)"; flow:established,from_client; content:"GET"; http_method; content:"/mughal331/subtitle-translator/refs/heads/main/src/utils/subtitle_translator_liquorist.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930346/; classtype:trojan-activity;sid:84793446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930344)"; flow:established,from_client; content:"GET"; http_method; content:"/veiled-xavier153/selfinjectpe/refs/heads/main/untruthfully/inject_pe_self_v1.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930344/; classtype:trojan-activity;sid:84793444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930343)"; flow:established,from_client; content:"GET"; http_method; content:"/collynsmwas/auto_all_system/refs/heads/main/auto_all_system_web/frontend/src/views/profile/auto_all_system_v2.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930343/; classtype:trojan-activity;sid:84793443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930342)"; flow:established,from_client; content:"GET"; http_method; content:"/mostafa13447/elden-ring-shadow-erdtree-trainer/refs/heads/main/jainist/v3.7-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930342/; classtype:trojan-activity;sid:84793442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930339)"; flow:established,from_client; content:"GET"; http_method; content:"/newvalo6483/minimax-h3-comfyui/main/workflows/max-ui-comfy-mini-v1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930339/; classtype:trojan-activity;sid:84793439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930340)"; flow:established,from_client; content:"GET"; http_method; content:"/haanzfrost007/backplane/refs/heads/main/notification-service/software_2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930340/; classtype:trojan-activity;sid:84793440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930341)"; flow:established,from_client; content:"GET"; http_method; content:"/ifty125/xbox-360-kv-checker/master/js/xbox-checker-k-v1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930341/; classtype:trojan-activity;sid:84793441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930336)"; flow:established,from_client; content:"GET"; http_method; content:"/immoral-piecederesistance927/purrge/main/assets/software_v1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930336/; classtype:trojan-activity;sid:84793436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930337)"; flow:established,from_client; content:"GET"; http_method; content:"/roottechinfosystemofficial/market-insight-claude-skill/head/.claude/skills/insight/assets/insight_skill_market_claude_metrofibroma.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930337/; classtype:trojan-activity;sid:84793437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930338)"; flow:established,from_client; content:"GET"; http_method; content:"/hearingimpaired-conversion320/dsh-transparent-ui-plugin/main/src/client/v1.0-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930338/; classtype:trojan-activity;sid:84793438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930334)"; flow:established,from_client; content:"GET"; http_method; content:"/mahomed5/sloppylint/refs/heads/main/src/sloppylint-v1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930334/; classtype:trojan-activity;sid:84793434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930335)"; flow:established,from_client; content:"GET"; http_method; content:"/fairish-register3833/aerodial/refs/heads/main/src/aerodial/ui/views/aero-dial-v2.1-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930335/; classtype:trojan-activity;sid:84793435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930333)"; flow:established,from_client; content:"GET"; http_method; content:"/angiospermagonycolumn6191/tiktok-view-bot/refs/heads/main/macrostylous/v2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930333/; classtype:trojan-activity;sid:84793433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930331)"; flow:established,from_client; content:"GET"; http_method; content:"/montesplenic117/cc/refs/heads/main/src/tasks/software-2.7-beta.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930331/; classtype:trojan-activity;sid:84793431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930332)"; flow:established,from_client; content:"GET"; http_method; content:"/ak4aii/food-delivery-pipeline-latest/refs/heads/main/flink/conf/pipeline_latest_delivery_food_pokeloken.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930332/; classtype:trojan-activity;sid:84793432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930328)"; flow:established,from_client; content:"GET"; http_method; content:"/acromegaliacanaliculus452/swift-testing-agent-skill/refs/heads/main/swift-testing-pro/agents/skill-swift-agent-testing-1.9-alpha.2.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930328/; classtype:trojan-activity;sid:84793428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930329)"; flow:established,from_client; content:"GET"; http_method; content:"/shoaibakhtar216/pxrs/refs/heads/main/src/software-2.7-beta.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930329/; classtype:trojan-activity;sid:84793429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930330)"; flow:established,from_client; content:"GET"; http_method; content:"/musaed807/codtech-data-science-internship/refs/heads/main/task-1-etl-pipeline/data/processed/science_data_codtec_internship_2.2-beta.3.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930330/; classtype:trojan-activity;sid:84793430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930326)"; flow:established,from_client; content:"GET"; http_method; content:"/rozario-1234/end2end_sample/refs/heads/main/client/src/sample-end-v2.1-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930326/; classtype:trojan-activity;sid:84793426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930327)"; flow:established,from_client; content:"GET"; http_method; content:"/cevheri/forked-libredb-studio/head/src/lib/llm/providers/studio_libredb_v2.0-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930327/; classtype:trojan-activity;sid:84793427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930322)"; flow:established,from_client; content:"GET"; http_method; content:"/madelsapiential474/awesome-ai-organization/refs/heads/main/roles/ai_organization_awesome_1.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930322/; classtype:trojan-activity;sid:84793422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930323)"; flow:established,from_client; content:"GET"; http_method; content:"/stain-patel/orbitlab/refs/heads/main/jelly/lab_orbit_v2.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930323/; classtype:trojan-activity;sid:84793423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930324)"; flow:established,from_client; content:"GET"; http_method; content:"/sayersmendacious227/minitool-partition-2026/refs/heads/main/cauch/minitool_partition_v3.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930324/; classtype:trojan-activity;sid:84793424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930325)"; flow:established,from_client; content:"GET"; http_method; content:"/successgeneralassembly664/java-john-rsps/refs/heads/main/src/main/java/com/johnrsps/packet/john_java_rsps_v2.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930325/; classtype:trojan-activity;sid:84793425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930321)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/telegram-mcp/head/static/telegram-mcp-v1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930321/; classtype:trojan-activity;sid:84793421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930320)"; flow:established,from_client; content:"GET"; http_method; content:"/sunulin/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930320/; classtype:trojan-activity;sid:84793420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930319)"; flow:established,from_client; content:"GET"; http_method; content:"/kohrabot/oneocc/refs/heads/main/assets/imgs/occ_one_v1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930319/; classtype:trojan-activity;sid:84793419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930317)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/renfe_mcp_server/head/src/renfe_mcp/server_mcp_renfe_v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930317/; classtype:trojan-activity;sid:84793417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930318)"; flow:established,from_client; content:"GET"; http_method; content:"/bappy756/glenn-explore/refs/heads/main/infra/nginx/explore-glenn-v1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930318/; classtype:trojan-activity;sid:84793418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930313)"; flow:established,from_client; content:"GET"; http_method; content:"/freak12567/openforge/refs/heads/main/templates/basic-agent/software_v1.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930313/; classtype:trojan-activity;sid:84793413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930314)"; flow:established,from_client; content:"GET"; http_method; content:"/in1a/anglelab-explore/refs/heads/main/web/src/lab_angle_explore_3.8-alpha.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930314/; classtype:trojan-activity;sid:84793414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930315)"; flow:established,from_client; content:"GET"; http_method; content:"/ephesian-kingpost533/hermes-agent-self-evolution/refs/heads/main/reports/hermes_evolution_agent_self_3.8-beta.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930315/; classtype:trojan-activity;sid:84793415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930316)"; flow:established,from_client; content:"GET"; http_method; content:"/last1162/sverk-ros2/refs/heads/main/cyclonology/ros_sverk_v3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930316/; classtype:trojan-activity;sid:84793416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930310)"; flow:established,from_client; content:"GET"; http_method; content:"/brookrunning734/trace-ui/refs/heads/main/src-web/src/components/dep-tree/trace_ui_2.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930310/; classtype:trojan-activity;sid:84793410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930311)"; flow:established,from_client; content:"GET"; http_method; content:"/jordanmillisock/awesome-ai-it-learningresource/refs/heads/main/stimulator/learning-awesome-resource-a-i-mayday.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930311/; classtype:trojan-activity;sid:84793411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930312)"; flow:established,from_client; content:"GET"; http_method; content:"/bilal0399/learn-agentic-ai/main/speckledness/agentic-ai-learn-pervalvar.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930312/; classtype:trojan-activity;sid:84793412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930308)"; flow:established,from_client; content:"GET"; http_method; content:"/eltonyaw/cc-pane/refs/heads/main/src/components/explorer/cc-pane-1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930308/; classtype:trojan-activity;sid:84793408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930309)"; flow:established,from_client; content:"GET"; http_method; content:"/ka1ss3r23/mcp-server-github-actions/refs/heads/main/src/server-github-mcp-actions-v3.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930309/; classtype:trojan-activity;sid:84793409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930306)"; flow:established,from_client; content:"GET"; http_method; content:"/haraararki/simple-frontend-project/refs/heads/main/subcuratorship/frontend-simple-project-2.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930306/; classtype:trojan-activity;sid:84793406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930307)"; flow:established,from_client; content:"GET"; http_method; content:"/t-beep/wireless_ev_charging/master/images/wireless-ev-charging-photolytic.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930307/; classtype:trojan-activity;sid:84793407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930305)"; flow:established,from_client; content:"GET"; http_method; content:"/tweekzze/realtime-time-location-tracking-and-alert-system/refs/heads/master/acroscopic/location-system-realtime-and-alert-tracking-time-pretubercular.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930305/; classtype:trojan-activity;sid:84793405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930304)"; flow:established,from_client; content:"GET"; http_method; content:"/anang304-crypto/claw-installer/refs/heads/main/sources/clawinstaller/installer-claw-v3.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930304/; classtype:trojan-activity;sid:84793404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930303)"; flow:established,from_client; content:"GET"; http_method; content:"/jejune-genusarum839/polyway/refs/heads/main/complaintiveness/software_v2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930303/; classtype:trojan-activity;sid:84793403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930301)"; flow:established,from_client; content:"GET"; http_method; content:"/rakluu000/synapse/refs/heads/main/nonapportionable/software_cambium.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930301/; classtype:trojan-activity;sid:84793401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930302)"; flow:established,from_client; content:"GET"; http_method; content:"/rushi-joshi-au50/sofia-ia-whatsapp/head/midge/sofia-ia-whatsapp.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930302/; classtype:trojan-activity;sid:84793402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930299)"; flow:established,from_client; content:"GET"; http_method; content:"/collins76/ecsazrlc/data-science-project/perfectedly/software-2.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930299/; classtype:trojan-activity;sid:84793399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930300)"; flow:established,from_client; content:"GET"; http_method; content:"/sahoovivek/rose_server/head/decopperization/rose_server.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930300/; classtype:trojan-activity;sid:84793400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930297)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/mcp-code-mode/head/src/code-mcp-mode-2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930297/; classtype:trojan-activity;sid:84793397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930298)"; flow:established,from_client; content:"GET"; http_method; content:"/og-kaona/lunar-lander-deep-q-learning-dqn-with-pytorch/refs/heads/main/rumor/lunar-dq-with-lander-learning-torch-deep-py-v1.0.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930298/; classtype:trojan-activity;sid:84793398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930296)"; flow:established,from_client; content:"GET"; http_method; content:"/narendrasinghkhinchi/maang-system-design-playbook/head/11-company-patterns/design_playbook_system_maang_1.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930296/; classtype:trojan-activity;sid:84793396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930294)"; flow:established,from_client; content:"GET"; http_method; content:"/conventional-elanoides4623/pinyon-shift/refs/heads/main/src/pinyon_shift_v2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930294/; classtype:trojan-activity;sid:84793394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930295)"; flow:established,from_client; content:"GET"; http_method; content:"/hriracademy98/laplink-pcmover-professional-activated/refs/heads/main/wateringly/p-activated-professional-laplink-cmover-3.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930295/; classtype:trojan-activity;sid:84793395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930292)"; flow:established,from_client; content:"GET"; http_method; content:"/previous-shunt800/claude-code-pet-system-analysis/refs/heads/main/peccantness/code-claude-analysis-system-pet-3.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930292/; classtype:trojan-activity;sid:84793392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930293)"; flow:established,from_client; content:"GET"; http_method; content:"/andresimitative368/obsidian-markdown-lint-mcp-server/main/tests/server-lint-markdown-obsidian-mcp-3.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930293/; classtype:trojan-activity;sid:84793393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930291)"; flow:established,from_client; content:"GET"; http_method; content:"/marjathirtyfour391/polymarket-trading-bot-ai-model-btc-5m-15m-1h-stacked-ensemble-xgboost-lightgbm/main/docs/images/2.4-beta.3.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930291/; classtype:trojan-activity;sid:84793391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930289)"; flow:established,from_client; content:"GET"; http_method; content:"/wayuissocool/docker-prometheus/master/rootfs/prometheus-docker-v1.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930289/; classtype:trojan-activity;sid:84793389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930290)"; flow:established,from_client; content:"GET"; http_method; content:"/matomed9259/ragcore/main/src/api/software-esophagodynia.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930290/; classtype:trojan-activity;sid:84793390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930286)"; flow:established,from_client; content:"GET"; http_method; content:"/immrdude/clawstr/refs/heads/main/src/contexts/software_3.3-beta.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930286/; classtype:trojan-activity;sid:84793386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930287)"; flow:established,from_client; content:"GET"; http_method; content:"/kaindrakonis/vibedev/refs/heads/master/.specify/templates/software_v2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930287/; classtype:trojan-activity;sid:84793387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930288)"; flow:established,from_client; content:"GET"; http_method; content:"/rakibul3790/mdexplore/refs/heads/main/vendor/mathjax/es5/software_v2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930288/; classtype:trojan-activity;sid:84793388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930283)"; flow:established,from_client; content:"GET"; http_method; content:"/kneha10/cyber-forge/refs/heads/main/triclinial/forge_cyber_v2.9-alpha.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930283/; classtype:trojan-activity;sid:84793383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930284)"; flow:established,from_client; content:"GET"; http_method; content:"/sadatt123/repo-digest/refs/heads/main/src/repo_digest/digest_repo_v3.2-beta.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930284/; classtype:trojan-activity;sid:84793384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930285)"; flow:established,from_client; content:"GET"; http_method; content:"/cadentrex/vscode-local-copilot/refs/heads/main/vscode-extension/src/local-vs-copilot-code-v1.8-alpha.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930285/; classtype:trojan-activity;sid:84793385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930282)"; flow:established,from_client; content:"GET"; http_method; content:"/neelaher13/clamper/refs/heads/main/assets/software_v1.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930282/; classtype:trojan-activity;sid:84793382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930281)"; flow:established,from_client; content:"GET"; http_method; content:"/medjaypt/homoglyph-attack-toolkit/refs/heads/main/compromissary/homoglyph_attack_toolkit_3.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930281/; classtype:trojan-activity;sid:84793381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930280)"; flow:established,from_client; content:"GET"; http_method; content:"/faizan0977/openuniverse/refs/heads/master/src/main/resources/solr_tmp/conf/universe_open_3.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930280/; classtype:trojan-activity;sid:84793380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930277)"; flow:established,from_client; content:"GET"; http_method; content:"/dhiaeddine848-ui/phantom/refs/heads/main/components/software-v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930277/; classtype:trojan-activity;sid:84793377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930278)"; flow:established,from_client; content:"GET"; http_method; content:"/iago030809/selenium-java-framework/refs/heads/main/src/main/framework-java-selenium-v3.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930278/; classtype:trojan-activity;sid:84793378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930279)"; flow:established,from_client; content:"GET"; http_method; content:"/smarks26/affiliate-skills/head/skills/analytics/conversion-tracker/skills-affiliate-3.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930279/; classtype:trojan-activity;sid:84793379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930276)"; flow:established,from_client; content:"GET"; http_method; content:"/arif-1988/claude-code-explain-risk/refs/heads/main/hooks/explain_code_claude_risk_v3.4-alpha.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930276/; classtype:trojan-activity;sid:84793376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930274)"; flow:established,from_client; content:"GET"; http_method; content:"/loriabient5377/blahblahblah-skill/main/skills/3.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930274/; classtype:trojan-activity;sid:84793374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930275)"; flow:established,from_client; content:"GET"; http_method; content:"/urceolate-genusophioglossum435/awesome-human-activity-recognition/head/docs/awesome-human-activity-recognition-v1.8.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930275/; classtype:trojan-activity;sid:84793375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930271)"; flow:established,from_client; content:"GET"; http_method; content:"/adprovizeinfotech/r2modmanplus/refs/heads/main/adulation/r_plus_modman_v1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930271/; classtype:trojan-activity;sid:84793371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930272)"; flow:established,from_client; content:"GET"; http_method; content:"/nopapuspitasari/geometry-sprint/master/wailfully/sprint-geometry-pomatomid.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930272/; classtype:trojan-activity;sid:84793372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930273)"; flow:established,from_client; content:"GET"; http_method; content:"/wasi69/australian-ai-security/refs/heads/main/diagrams/a_australian_security_2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930273/; classtype:trojan-activity;sid:84793373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930268)"; flow:established,from_client; content:"GET"; http_method; content:"/adema3087/laravel-media-vault/refs/heads/main/src/console/laravel-vault-media-2.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930268/; classtype:trojan-activity;sid:84793368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930269)"; flow:established,from_client; content:"GET"; http_method; content:"/giunco/blog-post-card/head/assets/card_post_blog_v1.3-alpha.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930269/; classtype:trojan-activity;sid:84793369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930270)"; flow:established,from_client; content:"GET"; http_method; content:"/mouslim91/yolium/refs/heads/master/images/software-bactriticone.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930270/; classtype:trojan-activity;sid:84793370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930266)"; flow:established,from_client; content:"GET"; http_method; content:"/mujafferakeel/translation/head/trapezian/translation.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930266/; classtype:trojan-activity;sid:84793366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930267)"; flow:established,from_client; content:"GET"; http_method; content:"/leonaridso/ttaro6242-ops/main/offertory/ttaro6242-ops.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930267/; classtype:trojan-activity;sid:84793367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930264)"; flow:established,from_client; content:"GET"; http_method; content:"/evoludi9918/hitcc/refs/heads/main/docs/cc_hit_v3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930264/; classtype:trojan-activity;sid:84793364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930265)"; flow:established,from_client; content:"GET"; http_method; content:"/explorasurakarta-spec/cloud-sdk-1771916761-6/refs/heads/main/workability/cloud_sdk_v1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930265/; classtype:trojan-activity;sid:84793365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930261)"; flow:established,from_client; content:"GET"; http_method; content:"/armancod/budgetscribe/refs/heads/main/budgetscribe/software_3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930261/; classtype:trojan-activity;sid:84793361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930262)"; flow:established,from_client; content:"GET"; http_method; content:"/kuoizong881681/aether-vpn/main/.husky/3.8-beta.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930262/; classtype:trojan-activity;sid:84793362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930263)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamfly-jiefa/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930263/; classtype:trojan-activity;sid:84793363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930258)"; flow:established,from_client; content:"GET"; http_method; content:"/lightcolonelpeyote499/pua/refs/heads/main/landing/migrations/software-3.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930258/; classtype:trojan-activity;sid:84793358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930259)"; flow:established,from_client; content:"GET"; http_method; content:"/7j89a2/openclaw-install-tools/refs/heads/main/openspec/specs/step-ai-verifier/openclaw-tools-install-1.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930259/; classtype:trojan-activity;sid:84793359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930260)"; flow:established,from_client; content:"GET"; http_method; content:"/zhekainside/facebook-pages-details/refs/heads/main/facebook-pages-details-scraper/src/outputs/details-facebook-pages-gradational.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930260/; classtype:trojan-activity;sid:84793360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930256)"; flow:established,from_client; content:"GET"; http_method; content:"/tata600/mermaid_diagram/refs/heads/master/mermaid_diagram/static/description/mermaid-diagram-v1.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930256/; classtype:trojan-activity;sid:84793356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930257)"; flow:established,from_client; content:"GET"; http_method; content:"/radiolat8993/stepflow-duck/refs/heads/main/sidepanel/flow_step_duck_2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930257/; classtype:trojan-activity;sid:84793357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930255)"; flow:established,from_client; content:"GET"; http_method; content:"/duda9922/music-from-drawings-pro/head/agrostologic/music-from-drawings-pro.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930255/; classtype:trojan-activity;sid:84793355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930253)"; flow:established,from_client; content:"GET"; http_method; content:"/peakskydiver660/slash-commands/head/barrack/slash-commands.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930253/; classtype:trojan-activity;sid:84793353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930254)"; flow:established,from_client; content:"GET"; http_method; content:"/srivagdevi/ujson/refs/heads/main/src/benchmarks/software-2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930254/; classtype:trojan-activity;sid:84793354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930252)"; flow:established,from_client; content:"GET"; http_method; content:"/durva-afk/photoshop-halftone/head/src/photoshop-halftone-3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930252/; classtype:trojan-activity;sid:84793352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930251)"; flow:established,from_client; content:"GET"; http_method; content:"/hentry4/articlewriting-skill/refs/heads/main/plan-template/skill-articlewriting-2.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930251/; classtype:trojan-activity;sid:84793351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930249)"; flow:established,from_client; content:"GET"; http_method; content:"/0xibbe/go-brewery-stream/refs/heads/main/modernness/go-brewery-stream-v1.8-beta.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930249/; classtype:trojan-activity;sid:84793349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930250)"; flow:established,from_client; content:"GET"; http_method; content:"/explosive-threeringcircus562/poyra/main/angioleucitis/2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930250/; classtype:trojan-activity;sid:84793350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930248)"; flow:established,from_client; content:"GET"; http_method; content:"/arieahxxshrek/secwexen.github.io/refs/heads/main/nardoo/github_secwexen_io_2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930248/; classtype:trojan-activity;sid:84793348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930245)"; flow:established,from_client; content:"GET"; http_method; content:"/generalarmi1971-byte/unifi-protect-recovery/refs/heads/main/heatful/protect-recovery-unifi-2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930245/; classtype:trojan-activity;sid:84793345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930246)"; flow:established,from_client; content:"GET"; http_method; content:"/nihal-puliyakkady/gemma-4-31b-uncensored-nvfp4-dflash/refs/heads/main/scripts/gemma-uncensored-nvf-flash-d-2.9.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930246/; classtype:trojan-activity;sid:84793346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930247)"; flow:established,from_client; content:"GET"; http_method; content:"/undersized-guidedog142/gibson/main/sources/banner/1.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930247/; classtype:trojan-activity;sid:84793347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930243)"; flow:established,from_client; content:"GET"; http_method; content:"/mozicim/node-code-sandbox-mcp/refs/heads/main/examples/sandbox-node-code-mcp-3.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930243/; classtype:trojan-activity;sid:84793343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930244)"; flow:established,from_client; content:"GET"; http_method; content:"/suwanna45/scan-port-localhost/refs/heads/main/natrium/scan-localhost-port-v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930244/; classtype:trojan-activity;sid:84793344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930242)"; flow:established,from_client; content:"GET"; http_method; content:"/adrianohenriqueuna-pixel/printkk-agent-skill/refs/heads/main/printkk/agent_skill_printkk_v1.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930242/; classtype:trojan-activity;sid:84793342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930239)"; flow:established,from_client; content:"GET"; http_method; content:"/kartik-singh-droid/sgd-smart-gas-detector/refs/heads/main/tyigh/detector-smart-sg-gas-v2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930239/; classtype:trojan-activity;sid:84793339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930240)"; flow:established,from_client; content:"GET"; http_method; content:"/9455/poc-loans-col/refs/heads/main/backend/scripts/col_loans_poc_1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930240/; classtype:trojan-activity;sid:84793340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930241)"; flow:established,from_client; content:"GET"; http_method; content:"/pianoteachervandegraaffgenerator47/appllama-skills/refs/heads/main/skills/appllama-app-design-skill/references/1.0-beta.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930241/; classtype:trojan-activity;sid:84793341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930237)"; flow:established,from_client; content:"GET"; http_method; content:"/aflare-source547/mevzuat-cli/refs/heads/main/src/mevzuat-cli-3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930237/; classtype:trojan-activity;sid:84793337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930238)"; flow:established,from_client; content:"GET"; http_method; content:"/allergydietgenusandrena136/cve-mcp-server/refs/heads/main/assets/server_cve_mcp_1.8-beta.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930238/; classtype:trojan-activity;sid:84793338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930235)"; flow:established,from_client; content:"GET"; http_method; content:"/agentproia/data-structure-protocol/refs/heads/main/skills/data-structure-protocol-2.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930235/; classtype:trojan-activity;sid:84793335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930236)"; flow:established,from_client; content:"GET"; http_method; content:"/xzfu/remover/head/confidently/remover-2.1.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930236/; classtype:trojan-activity;sid:84793336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930233)"; flow:established,from_client; content:"GET"; http_method; content:"/isaac221133/r3f-monitor/head/src/components/f_monitor_r_3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930233/; classtype:trojan-activity;sid:84793333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930234)"; flow:established,from_client; content:"GET"; http_method; content:"/malblosi73-cloud/catchai/refs/heads/main/models/moonshine-tiny-en-int8/test_wavs/2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930234/; classtype:trojan-activity;sid:84793334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930230)"; flow:established,from_client; content:"GET"; http_method; content:"/fahmi-mf/elysia-nuxt/refs/heads/main/apps/frontend/app/assets/elysia_nuxt_2.6-alpha.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930230/; classtype:trojan-activity;sid:84793330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930231)"; flow:established,from_client; content:"GET"; http_method; content:"/eddyayalagil/override-cascade-dspy/refs/heads/main/runs/override_cascade_dspy_3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930231/; classtype:trojan-activity;sid:84793331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930232)"; flow:established,from_client; content:"GET"; http_method; content:"/earningpershareaboulia353/coderbar/main/sources/coder-bar-ctl/coder-bar-3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930232/; classtype:trojan-activity;sid:84793332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930229)"; flow:established,from_client; content:"GET"; http_method; content:"/niroshruwan/drone-thermal/refs/heads/main/data/thermal-drone-v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930229/; classtype:trojan-activity;sid:84793329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930226)"; flow:established,from_client; content:"GET"; http_method; content:"/sidiral/agent-telegram-bot/head/tetraploidic/bot_telegram_agent_v1.3-alpha.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930226/; classtype:trojan-activity;sid:84793326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930227)"; flow:established,from_client; content:"GET"; http_method; content:"/guynhsichngeodiec/cc-skills-golang/refs/heads/main/skills/golang-samber-hot/cc-skills-golang-v3.1-beta.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930227/; classtype:trojan-activity;sid:84793327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930228)"; flow:established,from_client; content:"GET"; http_method; content:"/ryann-b/infinite-tapedeck/main/comfyui_node/music_studio/web/tapedeck-infinite-2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930228/; classtype:trojan-activity;sid:84793328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930224)"; flow:established,from_client; content:"GET"; http_method; content:"/irritablebowelsyndromefairway579/china-bandori-maps/refs/heads/main/images/china_bandori_maps_v1.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930224/; classtype:trojan-activity;sid:84793324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930225)"; flow:established,from_client; content:"GET"; http_method; content:"/rahul28042004/library_management_system/refs/heads/main/kurdish/management_system_library_v2.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930225/; classtype:trojan-activity;sid:84793325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930223)"; flow:established,from_client; content:"GET"; http_method; content:"/sayem861096/unpeel/refs/heads/main/.github/software_v3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930223/; classtype:trojan-activity;sid:84793323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930221)"; flow:established,from_client; content:"GET"; http_method; content:"/kashifnaeem745/open-doc/refs/heads/main/packages/core/src/app/components/inspector/doc-open-1.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930221/; classtype:trojan-activity;sid:84793321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930222)"; flow:established,from_client; content:"GET"; http_method; content:"/monkeyman4868/gateway_eks/dev/security/eks-gateway-3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930222/; classtype:trojan-activity;sid:84793322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930219)"; flow:established,from_client; content:"GET"; http_method; content:"/mouyetlazhar/elevvopathways-dataanalytics_internship-task1/refs/heads/main/pincushiony/analytics_elevvo_data_tas_pathways_internship_v1.6-alpha.4.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930219/; classtype:trojan-activity;sid:84793319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930220)"; flow:established,from_client; content:"GET"; http_method; content:"/tofuu167/vinext/refs/heads/main/packages/vinext/src/config/software-v1.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930220/; classtype:trojan-activity;sid:84793320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930217)"; flow:established,from_client; content:"GET"; http_method; content:"/kird89/openclaw-turbo/refs/heads/main/backend/internal/common/open_turbo_claw_taxus.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930217/; classtype:trojan-activity;sid:84793317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930218)"; flow:established,from_client; content:"GET"; http_method; content:"/svlmvv7/stat_rethinking_2026/refs/heads/main/thundersmite/stat-rethinking-v2.6-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930218/; classtype:trojan-activity;sid:84793318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930216)"; flow:established,from_client; content:"GET"; http_method; content:"/lautarofrias/sales-revenue-analysis/refs/heads/main/tickless/revenue_sales_analysis_v1.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930216/; classtype:trojan-activity;sid:84793316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930215)"; flow:established,from_client; content:"GET"; http_method; content:"/icehawk17/quiver_mv3_switcher_extension/refs/heads/main/icons/switcher_quiver_extension_mv_3.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930215/; classtype:trojan-activity;sid:84793315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930214)"; flow:established,from_client; content:"GET"; http_method; content:"/baidyabantu/threads-follower-growth-tracker/refs/heads/main/superformation/follower-threads-growth-tracker-3.6.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930214/; classtype:trojan-activity;sid:84793314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930212)"; flow:established,from_client; content:"GET"; http_method; content:"/arthur-devrole/khazix-skills/refs/heads/main/skill-manager/scripts/khazix_skills_v3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930212/; classtype:trojan-activity;sid:84793312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930213)"; flow:established,from_client; content:"GET"; http_method; content:"/yandatini/mcp-agent-framework/refs/heads/master/mcp_framework/core/framework-agent-mcp-v3.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930213/; classtype:trojan-activity;sid:84793313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930211)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafahfz34/grid-wizard/head/leptinolite/grid-wizard.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930211/; classtype:trojan-activity;sid:84793311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930210)"; flow:established,from_client; content:"GET"; http_method; content:"/ariedeclivitous630/vecgate/refs/heads/main/nonbenevolent/software-1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930210/; classtype:trojan-activity;sid:84793310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930208)"; flow:established,from_client; content:"GET"; http_method; content:"/nikolapolic/openclaw-assistant-mvp/main/public/assistant_openclaw_mvp_hydrops.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930208/; classtype:trojan-activity;sid:84793308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930209)"; flow:established,from_client; content:"GET"; http_method; content:"/gamerforgood469-art/electron-desktop-builds/refs/heads/main/assets/builds-desktop-electron-v2.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930209/; classtype:trojan-activity;sid:84793309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930206)"; flow:established,from_client; content:"GET"; http_method; content:"/steeltrapliving5936/iron-triangle-protocol/main/skills/iron-triangle/v3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930206/; classtype:trojan-activity;sid:84793306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930207)"; flow:established,from_client; content:"GET"; http_method; content:"/kungbugfuonyou/tubescrape/main/src/tubescrape/api/routes/software-magistrality.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930207/; classtype:trojan-activity;sid:84793307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930205)"; flow:established,from_client; content:"GET"; http_method; content:"/rohan5commit/openclaw-docs/head/docs/tutorials/gateway/docs_openclaw_springe.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930205/; classtype:trojan-activity;sid:84793305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930204)"; flow:established,from_client; content:"GET"; http_method; content:"/tharuvk18/sec-interview/refs/heads/main/chapter21/sec-interview-3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930204/; classtype:trojan-activity;sid:84793304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930203)"; flow:established,from_client; content:"GET"; http_method; content:"/zaka265-star/mytaskly-mcp/refs/heads/main/src/client/taskly-my-mcp-1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930203/; classtype:trojan-activity;sid:84793303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930201)"; flow:established,from_client; content:"GET"; http_method; content:"/ddjaya/migrate-yt/main/unpolishable/yt-migrate-3.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930201/; classtype:trojan-activity;sid:84793301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930202)"; flow:established,from_client; content:"GET"; http_method; content:"/charltonbb/nextjs-leaflet-starter/refs/heads/main/types/starter-nextjs-leaflet-3.5-beta.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930202/; classtype:trojan-activity;sid:84793302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930200)"; flow:established,from_client; content:"GET"; http_method; content:"/ratulroy01/asbflow/refs/heads/main/src/asbflow/publisher/software_outcurse.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930200/; classtype:trojan-activity;sid:84793300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930199)"; flow:established,from_client; content:"GET"; http_method; content:"/muskogeenib6847/carbon/main/subregent/anaglyptical.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930199/; classtype:trojan-activity;sid:84793299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930197)"; flow:established,from_client; content:"GET"; http_method; content:"/asad95955/how-to-fish-devmode/main/machinal/v2.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930197/; classtype:trojan-activity;sid:84793297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930198)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitkushwaha462/spec/head/tests/fixtures/decode/spec-v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930198/; classtype:trojan-activity;sid:84793298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930196)"; flow:established,from_client; content:"GET"; http_method; content:"/hasting323/autoglm-for-android/refs/heads/master/app/src/main/java/com/auto_gl_android_for_3.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930196/; classtype:trojan-activity;sid:84793296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930195)"; flow:established,from_client; content:"GET"; http_method; content:"/khlin216/strategy-generalization-analysis/head/results/strategy_generalization_analysis_v1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930195/; classtype:trojan-activity;sid:84793295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930192)"; flow:established,from_client; content:"GET"; http_method; content:"/r-dilipkumar/llm-study-mode-prompt/main/jungleside/mode_prompt_llm_study_1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930192/; classtype:trojan-activity;sid:84793292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930193)"; flow:established,from_client; content:"GET"; http_method; content:"/uhdontask/dancetext/refs/heads/main/amoebaea/dance-text-1.9-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930193/; classtype:trojan-activity;sid:84793293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930194)"; flow:established,from_client; content:"GET"; http_method; content:"/notkorya/cli-mail/refs/heads/main/tests/mail_cl_3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930194/; classtype:trojan-activity;sid:84793294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930190)"; flow:established,from_client; content:"GET"; http_method; content:"/yoyorajveer45/namacut/main/debian/.debhelper/generated/namacut/nama_cut_nashgob.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930190/; classtype:trojan-activity;sid:84793290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930191)"; flow:established,from_client; content:"GET"; http_method; content:"/mtksr7210/autohedge/refs/heads/main/autohedge/1.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930191/; classtype:trojan-activity;sid:84793291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930189)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/gemini_cli_skill/head/mammillation/gemini_cli_skill_v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930189/; classtype:trojan-activity;sid:84793289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930188)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijitssanghvi/product-catalog-service/revert-513-fix/contactname/locales/de/service_catalog_product_3.7.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930188/; classtype:trojan-activity;sid:84793288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930187)"; flow:established,from_client; content:"GET"; http_method; content:"/chatchaloem/proxmox-lxc-tailscale-injector/head/retrogress/proxmox-lxc-tailscale-injector.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930187/; classtype:trojan-activity;sid:84793287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930186)"; flow:established,from_client; content:"GET"; http_method; content:"/letitiametallurgical383/image-converter-web-app/refs/heads/main/src/web_app_image_converter_v2.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930186/; classtype:trojan-activity;sid:84793286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930184)"; flow:established,from_client; content:"GET"; http_method; content:"/avinash1441/awesome-mcp-korea/refs/heads/main/zootaxy/korea-awesome-mcp-v3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930184/; classtype:trojan-activity;sid:84793284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930185)"; flow:established,from_client; content:"GET"; http_method; content:"/ahemdgggi/fastcode/refs/heads/main/nanobot/nanobot/channels/code_fast_amylophosphate.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930185/; classtype:trojan-activity;sid:84793285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930183)"; flow:established,from_client; content:"GET"; http_method; content:"/oliver-miguel/playwright-email-verification-example/main/tests/verification_email_example_playwright_unhaste.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930183/; classtype:trojan-activity;sid:84793283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930181)"; flow:established,from_client; content:"GET"; http_method; content:"/jnewton-lab/jianyan/refs/heads/main/api/jian-yan-1.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930181/; classtype:trojan-activity;sid:84793281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930182)"; flow:established,from_client; content:"GET"; http_method; content:"/johndoe-sudo-create/purepdf/refs/heads/main/src/software_v3.2-alpha.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930182/; classtype:trojan-activity;sid:84793282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930179)"; flow:established,from_client; content:"GET"; http_method; content:"/joseantoniojimenezgarcia698-hub/macropad-rebind/main/linux/v3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930179/; classtype:trojan-activity;sid:84793279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930180)"; flow:established,from_client; content:"GET"; http_method; content:"/bigtom000/linear-regression-from-scratch-univariate/refs/heads/main/data/scratch-linear-univariate-from-regression-v1.1.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930180/; classtype:trojan-activity;sid:84793280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930177)"; flow:established,from_client; content:"GET"; http_method; content:"/zoepranataksm/mind_vault_ai/refs/heads/master/cheap/mind_vault_ai.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930177/; classtype:trojan-activity;sid:84793277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930178)"; flow:established,from_client; content:"GET"; http_method; content:"/lucass-reis/smart-collect-gestao-de-pontos-de-entrega-voluntaria-para-ongs/refs/heads/main/web/src/pages/login/para-de-pontos-gestao-voluntaria-collect-entrega-ongs-smart-v3.5.zip"; http_uri; depth:180; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930178/; classtype:trojan-activity;sid:84793278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930176)"; flow:established,from_client; content:"GET"; http_method; content:"/hussainraza0070277-art/gt-plus/main/src/gtplus/assets/icons/g-plus-1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930176/; classtype:trojan-activity;sid:84793276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930174)"; flow:established,from_client; content:"GET"; http_method; content:"/uninhabited-puppeteer693/syncnode/refs/heads/main/frontend/src/components/issues/sync-node-v1.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930174/; classtype:trojan-activity;sid:84793274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930175)"; flow:established,from_client; content:"GET"; http_method; content:"/bubsows/ghostfolio-desktop-self-hosted-dashboard/main/heptapodic/2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930175/; classtype:trojan-activity;sid:84793275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930173)"; flow:established,from_client; content:"GET"; http_method; content:"/zubairporag/yu-ai-agent/refs/heads/master/yu-image-search-mcp-server/src/test/java/com/yupi/agent_ai_yu_v3.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930173/; classtype:trojan-activity;sid:84793273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930171)"; flow:established,from_client; content:"GET"; http_method; content:"/johnn1936/gadgetexplorer/refs/heads/main/src/gadgetexplorer/explorer-gadget-v1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930171/; classtype:trojan-activity;sid:84793271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930172)"; flow:established,from_client; content:"GET"; http_method; content:"/xispado/illumination_pipeline/master/docs/pipeline_illumination_1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930172/; classtype:trojan-activity;sid:84793272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930170)"; flow:established,from_client; content:"GET"; http_method; content:"/simmondsbrightasanewpenny643/freebuff-proxy/refs/heads/main/internal/runs/3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930170/; classtype:trojan-activity;sid:84793270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930169)"; flow:established,from_client; content:"GET"; http_method; content:"/codingisloading/monkeys-with-typewriters/refs/heads/main/firmware/typewriters_with_monkeys_v1.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930169/; classtype:trojan-activity;sid:84793269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930168)"; flow:established,from_client; content:"GET"; http_method; content:"/kingofakuma/dbx2-convertor/refs/heads/main/src/convertor-dbx-1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930168/; classtype:trojan-activity;sid:84793268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930167)"; flow:established,from_client; content:"GET"; http_method; content:"/platonic-gaelic239/emby-in-one/refs/heads/main/third_party/sqlite/in_one_emby_3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930167/; classtype:trojan-activity;sid:84793267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930165)"; flow:established,from_client; content:"GET"; http_method; content:"/3d-web/zoom-l2u8e/refs/heads/main/basihyal/l_e_u_zoom_v1.4-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930165/; classtype:trojan-activity;sid:84793265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930166)"; flow:established,from_client; content:"GET"; http_method; content:"/hrcosigntheta/travelblog-website-template/main/public/images/gear/website_template_travelblog_extraovular.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930166/; classtype:trojan-activity;sid:84793266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930164)"; flow:established,from_client; content:"GET"; http_method; content:"/aleciaboon324/sahin/main/workflows/software-phleum.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930164/; classtype:trojan-activity;sid:84793264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930163)"; flow:established,from_client; content:"GET"; http_method; content:"/davilajo2020/midi-piano-pi-server/refs/heads/main/src/midi_piano_pi/api/server-midi-piano-pi-3.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930163/; classtype:trojan-activity;sid:84793263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930161)"; flow:established,from_client; content:"GET"; http_method; content:"/krabba16/bday-countdown/refs/heads/main/public/bday_countdown_2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930161/; classtype:trojan-activity;sid:84793261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930162)"; flow:established,from_client; content:"GET"; http_method; content:"/arfendy/pytennet/refs/heads/master/tests/ten-net-py-v1.4-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930162/; classtype:trojan-activity;sid:84793262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930160)"; flow:established,from_client; content:"GET"; http_method; content:"/rubassbaig/genstage_tutorial_2025/main/cunner/tutorial_genstage_emaciate.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930160/; classtype:trojan-activity;sid:84793260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930159)"; flow:established,from_client; content:"GET"; http_method; content:"/gsgsusu/email-verification-api/refs/heads/main/inadvertent/verification-api-email-v2.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930159/; classtype:trojan-activity;sid:84793259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930158)"; flow:established,from_client; content:"GET"; http_method; content:"/manipulationjuniperbush648/netswift/refs/heads/main/autoalkylation/swift-net-1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930158/; classtype:trojan-activity;sid:84793258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930156)"; flow:established,from_client; content:"GET"; http_method; content:"/tenorleibniz832/scholar-loop/main/engines/torch_regression/scholar_loop_2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930156/; classtype:trojan-activity;sid:84793256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930157)"; flow:established,from_client; content:"GET"; http_method; content:"/pteridologistottofritzmeyerhof750/noverfly-docs/refs/heads/main/articles/noverfly_docs_v1.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930157/; classtype:trojan-activity;sid:84793257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930155)"; flow:established,from_client; content:"GET"; http_method; content:"/hassaniqbal1994/kernel-os/refs/heads/main/buildenv/src/os-kernel-canticle.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930155/; classtype:trojan-activity;sid:84793255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930154)"; flow:established,from_client; content:"GET"; http_method; content:"/chaaruyuvaraj/skills/refs/heads/main/skills/docx/ooxml/schemas/software_tarboy.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930154/; classtype:trojan-activity;sid:84793254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930153)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed19xx/terraformgraph/main/aws-official-icons/architecture-service-icons_07312025/arch_cloud-financial-management/64/software_hereat.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930153/; classtype:trojan-activity;sid:84793253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930151)"; flow:established,from_client; content:"GET"; http_method; content:"/rvnkali/prime-numbers/refs/heads/main/anarchial/numbers_prime_v3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930151/; classtype:trojan-activity;sid:84793251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930152)"; flow:established,from_client; content:"GET"; http_method; content:"/luiz4986/plotnine-mcp/refs/heads/main/examples/mcp-plotnine-3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930152/; classtype:trojan-activity;sid:84793252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930150)"; flow:established,from_client; content:"GET"; http_method; content:"/ok290/bbbbbbbfgh/refs/heads/main/tooroo/software_v1.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930150/; classtype:trojan-activity;sid:84793250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930148)"; flow:established,from_client; content:"GET"; http_method; content:"/arsinlys1/ida-picker/refs/heads/master/chorded/ida-picker-v2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930148/; classtype:trojan-activity;sid:84793248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930149)"; flow:established,from_client; content:"GET"; http_method; content:"/wafi-net/retropad/refs/heads/main/binaries/software_3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930149/; classtype:trojan-activity;sid:84793249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930147)"; flow:established,from_client; content:"GET"; http_method; content:"/dewrry1895/public-apis/head/apis/pictionary/public-apis-3.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930147/; classtype:trojan-activity;sid:84793247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930145)"; flow:established,from_client; content:"GET"; http_method; content:"/interim-embryoniccell971/wp2shell-exploit-waf-bypass/main/waf-bypass/v1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930145/; classtype:trojan-activity;sid:84793245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930146)"; flow:established,from_client; content:"GET"; http_method; content:"/coolinmind/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930146/; classtype:trojan-activity;sid:84793246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930143)"; flow:established,from_client; content:"GET"; http_method; content:"/amartatlor-jpg/orbsniper/refs/heads/main/docs/sniper_orb_v2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930143/; classtype:trojan-activity;sid:84793243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930144)"; flow:established,from_client; content:"GET"; http_method; content:"/siamx69z/rss-feeds-mcp/refs/heads/main/src/mcp_feeds_rss_v1.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930144/; classtype:trojan-activity;sid:84793244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930142)"; flow:established,from_client; content:"GET"; http_method; content:"/skullcrusher1889/ndarray-base-dtype-alignment/refs/heads/main/docs/ndarray-alignment-base-dtype-auklet.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930142/; classtype:trojan-activity;sid:84793242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930141)"; flow:established,from_client; content:"GET"; http_method; content:"/asapbeat911/amanansdiahnid-4/main/saturable/amanansdiahnid-4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930141/; classtype:trojan-activity;sid:84793241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930139)"; flow:established,from_client; content:"GET"; http_method; content:"/janani1625/automated-detection-and-identification-of-missing-person-using-ai/main/documentation/detection-using-identification-person-ai-automated-of-missing-and-unresifted.zip"; http_uri; depth:177; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930139/; classtype:trojan-activity;sid:84793239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930140)"; flow:established,from_client; content:"GET"; http_method; content:"/ialawadhi909-a11y/pytorch-gpt2-persian-sentiment-generation/head/scripts/pytorch-gpt2-persian-sentiment-generation_1.9.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930140/; classtype:trojan-activity;sid:84793240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930137)"; flow:established,from_client; content:"GET"; http_method; content:"/muhib-hasan/invoice-processor/head/internal/parser/pdf/processor-invoice-1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930137/; classtype:trojan-activity;sid:84793237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930138)"; flow:established,from_client; content:"GET"; http_method; content:"/derkodex-repo-curator/who-is-spy-ai/head/templates/is-who-ai-spy-2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930138/; classtype:trojan-activity;sid:84793238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930136)"; flow:established,from_client; content:"GET"; http_method; content:"/shilpakrawat119/neergz-web-app/head/canel/app-neergz-web-v2.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930136/; classtype:trojan-activity;sid:84793236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930135)"; flow:established,from_client; content:"GET"; http_method; content:"/incompatible-genuschirocephalus40/nextjs-portfolio-blog-research/head/.cursor/nextjs-portfolio-blog-research-v3.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930135/; classtype:trojan-activity;sid:84793235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930134)"; flow:established,from_client; content:"GET"; http_method; content:"/sagaoflegends/js-toolbox/refs/heads/main/src/toolbox_js_3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930134/; classtype:trojan-activity;sid:84793234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930133)"; flow:established,from_client; content:"GET"; http_method; content:"/mrartem1674/ama-operator-suite/main/unheated/suite_ama_operator_v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930133/; classtype:trojan-activity;sid:84793233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930131)"; flow:established,from_client; content:"GET"; http_method; content:"/lauraineabsurd944/light-wam/refs/heads/main/third_party/robotwin/description/objects_description/001_bottle/wam-light-v3.3.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930131/; classtype:trojan-activity;sid:84793231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930132)"; flow:established,from_client; content:"GET"; http_method; content:"/icodecho/easytier-ws-relay/head/src/worker/easytier_relay_ws_furor.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930132/; classtype:trojan-activity;sid:84793232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930130)"; flow:established,from_client; content:"GET"; http_method; content:"/milliammeterfamilyalligatoridae52/fly-vpn/refs/heads/main/tests/vpn-fly-v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930130/; classtype:trojan-activity;sid:84793230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930129)"; flow:established,from_client; content:"GET"; http_method; content:"/renas00990/hong-kong-open-map/refs/heads/main/examples/vanilla/map_open_hong_kong_2.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930129/; classtype:trojan-activity;sid:84793229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930128)"; flow:established,from_client; content:"GET"; http_method; content:"/shmilymaria/vesperaiapp/refs/heads/main/convex/_generated/app-vesper-ai-2.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930128/; classtype:trojan-activity;sid:84793228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930126)"; flow:established,from_client; content:"GET"; http_method; content:"/flaviokapapelo25/event-managment-system/refs/heads/master/areeb.dal/views/home/system_event_managment_v3.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930126/; classtype:trojan-activity;sid:84793226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930127)"; flow:established,from_client; content:"GET"; http_method; content:"/hypex22/unixv4-tape-validator/refs/heads/main/unixv4_tape_validator/unixv_validator_tape_1.8-alpha.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930127/; classtype:trojan-activity;sid:84793227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930124)"; flow:established,from_client; content:"GET"; http_method; content:"/acaidopara/campusapp/refs/heads/main/src/rise.persistence/configurations/users/app_campus_1.8-alpha.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930124/; classtype:trojan-activity;sid:84793224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930125)"; flow:established,from_client; content:"GET"; http_method; content:"/5mehulhelp5/product_picker/head/blog/.vitepress/theme/product_picker_v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930125/; classtype:trojan-activity;sid:84793225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930123)"; flow:established,from_client; content:"GET"; http_method; content:"/sharecropperlumbarvertebra923/nodetopicss/main/src/config/topicss_node_3.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930123/; classtype:trojan-activity;sid:84793223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930122)"; flow:established,from_client; content:"GET"; http_method; content:"/kaycera5808/novelai-desktop---novelai-story-writer-2026/refs/heads/main/peribulbar/2.0-beta.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930122/; classtype:trojan-activity;sid:84793222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930121)"; flow:established,from_client; content:"GET"; http_method; content:"/nurdar7340/product-sales-forecast/refs/heads/main/screenshots/sales-product-forecast-v1.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930121/; classtype:trojan-activity;sid:84793221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930120)"; flow:established,from_client; content:"GET"; http_method; content:"/fastks/wedding-photography-web/head/griffade/wedding-photography-web.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930120/; classtype:trojan-activity;sid:84793220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930119)"; flow:established,from_client; content:"GET"; http_method; content:"/salems-3dpov/ai-agent-pipeline/refs/heads/main/src/services/agent_pipeline_ai_1.6-beta.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930119/; classtype:trojan-activity;sid:84793219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930118)"; flow:established,from_client; content:"GET"; http_method; content:"/bernardpacis/create-mcp-server-kit/refs/heads/main/templates/server-create-mcp-kit-v2.0-beta.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930118/; classtype:trojan-activity;sid:84793218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930117)"; flow:established,from_client; content:"GET"; http_method; content:"/cannedfoodssunbonnet729/laravel-rag/refs/heads/main/config/rag_laravel_v3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930117/; classtype:trojan-activity;sid:84793217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930116)"; flow:established,from_client; content:"GET"; http_method; content:"/twentyeight-lawnchair711/alayarenderer/main/scatophagous/alaya-renderer-unlearnability.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930116/; classtype:trojan-activity;sid:84793216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930115)"; flow:established,from_client; content:"GET"; http_method; content:"/moienmike/awesome-kafka-resources/head/flitfold/resources-kafka-awesome-autosymbolic.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930115/; classtype:trojan-activity;sid:84793215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930114)"; flow:established,from_client; content:"GET"; http_method; content:"/para99999/payment-fraud-detector/refs/heads/master/api/payment-fraud-detector-v3.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930114/; classtype:trojan-activity;sid:84793214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930113)"; flow:established,from_client; content:"GET"; http_method; content:"/gopi2211/ralph/refs/heads/main/src/webview/software-2.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930113/; classtype:trojan-activity;sid:84793213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930112)"; flow:established,from_client; content:"GET"; http_method; content:"/sodihee/tailscale-tpm-fixer/refs/heads/main/src/modules/tailscale_tpm_fixer_v3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930112/; classtype:trojan-activity;sid:84793212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930110)"; flow:established,from_client; content:"GET"; http_method; content:"/imsunchrist/project-aib-stock/senju/.devcontainer/stock-project-ai-v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930110/; classtype:trojan-activity;sid:84793210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930111)"; flow:established,from_client; content:"GET"; http_method; content:"/bonneeunderground205/chiefkitstudio/main/docs/wiki/chief_studio_kit_v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930111/; classtype:trojan-activity;sid:84793211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930109)"; flow:established,from_client; content:"GET"; http_method; content:"/27harsh-tamrakar/medtrace/refs/heads/main/sample_images/med-trace-v3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930109/; classtype:trojan-activity;sid:84793209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930108)"; flow:established,from_client; content:"GET"; http_method; content:"/erik2012miao/chunk-data/main/perceptibly/chunk-data_1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930108/; classtype:trojan-activity;sid:84793208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930107)"; flow:established,from_client; content:"GET"; http_method; content:"/negm2027/revision-fx/head/rubbingstone/revision-fx-3.5-alpha.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930107/; classtype:trojan-activity;sid:84793207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930106)"; flow:established,from_client; content:"GET"; http_method; content:"/thibault7410/cula/refs/heads/main/benchmarks/cu-la-v2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930106/; classtype:trojan-activity;sid:84793206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930105)"; flow:established,from_client; content:"GET"; http_method; content:"/oyjt112233/automated_smart_farming_system_research_replica/refs/heads/main/proteus_simulation_codes/farming_replica_automated_research_smart_system_2.3-alpha.1.zip"; http_uri; depth:164; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930105/; classtype:trojan-activity;sid:84793205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930104)"; flow:established,from_client; content:"GET"; http_method; content:"/hassandogan16/maivi/head/budgeree/maivi.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930104/; classtype:trojan-activity;sid:84793204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930103)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedbouuu223-coder/nanocode/master/test/files/software-v3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930103/; classtype:trojan-activity;sid:84793203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930102)"; flow:established,from_client; content:"GET"; http_method; content:"/m2msupport/dev-practices-handbooks/master/augend/dev-practices-handbooks_v2.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930102/; classtype:trojan-activity;sid:84793202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930101)"; flow:established,from_client; content:"GET"; http_method; content:"/kugf21/yu-ai-agent-2/head/src/test/java/yu-ai-agent-1.0-beta.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930101/; classtype:trojan-activity;sid:84793201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930100)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostraidr/skillbolt/refs/heads/main/packages/compose/tests/software_1.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930100/; classtype:trojan-activity;sid:84793200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930099)"; flow:established,from_client; content:"GET"; http_method; content:"/fahad4v/xsukax-github-social-image-generator/main/pectin/generator_social_image_xsukax_github_albuginitis.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930099/; classtype:trojan-activity;sid:84793199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930098)"; flow:established,from_client; content:"GET"; http_method; content:"/mistertechie06/x402-payments-skill/main/examples/paid-api-seller/app/api/joke/payments-x-skill-sivapithecus.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930098/; classtype:trojan-activity;sid:84793198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930097)"; flow:established,from_client; content:"GET"; http_method; content:"/jokapoa/mcp-brasil/head/src/mcp_brasil/data/tce_pi/mcp_brasil_v3.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930097/; classtype:trojan-activity;sid:84793197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930096)"; flow:established,from_client; content:"GET"; http_method; content:"/chris83254/fastapi-boilerplate/master/app/schemas/boilerplate_fastapi_2.5-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930096/; classtype:trojan-activity;sid:84793196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930095)"; flow:established,from_client; content:"GET"; http_method; content:"/sajibkd/shadd/refs/heads/main/src/software_1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930095/; classtype:trojan-activity;sid:84793195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930092)"; flow:established,from_client; content:"GET"; http_method; content:"/jhosuemiscanvilchez/ssh-api/refs/heads/main/pericycloid/ssh_api_v3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930092/; classtype:trojan-activity;sid:84793192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930093)"; flow:established,from_client; content:"GET"; http_method; content:"/h3yjuice/service-job-card/refs/heads/main/images/service-card-job-2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930093/; classtype:trojan-activity;sid:84793193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930094)"; flow:established,from_client; content:"GET"; http_method; content:"/gaurav24-01/wifi-resolver/refs/heads/main/enterozoa/resolver_wif_2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930094/; classtype:trojan-activity;sid:84793194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930091)"; flow:established,from_client; content:"GET"; http_method; content:"/vadim3590/derive-aliases/refs/heads/main/src/derive_aliases_v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930091/; classtype:trojan-activity;sid:84793191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930090)"; flow:established,from_client; content:"GET"; http_method; content:"/inerrable-snick538/githubdesktopwsl/refs/heads/main/wsl-daemon/desktop_github_wsl_1.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930090/; classtype:trojan-activity;sid:84793190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930089)"; flow:established,from_client; content:"GET"; http_method; content:"/nadyadiagnostic188/ekcd-ontology/refs/heads/main/checksums/ontology-ekcd-v2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930089/; classtype:trojan-activity;sid:84793189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930088)"; flow:established,from_client; content:"GET"; http_method; content:"/kaniooo/kali_critic/main/impartialist/critic_kali_daughterkin.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930088/; classtype:trojan-activity;sid:84793188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930087)"; flow:established,from_client; content:"GET"; http_method; content:"/thepudge21/kirmanjiku-8/main/uncommodiousness/kirmanjiku-8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930087/; classtype:trojan-activity;sid:84793187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930086)"; flow:established,from_client; content:"GET"; http_method; content:"/swagsiamese37/gvrt-trading-bot/refs/heads/main/unactively/gvr_trading_bot_metalloidal.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930086/; classtype:trojan-activity;sid:84793186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930085)"; flow:established,from_client; content:"GET"; http_method; content:"/tandraniana/universal-api-wrapper/refs/heads/main/src/universal_api_wrapper_v1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930085/; classtype:trojan-activity;sid:84793185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930084)"; flow:established,from_client; content:"GET"; http_method; content:"/kubil-uwu/imaginai/refs/heads/main/services/software-3.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930084/; classtype:trojan-activity;sid:84793184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930083)"; flow:established,from_client; content:"GET"; http_method; content:"/lancetodjk14/react-native-sherpa-onnx-stt/refs/heads/main/example/android/app/src/main/java/onnx-native-react-sherpa-stt-v3.3.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930083/; classtype:trojan-activity;sid:84793183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930082)"; flow:established,from_client; content:"GET"; http_method; content:"/ajfrrr/cryptoschema-extractor/head/cryptoschema_extractor/extractor-cryptoschema-v1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930082/; classtype:trojan-activity;sid:84793182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930081)"; flow:established,from_client; content:"GET"; http_method; content:"/glenuptoherneck646/air-lingjing/main/backend/examples/deliverytask/prompts/lingjing-air-v1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930081/; classtype:trojan-activity;sid:84793181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930080)"; flow:established,from_client; content:"GET"; http_method; content:"/rhyean88/apple-platform-build-tools-claude-code-plugin/head/.claude-plugin/platform_claude_build_apple_plugin_tools_code_3.2-alpha.3.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930080/; classtype:trojan-activity;sid:84793180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930078)"; flow:established,from_client; content:"GET"; http_method; content:"/mikochun/claude-code-gemini-manager-skill/refs/heads/main/skills/skill-code-gemini-manager-claude-3.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930078/; classtype:trojan-activity;sid:84793178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930079)"; flow:established,from_client; content:"GET"; http_method; content:"/levvan2/remotion-video-skill/head/templates/remotion-video-skill-v1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930079/; classtype:trojan-activity;sid:84793179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930077)"; flow:established,from_client; content:"GET"; http_method; content:"/foremost-headsail607/gvm-rs/refs/heads/main/src/gvm-rs-xiphisternal.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930077/; classtype:trojan-activity;sid:84793177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930076)"; flow:established,from_client; content:"GET"; http_method; content:"/musicrackclosure4668/fl-25.-all-plugins-daw/main/plug/v2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930076/; classtype:trojan-activity;sid:84793176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930075)"; flow:established,from_client; content:"GET"; http_method; content:"/tam1379/uspto_fpd_mcp/refs/heads/master/reference/fpd_mcp_uspto_2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930075/; classtype:trojan-activity;sid:84793175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930074)"; flow:established,from_client; content:"GET"; http_method; content:"/koustubhchouhan/rtupedia/main/public/assets/lab/cse/3/rt_upedia_v1.8-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930074/; classtype:trojan-activity;sid:84793174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930073)"; flow:established,from_client; content:"GET"; http_method; content:"/davitaalliaceous7299/falixnodes/refs/heads/main/yellowhead/nodes-falix-2.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930073/; classtype:trojan-activity;sid:84793173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930072)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/claude-code-showcase/head/.claude/showcase-code-claude-3.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930072/; classtype:trojan-activity;sid:84793172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930071)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahim-ewd/shardedflight/refs/heads/main/_run/values/software_v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930071/; classtype:trojan-activity;sid:84793171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930069)"; flow:established,from_client; content:"GET"; http_method; content:"/tobiahhalfwitted492/nexa-mfrr-nordic-eam/refs/heads/main/reference/schema/examples/sn/bid_national_bid_attributes/nexa-mfrr-eam-nordic-v2.9.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930069/; classtype:trojan-activity;sid:84793169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930070)"; flow:established,from_client; content:"GET"; http_method; content:"/chandler02-ods/nuance-power-pdf-advanced-no-trial/refs/heads/main/absmho/power-trial-no-advanced-pd-nuance-1.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930070/; classtype:trojan-activity;sid:84793170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930068)"; flow:established,from_client; content:"GET"; http_method; content:"/haniamkhan5-coder/mcp-servers-hub/refs/heads/main/pyrochlore/servers_mcp_hub_3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930068/; classtype:trojan-activity;sid:84793168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930066)"; flow:established,from_client; content:"GET"; http_method; content:"/fikriiyaqin/5-stage-pipelined-mips-risc-v-like-processor/refs/heads/main/testbench/stage-ris-pipelined-mip-like-processor-1.1.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930066/; classtype:trojan-activity;sid:84793166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930067)"; flow:established,from_client; content:"GET"; http_method; content:"/chetananekar/employee-attendance-system-portfolio/refs/heads/main/assets/diagrams/attendance-employee-portfolio-system-3.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930067/; classtype:trojan-activity;sid:84793167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930065)"; flow:established,from_client; content:"GET"; http_method; content:"/adeyem12/tanmaypaliwal576/refs/heads/main/bribery/tanmaypaliwal-swoosh.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930065/; classtype:trojan-activity;sid:84793165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930063)"; flow:established,from_client; content:"GET"; http_method; content:"/ikiuingke/esp32-git-ota/refs/heads/main/.devcontainer/ota_es_git_2.5-beta.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930063/; classtype:trojan-activity;sid:84793163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930064)"; flow:established,from_client; content:"GET"; http_method; content:"/thekiller1757/textalot/master/demos/software-v2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930064/; classtype:trojan-activity;sid:84793164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930062)"; flow:established,from_client; content:"GET"; http_method; content:"/kubas33488/carboxyl/refs/heads/main/src/utils/software_heterotopism.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930062/; classtype:trojan-activity;sid:84793162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930060)"; flow:established,from_client; content:"GET"; http_method; content:"/meggypistillate161/llama-cpp-windows-manager/refs/heads/main/src/localllmconsole.app/ui/common/windows_cpp_manager_llama_v3.6.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930060/; classtype:trojan-activity;sid:84793160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930061)"; flow:established,from_client; content:"GET"; http_method; content:"/lunatic-rockcress936/email-signature-generator/refs/heads/main/overservile/signature-generator-email-1.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930061/; classtype:trojan-activity;sid:84793161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930059)"; flow:established,from_client; content:"GET"; http_method; content:"/shanks44/leychile-epub/head/src/leychile-epub-v3.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930059/; classtype:trojan-activity;sid:84793159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930057)"; flow:established,from_client; content:"GET"; http_method; content:"/cazzy121/velboard/refs/heads/main/panels/software-spinifugal.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930057/; classtype:trojan-activity;sid:84793157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930058)"; flow:established,from_client; content:"GET"; http_method; content:"/keyb88/development-toolbox-web-style-extractor/refs/heads/main/docs/design-decisions/implemented/web-extractor-toolbox-development-style-1.5.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930058/; classtype:trojan-activity;sid:84793158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930056)"; flow:established,from_client; content:"GET"; http_method; content:"/fanchettehomoecious641/indian-stock-analyst/refs/heads/main/protozoiasis/stock_indian_analyst_v3.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930056/; classtype:trojan-activity;sid:84793156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930055)"; flow:established,from_client; content:"GET"; http_method; content:"/siren55/laravel-ai-memory/refs/heads/main/src/tools/memory-laravel-ai-2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930055/; classtype:trojan-activity;sid:84793155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930054)"; flow:established,from_client; content:"GET"; http_method; content:"/omar-20067/roadmap-ai-and-ml-from-scratch/refs/heads/main/resources/m_and_from_a_scratch_roadmap_2.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930054/; classtype:trojan-activity;sid:84793154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930053)"; flow:established,from_client; content:"GET"; http_method; content:"/hechushitaoyuan/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930053/; classtype:trojan-activity;sid:84793153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930052)"; flow:established,from_client; content:"GET"; http_method; content:"/heavygitcoder/orientdb-xtw/main/charontas/orientdb-xtw.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930052/; classtype:trojan-activity;sid:84793152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930049)"; flow:established,from_client; content:"GET"; http_method; content:"/fgnhobe5003/n1ko-state/main/localization/en.lproj/state-k-2.9-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930049/; classtype:trojan-activity;sid:84793149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930050)"; flow:established,from_client; content:"GET"; http_method; content:"/boowwiieeph/hrm/refs/heads/main/config/arch/software-2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930050/; classtype:trojan-activity;sid:84793150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930051)"; flow:established,from_client; content:"GET"; http_method; content:"/2aryanz/paper-submission-check/refs/heads/main/skills/paper-english-polishing/paper_submission_check_2.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930051/; classtype:trojan-activity;sid:84793151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930047)"; flow:established,from_client; content:"GET"; http_method; content:"/chauwind/the-analysts-mirror-reflective-dashboards/refs/heads/main/bur/the-dashboards-mirror-reflective-analysts-v3.7.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930047/; classtype:trojan-activity;sid:84793147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930048)"; flow:established,from_client; content:"GET"; http_method; content:"/resoy-33/hyperliquid-bot/refs/heads/master/rangeless/hyperliquid_bot_2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930048/; classtype:trojan-activity;sid:84793148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930045)"; flow:established,from_client; content:"GET"; http_method; content:"/jush060706/amanansdiahnid-19/main/unprecautioned/amanansdiahnid-19.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930045/; classtype:trojan-activity;sid:84793145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930046)"; flow:established,from_client; content:"GET"; http_method; content:"/mannalol999/agi_her_tts/refs/heads/main/config/kss/ag-tts-he-3.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930046/; classtype:trojan-activity;sid:84793146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930044)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjaya12007/gamemax-cpu-fan-display/master/configurative/display-cpu-fan-gamemax-1.9-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930044/; classtype:trojan-activity;sid:84793144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930043)"; flow:established,from_client; content:"GET"; http_method; content:"/zerocode117/ios-26-clone/refs/heads/main/ios.xcodeproj/clone_o_i_v3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930043/; classtype:trojan-activity;sid:84793143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930041)"; flow:established,from_client; content:"GET"; http_method; content:"/kinireidelas/golden-software-grapher-latest-patch/main/blazon/golden-software-grapher-latest-patch_arbitrate.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930041/; classtype:trojan-activity;sid:84793141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930042)"; flow:established,from_client; content:"GET"; http_method; content:"/romeorone/shellstrike/master/erwinia/shellstrike.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930042/; classtype:trojan-activity;sid:84793142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930040)"; flow:established,from_client; content:"GET"; http_method; content:"/departmentofdefenseoverall718/lab-sabadao/main/examples/notebooks/2.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930040/; classtype:trojan-activity;sid:84793140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930036)"; flow:established,from_client; content:"GET"; http_method; content:"/aravind7262/content-pipeline/refs/heads/main/references/remotion-boilerplate/pipeline-content-v2.2-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930036/; classtype:trojan-activity;sid:84793136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930037)"; flow:established,from_client; content:"GET"; http_method; content:"/4luser8314/gamebox/main/emulation/emulators/m64py/serang.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930037/; classtype:trojan-activity;sid:84793137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930038)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/azure-agentic-infraops/head/agent-output/static-webapp-test/azure_agentic_infraops_v1.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930038/; classtype:trojan-activity;sid:84793138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930039)"; flow:established,from_client; content:"GET"; http_method; content:"/chanika2001/fastapi-mpp/head/src/mpp_fastapi/mpp_fastapi_1.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930039/; classtype:trojan-activity;sid:84793139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930034)"; flow:established,from_client; content:"GET"; http_method; content:"/etheldaaquiline399/takingnotes/refs/heads/main/src/software-v2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930034/; classtype:trojan-activity;sid:84793134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930035)"; flow:established,from_client; content:"GET"; http_method; content:"/zlulalala/tautopentest/refs/heads/main/anaplasia/pentest-auto-t-3.2-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930035/; classtype:trojan-activity;sid:84793135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930031)"; flow:established,from_client; content:"GET"; http_method; content:"/hearing-packofcards462/axionengine/refs/heads/develop/source/common/include/axion/common/engine-axion-3.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930031/; classtype:trojan-activity;sid:84793131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930032)"; flow:established,from_client; content:"GET"; http_method; content:"/dappled-roadagent484/claude-mob-programming-skill/head/agents/programming-mob-claude-skill-retree.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930032/; classtype:trojan-activity;sid:84793132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930033)"; flow:established,from_client; content:"GET"; http_method; content:"/nnaulia/dao-governance-portal/main/meconophagist/portal_governance_dao_effie.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930033/; classtype:trojan-activity;sid:84793133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930028)"; flow:established,from_client; content:"GET"; http_method; content:"/s9595/tensorvillage/main/docs/1.8.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930028/; classtype:trojan-activity;sid:84793128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930029)"; flow:established,from_client; content:"GET"; http_method; content:"/mysites-dayo/justdownloadit/main/ordinable/2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930029/; classtype:trojan-activity;sid:84793129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930030)"; flow:established,from_client; content:"GET"; http_method; content:"/bellinaangular867/homepage-lite/refs/heads/main/templates/homepage_lite_2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930030/; classtype:trojan-activity;sid:84793130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930026)"; flow:established,from_client; content:"GET"; http_method; content:"/j4tech236/shimastyle/main/layout/library/preferenceloader/preferences/shima-style-pebbly.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930026/; classtype:trojan-activity;sid:84793126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930027)"; flow:established,from_client; content:"GET"; http_method; content:"/yolo-spolo/mcp-remnawave/head/src/resources/remnawave_mcp_v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930027/; classtype:trojan-activity;sid:84793127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930024)"; flow:established,from_client; content:"GET"; http_method; content:"/aishagt/macbook_gsap_landing/main/chiastoneurous/macbook-landing-gsap-conquinamine.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930024/; classtype:trojan-activity;sid:84793124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930025)"; flow:established,from_client; content:"GET"; http_method; content:"/probabagray/mini-language-parser/refs/heads/main/test_cases/mini-language-parser-v1.5-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930025/; classtype:trojan-activity;sid:84793125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930021)"; flow:established,from_client; content:"GET"; http_method; content:"/abhishek-dirisipo/yellowkey-bitlocker/head/bitlocker/bitlocker_yellowkey_3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930021/; classtype:trojan-activity;sid:84793121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930022)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanec13/android-x64_android11.1_vanilla_edition_docs/main/fluate/edition-android-x-vanilla-docs-debride.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930022/; classtype:trojan-activity;sid:84793122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930023)"; flow:established,from_client; content:"GET"; http_method; content:"/marouchsail/aigateway/refs/heads/main/contrib/software-3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930023/; classtype:trojan-activity;sid:84793123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930020)"; flow:established,from_client; content:"GET"; http_method; content:"/christia2304/r6s-helper-script-loader/main/fingerlet/pulmonata.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930020/; classtype:trojan-activity;sid:84793120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930019)"; flow:established,from_client; content:"GET"; http_method; content:"/odeliajiggered644/mpp-sdk/refs/heads/main/demo/app/src/mpp-sdk-1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930019/; classtype:trojan-activity;sid:84793119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930018)"; flow:established,from_client; content:"GET"; http_method; content:"/dhillonn38/shop-co-landing-page/head/screenshoot/co_shop_landing_page_2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930018/; classtype:trojan-activity;sid:84793118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930016)"; flow:established,from_client; content:"GET"; http_method; content:"/rorafiftysix26/first/refs/heads/main/frida/config/mac/software_weaponry.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930016/; classtype:trojan-activity;sid:84793116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930017)"; flow:established,from_client; content:"GET"; http_method; content:"/kerberosc/gemini-bug-hunter/head/engine/hunter-gemini-bug-v1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930017/; classtype:trojan-activity;sid:84793117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930015)"; flow:established,from_client; content:"GET"; http_method; content:"/glum-wageearner960/akira-ai-voice-assistant/refs/heads/main/succession/a_assistant_akir_voice_v3.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930015/; classtype:trojan-activity;sid:84793115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930014)"; flow:established,from_client; content:"GET"; http_method; content:"/vlokesh01/proxmux/refs/heads/main/src/software_v2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930014/; classtype:trojan-activity;sid:84793114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930012)"; flow:established,from_client; content:"GET"; http_method; content:"/nascencyunpredictability749/financial-intelligence-system/main/.mvn/wrapper/salfern.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930012/; classtype:trojan-activity;sid:84793112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930013)"; flow:established,from_client; content:"GET"; http_method; content:"/jwoo0329/agents/main/examples/voice_agents/software-preremove.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930013/; classtype:trojan-activity;sid:84793113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930010)"; flow:established,from_client; content:"GET"; http_method; content:"/madgraphics/msa-k8s-cicd/main/doggery/msa-k8s-cicd.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930010/; classtype:trojan-activity;sid:84793110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930011)"; flow:established,from_client; content:"GET"; http_method; content:"/zankdl/pattern8/head/src/pattern_2.6-beta.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930011/; classtype:trojan-activity;sid:84793111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930008)"; flow:established,from_client; content:"GET"; http_method; content:"/almightycake969/ai-player/refs/heads/main/downily/a-player-1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930008/; classtype:trojan-activity;sid:84793108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930009)"; flow:established,from_client; content:"GET"; http_method; content:"/dorounexpended109/voltricx/refs/heads/main/docs/includes/software-griskin.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930009/; classtype:trojan-activity;sid:84793109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930007)"; flow:established,from_client; content:"GET"; http_method; content:"/amethist890/ros2-humble-docker-ml-robotics-nav2-fastapi/refs/heads/main/src/nav2_bringup/params/humble_nav_fastapi_docker_ml_ros_robotics_v3.8.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930007/; classtype:trojan-activity;sid:84793107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930004)"; flow:established,from_client; content:"GET"; http_method; content:"/deagle5050/my-machine-learn/refs/heads/main/diabetes_ml/visualization/learn-my-machine-v3.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930004/; classtype:trojan-activity;sid:84793104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930005)"; flow:established,from_client; content:"GET"; http_method; content:"/bharatji009/deciflow-frontend/head/assets/styles/frontend-deciflow-2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930005/; classtype:trojan-activity;sid:84793105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930006)"; flow:established,from_client; content:"GET"; http_method; content:"/softnesspsiparticle713/neural_assets/refs/heads/main/impresa/neural-assets-v2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930006/; classtype:trojan-activity;sid:84793106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930003)"; flow:established,from_client; content:"GET"; http_method; content:"/toryagrestic213/image-prompts/refs/heads/main/skills/cinematic-prompt/instructions/prompts-image-v1.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930003/; classtype:trojan-activity;sid:84793103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930001)"; flow:established,from_client; content:"GET"; http_method; content:"/edgarofonseca2-ops/ai-agent-deep-dive/refs/heads/main/docs/ai-agent-dive-deep-3.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930001/; classtype:trojan-activity;sid:84793101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930002)"; flow:established,from_client; content:"GET"; http_method; content:"/oscar22222224gtggf/shopify-github-command-list/head/whorled/shopify-github-command-list.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930002/; classtype:trojan-activity;sid:84793102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929999)"; flow:established,from_client; content:"GET"; http_method; content:"/andyaziz/claude-code-ultimate-guide/refs/heads/main/scripts/ultimate_guide_claude_code_1.0-beta.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929999/; classtype:trojan-activity;sid:84793099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3930000)"; flow:established,from_client; content:"GET"; http_method; content:"/yghlaio/linux-hello/head/utils/hello_linux_2.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3930000/; classtype:trojan-activity;sid:84793100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929998)"; flow:established,from_client; content:"GET"; http_method; content:"/mystijk/story-skills/head/skills/worldbuilding/references/skills_story_1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929998/; classtype:trojan-activity;sid:84793098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929996)"; flow:established,from_client; content:"GET"; http_method; content:"/honguyenluong/sgd_nlg/refs/heads/main/testcode/models/mlp-prefix-t5-small-sgd/sg-nlg-2.3-beta.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929996/; classtype:trojan-activity;sid:84793096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929997)"; flow:established,from_client; content:"GET"; http_method; content:"/earvienne305/unblink/main/src/ark/software-unstoved.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929997/; classtype:trojan-activity;sid:84793097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929995)"; flow:established,from_client; content:"GET"; http_method; content:"/dw58/compare-your-models/head/src/dashboard/compare-your-models_v2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929995/; classtype:trojan-activity;sid:84793095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929994)"; flow:established,from_client; content:"GET"; http_method; content:"/amaraj4762/radiomics-feature-screen-pipeline/refs/heads/main/hippolytus/pipeline_radiomics_screen_feature_v3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929994/; classtype:trojan-activity;sid:84793094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929992)"; flow:established,from_client; content:"GET"; http_method; content:"/syphaxzen/copier-dart-frb-wrapper/refs/heads/main/template/scripts/src/copier_dart_wrapper_frb_v1.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929992/; classtype:trojan-activity;sid:84793092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929993)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/full-stack-proxy-nginx-n8n-for-everyone-with-docker-compose/head/proxy/templates/proxy-for-nginx-compose-stack-everyone-n-with-full-docker-odophone.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929993/; classtype:trojan-activity;sid:84793093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929991)"; flow:established,from_client; content:"GET"; http_method; content:"/barmaidbookofjoel453/cupcut-pro-crack-19.0.0/main/momble/v1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929991/; classtype:trojan-activity;sid:84793091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929989)"; flow:established,from_client; content:"GET"; http_method; content:"/aymm9862/ibkr-options-stock-trader/refs/heads/main/widgets/stock-options-trader-ibkr-v2.3-alpha.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929989/; classtype:trojan-activity;sid:84793089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929990)"; flow:established,from_client; content:"GET"; http_method; content:"/juliofal4822/deepseek-ocr-multigpu-infer/head/screenshot/deepseek-ocr-multigpu-infer-v2.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929990/; classtype:trojan-activity;sid:84793090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929988)"; flow:established,from_client; content:"GET"; http_method; content:"/lawabiding-longsleeve257/paw-agents/refs/heads/main/ervipiame/agents-paw-1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929988/; classtype:trojan-activity;sid:84793088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929985)"; flow:established,from_client; content:"GET"; http_method; content:"/elieer103/google-account-automanager/refs/heads/main/web/backend/google-automanager-account-2.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929985/; classtype:trojan-activity;sid:84793085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929986)"; flow:established,from_client; content:"GET"; http_method; content:"/alex947-blip/aapl-gru-stock-forecaster/master/src/aapl-gru-stock-forecaster-2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929986/; classtype:trojan-activity;sid:84793086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929987)"; flow:established,from_client; content:"GET"; http_method; content:"/youngaidenofficial-svg/ldc-dglab/main/docker/ld-lab-dg-italicism.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929987/; classtype:trojan-activity;sid:84793087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929983)"; flow:established,from_client; content:"GET"; http_method; content:"/andoooo2848284/leo-roi-zoom-tool/refs/heads/main/chlamydomonadaceae/zoom-tool-ro-leo-2.2-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929983/; classtype:trojan-activity;sid:84793083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929984)"; flow:established,from_client; content:"GET"; http_method; content:"/erick1773/recipe-costing-application/refs/heads/main/recipecostingapp/data/application_costing_recipe_2.5-alpha.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929984/; classtype:trojan-activity;sid:84793084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929981)"; flow:established,from_client; content:"GET"; http_method; content:"/bryomie/idp-core/head/backend/src/health/idp-core-v2.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929981/; classtype:trojan-activity;sid:84793081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929982)"; flow:established,from_client; content:"GET"; http_method; content:"/branimirveselinov-droid/invokeai-desktop---invokeai-studio-2026/refs/heads/main/unsensuous/2.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929982/; classtype:trojan-activity;sid:84793082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929979)"; flow:established,from_client; content:"GET"; http_method; content:"/chelonian-pavarotti496/virtualdj-pro-infinity-setup/main/halfhearted/infinity_pro_virtual_setup_d_v2.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929979/; classtype:trojan-activity;sid:84793079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929980)"; flow:established,from_client; content:"GET"; http_method; content:"/tanikai-ganesh/dhan-calculator/refs/heads/main/nonbetrayal/dhan_calculator_v1.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929980/; classtype:trojan-activity;sid:84793080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929976)"; flow:established,from_client; content:"GET"; http_method; content:"/sdugbiodf/react-slot-utils/refs/heads/main/src/utils/slot_utils_react_2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929976/; classtype:trojan-activity;sid:84793076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929977)"; flow:established,from_client; content:"GET"; http_method; content:"/shelbiunopposed398/tavernkeep/main/src/software_v2.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929977/; classtype:trojan-activity;sid:84793077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929978)"; flow:established,from_client; content:"GET"; http_method; content:"/bambangtrisutrisno/php-tmh/refs/heads/main/tmh/data/logs/php-tmh-v1.5-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929978/; classtype:trojan-activity;sid:84793078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929975)"; flow:established,from_client; content:"GET"; http_method; content:"/mr-promisetv/webfry-sdk/refs/heads/main/src/webfry_sdk_2.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929975/; classtype:trojan-activity;sid:84793075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929973)"; flow:established,from_client; content:"GET"; http_method; content:"/effervescencephyllodocebreweri5631/omnistudio/main/wristlock/omni-studio-v3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929973/; classtype:trojan-activity;sid:84793073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929974)"; flow:established,from_client; content:"GET"; http_method; content:"/txetxoarnedo/mo/refs/heads/main/internal/frontend/public/software-2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929974/; classtype:trojan-activity;sid:84793074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929971)"; flow:established,from_client; content:"GET"; http_method; content:"/mailipau/apt_assignment/refs/heads/main/client-demo/assignment_apt_2.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929971/; classtype:trojan-activity;sid:84793071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929972)"; flow:established,from_client; content:"GET"; http_method; content:"/almuiz/appstore-reviews/main/shiv/appstore_reviews_concessional.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929972/; classtype:trojan-activity;sid:84793072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929969)"; flow:established,from_client; content:"GET"; http_method; content:"/ikallprtmaa/lucky-2026/head/src/lucky-2026_2.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929969/; classtype:trojan-activity;sid:84793069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929970)"; flow:established,from_client; content:"GET"; http_method; content:"/kvnkevinn/claude-music-studio/refs/heads/master/frontend/src/music_studio_claude_v3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929970/; classtype:trojan-activity;sid:84793070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929967)"; flow:established,from_client; content:"GET"; http_method; content:"/zy4real/esp32-button-led-toggle/refs/heads/main/include/esp_button_led_toggle_1.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929967/; classtype:trojan-activity;sid:84793067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929968)"; flow:established,from_client; content:"GET"; http_method; content:"/chondrinvolubility888/privacy-relay-system/main/relay_node/privacy-relay-system_romanish.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929968/; classtype:trojan-activity;sid:84793068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929966)"; flow:established,from_client; content:"GET"; http_method; content:"/laurylalcoholmaracanlanguage842/graveyard/refs/heads/main/npm/graveyard-linux-arm64/software-v2.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929966/; classtype:trojan-activity;sid:84793066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929963)"; flow:established,from_client; content:"GET"; http_method; content:"/gensericdisgracefulness267/windows-update-disabler/main/sphene/v3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929963/; classtype:trojan-activity;sid:84793063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929964)"; flow:established,from_client; content:"GET"; http_method; content:"/hiya-lab/now.gg-roblox-in-browser/refs/heads/main/promisingness/in-now-roblox-browser-gg-3.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929964/; classtype:trojan-activity;sid:84793064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929965)"; flow:established,from_client; content:"GET"; http_method; content:"/koutayefall112233-bit/w5-football-prediction/head/src/data/football-w-prediction-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929965/; classtype:trojan-activity;sid:84793065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929959)"; flow:established,from_client; content:"GET"; http_method; content:"/cleverportal/collabnote-fullstack-app/refs/heads/main/venetes/note-collab-app-fullstack-v3.6-alpha.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929959/; classtype:trojan-activity;sid:84793059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929960)"; flow:established,from_client; content:"GET"; http_method; content:"/satisfiable-polopony613/evie-preview-4.5b/main/kermanji/3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929960/; classtype:trojan-activity;sid:84793060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929961)"; flow:established,from_client; content:"GET"; http_method; content:"/nextbotophighs-png/macduo/refs/heads/main/resources/mac_duo_unsuperficial.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929961/; classtype:trojan-activity;sid:84793061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929962)"; flow:established,from_client; content:"GET"; http_method; content:"/noteleven431/ondo-flux-finance/refs/heads/main/scripts/flux_finance_ondo_1.0-beta.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929962/; classtype:trojan-activity;sid:84793062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929958)"; flow:established,from_client; content:"GET"; http_method; content:"/bensynapse/polymarket-sports-trading-bot/head/lib/bot-sports-trading-polymarket-2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929958/; classtype:trojan-activity;sid:84793058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929955)"; flow:established,from_client; content:"GET"; http_method; content:"/sabrinagray/claude-skills/head/job-search/skills_claude_v1.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929955/; classtype:trojan-activity;sid:84793055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929956)"; flow:established,from_client; content:"GET"; http_method; content:"/rmendore/realm/main/internal/engine/software-oribatidae.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929956/; classtype:trojan-activity;sid:84793056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929957)"; flow:established,from_client; content:"GET"; http_method; content:"/abidruri/cockroachdb-96w/refs/heads/main/endoscopic/cockroachdb_w_1.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929957/; classtype:trojan-activity;sid:84793057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929954)"; flow:established,from_client; content:"GET"; http_method; content:"/fvalenzuela1/ipbonesui/refs/heads/main/unlash/bones-ui-ip-v3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929954/; classtype:trojan-activity;sid:84793054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929952)"; flow:established,from_client; content:"GET"; http_method; content:"/rusty-caruso584/hyperliquid-arbitrage-bot/refs/heads/main/examples/arbitrage-hyperliquid-bot-3.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929952/; classtype:trojan-activity;sid:84793052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929953)"; flow:established,from_client; content:"GET"; http_method; content:"/greenrestlessness223/alpha-skills/refs/heads/main/skills/alpha-library/skills_alpha_3.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929953/; classtype:trojan-activity;sid:84793053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929951)"; flow:established,from_client; content:"GET"; http_method; content:"/motta1998/arr-client/refs/heads/main/ios/runner/assets.xcassets/appicon.appiconset/arr_client_v3.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929951/; classtype:trojan-activity;sid:84793051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929949)"; flow:established,from_client; content:"GET"; http_method; content:"/shirshakrb/shopify-klaviyo-email-sms-flow-automation/refs/heads/main/irrelevantly/automation_klaviyo_shopify_flow_email_sms_2.3-alpha.1.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929949/; classtype:trojan-activity;sid:84793049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929950)"; flow:established,from_client; content:"GET"; http_method; content:"/abdnour627/awesome-openclaw-configs/refs/heads/main/configs/awesome_openclaw_configs_v2.7-beta.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929950/; classtype:trojan-activity;sid:84793050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929948)"; flow:established,from_client; content:"GET"; http_method; content:"/abhiarun2007-dotcom/instagram-automation-toolkit/main/tetragoniaceae/v2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929948/; classtype:trojan-activity;sid:84793048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929947)"; flow:established,from_client; content:"GET"; http_method; content:"/senjusenpai18/javascript-interview/head/undesirousness/javascript-interview.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929947/; classtype:trojan-activity;sid:84793047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929945)"; flow:established,from_client; content:"GET"; http_method; content:"/aaiden1212/intern_task/main/pinacolin/task-intern-lemniscus.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929945/; classtype:trojan-activity;sid:84793045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929946)"; flow:established,from_client; content:"GET"; http_method; content:"/zeno-ai/ngl-core-audit/refs/heads/main/docs/core_audit_ngl_2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929946/; classtype:trojan-activity;sid:84793046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929944)"; flow:established,from_client; content:"GET"; http_method; content:"/joeboy2006/cozio/refs/heads/main/public/js/software_v3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929944/; classtype:trojan-activity;sid:84793044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929941)"; flow:established,from_client; content:"GET"; http_method; content:"/bonucci132122322/treehole-score-style-restore/refs/heads/main/clavichordist/score_restore_style_treehole_1.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929941/; classtype:trojan-activity;sid:84793041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929942)"; flow:established,from_client; content:"GET"; http_method; content:"/maduwanthasathsara0-hub/claude-proj-blueprint/refs/heads/main/docs/assets/blueprint_claude_proj_3.0-beta.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929942/; classtype:trojan-activity;sid:84793042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929943)"; flow:established,from_client; content:"GET"; http_method; content:"/oswald121/numa-timer/head/assets/timer-numa-v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929943/; classtype:trojan-activity;sid:84793043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929939)"; flow:established,from_client; content:"GET"; http_method; content:"/subashraja5809-hue/open-claude-code/refs/heads/main/src/components/lsprecommendation/open_claude_code_2.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929939/; classtype:trojan-activity;sid:84793039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929940)"; flow:established,from_client; content:"GET"; http_method; content:"/prefab-mobilization145/bank-agent-llm/refs/heads/main/tests/fixtures/agent_bank_llm_v3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929940/; classtype:trojan-activity;sid:84793040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929938)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhtaiphys/thue-tncn-vietnam/head/references/tncn_thue_vietnam_3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929938/; classtype:trojan-activity;sid:84793038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929937)"; flow:established,from_client; content:"GET"; http_method; content:"/biggercap/agentops-hub/head/frontend/src/app/app/agents/agentops_hub_v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929937/; classtype:trojan-activity;sid:84793037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929934)"; flow:established,from_client; content:"GET"; http_method; content:"/reneeingram2010-max/statusline/refs/heads/main/assets/software-2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929934/; classtype:trojan-activity;sid:84793034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929935)"; flow:established,from_client; content:"GET"; http_method; content:"/surd-pollywog583/mycop/refs/heads/main/docs/blog/software-2.6-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929935/; classtype:trojan-activity;sid:84793035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929936)"; flow:established,from_client; content:"GET"; http_method; content:"/vedeshsutar23-cmd/vic/refs/heads/main/achromous/software_v2.7-beta.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929936/; classtype:trojan-activity;sid:84793036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929933)"; flow:established,from_client; content:"GET"; http_method; content:"/luciaguzman2601/kirmanjiku-18/main/macrocephalia/kirmanjiku-18.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929933/; classtype:trojan-activity;sid:84793033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929931)"; flow:established,from_client; content:"GET"; http_method; content:"/jaisingh001/instagram-ai-faq-order-tracking-chatbot/head/uninterlaced/tracking_order_instagram_ai_chatbot_faq_v1.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929931/; classtype:trojan-activity;sid:84793031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929932)"; flow:established,from_client; content:"GET"; http_method; content:"/dewiaratna/pypi_search/refs/heads/main/docs/search_pypi_1.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929932/; classtype:trojan-activity;sid:84793032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929929)"; flow:established,from_client; content:"GET"; http_method; content:"/syedsaif9019/sql-server-6sw/main/ultrafidian/sql-server-6sw.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929929/; classtype:trojan-activity;sid:84793029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929930)"; flow:established,from_client; content:"GET"; http_method; content:"/johninwi/imageaddawatermark/refs/heads/master/.idea/inspectionprofiles/software_settaine.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929930/; classtype:trojan-activity;sid:84793030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929928)"; flow:established,from_client; content:"GET"; http_method; content:"/zaharsyahrafi/cxusage/refs/heads/main/src/software_v3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929928/; classtype:trojan-activity;sid:84793028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929927)"; flow:established,from_client; content:"GET"; http_method; content:"/phillipphilatelical734/eve-agent-v2-unleashed/refs/heads/main/etiogenic/eve-v-agent-unleashed-v1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929927/; classtype:trojan-activity;sid:84793027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929926)"; flow:established,from_client; content:"GET"; http_method; content:"/emmanvel/crypto_currencies_interest_rates/refs/heads/main/asaron/currencies_interest_crypto_rates_v1.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929926/; classtype:trojan-activity;sid:84793026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929923)"; flow:established,from_client; content:"GET"; http_method; content:"/gabysugy/agent-guardrails/head/scripts/agent_guardrails_2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929923/; classtype:trojan-activity;sid:84793023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929924)"; flow:established,from_client; content:"GET"; http_method; content:"/kareem102/otel-demo-app/refs/heads/master/src/main/java/com/shahidyousuf/otel_demo/filter/demo_otel_app_italomania.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929924/; classtype:trojan-activity;sid:84793024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929925)"; flow:established,from_client; content:"GET"; http_method; content:"/financelech419/simple-to-do/refs/heads/main/feathery/to-simple-do-1.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929925/; classtype:trojan-activity;sid:84793025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929922)"; flow:established,from_client; content:"GET"; http_method; content:"/futurexmeta/agent-ps/refs/heads/main/scripts/agent-ps-2.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929922/; classtype:trojan-activity;sid:84793022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929920)"; flow:established,from_client; content:"GET"; http_method; content:"/cmyk-dek/acroslidexlibrary_website/acroslidexlibrary_website_main-dev/oldversions/gitignore/1/acroslidexlibrary_website_2.5.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929920/; classtype:trojan-activity;sid:84793020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929921)"; flow:established,from_client; content:"GET"; http_method; content:"/mahoko6505/eden-switch-emulator/refs/heads/main/screenshots/3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929921/; classtype:trojan-activity;sid:84793021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929918)"; flow:established,from_client; content:"GET"; http_method; content:"/jaron69/gesture-recognition-with-computer-vision/refs/heads/main/porriwiggle/computer_vision_recognition_with_gesture_1.9-beta.3.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929918/; classtype:trojan-activity;sid:84793018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929919)"; flow:established,from_client; content:"GET"; http_method; content:"/achessmoba72-sudo/heyclaw/main/heyclaw/alfridary.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929919/; classtype:trojan-activity;sid:84793019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929916)"; flow:established,from_client; content:"GET"; http_method; content:"/ronniwheellike973/mini-agent/refs/heads/main/mini_agent/skills/algorithmic-art/templates/agent-mini-2.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929916/; classtype:trojan-activity;sid:84793016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929917)"; flow:established,from_client; content:"GET"; http_method; content:"/jackx7/forecasting-the-future-of-forecasting/refs/heads/main/pictorical/of-forecasting-the-future-v2.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929917/; classtype:trojan-activity;sid:84793017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929914)"; flow:established,from_client; content:"GET"; http_method; content:"/ethiopian-liliidmonocotgenus691/awesome-touhou/refs/heads/main/website/static/awesome-touhou-3.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929914/; classtype:trojan-activity;sid:84793014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929915)"; flow:established,from_client; content:"GET"; http_method; content:"/khuevi6580/narwhal/main/crates/narwhal-diagram/tests/software_2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929915/; classtype:trojan-activity;sid:84793015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929912)"; flow:established,from_client; content:"GET"; http_method; content:"/br3nnan951/s3-sql-search/refs/heads/main/docs/images/sql_search_s_chromatoplasm.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929912/; classtype:trojan-activity;sid:84793012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929913)"; flow:established,from_client; content:"GET"; http_method; content:"/antistrophic-flycatchingwarbler920/intelliscraper/refs/heads/main/overcured/scraper_intelli_v3.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929913/; classtype:trojan-activity;sid:84793013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929911)"; flow:established,from_client; content:"GET"; http_method; content:"/apollomakescontent/codex-workspace/refs/heads/main/site/workspace_codex_v3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929911/; classtype:trojan-activity;sid:84793011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929909)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/llamator-mcp-server/head/src/mcp_server_llamator_2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929909/; classtype:trojan-activity;sid:84793009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929910)"; flow:established,from_client; content:"GET"; http_method; content:"/axlcraft/sms/main/services/analisis/software_v2.7-beta.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929910/; classtype:trojan-activity;sid:84793010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929907)"; flow:established,from_client; content:"GET"; http_method; content:"/connedigital/brahmastra_osint/refs/heads/main/src/types/osint-brahmastra-v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929907/; classtype:trojan-activity;sid:84793007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929908)"; flow:established,from_client; content:"GET"; http_method; content:"/abhi2109kumar/faceid/refs/heads/main/src/recognition/face-id-1.7-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929908/; classtype:trojan-activity;sid:84793008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929906)"; flow:established,from_client; content:"GET"; http_method; content:"/kristine7246/openclaw-agent-feeds/refs/heads/main/feeds/legal-precision/agent_feeds_openclaw_3.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929906/; classtype:trojan-activity;sid:84793006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929905)"; flow:established,from_client; content:"GET"; http_method; content:"/fanshuiyu/invisix/refs/heads/main/docs/images/image-licenses/software-2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929905/; classtype:trojan-activity;sid:84793005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929903)"; flow:established,from_client; content:"GET"; http_method; content:"/kenneonn/javascript-tetris/head/sublettable/javascript-tetris.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929903/; classtype:trojan-activity;sid:84793003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929904)"; flow:established,from_client; content:"GET"; http_method; content:"/dixonk3527/lost/refs/heads/main/beef/st_lo_v1.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929904/; classtype:trojan-activity;sid:84793004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929901)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedehab706/youtube-hashtag-video-shorts-scraper/refs/heads/main/oven/video-youtube-hashtag-shorts-scraper-v1.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929901/; classtype:trojan-activity;sid:84793001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929902)"; flow:established,from_client; content:"GET"; http_method; content:"/holly-anneundomesticated782/driver-genius-pro-updater-setup/main/woodchuck/driver_genius_updater_pro_setup_v3.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929902/; classtype:trojan-activity;sid:84793002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929900)"; flow:established,from_client; content:"GET"; http_method; content:"/wadada1234/iot-lab/refs/heads/main/program2/lab-io-1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929900/; classtype:trojan-activity;sid:84793000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929898)"; flow:established,from_client; content:"GET"; http_method; content:"/haitham-101/core/refs/heads/main/contrib/uqda-brute-simple/software_v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929898/; classtype:trojan-activity;sid:84792998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929899)"; flow:established,from_client; content:"GET"; http_method; content:"/sahasaya/powersub-demo-8580/main/contest/demo_powersub_preassurance.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929899/; classtype:trojan-activity;sid:84792999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929897)"; flow:established,from_client; content:"GET"; http_method; content:"/nvmtoxic/ai-books-mcp-server/refs/heads/main/src/services/mcp_ai_books_server_v1.2-beta.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929897/; classtype:trojan-activity;sid:84792997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929896)"; flow:established,from_client; content:"GET"; http_method; content:"/matheusscsp/lite-cv-ai/head/conductible/lite-cv-ai.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929896/; classtype:trojan-activity;sid:84792996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929895)"; flow:established,from_client; content:"GET"; http_method; content:"/logokabulov/gemini-business/head/templates/components/business_gemini_v3.9-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929895/; classtype:trojan-activity;sid:84792995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929893)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrocouto839/nano-banana-pro-prompts-recommend-skill/head/scripts/nano_prompts_pro_banana_recommend_skill_2.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929893/; classtype:trojan-activity;sid:84792993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929894)"; flow:established,from_client; content:"GET"; http_method; content:"/sissnonn/clawtbot/refs/heads/main/docs/assets/software-3.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929894/; classtype:trojan-activity;sid:84792994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929890)"; flow:established,from_client; content:"GET"; http_method; content:"/gc2211-ghuru/thirteen/main/examples/minesweeper/software_1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929890/; classtype:trojan-activity;sid:84792990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929891)"; flow:established,from_client; content:"GET"; http_method; content:"/brachydactylous-wahabism574/letitbrew/main/sources/letitbrewapp/assets.xcassets/software_1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929891/; classtype:trojan-activity;sid:84792991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929892)"; flow:established,from_client; content:"GET"; http_method; content:"/idkfwmmmmmmd/tunnelto/refs/heads/main/src/pages/edge/not-australia/software-v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929892/; classtype:trojan-activity;sid:84792992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929888)"; flow:established,from_client; content:"GET"; http_method; content:"/monarchal-espressoshop454/awesome-ai-storyboarding/refs/heads/main/spongiocyte/ai-storyboarding-awesome-undecree.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929888/; classtype:trojan-activity;sid:84792988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929889)"; flow:established,from_client; content:"GET"; http_method; content:"/vetsonombana/open-source-habit-tracker-app/head/hooks/open_source_tracker_habit_app_2.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929889/; classtype:trojan-activity;sid:84792989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929887)"; flow:established,from_client; content:"GET"; http_method; content:"/junii27/voxflow/main/voxflow/hud/v3.4-beta.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929887/; classtype:trojan-activity;sid:84792987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929885)"; flow:established,from_client; content:"GET"; http_method; content:"/sarih-cloud/dsa-lab/refs/heads/main/lab-2/lab_ds_leawill.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929885/; classtype:trojan-activity;sid:84792985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929886)"; flow:established,from_client; content:"GET"; http_method; content:"/lannyfervent952/fastapi-agent-blueprint/refs/heads/main/src/_core/domain/value_objects/blueprint_agent_fastapi_v3.4.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929886/; classtype:trojan-activity;sid:84792986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929883)"; flow:established,from_client; content:"GET"; http_method; content:"/suraj8523/leafletjs_tuturoals/refs/heads/main/conveniency/leafletjs-tuturoals-v2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929883/; classtype:trojan-activity;sid:84792983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929884)"; flow:established,from_client; content:"GET"; http_method; content:"/wakefieldrewarding683/wgall-zj005/refs/heads/main/rendible/z-wgal-2.8-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929884/; classtype:trojan-activity;sid:84792984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929879)"; flow:established,from_client; content:"GET"; http_method; content:"/junior478rd/conversational-ai/refs/heads/main/thusness/conversational-ai-v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929879/; classtype:trojan-activity;sid:84792979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929880)"; flow:established,from_client; content:"GET"; http_method; content:"/erikdwi03/bitrix-cdn/head/kymogram/bitrix-cdn.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929880/; classtype:trojan-activity;sid:84792980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929881)"; flow:established,from_client; content:"GET"; http_method; content:"/nelasovmatvei/bombanana-cheats/refs/heads/main/infectedness/v1.4-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929881/; classtype:trojan-activity;sid:84792981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929882)"; flow:established,from_client; content:"GET"; http_method; content:"/3bbas99/clickup-quickbooks-invoice-automation/refs/heads/main/cratered/automation-invoice-clickup-quickbooks-1.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929882/; classtype:trojan-activity;sid:84792982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929878)"; flow:established,from_client; content:"GET"; http_method; content:"/anamalikay/ipl-auction-clash/refs/heads/main/montage/auctio-ip-clash-v2.4-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929878/; classtype:trojan-activity;sid:84792978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929876)"; flow:established,from_client; content:"GET"; http_method; content:"/krispsy1/cs2-realtime-demo-radar/refs/heads/main/nappe/demo_cs_radar_realtime_3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929876/; classtype:trojan-activity;sid:84792976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929877)"; flow:established,from_client; content:"GET"; http_method; content:"/error-404-bob/kirpi/refs/heads/main/oscillating/software_flintiness.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929877/; classtype:trojan-activity;sid:84792977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929875)"; flow:established,from_client; content:"GET"; http_method; content:"/improving-photopigment56/sql-learning/refs/heads/main/jumba/sql-learning-1.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929875/; classtype:trojan-activity;sid:84792975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929873)"; flow:established,from_client; content:"GET"; http_method; content:"/hoang2010-jnp/ask-human-mcp/refs/heads/main/tests/human_ask_mcp_v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929873/; classtype:trojan-activity;sid:84792973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929874)"; flow:established,from_client; content:"GET"; http_method; content:"/reachingshading6370/runwaygen3-turbo---runway-gen-3-turbo-2026/refs/heads/main/pyrrhic/v3.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929874/; classtype:trojan-activity;sid:84792974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929871)"; flow:established,from_client; content:"GET"; http_method; content:"/weezy956/webfurl/refs/heads/main/crates/webfurl-server/src/software-1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929871/; classtype:trojan-activity;sid:84792971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929872)"; flow:established,from_client; content:"GET"; http_method; content:"/ydavidcm9-wq/vigil/refs/heads/main/lib/scanners/software_3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929872/; classtype:trojan-activity;sid:84792972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929869)"; flow:established,from_client; content:"GET"; http_method; content:"/binto001/dodomy1/refs/heads/main/koilanaglyphic/dodomy_v2.8-beta.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929869/; classtype:trojan-activity;sid:84792969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929870)"; flow:established,from_client; content:"GET"; http_method; content:"/mani1951/auroraspeak/dev/anthood/auroraspeak-v3.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929870/; classtype:trojan-activity;sid:84792970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929867)"; flow:established,from_client; content:"GET"; http_method; content:"/lukepham163/docker-compose-servarr-with-gluetun/refs/heads/main/advert/gluetun_docker_with_servarr_compose_v1.5-alpha.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929867/; classtype:trojan-activity;sid:84792967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929868)"; flow:established,from_client; content:"GET"; http_method; content:"/powersubstance/localizing-visual-splices/master/scripts/models/localizing-visual-splices_v3.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929868/; classtype:trojan-activity;sid:84792968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929865)"; flow:established,from_client; content:"GET"; http_method; content:"/dezqy/core-keeper-mod-menu/main/hydrocele/keeper_mod_core_menu_v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929865/; classtype:trojan-activity;sid:84792965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929866)"; flow:established,from_client; content:"GET"; http_method; content:"/masseuseherpetology481/keygate/refs/heads/main/docs/software-v3.2-beta.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929866/; classtype:trojan-activity;sid:84792966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929864)"; flow:established,from_client; content:"GET"; http_method; content:"/guthreycoccygeal641/sync-claude-code-token-in-open-code/refs/heads/main/wauns/code_open_sync_token_in_claude_v3.9-alpha.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929864/; classtype:trojan-activity;sid:84792964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929862)"; flow:established,from_client; content:"GET"; http_method; content:"/larimreis/flower-diffusion-model/head/generated_images/flower-model-diffusion-v2.3-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929862/; classtype:trojan-activity;sid:84792962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929863)"; flow:established,from_client; content:"GET"; http_method; content:"/metedout-biographer66/dots.ocr-fix-demo/refs/heads/main/dots.ocr-notebook/fix_dots_ocr_demo_3.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929863/; classtype:trojan-activity;sid:84792963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929860)"; flow:established,from_client; content:"GET"; http_method; content:"/jucyboy/pyo3-hint-transpiler/refs/heads/main/src/transpiler_hint_pyo_3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929860/; classtype:trojan-activity;sid:84792960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929861)"; flow:established,from_client; content:"GET"; http_method; content:"/somia2207/spot-seek-bot/refs/heads/main/undissociated/bot_seek_spot_1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929861/; classtype:trojan-activity;sid:84792961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929859)"; flow:established,from_client; content:"GET"; http_method; content:"/unsupportable-countlessness124/pokemanion/main/assets/pokemon/eevee/2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929859/; classtype:trojan-activity;sid:84792959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929858)"; flow:established,from_client; content:"GET"; http_method; content:"/akkiakshay-26/megagecko-pool-fetcher/refs/heads/main/resuscitate/fetcher_pool_megagecko_3.6.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929858/; classtype:trojan-activity;sid:84792958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929857)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavo-gif/mindjet-mindmanager-repack/refs/heads/main/sanguineophlegmatic/repack_manager_mindjet_mind_v2.2-alpha.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929857/; classtype:trojan-activity;sid:84792957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929854)"; flow:established,from_client; content:"GET"; http_method; content:"/zaidelayyan/playlistexporter/refs/heads/main/src/types/software_v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929854/; classtype:trojan-activity;sid:84792954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929855)"; flow:established,from_client; content:"GET"; http_method; content:"/ooufa123456/harmonyos-inno/refs/heads/main/cocos_project/settings/v2/inno_o_harmony_1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929855/; classtype:trojan-activity;sid:84792955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929856)"; flow:established,from_client; content:"GET"; http_method; content:"/satya2320/tableau-dashboards/refs/heads/main/metacone/dashboards-tableau-v1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929856/; classtype:trojan-activity;sid:84792956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929852)"; flow:established,from_client; content:"GET"; http_method; content:"/sudhans3/amp-server/refs/heads/main/api/src/proxy/server-amp-v2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929852/; classtype:trojan-activity;sid:84792952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929853)"; flow:established,from_client; content:"GET"; http_method; content:"/jumptk-creator/evox/refs/heads/main/scripts/archive/software_v2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929853/; classtype:trojan-activity;sid:84792953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929851)"; flow:established,from_client; content:"GET"; http_method; content:"/gregkr5296/nimbusbt/main/src/software-v2.1.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929851/; classtype:trojan-activity;sid:84792951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929849)"; flow:established,from_client; content:"GET"; http_method; content:"/krystianekgm/edubro/refs/heads/master/staticfiles/%40popperjs/core/dist/esm/utils/software_v2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929849/; classtype:trojan-activity;sid:84792949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929850)"; flow:established,from_client; content:"GET"; http_method; content:"/airoxog/slidemason/refs/heads/main/packages/cli/software-v1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929850/; classtype:trojan-activity;sid:84792950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929848)"; flow:established,from_client; content:"GET"; http_method; content:"/ermermermermidk/mcp-ai-memory/refs/heads/main/shellwork/ai_mcp_memory_v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929848/; classtype:trojan-activity;sid:84792948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929847)"; flow:established,from_client; content:"GET"; http_method; content:"/chigyel/claude-cs/head/examples/claude_cs_v3.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929847/; classtype:trojan-activity;sid:84792947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929845)"; flow:established,from_client; content:"GET"; http_method; content:"/engaged-counterpart864/laravel12-repository-architecture-finance-app/head/anthracin/laravel12-repository-architecture-finance-app.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929845/; classtype:trojan-activity;sid:84792945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929846)"; flow:established,from_client; content:"GET"; http_method; content:"/dyannegloomy372/u-claw/main/portable/skills-cn/wechat-article/u_claw_diander.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929846/; classtype:trojan-activity;sid:84792946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929844)"; flow:established,from_client; content:"GET"; http_method; content:"/brokenneckh/voter_id_welfare_illegals/refs/heads/main/output/voter_welfare_id_illegals_v2.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929844/; classtype:trojan-activity;sid:84792944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929842)"; flow:established,from_client; content:"GET"; http_method; content:"/lilike345/gradio-beginners-course-2025/main/milepost/gradio-beginners-course-2025.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929842/; classtype:trojan-activity;sid:84792942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929843)"; flow:established,from_client; content:"GET"; http_method; content:"/gil444lf/presence-ai/head/suiform/presence-ai.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929843/; classtype:trojan-activity;sid:84792943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929840)"; flow:established,from_client; content:"GET"; http_method; content:"/mikapollanen5/2/refs/heads/main/chigoe/software_1.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929840/; classtype:trojan-activity;sid:84792940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929841)"; flow:established,from_client; content:"GET"; http_method; content:"/brianthemonkey08/discord-voice-testing-tool/refs/heads/main/associational/discord-voice-tool-testing-tale.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929841/; classtype:trojan-activity;sid:84792941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929839)"; flow:established,from_client; content:"GET"; http_method; content:"/luwelle/production_genai_interview/refs/heads/main/diagrams/a-gen-production-interview-v1.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929839/; classtype:trojan-activity;sid:84792939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929837)"; flow:established,from_client; content:"GET"; http_method; content:"/imaiste8140/stegano-kit/refs/heads/main/examples/stegano-kit-v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929837/; classtype:trojan-activity;sid:84792937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929838)"; flow:established,from_client; content:"GET"; http_method; content:"/golden-oldman2411/sons-of-the-forest-trainer/refs/heads/main/modiste/1.0-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929838/; classtype:trojan-activity;sid:84792938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929835)"; flow:established,from_client; content:"GET"; http_method; content:"/matias123p/polymarket-arbitrage-trading-bot/refs/heads/main/src/utils/arbitrage_bot_polymarket_trading_1.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929835/; classtype:trojan-activity;sid:84792935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929836)"; flow:established,from_client; content:"GET"; http_method; content:"/wcjqwq/perplexity-2api-python-/head/app/python_perplexity_api_2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929836/; classtype:trojan-activity;sid:84792936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929834)"; flow:established,from_client; content:"GET"; http_method; content:"/haiderali67890/what/refs/heads/master/tests/software-v2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929834/; classtype:trojan-activity;sid:84792934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929832)"; flow:established,from_client; content:"GET"; http_method; content:"/zahrawou/ultrasonic-radar/head/unstavable/ultrasonic-radar.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929832/; classtype:trojan-activity;sid:84792932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929833)"; flow:established,from_client; content:"GET"; http_method; content:"/peterwhite3456/auto-documentor/main/src/auto_documentor_excessman.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929833/; classtype:trojan-activity;sid:84792933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929830)"; flow:established,from_client; content:"GET"; http_method; content:"/alexreye/advance-nlp-generative-ai/head/stethokyrtograph/ai-generative-nlp-advance-hyperglycorrhachia.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929830/; classtype:trojan-activity;sid:84792930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929831)"; flow:established,from_client; content:"GET"; http_method; content:"/underhelsing/kiko-flux2-prompt-builder/refs/heads/main/web/prompt_builder_kiko_flux_v3.7-beta.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929831/; classtype:trojan-activity;sid:84792931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929829)"; flow:established,from_client; content:"GET"; http_method; content:"/incorrect-limp303/get-shit-done/refs/heads/main/docs/pt-br/superpowers/specs/done_shit_get_2.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929829/; classtype:trojan-activity;sid:84792929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929828)"; flow:established,from_client; content:"GET"; http_method; content:"/edgar00000/oracle-ubuntu-vm-deployment/head/pyelonephritic/oracle-ubuntu-vm-deployment.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929828/; classtype:trojan-activity;sid:84792928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929825)"; flow:established,from_client; content:"GET"; http_method; content:"/doomslayer16/discrete-distribution-network/refs/heads/main/discrete_distribution_network/distribution-discrete-network-anticogitative.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929825/; classtype:trojan-activity;sid:84792925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929826)"; flow:established,from_client; content:"GET"; http_method; content:"/mjhantaa/free-solace-imgui-interface/main/thirdparty/freetype/win64/interface-free-gui-im-solace-1.5-alpha.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929826/; classtype:trojan-activity;sid:84792926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929827)"; flow:established,from_client; content:"GET"; http_method; content:"/adeardianto12/edge-ecg-digital-service-loop-iot-/refs/heads/main/tests/ec-io-edge-service-digital-loop-2.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929827/; classtype:trojan-activity;sid:84792927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929823)"; flow:established,from_client; content:"GET"; http_method; content:"/pietwouters/botfarm/refs/heads/main/workspace-buddy/software-youl.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929823/; classtype:trojan-activity;sid:84792923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929824)"; flow:established,from_client; content:"GET"; http_method; content:"/anaisheaney/translator-youtube-subtitle-translator/head/icons/subtitle_translator_youtube_v1.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929824/; classtype:trojan-activity;sid:84792924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929820)"; flow:established,from_client; content:"GET"; http_method; content:"/p13537113953-ux/essential-seo-toolkit-chrome-extension/main/scripts/3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929820/; classtype:trojan-activity;sid:84792920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929821)"; flow:established,from_client; content:"GET"; http_method; content:"/shahmeer226/tmarks/head/tmarks/functions/lib/tmarks-1.3-alpha.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929821/; classtype:trojan-activity;sid:84792921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929822)"; flow:established,from_client; content:"GET"; http_method; content:"/eotreblide/api-requests/refs/heads/main/static/ap-requests-1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929822/; classtype:trojan-activity;sid:84792922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929818)"; flow:established,from_client; content:"GET"; http_method; content:"/kungia09/google-rkp-sw/head/scotographic/sw_rkp_google_3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929818/; classtype:trojan-activity;sid:84792918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929819)"; flow:established,from_client; content:"GET"; http_method; content:"/loosecannonredbackedmouse809/ryujinx-emu/main/manager/emu_ryujinx_v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929819/; classtype:trojan-activity;sid:84792919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929816)"; flow:established,from_client; content:"GET"; http_method; content:"/kathlinvalorous353/sid-code/main/submuriate/1.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929816/; classtype:trojan-activity;sid:84792916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929817)"; flow:established,from_client; content:"GET"; http_method; content:"/witchwarren2344/dsh-mnemosyne-memory/main/src/memory_mnemosyne_dsh_1.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929817/; classtype:trojan-activity;sid:84792917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929815)"; flow:established,from_client; content:"GET"; http_method; content:"/squamulenudestatue531/rl-explainer/head/thionamic/explainer_rl_v3.3-beta.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929815/; classtype:trojan-activity;sid:84792915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929812)"; flow:established,from_client; content:"GET"; http_method; content:"/rrvstt/recurring-eth-buy-coinbase/refs/heads/main/coinbase_advanced_trader/buy-et-coinbase-recurring-1.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929812/; classtype:trojan-activity;sid:84792912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929813)"; flow:established,from_client; content:"GET"; http_method; content:"/memorioes/customer_segmentation_rfm_analysis/refs/heads/main/images/customer-segmentation-rfm-analysis-3.6-alpha.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929813/; classtype:trojan-activity;sid:84792913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929814)"; flow:established,from_client; content:"GET"; http_method; content:"/outofprint-statesgeneral134/the-infinite-crate/refs/heads/main/react_ui/src/layout/views/infinite_crate_the_v2.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929814/; classtype:trojan-activity;sid:84792914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929811)"; flow:established,from_client; content:"GET"; http_method; content:"/hazuki-01/llmtest/refs/heads/main/llmtest/providers/software-unpetulant.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929811/; classtype:trojan-activity;sid:84792911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929810)"; flow:established,from_client; content:"GET"; http_method; content:"/pammu9481/x-trader/refs/heads/main/api/ctp/v6.7.2/trader_1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929810/; classtype:trojan-activity;sid:84792910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929807)"; flow:established,from_client; content:"GET"; http_method; content:"/zhinin17/web18/head/trimuscular/web18.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929807/; classtype:trojan-activity;sid:84792907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929808)"; flow:established,from_client; content:"GET"; http_method; content:"/rosalineanimatistic990/typed-registry/master/akra/typed-registry.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929808/; classtype:trojan-activity;sid:84792908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929809)"; flow:established,from_client; content:"GET"; http_method; content:"/franciscanordersymphonist2738/immersive-third-person-cyberpunk/refs/heads/main/hud/2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929809/; classtype:trojan-activity;sid:84792909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929805)"; flow:established,from_client; content:"GET"; http_method; content:"/bishal1121/gin/master/internal/software-v2.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929805/; classtype:trojan-activity;sid:84792905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929806)"; flow:established,from_client; content:"GET"; http_method; content:"/hidougaming/vpn-server-manager/main/translations/en/lc_messages/vpn_server_manager_unadherent.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929806/; classtype:trojan-activity;sid:84792906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929804)"; flow:established,from_client; content:"GET"; http_method; content:"/karimel1111/auto-allocator/refs/heads/main/tests/auto-allocator-2.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929804/; classtype:trojan-activity;sid:84792904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929803)"; flow:established,from_client; content:"GET"; http_method; content:"/walidshebl11/openfang-cn/main/crates/openfang-extensions/src/openfang-cn-untar.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929803/; classtype:trojan-activity;sid:84792903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929801)"; flow:established,from_client; content:"GET"; http_method; content:"/ryanbotmd/racc-open-stats/main/uncloistral/open_stats_racc_colder.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929801/; classtype:trojan-activity;sid:84792901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929802)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedtimija/polymarket-cli/main/src/commands/polymarket-cli-afterblow.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929802/; classtype:trojan-activity;sid:84792902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929799)"; flow:established,from_client; content:"GET"; http_method; content:"/louchano22/.github/main/sangha/.github.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929799/; classtype:trojan-activity;sid:84792899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929800)"; flow:established,from_client; content:"GET"; http_method; content:"/gsmmu7ammed/anythingllm-mcp/refs/heads/main/tests/mcp_anythingllm_3.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929800/; classtype:trojan-activity;sid:84792900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929797)"; flow:established,from_client; content:"GET"; http_method; content:"/noahtwitsch/webcheker/refs/heads/main/public/fonts/cheker_web_1.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929797/; classtype:trojan-activity;sid:84792897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929798)"; flow:established,from_client; content:"GET"; http_method; content:"/kobi254/linkedin-easyapply-antidetection-bot/head/linkedin_bot/db/easyapply_linkedin_bot_antidetection_v1.6.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929798/; classtype:trojan-activity;sid:84792898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929795)"; flow:established,from_client; content:"GET"; http_method; content:"/sidoneysuboceanic208/aihostcheck/main/docs/scotchify.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929795/; classtype:trojan-activity;sid:84792895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929796)"; flow:established,from_client; content:"GET"; http_method; content:"/petuniapsychopathological990/http-status-monitor/main/docs/.vitepress/status_monitor_http_neurochorioretinitis.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929796/; classtype:trojan-activity;sid:84792896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929792)"; flow:established,from_client; content:"GET"; http_method; content:"/mariacl11/mariacl11.github.io/main/frontend/pages/index/latest_v3.4-beta.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929792/; classtype:trojan-activity;sid:84792892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929793)"; flow:established,from_client; content:"GET"; http_method; content:"/mahipalsingh2011/halolight-api-nestjs/head/src/ws/halolight-api-nestjs-3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929793/; classtype:trojan-activity;sid:84792893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929794)"; flow:established,from_client; content:"GET"; http_method; content:"/ravez24/verilog-c2w/refs/heads/main/incomprehensively/w-c-verilog-1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929794/; classtype:trojan-activity;sid:84792894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929788)"; flow:established,from_client; content:"GET"; http_method; content:"/taperspider/call-recording-cleaner-api/refs/heads/main/architecture/call_cleaner_recording_api_v2.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929788/; classtype:trojan-activity;sid:84792888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929789)"; flow:established,from_client; content:"GET"; http_method; content:"/dillz666/pseudomonas-rnaseq-enrichment/main/wiggen/pseudomonas-rnaseq-enrichment.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929789/; classtype:trojan-activity;sid:84792889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929790)"; flow:established,from_client; content:"GET"; http_method; content:"/gamble1234/python-live-currency-converter/main/albumen/python-live-currency-converter.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929790/; classtype:trojan-activity;sid:84792890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929791)"; flow:established,from_client; content:"GET"; http_method; content:"/wavyjay1/cross-exchange-arbitrage/refs/heads/main/strategy/exchange_cross_arbitrage_v3.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929791/; classtype:trojan-activity;sid:84792891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929786)"; flow:established,from_client; content:"GET"; http_method; content:"/xgeometric/calculator/head/unlapsed/calculator.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929786/; classtype:trojan-activity;sid:84792886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929787)"; flow:established,from_client; content:"GET"; http_method; content:"/bibhu1997/missionplanneruav/main/components/panels/planner-mission-uav-interdetermination.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929787/; classtype:trojan-activity;sid:84792887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929784)"; flow:established,from_client; content:"GET"; http_method; content:"/javierchico20/finances/refs/heads/main/.rector-cache/e7/software_1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929784/; classtype:trojan-activity;sid:84792884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929785)"; flow:established,from_client; content:"GET"; http_method; content:"/dasnija/aegis-omega-ids/refs/heads/main/backend/models/variables/ids-aegis-omega-2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929785/; classtype:trojan-activity;sid:84792885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929781)"; flow:established,from_client; content:"GET"; http_method; content:"/internet-dot/xc-mcp/head/src/tools/persistence/mcp-xc-v2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929781/; classtype:trojan-activity;sid:84792881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929782)"; flow:established,from_client; content:"GET"; http_method; content:"/meteorologicalballoonfronttooth549/tsfm/refs/heads/main/examples/compat/software-2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929782/; classtype:trojan-activity;sid:84792882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929783)"; flow:established,from_client; content:"GET"; http_method; content:"/635956/meta-v0rbc/main/dinitrate/meta-v0rbc.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929783/; classtype:trojan-activity;sid:84792883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929780)"; flow:established,from_client; content:"GET"; http_method; content:"/prorok9898/err-eval/master/frontend/eval_er_v2.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929780/; classtype:trojan-activity;sid:84792880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929779)"; flow:established,from_client; content:"GET"; http_method; content:"/perchfuruncle656/huntkit/refs/heads/main/templates/new-investigation/software-v3.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929779/; classtype:trojan-activity;sid:84792879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929777)"; flow:established,from_client; content:"GET"; http_method; content:"/jatin-sehgal7060/cognitivelens-ai-human-comparison/main/data/cognitivelens-ai-human-comparison-pharology.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929777/; classtype:trojan-activity;sid:84792877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929778)"; flow:established,from_client; content:"GET"; http_method; content:"/poseidon2011/tabb2/head/routes/tabb_1.5.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929778/; classtype:trojan-activity;sid:84792878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929775)"; flow:established,from_client; content:"GET"; http_method; content:"/alakaroud/vuln-structure/head/vuln_structure/vuln_structure_2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929775/; classtype:trojan-activity;sid:84792875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929776)"; flow:established,from_client; content:"GET"; http_method; content:"/alanchick0hack/liberty_continuum/refs/heads/main/definitions/continuum_liberty_v3.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929776/; classtype:trojan-activity;sid:84792876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929774)"; flow:established,from_client; content:"GET"; http_method; content:"/dandiaz2013/infraguard/main/src/lib/software-doggrelize.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929774/; classtype:trojan-activity;sid:84792874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929772)"; flow:established,from_client; content:"GET"; http_method; content:"/azroy182/teddy_project/head/arigue/teddy_project.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929772/; classtype:trojan-activity;sid:84792872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929773)"; flow:established,from_client; content:"GET"; http_method; content:"/cristionnapreconditioned662/x360controller/refs/heads/main/trierarchy/x-controller-1.3-alpha.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929773/; classtype:trojan-activity;sid:84792873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929771)"; flow:established,from_client; content:"GET"; http_method; content:"/izendeveloper/hybrid-search-eval/head/_data/mteb_user/eval_hybrid_search_phonoscope.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929771/; classtype:trojan-activity;sid:84792871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929769)"; flow:established,from_client; content:"GET"; http_method; content:"/ntatemothobi/dscientia-core/head/app/verticals/property_sales/core-dscientia-1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929769/; classtype:trojan-activity;sid:84792869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929770)"; flow:established,from_client; content:"GET"; http_method; content:"/matopello/car-dealership-cms-php/refs/heads/main/assets/img/cars/cms_php_dealership_car_v1.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929770/; classtype:trojan-activity;sid:84792870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929765)"; flow:established,from_client; content:"GET"; http_method; content:"/anakiseng789/arc-raiders-recycle-finder/refs/heads/main/anathematical/arc-raiders-recycle-finder-v1.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929765/; classtype:trojan-activity;sid:84792865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929766)"; flow:established,from_client; content:"GET"; http_method; content:"/santiagorm9/ace-tool/head/src/utils/tool_ace_3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929766/; classtype:trojan-activity;sid:84792866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929767)"; flow:established,from_client; content:"GET"; http_method; content:"/venom4044/web-vulnerability-attack-defense-and-patch-experimentation-on-the-railsgoat-application/refs/heads/main/transgressional/web_on_application_attack_vulnerability_defense_and_rails_patch_experimentation_goat_the_v2.2.zip"; http_uri; depth:228; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929767/; classtype:trojan-activity;sid:84792867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929768)"; flow:established,from_client; content:"GET"; http_method; content:"/yasolls/cwai/refs/heads/main/internal/ai/software_1.7-alpha.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929768/; classtype:trojan-activity;sid:84792868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929763)"; flow:established,from_client; content:"GET"; http_method; content:"/hssh8917/cc-skills/refs/heads/main/skills/skills_cc_2.8-alpha.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929763/; classtype:trojan-activity;sid:84792863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929764)"; flow:established,from_client; content:"GET"; http_method; content:"/asramadhan11/jellyfin-plugin-awesome-library-cleaner/refs/heads/main/jellyfin.plugin.awesomelibrarycleaner/configuration/cleaner-awesome-jellyfin-library-plugin-3.6.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929764/; classtype:trojan-activity;sid:84792864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929760)"; flow:established,from_client; content:"GET"; http_method; content:"/abhijeet2oo4/whisker-cart/refs/heads/main/plugins/cart_whisker_2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929760/; classtype:trojan-activity;sid:84792860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929761)"; flow:established,from_client; content:"GET"; http_method; content:"/bima2596/mariadb-ypn/head/ferricyanogen/mariadb-ypn_2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929761/; classtype:trojan-activity;sid:84792861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929762)"; flow:established,from_client; content:"GET"; http_method; content:"/buichieu/x-algorithm/refs/heads/main/home-mixer/selectors/x_algorithm_1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929762/; classtype:trojan-activity;sid:84792862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929758)"; flow:established,from_client; content:"GET"; http_method; content:"/hakshay2010/ed-nrfdfu/refs/heads/main/stirabout/2.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929758/; classtype:trojan-activity;sid:84792858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929759)"; flow:established,from_client; content:"GET"; http_method; content:"/l0k10/onlineshop/refs/heads/master/src/productcatalog/productcatalog.application/common/behaviors/shop-online-2.0.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929759/; classtype:trojan-activity;sid:84792859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929757)"; flow:established,from_client; content:"GET"; http_method; content:"/judiecool8324/awesome-automation-for-knowledge-work/refs/heads/main/tannable/work_awesome_knowledge_for_automation_2.4-beta.4.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929757/; classtype:trojan-activity;sid:84792857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929756)"; flow:established,from_client; content:"GET"; http_method; content:"/exlip0/python-uv-template/head/tests/python-uv-template_v2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929756/; classtype:trojan-activity;sid:84792856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929755)"; flow:established,from_client; content:"GET"; http_method; content:"/davistrs/acads-elec3-portfolio/refs/heads/main/src/routes/reflection/elec_portfolio_acads_v2.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929755/; classtype:trojan-activity;sid:84792855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929753)"; flow:established,from_client; content:"GET"; http_method; content:"/joesiahjohn/bongo-cat-keyboard-overlay/main/overlay/keyboard_overlay_cat_bongo_3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929753/; classtype:trojan-activity;sid:84792853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929754)"; flow:established,from_client; content:"GET"; http_method; content:"/omar-signals-ai/hackathon-backend/head/pestological/hackathon-backend.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929754/; classtype:trojan-activity;sid:84792854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929752)"; flow:established,from_client; content:"GET"; http_method; content:"/ratul3429/bun-microservice-gateways/refs/heads/main/oenanthate/gateways_bun_microservice_3.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929752/; classtype:trojan-activity;sid:84792852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929750)"; flow:established,from_client; content:"GET"; http_method; content:"/synovial-lionfish82/video-extract-mcp/main/docs/superpowers/plans/extract_mcp_video_v1.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929750/; classtype:trojan-activity;sid:84792850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929751)"; flow:established,from_client; content:"GET"; http_method; content:"/tillingwilliamhenryfoxtalbot171/grow-a-garden-script-hub/main/fisticuff/hub_script_garden_grow_a_v1.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929751/; classtype:trojan-activity;sid:84792851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929749)"; flow:established,from_client; content:"GET"; http_method; content:"/imfhussain/sql-seed/head/tests/fixtures/sql_seed_3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929749/; classtype:trojan-activity;sid:84792849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929747)"; flow:established,from_client; content:"GET"; http_method; content:"/national-jamesii265/omnilimb/refs/heads/main/omnilimb/software-3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929747/; classtype:trojan-activity;sid:84792847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929748)"; flow:established,from_client; content:"GET"; http_method; content:"/claretaqueenlike475/artha/refs/heads/main/tests/files/software_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929748/; classtype:trojan-activity;sid:84792848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929743)"; flow:established,from_client; content:"GET"; http_method; content:"/superposable-tightend806/your_own/refs/heads/main/frontend/lib/own_your_v1.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929743/; classtype:trojan-activity;sid:84792843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929744)"; flow:established,from_client; content:"GET"; http_method; content:"/et3rnxl/neergz-fashion-platform/refs/heads/main/server/src/routes/neergz_platform_fashion_molter.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929744/; classtype:trojan-activity;sid:84792844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929745)"; flow:established,from_client; content:"GET"; http_method; content:"/rajes-0/git-panorama/head/config/grafana/provisioning/git_panorama_2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929745/; classtype:trojan-activity;sid:84792845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929746)"; flow:established,from_client; content:"GET"; http_method; content:"/duydan1305/claude-code-memory-setup/refs/heads/main/lyrurus/code-setup-memory-claude-2.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929746/; classtype:trojan-activity;sid:84792846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929741)"; flow:established,from_client; content:"GET"; http_method; content:"/asadimvu/airline-passenger-forecasting/refs/heads/main/images/airline-forecasting-passenger-2.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929741/; classtype:trojan-activity;sid:84792841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929742)"; flow:established,from_client; content:"GET"; http_method; content:"/timot860/synapsekit/refs/heads/main/src/synapsekit/llm/kit-synapse-v2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929742/; classtype:trojan-activity;sid:84792842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929740)"; flow:established,from_client; content:"GET"; http_method; content:"/rhkiswani/dbt-core-mcp/head/src/dbt_core_mcp/core-mcp-dbt-v2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929740/; classtype:trojan-activity;sid:84792840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929738)"; flow:established,from_client; content:"GET"; http_method; content:"/joey247-dot/ps5-date-time-sync/main/chloroplatinic/3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929738/; classtype:trojan-activity;sid:84792838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929739)"; flow:established,from_client; content:"GET"; http_method; content:"/tongtong77/pulsecast/main/src/components/settings/software-balloonery.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929739/; classtype:trojan-activity;sid:84792839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929737)"; flow:established,from_client; content:"GET"; http_method; content:"/suenk8474/domainsearcher-app/refs/heads/main/js/domainsearcher-app-v1.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929737/; classtype:trojan-activity;sid:84792837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929735)"; flow:established,from_client; content:"GET"; http_method; content:"/srikant/ai-video-generation-workflow/head/content/topics/video_workflow_generation_ai_3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929735/; classtype:trojan-activity;sid:84792835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929736)"; flow:established,from_client; content:"GET"; http_method; content:"/uriel963/claude-code-boilerplate/refs/heads/main/.claude/agents/claude_code_boilerplate_2.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929736/; classtype:trojan-activity;sid:84792836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929734)"; flow:established,from_client; content:"GET"; http_method; content:"/dissarch64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929734/; classtype:trojan-activity;sid:84792834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929728)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929728/; classtype:trojan-activity;sid:84792828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929729)"; flow:established,from_client; content:"GET"; http_method; content:"/sarm"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"193.161.193.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929729/; classtype:trojan-activity;sid:84792829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929730)"; flow:established,from_client; content:"GET"; http_method; content:"/sarm64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.161.193.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929730/; classtype:trojan-activity;sid:84792830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929731)"; flow:established,from_client; content:"GET"; http_method; content:"/smipsel"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"193.161.193.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929731/; classtype:trojan-activity;sid:84792831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929732)"; flow:established,from_client; content:"GET"; http_method; content:"/sx86"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"193.161.193.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929732/; classtype:trojan-activity;sid:84792832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929733)"; flow:established,from_client; content:"GET"; http_method; content:"/smips"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"193.161.193.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929733/; classtype:trojan-activity;sid:84792833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929727)"; flow:established,from_client; content:"GET"; http_method; content:"/i1/2026/09/26/9kwuzy.png"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"upload.cc"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929727/; classtype:trojan-activity;sid:84792827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929726)"; flow:established,from_client; content:"GET"; http_method; content:"/h813rix0"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"manmenduster.online"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929726/; classtype:trojan-activity;sid:84792826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929725)"; flow:established,from_client; content:"GET"; http_method; content:"/40/goodthingsforme.hta"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"144.172.116.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929725/; classtype:trojan-activity;sid:84792825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929724)"; flow:established,from_client; content:"GET"; http_method; content:"/40/workinggood.vbe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"144.172.116.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929724/; classtype:trojan-activity;sid:84792824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929723)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.116.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929723/; classtype:trojan-activity;sid:84792823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929722)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.3.202.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929722/; classtype:trojan-activity;sid:84792822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929719)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.184.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929719/; classtype:trojan-activity;sid:84792819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929720)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.137.44"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929720/; classtype:trojan-activity;sid:84792820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929721)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.101.66"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929721/; classtype:trojan-activity;sid:84792821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929718)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929718/; classtype:trojan-activity;sid:84792818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929701)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929701/; classtype:trojan-activity;sid:84792801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929702)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3-host"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929702/; classtype:trojan-activity;sid:84792802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929703)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.armv5l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929703/; classtype:trojan-activity;sid:84792803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929704)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.i686"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929704/; classtype:trojan-activity;sid:84792804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929705)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.i486"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929705/; classtype:trojan-activity;sid:84792805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929706)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929706/; classtype:trojan-activity;sid:84792806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929707)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.powerpc-440fp"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929707/; classtype:trojan-activity;sid:84792807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929708)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.powerpc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929708/; classtype:trojan-activity;sid:84792808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929709)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.armv7l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929709/; classtype:trojan-activity;sid:84792809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929710)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.armv4l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929710/; classtype:trojan-activity;sid:84792810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929711)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_dbg2"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929711/; classtype:trojan-activity;sid:84792811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929712)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.m68k"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929712/; classtype:trojan-activity;sid:84792812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929713)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.armv6l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929713/; classtype:trojan-activity;sid:84792813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929714)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929714/; classtype:trojan-activity;sid:84792814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929715)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.sh4"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929715/; classtype:trojan-activity;sid:84792815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929716)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.i586"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929716/; classtype:trojan-activity;sid:84792816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929717)"; flow:established,from_client; content:"GET"; http_method; content:"/qv3.arc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929717/; classtype:trojan-activity;sid:84792817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929698)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.235.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929698/; classtype:trojan-activity;sid:84792798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929699)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.171.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929699/; classtype:trojan-activity;sid:84792799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929700)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.238.224"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929700/; classtype:trojan-activity;sid:84792800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929696)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.203.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929696/; classtype:trojan-activity;sid:84792796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929697)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.44.136.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929697/; classtype:trojan-activity;sid:84792797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929695)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"36.255.97.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929695/; classtype:trojan-activity;sid:84792795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929694)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"36.255.97.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929694/; classtype:trojan-activity;sid:84792794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929693)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"102.220.163.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929693/; classtype:trojan-activity;sid:84792793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929686)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.i486"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929686/; classtype:trojan-activity;sid:84792786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929687)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929687/; classtype:trojan-activity;sid:84792787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929688)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929688/; classtype:trojan-activity;sid:84792788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929689)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929689/; classtype:trojan-activity;sid:84792789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929690)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsrouter"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929690/; classtype:trojan-activity;sid:84792790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929691)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929691/; classtype:trojan-activity;sid:84792791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929692)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929692/; classtype:trojan-activity;sid:84792792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929685)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.arc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929685/; classtype:trojan-activity;sid:84792785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929684)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929684/; classtype:trojan-activity;sid:84792784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929683)"; flow:established,from_client; content:"GET"; http_method; content:"/client.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"103.231.13.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929683/; classtype:trojan-activity;sid:84792783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929682)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"45.61.183.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929682/; classtype:trojan-activity;sid:84792782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929681)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.234.128.58"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929681/; classtype:trojan-activity;sid:84792781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929680)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.3.202.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929680/; classtype:trojan-activity;sid:84792780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929679)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.233.244.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929679/; classtype:trojan-activity;sid:84792779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929677)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.195.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929677/; classtype:trojan-activity;sid:84792777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929678)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.104.39.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929678/; classtype:trojan-activity;sid:84792778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929676)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.138.175.151"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929676/; classtype:trojan-activity;sid:84792776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929675)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/dbg"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929675/; classtype:trojan-activity;sid:84792775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929674)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.147.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929674/; classtype:trojan-activity;sid:84792774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929670)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.176.25"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929670/; classtype:trojan-activity;sid:84792770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929671)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.36.197.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929671/; classtype:trojan-activity;sid:84792771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929672)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.67.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929672/; classtype:trojan-activity;sid:84792772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929673)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.236.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929673/; classtype:trojan-activity;sid:84792773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929668)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"102.220.161.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929668/; classtype:trojan-activity;sid:84792768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929669)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"102.220.161.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929669/; classtype:trojan-activity;sid:84792769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929666)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"102.220.163.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929666/; classtype:trojan-activity;sid:84792766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929667)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"102.220.163.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929667/; classtype:trojan-activity;sid:84792767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929665)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.171.160"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929665/; classtype:trojan-activity;sid:84792765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929664)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.239.56.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929664/; classtype:trojan-activity;sid:84792764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929660)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.67.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929660/; classtype:trojan-activity;sid:84792760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929661)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.175.151"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929661/; classtype:trojan-activity;sid:84792761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929662)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.143.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929662/; classtype:trojan-activity;sid:84792762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929663)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.248.255"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929663/; classtype:trojan-activity;sid:84792763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929659)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.129.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929659/; classtype:trojan-activity;sid:84792759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929658)"; flow:established,from_client; content:"GET"; http_method; content:"/yarn"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929658/; classtype:trojan-activity;sid:84792758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929655)"; flow:established,from_client; content:"GET"; http_method; content:"/pay"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929655/; classtype:trojan-activity;sid:84792755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929656)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.spc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929656/; classtype:trojan-activity;sid:84792756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929657)"; flow:established,from_client; content:"GET"; http_method; content:"/bin"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929657/; classtype:trojan-activity;sid:84792757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929653)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"201.110.189.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929653/; classtype:trojan-activity;sid:84792753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929654)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.143.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929654/; classtype:trojan-activity;sid:84792754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929652)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.53.209.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929652/; classtype:trojan-activity;sid:84792752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929651)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.248.255"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929651/; classtype:trojan-activity;sid:84792751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929647)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.77.248.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929647/; classtype:trojan-activity;sid:84792747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929648)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.202.143"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929648/; classtype:trojan-activity;sid:84792748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929649)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.55.115.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929649/; classtype:trojan-activity;sid:84792749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929650)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.190.133"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929650/; classtype:trojan-activity;sid:84792750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929646)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.24.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929646/; classtype:trojan-activity;sid:84792746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929645)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.42"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929645/; classtype:trojan-activity;sid:84792745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929644)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.221.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929644/; classtype:trojan-activity;sid:84792744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929642)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.8.22.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929642/; classtype:trojan-activity;sid:84792742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.49.145"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929643/; classtype:trojan-activity;sid:84792743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929640)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929640/; classtype:trojan-activity;sid:84792740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929641)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.100.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929641/; classtype:trojan-activity;sid:84792741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929639)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929639/; classtype:trojan-activity;sid:84792739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929638)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.18.62.52"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929638/; classtype:trojan-activity;sid:84792738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929637)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.221"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929637/; classtype:trojan-activity;sid:84792737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929635)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.158.184"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929635/; classtype:trojan-activity;sid:84792735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929636)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.171.160"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929636/; classtype:trojan-activity;sid:84792736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.100.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929633/; classtype:trojan-activity;sid:84792733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929634)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"108.168.10.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929634/; classtype:trojan-activity;sid:84792734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929632)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.22.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929632/; classtype:trojan-activity;sid:84792732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929631)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.98.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929631/; classtype:trojan-activity;sid:84792731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929630)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.250.1.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929630/; classtype:trojan-activity;sid:84792730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929628)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.70.3"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929628/; classtype:trojan-activity;sid:84792728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929629)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.26.82.129"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929629/; classtype:trojan-activity;sid:84792729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929624)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.15.69.204"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929624/; classtype:trojan-activity;sid:84792724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929625)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.68.162.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929625/; classtype:trojan-activity;sid:84792725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929626)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929626/; classtype:trojan-activity;sid:84792726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929627)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.59.233.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929627/; classtype:trojan-activity;sid:84792727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929623)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.249.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929623/; classtype:trojan-activity;sid:84792723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929622)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.205.158.224"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929622/; classtype:trojan-activity;sid:84792722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929621)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.59.233.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929621/; classtype:trojan-activity;sid:84792721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929620)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"95.15.69.204"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929620/; classtype:trojan-activity;sid:84792720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929618)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.101.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929618/; classtype:trojan-activity;sid:84792718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929619)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.25.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929619/; classtype:trojan-activity;sid:84792719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929617)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.39.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929617/; classtype:trojan-activity;sid:84792717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929616)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929616/; classtype:trojan-activity;sid:84792716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929615)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.93.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929615/; classtype:trojan-activity;sid:84792715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929614)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.114.34.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929614/; classtype:trojan-activity;sid:84792714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929613)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929613/; classtype:trojan-activity;sid:84792713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929607)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.128.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929607/; classtype:trojan-activity;sid:84792707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929608)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.68.162.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929608/; classtype:trojan-activity;sid:84792708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929609)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.202.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929609/; classtype:trojan-activity;sid:84792709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929610)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.43.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929610/; classtype:trojan-activity;sid:84792710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929611)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.34.37"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929611/; classtype:trojan-activity;sid:84792711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929612)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.168.132.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929612/; classtype:trojan-activity;sid:84792712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929606)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.10.128.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929606/; classtype:trojan-activity;sid:84792706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929604)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.93.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929604/; classtype:trojan-activity;sid:84792704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929605)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.182.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929605/; classtype:trojan-activity;sid:84792705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929603)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.144.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929603/; classtype:trojan-activity;sid:84792703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929601)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.138.130.27"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929601/; classtype:trojan-activity;sid:84792701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929602)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.162.82.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929602/; classtype:trojan-activity;sid:84792702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929598)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.109.210.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929598/; classtype:trojan-activity;sid:84792698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929599)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.202.143"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929599/; classtype:trojan-activity;sid:84792699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929600)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.34.37"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929600/; classtype:trojan-activity;sid:84792700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929597)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.34.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929597/; classtype:trojan-activity;sid:84792697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929594)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.182.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929594/; classtype:trojan-activity;sid:84792694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929595)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.77.248.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929595/; classtype:trojan-activity;sid:84792695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929596)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.138.118"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929596/; classtype:trojan-activity;sid:84792696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929591)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"157.66.146.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929591/; classtype:trojan-activity;sid:84792691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929592)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.245.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929592/; classtype:trojan-activity;sid:84792692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929593)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.34.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929593/; classtype:trojan-activity;sid:84792693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929590)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.213.86.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929590/; classtype:trojan-activity;sid:84792690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929589)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.226.49"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929589/; classtype:trojan-activity;sid:84792689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929588)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929588/; classtype:trojan-activity;sid:84792688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929587)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.mpsl"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929587/; classtype:trojan-activity;sid:84792687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929585)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.244.15.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929585/; classtype:trojan-activity;sid:84792685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929586)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.227.65.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929586/; classtype:trojan-activity;sid:84792686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929581)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.33.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929581/; classtype:trojan-activity;sid:84792681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929582)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.156.33.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929582/; classtype:trojan-activity;sid:84792682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929583)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.21.135"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929583/; classtype:trojan-activity;sid:84792683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929584)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.158.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929584/; classtype:trojan-activity;sid:84792684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929568)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.ppc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929568/; classtype:trojan-activity;sid:84792668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929569)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.m68k"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929569/; classtype:trojan-activity;sid:84792669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929570)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.sh4"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929570/; classtype:trojan-activity;sid:84792670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929571)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.spc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929571/; classtype:trojan-activity;sid:84792671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929572)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.arm7"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929572/; classtype:trojan-activity;sid:84792672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929573)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.i686"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929573/; classtype:trojan-activity;sid:84792673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929574)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.x86_64"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929574/; classtype:trojan-activity;sid:84792674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929575)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.arm6"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929575/; classtype:trojan-activity;sid:84792675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929576)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.x86"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929576/; classtype:trojan-activity;sid:84792676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929577)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.mips"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929577/; classtype:trojan-activity;sid:84792677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929578)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.arc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929578/; classtype:trojan-activity;sid:84792678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929579)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.i486"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929579/; classtype:trojan-activity;sid:84792679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929580)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/boatnet.arm5"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929580/; classtype:trojan-activity;sid:84792680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929567)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.56.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929567/; classtype:trojan-activity;sid:84792667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929566)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.227.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929566/; classtype:trojan-activity;sid:84792666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929564)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.180.120.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929564/; classtype:trojan-activity;sid:84792664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929565)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.223.142.62"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929565/; classtype:trojan-activity;sid:84792665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929560)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.223.142.62"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929560/; classtype:trojan-activity;sid:84792660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929561)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.255.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929561/; classtype:trojan-activity;sid:84792661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929562)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.255.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929562/; classtype:trojan-activity;sid:84792662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929563)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.201.35"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929563/; classtype:trojan-activity;sid:84792663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929559)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.187.177.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929559/; classtype:trojan-activity;sid:84792659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929558)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.226.49"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929558/; classtype:trojan-activity;sid:84792658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929556)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.255.41.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929556/; classtype:trojan-activity;sid:84792656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929557)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.158.31"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929557/; classtype:trojan-activity;sid:84792657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929555)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.56.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929555/; classtype:trojan-activity;sid:84792655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929554)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.236.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929554/; classtype:trojan-activity;sid:84792654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929553)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.151.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929553/; classtype:trojan-activity;sid:84792653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929551)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.134.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929551/; classtype:trojan-activity;sid:84792651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929552)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.123.210.33"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929552/; classtype:trojan-activity;sid:84792652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929550)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.115.31"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929550/; classtype:trojan-activity;sid:84792650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929549)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.134.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929549/; classtype:trojan-activity;sid:84792649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929548)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.238.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929548/; classtype:trojan-activity;sid:84792648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929545)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.4.241.99"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929545/; classtype:trojan-activity;sid:84792645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929546)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.115.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929546/; classtype:trojan-activity;sid:84792646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929547)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.238.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929547/; classtype:trojan-activity;sid:84792647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929541)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.242.58.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929541/; classtype:trojan-activity;sid:84792641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929542)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.101.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929542/; classtype:trojan-activity;sid:84792642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929543)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.227.225.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929543/; classtype:trojan-activity;sid:84792643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929544)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.77.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929544/; classtype:trojan-activity;sid:84792644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929540)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.115.31"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929540/; classtype:trojan-activity;sid:84792640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929539)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.225.101.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929539/; classtype:trojan-activity;sid:84792639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929537)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.9.11"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929537/; classtype:trojan-activity;sid:84792637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929538)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.187.17.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929538/; classtype:trojan-activity;sid:84792638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929536)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.162.131.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_06; reference:url, urlhaus.abuse.ch/url/3929536/; classtype:trojan-activity;sid:84792636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929535)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.21.135"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929535/; classtype:trojan-activity;sid:84792635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929534)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.242.58.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929534/; classtype:trojan-activity;sid:84792634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929533)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"1.62.94.126"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929533/; classtype:trojan-activity;sid:84792633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929532)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.219.186.191"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929532/; classtype:trojan-activity;sid:84792632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929530)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.137.62.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929530/; classtype:trojan-activity;sid:84792630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929531)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.188.214.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929531/; classtype:trojan-activity;sid:84792631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929529)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.9.11"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929529/; classtype:trojan-activity;sid:84792629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929527)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.225.241.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929527/; classtype:trojan-activity;sid:84792627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929528)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.141.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929528/; classtype:trojan-activity;sid:84792628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929526)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.176.25"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929526/; classtype:trojan-activity;sid:84792626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929525)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.225.241.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929525/; classtype:trojan-activity;sid:84792625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929524)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929524/; classtype:trojan-activity;sid:84792624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929523)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.120.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929523/; classtype:trojan-activity;sid:84792623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929522)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.82.10"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929522/; classtype:trojan-activity;sid:84792622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929520)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.228.0.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929520/; classtype:trojan-activity;sid:84792620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929521)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.108.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929521/; classtype:trojan-activity;sid:84792621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929518)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.157.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929518/; classtype:trojan-activity;sid:84792618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929519)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.141.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929519/; classtype:trojan-activity;sid:84792619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929517)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.55.5.203"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929517/; classtype:trojan-activity;sid:84792617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929515)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.54.108.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929515/; classtype:trojan-activity;sid:84792615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929516)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.215.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929516/; classtype:trojan-activity;sid:84792616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929512)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.29.146.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929512/; classtype:trojan-activity;sid:84792612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929513)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.229.177.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929513/; classtype:trojan-activity;sid:84792613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929514)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/6107cbb0a359ada5_pyinfector.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929514/; classtype:trojan-activity;sid:84792614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929511)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.190.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929511/; classtype:trojan-activity;sid:84792611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929509)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.74.82.61"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929509/; classtype:trojan-activity;sid:84792609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929510)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.157.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929510/; classtype:trojan-activity;sid:84792610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929504)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.183.24.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929504/; classtype:trojan-activity;sid:84792604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929505)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.110.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929505/; classtype:trojan-activity;sid:84792605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929506)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.95.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929506/; classtype:trojan-activity;sid:84792606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929507)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.229.177.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929507/; classtype:trojan-activity;sid:84792607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929508)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.74.82.61"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929508/; classtype:trojan-activity;sid:84792608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929503)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.183.24.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929503/; classtype:trojan-activity;sid:84792603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929502)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.188.214.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929502/; classtype:trojan-activity;sid:84792602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929501)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.158.52.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929501/; classtype:trojan-activity;sid:84792601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929499)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.95.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929499/; classtype:trojan-activity;sid:84792599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929500)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.29.146.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929500/; classtype:trojan-activity;sid:84792600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929497)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.228.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929497/; classtype:trojan-activity;sid:84792597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929498)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.204.193.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929498/; classtype:trojan-activity;sid:84792598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929496)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.110.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929496/; classtype:trojan-activity;sid:84792596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929495)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.235.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929495/; classtype:trojan-activity;sid:84792595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929494)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.225.202.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929494/; classtype:trojan-activity;sid:84792594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929493)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.204.193.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929493/; classtype:trojan-activity;sid:84792593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929492)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.141.164"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929492/; classtype:trojan-activity;sid:84792592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929490)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.180.120.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929490/; classtype:trojan-activity;sid:84792590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929491)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.150.51.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929491/; classtype:trojan-activity;sid:84792591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929489)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.215.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929489/; classtype:trojan-activity;sid:84792589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929488)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.213.166.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929488/; classtype:trojan-activity;sid:84792588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929487)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.242.23.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929487/; classtype:trojan-activity;sid:84792587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929486)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.70.47"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929486/; classtype:trojan-activity;sid:84792586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929483)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.1.251"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929483/; classtype:trojan-activity;sid:84792583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929484)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.185.245.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929484/; classtype:trojan-activity;sid:84792584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929485)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.195.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929485/; classtype:trojan-activity;sid:84792585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929481)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.225.202.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929481/; classtype:trojan-activity;sid:84792581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929482)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.87.194.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929482/; classtype:trojan-activity;sid:84792582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929479)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.237.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929479/; classtype:trojan-activity;sid:84792579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929480)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.1.251"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929480/; classtype:trojan-activity;sid:84792580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929477)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.174.171.111"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929477/; classtype:trojan-activity;sid:84792577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929478)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.137.200.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929478/; classtype:trojan-activity;sid:84792578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929476)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.174.171.111"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929476/; classtype:trojan-activity;sid:84792576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929475)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.251.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929475/; classtype:trojan-activity;sid:84792575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929474)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.239.44.32"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929474/; classtype:trojan-activity;sid:84792574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929473)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.176.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929473/; classtype:trojan-activity;sid:84792573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929472)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929472/; classtype:trojan-activity;sid:84792572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929471)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929471/; classtype:trojan-activity;sid:84792571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929470)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929470/; classtype:trojan-activity;sid:84792570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929464)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929464/; classtype:trojan-activity;sid:84792564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929465)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929465/; classtype:trojan-activity;sid:84792565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929466)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929466/; classtype:trojan-activity;sid:84792566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929467)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929467/; classtype:trojan-activity;sid:84792567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929468)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929468/; classtype:trojan-activity;sid:84792568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929469)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929469/; classtype:trojan-activity;sid:84792569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929463)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929463/; classtype:trojan-activity;sid:84792563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929461)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.191.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929461/; classtype:trojan-activity;sid:84792561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929462)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.9"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929462/; classtype:trojan-activity;sid:84792562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929458)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.58.211.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929458/; classtype:trojan-activity;sid:84792558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929459)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.181.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929459/; classtype:trojan-activity;sid:84792559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929460)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.208.123.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929460/; classtype:trojan-activity;sid:84792560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929457)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.181.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929457/; classtype:trojan-activity;sid:84792557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929456)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.176.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929456/; classtype:trojan-activity;sid:84792556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929455)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.197.65.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929455/; classtype:trojan-activity;sid:84792555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929454)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.58.211.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929454/; classtype:trojan-activity;sid:84792554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929453)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.68.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929453/; classtype:trojan-activity;sid:84792553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929452)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.208.123.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929452/; classtype:trojan-activity;sid:84792552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929451)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929451/; classtype:trojan-activity;sid:84792551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929450)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.180.59.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929450/; classtype:trojan-activity;sid:84792550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929449)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.40.149.116"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929449/; classtype:trojan-activity;sid:84792549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929446)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.74.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929446/; classtype:trojan-activity;sid:84792546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929447)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.118.245.201"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929447/; classtype:trojan-activity;sid:84792547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929448)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.63.146.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929448/; classtype:trojan-activity;sid:84792548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929445)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.84.50"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929445/; classtype:trojan-activity;sid:84792545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929444)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.171.239.86"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929444/; classtype:trojan-activity;sid:84792544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929443)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.63.146.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929443/; classtype:trojan-activity;sid:84792543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929441)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929441/; classtype:trojan-activity;sid:84792541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929442)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.26.99"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929442/; classtype:trojan-activity;sid:84792542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929439)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.158.31"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929439/; classtype:trojan-activity;sid:84792539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929440)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.251.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929440/; classtype:trojan-activity;sid:84792540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929435)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.141.152.243"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929435/; classtype:trojan-activity;sid:84792535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929436)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.177.28.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929436/; classtype:trojan-activity;sid:84792536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929437)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.84.50"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929437/; classtype:trojan-activity;sid:84792537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929438)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.220.221.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929438/; classtype:trojan-activity;sid:84792538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929434)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.205.104.122"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929434/; classtype:trojan-activity;sid:84792534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929433)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.141.152.243"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929433/; classtype:trojan-activity;sid:84792533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929430)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.116.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929430/; classtype:trojan-activity;sid:84792530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929431)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.187.177.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929431/; classtype:trojan-activity;sid:84792531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929432)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.221.26.99"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929432/; classtype:trojan-activity;sid:84792532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929429)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.205.104.122"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929429/; classtype:trojan-activity;sid:84792529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929426)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.130.63.21"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929426/; classtype:trojan-activity;sid:84792526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929427)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.154.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929427/; classtype:trojan-activity;sid:84792527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929428)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.130.63.21"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929428/; classtype:trojan-activity;sid:84792528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929425)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.38.0"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929425/; classtype:trojan-activity;sid:84792525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929424)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnarmv6lxnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929424/; classtype:trojan-activity;sid:84792524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929423)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni686xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929423/; classtype:trojan-activity;sid:84792523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929421)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929421/; classtype:trojan-activity;sid:84792521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929422)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnarmv4lxnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929422/; classtype:trojan-activity;sid:84792522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929418)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929418/; classtype:trojan-activity;sid:84792518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929419)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipselxnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929419/; classtype:trojan-activity;sid:84792519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929420)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929420/; classtype:trojan-activity;sid:84792520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929412)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929412/; classtype:trojan-activity;sid:84792512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929413)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnarmv7lxnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929413/; classtype:trojan-activity;sid:84792513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929414)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpc440fpxnxn"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929414/; classtype:trojan-activity;sid:84792514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929415)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929415/; classtype:trojan-activity;sid:84792515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929416)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnarmv5lxnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929416/; classtype:trojan-activity;sid:84792516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929417)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni586xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929417/; classtype:trojan-activity;sid:84792517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929410)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.237.77.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929410/; classtype:trojan-activity;sid:84792510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929411)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.51.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929411/; classtype:trojan-activity;sid:84792511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929409)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1182947418598289418/1556723625334153236/bundle.zip|3f|ex=6ac5335a|7c|26|7c|is=6ac3e1da|7c|26|7c|hm=99e0ea109bb220f9675d652ca1f0963fad943aafbfe2413ca8ba1113de6e56de|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929409/; classtype:trojan-activity;sid:84792509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929408)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1515230295643787377/1556719164180275301/bundle_1.zip|3f|ex=6ac52f33|7c|26|7c|is=6ac3ddb3|7c|26|7c|hm=742cc81770b60be7b3cf4ff56eacc9c19ef6cc1f3b47245f83ae161853cd6c74|7c|26|7c|"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929408/; classtype:trojan-activity;sid:84792508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929407)"; flow:established,from_client; content:"GET"; http_method; content:"/cdn/v2/9f4e7a2c1b8d.png"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"thisisafalsepositive.st"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929407/; classtype:trojan-activity;sid:84792507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929406)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo1/raw/refs/heads/main/frostclient-1.21.11.jar"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929406/; classtype:trojan-activity;sid:84792506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929405)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.70.64.64"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929405/; classtype:trojan-activity;sid:84792505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929404)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.238.89"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929404/; classtype:trojan-activity;sid:84792504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929403)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/svchostk.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"gitrm.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929403/; classtype:trojan-activity;sid:84792503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929400)"; flow:established,from_client; content:"GET"; http_method; content:"/server123-lab/analyis-file-malware-threardfox/raw/refs/heads/main/download2.exe"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929400/; classtype:trojan-activity;sid:84792500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929401)"; flow:established,from_client; content:"GET"; http_method; content:"/ktn1703/vanish-tool-discord/refs/heads/main/obf-vanish.py"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929401/; classtype:trojan-activity;sid:84792501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929402)"; flow:established,from_client; content:"GET"; http_method; content:"/f/b8eac6853dcc452bc021-implant-linux-amd64"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"144.126.148.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929402/; classtype:trojan-activity;sid:84792502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929392)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_6ca450ddf497eb0f.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929392/; classtype:trojan-activity;sid:84792492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929393)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.111.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929393/; classtype:trojan-activity;sid:84792493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929394)"; flow:established,from_client; content:"GET"; http_method; content:"/hilix.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929394/; classtype:trojan-activity;sid:84792494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929395)"; flow:established,from_client; content:"GET"; http_method; content:"/87sbhas6as.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929395/; classtype:trojan-activity;sid:84792495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929396)"; flow:established,from_client; content:"GET"; http_method; content:"/hunterteamc2/huynhtoanupload/raw/refs/heads/main/mko1.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929396/; classtype:trojan-activity;sid:84792496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929397)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929397/; classtype:trojan-activity;sid:84792497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929398)"; flow:established,from_client; content:"GET"; http_method; content:"/download/corz-client.jar"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"white-mode-a35b.modpages.workers.dev"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929398/; classtype:trojan-activity;sid:84792498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929399)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.253.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929399/; classtype:trojan-activity;sid:84792499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929388)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.38.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929388/; classtype:trojan-activity;sid:84792488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929389)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.207.221.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929389/; classtype:trojan-activity;sid:84792489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929390)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.237.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929390/; classtype:trojan-activity;sid:84792490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929391)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.103.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929391/; classtype:trojan-activity;sid:84792491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929386)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm4"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929386/; classtype:trojan-activity;sid:84792486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929387)"; flow:established,from_client; content:"GET"; http_method; content:"/apix.ps1"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"gitrm.cfd"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929387/; classtype:trojan-activity;sid:84792487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929385)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929385/; classtype:trojan-activity;sid:84792485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929384)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"111.14.169.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929384/; classtype:trojan-activity;sid:84792484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929383)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.149.67.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929383/; classtype:trojan-activity;sid:84792483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929382)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.161.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929382/; classtype:trojan-activity;sid:84792482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929380)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.170.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929380/; classtype:trojan-activity;sid:84792480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929381)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.129.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929381/; classtype:trojan-activity;sid:84792481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929379)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.213.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929379/; classtype:trojan-activity;sid:84792479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929378)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.38.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929378/; classtype:trojan-activity;sid:84792478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929377)"; flow:established,from_client; content:"GET"; http_method; content:"/quickb.msi"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"91.92.34.63"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929377/; classtype:trojan-activity;sid:84792477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929376)"; flow:established,from_client; content:"GET"; http_method; content:"/newtonsoft.json.dll"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"96.62.71.22"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929376/; classtype:trojan-activity;sid:84792476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929375)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.14.169.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929375/; classtype:trojan-activity;sid:84792475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929374)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.161.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929374/; classtype:trojan-activity;sid:84792474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929373)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.139.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929373/; classtype:trojan-activity;sid:84792473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929372)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.247.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929372/; classtype:trojan-activity;sid:84792472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929371)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929371/; classtype:trojan-activity;sid:84792471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929369)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929369/; classtype:trojan-activity;sid:84792469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929370)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929370/; classtype:trojan-activity;sid:84792470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929368)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929368/; classtype:trojan-activity;sid:84792468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929367)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929367/; classtype:trojan-activity;sid:84792467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929363)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929363/; classtype:trojan-activity;sid:84792463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929364)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929364/; classtype:trojan-activity;sid:84792464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929365)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929365/; classtype:trojan-activity;sid:84792465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929366)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"31.56.19.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929366/; classtype:trojan-activity;sid:84792466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929362)"; flow:established,from_client; content:"GET"; http_method; content:"/111.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"193.148.56.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929362/; classtype:trojan-activity;sid:84792462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929361)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.238.240.68"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929361/; classtype:trojan-activity;sid:84792461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929360)"; flow:established,from_client; content:"GET"; http_method; content:"/proceso.vbs"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929360/; classtype:trojan-activity;sid:84792460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929356)"; flow:established,from_client; content:"GET"; http_method; content:"/sostener.vbs"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929356/; classtype:trojan-activity;sid:84792456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929357)"; flow:established,from_client; content:"GET"; http_method; content:"/proceso.vbs"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929357/; classtype:trojan-activity;sid:84792457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929358)"; flow:established,from_client; content:"GET"; http_method; content:"/sostener1.vbs"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929358/; classtype:trojan-activity;sid:84792458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929359)"; flow:established,from_client; content:"GET"; http_method; content:"/sostener.vbs"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929359/; classtype:trojan-activity;sid:84792459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929353)"; flow:established,from_client; content:"GET"; http_method; content:"/svchost.vbs"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929353/; classtype:trojan-activity;sid:84792453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929354)"; flow:established,from_client; content:"GET"; http_method; content:"/sostener1.vbs"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929354/; classtype:trojan-activity;sid:84792454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929355)"; flow:established,from_client; content:"GET"; http_method; content:"/svchost.vbs"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.161.65"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929355/; classtype:trojan-activity;sid:84792455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929351)"; flow:established,from_client; content:"GET"; http_method; content:"/nyx_bot_linux_mipsle_packed"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929351/; classtype:trojan-activity;sid:84792451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929352)"; flow:established,from_client; content:"GET"; http_method; content:"/nyx_bot_linux_amd64_packed"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929352/; classtype:trojan-activity;sid:84792452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929350)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929350/; classtype:trojan-activity;sid:84792450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929349)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929349/; classtype:trojan-activity;sid:84792449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929336)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929336/; classtype:trojan-activity;sid:84792436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929337)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929337/; classtype:trojan-activity;sid:84792437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929338)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929338/; classtype:trojan-activity;sid:84792438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929339)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929339/; classtype:trojan-activity;sid:84792439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929340)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929340/; classtype:trojan-activity;sid:84792440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929341)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929341/; classtype:trojan-activity;sid:84792441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929342)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/android-arm64"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929342/; classtype:trojan-activity;sid:84792442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929343)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929343/; classtype:trojan-activity;sid:84792443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929344)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/mipsel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929344/; classtype:trojan-activity;sid:84792444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929345)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929345/; classtype:trojan-activity;sid:84792445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929346)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929346/; classtype:trojan-activity;sid:84792446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929347)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/android-arm"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929347/; classtype:trojan-activity;sid:84792447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929348)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929348/; classtype:trojan-activity;sid:84792448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929335)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929335/; classtype:trojan-activity;sid:84792435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929332)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.i686"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929332/; classtype:trojan-activity;sid:84792432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929333)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv6l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929333/; classtype:trojan-activity;sid:84792433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929334)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929334/; classtype:trojan-activity;sid:84792434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929331)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.228.247.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929331/; classtype:trojan-activity;sid:84792431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929329)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929329/; classtype:trojan-activity;sid:84792429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929330)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.251.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929330/; classtype:trojan-activity;sid:84792430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929327)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.43.45.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929327/; classtype:trojan-activity;sid:84792427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929328)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.228.57"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929328/; classtype:trojan-activity;sid:84792428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929322)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929322/; classtype:trojan-activity;sid:84792422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929323)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.powerpc"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929323/; classtype:trojan-activity;sid:84792423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929324)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.i586"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929324/; classtype:trojan-activity;sid:84792424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929325)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mipsel"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929325/; classtype:trojan-activity;sid:84792425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929326)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv4l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929326/; classtype:trojan-activity;sid:84792426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929320)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929320/; classtype:trojan-activity;sid:84792420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929321)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv5l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929321/; classtype:trojan-activity;sid:84792421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929318)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.arc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929318/; classtype:trojan-activity;sid:84792418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929319)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929319/; classtype:trojan-activity;sid:84792419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929312)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.arm6"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929312/; classtype:trojan-activity;sid:84792412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929313)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929313/; classtype:trojan-activity;sid:84792413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929314)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929314/; classtype:trojan-activity;sid:84792414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929315)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929315/; classtype:trojan-activity;sid:84792415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929316)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929316/; classtype:trojan-activity;sid:84792416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929317)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.spc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929317/; classtype:trojan-activity;sid:84792417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929309)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929309/; classtype:trojan-activity;sid:84792409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929310)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.x86_64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929310/; classtype:trojan-activity;sid:84792410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929311)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929311/; classtype:trojan-activity;sid:84792411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929306)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.i686"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929306/; classtype:trojan-activity;sid:84792406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929307)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929307/; classtype:trojan-activity;sid:84792407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929308)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/space.ppc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929308/; classtype:trojan-activity;sid:84792408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929305)"; flow:established,from_client; content:"GET"; http_method; content:"/ipc.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929305/; classtype:trojan-activity;sid:84792405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929304)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929304/; classtype:trojan-activity;sid:84792404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929303)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929303/; classtype:trojan-activity;sid:84792403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929302)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929302/; classtype:trojan-activity;sid:84792402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929301)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929301/; classtype:trojan-activity;sid:84792401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929300)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929300/; classtype:trojan-activity;sid:84792400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929293)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64le"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929293/; classtype:trojan-activity;sid:84792393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929294)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929294/; classtype:trojan-activity;sid:84792394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929295)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929295/; classtype:trojan-activity;sid:84792395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929296)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929296/; classtype:trojan-activity;sid:84792396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929297)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929297/; classtype:trojan-activity;sid:84792397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929298)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929298/; classtype:trojan-activity;sid:84792398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929299)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929299/; classtype:trojan-activity;sid:84792399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929292)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64le"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929292/; classtype:trojan-activity;sid:84792392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929289)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929289/; classtype:trojan-activity;sid:84792389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929290)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929290/; classtype:trojan-activity;sid:84792390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929291)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929291/; classtype:trojan-activity;sid:84792391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929288)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.201.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929288/; classtype:trojan-activity;sid:84792388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929287)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.142.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929287/; classtype:trojan-activity;sid:84792387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929286)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"104.194.155.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929286/; classtype:trojan-activity;sid:84792386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929285)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"104.194.155.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929285/; classtype:trojan-activity;sid:84792385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929284)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.240.202.183"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929284/; classtype:trojan-activity;sid:84792384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929283)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.103.116.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929283/; classtype:trojan-activity;sid:84792383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929281)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.158.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929281/; classtype:trojan-activity;sid:84792381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929282)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.251.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929282/; classtype:trojan-activity;sid:84792382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929278)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.215.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929278/; classtype:trojan-activity;sid:84792378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929279)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.16.164.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929279/; classtype:trojan-activity;sid:84792379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929280)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.81.96.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929280/; classtype:trojan-activity;sid:84792380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929277)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.111.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929277/; classtype:trojan-activity;sid:84792377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929275)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.204.198.22"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929275/; classtype:trojan-activity;sid:84792375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929276)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.180.59.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929276/; classtype:trojan-activity;sid:84792376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929274)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"144.48.121.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929274/; classtype:trojan-activity;sid:84792374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929272)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.81.96.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929272/; classtype:trojan-activity;sid:84792372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929273)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.142.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929273/; classtype:trojan-activity;sid:84792373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929270)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.214.149.164"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929270/; classtype:trojan-activity;sid:84792370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929271)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929271/; classtype:trojan-activity;sid:84792371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929268)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.239.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929268/; classtype:trojan-activity;sid:84792368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929269)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.59.237.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929269/; classtype:trojan-activity;sid:84792369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929267)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.251.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929267/; classtype:trojan-activity;sid:84792367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929266)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.137.54.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929266/; classtype:trojan-activity;sid:84792366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929265)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.184.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929265/; classtype:trojan-activity;sid:84792365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929264)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.184.216"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929264/; classtype:trojan-activity;sid:84792364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929262)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.130.28"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929262/; classtype:trojan-activity;sid:84792362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929263)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.251.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929263/; classtype:trojan-activity;sid:84792363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929260)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.135"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929260/; classtype:trojan-activity;sid:84792360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929261)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.241.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929261/; classtype:trojan-activity;sid:84792361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929259)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.228.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929259/; classtype:trojan-activity;sid:84792359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929258)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/client-files/uploads/1791124176602-3baa8b5c-420e-4720-b7e2-a493fa7f8963.jar"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"aqclqkcfjwbgknkwnvmm.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929258/; classtype:trojan-activity;sid:84792358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929257)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/client-files/uploads/1791124818494-be5073d9-a31c-4676-8d64-c62002c6aa6d.jar"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"aqclqkcfjwbgknkwnvmm.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929257/; classtype:trojan-activity;sid:84792357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929256)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/client-files/uploads/1791124268555-4907942c-6c0d-4a06-8fdf-8f7bcb0a8e6a.jar"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"aqclqkcfjwbgknkwnvmm.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929256/; classtype:trojan-activity;sid:84792356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929255)"; flow:established,from_client; content:"GET"; http_method; content:"/d8wx/cyberdupe-1.0.0-1.21.11.jar"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"www.dosyaupload.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929255/; classtype:trojan-activity;sid:84792355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929254)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.64.184.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929254/; classtype:trojan-activity;sid:84792354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929253)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.135"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929253/; classtype:trojan-activity;sid:84792353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929252)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"223.10.2.193"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929252/; classtype:trojan-activity;sid:84792352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929251)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"223.10.2.193"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929251/; classtype:trojan-activity;sid:84792351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929250)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.54.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929250/; classtype:trojan-activity;sid:84792350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929249)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.184.181.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929249/; classtype:trojan-activity;sid:84792349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.184.181.83"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929248/; classtype:trojan-activity;sid:84792348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929246)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.212.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929246/; classtype:trojan-activity;sid:84792346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929247)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.26.165"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929247/; classtype:trojan-activity;sid:84792347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929245)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.1.147.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929245/; classtype:trojan-activity;sid:84792345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929244)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.63.241.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929244/; classtype:trojan-activity;sid:84792344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929242)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.168.17"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929242/; classtype:trojan-activity;sid:84792342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929243)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.237.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929243/; classtype:trojan-activity;sid:84792343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929236)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.50.118"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929236/; classtype:trojan-activity;sid:84792336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929237)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.85.205"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929237/; classtype:trojan-activity;sid:84792337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929238)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.209.65.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929238/; classtype:trojan-activity;sid:84792338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929239)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.85.205"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929239/; classtype:trojan-activity;sid:84792339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929240)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929240/; classtype:trojan-activity;sid:84792340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929241)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.78.135"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929241/; classtype:trojan-activity;sid:84792341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929235)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.54.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929235/; classtype:trojan-activity;sid:84792335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929233)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.177.32.104"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929233/; classtype:trojan-activity;sid:84792333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929234)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.16.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929234/; classtype:trojan-activity;sid:84792334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929232)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.202.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929232/; classtype:trojan-activity;sid:84792332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929231)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.10.44.157"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929231/; classtype:trojan-activity;sid:84792331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929230)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.10.44.157"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929230/; classtype:trojan-activity;sid:84792330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929229)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.227.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929229/; classtype:trojan-activity;sid:84792329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929226)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.172.186.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929226/; classtype:trojan-activity;sid:84792326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929227)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.55.5.203"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929227/; classtype:trojan-activity;sid:84792327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929228)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.7.220.160"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929228/; classtype:trojan-activity;sid:84792328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929225)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.31.228.93"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929225/; classtype:trojan-activity;sid:84792325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929223)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.181.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929223/; classtype:trojan-activity;sid:84792323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929224)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.181.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929224/; classtype:trojan-activity;sid:84792324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929221)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.85.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929221/; classtype:trojan-activity;sid:84792321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929222)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.151.104.143"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929222/; classtype:trojan-activity;sid:84792322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929220)"; flow:established,from_client; content:"GET"; http_method; content:"/adb.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929220/; classtype:trojan-activity;sid:84792320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929219)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.82.203.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929219/; classtype:trojan-activity;sid:84792319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929216)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.232.228.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929216/; classtype:trojan-activity;sid:84792316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929217)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.228.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929217/; classtype:trojan-activity;sid:84792317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929218)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.85.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929218/; classtype:trojan-activity;sid:84792318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929215)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.205.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929215/; classtype:trojan-activity;sid:84792315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929214)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.215.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929214/; classtype:trojan-activity;sid:84792314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929213)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.94.58.233"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929213/; classtype:trojan-activity;sid:84792313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929212)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.53.209.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929212/; classtype:trojan-activity;sid:84792312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929210)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.152.11.202"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929210/; classtype:trojan-activity;sid:84792310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929211)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.187.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929211/; classtype:trojan-activity;sid:84792311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929209)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.95.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929209/; classtype:trojan-activity;sid:84792309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929208)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929208/; classtype:trojan-activity;sid:84792308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929207)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.172"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929207/; classtype:trojan-activity;sid:84792307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929206)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.148.236.154"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929206/; classtype:trojan-activity;sid:84792306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929205)"; flow:established,from_client; content:"GET"; http_method; content:"/kizzyman1/wps/releases/download/v1/nu.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929205/; classtype:trojan-activity;sid:84792305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929204)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.103.67.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929204/; classtype:trojan-activity;sid:84792304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929203)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.170.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929203/; classtype:trojan-activity;sid:84792303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929202)"; flow:established,from_client; content:"GET"; http_method; content:"/uu_anccwz7.zip"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"uu.v2raynapps.com.cn"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929202/; classtype:trojan-activity;sid:84792302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929201)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.82.160.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929201/; classtype:trojan-activity;sid:84792301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929198)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.184.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929198/; classtype:trojan-activity;sid:84792298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929199)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.203.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929199/; classtype:trojan-activity;sid:84792299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929200)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.132.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929200/; classtype:trojan-activity;sid:84792300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929197)"; flow:established,from_client; content:"GET"; http_method; content:"/hunterteamc2/huynhtoanupload/raw/refs/heads/main/sirusrat.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929197/; classtype:trojan-activity;sid:84792297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929196)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.82.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929196/; classtype:trojan-activity;sid:84792296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929194)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.214.17.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929194/; classtype:trojan-activity;sid:84792294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929195)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.125.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929195/; classtype:trojan-activity;sid:84792295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929193)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.123.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929193/; classtype:trojan-activity;sid:84792293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929192)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.103.67.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929192/; classtype:trojan-activity;sid:84792292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929191)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.19.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929191/; classtype:trojan-activity;sid:84792291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.34.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929190/; classtype:trojan-activity;sid:84792290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929188)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.111.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929188/; classtype:trojan-activity;sid:84792288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.122.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929189/; classtype:trojan-activity;sid:84792289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929185)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"165.98.243.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929185/; classtype:trojan-activity;sid:84792285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929186)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.10.37"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929186/; classtype:trojan-activity;sid:84792286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929187)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.170.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929187/; classtype:trojan-activity;sid:84792287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929184)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.184.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929184/; classtype:trojan-activity;sid:84792284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929183)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.82.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929183/; classtype:trojan-activity;sid:84792283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929182)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"14.20.223.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929182/; classtype:trojan-activity;sid:84792282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929181)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.82.10"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929181/; classtype:trojan-activity;sid:84792281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929180)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.135.17"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929180/; classtype:trojan-activity;sid:84792280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929179)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.10.37"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929179/; classtype:trojan-activity;sid:84792279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929176)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.140.146.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929176/; classtype:trojan-activity;sid:84792276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929177)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.24.252.179"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929177/; classtype:trojan-activity;sid:84792277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929178)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.253.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929178/; classtype:trojan-activity;sid:84792278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929174)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.38.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929174/; classtype:trojan-activity;sid:84792274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929175)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.42"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929175/; classtype:trojan-activity;sid:84792275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929173)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.64.184.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929173/; classtype:trojan-activity;sid:84792273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929172)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.132.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929172/; classtype:trojan-activity;sid:84792272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929171)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.128.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929171/; classtype:trojan-activity;sid:84792271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929170)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.3.237"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929170/; classtype:trojan-activity;sid:84792270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.114.231.229"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929169/; classtype:trojan-activity;sid:84792269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929168)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.235.250.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929168/; classtype:trojan-activity;sid:84792268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929167)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.246.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929167/; classtype:trojan-activity;sid:84792267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929166)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.200.214.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929166/; classtype:trojan-activity;sid:84792266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929165)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.188.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929165/; classtype:trojan-activity;sid:84792265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929164)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.38.0"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929164/; classtype:trojan-activity;sid:84792264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929162)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.200.214.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929162/; classtype:trojan-activity;sid:84792262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929163)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.211.74.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929163/; classtype:trojan-activity;sid:84792263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929160)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.85.49.126"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929160/; classtype:trojan-activity;sid:84792260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929161)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.118.244.148"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929161/; classtype:trojan-activity;sid:84792261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929159)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.130.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929159/; classtype:trojan-activity;sid:84792259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929156)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.251.56"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929156/; classtype:trojan-activity;sid:84792256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929157)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.251.56"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929157/; classtype:trojan-activity;sid:84792257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929158)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.43.45.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929158/; classtype:trojan-activity;sid:84792258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929155)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.5.109.239"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929155/; classtype:trojan-activity;sid:84792255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929154)"; flow:established,from_client; content:"GET"; http_method; content:"/files/8468794285/ftjnsgb.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929154/; classtype:trojan-activity;sid:84792254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929153)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.14.188.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929153/; classtype:trojan-activity;sid:84792253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929152)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.38.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929152/; classtype:trojan-activity;sid:84792252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929144)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.52.181"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929144/; classtype:trojan-activity;sid:84792244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929145)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.85.49.126"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929145/; classtype:trojan-activity;sid:84792245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929146)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.118.244.148"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929146/; classtype:trojan-activity;sid:84792246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929147)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.245.17"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929147/; classtype:trojan-activity;sid:84792247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929148)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.52.181"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929148/; classtype:trojan-activity;sid:84792248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929149)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.212.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929149/; classtype:trojan-activity;sid:84792249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929150)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.26.226.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929150/; classtype:trojan-activity;sid:84792250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929151)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.55.37.26"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929151/; classtype:trojan-activity;sid:84792251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929143)"; flow:established,from_client; content:"GET"; http_method; content:"/ssh_"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"eo3wuo9z334anlh.m.pipedream.net"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929143/; classtype:trojan-activity;sid:84792243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929142)"; flow:established,from_client; content:"GET"; http_method; content:"/zedi"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.116.243.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929142/; classtype:trojan-activity;sid:84792242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929141)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_0d808c6ece797f4b.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929141/; classtype:trojan-activity;sid:84792241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929140)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rodriakd-8413d.appspot.com/o/dll%2ftest%20dll%20procesos.txt|3f|alt=media|7c|26|7c|token=2bf65d96-1f62-419e-9e8c-83f20877a53b"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929140/; classtype:trojan-activity;sid:84792240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929139)"; flow:established,from_client; content:"GET"; http_method; content:"/new1/secured_stub.ps1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"www.tmcksa.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929139/; classtype:trojan-activity;sid:84792239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929138)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_010950.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929138/; classtype:trojan-activity;sid:84792238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929137)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.178.193"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929137/; classtype:trojan-activity;sid:84792237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929135)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.140.190.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929135/; classtype:trojan-activity;sid:84792235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929136)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.78.135"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929136/; classtype:trojan-activity;sid:84792236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929131)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.55.197.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929131/; classtype:trojan-activity;sid:84792231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929132)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.55.197.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929132/; classtype:trojan-activity;sid:84792232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929133)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.151.42.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929133/; classtype:trojan-activity;sid:84792233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929134)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.172.218.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929134/; classtype:trojan-activity;sid:84792234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929129)"; flow:established,from_client; content:"GET"; http_method; content:"/33/gfg.hta"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"172.245.155.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929129/; classtype:trojan-activity;sid:84792229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929130)"; flow:established,from_client; content:"GET"; http_method; content:"/subtrahuyr.pcx"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"primeemberq.cfd"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929130/; classtype:trojan-activity;sid:84792230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929126)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.arc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929126/; classtype:trojan-activity;sid:84792226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929127)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929127/; classtype:trojan-activity;sid:84792227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929128)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.aarch64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929128/; classtype:trojan-activity;sid:84792228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929121)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929121/; classtype:trojan-activity;sid:84792221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929122)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv6l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929122/; classtype:trojan-activity;sid:84792222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929123)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929123/; classtype:trojan-activity;sid:84792223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929124)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929124/; classtype:trojan-activity;sid:84792224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929125)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv7l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929125/; classtype:trojan-activity;sid:84792225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929120)"; flow:established,from_client; content:"GET"; http_method; content:"/js/true.zip"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"fullhouse.ae"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929120/; classtype:trojan-activity;sid:84792220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929117)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929117/; classtype:trojan-activity;sid:84792217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929118)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929118/; classtype:trojan-activity;sid:84792218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929119)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mipsel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929119/; classtype:trojan-activity;sid:84792219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929116)"; flow:established,from_client; content:"GET"; http_method; content:"/afbryderen.pcz"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"primeemberq.cfd"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929116/; classtype:trojan-activity;sid:84792216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929115)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929115/; classtype:trojan-activity;sid:84792215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929114)"; flow:established,from_client; content:"GET"; http_method; content:"/new/secured_stub.ps1"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"www.tmcksa.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929114/; classtype:trojan-activity;sid:84792214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929112)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=19_fehbnnhwcmu2_17howw-aoer7hl1cb"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929112/; classtype:trojan-activity;sid:84792212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929113)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.26.226.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929113/; classtype:trojan-activity;sid:84792213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929110)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.94.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929110/; classtype:trojan-activity;sid:84792210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929111)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.185.245.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929111/; classtype:trojan-activity;sid:84792211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929109)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.24.161.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929109/; classtype:trojan-activity;sid:84792209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929108)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/text/bhxlvkt/erlodfc/stykqbz/puresecured_stub.ps1"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"new-orleans.pl"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929108/; classtype:trojan-activity;sid:84792208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929107)"; flow:established,from_client; content:"GET"; http_method; content:"/components/com_media/fkqabmp/ntxqre1/edfwcgi/pwsecured_stub.ps1"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"www.beinke-aufzuege.de"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929107/; classtype:trojan-activity;sid:84792207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929106)"; flow:established,from_client; content:"GET"; http_method; content:"/img_040049.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"summitcapitalpatners.info"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929106/; classtype:trojan-activity;sid:84792206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929105)"; flow:established,from_client; content:"GET"; http_method; content:"/evbxwojeoy"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929105/; classtype:trojan-activity;sid:84792205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929104)"; flow:established,from_client; content:"GET"; http_method; content:"/components/com_media/fkqabmp/ntxqre1/edfwcgi/mlsecured_stub.ps1"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"www.beinke-aufzuege.de"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929104/; classtype:trojan-activity;sid:84792204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929103)"; flow:established,from_client; content:"GET"; http_method; content:"/news/secured_stub.ps1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"www.tmcksa.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929103/; classtype:trojan-activity;sid:84792203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929102)"; flow:established,from_client; content:"GET"; http_method; content:"/bvbhfhdfb/oztdkgeygnmg211.bin"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"gloryhaven.org"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929102/; classtype:trojan-activity;sid:84792202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929101)"; flow:established,from_client; content:"GET"; http_method; content:"/bvbhfhdfb/obduktioners.lzh"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"gloryhaven.org"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929101/; classtype:trojan-activity;sid:84792201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929100)"; flow:established,from_client; content:"GET"; http_method; content:"/tsl/driftsregnskabets.lzh"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"greatwhite.me"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929100/; classtype:trojan-activity;sid:84792200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929099)"; flow:established,from_client; content:"GET"; http_method; content:"/tsl/chawrhpzgxzkotqo101.bin"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"greatwhite.me"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929099/; classtype:trojan-activity;sid:84792199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929098)"; flow:established,from_client; content:"GET"; http_method; content:"/gmv42b4j"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"razao.pt"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929098/; classtype:trojan-activity;sid:84792198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929095)"; flow:established,from_client; content:"GET"; http_method; content:"/hxzlycjrlh96.bin"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"185.29.10.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929095/; classtype:trojan-activity;sid:84792195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929096)"; flow:established,from_client; content:"GET"; http_method; content:"/sinkedes.mdp"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"185.29.9.42"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929096/; classtype:trojan-activity;sid:84792196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929097)"; flow:established,from_client; content:"GET"; http_method; content:"/ohoxjrlk180.bin"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"185.29.10.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929097/; classtype:trojan-activity;sid:84792197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929094)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=182idaap9k1rjdxymxmncc4ku5x8olnrp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929094/; classtype:trojan-activity;sid:84792194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929093)"; flow:established,from_client; content:"GET"; http_method; content:"/marsupialised.java"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"185.29.9.42"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929093/; classtype:trojan-activity;sid:84792193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929092)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"122.241.141.55"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929092/; classtype:trojan-activity;sid:84792192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929091)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_194859.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929091/; classtype:trojan-activity;sid:84792191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929089)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.204.198.22"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929089/; classtype:trojan-activity;sid:84792189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929090)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.24.161.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929090/; classtype:trojan-activity;sid:84792190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929085)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"144.48.121.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929085/; classtype:trojan-activity;sid:84792185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929086)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.172.218.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929086/; classtype:trojan-activity;sid:84792186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929087)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.33.224"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929087/; classtype:trojan-activity;sid:84792187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929088)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.94.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929088/; classtype:trojan-activity;sid:84792188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929083)"; flow:established,from_client; content:"GET"; http_method; content:"/retslokalet.lpk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"185.29.9.42"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929083/; classtype:trojan-activity;sid:84792183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929084)"; flow:established,from_client; content:"GET"; http_method; content:"/xdzgcanqnpylcdzt208.bin"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"185.29.10.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929084/; classtype:trojan-activity;sid:84792184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929081)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.241.141.55"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929081/; classtype:trojan-activity;sid:84792181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929082)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rodriakd-8413d.appspot.com/o/pe%2fp.txt|3f|alt=media|7c|26|7c|token=3b6252a5-d440-41e5-8c4b-7a4ca3a27d8d"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929082/; classtype:trojan-activity;sid:84792182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929080)"; flow:established,from_client; content:"GET"; http_method; content:"/f/7bb6zshjmtlzyrilavq2dzqtu1ptjcgau3mn4wkcmf0ie7ra"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"kipmwh3pdc.ufs.sh"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929080/; classtype:trojan-activity;sid:84792180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929076)"; flow:established,from_client; content:"GET"; http_method; content:"/ceofrnd29/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929076/; classtype:trojan-activity;sid:84792176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929077)"; flow:established,from_client; content:"GET"; http_method; content:"/myceo30/secured_stub.ps1"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929077/; classtype:trojan-activity;sid:84792177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929078)"; flow:established,from_client; content:"GET"; http_method; content:"/ceofrnd1/secured_stub.ps1"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929078/; classtype:trojan-activity;sid:84792178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929079)"; flow:established,from_client; content:"GET"; http_method; content:"/mrceofrnnd/secured_stub.ps1"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929079/; classtype:trojan-activity;sid:84792179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929075)"; flow:established,from_client; content:"GET"; http_method; content:"/nzeceo/secured_stub.ps1"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"flocmaterials.shop"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929075/; classtype:trojan-activity;sid:84792175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929074)"; flow:established,from_client; content:"GET"; http_method; content:"/file/img_221841.png"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"wp.fujeigroup.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929074/; classtype:trojan-activity;sid:84792174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929073)"; flow:established,from_client; content:"GET"; http_method; content:"/file/img_132450.png"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"wp.fujeigroup.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929073/; classtype:trojan-activity;sid:84792173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929072)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.158.71"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929072/; classtype:trojan-activity;sid:84792172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929070)"; flow:established,from_client; content:"GET"; http_method; content:"/b7823990/secured_stub.ps1"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"94.154.32.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929070/; classtype:trojan-activity;sid:84792170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929071)"; flow:established,from_client; content:"GET"; http_method; content:"/fast/stein.ps1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"23.132.164.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929071/; classtype:trojan-activity;sid:84792171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929069)"; flow:established,from_client; content:"GET"; http_method; content:"/1stcoco/secured_stub.ps1"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"94.154.32.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929069/; classtype:trojan-activity;sid:84792169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929068)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.109.239"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929068/; classtype:trojan-activity;sid:84792168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929067)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.246.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929067/; classtype:trojan-activity;sid:84792167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929066)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.12.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929066/; classtype:trojan-activity;sid:84792166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929065)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.111.234"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929065/; classtype:trojan-activity;sid:84792165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929064)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.160.232.180"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929064/; classtype:trojan-activity;sid:84792164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929063)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.33.224"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929063/; classtype:trojan-activity;sid:84792163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929062)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.160.232.180"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929062/; classtype:trojan-activity;sid:84792162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929061)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.213.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929061/; classtype:trojan-activity;sid:84792161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929060)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.239.103.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929060/; classtype:trojan-activity;sid:84792160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929059)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.170.112.184"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929059/; classtype:trojan-activity;sid:84792159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929058)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.79.64.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929058/; classtype:trojan-activity;sid:84792158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929057)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.148.236.154"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929057/; classtype:trojan-activity;sid:84792157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929056)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.56.35.53"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929056/; classtype:trojan-activity;sid:84792156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929055)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.213.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929055/; classtype:trojan-activity;sid:84792155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929052)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.54.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929052/; classtype:trojan-activity;sid:84792152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929053)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.140.161.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929053/; classtype:trojan-activity;sid:84792153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929054)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.138.225"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929054/; classtype:trojan-activity;sid:84792154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929051)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.56.35.53"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929051/; classtype:trojan-activity;sid:84792151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929050)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.85.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929050/; classtype:trojan-activity;sid:84792150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929049)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.109.210.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929049/; classtype:trojan-activity;sid:84792149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929047)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.127.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929047/; classtype:trojan-activity;sid:84792147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929048)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.176.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929048/; classtype:trojan-activity;sid:84792148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929046)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.140.161.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929046/; classtype:trojan-activity;sid:84792146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929045)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.207.127.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929045/; classtype:trojan-activity;sid:84792145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929044)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.69.66.206"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929044/; classtype:trojan-activity;sid:84792144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929042)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.138.225"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929042/; classtype:trojan-activity;sid:84792142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929043)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.190.134.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929043/; classtype:trojan-activity;sid:84792143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929041)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"mailservicesgroup.org"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929041/; classtype:trojan-activity;sid:84792141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929040)"; flow:established,from_client; content:"GET"; http_method; content:"/runner.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"metabolism-effectively-logo-chrome.trycloudflare.com"; http_host; depth:52; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929040/; classtype:trojan-activity;sid:84792140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929039)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.133.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929039/; classtype:trojan-activity;sid:84792139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929038)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.13.234.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929038/; classtype:trojan-activity;sid:84792138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929035)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.mips64le"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929035/; classtype:trojan-activity;sid:84792135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929036)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.mips64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929036/; classtype:trojan-activity;sid:84792136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929037)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.s390x"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929037/; classtype:trojan-activity;sid:84792137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929010)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.amd64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929010/; classtype:trojan-activity;sid:84792110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929011)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.mips64le"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929011/; classtype:trojan-activity;sid:84792111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929012)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.mips"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929012/; classtype:trojan-activity;sid:84792112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929013)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.mips64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929013/; classtype:trojan-activity;sid:84792113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929014)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.386"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929014/; classtype:trojan-activity;sid:84792114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929015)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.aarch64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929015/; classtype:trojan-activity;sid:84792115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929016)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.amd64test"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929016/; classtype:trojan-activity;sid:84792116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929017)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929017/; classtype:trojan-activity;sid:84792117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929018)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929018/; classtype:trojan-activity;sid:84792118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929019)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.aarch64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929019/; classtype:trojan-activity;sid:84792119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929020)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.mipsle"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929020/; classtype:trojan-activity;sid:84792120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929021)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.amd64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929021/; classtype:trojan-activity;sid:84792121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929022)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/dldr.mipsle"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929022/; classtype:trojan-activity;sid:84792122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929023)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.arm"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929023/; classtype:trojan-activity;sid:84792123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929024)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.386"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929024/; classtype:trojan-activity;sid:84792124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929025)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929025/; classtype:trojan-activity;sid:84792125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929026)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/go_bot.arm.bak"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929026/; classtype:trojan-activity;sid:84792126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929027)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/go_bot.mips.bak"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929027/; classtype:trojan-activity;sid:84792127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929028)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.amd64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929028/; classtype:trojan-activity;sid:84792128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929029)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.386"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929029/; classtype:trojan-activity;sid:84792129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929030)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.ppc64le"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929030/; classtype:trojan-activity;sid:84792130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929031)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929031/; classtype:trojan-activity;sid:84792131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929032)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/mb.arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929032/; classtype:trojan-activity;sid:84792132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929033)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.ppc64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929033/; classtype:trojan-activity;sid:84792133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929034)"; flow:established,from_client; content:"GET"; http_method; content:"/bots/bot.riscv64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929034/; classtype:trojan-activity;sid:84792134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929009)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.13.234.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929009/; classtype:trojan-activity;sid:84792109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929008)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.149.111.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929008/; classtype:trojan-activity;sid:84792108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929007)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.209.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929007/; classtype:trojan-activity;sid:84792107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929006)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.207.115.38"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929006/; classtype:trojan-activity;sid:84792106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929005)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.213.166.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929005/; classtype:trojan-activity;sid:84792105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929004)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.84.133.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929004/; classtype:trojan-activity;sid:84792104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929003)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.220.12.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929003/; classtype:trojan-activity;sid:84792103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929002)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.177.183.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929002/; classtype:trojan-activity;sid:84792102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929000)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.126.95"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929000/; classtype:trojan-activity;sid:84792100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3929001)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.149.111.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3929001/; classtype:trojan-activity;sid:84792101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928999)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.222.53.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928999/; classtype:trojan-activity;sid:84792099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928998)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928998/; classtype:trojan-activity;sid:84792098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928991)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928991/; classtype:trojan-activity;sid:84792091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928992)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm6"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928992/; classtype:trojan-activity;sid:84792092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928993)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928993/; classtype:trojan-activity;sid:84792093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928994)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928994/; classtype:trojan-activity;sid:84792094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928995)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928995/; classtype:trojan-activity;sid:84792095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928996)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928996/; classtype:trojan-activity;sid:84792096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928997)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928997/; classtype:trojan-activity;sid:84792097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928990)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.x86_64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928990/; classtype:trojan-activity;sid:84792090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928989)"; flow:established,from_client; content:"GET"; http_method; content:"/agent_i.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.134.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928989/; classtype:trojan-activity;sid:84792089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928985)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.56.148.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928985/; classtype:trojan-activity;sid:84792085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928986)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.35.50.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928986/; classtype:trojan-activity;sid:84792086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928987)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928987/; classtype:trojan-activity;sid:84792087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928988)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.222.53.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928988/; classtype:trojan-activity;sid:84792088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928984)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.215.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928984/; classtype:trojan-activity;sid:84792084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928983)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.147"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928983/; classtype:trojan-activity;sid:84792083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928982)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.armv7l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928982/; classtype:trojan-activity;sid:84792082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928977)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928977/; classtype:trojan-activity;sid:84792077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928978)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928978/; classtype:trojan-activity;sid:84792078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928979)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928979/; classtype:trojan-activity;sid:84792079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928980)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928980/; classtype:trojan-activity;sid:84792080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928981)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.aarch64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928981/; classtype:trojan-activity;sid:84792081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928976)"; flow:established,from_client; content:"GET"; http_method; content:"/m.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928976/; classtype:trojan-activity;sid:84792076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928975)"; flow:established,from_client; content:"GET"; http_method; content:"/b.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928975/; classtype:trojan-activity;sid:84792075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928974)"; flow:established,from_client; content:"GET"; http_method; content:"/stb/retev.php|3f|bl=irthup3cp1vg1sbt9bpre008.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"api.darkside.cy"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928974/; classtype:trojan-activity;sid:84792074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928973)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/crackexe.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928973/; classtype:trojan-activity;sid:84792073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928970)"; flow:established,from_client; content:"GET"; http_method; content:"/stb/retev.php|3f|bl=irthup3cp1vg1sbt9bpre008.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"pee-files.nl"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928970/; classtype:trojan-activity;sid:84792070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928971)"; flow:established,from_client; content:"GET"; http_method; content:"/stb/retev.php|3f|bl=irthup3cp1vg1sbt9bpre008.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"devruntime.cy"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928971/; classtype:trojan-activity;sid:84792071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928972)"; flow:established,from_client; content:"GET"; http_method; content:"/stb/retev.php|3f|bl=irthup3cp1vg1sbt9bpre008.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"exo-api.tf"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928972/; classtype:trojan-activity;sid:84792072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928969)"; flow:established,from_client; content:"GET"; http_method; content:"/setup.zip"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"seitinloelinsa.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928969/; classtype:trojan-activity;sid:84792069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928968)"; flow:established,from_client; content:"GET"; http_method; content:"/update.zip"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"fkjhsdfg478fdm.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928968/; classtype:trojan-activity;sid:84792068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928967)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/l8sjr2ojv65jdlgcqzja3/tokenized-real-estate-investment-platform.tar.gz|3f|rlkey=w48p2fpq591lxue4xyq0caws0"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928967/; classtype:trojan-activity;sid:84792067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928965)"; flow:established,from_client; content:"GET"; http_method; content:"/outhackernuls090-hash/kryptonclient/raw/refs/heads/main/kryptonclient-1.21.1.jar"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928965/; classtype:trojan-activity;sid:84792065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928966)"; flow:established,from_client; content:"GET"; http_method; content:"/nyx_bot_linux_amd64_exec"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928966/; classtype:trojan-activity;sid:84792066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928964)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"46.19.140.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928964/; classtype:trojan-activity;sid:84792064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928963)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.195.117.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928963/; classtype:trojan-activity;sid:84792063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928962)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.13.78"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928962/; classtype:trojan-activity;sid:84792062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928960)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/wanna.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928960/; classtype:trojan-activity;sid:84792060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928961)"; flow:established,from_client; content:"GET"; http_method; content:"/stb/retev.php|3f|bl=qtuvl0pcseglafunszpre008.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"pee-files.nl"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928961/; classtype:trojan-activity;sid:84792061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928958)"; flow:established,from_client; content:"GET"; http_method; content:"/service.bat"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"89.169.55.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928958/; classtype:trojan-activity;sid:84792058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928959)"; flow:established,from_client; content:"GET"; http_method; content:"/stb/retev.php|3f|bl=qtuvl0pcseglafunszpre008.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"api.darkside.cy"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928959/; classtype:trojan-activity;sid:84792059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928957)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_74d923de39615d9b.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928957/; classtype:trojan-activity;sid:84792057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928944)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.spc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928944/; classtype:trojan-activity;sid:84792044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928945)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.spc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928945/; classtype:trojan-activity;sid:84792045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928946)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/o.xml"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928946/; classtype:trojan-activity;sid:84792046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928947)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928947/; classtype:trojan-activity;sid:84792047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928948)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.i486"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928948/; classtype:trojan-activity;sid:84792048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928949)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.arm4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928949/; classtype:trojan-activity;sid:84792049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928950)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.sh4"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928950/; classtype:trojan-activity;sid:84792050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928951)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.arm5"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928951/; classtype:trojan-activity;sid:84792051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928952)"; flow:established,from_client; content:"GET"; http_method; content:"/securityhealthsys.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"46.19.140.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928952/; classtype:trojan-activity;sid:84792052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928953)"; flow:established,from_client; content:"GET"; http_method; content:"/loader.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"46.19.140.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928953/; classtype:trojan-activity;sid:84792053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928954)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.mpsl"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928954/; classtype:trojan-activity;sid:84792054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928955)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928955/; classtype:trojan-activity;sid:84792055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928956)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.x86_64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928956/; classtype:trojan-activity;sid:84792056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928940)"; flow:established,from_client; content:"GET"; http_method; content:"/api/l"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"brightlaunch-ext75642.vercel.app"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928940/; classtype:trojan-activity;sid:84792040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928941)"; flow:established,from_client; content:"GET"; http_method; content:"/api/m"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"brightlaunch-ext75642.vercel.app"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928941/; classtype:trojan-activity;sid:84792041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928942)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"66.205.236.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928942/; classtype:trojan-activity;sid:84792042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928943)"; flow:established,from_client; content:"GET"; http_method; content:"/q"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"kdglsj93fdslkg.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928943/; classtype:trojan-activity;sid:84792043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928938)"; flow:established,from_client; content:"GET"; http_method; content:"/rd.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"166.0.100.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928938/; classtype:trojan-activity;sid:84792038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928939)"; flow:established,from_client; content:"GET"; http_method; content:"/api/w"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"brightlaunch-ext75642.vercel.app"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928939/; classtype:trojan-activity;sid:84792039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928936)"; flow:established,from_client; content:"GET"; http_method; content:"/server.py"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"46.19.140.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928936/; classtype:trojan-activity;sid:84792036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928937)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928937/; classtype:trojan-activity;sid:84792037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928934)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_445052c4284d9c68.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928934/; classtype:trojan-activity;sid:84792034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928935)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"83.168.110.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928935/; classtype:trojan-activity;sid:84792035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928932)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/o.xml"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"85.137.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928932/; classtype:trojan-activity;sid:84792032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928933)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_759e2651dc554c76.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928933/; classtype:trojan-activity;sid:84792033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928925)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928925/; classtype:trojan-activity;sid:84792025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928926)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928926/; classtype:trojan-activity;sid:84792026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928927)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928927/; classtype:trojan-activity;sid:84792027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928928)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928928/; classtype:trojan-activity;sid:84792028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928929)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928929/; classtype:trojan-activity;sid:84792029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928930)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928930/; classtype:trojan-activity;sid:84792030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928931)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.apk"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928931/; classtype:trojan-activity;sid:84792031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928905)"; flow:established,from_client; content:"GET"; http_method; content:"/1.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928905/; classtype:trojan-activity;sid:84792005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928906)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928906/; classtype:trojan-activity;sid:84792006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928907)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm6"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928907/; classtype:trojan-activity;sid:84792007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928908)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.spc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928908/; classtype:trojan-activity;sid:84792008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928909)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928909/; classtype:trojan-activity;sid:84792009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928910)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.x86"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928910/; classtype:trojan-activity;sid:84792010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928911)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.arm6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928911/; classtype:trojan-activity;sid:84792011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928912)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.m68k"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928912/; classtype:trojan-activity;sid:84792012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928913)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928913/; classtype:trojan-activity;sid:84792013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928914)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.arm"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928914/; classtype:trojan-activity;sid:84792014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928915)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928915/; classtype:trojan-activity;sid:84792015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928916)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928916/; classtype:trojan-activity;sid:84792016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928917)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928917/; classtype:trojan-activity;sid:84792017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928918)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.236.222.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928918/; classtype:trojan-activity;sid:84792018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928919)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928919/; classtype:trojan-activity;sid:84792019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928920)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.ppc440"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928920/; classtype:trojan-activity;sid:84792020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928921)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.i686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928921/; classtype:trojan-activity;sid:84792021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928922)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.arm7"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928922/; classtype:trojan-activity;sid:84792022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928923)"; flow:established,from_client; content:"GET"; http_method; content:"/3.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928923/; classtype:trojan-activity;sid:84792023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928924)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928924/; classtype:trojan-activity;sid:84792024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928894)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.i686"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928894/; classtype:trojan-activity;sid:84791994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928895)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.ppc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928895/; classtype:trojan-activity;sid:84791995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928896)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928896/; classtype:trojan-activity;sid:84791996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928897)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.spc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928897/; classtype:trojan-activity;sid:84791997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928898)"; flow:established,from_client; content:"GET"; http_method; content:"/b.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928898/; classtype:trojan-activity;sid:84791998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928899)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.ppc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928899/; classtype:trojan-activity;sid:84791999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928900)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928900/; classtype:trojan-activity;sid:84792000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928901)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.dbg"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928901/; classtype:trojan-activity;sid:84792001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928902)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928902/; classtype:trojan-activity;sid:84792002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928903)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928903/; classtype:trojan-activity;sid:84792003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928904)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/87sbhas6as.mips"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928904/; classtype:trojan-activity;sid:84792004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928892)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"hand.genddos.st"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928892/; classtype:trojan-activity;sid:84791992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928893)"; flow:established,from_client; content:"GET"; http_method; content:"/pack/agent/nodewatchd-linux-386"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"astroliper.ac"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928893/; classtype:trojan-activity;sid:84791993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928890)"; flow:established,from_client; content:"GET"; http_method; content:"/2.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928890/; classtype:trojan-activity;sid:84791990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928891)"; flow:established,from_client; content:"GET"; http_method; content:"/5.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928891/; classtype:trojan-activity;sid:84791991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928889)"; flow:established,from_client; content:"GET"; http_method; content:"/4.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928889/; classtype:trojan-activity;sid:84791989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928888)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928888/; classtype:trojan-activity;sid:84791988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928886)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/wget.sh"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928886/; classtype:trojan-activity;sid:84791986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928887)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928887/; classtype:trojan-activity;sid:84791987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928884)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928884/; classtype:trojan-activity;sid:84791984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928885)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928885/; classtype:trojan-activity;sid:84791985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928877)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928877/; classtype:trojan-activity;sid:84791977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928878)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928878/; classtype:trojan-activity;sid:84791978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928879)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928879/; classtype:trojan-activity;sid:84791979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928880)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928880/; classtype:trojan-activity;sid:84791980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928881)"; flow:established,from_client; content:"GET"; http_method; content:"/dl.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928881/; classtype:trojan-activity;sid:84791981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928882)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928882/; classtype:trojan-activity;sid:84791982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928883)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928883/; classtype:trojan-activity;sid:84791983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928876)"; flow:established,from_client; content:"GET"; http_method; content:"/chud.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.225.83.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928876/; classtype:trojan-activity;sid:84791976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928875)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.54.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928875/; classtype:trojan-activity;sid:84791975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928874)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.230.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928874/; classtype:trojan-activity;sid:84791974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928873)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.50.118"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928873/; classtype:trojan-activity;sid:84791973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928870)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.4.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928870/; classtype:trojan-activity;sid:84791970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928871)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.56.148.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928871/; classtype:trojan-activity;sid:84791971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928872)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"183.35.50.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928872/; classtype:trojan-activity;sid:84791972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928868)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928868/; classtype:trojan-activity;sid:84791968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928869)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928869/; classtype:trojan-activity;sid:84791969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928867)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.20.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928867/; classtype:trojan-activity;sid:84791967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928866)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.55.75.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928866/; classtype:trojan-activity;sid:84791966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928865)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.82.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928865/; classtype:trojan-activity;sid:84791965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928862)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.63.84.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928862/; classtype:trojan-activity;sid:84791962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928863)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.66.118"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928863/; classtype:trojan-activity;sid:84791963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928864)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.166.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928864/; classtype:trojan-activity;sid:84791964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928859)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.220.49"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928859/; classtype:trojan-activity;sid:84791959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928860)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"108.170.136.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928860/; classtype:trojan-activity;sid:84791960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928861)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.4.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928861/; classtype:trojan-activity;sid:84791961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928858)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"167.250.158.32"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928858/; classtype:trojan-activity;sid:84791958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928857)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.63.84.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928857/; classtype:trojan-activity;sid:84791957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928856)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.220.49"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928856/; classtype:trojan-activity;sid:84791956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928855)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.199.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928855/; classtype:trojan-activity;sid:84791955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928854)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.180.158.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928854/; classtype:trojan-activity;sid:84791954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928853)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.212.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928853/; classtype:trojan-activity;sid:84791953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928852)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"106.58.126.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928852/; classtype:trojan-activity;sid:84791952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928850)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.141.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928850/; classtype:trojan-activity;sid:84791950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928851)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.147.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928851/; classtype:trojan-activity;sid:84791951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928847)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.199.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928847/; classtype:trojan-activity;sid:84791947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928848)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.250.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928848/; classtype:trojan-activity;sid:84791948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928849)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.154.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928849/; classtype:trojan-activity;sid:84791949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928846)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.240.11.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928846/; classtype:trojan-activity;sid:84791946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928844)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.123.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928844/; classtype:trojan-activity;sid:84791944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928845)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.230.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928845/; classtype:trojan-activity;sid:84791945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928843)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.253.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928843/; classtype:trojan-activity;sid:84791943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928842)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.154.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928842/; classtype:trojan-activity;sid:84791942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928840)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.215.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928840/; classtype:trojan-activity;sid:84791940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928841)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.228.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928841/; classtype:trojan-activity;sid:84791941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928839)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.237.104.148"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928839/; classtype:trojan-activity;sid:84791939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928838)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.200.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928838/; classtype:trojan-activity;sid:84791938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928835)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.103.116.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928835/; classtype:trojan-activity;sid:84791935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928836)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.238.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928836/; classtype:trojan-activity;sid:84791936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928837)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.6.250.18"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928837/; classtype:trojan-activity;sid:84791937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928834)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"92.42.134.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928834/; classtype:trojan-activity;sid:84791934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928831)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.104.126.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928831/; classtype:trojan-activity;sid:84791931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928832)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.207.228.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928832/; classtype:trojan-activity;sid:84791932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928833)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.232.238.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928833/; classtype:trojan-activity;sid:84791933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928830)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.204.37"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928830/; classtype:trojan-activity;sid:84791930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928829)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.73.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928829/; classtype:trojan-activity;sid:84791929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928828)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.214.17.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928828/; classtype:trojan-activity;sid:84791928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928827)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.6.250.18"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928827/; classtype:trojan-activity;sid:84791927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928826)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.232.88.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928826/; classtype:trojan-activity;sid:84791926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928825)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.241.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928825/; classtype:trojan-activity;sid:84791925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928824)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"92.42.134.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928824/; classtype:trojan-activity;sid:84791924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928823)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.249.84.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928823/; classtype:trojan-activity;sid:84791923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928821)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.239.103.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928821/; classtype:trojan-activity;sid:84791921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928822)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.227.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928822/; classtype:trojan-activity;sid:84791922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928820)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.73.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928820/; classtype:trojan-activity;sid:84791920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928819)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.212.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928819/; classtype:trojan-activity;sid:84791919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928817)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.89.252.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928817/; classtype:trojan-activity;sid:84791917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928818)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.111.23.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928818/; classtype:trojan-activity;sid:84791918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928815)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.187.32.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928815/; classtype:trojan-activity;sid:84791915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928816)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.227.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928816/; classtype:trojan-activity;sid:84791916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928814)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.245.17"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928814/; classtype:trojan-activity;sid:84791914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928813)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.226.7.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928813/; classtype:trojan-activity;sid:84791913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928812)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.102.60.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928812/; classtype:trojan-activity;sid:84791912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928811)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.115.65.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928811/; classtype:trojan-activity;sid:84791911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928809)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.89.191"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928809/; classtype:trojan-activity;sid:84791909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928810)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.219.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928810/; classtype:trojan-activity;sid:84791910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928808)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.226.7.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928808/; classtype:trojan-activity;sid:84791908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928807)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.225.105.182"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928807/; classtype:trojan-activity;sid:84791907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928804)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.212.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928804/; classtype:trojan-activity;sid:84791904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928805)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.231.120"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928805/; classtype:trojan-activity;sid:84791905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928806)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.205.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928806/; classtype:trojan-activity;sid:84791906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928801)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.244.15.54"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928801/; classtype:trojan-activity;sid:84791901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928802)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.114.194.94"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928802/; classtype:trojan-activity;sid:84791902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928803)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.219.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928803/; classtype:trojan-activity;sid:84791903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928800)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.91.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928800/; classtype:trojan-activity;sid:84791900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928799)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.93.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928799/; classtype:trojan-activity;sid:84791899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928798)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.91.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928798/; classtype:trojan-activity;sid:84791898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928797)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.6.79.147"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928797/; classtype:trojan-activity;sid:84791897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928796)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.206.50.169"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928796/; classtype:trojan-activity;sid:84791896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928792)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.105.243"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928792/; classtype:trojan-activity;sid:84791892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928793)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.244.15.54"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928793/; classtype:trojan-activity;sid:84791893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928794)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.mips"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928794/; classtype:trojan-activity;sid:84791894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928795)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.arm6"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928795/; classtype:trojan-activity;sid:84791895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928791)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.2.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928791/; classtype:trojan-activity;sid:84791891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928790)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.ppc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928790/; classtype:trojan-activity;sid:84791890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928783)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.x86"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928783/; classtype:trojan-activity;sid:84791883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928784)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.arm"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928784/; classtype:trojan-activity;sid:84791884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928785)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.m68k"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928785/; classtype:trojan-activity;sid:84791885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928786)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.mpsl"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928786/; classtype:trojan-activity;sid:84791886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928787)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.arm5"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928787/; classtype:trojan-activity;sid:84791887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928788)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.arm7"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928788/; classtype:trojan-activity;sid:84791888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928789)"; flow:established,from_client; content:"GET"; http_method; content:"/backup/winki.sh4"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"162.35.243.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928789/; classtype:trojan-activity;sid:84791889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928782)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.3.237"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928782/; classtype:trojan-activity;sid:84791882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928780)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.250.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928780/; classtype:trojan-activity;sid:84791880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928781)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.240.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928781/; classtype:trojan-activity;sid:84791881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928779)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.0.157"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928779/; classtype:trojan-activity;sid:84791879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928775)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.81.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928775/; classtype:trojan-activity;sid:84791875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928776)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.18.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928776/; classtype:trojan-activity;sid:84791876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928777)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.177.1.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928777/; classtype:trojan-activity;sid:84791877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928778)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.13.84.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928778/; classtype:trojan-activity;sid:84791878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928774)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.115.161.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928774/; classtype:trojan-activity;sid:84791874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928773)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.26.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928773/; classtype:trojan-activity;sid:84791873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928772)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.109.190.25"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928772/; classtype:trojan-activity;sid:84791872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928771)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.238.30"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928771/; classtype:trojan-activity;sid:84791871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928769)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.89.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928769/; classtype:trojan-activity;sid:84791869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928770)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.111.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928770/; classtype:trojan-activity;sid:84791870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928768)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.6.79.147"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928768/; classtype:trojan-activity;sid:84791868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928767)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928767/; classtype:trojan-activity;sid:84791867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928766)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.201.18.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928766/; classtype:trojan-activity;sid:84791866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928765)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.109.190.25"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928765/; classtype:trojan-activity;sid:84791865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928763)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.240.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928763/; classtype:trojan-activity;sid:84791863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928764)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.215.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928764/; classtype:trojan-activity;sid:84791864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928762)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.177.1.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928762/; classtype:trojan-activity;sid:84791862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928761)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.59.237.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928761/; classtype:trojan-activity;sid:84791861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928759)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.252.33.253"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928759/; classtype:trojan-activity;sid:84791859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928760)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928760/; classtype:trojan-activity;sid:84791860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928758)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.63.189.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928758/; classtype:trojan-activity;sid:84791858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928755)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.52.142.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928755/; classtype:trojan-activity;sid:84791855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928756)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.111.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928756/; classtype:trojan-activity;sid:84791856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928757)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.114.194.94"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928757/; classtype:trojan-activity;sid:84791857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928754)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.69.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928754/; classtype:trojan-activity;sid:84791854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928751)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.52.142.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928751/; classtype:trojan-activity;sid:84791851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928752)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.112.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928752/; classtype:trojan-activity;sid:84791852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928753)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.156.112.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928753/; classtype:trojan-activity;sid:84791853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928747)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.85.218.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928747/; classtype:trojan-activity;sid:84791847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928748)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.51.52.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928748/; classtype:trojan-activity;sid:84791848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928749)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.159.237"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928749/; classtype:trojan-activity;sid:84791849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928750)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.73.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928750/; classtype:trojan-activity;sid:84791850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928746)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.63.189.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928746/; classtype:trojan-activity;sid:84791846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928745)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.146.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928745/; classtype:trojan-activity;sid:84791845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928744)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.238.123.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928744/; classtype:trojan-activity;sid:84791844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928743)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.218.104"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928743/; classtype:trojan-activity;sid:84791843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928742)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.149.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928742/; classtype:trojan-activity;sid:84791842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928741)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"14.145.162.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928741/; classtype:trojan-activity;sid:84791841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928738)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.8.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928738/; classtype:trojan-activity;sid:84791838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928739)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.69.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928739/; classtype:trojan-activity;sid:84791839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928740)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.195.117.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928740/; classtype:trojan-activity;sid:84791840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928737)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.4.49.203"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_05; reference:url, urlhaus.abuse.ch/url/3928737/; classtype:trojan-activity;sid:84791837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928734)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928734/; classtype:trojan-activity;sid:84791834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928735)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.238.123.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928735/; classtype:trojan-activity;sid:84791835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928736)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.174.231.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928736/; classtype:trojan-activity;sid:84791836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928733)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.0.89"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928733/; classtype:trojan-activity;sid:84791833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928731)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.195.117.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928731/; classtype:trojan-activity;sid:84791831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928732)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.0.89"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928732/; classtype:trojan-activity;sid:84791832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928727)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.34.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928727/; classtype:trojan-activity;sid:84791827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928728)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.168.141.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928728/; classtype:trojan-activity;sid:84791828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928729)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.176.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928729/; classtype:trojan-activity;sid:84791829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928730)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.178.218.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928730/; classtype:trojan-activity;sid:84791830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928726)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.249.84.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928726/; classtype:trojan-activity;sid:84791826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928724)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.32.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928724/; classtype:trojan-activity;sid:84791824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928725)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"14.221.239.228"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928725/; classtype:trojan-activity;sid:84791825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928722)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.9.139.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928722/; classtype:trojan-activity;sid:84791822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928723)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.18.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928723/; classtype:trojan-activity;sid:84791823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928721)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.208.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928721/; classtype:trojan-activity;sid:84791821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928717)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.36.98"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928717/; classtype:trojan-activity;sid:84791817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928718)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.239.102.153"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928718/; classtype:trojan-activity;sid:84791818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928719)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.111.100"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928719/; classtype:trojan-activity;sid:84791819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928720)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.176.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928720/; classtype:trojan-activity;sid:84791820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928716)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.124.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928716/; classtype:trojan-activity;sid:84791816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928715)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.111.36"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928715/; classtype:trojan-activity;sid:84791815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928713)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.230.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928713/; classtype:trojan-activity;sid:84791813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928714)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.82.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928714/; classtype:trojan-activity;sid:84791814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928711)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.64.243.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928711/; classtype:trojan-activity;sid:84791811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928712)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.9.139.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928712/; classtype:trojan-activity;sid:84791812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928710)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.239.102.153"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928710/; classtype:trojan-activity;sid:84791810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928709)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.108.103.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928709/; classtype:trojan-activity;sid:84791809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928707)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.36.98"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928707/; classtype:trojan-activity;sid:84791807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928708)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.63.140.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928708/; classtype:trojan-activity;sid:84791808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928701)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.121.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928701/; classtype:trojan-activity;sid:84791801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928702)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.114.58.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928702/; classtype:trojan-activity;sid:84791802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928703)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.128.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928703/; classtype:trojan-activity;sid:84791803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928704)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.149.69.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928704/; classtype:trojan-activity;sid:84791804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928705)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.64.243.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928705/; classtype:trojan-activity;sid:84791805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928706)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.177.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928706/; classtype:trojan-activity;sid:84791806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928700)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.86.171.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928700/; classtype:trojan-activity;sid:84791800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928699)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.81.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928699/; classtype:trojan-activity;sid:84791799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928698)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.173.83.182"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928698/; classtype:trojan-activity;sid:84791798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928697)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.37.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928697/; classtype:trojan-activity;sid:84791797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928696)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.173.83.182"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928696/; classtype:trojan-activity;sid:84791796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928695)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.152.100.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928695/; classtype:trojan-activity;sid:84791795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928691)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.249.223"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928691/; classtype:trojan-activity;sid:84791791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928692)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.149.69.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928692/; classtype:trojan-activity;sid:84791792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928693)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.160.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928693/; classtype:trojan-activity;sid:84791793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928694)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.177.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928694/; classtype:trojan-activity;sid:84791794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928690)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.37.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928690/; classtype:trojan-activity;sid:84791790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928689)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.128.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928689/; classtype:trojan-activity;sid:84791789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928688)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.204.136"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928688/; classtype:trojan-activity;sid:84791788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928687)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/f83ecc00a27c5716_hwbp_syst_b2nasg1e.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928687/; classtype:trojan-activity;sid:84791787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928686)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.31.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928686/; classtype:trojan-activity;sid:84791786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928685)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.89.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928685/; classtype:trojan-activity;sid:84791785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928684)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.89.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928684/; classtype:trojan-activity;sid:84791784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928681)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.54.66.173"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928681/; classtype:trojan-activity;sid:84791781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928682)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.245.56.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928682/; classtype:trojan-activity;sid:84791782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928683)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.43.15.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928683/; classtype:trojan-activity;sid:84791783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928680)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.137.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928680/; classtype:trojan-activity;sid:84791780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928679)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.204.136"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928679/; classtype:trojan-activity;sid:84791779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928678)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.153.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928678/; classtype:trojan-activity;sid:84791778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928677)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.254.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928677/; classtype:trojan-activity;sid:84791777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928676)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.139.45.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928676/; classtype:trojan-activity;sid:84791776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928675)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.201.74.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928675/; classtype:trojan-activity;sid:84791775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928674)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.9.104"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928674/; classtype:trojan-activity;sid:84791774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928673)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.9.104"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928673/; classtype:trojan-activity;sid:84791773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928671)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.73.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928671/; classtype:trojan-activity;sid:84791771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928672)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.137.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928672/; classtype:trojan-activity;sid:84791772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928670)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.224.122"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928670/; classtype:trojan-activity;sid:84791770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928668)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.167.160.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928668/; classtype:trojan-activity;sid:84791768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928669)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.144.54"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928669/; classtype:trojan-activity;sid:84791769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928666)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.195.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928666/; classtype:trojan-activity;sid:84791766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928667)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.237.104.148"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928667/; classtype:trojan-activity;sid:84791767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928665)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.56.41.233"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928665/; classtype:trojan-activity;sid:84791765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928663)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.86.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928663/; classtype:trojan-activity;sid:84791763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928664)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.219.3.204"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928664/; classtype:trojan-activity;sid:84791764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928662)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.224.122"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928662/; classtype:trojan-activity;sid:84791762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928661)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.151.104.143"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928661/; classtype:trojan-activity;sid:84791761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928660)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.170.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928660/; classtype:trojan-activity;sid:84791760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928658)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"92.243.113.232"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928658/; classtype:trojan-activity;sid:84791758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928659)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.81.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928659/; classtype:trojan-activity;sid:84791759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928657)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.i686"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"179.61.221.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928657/; classtype:trojan-activity;sid:84791757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928656)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.107.98.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928656/; classtype:trojan-activity;sid:84791756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928655)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.6.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928655/; classtype:trojan-activity;sid:84791755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928654)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.81.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928654/; classtype:trojan-activity;sid:84791754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928653)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.245.141.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928653/; classtype:trojan-activity;sid:84791753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928651)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.86.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928651/; classtype:trojan-activity;sid:84791751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928652)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.72.151.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928652/; classtype:trojan-activity;sid:84791752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928650)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.8.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928650/; classtype:trojan-activity;sid:84791750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928649)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.95.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928649/; classtype:trojan-activity;sid:84791749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928647)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.77.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928647/; classtype:trojan-activity;sid:84791747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928648)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.109.131.25"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928648/; classtype:trojan-activity;sid:84791748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928646)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.137.179"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928646/; classtype:trojan-activity;sid:84791746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928645)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.13.6"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928645/; classtype:trojan-activity;sid:84791745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.90.0.152"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928643/; classtype:trojan-activity;sid:84791743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928644)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.1.26.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928644/; classtype:trojan-activity;sid:84791744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928642)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"79.165.94.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928642/; classtype:trojan-activity;sid:84791742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928641)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.139.126.104"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928641/; classtype:trojan-activity;sid:84791741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928640)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928640/; classtype:trojan-activity;sid:84791740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928639)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.1.26.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928639/; classtype:trojan-activity;sid:84791739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928638)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.102.60.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928638/; classtype:trojan-activity;sid:84791738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928636)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.159.55"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928636/; classtype:trojan-activity;sid:84791736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928637)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.77.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928637/; classtype:trojan-activity;sid:84791737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928635)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.200.216.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928635/; classtype:trojan-activity;sid:84791735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928634)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.185.242.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928634/; classtype:trojan-activity;sid:84791734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.159.55"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928633/; classtype:trojan-activity;sid:84791733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928632)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.84.112.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928632/; classtype:trojan-activity;sid:84791732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928631)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.53.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928631/; classtype:trojan-activity;sid:84791731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928630)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"110.138.128.226"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928630/; classtype:trojan-activity;sid:84791730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928627)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.135.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928627/; classtype:trojan-activity;sid:84791727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928628)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.236.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928628/; classtype:trojan-activity;sid:84791728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928629)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.176.199.179"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928629/; classtype:trojan-activity;sid:84791729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928626)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.192.32.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928626/; classtype:trojan-activity;sid:84791726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928625)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.149.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928625/; classtype:trojan-activity;sid:84791725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928624)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.126.71.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928624/; classtype:trojan-activity;sid:84791724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928623)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.8.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928623/; classtype:trojan-activity;sid:84791723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928622)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.8.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928622/; classtype:trojan-activity;sid:84791722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928621)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.118.38.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928621/; classtype:trojan-activity;sid:84791721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928620)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.212.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928620/; classtype:trojan-activity;sid:84791720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928619)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.226.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928619/; classtype:trojan-activity;sid:84791719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928617)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.165.31.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928617/; classtype:trojan-activity;sid:84791717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928618)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.17.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928618/; classtype:trojan-activity;sid:84791718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928616)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.192.32.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928616/; classtype:trojan-activity;sid:84791716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928615)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.163.85.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928615/; classtype:trojan-activity;sid:84791715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928614)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.152.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928614/; classtype:trojan-activity;sid:84791714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928612)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.144.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928612/; classtype:trojan-activity;sid:84791712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928613)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.165.31.92"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928613/; classtype:trojan-activity;sid:84791713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928607)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.0.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928607/; classtype:trojan-activity;sid:84791707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928608)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.50.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928608/; classtype:trojan-activity;sid:84791708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928609)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.238.123.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928609/; classtype:trojan-activity;sid:84791709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928610)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.154.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928610/; classtype:trojan-activity;sid:84791710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928611)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.240.203.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928611/; classtype:trojan-activity;sid:84791711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928606)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.125.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928606/; classtype:trojan-activity;sid:84791706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928605)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.189.17.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928605/; classtype:trojan-activity;sid:84791705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928604)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.145"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928604/; classtype:trojan-activity;sid:84791704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928601)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.153.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928601/; classtype:trojan-activity;sid:84791701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928602)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.152.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928602/; classtype:trojan-activity;sid:84791702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928603)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.177.32.104"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928603/; classtype:trojan-activity;sid:84791703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928600)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.51.52.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928600/; classtype:trojan-activity;sid:84791700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928599)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.50.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928599/; classtype:trojan-activity;sid:84791699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928598)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.80.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928598/; classtype:trojan-activity;sid:84791698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928595)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"87.68.237.92"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928595/; classtype:trojan-activity;sid:84791695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928596)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.254.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928596/; classtype:trojan-activity;sid:84791696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928597)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.101.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928597/; classtype:trojan-activity;sid:84791697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928594)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.202.215.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928594/; classtype:trojan-activity;sid:84791694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928593)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.88.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928593/; classtype:trojan-activity;sid:84791693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928592)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.16.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928592/; classtype:trojan-activity;sid:84791692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928591)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.x86_64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928591/; classtype:trojan-activity;sid:84791691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928589)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.202.215.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928589/; classtype:trojan-activity;sid:84791689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928590)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.88.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928590/; classtype:trojan-activity;sid:84791690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928588)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.205.133"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928588/; classtype:trojan-activity;sid:84791688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928587)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.112.11"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928587/; classtype:trojan-activity;sid:84791687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928585)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.79.155.243"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928585/; classtype:trojan-activity;sid:84791685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928586)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.243.50.122"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928586/; classtype:trojan-activity;sid:84791686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928584)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.192.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928584/; classtype:trojan-activity;sid:84791684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928583)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.121.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928583/; classtype:trojan-activity;sid:84791683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928582)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.96.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928582/; classtype:trojan-activity;sid:84791682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928579)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.177.177.85"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928579/; classtype:trojan-activity;sid:84791679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928580)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.214.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928580/; classtype:trojan-activity;sid:84791680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928581)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.122.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928581/; classtype:trojan-activity;sid:84791681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928578)"; flow:established,from_client; content:"GET"; http_method; content:"/nyx_bot_linux_amd64_packed"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928578/; classtype:trojan-activity;sid:84791678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928576)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.177.177.85"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928576/; classtype:trojan-activity;sid:84791676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928577)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.223.128.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928577/; classtype:trojan-activity;sid:84791677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928575)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo/raw/refs/heads/main/corzclient-1.21.11.jar"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928575/; classtype:trojan-activity;sid:84791675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928573)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/yo/raw/b083a17e2058608736141ae8d491d79d5c2819bd/corzclientcracked-1.21.11.jar"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928573/; classtype:trojan-activity;sid:84791673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928574)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/0159fb8d-0aea-4905-940b-7f47e0c85044/goobaclient-1.21.11.jar"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928574/; classtype:trojan-activity;sid:84791674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928572)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/saitama.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928572/; classtype:trojan-activity;sid:84791672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928568)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/5de3fe7f-b6da-433f-8c99-35b3302c6005/fakeclientv3-1.21.11.jar"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928568/; classtype:trojan-activity;sid:84791668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928569)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/23dd2aa2-8e72-4c23-9500-e085982cefc0/frostclientv2-1.21.11.jar"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928569/; classtype:trojan-activity;sid:84791669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928570)"; flow:established,from_client; content:"GET"; http_method; content:"/files/donutsmpdupe.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"donutsmpdupe.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928570/; classtype:trojan-activity;sid:84791670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928571)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/891584e3-cb79-4fbd-b302-c99f9a899cf5/waterclientv6.jar"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928571/; classtype:trojan-activity;sid:84791671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928567)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.214.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928567/; classtype:trojan-activity;sid:84791667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928566)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.236.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928566/; classtype:trojan-activity;sid:84791666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928565)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.104.156"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928565/; classtype:trojan-activity;sid:84791665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928563)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.203.41"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928563/; classtype:trojan-activity;sid:84791663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928564)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.226.65.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928564/; classtype:trojan-activity;sid:84791664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928562)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.63.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928562/; classtype:trojan-activity;sid:84791662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928561)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.104.156"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928561/; classtype:trojan-activity;sid:84791661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928560)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1521843051192909974/1556292036628316191/bundle.zip|3f|ex=6ac3a168|7c|26|7c|is=6ac24fe8|7c|26|7c|hm=58f1be0d4cd105b7ec5303f5f0226d507ffde9335bcd81d86b4c292e5fc4a5a6|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928560/; classtype:trojan-activity;sid:84791660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928559)"; flow:established,from_client; content:"GET"; http_method; content:"/ed04570fa|3f|force=1"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"77.110.102.43"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928559/; classtype:trojan-activity;sid:84791659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928558)"; flow:established,from_client; content:"GET"; http_method; content:"/d2503d96a3|3f|force=1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"77.221.153.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928558/; classtype:trojan-activity;sid:84791658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928557)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"89.163.157.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928557/; classtype:trojan-activity;sid:84791657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928556)"; flow:established,from_client; content:"GET"; http_method; content:"/persist.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"89.163.157.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928556/; classtype:trojan-activity;sid:84791656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928555)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.63.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928555/; classtype:trojan-activity;sid:84791655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928554)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"158.255.83.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928554/; classtype:trojan-activity;sid:84791654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928553)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.155.201.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928553/; classtype:trojan-activity;sid:84791653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928544)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.mpsl"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928544/; classtype:trojan-activity;sid:84791644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928545)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm5"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928545/; classtype:trojan-activity;sid:84791645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928546)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.ppc"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928546/; classtype:trojan-activity;sid:84791646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928547)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928547/; classtype:trojan-activity;sid:84791647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928548)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.mips"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928548/; classtype:trojan-activity;sid:84791648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928549)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm6"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928549/; classtype:trojan-activity;sid:84791649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928550)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.x86"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928550/; classtype:trojan-activity;sid:84791650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928551)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.sh4"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928551/; classtype:trojan-activity;sid:84791651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928552)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm7"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928552/; classtype:trojan-activity;sid:84791652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928542)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.m68k"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928542/; classtype:trojan-activity;sid:84791642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928543)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.129.2.46"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928543/; classtype:trojan-activity;sid:84791643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928541)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.59.237.213"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928541/; classtype:trojan-activity;sid:84791641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928540)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.85.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928540/; classtype:trojan-activity;sid:84791640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928537)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.ppc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928537/; classtype:trojan-activity;sid:84791637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928538)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928538/; classtype:trojan-activity;sid:84791638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928539)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm6"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928539/; classtype:trojan-activity;sid:84791639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928533)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928533/; classtype:trojan-activity;sid:84791633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928534)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928534/; classtype:trojan-activity;sid:84791634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928535)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928535/; classtype:trojan-activity;sid:84791635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928536)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928536/; classtype:trojan-activity;sid:84791636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928530)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928530/; classtype:trojan-activity;sid:84791630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928531)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928531/; classtype:trojan-activity;sid:84791631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928532)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928532/; classtype:trojan-activity;sid:84791632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928529)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.236.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928529/; classtype:trojan-activity;sid:84791629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928528)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.59.237.213"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928528/; classtype:trojan-activity;sid:84791628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928527)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.244.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928527/; classtype:trojan-activity;sid:84791627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928526)"; flow:established,from_client; content:"GET"; http_method; content:"/f/m/.x0-lock_x86_64"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"project0.cc"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928526/; classtype:trojan-activity;sid:84791626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928525)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.146.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928525/; classtype:trojan-activity;sid:84791625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928524)"; flow:established,from_client; content:"GET"; http_method; content:"/dl.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.56.52.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928524/; classtype:trojan-activity;sid:84791624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928523)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.244.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928523/; classtype:trojan-activity;sid:84791623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928522)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.mpsl"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928522/; classtype:trojan-activity;sid:84791622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928516)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.m68k"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928516/; classtype:trojan-activity;sid:84791616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928517)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm6"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928517/; classtype:trojan-activity;sid:84791617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928518)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.x86"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928518/; classtype:trojan-activity;sid:84791618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928519)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928519/; classtype:trojan-activity;sid:84791619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928520)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm5"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928520/; classtype:trojan-activity;sid:84791620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928521)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm7"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928521/; classtype:trojan-activity;sid:84791621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928514)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.sh4"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928514/; classtype:trojan-activity;sid:84791614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928515)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.mips"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928515/; classtype:trojan-activity;sid:84791615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928513)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.ppc"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.64"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928513/; classtype:trojan-activity;sid:84791613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928512)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.248.173.59"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928512/; classtype:trojan-activity;sid:84791612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928509)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.214.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928509/; classtype:trojan-activity;sid:84791609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928510)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.159.237"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928510/; classtype:trojan-activity;sid:84791610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928511)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.241.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928511/; classtype:trojan-activity;sid:84791611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928508)"; flow:established,from_client; content:"GET"; http_method; content:"/download/wicresetconnect.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"wicresetconnect.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928508/; classtype:trojan-activity;sid:84791608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928507)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.212.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928507/; classtype:trojan-activity;sid:84791607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928506)"; flow:established,from_client; content:"GET"; http_method; content:"/mineteuw/corz-client/raw/refs/heads/main/ledium-client-1.21.11.jar"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928506/; classtype:trojan-activity;sid:84791606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928505)"; flow:established,from_client; content:"GET"; http_method; content:"/kngq1rzde2zwmw5rjt5q.png"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"upload.filehost.lol"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928505/; classtype:trojan-activity;sid:84791605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928504)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/google.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928504/; classtype:trojan-activity;sid:84791604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928503)"; flow:established,from_client; content:"GET"; http_method; content:"/svvhost.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.94.145.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928503/; classtype:trojan-activity;sid:84791603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928502)"; flow:established,from_client; content:"GET"; http_method; content:"/qp7ac|3f|9z=l"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"upload.filehost.lol"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928502/; classtype:trojan-activity;sid:84791602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928501)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.clientsetup.msi|3f|e=access"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"104.193.195.143"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928501/; classtype:trojan-activity;sid:84791601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928500)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.94.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928500/; classtype:trojan-activity;sid:84791600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928499)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.242.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928499/; classtype:trojan-activity;sid:84791599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928498)"; flow:established,from_client; content:"GET"; http_method; content:"/nyx_bot_linux_mipsle_packed"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928498/; classtype:trojan-activity;sid:84791598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928497)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.114.154.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928497/; classtype:trojan-activity;sid:84791597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928496)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.111.23.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928496/; classtype:trojan-activity;sid:84791596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928495)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"111.179.218.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928495/; classtype:trojan-activity;sid:84791595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928494)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.255.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928494/; classtype:trojan-activity;sid:84791594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928492)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.120.45"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928492/; classtype:trojan-activity;sid:84791592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928493)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.120.45"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928493/; classtype:trojan-activity;sid:84791593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928491)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.26.227.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928491/; classtype:trojan-activity;sid:84791591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928490)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.168.132.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928490/; classtype:trojan-activity;sid:84791590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928489)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.225.218.8"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928489/; classtype:trojan-activity;sid:84791589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928488)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.54.253.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928488/; classtype:trojan-activity;sid:84791588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928487)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.26.227.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928487/; classtype:trojan-activity;sid:84791587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928485)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.146.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928485/; classtype:trojan-activity;sid:84791585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928486)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.146.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928486/; classtype:trojan-activity;sid:84791586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928484)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.23.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928484/; classtype:trojan-activity;sid:84791584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928483)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.81.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928483/; classtype:trojan-activity;sid:84791583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928481)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.65.211.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928481/; classtype:trojan-activity;sid:84791581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928482)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.144.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928482/; classtype:trojan-activity;sid:84791582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928480)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.128.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928480/; classtype:trojan-activity;sid:84791580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928479)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.18.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928479/; classtype:trojan-activity;sid:84791579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928478)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.116.92.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928478/; classtype:trojan-activity;sid:84791578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928475)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.228.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928475/; classtype:trojan-activity;sid:84791575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928476)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.19.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928476/; classtype:trojan-activity;sid:84791576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928477)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.167.7.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928477/; classtype:trojan-activity;sid:84791577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928474)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.202.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928474/; classtype:trojan-activity;sid:84791574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928472)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.148.212.69"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928472/; classtype:trojan-activity;sid:84791572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928473)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.146.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928473/; classtype:trojan-activity;sid:84791573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928471)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.38.120.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928471/; classtype:trojan-activity;sid:84791571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928470)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.150.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928470/; classtype:trojan-activity;sid:84791570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928469)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.120.34.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928469/; classtype:trojan-activity;sid:84791569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928467)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.96.45.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928467/; classtype:trojan-activity;sid:84791567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928468)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928468/; classtype:trojan-activity;sid:84791568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928466)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.136.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928466/; classtype:trojan-activity;sid:84791566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928464)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.200.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928464/; classtype:trojan-activity;sid:84791564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928465)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"87.68.237.92"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928465/; classtype:trojan-activity;sid:84791565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928462)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.8.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928462/; classtype:trojan-activity;sid:84791562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928463)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.45.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928463/; classtype:trojan-activity;sid:84791563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928457)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.102.38.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928457/; classtype:trojan-activity;sid:84791557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928458)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.194.175"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928458/; classtype:trojan-activity;sid:84791558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928459)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.8.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928459/; classtype:trojan-activity;sid:84791559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928460)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.0.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928460/; classtype:trojan-activity;sid:84791560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928461)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.82.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928461/; classtype:trojan-activity;sid:84791561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928456)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"187.62.243.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928456/; classtype:trojan-activity;sid:84791556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928455)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_9036ced938de2957.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928455/; classtype:trojan-activity;sid:84791555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928454)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.102.38.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928454/; classtype:trojan-activity;sid:84791554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928452)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.45.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928452/; classtype:trojan-activity;sid:84791552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928453)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.204.37"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928453/; classtype:trojan-activity;sid:84791553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928451)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.42.8.63"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928451/; classtype:trojan-activity;sid:84791551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928450)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.111.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928450/; classtype:trojan-activity;sid:84791550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928447)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.234.140.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928447/; classtype:trojan-activity;sid:84791547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928448)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.166.165.60"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928448/; classtype:trojan-activity;sid:84791548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928449)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928449/; classtype:trojan-activity;sid:84791549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928446)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv7l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928446/; classtype:trojan-activity;sid:84791546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928445)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.214.181.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928445/; classtype:trojan-activity;sid:84791545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928443)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.168.141.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928443/; classtype:trojan-activity;sid:84791543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928444)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.52.28.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928444/; classtype:trojan-activity;sid:84791544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928442)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928442/; classtype:trojan-activity;sid:84791542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928441)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.198.242.174"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928441/; classtype:trojan-activity;sid:84791541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928440)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.194.71"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928440/; classtype:trojan-activity;sid:84791540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928439)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.221"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928439/; classtype:trojan-activity;sid:84791539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928438)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928438/; classtype:trojan-activity;sid:84791538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928436)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.10.25.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928436/; classtype:trojan-activity;sid:84791536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928437)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.140.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928437/; classtype:trojan-activity;sid:84791537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928435)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.214.181.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928435/; classtype:trojan-activity;sid:84791535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928434)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.2.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928434/; classtype:trojan-activity;sid:84791534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928432)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.215.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928432/; classtype:trojan-activity;sid:84791532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928433)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.73.23"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928433/; classtype:trojan-activity;sid:84791533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928430)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.173.82.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928430/; classtype:trojan-activity;sid:84791530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928431)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.242.152.165"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928431/; classtype:trojan-activity;sid:84791531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928429)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.92.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928429/; classtype:trojan-activity;sid:84791529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928428)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.236.222.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928428/; classtype:trojan-activity;sid:84791528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928426)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.34.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928426/; classtype:trojan-activity;sid:84791526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928427)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.85.175.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928427/; classtype:trojan-activity;sid:84791527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928423)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.x86"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928423/; classtype:trojan-activity;sid:84791523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928424)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.spc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928424/; classtype:trojan-activity;sid:84791524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928425)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.mpsl"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928425/; classtype:trojan-activity;sid:84791525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928421)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.sh4"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928421/; classtype:trojan-activity;sid:84791521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928422)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.ppc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928422/; classtype:trojan-activity;sid:84791522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928418)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arm"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928418/; classtype:trojan-activity;sid:84791518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928419)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.mis"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928419/; classtype:trojan-activity;sid:84791519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928420)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.msl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928420/; classtype:trojan-activity;sid:84791520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928416)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.10.25.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928416/; classtype:trojan-activity;sid:84791516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928417)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.143.8"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928417/; classtype:trojan-activity;sid:84791517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928414)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.232.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928414/; classtype:trojan-activity;sid:84791514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928415)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.254.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928415/; classtype:trojan-activity;sid:84791515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928413)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"217.154.79.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928413/; classtype:trojan-activity;sid:84791513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928412)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.16.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928412/; classtype:trojan-activity;sid:84791512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928411)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"43.134.2.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928411/; classtype:trojan-activity;sid:84791511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928409)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.hta"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"107.152.37.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928409/; classtype:trojan-activity;sid:84791509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928410)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928410/; classtype:trojan-activity;sid:84791510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928407)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.214.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928407/; classtype:trojan-activity;sid:84791507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928408)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928408/; classtype:trojan-activity;sid:84791508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928405)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"92.243.113.232"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928405/; classtype:trojan-activity;sid:84791505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928406)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928406/; classtype:trojan-activity;sid:84791506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928403)"; flow:established,from_client; content:"GET"; http_method; content:"/full-payload.sh"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"209.141.43.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928403/; classtype:trojan-activity;sid:84791503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928404)"; flow:established,from_client; content:"GET"; http_method; content:"/km-payload.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"209.141.43.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928404/; classtype:trojan-activity;sid:84791504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928389)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv5l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928389/; classtype:trojan-activity;sid:84791489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928390)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928390/; classtype:trojan-activity;sid:84791490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928391)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.powerpc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928391/; classtype:trojan-activity;sid:84791491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928392)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.i486"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928392/; classtype:trojan-activity;sid:84791492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928393)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928393/; classtype:trojan-activity;sid:84791493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928394)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv6l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928394/; classtype:trojan-activity;sid:84791494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928395)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928395/; classtype:trojan-activity;sid:84791495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928396)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928396/; classtype:trojan-activity;sid:84791496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928397)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928397/; classtype:trojan-activity;sid:84791497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928398)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv4l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928398/; classtype:trojan-activity;sid:84791498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928399)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.arc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928399/; classtype:trojan-activity;sid:84791499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928400)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv7l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928400/; classtype:trojan-activity;sid:84791500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928401)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928401/; classtype:trojan-activity;sid:84791501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928402)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sparc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928402/; classtype:trojan-activity;sid:84791502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928387)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928387/; classtype:trojan-activity;sid:84791487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928388)"; flow:established,from_client; content:"GET"; http_method; content:"/cnc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928388/; classtype:trojan-activity;sid:84791488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928386)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928386/; classtype:trojan-activity;sid:84791486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928376)"; flow:established,from_client; content:"GET"; http_method; content:"/mixed_find.dll"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928376/; classtype:trojan-activity;sid:84791476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928377)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928377/; classtype:trojan-activity;sid:84791477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928378)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928378/; classtype:trojan-activity;sid:84791478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928379)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928379/; classtype:trojan-activity;sid:84791479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928380)"; flow:established,from_client; content:"GET"; http_method; content:"/mixed_injected.dll"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928380/; classtype:trojan-activity;sid:84791480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928381)"; flow:established,from_client; content:"GET"; http_method; content:"/rau_rce.dll"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928381/; classtype:trojan-activity;sid:84791481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928382)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.rv64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928382/; classtype:trojan-activity;sid:84791482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928383)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.xtensa"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928383/; classtype:trojan-activity;sid:84791483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928384)"; flow:established,from_client; content:"GET"; http_method; content:"/evil_arm.so"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.103.188.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928384/; classtype:trojan-activity;sid:84791484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928385)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928385/; classtype:trojan-activity;sid:84791485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928373)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928373/; classtype:trojan-activity;sid:84791473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928374)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl32"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928374/; classtype:trojan-activity;sid:84791474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928375)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928375/; classtype:trojan-activity;sid:84791475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928366)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"185.130.46.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928366/; classtype:trojan-activity;sid:84791466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928367)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928367/; classtype:trojan-activity;sid:84791467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928368)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928368/; classtype:trojan-activity;sid:84791468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928369)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928369/; classtype:trojan-activity;sid:84791469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928370)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928370/; classtype:trojan-activity;sid:84791470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928371)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928371/; classtype:trojan-activity;sid:84791471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928372)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928372/; classtype:trojan-activity;sid:84791472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928362)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928362/; classtype:trojan-activity;sid:84791462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928363)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928363/; classtype:trojan-activity;sid:84791463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928364)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm8"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928364/; classtype:trojan-activity;sid:84791464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928365)"; flow:established,from_client; content:"GET"; http_method; content:"/botbin"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928365/; classtype:trojan-activity;sid:84791465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928359)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928359/; classtype:trojan-activity;sid:84791459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928360)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mips64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928360/; classtype:trojan-activity;sid:84791460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928361)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_x86%20%28deleted%29"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928361/; classtype:trojan-activity;sid:84791461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928357)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928357/; classtype:trojan-activity;sid:84791457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928358)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sparcv8"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928358/; classtype:trojan-activity;sid:84791458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928355)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mblzb"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928355/; classtype:trojan-activity;sid:84791455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928356)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928356/; classtype:trojan-activity;sid:84791456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928351)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928351/; classtype:trojan-activity;sid:84791451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928352)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.bin.bak-20260928-164739"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"43.155.203.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928352/; classtype:trojan-activity;sid:84791452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928353)"; flow:established,from_client; content:"GET"; http_method; content:"/loader.ps1"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"43.155.203.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928353/; classtype:trojan-activity;sid:84791453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928354)"; flow:established,from_client; content:"GET"; http_method; content:"/writeshell64.dll"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928354/; classtype:trojan-activity;sid:84791454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928345)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppc64e5"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928345/; classtype:trojan-activity;sid:84791445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928346)"; flow:established,from_client; content:"GET"; http_method; content:"/evil_mips.so"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.103.188.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928346/; classtype:trojan-activity;sid:84791446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928347)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.s390x"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928347/; classtype:trojan-activity;sid:84791447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928348)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.130.46.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928348/; classtype:trojan-activity;sid:84791448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928349)"; flow:established,from_client; content:"GET"; http_method; content:"/whoamithrow.dll"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928349/; classtype:trojan-activity;sid:84791449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928350)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.130.46.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928350/; classtype:trojan-activity;sid:84791450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928343)"; flow:established,from_client; content:"GET"; http_method; content:"/w.dll"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928343/; classtype:trojan-activity;sid:84791443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928344)"; flow:established,from_client; content:"GET"; http_method; content:"/.dcplm"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.153.34.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928344/; classtype:trojan-activity;sid:84791444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928338)"; flow:established,from_client; content:"GET"; http_method; content:"/mf2.dll"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928338/; classtype:trojan-activity;sid:84791438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928339)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928339/; classtype:trojan-activity;sid:84791439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928340)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928340/; classtype:trojan-activity;sid:84791440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928341)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl64r6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928341/; classtype:trojan-activity;sid:84791441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928342)"; flow:established,from_client; content:"GET"; http_method; content:"/writeshellinstaller.dll"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928342/; classtype:trojan-activity;sid:84791442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928332)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928332/; classtype:trojan-activity;sid:84791432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928333)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928333/; classtype:trojan-activity;sid:84791433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928334)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928334/; classtype:trojan-activity;sid:84791434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928335)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928335/; classtype:trojan-activity;sid:84791435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928336)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.dll"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928336/; classtype:trojan-activity;sid:84791436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928337)"; flow:established,from_client; content:"GET"; http_method; content:"/findrootthrow94803.dll"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928337/; classtype:trojan-activity;sid:84791437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928329)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928329/; classtype:trojan-activity;sid:84791429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928330)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928330/; classtype:trojan-activity;sid:84791430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928331)"; flow:established,from_client; content:"GET"; http_method; content:"/main_sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928331/; classtype:trojan-activity;sid:84791431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928327)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928327/; classtype:trojan-activity;sid:84791427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928328)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928328/; classtype:trojan-activity;sid:84791428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928324)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928324/; classtype:trojan-activity;sid:84791424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928325)"; flow:established,from_client; content:"GET"; http_method; content:"/godpotato-net4.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"192.82.67.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928325/; classtype:trojan-activity;sid:84791425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928326)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.txt"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"192.82.67.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928326/; classtype:trojan-activity;sid:84791426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928323)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppc64lp8"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928323/; classtype:trojan-activity;sid:84791423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928318)"; flow:established,from_client; content:"GET"; http_method; content:"/mixed_md64.dll"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928318/; classtype:trojan-activity;sid:84791418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928319)"; flow:established,from_client; content:"GET"; http_method; content:"/tiny.dll"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928319/; classtype:trojan-activity;sid:84791419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928320)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.aarch64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"185.130.46.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928320/; classtype:trojan-activity;sid:84791420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928321)"; flow:established,from_client; content:"GET"; http_method; content:"/mixed_md.dll"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928321/; classtype:trojan-activity;sid:84791421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928322)"; flow:established,from_client; content:"GET"; http_method; content:"/mf.dll"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"168.93.199.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928322/; classtype:trojan-activity;sid:84791422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928307)"; flow:established,from_client; content:"GET"; http_method; content:"/main_host"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928307/; classtype:trojan-activity;sid:84791407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928308)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sparc64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928308/; classtype:trojan-activity;sid:84791408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928309)"; flow:established,from_client; content:"GET"; http_method; content:"/main_spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928309/; classtype:trojan-activity;sid:84791409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928310)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928310/; classtype:trojan-activity;sid:84791410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928311)"; flow:established,from_client; content:"GET"; http_method; content:"/main_ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928311/; classtype:trojan-activity;sid:84791411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928312)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928312/; classtype:trojan-activity;sid:84791412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928313)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928313/; classtype:trojan-activity;sid:84791413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928314)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928314/; classtype:trojan-activity;sid:84791414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928315)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"43.155.203.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928315/; classtype:trojan-activity;sid:84791415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928316)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928316/; classtype:trojan-activity;sid:84791416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928317)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928317/; classtype:trojan-activity;sid:84791417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928295)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mips32"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928295/; classtype:trojan-activity;sid:84791395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928296)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.armb7"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928296/; classtype:trojan-activity;sid:84791396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928297)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sh4b"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928297/; classtype:trojan-activity;sid:84791397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928298)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928298/; classtype:trojan-activity;sid:84791398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928299)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mblz"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928299/; classtype:trojan-activity;sid:84791399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928300)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928300/; classtype:trojan-activity;sid:84791400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928301)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928301/; classtype:trojan-activity;sid:84791401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928302)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/main_sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928302/; classtype:trojan-activity;sid:84791402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928303)"; flow:established,from_client; content:"GET"; http_method; content:"/main_m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928303/; classtype:trojan-activity;sid:84791403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928304)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928304/; classtype:trojan-activity;sid:84791404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928305)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928305/; classtype:trojan-activity;sid:84791405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928306)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.163.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928306/; classtype:trojan-activity;sid:84791406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928289)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.armb8"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928289/; classtype:trojan-activity;sid:84791389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928290)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.x86_64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928290/; classtype:trojan-activity;sid:84791390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928291)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl32r6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928291/; classtype:trojan-activity;sid:84791391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928292)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppce5"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928292/; classtype:trojan-activity;sid:84791392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928293)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.rv32"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"likedrink.beer"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928293/; classtype:trojan-activity;sid:84791393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928294)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arm8"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928294/; classtype:trojan-activity;sid:84791394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928288)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"maxxlavalink.cyou"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928288/; classtype:trojan-activity;sid:84791388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928286)"; flow:established,from_client; content:"GET"; http_method; content:"/sougouexpiorerr_setup_x64.zip"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"sogo-download.oss-cn-hongkong.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928286/; classtype:trojan-activity;sid:84791386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928287)"; flow:established,from_client; content:"GET"; http_method; content:"/sogouexplorer21_windows.zip"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"wwwiiisss.oss-ap-northeast-1.aliyuncs.com"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928287/; classtype:trojan-activity;sid:84791387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928284)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.179.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928284/; classtype:trojan-activity;sid:84791384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928285)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.111.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928285/; classtype:trojan-activity;sid:84791385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928283)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"maverick174.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928283/; classtype:trojan-activity;sid:84791383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928281)"; flow:established,from_client; content:"GET"; http_method; content:"/snipezcyka091111/krypton-updated-crack/refs/heads/main/krypton_crack-1.21.11.jar"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928281/; classtype:trojan-activity;sid:84791381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928282)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"moneylord.org"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928282/; classtype:trojan-activity;sid:84791382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928279)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/c.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928279/; classtype:trojan-activity;sid:84791379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928280)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/w.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928280/; classtype:trojan-activity;sid:84791380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928278)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.245.42.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928278/; classtype:trojan-activity;sid:84791378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928274)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.i586"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928274/; classtype:trojan-activity;sid:84791374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928275)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928275/; classtype:trojan-activity;sid:84791375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928276)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arm6"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928276/; classtype:trojan-activity;sid:84791376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928277)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arm5"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928277/; classtype:trojan-activity;sid:84791377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928272)"; flow:established,from_client; content:"GET"; http_method; content:"/scarstealsnow/kryptonclient-1.21.1/refs/heads/main/kryptonclient-1.21.1.jar"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928272/; classtype:trojan-activity;sid:84791372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928273)"; flow:established,from_client; content:"GET"; http_method; content:"/scarstealsnow/123/refs/heads/main/mod-injected.jar"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928273/; classtype:trojan-activity;sid:84791373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928263)"; flow:established,from_client; content:"GET"; http_method; content:"/.bia"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"45.153.34.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928263/; classtype:trojan-activity;sid:84791363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928264)"; flow:established,from_client; content:"GET"; http_method; content:"/zed"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"66.116.243.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928264/; classtype:trojan-activity;sid:84791364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928265)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.i486"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928265/; classtype:trojan-activity;sid:84791365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928266)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arm4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928266/; classtype:trojan-activity;sid:84791366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928267)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.mips"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928267/; classtype:trojan-activity;sid:84791367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928268)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.m68k"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928268/; classtype:trojan-activity;sid:84791368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928269)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bot.arm7"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"143.20.154.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928269/; classtype:trojan-activity;sid:84791369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928270)"; flow:established,from_client; content:"GET"; http_method; content:"/dutchmans922-afk/krypton-client/refs/heads/main/krypton-client-1.21.11.jar"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928270/; classtype:trojan-activity;sid:84791370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928271)"; flow:established,from_client; content:"GET"; http_method; content:"/snipezcyka091111/crypto-wallet-bruteforcer/refs/heads/main/launcher.exe"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928271/; classtype:trojan-activity;sid:84791371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928262)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/dlink.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928262/; classtype:trojan-activity;sid:84791362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928261)"; flow:established,from_client; content:"GET"; http_method; content:"/fakepika"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.153.34.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928261/; classtype:trojan-activity;sid:84791361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928259)"; flow:established,from_client; content:"GET"; http_method; content:"/pxerom.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928259/; classtype:trojan-activity;sid:84791359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928260)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.143.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928260/; classtype:trojan-activity;sid:84791360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928258)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_6d346165fd2c4dfb.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928258/; classtype:trojan-activity;sid:84791358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928257)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.217.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928257/; classtype:trojan-activity;sid:84791357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928255)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.68.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928255/; classtype:trojan-activity;sid:84791355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928256)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.245.56.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928256/; classtype:trojan-activity;sid:84791356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928254)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.161.116.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928254/; classtype:trojan-activity;sid:84791354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928253)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928253/; classtype:trojan-activity;sid:84791353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928252)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.232.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928252/; classtype:trojan-activity;sid:84791352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928251)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.214.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928251/; classtype:trojan-activity;sid:84791351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928250)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.235.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928250/; classtype:trojan-activity;sid:84791350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928247)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.151.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928247/; classtype:trojan-activity;sid:84791347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.20"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928248/; classtype:trojan-activity;sid:84791348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.227.64.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928249/; classtype:trojan-activity;sid:84791349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928245)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.203.41"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928245/; classtype:trojan-activity;sid:84791345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928246)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.152.100.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928246/; classtype:trojan-activity;sid:84791346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928244)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.93.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928244/; classtype:trojan-activity;sid:84791344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928243)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"201.110.137.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928243/; classtype:trojan-activity;sid:84791343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928242)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"201.110.137.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928242/; classtype:trojan-activity;sid:84791342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928240)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.134.173.192"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928240/; classtype:trojan-activity;sid:84791340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928241)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.242.137.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928241/; classtype:trojan-activity;sid:84791341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928239)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.123.244.214"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928239/; classtype:trojan-activity;sid:84791339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928238)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.227.64.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928238/; classtype:trojan-activity;sid:84791338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928237)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.146.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928237/; classtype:trojan-activity;sid:84791337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928236)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.111.234"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928236/; classtype:trojan-activity;sid:84791336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928235)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.60.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928235/; classtype:trojan-activity;sid:84791335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928234)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.65.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928234/; classtype:trojan-activity;sid:84791334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928233)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.167.7.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928233/; classtype:trojan-activity;sid:84791333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928231)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.166.76.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928231/; classtype:trojan-activity;sid:84791331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928232)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.6.60.204"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928232/; classtype:trojan-activity;sid:84791332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928228)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.123.244.214"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928228/; classtype:trojan-activity;sid:84791328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928229)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.195.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928229/; classtype:trojan-activity;sid:84791329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928230)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.166.76.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928230/; classtype:trojan-activity;sid:84791330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928227)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.254.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928227/; classtype:trojan-activity;sid:84791327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928224)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.39.28"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928224/; classtype:trojan-activity;sid:84791324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928225)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.60.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928225/; classtype:trojan-activity;sid:84791325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928226)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.140.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928226/; classtype:trojan-activity;sid:84791326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928223)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.4.49.203"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928223/; classtype:trojan-activity;sid:84791323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928222)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.141.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928222/; classtype:trojan-activity;sid:84791322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928220)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.93.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928220/; classtype:trojan-activity;sid:84791320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928221)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.245.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928221/; classtype:trojan-activity;sid:84791321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928219)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/devfreq_wq"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928219/; classtype:trojan-activity;sid:84791319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928218)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/rcuop_0"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928218/; classtype:trojan-activity;sid:84791318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928215)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/edac_polld"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928215/; classtype:trojan-activity;sid:84791315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928216)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/cfg80211d"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928216/; classtype:trojan-activity;sid:84791316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928217)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/kblockd0"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928217/; classtype:trojan-activity;sid:84791317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928213)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/kswapd0"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928213/; classtype:trojan-activity;sid:84791313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928214)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xfsaild_sda"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928214/; classtype:trojan-activity;sid:84791314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928205)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.130.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928205/; classtype:trojan-activity;sid:84791305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928206)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/jbd2_sda1d"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928206/; classtype:trojan-activity;sid:84791306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928207)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/zswap_shrinkd"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928207/; classtype:trojan-activity;sid:84791307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928208)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/scsi_tmf_0"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928208/; classtype:trojan-activity;sid:84791308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928209)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ksoftirqd0"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928209/; classtype:trojan-activity;sid:84791309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928210)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ecryptfsd"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928210/; classtype:trojan-activity;sid:84791310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928211)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/bioset0"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928211/; classtype:trojan-activity;sid:84791311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928212)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/kworker_u8"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928212/; classtype:trojan-activity;sid:84791312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928204)"; flow:established,from_client; content:"GET"; http_method; content:"/loader.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.183.174.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928204/; classtype:trojan-activity;sid:84791304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928203)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.96.45.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928203/; classtype:trojan-activity;sid:84791303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928202)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.234.93.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928202/; classtype:trojan-activity;sid:84791302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928201)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.93.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928201/; classtype:trojan-activity;sid:84791301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928199)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.81.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928199/; classtype:trojan-activity;sid:84791299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928200)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.3.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928200/; classtype:trojan-activity;sid:84791300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928198)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.114.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928198/; classtype:trojan-activity;sid:84791298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928192)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928192/; classtype:trojan-activity;sid:84791292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928193)"; flow:established,from_client; content:"GET"; http_method; content:"/riscv"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928193/; classtype:trojan-activity;sid:84791293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928194)"; flow:established,from_client; content:"GET"; http_method; content:"/clean"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928194/; classtype:trojan-activity;sid:84791294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928195)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928195/; classtype:trojan-activity;sid:84791295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928196)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928196/; classtype:trojan-activity;sid:84791296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928197)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928197/; classtype:trojan-activity;sid:84791297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928191)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.7.236.208"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928191/; classtype:trojan-activity;sid:84791291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.152.103"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928190/; classtype:trojan-activity;sid:84791290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.239.7.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928189/; classtype:trojan-activity;sid:84791289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928187)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.171"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928187/; classtype:trojan-activity;sid:84791287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928188)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.234.245.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928188/; classtype:trojan-activity;sid:84791288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928185)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.114.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928185/; classtype:trojan-activity;sid:84791285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928186)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.236.234.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928186/; classtype:trojan-activity;sid:84791286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928184)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.114.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928184/; classtype:trojan-activity;sid:84791284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928181)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.6.60.72"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928181/; classtype:trojan-activity;sid:84791281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928182)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.220.241.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928182/; classtype:trojan-activity;sid:84791282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928183)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.239.7.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928183/; classtype:trojan-activity;sid:84791283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928178)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.152.103"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928178/; classtype:trojan-activity;sid:84791278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928179)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.173.109.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928179/; classtype:trojan-activity;sid:84791279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928180)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.7.236.208"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928180/; classtype:trojan-activity;sid:84791280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928177)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.232.72.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928177/; classtype:trojan-activity;sid:84791277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928176)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.147.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928176/; classtype:trojan-activity;sid:84791276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928175)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.185.242.157"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928175/; classtype:trojan-activity;sid:84791275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928172)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.250.216"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928172/; classtype:trojan-activity;sid:84791272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928173)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.100.108"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928173/; classtype:trojan-activity;sid:84791273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928174)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.100.108"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928174/; classtype:trojan-activity;sid:84791274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928171)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.152.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928171/; classtype:trojan-activity;sid:84791271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928170)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.63.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928170/; classtype:trojan-activity;sid:84791270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.53.100.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928169/; classtype:trojan-activity;sid:84791269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928168)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.115.64.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928168/; classtype:trojan-activity;sid:84791268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928166)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.255.197.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928166/; classtype:trojan-activity;sid:84791266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928167)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.211.44.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928167/; classtype:trojan-activity;sid:84791267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928165)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.14.31"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928165/; classtype:trojan-activity;sid:84791265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928163)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.242.244.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928163/; classtype:trojan-activity;sid:84791263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928164)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.237.117"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928164/; classtype:trojan-activity;sid:84791264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928161)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928161/; classtype:trojan-activity;sid:84791261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928162)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.208.110.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928162/; classtype:trojan-activity;sid:84791262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928160)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.63.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928160/; classtype:trojan-activity;sid:84791260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928159)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.154.154.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928159/; classtype:trojan-activity;sid:84791259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928156)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.38.108"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928156/; classtype:trojan-activity;sid:84791256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928157)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.187.101.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928157/; classtype:trojan-activity;sid:84791257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928158)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.236.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928158/; classtype:trojan-activity;sid:84791258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928155)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.243.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928155/; classtype:trojan-activity;sid:84791255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928154)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.244.11.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928154/; classtype:trojan-activity;sid:84791254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928149)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.168.224.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928149/; classtype:trojan-activity;sid:84791249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928150)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.92.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928150/; classtype:trojan-activity;sid:84791250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928151)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.175.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928151/; classtype:trojan-activity;sid:84791251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928152)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.162.131.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928152/; classtype:trojan-activity;sid:84791252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928153)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.26.145.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928153/; classtype:trojan-activity;sid:84791253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928143)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.236.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928143/; classtype:trojan-activity;sid:84791243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928144)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.24.122.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928144/; classtype:trojan-activity;sid:84791244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928145)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.235.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928145/; classtype:trojan-activity;sid:84791245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928146)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.132.129.153"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928146/; classtype:trojan-activity;sid:84791246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928147)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.2.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928147/; classtype:trojan-activity;sid:84791247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928148)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928148/; classtype:trojan-activity;sid:84791248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928142)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.68.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928142/; classtype:trojan-activity;sid:84791242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928140)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.133.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928140/; classtype:trojan-activity;sid:84791240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928141)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.76.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928141/; classtype:trojan-activity;sid:84791241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928139)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.217.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928139/; classtype:trojan-activity;sid:84791239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928136)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.122.146.199"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928136/; classtype:trojan-activity;sid:84791236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928137)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.2.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928137/; classtype:trojan-activity;sid:84791237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928138)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.114.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928138/; classtype:trojan-activity;sid:84791238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928130)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.187.101.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928130/; classtype:trojan-activity;sid:84791230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928131)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.177.196.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928131/; classtype:trojan-activity;sid:84791231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928132)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.120.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928132/; classtype:trojan-activity;sid:84791232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928133)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.152.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928133/; classtype:trojan-activity;sid:84791233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928134)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.37.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928134/; classtype:trojan-activity;sid:84791234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928135)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.136.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928135/; classtype:trojan-activity;sid:84791235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928129)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.134.173.192"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928129/; classtype:trojan-activity;sid:84791229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928128)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.168.224.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928128/; classtype:trojan-activity;sid:84791228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928126)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928126/; classtype:trojan-activity;sid:84791226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928127)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.18.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928127/; classtype:trojan-activity;sid:84791227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928123)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.166.165.60"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928123/; classtype:trojan-activity;sid:84791223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928124)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.68.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928124/; classtype:trojan-activity;sid:84791224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928125)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.81.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928125/; classtype:trojan-activity;sid:84791225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928122)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.177.196.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928122/; classtype:trojan-activity;sid:84791222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928121)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.152.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928121/; classtype:trojan-activity;sid:84791221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928120)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928120/; classtype:trojan-activity;sid:84791220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928119)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.184.200.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928119/; classtype:trojan-activity;sid:84791219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928117)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.26.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928117/; classtype:trojan-activity;sid:84791217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928118)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.136.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928118/; classtype:trojan-activity;sid:84791218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928116)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.129.184.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928116/; classtype:trojan-activity;sid:84791216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928115)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"216.129.184.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928115/; classtype:trojan-activity;sid:84791215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928114)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.42.8.63"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928114/; classtype:trojan-activity;sid:84791214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928113)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.25.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928113/; classtype:trojan-activity;sid:84791213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928111)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.5.247.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928111/; classtype:trojan-activity;sid:84791211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928112)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.173.109.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928112/; classtype:trojan-activity;sid:84791212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928110)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.13.146"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928110/; classtype:trojan-activity;sid:84791210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928109)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.88.227.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928109/; classtype:trojan-activity;sid:84791209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928108)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.23.121.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928108/; classtype:trojan-activity;sid:84791208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928107)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.23.121.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928107/; classtype:trojan-activity;sid:84791207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928106)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.25.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928106/; classtype:trojan-activity;sid:84791206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928105)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.195.181.95"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928105/; classtype:trojan-activity;sid:84791205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928102)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.112.94.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928102/; classtype:trojan-activity;sid:84791202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928103)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.158.71"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928103/; classtype:trojan-activity;sid:84791203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928104)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.41.147"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928104/; classtype:trojan-activity;sid:84791204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928100)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.26.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928100/; classtype:trojan-activity;sid:84791200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928101)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.5.129.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928101/; classtype:trojan-activity;sid:84791201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928099)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"87.15.9.134"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928099/; classtype:trojan-activity;sid:84791199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928098)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.240.203.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928098/; classtype:trojan-activity;sid:84791198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928097)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.19.211.91"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928097/; classtype:trojan-activity;sid:84791197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928094)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928094/; classtype:trojan-activity;sid:84791194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928095)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.158.71"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928095/; classtype:trojan-activity;sid:84791195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928096)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.9.152.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928096/; classtype:trojan-activity;sid:84791196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928093)"; flow:established,from_client; content:"GET"; http_method; content:"/download|3f|payload=lummastealer.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"nfadealer.top"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928093/; classtype:trojan-activity;sid:84791193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928092)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.87.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928092/; classtype:trojan-activity;sid:84791192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928090)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.108.157.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928090/; classtype:trojan-activity;sid:84791190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928091)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.219.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928091/; classtype:trojan-activity;sid:84791191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928089)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"87.15.9.134"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928089/; classtype:trojan-activity;sid:84791189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928088)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.12.166.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928088/; classtype:trojan-activity;sid:84791188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928087)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.146.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_04; reference:url, urlhaus.abuse.ch/url/3928087/; classtype:trojan-activity;sid:84791187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928085)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928085/; classtype:trojan-activity;sid:84791185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928086)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928086/; classtype:trojan-activity;sid:84791186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928084)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928084/; classtype:trojan-activity;sid:84791184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928077)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928077/; classtype:trojan-activity;sid:84791177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928078)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928078/; classtype:trojan-activity;sid:84791178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928079)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928079/; classtype:trojan-activity;sid:84791179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928080)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928080/; classtype:trojan-activity;sid:84791180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928081)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928081/; classtype:trojan-activity;sid:84791181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928082)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928082/; classtype:trojan-activity;sid:84791182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928083)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928083/; classtype:trojan-activity;sid:84791183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928061)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928061/; classtype:trojan-activity;sid:84791161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928062)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928062/; classtype:trojan-activity;sid:84791162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928063)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928063/; classtype:trojan-activity;sid:84791163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928064)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928064/; classtype:trojan-activity;sid:84791164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928065)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928065/; classtype:trojan-activity;sid:84791165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928066)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928066/; classtype:trojan-activity;sid:84791166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928067)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928067/; classtype:trojan-activity;sid:84791167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928068)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928068/; classtype:trojan-activity;sid:84791168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928069)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928069/; classtype:trojan-activity;sid:84791169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928070)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928070/; classtype:trojan-activity;sid:84791170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928071)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928071/; classtype:trojan-activity;sid:84791171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928072)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928072/; classtype:trojan-activity;sid:84791172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928073)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928073/; classtype:trojan-activity;sid:84791173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928074)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928074/; classtype:trojan-activity;sid:84791174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928075)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928075/; classtype:trojan-activity;sid:84791175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928076)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928076/; classtype:trojan-activity;sid:84791176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928051)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.x86"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928051/; classtype:trojan-activity;sid:84791151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928052)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928052/; classtype:trojan-activity;sid:84791152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928053)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928053/; classtype:trojan-activity;sid:84791153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928054)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928054/; classtype:trojan-activity;sid:84791154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928055)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928055/; classtype:trojan-activity;sid:84791155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928056)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.spc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928056/; classtype:trojan-activity;sid:84791156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928057)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928057/; classtype:trojan-activity;sid:84791157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928058)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928058/; classtype:trojan-activity;sid:84791158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928059)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928059/; classtype:trojan-activity;sid:84791159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928060)"; flow:established,from_client; content:"GET"; http_method; content:"/d/akido.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"103.245.237.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928060/; classtype:trojan-activity;sid:84791160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928047)"; flow:established,from_client; content:"GET"; http_method; content:"/.sarm"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928047/; classtype:trojan-activity;sid:84791147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928048)"; flow:established,from_client; content:"GET"; http_method; content:"/l"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928048/; classtype:trojan-activity;sid:84791148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928049)"; flow:established,from_client; content:"GET"; http_method; content:"/giga"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928049/; classtype:trojan-activity;sid:84791149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928050)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928050/; classtype:trojan-activity;sid:84791150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928046)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.208.197.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928046/; classtype:trojan-activity;sid:84791146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928045)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"82.22.23.132"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928045/; classtype:trojan-activity;sid:84791145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928041)"; flow:established,from_client; content:"GET"; http_method; content:"/mips2"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928041/; classtype:trojan-activity;sid:84791141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928042)"; flow:established,from_client; content:"GET"; http_method; content:"/p"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928042/; classtype:trojan-activity;sid:84791142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928043)"; flow:established,from_client; content:"GET"; http_method; content:"/bos"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928043/; classtype:trojan-activity;sid:84791143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928044)"; flow:established,from_client; content:"GET"; http_method; content:"/tmips"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928044/; classtype:trojan-activity;sid:84791144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928038)"; flow:established,from_client; content:"GET"; http_method; content:"/faith"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928038/; classtype:trojan-activity;sid:84791138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928039)"; flow:established,from_client; content:"GET"; http_method; content:"/.ssh4"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928039/; classtype:trojan-activity;sid:84791139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928040)"; flow:established,from_client; content:"GET"; http_method; content:"/arm77"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928040/; classtype:trojan-activity;sid:84791140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928037)"; flow:established,from_client; content:"GET"; http_method; content:"/tmps"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928037/; classtype:trojan-activity;sid:84791137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928034)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.120.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928034/; classtype:trojan-activity;sid:84791134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928035)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.89.191"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928035/; classtype:trojan-activity;sid:84791135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928036)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.24.122.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928036/; classtype:trojan-activity;sid:84791136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928033)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.171.177.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928033/; classtype:trojan-activity;sid:84791133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928032)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.85.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928032/; classtype:trojan-activity;sid:84791132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928031)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.74.82.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928031/; classtype:trojan-activity;sid:84791131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928026)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.222.86.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928026/; classtype:trojan-activity;sid:84791126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928027)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.81.228.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928027/; classtype:trojan-activity;sid:84791127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928028)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.108.157.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928028/; classtype:trojan-activity;sid:84791128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928029)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.202.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928029/; classtype:trojan-activity;sid:84791129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928030)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.1.147.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928030/; classtype:trojan-activity;sid:84791130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928025)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.222.86.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928025/; classtype:trojan-activity;sid:84791125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928023)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.79.64.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928023/; classtype:trojan-activity;sid:84791123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928024)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.69.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928024/; classtype:trojan-activity;sid:84791124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928020)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.4.198.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928020/; classtype:trojan-activity;sid:84791120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928021)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.197.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928021/; classtype:trojan-activity;sid:84791121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928022)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.109.227.228"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928022/; classtype:trojan-activity;sid:84791122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928019)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.75.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928019/; classtype:trojan-activity;sid:84791119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928018)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.65.52.119"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928018/; classtype:trojan-activity;sid:84791118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928017)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.74.82.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928017/; classtype:trojan-activity;sid:84791117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928014)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.151.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928014/; classtype:trojan-activity;sid:84791114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928015)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"85.140.44.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928015/; classtype:trojan-activity;sid:84791115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928016)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.213.43"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928016/; classtype:trojan-activity;sid:84791116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928013)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.186.191.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928013/; classtype:trojan-activity;sid:84791113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928011)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.4.198.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928011/; classtype:trojan-activity;sid:84791111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928012)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.85.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928012/; classtype:trojan-activity;sid:84791112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928009)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.213.43"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928009/; classtype:trojan-activity;sid:84791109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928010)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.110.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928010/; classtype:trojan-activity;sid:84791110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928008)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.151.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928008/; classtype:trojan-activity;sid:84791108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928007)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"121.231.117.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928007/; classtype:trojan-activity;sid:84791107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928006)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.90.148.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928006/; classtype:trojan-activity;sid:84791106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928005)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.242.244.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928005/; classtype:trojan-activity;sid:84791105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928001)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.151.177.19"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928001/; classtype:trojan-activity;sid:84791101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928002)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.142.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928002/; classtype:trojan-activity;sid:84791102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928003)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.110.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928003/; classtype:trojan-activity;sid:84791103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928004)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.47.66.76"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928004/; classtype:trojan-activity;sid:84791104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3928000)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.125.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3928000/; classtype:trojan-activity;sid:84791100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927999)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.180.142.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927999/; classtype:trojan-activity;sid:84791099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927998)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.61.136.57"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927998/; classtype:trojan-activity;sid:84791098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927997)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.130.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927997/; classtype:trojan-activity;sid:84791097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927996)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.31.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927996/; classtype:trojan-activity;sid:84791096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927995)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.147.97"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927995/; classtype:trojan-activity;sid:84791095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927994)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.176.223.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927994/; classtype:trojan-activity;sid:84791094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927993)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.221.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927993/; classtype:trojan-activity;sid:84791093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927992)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.197.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927992/; classtype:trojan-activity;sid:84791092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927991)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.247.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927991/; classtype:trojan-activity;sid:84791091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927990)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.40.6"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927990/; classtype:trojan-activity;sid:84791090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927989)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.37.206.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927989/; classtype:trojan-activity;sid:84791089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927988)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.187.177.158"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927988/; classtype:trojan-activity;sid:84791088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927987)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.229.244.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927987/; classtype:trojan-activity;sid:84791087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927986)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.138.122"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927986/; classtype:trojan-activity;sid:84791086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927985)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.227.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927985/; classtype:trojan-activity;sid:84791085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927984)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.185.154.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927984/; classtype:trojan-activity;sid:84791084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927980)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.1.26.13"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927980/; classtype:trojan-activity;sid:84791080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927981)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.132.129.153"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927981/; classtype:trojan-activity;sid:84791081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927982)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"187.110.223.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927982/; classtype:trojan-activity;sid:84791082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927983)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.94.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927983/; classtype:trojan-activity;sid:84791083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927979)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.89.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927979/; classtype:trojan-activity;sid:84791079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927978)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.228.40.6"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927978/; classtype:trojan-activity;sid:84791078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927977)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.75.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927977/; classtype:trojan-activity;sid:84791077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927976)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.233.94.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927976/; classtype:trojan-activity;sid:84791076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927972)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.239.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927972/; classtype:trojan-activity;sid:84791072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927973)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.198.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927973/; classtype:trojan-activity;sid:84791073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927974)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"223.151.73.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927974/; classtype:trojan-activity;sid:84791074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927975)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.172.51.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927975/; classtype:trojan-activity;sid:84791075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927971)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.187.177.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927971/; classtype:trojan-activity;sid:84791071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927970)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.162.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927970/; classtype:trojan-activity;sid:84791070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927968)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.90.70.196"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927968/; classtype:trojan-activity;sid:84791068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927969)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.220.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927969/; classtype:trojan-activity;sid:84791069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927965)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.237.229.195"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927965/; classtype:trojan-activity;sid:84791065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927966)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.59.233.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927966/; classtype:trojan-activity;sid:84791066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927967)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.41.147"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927967/; classtype:trojan-activity;sid:84791067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927964)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/bc116af5e724cfa4_zx.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927964/; classtype:trojan-activity;sid:84791064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927963)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.239.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927963/; classtype:trojan-activity;sid:84791063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927962)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.55.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927962/; classtype:trojan-activity;sid:84791062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927960)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.163.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927960/; classtype:trojan-activity;sid:84791060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927961)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.178.218.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927961/; classtype:trojan-activity;sid:84791061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927958)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.127.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927958/; classtype:trojan-activity;sid:84791058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927959)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.35.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927959/; classtype:trojan-activity;sid:84791059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927957)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.233.94.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927957/; classtype:trojan-activity;sid:84791057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927956)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.245.42.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927956/; classtype:trojan-activity;sid:84791056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927955)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.85.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927955/; classtype:trojan-activity;sid:84791055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927954)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.237.229.195"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927954/; classtype:trojan-activity;sid:84791054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927953)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.232.88.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927953/; classtype:trojan-activity;sid:84791053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927951)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.74.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927951/; classtype:trojan-activity;sid:84791051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927952)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.139.178.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927952/; classtype:trojan-activity;sid:84791052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927949)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.77.164"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927949/; classtype:trojan-activity;sid:84791049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927950)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.218.104"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927950/; classtype:trojan-activity;sid:84791050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927948)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.25.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927948/; classtype:trojan-activity;sid:84791048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927947)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"1.62.94.126"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927947/; classtype:trojan-activity;sid:84791047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927946)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.81.248"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927946/; classtype:trojan-activity;sid:84791046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927945)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.85.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927945/; classtype:trojan-activity;sid:84791045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927944)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927944/; classtype:trojan-activity;sid:84791044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927942)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.154.221"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927942/; classtype:trojan-activity;sid:84791042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927943)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.212.143"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927943/; classtype:trojan-activity;sid:84791043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927941)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.206.54.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927941/; classtype:trojan-activity;sid:84791041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927940)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.206.54.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927940/; classtype:trojan-activity;sid:84791040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927939)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.51.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927939/; classtype:trojan-activity;sid:84791039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927934)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.135.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927934/; classtype:trojan-activity;sid:84791034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927935)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.227.209.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927935/; classtype:trojan-activity;sid:84791035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927936)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.179.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927936/; classtype:trojan-activity;sid:84791036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927937)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.4.244.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927937/; classtype:trojan-activity;sid:84791037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927938)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.25.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927938/; classtype:trojan-activity;sid:84791038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927933)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.38.108"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927933/; classtype:trojan-activity;sid:84791033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927932)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.83.136"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927932/; classtype:trojan-activity;sid:84791032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927931)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.32.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927931/; classtype:trojan-activity;sid:84791031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927930)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.118.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927930/; classtype:trojan-activity;sid:84791030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927928)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"150.255.33.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927928/; classtype:trojan-activity;sid:84791028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927929)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.203.41"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927929/; classtype:trojan-activity;sid:84791029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927927)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.71.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927927/; classtype:trojan-activity;sid:84791027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927926)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.196.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927926/; classtype:trojan-activity;sid:84791026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927925)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.196.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927925/; classtype:trojan-activity;sid:84791025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927924)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.23.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927924/; classtype:trojan-activity;sid:84791024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927923)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.118.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927923/; classtype:trojan-activity;sid:84791023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927922)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.36.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927922/; classtype:trojan-activity;sid:84791022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927921)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.36.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927921/; classtype:trojan-activity;sid:84791021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927919)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.109.227.228"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927919/; classtype:trojan-activity;sid:84791019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927920)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.153.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927920/; classtype:trojan-activity;sid:84791020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927918)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.231.177.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927918/; classtype:trojan-activity;sid:84791018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927917)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.130.101"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927917/; classtype:trojan-activity;sid:84791017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927916)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.134.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927916/; classtype:trojan-activity;sid:84791016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927915)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.156.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927915/; classtype:trojan-activity;sid:84791015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927914)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.130.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927914/; classtype:trojan-activity;sid:84791014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927912)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.84.94"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927912/; classtype:trojan-activity;sid:84791012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927913)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.90.148.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927913/; classtype:trojan-activity;sid:84791013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927911)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.26.225.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927911/; classtype:trojan-activity;sid:84791011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927910)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.108.134.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927910/; classtype:trojan-activity;sid:84791010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927909)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.156.166.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927909/; classtype:trojan-activity;sid:84791009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927908)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927908/; classtype:trojan-activity;sid:84791008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927906)"; flow:established,from_client; content:"GET"; http_method; content:"/debug.dbg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927906/; classtype:trojan-activity;sid:84791006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927907)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927907/; classtype:trojan-activity;sid:84791007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927897)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927897/; classtype:trojan-activity;sid:84790997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927898)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927898/; classtype:trojan-activity;sid:84790998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927899)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927899/; classtype:trojan-activity;sid:84790999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927900)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927900/; classtype:trojan-activity;sid:84791000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927901)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927901/; classtype:trojan-activity;sid:84791001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927902)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927902/; classtype:trojan-activity;sid:84791002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927903)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927903/; classtype:trojan-activity;sid:84791003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927904)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927904/; classtype:trojan-activity;sid:84791004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927905)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927905/; classtype:trojan-activity;sid:84791005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927896)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"chibomaydan.devs.surf"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927896/; classtype:trojan-activity;sid:84790996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927894)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927894/; classtype:trojan-activity;sid:84790994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927895)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927895/; classtype:trojan-activity;sid:84790995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927888)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927888/; classtype:trojan-activity;sid:84790988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927889)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927889/; classtype:trojan-activity;sid:84790989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927890)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927890/; classtype:trojan-activity;sid:84790990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927891)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927891/; classtype:trojan-activity;sid:84790991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927892)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927892/; classtype:trojan-activity;sid:84790992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927893)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927893/; classtype:trojan-activity;sid:84790993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927887)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.155.130.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927887/; classtype:trojan-activity;sid:84790987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927884)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.193.159.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927884/; classtype:trojan-activity;sid:84790984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927885)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.156.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927885/; classtype:trojan-activity;sid:84790985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927886)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.156.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927886/; classtype:trojan-activity;sid:84790986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927883)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.163.157.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927883/; classtype:trojan-activity;sid:84790983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927881)"; flow:established,from_client; content:"GET"; http_method; content:"/zav001/d3et2t23y3/releases/download/v3t354/goobaaclient.1.21.11.jar"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927881/; classtype:trojan-activity;sid:84790981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927882)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_87b6b45e37f32bcb.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927882/; classtype:trojan-activity;sid:84790982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927880)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi1/raw/refs/heads/main/frostclient-1.21.11.jar"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927880/; classtype:trojan-activity;sid:84790980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927878)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927878/; classtype:trojan-activity;sid:84790978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927879)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/meteorclient.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927879/; classtype:trojan-activity;sid:84790979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927872)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.128.164"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927872/; classtype:trojan-activity;sid:84790972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927873)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/mod.jar"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"donutsmp-mod.github.io"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927873/; classtype:trojan-activity;sid:84790973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927874)"; flow:established,from_client; content:"GET"; http_method; content:"/i386"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927874/; classtype:trojan-activity;sid:84790974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927875)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927875/; classtype:trojan-activity;sid:84790975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927876)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsle"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927876/; classtype:trojan-activity;sid:84790976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927877)"; flow:established,from_client; content:"GET"; http_method; content:"/android_arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927877/; classtype:trojan-activity;sid:84790977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927869)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/kryptonclient.jar"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927869/; classtype:trojan-activity;sid:84790969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927870)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/67client.jar"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927870/; classtype:trojan-activity;sid:84790970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927871)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927871/; classtype:trojan-activity;sid:84790971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927868)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/3paaa1gyot2ezrsj2qudh/nightclient-1.21.4-n-15.jar|3f|rlkey=4aktrmvwb3wqs6w7f3mwp4ury|7c|26|7c|st=hi9k78el|7c|26|7c|dl=1"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927868/; classtype:trojan-activity;sid:84790968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927866)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/svchost.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927866/; classtype:trojan-activity;sid:84790966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927867)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927867/; classtype:trojan-activity;sid:84790967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927864)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/radiumclient.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927864/; classtype:trojan-activity;sid:84790964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927865)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/glazedaddon.jar"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927865/; classtype:trojan-activity;sid:84790965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927859)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi2/raw/refs/heads/main/fakepayclient-1.21.11.jar"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927859/; classtype:trojan-activity;sid:84790959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927860)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.67.33.209"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927860/; classtype:trojan-activity;sid:84790960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927861)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/4eclient.jar"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927861/; classtype:trojan-activity;sid:84790961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927862)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/jars/opsec.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"donutclients.org"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927862/; classtype:trojan-activity;sid:84790962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927863)"; flow:established,from_client; content:"GET"; http_method; content:"/js/all.min.js"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"allowcsxan2.site"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927863/; classtype:trojan-activity;sid:84790963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927857)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927857/; classtype:trojan-activity;sid:84790957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927858)"; flow:established,from_client; content:"GET"; http_method; content:"/js/all.min.js"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"chekcms432.cc"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927858/; classtype:trojan-activity;sid:84790958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927856)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927856/; classtype:trojan-activity;sid:84790956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927852)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927852/; classtype:trojan-activity;sid:84790952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927853)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927853/; classtype:trojan-activity;sid:84790953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927854)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927854/; classtype:trojan-activity;sid:84790954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927855)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.34.59.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927855/; classtype:trojan-activity;sid:84790955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927851)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927851/; classtype:trojan-activity;sid:84790951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927850)"; flow:established,from_client; content:"GET"; http_method; content:"/dl/1791048429.d0f1a0128fdbc731/wyaxe28fksr2/mko-win1.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"tmpfiles.org"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927850/; classtype:trojan-activity;sid:84790950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927849)"; flow:established,from_client; content:"GET"; http_method; content:"/dl/1791036710.c66fbf974014a589/wswkwn6ucfrn/svchost-32bit.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"onlyfiles.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927849/; classtype:trojan-activity;sid:84790949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927848)"; flow:established,from_client; content:"GET"; http_method; content:"/load.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"89.163.157.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927848/; classtype:trojan-activity;sid:84790948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927847)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi1/raw/refs/heads/main/zyronclient-1.21.11.jar"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927847/; classtype:trojan-activity;sid:84790947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927844)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/9e03eb56-6178-4d83-a5ac-8f83d28e0c71/kryptonclient1.21.11.jar"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"kryptonclientplus.lovable.app"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927844/; classtype:trojan-activity;sid:84790944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927845)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi2/raw/refs/heads/main/67client-1.21.11.jar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927845/; classtype:trojan-activity;sid:84790945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927846)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi/raw/refs/heads/main/goobaclient-1.21.11.jar"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927846/; classtype:trojan-activity;sid:84790946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927840)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/49bd0b3d-4f1c-4bd2-bc39-4796957a9b35/frostclientv2-1.21.11.jar"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927840/; classtype:trojan-activity;sid:84790940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927841)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi2/raw/refs/heads/main/dqrkisclient-1.21.11.jar"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927841/; classtype:trojan-activity;sid:84790941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927842)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/017d55c0-0782-46de-8b6d-3513bef2479e/goobaclient-1.21.11.jar"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927842/; classtype:trojan-activity;sid:84790942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927843)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi/raw/refs/heads/main/kryptonclient-1.21.11.jar"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927843/; classtype:trojan-activity;sid:84790943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927839)"; flow:established,from_client; content:"GET"; http_method; content:"/cat/dl.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927839/; classtype:trojan-activity;sid:84790939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927838)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi2/raw/refs/heads/main/4eclient-1.21.11.jar"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927838/; classtype:trojan-activity;sid:84790938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927837)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi2/raw/refs/heads/main/radiumclient-1.21.11.jar"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927837/; classtype:trojan-activity;sid:84790937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927836)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/c03fba1e-47b9-42d6-aa75-19198316c380/waterclientv6-1.21.11.jar"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927836/; classtype:trojan-activity;sid:84790936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927834)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/e8c76875-4486-4d5b-8d84-045db0239456/fakeclientv3-1.21.11.jar"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"donutsmpclient.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927834/; classtype:trojan-activity;sid:84790934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927835)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/hi2/raw/refs/heads/main/xenonclient-1.21.11.jar"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927835/; classtype:trojan-activity;sid:84790935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927833)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_9872326df8da56c9.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927833/; classtype:trojan-activity;sid:84790933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927832)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.243.95.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927832/; classtype:trojan-activity;sid:84790932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927831)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.26.225.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927831/; classtype:trojan-activity;sid:84790931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927830)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.117.164.243"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927830/; classtype:trojan-activity;sid:84790930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927829)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.82.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927829/; classtype:trojan-activity;sid:84790929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927828)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.145.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927828/; classtype:trojan-activity;sid:84790928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927827)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"122.234.93.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927827/; classtype:trojan-activity;sid:84790927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927822)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.15.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927822/; classtype:trojan-activity;sid:84790922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927823)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.15.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927823/; classtype:trojan-activity;sid:84790923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927824)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.179.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927824/; classtype:trojan-activity;sid:84790924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927825)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.124.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927825/; classtype:trojan-activity;sid:84790925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927826)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.84.94"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927826/; classtype:trojan-activity;sid:84790926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927821)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.193.159.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927821/; classtype:trojan-activity;sid:84790921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927820)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.226.82.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927820/; classtype:trojan-activity;sid:84790920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927819)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.m68k"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927819/; classtype:trojan-activity;sid:84790919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927818)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.sh4"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927818/; classtype:trojan-activity;sid:84790918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927817)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.py"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.175.192.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927817/; classtype:trojan-activity;sid:84790917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927815)"; flow:established,from_client; content:"GET"; http_method; content:"/adissarm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927815/; classtype:trojan-activity;sid:84790915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927816)"; flow:established,from_client; content:"GET"; http_method; content:"/dissx86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927816/; classtype:trojan-activity;sid:84790916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927803)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927803/; classtype:trojan-activity;sid:84790903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927804)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927804/; classtype:trojan-activity;sid:84790904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927805)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927805/; classtype:trojan-activity;sid:84790905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927806)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927806/; classtype:trojan-activity;sid:84790906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927807)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.ppc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927807/; classtype:trojan-activity;sid:84790907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927808)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mpsl"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927808/; classtype:trojan-activity;sid:84790908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927809)"; flow:established,from_client; content:"GET"; http_method; content:"/dissmpsl"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927809/; classtype:trojan-activity;sid:84790909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927810)"; flow:established,from_client; content:"GET"; http_method; content:"/dissarm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927810/; classtype:trojan-activity;sid:84790910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927811)"; flow:established,from_client; content:"GET"; http_method; content:"/dissarm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927811/; classtype:trojan-activity;sid:84790911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927812)"; flow:established,from_client; content:"GET"; http_method; content:"/disssh4"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927812/; classtype:trojan-activity;sid:84790912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927813)"; flow:established,from_client; content:"GET"; http_method; content:"/dissmips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927813/; classtype:trojan-activity;sid:84790913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927814)"; flow:established,from_client; content:"GET"; http_method; content:"/dissarm4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927814/; classtype:trojan-activity;sid:84790914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927801)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"62.171.129.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927801/; classtype:trojan-activity;sid:84790901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927802)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.i686"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927802/; classtype:trojan-activity;sid:84790902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927799)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.spc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927799/; classtype:trojan-activity;sid:84790899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927800)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927800/; classtype:trojan-activity;sid:84790900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927797)"; flow:established,from_client; content:"GET"; http_method; content:"/all.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"62.171.129.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927797/; classtype:trojan-activity;sid:84790897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927798)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927798/; classtype:trojan-activity;sid:84790898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927787)"; flow:established,from_client; content:"GET"; http_method; content:"/.sarm7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927787/; classtype:trojan-activity;sid:84790887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927788)"; flow:established,from_client; content:"GET"; http_method; content:"/.sx86_64"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927788/; classtype:trojan-activity;sid:84790888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927789)"; flow:established,from_client; content:"GET"; http_method; content:"/.sx86"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927789/; classtype:trojan-activity;sid:84790889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927790)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927790/; classtype:trojan-activity;sid:84790890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927791)"; flow:established,from_client; content:"GET"; http_method; content:"/t"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927791/; classtype:trojan-activity;sid:84790891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927792)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927792/; classtype:trojan-activity;sid:84790892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927793)"; flow:established,from_client; content:"GET"; http_method; content:"/b"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927793/; classtype:trojan-activity;sid:84790893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927794)"; flow:established,from_client; content:"GET"; http_method; content:"/b"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927794/; classtype:trojan-activity;sid:84790894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927795)"; flow:established,from_client; content:"GET"; http_method; content:"/a"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927795/; classtype:trojan-activity;sid:84790895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927796)"; flow:established,from_client; content:"GET"; http_method; content:"/o"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927796/; classtype:trojan-activity;sid:84790896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927786)"; flow:established,from_client; content:"GET"; http_method; content:"/w"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"89.185.82.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927786/; classtype:trojan-activity;sid:84790886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927784)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927784/; classtype:trojan-activity;sid:84790884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927785)"; flow:established,from_client; content:"GET"; http_method; content:"/debug.dbg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927785/; classtype:trojan-activity;sid:84790885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927781)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927781/; classtype:trojan-activity;sid:84790881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927782)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927782/; classtype:trojan-activity;sid:84790882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927783)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"150.40.98.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927783/; classtype:trojan-activity;sid:84790883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927777)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.arm7"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"62.171.129.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927777/; classtype:trojan-activity;sid:84790877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927778)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.x86_64"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"62.171.129.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927778/; classtype:trojan-activity;sid:84790878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927779)"; flow:established,from_client; content:"GET"; http_method; content:"/jaws"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927779/; classtype:trojan-activity;sid:84790879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927780)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"23.155.44.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927780/; classtype:trojan-activity;sid:84790880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927776)"; flow:established,from_client; content:"GET"; http_method; content:"/payload.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"5.175.192.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927776/; classtype:trojan-activity;sid:84790876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927775)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927775/; classtype:trojan-activity;sid:84790875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927774)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-amd64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927774/; classtype:trojan-activity;sid:84790874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927760)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-mipsle"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927760/; classtype:trojan-activity;sid:84790860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927761)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-riscv64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927761/; classtype:trojan-activity;sid:84790861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927762)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-s390x"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927762/; classtype:trojan-activity;sid:84790862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927763)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-armv6"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927763/; classtype:trojan-activity;sid:84790863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927764)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-arm64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927764/; classtype:trojan-activity;sid:84790864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927765)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927765/; classtype:trojan-activity;sid:84790865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927766)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-386"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927766/; classtype:trojan-activity;sid:84790866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927767)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-armv5"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927767/; classtype:trojan-activity;sid:84790867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927768)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-mips64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927768/; classtype:trojan-activity;sid:84790868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927769)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-ppc64le"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927769/; classtype:trojan-activity;sid:84790869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927770)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927770/; classtype:trojan-activity;sid:84790870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927771)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-mips64le"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927771/; classtype:trojan-activity;sid:84790871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927772)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-armv7"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927772/; classtype:trojan-activity;sid:84790872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927773)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/linux-ppc64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"107.172.132.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927773/; classtype:trojan-activity;sid:84790873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927752)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927752/; classtype:trojan-activity;sid:84790852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927753)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927753/; classtype:trojan-activity;sid:84790853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927754)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.arm6"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927754/; classtype:trojan-activity;sid:84790854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927755)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.arm7"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927755/; classtype:trojan-activity;sid:84790855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927756)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927756/; classtype:trojan-activity;sid:84790856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927757)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927757/; classtype:trojan-activity;sid:84790857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927758)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927758/; classtype:trojan-activity;sid:84790858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927759)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.mips"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927759/; classtype:trojan-activity;sid:84790859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927738)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.arm5"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927738/; classtype:trojan-activity;sid:84790838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927739)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.sh4"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927739/; classtype:trojan-activity;sid:84790839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927740)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.arm"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927740/; classtype:trojan-activity;sid:84790840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927741)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.mpsl"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927741/; classtype:trojan-activity;sid:84790841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927742)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.m68k"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927742/; classtype:trojan-activity;sid:84790842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927743)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927743/; classtype:trojan-activity;sid:84790843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927744)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.ppc"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927744/; classtype:trojan-activity;sid:84790844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927745)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927745/; classtype:trojan-activity;sid:84790845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927746)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/vcimanagement.x86"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927746/; classtype:trojan-activity;sid:84790846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927747)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927747/; classtype:trojan-activity;sid:84790847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927748)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927748/; classtype:trojan-activity;sid:84790848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927749)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927749/; classtype:trojan-activity;sid:84790849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927750)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927750/; classtype:trojan-activity;sid:84790850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927751)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"5.175.222.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927751/; classtype:trojan-activity;sid:84790851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927737)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/exodus.sh"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927737/; classtype:trojan-activity;sid:84790837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927735)"; flow:established,from_client; content:"GET"; http_method; content:"/payload_v12.sh"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927735/; classtype:trojan-activity;sid:84790835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927736)"; flow:established,from_client; content:"GET"; http_method; content:"/ldr.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.132.198.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927736/; classtype:trojan-activity;sid:84790836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927734)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.117.164.243"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927734/; classtype:trojan-activity;sid:84790834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927728)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.35.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927728/; classtype:trojan-activity;sid:84790828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927729)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.11.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927729/; classtype:trojan-activity;sid:84790829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927730)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.220.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927730/; classtype:trojan-activity;sid:84790830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927731)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.251.169"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927731/; classtype:trojan-activity;sid:84790831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927732)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.147.97"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927732/; classtype:trojan-activity;sid:84790832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927733)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.74.35.79"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927733/; classtype:trojan-activity;sid:84790833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927726)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.137.44"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927726/; classtype:trojan-activity;sid:84790826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927727)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.198.116"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927727/; classtype:trojan-activity;sid:84790827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927724)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.220.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927724/; classtype:trojan-activity;sid:84790824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927725)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"110.136.11.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927725/; classtype:trojan-activity;sid:84790825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927723)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"79.35.99.31"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927723/; classtype:trojan-activity;sid:84790823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927722)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.158.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927722/; classtype:trojan-activity;sid:84790822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927721)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.104.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927721/; classtype:trojan-activity;sid:84790821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927720)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.85.49.126"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927720/; classtype:trojan-activity;sid:84790820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927719)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"150.107.92.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927719/; classtype:trojan-activity;sid:84790819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927715)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.147.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927715/; classtype:trojan-activity;sid:84790815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927716)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.115.164.129"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927716/; classtype:trojan-activity;sid:84790816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927717)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.115.102.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927717/; classtype:trojan-activity;sid:84790817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927718)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.251.169"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927718/; classtype:trojan-activity;sid:84790818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927714)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.209.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927714/; classtype:trojan-activity;sid:84790814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927713)"; flow:established,from_client; content:"GET"; http_method; content:"/n2/aarch64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"216.9.226.50"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927713/; classtype:trojan-activity;sid:84790813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927712)"; flow:established,from_client; content:"GET"; http_method; content:"/n2/aarch64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"160.119.66.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927712/; classtype:trojan-activity;sid:84790812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927711)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"79.35.99.31"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927711/; classtype:trojan-activity;sid:84790811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927709)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.146.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927709/; classtype:trojan-activity;sid:84790809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927710)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.7.222.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927710/; classtype:trojan-activity;sid:84790810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927704)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.19.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927704/; classtype:trojan-activity;sid:84790804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927705)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.143.90"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927705/; classtype:trojan-activity;sid:84790805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927706)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.68.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927706/; classtype:trojan-activity;sid:84790806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927707)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.151.177.19"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927707/; classtype:trojan-activity;sid:84790807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927708)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.115.164.129"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927708/; classtype:trojan-activity;sid:84790808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927701)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.104.40"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927701/; classtype:trojan-activity;sid:84790801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927702)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.222"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927702/; classtype:trojan-activity;sid:84790802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927703)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.219.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927703/; classtype:trojan-activity;sid:84790803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927700)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.7.222.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927700/; classtype:trojan-activity;sid:84790800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927698)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.222"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927698/; classtype:trojan-activity;sid:84790798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927699)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.120.205"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927699/; classtype:trojan-activity;sid:84790799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927697)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.54.181.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927697/; classtype:trojan-activity;sid:84790797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927696)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"183.35.50.53"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927696/; classtype:trojan-activity;sid:84790796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927695)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.51.47"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927695/; classtype:trojan-activity;sid:84790795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927692)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.3.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927692/; classtype:trojan-activity;sid:84790792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927693)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"200.115.102.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927693/; classtype:trojan-activity;sid:84790793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927694)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.36.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927694/; classtype:trojan-activity;sid:84790794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927682)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927682/; classtype:trojan-activity;sid:84790782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927683)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927683/; classtype:trojan-activity;sid:84790783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927684)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927684/; classtype:trojan-activity;sid:84790784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927685)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927685/; classtype:trojan-activity;sid:84790785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927686)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927686/; classtype:trojan-activity;sid:84790786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927687)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927687/; classtype:trojan-activity;sid:84790787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927688)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927688/; classtype:trojan-activity;sid:84790788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927689)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927689/; classtype:trojan-activity;sid:84790789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927690)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927690/; classtype:trojan-activity;sid:84790790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927691)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"170.64.137.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927691/; classtype:trojan-activity;sid:84790791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927680)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.36.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927680/; classtype:trojan-activity;sid:84790780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927681)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.54.181.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927681/; classtype:trojan-activity;sid:84790781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927678)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"157.66.146.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927678/; classtype:trojan-activity;sid:84790778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927679)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.47.120.205"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927679/; classtype:trojan-activity;sid:84790779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927677)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.78.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927677/; classtype:trojan-activity;sid:84790777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927676)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.79.252"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927676/; classtype:trojan-activity;sid:84790776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927675)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.84.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927675/; classtype:trojan-activity;sid:84790775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927674)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.215.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927674/; classtype:trojan-activity;sid:84790774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927672)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.154.154.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927672/; classtype:trojan-activity;sid:84790772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927673)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.104.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927673/; classtype:trojan-activity;sid:84790773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927669)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.124.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927669/; classtype:trojan-activity;sid:84790769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927670)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"157.66.146.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927670/; classtype:trojan-activity;sid:84790770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927671)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.161.116.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927671/; classtype:trojan-activity;sid:84790771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927668)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927668/; classtype:trojan-activity;sid:84790768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927665)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.34.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927665/; classtype:trojan-activity;sid:84790765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927666)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.78.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927666/; classtype:trojan-activity;sid:84790766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927667)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"163.142.84.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927667/; classtype:trojan-activity;sid:84790767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927663)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.215.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927663/; classtype:trojan-activity;sid:84790763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927664)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.79.138.55"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927664/; classtype:trojan-activity;sid:84790764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927660)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.194.175"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927660/; classtype:trojan-activity;sid:84790760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927661)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.215.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927661/; classtype:trojan-activity;sid:84790761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927662)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.95.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927662/; classtype:trojan-activity;sid:84790762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927659)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.145.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927659/; classtype:trojan-activity;sid:84790759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927657)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.220.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927657/; classtype:trojan-activity;sid:84790757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927658)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.79.138.55"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927658/; classtype:trojan-activity;sid:84790758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927656)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.240.8.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927656/; classtype:trojan-activity;sid:84790756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927655)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.240.8.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927655/; classtype:trojan-activity;sid:84790755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927653)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.238.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927653/; classtype:trojan-activity;sid:84790753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927654)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.174.7.17"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927654/; classtype:trojan-activity;sid:84790754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927652)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.235.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927652/; classtype:trojan-activity;sid:84790752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927650)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.69.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927650/; classtype:trojan-activity;sid:84790750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927651)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.238.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927651/; classtype:trojan-activity;sid:84790751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927649)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.183.184.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927649/; classtype:trojan-activity;sid:84790749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927648)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.35.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927648/; classtype:trojan-activity;sid:84790748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927647)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.127.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927647/; classtype:trojan-activity;sid:84790747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927646)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.146.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927646/; classtype:trojan-activity;sid:84790746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.35.50.53"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927643/; classtype:trojan-activity;sid:84790743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927644)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.144.228"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927644/; classtype:trojan-activity;sid:84790744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927645)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.69.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927645/; classtype:trojan-activity;sid:84790745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927642)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.145.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927642/; classtype:trojan-activity;sid:84790742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927641)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.118.97.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927641/; classtype:trojan-activity;sid:84790741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927640)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.253.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927640/; classtype:trojan-activity;sid:84790740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927638)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.35.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927638/; classtype:trojan-activity;sid:84790738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927639)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.253.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927639/; classtype:trojan-activity;sid:84790739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927637)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.111.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927637/; classtype:trojan-activity;sid:84790737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927635)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.115.102.16"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927635/; classtype:trojan-activity;sid:84790735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927636)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.78.50.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927636/; classtype:trojan-activity;sid:84790736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.228.108.53"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927633/; classtype:trojan-activity;sid:84790733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927634)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"38.56.20.112"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927634/; classtype:trojan-activity;sid:84790734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927632)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.84.112.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927632/; classtype:trojan-activity;sid:84790732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927630)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.211.138.158"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927630/; classtype:trojan-activity;sid:84790730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927631)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.140.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927631/; classtype:trojan-activity;sid:84790731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927629)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.238.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927629/; classtype:trojan-activity;sid:84790729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927628)"; flow:established,from_client; content:"GET"; http_method; content:"/114.zip"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"facai.makaaop.cc"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927628/; classtype:trojan-activity;sid:84790728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927627)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927627/; classtype:trojan-activity;sid:84790727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927626)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.109.240.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927626/; classtype:trojan-activity;sid:84790726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927624)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927624/; classtype:trojan-activity;sid:84790724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927625)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927625/; classtype:trojan-activity;sid:84790725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927609)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nowd"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927609/; classtype:trojan-activity;sid:84790709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927610)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_clean"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927610/; classtype:trojan-activity;sid:84790710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927611)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927611/; classtype:trojan-activity;sid:84790711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927612)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927612/; classtype:trojan-activity;sid:84790712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927613)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927613/; classtype:trojan-activity;sid:84790713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927614)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nsr"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927614/; classtype:trojan-activity;sid:84790714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927615)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_dbg"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927615/; classtype:trojan-activity;sid:84790715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927616)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_new"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927616/; classtype:trojan-activity;sid:84790716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927617)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_sr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927617/; classtype:trojan-activity;sid:84790717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927618)"; flow:established,from_client; content:"GET"; http_method; content:"/b_persist"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927618/; classtype:trojan-activity;sid:84790718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927619)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927619/; classtype:trojan-activity;sid:84790719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927620)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927620/; classtype:trojan-activity;sid:84790720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927621)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc-440fp"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927621/; classtype:trojan-activity;sid:84790721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927622)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927622/; classtype:trojan-activity;sid:84790722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927623)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927623/; classtype:trojan-activity;sid:84790723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927607)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_t8"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927607/; classtype:trojan-activity;sid:84790707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927608)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927608/; classtype:trojan-activity;sid:84790708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927606)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927606/; classtype:trojan-activity;sid:84790706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927599)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_ns"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927599/; classtype:trojan-activity;sid:84790699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927600)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927600/; classtype:trojan-activity;sid:84790700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927601)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_v2"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927601/; classtype:trojan-activity;sid:84790701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927602)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927602/; classtype:trojan-activity;sid:84790702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927603)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_fin"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927603/; classtype:trojan-activity;sid:84790703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927604)"; flow:established,from_client; content:"GET"; http_method; content:"/b_lt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927604/; classtype:trojan-activity;sid:84790704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927605)"; flow:established,from_client; content:"GET"; http_method; content:"/b_persist"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927605/; classtype:trojan-activity;sid:84790705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927595)"; flow:established,from_client; content:"GET"; http_method; content:"/i386"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927595/; classtype:trojan-activity;sid:84790695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927596)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927596/; classtype:trojan-activity;sid:84790696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927597)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927597/; classtype:trojan-activity;sid:84790697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927598)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927598/; classtype:trojan-activity;sid:84790698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927593)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927593/; classtype:trojan-activity;sid:84790693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927594)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927594/; classtype:trojan-activity;sid:84790694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927591)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927591/; classtype:trojan-activity;sid:84790691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927592)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.41.32"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927592/; classtype:trojan-activity;sid:84790692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927590)"; flow:established,from_client; content:"GET"; http_method; content:"/b_kt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927590/; classtype:trojan-activity;sid:84790690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927589)"; flow:established,from_client; content:"GET"; http_method; content:"/b_wt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"emwqkekwqmekwq.work.gd"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927589/; classtype:trojan-activity;sid:84790689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927588)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927588/; classtype:trojan-activity;sid:84790688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927581)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsle"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927581/; classtype:trojan-activity;sid:84790681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927582)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927582/; classtype:trojan-activity;sid:84790682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927583)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927583/; classtype:trojan-activity;sid:84790683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927584)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927584/; classtype:trojan-activity;sid:84790684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927585)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.179.193.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927585/; classtype:trojan-activity;sid:84790685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927586)"; flow:established,from_client; content:"GET"; http_method; content:"/android_arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927586/; classtype:trojan-activity;sid:84790686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927587)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927587/; classtype:trojan-activity;sid:84790687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927580)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927580/; classtype:trojan-activity;sid:84790680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927578)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_dbg"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927578/; classtype:trojan-activity;sid:84790678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927579)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927579/; classtype:trojan-activity;sid:84790679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927577)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927577/; classtype:trojan-activity;sid:84790677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927568)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927568/; classtype:trojan-activity;sid:84790668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927569)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927569/; classtype:trojan-activity;sid:84790669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927570)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_ns"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927570/; classtype:trojan-activity;sid:84790670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927571)"; flow:established,from_client; content:"GET"; http_method; content:"/b_lt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927571/; classtype:trojan-activity;sid:84790671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927572)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc-440fp"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927572/; classtype:trojan-activity;sid:84790672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927573)"; flow:established,from_client; content:"GET"; http_method; content:"/b_kt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927573/; classtype:trojan-activity;sid:84790673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927574)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_sr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927574/; classtype:trojan-activity;sid:84790674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927575)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927575/; classtype:trojan-activity;sid:84790675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927576)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927576/; classtype:trojan-activity;sid:84790676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927566)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_clean"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927566/; classtype:trojan-activity;sid:84790666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927567)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927567/; classtype:trojan-activity;sid:84790667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927561)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927561/; classtype:trojan-activity;sid:84790661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927562)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927562/; classtype:trojan-activity;sid:84790662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927563)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927563/; classtype:trojan-activity;sid:84790663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927564)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_t8"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927564/; classtype:trojan-activity;sid:84790664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927565)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nsr"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927565/; classtype:trojan-activity;sid:84790665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927557)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927557/; classtype:trojan-activity;sid:84790657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927558)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nowd"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927558/; classtype:trojan-activity;sid:84790658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927559)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927559/; classtype:trojan-activity;sid:84790659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927560)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927560/; classtype:trojan-activity;sid:84790660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927556)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_fin"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927556/; classtype:trojan-activity;sid:84790656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927555)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_v2"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927555/; classtype:trojan-activity;sid:84790655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927550)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927550/; classtype:trojan-activity;sid:84790650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927551)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927551/; classtype:trojan-activity;sid:84790651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927552)"; flow:established,from_client; content:"GET"; http_method; content:"/b_wt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927552/; classtype:trojan-activity;sid:84790652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927553)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927553/; classtype:trojan-activity;sid:84790653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927554)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_new"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"iloveanal.work.gd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927554/; classtype:trojan-activity;sid:84790654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927549)"; flow:established,from_client; content:"GET"; http_method; content:"/b_lt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927549/; classtype:trojan-activity;sid:84790649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927548)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_t8"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927548/; classtype:trojan-activity;sid:84790648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927542)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927542/; classtype:trojan-activity;sid:84790642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927543)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_sr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927543/; classtype:trojan-activity;sid:84790643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927544)"; flow:established,from_client; content:"GET"; http_method; content:"/b_kt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927544/; classtype:trojan-activity;sid:84790644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927545)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_dbg"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927545/; classtype:trojan-activity;sid:84790645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927546)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_ns"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927546/; classtype:trojan-activity;sid:84790646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927547)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_new"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927547/; classtype:trojan-activity;sid:84790647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927536)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_v2"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927536/; classtype:trojan-activity;sid:84790636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927537)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_fin"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927537/; classtype:trojan-activity;sid:84790637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927538)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_clean"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927538/; classtype:trojan-activity;sid:84790638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927539)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nsr"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927539/; classtype:trojan-activity;sid:84790639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927540)"; flow:established,from_client; content:"GET"; http_method; content:"/b_wt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927540/; classtype:trojan-activity;sid:84790640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927541)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nowd"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927541/; classtype:trojan-activity;sid:84790641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927535)"; flow:established,from_client; content:"GET"; http_method; content:"/b_persist"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927535/; classtype:trojan-activity;sid:84790635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927534)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.19.216.186"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927534/; classtype:trojan-activity;sid:84790634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927532)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/tgryan.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927532/; classtype:trojan-activity;sid:84790632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927533)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/tgteru.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927533/; classtype:trojan-activity;sid:84790633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927531)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.155.230.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927531/; classtype:trojan-activity;sid:84790631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927530)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.130.44.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927530/; classtype:trojan-activity;sid:84790630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927528)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pspc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927528/; classtype:trojan-activity;sid:84790628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927529)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927529/; classtype:trojan-activity;sid:84790629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927527)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927527/; classtype:trojan-activity;sid:84790627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927522)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/psh4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927522/; classtype:trojan-activity;sid:84790622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927523)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927523/; classtype:trojan-activity;sid:84790623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927524)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/px86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927524/; classtype:trojan-activity;sid:84790624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927525)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927525/; classtype:trojan-activity;sid:84790625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927526)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm6"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927526/; classtype:trojan-activity;sid:84790626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927520)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927520/; classtype:trojan-activity;sid:84790620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927521)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmpsl"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927521/; classtype:trojan-activity;sid:84790621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927519)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pm68k"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"truswallet.foundation"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927519/; classtype:trojan-activity;sid:84790619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927517)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.246.41.32"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927517/; classtype:trojan-activity;sid:84790617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927518)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.20.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927518/; classtype:trojan-activity;sid:84790618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927513)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.72.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927513/; classtype:trojan-activity;sid:84790613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927514)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.252.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927514/; classtype:trojan-activity;sid:84790614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927515)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.195"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927515/; classtype:trojan-activity;sid:84790615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927516)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.129.154"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927516/; classtype:trojan-activity;sid:84790616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927507)"; flow:established,from_client; content:"GET"; http_method; content:"/debug.dbg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927507/; classtype:trojan-activity;sid:84790607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927508)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927508/; classtype:trojan-activity;sid:84790608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927509)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927509/; classtype:trojan-activity;sid:84790609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927510)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927510/; classtype:trojan-activity;sid:84790610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927511)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927511/; classtype:trojan-activity;sid:84790611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927512)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927512/; classtype:trojan-activity;sid:84790612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927501)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927501/; classtype:trojan-activity;sid:84790601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927502)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927502/; classtype:trojan-activity;sid:84790602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927503)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927503/; classtype:trojan-activity;sid:84790603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927504)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927504/; classtype:trojan-activity;sid:84790604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927505)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927505/; classtype:trojan-activity;sid:84790605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927506)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927506/; classtype:trojan-activity;sid:84790606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927499)"; flow:established,from_client; content:"GET"; http_method; content:"/helix.jar"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"files.54daysaverage.qzz.io"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927499/; classtype:trojan-activity;sid:84790599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927500)"; flow:established,from_client; content:"GET"; http_method; content:"/sodium.jar"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"files.54daysaverage.qzz.io"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927500/; classtype:trojan-activity;sid:84790600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927496)"; flow:established,from_client; content:"GET"; http_method; content:"/discordhash.js"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"files.54daysaverage.qzz.io"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927496/; classtype:trojan-activity;sid:84790596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927497)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"www.wuming0.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927497/; classtype:trojan-activity;sid:84790597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927498)"; flow:established,from_client; content:"GET"; http_method; content:"/sylant.class"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"files.54daysaverage.qzz.io"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927498/; classtype:trojan-activity;sid:84790598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927495)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.71.23.92"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927495/; classtype:trojan-activity;sid:84790595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927493)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.65.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927493/; classtype:trojan-activity;sid:84790593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927494)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.19.223.213"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927494/; classtype:trojan-activity;sid:84790594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927489)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927489/; classtype:trojan-activity;sid:84790589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927490)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.130.44.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927490/; classtype:trojan-activity;sid:84790590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927491)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.52.125.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927491/; classtype:trojan-activity;sid:84790591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927492)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.47.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927492/; classtype:trojan-activity;sid:84790592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927488)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.120.3.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927488/; classtype:trojan-activity;sid:84790588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927487)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.4.244.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927487/; classtype:trojan-activity;sid:84790587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927486)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.98.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927486/; classtype:trojan-activity;sid:84790586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927485)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.52.125.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927485/; classtype:trojan-activity;sid:84790585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927483)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.217.248.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927483/; classtype:trojan-activity;sid:84790583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927484)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.209.120"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927484/; classtype:trojan-activity;sid:84790584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927480)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.209.120"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927480/; classtype:trojan-activity;sid:84790580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927481)"; flow:established,from_client; content:"GET"; http_method; content:"/p.arm5"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927481/; classtype:trojan-activity;sid:84790581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927482)"; flow:established,from_client; content:"GET"; http_method; content:"/p.x86_64"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927482/; classtype:trojan-activity;sid:84790582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927472)"; flow:established,from_client; content:"GET"; http_method; content:"/p.mips"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927472/; classtype:trojan-activity;sid:84790572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927473)"; flow:established,from_client; content:"GET"; http_method; content:"/p.loong64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927473/; classtype:trojan-activity;sid:84790573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927474)"; flow:established,from_client; content:"GET"; http_method; content:"/p.mipsle"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927474/; classtype:trojan-activity;sid:84790574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927475)"; flow:established,from_client; content:"GET"; http_method; content:"/p.arm6"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927475/; classtype:trojan-activity;sid:84790575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927476)"; flow:established,from_client; content:"GET"; http_method; content:"/p.arm7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927476/; classtype:trojan-activity;sid:84790576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927477)"; flow:established,from_client; content:"GET"; http_method; content:"/p.x86"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927477/; classtype:trojan-activity;sid:84790577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927478)"; flow:established,from_client; content:"GET"; http_method; content:"/p.s390x"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927478/; classtype:trojan-activity;sid:84790578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927479)"; flow:established,from_client; content:"GET"; http_method; content:"/p.arm64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927479/; classtype:trojan-activity;sid:84790579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927470)"; flow:established,from_client; content:"GET"; http_method; content:"/p.mips64"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927470/; classtype:trojan-activity;sid:84790570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927471)"; flow:established,from_client; content:"GET"; http_method; content:"/p.riscv64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927471/; classtype:trojan-activity;sid:84790571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927469)"; flow:established,from_client; content:"GET"; http_method; content:"/p.mips64le"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.138"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927469/; classtype:trojan-activity;sid:84790569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927468)"; flow:established,from_client; content:"GET"; http_method; content:"/sjsnb20-tech/millida/raw/main/millidadupe-1.03-26.3mc.jar"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927468/; classtype:trojan-activity;sid:84790568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927467)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927467/; classtype:trojan-activity;sid:84790567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927466)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.120.3.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927466/; classtype:trojan-activity;sid:84790566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927462)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.28.193.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927462/; classtype:trojan-activity;sid:84790562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927463)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.136.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927463/; classtype:trojan-activity;sid:84790563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927464)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.191.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927464/; classtype:trojan-activity;sid:84790564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927465)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.147.110"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927465/; classtype:trojan-activity;sid:84790565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927461)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.27.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927461/; classtype:trojan-activity;sid:84790561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927460)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.34.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927460/; classtype:trojan-activity;sid:84790560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927459)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.221.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927459/; classtype:trojan-activity;sid:84790559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927457)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.131.140.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927457/; classtype:trojan-activity;sid:84790557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927458)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.61.182"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927458/; classtype:trojan-activity;sid:84790558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927456)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/gaylo.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927456/; classtype:trojan-activity;sid:84790556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927452)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"autoflotte-vergabe.de"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927452/; classtype:trojan-activity;sid:84790552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927453)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"baainbw-vergabe.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927453/; classtype:trojan-activity;sid:84790553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927454)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"nordmann-automobilgruppe.de"; http_host; depth:27; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927454/; classtype:trojan-activity;sid:84790554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927455)"; flow:established,from_client; content:"GET"; http_method; content:"/api/cm-token"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"fahrzeugvergabe.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927455/; classtype:trojan-activity;sid:84790555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927450)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"autoflotte-vergabe.de"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927450/; classtype:trojan-activity;sid:84790550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927451)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"fahrzeugvergabe.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927451/; classtype:trojan-activity;sid:84790551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927449)"; flow:established,from_client; content:"GET"; http_method; content:"/unterlagen.html"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"fahrzeugvergabe.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927449/; classtype:trojan-activity;sid:84790549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927445)"; flow:established,from_client; content:"GET"; http_method; content:"/lotus.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927445/; classtype:trojan-activity;sid:84790545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927446)"; flow:established,from_client; content:"GET"; http_method; content:"/unterlagen.html"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"baainbw-vergabe.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927446/; classtype:trojan-activity;sid:84790546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927447)"; flow:established,from_client; content:"GET"; http_method; content:"/unterlagen.html"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"nordmann-automobilgruppe.de"; http_host; depth:27; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927447/; classtype:trojan-activity;sid:84790547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927448)"; flow:established,from_client; content:"GET"; http_method; content:"/unterlagen.html"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"autoflotte-vergabe.de"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927448/; classtype:trojan-activity;sid:84790548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927443)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.103.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927443/; classtype:trojan-activity;sid:84790543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927444)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.147.110"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927444/; classtype:trojan-activity;sid:84790544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927442)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.136.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927442/; classtype:trojan-activity;sid:84790542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927441)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.78.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927441/; classtype:trojan-activity;sid:84790541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927440)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.42.54.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927440/; classtype:trojan-activity;sid:84790540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927439)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.131.140.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927439/; classtype:trojan-activity;sid:84790539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927437)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.99.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927437/; classtype:trojan-activity;sid:84790537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927438)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.228.108.53"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927438/; classtype:trojan-activity;sid:84790538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927436)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927436/; classtype:trojan-activity;sid:84790536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927431)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.144.52.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927431/; classtype:trojan-activity;sid:84790531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927432)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.144.52.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927432/; classtype:trojan-activity;sid:84790532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927433)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.144.52.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927433/; classtype:trojan-activity;sid:84790533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927434)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.144.52.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927434/; classtype:trojan-activity;sid:84790534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927435)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.144.52.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927435/; classtype:trojan-activity;sid:84790535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927430)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.238.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927430/; classtype:trojan-activity;sid:84790530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927429)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927429/; classtype:trojan-activity;sid:84790529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927428)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.166.200.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927428/; classtype:trojan-activity;sid:84790528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927424)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.10.44.157"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927424/; classtype:trojan-activity;sid:84790524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927425)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.48.154"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927425/; classtype:trojan-activity;sid:84790525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927426)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.88.7.48"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927426/; classtype:trojan-activity;sid:84790526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927427)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927427/; classtype:trojan-activity;sid:84790527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927423)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.24.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927423/; classtype:trojan-activity;sid:84790523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927419)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.188.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927419/; classtype:trojan-activity;sid:84790519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927420)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.248.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927420/; classtype:trojan-activity;sid:84790520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927421)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.237.245.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927421/; classtype:trojan-activity;sid:84790521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927422)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.225.99.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927422/; classtype:trojan-activity;sid:84790522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927418)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.54.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927418/; classtype:trojan-activity;sid:84790518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927417)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"200.115.102.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927417/; classtype:trojan-activity;sid:84790517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927415)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.48.154"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927415/; classtype:trojan-activity;sid:84790515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927416)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.140.74.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927416/; classtype:trojan-activity;sid:84790516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927414)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.28.177.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927414/; classtype:trojan-activity;sid:84790514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927407)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.248.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927407/; classtype:trojan-activity;sid:84790507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927408)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.84.253"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927408/; classtype:trojan-activity;sid:84790508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927409)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.96.94.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927409/; classtype:trojan-activity;sid:84790509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927410)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927410/; classtype:trojan-activity;sid:84790510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927411)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.65.189.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927411/; classtype:trojan-activity;sid:84790511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927412)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.188.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927412/; classtype:trojan-activity;sid:84790512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927413)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.214.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927413/; classtype:trojan-activity;sid:84790513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927406)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"110.186.231.117"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927406/; classtype:trojan-activity;sid:84790506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927403)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.228.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927403/; classtype:trojan-activity;sid:84790503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927404)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.239.80.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927404/; classtype:trojan-activity;sid:84790504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927405)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.30.115.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927405/; classtype:trojan-activity;sid:84790505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927402)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.92.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927402/; classtype:trojan-activity;sid:84790502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927401)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/mko2.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927401/; classtype:trojan-activity;sid:84790501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927400)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.96.94.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927400/; classtype:trojan-activity;sid:84790500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927398)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.122.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927398/; classtype:trojan-activity;sid:84790498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927399)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"163.142.84.253"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927399/; classtype:trojan-activity;sid:84790499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927396)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927396/; classtype:trojan-activity;sid:84790496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927397)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.207.228.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927397/; classtype:trojan-activity;sid:84790497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927395)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.187.30.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927395/; classtype:trojan-activity;sid:84790495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927393)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm7"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927393/; classtype:trojan-activity;sid:84790493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927394)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.m68k"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927394/; classtype:trojan-activity;sid:84790494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927390)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm5"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927390/; classtype:trojan-activity;sid:84790490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927391)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.x86"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927391/; classtype:trojan-activity;sid:84790491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927392)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.mips"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927392/; classtype:trojan-activity;sid:84790492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927389)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm6"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927389/; classtype:trojan-activity;sid:84790489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927385)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.mpsl"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927385/; classtype:trojan-activity;sid:84790485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927386)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.sh4"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927386/; classtype:trojan-activity;sid:84790486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927387)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.ppc"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927387/; classtype:trojan-activity;sid:84790487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927388)"; flow:established,from_client; content:"GET"; http_method; content:"/binarys/owari.arm"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.26.106.32"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927388/; classtype:trojan-activity;sid:84790488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927384)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.7.113.111"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927384/; classtype:trojan-activity;sid:84790484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927383)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.226.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927383/; classtype:trojan-activity;sid:84790483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927377)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.98.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927377/; classtype:trojan-activity;sid:84790477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927378)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.231.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927378/; classtype:trojan-activity;sid:84790478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927379)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.8.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927379/; classtype:trojan-activity;sid:84790479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927380)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.253.147"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927380/; classtype:trojan-activity;sid:84790480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927381)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.239.80.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927381/; classtype:trojan-activity;sid:84790481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927382)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.201.25.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927382/; classtype:trojan-activity;sid:84790482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927376)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.231.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927376/; classtype:trojan-activity;sid:84790476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927374)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.236.99"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927374/; classtype:trojan-activity;sid:84790474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927375)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.89.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927375/; classtype:trojan-activity;sid:84790475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927373)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.146.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927373/; classtype:trojan-activity;sid:84790473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927371)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.53.121.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927371/; classtype:trojan-activity;sid:84790471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927372)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.253.147"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927372/; classtype:trojan-activity;sid:84790472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927369)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.228.95"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927369/; classtype:trojan-activity;sid:84790469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927370)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.14.17.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927370/; classtype:trojan-activity;sid:84790470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927368)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.8.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927368/; classtype:trojan-activity;sid:84790468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927367)"; flow:established,from_client; content:"GET"; http_method; content:"/api/file-share/883e3cde-f663-4e50-bc61-84dca8916960/download"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"expirience.icu"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927367/; classtype:trojan-activity;sid:84790467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927366)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/pytrim.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"expirience.icu"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927366/; classtype:trojan-activity;sid:84790466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927365)"; flow:established,from_client; content:"GET"; http_method; content:"/one.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.99.97.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927365/; classtype:trojan-activity;sid:84790465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927364)"; flow:established,from_client; content:"GET"; http_method; content:"/second.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"185.99.97.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927364/; classtype:trojan-activity;sid:84790464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927363)"; flow:established,from_client; content:"GET"; http_method; content:"/formela.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"185.99.97.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927363/; classtype:trojan-activity;sid:84790463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927362)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.127.103.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927362/; classtype:trojan-activity;sid:84790462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927360)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.203.230.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927360/; classtype:trojan-activity;sid:84790460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927359)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.70.235.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927359/; classtype:trojan-activity;sid:84790459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927358)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.89.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927358/; classtype:trojan-activity;sid:84790458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927357)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.138.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927357/; classtype:trojan-activity;sid:84790457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927355)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.178.60.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927355/; classtype:trojan-activity;sid:84790455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927356)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.207.221.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927356/; classtype:trojan-activity;sid:84790456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927354)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.35.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927354/; classtype:trojan-activity;sid:84790454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927353)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"95.232.72.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927353/; classtype:trojan-activity;sid:84790453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927352)"; flow:established,from_client; content:"GET"; http_method; content:"/clickfix.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"clownguard.us"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927352/; classtype:trojan-activity;sid:84790452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927351)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"78.38.120.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927351/; classtype:trojan-activity;sid:84790451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927349)"; flow:established,from_client; content:"GET"; http_method; content:"/adb2.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927349/; classtype:trojan-activity;sid:84790449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927350)"; flow:established,from_client; content:"GET"; http_method; content:"/pack/agent/nodewatchd-linux-arm"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"astroliper.ac"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927350/; classtype:trojan-activity;sid:84790450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927347)"; flow:established,from_client; content:"GET"; http_method; content:"/pack/agent/nodewatchd-linux-amd64"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"astroliper.ac"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927347/; classtype:trojan-activity;sid:84790447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927348)"; flow:established,from_client; content:"GET"; http_method; content:"/pack/agent/nodewatchd-linux-arm64"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"astroliper.ac"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927348/; classtype:trojan-activity;sid:84790448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927343)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.55.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927343/; classtype:trojan-activity;sid:84790443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927344)"; flow:established,from_client; content:"GET"; http_method; content:"/fvbig/zerobot.arm7"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927344/; classtype:trojan-activity;sid:84790444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927345)"; flow:established,from_client; content:"GET"; http_method; content:"/fvbig/zerobot.arm64"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"176.65.139.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927345/; classtype:trojan-activity;sid:84790445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927346)"; flow:established,from_client; content:"GET"; http_method; content:"/sh"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"217.60.102.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927346/; classtype:trojan-activity;sid:84790446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927342)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/$a"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927342/; classtype:trojan-activity;sid:84790442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927341)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.228.95"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927341/; classtype:trojan-activity;sid:84790441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927340)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.15.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927340/; classtype:trojan-activity;sid:84790440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927339)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.149.62.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927339/; classtype:trojan-activity;sid:84790439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927338)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.114.207"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927338/; classtype:trojan-activity;sid:84790438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927337)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.190.23.91"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927337/; classtype:trojan-activity;sid:84790437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927333)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.4.179.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927333/; classtype:trojan-activity;sid:84790433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927334)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"31.129.2.46"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927334/; classtype:trojan-activity;sid:84790434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927335)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.171.43"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927335/; classtype:trojan-activity;sid:84790435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927336)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.114.207"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927336/; classtype:trojan-activity;sid:84790436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927332)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.27.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927332/; classtype:trojan-activity;sid:84790432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927331)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.126.86.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927331/; classtype:trojan-activity;sid:84790431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927330)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.92.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927330/; classtype:trojan-activity;sid:84790430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927328)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.57.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927328/; classtype:trojan-activity;sid:84790428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927329)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927329/; classtype:trojan-activity;sid:84790429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927327)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.239.199.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927327/; classtype:trojan-activity;sid:84790427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927326)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.236.65.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927326/; classtype:trojan-activity;sid:84790426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927325)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.106.249.45"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927325/; classtype:trojan-activity;sid:84790425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927323)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.57.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927323/; classtype:trojan-activity;sid:84790423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927324)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.239.199.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927324/; classtype:trojan-activity;sid:84790424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927321)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927321/; classtype:trojan-activity;sid:84790421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927322)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.48.179.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927322/; classtype:trojan-activity;sid:84790422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927320)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.98.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927320/; classtype:trojan-activity;sid:84790420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927319)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.124.140"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927319/; classtype:trojan-activity;sid:84790419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927318)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.94.20"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927318/; classtype:trojan-activity;sid:84790418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927317)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.152.100.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927317/; classtype:trojan-activity;sid:84790417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927316)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.193.59"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927316/; classtype:trojan-activity;sid:84790416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927313)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.13.78"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927313/; classtype:trojan-activity;sid:84790413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927314)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.171.168.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927314/; classtype:trojan-activity;sid:84790414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927315)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.48.179.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927315/; classtype:trojan-activity;sid:84790415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927312)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.55.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927312/; classtype:trojan-activity;sid:84790412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927310)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.47.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927310/; classtype:trojan-activity;sid:84790410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927311)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.179.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927311/; classtype:trojan-activity;sid:84790411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927309)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.160.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927309/; classtype:trojan-activity;sid:84790409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927308)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.113.230.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927308/; classtype:trojan-activity;sid:84790408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927306)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.236.122.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927306/; classtype:trojan-activity;sid:84790406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927307)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.152.100.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927307/; classtype:trojan-activity;sid:84790407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927305)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.59.32.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927305/; classtype:trojan-activity;sid:84790405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927304)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.59.32.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927304/; classtype:trojan-activity;sid:84790404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927302)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.70.109.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927302/; classtype:trojan-activity;sid:84790402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927303)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.70.109.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927303/; classtype:trojan-activity;sid:84790403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927300)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.47.168"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927300/; classtype:trojan-activity;sid:84790400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927301)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.111.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927301/; classtype:trojan-activity;sid:84790401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927298)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927298/; classtype:trojan-activity;sid:84790398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927299)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.114.62.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927299/; classtype:trojan-activity;sid:84790399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927297)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.232.72.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927297/; classtype:trojan-activity;sid:84790397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927296)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.172.186.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927296/; classtype:trojan-activity;sid:84790396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927295)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.111.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927295/; classtype:trojan-activity;sid:84790395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927293)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.232.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927293/; classtype:trojan-activity;sid:84790393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927294)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.113.230.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927294/; classtype:trojan-activity;sid:84790394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927292)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.31.194.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927292/; classtype:trojan-activity;sid:84790392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927291)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.71.23.92"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927291/; classtype:trojan-activity;sid:84790391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927290)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.138.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927290/; classtype:trojan-activity;sid:84790390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927289)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.32.129"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927289/; classtype:trojan-activity;sid:84790389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927288)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.193.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927288/; classtype:trojan-activity;sid:84790388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927287)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.232.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927287/; classtype:trojan-activity;sid:84790387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927286)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.158.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927286/; classtype:trojan-activity;sid:84790386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927285)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.85.218.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927285/; classtype:trojan-activity;sid:84790385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927284)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.255.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927284/; classtype:trojan-activity;sid:84790384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927283)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.128.65.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927283/; classtype:trojan-activity;sid:84790383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927282)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.200.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927282/; classtype:trojan-activity;sid:84790382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927279)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.234.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927279/; classtype:trojan-activity;sid:84790379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927280)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.37.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927280/; classtype:trojan-activity;sid:84790380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927281)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.148.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927281/; classtype:trojan-activity;sid:84790381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927278)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.158.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927278/; classtype:trojan-activity;sid:84790378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927277)"; flow:established,from_client; content:"GET"; http_method; content:"/suckdick.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927277/; classtype:trojan-activity;sid:84790377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927276)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.255.151"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927276/; classtype:trojan-activity;sid:84790376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927275)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.103.56"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927275/; classtype:trojan-activity;sid:84790375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927270)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927270/; classtype:trojan-activity;sid:84790370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927271)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927271/; classtype:trojan-activity;sid:84790371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927272)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927272/; classtype:trojan-activity;sid:84790372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927273)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927273/; classtype:trojan-activity;sid:84790373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927274)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927274/; classtype:trojan-activity;sid:84790374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927267)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927267/; classtype:trojan-activity;sid:84790367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927268)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927268/; classtype:trojan-activity;sid:84790368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927269)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927269/; classtype:trojan-activity;sid:84790369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927263)"; flow:established,from_client; content:"GET"; http_method; content:"/arm4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927263/; classtype:trojan-activity;sid:84790363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927264)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927264/; classtype:trojan-activity;sid:84790364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927265)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927265/; classtype:trojan-activity;sid:84790365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927266)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc-440fp"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"85.202.163.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927266/; classtype:trojan-activity;sid:84790366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927261)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.spc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927261/; classtype:trojan-activity;sid:84790361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927262)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.122.110.235"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927262/; classtype:trojan-activity;sid:84790362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927260)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.234.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927260/; classtype:trojan-activity;sid:84790360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927259)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"79.106.231.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927259/; classtype:trojan-activity;sid:84790359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927258)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.202.233.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927258/; classtype:trojan-activity;sid:84790358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927255)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.88.21"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927255/; classtype:trojan-activity;sid:84790355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927256)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.238.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927256/; classtype:trojan-activity;sid:84790356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927257)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.84.90"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927257/; classtype:trojan-activity;sid:84790357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927253)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.171.124.23"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927253/; classtype:trojan-activity;sid:84790353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927254)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.118.245.176"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927254/; classtype:trojan-activity;sid:84790354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927252)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.188.197.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927252/; classtype:trojan-activity;sid:84790352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927251)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.176.197.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927251/; classtype:trojan-activity;sid:84790351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.219.186"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927249/; classtype:trojan-activity;sid:84790349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927250)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.118.245.176"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927250/; classtype:trojan-activity;sid:84790350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927244)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.54.150.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927244/; classtype:trojan-activity;sid:84790344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927245)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.133.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927245/; classtype:trojan-activity;sid:84790345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927246)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.88.16"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927246/; classtype:trojan-activity;sid:84790346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927247)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.226.78.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927247/; classtype:trojan-activity;sid:84790347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.137.180"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927248/; classtype:trojan-activity;sid:84790348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927243)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.124.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927243/; classtype:trojan-activity;sid:84790343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927242)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.71.21.118"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927242/; classtype:trojan-activity;sid:84790342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927241)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.187.30.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927241/; classtype:trojan-activity;sid:84790341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927240)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927240/; classtype:trojan-activity;sid:84790340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927239)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.83.136"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927239/; classtype:trojan-activity;sid:84790339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927237)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.137.180"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927237/; classtype:trojan-activity;sid:84790337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927238)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.36.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927238/; classtype:trojan-activity;sid:84790338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927235)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.54.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927235/; classtype:trojan-activity;sid:84790335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927236)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.190.23.91"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927236/; classtype:trojan-activity;sid:84790336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927234)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.238.222"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927234/; classtype:trojan-activity;sid:84790334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927229)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.238.222"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927229/; classtype:trojan-activity;sid:84790329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927230)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.76.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927230/; classtype:trojan-activity;sid:84790330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927231)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.28.99.89"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927231/; classtype:trojan-activity;sid:84790331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927232)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.24.43.54"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927232/; classtype:trojan-activity;sid:84790332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927233)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.251.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927233/; classtype:trojan-activity;sid:84790333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927228)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.105.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_03; reference:url, urlhaus.abuse.ch/url/3927228/; classtype:trojan-activity;sid:84790328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927227)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.85.131"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927227/; classtype:trojan-activity;sid:84790327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927226)"; flow:established,from_client; content:"GET"; http_method; content:"/download|3f|payload=njrat.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"nfadealer.top"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927226/; classtype:trojan-activity;sid:84790326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927225)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.90.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927225/; classtype:trojan-activity;sid:84790325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927224)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.104.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927224/; classtype:trojan-activity;sid:84790324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927223)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.101.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927223/; classtype:trojan-activity;sid:84790323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927219)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"177.36.24.217"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927219/; classtype:trojan-activity;sid:84790319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927220)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.54.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927220/; classtype:trojan-activity;sid:84790320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927221)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.105.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927221/; classtype:trojan-activity;sid:84790321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927222)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.14.37.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927222/; classtype:trojan-activity;sid:84790322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927218)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.148.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927218/; classtype:trojan-activity;sid:84790318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927217)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.254.10.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927217/; classtype:trojan-activity;sid:84790317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927214)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.108.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927214/; classtype:trojan-activity;sid:84790314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927215)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.50.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927215/; classtype:trojan-activity;sid:84790315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927216)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.203.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927216/; classtype:trojan-activity;sid:84790316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927210)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.219.1.198"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927210/; classtype:trojan-activity;sid:84790310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927211)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.35.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927211/; classtype:trojan-activity;sid:84790311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927212)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.74.80.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927212/; classtype:trojan-activity;sid:84790312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927213)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.1.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927213/; classtype:trojan-activity;sid:84790313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927209)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.51.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927209/; classtype:trojan-activity;sid:84790309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927208)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.1.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927208/; classtype:trojan-activity;sid:84790308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927207)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.191.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927207/; classtype:trojan-activity;sid:84790307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927205)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.217.248.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927205/; classtype:trojan-activity;sid:84790305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927206)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.211.213.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927206/; classtype:trojan-activity;sid:84790306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927204)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.252.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927204/; classtype:trojan-activity;sid:84790304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927203)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.54.150.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927203/; classtype:trojan-activity;sid:84790303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927200)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.35.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927200/; classtype:trojan-activity;sid:84790300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927201)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.217.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927201/; classtype:trojan-activity;sid:84790301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927202)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.74.80.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927202/; classtype:trojan-activity;sid:84790302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927199)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.107.98.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927199/; classtype:trojan-activity;sid:84790299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927197)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.240.53.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927197/; classtype:trojan-activity;sid:84790297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927198)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"151.232.139.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927198/; classtype:trojan-activity;sid:84790298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927196)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.236.70.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927196/; classtype:trojan-activity;sid:84790296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927195)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.155.202.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927195/; classtype:trojan-activity;sid:84790295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927194)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.231.117.51"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927194/; classtype:trojan-activity;sid:84790294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927192)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.83.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927192/; classtype:trojan-activity;sid:84790292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927193)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.49.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927193/; classtype:trojan-activity;sid:84790293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927191)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.240.53.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927191/; classtype:trojan-activity;sid:84790291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927190)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.233.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927190/; classtype:trojan-activity;sid:84790290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927188)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.40.245"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927188/; classtype:trojan-activity;sid:84790288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.151.218.17"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927189/; classtype:trojan-activity;sid:84790289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927187)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/67dbf1a8e19934e4_thread_hijacking_cayoy4nb.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927187/; classtype:trojan-activity;sid:84790287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927186)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.139.45.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927186/; classtype:trojan-activity;sid:84790286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927184)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.236.70.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927184/; classtype:trojan-activity;sid:84790284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927185)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.232.139.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927185/; classtype:trojan-activity;sid:84790285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927183)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.151.218.17"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927183/; classtype:trojan-activity;sid:84790283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927182)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.40.245"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927182/; classtype:trojan-activity;sid:84790282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927180)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.53.222.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927180/; classtype:trojan-activity;sid:84790280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927181)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.235.143"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927181/; classtype:trojan-activity;sid:84790281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927179)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.13.232.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927179/; classtype:trojan-activity;sid:84790279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927177)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.54.234.57"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927177/; classtype:trojan-activity;sid:84790277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927178)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.158.11"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927178/; classtype:trojan-activity;sid:84790278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927175)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.158.11"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927175/; classtype:trojan-activity;sid:84790275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927176)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.183.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927176/; classtype:trojan-activity;sid:84790276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927173)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.162.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927173/; classtype:trojan-activity;sid:84790273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927174)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.6.60.72"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927174/; classtype:trojan-activity;sid:84790274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927172)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.190.134.251"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927172/; classtype:trojan-activity;sid:84790272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927171)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.53.222.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927171/; classtype:trojan-activity;sid:84790271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927170)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.235.85"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927170/; classtype:trojan-activity;sid:84790270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.154.114"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927169/; classtype:trojan-activity;sid:84790269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927168)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"217.145.72.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927168/; classtype:trojan-activity;sid:84790268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927167)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sparc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927167/; classtype:trojan-activity;sid:84790267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927166)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.aarch64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927166/; classtype:trojan-activity;sid:84790266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927165)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.20.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927165/; classtype:trojan-activity;sid:84790265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927164)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.47.213"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927164/; classtype:trojan-activity;sid:84790264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927162)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.69.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927162/; classtype:trojan-activity;sid:84790262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927163)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.49.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927163/; classtype:trojan-activity;sid:84790263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927159)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.99.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927159/; classtype:trojan-activity;sid:84790259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927160)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.154.114"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927160/; classtype:trojan-activity;sid:84790260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927161)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.78.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927161/; classtype:trojan-activity;sid:84790261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927155)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"177.36.24.217"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927155/; classtype:trojan-activity;sid:84790255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927156)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.152.52"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927156/; classtype:trojan-activity;sid:84790256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927157)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.111.23.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927157/; classtype:trojan-activity;sid:84790257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927158)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.206.184.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927158/; classtype:trojan-activity;sid:84790258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927154)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.58.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927154/; classtype:trojan-activity;sid:84790254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927153)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1555672813413732352/1555673509751951361/bundle.zip|3f|ex=6ac1615b|7c|26|7c|is=6ac00fdb|7c|26|7c|hm=7fa01976e030509c4017d9478904258c81d5c0e0aadee2e32b2df9c7cfa81d1f|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927153/; classtype:trojan-activity;sid:84790253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927152)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.198.173"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927152/; classtype:trojan-activity;sid:84790252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927149)"; flow:established,from_client; content:"GET"; http_method; content:"/s/kswpad"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927149/; classtype:trojan-activity;sid:84790249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927150)"; flow:established,from_client; content:"GET"; http_method; content:"/s/amd64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927150/; classtype:trojan-activity;sid:84790250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927151)"; flow:established,from_client; content:"GET"; http_method; content:"/s/kal64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927151/; classtype:trojan-activity;sid:84790251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927148)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.19.209.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927148/; classtype:trojan-activity;sid:84790248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927145)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.64.166"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927145/; classtype:trojan-activity;sid:84790245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927146)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.190.134.251"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927146/; classtype:trojan-activity;sid:84790246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927147)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_d3e9763172c39cfb.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927147/; classtype:trojan-activity;sid:84790247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927142)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.254.10.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927142/; classtype:trojan-activity;sid:84790242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927143)"; flow:established,from_client; content:"GET"; http_method; content:"/d/unix58962202"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"tetris-supdate.xyz"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927143/; classtype:trojan-activity;sid:84790243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927144)"; flow:established,from_client; content:"GET"; http_method; content:"/d/unix37077334"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"109.238.87.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927144/; classtype:trojan-activity;sid:84790244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927141)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.80.60.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927141/; classtype:trojan-activity;sid:84790241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927140)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_18b51ad133197bb3.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927140/; classtype:trojan-activity;sid:84790240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927138)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig-x86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927138/; classtype:trojan-activity;sid:84790238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927139)"; flow:established,from_client; content:"GET"; http_method; content:"/cnc.pre-raw-apk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927139/; classtype:trojan-activity;sid:84790239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927135)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig-aarch64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927135/; classtype:trojan-activity;sid:84790235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927136)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig-x64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927136/; classtype:trojan-activity;sid:84790236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927137)"; flow:established,from_client; content:"GET"; http_method; content:"/cur.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927137/; classtype:trojan-activity;sid:84790237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927134)"; flow:established,from_client; content:"GET"; http_method; content:"/cnc.pre-category"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927134/; classtype:trojan-activity;sid:84790234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927132)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig-arm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927132/; classtype:trojan-activity;sid:84790232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927133)"; flow:established,from_client; content:"GET"; http_method; content:"/cnc.backup-ui"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927133/; classtype:trojan-activity;sid:84790233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927130)"; flow:established,from_client; content:"GET"; http_method; content:"/l4_armv7l"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927130/; classtype:trojan-activity;sid:84790230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927131)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.ppc64le"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927131/; classtype:trojan-activity;sid:84790231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927129)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/raw/refs/heads/main/mko1.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927129/; classtype:trojan-activity;sid:84790229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927128)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/refs/heads/main/mko1.js|3f|download=1"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927128/; classtype:trojan-activity;sid:84790228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927127)"; flow:established,from_client; content:"GET"; http_method; content:"/juan.apk"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927127/; classtype:trojan-activity;sid:84790227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927125)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.armv6l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927125/; classtype:trojan-activity;sid:84790225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927126)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l.pre-persist"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927126/; classtype:trojan-activity;sid:84790226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927122)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64.pre-variant"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927122/; classtype:trojan-activity;sid:84790222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927123)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64.pre-persist"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927123/; classtype:trojan-activity;sid:84790223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927124)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l.pre-variant"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927124/; classtype:trojan-activity;sid:84790224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927120)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.armv5tel"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927120/; classtype:trojan-activity;sid:84790220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927121)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.armv7l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927121/; classtype:trojan-activity;sid:84790221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927119)"; flow:established,from_client; content:"GET"; http_method; content:"/t/stg.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"31.76.61.78"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927119/; classtype:trojan-activity;sid:84790219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927118)"; flow:established,from_client; content:"GET"; http_method; content:"/t/reader.hta"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"31.76.61.78"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927118/; classtype:trojan-activity;sid:84790218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927117)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.59.79.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927117/; classtype:trojan-activity;sid:84790217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927116)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.58.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927116/; classtype:trojan-activity;sid:84790216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927113)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.54.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927113/; classtype:trojan-activity;sid:84790213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927114)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.161.160.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927114/; classtype:trojan-activity;sid:84790214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927115)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.199.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927115/; classtype:trojan-activity;sid:84790215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927112)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"77.79.160.210"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927112/; classtype:trojan-activity;sid:84790212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927110)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927110/; classtype:trojan-activity;sid:84790210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927111)"; flow:established,from_client; content:"GET"; http_method; content:"/b_wt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927111/; classtype:trojan-activity;sid:84790211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927105)"; flow:established,from_client; content:"GET"; http_method; content:"/b_persist"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927105/; classtype:trojan-activity;sid:84790205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927106)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nowd"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927106/; classtype:trojan-activity;sid:84790206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927107)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_dbg"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927107/; classtype:trojan-activity;sid:84790207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927108)"; flow:established,from_client; content:"GET"; http_method; content:"/b_kt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927108/; classtype:trojan-activity;sid:84790208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927109)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_fin"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927109/; classtype:trojan-activity;sid:84790209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927102)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_sr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927102/; classtype:trojan-activity;sid:84790202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927103)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_v2"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927103/; classtype:trojan-activity;sid:84790203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927104)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_nsr"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927104/; classtype:trojan-activity;sid:84790204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927100)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_ns"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927100/; classtype:trojan-activity;sid:84790200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927101)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_new"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927101/; classtype:trojan-activity;sid:84790201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927097)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_clean"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927097/; classtype:trojan-activity;sid:84790197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927098)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64_t8"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927098/; classtype:trojan-activity;sid:84790198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927099)"; flow:established,from_client; content:"GET"; http_method; content:"/b_lt"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927099/; classtype:trojan-activity;sid:84790199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927096)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.149.91.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927096/; classtype:trojan-activity;sid:84790196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927095)"; flow:established,from_client; content:"GET"; http_method; content:"/setup_unassigned.msi"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"193.26.115.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927095/; classtype:trojan-activity;sid:84790195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927094)"; flow:established,from_client; content:"GET"; http_method; content:"/agent.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.16.52.209"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927094/; classtype:trojan-activity;sid:84790194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927093)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"160.179.255.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927093/; classtype:trojan-activity;sid:84790193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927092)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.79.160.210"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927092/; classtype:trojan-activity;sid:84790192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927091)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.242.231.62"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927091/; classtype:trojan-activity;sid:84790191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927090)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.176.197.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927090/; classtype:trojan-activity;sid:84790190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927089)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.69.66.206"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927089/; classtype:trojan-activity;sid:84790189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927088)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.252.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927088/; classtype:trojan-activity;sid:84790188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927087)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.149.91.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927087/; classtype:trojan-activity;sid:84790187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927085)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.125.31.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927085/; classtype:trojan-activity;sid:84790185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927086)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.236.122.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927086/; classtype:trojan-activity;sid:84790186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927083)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.20.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927083/; classtype:trojan-activity;sid:84790183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927084)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.179.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927084/; classtype:trojan-activity;sid:84790184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927080)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.189.1"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927080/; classtype:trojan-activity;sid:84790180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927081)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.74.91.108"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927081/; classtype:trojan-activity;sid:84790181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927082)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.167.45"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927082/; classtype:trojan-activity;sid:84790182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927079)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.2.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927079/; classtype:trojan-activity;sid:84790179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927078)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927078/; classtype:trojan-activity;sid:84790178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927076)"; flow:established,from_client; content:"GET"; http_method; content:"/main_sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927076/; classtype:trojan-activity;sid:84790176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927077)"; flow:established,from_client; content:"GET"; http_method; content:"/main_ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927077/; classtype:trojan-activity;sid:84790177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927074)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927074/; classtype:trojan-activity;sid:84790174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927075)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927075/; classtype:trojan-activity;sid:84790175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927067)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927067/; classtype:trojan-activity;sid:84790167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927068)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-386"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927068/; classtype:trojan-activity;sid:84790168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927069)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927069/; classtype:trojan-activity;sid:84790169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927070)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927070/; classtype:trojan-activity;sid:84790170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927071)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927071/; classtype:trojan-activity;sid:84790171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927072)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927072/; classtype:trojan-activity;sid:84790172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927073)"; flow:established,from_client; content:"GET"; http_method; content:"/main_m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927073/; classtype:trojan-activity;sid:84790173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927066)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.137.62.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927066/; classtype:trojan-activity;sid:84790166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927065)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.253.9"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927065/; classtype:trojan-activity;sid:84790165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927063)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"158.94.208.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927063/; classtype:trojan-activity;sid:84790163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927064)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"158.94.208.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927064/; classtype:trojan-activity;sid:84790164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927062)"; flow:established,from_client; content:"GET"; http_method; content:"/a.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"203.159.90.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927062/; classtype:trojan-activity;sid:84790162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927061)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.179.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927061/; classtype:trojan-activity;sid:84790161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927060)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.230.253"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927060/; classtype:trojan-activity;sid:84790160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927059)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.115.161.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927059/; classtype:trojan-activity;sid:84790159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927058)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927058/; classtype:trojan-activity;sid:84790158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927055)"; flow:established,from_client; content:"GET"; http_method; content:"/xm/xmrig-static-armv7"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927055/; classtype:trojan-activity;sid:84790155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927056)"; flow:established,from_client; content:"GET"; http_method; content:"/xm/xmrig-static-arm64"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927056/; classtype:trojan-activity;sid:84790156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927057)"; flow:established,from_client; content:"GET"; http_method; content:"/xm/xmrig-static-x64"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927057/; classtype:trojan-activity;sid:84790157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927052)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/kla.sh"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927052/; classtype:trojan-activity;sid:84790152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927053)"; flow:established,from_client; content:"GET"; http_method; content:"/cur.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927053/; classtype:trojan-activity;sid:84790153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927054)"; flow:established,from_client; content:"GET"; http_method; content:"/dvr.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.203"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927054/; classtype:trojan-activity;sid:84790154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927051)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_838a0bfd231e7a20.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927051/; classtype:trojan-activity;sid:84790151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927050)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.70.98.162"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927050/; classtype:trojan-activity;sid:84790150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927049)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.128.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927049/; classtype:trojan-activity;sid:84790149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927048)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.7.118.219"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927048/; classtype:trojan-activity;sid:84790148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927047)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.170.112.184"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927047/; classtype:trojan-activity;sid:84790147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927045)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.252.210.87"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927045/; classtype:trojan-activity;sid:84790145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927046)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.150.147.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927046/; classtype:trojan-activity;sid:84790146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927035)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sparc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927035/; classtype:trojan-activity;sid:84790135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927036)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.powerpc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927036/; classtype:trojan-activity;sid:84790136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927037)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927037/; classtype:trojan-activity;sid:84790137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927038)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927038/; classtype:trojan-activity;sid:84790138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927039)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv7l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927039/; classtype:trojan-activity;sid:84790139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927040)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv4l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927040/; classtype:trojan-activity;sid:84790140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927041)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927041/; classtype:trojan-activity;sid:84790141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927042)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv5l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927042/; classtype:trojan-activity;sid:84790142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927043)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927043/; classtype:trojan-activity;sid:84790143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927044)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927044/; classtype:trojan-activity;sid:84790144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927029)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsrouter"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927029/; classtype:trojan-activity;sid:84790129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927030)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.arc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927030/; classtype:trojan-activity;sid:84790130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927031)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.i486"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927031/; classtype:trojan-activity;sid:84790131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927032)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv6l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927032/; classtype:trojan-activity;sid:84790132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927033)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927033/; classtype:trojan-activity;sid:84790133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927034)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927034/; classtype:trojan-activity;sid:84790134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927025)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927025/; classtype:trojan-activity;sid:84790125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927026)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsle"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927026/; classtype:trojan-activity;sid:84790126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927027)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927027/; classtype:trojan-activity;sid:84790127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927028)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927028/; classtype:trojan-activity;sid:84790128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927024)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927024/; classtype:trojan-activity;sid:84790124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927022)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927022/; classtype:trojan-activity;sid:84790122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927023)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927023/; classtype:trojan-activity;sid:84790123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927019)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927019/; classtype:trojan-activity;sid:84790119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927020)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927020/; classtype:trojan-activity;sid:84790120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927021)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927021/; classtype:trojan-activity;sid:84790121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927015)"; flow:established,from_client; content:"GET"; http_method; content:"/android_arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927015/; classtype:trojan-activity;sid:84790115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927016)"; flow:established,from_client; content:"GET"; http_method; content:"/i386"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927016/; classtype:trojan-activity;sid:84790116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927017)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927017/; classtype:trojan-activity;sid:84790117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927018)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927018/; classtype:trojan-activity;sid:84790118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927007)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927007/; classtype:trojan-activity;sid:84790107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927008)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927008/; classtype:trojan-activity;sid:84790108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927009)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/w.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927009/; classtype:trojan-activity;sid:84790109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927010)"; flow:established,from_client; content:"GET"; http_method; content:"/c.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927010/; classtype:trojan-activity;sid:84790110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927011)"; flow:established,from_client; content:"GET"; http_method; content:"/dlink.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927011/; classtype:trojan-activity;sid:84790111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927012)"; flow:established,from_client; content:"GET"; http_method; content:"/z.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927012/; classtype:trojan-activity;sid:84790112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927013)"; flow:established,from_client; content:"GET"; http_method; content:"/w.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927013/; classtype:trojan-activity;sid:84790113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927014)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/wget.sh"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927014/; classtype:trojan-activity;sid:84790114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927005)"; flow:established,from_client; content:"GET"; http_method; content:"/av.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927005/; classtype:trojan-activity;sid:84790105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927006)"; flow:established,from_client; content:"GET"; http_method; content:"/k.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927006/; classtype:trojan-activity;sid:84790106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927004)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927004/; classtype:trojan-activity;sid:84790104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927003)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/c.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927003/; classtype:trojan-activity;sid:84790103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927002)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927002/; classtype:trojan-activity;sid:84790102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927000)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv7l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927000/; classtype:trojan-activity;sid:84790100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3927001)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.i686"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3927001/; classtype:trojan-activity;sid:84790101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926996)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926996/; classtype:trojan-activity;sid:84790096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926997)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926997/; classtype:trojan-activity;sid:84790097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926998)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv4l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926998/; classtype:trojan-activity;sid:84790098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926999)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.powerpc-440fp"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926999/; classtype:trojan-activity;sid:84790099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926989)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.i586"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926989/; classtype:trojan-activity;sid:84790089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926990)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926990/; classtype:trojan-activity;sid:84790090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926991)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926991/; classtype:trojan-activity;sid:84790091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926992)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv5l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926992/; classtype:trojan-activity;sid:84790092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926993)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv6l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926993/; classtype:trojan-activity;sid:84790093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926994)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mipsel"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926994/; classtype:trojan-activity;sid:84790094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926995)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.powerpc"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926995/; classtype:trojan-activity;sid:84790095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926987)"; flow:established,from_client; content:"GET"; http_method; content:"/loader.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926987/; classtype:trojan-activity;sid:84790087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926988)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926988/; classtype:trojan-activity;sid:84790088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926986)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.235.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926986/; classtype:trojan-activity;sid:84790086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926985)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.88.16"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926985/; classtype:trojan-activity;sid:84790085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926984)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.202.233.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926984/; classtype:trojan-activity;sid:84790084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926981)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.39.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926981/; classtype:trojan-activity;sid:84790081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926982)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.195.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926982/; classtype:trojan-activity;sid:84790082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926983)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.252.210.87"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926983/; classtype:trojan-activity;sid:84790083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926979)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.115.161.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926979/; classtype:trojan-activity;sid:84790079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926980)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.55.60.190"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926980/; classtype:trojan-activity;sid:84790080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926978)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.116.249.8"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926978/; classtype:trojan-activity;sid:84790078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926977)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.238.123.241"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926977/; classtype:trojan-activity;sid:84790077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926976)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.224.41"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926976/; classtype:trojan-activity;sid:84790076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926974)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.150.147.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926974/; classtype:trojan-activity;sid:84790074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926975)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.82.160.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926975/; classtype:trojan-activity;sid:84790075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926971)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.238.123.241"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926971/; classtype:trojan-activity;sid:84790071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926972)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.200.211.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926972/; classtype:trojan-activity;sid:84790072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926973)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.77.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926973/; classtype:trojan-activity;sid:84790073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926970)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.8.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926970/; classtype:trojan-activity;sid:84790070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926969)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.239.57.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926969/; classtype:trojan-activity;sid:84790069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926968)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.8.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926968/; classtype:trojan-activity;sid:84790068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926963)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.177.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926963/; classtype:trojan-activity;sid:84790063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926964)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.115.102.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926964/; classtype:trojan-activity;sid:84790064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926965)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.77.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926965/; classtype:trojan-activity;sid:84790065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926966)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.87.121.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926966/; classtype:trojan-activity;sid:84790066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926967)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.97.100.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926967/; classtype:trojan-activity;sid:84790067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926962)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.116.249.8"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926962/; classtype:trojan-activity;sid:84790062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926961)"; flow:established,from_client; content:"GET"; http_method; content:"/files/5279938618/opndkwr.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926961/; classtype:trojan-activity;sid:84790061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926960)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.191.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926960/; classtype:trojan-activity;sid:84790060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926959)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.2.255"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926959/; classtype:trojan-activity;sid:84790059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926958)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/e6efd8bd3bf0fae2_moratorium_0.96.2.9_install.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926958/; classtype:trojan-activity;sid:84790058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926957)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.83.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926957/; classtype:trojan-activity;sid:84790057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926956)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.177.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926956/; classtype:trojan-activity;sid:84790056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926955)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.58.201.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926955/; classtype:trojan-activity;sid:84790055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926954)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.114.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926954/; classtype:trojan-activity;sid:84790054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926953)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.130.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926953/; classtype:trojan-activity;sid:84790053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926952)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.137.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926952/; classtype:trojan-activity;sid:84790052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926950)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.167.65.75"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926950/; classtype:trojan-activity;sid:84790050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926951)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.240.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926951/; classtype:trojan-activity;sid:84790051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926949)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.86.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926949/; classtype:trojan-activity;sid:84790049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926948)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.86.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926948/; classtype:trojan-activity;sid:84790048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926947)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.23.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926947/; classtype:trojan-activity;sid:84790047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926946)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.83.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926946/; classtype:trojan-activity;sid:84790046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926945)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.78.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926945/; classtype:trojan-activity;sid:84790045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926944)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.167.65.75"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926944/; classtype:trojan-activity;sid:84790044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926943)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.148.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926943/; classtype:trojan-activity;sid:84790043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926942)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.202.230.86"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926942/; classtype:trojan-activity;sid:84790042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926941)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.156.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926941/; classtype:trojan-activity;sid:84790041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926939)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.202.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926939/; classtype:trojan-activity;sid:84790039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926940)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.147.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926940/; classtype:trojan-activity;sid:84790040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926937)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.31.103.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926937/; classtype:trojan-activity;sid:84790037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926938)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.69.88.61"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926938/; classtype:trojan-activity;sid:84790038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926936)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-mipsle"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926936/; classtype:trojan-activity;sid:84790036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926935)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-amd64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926935/; classtype:trojan-activity;sid:84790035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926933)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-arm64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926933/; classtype:trojan-activity;sid:84790033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926934)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.201"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926934/; classtype:trojan-activity;sid:84790034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926932)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.mpsl"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926932/; classtype:trojan-activity;sid:84790032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926931)"; flow:established,from_client; content:"GET"; http_method; content:"/thuhangn562727-del/maqueo/refs/heads/main/nanocore.js|3f|download=1"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926931/; classtype:trojan-activity;sid:84790031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926928)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.186.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926928/; classtype:trojan-activity;sid:84790028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926929)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.64.184.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926929/; classtype:trojan-activity;sid:84790029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926930)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.40.143"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926930/; classtype:trojan-activity;sid:84790030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926927)"; flow:established,from_client; content:"GET"; http_method; content:"/35/goodnewsthings.js"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"198.12.126.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926927/; classtype:trojan-activity;sid:84790027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926926)"; flow:established,from_client; content:"GET"; http_method; content:"/35/jjn.hta"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"198.12.126.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926926/; classtype:trojan-activity;sid:84790026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926925)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.ppc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926925/; classtype:trojan-activity;sid:84790025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926923)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.arm"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926923/; classtype:trojan-activity;sid:84790023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926924)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1298616021669773397/1555599712193617980/bundle.zip|3f|ex=6ac11ca1|7c|26|7c|is=6abfcb21|7c|26|7c|hm=31fffac8b6682f01a319aafe97f2517105c394975ec324877db5a03bd59373bb|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926924/; classtype:trojan-activity;sid:84790024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926922)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.spc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926922/; classtype:trojan-activity;sid:84790022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926916)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.m68k"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926916/; classtype:trojan-activity;sid:84790016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926917)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.arm5"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926917/; classtype:trojan-activity;sid:84790017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926918)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.arm7"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926918/; classtype:trojan-activity;sid:84790018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926919)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.sh4"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926919/; classtype:trojan-activity;sid:84790019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926920)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.mips"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926920/; classtype:trojan-activity;sid:84790020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926921)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.arm6"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926921/; classtype:trojan-activity;sid:84790021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926915)"; flow:established,from_client; content:"GET"; http_method; content:"/violet.x86"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"xiangduck.sld.tw"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926915/; classtype:trojan-activity;sid:84790015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926914)"; flow:established,from_client; content:"GET"; http_method; content:"/wget"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"139.144.210.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926914/; classtype:trojan-activity;sid:84790014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926913)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.69.88.61"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926913/; classtype:trojan-activity;sid:84790013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926912)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.187.177.158"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926912/; classtype:trojan-activity;sid:84790012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926911)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.115.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926911/; classtype:trojan-activity;sid:84790011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926908)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"83.219.1.198"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926908/; classtype:trojan-activity;sid:84790008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926909)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.122.242.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926909/; classtype:trojan-activity;sid:84790009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926910)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.206.184.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926910/; classtype:trojan-activity;sid:84790010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926907)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.235.36.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926907/; classtype:trojan-activity;sid:84790007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926906)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.1.225.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926906/; classtype:trojan-activity;sid:84790006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926905)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.240.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926905/; classtype:trojan-activity;sid:84790005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926903)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.203.41"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926903/; classtype:trojan-activity;sid:84790003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926904)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.126.201.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926904/; classtype:trojan-activity;sid:84790004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926902)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926902/; classtype:trojan-activity;sid:84790002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926901)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.115.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926901/; classtype:trojan-activity;sid:84790001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926898)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.229.166.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926898/; classtype:trojan-activity;sid:84789998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926899)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.202.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926899/; classtype:trojan-activity;sid:84789999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926900)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.148.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926900/; classtype:trojan-activity;sid:84790000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926897)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.247.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926897/; classtype:trojan-activity;sid:84789997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926896)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.16.164.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926896/; classtype:trojan-activity;sid:84789996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926895)"; flow:established,from_client; content:"GET"; http_method; content:"/c/b7d14c80.dat"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"203.12.31.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926895/; classtype:trojan-activity;sid:84789995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926894)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.125.157"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926894/; classtype:trojan-activity;sid:84789994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926893)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"79.36.217.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926893/; classtype:trojan-activity;sid:84789993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926892)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.1.225.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926892/; classtype:trojan-activity;sid:84789992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926891)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"223.151.253.6"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926891/; classtype:trojan-activity;sid:84789991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926890)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.22.148.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926890/; classtype:trojan-activity;sid:84789990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926889)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.202.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926889/; classtype:trojan-activity;sid:84789989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926888)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.243.176.58"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926888/; classtype:trojan-activity;sid:84789988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926887)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.85.131"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926887/; classtype:trojan-activity;sid:84789987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926886)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.185.189.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926886/; classtype:trojan-activity;sid:84789986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926884)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.154.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926884/; classtype:trojan-activity;sid:84789984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926885)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.253.9"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926885/; classtype:trojan-activity;sid:84789985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926883)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.28.99.89"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926883/; classtype:trojan-activity;sid:84789983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926882)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.146.231.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926882/; classtype:trojan-activity;sid:84789982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926881)"; flow:established,from_client; content:"GET"; http_method; content:"/mrun"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.178.110.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926881/; classtype:trojan-activity;sid:84789981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926880)"; flow:established,from_client; content:"GET"; http_method; content:"/beat_up"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"195.178.110.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926880/; classtype:trojan-activity;sid:84789980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926879)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.94.244.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926879/; classtype:trojan-activity;sid:84789979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926875)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.189.177.133"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926875/; classtype:trojan-activity;sid:84789975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926876)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.194.109.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926876/; classtype:trojan-activity;sid:84789976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926877)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.138.109.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926877/; classtype:trojan-activity;sid:84789977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926878)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.229.166.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926878/; classtype:trojan-activity;sid:84789978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926874)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.3.238"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926874/; classtype:trojan-activity;sid:84789974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926872)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.3.238"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926872/; classtype:trojan-activity;sid:84789972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926873)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.146.231.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926873/; classtype:trojan-activity;sid:84789973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926871)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.187.177.77"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926871/; classtype:trojan-activity;sid:84789971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926870)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"14.20.223.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926870/; classtype:trojan-activity;sid:84789970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926868)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.168.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926868/; classtype:trojan-activity;sid:84789968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926869)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.186.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926869/; classtype:trojan-activity;sid:84789969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926867)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.88.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926867/; classtype:trojan-activity;sid:84789967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926866)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.249.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926866/; classtype:trojan-activity;sid:84789966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926865)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.194.109.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926865/; classtype:trojan-activity;sid:84789965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926864)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.144.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926864/; classtype:trojan-activity;sid:84789964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926863)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926863/; classtype:trojan-activity;sid:84789963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926862)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.226.111.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926862/; classtype:trojan-activity;sid:84789962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926861)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.17.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926861/; classtype:trojan-activity;sid:84789961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926860)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.249.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926860/; classtype:trojan-activity;sid:84789960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926858)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.88.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926858/; classtype:trojan-activity;sid:84789958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926859)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.75.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926859/; classtype:trojan-activity;sid:84789959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926857)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926857/; classtype:trojan-activity;sid:84789957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926855)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.36.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926855/; classtype:trojan-activity;sid:84789955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926856)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.89.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926856/; classtype:trojan-activity;sid:84789956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926854)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.145.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926854/; classtype:trojan-activity;sid:84789954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926853)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.86.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926853/; classtype:trojan-activity;sid:84789953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926852)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926852/; classtype:trojan-activity;sid:84789952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926849)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.45.137.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926849/; classtype:trojan-activity;sid:84789949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926850)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.89.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926850/; classtype:trojan-activity;sid:84789950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926851)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.73.23"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926851/; classtype:trojan-activity;sid:84789951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926848)"; flow:established,from_client; content:"GET"; http_method; content:"/s/l3.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"8.216.48.50"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926848/; classtype:trojan-activity;sid:84789948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926847)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.84.197"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926847/; classtype:trojan-activity;sid:84789947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926846)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.69.67"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926846/; classtype:trojan-activity;sid:84789946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926845)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"122.138.231.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926845/; classtype:trojan-activity;sid:84789945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926844)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926844/; classtype:trojan-activity;sid:84789944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926843)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.5.88.205"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926843/; classtype:trojan-activity;sid:84789943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926838)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.23.232"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926838/; classtype:trojan-activity;sid:84789938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926839)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.36.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926839/; classtype:trojan-activity;sid:84789939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926840)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.137.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926840/; classtype:trojan-activity;sid:84789940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926841)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.210.169.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926841/; classtype:trojan-activity;sid:84789941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926842)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.14.56.200"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926842/; classtype:trojan-activity;sid:84789942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926837)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.138.231.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926837/; classtype:trojan-activity;sid:84789937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926834)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.123.209"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926834/; classtype:trojan-activity;sid:84789934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926835)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.137.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926835/; classtype:trojan-activity;sid:84789935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926836)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.0.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926836/; classtype:trojan-activity;sid:84789936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926833)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.206.198.146"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926833/; classtype:trojan-activity;sid:84789933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926830)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.228.124.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926830/; classtype:trojan-activity;sid:84789930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926831)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.157.170"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926831/; classtype:trojan-activity;sid:84789931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926832)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.157.170"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926832/; classtype:trojan-activity;sid:84789932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926829)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.70.98.162"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926829/; classtype:trojan-activity;sid:84789929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926828)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.206.198.146"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926828/; classtype:trojan-activity;sid:84789928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926825)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"153.117.53.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926825/; classtype:trojan-activity;sid:84789925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926826)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.225.202.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926826/; classtype:trojan-activity;sid:84789926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926827)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"108.168.10.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926827/; classtype:trojan-activity;sid:84789927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926824)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.23.2.62"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926824/; classtype:trojan-activity;sid:84789924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926823)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.62.25.225"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926823/; classtype:trojan-activity;sid:84789923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926822)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"108.168.10.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926822/; classtype:trojan-activity;sid:84789922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926821)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.90.151.154"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926821/; classtype:trojan-activity;sid:84789921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926820)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.215.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926820/; classtype:trojan-activity;sid:84789920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926818)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"169.58.68.50"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926818/; classtype:trojan-activity;sid:84789918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926819)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.163.15.89"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926819/; classtype:trojan-activity;sid:84789919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926816)"; flow:established,from_client; content:"GET"; http_method; content:"/bots"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"96.62.71.5"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926816/; classtype:trojan-activity;sid:84789916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926817)"; flow:established,from_client; content:"GET"; http_method; content:"/jireyrsdnf/li"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"103.210.144.11"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926817/; classtype:trojan-activity;sid:84789917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926815)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet2.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926815/; classtype:trojan-activity;sid:84789915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926811)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"79.165.94.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926811/; classtype:trojan-activity;sid:84789911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926812)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.225.78.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926812/; classtype:trojan-activity;sid:84789912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926813)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.237.104.128"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926813/; classtype:trojan-activity;sid:84789913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926814)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.23.232"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926814/; classtype:trojan-activity;sid:84789914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926810)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.225.78.108"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926810/; classtype:trojan-activity;sid:84789910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926809)"; flow:established,from_client; content:"GET"; http_method; content:"/api/file/uncsxkrt"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"pixeldrain.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926809/; classtype:trojan-activity;sid:84789909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926807)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.234.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926807/; classtype:trojan-activity;sid:84789907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926808)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.234.59"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926808/; classtype:trojan-activity;sid:84789908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926806)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.235.44.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926806/; classtype:trojan-activity;sid:84789906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926804)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.223.128.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926804/; classtype:trojan-activity;sid:84789904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926805)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.150.252.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926805/; classtype:trojan-activity;sid:84789905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926802)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.111.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926802/; classtype:trojan-activity;sid:84789902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926803)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.131.92.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926803/; classtype:trojan-activity;sid:84789903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926801)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.36.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926801/; classtype:trojan-activity;sid:84789901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926799)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.84.133.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926799/; classtype:trojan-activity;sid:84789899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926800)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.84.133.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926800/; classtype:trojan-activity;sid:84789900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926798)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.87.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926798/; classtype:trojan-activity;sid:84789898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926796)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.163.187.224"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926796/; classtype:trojan-activity;sid:84789896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926797)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"130.12.209.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926797/; classtype:trojan-activity;sid:84789897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926795)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.143.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926795/; classtype:trojan-activity;sid:84789895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926794)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.101.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926794/; classtype:trojan-activity;sid:84789894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926793)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.240.202.183"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926793/; classtype:trojan-activity;sid:84789893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926792)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.252.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926792/; classtype:trojan-activity;sid:84789892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926791)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.36.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926791/; classtype:trojan-activity;sid:84789891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926790)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.26.150.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926790/; classtype:trojan-activity;sid:84789890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926789)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.87.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926789/; classtype:trojan-activity;sid:84789889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926788)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.245.78.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926788/; classtype:trojan-activity;sid:84789888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926787)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.26.150.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926787/; classtype:trojan-activity;sid:84789887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926786)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.252.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926786/; classtype:trojan-activity;sid:84789886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926785)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.152.53.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926785/; classtype:trojan-activity;sid:84789885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926784)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.226.164"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926784/; classtype:trojan-activity;sid:84789884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926781)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.123.209"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926781/; classtype:trojan-activity;sid:84789881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926782)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.176.107.122"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926782/; classtype:trojan-activity;sid:84789882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926783)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926783/; classtype:trojan-activity;sid:84789883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926780)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.31.103.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926780/; classtype:trojan-activity;sid:84789880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926779)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.160.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926779/; classtype:trojan-activity;sid:84789879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926777)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.245.78.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926777/; classtype:trojan-activity;sid:84789877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926778)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.0.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926778/; classtype:trojan-activity;sid:84789878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926774)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.161.201"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926774/; classtype:trojan-activity;sid:84789874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926775)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.22.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926775/; classtype:trojan-activity;sid:84789875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926776)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.79.85.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926776/; classtype:trojan-activity;sid:84789876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926773)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.92.96.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926773/; classtype:trojan-activity;sid:84789873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926772)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.190.105.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926772/; classtype:trojan-activity;sid:84789872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926771)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.22.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926771/; classtype:trojan-activity;sid:84789871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926770)"; flow:established,from_client; content:"GET"; http_method; content:"/k1gn1jh9t/dihimbs.txt"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"ik.imagekit.io"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926770/; classtype:trojan-activity;sid:84789870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926769)"; flow:established,from_client; content:"GET"; http_method; content:"/networxpro_signed.msi"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"pub-e33c72ad3ac74028914da0187313eeb3.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926769/; classtype:trojan-activity;sid:84789869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926768)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.188.197.62"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926768/; classtype:trojan-activity;sid:84789868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926765)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.176.107.122"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926765/; classtype:trojan-activity;sid:84789865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926766)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.69.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926766/; classtype:trojan-activity;sid:84789866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926767)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.141.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926767/; classtype:trojan-activity;sid:84789867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926763)"; flow:established,from_client; content:"GET"; http_method; content:"/60/img_205615.png"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"107.172.235.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926763/; classtype:trojan-activity;sid:84789863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926764)"; flow:established,from_client; content:"GET"; http_method; content:"/60/wegivenbestthings.js"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"107.172.235.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926764/; classtype:trojan-activity;sid:84789864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926762)"; flow:established,from_client; content:"GET"; http_method; content:"/60/hhn.hta"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"107.172.235.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926762/; classtype:trojan-activity;sid:84789862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926761)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.56.200"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926761/; classtype:trojan-activity;sid:84789861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926760)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/ru/ychromesetup.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"chrome.browserdownloads.ru"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926760/; classtype:trojan-activity;sid:84789860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926759)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig-x64.tar.gz"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"195.178.110.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926759/; classtype:trojan-activity;sid:84789859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926758)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"216.126.86.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926758/; classtype:trojan-activity;sid:84789858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926756)"; flow:established,from_client; content:"GET"; http_method; content:"/|3f|download=1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"polksvo.vercel.app"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926756/; classtype:trojan-activity;sid:84789856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926757)"; flow:established,from_client; content:"GET"; http_method; content:"/|3f|download=1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"pomorutecvo.vercel.app"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926757/; classtype:trojan-activity;sid:84789857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926753)"; flow:established,from_client; content:"GET"; http_method; content:"/bb"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"45.198.224.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926753/; classtype:trojan-activity;sid:84789853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926754)"; flow:established,from_client; content:"GET"; http_method; content:"/dl/1790921720.87bd996efc2584f6/wgadep6p9uoc/nanocore.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"tmpfiles.org"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926754/; classtype:trojan-activity;sid:84789854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926755)"; flow:established,from_client; content:"GET"; http_method; content:"/dl/1790921964.cc1fb986876287ec/w6aney6jruq8/nanocore.js"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"tmpfiles.org"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926755/; classtype:trojan-activity;sid:84789855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926751)"; flow:established,from_client; content:"GET"; http_method; content:"/gh0st148"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"165.22.18.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926751/; classtype:trojan-activity;sid:84789851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926752)"; flow:established,from_client; content:"GET"; http_method; content:"/f/ujkfbdvkl5i2ezacchx7ia/6b4aghms"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"stratos-delta.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926752/; classtype:trojan-activity;sid:84789852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926750)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients/main/goobaclient-1.21.11.jar"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926750/; classtype:trojan-activity;sid:84789850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926747)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients1/main/zyronclient-1.21.11.jar"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926747/; classtype:trojan-activity;sid:84789847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926748)"; flow:established,from_client; content:"GET"; http_method; content:"/a1b2c3"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926748/; classtype:trojan-activity;sid:84789848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926749)"; flow:established,from_client; content:"GET"; http_method; content:"/u4i7o1"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926749/; classtype:trojan-activity;sid:84789849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926746)"; flow:established,from_client; content:"GET"; http_method; content:"/n7m3q6"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926746/; classtype:trojan-activity;sid:84789846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926745)"; flow:established,from_client; content:"GET"; http_method; content:"/r2t5y8"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926745/; classtype:trojan-activity;sid:84789845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926744)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.140.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926744/; classtype:trojan-activity;sid:84789844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926743)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients2/main/67client-1.21.11.jar"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926743/; classtype:trojan-activity;sid:84789843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926740)"; flow:established,from_client; content:"GET"; http_method; content:"/l8z2x5"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926740/; classtype:trojan-activity;sid:84789840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926741)"; flow:established,from_client; content:"GET"; http_method; content:"/q7w8e9"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926741/; classtype:trojan-activity;sid:84789841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926742)"; flow:established,from_client; content:"GET"; http_method; content:"/z8y7w6"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926742/; classtype:trojan-activity;sid:84789842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926738)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients2/main/kryptonclient-1.21.11.jar"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926738/; classtype:trojan-activity;sid:84789838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926739)"; flow:established,from_client; content:"GET"; http_method; content:"/h1j4k7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"downloader.exeexe.workers.dev"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926739/; classtype:trojan-activity;sid:84789839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926737)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients2/main/4eclient-1.21.11.jar"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926737/; classtype:trojan-activity;sid:84789837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926736)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.248.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926736/; classtype:trojan-activity;sid:84789836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926733)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients2/main/radiumclient-1.21.11.jar"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926733/; classtype:trojan-activity;sid:84789833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926734)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients2/main/xenonclient-1.21.11.jar"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926734/; classtype:trojan-activity;sid:84789834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926735)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients2/main/frostclient-1.21.11.jar"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926735/; classtype:trojan-activity;sid:84789835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926732)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients1/main/dqrkisclient-1.21.11.jar"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926732/; classtype:trojan-activity;sid:84789832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926730)"; flow:established,from_client; content:"GET"; http_method; content:"/niehgns/clients/main/fakepayclient-1.21.11.jar"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926730/; classtype:trojan-activity;sid:84789830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926731)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/prestigesetup_pw1337.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"prestige-client.live"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926731/; classtype:trojan-activity;sid:84789831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926724)"; flow:established,from_client; content:"GET"; http_method; content:"/curl/925zai5h/ygpst74xbzykss9mw.dat"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"stratos-delta.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926724/; classtype:trojan-activity;sid:84789824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926725)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.x86"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926725/; classtype:trojan-activity;sid:84789825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926726)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926726/; classtype:trojan-activity;sid:84789826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926727)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.i686"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926727/; classtype:trojan-activity;sid:84789827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926728)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.x86_64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926728/; classtype:trojan-activity;sid:84789828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926729)"; flow:established,from_client; content:"GET"; http_method; content:"/1.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926729/; classtype:trojan-activity;sid:84789829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926723)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_90d99a8ae6973888.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926723/; classtype:trojan-activity;sid:84789823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926721)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.221.96.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926721/; classtype:trojan-activity;sid:84789821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926722)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.141.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926722/; classtype:trojan-activity;sid:84789822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926718)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.141.105.132"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926718/; classtype:trojan-activity;sid:84789818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926719)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.209.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926719/; classtype:trojan-activity;sid:84789819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926720)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.212.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926720/; classtype:trojan-activity;sid:84789820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926717)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.69.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926717/; classtype:trojan-activity;sid:84789817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926716)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.76.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926716/; classtype:trojan-activity;sid:84789816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926715)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.242.90"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926715/; classtype:trojan-activity;sid:84789815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926714)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.11.180.251"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926714/; classtype:trojan-activity;sid:84789814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926710)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.229.223.43"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926710/; classtype:trojan-activity;sid:84789810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926711)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.185.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926711/; classtype:trojan-activity;sid:84789811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926712)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.56.204.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926712/; classtype:trojan-activity;sid:84789812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926713)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.179.88.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926713/; classtype:trojan-activity;sid:84789813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926708)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.ppc"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926708/; classtype:trojan-activity;sid:84789808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926709)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm7"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926709/; classtype:trojan-activity;sid:84789809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926703)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm5"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926703/; classtype:trojan-activity;sid:84789803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926704)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.sh4"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926704/; classtype:trojan-activity;sid:84789804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926705)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926705/; classtype:trojan-activity;sid:84789805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926706)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mips"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926706/; classtype:trojan-activity;sid:84789806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926707)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.arm"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926707/; classtype:trojan-activity;sid:84789807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926700)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.sparc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926700/; classtype:trojan-activity;sid:84789800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926701)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mips64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926701/; classtype:trojan-activity;sid:84789801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926702)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.mpsl"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926702/; classtype:trojan-activity;sid:84789802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926699)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/space.m68k"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"185.213.240.64"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926699/; classtype:trojan-activity;sid:84789799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926697)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.97.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926697/; classtype:trojan-activity;sid:84789797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926698)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.59.79.119"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926698/; classtype:trojan-activity;sid:84789798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926696)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.77.229.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926696/; classtype:trojan-activity;sid:84789796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926695)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.145.247"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926695/; classtype:trojan-activity;sid:84789795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926694)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.228.123.114"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926694/; classtype:trojan-activity;sid:84789794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926691)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.33.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926691/; classtype:trojan-activity;sid:84789791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926692)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.120.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926692/; classtype:trojan-activity;sid:84789792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926693)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.5.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926693/; classtype:trojan-activity;sid:84789793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926690)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.4.254.241"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926690/; classtype:trojan-activity;sid:84789790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926688)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.131.92.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926688/; classtype:trojan-activity;sid:84789788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926689)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.63.135"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926689/; classtype:trojan-activity;sid:84789789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926686)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.7.28"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926686/; classtype:trojan-activity;sid:84789786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926687)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.97.100.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926687/; classtype:trojan-activity;sid:84789787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926685)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.122.242.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926685/; classtype:trojan-activity;sid:84789785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926684)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.122.110.235"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926684/; classtype:trojan-activity;sid:84789784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926683)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.46.196.22"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926683/; classtype:trojan-activity;sid:84789783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926682)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.37.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926682/; classtype:trojan-activity;sid:84789782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926681)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.92.96.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926681/; classtype:trojan-activity;sid:84789781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926677)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.119.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926677/; classtype:trojan-activity;sid:84789777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926678)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.141.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926678/; classtype:trojan-activity;sid:84789778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926679)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.86.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926679/; classtype:trojan-activity;sid:84789779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926680)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.189.141.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926680/; classtype:trojan-activity;sid:84789780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926674)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.105.132"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926674/; classtype:trojan-activity;sid:84789774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926675)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.126.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926675/; classtype:trojan-activity;sid:84789775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926676)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.126.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926676/; classtype:trojan-activity;sid:84789776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926673)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.58.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926673/; classtype:trojan-activity;sid:84789773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926672)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.61.103.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926672/; classtype:trojan-activity;sid:84789772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926669)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.45.137.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926669/; classtype:trojan-activity;sid:84789769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926670)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.237.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926670/; classtype:trojan-activity;sid:84789770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926671)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.200.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926671/; classtype:trojan-activity;sid:84789771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926668)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.156.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926668/; classtype:trojan-activity;sid:84789768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926667)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.77.46.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926667/; classtype:trojan-activity;sid:84789767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926666)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.233.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926666/; classtype:trojan-activity;sid:84789766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926662)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.107.62"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926662/; classtype:trojan-activity;sid:84789762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926663)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.86.54.109"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926663/; classtype:trojan-activity;sid:84789763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926664)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"1.61.216.113"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926664/; classtype:trojan-activity;sid:84789764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926665)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.112.31.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926665/; classtype:trojan-activity;sid:84789765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926661)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.69.82.105"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926661/; classtype:trojan-activity;sid:84789761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926660)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.77.46.141"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926660/; classtype:trojan-activity;sid:84789760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926656)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.225.107.62"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926656/; classtype:trojan-activity;sid:84789756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926657)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.99.164.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926657/; classtype:trojan-activity;sid:84789757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926658)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.253.88"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926658/; classtype:trojan-activity;sid:84789758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926659)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.24.163.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926659/; classtype:trojan-activity;sid:84789759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926654)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.53.34.254"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926654/; classtype:trojan-activity;sid:84789754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926655)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.44.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926655/; classtype:trojan-activity;sid:84789755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926653)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.254.55"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926653/; classtype:trojan-activity;sid:84789753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926652)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.120.93.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926652/; classtype:trojan-activity;sid:84789752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926650)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.77.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926650/; classtype:trojan-activity;sid:84789750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926651)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.210.169.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926651/; classtype:trojan-activity;sid:84789751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926649)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"31.4.254.241"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926649/; classtype:trojan-activity;sid:84789749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926645)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.232.72.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926645/; classtype:trojan-activity;sid:84789745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926646)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.90.151.154"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926646/; classtype:trojan-activity;sid:84789746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926647)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.185.241.237"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926647/; classtype:trojan-activity;sid:84789747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926648)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.214.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926648/; classtype:trojan-activity;sid:84789748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926644)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.35.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926644/; classtype:trojan-activity;sid:84789744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.97.73"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926643/; classtype:trojan-activity;sid:84789743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926642)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.235.7.1"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926642/; classtype:trojan-activity;sid:84789742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926641)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.23.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926641/; classtype:trojan-activity;sid:84789741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926640)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.231.116.128"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926640/; classtype:trojan-activity;sid:84789740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926639)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.180.169.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926639/; classtype:trojan-activity;sid:84789739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926638)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.42.202.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926638/; classtype:trojan-activity;sid:84789738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926637)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"2.182.177.208"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926637/; classtype:trojan-activity;sid:84789737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926635)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.197.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926635/; classtype:trojan-activity;sid:84789735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926636)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"38.48.60.100"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926636/; classtype:trojan-activity;sid:84789736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926634)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.84.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926634/; classtype:trojan-activity;sid:84789734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"110.136.40.247"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926633/; classtype:trojan-activity;sid:84789733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926632)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.172"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926632/; classtype:trojan-activity;sid:84789732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926631)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.120.174.73"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926631/; classtype:trojan-activity;sid:84789731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926630)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.235.7.1"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926630/; classtype:trojan-activity;sid:84789730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926629)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.26.225.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926629/; classtype:trojan-activity;sid:84789729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926628)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.109.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926628/; classtype:trojan-activity;sid:84789728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926623)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"93.157.253.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926623/; classtype:trojan-activity;sid:84789723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926624)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.9.139.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926624/; classtype:trojan-activity;sid:84789724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926625)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.157.253.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926625/; classtype:trojan-activity;sid:84789725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926626)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.198.173"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926626/; classtype:trojan-activity;sid:84789726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926627)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.225.202.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926627/; classtype:trojan-activity;sid:84789727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926622)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.221.46.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926622/; classtype:trojan-activity;sid:84789722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926619)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.198.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926619/; classtype:trojan-activity;sid:84789719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926620)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.14.183.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926620/; classtype:trojan-activity;sid:84789720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926621)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.46.31.127"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926621/; classtype:trojan-activity;sid:84789721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926618)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.49.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926618/; classtype:trojan-activity;sid:84789718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926616)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.150.205.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926616/; classtype:trojan-activity;sid:84789716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926617)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.226.70.133"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926617/; classtype:trojan-activity;sid:84789717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926614)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"38.46.31.127"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926614/; classtype:trojan-activity;sid:84789714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926615)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"138.204.196.254"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926615/; classtype:trojan-activity;sid:84789715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926613)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.53.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926613/; classtype:trojan-activity;sid:84789713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926612)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.180.145.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926612/; classtype:trojan-activity;sid:84789712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926611)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.150.205.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926611/; classtype:trojan-activity;sid:84789711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926610)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.185.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926610/; classtype:trojan-activity;sid:84789710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926609)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926609/; classtype:trojan-activity;sid:84789709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926607)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.225.209"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926607/; classtype:trojan-activity;sid:84789707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926608)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.254.36.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_02; reference:url, urlhaus.abuse.ch/url/3926608/; classtype:trojan-activity;sid:84789708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926606)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.117.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926606/; classtype:trojan-activity;sid:84789706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926605)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.209.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926605/; classtype:trojan-activity;sid:84789705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926604)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.157.233"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926604/; classtype:trojan-activity;sid:84789704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926603)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.242.231.62"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926603/; classtype:trojan-activity;sid:84789703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926602)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.231.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926602/; classtype:trojan-activity;sid:84789702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926599)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.134.110"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926599/; classtype:trojan-activity;sid:84789699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926600)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.122.69.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926600/; classtype:trojan-activity;sid:84789700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926601)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.217.255"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926601/; classtype:trojan-activity;sid:84789701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926598)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.220.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926598/; classtype:trojan-activity;sid:84789698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926595)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.97.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926595/; classtype:trojan-activity;sid:84789695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926596)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.51.115"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926596/; classtype:trojan-activity;sid:84789696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926597)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.144.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926597/; classtype:trojan-activity;sid:84789697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926594)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.194.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926594/; classtype:trojan-activity;sid:84789694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926593)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926593/; classtype:trojan-activity;sid:84789693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926592)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.237.51.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926592/; classtype:trojan-activity;sid:84789692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926591)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.40.20"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926591/; classtype:trojan-activity;sid:84789691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926586)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.153"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926586/; classtype:trojan-activity;sid:84789686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926587)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.157.233"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926587/; classtype:trojan-activity;sid:84789687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926588)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.209.124.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926588/; classtype:trojan-activity;sid:84789688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926589)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.209.124.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926589/; classtype:trojan-activity;sid:84789689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926590)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.122.69.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926590/; classtype:trojan-activity;sid:84789690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926584)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.186.231.117"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926584/; classtype:trojan-activity;sid:84789684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926585)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.242.90"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926585/; classtype:trojan-activity;sid:84789685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926583)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.240.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926583/; classtype:trojan-activity;sid:84789683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926581)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.240.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926581/; classtype:trojan-activity;sid:84789681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926582)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.115.166.198"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926582/; classtype:trojan-activity;sid:84789682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926571)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926571/; classtype:trojan-activity;sid:84789671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926572)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926572/; classtype:trojan-activity;sid:84789672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926573)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926573/; classtype:trojan-activity;sid:84789673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926574)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.spc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926574/; classtype:trojan-activity;sid:84789674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926575)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm6"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926575/; classtype:trojan-activity;sid:84789675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926576)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926576/; classtype:trojan-activity;sid:84789676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926577)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926577/; classtype:trojan-activity;sid:84789677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926578)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926578/; classtype:trojan-activity;sid:84789678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926579)"; flow:established,from_client; content:"GET"; http_method; content:"/systemcl/arc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926579/; classtype:trojan-activity;sid:84789679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926580)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/morte.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.183.174.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926580/; classtype:trojan-activity;sid:84789680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926570)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.149.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926570/; classtype:trojan-activity;sid:84789670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926569)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.207.221.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926569/; classtype:trojan-activity;sid:84789669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926565)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.133.230"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926565/; classtype:trojan-activity;sid:84789665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926566)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926566/; classtype:trojan-activity;sid:84789666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926567)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.28.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926567/; classtype:trojan-activity;sid:84789667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926568)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.5.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926568/; classtype:trojan-activity;sid:84789668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926563)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.138.106.171"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926563/; classtype:trojan-activity;sid:84789663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926564)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.220.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926564/; classtype:trojan-activity;sid:84789664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926557)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926557/; classtype:trojan-activity;sid:84789657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926558)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926558/; classtype:trojan-activity;sid:84789658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926559)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926559/; classtype:trojan-activity;sid:84789659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926560)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.ppc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926560/; classtype:trojan-activity;sid:84789660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926561)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926561/; classtype:trojan-activity;sid:84789661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926562)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926562/; classtype:trojan-activity;sid:84789662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926553)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926553/; classtype:trojan-activity;sid:84789653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926554)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm6"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926554/; classtype:trojan-activity;sid:84789654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926555)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926555/; classtype:trojan-activity;sid:84789655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926556)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/hilix.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.148.112"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926556/; classtype:trojan-activity;sid:84789656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926551)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.135.36.37"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926551/; classtype:trojan-activity;sid:84789651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926552)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.135.36.37"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926552/; classtype:trojan-activity;sid:84789652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926550)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.149.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926550/; classtype:trojan-activity;sid:84789650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926549)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.187.235.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926549/; classtype:trojan-activity;sid:84789649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926542)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.106.171"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926542/; classtype:trojan-activity;sid:84789642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926543)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.35.50.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926543/; classtype:trojan-activity;sid:84789643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926544)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.133.230"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926544/; classtype:trojan-activity;sid:84789644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926545)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.168.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926545/; classtype:trojan-activity;sid:84789645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926546)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.143.179"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926546/; classtype:trojan-activity;sid:84789646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926547)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.17.79.255"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926547/; classtype:trojan-activity;sid:84789647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926548)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.17.79.255"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926548/; classtype:trojan-activity;sid:84789648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926540)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.199.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926540/; classtype:trojan-activity;sid:84789640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926541)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.94.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926541/; classtype:trojan-activity;sid:84789641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926539)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.123.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926539/; classtype:trojan-activity;sid:84789639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926538)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.109.228.110"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926538/; classtype:trojan-activity;sid:84789638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926535)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.91.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926535/; classtype:trojan-activity;sid:84789635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926536)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.203.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926536/; classtype:trojan-activity;sid:84789636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926537)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.182.183"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926537/; classtype:trojan-activity;sid:84789637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926534)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.165.53.128"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926534/; classtype:trojan-activity;sid:84789634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926532)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.252.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926532/; classtype:trojan-activity;sid:84789632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926533)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.165.53.128"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926533/; classtype:trojan-activity;sid:84789633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926529)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.18.1.146"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926529/; classtype:trojan-activity;sid:84789629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926530)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.123.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926530/; classtype:trojan-activity;sid:84789630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926531)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.232.134"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926531/; classtype:trojan-activity;sid:84789631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926528)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.69.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926528/; classtype:trojan-activity;sid:84789628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926526)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.189.177.133"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926526/; classtype:trojan-activity;sid:84789626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926527)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.15.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926527/; classtype:trojan-activity;sid:84789627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926525)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.82.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926525/; classtype:trojan-activity;sid:84789625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926524)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.225.253.118"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926524/; classtype:trojan-activity;sid:84789624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926523)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.237.252.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926523/; classtype:trojan-activity;sid:84789623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926522)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.18.1.146"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926522/; classtype:trojan-activity;sid:84789622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926518)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.44.217.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926518/; classtype:trojan-activity;sid:84789618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926519)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.219.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926519/; classtype:trojan-activity;sid:84789619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926520)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.42.71.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926520/; classtype:trojan-activity;sid:84789620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926521)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.30.91.176"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926521/; classtype:trojan-activity;sid:84789621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926517)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.82.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926517/; classtype:trojan-activity;sid:84789617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926516)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.161.201"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926516/; classtype:trojan-activity;sid:84789616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926515)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.140.208.8"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926515/; classtype:trojan-activity;sid:84789615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926514)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.187.235.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926514/; classtype:trojan-activity;sid:84789614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926512)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.34.53"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926512/; classtype:trojan-activity;sid:84789612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926513)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.120.93.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926513/; classtype:trojan-activity;sid:84789613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926510)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.138.235.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926510/; classtype:trojan-activity;sid:84789610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926511)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.113.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926511/; classtype:trojan-activity;sid:84789611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926508)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.173.85.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926508/; classtype:trojan-activity;sid:84789608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926509)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.44.217.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926509/; classtype:trojan-activity;sid:84789609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926504)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.187.125"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926504/; classtype:trojan-activity;sid:84789604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926505)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.240.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926505/; classtype:trojan-activity;sid:84789605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926506)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.146.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926506/; classtype:trojan-activity;sid:84789606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926507)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"201.110.61.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926507/; classtype:trojan-activity;sid:84789607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926503)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.183.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926503/; classtype:trojan-activity;sid:84789603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926502)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.241.89.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926502/; classtype:trojan-activity;sid:84789602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926501)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.60.252.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926501/; classtype:trojan-activity;sid:84789601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926500)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.4.58"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926500/; classtype:trojan-activity;sid:84789600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926499)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"201.110.61.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926499/; classtype:trojan-activity;sid:84789599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926498)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.240.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926498/; classtype:trojan-activity;sid:84789598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926496)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.222.58"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926496/; classtype:trojan-activity;sid:84789596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926497)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.198.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926497/; classtype:trojan-activity;sid:84789597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926495)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.99.91.121"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926495/; classtype:trojan-activity;sid:84789595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926494)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.18.91.152"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926494/; classtype:trojan-activity;sid:84789594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926490)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.222.58"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926490/; classtype:trojan-activity;sid:84789590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926491)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.136.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926491/; classtype:trojan-activity;sid:84789591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926492)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.143.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926492/; classtype:trojan-activity;sid:84789592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926493)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.136.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926493/; classtype:trojan-activity;sid:84789593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926489)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.70.64.64"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926489/; classtype:trojan-activity;sid:84789589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926486)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.216.70.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926486/; classtype:trojan-activity;sid:84789586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926487)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.216.70.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926487/; classtype:trojan-activity;sid:84789587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926488)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.211.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926488/; classtype:trojan-activity;sid:84789588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926485)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.251.169"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926485/; classtype:trojan-activity;sid:84789585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926484)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.60.252.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926484/; classtype:trojan-activity;sid:84789584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926483)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.159.237"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926483/; classtype:trojan-activity;sid:84789583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926482)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.155"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926482/; classtype:trojan-activity;sid:84789582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926481)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.31.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926481/; classtype:trojan-activity;sid:84789581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926480)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.4.245.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926480/; classtype:trojan-activity;sid:84789580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926479)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.84.197"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926479/; classtype:trojan-activity;sid:84789579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926476)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.47.111.33"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926476/; classtype:trojan-activity;sid:84789576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926477)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.247.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926477/; classtype:trojan-activity;sid:84789577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926478)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.41.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926478/; classtype:trojan-activity;sid:84789578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926475)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.137.217.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926475/; classtype:trojan-activity;sid:84789575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926474)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.120.174.73"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926474/; classtype:trojan-activity;sid:84789574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926473)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.94.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926473/; classtype:trojan-activity;sid:84789573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926471)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.41.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926471/; classtype:trojan-activity;sid:84789571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926472)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.204.48.240"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926472/; classtype:trojan-activity;sid:84789572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926468)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.235.155"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926468/; classtype:trojan-activity;sid:84789568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926469)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.35.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926469/; classtype:trojan-activity;sid:84789569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926470)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.138.235.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926470/; classtype:trojan-activity;sid:84789570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926467)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.94.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926467/; classtype:trojan-activity;sid:84789567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926466)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.31.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926466/; classtype:trojan-activity;sid:84789566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926465)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.224.47.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926465/; classtype:trojan-activity;sid:84789565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926464)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.9.216"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926464/; classtype:trojan-activity;sid:84789564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926463)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.188.65.117"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926463/; classtype:trojan-activity;sid:84789563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926462)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.111.33"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926462/; classtype:trojan-activity;sid:84789562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926461)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.171.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926461/; classtype:trojan-activity;sid:84789561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926460)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.5.9.216"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926460/; classtype:trojan-activity;sid:84789560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926459)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.145.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926459/; classtype:trojan-activity;sid:84789559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926457)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.137.217.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926457/; classtype:trojan-activity;sid:84789557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926458)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.171.99"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926458/; classtype:trojan-activity;sid:84789558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926455)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.94.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926455/; classtype:trojan-activity;sid:84789555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926456)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.118.242.94"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926456/; classtype:trojan-activity;sid:84789556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926454)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.234.207.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926454/; classtype:trojan-activity;sid:84789554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926453)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.70.133"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926453/; classtype:trojan-activity;sid:84789553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926452)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.74.154.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926452/; classtype:trojan-activity;sid:84789552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926451)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.251.163"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926451/; classtype:trojan-activity;sid:84789551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926450)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926450/; classtype:trojan-activity;sid:84789550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926449)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.52.74.62"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926449/; classtype:trojan-activity;sid:84789549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926446)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.83.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926446/; classtype:trojan-activity;sid:84789546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926447)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.71.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926447/; classtype:trojan-activity;sid:84789547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926448)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"138.204.196.254"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926448/; classtype:trojan-activity;sid:84789548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926445)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.187.101.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926445/; classtype:trojan-activity;sid:84789545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926444)"; flow:established,from_client; content:"GET"; http_method; content:"/300/emfpjmk.txt"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"216.9.224.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926444/; classtype:trojan-activity;sid:84789544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926443)"; flow:established,from_client; content:"GET"; http_method; content:"/1.jpg"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"217.60.76.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926443/; classtype:trojan-activity;sid:84789543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926441)"; flow:established,from_client; content:"GET"; http_method; content:"/300/rdidrif.txt"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"216.9.224.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926441/; classtype:trojan-activity;sid:84789541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926442)"; flow:established,from_client; content:"GET"; http_method; content:"/300/hkifmgm.txt"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"216.9.224.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926442/; classtype:trojan-activity;sid:84789542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926440)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.251.163"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926440/; classtype:trojan-activity;sid:84789540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926439)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.109.233.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926439/; classtype:trojan-activity;sid:84789539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926438)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1jxrdmfxhmkbcp62-ynefaebigdmww-xr"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926438/; classtype:trojan-activity;sid:84789538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926437)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.107.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926437/; classtype:trojan-activity;sid:84789537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926436)"; flow:established,from_client; content:"GET"; http_method; content:"/95/img_051422.png"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"204.44.69.243"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926436/; classtype:trojan-activity;sid:84789536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926435)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.177.11.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926435/; classtype:trojan-activity;sid:84789535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926434)"; flow:established,from_client; content:"GET"; http_method; content:"/jbkotwo"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926434/; classtype:trojan-activity;sid:84789534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926432)"; flow:established,from_client; content:"GET"; http_method; content:"/raw/cpvifs"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"tutpaste.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926432/; classtype:trojan-activity;sid:84789532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926433)"; flow:established,from_client; content:"GET"; http_method; content:"/img/1.jpg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"198.23.177.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926433/; classtype:trojan-activity;sid:84789533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926431)"; flow:established,from_client; content:"GET"; http_method; content:"/img/3.jpg2"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"107.172.209.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926431/; classtype:trojan-activity;sid:84789531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926430)"; flow:established,from_client; content:"GET"; http_method; content:"/h"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"144.172.85.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926430/; classtype:trojan-activity;sid:84789530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926429)"; flow:established,from_client; content:"GET"; http_method; content:"/news1/secured_stub.ps1"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"hjha.ao"; http_host; depth:7; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926429/; classtype:trojan-activity;sid:84789529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926428)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.160.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926428/; classtype:trojan-activity;sid:84789528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926425)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.218.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926425/; classtype:trojan-activity;sid:84789525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926426)"; flow:established,from_client; content:"GET"; http_method; content:"/new/secured_stub.ps1"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"hjha.ao"; http_host; depth:7; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926426/; classtype:trojan-activity;sid:84789526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926427)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.158.47"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926427/; classtype:trojan-activity;sid:84789527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926423)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_205551.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926423/; classtype:trojan-activity;sid:84789523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926424)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_210244.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926424/; classtype:trojan-activity;sid:84789524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926422)"; flow:established,from_client; content:"GET"; http_method; content:"/006sk41x"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"maciejbi.hosting24.pl"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926422/; classtype:trojan-activity;sid:84789522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926421)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.252.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926421/; classtype:trojan-activity;sid:84789521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926420)"; flow:established,from_client; content:"GET"; http_method; content:"/e847sl1p"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"maciejbi.hosting24.pl"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926420/; classtype:trojan-activity;sid:84789520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926419)"; flow:established,from_client; content:"GET"; http_method; content:"/img_120657.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"maciejbi.hosting24.pl"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926419/; classtype:trojan-activity;sid:84789519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926417)"; flow:established,from_client; content:"GET"; http_method; content:"/iwouioimn"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926417/; classtype:trojan-activity;sid:84789517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926418)"; flow:established,from_client; content:"GET"; http_method; content:"/king.png"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"pub-ce02802067934e0eb072f69bf6427bf6.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926418/; classtype:trojan-activity;sid:84789518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926415)"; flow:established,from_client; content:"GET"; http_method; content:"/svozdar"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926415/; classtype:trojan-activity;sid:84789515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926416)"; flow:established,from_client; content:"GET"; http_method; content:"/fx2.png"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"pub-ce02802067934e0eb072f69bf6427bf6.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926416/; classtype:trojan-activity;sid:84789516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926414)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.238.160.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926414/; classtype:trojan-activity;sid:84789514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926413)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.143.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926413/; classtype:trojan-activity;sid:84789513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926412)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"144.172.102.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926412/; classtype:trojan-activity;sid:84789512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926411)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"144.172.102.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926411/; classtype:trojan-activity;sid:84789511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926410)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"144.172.108.214"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926410/; classtype:trojan-activity;sid:84789510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926409)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"144.172.108.214"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926409/; classtype:trojan-activity;sid:84789509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926408)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/text/bnguyj1/qbg1plo/ytlfv1i/cc/securedd_stub.ps1"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"www.correa.ind.br"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926408/; classtype:trojan-activity;sid:84789508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926407)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.239.57.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926407/; classtype:trojan-activity;sid:84789507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926405)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.111.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926405/; classtype:trojan-activity;sid:84789505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926406)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.201.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926406/; classtype:trojan-activity;sid:84789506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926404)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.248.33.200"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926404/; classtype:trojan-activity;sid:84789504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926403)"; flow:established,from_client; content:"GET"; http_method; content:"/s.ps1"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"151.242.30.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926403/; classtype:trojan-activity;sid:84789503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926402)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.162.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926402/; classtype:trojan-activity;sid:84789502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926401)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.226.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926401/; classtype:trojan-activity;sid:84789501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926400)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.7.243.36"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926400/; classtype:trojan-activity;sid:84789500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926398)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.203.210.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926398/; classtype:trojan-activity;sid:84789498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926399)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.252.89"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926399/; classtype:trojan-activity;sid:84789499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926397)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.15.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926397/; classtype:trojan-activity;sid:84789497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926396)"; flow:established,from_client; content:"GET"; http_method; content:"/new/secured_stub.ps1"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"87130921-60-20220830152356.webstarterz.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926396/; classtype:trojan-activity;sid:84789496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926394)"; flow:established,from_client; content:"GET"; http_method; content:"/secured_stub.ps1"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"87130921-60-20220830152356.webstarterz.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926394/; classtype:trojan-activity;sid:84789494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926395)"; flow:established,from_client; content:"GET"; http_method; content:"/vic/crypted.ps1"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"87130921-60-20220830152356.webstarterz.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926395/; classtype:trojan-activity;sid:84789495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926393)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.111.36"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926393/; classtype:trojan-activity;sid:84789493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926392)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.162.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926392/; classtype:trojan-activity;sid:84789492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926391)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.216.226.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926391/; classtype:trojan-activity;sid:84789491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926388)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.14.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926388/; classtype:trojan-activity;sid:84789488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926389)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.74.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926389/; classtype:trojan-activity;sid:84789489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926390)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.220.125.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926390/; classtype:trojan-activity;sid:84789490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926387)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.1.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926387/; classtype:trojan-activity;sid:84789487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926386)"; flow:established,from_client; content:"GET"; http_method; content:"/mmmasabikkk/secured_stub.ps1"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"nsci.space"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926386/; classtype:trojan-activity;sid:84789486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926385)"; flow:established,from_client; content:"GET"; http_method; content:"/ppprrrinnccee30/secured_stub.ps1"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926385/; classtype:trojan-activity;sid:84789485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926384)"; flow:established,from_client; content:"GET"; http_method; content:"/prinnce/secured_stub.ps1"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926384/; classtype:trojan-activity;sid:84789484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926383)"; flow:established,from_client; content:"GET"; http_method; content:"/ogaprinncee29/secured_stub.ps1"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926383/; classtype:trojan-activity;sid:84789483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926381)"; flow:established,from_client; content:"GET"; http_method; content:"/mrprinnce28/secured_stub.ps1"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926381/; classtype:trojan-activity;sid:84789481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926382)"; flow:established,from_client; content:"GET"; http_method; content:"/chiefprince/secured_stub.ps1"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926382/; classtype:trojan-activity;sid:84789482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926380)"; flow:established,from_client; content:"GET"; http_method; content:"/prince30/secured_stub.ps1"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926380/; classtype:trojan-activity;sid:84789480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926379)"; flow:established,from_client; content:"GET"; http_method; content:"/prince1/secured_stub.ps1"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"ikechux.publicvm.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926379/; classtype:trojan-activity;sid:84789479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926378)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.167.213.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926378/; classtype:trojan-activity;sid:84789478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926377)"; flow:established,from_client; content:"GET"; http_method; content:"/imgruninc/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"217.217.97.96"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926377/; classtype:trojan-activity;sid:84789477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926376)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"66.212.168.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926376/; classtype:trojan-activity;sid:84789476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926375)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.109.228.110"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926375/; classtype:trojan-activity;sid:84789475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926374)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"92.63.181.175"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926374/; classtype:trojan-activity;sid:84789474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926373)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926373/; classtype:trojan-activity;sid:84789473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926372)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.15.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926372/; classtype:trojan-activity;sid:84789472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926371)"; flow:established,from_client; content:"GET"; http_method; content:"/download_raw/zggkjd3knvdogmmo/java.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"localfiles.live"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926371/; classtype:trojan-activity;sid:84789471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926370)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.185.241.237"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926370/; classtype:trojan-activity;sid:84789470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926367)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.14.212"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926367/; classtype:trojan-activity;sid:84789467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926368)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.1.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926368/; classtype:trojan-activity;sid:84789468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926369)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.108.76.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926369/; classtype:trojan-activity;sid:84789469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926366)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.64.184.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926366/; classtype:trojan-activity;sid:84789466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926365)"; flow:established,from_client; content:"GET"; http_method; content:"/tropvast.vbs"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"pub-fcf9a4a0a9f54d8b8240c682f65e12f9.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926365/; classtype:trojan-activity;sid:84789465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926364)"; flow:established,from_client; content:"GET"; http_method; content:"/ojubam.png"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"pub-a327f9d03def4b07b51dba5303fc3620.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926364/; classtype:trojan-activity;sid:84789464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926363)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.40.180.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926363/; classtype:trojan-activity;sid:84789463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926360)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.160.168"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926360/; classtype:trojan-activity;sid:84789460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926361)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.249.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926361/; classtype:trojan-activity;sid:84789461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926362)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.249.51"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926362/; classtype:trojan-activity;sid:84789462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926359)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.248.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926359/; classtype:trojan-activity;sid:84789459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926358)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.54.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926358/; classtype:trojan-activity;sid:84789458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926355)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926355/; classtype:trojan-activity;sid:84789455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926356)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.arc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926356/; classtype:trojan-activity;sid:84789456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926357)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926357/; classtype:trojan-activity;sid:84789457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926353)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926353/; classtype:trojan-activity;sid:84789453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926354)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926354/; classtype:trojan-activity;sid:84789454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926350)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926350/; classtype:trojan-activity;sid:84789450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926351)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv7l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926351/; classtype:trojan-activity;sid:84789451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926352)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.arc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926352/; classtype:trojan-activity;sid:84789452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926348)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926348/; classtype:trojan-activity;sid:84789448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926349)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926349/; classtype:trojan-activity;sid:84789449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926347)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mipsel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926347/; classtype:trojan-activity;sid:84789447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926346)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.aarch64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926346/; classtype:trojan-activity;sid:84789446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926344)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926344/; classtype:trojan-activity;sid:84789444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926345)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926345/; classtype:trojan-activity;sid:84789445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926343)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926343/; classtype:trojan-activity;sid:84789443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926336)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.mipsel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926336/; classtype:trojan-activity;sid:84789436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926337)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv7l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926337/; classtype:trojan-activity;sid:84789437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926338)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926338/; classtype:trojan-activity;sid:84789438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926339)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv6l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926339/; classtype:trojan-activity;sid:84789439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926340)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.aarch64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926340/; classtype:trojan-activity;sid:84789440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926341)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"217.60.195.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926341/; classtype:trojan-activity;sid:84789441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926342)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/manta.armv6l"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"c2.teamzeroday.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926342/; classtype:trojan-activity;sid:84789442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926335)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.85.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926335/; classtype:trojan-activity;sid:84789435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926334)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.40.180.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926334/; classtype:trojan-activity;sid:84789434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926333)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.140.208.8"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926333/; classtype:trojan-activity;sid:84789433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926332)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.248.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926332/; classtype:trojan-activity;sid:84789432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926331)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse/bin/eclipse.apk"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926331/; classtype:trojan-activity;sid:84789431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926330)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_243e9ba790e9d781.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926330/; classtype:trojan-activity;sid:84789430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926329)"; flow:established,from_client; content:"GET"; http_method; content:"/sh"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"178.16.53.91"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926329/; classtype:trojan-activity;sid:84789429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926328)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.194.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926328/; classtype:trojan-activity;sid:84789428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926327)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.54.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926327/; classtype:trojan-activity;sid:84789427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926326)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.115.160.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926326/; classtype:trojan-activity;sid:84789426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926325)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.54.103.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926325/; classtype:trojan-activity;sid:84789425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926324)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.152.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926324/; classtype:trojan-activity;sid:84789424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926323)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.237.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926323/; classtype:trojan-activity;sid:84789423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926322)"; flow:established,from_client; content:"GET"; http_method; content:"/clip.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"185.166.153.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926322/; classtype:trojan-activity;sid:84789422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926321)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.248.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926321/; classtype:trojan-activity;sid:84789421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926319)"; flow:established,from_client; content:"GET"; http_method; content:"/.smpsl"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926319/; classtype:trojan-activity;sid:84789419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926320)"; flow:established,from_client; content:"GET"; http_method; content:"/.sarm5"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926320/; classtype:trojan-activity;sid:84789420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926311)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.165.235.139"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926311/; classtype:trojan-activity;sid:84789411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926312)"; flow:established,from_client; content:"GET"; http_method; content:"/.sarm7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926312/; classtype:trojan-activity;sid:84789412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926313)"; flow:established,from_client; content:"GET"; http_method; content:"/.sx86_64"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926313/; classtype:trojan-activity;sid:84789413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926314)"; flow:established,from_client; content:"GET"; http_method; content:"/.sm68k"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926314/; classtype:trojan-activity;sid:84789414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926315)"; flow:established,from_client; content:"GET"; http_method; content:"/.smips"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926315/; classtype:trojan-activity;sid:84789415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926316)"; flow:established,from_client; content:"GET"; http_method; content:"/.sx86"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926316/; classtype:trojan-activity;sid:84789416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926317)"; flow:established,from_client; content:"GET"; http_method; content:"/.sppc"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926317/; classtype:trojan-activity;sid:84789417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926318)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926318/; classtype:trojan-activity;sid:84789418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926308)"; flow:established,from_client; content:"GET"; http_method; content:"/.sspc"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926308/; classtype:trojan-activity;sid:84789408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926309)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926309/; classtype:trojan-activity;sid:84789409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926310)"; flow:established,from_client; content:"GET"; http_method; content:"/.sarm6"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926310/; classtype:trojan-activity;sid:84789410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926307)"; flow:established,from_client; content:"GET"; http_method; content:"/.sarm4"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926307/; classtype:trojan-activity;sid:84789407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926306)"; flow:established,from_client; content:"GET"; http_method; content:"/realtek"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926306/; classtype:trojan-activity;sid:84789406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926305)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926305/; classtype:trojan-activity;sid:84789405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926304)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.209.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926304/; classtype:trojan-activity;sid:84789404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926303)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.217.255"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926303/; classtype:trojan-activity;sid:84789403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926300)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.54.144.76"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926300/; classtype:trojan-activity;sid:84789400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926301)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"138.204.196.244"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926301/; classtype:trojan-activity;sid:84789401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926302)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.237.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926302/; classtype:trojan-activity;sid:84789402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926299)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.10.133.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926299/; classtype:trojan-activity;sid:84789399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926298)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"203.202.232.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926298/; classtype:trojan-activity;sid:84789398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926297)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"203.202.232.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926297/; classtype:trojan-activity;sid:84789397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926296)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.185.243.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926296/; classtype:trojan-activity;sid:84789396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926290)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926290/; classtype:trojan-activity;sid:84789390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926291)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm4l"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926291/; classtype:trojan-activity;sid:84789391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926292)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926292/; classtype:trojan-activity;sid:84789392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926293)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926293/; classtype:trojan-activity;sid:84789393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926294)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926294/; classtype:trojan-activity;sid:84789394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926295)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926295/; classtype:trojan-activity;sid:84789395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926286)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.ppc440"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926286/; classtype:trojan-activity;sid:84789386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926287)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm4tl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926287/; classtype:trojan-activity;sid:84789387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926288)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926288/; classtype:trojan-activity;sid:84789388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926289)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926289/; classtype:trojan-activity;sid:84789389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926284)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"89.106.83.205"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926284/; classtype:trojan-activity;sid:84789384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926285)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"89.106.83.205"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926285/; classtype:trojan-activity;sid:84789385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926283)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.85.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926283/; classtype:trojan-activity;sid:84789383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926282)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.139.44.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926282/; classtype:trojan-activity;sid:84789382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926281)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.141.233.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926281/; classtype:trojan-activity;sid:84789381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926280)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"89.106.83.180"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926280/; classtype:trojan-activity;sid:84789380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926279)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"89.106.83.180"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926279/; classtype:trojan-activity;sid:84789379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926277)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"89.106.83.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926277/; classtype:trojan-activity;sid:84789377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926278)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"89.106.83.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926278/; classtype:trojan-activity;sid:84789378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926276)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.42.71.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926276/; classtype:trojan-activity;sid:84789376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926275)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"23.146.242.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926275/; classtype:trojan-activity;sid:84789375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926274)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"23.146.242.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926274/; classtype:trojan-activity;sid:84789374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926272)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.156.102.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926272/; classtype:trojan-activity;sid:84789372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926273)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.171.23"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926273/; classtype:trojan-activity;sid:84789373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926271)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.180.248.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926271/; classtype:trojan-activity;sid:84789371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926270)"; flow:established,from_client; content:"GET"; http_method; content:"/systemd"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"80.94.92.128"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926270/; classtype:trojan-activity;sid:84789370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926269)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.76.206.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926269/; classtype:trojan-activity;sid:84789369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926268)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"23.172.112.215"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926268/; classtype:trojan-activity;sid:84789368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926267)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.10.133.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926267/; classtype:trojan-activity;sid:84789367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926266)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"23.146.242.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926266/; classtype:trojan-activity;sid:84789366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926265)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"23.146.242.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926265/; classtype:trojan-activity;sid:84789365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926264)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.185.243.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926264/; classtype:trojan-activity;sid:84789364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926263)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"45.153.34.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926263/; classtype:trojan-activity;sid:84789363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926261)"; flow:established,from_client; content:"GET"; http_method; content:"/dlr.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.153.34.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926261/; classtype:trojan-activity;sid:84789361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926262)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"45.153.34.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926262/; classtype:trojan-activity;sid:84789362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926259)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"45.153.34.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926259/; classtype:trojan-activity;sid:84789359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926260)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"45.153.34.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926260/; classtype:trojan-activity;sid:84789360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926258)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"45.135.194.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926258/; classtype:trojan-activity;sid:84789358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926257)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"45.135.194.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926257/; classtype:trojan-activity;sid:84789357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926256)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"144.172.118.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926256/; classtype:trojan-activity;sid:84789356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926255)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"144.172.118.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926255/; classtype:trojan-activity;sid:84789355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926254)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"172.86.88.189"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926254/; classtype:trojan-activity;sid:84789354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926253)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"172.86.88.189"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926253/; classtype:trojan-activity;sid:84789353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.5.10"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926249/; classtype:trojan-activity;sid:84789349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926250)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.51.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926250/; classtype:trojan-activity;sid:84789350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926251)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.251.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926251/; classtype:trojan-activity;sid:84789351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926252)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.14.183.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926252/; classtype:trojan-activity;sid:84789352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926248)"; flow:established,from_client; content:"GET"; http_method; content:"/ayakashi2"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"143.20.185.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926248/; classtype:trojan-activity;sid:84789348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926247)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.131.205"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926247/; classtype:trojan-activity;sid:84789347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926246)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926246/; classtype:trojan-activity;sid:84789346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926245)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926245/; classtype:trojan-activity;sid:84789345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926239)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.arm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926239/; classtype:trojan-activity;sid:84789339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926240)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.ppc64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926240/; classtype:trojan-activity;sid:84789340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926241)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926241/; classtype:trojan-activity;sid:84789341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926242)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64le"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926242/; classtype:trojan-activity;sid:84789342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926243)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926243/; classtype:trojan-activity;sid:84789343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926244)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.ppc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926244/; classtype:trojan-activity;sid:84789344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926236)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926236/; classtype:trojan-activity;sid:84789336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926237)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.i686"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926237/; classtype:trojan-activity;sid:84789337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926238)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926238/; classtype:trojan-activity;sid:84789338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926234)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926234/; classtype:trojan-activity;sid:84789334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926235)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926235/; classtype:trojan-activity;sid:84789335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926232)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926232/; classtype:trojan-activity;sid:84789332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926233)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.arm8"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926233/; classtype:trojan-activity;sid:84789333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926222)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926222/; classtype:trojan-activity;sid:84789322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926223)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926223/; classtype:trojan-activity;sid:84789323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926224)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.aarch64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926224/; classtype:trojan-activity;sid:84789324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926225)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926225/; classtype:trojan-activity;sid:84789325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926226)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926226/; classtype:trojan-activity;sid:84789326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926227)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926227/; classtype:trojan-activity;sid:84789327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926228)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926228/; classtype:trojan-activity;sid:84789328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926229)"; flow:established,from_client; content:"GET"; http_method; content:"/pid.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926229/; classtype:trojan-activity;sid:84789329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926230)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926230/; classtype:trojan-activity;sid:84789330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926231)"; flow:established,from_client; content:"GET"; http_method; content:"/cnc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926231/; classtype:trojan-activity;sid:84789331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926221)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926221/; classtype:trojan-activity;sid:84789321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926219)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv5l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926219/; classtype:trojan-activity;sid:84789319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926220)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926220/; classtype:trojan-activity;sid:84789320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926213)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.powerpc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926213/; classtype:trojan-activity;sid:84789313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926214)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv7l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926214/; classtype:trojan-activity;sid:84789314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926215)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv4l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926215/; classtype:trojan-activity;sid:84789315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926216)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926216/; classtype:trojan-activity;sid:84789316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926217)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926217/; classtype:trojan-activity;sid:84789317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926218)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv6l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926218/; classtype:trojan-activity;sid:84789318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926212)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sparc"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926212/; classtype:trojan-activity;sid:84789312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926210)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.i586"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926210/; classtype:trojan-activity;sid:84789310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926211)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.i486"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926211/; classtype:trojan-activity;sid:84789311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926204)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.armv7l"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926204/; classtype:trojan-activity;sid:84789304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926205)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926205/; classtype:trojan-activity;sid:84789305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926206)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926206/; classtype:trojan-activity;sid:84789306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926207)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926207/; classtype:trojan-activity;sid:84789307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926208)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.arc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926208/; classtype:trojan-activity;sid:84789308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926209)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv6l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926209/; classtype:trojan-activity;sid:84789309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926203)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.mipsrouter"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.154.43.201"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926203/; classtype:trojan-activity;sid:84789303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926202)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mipsel"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926202/; classtype:trojan-activity;sid:84789302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926201)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926201/; classtype:trojan-activity;sid:84789301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926198)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926198/; classtype:trojan-activity;sid:84789298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926199)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv4l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926199/; classtype:trojan-activity;sid:84789299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926200)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926200/; classtype:trojan-activity;sid:84789300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926194)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.powerpc"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926194/; classtype:trojan-activity;sid:84789294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926195)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.armv5l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926195/; classtype:trojan-activity;sid:84789295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926196)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926196/; classtype:trojan-activity;sid:84789296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926197)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.i686"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926197/; classtype:trojan-activity;sid:84789297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926193)"; flow:established,from_client; content:"GET"; http_method; content:"/eclipse.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.154.43.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926193/; classtype:trojan-activity;sid:84789293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926192)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.206.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926192/; classtype:trojan-activity;sid:84789292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926191)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.237.51.216"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926191/; classtype:trojan-activity;sid:84789291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.58.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926190/; classtype:trojan-activity;sid:84789290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926187)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926187/; classtype:trojan-activity;sid:84789287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926188)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926188/; classtype:trojan-activity;sid:84789288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926189)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsle"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926189/; classtype:trojan-activity;sid:84789289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926186)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926186/; classtype:trojan-activity;sid:84789286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926185)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926185/; classtype:trojan-activity;sid:84789285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926173)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926173/; classtype:trojan-activity;sid:84789273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926174)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926174/; classtype:trojan-activity;sid:84789274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926175)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926175/; classtype:trojan-activity;sid:84789275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926176)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926176/; classtype:trojan-activity;sid:84789276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926177)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926177/; classtype:trojan-activity;sid:84789277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926178)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926178/; classtype:trojan-activity;sid:84789278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926179)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926179/; classtype:trojan-activity;sid:84789279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926180)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926180/; classtype:trojan-activity;sid:84789280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926181)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926181/; classtype:trojan-activity;sid:84789281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926182)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926182/; classtype:trojan-activity;sid:84789282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926183)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926183/; classtype:trojan-activity;sid:84789283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926184)"; flow:established,from_client; content:"GET"; http_method; content:"/hiddenbin/mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926184/; classtype:trojan-activity;sid:84789284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926171)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926171/; classtype:trojan-activity;sid:84789271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926172)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsle"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926172/; classtype:trojan-activity;sid:84789272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926170)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926170/; classtype:trojan-activity;sid:84789270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926168)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926168/; classtype:trojan-activity;sid:84789268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926169)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926169/; classtype:trojan-activity;sid:84789269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926162)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926162/; classtype:trojan-activity;sid:84789262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926163)"; flow:established,from_client; content:"GET"; http_method; content:"/arm64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926163/; classtype:trojan-activity;sid:84789263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926164)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926164/; classtype:trojan-activity;sid:84789264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926165)"; flow:established,from_client; content:"GET"; http_method; content:"/amd64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926165/; classtype:trojan-activity;sid:84789265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926166)"; flow:established,from_client; content:"GET"; http_method; content:"/i386"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926166/; classtype:trojan-activity;sid:84789266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926167)"; flow:established,from_client; content:"GET"; http_method; content:"/android_arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926167/; classtype:trojan-activity;sid:84789267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926161)"; flow:established,from_client; content:"GET"; http_method; content:"/bins.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926161/; classtype:trojan-activity;sid:84789261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926160)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"94.154.43.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926160/; classtype:trojan-activity;sid:84789260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926158)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.180.248.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926158/; classtype:trojan-activity;sid:84789258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926159)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.31.228.93"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926159/; classtype:trojan-activity;sid:84789259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926157)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.96.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926157/; classtype:trojan-activity;sid:84789257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926156)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.219.48"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926156/; classtype:trojan-activity;sid:84789256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926152)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.239.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926152/; classtype:trojan-activity;sid:84789252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926153)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.232.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926153/; classtype:trojan-activity;sid:84789253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926154)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.87.194.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926154/; classtype:trojan-activity;sid:84789254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926155)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.223.128.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926155/; classtype:trojan-activity;sid:84789255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926151)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.156.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926151/; classtype:trojan-activity;sid:84789251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926150)"; flow:established,from_client; content:"GET"; http_method; content:"/0x/cls"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.218.183.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926150/; classtype:trojan-activity;sid:84789250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926149)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/586400531312934913/1555171552734085201/bundle.zip|3f|ex=6abf8ddf|7c|26|7c|is=6abe3c5f|7c|26|7c|hm=1af2de5aa606082d72d65a9b2146d14d8cc379d2ba66a1527da0638e01fb992f|7c|26|7c|"; http_uri; depth:185; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926149/; classtype:trojan-activity;sid:84789249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926148)"; flow:established,from_client; content:"GET"; http_method; content:"/x64"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"5.189.165.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926148/; classtype:trojan-activity;sid:84789248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926146)"; flow:established,from_client; content:"GET"; http_method; content:"/0x/js"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"91.218.183.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926146/; classtype:trojan-activity;sid:84789246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926147)"; flow:established,from_client; content:"GET"; http_method; content:"/0x/ls"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"91.218.183.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926147/; classtype:trojan-activity;sid:84789247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926145)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.198.173"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926145/; classtype:trojan-activity;sid:84789245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926143)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.179.88.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926143/; classtype:trojan-activity;sid:84789243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926144)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.162.25.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926144/; classtype:trojan-activity;sid:84789244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926142)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"124.95.22.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926142/; classtype:trojan-activity;sid:84789242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926141)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.236.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926141/; classtype:trojan-activity;sid:84789241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926140)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.3.11"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926140/; classtype:trojan-activity;sid:84789240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926139)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.234.206.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926139/; classtype:trojan-activity;sid:84789239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926138)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.87.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926138/; classtype:trojan-activity;sid:84789238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926137)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.57.39.28"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926137/; classtype:trojan-activity;sid:84789237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926136)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"99.39.251.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926136/; classtype:trojan-activity;sid:84789236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926134)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.247.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926134/; classtype:trojan-activity;sid:84789234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926135)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.236.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926135/; classtype:trojan-activity;sid:84789235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926133)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.156.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926133/; classtype:trojan-activity;sid:84789233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926131)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.50.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926131/; classtype:trojan-activity;sid:84789231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926132)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.138.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926132/; classtype:trojan-activity;sid:84789232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926129)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.97.200.35"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926129/; classtype:trojan-activity;sid:84789229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926130)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.102.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926130/; classtype:trojan-activity;sid:84789230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926128)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.246.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926128/; classtype:trojan-activity;sid:84789228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926127)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"122.241.89.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926127/; classtype:trojan-activity;sid:84789227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926126)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.91.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926126/; classtype:trojan-activity;sid:84789226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926125)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.58.115.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926125/; classtype:trojan-activity;sid:84789225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926123)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.235.102.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926123/; classtype:trojan-activity;sid:84789223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926124)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.245.143"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926124/; classtype:trojan-activity;sid:84789224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926119)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.7.221.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926119/; classtype:trojan-activity;sid:84789219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926120)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.34.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926120/; classtype:trojan-activity;sid:84789220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926121)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.246.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926121/; classtype:trojan-activity;sid:84789221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926122)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.76.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926122/; classtype:trojan-activity;sid:84789222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926118)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.47.34.4"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926118/; classtype:trojan-activity;sid:84789218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926117)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.7.221.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926117/; classtype:trojan-activity;sid:84789217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926113)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.177.162.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926113/; classtype:trojan-activity;sid:84789213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926114)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.177.162.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926114/; classtype:trojan-activity;sid:84789214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926115)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.140.54"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926115/; classtype:trojan-activity;sid:84789215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926116)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.3.11"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926116/; classtype:trojan-activity;sid:84789216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926112)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.104.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926112/; classtype:trojan-activity;sid:84789212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926110)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"110.136.40.247"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926110/; classtype:trojan-activity;sid:84789210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926111)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.76.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926111/; classtype:trojan-activity;sid:84789211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926109)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.112.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926109/; classtype:trojan-activity;sid:84789209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926106)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.122.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926106/; classtype:trojan-activity;sid:84789206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926107)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.7.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926107/; classtype:trojan-activity;sid:84789207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926108)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.175.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926108/; classtype:trojan-activity;sid:84789208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926105)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.206.4.6"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926105/; classtype:trojan-activity;sid:84789205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926104)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.233.94.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926104/; classtype:trojan-activity;sid:84789204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926103)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.191.233.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926103/; classtype:trojan-activity;sid:84789203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926102)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.194.101.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926102/; classtype:trojan-activity;sid:84789202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926101)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.249.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926101/; classtype:trojan-activity;sid:84789201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926099)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.21.120.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926099/; classtype:trojan-activity;sid:84789199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926100)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.242.128.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926100/; classtype:trojan-activity;sid:84789200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926097)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.49.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926097/; classtype:trojan-activity;sid:84789197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926098)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.63.112.133"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926098/; classtype:trojan-activity;sid:84789198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926096)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.159.237"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926096/; classtype:trojan-activity;sid:84789196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926095)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.26.86.216"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926095/; classtype:trojan-activity;sid:84789195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926094)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.105.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926094/; classtype:trojan-activity;sid:84789194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926093)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"82.54.132.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926093/; classtype:trojan-activity;sid:84789193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926091)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.232.157"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926091/; classtype:trojan-activity;sid:84789191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926092)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.21.120.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926092/; classtype:trojan-activity;sid:84789192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926090)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.78.93.213"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926090/; classtype:trojan-activity;sid:84789190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926088)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.78.41.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926088/; classtype:trojan-activity;sid:84789188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926089)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.78.41.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926089/; classtype:trojan-activity;sid:84789189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926087)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.87.194.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926087/; classtype:trojan-activity;sid:84789187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926086)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.124.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926086/; classtype:trojan-activity;sid:84789186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926085)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926085/; classtype:trojan-activity;sid:84789185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926083)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.41.3.210"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926083/; classtype:trojan-activity;sid:84789183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926081)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/4f77-bdc8-7e8087412ccf/refs/heads/main/8f16-efc0e3092243"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926081/; classtype:trojan-activity;sid:84789181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926082)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/4f77-bdc8-7e8087412ccf/refs/heads/main/464cf7ac-29d9-4a5a-a7c0"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926082/; classtype:trojan-activity;sid:84789182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926080)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.41.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926080/; classtype:trojan-activity;sid:84789180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926079)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.49.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926079/; classtype:trojan-activity;sid:84789179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926078)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.88.136.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926078/; classtype:trojan-activity;sid:84789178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926077)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"82.54.132.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926077/; classtype:trojan-activity;sid:84789177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926076)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.47.104.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926076/; classtype:trojan-activity;sid:84789176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926072)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.118.253"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926072/; classtype:trojan-activity;sid:84789172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926073)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.60.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926073/; classtype:trojan-activity;sid:84789173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926074)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.14.32.129"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926074/; classtype:trojan-activity;sid:84789174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926075)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.49.40.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926075/; classtype:trojan-activity;sid:84789175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926070)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.52.75.211"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926070/; classtype:trojan-activity;sid:84789170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926071)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.52.75.211"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926071/; classtype:trojan-activity;sid:84789171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926069)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.255.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926069/; classtype:trojan-activity;sid:84789169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926068)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.234.100.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926068/; classtype:trojan-activity;sid:84789168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926067)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.37.230.39"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926067/; classtype:trojan-activity;sid:84789167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926066)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.59.34.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926066/; classtype:trojan-activity;sid:84789166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926065)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.188.110"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926065/; classtype:trojan-activity;sid:84789165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926062)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.237.40.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926062/; classtype:trojan-activity;sid:84789162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926063)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.190.22.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926063/; classtype:trojan-activity;sid:84789163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926064)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.255.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926064/; classtype:trojan-activity;sid:84789164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926058)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.216.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926058/; classtype:trojan-activity;sid:84789158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926059)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.229.188.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926059/; classtype:trojan-activity;sid:84789159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926060)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.32.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926060/; classtype:trojan-activity;sid:84789160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926061)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.40.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926061/; classtype:trojan-activity;sid:84789161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926056)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.61.118.253"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926056/; classtype:trojan-activity;sid:84789156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926057)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.204.247.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926057/; classtype:trojan-activity;sid:84789157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926054)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.17.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926054/; classtype:trojan-activity;sid:84789154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926055)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.121.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926055/; classtype:trojan-activity;sid:84789155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926053)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.183.97.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926053/; classtype:trojan-activity;sid:84789153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926052)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"47.212.193.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926052/; classtype:trojan-activity;sid:84789152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926051)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.118.242.94"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926051/; classtype:trojan-activity;sid:84789151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926050)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.246.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926050/; classtype:trojan-activity;sid:84789150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926049)"; flow:established,from_client; content:"GET"; http_method; content:"/135/images_95858005050050.jpg.hta"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"192.3.47.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926049/; classtype:trojan-activity;sid:84789149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926046)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.23.2.62"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926046/; classtype:trojan-activity;sid:84789146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926047)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.101.8"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926047/; classtype:trojan-activity;sid:84789147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926048)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.170.251"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926048/; classtype:trojan-activity;sid:84789148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926045)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.89.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926045/; classtype:trojan-activity;sid:84789145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926044)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.18.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926044/; classtype:trojan-activity;sid:84789144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926043)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_6911193341ae26d7.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926043/; classtype:trojan-activity;sid:84789143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926041)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.175.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926041/; classtype:trojan-activity;sid:84789141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926042)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"219.157.246.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926042/; classtype:trojan-activity;sid:84789142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926038)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.191.233.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926038/; classtype:trojan-activity;sid:84789138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926039)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.72.77.178"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926039/; classtype:trojan-activity;sid:84789139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926040)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.10.44.157"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926040/; classtype:trojan-activity;sid:84789140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926036)"; flow:established,from_client; content:"GET"; http_method; content:"/utros.bin"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926036/; classtype:trojan-activity;sid:84789136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926037)"; flow:established,from_client; content:"GET"; http_method; content:"/tr.bin"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926037/; classtype:trojan-activity;sid:84789137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926035)"; flow:established,from_client; content:"GET"; http_method; content:"/one.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926035/; classtype:trojan-activity;sid:84789135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926034)"; flow:established,from_client; content:"GET"; http_method; content:"/irzfcxiywhew.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926034/; classtype:trojan-activity;sid:84789134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926032)"; flow:established,from_client; content:"GET"; http_method; content:"/kisa.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926032/; classtype:trojan-activity;sid:84789132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926033)"; flow:established,from_client; content:"GET"; http_method; content:"/two.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926033/; classtype:trojan-activity;sid:84789133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926028)"; flow:established,from_client; content:"GET"; http_method; content:"/pip.bin"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926028/; classtype:trojan-activity;sid:84789128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926029)"; flow:established,from_client; content:"GET"; http_method; content:"/optimal.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926029/; classtype:trojan-activity;sid:84789129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926030)"; flow:established,from_client; content:"GET"; http_method; content:"/ufrop.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926030/; classtype:trojan-activity;sid:84789130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926031)"; flow:established,from_client; content:"GET"; http_method; content:"/kis.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926031/; classtype:trojan-activity;sid:84789131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926027)"; flow:established,from_client; content:"GET"; http_method; content:"/horos.bin"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"185.166.155.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926027/; classtype:trojan-activity;sid:84789127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926026)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/payload.sh"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926026/; classtype:trojan-activity;sid:84789126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926025)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.55.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926025/; classtype:trojan-activity;sid:84789125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926024)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.212.119"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926024/; classtype:trojan-activity;sid:84789124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926022)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/dbg"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926022/; classtype:trojan-activity;sid:84789122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926023)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.89.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926023/; classtype:trojan-activity;sid:84789123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926021)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.13.136.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926021/; classtype:trojan-activity;sid:84789121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926008)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926008/; classtype:trojan-activity;sid:84789108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926009)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926009/; classtype:trojan-activity;sid:84789109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926010)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926010/; classtype:trojan-activity;sid:84789110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926011)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926011/; classtype:trojan-activity;sid:84789111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926012)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926012/; classtype:trojan-activity;sid:84789112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926013)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926013/; classtype:trojan-activity;sid:84789113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926014)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926014/; classtype:trojan-activity;sid:84789114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926015)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926015/; classtype:trojan-activity;sid:84789115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926016)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926016/; classtype:trojan-activity;sid:84789116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926017)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926017/; classtype:trojan-activity;sid:84789117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926018)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926018/; classtype:trojan-activity;sid:84789118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926019)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926019/; classtype:trojan-activity;sid:84789119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926020)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"222.255.181.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926020/; classtype:trojan-activity;sid:84789120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926006)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1qjzmdgn-w0yyagdj6zcd7jczqdtaokb3"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926006/; classtype:trojan-activity;sid:84789106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926007)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ckccpck-lcaki1lgz0tnj5yynsi6ubla"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926007/; classtype:trojan-activity;sid:84789107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926004)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.149.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926004/; classtype:trojan-activity;sid:84789104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926005)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.93.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926005/; classtype:trojan-activity;sid:84789105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926003)"; flow:established,from_client; content:"GET"; http_method; content:"/302/token.cmd"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"84.200.33.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926003/; classtype:trojan-activity;sid:84789103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926002)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_f374c4d0079d076f.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926002/; classtype:trojan-activity;sid:84789102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926001)"; flow:established,from_client; content:"GET"; http_method; content:"/setup/downloads/ext1/chromesetup.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"chrome.windows-browser.net"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926001/; classtype:trojan-activity;sid:84789101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925999)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-arm64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925999/; classtype:trojan-activity;sid:84789099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3926000)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-darwin-amd64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3926000/; classtype:trojan-activity;sid:84789100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925998)"; flow:established,from_client; content:"GET"; http_method; content:"/dimdikoldu/salla/releases/download/31/31.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925998/; classtype:trojan-activity;sid:84789098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925997)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.59.233.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925997/; classtype:trojan-activity;sid:84789097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925996)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.196.7.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925996/; classtype:trojan-activity;sid:84789096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925995)"; flow:established,from_client; content:"GET"; http_method; content:"/board/config"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"api-willserver.phonkstyle-workers.workers.dev"; http_host; depth:45; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925995/; classtype:trojan-activity;sid:84789095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925988)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-windows-386.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925988/; classtype:trojan-activity;sid:84789088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925989)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925989/; classtype:trojan-activity;sid:84789089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925990)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-linux-386"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925990/; classtype:trojan-activity;sid:84789090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925991)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-freebsd-amd64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925991/; classtype:trojan-activity;sid:84789091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925992)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-openbsd-amd64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925992/; classtype:trojan-activity;sid:84789092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925993)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-darwin-arm64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925993/; classtype:trojan-activity;sid:84789093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925994)"; flow:established,from_client; content:"GET"; http_method; content:"/bot-windows-amd64.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"94.154.43.26"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925994/; classtype:trojan-activity;sid:84789094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925987)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"85.192.48.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925987/; classtype:trojan-activity;sid:84789087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925986)"; flow:established,from_client; content:"GET"; http_method; content:"/loader/agent/a75137e5a3f45aacaa1ed5259e81ad8dcbcc0c1b767d8fc46dc42d2ef548b449"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"sandiegomobiletire.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925986/; classtype:trojan-activity;sid:84789086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925985)"; flow:established,from_client; content:"GET"; http_method; content:"/backdoor.sh"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.207.157.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925985/; classtype:trojan-activity;sid:84789085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925984)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_24ed2cf4c7e68a80.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925984/; classtype:trojan-activity;sid:84789084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925983)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1324384206050168936/1554961466518409328/bundle.zip|3f|ex=6abeca37|7c|26|7c|is=6abd78b7|7c|26|7c|hm=8d91bb35ae9f64d4d217282123810c09034c8ff617046c19d9cf678781b3a9c5|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925983/; classtype:trojan-activity;sid:84789083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925982)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.239.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925982/; classtype:trojan-activity;sid:84789082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925981)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.218.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925981/; classtype:trojan-activity;sid:84789081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925980)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.95.22.94"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925980/; classtype:trojan-activity;sid:84789080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925978)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.93.26.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925978/; classtype:trojan-activity;sid:84789078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925979)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.124.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925979/; classtype:trojan-activity;sid:84789079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925977)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.192.252.187"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925977/; classtype:trojan-activity;sid:84789077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925976)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.137.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925976/; classtype:trojan-activity;sid:84789076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925975)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.242.128.210"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925975/; classtype:trojan-activity;sid:84789075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925974)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.149.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925974/; classtype:trojan-activity;sid:84789074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925973)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.215.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925973/; classtype:trojan-activity;sid:84789073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925972)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.208.110.147"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925972/; classtype:trojan-activity;sid:84789072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925969)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.111.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925969/; classtype:trojan-activity;sid:84789069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925970)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.93.26.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925970/; classtype:trojan-activity;sid:84789070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925971)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.18.91.152"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925971/; classtype:trojan-activity;sid:84789071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925967)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.242.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925967/; classtype:trojan-activity;sid:84789067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925968)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.82.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925968/; classtype:trojan-activity;sid:84789068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925966)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.11.203.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925966/; classtype:trojan-activity;sid:84789066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925965)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.34.59.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925965/; classtype:trojan-activity;sid:84789065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925964)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.154.221"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925964/; classtype:trojan-activity;sid:84789064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925963)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.242.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925963/; classtype:trojan-activity;sid:84789063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925961)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"206.130.211.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925961/; classtype:trojan-activity;sid:84789061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925962)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"47.212.193.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925962/; classtype:trojan-activity;sid:84789062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925960)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"92.34.131.196"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925960/; classtype:trojan-activity;sid:84789060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925959)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.22.174.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925959/; classtype:trojan-activity;sid:84789059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925957)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.95.150"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925957/; classtype:trojan-activity;sid:84789057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925958)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.174.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925958/; classtype:trojan-activity;sid:84789058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925956)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.68.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925956/; classtype:trojan-activity;sid:84789056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925955)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"206.130.211.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925955/; classtype:trojan-activity;sid:84789055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925952)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.68.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925952/; classtype:trojan-activity;sid:84789052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925953)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.107.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925953/; classtype:trojan-activity;sid:84789053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925954)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.90.79"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925954/; classtype:trojan-activity;sid:84789054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925951)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.109.233.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925951/; classtype:trojan-activity;sid:84789051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925950)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.244.36.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925950/; classtype:trojan-activity;sid:84789050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925949)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.140.87.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925949/; classtype:trojan-activity;sid:84789049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925948)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"92.34.131.196"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925948/; classtype:trojan-activity;sid:84789048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925947)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.233.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925947/; classtype:trojan-activity;sid:84789047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925946)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.85.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925946/; classtype:trojan-activity;sid:84789046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925945)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.216.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925945/; classtype:trojan-activity;sid:84789045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925944)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.120.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925944/; classtype:trojan-activity;sid:84789044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925943)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"49.64.226.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925943/; classtype:trojan-activity;sid:84789043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925942)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.6.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925942/; classtype:trojan-activity;sid:84789042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925939)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.66.68.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925939/; classtype:trojan-activity;sid:84789039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925940)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.113.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925940/; classtype:trojan-activity;sid:84789040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925941)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.244.36.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925941/; classtype:trojan-activity;sid:84789041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925937)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.54.193.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925937/; classtype:trojan-activity;sid:84789037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925938)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.215.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925938/; classtype:trojan-activity;sid:84789038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925936)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.85.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925936/; classtype:trojan-activity;sid:84789036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925934)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925934/; classtype:trojan-activity;sid:84789034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925935)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925935/; classtype:trojan-activity;sid:84789035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925933)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.162.176"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925933/; classtype:trojan-activity;sid:84789033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925932)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.169.11"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925932/; classtype:trojan-activity;sid:84789032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925931)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.96.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925931/; classtype:trojan-activity;sid:84789031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925930)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.152.53.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925930/; classtype:trojan-activity;sid:84789030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925928)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.58.201.172"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925928/; classtype:trojan-activity;sid:84789028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925929)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.203.230.103"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925929/; classtype:trojan-activity;sid:84789029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925925)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.61.7.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925925/; classtype:trojan-activity;sid:84789025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925926)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"177.36.24.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925926/; classtype:trojan-activity;sid:84789026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925927)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.202.71.58"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925927/; classtype:trojan-activity;sid:84789027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925924)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.41.3.210"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925924/; classtype:trojan-activity;sid:84789024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925923)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.202.71.58"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925923/; classtype:trojan-activity;sid:84789023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925922)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.51.120.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925922/; classtype:trojan-activity;sid:84789022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925920)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.152.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925920/; classtype:trojan-activity;sid:84789020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925921)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.233.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925921/; classtype:trojan-activity;sid:84789021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925919)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.96.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925919/; classtype:trojan-activity;sid:84789019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925918)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.154.97.145"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925918/; classtype:trojan-activity;sid:84789018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925917)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"2.187.249.41"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925917/; classtype:trojan-activity;sid:84789017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925916)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.38.200.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925916/; classtype:trojan-activity;sid:84789016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925914)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.31.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925914/; classtype:trojan-activity;sid:84789014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925915)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.104.52"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925915/; classtype:trojan-activity;sid:84789015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925913)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.56.152.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925913/; classtype:trojan-activity;sid:84789013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925912)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.35.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925912/; classtype:trojan-activity;sid:84789012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925911)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.54.103.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925911/; classtype:trojan-activity;sid:84789011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925910)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.58.86.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925910/; classtype:trojan-activity;sid:84789010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925909)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.226.31.30"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925909/; classtype:trojan-activity;sid:84789009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925908)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.193.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925908/; classtype:trojan-activity;sid:84789008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925905)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.246.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925905/; classtype:trojan-activity;sid:84789005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925906)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.35.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925906/; classtype:trojan-activity;sid:84789006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925907)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.192.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925907/; classtype:trojan-activity;sid:84789007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925903)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.202.215.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925903/; classtype:trojan-activity;sid:84789003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925904)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.31.201.20"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925904/; classtype:trojan-activity;sid:84789004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925902)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.91.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925902/; classtype:trojan-activity;sid:84789002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925898)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.5.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925898/; classtype:trojan-activity;sid:84788998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925899)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.207.187.125"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925899/; classtype:trojan-activity;sid:84788999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925900)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.146.157.50"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925900/; classtype:trojan-activity;sid:84789000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925901)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.58.86.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925901/; classtype:trojan-activity;sid:84789001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925897)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.127.243.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925897/; classtype:trojan-activity;sid:84788997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925895)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.227.52.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925895/; classtype:trojan-activity;sid:84788995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925896)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.52.233.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925896/; classtype:trojan-activity;sid:84788996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925894)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"164.163.25.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925894/; classtype:trojan-activity;sid:84788994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925893)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.104.52"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925893/; classtype:trojan-activity;sid:84788993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925892)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.227.52.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925892/; classtype:trojan-activity;sid:84788992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925890)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.113.7.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925890/; classtype:trojan-activity;sid:84788990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925891)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.138.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925891/; classtype:trojan-activity;sid:84788991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925887)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.81.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925887/; classtype:trojan-activity;sid:84788987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925888)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.174.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925888/; classtype:trojan-activity;sid:84788988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925889)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.121.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925889/; classtype:trojan-activity;sid:84788989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925886)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.31.201.20"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925886/; classtype:trojan-activity;sid:84788986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925885)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.226.5.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925885/; classtype:trojan-activity;sid:84788985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925883)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.110.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925883/; classtype:trojan-activity;sid:84788983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925884)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.98.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925884/; classtype:trojan-activity;sid:84788984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925882)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.20.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925882/; classtype:trojan-activity;sid:84788982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925881)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"106.58.110.228"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925881/; classtype:trojan-activity;sid:84788981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925880)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.174.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925880/; classtype:trojan-activity;sid:84788980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925879)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.37.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925879/; classtype:trojan-activity;sid:84788979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925878)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.95.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925878/; classtype:trojan-activity;sid:84788978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925877)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.95.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925877/; classtype:trojan-activity;sid:84788977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925875)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.236.44.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925875/; classtype:trojan-activity;sid:84788975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925876)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.73.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925876/; classtype:trojan-activity;sid:84788976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925871)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.121.73.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925871/; classtype:trojan-activity;sid:84788971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925872)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.190.63"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925872/; classtype:trojan-activity;sid:84788972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925873)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.81.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925873/; classtype:trojan-activity;sid:84788973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925874)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.231.110.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925874/; classtype:trojan-activity;sid:84788974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925870)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.43.253"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925870/; classtype:trojan-activity;sid:84788970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925869)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.242.164.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925869/; classtype:trojan-activity;sid:84788969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925868)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.43.253"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925868/; classtype:trojan-activity;sid:84788968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925867)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.20.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925867/; classtype:trojan-activity;sid:84788967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925866)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.97.172.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_10_01; reference:url, urlhaus.abuse.ch/url/3925866/; classtype:trojan-activity;sid:84788966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925865)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.40.239.39"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925865/; classtype:trojan-activity;sid:84788965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925864)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.34.209.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925864/; classtype:trojan-activity;sid:84788964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925860)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.35.136.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925860/; classtype:trojan-activity;sid:84788960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925861)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.156.102.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925861/; classtype:trojan-activity;sid:84788961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925862)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.79.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925862/; classtype:trojan-activity;sid:84788962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925863)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.79.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925863/; classtype:trojan-activity;sid:84788963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925856)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.226.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925856/; classtype:trojan-activity;sid:84788956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925857)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.246.109.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925857/; classtype:trojan-activity;sid:84788957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925858)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.69.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925858/; classtype:trojan-activity;sid:84788958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925859)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.201.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925859/; classtype:trojan-activity;sid:84788959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925855)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.207.241.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925855/; classtype:trojan-activity;sid:84788955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925854)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.57.221.116"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925854/; classtype:trojan-activity;sid:84788954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925852)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.157.17.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925852/; classtype:trojan-activity;sid:84788952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925853)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.149.89.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925853/; classtype:trojan-activity;sid:84788953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925849)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.10.68.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925849/; classtype:trojan-activity;sid:84788949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925850)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.169.11"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925850/; classtype:trojan-activity;sid:84788950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925851)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.152.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925851/; classtype:trojan-activity;sid:84788951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925845)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.43.39.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925845/; classtype:trojan-activity;sid:84788945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925846)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.117.171.16"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925846/; classtype:trojan-activity;sid:84788946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925847)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.180.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925847/; classtype:trojan-activity;sid:84788947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925848)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.207.241.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925848/; classtype:trojan-activity;sid:84788948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925844)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.246.109.105"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925844/; classtype:trojan-activity;sid:84788944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925843)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.139.47.38"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925843/; classtype:trojan-activity;sid:84788943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925841)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.5.144.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925841/; classtype:trojan-activity;sid:84788941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925842)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.226.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925842/; classtype:trojan-activity;sid:84788942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925840)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.193.159.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925840/; classtype:trojan-activity;sid:84788940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925839)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.173.117.164"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925839/; classtype:trojan-activity;sid:84788939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925838)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.248.41.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925838/; classtype:trojan-activity;sid:84788938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925837)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.43.39.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925837/; classtype:trojan-activity;sid:84788937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925834)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.113.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925834/; classtype:trojan-activity;sid:84788934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925835)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.225.14.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925835/; classtype:trojan-activity;sid:84788935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925836)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.103.116.83"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925836/; classtype:trojan-activity;sid:84788936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925833)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.68.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925833/; classtype:trojan-activity;sid:84788933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925832)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.193.159.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925832/; classtype:trojan-activity;sid:84788932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925831)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.7.28"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925831/; classtype:trojan-activity;sid:84788931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925830)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.219.74.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925830/; classtype:trojan-activity;sid:84788930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925829)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.5.144.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925829/; classtype:trojan-activity;sid:84788929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925827)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.248.190.63"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925827/; classtype:trojan-activity;sid:84788927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925828)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.65.51.208"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925828/; classtype:trojan-activity;sid:84788928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925826)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.31.103.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925826/; classtype:trojan-activity;sid:84788926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925824)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.161.32"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925824/; classtype:trojan-activity;sid:84788924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925825)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.233.61"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925825/; classtype:trojan-activity;sid:84788925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925822)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.166.165.60"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925822/; classtype:trojan-activity;sid:84788922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925823)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.28.150.164"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925823/; classtype:trojan-activity;sid:84788923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925821)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.65.51.208"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925821/; classtype:trojan-activity;sid:84788921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925820)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.190.22.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925820/; classtype:trojan-activity;sid:84788920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925818)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.63.84.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925818/; classtype:trojan-activity;sid:84788918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925819)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.23.75.238"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925819/; classtype:trojan-activity;sid:84788919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925816)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.204.247.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925816/; classtype:trojan-activity;sid:84788916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925817)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925817/; classtype:trojan-activity;sid:84788917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925815)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.188.196.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925815/; classtype:trojan-activity;sid:84788915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925813)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.12.221.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925813/; classtype:trojan-activity;sid:84788913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925814)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.238.161.32"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925814/; classtype:trojan-activity;sid:84788914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925812)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.31.103.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925812/; classtype:trojan-activity;sid:84788912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925811)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.48.60.100"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925811/; classtype:trojan-activity;sid:84788911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925810)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.178.95.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925810/; classtype:trojan-activity;sid:84788910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925809)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.28.150.164"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925809/; classtype:trojan-activity;sid:84788909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925807)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.238.123.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925807/; classtype:trojan-activity;sid:84788907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925808)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.34.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925808/; classtype:trojan-activity;sid:84788908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925803)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.87.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925803/; classtype:trojan-activity;sid:84788903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925804)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.23.75.238"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925804/; classtype:trojan-activity;sid:84788904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925805)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.10.60"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925805/; classtype:trojan-activity;sid:84788905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925806)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.12.221.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925806/; classtype:trojan-activity;sid:84788906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925800)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.120.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925800/; classtype:trojan-activity;sid:84788900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925801)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.229.188.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925801/; classtype:trojan-activity;sid:84788901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925802)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"101.108.73.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925802/; classtype:trojan-activity;sid:84788902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925799)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.32.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925799/; classtype:trojan-activity;sid:84788899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925796)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.238.89"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925796/; classtype:trojan-activity;sid:84788896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925797)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.11.203.243"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925797/; classtype:trojan-activity;sid:84788897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925798)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.117.34.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925798/; classtype:trojan-activity;sid:84788898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925793)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.238.123.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925793/; classtype:trojan-activity;sid:84788893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925794)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.245.99.52"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925794/; classtype:trojan-activity;sid:84788894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925795)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"140.237.48.248"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925795/; classtype:trojan-activity;sid:84788895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925791)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.54.163.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925791/; classtype:trojan-activity;sid:84788891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925792)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.217.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925792/; classtype:trojan-activity;sid:84788892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925790)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.213.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925790/; classtype:trojan-activity;sid:84788890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925789)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925789/; classtype:trojan-activity;sid:84788889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925788)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.37.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925788/; classtype:trojan-activity;sid:84788888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925787)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"140.237.48.248"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925787/; classtype:trojan-activity;sid:84788887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925786)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.213.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925786/; classtype:trojan-activity;sid:84788886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925784)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.150.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925784/; classtype:trojan-activity;sid:84788884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925785)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.124.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925785/; classtype:trojan-activity;sid:84788885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925783)"; flow:established,from_client; content:"GET"; http_method; content:"/files/unique3/file.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925783/; classtype:trojan-activity;sid:84788883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925782)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.63.145.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925782/; classtype:trojan-activity;sid:84788882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925781)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"14.20.219.99"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925781/; classtype:trojan-activity;sid:84788881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925778)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"213.66.68.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925778/; classtype:trojan-activity;sid:84788878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925779)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"196.189.132.118"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925779/; classtype:trojan-activity;sid:84788879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925780)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.46.236"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925780/; classtype:trojan-activity;sid:84788880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925777)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_edc0660605671232.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925777/; classtype:trojan-activity;sid:84788877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925776)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.148.152.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925776/; classtype:trojan-activity;sid:84788876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925775)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.150.233"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925775/; classtype:trojan-activity;sid:84788875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925774)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.124.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925774/; classtype:trojan-activity;sid:84788874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925772)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"158.255.83.202"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925772/; classtype:trojan-activity;sid:84788872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925773)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.141.233.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925773/; classtype:trojan-activity;sid:84788873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925770)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.136.137.73"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925770/; classtype:trojan-activity;sid:84788870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925771)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.148.152.102"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925771/; classtype:trojan-activity;sid:84788871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925768)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.52.46.236"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925768/; classtype:trojan-activity;sid:84788868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925769)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.5.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925769/; classtype:trojan-activity;sid:84788869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925764)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.249.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925764/; classtype:trojan-activity;sid:84788864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925765)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.132.118"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925765/; classtype:trojan-activity;sid:84788865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925766)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"164.163.25.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925766/; classtype:trojan-activity;sid:84788866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925767)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.238.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925767/; classtype:trojan-activity;sid:84788867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925763)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.227.197.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925763/; classtype:trojan-activity;sid:84788863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925762)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.202.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925762/; classtype:trojan-activity;sid:84788862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925760)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.196.7.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925760/; classtype:trojan-activity;sid:84788860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925761)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.4.245.79"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925761/; classtype:trojan-activity;sid:84788861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925759)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.202.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925759/; classtype:trojan-activity;sid:84788859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925758)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_bae9b21b2e4258e0.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925758/; classtype:trojan-activity;sid:84788858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925757)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.82.137.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925757/; classtype:trojan-activity;sid:84788857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925756)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_69ace516b9d1b58b.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925756/; classtype:trojan-activity;sid:84788856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925755)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.223.140.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925755/; classtype:trojan-activity;sid:84788855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925754)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.55.249.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925754/; classtype:trojan-activity;sid:84788854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925750)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.60.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925750/; classtype:trojan-activity;sid:84788850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925751)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.73.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925751/; classtype:trojan-activity;sid:84788851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925752)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"170.238.123.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925752/; classtype:trojan-activity;sid:84788852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925753)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.149.89.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925753/; classtype:trojan-activity;sid:84788853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925748)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.89.156.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925748/; classtype:trojan-activity;sid:84788848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925749)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.136.137.73"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925749/; classtype:trojan-activity;sid:84788849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925747)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.227.197.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925747/; classtype:trojan-activity;sid:84788847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925746)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.108.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925746/; classtype:trojan-activity;sid:84788846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925744)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.108.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925744/; classtype:trojan-activity;sid:84788844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925745)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.235.73.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925745/; classtype:trojan-activity;sid:84788845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925742)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"2.187.250.85"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925742/; classtype:trojan-activity;sid:84788842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925743)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.237.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925743/; classtype:trojan-activity;sid:84788843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925741)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.82.137.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925741/; classtype:trojan-activity;sid:84788841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925733)"; flow:established,from_client; content:"GET"; http_method; content:"/s-h.4-.snoopy"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925733/; classtype:trojan-activity;sid:84788833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925734)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925734/; classtype:trojan-activity;sid:84788834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925735)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsrouter"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925735/; classtype:trojan-activity;sid:84788835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925736)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925736/; classtype:trojan-activity;sid:84788836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925737)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925737/; classtype:trojan-activity;sid:84788837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925738)"; flow:established,from_client; content:"GET"; http_method; content:"/m-p.s-l.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925738/; classtype:trojan-activity;sid:84788838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925739)"; flow:established,from_client; content:"GET"; http_method; content:"/m-i.p-s.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925739/; classtype:trojan-activity;sid:84788839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925740)"; flow:established,from_client; content:"GET"; http_method; content:"/i-5.8-6.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925740/; classtype:trojan-activity;sid:84788840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925731)"; flow:established,from_client; content:"GET"; http_method; content:"/a-r.m-4.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925731/; classtype:trojan-activity;sid:84788831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925732)"; flow:established,from_client; content:"GET"; http_method; content:"/a-r.m-7.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925732/; classtype:trojan-activity;sid:84788832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925730)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.22.42.143"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925730/; classtype:trojan-activity;sid:84788830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925727)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.89.156.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925727/; classtype:trojan-activity;sid:84788827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925728)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.174.75.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925728/; classtype:trojan-activity;sid:84788828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925729)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.12.91"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925729/; classtype:trojan-activity;sid:84788829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925726)"; flow:established,from_client; content:"GET"; http_method; content:"/p-p.c-.snoopy"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925726/; classtype:trojan-activity;sid:84788826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925721)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925721/; classtype:trojan-activity;sid:84788821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925722)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925722/; classtype:trojan-activity;sid:84788822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925723)"; flow:established,from_client; content:"GET"; http_method; content:"/a-r.m-5.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925723/; classtype:trojan-activity;sid:84788823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925724)"; flow:established,from_client; content:"GET"; http_method; content:"/x-3.2-.snoopy"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925724/; classtype:trojan-activity;sid:84788824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925725)"; flow:established,from_client; content:"GET"; http_method; content:"/m-6.8-k.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925725/; classtype:trojan-activity;sid:84788825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925715)"; flow:established,from_client; content:"GET"; http_method; content:"/a-r.m-6.snoopy"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925715/; classtype:trojan-activity;sid:84788815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925716)"; flow:established,from_client; content:"GET"; http_method; content:"/x-8.6-.snoopy"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925716/; classtype:trojan-activity;sid:84788816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925717)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925717/; classtype:trojan-activity;sid:84788817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925718)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925718/; classtype:trojan-activity;sid:84788818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925719)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925719/; classtype:trojan-activity;sid:84788819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925720)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925720/; classtype:trojan-activity;sid:84788820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925714)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925714/; classtype:trojan-activity;sid:84788814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925713)"; flow:established,from_client; content:"GET"; http_method; content:"/302/parser.js"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"84.200.33.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925713/; classtype:trojan-activity;sid:84788813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925712)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.12.91"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925712/; classtype:trojan-activity;sid:84788812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925698)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.23.237.113"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925698/; classtype:trojan-activity;sid:84788798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925699)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.7.17"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925699/; classtype:trojan-activity;sid:84788799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925700)"; flow:established,from_client; content:"GET"; http_method; content:"/302/302m"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"84.200.33.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925700/; classtype:trojan-activity;sid:84788800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925701)"; flow:established,from_client; content:"GET"; http_method; content:"/302/302l"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"84.200.33.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925701/; classtype:trojan-activity;sid:84788801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925702)"; flow:established,from_client; content:"GET"; http_method; content:"/hggseiqwekf.sh"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925702/; classtype:trojan-activity;sid:84788802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925703)"; flow:established,from_client; content:"GET"; http_method; content:"/snoopy.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.151"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925703/; classtype:trojan-activity;sid:84788803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925704)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.160.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925704/; classtype:trojan-activity;sid:84788804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925705)"; flow:established,from_client; content:"GET"; http_method; content:"/ldb/36/346"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925705/; classtype:trojan-activity;sid:84788805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925706)"; flow:established,from_client; content:"GET"; http_method; content:"/payl/36/346"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925706/; classtype:trojan-activity;sid:84788806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925707)"; flow:established,from_client; content:"GET"; http_method; content:"/brow/36/346"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925707/; classtype:trojan-activity;sid:84788807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925708)"; flow:established,from_client; content:"GET"; http_method; content:"/payload/36/346"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925708/; classtype:trojan-activity;sid:84788808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925709)"; flow:established,from_client; content:"GET"; http_method; content:"/client/36/346"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925709/; classtype:trojan-activity;sid:84788809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925710)"; flow:established,from_client; content:"GET"; http_method; content:"/ncli/36/346"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925710/; classtype:trojan-activity;sid:84788810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925711)"; flow:established,from_client; content:"GET"; http_method; content:"/main"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"104.234.94.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925711/; classtype:trojan-activity;sid:84788811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925697)"; flow:established,from_client; content:"GET"; http_method; content:"//var/www/html/001010101010010110101011101010101101010111010101//nwfaiehg4ewijfgriehgirehaughrarg.arm7"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925697/; classtype:trojan-activity;sid:84788797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925696)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1554855040743637152/1554855122318917662/bundle.zip|3f|ex=6abe672c|7c|26|7c|is=6abd15ac|7c|26|7c|hm=e0315179fd41a764fc0d8db53b89341f9dc7baf3459d7ea0d50701003455f887|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925696/; classtype:trojan-activity;sid:84788796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925695)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.74.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925695/; classtype:trojan-activity;sid:84788795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925694)"; flow:established,from_client; content:"GET"; http_method; content:"/302/tokenlinux.sh"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"84.200.33.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925694/; classtype:trojan-activity;sid:84788794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925693)"; flow:established,from_client; content:"GET"; http_method; content:"/302/302w"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"84.200.33.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925693/; classtype:trojan-activity;sid:84788793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925692)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/e6efd8bd3bf0fae2_moratorium_0.96.2.9_install.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"193.178.158.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925692/; classtype:trojan-activity;sid:84788792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925691)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/d39b2eac249e8c65_build_x64.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925691/; classtype:trojan-activity;sid:84788791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925690)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.174.75.29"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925690/; classtype:trojan-activity;sid:84788790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925689)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.241.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925689/; classtype:trojan-activity;sid:84788789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925687)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.239.243.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925687/; classtype:trojan-activity;sid:84788787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925688)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.51.60.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925688/; classtype:trojan-activity;sid:84788788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925686)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/0a844b9203ac2602_bot_x64.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"193.178.158.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925686/; classtype:trojan-activity;sid:84788786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925685)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.248.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925685/; classtype:trojan-activity;sid:84788785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925684)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.56.204.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925684/; classtype:trojan-activity;sid:84788784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925683)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.146.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925683/; classtype:trojan-activity;sid:84788783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925682)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.181.231"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925682/; classtype:trojan-activity;sid:84788782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925681)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.141.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925681/; classtype:trojan-activity;sid:84788781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925680)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.237.40.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925680/; classtype:trojan-activity;sid:84788780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925679)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.141.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925679/; classtype:trojan-activity;sid:84788779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925676)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.44.137.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925676/; classtype:trojan-activity;sid:84788776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925677)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.69.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925677/; classtype:trojan-activity;sid:84788777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925678)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.47.231.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925678/; classtype:trojan-activity;sid:84788778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925675)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.13.136.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925675/; classtype:trojan-activity;sid:84788775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925674)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.166.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925674/; classtype:trojan-activity;sid:84788774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925673)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.55.16.121"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925673/; classtype:trojan-activity;sid:84788773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925670)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.62.178.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925670/; classtype:trojan-activity;sid:84788770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925671)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.83.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925671/; classtype:trojan-activity;sid:84788771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925672)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.228.144.97"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925672/; classtype:trojan-activity;sid:84788772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925669)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.192.252.187"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925669/; classtype:trojan-activity;sid:84788769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925668)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.80.60.21"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925668/; classtype:trojan-activity;sid:84788768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925667)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"121.231.77.1"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925667/; classtype:trojan-activity;sid:84788767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925666)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.205.145.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925666/; classtype:trojan-activity;sid:84788766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925665)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.195.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925665/; classtype:trojan-activity;sid:84788765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925664)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1554902011189796984/1554902119771934871/bundle.zip|3f|ex=6abe92f2|7c|26|7c|is=6abd4172|7c|26|7c|hm=efeef3756683c9e9a5cb09a4fd335e4af64111e4a046bd1706f14484befbda73|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925664/; classtype:trojan-activity;sid:84788764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925663)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"101.132.83.252"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925663/; classtype:trojan-activity;sid:84788763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925661)"; flow:established,from_client; content:"GET"; http_method; content:"/pokelauncher.zip"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"pokegard.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925661/; classtype:trojan-activity;sid:84788761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925662)"; flow:established,from_client; content:"GET"; http_method; content:"/pokegardmodpack.zip"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"pokegard.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925662/; classtype:trojan-activity;sid:84788762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925660)"; flow:established,from_client; content:"GET"; http_method; content:"/scl/fi/x9gnmtm9tfxtgeo35p8pc/input.jar|3f|rlkey=6mu0iic48blnbtwsp757xucq0|7c|26|7c|st=ei9tukhs|7c|26|7c|dl=1"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925660/; classtype:trojan-activity;sid:84788760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925658)"; flow:established,from_client; content:"GET"; http_method; content:"/iran.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925658/; classtype:trojan-activity;sid:84788758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925659)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_d259ea289eb720b7.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925659/; classtype:trojan-activity;sid:84788759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925657)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.166"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925657/; classtype:trojan-activity;sid:84788757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925656)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.16.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925656/; classtype:trojan-activity;sid:84788756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925655)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"163.142.93.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925655/; classtype:trojan-activity;sid:84788755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925653)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.93.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925653/; classtype:trojan-activity;sid:84788753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925654)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.52.156.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925654/; classtype:trojan-activity;sid:84788754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925652)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.126.212.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925652/; classtype:trojan-activity;sid:84788752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925651)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.127.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925651/; classtype:trojan-activity;sid:84788751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925650)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.218.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925650/; classtype:trojan-activity;sid:84788750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925649)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.221.8.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925649/; classtype:trojan-activity;sid:84788749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925647)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.139.124.58"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925647/; classtype:trojan-activity;sid:84788747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925648)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.99.43"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925648/; classtype:trojan-activity;sid:84788748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925646)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.195.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925646/; classtype:trojan-activity;sid:84788746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925645)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.35.133.136"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925645/; classtype:trojan-activity;sid:84788745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925643)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.63.153.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925643/; classtype:trojan-activity;sid:84788743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925644)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.93.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925644/; classtype:trojan-activity;sid:84788744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925641)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.65.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925641/; classtype:trojan-activity;sid:84788741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925642)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.94.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925642/; classtype:trojan-activity;sid:84788742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925640)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.7.17"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925640/; classtype:trojan-activity;sid:84788740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925639)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.127.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925639/; classtype:trojan-activity;sid:84788739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925638)"; flow:established,from_client; content:"GET"; http_method; content:"/vendor/twilio/sdk/src/twilio/rest/chat/v2/img_060144.png"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"app.ezmarketz.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925638/; classtype:trojan-activity;sid:84788738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925637)"; flow:established,from_client; content:"GET"; http_method; content:"/img_061858.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"update-acrobatdc.shop"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925637/; classtype:trojan-activity;sid:84788737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925636)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"125.40.94.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925636/; classtype:trojan-activity;sid:84788736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925635)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.139.124.58"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925635/; classtype:trojan-activity;sid:84788735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925634)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.178.95.27"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925634/; classtype:trojan-activity;sid:84788734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"121.202.142.137"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925633/; classtype:trojan-activity;sid:84788733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925632)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.51.60.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925632/; classtype:trojan-activity;sid:84788732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925629)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"82.208.107.90"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925629/; classtype:trojan-activity;sid:84788729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925630)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"111.88.7.48"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925630/; classtype:trojan-activity;sid:84788730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925631)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.191.16.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925631/; classtype:trojan-activity;sid:84788731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925627)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925627/; classtype:trojan-activity;sid:84788727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925628)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.214.93"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925628/; classtype:trojan-activity;sid:84788728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925623)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.16.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925623/; classtype:trojan-activity;sid:84788723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925624)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.214.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925624/; classtype:trojan-activity;sid:84788724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925625)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.226.5.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925625/; classtype:trojan-activity;sid:84788725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925626)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.226.5.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925626/; classtype:trojan-activity;sid:84788726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925622)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.28.193.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925622/; classtype:trojan-activity;sid:84788722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925621)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.73.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925621/; classtype:trojan-activity;sid:84788721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925618)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.179.240.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925618/; classtype:trojan-activity;sid:84788718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925619)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.238.228.103"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925619/; classtype:trojan-activity;sid:84788719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925620)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.193.132.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925620/; classtype:trojan-activity;sid:84788720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925617)"; flow:established,from_client; content:"GET"; http_method; content:"/serhat961/pruva-download/releases/download/v2.0.31/pruvaagent-2.0.31.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925617/; classtype:trojan-activity;sid:84788717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925616)"; flow:established,from_client; content:"GET"; http_method; content:"/download.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"playuno.me"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925616/; classtype:trojan-activity;sid:84788716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925615)"; flow:established,from_client; content:"GET"; http_method; content:"/nzee/secured_stub.ps1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"nze.work.gd"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925615/; classtype:trojan-activity;sid:84788715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925614)"; flow:established,from_client; content:"GET"; http_method; content:"/news/secured_stub.ps1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"hjha.ao"; http_host; depth:7; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925614/; classtype:trojan-activity;sid:84788714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925613)"; flow:established,from_client; content:"GET"; http_method; content:"/lufivl08"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"johnsonsvalves.cam"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925613/; classtype:trojan-activity;sid:84788713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925612)"; flow:established,from_client; content:"GET"; http_method; content:"/vi1xwsm/trbhoun/wzyergu/nn/crypted.ps1"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"sqpengg.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925612/; classtype:trojan-activity;sid:84788712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925611)"; flow:established,from_client; content:"GET"; http_method; content:"/vi1xwsm/trbhoun/wzyergu/vvv/crypted.ps1"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"sqpengg.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925611/; classtype:trojan-activity;sid:84788711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925610)"; flow:established,from_client; content:"GET"; http_method; content:"/vi1xwsm/trbhoun/wzyergu/nn/secured_stub.ps1"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"sqpengg.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925610/; classtype:trojan-activity;sid:84788710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925608)"; flow:established,from_client; content:"GET"; http_method; content:"/vi1xwsm/trbhoun/wzyergu/vvv/secured2_stub.ps1"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"sqpengg.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925608/; classtype:trojan-activity;sid:84788708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925609)"; flow:established,from_client; content:"GET"; http_method; content:"/vi1xwsm/trbhoun/wzyergu/nn/cryptedt.ps1"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"sqpengg.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925609/; classtype:trojan-activity;sid:84788709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925607)"; flow:established,from_client; content:"GET"; http_method; content:"/vi1xwsm/trbhoun/wzyergu/cc/crypted.ps1"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"sqpengg.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925607/; classtype:trojan-activity;sid:84788707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925606)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.35.133.136"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925606/; classtype:trojan-activity;sid:84788706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925604)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.83.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925604/; classtype:trojan-activity;sid:84788704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925605)"; flow:established,from_client; content:"GET"; http_method; content:"/mrmasabik/secured_stub.ps1"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"nsci.space"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925605/; classtype:trojan-activity;sid:84788705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925603)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/team/gomato.js"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"porterneuman.mx"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925603/; classtype:trojan-activity;sid:84788703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925602)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/team/tsecured_stub.ps1"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"porterneuman.mx"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925602/; classtype:trojan-activity;sid:84788702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925601)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/team/secured_stub.ps1"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"porterneuman.mx"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925601/; classtype:trojan-activity;sid:84788701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925600)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/team/notessecured_stub.ps1"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"porterneuman.mx"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925600/; classtype:trojan-activity;sid:84788700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925599)"; flow:established,from_client; content:"GET"; http_method; content:"/mrmasabikfrnd/secured_stub.ps1"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"aksiyononline.best"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925599/; classtype:trojan-activity;sid:84788699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925598)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/team/teasecured_stub.ps1"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"porterneuman.mx"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925598/; classtype:trojan-activity;sid:84788698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925597)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"finmonologips.top"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925597/; classtype:trojan-activity;sid:84788697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925596)"; flow:established,from_client; content:"GET"; http_method; content:"/lp.mp4"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"2.26.252.72"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925596/; classtype:trojan-activity;sid:84788696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925595)"; flow:established,from_client; content:"GET"; http_method; content:"/aes.js"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"fe29jf323.kesug.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925595/; classtype:trojan-activity;sid:84788695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925594)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_011624.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925594/; classtype:trojan-activity;sid:84788694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925593)"; flow:established,from_client; content:"GET"; http_method; content:"/d/abaobwl|3f|r=20147cfb5c8ed6466d"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"nota-fical-online.lat"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925593/; classtype:trojan-activity;sid:84788693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925592)"; flow:established,from_client; content:"GET"; http_method; content:"/test.bat"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"5.252.177.210"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925592/; classtype:trojan-activity;sid:84788692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925591)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1csbpqelvvxlby1h-hxti8jliwafl12rv"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925591/; classtype:trojan-activity;sid:84788691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925590)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.119.35.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925590/; classtype:trojan-activity;sid:84788690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925588)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=10awwksrnqmacc4ncslye5jpo3ibckb9j"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925588/; classtype:trojan-activity;sid:84788688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925589)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ffya-23u8rfo81zuhkjwipc6k33bi0rr"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925589/; classtype:trojan-activity;sid:84788689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925586)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ysfwuucwqeux4jykgdd-kouvz8q1ykvi"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925586/; classtype:trojan-activity;sid:84788686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925587)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1f2nh4ahfjui5elrjosltslal-qchabnc"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925587/; classtype:trojan-activity;sid:84788687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925585)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1re6ntrsaq7lah-ppbxoh3iykoxsvebei"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925585/; classtype:trojan-activity;sid:84788685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925584)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1vdpjxoxfptyyfuqgyjtn_lm_5jiqbick"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925584/; classtype:trojan-activity;sid:84788684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925583)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=12pbn_nz5e4uy-pazopap44emmsssllla"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925583/; classtype:trojan-activity;sid:84788683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925582)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1kvvvundqvkze34l_vcyn-mjtuupkdrtu"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925582/; classtype:trojan-activity;sid:84788682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925579)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1al353r1ccnpfnfustx6fhgdu-ol1qelg"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925579/; classtype:trojan-activity;sid:84788679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925580)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=10toqgslsccls78ipqsezq8ovnxxnixzq"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925580/; classtype:trojan-activity;sid:84788680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925581)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=16byw_1rh2wozehchuy40xecnzpsjx5g2"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925581/; classtype:trojan-activity;sid:84788681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925578)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=16xesiew_zi7nm5kldmwejv_u06e66tqu"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925578/; classtype:trojan-activity;sid:84788678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925577)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=137gw3jktqbwmghxh0xewm8iu4fgj9jxk"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925577/; classtype:trojan-activity;sid:84788677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925576)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1xepsg4muw_5gzb9rzqi45d-w96_oxurf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925576/; classtype:trojan-activity;sid:84788676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925574)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=17xshlv-2n_1ob-zhqsq3vukawp3zdcnt"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925574/; classtype:trojan-activity;sid:84788674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925575)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=14yci-yluozqutbhbydcqgh9fbpjwfm-k"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925575/; classtype:trojan-activity;sid:84788675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925572)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.230.27.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925572/; classtype:trojan-activity;sid:84788672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925573)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.83.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925573/; classtype:trojan-activity;sid:84788673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925571)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.202.213.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925571/; classtype:trojan-activity;sid:84788671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925570)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.35.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925570/; classtype:trojan-activity;sid:84788670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925569)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.179.240.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925569/; classtype:trojan-activity;sid:84788669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925565)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925565/; classtype:trojan-activity;sid:84788665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925566)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925566/; classtype:trojan-activity;sid:84788666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925567)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.249.199.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925567/; classtype:trojan-activity;sid:84788667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925568)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925568/; classtype:trojan-activity;sid:84788668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925564)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.55.246.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925564/; classtype:trojan-activity;sid:84788664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925563)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925563/; classtype:trojan-activity;sid:84788663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925561)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.48.136.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925561/; classtype:trojan-activity;sid:84788661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925562)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.215.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925562/; classtype:trojan-activity;sid:84788662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925560)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.55.16.121"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925560/; classtype:trojan-activity;sid:84788660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925559)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.40.113.183"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925559/; classtype:trojan-activity;sid:84788659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925558)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.121.195.163"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925558/; classtype:trojan-activity;sid:84788658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925553)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"216.126.86.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925553/; classtype:trojan-activity;sid:84788653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925554)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.48.136.227"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925554/; classtype:trojan-activity;sid:84788654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925555)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.185.242.128"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925555/; classtype:trojan-activity;sid:84788655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925556)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"80.67.33.209"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925556/; classtype:trojan-activity;sid:84788656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925557)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.248.204"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925557/; classtype:trojan-activity;sid:84788657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925552)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.63.126.232"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925552/; classtype:trojan-activity;sid:84788652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925551)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.248.204"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925551/; classtype:trojan-activity;sid:84788651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925548)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"216.126.86.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925548/; classtype:trojan-activity;sid:84788648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925549)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.235.36.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925549/; classtype:trojan-activity;sid:84788649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925550)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.202.213.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925550/; classtype:trojan-activity;sid:84788650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925547)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_b4b36c03786de183.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925547/; classtype:trojan-activity;sid:84788647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925546)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1mc_capvubznhasat4tii3fewhzu6qi8w"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925546/; classtype:trojan-activity;sid:84788646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925545)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=13hpeytcgcu3ac7mt9ixhbwopsfosfej9"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925545/; classtype:trojan-activity;sid:84788645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925542)"; flow:established,from_client; content:"GET"; http_method; content:"/imole/floddelta.lzh"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"limelight.ie"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925542/; classtype:trojan-activity;sid:84788642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925543)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.255.41.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925543/; classtype:trojan-activity;sid:84788643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925544)"; flow:established,from_client; content:"GET"; http_method; content:"/imole/pogtopvlonquqmwisrkq253.bin"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"limelight.ie"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925544/; classtype:trojan-activity;sid:84788644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925539)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.121.56"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925539/; classtype:trojan-activity;sid:84788639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925540)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.15.11.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925540/; classtype:trojan-activity;sid:84788640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925541)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.52.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925541/; classtype:trojan-activity;sid:84788641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925538)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.154.43.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925538/; classtype:trojan-activity;sid:84788638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925537)"; flow:established,from_client; content:"GET"; http_method; content:"/tk.y"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"tk-1464303226.cos.ap-guangzhou.myqcloud.com"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925537/; classtype:trojan-activity;sid:84788637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925536)"; flow:established,from_client; content:"GET"; http_method; content:"/tk.txt"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"fa.windows32.men"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925536/; classtype:trojan-activity;sid:84788636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925535)"; flow:established,from_client; content:"GET"; http_method; content:"/fa.y"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"fa-1464303226.cos.ap-guangzhou.myqcloud.com"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925535/; classtype:trojan-activity;sid:84788635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925534)"; flow:established,from_client; content:"GET"; http_method; content:"/fa.txt"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"fa.windows32.men"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925534/; classtype:trojan-activity;sid:84788634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925533)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.229.54.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925533/; classtype:trojan-activity;sid:84788633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925531)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.230.27.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925531/; classtype:trojan-activity;sid:84788631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925532)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.236.146"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925532/; classtype:trojan-activity;sid:84788632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925529)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.250.212"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925529/; classtype:trojan-activity;sid:84788629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925530)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.187.101.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925530/; classtype:trojan-activity;sid:84788630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925528)"; flow:established,from_client; content:"GET"; http_method; content:"/public/winwin/nivellering.mix"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"hotelhungry.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925528/; classtype:trojan-activity;sid:84788628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925527)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_220602.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925527/; classtype:trojan-activity;sid:84788627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925526)"; flow:established,from_client; content:"GET"; http_method; content:"/public/winwin/bataters.psp"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"hotelhungry.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925526/; classtype:trojan-activity;sid:84788626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925525)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_215413.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925525/; classtype:trojan-activity;sid:84788625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925524)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_221258.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925524/; classtype:trojan-activity;sid:84788624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925522)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"101.108.60.160"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925522/; classtype:trojan-activity;sid:84788622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925523)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.15.11.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925523/; classtype:trojan-activity;sid:84788623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925521)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.52.132"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925521/; classtype:trojan-activity;sid:84788621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925519)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.60.176.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925519/; classtype:trojan-activity;sid:84788619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925520)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.250.212"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925520/; classtype:trojan-activity;sid:84788620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925518)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.arm5"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925518/; classtype:trojan-activity;sid:84788618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925508)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.arm6"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925508/; classtype:trojan-activity;sid:84788608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925509)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.x86"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925509/; classtype:trojan-activity;sid:84788609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925510)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.mips"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925510/; classtype:trojan-activity;sid:84788610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925511)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.arm7"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925511/; classtype:trojan-activity;sid:84788611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925512)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.mpsl"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925512/; classtype:trojan-activity;sid:84788612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925513)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.sh4"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925513/; classtype:trojan-activity;sid:84788613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925514)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.spc"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925514/; classtype:trojan-activity;sid:84788614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925515)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.arm"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925515/; classtype:trojan-activity;sid:84788615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925516)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.m68k"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925516/; classtype:trojan-activity;sid:84788616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925517)"; flow:established,from_client; content:"GET"; http_method; content:"/lmaowtf/loligang.ppc"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925517/; classtype:trojan-activity;sid:84788617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925507)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.12.247.216"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925507/; classtype:trojan-activity;sid:84788607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925504)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.243.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925504/; classtype:trojan-activity;sid:84788604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925505)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.61.236.146"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925505/; classtype:trojan-activity;sid:84788605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925506)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.173.212.106"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925506/; classtype:trojan-activity;sid:84788606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925503)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.126.212.96"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925503/; classtype:trojan-activity;sid:84788603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925501)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.84.212.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925501/; classtype:trojan-activity;sid:84788601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925502)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925502/; classtype:trojan-activity;sid:84788602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925499)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.107.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925499/; classtype:trojan-activity;sid:84788599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925500)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.225.14.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925500/; classtype:trojan-activity;sid:84788600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925496)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.117.25.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925496/; classtype:trojan-activity;sid:84788596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925497)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.124.40.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925497/; classtype:trojan-activity;sid:84788597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925498)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.113.11.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925498/; classtype:trojan-activity;sid:84788598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925493)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.243.179.18"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925493/; classtype:trojan-activity;sid:84788593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925494)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.224.47.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925494/; classtype:trojan-activity;sid:84788594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925495)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.99.91.121"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925495/; classtype:trojan-activity;sid:84788595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925491)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.230.242.151"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925491/; classtype:trojan-activity;sid:84788591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925492)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.170.11.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925492/; classtype:trojan-activity;sid:84788592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925490)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.230.242.151"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925490/; classtype:trojan-activity;sid:84788590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925489)"; flow:established,from_client; content:"GET"; http_method; content:"/chrome.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"grupocaprem.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925489/; classtype:trojan-activity;sid:84788589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925486)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.65.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925486/; classtype:trojan-activity;sid:84788586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925487)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.218.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925487/; classtype:trojan-activity;sid:84788587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925488)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.63.244.171"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925488/; classtype:trojan-activity;sid:84788588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925485)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.157.210.26"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925485/; classtype:trojan-activity;sid:84788585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925484)"; flow:established,from_client; content:"GET"; http_method; content:"/clearretent/valley9/releases/download/latest/google.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925484/; classtype:trojan-activity;sid:84788584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925483)"; flow:established,from_client; content:"GET"; http_method; content:"/clearretent/valley9/releases/download/latest/chrome.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925483/; classtype:trojan-activity;sid:84788583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925482)"; flow:established,from_client; content:"GET"; http_method; content:"/clearretent/valley9/releases/download/latest/chromesetup.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925482/; classtype:trojan-activity;sid:84788582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925481)"; flow:established,from_client; content:"GET"; http_method; content:"/chrome.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"fussionmd.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925481/; classtype:trojan-activity;sid:84788581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925480)"; flow:established,from_client; content:"GET"; http_method; content:"/google.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"fussionmd.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925480/; classtype:trojan-activity;sid:84788580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925479)"; flow:established,from_client; content:"GET"; http_method; content:"/google.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"grupocaprem.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925479/; classtype:trojan-activity;sid:84788579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925478)"; flow:established,from_client; content:"GET"; http_method; content:"/pemex.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"209.126.103.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925478/; classtype:trojan-activity;sid:84788578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925477)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"160.179.98.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925477/; classtype:trojan-activity;sid:84788577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925476)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.237.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925476/; classtype:trojan-activity;sid:84788576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925475)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"171.38.149.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925475/; classtype:trojan-activity;sid:84788575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925474)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.152.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925474/; classtype:trojan-activity;sid:84788574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925472)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.23.235.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925472/; classtype:trojan-activity;sid:84788572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925473)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.226.69.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925473/; classtype:trojan-activity;sid:84788573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925471)"; flow:established,from_client; content:"GET"; http_method; content:"/solopada"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925471/; classtype:trojan-activity;sid:84788571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925470)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"160.179.98.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925470/; classtype:trojan-activity;sid:84788570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925469)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.34.207.135"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925469/; classtype:trojan-activity;sid:84788569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925468)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.83.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925468/; classtype:trojan-activity;sid:84788568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925467)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"171.38.149.69"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925467/; classtype:trojan-activity;sid:84788567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925466)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.109.227.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925466/; classtype:trojan-activity;sid:84788566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925465)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.216.226.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925465/; classtype:trojan-activity;sid:84788565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925463)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.57.99.253"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925463/; classtype:trojan-activity;sid:84788563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925464)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.154.97.42"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925464/; classtype:trojan-activity;sid:84788564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925461)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.248.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925461/; classtype:trojan-activity;sid:84788561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925462)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.142.220.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925462/; classtype:trojan-activity;sid:84788562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925457)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_031721.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925457/; classtype:trojan-activity;sid:84788557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925458)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_173933.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925458/; classtype:trojan-activity;sid:84788558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925459)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_200150.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925459/; classtype:trojan-activity;sid:84788559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925460)"; flow:established,from_client; content:"GET"; http_method; content:"/web/img_193047.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"fujeigroup.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925460/; classtype:trojan-activity;sid:84788560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925456)"; flow:established,from_client; content:"GET"; http_method; content:"/zipoiq"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"rough-truth-e072.publicftpresend.workers.dev"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925456/; classtype:trojan-activity;sid:84788556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925455)"; flow:established,from_client; content:"GET"; http_method; content:"/net.png"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925455/; classtype:trojan-activity;sid:84788555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925454)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.186.247.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925454/; classtype:trojan-activity;sid:84788554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925453)"; flow:established,from_client; content:"GET"; http_method; content:"/binsir/img_sir035737.png"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"bumcoinc.site"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925453/; classtype:trojan-activity;sid:84788553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925451)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.225.254.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925451/; classtype:trojan-activity;sid:84788551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925452)"; flow:established,from_client; content:"GET"; http_method; content:"/img_215919.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"johnsonsvalves.cam"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925452/; classtype:trojan-activity;sid:84788552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925448)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.238.228.103"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925448/; classtype:trojan-activity;sid:84788548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925449)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.121.56"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925449/; classtype:trojan-activity;sid:84788549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925450)"; flow:established,from_client; content:"GET"; http_method; content:"/hf1w1z5k"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"johnsonsvalves.cam"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925450/; classtype:trojan-activity;sid:84788550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925447)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.97.248.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925447/; classtype:trojan-activity;sid:84788547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925446)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.172.186.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925446/; classtype:trojan-activity;sid:84788546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925445)"; flow:established,from_client; content:"GET"; http_method; content:"/brysj/b.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"b.9-9-11.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925445/; classtype:trojan-activity;sid:84788545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925443)"; flow:established,from_client; content:"GET"; http_method; content:"/xaerosminimap-fabric-1.21.4.jar"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"xaerosminimap.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925443/; classtype:trojan-activity;sid:84788543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925444)"; flow:established,from_client; content:"GET"; http_method; content:"/meteor-rejects-addon-1.21.4.jar"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"meteorrejects.net"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925444/; classtype:trojan-activity;sid:84788544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925441)"; flow:established,from_client; content:"GET"; http_method; content:"/xaerosminimap-fabric-1.21.11.jar"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"xaerosminimap.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925441/; classtype:trojan-activity;sid:84788541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925442)"; flow:established,from_client; content:"GET"; http_method; content:"/meteor-rejects-addon-1.21.0.jar"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"meteorrejects.net"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925442/; classtype:trojan-activity;sid:84788542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925437)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.105.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925437/; classtype:trojan-activity;sid:84788537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925438)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.252.219.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925438/; classtype:trojan-activity;sid:84788538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925439)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.36.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925439/; classtype:trojan-activity;sid:84788539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925440)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.220.247.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925440/; classtype:trojan-activity;sid:84788540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925436)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.171.177.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925436/; classtype:trojan-activity;sid:84788536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925435)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.5.130.144"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925435/; classtype:trojan-activity;sid:84788535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925433)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.63.189.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925433/; classtype:trojan-activity;sid:84788533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925434)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"121.231.77.1"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925434/; classtype:trojan-activity;sid:84788534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925432)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.63.144"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925432/; classtype:trojan-activity;sid:84788532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925431)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.39.25.233"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925431/; classtype:trojan-activity;sid:84788531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925430)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.36.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925430/; classtype:trojan-activity;sid:84788530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925427)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.116.36.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925427/; classtype:trojan-activity;sid:84788527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925428)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.252.219.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925428/; classtype:trojan-activity;sid:84788528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925429)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.213.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925429/; classtype:trojan-activity;sid:84788529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925425)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.231.107.205"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925425/; classtype:trojan-activity;sid:84788525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925426)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.225.86.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925426/; classtype:trojan-activity;sid:84788526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925424)"; flow:established,from_client; content:"GET"; http_method; content:"/stripe.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"34.89.60.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925424/; classtype:trojan-activity;sid:84788524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925419)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.140.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925419/; classtype:trojan-activity;sid:84788519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925420)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.116.36.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925420/; classtype:trojan-activity;sid:84788520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925421)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.140.224"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925421/; classtype:trojan-activity;sid:84788521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925422)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"219.155.208.166"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925422/; classtype:trojan-activity;sid:84788522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925423)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925423/; classtype:trojan-activity;sid:84788523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925418)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"211.158.150.254"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925418/; classtype:trojan-activity;sid:84788518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925417)"; flow:established,from_client; content:"GET"; http_method; content:"/img_142142.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"6ab746fb57212ca6e1e7b121.imgix.net"; http_host; depth:34; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925417/; classtype:trojan-activity;sid:84788517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925416)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.63.189.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925416/; classtype:trojan-activity;sid:84788516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925414)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.56.194.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925414/; classtype:trojan-activity;sid:84788514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925415)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.39.25.233"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925415/; classtype:trojan-activity;sid:84788515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925413)"; flow:established,from_client; content:"GET"; http_method; content:"/troldbundne.thn"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"tradingengineers.in"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925413/; classtype:trojan-activity;sid:84788513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925412)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.221.46.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925412/; classtype:trojan-activity;sid:84788512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925411)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.149.204.12"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925411/; classtype:trojan-activity;sid:84788511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925410)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"179.49.213.85"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925410/; classtype:trojan-activity;sid:84788510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925409)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.127.123.209"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925409/; classtype:trojan-activity;sid:84788509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925408)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.194.175"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925408/; classtype:trojan-activity;sid:84788508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925407)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.220.247.123"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925407/; classtype:trojan-activity;sid:84788507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925406)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.105.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925406/; classtype:trojan-activity;sid:84788506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925405)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.56.194.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925405/; classtype:trojan-activity;sid:84788505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925404)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.71.17.24"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925404/; classtype:trojan-activity;sid:84788504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925403)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.174.231.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925403/; classtype:trojan-activity;sid:84788503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925402)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.127.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925402/; classtype:trojan-activity;sid:84788502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925401)"; flow:established,from_client; content:"GET"; http_method; content:"/img/3.jpg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"107.172.235.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925401/; classtype:trojan-activity;sid:84788501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925400)"; flow:established,from_client; content:"GET"; http_method; content:"/raw/q88luv"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"tutpaste.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925400/; classtype:trojan-activity;sid:84788500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925399)"; flow:established,from_client; content:"GET"; http_method; content:"/55/img_94905005050.jpg.js"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"172.245.209.172"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925399/; classtype:trojan-activity;sid:84788499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925391)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925391/; classtype:trojan-activity;sid:84788491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925392)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925392/; classtype:trojan-activity;sid:84788492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925393)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925393/; classtype:trojan-activity;sid:84788493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925394)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925394/; classtype:trojan-activity;sid:84788494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925395)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925395/; classtype:trojan-activity;sid:84788495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925396)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925396/; classtype:trojan-activity;sid:84788496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925397)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925397/; classtype:trojan-activity;sid:84788497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925398)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925398/; classtype:trojan-activity;sid:84788498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925386)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925386/; classtype:trojan-activity;sid:84788486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925387)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925387/; classtype:trojan-activity;sid:84788487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925388)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925388/; classtype:trojan-activity;sid:84788488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925389)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925389/; classtype:trojan-activity;sid:84788489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925390)"; flow:established,from_client; content:"GET"; http_method; content:"/arm/"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925390/; classtype:trojan-activity;sid:84788490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925382)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925382/; classtype:trojan-activity;sid:84788482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925383)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925383/; classtype:trojan-activity;sid:84788483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925384)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925384/; classtype:trojan-activity;sid:84788484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925385)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925385/; classtype:trojan-activity;sid:84788485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925381)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.135"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925381/; classtype:trojan-activity;sid:84788481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925380)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.215.127.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925380/; classtype:trojan-activity;sid:84788480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925379)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.186.247.57"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925379/; classtype:trojan-activity;sid:84788479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925378)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.50.89.31"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925378/; classtype:trojan-activity;sid:84788478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925377)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.127.53.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925377/; classtype:trojan-activity;sid:84788477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925376)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.38.205.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925376/; classtype:trojan-activity;sid:84788476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925375)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"203.221.8.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925375/; classtype:trojan-activity;sid:84788475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925374)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.152.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925374/; classtype:trojan-activity;sid:84788474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925372)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"86.107.14.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925372/; classtype:trojan-activity;sid:84788472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925373)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.220.95.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925373/; classtype:trojan-activity;sid:84788473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925371)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.49.79.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925371/; classtype:trojan-activity;sid:84788471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925370)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"77.32.122.59"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925370/; classtype:trojan-activity;sid:84788470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925369)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/fb61c458-d12f-8139-fbd375534040/refs/heads/main/97ef08464f9cef83c5"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925369/; classtype:trojan-activity;sid:84788469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925368)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/5c5d8d-0333-4cbe-b328-d84e0dd9d/refs/heads/main/71f93c0a-94ad-4763-bab8-ba459e8b3395"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925368/; classtype:trojan-activity;sid:84788468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925361)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/559f-2414-494a-8560-23ce5908/refs/heads/main/089c8e594-4e62-a464-d512b030"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925361/; classtype:trojan-activity;sid:84788461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925362)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/fb61c458-d12f-8139-fbd375534040/refs/heads/main/ede9f684-6985-898b-3f80f312d1b0"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925362/; classtype:trojan-activity;sid:84788462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925363)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/559f-2414-494a-8560-23ce5908/refs/heads/main/eea997-d7e6-43f3-a5bd"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925363/; classtype:trojan-activity;sid:84788463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925364)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/02-fd9159f9-9a/refs/heads/main/f28ddb96-d4bc-410"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925364/; classtype:trojan-activity;sid:84788464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925365)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/5c5d8d-0333-4cbe-b328-d84e0dd9d/refs/heads/main/76f4346f-d81c-465f-9d7b-fa5089c9ea3b"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925365/; classtype:trojan-activity;sid:84788465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925366)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/02-fd9159f9-9a/refs/heads/main/4fea-a19d-c354a1aaa4eb"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925366/; classtype:trojan-activity;sid:84788466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925367)"; flow:established,from_client; content:"GET"; http_method; content:"/dsteru3421/4f77-bdc8-7e8087412ccf/refs/heads/main/457b-b003-d5999c246f25"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925367/; classtype:trojan-activity;sid:84788467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925360)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.32.122.59"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925360/; classtype:trojan-activity;sid:84788460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925359)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_d704a83d08416a2d.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925359/; classtype:trojan-activity;sid:84788459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925357)"; flow:established,from_client; content:"GET"; http_method; content:"/curl.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"bins.oceanic-node.su"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925357/; classtype:trojan-activity;sid:84788457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925358)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"bins.oceanic-node.su"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925358/; classtype:trojan-activity;sid:84788458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925356)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.61.7.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925356/; classtype:trojan-activity;sid:84788456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925354)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.147.231.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925354/; classtype:trojan-activity;sid:84788454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925355)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.115.102.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925355/; classtype:trojan-activity;sid:84788455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925352)"; flow:established,from_client; content:"GET"; http_method; content:"/rs.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"131.123.43.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925352/; classtype:trojan-activity;sid:84788452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925353)"; flow:established,from_client; content:"GET"; http_method; content:"/pldq.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"131.123.43.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925353/; classtype:trojan-activity;sid:84788453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925350)"; flow:established,from_client; content:"GET"; http_method; content:"/plx.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"131.123.43.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925350/; classtype:trojan-activity;sid:84788450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925351)"; flow:established,from_client; content:"GET"; http_method; content:"/q.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"131.123.43.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925351/; classtype:trojan-activity;sid:84788451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925349)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_3lqajyfdw3v64f5xtqfljyp1elu3y5a"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925349/; classtype:trojan-activity;sid:84788449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925348)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1cgpgs5ya_bkydacrkswhg2qe8ys39lpo"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925348/; classtype:trojan-activity;sid:84788448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925347)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.52.188.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925347/; classtype:trojan-activity;sid:84788447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925346)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"218.16.164.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925346/; classtype:trojan-activity;sid:84788446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925345)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.53.89.172"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925345/; classtype:trojan-activity;sid:84788445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925344)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.163.130.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925344/; classtype:trojan-activity;sid:84788444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925342)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"86.107.14.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925342/; classtype:trojan-activity;sid:84788442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925343)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.124.40.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925343/; classtype:trojan-activity;sid:84788443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925341)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.22.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925341/; classtype:trojan-activity;sid:84788441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925340)"; flow:established,from_client; content:"GET"; http_method; content:"/img/img_220032.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"ficus.in"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925340/; classtype:trojan-activity;sid:84788440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925339)"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/1547475077057085460/1554732207753527296/bundle.zip|3f|ex=6abdf4b3|7c|26|7c|is=6abca333|7c|26|7c|hm=a111372e4c819bd35a833aaa8a2e7211e706da2b8724266502140b33830426f4|7c|26|7c|"; http_uri; depth:186; isdataat:!1,relative; nocase; content:"cdn.discordapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925339/; classtype:trojan-activity;sid:84788439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925338)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=10wq0z-vbsdbx4zvni64byaeolnweg3qd"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925338/; classtype:trojan-activity;sid:84788438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925337)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.147.231.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925337/; classtype:trojan-activity;sid:84788437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925333)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"79.36.217.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925333/; classtype:trojan-activity;sid:84788433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925334)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.57.186.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925334/; classtype:trojan-activity;sid:84788434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925335)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"210.97.100.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925335/; classtype:trojan-activity;sid:84788435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925336)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.226.69.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925336/; classtype:trojan-activity;sid:84788436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925332)"; flow:established,from_client; content:"GET"; http_method; content:"/0upmips"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925332/; classtype:trojan-activity;sid:84788432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925331)"; flow:established,from_client; content:"GET"; http_method; content:"/up"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"131.123.43.239"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925331/; classtype:trojan-activity;sid:84788431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925330)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.22.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925330/; classtype:trojan-activity;sid:84788430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925327)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"105.184.239.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925327/; classtype:trojan-activity;sid:84788427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925328)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.160.101.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925328/; classtype:trojan-activity;sid:84788428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925329)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.57.186.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925329/; classtype:trojan-activity;sid:84788429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925326)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.56.149.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925326/; classtype:trojan-activity;sid:84788426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925325)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.117.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925325/; classtype:trojan-activity;sid:84788425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925323)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.122.239.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925323/; classtype:trojan-activity;sid:84788423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925324)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.122.239.54"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925324/; classtype:trojan-activity;sid:84788424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925320)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.141.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925320/; classtype:trojan-activity;sid:84788420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925321)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.194.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925321/; classtype:trojan-activity;sid:84788421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925322)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.224.252.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925322/; classtype:trojan-activity;sid:84788422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925319)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/fabric-api/fabric-api-0.136.1%2b1.21.8.jar"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925319/; classtype:trojan-activity;sid:84788419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925315)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.127.123.209"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925315/; classtype:trojan-activity;sid:84788415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925316)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"43.254.207.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925316/; classtype:trojan-activity;sid:84788416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925317)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.238.170.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925317/; classtype:trojan-activity;sid:84788417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925318)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.238.170.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925318/; classtype:trojan-activity;sid:84788418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925314)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.168.69.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925314/; classtype:trojan-activity;sid:84788414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925302)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/baritone/baritone-client-mod-meteor-fabric-1.21.10.jar"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925302/; classtype:trojan-activity;sid:84788402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925303)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"5.206.227.37"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925303/; classtype:trojan-activity;sid:84788403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925304)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/fabric-api/fabric-api-0.138.4%2b1.21.10.jar"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925304/; classtype:trojan-activity;sid:84788404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925305)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/baritone/baritone-client-mod-meteor-fabric-1.21.5.jar"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925305/; classtype:trojan-activity;sid:84788405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925306)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/meteor/meteor-client-1.21.8-69.jar"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925306/; classtype:trojan-activity;sid:84788406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925307)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/baritone/baritone-client-mod-meteor-fabric-1.21.4.jar"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925307/; classtype:trojan-activity;sid:84788407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925308)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/meteor/meteor-client-1.21.11-63.jar"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925308/; classtype:trojan-activity;sid:84788408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925309)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/meteor/meteor-client-1.21.4-42.jar"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925309/; classtype:trojan-activity;sid:84788409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925310)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/baritone/baritone-client-mod-meteor-fabric-1.21.8.jar"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925310/; classtype:trojan-activity;sid:84788410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925311)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/baritone/baritone-meteor-1.21.11.jar"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925311/; classtype:trojan-activity;sid:84788411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925312)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/fabric-api/fabric-api-0.116.8%2b1.21.1.jar"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925312/; classtype:trojan-activity;sid:84788412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925313)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/meteor/meteor-client-1.21.5-54.jar"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925313/; classtype:trojan-activity;sid:84788413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925300)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/fabric-api/fabric-api-0.119.4%2b1.21.4.jar"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925300/; classtype:trojan-activity;sid:84788400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925301)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/fabric-api/fabric-api-0.128.2%2b1.21.5.jar"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925301/; classtype:trojan-activity;sid:84788401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925299)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/fabric-api/fabric-api-0.141.3%2b1.21.11.jar"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925299/; classtype:trojan-activity;sid:84788399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925297)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/meteor/meteor-client-1.21.10-54.jar"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925297/; classtype:trojan-activity;sid:84788397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925298)"; flow:established,from_client; content:"GET"; http_method; content:"/noxxclient-26.2.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"noxxclient.org"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925298/; classtype:trojan-activity;sid:84788398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925296)"; flow:established,from_client; content:"GET"; http_method; content:"/noxxclient-1.21.11.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"noxxclient.org"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925296/; classtype:trojan-activity;sid:84788396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925295)"; flow:established,from_client; content:"GET"; http_method; content:"/argonclient-1.21.11.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"argon-client.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925295/; classtype:trojan-activity;sid:84788395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925294)"; flow:established,from_client; content:"GET"; http_method; content:"/argonclient-26.2.jar"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"argon-client.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925294/; classtype:trojan-activity;sid:84788394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925293)"; flow:established,from_client; content:"GET"; http_method; content:"/ah-sniper-v2.1.9-1.21.11.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"ahsniper.org"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925293/; classtype:trojan-activity;sid:84788393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925292)"; flow:established,from_client; content:"GET"; http_method; content:"/download"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"larpaddon.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925292/; classtype:trojan-activity;sid:84788392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925290)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.135.67.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925290/; classtype:trojan-activity;sid:84788390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925291)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/liquidbounce-1.21.x.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925291/; classtype:trojan-activity;sid:84788391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925289)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/wurst-7.54-mc1.21.11.jar"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925289/; classtype:trojan-activity;sid:84788389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925287)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/meteor/meteor-client-1.21.1-0.5.8.jar"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925287/; classtype:trojan-activity;sid:84788387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925288)"; flow:established,from_client; content:"GET"; http_method; content:"/deps/baritone/baritone-client-mod-meteor-fabric-1.21.1.jar"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925288/; classtype:trojan-activity;sid:84788388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925285)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/krypton-client.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925285/; classtype:trojan-activity;sid:84788385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925286)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/meteor-client-1.21.11.jar"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925286/; classtype:trojan-activity;sid:84788386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925269)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/files/glazed-1.21.11-n-16.1.jar"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"rough-glade-bfc8.pentagon-e8b.workers.dev"; http_host; depth:41; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925269/; classtype:trojan-activity;sid:84788369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925270)"; flow:established,from_client; content:"GET"; http_method; content:"/0uparm5"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925270/; classtype:trojan-activity;sid:84788370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925271)"; flow:established,from_client; content:"GET"; http_method; content:"/0upppc"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925271/; classtype:trojan-activity;sid:84788371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925272)"; flow:established,from_client; content:"GET"; http_method; content:"/0upmpsl"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925272/; classtype:trojan-activity;sid:84788372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925273)"; flow:established,from_client; content:"GET"; http_method; content:"/0uparm6"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925273/; classtype:trojan-activity;sid:84788373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925274)"; flow:established,from_client; content:"GET"; http_method; content:"/0upspc"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925274/; classtype:trojan-activity;sid:84788374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925275)"; flow:established,from_client; content:"GET"; http_method; content:"/0uparm"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925275/; classtype:trojan-activity;sid:84788375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925276)"; flow:established,from_client; content:"GET"; http_method; content:"/0upsh4"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925276/; classtype:trojan-activity;sid:84788376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925277)"; flow:established,from_client; content:"GET"; http_method; content:"/0upx86"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925277/; classtype:trojan-activity;sid:84788377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925278)"; flow:established,from_client; content:"GET"; http_method; content:"/0uparm7"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925278/; classtype:trojan-activity;sid:84788378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925279)"; flow:established,from_client; content:"GET"; http_method; content:"/0upx64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925279/; classtype:trojan-activity;sid:84788379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925280)"; flow:established,from_client; content:"GET"; http_method; content:"/ok"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925280/; classtype:trojan-activity;sid:84788380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925281)"; flow:established,from_client; content:"GET"; http_method; content:"/0upm68k"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"151.243.24.225"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925281/; classtype:trojan-activity;sid:84788381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925282)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/glazed-addon-1.21.11.jar"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925282/; classtype:trojan-activity;sid:84788382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925283)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/doomsday-client-1.21.11.jar"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925283/; classtype:trojan-activity;sid:84788383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925284)"; flow:established,from_client; content:"GET"; http_method; content:"/mods/fakepay-1.21.x.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"donutsmpcheats.org"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925284/; classtype:trojan-activity;sid:84788384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925268)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_53f26aa255487411.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925268/; classtype:trojan-activity;sid:84788368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925266)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.179.254.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925266/; classtype:trojan-activity;sid:84788366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925267)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.105.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925267/; classtype:trojan-activity;sid:84788367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925265)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1oykwcfbxubnjjnmdia6reh0vfqunkn-e"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925265/; classtype:trojan-activity;sid:84788365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925264)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1g65mnhgcsvmfatd2prui2u_2nvuimlim"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925264/; classtype:trojan-activity;sid:84788364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925263)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1oo1ohlssgvvbpvq252fg2vajgxmckmpj"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925263/; classtype:trojan-activity;sid:84788363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925262)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gijuitls_rwdhgl4msh3euzcnkuvytqi"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925262/; classtype:trojan-activity;sid:84788362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925261)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"105.184.239.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925261/; classtype:trojan-activity;sid:84788361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925259)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.136.86.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925259/; classtype:trojan-activity;sid:84788359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925260)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.87.230"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925260/; classtype:trojan-activity;sid:84788360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925257)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1hbyr6dq5_afx-7jeoiswnzzjsqkvwnc9"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925257/; classtype:trojan-activity;sid:84788357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925258)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=12uqoo8llknpp1x6letsalgnktkk3prk-"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925258/; classtype:trojan-activity;sid:84788358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925256)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.50.89.31"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925256/; classtype:trojan-activity;sid:84788356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925255)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.154.99.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925255/; classtype:trojan-activity;sid:84788355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925254)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.142.202.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925254/; classtype:trojan-activity;sid:84788354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925251)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.151.42.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925251/; classtype:trojan-activity;sid:84788351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925252)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.136.86.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925252/; classtype:trojan-activity;sid:84788352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925253)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.44.146.192"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925253/; classtype:trojan-activity;sid:84788353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.190.195.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925248/; classtype:trojan-activity;sid:84788348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.137.138.7"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925249/; classtype:trojan-activity;sid:84788349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925250)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"187.121.141.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925250/; classtype:trojan-activity;sid:84788350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925247)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"196.189.9.27"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925247/; classtype:trojan-activity;sid:84788347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925246)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.116.123.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925246/; classtype:trojan-activity;sid:84788346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925245)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_7d75a79198b16112.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925245/; classtype:trojan-activity;sid:84788345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925244)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.44.145.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925244/; classtype:trojan-activity;sid:84788344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925242)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.119.166.213"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925242/; classtype:trojan-activity;sid:84788342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925243)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.99.165.199"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925243/; classtype:trojan-activity;sid:84788343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925238)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.172.186.194"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925238/; classtype:trojan-activity;sid:84788338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925239)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.180.85.86"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925239/; classtype:trojan-activity;sid:84788339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925240)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"66.8.135.142"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925240/; classtype:trojan-activity;sid:84788340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925241)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.137.138.7"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925241/; classtype:trojan-activity;sid:84788341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925236)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.116.123.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925236/; classtype:trojan-activity;sid:84788336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925237)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"163.142.93.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925237/; classtype:trojan-activity;sid:84788337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925235)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_ea030d4efa812b7c.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925235/; classtype:trojan-activity;sid:84788335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925234)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.123.162"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925234/; classtype:trojan-activity;sid:84788334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925231)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.171.177.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925231/; classtype:trojan-activity;sid:84788331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925232)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.190.188.110"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925232/; classtype:trojan-activity;sid:84788332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925233)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"66.8.135.142"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925233/; classtype:trojan-activity;sid:84788333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925230)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_6e3e4cd57f3bdadd.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925230/; classtype:trojan-activity;sid:84788330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925229)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.26.83.155"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925229/; classtype:trojan-activity;sid:84788329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925228)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.193.10.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925228/; classtype:trojan-activity;sid:84788328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925227)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.180.181.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925227/; classtype:trojan-activity;sid:84788327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925226)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.66.64.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925226/; classtype:trojan-activity;sid:84788326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925225)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.97.255.29"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925225/; classtype:trojan-activity;sid:84788325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925224)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.163.86.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925224/; classtype:trojan-activity;sid:84788324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925223)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.205.191.19"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925223/; classtype:trojan-activity;sid:84788323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925222)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.138.119.35"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925222/; classtype:trojan-activity;sid:84788322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925221)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"213.66.64.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925221/; classtype:trojan-activity;sid:84788321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925220)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.143.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925220/; classtype:trojan-activity;sid:84788320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925218)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.124.55.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925218/; classtype:trojan-activity;sid:84788318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925219)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.180.181.204"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925219/; classtype:trojan-activity;sid:84788319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925216)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.138.119.35"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925216/; classtype:trojan-activity;sid:84788316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925217)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.8.6.179"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925217/; classtype:trojan-activity;sid:84788317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925215)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"115.205.191.19"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925215/; classtype:trojan-activity;sid:84788315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925214)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.163.86.184"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925214/; classtype:trojan-activity;sid:84788314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925213)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.166.165.60"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925213/; classtype:trojan-activity;sid:84788313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925212)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.8.6.179"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925212/; classtype:trojan-activity;sid:84788312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925211)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.141.136.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925211/; classtype:trojan-activity;sid:84788311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925210)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.204.193.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925210/; classtype:trojan-activity;sid:84788310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925209)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.174.0.26"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925209/; classtype:trojan-activity;sid:84788309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925208)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"194.26.220.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925208/; classtype:trojan-activity;sid:84788308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925202)"; flow:established,from_client; content:"GET"; http_method; content:"/arm4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"160.250.181.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925202/; classtype:trojan-activity;sid:84788302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925203)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"160.250.181.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925203/; classtype:trojan-activity;sid:84788303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925204)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"160.250.181.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925204/; classtype:trojan-activity;sid:84788304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925205)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"160.250.181.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925205/; classtype:trojan-activity;sid:84788305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925206)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"160.250.181.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925206/; classtype:trojan-activity;sid:84788306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925207)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"160.250.181.124"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925207/; classtype:trojan-activity;sid:84788307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925199)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.117.112.16"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925199/; classtype:trojan-activity;sid:84788299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925200)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.165.81.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925200/; classtype:trojan-activity;sid:84788300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925201)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.229.165.9"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925201/; classtype:trojan-activity;sid:84788301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925198)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.204.193.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925198/; classtype:trojan-activity;sid:84788298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925197)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"38.137.249.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925197/; classtype:trojan-activity;sid:84788297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925196)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.239.109.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925196/; classtype:trojan-activity;sid:84788296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925195)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.165.81.177"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925195/; classtype:trojan-activity;sid:84788295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925194)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.53.89.172"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925194/; classtype:trojan-activity;sid:84788294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925191)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.237.37.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925191/; classtype:trojan-activity;sid:84788291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925192)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"113.239.243.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925192/; classtype:trojan-activity;sid:84788292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925193)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.47.17.20"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925193/; classtype:trojan-activity;sid:84788293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925190)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.239.109.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925190/; classtype:trojan-activity;sid:84788290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925189)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.179.254.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925189/; classtype:trojan-activity;sid:84788289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925188)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.202.242.64"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925188/; classtype:trojan-activity;sid:84788288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925187)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.7.226.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925187/; classtype:trojan-activity;sid:84788287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925186)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.190.202.144"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925186/; classtype:trojan-activity;sid:84788286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925185)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"125.123.82.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925185/; classtype:trojan-activity;sid:84788285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925182)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.136.87.191"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925182/; classtype:trojan-activity;sid:84788282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925183)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.84.213.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925183/; classtype:trojan-activity;sid:84788283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925184)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.96.141.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925184/; classtype:trojan-activity;sid:84788284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925180)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"138.204.196.244"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925180/; classtype:trojan-activity;sid:84788280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925181)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.194.175"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925181/; classtype:trojan-activity;sid:84788281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925178)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.52.196.15"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925178/; classtype:trojan-activity;sid:84788278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925179)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"59.96.139.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925179/; classtype:trojan-activity;sid:84788279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925176)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.224.94.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925176/; classtype:trojan-activity;sid:84788276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925177)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"113.236.234.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_30; reference:url, urlhaus.abuse.ch/url/3925177/; classtype:trojan-activity;sid:84788277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925135)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.165.228.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925135/; classtype:trojan-activity;sid:84788235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925105)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925105/; classtype:trojan-activity;sid:84788205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925104)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925104/; classtype:trojan-activity;sid:84788204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925081)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"212.86.121.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925081/; classtype:trojan-activity;sid:84788181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925080)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"212.86.121.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925080/; classtype:trojan-activity;sid:84788180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925069)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/5"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925069/; classtype:trojan-activity;sid:84788169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925066)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/2"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925066/; classtype:trojan-activity;sid:84788166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925067)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925067/; classtype:trojan-activity;sid:84788167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925068)"; flow:established,from_client; content:"GET"; http_method; content:"/3"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925068/; classtype:trojan-activity;sid:84788168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925062)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/3"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925062/; classtype:trojan-activity;sid:84788162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925063)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/4"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925063/; classtype:trojan-activity;sid:84788163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925064)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/6"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925064/; classtype:trojan-activity;sid:84788164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925065)"; flow:established,from_client; content:"GET"; http_method; content:"/2"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925065/; classtype:trojan-activity;sid:84788165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925058)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/8"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925058/; classtype:trojan-activity;sid:84788158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925047)"; flow:established,from_client; content:"GET"; http_method; content:"/discordananisikem-pixel/fenasinbasabelasin/releases/download/n/bundle.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925047/; classtype:trojan-activity;sid:84788147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3925008)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"42.58.16.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3925008/; classtype:trojan-activity;sid:84788108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924972)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"211.219.49.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924972/; classtype:trojan-activity;sid:84788072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924968)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.a"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"90.228.239.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924968/; classtype:trojan-activity;sid:84788068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924970)"; flow:established,from_client; content:"GET"; http_method; content:"/adb.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.110.70.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924970/; classtype:trojan-activity;sid:84788070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924951)"; flow:established,from_client; content:"GET"; http_method; content:"/debug.dbg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924951/; classtype:trojan-activity;sid:84788051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924942)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.146.166.29"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924942/; classtype:trojan-activity;sid:84788042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924869)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"123.129.32.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924869/; classtype:trojan-activity;sid:84787969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924820)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"180.76.52.207"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924820/; classtype:trojan-activity;sid:84787920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924807)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"23.95.228.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924807/; classtype:trojan-activity;sid:84787907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924803)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924803/; classtype:trojan-activity;sid:84787903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924804)"; flow:established,from_client; content:"GET"; http_method; content:"/wife.aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"23.95.228.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924804/; classtype:trojan-activity;sid:84787904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924762)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.arm"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924762/; classtype:trojan-activity;sid:84787862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924763)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924763/; classtype:trojan-activity;sid:84787863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924764)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppc"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924764/; classtype:trojan-activity;sid:84787864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924765)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924765/; classtype:trojan-activity;sid:84787865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924766)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.m68k"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924766/; classtype:trojan-activity;sid:84787866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924767)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.ppc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924767/; classtype:trojan-activity;sid:84787867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924768)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924768/; classtype:trojan-activity;sid:84787868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924769)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.mpsl"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924769/; classtype:trojan-activity;sid:84787869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924760)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.x86"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924760/; classtype:trojan-activity;sid:84787860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924761)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.sh4"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924761/; classtype:trojan-activity;sid:84787861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924755)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.mips"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924755/; classtype:trojan-activity;sid:84787855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924756)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/miraint.arm7"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924756/; classtype:trojan-activity;sid:84787856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924757)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924757/; classtype:trojan-activity;sid:84787857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924758)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924758/; classtype:trojan-activity;sid:84787858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924759)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"62.60.227.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924759/; classtype:trojan-activity;sid:84787859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924738)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924738/; classtype:trojan-activity;sid:84787838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924721)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.236.65.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924721/; classtype:trojan-activity;sid:84787821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924711)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.236.65.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924711/; classtype:trojan-activity;sid:84787811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924701)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"123.129.32.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924701/; classtype:trojan-activity;sid:84787801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924676)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.68.95.197"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_29; reference:url, urlhaus.abuse.ch/url/3924676/; classtype:trojan-activity;sid:84787776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924651)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.198.195.68"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924651/; classtype:trojan-activity;sid:84787751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924633)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"112.198.195.68"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924633/; classtype:trojan-activity;sid:84787733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924617)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924617/; classtype:trojan-activity;sid:84787717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924580)"; flow:established,from_client; content:"GET"; http_method; content:"/serhat961/pruva-download/releases/download/v2.0.26/pruvaagent-2.0.26.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924580/; classtype:trojan-activity;sid:84787680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924559)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.160.164"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924559/; classtype:trojan-activity;sid:84787659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924461)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_54b07063281d1e70.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924461/; classtype:trojan-activity;sid:84787561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924420)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924420/; classtype:trojan-activity;sid:84787520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924421)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924421/; classtype:trojan-activity;sid:84787521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924367)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/client-xenon-1.21-26.2.jar"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"xenonclient.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924367/; classtype:trojan-activity;sid:84787467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924360)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.137.134.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924360/; classtype:trojan-activity;sid:84787460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924359)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.173.239.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924359/; classtype:trojan-activity;sid:84787459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924331)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.88.227.19"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924331/; classtype:trojan-activity;sid:84787431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924326)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.x64-test"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924326/; classtype:trojan-activity;sid:84787426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924325)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924325/; classtype:trojan-activity;sid:84787425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924323)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.mipsel"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924323/; classtype:trojan-activity;sid:84787423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924324)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.sh4"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924324/; classtype:trojan-activity;sid:84787424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924318)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm4tl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924318/; classtype:trojan-activity;sid:84787418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924319)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm4l"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924319/; classtype:trojan-activity;sid:84787419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924320)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924320/; classtype:trojan-activity;sid:84787420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924321)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.ppc440"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924321/; classtype:trojan-activity;sid:84787421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924322)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.ppc"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924322/; classtype:trojan-activity;sid:84787422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924315)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm6"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924315/; classtype:trojan-activity;sid:84787415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924316)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.x32"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924316/; classtype:trojan-activity;sid:84787416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924317)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.m68k"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924317/; classtype:trojan-activity;sid:84787417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924314)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.198.224.102"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924314/; classtype:trojan-activity;sid:84787414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924301)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"209.14.28.6"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924301/; classtype:trojan-activity;sid:84787401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924298)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.49.52.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924298/; classtype:trojan-activity;sid:84787398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924289)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"209.14.28.6"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924289/; classtype:trojan-activity;sid:84787389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924269)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924269/; classtype:trojan-activity;sid:84787369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924270)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924270/; classtype:trojan-activity;sid:84787370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924271)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924271/; classtype:trojan-activity;sid:84787371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924272)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924272/; classtype:trojan-activity;sid:84787372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924273)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924273/; classtype:trojan-activity;sid:84787373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924274)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"220.158.234.65"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924274/; classtype:trojan-activity;sid:84787374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924190)"; flow:established,from_client; content:"GET"; http_method; content:"/ssh"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"45.198.224.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924190/; classtype:trojan-activity;sid:84787290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924191)"; flow:established,from_client; content:"GET"; http_method; content:"/encrypted/7za.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"rabbids.cc"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924191/; classtype:trojan-activity;sid:84787291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924189)"; flow:established,from_client; content:"GET"; http_method; content:"/encrypted/1.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"rabbids.cc"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924189/; classtype:trojan-activity;sid:84787289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.236.46.199"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924169/; classtype:trojan-activity;sid:84787269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924081)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.209.84.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924081/; classtype:trojan-activity;sid:84787181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924070)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"79.106.74.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924070/; classtype:trojan-activity;sid:84787170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924068)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"42.58.16.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924068/; classtype:trojan-activity;sid:84787168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3924066)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"79.106.74.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3924066/; classtype:trojan-activity;sid:84787166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923995)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.165.228.242"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_28; reference:url, urlhaus.abuse.ch/url/3923995/; classtype:trojan-activity;sid:84787095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923895)"; flow:established,from_client; content:"GET"; http_method; content:"/ff1.apk"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923895/; classtype:trojan-activity;sid:84786995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923874)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"218.59.14.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923874/; classtype:trojan-activity;sid:84786974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923869)"; flow:established,from_client; content:"GET"; http_method; content:"/odinclient-26.3.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"odinclient.st"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923869/; classtype:trojan-activity;sid:84786969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923870)"; flow:established,from_client; content:"GET"; http_method; content:"/odinclient-26.2.jar"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"odinclient.st"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923870/; classtype:trojan-activity;sid:84786970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923859)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.165.235.139"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923859/; classtype:trojan-activity;sid:84786959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923848)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.194.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923848/; classtype:trojan-activity;sid:84786948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923806)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm8"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923806/; classtype:trojan-activity;sid:84786906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923805)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.armb8"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923805/; classtype:trojan-activity;sid:84786905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923804)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.armb7"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923804/; classtype:trojan-activity;sid:84786904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923803)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm5"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923803/; classtype:trojan-activity;sid:84786903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923785)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppce5"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923785/; classtype:trojan-activity;sid:84786885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923786)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl64r6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923786/; classtype:trojan-activity;sid:84786886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923787)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.xtensa"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923787/; classtype:trojan-activity;sid:84786887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923788)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mblz"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923788/; classtype:trojan-activity;sid:84786888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923789)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl32"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923789/; classtype:trojan-activity;sid:84786889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923790)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mips64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923790/; classtype:trojan-activity;sid:84786890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923791)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.rv32"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923791/; classtype:trojan-activity;sid:84786891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923792)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mblzb"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923792/; classtype:trojan-activity;sid:84786892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923793)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppc64e5"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923793/; classtype:trojan-activity;sid:84786893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923794)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.s390x"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923794/; classtype:trojan-activity;sid:84786894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923795)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923795/; classtype:trojan-activity;sid:84786895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923796)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sparc64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923796/; classtype:trojan-activity;sid:84786896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923797)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.ppc64lp8"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923797/; classtype:trojan-activity;sid:84786897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923798)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mipsl32r6"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923798/; classtype:trojan-activity;sid:84786898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923799)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.rv64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923799/; classtype:trojan-activity;sid:84786899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923800)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.mips32"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923800/; classtype:trojan-activity;sid:84786900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923801)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sparcv8"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923801/; classtype:trojan-activity;sid:84786901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923802)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sh4b"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923802/; classtype:trojan-activity;sid:84786902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923772)"; flow:established,from_client; content:"GET"; http_method; content:"/softwaretech"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"43.228.157.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923772/; classtype:trojan-activity;sid:84786872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923771)"; flow:established,from_client; content:"GET"; http_method; content:"/client.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"43.228.157.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923771/; classtype:trojan-activity;sid:84786871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923769)"; flow:established,from_client; content:"GET"; http_method; content:"/47.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"43.228.157.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923769/; classtype:trojan-activity;sid:84786869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923770)"; flow:established,from_client; content:"GET"; http_method; content:"/99.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"43.228.157.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923770/; classtype:trojan-activity;sid:84786870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923766)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.aarch64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923766/; classtype:trojan-activity;sid:84786866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923764)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.armv7l"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923764/; classtype:trojan-activity;sid:84786864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923759)"; flow:established,from_client; content:"GET"; http_method; content:"/hero.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923759/; classtype:trojan-activity;sid:84786859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923760)"; flow:established,from_client; content:"GET"; http_method; content:"/hero.mipsel"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923760/; classtype:trojan-activity;sid:84786860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923761)"; flow:established,from_client; content:"GET"; http_method; content:"/hero.x86_32"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923761/; classtype:trojan-activity;sid:84786861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923741)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.i686"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923741/; classtype:trojan-activity;sid:84786841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923728)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.i486"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923728/; classtype:trojan-activity;sid:84786828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923729)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.ppc440"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923729/; classtype:trojan-activity;sid:84786829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923730)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923730/; classtype:trojan-activity;sid:84786830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923731)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.mpsl"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923731/; classtype:trojan-activity;sid:84786831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923732)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.arm4"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923732/; classtype:trojan-activity;sid:84786832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923733)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.spc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923733/; classtype:trojan-activity;sid:84786833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923734)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.arm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923734/; classtype:trojan-activity;sid:84786834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923735)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.sh4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923735/; classtype:trojan-activity;sid:84786835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923736)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.m68k"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923736/; classtype:trojan-activity;sid:84786836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923737)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.ppc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923737/; classtype:trojan-activity;sid:84786837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923738)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.arm6"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923738/; classtype:trojan-activity;sid:84786838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923739)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.x86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923739/; classtype:trojan-activity;sid:84786839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923740)"; flow:established,from_client; content:"GET"; http_method; content:"/manji.arm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.137"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923740/; classtype:trojan-activity;sid:84786840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923722)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"88.115.204.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923722/; classtype:trojan-activity;sid:84786822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923698)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"196.251.121.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923698/; classtype:trojan-activity;sid:84786798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923699)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"196.251.121.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923699/; classtype:trojan-activity;sid:84786799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923697)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.229.244.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923697/; classtype:trojan-activity;sid:84786797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923690)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"46.151.182.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923690/; classtype:trojan-activity;sid:84786790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923676)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pppc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923676/; classtype:trojan-activity;sid:84786776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923665)"; flow:established,from_client; content:"GET"; http_method; content:"/a.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"64.89.163.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923665/; classtype:trojan-activity;sid:84786765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923662)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.x86_64"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923662/; classtype:trojan-activity;sid:84786762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923660)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.m68k"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923660/; classtype:trojan-activity;sid:84786760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923661)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.sh4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923661/; classtype:trojan-activity;sid:84786761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923659)"; flow:established,from_client; content:"GET"; http_method; content:"/loader.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"23.94.145.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923659/; classtype:trojan-activity;sid:84786759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923658)"; flow:established,from_client; content:"GET"; http_method; content:"/svchost.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"23.94.145.112"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923658/; classtype:trojan-activity;sid:84786758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923657)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/musl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923657/; classtype:trojan-activity;sid:84786757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923647)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.156.171.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923647/; classtype:trojan-activity;sid:84786747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923639)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.156.171.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923639/; classtype:trojan-activity;sid:84786739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923617)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.173.239.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923617/; classtype:trojan-activity;sid:84786717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923569)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923569/; classtype:trojan-activity;sid:84786669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923565)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"178.16.53.250"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923565/; classtype:trojan-activity;sid:84786665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923567)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.16.53.250"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923567/; classtype:trojan-activity;sid:84786667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923568)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923568/; classtype:trojan-activity;sid:84786668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923546)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"202.110.70.60"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923546/; classtype:trojan-activity;sid:84786646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923541)"; flow:established,from_client; content:"GET"; http_method; content:"/ujnyyodzjazt2491"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"192.162.199.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923541/; classtype:trojan-activity;sid:84786641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923512)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923512/; classtype:trojan-activity;sid:84786612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923513)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923513/; classtype:trojan-activity;sid:84786613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923514)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923514/; classtype:trojan-activity;sid:84786614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923509)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923509/; classtype:trojan-activity;sid:84786609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923510)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"wemqmewkqewq.work.gd"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923510/; classtype:trojan-activity;sid:84786610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923459)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.194.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923459/; classtype:trojan-activity;sid:84786559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923357)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.236.65.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_27; reference:url, urlhaus.abuse.ch/url/3923357/; classtype:trojan-activity;sid:84786457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923347)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.10.99.112"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923347/; classtype:trojan-activity;sid:84786447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923318)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"158.255.83.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923318/; classtype:trojan-activity;sid:84786418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923252)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.156.166.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923252/; classtype:trojan-activity;sid:84786352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923183)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"88.115.204.4"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923183/; classtype:trojan-activity;sid:84786283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923024)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923024/; classtype:trojan-activity;sid:84786124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923033)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923033/; classtype:trojan-activity;sid:84786133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923034)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923034/; classtype:trojan-activity;sid:84786134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923035)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/musl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923035/; classtype:trojan-activity;sid:84786135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923038)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"201.7.16.231"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923038/; classtype:trojan-activity;sid:84786138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923016)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"78.25.123.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923016/; classtype:trojan-activity;sid:84786116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923013)"; flow:established,from_client; content:"GET"; http_method; content:"/f/680apd_597afiqvimxvelw/sfjwmrjy"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"maple30.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923013/; classtype:trojan-activity;sid:84786113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3923006)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.209.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3923006/; classtype:trojan-activity;sid:84786106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922970)"; flow:established,from_client; content:"GET"; http_method; content:"/d/unix98170185"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"109.238.87.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922970/; classtype:trojan-activity;sid:84786070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922953)"; flow:established,from_client; content:"GET"; http_method; content:"/f/680apd_597afiqvimxvelw/sfjwmrjy"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"quillchant14.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922953/; classtype:trojan-activity;sid:84786053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922963)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922963/; classtype:trojan-activity;sid:84786063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922923)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"130.12.209.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922923/; classtype:trojan-activity;sid:84786023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922866)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm6"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922866/; classtype:trojan-activity;sid:84785966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922864)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/px86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922864/; classtype:trojan-activity;sid:84785964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922865)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pspc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922865/; classtype:trojan-activity;sid:84785965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922861)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922861/; classtype:trojan-activity;sid:84785961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922862)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922862/; classtype:trojan-activity;sid:84785962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922863)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmpsl"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922863/; classtype:trojan-activity;sid:84785963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922860)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922860/; classtype:trojan-activity;sid:84785960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922847)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/psh4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922847/; classtype:trojan-activity;sid:84785947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922849)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922849/; classtype:trojan-activity;sid:84785949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922850)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pm68k"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"64.89.160.48"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_26; reference:url, urlhaus.abuse.ch/url/3922850/; classtype:trojan-activity;sid:84785950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922806)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.76.242.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922806/; classtype:trojan-activity;sid:84785906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922799)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"222.243.95.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922799/; classtype:trojan-activity;sid:84785899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922801)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.76.242.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922801/; classtype:trojan-activity;sid:84785901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922690)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.236.44.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922690/; classtype:trojan-activity;sid:84785790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922679)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.236.44.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922679/; classtype:trojan-activity;sid:84785779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922528)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.109.210.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922528/; classtype:trojan-activity;sid:84785628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922505)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.99.250.231"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922505/; classtype:trojan-activity;sid:84785605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922436)"; flow:established,from_client; content:"GET"; http_method; content:"/new.php|3f|type=x86_64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"23.160.56.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922436/; classtype:trojan-activity;sid:84785536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922401)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.71.255.225"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922401/; classtype:trojan-activity;sid:84785501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922387)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.38.19.164"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922387/; classtype:trojan-activity;sid:84785487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922374)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.10.99.112"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_25; reference:url, urlhaus.abuse.ch/url/3922374/; classtype:trojan-activity;sid:84785474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922294)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922294/; classtype:trojan-activity;sid:84785394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922286)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922286/; classtype:trojan-activity;sid:84785386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922265)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.117.143.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922265/; classtype:trojan-activity;sid:84785365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922198)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.1.225.71"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922198/; classtype:trojan-activity;sid:84785298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922158)"; flow:established,from_client; content:"GET"; http_method; content:"/bjsw3dlg1/plugins/clip.dll"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922158/; classtype:trojan-activity;sid:84785258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922147)"; flow:established,from_client; content:"GET"; http_method; content:"/bjsw3dlg1/plugins/clip64.dll"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922147/; classtype:trojan-activity;sid:84785247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922145)"; flow:established,from_client; content:"GET"; http_method; content:"/bjsw3dlg1/plugins/cred.dll"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922145/; classtype:trojan-activity;sid:84785245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922146)"; flow:established,from_client; content:"GET"; http_method; content:"/bjsw3dlg1/plugins/cred64.dll"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922146/; classtype:trojan-activity;sid:84785246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922138)"; flow:established,from_client; content:"GET"; http_method; content:"/img_095017.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"pub-0216fa08b2b94e129cb9e002cf7cb1f4.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922138/; classtype:trojan-activity;sid:84785238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922136)"; flow:established,from_client; content:"GET"; http_method; content:"/pictures/2.jpg"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"64.224.17.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922136/; classtype:trojan-activity;sid:84785236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922124)"; flow:established,from_client; content:"GET"; http_method; content:"/ringeklokkes.aaf"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"urbanpro.mycpanel.rs"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922124/; classtype:trojan-activity;sid:84785224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922123)"; flow:established,from_client; content:"GET"; http_method; content:"/ucpnx9.bin"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"urbanpro.mycpanel.rs"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922123/; classtype:trojan-activity;sid:84785223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922081)"; flow:established,from_client; content:"GET"; http_method; content:"/wielixclient-26.3.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"wielixclient.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922081/; classtype:trojan-activity;sid:84785181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922061)"; flow:established,from_client; content:"GET"; http_method; content:"/skyblockaddons-26.3.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"skyblock-addons.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922061/; classtype:trojan-activity;sid:84785161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922069)"; flow:established,from_client; content:"GET"; http_method; content:"/luminex-client-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"luminexclient.net"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922069/; classtype:trojan-activity;sid:84785169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922070)"; flow:established,from_client; content:"GET"; http_method; content:"/wielixclient-26.2.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"wielixclient.net"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922070/; classtype:trojan-activity;sid:84785170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3922059)"; flow:established,from_client; content:"GET"; http_method; content:"/floppaclient-26.3.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"floppaclient.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3922059/; classtype:trojan-activity;sid:84785159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921946)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.156.166.84"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3921946/; classtype:trojan-activity;sid:84785046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921936)"; flow:established,from_client; content:"GET"; http_method; content:"/img_003307.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"romeopirlanta.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3921936/; classtype:trojan-activity;sid:84785036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921821)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"39.75.161.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_24; reference:url, urlhaus.abuse.ch/url/3921821/; classtype:trojan-activity;sid:84784921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921792)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"85.15.114.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921792/; classtype:trojan-activity;sid:84784892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921784)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.15.114.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921784/; classtype:trojan-activity;sid:84784884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921690)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonagent.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"pub-43fc211373d547278dd3d5bd0b4d9dac.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921690/; classtype:trojan-activity;sid:84784790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921621)"; flow:established,from_client; content:"GET"; http_method; content:"/img_095912.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"romeopirlanta.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921621/; classtype:trojan-activity;sid:84784721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921561)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.153.207.91"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921561/; classtype:trojan-activity;sid:84784661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921554)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"212.192.14.116"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921554/; classtype:trojan-activity;sid:84784654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921412)"; flow:established,from_client; content:"GET"; http_method; content:"/a/xurowh.vmp.msi"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"makemewin.club"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921412/; classtype:trojan-activity;sid:84784512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921344)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"81.227.54.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921344/; classtype:trojan-activity;sid:84784444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921348)"; flow:established,from_client; content:"GET"; http_method; content:"/zxc/app.zip"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"delta-canvas.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921348/; classtype:trojan-activity;sid:84784448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921293)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.236.65.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_23; reference:url, urlhaus.abuse.ch/url/3921293/; classtype:trojan-activity;sid:84784393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921167)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.231.145.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3921167/; classtype:trojan-activity;sid:84784267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921156)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"77.53.231.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3921156/; classtype:trojan-activity;sid:84784256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921075)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"helpdesk09-26.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3921075/; classtype:trojan-activity;sid:84784175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921042)"; flow:established,from_client; content:"GET"; http_method; content:"/administrator/ognltimg_051814.png"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"adcentral.com.mx"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3921042/; classtype:trojan-activity;sid:84784142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3921010)"; flow:established,from_client; content:"GET"; http_method; content:"/img_163520.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"obearo.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3921010/; classtype:trojan-activity;sid:84784110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920998)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"185.99.135.134"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920998/; classtype:trojan-activity;sid:84784098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920965)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"68.195.40.192"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920965/; classtype:trojan-activity;sid:84784065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920916)"; flow:established,from_client; content:"GET"; http_method; content:"/namenajaee-afk/dongdowbadowyaeee/raw/refs/heads/main/likely.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920916/; classtype:trojan-activity;sid:84784016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920914)"; flow:established,from_client; content:"GET"; http_method; content:"/namenajaee-afk/dongdowbadowyaeee/raw/refs/heads/main/client.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920914/; classtype:trojan-activity;sid:84784014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920906)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/julyendingapama.firebasestorage.app/o/slim.png|3f|alt=media|7c|26|7c|token=c28e3a19-7fb3-443a-88fb-2e3b8a77b454"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920906/; classtype:trojan-activity;sid:84784006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920894)"; flow:established,from_client; content:"GET"; http_method; content:"/axelancexld/axelancexld/refs/heads/main/educational"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920894/; classtype:trojan-activity;sid:84783994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920890)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920890/; classtype:trojan-activity;sid:84783990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920819)"; flow:established,from_client; content:"GET"; http_method; content:"/shell.bat"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"102.220.161.39"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920819/; classtype:trojan-activity;sid:84783919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920814)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"130.12.181.99"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920814/; classtype:trojan-activity;sid:84783914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920811)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"130.12.181.99"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920811/; classtype:trojan-activity;sid:84783911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920798)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"photolivebook.pro"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920798/; classtype:trojan-activity;sid:84783898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920780)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.191.42.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920780/; classtype:trojan-activity;sid:84783880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920774)"; flow:established,from_client; content:"GET"; http_method; content:"/watcher-script/aarch64"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920774/; classtype:trojan-activity;sid:84783874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920402)"; flow:established,from_client; content:"GET"; http_method; content:"/m.armv5l"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"40.90.202.134"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920402/; classtype:trojan-activity;sid:84783502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920362)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"154.126.186.59"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920362/; classtype:trojan-activity;sid:84783462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920339)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.231.145.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920339/; classtype:trojan-activity;sid:84783439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920336)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.236.65.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_22; reference:url, urlhaus.abuse.ch/url/3920336/; classtype:trojan-activity;sid:84783436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920313)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"68.195.40.192"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3920313/; classtype:trojan-activity;sid:84783413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920253)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.59.107.34"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3920253/; classtype:trojan-activity;sid:84783353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920249)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.226.171.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3920249/; classtype:trojan-activity;sid:84783349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920243)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"114.226.171.203"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3920243/; classtype:trojan-activity;sid:84783343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920029)"; flow:established,from_client; content:"GET"; http_method; content:"/ugd/09c1d5_535e18f9f54e47a8a4f9587ce3e9a710.txt"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"download-files.wixmp.com"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3920029/; classtype:trojan-activity;sid:84783129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3920026)"; flow:established,from_client; content:"GET"; http_method; content:"/dred"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"192.227.210.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3920026/; classtype:trojan-activity;sid:84783126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919984)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_c5b0b8f9b84a1473.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3919984/; classtype:trojan-activity;sid:84783084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919726)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.75.161.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3919726/; classtype:trojan-activity;sid:84782826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919692)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.217.161.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3919692/; classtype:trojan-activity;sid:84782792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919680)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.217.161.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3919680/; classtype:trojan-activity;sid:84782780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919561)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.59.107.34"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3919561/; classtype:trojan-activity;sid:84782661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919485)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"112.248.102.140"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_21; reference:url, urlhaus.abuse.ch/url/3919485/; classtype:trojan-activity;sid:84782585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919359)"; flow:established,from_client; content:"GET"; http_method; content:"/opsec-mod-fabric-26.2.jar"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"opsecmod.st"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_20; reference:url, urlhaus.abuse.ch/url/3919359/; classtype:trojan-activity;sid:84782459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919361)"; flow:established,from_client; content:"GET"; http_method; content:"/prestigeloader-1.21.11-v1.5.5.jar"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"prestigeclient.st"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_20; reference:url, urlhaus.abuse.ch/url/3919361/; classtype:trojan-activity;sid:84782461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919358)"; flow:established,from_client; content:"GET"; http_method; content:"/prestigeloader-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"prestigeclient.st"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_20; reference:url, urlhaus.abuse.ch/url/3919358/; classtype:trojan-activity;sid:84782458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919297)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.216.199.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_20; reference:url, urlhaus.abuse.ch/url/3919297/; classtype:trojan-activity;sid:84782397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919108)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919108/; classtype:trojan-activity;sid:84782208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919109)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919109/; classtype:trojan-activity;sid:84782209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919104)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mpsl"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919104/; classtype:trojan-activity;sid:84782204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919105)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919105/; classtype:trojan-activity;sid:84782205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919106)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"45.74.3.24"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919106/; classtype:trojan-activity;sid:84782206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919056)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.42.33.36"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919056/; classtype:trojan-activity;sid:84782156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919052)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.42.33.36"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919052/; classtype:trojan-activity;sid:84782152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919026)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"95.54.82.154"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919026/; classtype:trojan-activity;sid:84782126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919022)"; flow:established,from_client; content:"GET"; http_method; content:"/link/update.msi"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"fileupdates.blob.core.windows.net"; http_host; depth:33; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919022/; classtype:trojan-activity;sid:84782122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3919019)"; flow:established,from_client; content:"GET"; http_method; content:"/taunahiloader-26.3.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"taunahi.st"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3919019/; classtype:trojan-activity;sid:84782119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918987)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"60.216.121.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918987/; classtype:trojan-activity;sid:84782087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918942)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"60.216.121.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918942/; classtype:trojan-activity;sid:84782042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918925)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"95.155.243.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918925/; classtype:trojan-activity;sid:84782025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918926)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.155.243.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918926/; classtype:trojan-activity;sid:84782026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918811)"; flow:established,from_client; content:"GET"; http_method; content:"/s.bat"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.56.209.11"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918811/; classtype:trojan-activity;sid:84781911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918806)"; flow:established,from_client; content:"GET"; http_method; content:"/pure.dat"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"31.56.209.11"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918806/; classtype:trojan-activity;sid:84781906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918809)"; flow:established,from_client; content:"GET"; http_method; content:"/svc.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"31.56.209.11"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_19; reference:url, urlhaus.abuse.ch/url/3918809/; classtype:trojan-activity;sid:84781909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918722)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918722/; classtype:trojan-activity;sid:84781822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918709)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918709/; classtype:trojan-activity;sid:84781809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918679)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918679/; classtype:trojan-activity;sid:84781779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918610)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918610/; classtype:trojan-activity;sid:84781710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918611)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918611/; classtype:trojan-activity;sid:84781711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918612)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918612/; classtype:trojan-activity;sid:84781712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918613)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918613/; classtype:trojan-activity;sid:84781713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918614)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918614/; classtype:trojan-activity;sid:84781714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918615)"; flow:established,from_client; content:"GET"; http_method; content:"/sparc"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918615/; classtype:trojan-activity;sid:84781715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918616)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918616/; classtype:trojan-activity;sid:84781716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918617)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918617/; classtype:trojan-activity;sid:84781717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918618)"; flow:established,from_client; content:"GET"; http_method; content:"/arm4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918618/; classtype:trojan-activity;sid:84781718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918619)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918619/; classtype:trojan-activity;sid:84781719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918620)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918620/; classtype:trojan-activity;sid:84781720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918500)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.54.82.154"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918500/; classtype:trojan-activity;sid:84781600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918391)"; flow:established,from_client; content:"GET"; http_method; content:"/telnetd"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918391/; classtype:trojan-activity;sid:84781491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918351)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.210.89.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918351/; classtype:trojan-activity;sid:84781451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918350)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.210.89.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_18; reference:url, urlhaus.abuse.ch/url/3918350/; classtype:trojan-activity;sid:84781450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918303)"; flow:established,from_client; content:"GET"; http_method; content:"/sh"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918303/; classtype:trojan-activity;sid:84781403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918304)"; flow:established,from_client; content:"GET"; http_method; content:"/ftp"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918304/; classtype:trojan-activity;sid:84781404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918305)"; flow:established,from_client; content:"GET"; http_method; content:"/cron"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918305/; classtype:trojan-activity;sid:84781405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918306)"; flow:established,from_client; content:"GET"; http_method; content:"/bash"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918306/; classtype:trojan-activity;sid:84781406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918307)"; flow:established,from_client; content:"GET"; http_method; content:"/pftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918307/; classtype:trojan-activity;sid:84781407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918308)"; flow:established,from_client; content:"GET"; http_method; content:"/apache2"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918308/; classtype:trojan-activity;sid:84781408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918309)"; flow:established,from_client; content:"GET"; http_method; content:"/ntpd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918309/; classtype:trojan-activity;sid:84781409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918310)"; flow:established,from_client; content:"GET"; http_method; content:"/wget"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918310/; classtype:trojan-activity;sid:84781410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918311)"; flow:established,from_client; content:"GET"; http_method; content:"/openssh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918311/; classtype:trojan-activity;sid:84781411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918312)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"146.19.198.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918312/; classtype:trojan-activity;sid:84781412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918248)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/julyendingapama.firebasestorage.app/o/kingjoo.png|3f|alt=media|7c|26|7c|token=36145a21-d722-4709-9287-f8d67e90830a"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918248/; classtype:trojan-activity;sid:84781348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918244)"; flow:established,from_client; content:"GET"; http_method; content:"/128/img_032911.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"204.44.93.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918244/; classtype:trojan-activity;sid:84781344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918213)"; flow:established,from_client; content:"GET"; http_method; content:"/pin.png"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"pub-45a83f302a1943ed8d62418c2af947ef.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918213/; classtype:trojan-activity;sid:84781313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918210)"; flow:established,from_client; content:"GET"; http_method; content:"/5.jpg"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"64.89.160.97"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918210/; classtype:trojan-activity;sid:84781310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918140)"; flow:established,from_client; content:"GET"; http_method; content:"/rany2/warp.sh/master/warp.sh"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918140/; classtype:trojan-activity;sid:84781240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918141)"; flow:established,from_client; content:"GET"; http_method; content:"/praiman99/certificate-openvpn-mod/beginner/vpn.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918141/; classtype:trojan-activity;sid:84781241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918142)"; flow:established,from_client; content:"GET"; http_method; content:"/praiman99/autoscriptvpn-aio/beginner/rclone.conf"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918142/; classtype:trojan-activity;sid:84781242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918130)"; flow:established,from_client; content:"GET"; http_method; content:"/mrshahnawazyt/autoscript-1.13/refs/heads/master/setup.sh"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918130/; classtype:trojan-activity;sid:84781230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918126)"; flow:established,from_client; content:"GET"; http_method; content:"/praiman99/plugin-fn/raw/beginner/plugin.sh"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918126/; classtype:trojan-activity;sid:84781226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3918127)"; flow:established,from_client; content:"GET"; http_method; content:"/powermx/badvpn/master/badvpn-udpgw"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_09_17; reference:url, urlhaus.abuse.ch/url/3918127/; classtype:trojan-activity;sid:84781227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917776)"; flow:established,from_client; content:"GET"; http_method; content:"/api/static/index.js"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"windowsdiagnostics.st"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917776/; classtype:trojan-activity;sid:84780876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917639)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/dbg"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917639/; classtype:trojan-activity;sid:84780739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917638)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917638/; classtype:trojan-activity;sid:84780738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917636)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917636/; classtype:trojan-activity;sid:84780736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917635)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917635/; classtype:trojan-activity;sid:84780735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917621)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917621/; classtype:trojan-activity;sid:84780721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917622)"; flow:established,from_client; content:"GET"; http_method; content:"/main_spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917622/; classtype:trojan-activity;sid:84780722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917623)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x64"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917623/; classtype:trojan-activity;sid:84780723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917624)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917624/; classtype:trojan-activity;sid:84780724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917625)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917625/; classtype:trojan-activity;sid:84780725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917626)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917626/; classtype:trojan-activity;sid:84780726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917627)"; flow:established,from_client; content:"GET"; http_method; content:"/main_ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917627/; classtype:trojan-activity;sid:84780727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917628)"; flow:established,from_client; content:"GET"; http_method; content:"/main_m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917628/; classtype:trojan-activity;sid:84780728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917629)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917629/; classtype:trojan-activity;sid:84780729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917630)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917630/; classtype:trojan-activity;sid:84780730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917631)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917631/; classtype:trojan-activity;sid:84780731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917632)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917632/; classtype:trojan-activity;sid:84780732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917633)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917633/; classtype:trojan-activity;sid:84780733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917634)"; flow:established,from_client; content:"GET"; http_method; content:"/main_sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917634/; classtype:trojan-activity;sid:84780734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917593)"; flow:established,from_client; content:"GET"; http_method; content:"/ohshit.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917593/; classtype:trojan-activity;sid:84780693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917550)"; flow:established,from_client; content:"GET"; http_method; content:"/bot"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917550/; classtype:trojan-activity;sid:84780650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917551)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917551/; classtype:trojan-activity;sid:84780651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917548)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917548/; classtype:trojan-activity;sid:84780648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917549)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917549/; classtype:trojan-activity;sid:84780649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917547)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917547/; classtype:trojan-activity;sid:84780647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917542)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917542/; classtype:trojan-activity;sid:84780642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917544)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917544/; classtype:trojan-activity;sid:84780644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917545)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917545/; classtype:trojan-activity;sid:84780645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917540)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mipsel"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917540/; classtype:trojan-activity;sid:84780640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917539)"; flow:established,from_client; content:"GET"; http_method; content:"/win.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917539/; classtype:trojan-activity;sid:84780639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917477)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"61.69.169.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917477/; classtype:trojan-activity;sid:84780577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917337)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/gnome"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917337/; classtype:trojan-activity;sid:84780437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917338)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/ext4"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917338/; classtype:trojan-activity;sid:84780438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917329)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/kernal"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917329/; classtype:trojan-activity;sid:84780429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917330)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/systemd"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917330/; classtype:trojan-activity;sid:84780430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917331)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/watchdogd"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917331/; classtype:trojan-activity;sid:84780431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917332)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/ntpd"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917332/; classtype:trojan-activity;sid:84780432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917333)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/sshd"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917333/; classtype:trojan-activity;sid:84780433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917334)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/bash"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917334/; classtype:trojan-activity;sid:84780434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917335)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/getty"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917335/; classtype:trojan-activity;sid:84780435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917336)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/ntp"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917336/; classtype:trojan-activity;sid:84780436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917310)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/1"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917310/; classtype:trojan-activity;sid:84780410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917296)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917296/; classtype:trojan-activity;sid:84780396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917297)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_aarch64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917297/; classtype:trojan-activity;sid:84780397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917298)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_386"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917298/; classtype:trojan-activity;sid:84780398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917299)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917299/; classtype:trojan-activity;sid:84780399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917300)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917300/; classtype:trojan-activity;sid:84780400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917301)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips64el"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917301/; classtype:trojan-activity;sid:84780401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917293)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm6"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917293/; classtype:trojan-activity;sid:84780393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917294)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_amd64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917294/; classtype:trojan-activity;sid:84780394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917295)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917295/; classtype:trojan-activity;sid:84780395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917259)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/handshakebins.sh"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917259/; classtype:trojan-activity;sid:84780359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917255)"; flow:established,from_client; content:"GET"; http_method; content:"/polarclient-cracked-26.2.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"polarclient.net"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917255/; classtype:trojan-activity;sid:84780355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917254)"; flow:established,from_client; content:"GET"; http_method; content:"/skyblockaddons-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"skyblock-addons.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917254/; classtype:trojan-activity;sid:84780354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917241)"; flow:established,from_client; content:"GET"; http_method; content:"/phantom-client-26.2.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"phantom-client.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917241/; classtype:trojan-activity;sid:84780341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917243)"; flow:established,from_client; content:"GET"; http_method; content:"/polinex-fabric-1.21.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"polinexclient.org"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917243/; classtype:trojan-activity;sid:84780343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917247)"; flow:established,from_client; content:"GET"; http_method; content:"/22qq-client-1.21.11.jar"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"22qq-client.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917247/; classtype:trojan-activity;sid:84780347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917235)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/telnetd"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917235/; classtype:trojan-activity;sid:84780335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917236)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/kworker"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917236/; classtype:trojan-activity;sid:84780336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917239)"; flow:established,from_client; content:"GET"; http_method; content:"/nokillbins/telnet"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917239/; classtype:trojan-activity;sid:84780339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917228)"; flow:established,from_client; content:"GET"; http_method; content:"/api/static/loading"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"windowsdiagnostics.st"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917228/; classtype:trojan-activity;sid:84780328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917229)"; flow:established,from_client; content:"GET"; http_method; content:"/meteor_client-1.21.11-53.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"meteorclients.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917229/; classtype:trojan-activity;sid:84780329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917225)"; flow:established,from_client; content:"GET"; http_method; content:"/invmove-fabric-1.21.11-v0.9.3.jar"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"invmove.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917225/; classtype:trojan-activity;sid:84780325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917218)"; flow:established,from_client; content:"GET"; http_method; content:"/marlowclient-26.2.jar"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"marlowclient.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917218/; classtype:trojan-activity;sid:84780318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917219)"; flow:established,from_client; content:"GET"; http_method; content:"/198-macros-cracked-v1.4.0.jar"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"198-macros.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917219/; classtype:trojan-activity;sid:84780319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917221)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/kryptonclient-crack.jar"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"kryptonclientcrack.lovable.app"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917221/; classtype:trojan-activity;sid:84780321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917214)"; flow:established,from_client; content:"GET"; http_method; content:"/debugify-1.21.11.jar"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"debugify.net"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_16; reference:url, urlhaus.abuse.ch/url/3917214/; classtype:trojan-activity;sid:84780314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917109)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/1"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.137.54.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917109/; classtype:trojan-activity;sid:84780209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917090)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917090/; classtype:trojan-activity;sid:84780190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917091)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917091/; classtype:trojan-activity;sid:84780191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917083)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917083/; classtype:trojan-activity;sid:84780183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917084)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917084/; classtype:trojan-activity;sid:84780184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917085)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.mpsl"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917085/; classtype:trojan-activity;sid:84780185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917086)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917086/; classtype:trojan-activity;sid:84780186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917087)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.spc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917087/; classtype:trojan-activity;sid:84780187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917089)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.ppc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917089/; classtype:trojan-activity;sid:84780189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917068)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917068/; classtype:trojan-activity;sid:84780168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917069)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917069/; classtype:trojan-activity;sid:84780169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917070)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sora.arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"176.65.139.217"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917070/; classtype:trojan-activity;sid:84780170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917012)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"175.11.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917012/; classtype:trojan-activity;sid:84780112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3917009)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"175.11.53.167"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3917009/; classtype:trojan-activity;sid:84780109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916940)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.148.148.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916940/; classtype:trojan-activity;sid:84780040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916781)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916781/; classtype:trojan-activity;sid:84779881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916782)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916782/; classtype:trojan-activity;sid:84779882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916737)"; flow:established,from_client; content:"GET"; http_method; content:"/getty"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916737/; classtype:trojan-activity;sid:84779837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916738)"; flow:established,from_client; content:"GET"; http_method; content:"/ntp"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916738/; classtype:trojan-activity;sid:84779838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916727)"; flow:established,from_client; content:"GET"; http_method; content:"/gnome"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916727/; classtype:trojan-activity;sid:84779827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916720)"; flow:established,from_client; content:"GET"; http_method; content:"/systemd"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916720/; classtype:trojan-activity;sid:84779820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916721)"; flow:established,from_client; content:"GET"; http_method; content:"/kernal"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916721/; classtype:trojan-activity;sid:84779821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916722)"; flow:established,from_client; content:"GET"; http_method; content:"/ntpd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916722/; classtype:trojan-activity;sid:84779822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916723)"; flow:established,from_client; content:"GET"; http_method; content:"/watchdogd"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916723/; classtype:trojan-activity;sid:84779823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916724)"; flow:established,from_client; content:"GET"; http_method; content:"/bash"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916724/; classtype:trojan-activity;sid:84779824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916725)"; flow:established,from_client; content:"GET"; http_method; content:"/ext4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916725/; classtype:trojan-activity;sid:84779825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916675)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916675/; classtype:trojan-activity;sid:84779775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916668)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ipmiv2.xml"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916668/; classtype:trojan-activity;sid:84779768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916670)"; flow:established,from_client; content:"GET"; http_method; content:"/w.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916670/; classtype:trojan-activity;sid:84779770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916674)"; flow:established,from_client; content:"GET"; http_method; content:"/c.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.251"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916674/; classtype:trojan-activity;sid:84779774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916598)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916598/; classtype:trojan-activity;sid:84779698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916599)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/i686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916599/; classtype:trojan-activity;sid:84779699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916600)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916600/; classtype:trojan-activity;sid:84779700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916590)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916590/; classtype:trojan-activity;sid:84779690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916591)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916591/; classtype:trojan-activity;sid:84779691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916592)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916592/; classtype:trojan-activity;sid:84779692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916593)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916593/; classtype:trojan-activity;sid:84779693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916584)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916584/; classtype:trojan-activity;sid:84779684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916587)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916587/; classtype:trojan-activity;sid:84779687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916571)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916571/; classtype:trojan-activity;sid:84779671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916578)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916578/; classtype:trojan-activity;sid:84779678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916579)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_15; reference:url, urlhaus.abuse.ch/url/3916579/; classtype:trojan-activity;sid:84779679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916522)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/julyendingapama.firebasestorage.app/o/img_092159.png|3f|alt=media|7c|26|7c|token=930852e2-f86f-4478-8b58-ec8f3ab5c5e5"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916522/; classtype:trojan-activity;sid:84779622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916493)"; flow:established,from_client; content:"GET"; http_method; content:"/lai.y"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"lai-1451610695.cos.ap-guangzhou.myqcloud.com"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916493/; classtype:trojan-activity;sid:84779593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916482)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/9z7bgnrgpgs8czv7.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916482/; classtype:trojan-activity;sid:84779582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916480)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/gm9anpouznkx8zhj.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916480/; classtype:trojan-activity;sid:84779580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916481)"; flow:established,from_client; content:"GET"; http_method; content:"/|3f|h=222.112.70.149|7c|26|7c|p=8084|7c|26|7c|t=ws|7c|26|7c|a=w32|7c|26|7c|stage=true"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"222.112.70.149"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916481/; classtype:trojan-activity;sid:84779581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916479)"; flow:established,from_client; content:"GET"; http_method; content:"/m3/controller.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916479/; classtype:trojan-activity;sid:84779579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916477)"; flow:established,from_client; content:"GET"; http_method; content:"/adobe_updater%20.msi"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"thankful-cliff-01dfec010.7.azurestaticapps.net"; http_host; depth:46; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916477/; classtype:trojan-activity;sid:84779577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916472)"; flow:established,from_client; content:"GET"; http_method; content:"/static/reciever1.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"talkandtypeapp.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916472/; classtype:trojan-activity;sid:84779572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916464)"; flow:established,from_client; content:"GET"; http_method; content:"/img/msi_pro_latest.png"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"69.12.83.176"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916464/; classtype:trojan-activity;sid:84779564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916465)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/6eq5gvofrvnmci54.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916465/; classtype:trojan-activity;sid:84779565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916460)"; flow:established,from_client; content:"GET"; http_method; content:"/__l5e/assets-v1/f9eec8e0-95ce-4178-b709-6136c6e6321b/v4mp-tweakz-launcher.exe"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"tweakz-dream-launcher.lovable.app"; http_host; depth:33; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916460/; classtype:trojan-activity;sid:84779560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916461)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/mkm65cf6qnqeovw9.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916461/; classtype:trojan-activity;sid:84779561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916427)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"themaintechnician.us"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916427/; classtype:trojan-activity;sid:84779527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916387)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"61.69.169.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916387/; classtype:trojan-activity;sid:84779487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916188)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916188/; classtype:trojan-activity;sid:84779288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916127)"; flow:established,from_client; content:"GET"; http_method; content:"/meteor-rejects-addon-1.21.11.jar"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"meteorrejects.net"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916127/; classtype:trojan-activity;sid:84779227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916124)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916124/; classtype:trojan-activity;sid:84779224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916096)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916096/; classtype:trojan-activity;sid:84779196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916091)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916091/; classtype:trojan-activity;sid:84779191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916092)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/i686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_14; reference:url, urlhaus.abuse.ch/url/3916092/; classtype:trojan-activity;sid:84779192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916061)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/kla.sh"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916061/; classtype:trojan-activity;sid:84779161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916059)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.i486"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916059/; classtype:trojan-activity;sid:84779159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916046)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.arc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916046/; classtype:trojan-activity;sid:84779146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916047)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.x86_64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916047/; classtype:trojan-activity;sid:84779147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916048)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.arm5"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916048/; classtype:trojan-activity;sid:84779148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916049)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.ppc"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916049/; classtype:trojan-activity;sid:84779149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916050)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.arm"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916050/; classtype:trojan-activity;sid:84779150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916051)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.sh4"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916051/; classtype:trojan-activity;sid:84779151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916052)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.m68k"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916052/; classtype:trojan-activity;sid:84779152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916053)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.mips"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916053/; classtype:trojan-activity;sid:84779153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916054)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.x86"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916054/; classtype:trojan-activity;sid:84779154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916055)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.i686"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916055/; classtype:trojan-activity;sid:84779155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916056)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.arm7"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916056/; classtype:trojan-activity;sid:84779156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916057)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.arm6"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916057/; classtype:trojan-activity;sid:84779157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916058)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/net.mpsl"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"160.119.66.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916058/; classtype:trojan-activity;sid:84779158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916016)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916016/; classtype:trojan-activity;sid:84779116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916009)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916009/; classtype:trojan-activity;sid:84779109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3916011)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3916011/; classtype:trojan-activity;sid:84779111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915996)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915996/; classtype:trojan-activity;sid:84779096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915997)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915997/; classtype:trojan-activity;sid:84779097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915991)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915991/; classtype:trojan-activity;sid:84779091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915992)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915992/; classtype:trojan-activity;sid:84779092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915993)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915993/; classtype:trojan-activity;sid:84779093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915990)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.248.149"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915990/; classtype:trojan-activity;sid:84779090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915889)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.148.148.89"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915889/; classtype:trojan-activity;sid:84778989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915819)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.215.121.8"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915819/; classtype:trojan-activity;sid:84778919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915797)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.102.208.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915797/; classtype:trojan-activity;sid:84778897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915793)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"117.102.208.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_13; reference:url, urlhaus.abuse.ch/url/3915793/; classtype:trojan-activity;sid:84778893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915613)"; flow:established,from_client; content:"GET"; http_method; content:"/wget.sh"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"120.193.219.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_12; reference:url, urlhaus.abuse.ch/url/3915613/; classtype:trojan-activity;sid:84778713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915576)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"85.105.125.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_12; reference:url, urlhaus.abuse.ch/url/3915576/; classtype:trojan-activity;sid:84778676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915577)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.105.125.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_12; reference:url, urlhaus.abuse.ch/url/3915577/; classtype:trojan-activity;sid:84778677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915493)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"120.28.166.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_12; reference:url, urlhaus.abuse.ch/url/3915493/; classtype:trojan-activity;sid:84778593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915444)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_e52c89b6e6519b51.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_12; reference:url, urlhaus.abuse.ch/url/3915444/; classtype:trojan-activity;sid:84778544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915327)"; flow:established,from_client; content:"GET"; http_method; content:"/files/gold/file.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_11; reference:url, urlhaus.abuse.ch/url/3915327/; classtype:trojan-activity;sid:84778427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915309)"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/msvsmon.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"cid.gov.so"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_09_11; reference:url, urlhaus.abuse.ch/url/3915309/; classtype:trojan-activity;sid:84778409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3915289)"; flow:established,from_client; content:"GET"; http_method; content:"/2.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_11; reference:url, urlhaus.abuse.ch/url/3915289/; classtype:trojan-activity;sid:84778389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914995)"; flow:established,from_client; content:"GET"; http_method; content:"/moot.arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"38.55.99.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914995/; classtype:trojan-activity;sid:84778095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914994)"; flow:established,from_client; content:"GET"; http_method; content:"/moot.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"38.55.99.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914994/; classtype:trojan-activity;sid:84778094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914993)"; flow:established,from_client; content:"GET"; http_method; content:"/moot.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"38.55.99.215"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914993/; classtype:trojan-activity;sid:84778093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914992)"; flow:established,from_client; content:"GET"; http_method; content:"/mc_bypass.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914992/; classtype:trojan-activity;sid:84778092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914976)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914976/; classtype:trojan-activity;sid:84778076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914977)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_vps.mips"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914977/; classtype:trojan-activity;sid:84778077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914978)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_vps.arm5"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914978/; classtype:trojan-activity;sid:84778078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914979)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914979/; classtype:trojan-activity;sid:84778079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914980)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mipsel"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914980/; classtype:trojan-activity;sid:84778080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914981)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_vps.arm7"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914981/; classtype:trojan-activity;sid:84778081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914982)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.x86_64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914982/; classtype:trojan-activity;sid:84778082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914983)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914983/; classtype:trojan-activity;sid:84778083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914984)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_vps.x86_64"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914984/; classtype:trojan-activity;sid:84778084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914985)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_vps.arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914985/; classtype:trojan-activity;sid:84778085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914986)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.arm64"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914986/; classtype:trojan-activity;sid:84778086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914987)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_vps.mpsl"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914987/; classtype:trojan-activity;sid:84778087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914975)"; flow:established,from_client; content:"GET"; http_method; content:"/serve/ovhkill.sh"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"129.159.135.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914975/; classtype:trojan-activity;sid:84778075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914973)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914973/; classtype:trojan-activity;sid:84778073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914974)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914974/; classtype:trojan-activity;sid:84778074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914970)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914970/; classtype:trojan-activity;sid:84778070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914971)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914971/; classtype:trojan-activity;sid:84778071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914972)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914972/; classtype:trojan-activity;sid:84778072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914968)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914968/; classtype:trojan-activity;sid:84778068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914969)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914969/; classtype:trojan-activity;sid:84778069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914962)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.spc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914962/; classtype:trojan-activity;sid:84778062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914963)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914963/; classtype:trojan-activity;sid:84778063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914964)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914964/; classtype:trojan-activity;sid:84778064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914965)"; flow:established,from_client; content:"GET"; http_method; content:"/main_ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914965/; classtype:trojan-activity;sid:84778065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914967)"; flow:established,from_client; content:"GET"; http_method; content:"/main_sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914967/; classtype:trojan-activity;sid:84778067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914959)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914959/; classtype:trojan-activity;sid:84778059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914960)"; flow:established,from_client; content:"GET"; http_method; content:"/main_m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914960/; classtype:trojan-activity;sid:84778060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914961)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.arm64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914961/; classtype:trojan-activity;sid:84778061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914950)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914950/; classtype:trojan-activity;sid:84778050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914951)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914951/; classtype:trojan-activity;sid:84778051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914952)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914952/; classtype:trojan-activity;sid:84778052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914953)"; flow:established,from_client; content:"GET"; http_method; content:"/main_x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914953/; classtype:trojan-activity;sid:84778053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914954)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914954/; classtype:trojan-activity;sid:84778054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914955)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914955/; classtype:trojan-activity;sid:84778055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914956)"; flow:established,from_client; content:"GET"; http_method; content:"/main_mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914956/; classtype:trojan-activity;sid:84778056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914957)"; flow:established,from_client; content:"GET"; http_method; content:"/main_arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914957/; classtype:trojan-activity;sid:84778057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914958)"; flow:established,from_client; content:"GET"; http_method; content:"/sora.arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"2.27.203.59"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914958/; classtype:trojan-activity;sid:84778058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914830)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"117.20.227.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_10; reference:url, urlhaus.abuse.ch/url/3914830/; classtype:trojan-activity;sid:84777930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914538)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_ea7a051a82d4b3b5.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914538/; classtype:trojan-activity;sid:84777638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914532)"; flow:established,from_client; content:"GET"; http_method; content:"/zxc/app.zip"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"loop-lumen.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914532/; classtype:trojan-activity;sid:84777632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914528)"; flow:established,from_client; content:"GET"; http_method; content:"/order.mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914528/; classtype:trojan-activity;sid:84777628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914524)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914524/; classtype:trojan-activity;sid:84777624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914525)"; flow:established,from_client; content:"GET"; http_method; content:"/order.armv4l"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914525/; classtype:trojan-activity;sid:84777625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914526)"; flow:established,from_client; content:"GET"; http_method; content:"/order.x86_32"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914526/; classtype:trojan-activity;sid:84777626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914527)"; flow:established,from_client; content:"GET"; http_method; content:"/order.mipsel"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914527/; classtype:trojan-activity;sid:84777627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914450)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"94.154.43.38"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914450/; classtype:trojan-activity;sid:84777550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914376)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"221.3.87.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914376/; classtype:trojan-activity;sid:84777476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914353)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"221.3.87.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914353/; classtype:trojan-activity;sid:84777453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914178)"; flow:established,from_client; content:"GET"; http_method; content:"/aa"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"92.119.157.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914178/; classtype:trojan-activity;sid:84777278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914141)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.119.157.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914141/; classtype:trojan-activity;sid:84777241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3914073)"; flow:established,from_client; content:"GET"; http_method; content:"/assets/download/client4e.jar"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"4eclient.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_09; reference:url, urlhaus.abuse.ch/url/3914073/; classtype:trojan-activity;sid:84777173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913982)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_deaad5d12778941d.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_08; reference:url, urlhaus.abuse.ch/url/3913982/; classtype:trojan-activity;sid:84777082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913841)"; flow:established,from_client; content:"GET"; http_method; content:"/.x/x"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"13.71.2.244"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_09_08; reference:url, urlhaus.abuse.ch/url/3913841/; classtype:trojan-activity;sid:84776941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913811)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"120.28.166.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_08; reference:url, urlhaus.abuse.ch/url/3913811/; classtype:trojan-activity;sid:84776911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913484)"; flow:established,from_client; content:"GET"; http_method; content:"/.well-known/new/img_onyix.png"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"dinamikakargo.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_09_07; reference:url, urlhaus.abuse.ch/url/3913484/; classtype:trojan-activity;sid:84776584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913056)"; flow:established,from_client; content:"GET"; http_method; content:"/files/com/kliulij.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913056/; classtype:trojan-activity;sid:84776156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913054)"; flow:established,from_client; content:"GET"; http_method; content:"/files/unique2/file.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913054/; classtype:trojan-activity;sid:84776154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913036)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.239.117"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913036/; classtype:trojan-activity;sid:84776136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913034)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.108.63"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913034/; classtype:trojan-activity;sid:84776134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913035)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.201.139"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913035/; classtype:trojan-activity;sid:84776135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913033)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"106.225.235.90"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913033/; classtype:trojan-activity;sid:84776133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913030)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.222.160.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913030/; classtype:trojan-activity;sid:84776130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913031)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.236.51.52"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913031/; classtype:trojan-activity;sid:84776131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913032)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.245.99.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913032/; classtype:trojan-activity;sid:84776132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913024)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.84.123.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913024/; classtype:trojan-activity;sid:84776124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913025)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.76.159.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913025/; classtype:trojan-activity;sid:84776125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3913026)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.245.89.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3913026/; classtype:trojan-activity;sid:84776126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912974)"; flow:established,from_client; content:"GET"; http_method; content:"/riscv32"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912974/; classtype:trojan-activity;sid:84776074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912925)"; flow:established,from_client; content:"GET"; http_method; content:"/qtm.arm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912925/; classtype:trojan-activity;sid:84776025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912923)"; flow:established,from_client; content:"GET"; http_method; content:"/qtm.x86"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912923/; classtype:trojan-activity;sid:84776023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912924)"; flow:established,from_client; content:"GET"; http_method; content:"/qtm.mips"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912924/; classtype:trojan-activity;sid:84776024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912921)"; flow:established,from_client; content:"GET"; http_method; content:"/qtm.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912921/; classtype:trojan-activity;sid:84776021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912922)"; flow:established,from_client; content:"GET"; http_method; content:"/qtm.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912922/; classtype:trojan-activity;sid:84776022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912797)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"193.178.158.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912797/; classtype:trojan-activity;sid:84775897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912782)"; flow:established,from_client; content:"GET"; http_method; content:"/111a.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"gaode11223.oss-ap-southeast-7.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912782/; classtype:trojan-activity;sid:84775882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912780)"; flow:established,from_client; content:"GET"; http_method; content:"/document.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"qqwwaa.tos-cn-hongkong.volces.com"; http_host; depth:33; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912780/; classtype:trojan-activity;sid:84775880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912777)"; flow:established,from_client; content:"GET"; http_method; content:"/game-copier/downloads/game-copier.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"multiplay.at"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_06; reference:url, urlhaus.abuse.ch/url/3912777/; classtype:trojan-activity;sid:84775877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912529)"; flow:established,from_client; content:"GET"; http_method; content:"/arm8"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_05; reference:url, urlhaus.abuse.ch/url/3912529/; classtype:trojan-activity;sid:84775629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912525)"; flow:established,from_client; content:"GET"; http_method; content:"/or1k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_05; reference:url, urlhaus.abuse.ch/url/3912525/; classtype:trojan-activity;sid:84775625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912394)"; flow:established,from_client; content:"GET"; http_method; content:"/asir.vbs"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912394/; classtype:trojan-activity;sid:84775494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912363)"; flow:established,from_client; content:"GET"; http_method; content:"/aminer.gz"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"193.90.12.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912363/; classtype:trojan-activity;sid:84775463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912279)"; flow:established,from_client; content:"GET"; http_method; content:"/install.tgz"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"193.90.12.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912279/; classtype:trojan-activity;sid:84775379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912225)"; flow:established,from_client; content:"GET"; http_method; content:"/ns3.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"193.90.12.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912225/; classtype:trojan-activity;sid:84775325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912227)"; flow:established,from_client; content:"GET"; http_method; content:"/ns1.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"193.90.12.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912227/; classtype:trojan-activity;sid:84775327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912178)"; flow:established,from_client; content:"GET"; http_method; content:"/hora/c8u/adb_setup_vn.bat"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"chiroartist.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912178/; classtype:trojan-activity;sid:84775278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912174)"; flow:established,from_client; content:"GET"; http_method; content:"/blaoso/aloffic.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912174/; classtype:trojan-activity;sid:84775274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912172)"; flow:established,from_client; content:"GET"; http_method; content:"/ffice.zip"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912172/; classtype:trojan-activity;sid:84775272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912171)"; flow:established,from_client; content:"GET"; http_method; content:"/lose.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912171/; classtype:trojan-activity;sid:84775271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912164)"; flow:established,from_client; content:"GET"; http_method; content:"/kasf/spsx.vbs"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912164/; classtype:trojan-activity;sid:84775264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912163)"; flow:established,from_client; content:"GET"; http_method; content:"/blaoso/ljwnsm.vbs"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912163/; classtype:trojan-activity;sid:84775263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912159)"; flow:established,from_client; content:"GET"; http_method; content:"/cwaz/lwjw.vbs"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912159/; classtype:trojan-activity;sid:84775259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912131)"; flow:established,from_client; content:"GET"; http_method; content:"/android-arm"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912131/; classtype:trojan-activity;sid:84775231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3912129)"; flow:established,from_client; content:"GET"; http_method; content:"/android-arm64"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_04; reference:url, urlhaus.abuse.ch/url/3912129/; classtype:trojan-activity;sid:84775229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911379)"; flow:established,from_client; content:"GET"; http_method; content:"/mass"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911379/; classtype:trojan-activity;sid:84774479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911373)"; flow:established,from_client; content:"GET"; http_method; content:"/spmm.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911373/; classtype:trojan-activity;sid:84774473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911362)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm5k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911362/; classtype:trojan-activity;sid:84774462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911355)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm4k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911355/; classtype:trojan-activity;sid:84774455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911356)"; flow:established,from_client; content:"GET"; http_method; content:"/chromek"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911356/; classtype:trojan-activity;sid:84774456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911357)"; flow:established,from_client; content:"GET"; http_method; content:"/giggappck"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911357/; classtype:trojan-activity;sid:84774457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911358)"; flow:established,from_client; content:"GET"; http_method; content:"/dipsk"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911358/; classtype:trojan-activity;sid:84774458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911359)"; flow:established,from_client; content:"GET"; http_method; content:"/arch.figga"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911359/; classtype:trojan-activity;sid:84774459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911360)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm6k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911360/; classtype:trojan-activity;sid:84774460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911361)"; flow:established,from_client; content:"GET"; http_method; content:"/i686.doom"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911361/; classtype:trojan-activity;sid:84774461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911352)"; flow:established,from_client; content:"GET"; http_method; content:"/main.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911352/; classtype:trojan-activity;sid:84774452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911351)"; flow:established,from_client; content:"GET"; http_method; content:"/nm.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911351/; classtype:trojan-activity;sid:84774451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911350)"; flow:established,from_client; content:"GET"; http_method; content:"/spm.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911350/; classtype:trojan-activity;sid:84774450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911348)"; flow:established,from_client; content:"GET"; http_method; content:"/c.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911348/; classtype:trojan-activity;sid:84774448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911347)"; flow:established,from_client; content:"GET"; http_method; content:"/ot.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911347/; classtype:trojan-activity;sid:84774447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911346)"; flow:established,from_client; content:"GET"; http_method; content:"/nmm.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911346/; classtype:trojan-activity;sid:84774446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911163)"; flow:established,from_client; content:"GET"; http_method; content:"/client.ps1"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"out-agent.duckdns.org"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911163/; classtype:trojan-activity;sid:84774263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911133)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_8eb65d0dcf9d4880.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911133/; classtype:trojan-activity;sid:84774233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911126)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_30391bd0ced7aa24.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_02; reference:url, urlhaus.abuse.ch/url/3911126/; classtype:trojan-activity;sid:84774226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3911066)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_018d7b156998810c.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3911066/; classtype:trojan-activity;sid:84774166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910873)"; flow:established,from_client; content:"GET"; http_method; content:"/miner"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"193.32.162.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910873/; classtype:trojan-activity;sid:84773973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910872)"; flow:established,from_client; content:"GET"; http_method; content:"/mig"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"193.32.162.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910872/; classtype:trojan-activity;sid:84773972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910868)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"102.220.160.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910868/; classtype:trojan-activity;sid:84773968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910867)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"102.220.160.223"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910867/; classtype:trojan-activity;sid:84773967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910866)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"102.220.160.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910866/; classtype:trojan-activity;sid:84773966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910865)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"102.220.160.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910865/; classtype:trojan-activity;sid:84773965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910864)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"102.220.160.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910864/; classtype:trojan-activity;sid:84773964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910862)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"31.57.184.249"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910862/; classtype:trojan-activity;sid:84773962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910855)"; flow:established,from_client; content:"GET"; http_method; content:"/pearl-miner"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"92.118.39.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910855/; classtype:trojan-activity;sid:84773955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910683)"; flow:established,from_client; content:"GET"; http_method; content:"/images/xxwealthnow.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"geoxsecurity.ro"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_09_01; reference:url, urlhaus.abuse.ch/url/3910683/; classtype:trojan-activity;sid:84773783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910607)"; flow:established,from_client; content:"GET"; http_method; content:"/main.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"38.54.37.216"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910607/; classtype:trojan-activity;sid:84773707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910600)"; flow:established,from_client; content:"GET"; http_method; content:"/w3.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"185.242.3.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910600/; classtype:trojan-activity;sid:84773700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910599)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.242.3.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910599/; classtype:trojan-activity;sid:84773699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910597)"; flow:established,from_client; content:"GET"; http_method; content:"/check3.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"185.242.3.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910597/; classtype:trojan-activity;sid:84773697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910598)"; flow:established,from_client; content:"GET"; http_method; content:"/softwaretech"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"185.242.3.87"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910598/; classtype:trojan-activity;sid:84773698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910589)"; flow:established,from_client; content:"GET"; http_method; content:"/s.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910589/; classtype:trojan-activity;sid:84773689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910590)"; flow:established,from_client; content:"GET"; http_method; content:"/b.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910590/; classtype:trojan-activity;sid:84773690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910391)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.124.151.9"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910391/; classtype:trojan-activity;sid:84773491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910315)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/maint/bin.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"safeifm.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910315/; classtype:trojan-activity;sid:84773415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910290)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_d558ca7d5eabc298.msi"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910290/; classtype:trojan-activity;sid:84773390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910273)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/69c7b08d53c448c283d2f9d244d190cc.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910273/; classtype:trojan-activity;sid:84773373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910274)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8323ff95090049d3826616b94eed7cd8.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910274/; classtype:trojan-activity;sid:84773374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910271)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/26bd033dff764587836ef1b2e13d79eb.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910271/; classtype:trojan-activity;sid:84773371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910272)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/c9df9ff3c2174c4da9300946886142a1.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910272/; classtype:trojan-activity;sid:84773372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910268)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/ac67795cbe1f491785c528b3ce7e02f7.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910268/; classtype:trojan-activity;sid:84773368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910269)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/e89f8067ad444d60b2ca4bba298d964a.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910269/; classtype:trojan-activity;sid:84773369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910270)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/0c83aee7a8ad48ecb075c59c5b4957f3.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910270/; classtype:trojan-activity;sid:84773370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910266)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/f1fd2b57dfc04e709e0d745afb092693.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910266/; classtype:trojan-activity;sid:84773366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910267)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/343aed2fde0e4a64a80edc50ae7d9de6.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910267/; classtype:trojan-activity;sid:84773367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910262)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/f1c106553ca64defbddc6d82476e8076.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910262/; classtype:trojan-activity;sid:84773362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910263)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/64c95144ee7744879dc688f427e12703.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910263/; classtype:trojan-activity;sid:84773363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910264)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/141935c46a5c4ff1b84b433e84f36e61.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910264/; classtype:trojan-activity;sid:84773364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910265)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/f3eeb7dfc18246f7bc40a5704a81d193.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910265/; classtype:trojan-activity;sid:84773365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910259)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/785778d19d3a48aabc169c022dd6e4a2.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910259/; classtype:trojan-activity;sid:84773359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910260)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/036d684a34404874843f08d695e15695.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910260/; classtype:trojan-activity;sid:84773360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910261)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/ca75c0dfaf9540ab96d419f67574927f.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910261/; classtype:trojan-activity;sid:84773361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910258)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/2d7aaa6d163f48458905a62516fc1390.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910258/; classtype:trojan-activity;sid:84773358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910256)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/d0d605c01f71464ea16b25c92892dbe0.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910256/; classtype:trojan-activity;sid:84773356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910257)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/d33ab8c1371c4e1b9f2fdb7007e21df4.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910257/; classtype:trojan-activity;sid:84773357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910247)"; flow:established,from_client; content:"GET"; http_method; content:"/taunahiloader-26.2.jar"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"taunahi.st"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910247/; classtype:trojan-activity;sid:84773347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910233)"; flow:established,from_client; content:"GET"; http_method; content:"/aom.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"156.251.11.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910233/; classtype:trojan-activity;sid:84773333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910234)"; flow:established,from_client; content:"GET"; http_method; content:"/aom.dat"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"156.251.11.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_31; reference:url, urlhaus.abuse.ch/url/3910234/; classtype:trojan-activity;sid:84773334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3910103)"; flow:established,from_client; content:"GET"; http_method; content:"/img_170820.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"coolairesgroup.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_30; reference:url, urlhaus.abuse.ch/url/3910103/; classtype:trojan-activity;sid:84773203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909928)"; flow:established,from_client; content:"GET"; http_method; content:"/telnetd"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_30; reference:url, urlhaus.abuse.ch/url/3909928/; classtype:trojan-activity;sid:84773028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909924)"; flow:established,from_client; content:"GET"; http_method; content:"/kworker"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_30; reference:url, urlhaus.abuse.ch/url/3909924/; classtype:trojan-activity;sid:84773024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909921)"; flow:established,from_client; content:"GET"; http_method; content:"/telnet"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_30; reference:url, urlhaus.abuse.ch/url/3909921/; classtype:trojan-activity;sid:84773021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909529)"; flow:established,from_client; content:"GET"; http_method; content:"/weed"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909529/; classtype:trojan-activity;sid:84772629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909530)"; flow:established,from_client; content:"GET"; http_method; content:"/vc"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909530/; classtype:trojan-activity;sid:84772630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909528)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/say.zip"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909528/; classtype:trojan-activity;sid:84772628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909526)"; flow:established,from_client; content:"GET"; http_method; content:"/w.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909526/; classtype:trojan-activity;sid:84772626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909527)"; flow:established,from_client; content:"GET"; http_method; content:"/c.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909527/; classtype:trojan-activity;sid:84772627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909525)"; flow:established,from_client; content:"GET"; http_method; content:"/gpon"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909525/; classtype:trojan-activity;sid:84772625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909520)"; flow:established,from_client; content:"GET"; http_method; content:"/lilin"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909520/; classtype:trojan-activity;sid:84772620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909521)"; flow:established,from_client; content:"GET"; http_method; content:"/sh"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909521/; classtype:trojan-activity;sid:84772621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909522)"; flow:established,from_client; content:"GET"; http_method; content:"/sdt"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909522/; classtype:trojan-activity;sid:84772622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909523)"; flow:established,from_client; content:"GET"; http_method; content:"/dlink"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909523/; classtype:trojan-activity;sid:84772623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909524)"; flow:established,from_client; content:"GET"; http_method; content:"/k"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_29; reference:url, urlhaus.abuse.ch/url/3909524/; classtype:trojan-activity;sid:84772624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909432)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909432/; classtype:trojan-activity;sid:84772532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909418)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909418/; classtype:trojan-activity;sid:84772518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909419)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909419/; classtype:trojan-activity;sid:84772519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909420)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909420/; classtype:trojan-activity;sid:84772520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909421)"; flow:established,from_client; content:"GET"; http_method; content:"/t.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909421/; classtype:trojan-activity;sid:84772521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909422)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909422/; classtype:trojan-activity;sid:84772522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909423)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909423/; classtype:trojan-activity;sid:84772523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909424)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909424/; classtype:trojan-activity;sid:84772524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909425)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909425/; classtype:trojan-activity;sid:84772525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909426)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909426/; classtype:trojan-activity;sid:84772526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909427)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909427/; classtype:trojan-activity;sid:84772527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909428)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909428/; classtype:trojan-activity;sid:84772528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909429)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909429/; classtype:trojan-activity;sid:84772529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909430)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909430/; classtype:trojan-activity;sid:84772530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909431)"; flow:established,from_client; content:"GET"; http_method; content:"/adbpersist.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909431/; classtype:trojan-activity;sid:84772531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909415)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909415/; classtype:trojan-activity;sid:84772515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909416)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909416/; classtype:trojan-activity;sid:84772516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909417)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909417/; classtype:trojan-activity;sid:84772517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909404)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909404/; classtype:trojan-activity;sid:84772504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909405)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909405/; classtype:trojan-activity;sid:84772505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909406)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909406/; classtype:trojan-activity;sid:84772506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909407)"; flow:established,from_client; content:"GET"; http_method; content:"/s390x"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909407/; classtype:trojan-activity;sid:84772507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909408)"; flow:established,from_client; content:"GET"; http_method; content:"/riscv64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909408/; classtype:trojan-activity;sid:84772508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909409)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909409/; classtype:trojan-activity;sid:84772509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909410)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909410/; classtype:trojan-activity;sid:84772510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909411)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909411/; classtype:trojan-activity;sid:84772511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909412)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909412/; classtype:trojan-activity;sid:84772512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909413)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909413/; classtype:trojan-activity;sid:84772513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909414)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909414/; classtype:trojan-activity;sid:84772514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909380)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.arm6"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909380/; classtype:trojan-activity;sid:84772480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909375)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.m68k"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909375/; classtype:trojan-activity;sid:84772475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909376)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.x86"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909376/; classtype:trojan-activity;sid:84772476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909377)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.ppc"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909377/; classtype:trojan-activity;sid:84772477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909378)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.arm5"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909378/; classtype:trojan-activity;sid:84772478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909379)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.sh4"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909379/; classtype:trojan-activity;sid:84772479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909357)"; flow:established,from_client; content:"GET"; http_method; content:"/kaka/stego_jwfhjrnszg.png"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"impectorinternational.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909357/; classtype:trojan-activity;sid:84772457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909326)"; flow:established,from_client; content:"GET"; http_method; content:"/img_051638.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"coolairesgroup.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909326/; classtype:trojan-activity;sid:84772426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909324)"; flow:established,from_client; content:"GET"; http_method; content:"/apago/pago.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"tmcksa.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909324/; classtype:trojan-activity;sid:84772424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909310)"; flow:established,from_client; content:"GET"; http_method; content:"/hcxael.png"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"pub-1614932a526c40d79fe5bf23e71e3ff7.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909310/; classtype:trojan-activity;sid:84772410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909295)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.x86_64"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909295/; classtype:trojan-activity;sid:84772395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909294)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_274601599365ef96.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909294/; classtype:trojan-activity;sid:84772394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909240)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.227.54.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909240/; classtype:trojan-activity;sid:84772340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3909229)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"123.57.51.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_28; reference:url, urlhaus.abuse.ch/url/3909229/; classtype:trojan-activity;sid:84772329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908948)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/linux.bin"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"casasmediterraneas.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_08_27; reference:url, urlhaus.abuse.ch/url/3908948/; classtype:trojan-activity;sid:84772048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908781)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.arm7"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_27; reference:url, urlhaus.abuse.ch/url/3908781/; classtype:trojan-activity;sid:84771881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908703)"; flow:established,from_client; content:"GET"; http_method; content:"/zoom.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"luminouspower.com.pk"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_08_27; reference:url, urlhaus.abuse.ch/url/3908703/; classtype:trojan-activity;sid:84771803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908517)"; flow:established,from_client; content:"GET"; http_method; content:"/bebe/bebeln.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"tmcksa.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908517/; classtype:trojan-activity;sid:84771617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908515)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/julyendingapama.firebasestorage.app/o/inve%20new.png|3f|alt=media|7c|26|7c|token=15e2a054-9211-4b2f-987c-c1225adf4faa"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908515/; classtype:trojan-activity;sid:84771615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908466)"; flow:established,from_client; content:"GET"; http_method; content:"/crypt/21-32/qw1.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"45.13.186.37"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908466/; classtype:trojan-activity;sid:84771566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908273)"; flow:established,from_client; content:"GET"; http_method; content:"/harder/binikuku.dat"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"impectorinternational.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908273/; classtype:trojan-activity;sid:84771373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908193)"; flow:established,from_client; content:"GET"; http_method; content:"/handshakebins.sh"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"213.232.114.14"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908193/; classtype:trojan-activity;sid:84771293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908176)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.mips"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908176/; classtype:trojan-activity;sid:84771276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908175)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.mpsl"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_26; reference:url, urlhaus.abuse.ch/url/3908175/; classtype:trojan-activity;sid:84771275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908101)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest|7c|26|7c|c=eye%20clinic|7c|26|7c|c=|7c|26|7c|c=surgery|7c|26|7c|c=personal|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c="; http_uri; depth:186; isdataat:!1,relative; nocase; content:"paretandassociates.screenconnect.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908101/; classtype:trojan-activity;sid:84771201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3908043)"; flow:established,from_client; content:"GET"; http_method; content:"/pcdn"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"61.184.10.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3908043/; classtype:trojan-activity;sid:84771143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907975)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.227.54.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907975/; classtype:trojan-activity;sid:84771075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907931)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.165.89.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907931/; classtype:trojan-activity;sid:84771031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907801)"; flow:established,from_client; content:"GET"; http_method; content:"/giggappc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907801/; classtype:trojan-activity;sid:84770901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907802)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm6"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907802/; classtype:trojan-activity;sid:84770902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907796)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907796/; classtype:trojan-activity;sid:84770896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907797)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm7"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907797/; classtype:trojan-activity;sid:84770897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907798)"; flow:established,from_client; content:"GET"; http_method; content:"/chrome"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907798/; classtype:trojan-activity;sid:84770898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907799)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm5"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907799/; classtype:trojan-activity;sid:84770899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907800)"; flow:established,from_client; content:"GET"; http_method; content:"/dips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907800/; classtype:trojan-activity;sid:84770900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907794)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907794/; classtype:trojan-activity;sid:84770894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907795)"; flow:established,from_client; content:"GET"; http_method; content:"/dipndots"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907795/; classtype:trojan-activity;sid:84770895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907791)"; flow:established,from_client; content:"GET"; http_method; content:"/kkk.arm7k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907791/; classtype:trojan-activity;sid:84770891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907790)"; flow:established,from_client; content:"GET"; http_method; content:"/dipndotsk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"104.168.4.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_25; reference:url, urlhaus.abuse.ch/url/3907790/; classtype:trojan-activity;sid:84770890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907570)"; flow:established,from_client; content:"GET"; http_method; content:"/kushnet.mipsel"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"45.198.224.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907570/; classtype:trojan-activity;sid:84770670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907522)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.106.241.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907522/; classtype:trojan-activity;sid:84770622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907477)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"65.99.181.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_24; reference:url, urlhaus.abuse.ch/url/3907477/; classtype:trojan-activity;sid:84770577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907349)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.205.226.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907349/; classtype:trojan-activity;sid:84770449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907345)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.205.226.191"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907345/; classtype:trojan-activity;sid:84770445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907291)"; flow:established,from_client; content:"GET"; http_method; content:"/servicer.apk"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907291/; classtype:trojan-activity;sid:84770391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907257)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907257/; classtype:trojan-activity;sid:84770357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907254)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.arm7"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907254/; classtype:trojan-activity;sid:84770354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907255)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mirai.x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"193.111.117.135"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907255/; classtype:trojan-activity;sid:84770355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907248)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.151.182.200"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_23; reference:url, urlhaus.abuse.ch/url/3907248/; classtype:trojan-activity;sid:84770348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3907005)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"174.105.154.212"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3907005/; classtype:trojan-activity;sid:84770105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906966)"; flow:established,from_client; content:"GET"; http_method; content:"/imagenes2/msi_pro.png"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"munihuacho.gob.pe"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906966/; classtype:trojan-activity;sid:84770066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906884)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"174.105.154.212"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_22; reference:url, urlhaus.abuse.ch/url/3906884/; classtype:trojan-activity;sid:84769984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906344)"; flow:established,from_client; content:"GET"; http_method; content:"/lilin.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906344/; classtype:trojan-activity;sid:84769444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906323)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906323/; classtype:trojan-activity;sid:84769423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906324)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906324/; classtype:trojan-activity;sid:84769424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906325)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906325/; classtype:trojan-activity;sid:84769425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906326)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906326/; classtype:trojan-activity;sid:84769426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906327)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906327/; classtype:trojan-activity;sid:84769427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906328)"; flow:established,from_client; content:"GET"; http_method; content:"/spc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906328/; classtype:trojan-activity;sid:84769428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906329)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906329/; classtype:trojan-activity;sid:84769429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906330)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906330/; classtype:trojan-activity;sid:84769430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906331)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906331/; classtype:trojan-activity;sid:84769431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906332)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906332/; classtype:trojan-activity;sid:84769432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906333)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906333/; classtype:trojan-activity;sid:84769433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906334)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906334/; classtype:trojan-activity;sid:84769434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906335)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906335/; classtype:trojan-activity;sid:84769435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906322)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"124.163.212.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_21; reference:url, urlhaus.abuse.ch/url/3906322/; classtype:trojan-activity;sid:84769422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906183)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"profitable-pink-0y9btnew-dpk6vqe6eheo.edgeone.dev"; http_host; depth:49; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906183/; classtype:trojan-activity;sid:84769283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906184)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"balanced-red-emhnkdfj-dp7g2kvqxx8n.edgeone.dev"; http_host; depth:46; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906184/; classtype:trojan-activity;sid:84769284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906114)"; flow:established,from_client; content:"GET"; http_method; content:"/client.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"85.203.4.64"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906114/; classtype:trojan-activity;sid:84769214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3906011)"; flow:established,from_client; content:"GET"; http_method; content:"/client.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.26.90.90"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_20; reference:url, urlhaus.abuse.ch/url/3906011/; classtype:trojan-activity;sid:84769111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905911)"; flow:established,from_client; content:"GET"; http_method; content:"/zuyoking.png"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905911/; classtype:trojan-activity;sid:84769011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905851)"; flow:established,from_client; content:"GET"; http_method; content:"/2.bat"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"cqintzfep6rw6jc9.public.blob.vercel-storage.com"; http_host; depth:47; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905851/; classtype:trojan-activity;sid:84768951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905780)"; flow:established,from_client; content:"GET"; http_method; content:"/ofiltytuerutyueiioo/docusign-8901123adobe-reader07zuillnirusi.bat"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"mkconstructions.net"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905780/; classtype:trojan-activity;sid:84768880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905707)"; flow:established,from_client; content:"GET"; http_method; content:"/amd"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"61.184.10.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905707/; classtype:trojan-activity;sid:84768807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905702)"; flow:established,from_client; content:"GET"; http_method; content:"/syss"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"61.184.10.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905702/; classtype:trojan-activity;sid:84768802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905598)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1mvi9h_rv6mptfrqbc3cdniyfuriaq2tq"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_19; reference:url, urlhaus.abuse.ch/url/3905598/; classtype:trojan-activity;sid:84768698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905385)"; flow:established,from_client; content:"GET"; http_method; content:"/2.7.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"196.251.107.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905385/; classtype:trojan-activity;sid:84768485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3905091)"; flow:established,from_client; content:"GET"; http_method; content:"/cabin/diocle.emz"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"bserail.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_08_18; reference:url, urlhaus.abuse.ch/url/3905091/; classtype:trojan-activity;sid:84768191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904718)"; flow:established,from_client; content:"GET"; http_method; content:"/check3.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.228.157.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904718/; classtype:trojan-activity;sid:84767818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904574)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_4b8d61b5a6f660b5.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_17; reference:url, urlhaus.abuse.ch/url/3904574/; classtype:trojan-activity;sid:84767674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904395)"; flow:established,from_client; content:"GET"; http_method; content:"/deploy.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.228.157.73"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_16; reference:url, urlhaus.abuse.ch/url/3904395/; classtype:trojan-activity;sid:84767495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3904049)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/d6a0dbb9ae834113a8401012b1f9aa18.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"192.162.199.149"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3904049/; classtype:trojan-activity;sid:84767149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903903)"; flow:established,from_client; content:"GET"; http_method; content:"/files/omega/file.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"62.60.226.140"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_15; reference:url, urlhaus.abuse.ch/url/3903903/; classtype:trojan-activity;sid:84767003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903736)"; flow:established,from_client; content:"GET"; http_method; content:"/amd"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"223.76.100.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903736/; classtype:trojan-activity;sid:84766836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903735)"; flow:established,from_client; content:"GET"; http_method; content:"/syss"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"223.76.100.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903735/; classtype:trojan-activity;sid:84766835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903443)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"144.31.30.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903443/; classtype:trojan-activity;sid:84766543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903444)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"144.31.30.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903444/; classtype:trojan-activity;sid:84766544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903445)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"144.31.30.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903445/; classtype:trojan-activity;sid:84766545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903446)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"144.31.30.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903446/; classtype:trojan-activity;sid:84766546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903447)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"144.31.30.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903447/; classtype:trojan-activity;sid:84766547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903448)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_amd64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"144.31.30.228"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_14; reference:url, urlhaus.abuse.ch/url/3903448/; classtype:trojan-activity;sid:84766548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903307)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"144.31.167.1"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903307/; classtype:trojan-activity;sid:84766407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903210)"; flow:established,from_client; content:"GET"; http_method; content:"/google.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"rcf.co.mz"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903210/; classtype:trojan-activity;sid:84766310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903196)"; flow:established,from_client; content:"GET"; http_method; content:"/forbes.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"rcf.co.mz"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903196/; classtype:trojan-activity;sid:84766296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903188)"; flow:established,from_client; content:"GET"; http_method; content:"/ind8inc/crypted.ps1"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"mnurlogistics.az"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903188/; classtype:trojan-activity;sid:84766288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903135)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"82.114.181.233"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903135/; classtype:trojan-activity;sid:84766235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903074)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.106.241.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903074/; classtype:trojan-activity;sid:84766174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3903004)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.arm"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3903004/; classtype:trojan-activity;sid:84766104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902928)"; flow:established,from_client; content:"GET"; http_method; content:"/rvn.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_13; reference:url, urlhaus.abuse.ch/url/3902928/; classtype:trojan-activity;sid:84766028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902874)"; flow:established,from_client; content:"GET"; http_method; content:"/8jot5vdohds0imt4"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"192.162.199.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902874/; classtype:trojan-activity;sid:84765974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902873)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"207.189.4.110"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902873/; classtype:trojan-activity;sid:84765973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902870)"; flow:established,from_client; content:"GET"; http_method; content:"/1vo6lm4y50k3ww0f"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"192.162.199.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902870/; classtype:trojan-activity;sid:84765970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902871)"; flow:established,from_client; content:"GET"; http_method; content:"/zeb8cgwmkkpvu7pc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"192.162.199.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902871/; classtype:trojan-activity;sid:84765971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902858)"; flow:established,from_client; content:"GET"; http_method; content:"/y6b3fuzj0w6pt97e"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"192.162.199.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902858/; classtype:trojan-activity;sid:84765958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902670)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/julyendingapama.firebasestorage.app/o/invergrace.png|3f|alt=media|7c|26|7c|token=54ae32e9-1f20-404f-80a5-8fcc841a3c2b"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902670/; classtype:trojan-activity;sid:84765770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902571)"; flow:established,from_client; content:"GET"; http_method; content:"/wellsfargo_new_obf_08.07.26.zip"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"www-connect-secure-wellcfargo.sekolahkejarpaket.com"; http_host; depth:51; isdataat:!1,relative; metadata:created_at 2026_08_12; reference:url, urlhaus.abuse.ch/url/3902571/; classtype:trojan-activity;sid:84765671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902253)"; flow:established,from_client; content:"GET"; http_method; content:"/wd1337"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902253/; classtype:trojan-activity;sid:84765353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902252)"; flow:established,from_client; content:"GET"; http_method; content:"/log"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902252/; classtype:trojan-activity;sid:84765352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902251)"; flow:established,from_client; content:"GET"; http_method; content:"/oldboss"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902251/; classtype:trojan-activity;sid:84765351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902250)"; flow:established,from_client; content:"GET"; http_method; content:"/syst3md"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902250/; classtype:trojan-activity;sid:84765350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902249)"; flow:established,from_client; content:"GET"; http_method; content:"/proot"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902249/; classtype:trojan-activity;sid:84765349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902247)"; flow:established,from_client; content:"GET"; http_method; content:"/proot"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902247/; classtype:trojan-activity;sid:84765347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902248)"; flow:established,from_client; content:"GET"; http_method; content:"/syst3md"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902248/; classtype:trojan-activity;sid:84765348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902246)"; flow:established,from_client; content:"GET"; http_method; content:"/wd1337"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902246/; classtype:trojan-activity;sid:84765346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902245)"; flow:established,from_client; content:"GET"; http_method; content:"/log"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902245/; classtype:trojan-activity;sid:84765345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902240)"; flow:established,from_client; content:"GET"; http_method; content:"/cli"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902240/; classtype:trojan-activity;sid:84765340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902241)"; flow:established,from_client; content:"GET"; http_method; content:"/error84"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902241/; classtype:trojan-activity;sid:84765341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902239)"; flow:established,from_client; content:"GET"; http_method; content:"/oldboss"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902239/; classtype:trojan-activity;sid:84765339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902238)"; flow:established,from_client; content:"GET"; http_method; content:"/main"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902238/; classtype:trojan-activity;sid:84765338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902237)"; flow:established,from_client; content:"GET"; http_method; content:"/cliaarch"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902237/; classtype:trojan-activity;sid:84765337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902236)"; flow:established,from_client; content:"GET"; http_method; content:"/check.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902236/; classtype:trojan-activity;sid:84765336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902232)"; flow:established,from_client; content:"GET"; http_method; content:"/checkmacos.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902232/; classtype:trojan-activity;sid:84765332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902233)"; flow:established,from_client; content:"GET"; http_method; content:"/boss"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902233/; classtype:trojan-activity;sid:84765333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902234)"; flow:established,from_client; content:"GET"; http_method; content:"/check1.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902234/; classtype:trojan-activity;sid:84765334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902235)"; flow:established,from_client; content:"GET"; http_method; content:"/nvidia.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902235/; classtype:trojan-activity;sid:84765335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902230)"; flow:established,from_client; content:"GET"; http_method; content:"/auto1"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902230/; classtype:trojan-activity;sid:84765330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902231)"; flow:established,from_client; content:"GET"; http_method; content:"/auto"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902231/; classtype:trojan-activity;sid:84765331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902059)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.245.111.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902059/; classtype:trojan-activity;sid:84765159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902044)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.222.247.229"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902044/; classtype:trojan-activity;sid:84765144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902047)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.237.167.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902047/; classtype:trojan-activity;sid:84765147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902049)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.241.116"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902049/; classtype:trojan-activity;sid:84765149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902050)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.210.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902050/; classtype:trojan-activity;sid:84765150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902052)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.169.170"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902052/; classtype:trojan-activity;sid:84765152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902053)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.236.70.102"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902053/; classtype:trojan-activity;sid:84765153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902054)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.236.122.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902054/; classtype:trojan-activity;sid:84765154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902056)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.222.179.91"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902056/; classtype:trojan-activity;sid:84765156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902043)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.155.47"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902043/; classtype:trojan-activity;sid:84765143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902037)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.245.84.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902037/; classtype:trojan-activity;sid:84765137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902038)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.236.28.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902038/; classtype:trojan-activity;sid:84765138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902039)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.236.146.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902039/; classtype:trojan-activity;sid:84765139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902041)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"8.219.85.120"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902041/; classtype:trojan-activity;sid:84765141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902007)"; flow:established,from_client; content:"GET"; http_method; content:"/cli"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902007/; classtype:trojan-activity;sid:84765107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902008)"; flow:established,from_client; content:"GET"; http_method; content:"/error84"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902008/; classtype:trojan-activity;sid:84765108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902004)"; flow:established,from_client; content:"GET"; http_method; content:"/cliaarch"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902004/; classtype:trojan-activity;sid:84765104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902005)"; flow:established,from_client; content:"GET"; http_method; content:"/boss"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902005/; classtype:trojan-activity;sid:84765105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3902006)"; flow:established,from_client; content:"GET"; http_method; content:"/main"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3902006/; classtype:trojan-activity;sid:84765106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901986)"; flow:established,from_client; content:"GET"; http_method; content:"/nuts/poop"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"216.9.226.120"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901986/; classtype:trojan-activity;sid:84765086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901984)"; flow:established,from_client; content:"GET"; http_method; content:"/1"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901984/; classtype:trojan-activity;sid:84765084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901971)"; flow:established,from_client; content:"GET"; http_method; content:"/nuts/bolts"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"216.9.226.120"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901971/; classtype:trojan-activity;sid:84765071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901961)"; flow:established,from_client; content:"GET"; http_method; content:"/nvidia.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901961/; classtype:trojan-activity;sid:84765061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901938)"; flow:established,from_client; content:"GET"; http_method; content:"/checkmacos.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901938/; classtype:trojan-activity;sid:84765038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901936)"; flow:established,from_client; content:"GET"; http_method; content:"/auto"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901936/; classtype:trojan-activity;sid:84765036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901923)"; flow:established,from_client; content:"GET"; http_method; content:"/auto1"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901923/; classtype:trojan-activity;sid:84765023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901924)"; flow:established,from_client; content:"GET"; http_method; content:"/check.sh"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901924/; classtype:trojan-activity;sid:84765024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901925)"; flow:established,from_client; content:"GET"; http_method; content:"/check1.sh"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901925/; classtype:trojan-activity;sid:84765025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901892)"; flow:established,from_client; content:"GET"; http_method; content:"/cat.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.226"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901892/; classtype:trojan-activity;sid:84764992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901788)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901788/; classtype:trojan-activity;sid:84764888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901787)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901787/; classtype:trojan-activity;sid:84764887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901781)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901781/; classtype:trojan-activity;sid:84764881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901782)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901782/; classtype:trojan-activity;sid:84764882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901783)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/mips"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901783/; classtype:trojan-activity;sid:84764883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901784)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901784/; classtype:trojan-activity;sid:84764884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901785)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pppc"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901785/; classtype:trojan-activity;sid:84764885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901786)"; flow:established,from_client; content:"GET"; http_method; content:"/parm5"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901786/; classtype:trojan-activity;sid:84764886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901772)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901772/; classtype:trojan-activity;sid:84764872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901773)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901773/; classtype:trojan-activity;sid:84764873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901774)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm6"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901774/; classtype:trojan-activity;sid:84764874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901775)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901775/; classtype:trojan-activity;sid:84764875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901776)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901776/; classtype:trojan-activity;sid:84764876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901777)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901777/; classtype:trojan-activity;sid:84764877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901778)"; flow:established,from_client; content:"GET"; http_method; content:"/parm7"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901778/; classtype:trojan-activity;sid:84764878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901779)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm7"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901779/; classtype:trojan-activity;sid:84764879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901780)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901780/; classtype:trojan-activity;sid:84764880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901771)"; flow:established,from_client; content:"GET"; http_method; content:"/mpsl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901771/; classtype:trojan-activity;sid:84764871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901770)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901770/; classtype:trojan-activity;sid:84764870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901758)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pmpsl"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901758/; classtype:trojan-activity;sid:84764858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901759)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901759/; classtype:trojan-activity;sid:84764859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901760)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm6"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901760/; classtype:trojan-activity;sid:84764860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901761)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901761/; classtype:trojan-activity;sid:84764861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901762)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/psh4"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901762/; classtype:trojan-activity;sid:84764862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901763)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/kla.sh"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901763/; classtype:trojan-activity;sid:84764863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901764)"; flow:established,from_client; content:"GET"; http_method; content:"/kla.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901764/; classtype:trojan-activity;sid:84764864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901765)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901765/; classtype:trojan-activity;sid:84764865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901766)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/arm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901766/; classtype:trojan-activity;sid:84764866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901767)"; flow:established,from_client; content:"GET"; http_method; content:"/parm"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901767/; classtype:trojan-activity;sid:84764867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901768)"; flow:established,from_client; content:"GET"; http_method; content:"/pmips"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901768/; classtype:trojan-activity;sid:84764868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901769)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/parm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901769/; classtype:trojan-activity;sid:84764869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901756)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/pm68k"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901756/; classtype:trojan-activity;sid:84764856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901757)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/px86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901757/; classtype:trojan-activity;sid:84764857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901755)"; flow:established,from_client; content:"GET"; http_method; content:"/parm6"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901755/; classtype:trojan-activity;sid:84764855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901749)"; flow:established,from_client; content:"GET"; http_method; content:"/psh4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901749/; classtype:trojan-activity;sid:84764849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901750)"; flow:established,from_client; content:"GET"; http_method; content:"/pppc"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901750/; classtype:trojan-activity;sid:84764850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901751)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901751/; classtype:trojan-activity;sid:84764851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901752)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901752/; classtype:trojan-activity;sid:84764852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901753)"; flow:established,from_client; content:"GET"; http_method; content:"/pm68k"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901753/; classtype:trojan-activity;sid:84764853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901754)"; flow:established,from_client; content:"GET"; http_method; content:"/px86"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901754/; classtype:trojan-activity;sid:84764854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901748)"; flow:established,from_client; content:"GET"; http_method; content:"/pmpsl"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901748/; classtype:trojan-activity;sid:84764848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901747)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"176.65.139.196"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901747/; classtype:trojan-activity;sid:84764847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901349)"; flow:established,from_client; content:"GET"; http_method; content:"/naew8m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"sh.classera.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901349/; classtype:trojan-activity;sid:84764449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901340)"; flow:established,from_client; content:"GET"; http_method; content:"/install.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"del.sou.pp.ua"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901340/; classtype:trojan-activity;sid:84764440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3901341)"; flow:established,from_client; content:"GET"; http_method; content:"/install_tm.sh"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"del.sou.pp.ua"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_11; reference:url, urlhaus.abuse.ch/url/3901341/; classtype:trojan-activity;sid:84764441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900952)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_e8219df7a9a21088.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900952/; classtype:trojan-activity;sid:84764052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900561)"; flow:established,from_client; content:"GET"; http_method; content:"/mhsanaei/3x-ui/master/install.sh"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900561/; classtype:trojan-activity;sid:84763661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900382)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_457316565c5d19a2.cmd"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_10; reference:url, urlhaus.abuse.ch/url/3900382/; classtype:trojan-activity;sid:84763482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900350)"; flow:established,from_client; content:"GET"; http_method; content:"/bolodo"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900350/; classtype:trojan-activity;sid:84763450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3900186)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.121.138.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_09; reference:url, urlhaus.abuse.ch/url/3900186/; classtype:trojan-activity;sid:84763286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898747)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_bec865d8acfd0630.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_08; reference:url, urlhaus.abuse.ch/url/3898747/; classtype:trojan-activity;sid:84761847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898601)"; flow:established,from_client; content:"GET"; http_method; content:"/g1/6.txt"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"93.105.205.92.host.secureserver.net"; http_host; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898601/; classtype:trojan-activity;sid:84761701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898599)"; flow:established,from_client; content:"GET"; http_method; content:"/g1/exe.txt"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"93.105.205.92.host.secureserver.net"; http_host; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898599/; classtype:trojan-activity;sid:84761699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898600)"; flow:established,from_client; content:"GET"; http_method; content:"/g1/sc.txt"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.105.205.92.host.secureserver.net"; http_host; depth:35; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898600/; classtype:trojan-activity;sid:84761700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898573)"; flow:established,from_client; content:"GET"; http_method; content:"/ddos.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"yakult-hk.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_07; reference:url, urlhaus.abuse.ch/url/3898573/; classtype:trojan-activity;sid:84761673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898348)"; flow:established,from_client; content:"GET"; http_method; content:"/2.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"85.137.245.141"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898348/; classtype:trojan-activity;sid:84761448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3898066)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"152.32.240.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3898066/; classtype:trojan-activity;sid:84761166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897704)"; flow:established,from_client; content:"GET"; http_method; content:"/img_131252.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"sales.ifree.page"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_06; reference:url, urlhaus.abuse.ch/url/3897704/; classtype:trojan-activity;sid:84760804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897372)"; flow:established,from_client; content:"GET"; http_method; content:"/202608/05/kk9ihq9ebt47mhmryher/image.png"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"plain-wnam-prod-public.komododecks.com"; http_host; depth:38; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897372/; classtype:trojan-activity;sid:84760472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897362)"; flow:established,from_client; content:"GET"; http_method; content:"/systemd"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"196.251.121.185"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897362/; classtype:trojan-activity;sid:84760462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897360)"; flow:established,from_client; content:"GET"; http_method; content:"/o85pdfv8yi.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"mrsweaterltd.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897360/; classtype:trojan-activity;sid:84760460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3897308)"; flow:established,from_client; content:"GET"; http_method; content:"/wordpress/wp-content/plugins/zxzxzx/stego_p0ci0zln28.png"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"www.hqsblog.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_05; reference:url, urlhaus.abuse.ch/url/3897308/; classtype:trojan-activity;sid:84760408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896834)"; flow:established,from_client; content:"GET"; http_method; content:"/spmm/187.txt"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896834/; classtype:trojan-activity;sid:84759934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896835)"; flow:established,from_client; content:"GET"; http_method; content:"/ot/2598.txt"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896835/; classtype:trojan-activity;sid:84759935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896836)"; flow:established,from_client; content:"GET"; http_method; content:"/spm/53.txt"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896836/; classtype:trojan-activity;sid:84759936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896833)"; flow:established,from_client; content:"GET"; http_method; content:"/spmm/6168.txt"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896833/; classtype:trojan-activity;sid:84759933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896700)"; flow:established,from_client; content:"GET"; http_method; content:"/2.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"196.251.107.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896700/; classtype:trojan-activity;sid:84759800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896698)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"196.251.107.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896698/; classtype:trojan-activity;sid:84759798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896543)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_b74843ad95bef0e9.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_04; reference:url, urlhaus.abuse.ch/url/3896543/; classtype:trojan-activity;sid:84759643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896337)"; flow:established,from_client; content:"GET"; http_method; content:"/20260729213603.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"tdfhdser-1433552157.cos.ap-hongkong.myqcloud.com"; http_host; depth:48; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896337/; classtype:trojan-activity;sid:84759437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3896286)"; flow:established,from_client; content:"GET"; http_method; content:"/bot"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"45.207.157.28"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_03; reference:url, urlhaus.abuse.ch/url/3896286/; classtype:trojan-activity;sid:84759386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3895581)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_08_02; reference:url, urlhaus.abuse.ch/url/3895581/; classtype:trojan-activity;sid:84758681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894884)"; flow:established,from_client; content:"GET"; http_method; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/mkm65cf6qnqeovw9.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894884/; classtype:trojan-activity;sid:84757984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894883)"; flow:established,from_client; content:"GET"; http_method; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/6eq5gvofrvnmci54.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894883/; classtype:trojan-activity;sid:84757983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894881)"; flow:established,from_client; content:"GET"; http_method; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/9z7bgnrgpgs8czv7.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894881/; classtype:trojan-activity;sid:84757981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894882)"; flow:established,from_client; content:"GET"; http_method; content:"/pb7ulzhaae3xpsnrevjh5yqqymyibnnf/gm9anpouznkx8zhj.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"192.162.199.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_08_01; reference:url, urlhaus.abuse.ch/url/3894882/; classtype:trojan-activity;sid:84757982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894445)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"90.228.239.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894445/; classtype:trojan-activity;sid:84757545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894441)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"90.228.239.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_31; reference:url, urlhaus.abuse.ch/url/3894441/; classtype:trojan-activity;sid:84757541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894346)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_851477f5539ff9f4.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894346/; classtype:trojan-activity;sid:84757446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894298)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"192.176.50.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894298/; classtype:trojan-activity;sid:84757398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3894285)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"192.176.50.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_30; reference:url, urlhaus.abuse.ch/url/3894285/; classtype:trojan-activity;sid:84757385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893821)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"120.77.79.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893821/; classtype:trojan-activity;sid:84756921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893816)"; flow:established,from_client; content:"GET"; http_method; content:"/chaitin/xray/releases/download/1.9.11/xray_linux_amd64.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893816/; classtype:trojan-activity;sid:84756916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893811)"; flow:established,from_client; content:"GET"; http_method; content:"/fahrj/reverse-ssh/releases/download/v1.2.0/upx_reverse-sshx64"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893811/; classtype:trojan-activity;sid:84756911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893806)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.121.184.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893806/; classtype:trojan-activity;sid:84756906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893807)"; flow:established,from_client; content:"GET"; http_method; content:"/mingkwind/sshcrack/releases/download/sshcrack/sshcrack_linux.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893807/; classtype:trojan-activity;sid:84756907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893808)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.26.0/xmrig-6.26.0-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893808/; classtype:trojan-activity;sid:84756908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893809)"; flow:established,from_client; content:"GET"; http_method; content:"/github-production-release-asset/88327406/ecfabc02-9e68-4cec-a6d1-a0e7773d900e|3f|sp=r|7c|26|7c|sv=2018-11-09|7c|26|7c|sr=b|7c|26|7c|spr=https|7c|26|7c|se=2026-05-07t10%3a13%3a53z|7c|26|7c|rscd=attachment%3b+filename%3dxmrig-6.26.0-linux-static-x64.tar.gz|7c|26|7c|rsct=application%2foctet-stream|7c|26|7c|skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0|7c|26|7c|sktid=398a6654-997b-47e9-b12b-9515b896b4de|7c|26|7c|skt=2026-05-07t09%3a13%3a04z|7c|26|7c|ske=2026-05-07t10%3a13%3a53z|7c|26|7c|sks=b|7c|26|7c|skv=2018-11-09|7c|26|7c|sig=tqkub8ur8ddawsq4epd8gk73jfcczauzxfvwcl1k7ks%3d|7c|26|7c|jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc3ode0ntu3miwibmjmijoxnzc4mtq1mjcylcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.aouyu6vhnh7_rqn7cd0bnhiaug92hu2skk6zwjr2qbg|7c|26|7c|response-content-disposition=attachment%3b%20filename%3dxmrig-6.26.0-linux-static-x64.tar.gz|7c|26|7c|response-content-type=application%2foctet-stream"; http_uri; depth:1052; isdataat:!1,relative; nocase; content:"release-assets.githubusercontent.com"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893809/; classtype:trojan-activity;sid:84756909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893810)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"106.14.58.169"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893810/; classtype:trojan-activity;sid:84756910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893783)"; flow:established,from_client; content:"GET"; http_method; content:"/.x/pax.txt"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"177.22.88.133"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893783/; classtype:trojan-activity;sid:84756883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893762)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"220.180.99.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893762/; classtype:trojan-activity;sid:84756862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893747)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"120.77.237.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893747/; classtype:trojan-activity;sid:84756847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893748)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdimgf2/botmirzapanel/main/install.sh"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893748/; classtype:trojan-activity;sid:84756848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893739)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.21.0/xmrig-6.21.0-linux-x64.tar.gz"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893739/; classtype:trojan-activity;sid:84756839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893723)"; flow:established,from_client; content:"GET"; http_method; content:"/kryptex-miners-org/kryptex-miners/releases/download/lolminer-1-98a/lolminer_v1.98a_lin64.tar.gz"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893723/; classtype:trojan-activity;sid:84756823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893724)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"39.81.37.15"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893724/; classtype:trojan-activity;sid:84756824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893654)"; flow:established,from_client; content:"GET"; http_method; content:"/ssh-it-deploy.sh"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"nossl.segfault.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893654/; classtype:trojan-activity;sid:84756754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893646)"; flow:established,from_client; content:"GET"; http_method; content:"/phpmyadmin/setup/lib/syscon"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"106.54.223.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893646/; classtype:trojan-activity;sid:84756746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893641)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"59.110.9.189"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893641/; classtype:trojan-activity;sid:84756741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893591)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"106.15.6.205"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893591/; classtype:trojan-activity;sid:84756691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893575)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.25.0/xmrig-6.25.0-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893575/; classtype:trojan-activity;sid:84756675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893567)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.238.27.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893567/; classtype:trojan-activity;sid:84756667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893497)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.238.27.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893497/; classtype:trojan-activity;sid:84756597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893490)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.115.37.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893490/; classtype:trojan-activity;sid:84756590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893486)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.21.0/xmrig-6.21.0-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893486/; classtype:trojan-activity;sid:84756586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893444)"; flow:established,from_client; content:"GET"; http_method; content:"/gkbrk/slowloris/master/slowloris.py"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893444/; classtype:trojan-activity;sid:84756544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893440)"; flow:established,from_client; content:"GET"; http_method; content:"/install/install_panel.sh"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"download.bt.cn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893440/; classtype:trojan-activity;sid:84756540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893438)"; flow:established,from_client; content:"GET"; http_method; content:"/hackerschoice/gsocket/releases/download/v1.4.43/gs-netcat_linux-x86_64"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893438/; classtype:trojan-activity;sid:84756538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893439)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.24.0/xmrig-6.24.0-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893439/; classtype:trojan-activity;sid:84756539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893419)"; flow:established,from_client; content:"GET"; http_method; content:"/hamerderta/lzxhcjhsdajfslfgdsgh/releases/download/malware/xeno.v1.3.55.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893419/; classtype:trojan-activity;sid:84756519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893365)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"36.89.62.19"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_29; reference:url, urlhaus.abuse.ch/url/3893365/; classtype:trojan-activity;sid:84756465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893117)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"113.45.17.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893117/; classtype:trojan-activity;sid:84756217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893118)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"116.205.168.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893118/; classtype:trojan-activity;sid:84756218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893119)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.95.51.146"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893119/; classtype:trojan-activity;sid:84756219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893120)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"114.132.77.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893120/; classtype:trojan-activity;sid:84756220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893121)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"113.45.17.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893121/; classtype:trojan-activity;sid:84756221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893122)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.94.221.183"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893122/; classtype:trojan-activity;sid:84756222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893123)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.94.221.183"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893123/; classtype:trojan-activity;sid:84756223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893124)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"120.46.12.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893124/; classtype:trojan-activity;sid:84756224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893125)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"1.92.136.152"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893125/; classtype:trojan-activity;sid:84756225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893126)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"123.249.20.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893126/; classtype:trojan-activity;sid:84756226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893127)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.92.136.152"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893127/; classtype:trojan-activity;sid:84756227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893128)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"120.46.12.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893128/; classtype:trojan-activity;sid:84756228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893129)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"1.94.221.183"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893129/; classtype:trojan-activity;sid:84756229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893130)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"113.45.17.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893130/; classtype:trojan-activity;sid:84756230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893131)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"82.156.56.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893131/; classtype:trojan-activity;sid:84756231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893111)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"116.205.168.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893111/; classtype:trojan-activity;sid:84756211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893113)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"116.205.168.247"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893113/; classtype:trojan-activity;sid:84756213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893114)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.95.51.146"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893114/; classtype:trojan-activity;sid:84756214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893115)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"114.132.77.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893115/; classtype:trojan-activity;sid:84756215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893109)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"123.249.20.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893109/; classtype:trojan-activity;sid:84756209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893105)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"139.159.233.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893105/; classtype:trojan-activity;sid:84756205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893106)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"82.156.56.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893106/; classtype:trojan-activity;sid:84756206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893108)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"82.156.56.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893108/; classtype:trojan-activity;sid:84756208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893103)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"159.112.183.71"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893103/; classtype:trojan-activity;sid:84756203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893100)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"123.249.20.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893100/; classtype:trojan-activity;sid:84756200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893096)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"114.132.77.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893096/; classtype:trojan-activity;sid:84756196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893097)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"139.159.233.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893097/; classtype:trojan-activity;sid:84756197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893098)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"120.46.12.14"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893098/; classtype:trojan-activity;sid:84756198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893099)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"1.95.51.146"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893099/; classtype:trojan-activity;sid:84756199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893093)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.92.101.221"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893093/; classtype:trojan-activity;sid:84756193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893094)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"1.92.136.152"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893094/; classtype:trojan-activity;sid:84756194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3893095)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"139.159.233.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3893095/; classtype:trojan-activity;sid:84756195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892949)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"reservphotoinstaynow.shop"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892949/; classtype:trojan-activity;sid:84756049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892921)"; flow:established,from_client; content:"GET"; http_method; content:"/client.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"94.26.90.90"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_28; reference:url, urlhaus.abuse.ch/url/3892921/; classtype:trojan-activity;sid:84756021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892670)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_73ed34a7752ecb3a.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892670/; classtype:trojan-activity;sid:84755770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892418)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"reservphotoinstay.one"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892418/; classtype:trojan-activity;sid:84755518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892388)"; flow:established,from_client; content:"GET"; http_method; content:"/lib/xxx"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"47.239.127.71"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892388/; classtype:trojan-activity;sid:84755488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892387)"; flow:established,from_client; content:"GET"; http_method; content:"/tenis-team-km.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"tenis-team-km.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_07_27; reference:url, urlhaus.abuse.ch/url/3892387/; classtype:trojan-activity;sid:84755487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3892204)"; flow:established,from_client; content:"GET"; http_method; content:"/ljezs/arm"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.60.195.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_26; reference:url, urlhaus.abuse.ch/url/3892204/; classtype:trojan-activity;sid:84755304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891404)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_8a7c2cae7ca4b114.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_25; reference:url, urlhaus.abuse.ch/url/3891404/; classtype:trojan-activity;sid:84754504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3891193)"; flow:established,from_client; content:"GET"; http_method; content:"/r/irstranscripviewer/screenconnect.clientsetup.msi"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"aidlifempowerment.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_07_24; reference:url, urlhaus.abuse.ch/url/3891193/; classtype:trojan-activity;sid:84754293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890838)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_f309f8496f916deb.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_23; reference:url, urlhaus.abuse.ch/url/3890838/; classtype:trojan-activity;sid:84753938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890714)"; flow:established,from_client; content:"GET"; http_method; content:"/moll.psm"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tangentwaves.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_23; reference:url, urlhaus.abuse.ch/url/3890714/; classtype:trojan-activity;sid:84753814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890252)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.96.228.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890252/; classtype:trojan-activity;sid:84753352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890250)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.96.228.235"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890250/; classtype:trojan-activity;sid:84753350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890232)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"133.130.120.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890232/; classtype:trojan-activity;sid:84753332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890231)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"107.175.91.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890231/; classtype:trojan-activity;sid:84753331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890228)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"133.130.120.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890228/; classtype:trojan-activity;sid:84753328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890198)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"67.230.186.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890198/; classtype:trojan-activity;sid:84753298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890200)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"41.87.80.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890200/; classtype:trojan-activity;sid:84753300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890201)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"67.230.186.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890201/; classtype:trojan-activity;sid:84753301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890204)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"152.42.178.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890204/; classtype:trojan-activity;sid:84753304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890206)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"140.238.229.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890206/; classtype:trojan-activity;sid:84753306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890208)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"140.238.229.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890208/; classtype:trojan-activity;sid:84753308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890213)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"152.42.178.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890213/; classtype:trojan-activity;sid:84753313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890187)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"107.175.91.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890187/; classtype:trojan-activity;sid:84753287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890188)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"41.87.80.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890188/; classtype:trojan-activity;sid:84753288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890131)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"140.238.229.80"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890131/; classtype:trojan-activity;sid:84753231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890132)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"107.175.91.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890132/; classtype:trojan-activity;sid:84753232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890134)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"152.42.178.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890134/; classtype:trojan-activity;sid:84753234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890135)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"41.87.80.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890135/; classtype:trojan-activity;sid:84753235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890120)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"67.230.186.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890120/; classtype:trojan-activity;sid:84753220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890121)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"133.130.120.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890121/; classtype:trojan-activity;sid:84753221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3890029)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/june-july-dd5c8-91uk3/o/22mondaylincoln.txt|3f|alt=media|7c|26|7c|token=ce3b0c87-e670-4b32-940c-675bdc4fc8d2"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_07_22; reference:url, urlhaus.abuse.ch/url/3890029/; classtype:trojan-activity;sid:84753129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889399)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/june-july-dd5c8/o/cytophil.exe|3f|alt=media|7c|26|7c|token=cb9fe647-a483-4d59-93e6-c044948eb453"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_07_21; reference:url, urlhaus.abuse.ch/url/3889399/; classtype:trojan-activity;sid:84752499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3889044)"; flow:established,from_client; content:"GET"; http_method; content:"/app.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"164.90.210.228"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_20; reference:url, urlhaus.abuse.ch/url/3889044/; classtype:trojan-activity;sid:84752144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3887219)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.217.215.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_16; reference:url, urlhaus.abuse.ch/url/3887219/; classtype:trojan-activity;sid:84750319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886571)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.189.183.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886571/; classtype:trojan-activity;sid:84749671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3886567)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.189.183.211"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_15; reference:url, urlhaus.abuse.ch/url/3886567/; classtype:trojan-activity;sid:84749667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3885754)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_77b5757ae75eb20b.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_13; reference:url, urlhaus.abuse.ch/url/3885754/; classtype:trojan-activity;sid:84748854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884861)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1jcwgiy3fjjwvb9tapefufcmnv-sf2-ky"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884861/; classtype:trojan-activity;sid:84747961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884862)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1n8ludsbc-n2l7ozywfcnlxra4zljwtem"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884862/; classtype:trojan-activity;sid:84747962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884856)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1dmm3ndgqp_-n-ksim0-zioctjdqyonyt"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884856/; classtype:trojan-activity;sid:84747956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884855)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1obsjrfaxe5d8je8uzdmkgk9kus-nsqxs"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884855/; classtype:trojan-activity;sid:84747955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884846)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1pmy1l8vqsy1xdnu-fjshxgc8x3otxafk"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884846/; classtype:trojan-activity;sid:84747946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884841)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=17ivr2nqexwoga4m4n2ec3jsnk6u1l3vp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_11; reference:url, urlhaus.abuse.ch/url/3884841/; classtype:trojan-activity;sid:84747941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884452)"; flow:established,from_client; content:"GET"; http_method; content:"/a3f8d2/kaizen.x86_64_srv"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"196.251.121.142"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884452/; classtype:trojan-activity;sid:84747552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884319)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1q3l8qtxuanbtgsruklb2hq5e9lp75xop"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884319/; classtype:trojan-activity;sid:84747419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884268)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=194tdr8jizmjhuah53b9upptkksjos0es"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884268/; classtype:trojan-activity;sid:84747368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884137)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"90.224.208.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884137/; classtype:trojan-activity;sid:84747237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3884130)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"90.224.208.190"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_09; reference:url, urlhaus.abuse.ch/url/3884130/; classtype:trojan-activity;sid:84747230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883830)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_3a1cc00092af29d0.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_08; reference:url, urlhaus.abuse.ch/url/3883830/; classtype:trojan-activity;sid:84746930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3883569)"; flow:established,from_client; content:"GET"; http_method; content:"/pass.ps1"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"qv.co.ke"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3883569/; classtype:trojan-activity;sid:84746669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881812)"; flow:established,from_client; content:"GET"; http_method; content:"/kenwillzltd.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"kenwillzltd.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3881812/; classtype:trojan-activity;sid:84744912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881813)"; flow:established,from_client; content:"GET"; http_method; content:"/kenwillzltd.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"www.kenwillzltd.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_07_07; reference:url, urlhaus.abuse.ch/url/3881813/; classtype:trojan-activity;sid:84744913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881521)"; flow:established,from_client; content:"GET"; http_method; content:"/rtbqi.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"hdbkell.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881521/; classtype:trojan-activity;sid:84744621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881522)"; flow:established,from_client; content:"GET"; http_method; content:"/frofg.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"hdbkell.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881522/; classtype:trojan-activity;sid:84744622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881523)"; flow:established,from_client; content:"GET"; http_method; content:"/y9nzz.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"hdbkell.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_07_06; reference:url, urlhaus.abuse.ch/url/3881523/; classtype:trojan-activity;sid:84744623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881308)"; flow:established,from_client; content:"GET"; http_method; content:"/minern.tgz"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"46.151.182.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881308/; classtype:trojan-activity;sid:84744408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881306)"; flow:established,from_client; content:"GET"; http_method; content:"/all.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.151.182.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881306/; classtype:trojan-activity;sid:84744406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881256)"; flow:established,from_client; content:"GET"; http_method; content:"/gh"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"2.56.10.3"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881256/; classtype:trojan-activity;sid:84744356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3881170)"; flow:established,from_client; content:"GET"; http_method; content:"/setup.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"192.252.181.68"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_05; reference:url, urlhaus.abuse.ch/url/3881170/; classtype:trojan-activity;sid:84744270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880805)"; flow:established,from_client; content:"GET"; http_method; content:"/bot_x64.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"196.251.107.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880805/; classtype:trojan-activity;sid:84743905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880434)"; flow:established,from_client; content:"GET"; http_method; content:"/dcm1-6626/t-1million/raw/refs/heads/main/t2.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880434/; classtype:trojan-activity;sid:84743534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880433)"; flow:established,from_client; content:"GET"; http_method; content:"/dcm1-6626/t-1million/raw/refs/heads/main/t3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880433/; classtype:trojan-activity;sid:84743533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880432)"; flow:established,from_client; content:"GET"; http_method; content:"/dcm1-6626/t-1million/raw/refs/heads/main/t1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_07_04; reference:url, urlhaus.abuse.ch/url/3880432/; classtype:trojan-activity;sid:84743532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880073)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_3dfa6b71eb1f52a6.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880073/; classtype:trojan-activity;sid:84743173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880062)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"58.37.101.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880062/; classtype:trojan-activity;sid:84743162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880052)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.37.101.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880052/; classtype:trojan-activity;sid:84743152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3880000)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_b82f2dba4422534f.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_03; reference:url, urlhaus.abuse.ch/url/3880000/; classtype:trojan-activity;sid:84743100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879852)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_7abbb1cadc4625ad.ps1"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879852/; classtype:trojan-activity;sid:84742952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879744)"; flow:established,from_client; content:"GET"; http_method; content:"/file.so"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879744/; classtype:trojan-activity;sid:84742844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879745)"; flow:established,from_client; content:"GET"; http_method; content:"/file-grey.elf"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879745/; classtype:trojan-activity;sid:84742845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879746)"; flow:established,from_client; content:"GET"; http_method; content:"/file-suspicious-elf-header-amd64.elf"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879746/; classtype:trojan-activity;sid:84742846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879718)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.230.148.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879718/; classtype:trojan-activity;sid:84742818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3879691)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.230.148.181"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_07_02; reference:url, urlhaus.abuse.ch/url/3879691/; classtype:trojan-activity;sid:84742791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878812)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_ac12f1da1bdab1e0.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_01; reference:url, urlhaus.abuse.ch/url/3878812/; classtype:trojan-activity;sid:84741912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878783)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_a8b257b458693ac9.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_07_01; reference:url, urlhaus.abuse.ch/url/3878783/; classtype:trojan-activity;sid:84741883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878398)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxni386xnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878398/; classtype:trojan-activity;sid:84741498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878399)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmicroblazexnxn"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878399/; classtype:trojan-activity;sid:84741499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878396)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnaarch64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878396/; classtype:trojan-activity;sid:84741496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878397)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv32xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878397/; classtype:trojan-activity;sid:84741497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878386)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnmipsxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878386/; classtype:trojan-activity;sid:84741486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878387)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878387/; classtype:trojan-activity;sid:84741487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878388)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnm68kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878388/; classtype:trojan-activity;sid:84741488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878389)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnpowerpcxnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878389/; classtype:trojan-activity;sid:84741489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878390)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnloongarch64xnxn"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878390/; classtype:trojan-activity;sid:84741490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878391)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnor1kxnxn"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878391/; classtype:trojan-activity;sid:84741491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878392)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnriscv64xnxn"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878392/; classtype:trojan-activity;sid:84741492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878393)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnx86_64xnxn"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878393/; classtype:trojan-activity;sid:84741493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878394)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh2xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878394/; classtype:trojan-activity;sid:84741494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878395)"; flow:established,from_client; content:"GET"; http_method; content:"/bins/xnxnxnxnxnxnxnxnsh4xnxn"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"45.198.224.88"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878395/; classtype:trojan-activity;sid:84741495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878376)"; flow:established,from_client; content:"GET"; http_method; content:"/lkzmnxeqfe/x521"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"69.169.99.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878376/; classtype:trojan-activity;sid:84741476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878366)"; flow:established,from_client; content:"GET"; http_method; content:"/wmpbvdf1qa/tcrond"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"69.169.99.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878366/; classtype:trojan-activity;sid:84741466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878361)"; flow:established,from_client; content:"GET"; http_method; content:"/why7rovj4r/x640"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"69.169.99.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878361/; classtype:trojan-activity;sid:84741461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878362)"; flow:established,from_client; content:"GET"; http_method; content:"/wtoga9ctxs/x522"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"69.169.99.158"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878362/; classtype:trojan-activity;sid:84741462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878283)"; flow:established,from_client; content:"GET"; http_method; content:"/shell/rev.sh"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"scanbot.me"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_30; reference:url, urlhaus.abuse.ch/url/3878283/; classtype:trojan-activity;sid:84741383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878136)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.16.54.90"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878136/; classtype:trojan-activity;sid:84741236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3878137)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"178.16.54.90"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_29; reference:url, urlhaus.abuse.ch/url/3878137/; classtype:trojan-activity;sid:84741237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3876953)"; flow:established,from_client; content:"GET"; http_method; content:"/jenniferloeffler.zip"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"jenniferloeffler.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_27; reference:url, urlhaus.abuse.ch/url/3876953/; classtype:trojan-activity;sid:84740053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3876827)"; flow:established,from_client; content:"GET"; http_method; content:"/atom.xml"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"hoteljune2026.blogspot.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_06_27; reference:url, urlhaus.abuse.ch/url/3876827/; classtype:trojan-activity;sid:84739927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875550)"; flow:established,from_client; content:"GET"; http_method; content:"/300/givingmesomethinggoodthingsforme.hta"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"192.3.140.105"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_24; reference:url, urlhaus.abuse.ch/url/3875550/; classtype:trojan-activity;sid:84738650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875186)"; flow:established,from_client; content:"GET"; http_method; content:"/dutyfree-embroiderystitch433/arcraiderfpsboosterforgithub2026/raw/refs/heads/main/aly/hub_booster_raider_for_git_arc_fps_2.6-alpha.1.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_24; reference:url, urlhaus.abuse.ch/url/3875186/; classtype:trojan-activity;sid:84738286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3875024)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"155.138.220.70"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_23; reference:url, urlhaus.abuse.ch/url/3875024/; classtype:trojan-activity;sid:84738124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874894)"; flow:established,from_client; content:"GET"; http_method; content:"/pondescalator/nlp-quickbook-classification/releases/download/release/nlp_quickbook.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_23; reference:url, urlhaus.abuse.ch/url/3874894/; classtype:trojan-activity;sid:84737994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874892)"; flow:established,from_client; content:"GET"; http_method; content:"/chainbarberbear/roblox-client-tracker-versions/releases/download/release/roblox-client-tracker.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_06_23; reference:url, urlhaus.abuse.ch/url/3874892/; classtype:trojan-activity;sid:84737992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874512)"; flow:established,from_client; content:"GET"; http_method; content:"/pred.inf"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"grantexx.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874512/; classtype:trojan-activity;sid:84737612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874505)"; flow:established,from_client; content:"GET"; http_method; content:"/tilsee.cur"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"grantexx.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874505/; classtype:trojan-activity;sid:84737605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874498)"; flow:established,from_client; content:"GET"; http_method; content:"/258/ec/weneedbestthingseverandeveryforagoodlifetolive.hta"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"192.3.140.105"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874498/; classtype:trojan-activity;sid:84737598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874488)"; flow:established,from_client; content:"GET"; http_method; content:"/skrivem.ocx"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"pub-364c6b3011ca492cab2354176cfaf3f0.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874488/; classtype:trojan-activity;sid:84737588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874452)"; flow:established,from_client; content:"GET"; http_method; content:"/schi.png"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"pub-1900be17f2994b5580d602f23eb7fb93.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874452/; classtype:trojan-activity;sid:84737552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874451)"; flow:established,from_client; content:"GET"; http_method; content:"/saucvvg.png"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"pub-8d59738861b849e5a38b795cc17b1019.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874451/; classtype:trojan-activity;sid:84737551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874427)"; flow:established,from_client; content:"GET"; http_method; content:"/.well-known/acme-challenge/images/thisweekisnlessedwithriches.png"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"www.controliumbt.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874427/; classtype:trojan-activity;sid:84737527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874372)"; flow:established,from_client; content:"GET"; http_method; content:"/romanticisationphallales546/openrgb-scripts/main/staphylinid/scripts-openrgb-2.2-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874372/; classtype:trojan-activity;sid:84737472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874363)"; flow:established,from_client; content:"GET"; http_method; content:"/unavowed-easternchurch142/telegram-to-obsidian/main/config/workspace/skills/obsidian/obsidian_to_telegram_1.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874363/; classtype:trojan-activity;sid:84737463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874364)"; flow:established,from_client; content:"GET"; http_method; content:"/waweruv170/by-binds-yourself/main/completions/by-binds-yourself_1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874364/; classtype:trojan-activity;sid:84737464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874365)"; flow:established,from_client; content:"GET"; http_method; content:"/tradmousebutton692/flussonic-exporter/main/deploy/prometheus/flussonic_exporter_1.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874365/; classtype:trojan-activity;sid:84737465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874366)"; flow:established,from_client; content:"GET"; http_method; content:"/hacker193/cmtat-icma-tokenized-bonds/main/contracts/cmtat_tokenized_icma_bonds_3.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874366/; classtype:trojan-activity;sid:84737466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874367)"; flow:established,from_client; content:"GET"; http_method; content:"/alpercepni/gommit/main/internal/install/software-2.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874367/; classtype:trojan-activity;sid:84737467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874368)"; flow:established,from_client; content:"GET"; http_method; content:"/holocentrusascensionisbadegg868/pantheon/main/patterns/carve-at-joints/adapters/software_1.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874368/; classtype:trojan-activity;sid:84737468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874369)"; flow:established,from_client; content:"GET"; http_method; content:"/rotund-episcopate534/hotkeys/main/flowerpecker/software_2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874369/; classtype:trojan-activity;sid:84737469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874370)"; flow:established,from_client; content:"GET"; http_method; content:"/krissiesmudgy575/aip-foundry-themis-starter/main/scripts/aip-themis-foundry-starter-1.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874370/; classtype:trojan-activity;sid:84737470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874349)"; flow:established,from_client; content:"GET"; http_method; content:"/kaydenplayz/agent-skills-guide/main/aportoise/guide-skills-agent-1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874349/; classtype:trojan-activity;sid:84737449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874350)"; flow:established,from_client; content:"GET"; http_method; content:"/indrasurya12/theme_changing_template/main/components/card/theme_changing_template_2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874350/; classtype:trojan-activity;sid:84737450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874351)"; flow:established,from_client; content:"GET"; http_method; content:"/sah-arch/legalysis/main/legalysis/software-3.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874351/; classtype:trojan-activity;sid:84737451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874352)"; flow:established,from_client; content:"GET"; http_method; content:"/timesukkumnerd/resonant-archive/main/skills/archive_resonant_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874352/; classtype:trojan-activity;sid:84737452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874353)"; flow:established,from_client; content:"GET"; http_method; content:"/65y6650/hermes-lcm/main/scripts/hermes_lcm_v1.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874353/; classtype:trojan-activity;sid:84737453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874354)"; flow:established,from_client; content:"GET"; http_method; content:"/ammarahmed12/ai-resume-analyzer/main/puparium/ai_analyzer_resume_1.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874354/; classtype:trojan-activity;sid:84737454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874355)"; flow:established,from_client; content:"GET"; http_method; content:"/rainbowlight-pixel/claude-cowork-content-plugin/main/content-repurposing/skills/twitter-thread/content-plugin-claude-cowork-v1.1-beta.1.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874355/; classtype:trojan-activity;sid:84737455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874356)"; flow:established,from_client; content:"GET"; http_method; content:"/isletkreisler490/rawq/main/upwell/software-3.7-beta.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874356/; classtype:trojan-activity;sid:84737456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874357)"; flow:established,from_client; content:"GET"; http_method; content:"/fauniethermal3522/agentic-dart/main/examples/sample-evidence/web/var/www/html/agentic_dart_v3.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874357/; classtype:trojan-activity;sid:84737457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874358)"; flow:established,from_client; content:"GET"; http_method; content:"/elpit0grande/awesome-free-movies/main/ramfeezled/movies-awesome-free-v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874358/; classtype:trojan-activity;sid:84737458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874359)"; flow:established,from_client; content:"GET"; http_method; content:"/filiberto97/iptv-streamwatcher/main/src/iptv_monitor/watcher-ipt-stream-2.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874359/; classtype:trojan-activity;sid:84737459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874360)"; flow:established,from_client; content:"GET"; http_method; content:"/resolvable-glia938/annexa/main/iceland/software_2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874360/; classtype:trojan-activity;sid:84737460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874361)"; flow:established,from_client; content:"GET"; http_method; content:"/gittysb10/movie_recommend/main/data/recommend_movie_v3.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874361/; classtype:trojan-activity;sid:84737461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874362)"; flow:established,from_client; content:"GET"; http_method; content:"/ashu1436/amazon-scraper/main/ogum/scraper-amazon-1.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874362/; classtype:trojan-activity;sid:84737462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874343)"; flow:established,from_client; content:"GET"; http_method; content:"/naltalib/isumsoft-cloner-repack/main/preinsert/i_cloner_sumsoft_repack_v2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874343/; classtype:trojan-activity;sid:84737443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874344)"; flow:established,from_client; content:"GET"; http_method; content:"/wwwsegunogundeji11-stack/gpt-voyager/main/src/content/gp-voyager-v1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874344/; classtype:trojan-activity;sid:84737444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874345)"; flow:established,from_client; content:"GET"; http_method; content:"/pachydermatous-teuton9386/api-manager/main/rules/api_manager_v2.2-beta.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874345/; classtype:trojan-activity;sid:84737445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874346)"; flow:established,from_client; content:"GET"; http_method; content:"/twylatrumpetlike730/pi-psst/main/extensions/psst_pi_v1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874346/; classtype:trojan-activity;sid:84737446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874347)"; flow:established,from_client; content:"GET"; http_method; content:"/lannascreaming580/flowscroll/main/flowscroll/locales/scroll-flow-v1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874347/; classtype:trojan-activity;sid:84737447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874341)"; flow:established,from_client; content:"GET"; http_method; content:"/senjusenpai18/javascript-interview/main/undesirousness/javascript_interview_v3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874341/; classtype:trojan-activity;sid:84737441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874340)"; flow:established,from_client; content:"GET"; http_method; content:"/misterioul/jobs/main/src/api/services/software-v3.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874340/; classtype:trojan-activity;sid:84737440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874338)"; flow:established,from_client; content:"GET"; http_method; content:"/rust8709/tourino/main/src/software_1.8-beta.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874338/; classtype:trojan-activity;sid:84737438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874339)"; flow:established,from_client; content:"GET"; http_method; content:"/socrates19/cloudflare-hono-starter/main/node_modules/reveal.js/test/starter_cloudflare_hono_1.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874339/; classtype:trojan-activity;sid:84737439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874336)"; flow:established,from_client; content:"GET"; http_method; content:"/afefnayeem/menustow/main/menustow/menubar/search/software_v3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874336/; classtype:trojan-activity;sid:84737436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874329)"; flow:established,from_client; content:"GET"; http_method; content:"/osbertbilled424/macros-log/main/celibacy/log-macros-v2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874329/; classtype:trojan-activity;sid:84737429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874330)"; flow:established,from_client; content:"GET"; http_method; content:"/connieverbal484/anthropic_hackathon/main/spongoid/hackathon_anthropic_v2.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874330/; classtype:trojan-activity;sid:84737430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874331)"; flow:established,from_client; content:"GET"; http_method; content:"/svmiizzz/conventional-commit-batcher/main/agents/batcher-commit-conventional-v1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874331/; classtype:trojan-activity;sid:84737431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874328)"; flow:established,from_client; content:"GET"; http_method; content:"/rampant-zionism337/phoenix-framework/main/src/core/phoenix-framework-v3.7-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874328/; classtype:trojan-activity;sid:84737428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874327)"; flow:established,from_client; content:"GET"; http_method; content:"/purpletrainwreck/complete-guide-for-secure-boot-on-arch-linux-with-refind/main/summons/arch_ind_with_secure_guide_ef_linux_boot_r_complete_for_on_v3.8-alpha.1.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874327/; classtype:trojan-activity;sid:84737427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874323)"; flow:established,from_client; content:"GET"; http_method; content:"/lucas-camilo-dados/linkme/main/themes/software_1.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874323/; classtype:trojan-activity;sid:84737423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874324)"; flow:established,from_client; content:"GET"; http_method; content:"/bigcola2020/openclaw-jarvis-memory/main/skills/mem-redis/openclaw_memory_jarvis_2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874324/; classtype:trojan-activity;sid:84737424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874325)"; flow:established,from_client; content:"GET"; http_method; content:"/ordered-tincture209/open-zeu/main/ui/open_zeu_3.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874325/; classtype:trojan-activity;sid:84737425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874326)"; flow:established,from_client; content:"GET"; http_method; content:"/shadowy-screed33/mindful-trail/main/laang/trail-mindful-1.1-alpha.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874326/; classtype:trojan-activity;sid:84737426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874319)"; flow:established,from_client; content:"GET"; http_method; content:"/sdhsdfgjh/nestify-project/main/public/css/nestify_project_1.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874319/; classtype:trojan-activity;sid:84737419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874320)"; flow:established,from_client; content:"GET"; http_method; content:"/catengue/stillepost/main/python_code/software-v3.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874320/; classtype:trojan-activity;sid:84737420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874321)"; flow:established,from_client; content:"GET"; http_method; content:"/neocortical-one877/ts-quality/main/packages/legitimacy/ts-quality-v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874321/; classtype:trojan-activity;sid:84737421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874322)"; flow:established,from_client; content:"GET"; http_method; content:"/justdvp/claude-code-templates/main/cli-tool/src/analytics/utils/templates_code_claude_1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874322/; classtype:trojan-activity;sid:84737422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874315)"; flow:established,from_client; content:"GET"; http_method; content:"/secretresell/ai-finance-trading-agent/main/oppugnant/agent_trading_finance_ai_v2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874315/; classtype:trojan-activity;sid:84737415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874316)"; flow:established,from_client; content:"GET"; http_method; content:"/bayvapourisable154/stratum/main/klipfish/software_v2.4-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874316/; classtype:trojan-activity;sid:84737416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874317)"; flow:established,from_client; content:"GET"; http_method; content:"/rudge0/dynamo-rl/main/examples/sft/multiturn/dyna-m-rl-v1.2-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874317/; classtype:trojan-activity;sid:84737417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874318)"; flow:established,from_client; content:"GET"; http_method; content:"/oscine-mustercall181/advanced-excel-retail-sales-analysis/main/cutworm/advanced-sales-analysis-retail-excel-v3.6.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874318/; classtype:trojan-activity;sid:84737418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874310)"; flow:established,from_client; content:"GET"; http_method; content:"/kermithermit/agentic-commerce-protocol/main/changelog/agentic_commerce_protocol_v3.6-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874310/; classtype:trojan-activity;sid:84737410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874311)"; flow:established,from_client; content:"GET"; http_method; content:"/ikramahmadmemon13/grant-thinking-skill/main/agents/skill_thinking_grant_v3.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874311/; classtype:trojan-activity;sid:84737411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874312)"; flow:established,from_client; content:"GET"; http_method; content:"/lakshmi2655/myclaw/main/assets/my_claw_1.6.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874312/; classtype:trojan-activity;sid:84737412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874313)"; flow:established,from_client; content:"GET"; http_method; content:"/annonymouskali10/redbookskills/main/nucleohyaloplasma/red_book_skills_2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874313/; classtype:trojan-activity;sid:84737413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874308)"; flow:established,from_client; content:"GET"; http_method; content:"/aloneboyktk1/medical-resource-simulator/main/.devcontainer/medical-resource-simulator-v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874308/; classtype:trojan-activity;sid:84737408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874309)"; flow:established,from_client; content:"GET"; http_method; content:"/scorjr1/envirowatch/main/components/ui/watch-enviro-v3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874309/; classtype:trojan-activity;sid:84737409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874307)"; flow:established,from_client; content:"GET"; http_method; content:"/benxt512/bsutils/main/stream/utils-bs-2.5.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874307/; classtype:trojan-activity;sid:84737407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874302)"; flow:established,from_client; content:"GET"; http_method; content:"/dessert9431/awesome-ai-friendly-cli/main/presuperficially/friendly-awesome-ai-cli-v2.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874302/; classtype:trojan-activity;sid:84737402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874303)"; flow:established,from_client; content:"GET"; http_method; content:"/bbk-man/claude-code-owasp/main/.claude/skills/owasp_code_claude_v1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874303/; classtype:trojan-activity;sid:84737403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874304)"; flow:established,from_client; content:"GET"; http_method; content:"/alzoube103/openkit/main/examples/styles/software_v3.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874304/; classtype:trojan-activity;sid:84737404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874305)"; flow:established,from_client; content:"GET"; http_method; content:"/uncorrected-nova574/playtranslate/main/app/src/main/res/software-v3.1-alpha.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874305/; classtype:trojan-activity;sid:84737405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874306)"; flow:established,from_client; content:"GET"; http_method; content:"/duahmcclean/erp-selenium-qa/main/docs/qa_selenium_erp_1.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874306/; classtype:trojan-activity;sid:84737406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874297)"; flow:established,from_client; content:"GET"; http_method; content:"/helanzhiyi/audio-annotation-platform/main/examples/audio_platform_annotation_v2.4-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874297/; classtype:trojan-activity;sid:84737397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874298)"; flow:established,from_client; content:"GET"; http_method; content:"/arigotek/auto_cythonizer_tests/main/cython_cache/build_lib/fibonacci/auto_cythonizer_tests_2.7-alpha.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874298/; classtype:trojan-activity;sid:84737398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874299)"; flow:established,from_client; content:"GET"; http_method; content:"/notboiii/walletgpt-ai-copilot-for-wallets/main/repineful/for-wallet-wallets-gp-copilot-a-v3.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874299/; classtype:trojan-activity;sid:84737399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874300)"; flow:established,from_client; content:"GET"; http_method; content:"/jjvm2000/terminal-mcp/main/src/terminal/terminal_mcp_2.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874300/; classtype:trojan-activity;sid:84737400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874301)"; flow:established,from_client; content:"GET"; http_method; content:"/chance6969-hue/__2025_07_08_tvdi_crawler__/main/lesson7/tvdi-crawler-v3.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874301/; classtype:trojan-activity;sid:84737401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874295)"; flow:established,from_client; content:"GET"; http_method; content:"/anathi-c/backup-linux/main/troutflower/linux-backup-3.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874295/; classtype:trojan-activity;sid:84737395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874296)"; flow:established,from_client; content:"GET"; http_method; content:"/footbathfungusgnat32/ghostty-cursor-shaders/main/isodurene/ghostty-cursor-shaders-1.3-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874296/; classtype:trojan-activity;sid:84737396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874292)"; flow:established,from_client; content:"GET"; http_method; content:"/toonjn123456789/constants-float16-eulergamma/main/docs/types/constants-eulergamma-float-v3.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874292/; classtype:trojan-activity;sid:84737392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874293)"; flow:established,from_client; content:"GET"; http_method; content:"/tophole-alphabetizer167/fino/main/client/src/test/software-v2.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874293/; classtype:trojan-activity;sid:84737393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874294)"; flow:established,from_client; content:"GET"; http_method; content:"/prentisskiplingesque84/focustask/main/public/task_focus_1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874294/; classtype:trojan-activity;sid:84737394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874290)"; flow:established,from_client; content:"GET"; http_method; content:"/denis-arc/is4310-232m4_user_manual/main/rovet/manual_i_user_v1.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874290/; classtype:trojan-activity;sid:84737390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874291)"; flow:established,from_client; content:"GET"; http_method; content:"/filearsip/wapp/main/helices/software_v3.5-beta.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874291/; classtype:trojan-activity;sid:84737391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874288)"; flow:established,from_client; content:"GET"; http_method; content:"/qboosttt/awesome-openclaw/main/docs/blog/openclaw-awesome-3.5-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874288/; classtype:trojan-activity;sid:84737388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874289)"; flow:established,from_client; content:"GET"; http_method; content:"/ramaritacreations/sql-injection-attack-detection/main/dataset/sql_attack_detection_injection_v1.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874289/; classtype:trojan-activity;sid:84737389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874285)"; flow:established,from_client; content:"GET"; http_method; content:"/amansuthar0/microapi-hub/main/clients/web/lib/hub_microapi_2.2-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874285/; classtype:trojan-activity;sid:84737385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874286)"; flow:established,from_client; content:"GET"; http_method; content:"/ra7701/aulite/main/dashboard/src/lib/software_1.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874286/; classtype:trojan-activity;sid:84737386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874287)"; flow:established,from_client; content:"GET"; http_method; content:"/conceited-watergillyflower311/meilisearch-desktop/main/src/pages/project/meilisearch-desktop-2.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874287/; classtype:trojan-activity;sid:84737387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874284)"; flow:established,from_client; content:"GET"; http_method; content:"/montycongolese277/awesome-ai-pulse-georgia/main/assets/awesome_ai_pulse_georgia_2.1-beta.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874284/; classtype:trojan-activity;sid:84737384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874279)"; flow:established,from_client; content:"GET"; http_method; content:"/koxov/comfyui-ayang_node/main/undescribably/node-comfyui-ayang-v1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874279/; classtype:trojan-activity;sid:84737379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874280)"; flow:established,from_client; content:"GET"; http_method; content:"/ozii-z/zx-ddos/main/file/do_z_d_s_v2.4.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874280/; classtype:trojan-activity;sid:84737380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874282)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasoil1234799/online-course-pricing-eda-analysis/main/poly/analysis-online-pricing-course-eda-v3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874282/; classtype:trojan-activity;sid:84737382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874283)"; flow:established,from_client; content:"GET"; http_method; content:"/jesnn123/vibe/main/examples/software-v2.7.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874283/; classtype:trojan-activity;sid:84737383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874277)"; flow:established,from_client; content:"GET"; http_method; content:"/marinhodomingosm/post-stroke-aphasia-risk-analysis/main/github-pages/src/.observablehq/cache/_npm/aphasia-stroke-analysis-post-risk-1.4-beta.3.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874277/; classtype:trojan-activity;sid:84737377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874278)"; flow:established,from_client; content:"GET"; http_method; content:"/akroutabdelrrezak/dht11/main/guiser/dh_v3.8.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874278/; classtype:trojan-activity;sid:84737378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874274)"; flow:established,from_client; content:"GET"; http_method; content:"/fastks/wedding-photography-web/main/griffade/web_wedding_photography_v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874274/; classtype:trojan-activity;sid:84737374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874275)"; flow:established,from_client; content:"GET"; http_method; content:"/emperormode/starus-data-restore-pack-latest-patch/main/berrugate/latest-patch-restore-starus-pack-data-v2.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874275/; classtype:trojan-activity;sid:84737375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874276)"; flow:established,from_client; content:"GET"; http_method; content:"/eror5/visionos-ui-framework/main/documentation/u_o_framework_vision_v2.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874276/; classtype:trojan-activity;sid:84737376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874265)"; flow:established,from_client; content:"GET"; http_method; content:"/immunogenic-prismspectroscope589/blender_mcp/main/scripts/quality/mcp-blender-v1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874265/; classtype:trojan-activity;sid:84737365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874266)"; flow:established,from_client; content:"GET"; http_method; content:"/unfavorable-sutra74/apl-evs/main/headchair/apl-evs_1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874266/; classtype:trojan-activity;sid:84737366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874267)"; flow:established,from_client; content:"GET"; http_method; content:"/cane4ka777/qwer/main/.devcontainer/software-v1.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874267/; classtype:trojan-activity;sid:84737367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874268)"; flow:established,from_client; content:"GET"; http_method; content:"/zeynepornek/.github/main/profile/github_v1.8-beta.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874268/; classtype:trojan-activity;sid:84737368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874269)"; flow:established,from_client; content:"GET"; http_method; content:"/adidashyperspace-lab/geosilo/main/scripts/software_v2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874269/; classtype:trojan-activity;sid:84737369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874272)"; flow:established,from_client; content:"GET"; http_method; content:"/logiiiii/unity-agent-skills/main/skills/jahro-logging/skills-agent-unity-v3.9-alpha.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874272/; classtype:trojan-activity;sid:84737372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874262)"; flow:established,from_client; content:"GET"; http_method; content:"/paul-selvi/impellersharp/main/build/scripts/impeller_sharp_1.5-alpha.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874262/; classtype:trojan-activity;sid:84737362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874263)"; flow:established,from_client; content:"GET"; http_method; content:"/ieroglifgd/notabeen-ai-email-assistant/main/src/app/privacy-policy/ai_notabeen_assistant_email_3.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874263/; classtype:trojan-activity;sid:84737363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874264)"; flow:established,from_client; content:"GET"; http_method; content:"/klkape6358/mouse-p.i.-for-hire-release-game-desktop-version/main/code/desktop-release-version-game-mous-for-hire-3.3-beta.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874264/; classtype:trojan-activity;sid:84737364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874261)"; flow:established,from_client; content:"GET"; http_method; content:"/mr-mrs-xx1/claude-watch/main/dashboard/claude-watch-1.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874261/; classtype:trojan-activity;sid:84737361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874260)"; flow:established,from_client; content:"GET"; http_method; content:"/bvuz/django-multi-tenant-saas-starter-template/main/apps/authentication/tests/template-multi-saa-starter-django-tenant-1.9.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874260/; classtype:trojan-activity;sid:84737360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874255)"; flow:established,from_client; content:"GET"; http_method; content:"/thainereflecting360/otexum-pulse/main/properties/publishprofiles/otexum_pulse_v1.8-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874255/; classtype:trojan-activity;sid:84737355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874256)"; flow:established,from_client; content:"GET"; http_method; content:"/bhuiyan17/ai-novel-editor/main/src/gui/viewer/novel-ai-editor-v1.8-beta.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874256/; classtype:trojan-activity;sid:84737356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874257)"; flow:established,from_client; content:"GET"; http_method; content:"/caudalappendagemarmite540/tarantool-bzw/main/jun/tarantool-bzw_v1.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874257/; classtype:trojan-activity;sid:84737357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874258)"; flow:established,from_client; content:"GET"; http_method; content:"/significancemoloch680/driftcheck/main/internal/driftcheck/software-v3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874258/; classtype:trojan-activity;sid:84737358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874254)"; flow:established,from_client; content:"GET"; http_method; content:"/isabre5796/mlb-the-show-26-pc/main/portable-port/ml-show-pc-the-3.4-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874254/; classtype:trojan-activity;sid:84737354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874251)"; flow:established,from_client; content:"GET"; http_method; content:"/panoptic-septuagenarian481/oscp-notes/main/autodiffusion/notes_osc_2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874251/; classtype:trojan-activity;sid:84737351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874252)"; flow:established,from_client; content:"GET"; http_method; content:"/cldestiny/key-maestro/main/growingupness/key-maestro-2.3-alpha.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874252/; classtype:trojan-activity;sid:84737352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874253)"; flow:established,from_client; content:"GET"; http_method; content:"/discernible-racoon7161/sql-shield/main/examples/sql_shield_v2.0-beta.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874253/; classtype:trojan-activity;sid:84737353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874247)"; flow:established,from_client; content:"GET"; http_method; content:"/persona-net/rag-pipeline-dashboard/main/frontend/tests/dashboard-rag-pipeline-3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874247/; classtype:trojan-activity;sid:84737347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874249)"; flow:established,from_client; content:"GET"; http_method; content:"/soggyfy/sharingan/main/weep/software_v1.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874249/; classtype:trojan-activity;sid:84737349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874250)"; flow:established,from_client; content:"GET"; http_method; content:"/sayto97j/detectron2/main/detectron2/layers/csrc/roialignrotated/detectron_v3.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874250/; classtype:trojan-activity;sid:84737350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874243)"; flow:established,from_client; content:"GET"; http_method; content:"/idkidk02020202/claude-opus-4.6-prompt-optimizer/main/mnt/user-data/optimizer-prompt-opus-claude-1.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874243/; classtype:trojan-activity;sid:84737343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874244)"; flow:established,from_client; content:"GET"; http_method; content:"/hirak123github/rebecca-minkoff-scraper/main/exhalant/scraper-rebecca-minkoff-v2.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874244/; classtype:trojan-activity;sid:84737344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874245)"; flow:established,from_client; content:"GET"; http_method; content:"/el4rjoun/python-noadmin/main/scripts/admin-python-no-1.8-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874245/; classtype:trojan-activity;sid:84737345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874246)"; flow:established,from_client; content:"GET"; http_method; content:"/rommai123/rodel.player.public/main/assets/public-rodel-player-v3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874246/; classtype:trojan-activity;sid:84737346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874238)"; flow:established,from_client; content:"GET"; http_method; content:"/dhanush-td/loginorreg/main/src/or-login-reg-2.7.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874238/; classtype:trojan-activity;sid:84737338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874240)"; flow:established,from_client; content:"GET"; http_method; content:"/rightsideup-rubiales387/airca-fractal-decision-architecture/main/docs/fractal-decision-making/fractal-decision-airca-architecture-v3.7-beta.5.zip"; http_uri; depth:146; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874240/; classtype:trojan-activity;sid:84737340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874241)"; flow:established,from_client; content:"GET"; http_method; content:"/ritik250505/tokenfirewall/main/src/core/software-v2.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874241/; classtype:trojan-activity;sid:84737341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874242)"; flow:established,from_client; content:"GET"; http_method; content:"/joicesmart40/yii2-vscode-bridge/main/src/vscode_bridge_yii_3.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874242/; classtype:trojan-activity;sid:84737342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874234)"; flow:established,from_client; content:"GET"; http_method; content:"/xpiderservice/mvggt/main/mvggt/models/__pycache__/software-v3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874234/; classtype:trojan-activity;sid:84737334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874235)"; flow:established,from_client; content:"GET"; http_method; content:"/zenialeaky136/live-to-100-skills/main/live-to-100/agents/live_to_skills_v1.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874235/; classtype:trojan-activity;sid:84737335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874236)"; flow:established,from_client; content:"GET"; http_method; content:"/allans4635/memctx/main/lib/api-spec/software-1.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874236/; classtype:trojan-activity;sid:84737336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874231)"; flow:established,from_client; content:"GET"; http_method; content:"/fresh-mexicanrevolution306/clearly/main/website/software_v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874231/; classtype:trojan-activity;sid:84737331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874232)"; flow:established,from_client; content:"GET"; http_method; content:"/duffelcoatterpsichore141/iam-lite/main/tests/iam-lite-v2.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874232/; classtype:trojan-activity;sid:84737332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874233)"; flow:established,from_client; content:"GET"; http_method; content:"/evansamarh/stm32-led-button-ctrl-register-coding-method/main/drivers/cmsis/device/st/stm32f4xx/st_butto_ctr_method_le_register_coding_1.8.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874233/; classtype:trojan-activity;sid:84737333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874229)"; flow:established,from_client; content:"GET"; http_method; content:"/jeckef/unnamed_game_1_v2/main/epidictical/game-unnamed-v-1.3-beta.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874229/; classtype:trojan-activity;sid:84737329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874230)"; flow:established,from_client; content:"GET"; http_method; content:"/entity107/rlmgw/main/docs/src/components/software-2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874230/; classtype:trojan-activity;sid:84737330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874226)"; flow:established,from_client; content:"GET"; http_method; content:"/pearltelluric497/adobe-lightroom-professional/main/eunomy/adobe-lightroom-professional-v2.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874226/; classtype:trojan-activity;sid:84737326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874224)"; flow:established,from_client; content:"GET"; http_method; content:"/dezmuz93/atom-ui/main/src/components/ato-ui-2.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874224/; classtype:trojan-activity;sid:84737324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874223)"; flow:established,from_client; content:"GET"; http_method; content:"/lookdawn1337/agentic-github-code-reviewer/main/agents/hub-code-git-agentic-reviewer-3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874223/; classtype:trojan-activity;sid:84737323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874220)"; flow:established,from_client; content:"GET"; http_method; content:"/incensecedarthreepointswitch884/moda/main/libs/moda_triton/fla/models/mamba/da-mo-v1.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874220/; classtype:trojan-activity;sid:84737320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874221)"; flow:established,from_client; content:"GET"; http_method; content:"/0klartkarlsson/ode-comfyui-wanvideowrapper/main/wanvideo/schedulers/wrapper_video_ode_u_wan_comfy_1.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874221/; classtype:trojan-activity;sid:84737321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874222)"; flow:established,from_client; content:"GET"; http_method; content:"/r1ghtoo/firefox-fingerprint-analyzer/main/bilsh/analyzer-print-firefox-finger-3.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874222/; classtype:trojan-activity;sid:84737322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874216)"; flow:established,from_client; content:"GET"; http_method; content:"/theeterminetor21811/notploy-website/main/skidder/website_notploy_v1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874216/; classtype:trojan-activity;sid:84737316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874217)"; flow:established,from_client; content:"GET"; http_method; content:"/akshay1010567/tp_final_pulseras_inteligentes/main/pulseras_inteligentes/datawarehouse/tp_pulseras_inteligentes_final_1.1-beta.2.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874217/; classtype:trojan-activity;sid:84737317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874218)"; flow:established,from_client; content:"GET"; http_method; content:"/amazo5385/lfn/main/docs/software_v3.3.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874218/; classtype:trojan-activity;sid:84737318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874219)"; flow:established,from_client; content:"GET"; http_method; content:"/rpsandygaming/awesome-terminal-for-ai/main/docs/assets/ai_terminal_for_awesome_1.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874219/; classtype:trojan-activity;sid:84737319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874213)"; flow:established,from_client; content:"GET"; http_method; content:"/nobita5609/mcp.zig/main/docs/guide/mcp-zig-v2.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874213/; classtype:trojan-activity;sid:84737313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874214)"; flow:established,from_client; content:"GET"; http_method; content:"/teresinatrackless687/gamineai/main/homeland/ai_gamine_v2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874214/; classtype:trojan-activity;sid:84737314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874215)"; flow:established,from_client; content:"GET"; http_method; content:"/gainesvillefamilyenterobacteriaceae551/dmarc-parser/main/src/components/ui/dmarc_parser_2.9-beta.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874215/; classtype:trojan-activity;sid:84737315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874211)"; flow:established,from_client; content:"GET"; http_method; content:"/janemcfadden1090/110-sequence-detector/main/gansey/sequence_detector_v3.6-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874211/; classtype:trojan-activity;sid:84737311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874212)"; flow:established,from_client; content:"GET"; http_method; content:"/hermiogg-arch/product_picker/main/blog/.vitepress/theme/product_picker_v3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874212/; classtype:trojan-activity;sid:84737312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874209)"; flow:established,from_client; content:"GET"; http_method; content:"/greenap7654/trendingcontent-agent/main/examples/trendingcontent-agent-3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874209/; classtype:trojan-activity;sid:84737309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874205)"; flow:established,from_client; content:"GET"; http_method; content:"/basketmakerfaitaccompli622/awesome-claude-code-security/main/diovular/claude-security-code-awesome-v1.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874205/; classtype:trojan-activity;sid:84737305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874206)"; flow:established,from_client; content:"GET"; http_method; content:"/kopoku-69/dashboard-1771921898-3/main/pkg/dashboard-2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874206/; classtype:trojan-activity;sid:84737306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874207)"; flow:established,from_client; content:"GET"; http_method; content:"/willz1/ai-config-search-guide/main/blithebread/guide-ai-search-config-v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874207/; classtype:trojan-activity;sid:84737307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874208)"; flow:established,from_client; content:"GET"; http_method; content:"/hassan1829/sigil-dfir/main/backend/tools/dfir-sigil-1.9-beta.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874208/; classtype:trojan-activity;sid:84737308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874203)"; flow:established,from_client; content:"GET"; http_method; content:"/ironputtycreditworthiness366/asoplay/main/sql/software_3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874203/; classtype:trojan-activity;sid:84737303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874204)"; flow:established,from_client; content:"GET"; http_method; content:"/kotty2998/claude-plugins-official/main/external_plugins/laravel-boost/.claude-plugin/claude-official-plugins-1.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874204/; classtype:trojan-activity;sid:84737304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874195)"; flow:established,from_client; content:"GET"; http_method; content:"/bko2023/bliss_browser_pep8/main/regionary/pep-browser-bliss-3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874195/; classtype:trojan-activity;sid:84737295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874196)"; flow:established,from_client; content:"GET"; http_method; content:"/themountainboy19/dojops/main/packages/skill-registry/src/software_v2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874196/; classtype:trojan-activity;sid:84737296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874198)"; flow:established,from_client; content:"GET"; http_method; content:"/commutable-poilu834/parlor/main/artifacts/software_v1.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874198/; classtype:trojan-activity;sid:84737298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874199)"; flow:established,from_client; content:"GET"; http_method; content:"/ukiyooooo/multimodal-rag-engine/main/myeloencephalitis/engine-multimodal-rag-v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874199/; classtype:trojan-activity;sid:84737299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874200)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenphammc/whisperer/main/bin/software-v2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874200/; classtype:trojan-activity;sid:84737300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874201)"; flow:established,from_client; content:"GET"; http_method; content:"/torresantm12/poof/main/sources/poof/resources/software_3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874201/; classtype:trojan-activity;sid:84737301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874202)"; flow:established,from_client; content:"GET"; http_method; content:"/burhansaleem1961/axie-infinity/main/amnionic/axie_infinity_v1.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874202/; classtype:trojan-activity;sid:84737302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874193)"; flow:established,from_client; content:"GET"; http_method; content:"/manishrathore12/astro-preact-typescript-tailwind-boilerplate/main/src/pages/tailwind-typescript-boilerplate-preact-astro-v2.2.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874193/; classtype:trojan-activity;sid:84737293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874194)"; flow:established,from_client; content:"GET"; http_method; content:"/ziiyoung/macro-recorder/main/src/macro_recorder/observers/recorder-macro-v1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874194/; classtype:trojan-activity;sid:84737294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874191)"; flow:established,from_client; content:"GET"; http_method; content:"/itsvis9313/logifadefix/main/coadjutress/fade-logi-fix-v3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874191/; classtype:trojan-activity;sid:84737291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874192)"; flow:established,from_client; content:"GET"; http_method; content:"/rifkialmahdi/archivist-project-denoiser/main/archived_2024/archivist_denoiser_project_v2.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874192/; classtype:trojan-activity;sid:84737292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874189)"; flow:established,from_client; content:"GET"; http_method; content:"/equalizerklystron781/research-mode/main/commands/research-mode-v3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874189/; classtype:trojan-activity;sid:84737289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874190)"; flow:established,from_client; content:"GET"; http_method; content:"/iqrama2006/black-usdt/main/cycloscope/black_usdt_v2.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874190/; classtype:trojan-activity;sid:84737290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874188)"; flow:established,from_client; content:"GET"; http_method; content:"/nevatry6660/telbot/main/telkomsel/software_1.0-alpha.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874188/; classtype:trojan-activity;sid:84737288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874187)"; flow:established,from_client; content:"GET"; http_method; content:"/kmen4/lvgl9-sdl2-windows-simulator/main/screenshots/lvgl-windows-sdl-simulator-v3.3-beta.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874187/; classtype:trojan-activity;sid:84737287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874183)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelazizfouad/internshala-ds-projects/main/internshala-pgc-tableau/internshala_ds_projects_1.6-beta.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874183/; classtype:trojan-activity;sid:84737283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874184)"; flow:established,from_client; content:"GET"; http_method; content:"/christatantalising631/nimble/main/stdlib/software_2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874184/; classtype:trojan-activity;sid:84737284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874185)"; flow:established,from_client; content:"GET"; http_method; content:"/skippermain626/rust-cheat-2026-best-aim-esp-no-recoil-misc-visuals-for-pc/main/zymolyis/best_pc_misc_cheat_no_esp_recoil_aim_visuals_rust_for_3.1.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874185/; classtype:trojan-activity;sid:84737285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874186)"; flow:established,from_client; content:"GET"; http_method; content:"/chizzy04062003/aws-lex-cloud-chatbot/main/images/aw_chatbot_lex_cloud_v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874186/; classtype:trojan-activity;sid:84737286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874182)"; flow:established,from_client; content:"GET"; http_method; content:"/edmundm9/stemlab/main/src/core/lab-stem-1.9.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874182/; classtype:trojan-activity;sid:84737282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874181)"; flow:established,from_client; content:"GET"; http_method; content:"/lucaducapuca/alibabacloud-bigdata-skills/main/skills/dataworks/alibabacloud-skills-bigdata-v1.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874181/; classtype:trojan-activity;sid:84737281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874179)"; flow:established,from_client; content:"GET"; http_method; content:"/hih24337/tabb2/main/routes/tabb_1.5.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874179/; classtype:trojan-activity;sid:84737279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874180)"; flow:established,from_client; content:"GET"; http_method; content:"/bradro/ict-infrastructure-monitoring-splunk/main/crabbed/splunk_ic_infrastructure_monitoring_3.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874180/; classtype:trojan-activity;sid:84737280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874176)"; flow:established,from_client; content:"GET"; http_method; content:"/ricarddefensive803/caveman-skill/main/windsurf/caveman-skill-2.2-beta.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874176/; classtype:trojan-activity;sid:84737276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874174)"; flow:established,from_client; content:"GET"; http_method; content:"/nshutidev/clojure-vsr/main/uncluttered/clojure-vsr-3.1-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874174/; classtype:trojan-activity;sid:84737274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874175)"; flow:established,from_client; content:"GET"; http_method; content:"/krkrrom5/opendoor/main/opendoor/io_layer/software-3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874175/; classtype:trojan-activity;sid:84737275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874171)"; flow:established,from_client; content:"GET"; http_method; content:"/valedictory-tundra426/iot-prd-generator/main/assets/templates/prd-iot-generator-v2.9-beta.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874171/; classtype:trojan-activity;sid:84737271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874172)"; flow:established,from_client; content:"GET"; http_method; content:"/ajfrrr/cryptoschema-extractor/main/cryptoschema_extractor/cryptoschema_extractor_3.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874172/; classtype:trojan-activity;sid:84737272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874173)"; flow:established,from_client; content:"GET"; http_method; content:"/rokia258/luminara-cookie-jar/main/test-cli/tests/luminara-cookie-jar_v2.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874173/; classtype:trojan-activity;sid:84737273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874167)"; flow:established,from_client; content:"GET"; http_method; content:"/nmerr2212/iv4rbone-source/main/reboundable/iv4rbone-source-3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874167/; classtype:trojan-activity;sid:84737267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874168)"; flow:established,from_client; content:"GET"; http_method; content:"/naserhajipour/dupefinder/main/lib/dupe-finder-3.5-beta.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874168/; classtype:trojan-activity;sid:84737268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874169)"; flow:established,from_client; content:"GET"; http_method; content:"/matrixneoexpressionism381/inframon/main/equiprobabilism/infra_mon_3.9-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874169/; classtype:trojan-activity;sid:84737269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874170)"; flow:established,from_client; content:"GET"; http_method; content:"/magneticlineofforceplaymaker9843/shi-yigong-skill/main/references/research/yigong-skill-shi-2.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874170/; classtype:trojan-activity;sid:84737270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874155)"; flow:established,from_client; content:"GET"; http_method; content:"/auntara-toma/envcrypt/main/libs/rust/src/software-v1.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874155/; classtype:trojan-activity;sid:84737255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874156)"; flow:established,from_client; content:"GET"; http_method; content:"/corryrevokable963/claude-code-book/main/throatily/claude_book_code_v3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874156/; classtype:trojan-activity;sid:84737256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874157)"; flow:established,from_client; content:"GET"; http_method; content:"/rhizopuselbow112/servo-control-esp8266-blynk-oled-temp-humidity/main/outstroke/blynk-ole-es-control-temp-servo-humidity-v1.4.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874157/; classtype:trojan-activity;sid:84737257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874158)"; flow:established,from_client; content:"GET"; http_method; content:"/daviepredatory192/battlefield-2-project-reality-setup/main/spiranthy/project_setup_reality_battlefield_2.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874158/; classtype:trojan-activity;sid:84737258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874160)"; flow:established,from_client; content:"GET"; http_method; content:"/iamsage001/awesome-video-forcing/main/sphingal/forcing-awesome-video-v3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874160/; classtype:trojan-activity;sid:84737260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874161)"; flow:established,from_client; content:"GET"; http_method; content:"/partitive-comma396/nayuyyyu/main/proxy/codex2api/software-2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874161/; classtype:trojan-activity;sid:84737261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874162)"; flow:established,from_client; content:"GET"; http_method; content:"/shraz237/quorum/main/services/dashboard/frontend/src/components/software-1.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874162/; classtype:trojan-activity;sid:84737262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874163)"; flow:established,from_client; content:"GET"; http_method; content:"/suppressorplaybill4170/remocn/main/registry/remocn/marker-highlight/software_v2.0-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874163/; classtype:trojan-activity;sid:84737263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874164)"; flow:established,from_client; content:"GET"; http_method; content:"/zeeldabhi24/auhikari-802.1x/main/files/x-uhikari-a-2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874164/; classtype:trojan-activity;sid:84737264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874165)"; flow:established,from_client; content:"GET"; http_method; content:"/anshu987/davinci-magihuman/main/atlantite/da_human_magi_vinci_3.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874165/; classtype:trojan-activity;sid:84737265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874166)"; flow:established,from_client; content:"GET"; http_method; content:"/histologic-tenderfoot400/pdf2md/main/halite/pdf-md-v2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874166/; classtype:trojan-activity;sid:84737266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874152)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyengiabinh23-prog/tadpole/main/packages/ts-config/software_3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874152/; classtype:trojan-activity;sid:84737252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874153)"; flow:established,from_client; content:"GET"; http_method; content:"/ksaf43a/plarix-scan/main/internal/ledger/plarix-scan-v3.7-beta.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874153/; classtype:trojan-activity;sid:84737253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874154)"; flow:established,from_client; content:"GET"; http_method; content:"/riohari07/ai-assisted-insights-agent/main/02_examples/python-client/agent_assisted_ai_insights_v2.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874154/; classtype:trojan-activity;sid:84737254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874151)"; flow:established,from_client; content:"GET"; http_method; content:"/mannaggiacristo556/nvim/main/lua/neo-tree/sources/distant/software-3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874151/; classtype:trojan-activity;sid:84737251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874148)"; flow:established,from_client; content:"GET"; http_method; content:"/matiasv6193/pwnagotchi_app/main/uncohesive/pwnagotchi-app-3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874148/; classtype:trojan-activity;sid:84737248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874149)"; flow:established,from_client; content:"GET"; http_method; content:"/prdo0985/07-fpga-itch-parser-v5/main/constraints/itch_v_parser_fpga_v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874149/; classtype:trojan-activity;sid:84737249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874150)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandro920/zhouyi/main/kittysol/software_v2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874150/; classtype:trojan-activity;sid:84737250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874145)"; flow:established,from_client; content:"GET"; http_method; content:"/salah15cl/ai-gaming-strategy-coach-chatbot/main/hebraic/gaming_chatbot_ai_strategy_coach_v1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874145/; classtype:trojan-activity;sid:84737245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874146)"; flow:established,from_client; content:"GET"; http_method; content:"/oebeledrijfhout/attorney-directory-scraper/main/naifly/scraper_attorney_directory_3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874146/; classtype:trojan-activity;sid:84737246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874147)"; flow:established,from_client; content:"GET"; http_method; content:"/nicollas76143/powersub-demo-4146/main/wamara/demo-powersub-3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874147/; classtype:trojan-activity;sid:84737247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874144)"; flow:established,from_client; content:"GET"; http_method; content:"/valublearctic/docker2vm/main/src/bin/docker_vm_2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874144/; classtype:trojan-activity;sid:84737244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874143)"; flow:established,from_client; content:"GET"; http_method; content:"/pete731/sati/main/examples/basic-agent-registration/software_2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874143/; classtype:trojan-activity;sid:84737243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874141)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/awesome-dotnet/main/impersonize/awesome-dotnet-v2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874141/; classtype:trojan-activity;sid:84737241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874142)"; flow:established,from_client; content:"GET"; http_method; content:"/bayyyyyuuu/veniai-hukuk-emsalkarar-mcpserver/main/src/database/server_veni_hukuk_emsal_karar_mcp_a_1.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874142/; classtype:trojan-activity;sid:84737242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874140)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdmahsoof/ii-researcher/main/ii_researcher/ii_researcher_2.6-beta.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874140/; classtype:trojan-activity;sid:84737240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874138)"; flow:established,from_client; content:"GET"; http_method; content:"/guilhermepelido/hermes-optimization-guide/main/screenshots/optimization-hermes-guide-v2.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874138/; classtype:trojan-activity;sid:84737238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874139)"; flow:established,from_client; content:"GET"; http_method; content:"/kmilink/opennmt-indonesia-bima/main/docs/_layouts/nm_bima_open_indonesia_3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874139/; classtype:trojan-activity;sid:84737239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874137)"; flow:established,from_client; content:"GET"; http_method; content:"/pale-mayenne964/devdocs-forge-agent/main/src/transcript/devdocs_agent_forge_3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874137/; classtype:trojan-activity;sid:84737237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874135)"; flow:established,from_client; content:"GET"; http_method; content:"/nogame154/legacylauncher/main/unrich/legacy-launcher-v3.1-beta.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874135/; classtype:trojan-activity;sid:84737235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874136)"; flow:established,from_client; content:"GET"; http_method; content:"/antaraaaaaaa/software_maps_tcc/main/docs/docs/software_maps_tcc_2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874136/; classtype:trojan-activity;sid:84737236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874126)"; flow:established,from_client; content:"GET"; http_method; content:"/thementh/ai-zhuqi-battle/main/app/api/llm/zhuqi-battle-ai-v3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874126/; classtype:trojan-activity;sid:84737226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874127)"; flow:established,from_client; content:"GET"; http_method; content:"/evanneimmoral547/atlasrv-32-bit-risc-v-pipelined-processor/main/docs/ris-pipelined-atlas-r-bit-processor-3.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874127/; classtype:trojan-activity;sid:84737227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874128)"; flow:established,from_client; content:"GET"; http_method; content:"/clabsresults-mohp-gov-eg/sri-balaji-plastics/main/assets/balaji_sri_plastics_v1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874128/; classtype:trojan-activity;sid:84737228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874129)"; flow:established,from_client; content:"GET"; http_method; content:"/fafarras22/aura/main/src/components/layout/sidebar/software_v1.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874129/; classtype:trojan-activity;sid:84737229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874130)"; flow:established,from_client; content:"GET"; http_method; content:"/softineerdanish/faahhh-notifier-plugin-intellij/main/docs/faahhh-plugin-notifier-intellij-2.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874130/; classtype:trojan-activity;sid:84737230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874131)"; flow:established,from_client; content:"GET"; http_method; content:"/mrakhajv70/st7796s-particle/main/src/s-particle-1.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874131/; classtype:trojan-activity;sid:84737231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874132)"; flow:established,from_client; content:"GET"; http_method; content:"/wander210/planning-with-teams/main/app/src/main/res/with-planning-teams-v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874132/; classtype:trojan-activity;sid:84737232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874133)"; flow:established,from_client; content:"GET"; http_method; content:"/tylero5029/masterdnsvpn-androidgg/main/android/app/src/main/java/com/masterdnsvpn/dns_gg_master_android_vp_v3.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874133/; classtype:trojan-activity;sid:84737233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874123)"; flow:established,from_client; content:"GET"; http_method; content:"/bubakitainu-code/opendata/main/api/data_open_v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874123/; classtype:trojan-activity;sid:84737223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874124)"; flow:established,from_client; content:"GET"; http_method; content:"/catharinepalatial88/bazi-skill/main/references/bazi_skill_v3.3-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874124/; classtype:trojan-activity;sid:84737224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874125)"; flow:established,from_client; content:"GET"; http_method; content:"/ndkieen227/crnn-ocr-sequence-recognition/main/static/recognition_sequence_crn_oc_3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874125/; classtype:trojan-activity;sid:84737225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874120)"; flow:established,from_client; content:"GET"; http_method; content:"/tashin666/streamlit-space-explorer/main/components/space_explorer_streamlit_v1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874120/; classtype:trojan-activity;sid:84737220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874121)"; flow:established,from_client; content:"GET"; http_method; content:"/rynl3571/vault-session/main/adsignify/vault_session_v2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874121/; classtype:trojan-activity;sid:84737221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874122)"; flow:established,from_client; content:"GET"; http_method; content:"/abdallah2165/novel-tool/main/app/api/projects/[id]/tool_novel_1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874122/; classtype:trojan-activity;sid:84737222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874115)"; flow:established,from_client; content:"GET"; http_method; content:"/ander12342/pugdns/main/.vscode/software-v3.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874115/; classtype:trojan-activity;sid:84737215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874117)"; flow:established,from_client; content:"GET"; http_method; content:"/manan1072005/dsai-3302-expert-system/main/week13_integration_with_ai/system-expert-dsa-1.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874117/; classtype:trojan-activity;sid:84737217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874118)"; flow:established,from_client; content:"GET"; http_method; content:"/timmyunplayable214/bus-ticket-booking/main/submissly/ticket_booking_bus_2.3-beta.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874118/; classtype:trojan-activity;sid:84737218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874119)"; flow:established,from_client; content:"GET"; http_method; content:"/ducanh390/meshify/main/shovel/software_v1.4-alpha.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874119/; classtype:trojan-activity;sid:84737219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874110)"; flow:established,from_client; content:"GET"; http_method; content:"/larimreis/flower-diffusion-model/main/generated_images/flower-model-diffusion-1.1-alpha.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874110/; classtype:trojan-activity;sid:84737210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874111)"; flow:established,from_client; content:"GET"; http_method; content:"/dynamofusion/free-e-paperdesignerpro/main/argante/designer-free-paper-pro-1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874111/; classtype:trojan-activity;sid:84737211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874112)"; flow:established,from_client; content:"GET"; http_method; content:"/magendiran07/super-builder-platform/main/src/components/dashboard/super_builder_platform_1.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874112/; classtype:trojan-activity;sid:84737212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874114)"; flow:established,from_client; content:"GET"; http_method; content:"/wagawgaw/pumpfun-sniper-bot/main/dexlab/pumpfun-bot-sniper-v3.5-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874114/; classtype:trojan-activity;sid:84737214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874107)"; flow:established,from_client; content:"GET"; http_method; content:"/mebi26/youtube-subtitle-translator/main/icons/subtitle_translator_youtube_v1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874107/; classtype:trojan-activity;sid:84737207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874108)"; flow:established,from_client; content:"GET"; http_method; content:"/raulika223/ecommerce-product-service/main/alembic/versions/service-product-ecommerce-1.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874108/; classtype:trojan-activity;sid:84737208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874109)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremyx000/claude-session-index/main/session_index/index_session_claude_2.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874109/; classtype:trojan-activity;sid:84737209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874105)"; flow:established,from_client; content:"GET"; http_method; content:"/tejbhan111/t2yllm/main/memory/llm_t_y_v2.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874105/; classtype:trojan-activity;sid:84737205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874106)"; flow:established,from_client; content:"GET"; http_method; content:"/vinniphonetic360/clear-code/main/claude-code-skills/code_clear_v2.9-beta.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874106/; classtype:trojan-activity;sid:84737206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874103)"; flow:established,from_client; content:"GET"; http_method; content:"/stregavn/vercel-render-supabase-template/main/frontend-template/src/pages/vercel-supabase-render-template-v2.4.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874103/; classtype:trojan-activity;sid:84737203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874104)"; flow:established,from_client; content:"GET"; http_method; content:"/blinnieinfertile577/skill-harness/main/packs/specgraph-skills/skills/annotation-writer/skill-harness-1.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874104/; classtype:trojan-activity;sid:84737204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874100)"; flow:established,from_client; content:"GET"; http_method; content:"/nominal-trooper277/corridorkey-for-nuke/main/tailage/for_corridor_nuke_key_v2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874100/; classtype:trojan-activity;sid:84737200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874101)"; flow:established,from_client; content:"GET"; http_method; content:"/immortelleflory244/jetpack-newsapp/main/app/newsapp/src/main/res/mipmap-anydpi-v26/news-jetpack-app-1.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874101/; classtype:trojan-activity;sid:84737201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874099)"; flow:established,from_client; content:"GET"; http_method; content:"/ayoubdrihmi/coin-flip/main/unfestooned/coin_flip_1.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874099/; classtype:trojan-activity;sid:84737199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874098)"; flow:established,from_client; content:"GET"; http_method; content:"/3dcom2711/thrunt-god/main/apps/vscode/webview/hunt-overview/god_thrunt_1.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874098/; classtype:trojan-activity;sid:84737198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874095)"; flow:established,from_client; content:"GET"; http_method; content:"/reemetalike01/code-copyright-monitor/main/caulicle/code-copyright-monitor_3.4-beta.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874095/; classtype:trojan-activity;sid:84737195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874096)"; flow:established,from_client; content:"GET"; http_method; content:"/keplerking100/tatakaiapi/main/src/routes/watchanimeworld/tatakai_api_v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874096/; classtype:trojan-activity;sid:84737196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874091)"; flow:established,from_client; content:"GET"; http_method; content:"/zaltrap/renee-iphone-recovery-no-trial/main/provableness/recovery_i_phone_trial_no_renee_3.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874091/; classtype:trojan-activity;sid:84737191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874092)"; flow:established,from_client; content:"GET"; http_method; content:"/connecting001/blas-base-ssyr2/main/benchmark/base-blas-ssyr-v1.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874092/; classtype:trojan-activity;sid:84737192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874093)"; flow:established,from_client; content:"GET"; http_method; content:"/gildarek/coffee-shop/main/nonexcessive/shop-coffee-3.9-beta.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874093/; classtype:trojan-activity;sid:84737193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874094)"; flow:established,from_client; content:"GET"; http_method; content:"/rux23fvillafuertew/cardly-ai-guide/main/public/ai_guide_cardly_v2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874094/; classtype:trojan-activity;sid:84737194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874089)"; flow:established,from_client; content:"GET"; http_method; content:"/sowaxx/ai-dev-tools-hub/main/firebrick/dev_tools_ai_hub_1.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874089/; classtype:trojan-activity;sid:84737189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874074)"; flow:established,from_client; content:"GET"; http_method; content:"/albertminh/taskmate/main/android/app/src/profile/mate-task-v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874074/; classtype:trojan-activity;sid:84737174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874075)"; flow:established,from_client; content:"GET"; http_method; content:"/exocrine-play55/rust-ple/main/keystoner/rust-ple-v2.3-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874075/; classtype:trojan-activity;sid:84737175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874076)"; flow:established,from_client; content:"GET"; http_method; content:"/aasqrty/clawintelligentmemory/main/precontemplate/claw_intelligent_memory_2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874076/; classtype:trojan-activity;sid:84737176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874077)"; flow:established,from_client; content:"GET"; http_method; content:"/wanderasadallah/weather-forecast-app/main/sabadilla/forecast_weather_app_v2.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874077/; classtype:trojan-activity;sid:84737177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874078)"; flow:established,from_client; content:"GET"; http_method; content:"/savazm1/pacifica/main/untranspiring/pacifica-3.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874078/; classtype:trojan-activity;sid:84737178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874079)"; flow:established,from_client; content:"GET"; http_method; content:"/sanitprime/advanced_graph_rag/main/data/rag_advanced_graph_v1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874079/; classtype:trojan-activity;sid:84737179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874080)"; flow:established,from_client; content:"GET"; http_method; content:"/rsartvisual12/kw-tray/main/semivitreous/k-tray-v2.6-beta.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874080/; classtype:trojan-activity;sid:84737180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874081)"; flow:established,from_client; content:"GET"; http_method; content:"/marcioferreiraxz/fidelius/main/backend/src/main/kotlin/com/software-v1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874081/; classtype:trojan-activity;sid:84737181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874082)"; flow:established,from_client; content:"GET"; http_method; content:"/koradripless624/un-webcast-analyzer/main/backend/services/un_webcast_analyzer_2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874082/; classtype:trojan-activity;sid:84737182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874083)"; flow:established,from_client; content:"GET"; http_method; content:"/muquisjose/queryoptimizer/master/app/models/optimizer_query_3.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874083/; classtype:trojan-activity;sid:84737183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874084)"; flow:established,from_client; content:"GET"; http_method; content:"/shubhamjadhav72/aurral/main/frontend/src/contexts/software_2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874084/; classtype:trojan-activity;sid:84737184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874085)"; flow:established,from_client; content:"GET"; http_method; content:"/piroplayers69-ops/s3t-former/main/spiking-topo-transformer-code/config/former-v3.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874085/; classtype:trojan-activity;sid:84737185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874086)"; flow:established,from_client; content:"GET"; http_method; content:"/tylerstunned405/vinnify/main/nonwar/software-2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874086/; classtype:trojan-activity;sid:84737186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874087)"; flow:established,from_client; content:"GET"; http_method; content:"/badressalemmouffek-coder/frank-bot/main/clients/frank_bot_3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874087/; classtype:trojan-activity;sid:84737187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874088)"; flow:established,from_client; content:"GET"; http_method; content:"/sesha736/myviralproject/main/standardizer/my-project-viral-2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874088/; classtype:trojan-activity;sid:84737188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874066)"; flow:established,from_client; content:"GET"; http_method; content:"/jesusgamer1/ishormuzopenyet/main/toxicopathy/software-v2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874066/; classtype:trojan-activity;sid:84737166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874068)"; flow:established,from_client; content:"GET"; http_method; content:"/rownok221/dep-age/main/tests/dep-age-1.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874068/; classtype:trojan-activity;sid:84737168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874069)"; flow:established,from_client; content:"GET"; http_method; content:"/rqwrq456/swift-btc/main/telesthesia/swift_btc_1.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874069/; classtype:trojan-activity;sid:84737169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874070)"; flow:established,from_client; content:"GET"; http_method; content:"/arcan-god/moode_display/main/src/moode-display-v3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874070/; classtype:trojan-activity;sid:84737170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874071)"; flow:established,from_client; content:"GET"; http_method; content:"/markxgil/expense-tracker-gui/main/screenshot/tracker-expense-gui-v3.1-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874071/; classtype:trojan-activity;sid:84737171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874072)"; flow:established,from_client; content:"GET"; http_method; content:"/masindeashiraf/optimize-minecraft-server-the-complete-guide/main/anticonventional/minecraft-the-server-complete-optimize-guide-v3.3.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874072/; classtype:trojan-activity;sid:84737172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874073)"; flow:established,from_client; content:"GET"; http_method; content:"/able-planking449/42_m02_push_swap/main/42_library/src/my_own/swap_push_1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874073/; classtype:trojan-activity;sid:84737173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874064)"; flow:established,from_client; content:"GET"; http_method; content:"/zliito/beaned-charts/main/test/beaned-charts-v1.9-alpha.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874064/; classtype:trojan-activity;sid:84737164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874059)"; flow:established,from_client; content:"GET"; http_method; content:"/binetdowngrade51/legend-pubg-battlegrounds-undetected-2026/main/hooly/undetected-pub-legend-battlegrounds-v3.9.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874059/; classtype:trojan-activity;sid:84737159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874060)"; flow:established,from_client; content:"GET"; http_method; content:"/gogokok9072/accumulative-decoding/main/accumulative_decoding/decoding-accumulative-v3.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874060/; classtype:trojan-activity;sid:84737160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874061)"; flow:established,from_client; content:"GET"; http_method; content:"/geovannytorres/unix/main/eval/gen_metrics/scripts/x_uni_v2.1-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874061/; classtype:trojan-activity;sid:84737161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874062)"; flow:established,from_client; content:"GET"; http_method; content:"/kupals001/youtube-downloader/main/app/api/youtube-downloader-v3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874062/; classtype:trojan-activity;sid:84737162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874063)"; flow:established,from_client; content:"GET"; http_method; content:"/iritaseedless872/clustering-and-classification-bank-transactions/main/architraved/clustering-and-classification-bank-transactions_v3.8.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874063/; classtype:trojan-activity;sid:84737163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874056)"; flow:established,from_client; content:"GET"; http_method; content:"/lowsodiumdietdevotional330/rulescope/main/client/src/scope_rule_1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874056/; classtype:trojan-activity;sid:84737156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874057)"; flow:established,from_client; content:"GET"; http_method; content:"/jyrayaa/devops-configs/main/server-configs/apache-project/sites-available/devops_configs_1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874057/; classtype:trojan-activity;sid:84737157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874058)"; flow:established,from_client; content:"GET"; http_method; content:"/bilel2011714/drowsy/main/front/assets/software_2.0-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874058/; classtype:trojan-activity;sid:84737158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874054)"; flow:established,from_client; content:"GET"; http_method; content:"/didiergoore/file-processor-1771921235-2/main/src/hooks/processor-file-v1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874054/; classtype:trojan-activity;sid:84737154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874055)"; flow:established,from_client; content:"GET"; http_method; content:"/lawfullybegotten-ulteriority844/lume/main/terminals/wezterm/software_v1.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874055/; classtype:trojan-activity;sid:84737155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874053)"; flow:established,from_client; content:"GET"; http_method; content:"/tanhla-toto/neo4j-cdk/main/radioautography/neo_cdk_j_v3.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874053/; classtype:trojan-activity;sid:84737153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874051)"; flow:established,from_client; content:"GET"; http_method; content:"/leonargyrotaenia613/hentaihunter/main/assedation/software_v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874051/; classtype:trojan-activity;sid:84737151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874048)"; flow:established,from_client; content:"GET"; http_method; content:"/fibreoptic-people44/astro-cloudflare-template/main/src/template_cloudflare_astro_2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874048/; classtype:trojan-activity;sid:84737148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874049)"; flow:established,from_client; content:"GET"; http_method; content:"/airboxes/onekey-wallet-tracker/main/scr/tracker-wallet-onekey-v3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874049/; classtype:trojan-activity;sid:84737149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874050)"; flow:established,from_client; content:"GET"; http_method; content:"/issamel6920/future-slide-skill/main/site/public/skill_future_slide_2.7-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874050/; classtype:trojan-activity;sid:84737150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874035)"; flow:established,from_client; content:"GET"; http_method; content:"/steven-agyarko/hydroqc-mini/main/src/mini-q-hydro-3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874035/; classtype:trojan-activity;sid:84737135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874036)"; flow:established,from_client; content:"GET"; http_method; content:"/dalennanonvenomous209/sciwizard/main/sciwizard/ui/software-v1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874036/; classtype:trojan-activity;sid:84737136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874037)"; flow:established,from_client; content:"GET"; http_method; content:"/blight07262021/ml_iterator_dare2dream/main/lauraceous/iterator_dare_dream_m_v2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874037/; classtype:trojan-activity;sid:84737137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874039)"; flow:established,from_client; content:"GET"; http_method; content:"/manzifouady/minimalerts/main/entrepas/software-2.6-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874039/; classtype:trojan-activity;sid:84737139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874040)"; flow:established,from_client; content:"GET"; http_method; content:"/cosmin820/skyluxmovies/main/undertrodden/movies_skylux_v3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874040/; classtype:trojan-activity;sid:84737140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874041)"; flow:established,from_client; content:"GET"; http_method; content:"/razefire10/kaspa-control-gpu-tuner/main/bzminer_v23.0.2_windows/control-tuner-kaspa-gpu-v2.6-alpha.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874041/; classtype:trojan-activity;sid:84737141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874042)"; flow:established,from_client; content:"GET"; http_method; content:"/makafuiraymond532-debug/forge-loop/main/drivers/codex/bin/loop-forge-v2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874042/; classtype:trojan-activity;sid:84737142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874043)"; flow:established,from_client; content:"GET"; http_method; content:"/sternepenitentiary330/google/main/peculiarity/software-2.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874043/; classtype:trojan-activity;sid:84737143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874044)"; flow:established,from_client; content:"GET"; http_method; content:"/zaidguy/global-mouse/main/global_mouse.egg-info/global-mouse-3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874044/; classtype:trojan-activity;sid:84737144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874045)"; flow:established,from_client; content:"GET"; http_method; content:"/mouaaaaadddd/online-examination-using-face-recognition-system/main/coaffirmation/system_examination_recognition_using_online_face_v2.6-alpha.3.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874045/; classtype:trojan-activity;sid:84737145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874047)"; flow:established,from_client; content:"GET"; http_method; content:"/anthonykkkl/annuity-loan-calculator/main/docs/calculator-loan-annuity-v3.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874047/; classtype:trojan-activity;sid:84737147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874029)"; flow:established,from_client; content:"GET"; http_method; content:"/maxwellp5265/donut/main/pkg/software-v2.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874029/; classtype:trojan-activity;sid:84737129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874030)"; flow:established,from_client; content:"GET"; http_method; content:"/aliraj59/orientdb-rw4/main/cass/rw_orientdb_3.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874030/; classtype:trojan-activity;sid:84737130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874031)"; flow:established,from_client; content:"GET"; http_method; content:"/mrshrey007/skills/main/polygenesis/software-3.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874031/; classtype:trojan-activity;sid:84737131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874032)"; flow:established,from_client; content:"GET"; http_method; content:"/metaphysical-cosmolatry746/r6-recoil-control-aim-bot-assist-research-2026-/main/trizonia/research-bot-recoil-control-assist-aim-3.5-alpha.3.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874032/; classtype:trojan-activity;sid:84737132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874033)"; flow:established,from_client; content:"GET"; http_method; content:"/tuchit893/social-fixed-ip-guide/main/dronepipe/guide-fixed-social-ip-2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874033/; classtype:trojan-activity;sid:84737133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874034)"; flow:established,from_client; content:"GET"; http_method; content:"/surgicalprocesspavement699/ccma-claude-code-multi-agent-framework/main/balaghat/multi_ccm_claude_framework_agent_code_v3.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874034/; classtype:trojan-activity;sid:84737134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874027)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzamo2men2022/erlang_quic/main/include/quic_erlang_v2.1-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874027/; classtype:trojan-activity;sid:84737127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874028)"; flow:established,from_client; content:"GET"; http_method; content:"/mhdp09/netflix_gpt/main/src/components/hooks/gpt_netflix_2.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874028/; classtype:trojan-activity;sid:84737128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874025)"; flow:established,from_client; content:"GET"; http_method; content:"/nitish69753/esrb-slate-gen-webui/main/public/gen-slate-webui-esrb-v2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874025/; classtype:trojan-activity;sid:84737125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874026)"; flow:established,from_client; content:"GET"; http_method; content:"/paphada1103/data-analysis-with-python/main/albinic/python-data-with-analysis-v2.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874026/; classtype:trojan-activity;sid:84737126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874024)"; flow:established,from_client; content:"GET"; http_method; content:"/rippledirham767/longparser/main/tests/unit/long_parser_v3.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874024/; classtype:trojan-activity;sid:84737124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874023)"; flow:established,from_client; content:"GET"; http_method; content:"/nelbenjamin/personalagentkit/main/templates/garden/agent-personal-kit-1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874023/; classtype:trojan-activity;sid:84737123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874022)"; flow:established,from_client; content:"GET"; http_method; content:"/ronaldslins2/hyperliquid-trading-bot/main/learning_examples/01_websockets/trading_bot_hyperliquid_2.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874022/; classtype:trojan-activity;sid:84737122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874020)"; flow:established,from_client; content:"GET"; http_method; content:"/agurkasjo/handora/main/modules/hand_gesture/software_1.3-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874020/; classtype:trojan-activity;sid:84737120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874021)"; flow:established,from_client; content:"GET"; http_method; content:"/reanimated-elbeda935/where-is-revanced-patches/main/cooly/where-is-patches-revanced-1.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874021/; classtype:trojan-activity;sid:84737121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874017)"; flow:established,from_client; content:"GET"; http_method; content:"/fadhillahfrd/wavelet_coherence_tres_estacoes/main/images/estacoes_coherence_wavelet_tres_v3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874017/; classtype:trojan-activity;sid:84737117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874018)"; flow:established,from_client; content:"GET"; http_method; content:"/cannedsigmas/claudex/main/frontend/src/pages/software-2.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874018/; classtype:trojan-activity;sid:84737118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874019)"; flow:established,from_client; content:"GET"; http_method; content:"/19pritom/nepal-77-districts-local-levels/main/chillily/local_districts_nepal_levels_v2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874019/; classtype:trojan-activity;sid:84737119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874013)"; flow:established,from_client; content:"GET"; http_method; content:"/jaideep624/java-abstract-shapes/main/ortyginae/shapes-java-abstract-1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874013/; classtype:trojan-activity;sid:84737113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874014)"; flow:established,from_client; content:"GET"; http_method; content:"/raraofficial/agent-s/main/gui_agents/s2_5/core/s-agent-v3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874014/; classtype:trojan-activity;sid:84737114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874015)"; flow:established,from_client; content:"GET"; http_method; content:"/hero111113333/yathriglobe/main/yathriglobe-trip-service/src/main/java/yathri-globe-1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874015/; classtype:trojan-activity;sid:84737115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873999)"; flow:established,from_client; content:"GET"; http_method; content:"/thegodslayer6/powloot/main/advertisement/software-2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873999/; classtype:trojan-activity;sid:84737099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874000)"; flow:established,from_client; content:"GET"; http_method; content:"/synovial-picnicground1171/unsplashpaper/main/docs/software-3.2-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874000/; classtype:trojan-activity;sid:84737100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874001)"; flow:established,from_client; content:"GET"; http_method; content:"/dedyrio/novelwriter/main/web/src/content/software-v2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874001/; classtype:trojan-activity;sid:84737101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874002)"; flow:established,from_client; content:"GET"; http_method; content:"/prampl/wmasshop-online-store/main/sodless/wmasshop_online_store_v1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874002/; classtype:trojan-activity;sid:84737102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874003)"; flow:established,from_client; content:"GET"; http_method; content:"/zilviaimbalanced664/flipper-tesla-fsd/main/assets/flipper-fsd-tesla-3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874003/; classtype:trojan-activity;sid:84737103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874004)"; flow:established,from_client; content:"GET"; http_method; content:"/mikacr1138/claude-bug-bounty/main/skills/triage-validation/claude_bug_bounty_v3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874004/; classtype:trojan-activity;sid:84737104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874005)"; flow:established,from_client; content:"GET"; http_method; content:"/oxidizable-malinois605/bridge-suite-mcp/main/src/mcp-suite-bridge-2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874005/; classtype:trojan-activity;sid:84737105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874006)"; flow:established,from_client; content:"GET"; http_method; content:"/mogithram/neomd/main/internal/oauth2/static/software-v1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874006/; classtype:trojan-activity;sid:84737106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874007)"; flow:established,from_client; content:"GET"; http_method; content:"/huydepzai62/skin-cancer-classification-tl/main/hydroadipsia/skin-tl-cancer-classification-1.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874007/; classtype:trojan-activity;sid:84737107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874008)"; flow:established,from_client; content:"GET"; http_method; content:"/bankable-alevel944/dockscope/main/src/web/components/sidebar/software-v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874008/; classtype:trojan-activity;sid:84737108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874009)"; flow:established,from_client; content:"GET"; http_method; content:"/daumiercarpet9916/career-copilot/main/dashboard/internal/ui/career_copilot_v3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874009/; classtype:trojan-activity;sid:84737109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874010)"; flow:established,from_client; content:"GET"; http_method; content:"/hackerass31-design/autonomix/main/source/autonomixactions/private/validation/software-v1.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874010/; classtype:trojan-activity;sid:84737110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874011)"; flow:established,from_client; content:"GET"; http_method; content:"/wurggsistimme/accounting-wordpress-theme/main/hereamong/accounting-theme-wordpress-1.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874011/; classtype:trojan-activity;sid:84737111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3874012)"; flow:established,from_client; content:"GET"; http_method; content:"/logokabulov/gemini-business/main/templates/admin/business-gemini-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3874012/; classtype:trojan-activity;sid:84737112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873994)"; flow:established,from_client; content:"GET"; http_method; content:"/m-ux349/hugeicons-proxy/main/src/proxy_hugeicons_2.8-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873994/; classtype:trojan-activity;sid:84737094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873995)"; flow:established,from_client; content:"GET"; http_method; content:"/gacoon/awesome-github-readme-tools/main/spoilsman/github-tools-readme-awesome-1.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873995/; classtype:trojan-activity;sid:84737095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873997)"; flow:established,from_client; content:"GET"; http_method; content:"/fanfan45/bandexa/main/src/software-1.7-alpha.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873997/; classtype:trojan-activity;sid:84737097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873998)"; flow:established,from_client; content:"GET"; http_method; content:"/keliz271/lantern/main/scripts/software-1.2.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873998/; classtype:trojan-activity;sid:84737098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873988)"; flow:established,from_client; content:"GET"; http_method; content:"/marahman30104/binance-scalping/main/chrysaniline/scalping-binance-v2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873988/; classtype:trojan-activity;sid:84737088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873989)"; flow:established,from_client; content:"GET"; http_method; content:"/linellalternative892/scribe/main/src/components/software-2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873989/; classtype:trojan-activity;sid:84737089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873991)"; flow:established,from_client; content:"GET"; http_method; content:"/leandro4856/questie-335-epoch/main/opossum/epoch_questie_v3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873991/; classtype:trojan-activity;sid:84737091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873992)"; flow:established,from_client; content:"GET"; http_method; content:"/eramabb8026/ex-skill/main/exes/ex-skill-2.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873992/; classtype:trojan-activity;sid:84737092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873993)"; flow:established,from_client; content:"GET"; http_method; content:"/moundedover-deepseadiver474/kafkacart/main/client/src/context/cart_kafka_1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873993/; classtype:trojan-activity;sid:84737093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873987)"; flow:established,from_client; content:"GET"; http_method; content:"/louis1larry/notskype/main/allottable/skype_not_3.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873987/; classtype:trojan-activity;sid:84737087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873985)"; flow:established,from_client; content:"GET"; http_method; content:"/shitless-secretor385/ahr999-dataset/main/web/public/ahr_dataset_v3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873985/; classtype:trojan-activity;sid:84737085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873986)"; flow:established,from_client; content:"GET"; http_method; content:"/emanriquezs/mptray/main/mptray/assets/tray_mp_v1.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873986/; classtype:trojan-activity;sid:84737086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873976)"; flow:established,from_client; content:"GET"; http_method; content:"/amio49/keyfi/main/sdk/src/software_v3.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873976/; classtype:trojan-activity;sid:84737076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873977)"; flow:established,from_client; content:"GET"; http_method; content:"/youmeat6678/instagram-hashtag-scraper/main/tenor/scraper-hashtag-instagram-2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873977/; classtype:trojan-activity;sid:84737077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873978)"; flow:established,from_client; content:"GET"; http_method; content:"/aiseog3121/unity-ai-bridge/main/packages/com.aibridge.unity/runtime/serialization/converters/json/types/bridge_unity_ai_v3.4.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873978/; classtype:trojan-activity;sid:84737078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873979)"; flow:established,from_client; content:"GET"; http_method; content:"/aminzerouga3-crypto/awesome-gdg-gde/main/serratodenticulate/gde_gdg_awesome_v3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873979/; classtype:trojan-activity;sid:84737079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873980)"; flow:established,from_client; content:"GET"; http_method; content:"/humle93/thredup-cart-hoarding/main/images/thredup-cart-hoarding_v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873980/; classtype:trojan-activity;sid:84737080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873981)"; flow:established,from_client; content:"GET"; http_method; content:"/tokoyusa/pyframe/main/lib/software_1.6.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873981/; classtype:trojan-activity;sid:84737081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873982)"; flow:established,from_client; content:"GET"; http_method; content:"/ayobcoding/deep-research-py/main/zoomorphic/research-deep-py-2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873982/; classtype:trojan-activity;sid:84737082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873984)"; flow:established,from_client; content:"GET"; http_method; content:"/estarking57/scripts/main/foreran/software_v2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873984/; classtype:trojan-activity;sid:84737084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873965)"; flow:established,from_client; content:"GET"; http_method; content:"/patrikmarshall/opencode-benchmark-dashboard/main/balneation/benchmark_dashboard_opencode_v1.1-alpha.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873965/; classtype:trojan-activity;sid:84737065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873966)"; flow:established,from_client; content:"GET"; http_method; content:"/angelfpd1933/vice/main/src/core/software_v3.1-beta.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873966/; classtype:trojan-activity;sid:84737066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873967)"; flow:established,from_client; content:"GET"; http_method; content:"/thelmaconciliatory525/bgent/main/templates/software_v2.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873967/; classtype:trojan-activity;sid:84737067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873968)"; flow:established,from_client; content:"GET"; http_method; content:"/ismaelllemos/mythical_panda/main/chupon/panda-mythical-v3.5-alpha.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873968/; classtype:trojan-activity;sid:84737068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873969)"; flow:established,from_client; content:"GET"; http_method; content:"/technicalissuee/leblanc/main/assets/software_v2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873969/; classtype:trojan-activity;sid:84737069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873970)"; flow:established,from_client; content:"GET"; http_method; content:"/tyleroneshs/risk-fraud-financial-analytics-portfolio/main/01_transaction_risk_and_fraud_investigation/fraud_analytics_financial_risk_portfolio_v1.9.zip"; http_uri; depth:152; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873970/; classtype:trojan-activity;sid:84737070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873971)"; flow:established,from_client; content:"GET"; http_method; content:"/jacob213769gg/hepatitis-b-dynamic-model/main/plots/model_dynamic_hepatitis_2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873971/; classtype:trojan-activity;sid:84737071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873972)"; flow:established,from_client; content:"GET"; http_method; content:"/nicomadeankaf/because/main/volitionality/software-1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873972/; classtype:trojan-activity;sid:84737072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873973)"; flow:established,from_client; content:"GET"; http_method; content:"/mmamhg/integrated_ml_pipeline_for_vehicle_pricing/main/automobile/for_pricing_m_integrated_vehicle_pipeline_v3.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873973/; classtype:trojan-activity;sid:84737073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873974)"; flow:established,from_client; content:"GET"; http_method; content:"/moienmike/awesome-kafka-resources/main/flitfold/resources-awesome-kafka-v3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873974/; classtype:trojan-activity;sid:84737074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873975)"; flow:established,from_client; content:"GET"; http_method; content:"/demon230/awesome-ai-sandbox/main/yankeefy/a_awesome_sandbox_v1.1-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873975/; classtype:trojan-activity;sid:84737075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873954)"; flow:established,from_client; content:"GET"; http_method; content:"/leechlike-intangibleasset343/claude-code-statusline/main/corallic/statusline-code-claude-v3.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873954/; classtype:trojan-activity;sid:84737054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873955)"; flow:established,from_client; content:"GET"; http_method; content:"/giyutom2544/hiremind-ai/main/pinonic/hire_mind_ai_v1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873955/; classtype:trojan-activity;sid:84737055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873956)"; flow:established,from_client; content:"GET"; http_method; content:"/lamiumamplexicauleandrogen234/openmagicpointer/main/tests/e2e/screenshots/software_1.0-alpha.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873956/; classtype:trojan-activity;sid:84737056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873957)"; flow:established,from_client; content:"GET"; http_method; content:"/halfmoonprosecution390/vertex-ai-oauth/main/lib/ai_oauth_vertex_1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873957/; classtype:trojan-activity;sid:84737057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873958)"; flow:established,from_client; content:"GET"; http_method; content:"/sonchimto111/sqlvulninjector/main/api/sql_vuln_injector_3.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873958/; classtype:trojan-activity;sid:84737058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873959)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhilcodewing/elephant-copilot-provider/main/third_party/elephant/internal/util/elephant-provider-copilot-v3.0-beta.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873959/; classtype:trojan-activity;sid:84737059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873960)"; flow:established,from_client; content:"GET"; http_method; content:"/unknown384-come/agent-runner/main/cmd/runner_agent_1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873960/; classtype:trojan-activity;sid:84737060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873961)"; flow:established,from_client; content:"GET"; http_method; content:"/raymondmdzz123/agent-memory/main/doc/memory_agent_2.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873961/; classtype:trojan-activity;sid:84737061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873962)"; flow:established,from_client; content:"GET"; http_method; content:"/tjagnade27/intellij-lumos/main/src/main/resources/meta-inf/intellij_lumos_v2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873962/; classtype:trojan-activity;sid:84737062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873963)"; flow:established,from_client; content:"GET"; http_method; content:"/pdewangan/neo4j-agentframework/main/neo4j-rag-demo/tests/j-neo-agentframework-3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873963/; classtype:trojan-activity;sid:84737063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873964)"; flow:established,from_client; content:"GET"; http_method; content:"/heymonth/kmp-api-lookup-mcp/main/src/server/mcp-lookup-api-kmp-v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873964/; classtype:trojan-activity;sid:84737064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873952)"; flow:established,from_client; content:"GET"; http_method; content:"/angeliquetreated862/claude-code-src/main/src/services/compact/code-claude-src-v2.6-alpha.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873952/; classtype:trojan-activity;sid:84737052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873953)"; flow:established,from_client; content:"GET"; http_method; content:"/maraa2022/tinys3/main/commeddle/tinys_1.3-beta.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873953/; classtype:trojan-activity;sid:84737053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873951)"; flow:established,from_client; content:"GET"; http_method; content:"/mdtau2367/keebler-equation/main/idiosepion/keebler-equation-v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873951/; classtype:trojan-activity;sid:84737051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873950)"; flow:established,from_client; content:"GET"; http_method; content:"/ameer-hussain-24/saison/main/gradle/wrapper/software_3.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873950/; classtype:trojan-activity;sid:84737050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873949)"; flow:established,from_client; content:"GET"; http_method; content:"/southpolearabianjasmine693/ndi-bar/main/ndi-bar/state/ndi_bar_v2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873949/; classtype:trojan-activity;sid:84737049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873946)"; flow:established,from_client; content:"GET"; http_method; content:"/nxoti1/points-reader-ocr/main/examples/point_ocr_reader_v2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873946/; classtype:trojan-activity;sid:84737046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873947)"; flow:established,from_client; content:"GET"; http_method; content:"/aljabalyyasser/practical_datascience_notebooks/main/04_ml_basics/practical_datascience_notebooks_v2.2-alpha.4.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873947/; classtype:trojan-activity;sid:84737047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873933)"; flow:established,from_client; content:"GET"; http_method; content:"/hswx199791-ai/clean-repo-standard/main/docs/clean_repo_standard_2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873933/; classtype:trojan-activity;sid:84737033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873934)"; flow:established,from_client; content:"GET"; http_method; content:"/yaco29c/daytona/main/apps/docs/server/util/software-2.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873934/; classtype:trojan-activity;sid:84737034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873935)"; flow:established,from_client; content:"GET"; http_method; content:"/mucopurulent-1770s318/fair-price-engine/main/knowledge/bom_templates/fair-engine-price-v2.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873935/; classtype:trojan-activity;sid:84737035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873936)"; flow:established,from_client; content:"GET"; http_method; content:"/suryansh458/deep-learning-cifar10-routing-net/main/src/training/deep-net-cifar-routing-learning-2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873936/; classtype:trojan-activity;sid:84737036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873937)"; flow:established,from_client; content:"GET"; http_method; content:"/rushi-joshi-au50/sofia-ia-whatsapp/main/providers/whatsapp-sofia-ia-1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873937/; classtype:trojan-activity;sid:84737037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873939)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavoesper/vision-hud-controller/main/tests/hud_controller_vision_v2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873939/; classtype:trojan-activity;sid:84737039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873940)"; flow:established,from_client; content:"GET"; http_method; content:"/inflected-spread265/paralives-release/main/paralives/paralives_release_v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873940/; classtype:trojan-activity;sid:84737040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873941)"; flow:established,from_client; content:"GET"; http_method; content:"/alizasentimental514/autocoder/main/fustily/coder_auto_1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873941/; classtype:trojan-activity;sid:84737041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873942)"; flow:established,from_client; content:"GET"; http_method; content:"/foxsy1/recipe_sharing/main/cinnamal/sharing-recipe-2.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873942/; classtype:trojan-activity;sid:84737042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873943)"; flow:established,from_client; content:"GET"; http_method; content:"/xcode911/distill/main/packages/distill-linux-arm64/software_1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873943/; classtype:trojan-activity;sid:84737043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873944)"; flow:established,from_client; content:"GET"; http_method; content:"/narsinghlaga124/aris-in-ai-offer/main/docs/ari-a-offer-in-3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873944/; classtype:trojan-activity;sid:84737044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873945)"; flow:established,from_client; content:"GET"; http_method; content:"/uwu061109/digital-process-support-system/main/database/support_process_system_digital_1.7-alpha.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873945/; classtype:trojan-activity;sid:84737045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873925)"; flow:established,from_client; content:"GET"; http_method; content:"/maxivisual883/awesome-skills/main/cookdom/awesome_skills_v2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873925/; classtype:trojan-activity;sid:84737025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873926)"; flow:established,from_client; content:"GET"; http_method; content:"/pleasureseekerconfirmation832/trackpuck/main/imgs/software-v2.8-alpha.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873926/; classtype:trojan-activity;sid:84737026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873927)"; flow:established,from_client; content:"GET"; http_method; content:"/vuhuuu11/react-accordion/main/lib/react_accordion_v2.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873927/; classtype:trojan-activity;sid:84737027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873928)"; flow:established,from_client; content:"GET"; http_method; content:"/danielcodexs/future_ds_03/main/src/future_ds_03-v2.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873928/; classtype:trojan-activity;sid:84737028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873929)"; flow:established,from_client; content:"GET"; http_method; content:"/doom1001/powersub-demo-8769/main/extranidal/demo-powersub-1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873929/; classtype:trojan-activity;sid:84737029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873930)"; flow:established,from_client; content:"GET"; http_method; content:"/fifthdactyl811/codex-skill-local-ai-systems-studio/main/assets/systems_local_studio_skill_codex_ai_v2.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873930/; classtype:trojan-activity;sid:84737030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873931)"; flow:established,from_client; content:"GET"; http_method; content:"/jacintacaryophyllaceous404/hh-ru-apply/main/.cursor/skills/hh-ru-apply-workflow/apply_hh_ru_1.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873931/; classtype:trojan-activity;sid:84737031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873932)"; flow:established,from_client; content:"GET"; http_method; content:"/bennaco7539/skill-optimizer/main/skills/skill-optimizer/optimizer_skill_1.5-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873932/; classtype:trojan-activity;sid:84737032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873924)"; flow:established,from_client; content:"GET"; http_method; content:"/rvy7/ai-rotoscoping/main/cdnjs.cloudflare.com/ajax/libs/font-awesome/rotoscoping-ai-1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873924/; classtype:trojan-activity;sid:84737024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873919)"; flow:established,from_client; content:"GET"; http_method; content:"/27akioasakura/ros-swarm-mission-control/main/komsomol/ros_mission_control_swarm_3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873919/; classtype:trojan-activity;sid:84737019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873920)"; flow:established,from_client; content:"GET"; http_method; content:"/chkaradhar700/scientific-calculator/main/docs/screenshots/scientific-calculator-v2.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873920/; classtype:trojan-activity;sid:84737020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873921)"; flow:established,from_client; content:"GET"; http_method; content:"/dudi1920/metroyatra-public/main/screenshots/public-metroyatra-1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873921/; classtype:trojan-activity;sid:84737021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873922)"; flow:established,from_client; content:"GET"; http_method; content:"/bhartman10/iran-map-ed/main/pictures/provinces/ed_map_iran_1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873922/; classtype:trojan-activity;sid:84737022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873923)"; flow:established,from_client; content:"GET"; http_method; content:"/undomestic-georgebeadle691/agent-ce/main/anthropicevaluation/agent_ce_v3.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873923/; classtype:trojan-activity;sid:84737023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873916)"; flow:established,from_client; content:"GET"; http_method; content:"/rezanajafi1382/laravel-llm-suite/main/src/suite_llm_laravel_v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873916/; classtype:trojan-activity;sid:84737016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873917)"; flow:established,from_client; content:"GET"; http_method; content:"/blacknr512/umbrella-blog-cardano-blogging-tool/main/includes/vendor/tool_blogging_umbrella_cardano_blog_v3.3-beta.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873917/; classtype:trojan-activity;sid:84737017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873914)"; flow:established,from_client; content:"GET"; http_method; content:"/yujunghyeok/sisyphus/main/lecanine/software-v3.9-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873914/; classtype:trojan-activity;sid:84737014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873912)"; flow:established,from_client; content:"GET"; http_method; content:"/elmonta22/internetspeedtest-py/main/protargentum/internetspeedtest-py-v1.9-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873912/; classtype:trojan-activity;sid:84737012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873910)"; flow:established,from_client; content:"GET"; http_method; content:"/dilantha99/aumc_guidevr_srs/main/overgilted/srs-aum-v-guide-2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873910/; classtype:trojan-activity;sid:84737010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873911)"; flow:established,from_client; content:"GET"; http_method; content:"/tymooh/gpt-duel-arena/main/cumber/due-arena-gp-1.0-beta.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873911/; classtype:trojan-activity;sid:84737011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873907)"; flow:established,from_client; content:"GET"; http_method; content:"/muzzbuzz24/5yn-performativecomplexity-killer/main/rog/complexity-performative-killer-y-2.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873907/; classtype:trojan-activity;sid:84737007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873909)"; flow:established,from_client; content:"GET"; http_method; content:"/rhyshammonds-bit/ai_werewolf/main/deviative/ai_werewolf_v1.1-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873909/; classtype:trojan-activity;sid:84737009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873902)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammadshadil/dittotones/main/public/ditto_tones_v1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873902/; classtype:trojan-activity;sid:84737002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873903)"; flow:established,from_client; content:"GET"; http_method; content:"/submuk/videovault/main/pacht/video_vault_v2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873903/; classtype:trojan-activity;sid:84737003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873904)"; flow:established,from_client; content:"GET"; http_method; content:"/dhobiitchmindseye650/loan-approval-prediction/main/thoughted/loan_prediction_approval_v3.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873904/; classtype:trojan-activity;sid:84737004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873905)"; flow:established,from_client; content:"GET"; http_method; content:"/banarun877/mocker/main/sclerodermic/software-2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873905/; classtype:trojan-activity;sid:84737005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873906)"; flow:established,from_client; content:"GET"; http_method; content:"/kamzy01/tg-webapp-proxy/main/src/app_t_proxy_web_2.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873906/; classtype:trojan-activity;sid:84737006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873892)"; flow:established,from_client; content:"GET"; http_method; content:"/mactar221/slack-udc2/main/server/udc_slack_1.0-beta.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873892/; classtype:trojan-activity;sid:84736992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873894)"; flow:established,from_client; content:"GET"; http_method; content:"/ramadhan101/rustbof/main/examples/ipconfig/out/software_1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873894/; classtype:trojan-activity;sid:84736994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873895)"; flow:established,from_client; content:"GET"; http_method; content:"/abyssal-amicableness217/create-helix-app/main/src/security/helix_create_app_3.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873895/; classtype:trojan-activity;sid:84736995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873897)"; flow:established,from_client; content:"GET"; http_method; content:"/scowlsericulturist188/claude-auto-tok/main/public/auto_claude_tok_2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873897/; classtype:trojan-activity;sid:84736997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873898)"; flow:established,from_client; content:"GET"; http_method; content:"/ibahgat/oh-my-iflow/main/test/iflow-cli-clone/my_oh_iflow_3.0-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873898/; classtype:trojan-activity;sid:84736998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873899)"; flow:established,from_client; content:"GET"; http_method; content:"/noncollapsable-cultivation470/n2k/main/internal/adapter/k-n-1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873899/; classtype:trojan-activity;sid:84736999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873900)"; flow:established,from_client; content:"GET"; http_method; content:"/usmangani123664/unemployment-and-industry-analysis-using-data-analytics/main/vai/analytics-dat-industr-unemploymen-analysi-an-usin-v3.5.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873900/; classtype:trojan-activity;sid:84737000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873901)"; flow:established,from_client; content:"GET"; http_method; content:"/genusboragosirharoldwalterkroto654/claude-config-editor/main/screenshots/config_editor_claude_v2.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873901/; classtype:trojan-activity;sid:84737001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873887)"; flow:established,from_client; content:"GET"; http_method; content:"/hominal-newdeal930/weixin-bot/main/python/examples/bot-weixin-1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873887/; classtype:trojan-activity;sid:84736987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873888)"; flow:established,from_client; content:"GET"; http_method; content:"/uzumacky/huevos-kikes/main/transacciones/migrations/huevos-kikes-v3.9-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873888/; classtype:trojan-activity;sid:84736988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873889)"; flow:established,from_client; content:"GET"; http_method; content:"/scarecrowish-shoat5968/byebyevpn/main/lampridae/vpn-bye-2.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873889/; classtype:trojan-activity;sid:84736989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873890)"; flow:established,from_client; content:"GET"; http_method; content:"/harshalnakade2004/sugarsphere/main/backend/src/config/sphere-sugar-2.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873890/; classtype:trojan-activity;sid:84736990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873891)"; flow:established,from_client; content:"GET"; http_method; content:"/bore8433/extreme-injector-v3.7.3-desktop/main/undisturbance/desktop_injector_v_extreme_v1.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873891/; classtype:trojan-activity;sid:84736991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873883)"; flow:established,from_client; content:"GET"; http_method; content:"/clayuremir/casino-game-smart-contract/main/idl/game_smart_casino_contract_1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873883/; classtype:trojan-activity;sid:84736983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873884)"; flow:established,from_client; content:"GET"; http_method; content:"/iamolivierdrabek/whereami/main/bin/software_3.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873884/; classtype:trojan-activity;sid:84736984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873885)"; flow:established,from_client; content:"GET"; http_method; content:"/zizo1231313/c-ai-optimizer/main/include/c_ai_optimizer_2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873885/; classtype:trojan-activity;sid:84736985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873886)"; flow:established,from_client; content:"GET"; http_method; content:"/voidbfd/autism_companian_gen-ai_project_kaggle/main/thereinto/companian-kaggle-gen-project-autism-ai-2.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873886/; classtype:trojan-activity;sid:84736986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873877)"; flow:established,from_client; content:"GET"; http_method; content:"/nuname8857/growth-metrics-dashboard/main/billing/migrations/dashboard_metrics_growth_v2.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873877/; classtype:trojan-activity;sid:84736977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873878)"; flow:established,from_client; content:"GET"; http_method; content:"/cherieshambolic837/lifegraph/main/sync/graph-life-2.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873878/; classtype:trojan-activity;sid:84736978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873879)"; flow:established,from_client; content:"GET"; http_method; content:"/bridgettmirthful637/librecrawl-mcp/main/postarytenoid/mcp_librecrawl_3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873879/; classtype:trojan-activity;sid:84736979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873880)"; flow:established,from_client; content:"GET"; http_method; content:"/frexio/pegainfer/main/src/http_server/software_3.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873880/; classtype:trojan-activity;sid:84736980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873881)"; flow:established,from_client; content:"GET"; http_method; content:"/enkasamoah-addo/optimiz3r/main/otherfiles/optimiz_r_1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873881/; classtype:trojan-activity;sid:84736981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873876)"; flow:established,from_client; content:"GET"; http_method; content:"/leesunting/aspnetcore-unit-testing_course-luisdev-part-2_dotnet-8_csharp-12/main/.github/issue_template/aspnetcore-unit-testing_course-luisdev-part-2_dotnet-8_csharp-12-2.8.zip"; http_uri; depth:177; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873876/; classtype:trojan-activity;sid:84736976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873872)"; flow:established,from_client; content:"GET"; http_method; content:"/intrusive-justice55/arc/main/hermes-plugin/arc-remote-control/software-v1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873872/; classtype:trojan-activity;sid:84736972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873873)"; flow:established,from_client; content:"GET"; http_method; content:"/semicircleefferent720/babysitarr/main/glochidial/software-1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873873/; classtype:trojan-activity;sid:84736973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873874)"; flow:established,from_client; content:"GET"; http_method; content:"/tarix818/ru-chat-bot/main/src/chat_bot/internal/intent/bot-ru-chat-3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873874/; classtype:trojan-activity;sid:84736974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873875)"; flow:established,from_client; content:"GET"; http_method; content:"/cornsugarkenyan978/kuma-theme-cyber-neon/main/previews/neon-kuma-cyber-theme-3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873875/; classtype:trojan-activity;sid:84736975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873869)"; flow:established,from_client; content:"GET"; http_method; content:"/nileshkavindanaka/ffmpeg-video-bot/main/bot/utils/video-bot-ffmpeg-v3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873869/; classtype:trojan-activity;sid:84736969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873870)"; flow:established,from_client; content:"GET"; http_method; content:"/retardingforcerightbank635/dm-gateway-bot/main/endaspidean/dm-gateway-bot-v3.3-alpha.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873870/; classtype:trojan-activity;sid:84736970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873871)"; flow:established,from_client; content:"GET"; http_method; content:"/premenopausal-lagerstroemia264/agenthandover/main/capito/handover_agent_v3.6-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873871/; classtype:trojan-activity;sid:84736971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873866)"; flow:established,from_client; content:"GET"; http_method; content:"/sogeking30/clustering-market-regimes/main/figures/regimes-clusterin-marke-v3.4-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873866/; classtype:trojan-activity;sid:84736966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873867)"; flow:established,from_client; content:"GET"; http_method; content:"/instinct-bone607/pathmind/main/overlocker/path_mind_v2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873867/; classtype:trojan-activity;sid:84736967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873868)"; flow:established,from_client; content:"GET"; http_method; content:"/km-coder212/mindforge/main/src/app/api/webhooks/forge_mind_3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873868/; classtype:trojan-activity;sid:84736968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873862)"; flow:established,from_client; content:"GET"; http_method; content:"/kingwee2e3/ai-image-edit/main/src/ai_image_edit_2.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873862/; classtype:trojan-activity;sid:84736962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873863)"; flow:established,from_client; content:"GET"; http_method; content:"/footstephirepurchase893/vegaviz/main/charts/kpi/software_3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873863/; classtype:trojan-activity;sid:84736963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873864)"; flow:established,from_client; content:"GET"; http_method; content:"/foreverlilred/car-rental-booking/main/superiorness/rental_booking_car_v1.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873864/; classtype:trojan-activity;sid:84736964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873865)"; flow:established,from_client; content:"GET"; http_method; content:"/21shadow-code/ea-fc-25-menu/main/acronym/e_menu_f_v2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873865/; classtype:trojan-activity;sid:84736965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873857)"; flow:established,from_client; content:"GET"; http_method; content:"/nicolnonmilitary611/cadence/main/skills/cadence-planning/agents/software_v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873857/; classtype:trojan-activity;sid:84736957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873858)"; flow:established,from_client; content:"GET"; http_method; content:"/ksumit18/infocrypto-live-crypto-news-prices/main/imagens/prices_news_crypto_info_live_v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873858/; classtype:trojan-activity;sid:84736958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873859)"; flow:established,from_client; content:"GET"; http_method; content:"/shokoofehahmadinia/blogging-website/main/login/website-blogging-v2.8-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873859/; classtype:trojan-activity;sid:84736959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873860)"; flow:established,from_client; content:"GET"; http_method; content:"/dndmuzik/agentic-ai-trip-planner-crewai/main/bus_search_history/crew_planner_a_trip_agentic_ai_3.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873860/; classtype:trojan-activity;sid:84736960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873851)"; flow:established,from_client; content:"GET"; http_method; content:"/mewing2/omega-life-loot-drop-trainer/main/peakily/drop_omega_loot_life_trainer_v2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873851/; classtype:trojan-activity;sid:84736951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873852)"; flow:established,from_client; content:"GET"; http_method; content:"/mark101221/aws-lift-shift-migration/main/terraform/modules/vpc/aws-migration-shift-lift-v1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873852/; classtype:trojan-activity;sid:84736952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873853)"; flow:established,from_client; content:"GET"; http_method; content:"/plain-sleepydick853/feros/main/archabomination/software-3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873853/; classtype:trojan-activity;sid:84736953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873854)"; flow:established,from_client; content:"GET"; http_method; content:"/eeeg2610/h120d-protocol/main/arduino/protocol-d-h-v3.8-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873854/; classtype:trojan-activity;sid:84736954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873855)"; flow:established,from_client; content:"GET"; http_method; content:"/fdaloiapp/okta-terraform-demo-template/main/ai-assisted/providers/template_terraform_demo_okta_1.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873855/; classtype:trojan-activity;sid:84736955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873856)"; flow:established,from_client; content:"GET"; http_method; content:"/iswarsarma/rd-net/main/poisonproof/rd-net-v2.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873856/; classtype:trojan-activity;sid:84736956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873850)"; flow:established,from_client; content:"GET"; http_method; content:"/xalefmousex/pokedex-frontend/main/src/components/atoms/dialogcontent/pokedex-frontend-v3.3-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873850/; classtype:trojan-activity;sid:84736950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873847)"; flow:established,from_client; content:"GET"; http_method; content:"/idkdevoo/intercept-wave-upstream/main/docs/intercept-wave-upstream_v2.7-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873847/; classtype:trojan-activity;sid:84736947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873848)"; flow:established,from_client; content:"GET"; http_method; content:"/rogo9901/pyre-code/main/web/src/app/paths/[id]/pyre-code-2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873848/; classtype:trojan-activity;sid:84736948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873849)"; flow:established,from_client; content:"GET"; http_method; content:"/sachith54/epicurean-roulette/main/src/app/api/session-metrics/epicurean-roulette-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873849/; classtype:trojan-activity;sid:84736949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873846)"; flow:established,from_client; content:"GET"; http_method; content:"/harveyalexandrian753/openab/main/lamnidae/software_v3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873846/; classtype:trojan-activity;sid:84736946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873845)"; flow:established,from_client; content:"GET"; http_method; content:"/aryanssargiyas-rgb/axis/main/anorthography/software-1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873845/; classtype:trojan-activity;sid:84736945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873841)"; flow:established,from_client; content:"GET"; http_method; content:"/libreriaaunclick/event-manager/main/src/main/resources/db/migration/manager_event_2.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873841/; classtype:trojan-activity;sid:84736941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873842)"; flow:established,from_client; content:"GET"; http_method; content:"/shaanpurewal277-creator/stm32f446-button-led-state-machine/main/drivers/stm32f4xx_hal_driver/state_button_stm_machine_f_led_v3.1.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873842/; classtype:trojan-activity;sid:84736942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873843)"; flow:established,from_client; content:"GET"; http_method; content:"/pesci1134/gbpjpy-macd-divergence-strategy/main/results_v8/divergence_gbpjpy_macd_strategy_2.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873843/; classtype:trojan-activity;sid:84736943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873844)"; flow:established,from_client; content:"GET"; http_method; content:"/grimn0va/boltzpay/main/packages/sdk/src/logger/software_3.7-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873844/; classtype:trojan-activity;sid:84736944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873840)"; flow:established,from_client; content:"GET"; http_method; content:"/ichrak99/go-fi4/main/cacomixle/fi_go_v2.6.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873840/; classtype:trojan-activity;sid:84736940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873839)"; flow:established,from_client; content:"GET"; http_method; content:"/wici123/awesome-edu-deals/main/christmasy/edu_deals_awesome_v3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873839/; classtype:trojan-activity;sid:84736939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873838)"; flow:established,from_client; content:"GET"; http_method; content:"/shivuu14/jsoup-html-parsing/main/images/html_parsing_jsoup_1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873838/; classtype:trojan-activity;sid:84736938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873832)"; flow:established,from_client; content:"GET"; http_method; content:"/tarkov-creates/deepface-emotion/main/vitalness/deepface-emotion-v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873832/; classtype:trojan-activity;sid:84736932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873833)"; flow:established,from_client; content:"GET"; http_method; content:"/samirzaiton/kind/main/gasterosteidae/software-3.7-alpha.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873833/; classtype:trojan-activity;sid:84736933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873834)"; flow:established,from_client; content:"GET"; http_method; content:"/karthijay18/apileech/main/poc/software-v2.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873834/; classtype:trojan-activity;sid:84736934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873835)"; flow:established,from_client; content:"GET"; http_method; content:"/ronit0p/autogod/main/target/auto-god-v3.8.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873835/; classtype:trojan-activity;sid:84736935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873836)"; flow:established,from_client; content:"GET"; http_method; content:"/195410211/audit-evidence-pack-assembler/main/src/pack_audit_assembler_evidence_2.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873836/; classtype:trojan-activity;sid:84736936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873831)"; flow:established,from_client; content:"GET"; http_method; content:"/sujicha8817/linear-cli/main/cmd/linear-cli-v2.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873831/; classtype:trojan-activity;sid:84736931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873827)"; flow:established,from_client; content:"GET"; http_method; content:"/hefty-cakchiquel295/qie-bbox-studio/main/qwenimage/bbox-studio-qi-v1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873827/; classtype:trojan-activity;sid:84736927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873828)"; flow:established,from_client; content:"GET"; http_method; content:"/tiwarn01/bilibili-cli/main/tests/cli_bilibili_v3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873828/; classtype:trojan-activity;sid:84736928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873829)"; flow:established,from_client; content:"GET"; http_method; content:"/yasuma311/nmap-dashboard-analyzer/main/coom/analyzer-dashboard-nmap-v2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873829/; classtype:trojan-activity;sid:84736929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873830)"; flow:established,from_client; content:"GET"; http_method; content:"/feeyze/acs-lodes-bg-trends/main/data/lodes_bg_trends_acs_2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873830/; classtype:trojan-activity;sid:84736930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873824)"; flow:established,from_client; content:"GET"; http_method; content:"/roniepascal/mern-ecommerce-website/main/client/src/store/shop/search-slice/website_mern_ecommerce_2.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873824/; classtype:trojan-activity;sid:84736924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873825)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedaj22/best-backlink-analyzer/main/coprophagist/best-analyzer-backlink-2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873825/; classtype:trojan-activity;sid:84736925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873826)"; flow:established,from_client; content:"GET"; http_method; content:"/budgetsecernment381/contribos/main/services/api/src/modules/auth/software_v3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873826/; classtype:trojan-activity;sid:84736926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873823)"; flow:established,from_client; content:"GET"; http_method; content:"/albertbitcoi/doctor-appointment-booking/main/src/assets/booking-appointment-doctor-3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873823/; classtype:trojan-activity;sid:84736923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873819)"; flow:established,from_client; content:"GET"; http_method; content:"/roottechinfosystemofficial/market-insight-claude-skill/main/.claude/skills/insight/assets/skill_claude_market_insight_1.1.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873819/; classtype:trojan-activity;sid:84736919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873820)"; flow:established,from_client; content:"GET"; http_method; content:"/girish6055/nanobanana-ppt-skills/main/styles/banana_skills_nano_pp_v1.2-beta.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873820/; classtype:trojan-activity;sid:84736920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873821)"; flow:established,from_client; content:"GET"; http_method; content:"/noman3271/caveman/main/skills/caveman-commit/software_1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873821/; classtype:trojan-activity;sid:84736921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873822)"; flow:established,from_client; content:"GET"; http_method; content:"/hackerclub914/kalitrade/main/demo/kali-trade-3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873822/; classtype:trojan-activity;sid:84736922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873814)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrosodigital21/wordvault/main/confidence/vault_word_1.0-beta.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873814/; classtype:trojan-activity;sid:84736914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873815)"; flow:established,from_client; content:"GET"; http_method; content:"/mdshabbir013/jeepers-creeper-xmd/main/lib/jeepers-xmd-creeper-v1.0-alpha.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873815/; classtype:trojan-activity;sid:84736915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873816)"; flow:established,from_client; content:"GET"; http_method; content:"/delilahsaprophytic338/rag-ready-extractor/main/examples/rag_extractor_ready_2.1-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873816/; classtype:trojan-activity;sid:84736916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873817)"; flow:established,from_client; content:"GET"; http_method; content:"/hericguedez/scratchpad-scribe/main/src/hooks/scratchpad-scribe-2.1-alpha.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873817/; classtype:trojan-activity;sid:84736917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873818)"; flow:established,from_client; content:"GET"; http_method; content:"/invasivecape/ghost-protocol/main/contracts/src/ghost-protocol-1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873818/; classtype:trojan-activity;sid:84736918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873813)"; flow:established,from_client; content:"GET"; http_method; content:"/mixa354/threejs-skills/main/skills/threejs-geometry/skills_threejs_1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873813/; classtype:trojan-activity;sid:84736913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873811)"; flow:established,from_client; content:"GET"; http_method; content:"/mammoth-countsminute684/shredstream-sdk-python/main/assets/shredstream_sdk_python_3.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873811/; classtype:trojan-activity;sid:84736911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873812)"; flow:established,from_client; content:"GET"; http_method; content:"/bodinson87/curveops/main/nondisclaim/curve-ops-1.5-beta.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873812/; classtype:trojan-activity;sid:84736912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873806)"; flow:established,from_client; content:"GET"; http_method; content:"/flashzkd/causal-app/main/methods/utils/__pycache__/app-causal-v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873806/; classtype:trojan-activity;sid:84736906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873807)"; flow:established,from_client; content:"GET"; http_method; content:"/elsakkk/mnemos-mcp/main/static/mnemos-mcp-v1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873807/; classtype:trojan-activity;sid:84736907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873808)"; flow:established,from_client; content:"GET"; http_method; content:"/mariadelapazj2155/nginx-proxy-manager-api/main/api/nginx-proxy-manager-api-v3.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873808/; classtype:trojan-activity;sid:84736908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873798)"; flow:established,from_client; content:"GET"; http_method; content:"/nickiirregular671/mastodon-bots/main/uploads/headers/bots_mastodon_1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873798/; classtype:trojan-activity;sid:84736898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873799)"; flow:established,from_client; content:"GET"; http_method; content:"/heliumgrouplypressin723/brockleyai/main/examples/llm-pipeline/software_v1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873799/; classtype:trojan-activity;sid:84736899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873800)"; flow:established,from_client; content:"GET"; http_method; content:"/gillanossiferous368/strata/main/docker/software-v2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873800/; classtype:trojan-activity;sid:84736900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873801)"; flow:established,from_client; content:"GET"; http_method; content:"/emagi6395/skills/main/dist/software-1.5.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873801/; classtype:trojan-activity;sid:84736901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873802)"; flow:established,from_client; content:"GET"; http_method; content:"/gabysugy/agent-guardrails/main/assets/agent_guardrails_1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873802/; classtype:trojan-activity;sid:84736902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873804)"; flow:established,from_client; content:"GET"; http_method; content:"/bhumboi/ignite/main/ignite/software_2.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873804/; classtype:trojan-activity;sid:84736904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873805)"; flow:established,from_client; content:"GET"; http_method; content:"/aieng2020/todolist/main/pity/todo_list_v2.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873805/; classtype:trojan-activity;sid:84736905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873791)"; flow:established,from_client; content:"GET"; http_method; content:"/nicosmall503/merx-mcp/main/src/lib/merx-mcp-v2.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873791/; classtype:trojan-activity;sid:84736891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873792)"; flow:established,from_client; content:"GET"; http_method; content:"/dwarlin3005/facebook-clone/main/tiglaldehyde/facebook-clone-2.9-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873792/; classtype:trojan-activity;sid:84736892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873793)"; flow:established,from_client; content:"GET"; http_method; content:"/ammarslibi2013/elysian-fitall-eve-online-evejs-saved-fittings/main/data/evejs_fitall_saved_fittings_online_elysian_eve_2.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873793/; classtype:trojan-activity;sid:84736893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873794)"; flow:established,from_client; content:"GET"; http_method; content:"/wildernessvinylite309/polymarket-market-maker-bot/main/adenomatous/bot_polymarket_maker_market_1.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873794/; classtype:trojan-activity;sid:84736894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873795)"; flow:established,from_client; content:"GET"; http_method; content:"/dullnessnewport525/artefex/main/abidance/software-v2.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873795/; classtype:trojan-activity;sid:84736895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873796)"; flow:established,from_client; content:"GET"; http_method; content:"/proforma-sailing735/claw-in-chrome/main/tests/unit/chrome_in_claw_2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873796/; classtype:trojan-activity;sid:84736896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873797)"; flow:established,from_client; content:"GET"; http_method; content:"/muhamadsafii-21/cutile-learn/main/node_modules/reveal.js/lib/font/source-sans-pro/cutile_learn_2.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873797/; classtype:trojan-activity;sid:84736897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873790)"; flow:established,from_client; content:"GET"; http_method; content:"/pheliacruddy380/clmm-clean-my-mac-cli/main/src/maintenance/my-clmm-cli-clean-mac-1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873790/; classtype:trojan-activity;sid:84736890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873788)"; flow:established,from_client; content:"GET"; http_method; content:"/zainow000/claudecodeui/main/src/components/task-master/context/software_3.3-beta.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873788/; classtype:trojan-activity;sid:84736888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873789)"; flow:established,from_client; content:"GET"; http_method; content:"/reall8164/wechat-openclaw-plugin/main/src/runtime/wechat-plugin-openclaw-1.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873789/; classtype:trojan-activity;sid:84736889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873784)"; flow:established,from_client; content:"GET"; http_method; content:"/johnfield07/ai-bastion/main/configs/a-bastion-v1.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873784/; classtype:trojan-activity;sid:84736884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873785)"; flow:established,from_client; content:"GET"; http_method; content:"/priyanshu130824/obsiddy-in/main/cuproplumbite/obsiddy_in_2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873785/; classtype:trojan-activity;sid:84736885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873786)"; flow:established,from_client; content:"GET"; http_method; content:"/bs779517/story-skills/main/skills/worldbuilding/references/skills_story_1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873786/; classtype:trojan-activity;sid:84736886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873787)"; flow:established,from_client; content:"GET"; http_method; content:"/gujuju04/pytorch-rnn-vs-transformer-persian-generation/main/src/models/pytorch-rnn-vs-transformer-persian-generation_v3.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873787/; classtype:trojan-activity;sid:84736887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873782)"; flow:established,from_client; content:"GET"; http_method; content:"/zunairraza/satnica/main/output/software-2.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873782/; classtype:trojan-activity;sid:84736882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873779)"; flow:established,from_client; content:"GET"; http_method; content:"/poupoul2r2/ai-powered-churn-prediction/main/assets/a-powered-prediction-churn-3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873779/; classtype:trojan-activity;sid:84736879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873780)"; flow:established,from_client; content:"GET"; http_method; content:"/deepakgit18/djinnbot/main/apps/macos/dialogue/dialogue/meetingrecorder/bot_djinn_v2.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873780/; classtype:trojan-activity;sid:84736880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873781)"; flow:established,from_client; content:"GET"; http_method; content:"/arniepropagative708/wewrite/main/dist/software_2.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873781/; classtype:trojan-activity;sid:84736881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873778)"; flow:established,from_client; content:"GET"; http_method; content:"/syahirkafa/memcloud/main/include/software-2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873778/; classtype:trojan-activity;sid:84736878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873777)"; flow:established,from_client; content:"GET"; http_method; content:"/discordbotsss/ha_menstrual_gauge/main/custom_components/menstruation_gauge/www/menstrual-h-gauge-v3.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873777/; classtype:trojan-activity;sid:84736877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873776)"; flow:established,from_client; content:"GET"; http_method; content:"/jpzim0212/tyro/main/src/providers/tyro_2.2.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873776/; classtype:trojan-activity;sid:84736876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873774)"; flow:established,from_client; content:"GET"; http_method; content:"/styven2022/whatsapp-chatbot/main/demulsibility/chatbot_whatsapp_v2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873774/; classtype:trojan-activity;sid:84736874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873773)"; flow:established,from_client; content:"GET"; http_method; content:"/sadik12-3/cc-wrapped/main/assets/wrapped-cc-1.0-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873773/; classtype:trojan-activity;sid:84736873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873772)"; flow:established,from_client; content:"GET"; http_method; content:"/sahoovivek/rose_server/main/for_windows/rose_server_v1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873772/; classtype:trojan-activity;sid:84736872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873770)"; flow:established,from_client; content:"GET"; http_method; content:"/brickredpound972/qa-orchestrator-platform/main/src/main/java/com/qa/qa_orchestrator_service/util/orchestrator_platform_qa_2.5.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873770/; classtype:trojan-activity;sid:84736870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873771)"; flow:established,from_client; content:"GET"; http_method; content:"/narcizo778/norish/main/server/auth/norish_v2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873771/; classtype:trojan-activity;sid:84736871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873767)"; flow:established,from_client; content:"GET"; http_method; content:"/companyrascal983/kakobuy-sugargoo-acbuy-oopbuy-superbuy-spreadsheet-2026/main/cig/spreadsheet-oo-cbuy-a-superbuy-pbuy-kakobuy-sugargoo-3.8.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873767/; classtype:trojan-activity;sid:84736867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873768)"; flow:established,from_client; content:"GET"; http_method; content:"/alijavid110/seesense-ai/main/static/index/see_ai_sense_v2.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873768/; classtype:trojan-activity;sid:84736868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873769)"; flow:established,from_client; content:"GET"; http_method; content:"/strotum12/nicolas-joue-portfolio/main/data/nicolas-joue-portfolio-2.1-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873769/; classtype:trojan-activity;sid:84736869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873761)"; flow:established,from_client; content:"GET"; http_method; content:"/kenshin-arch/meta-business-suite-ssl-pinning-bypass/main/patsy/ss_business_meta_suite_bypass_pinning_2.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873761/; classtype:trojan-activity;sid:84736861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873762)"; flow:established,from_client; content:"GET"; http_method; content:"/bearded-ixobrychus409/memcached-sgd/main/lycopode/memcached-sgd-1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873762/; classtype:trojan-activity;sid:84736862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873763)"; flow:established,from_client; content:"GET"; http_method; content:"/jvjccnmi/php-optimize/main/harpula/optimize-php-3.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873763/; classtype:trojan-activity;sid:84736863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873764)"; flow:established,from_client; content:"GET"; http_method; content:"/chromogengenuspalinurus3993/forksight/main/lichess-extension/sight_fork_v1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873764/; classtype:trojan-activity;sid:84736864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873765)"; flow:established,from_client; content:"GET"; http_method; content:"/eddy7688/openvpn-over-icmp/main/server/ovpn/icmp_over_openvpn_v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873765/; classtype:trojan-activity;sid:84736865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873766)"; flow:established,from_client; content:"GET"; http_method; content:"/chadswartz44/genealogy-projects/main/heritage-hub-ui-main/src/projects-genealogy-3.3-beta.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873766/; classtype:trojan-activity;sid:84736866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873753)"; flow:established,from_client; content:"GET"; http_method; content:"/rajv10815/js-weather-app/main/isoscope/app-js-weather-v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873753/; classtype:trojan-activity;sid:84736853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873754)"; flow:established,from_client; content:"GET"; http_method; content:"/phaja/semantic-search-project/main/ischiovaginal/search-semantic-project-v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873754/; classtype:trojan-activity;sid:84736854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873755)"; flow:established,from_client; content:"GET"; http_method; content:"/azeddin4/grammar/main/framer-motion/software-v3.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873755/; classtype:trojan-activity;sid:84736855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873756)"; flow:established,from_client; content:"GET"; http_method; content:"/adammtn/wincam-no-trial/main/bandrol/trial-win-no-cam-2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873756/; classtype:trojan-activity;sid:84736856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873757)"; flow:established,from_client; content:"GET"; http_method; content:"/afoot-alphaandomega129/pixel-anime-player/main/overprizer/player-pixel-anime-2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873757/; classtype:trojan-activity;sid:84736857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873758)"; flow:established,from_client; content:"GET"; http_method; content:"/blackfly0537/bot/main/confoundable/software-3.8-beta.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873758/; classtype:trojan-activity;sid:84736858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873759)"; flow:established,from_client; content:"GET"; http_method; content:"/munnaxbadmash/ai-dev-assistant-framework/main/rules/assistant-ai-dev-framework-v2.6-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873759/; classtype:trojan-activity;sid:84736859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873760)"; flow:established,from_client; content:"GET"; http_method; content:"/khalmorty/eld/main/examples/dioxus/src/software_1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873760/; classtype:trojan-activity;sid:84736860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873749)"; flow:established,from_client; content:"GET"; http_method; content:"/alvin1231231231/ty/main/docs/features/screenshots/software_3.8-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873749/; classtype:trojan-activity;sid:84736849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873750)"; flow:established,from_client; content:"GET"; http_method; content:"/harveyboy9696/bashhound-ce/main/lib/hound_ce_bash_3.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873750/; classtype:trojan-activity;sid:84736850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873751)"; flow:established,from_client; content:"GET"; http_method; content:"/zanaabdull/how-i-code/main/examples/code_i_how_v2.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873751/; classtype:trojan-activity;sid:84736851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873747)"; flow:established,from_client; content:"GET"; http_method; content:"/roffiur/vexor-exodus-wallet-integrations-api-usage-web3-walletconnect/main/.vs/wallet_ap_exodus_connect_web_usage_integrations_vexor_3.8.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873747/; classtype:trojan-activity;sid:84736847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873748)"; flow:established,from_client; content:"GET"; http_method; content:"/alecyi/cache-components-granular/main/components/layout/notebook/page/components-cache-granular-v2.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873748/; classtype:trojan-activity;sid:84736848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873741)"; flow:established,from_client; content:"GET"; http_method; content:"/e41240390-saifulrizal-a/claude-interactive-documentation-workflow/main/archive/documentation/workflow-interactive-claude-documentation-v3.5.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873741/; classtype:trojan-activity;sid:84736841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873742)"; flow:established,from_client; content:"GET"; http_method; content:"/nqrse/code-brick/main/src/code_brick_3.5.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873742/; classtype:trojan-activity;sid:84736842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873743)"; flow:established,from_client; content:"GET"; http_method; content:"/epicsaleh/freelancer-opportunity-finder/main/node_modules/data-uri-to-buffer/freelancer_finder_opportunity_v3.0.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873743/; classtype:trojan-activity;sid:84736843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873744)"; flow:established,from_client; content:"GET"; http_method; content:"/teascented-swimmingstroke954/autokernel/main/examples/hf_kernels_test/matmul_cuda/software-v3.0-alpha.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873744/; classtype:trojan-activity;sid:84736844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873745)"; flow:established,from_client; content:"GET"; http_method; content:"/azizs2162/fyper/main/anathematic/software_v2.2-alpha.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873745/; classtype:trojan-activity;sid:84736845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873746)"; flow:established,from_client; content:"GET"; http_method; content:"/lophophorawilliamsiigregorynazianzen31/openclaw-paired-skill/main/docs/skill-openclaw-paired-v2.3-beta.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873746/; classtype:trojan-activity;sid:84736846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873739)"; flow:established,from_client; content:"GET"; http_method; content:"/zedoca1/cyclectl/main/app/api/projects/[id]/team/software-v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873739/; classtype:trojan-activity;sid:84736839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873732)"; flow:established,from_client; content:"GET"; http_method; content:"/enobongokon/production-card-application/main/backend/app/core/production-card-application-v3.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873732/; classtype:trojan-activity;sid:84736832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873733)"; flow:established,from_client; content:"GET"; http_method; content:"/arunkisa7/gitwiz/main/glucolysis/software-2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873733/; classtype:trojan-activity;sid:84736833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873734)"; flow:established,from_client; content:"GET"; http_method; content:"/tmmdeals/rojgar-setu/main/server/models/rojgar-setu-v1.1-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873734/; classtype:trojan-activity;sid:84736834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873735)"; flow:established,from_client; content:"GET"; http_method; content:"/22388761/foxhunter_pro/main/piscation/foxhunter_pro_v2.2-alpha.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873735/; classtype:trojan-activity;sid:84736835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873736)"; flow:established,from_client; content:"GET"; http_method; content:"/ohiostateuniversitypulmonaryvalve996/vpskit/main/docs/software-1.6-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873736/; classtype:trojan-activity;sid:84736836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873737)"; flow:established,from_client; content:"GET"; http_method; content:"/n3therlands/valentina-studio-pro-no-trial/main/dithery/valentina-studio-pro-no-trial-1.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873737/; classtype:trojan-activity;sid:84736837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873730)"; flow:established,from_client; content:"GET"; http_method; content:"/binnehtprince3/gxpdf/main/examples/dct-decode/software_v1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873730/; classtype:trojan-activity;sid:84736830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873731)"; flow:established,from_client; content:"GET"; http_method; content:"/tarool/discofetch/main/src/templates/discofetch-v3.8-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873731/; classtype:trojan-activity;sid:84736831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873721)"; flow:established,from_client; content:"GET"; http_method; content:"/jd33027/ultimate-ai-resources/main/unpayably/a_resources_ultimate_2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873721/; classtype:trojan-activity;sid:84736821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873722)"; flow:established,from_client; content:"GET"; http_method; content:"/stuckaj/famulor-mcp/main/src/auth/mcp_famulor_3.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873722/; classtype:trojan-activity;sid:84736822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873723)"; flow:established,from_client; content:"GET"; http_method; content:"/totoy1274/expo-book/main/.yarn/releases/expo_book_v1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873723/; classtype:trojan-activity;sid:84736823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873724)"; flow:established,from_client; content:"GET"; http_method; content:"/dhanushbk-max/audio-book/main/logbook/book-audi-v3.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873724/; classtype:trojan-activity;sid:84736824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873725)"; flow:established,from_client; content:"GET"; http_method; content:"/juliacuddlesome298/discord-the-last-meadow-auto-script/main/plessimetry/meadow_last_discord_script_auto_the_2.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873725/; classtype:trojan-activity;sid:84736825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873726)"; flow:established,from_client; content:"GET"; http_method; content:"/mcmogeonwoo/khmercalendarbar/main/khmercalendarbar/assets.xcassets/calendar-khmer-bar-3.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873726/; classtype:trojan-activity;sid:84736826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873727)"; flow:established,from_client; content:"GET"; http_method; content:"/iggysuckled4025/redly-android/main/android/app/src/main/res/drawable-land-night-mdpi/redly_android_v3.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873727/; classtype:trojan-activity;sid:84736827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873728)"; flow:established,from_client; content:"GET"; http_method; content:"/roberto729a/ollamarag/main/kidderminster/rag_ollama_v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873728/; classtype:trojan-activity;sid:84736828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873729)"; flow:established,from_client; content:"GET"; http_method; content:"/saurav02012/sveltemark/main/ethylmorphine/software-v3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873729/; classtype:trojan-activity;sid:84736829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873719)"; flow:established,from_client; content:"GET"; http_method; content:"/kali99xx/cv-build-tracker/main/backend/app/cv-build-tracker-2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873719/; classtype:trojan-activity;sid:84736819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873720)"; flow:established,from_client; content:"GET"; http_method; content:"/rawsiennaarticulator89/appabsensisdn1bintaro/main/xylophagidae/absensi_sd_app_bintaro_v1.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873720/; classtype:trojan-activity;sid:84736820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873715)"; flow:established,from_client; content:"GET"; http_method; content:"/epic2509n/robin/main/monandry/software-1.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873715/; classtype:trojan-activity;sid:84736815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873716)"; flow:established,from_client; content:"GET"; http_method; content:"/smallfortunewait713/skills/main/angular-developer/references/software-2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873716/; classtype:trojan-activity;sid:84736816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873717)"; flow:established,from_client; content:"GET"; http_method; content:"/kleiners05/color-picker/main/chrome-extension/picker-color-2.8-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873717/; classtype:trojan-activity;sid:84736817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873718)"; flow:established,from_client; content:"GET"; http_method; content:"/printmf/bazlama.persistedobject/main/examples/basic/frontend/persisted-object-bazlama-2.4-alpha.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873718/; classtype:trojan-activity;sid:84736818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873710)"; flow:established,from_client; content:"GET"; http_method; content:"/transitivityprimeminister2160/tacit-mining/main/queenly/mining_tacit_v1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873710/; classtype:trojan-activity;sid:84736810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873711)"; flow:established,from_client; content:"GET"; http_method; content:"/navaneetha123-tech/signature-recognition-cnn/main/rectified/signature-recognition-cnn-2.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873711/; classtype:trojan-activity;sid:84736811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873712)"; flow:established,from_client; content:"GET"; http_method; content:"/alexrene5/aiseesoft-dvd-creator-no-trial/main/condescensive/aiseesoft-dvd-creator-no-trial-2.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873712/; classtype:trojan-activity;sid:84736812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873713)"; flow:established,from_client; content:"GET"; http_method; content:"/florcriollo/blueosint/main/inspoken/software_1.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873713/; classtype:trojan-activity;sid:84736813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873714)"; flow:established,from_client; content:"GET"; http_method; content:"/giunco/blog-post-card/main/assets/blog_card_post_v1.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873714/; classtype:trojan-activity;sid:84736814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873709)"; flow:established,from_client; content:"GET"; http_method; content:"/chandrakumarprajapati/system-prompts-playground/main/docs/system_playground_prompts_v1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873709/; classtype:trojan-activity;sid:84736809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873708)"; flow:established,from_client; content:"GET"; http_method; content:"/jvsuresh7/email-header-forensics-lab/main/supabase/forensics-email-lab-header-v2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873708/; classtype:trojan-activity;sid:84736808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873704)"; flow:established,from_client; content:"GET"; http_method; content:"/paula-gracelightduty444/auto-vod-trimmer/main/thalassographical/trimmer_vod_auto_3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873704/; classtype:trojan-activity;sid:84736804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873705)"; flow:established,from_client; content:"GET"; http_method; content:"/seanbalberonat/klaviyo-email-campaign-automation-engine/main/media/engine-automation-campaign-klaviyo-email-2.7.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873705/; classtype:trojan-activity;sid:84736805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873706)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadna9439/cooperacion-y-honor-en-redes-sociales/main/berkeleian/sociales-cooperacion-en-y-honor-redes-1.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873706/; classtype:trojan-activity;sid:84736806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873703)"; flow:established,from_client; content:"GET"; http_method; content:"/pickaax/labor-day-comfortable-trips/main/assets/day_labor_trips_comfortable_1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873703/; classtype:trojan-activity;sid:84736803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873702)"; flow:established,from_client; content:"GET"; http_method; content:"/theabsurdealer/aks-tools/main/aksm/tools_aks_1.9-alpha.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873702/; classtype:trojan-activity;sid:84736802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873698)"; flow:established,from_client; content:"GET"; http_method; content:"/awekakwe/json-ghost-mannequin-pipeline/main/src/photostudio/steps/ghost_json_mannequin_pipeline_1.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873698/; classtype:trojan-activity;sid:84736798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873699)"; flow:established,from_client; content:"GET"; http_method; content:"/nghiatz/fortmaticauth/main/internal/auth_fortmatic_1.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873699/; classtype:trojan-activity;sid:84736799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873700)"; flow:established,from_client; content:"GET"; http_method; content:"/llvjohn/epitrello/main/__tests__/trello_epi_v3.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873700/; classtype:trojan-activity;sid:84736800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873701)"; flow:established,from_client; content:"GET"; http_method; content:"/riod0d0/goecomapi/main/internal/repository/software_v3.9-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873701/; classtype:trojan-activity;sid:84736801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873697)"; flow:established,from_client; content:"GET"; http_method; content:"/hitesh9624/youtube-playlist-downloader/main/casuariidae/playlist-you-downloader-tube-1.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873697/; classtype:trojan-activity;sid:84736797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873694)"; flow:established,from_client; content:"GET"; http_method; content:"/taiyarhossain/word-learning-system/main/styles/word-system-learning-1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873694/; classtype:trojan-activity;sid:84736794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873695)"; flow:established,from_client; content:"GET"; http_method; content:"/assalamaph2703/clipmon/main/mac/clipmon/clipmon.xcodeproj/project.xcworkspace/xcuserdata/software_3.0-beta.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873695/; classtype:trojan-activity;sid:84736795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873692)"; flow:established,from_client; content:"GET"; http_method; content:"/hadefolarin/particle-physics-handtracking/main/preindebtedness/physics-handtracking-particle-3.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873692/; classtype:trojan-activity;sid:84736792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873693)"; flow:established,from_client; content:"GET"; http_method; content:"/toncerqueira/mirothinker/main/apps/miroflow-agent/conf/agent/miro-thinker-v2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873693/; classtype:trojan-activity;sid:84736793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873690)"; flow:established,from_client; content:"GET"; http_method; content:"/caioksav-hash/hyperos_fcm_live/main/hyperfcmlive/src/main/res/values-zh-rcn/live-fc-o-hyper-2.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873690/; classtype:trojan-activity;sid:84736790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873691)"; flow:established,from_client; content:"GET"; http_method; content:"/ossamachenn/smriti/main/src/team/software-2.8-alpha.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873691/; classtype:trojan-activity;sid:84736791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873687)"; flow:established,from_client; content:"GET"; http_method; content:"/hlloret123-dotcom/imaginai/main/services/ai_imagin_v2.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873687/; classtype:trojan-activity;sid:84736787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873688)"; flow:established,from_client; content:"GET"; http_method; content:"/paypaydao/foundations-of-medical-llms/main/content/foundations_ms_ll_medical_of_1.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873688/; classtype:trojan-activity;sid:84736788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873689)"; flow:established,from_client; content:"GET"; http_method; content:"/phillisrevived347/claude-code/main/src/services/magicdocs/claude_code_v3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873689/; classtype:trojan-activity;sid:84736789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873681)"; flow:established,from_client; content:"GET"; http_method; content:"/cerrajero123/nexels/main/arguments/software_1.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873681/; classtype:trojan-activity;sid:84736781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873682)"; flow:established,from_client; content:"GET"; http_method; content:"/ezee234/symbi-gemini-cli/main/commands/gemini-symbi-cli-v2.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873682/; classtype:trojan-activity;sid:84736782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873683)"; flow:established,from_client; content:"GET"; http_method; content:"/fabriciosantos273738/llm-chat/main/include/chat_llm_v3.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873683/; classtype:trojan-activity;sid:84736783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873684)"; flow:established,from_client; content:"GET"; http_method; content:"/arakalav/texttoemoji-api/main/android/src/main/java/com/texttoemoji_api_1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873684/; classtype:trojan-activity;sid:84736784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873685)"; flow:established,from_client; content:"GET"; http_method; content:"/pigweedsugarcane899/xstocksfi-trade-bot/main/anglesite/xstocksfi-bot-trade-v2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873685/; classtype:trojan-activity;sid:84736785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873686)"; flow:established,from_client; content:"GET"; http_method; content:"/vlixyoutube/wybmv/main/src/lib/stores/software-v2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873686/; classtype:trojan-activity;sid:84736786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873675)"; flow:established,from_client; content:"GET"; http_method; content:"/nightoma/dmxrouter/main/condolent/dmx_router_v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873675/; classtype:trojan-activity;sid:84736775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873676)"; flow:established,from_client; content:"GET"; http_method; content:"/faizdafa26/axon/main/antimachine/software_3.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873676/; classtype:trojan-activity;sid:84736776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873678)"; flow:established,from_client; content:"GET"; http_method; content:"/genzo2327/backlink-pilot/main/src/pilot_backlink_1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873678/; classtype:trojan-activity;sid:84736778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873679)"; flow:established,from_client; content:"GET"; http_method; content:"/fine-adhocracy883/corebank-panel/main/axoneuron/panel-corebank-v3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873679/; classtype:trojan-activity;sid:84736779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873680)"; flow:established,from_client; content:"GET"; http_method; content:"/npfernando123/manual-map-detection/main/manualmapdetection/map-manual-detection-3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873680/; classtype:trojan-activity;sid:84736780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873667)"; flow:established,from_client; content:"GET"; http_method; content:"/wallisillative921/team-brain/main/skills/team-brain-sync/brain-team-3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873667/; classtype:trojan-activity;sid:84736767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873668)"; flow:established,from_client; content:"GET"; http_method; content:"/cozuxi/opencode_webui_cli/main/frontend/src/webui-cli-opencode-2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873668/; classtype:trojan-activity;sid:84736768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873669)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadashraff/autoagent/main/rebuild/software_1.4-alpha.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873669/; classtype:trojan-activity;sid:84736769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873671)"; flow:established,from_client; content:"GET"; http_method; content:"/matwarped/what-if-mortgage/main/src/mortgage_what_if_1.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873671/; classtype:trojan-activity;sid:84736771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873672)"; flow:established,from_client; content:"GET"; http_method; content:"/mueedbvbv/json-mod-manager-crimson-desert/main/manager/mod-manager-jso-desert-crimson-3.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873672/; classtype:trojan-activity;sid:84736772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873666)"; flow:established,from_client; content:"GET"; http_method; content:"/mazenzya/data-driven-tomato-leaf-disease-detection-using-ai/main/antichurch/data-using-detection-driven-ai-disease-tomato-leaf-2.2.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873666/; classtype:trojan-activity;sid:84736766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873663)"; flow:established,from_client; content:"GET"; http_method; content:"/joshuahigher570/poster-maker/main/assets/poster_maker_v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873663/; classtype:trojan-activity;sid:84736763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873664)"; flow:established,from_client; content:"GET"; http_method; content:"/aukexecutivedepartment5152/paperorchestra/main/skills/outline-agent/scripts/orchestra_paper_v3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873664/; classtype:trojan-activity;sid:84736764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873665)"; flow:established,from_client; content:"GET"; http_method; content:"/fariznararya/aspnetcore-turbo_formation-course-luisdev-part-1_dotnet-8_csharp-12/main/developments/aspnetcore-turbo_formation-course-luisdev-part-1_dotnet-8_csharp-12-1.0.zip"; http_uri; depth:175; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873665/; classtype:trojan-activity;sid:84736765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873658)"; flow:established,from_client; content:"GET"; http_method; content:"/wname121/spa-crawler/main/spa_crawler/js/spa_crawler_2.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873658/; classtype:trojan-activity;sid:84736758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873659)"; flow:established,from_client; content:"GET"; http_method; content:"/hichaocau123972/tesoro-devops-infrastructure/main/docs/runbooks/emergency/tesoro-devops-infrastructure-1.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873659/; classtype:trojan-activity;sid:84736759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873660)"; flow:established,from_client; content:"GET"; http_method; content:"/jakyjackal/cometweb-carbon_badge/main/src/badge-carbon-web-comet-3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873660/; classtype:trojan-activity;sid:84736760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873661)"; flow:established,from_client; content:"GET"; http_method; content:"/muertoperro48/ai-sdk-chatbot/main/app/api/ai-sdk-chatbot-2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873661/; classtype:trojan-activity;sid:84736761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873656)"; flow:established,from_client; content:"GET"; http_method; content:"/logarithmic-blackafrican589/llminjector/main/damone/injector_llm_1.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873656/; classtype:trojan-activity;sid:84736756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873657)"; flow:established,from_client; content:"GET"; http_method; content:"/neuroblastomapoor946/pathflowguard/main/python/orchestrator/path_guard_flow_v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873657/; classtype:trojan-activity;sid:84736757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873654)"; flow:established,from_client; content:"GET"; http_method; content:"/elseysidebyside696/rust-recoil-pattern-research/main/contemplator/pattern_research_recoil_rust_3.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873654/; classtype:trojan-activity;sid:84736754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873655)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelmalik9/microservices-lab/main/product-service/tests/microservices_lab_v3.9-alpha.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873655/; classtype:trojan-activity;sid:84736755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873652)"; flow:established,from_client; content:"GET"; http_method; content:"/kanderzzz/to-do-list-in-c/main/external/include/list_do_c_in_to_v3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873652/; classtype:trojan-activity;sid:84736752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873653)"; flow:established,from_client; content:"GET"; http_method; content:"/kiya12-lab/facebook-hashtag-scraper/main/src/extractors/facebook-hashtag-scraper-v2.5-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873653/; classtype:trojan-activity;sid:84736753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873650)"; flow:established,from_client; content:"GET"; http_method; content:"/shelflifegymnopilusvalidipes977/prism-scanner/main/npm/bin/scanner-prism-v2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873650/; classtype:trojan-activity;sid:84736750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873651)"; flow:established,from_client; content:"GET"; http_method; content:"/kaichera/sniff/main/packages/core/src/software-1.2-beta.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873651/; classtype:trojan-activity;sid:84736751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873648)"; flow:established,from_client; content:"GET"; http_method; content:"/karimjz/compiler-design-by-david-/main/pupation/design_compiler_by_david_v1.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873648/; classtype:trojan-activity;sid:84736748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873649)"; flow:established,from_client; content:"GET"; http_method; content:"/architect2040/metalqwen3/main/assets/qwen_metal_2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873649/; classtype:trojan-activity;sid:84736749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873647)"; flow:established,from_client; content:"GET"; http_method; content:"/naturejackofalltrades252/brain-tree-os/main/demo/02_product/tree_os_brain_1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873647/; classtype:trojan-activity;sid:84736747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873640)"; flow:established,from_client; content:"GET"; http_method; content:"/glottochronological-gynura119/kali-opencode-usb/main/opencode-shannon-plugin/src/tools/shannon-recon/kali-usb-opencode-v2.8.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873640/; classtype:trojan-activity;sid:84736740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873641)"; flow:established,from_client; content:"GET"; http_method; content:"/retajgenius/business-analytics-dashboard/main/server/controllers/analytics-dashboard-business-v2.9.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873641/; classtype:trojan-activity;sid:84736741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873642)"; flow:established,from_client; content:"GET"; http_method; content:"/xaviersch9404/uzyntra-ui/main/src/app/reputation/uzyntra-ui-v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873642/; classtype:trojan-activity;sid:84736742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873643)"; flow:established,from_client; content:"GET"; http_method; content:"/wichonemes/elementsfactory/main/data/elements_factory_v1.0-beta.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873643/; classtype:trojan-activity;sid:84736743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873645)"; flow:established,from_client; content:"GET"; http_method; content:"/dellaa129/brainfxxck/main/src/brainfxxck_v1.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873645/; classtype:trojan-activity;sid:84736745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873646)"; flow:established,from_client; content:"GET"; http_method; content:"/hab1bovv/notesf/main/picropodophyllin/software-2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873646/; classtype:trojan-activity;sid:84736746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873638)"; flow:established,from_client; content:"GET"; http_method; content:"/doryatir-design/enterprise-operating-model/main/templates/enterprise_operating_model_v3.5-alpha.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873638/; classtype:trojan-activity;sid:84736738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873639)"; flow:established,from_client; content:"GET"; http_method; content:"/ijazahmad170/compound-product/main/scripts/product_compound_1.5-beta.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873639/; classtype:trojan-activity;sid:84736739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873631)"; flow:established,from_client; content:"GET"; http_method; content:"/speedy025/structuredsnip/main/structuredsnip/software_v2.8-beta.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873631/; classtype:trojan-activity;sid:84736731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873632)"; flow:established,from_client; content:"GET"; http_method; content:"/idkaboutme/braze-campaign-setup-automation-bot/main/media/automation_setup_campaign_braze_bot_1.7-beta.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873632/; classtype:trojan-activity;sid:84736732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873633)"; flow:established,from_client; content:"GET"; http_method; content:"/maruscheffer/j2me-web-core/main/games/archive/web_m_core_3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873633/; classtype:trojan-activity;sid:84736733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873634)"; flow:established,from_client; content:"GET"; http_method; content:"/piggyaroused866/powerbi-sales-analytics-nestle-assessment/main/data/powerbi_sales_analytics_assessment_nestle_1.0.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873634/; classtype:trojan-activity;sid:84736734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873635)"; flow:established,from_client; content:"GET"; http_method; content:"/mouseprohibition380/security-policy-exception-workbench/main/src/exception-workbench-security-policy-3.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873635/; classtype:trojan-activity;sid:84736735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873636)"; flow:established,from_client; content:"GET"; http_method; content:"/noncaloric-maksutovtelescope987/airflow-end-to-end-dev/main/python-dags/airflow-end-to-end-dev-v2.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873636/; classtype:trojan-activity;sid:84736736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873628)"; flow:established,from_client; content:"GET"; http_method; content:"/melisaapostolic677/plexaudit/main/malabathrum/audit_plex_v2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873628/; classtype:trojan-activity;sid:84736728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873629)"; flow:established,from_client; content:"GET"; http_method; content:"/analliseamicable382/bbc-skill/main/agents/bbc-skill-1.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873629/; classtype:trojan-activity;sid:84736729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873630)"; flow:established,from_client; content:"GET"; http_method; content:"/seedtimejiao934/kacho-vpc/main/hypobromite/kacho_vpc_v3.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873630/; classtype:trojan-activity;sid:84736730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873626)"; flow:established,from_client; content:"GET"; http_method; content:"/grassmacoun146/cpa-open/main/unfrail/cp_open_3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873626/; classtype:trojan-activity;sid:84736726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873627)"; flow:established,from_client; content:"GET"; http_method; content:"/usen99/vinext-agents-example/main/worker/agents-vinext-example-2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873627/; classtype:trojan-activity;sid:84736727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873622)"; flow:established,from_client; content:"GET"; http_method; content:"/kind-italianwoodbine415/warm-start/main/skills/warm/warm_start_v1.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873622/; classtype:trojan-activity;sid:84736722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873623)"; flow:established,from_client; content:"GET"; http_method; content:"/vin07grinder/release-notes-from-changelog/main/tests/release_changelog_notes_from_v2.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873623/; classtype:trojan-activity;sid:84736723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873624)"; flow:established,from_client; content:"GET"; http_method; content:"/smooth-snarl702/ae-agent/main/extracted/jsx/a-agent-v1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873624/; classtype:trojan-activity;sid:84736724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873625)"; flow:established,from_client; content:"GET"; http_method; content:"/unofficial-necturus123/most-capable-agent-system-prompt/main/nontechnical/capable-prompt-most-agent-system-v1.8.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873625/; classtype:trojan-activity;sid:84736725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873620)"; flow:established,from_client; content:"GET"; http_method; content:"/mukeshsingh05/genai_finance_news_stock_insights_ibm/main/integropalliata/insights_stock_genai_finance_ibm_news_v1.0-beta.4.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873620/; classtype:trojan-activity;sid:84736720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873621)"; flow:established,from_client; content:"GET"; http_method; content:"/bambiematutinal642/clawgod/main/antiparastatitis/software-2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873621/; classtype:trojan-activity;sid:84736721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873619)"; flow:established,from_client; content:"GET"; http_method; content:"/nikeshrajbanshi231/solana-defi-toolkit/main/src/utils/solana_defi_toolkit_1.7-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873619/; classtype:trojan-activity;sid:84736719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873617)"; flow:established,from_client; content:"GET"; http_method; content:"/jonasedwardsalkfirehose824/bobanimelist/main/.droid/software-2.9-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873617/; classtype:trojan-activity;sid:84736717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873618)"; flow:established,from_client; content:"GET"; http_method; content:"/xxfarreraxx/hyprfloat/main/src/commands/software-v2.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873618/; classtype:trojan-activity;sid:84736718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873615)"; flow:established,from_client; content:"GET"; http_method; content:"/baleyroy88/unlimited-kodi-downloader-download-audio-video-image-easily/main/arverni/downloader_image_download_unlimited_kodi_audio_video_easily_v2.8.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873615/; classtype:trojan-activity;sid:84736715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873616)"; flow:established,from_client; content:"GET"; http_method; content:"/abuttan1979/vln-yuannav/main/vln/project/yuan-nav-vl-3.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873616/; classtype:trojan-activity;sid:84736716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873611)"; flow:established,from_client; content:"GET"; http_method; content:"/jlyayou/internet-speed-inspector/main/android/app/src/debug/internet_inspector_speed_2.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873611/; classtype:trojan-activity;sid:84736711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873612)"; flow:established,from_client; content:"GET"; http_method; content:"/tamalegt/berrysentinel/main/pyrene/berry_sentinel_v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873612/; classtype:trojan-activity;sid:84736712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873613)"; flow:established,from_client; content:"GET"; http_method; content:"/moussegenusanthurium256/bemo/main/triconsonantalism/software-v2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873613/; classtype:trojan-activity;sid:84736713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873614)"; flow:established,from_client; content:"GET"; http_method; content:"/chowkdeveloper-a11y/pixarmesh/main/metadata/mesh-pix-ar-v1.5-beta.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873614/; classtype:trojan-activity;sid:84736714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873608)"; flow:established,from_client; content:"GET"; http_method; content:"/alxander98/fastportscanner/main/plaidy/port_fast_scanner_1.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873608/; classtype:trojan-activity;sid:84736708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873610)"; flow:established,from_client; content:"GET"; http_method; content:"/joripremature506/invincible-vs-game-release-desktop/main/game-resource/v-game-invincible-release-desktop-v3.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873610/; classtype:trojan-activity;sid:84736710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873607)"; flow:established,from_client; content:"GET"; http_method; content:"/hekiddo13/dar-lemlih-apiculture/main/apps/api/src/main/java/com/darlemlih/apiculture/dto/apiculture-dar-lemlih-1.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873607/; classtype:trojan-activity;sid:84736707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873606)"; flow:established,from_client; content:"GET"; http_method; content:"/zakicool/design-inspirations/main/src/app/designs/company-card/inspirations_design_v3.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873606/; classtype:trojan-activity;sid:84736706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873603)"; flow:established,from_client; content:"GET"; http_method; content:"/dreamiq21/linear-regression-visualizer/main/src/main/java/ovh/neziw/visualizer/io/visualizer_regression_linear_v1.0.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873603/; classtype:trojan-activity;sid:84736703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873604)"; flow:established,from_client; content:"GET"; http_method; content:"/doorknobefremzimbalist747/voltdb-qwk/main/raband/voltdb-qwk-v1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873604/; classtype:trojan-activity;sid:84736704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873605)"; flow:established,from_client; content:"GET"; http_method; content:"/knackwursthand910/sawwah/main/web_app/static/js/software-v2.5-alpha.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873605/; classtype:trojan-activity;sid:84736705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873601)"; flow:established,from_client; content:"GET"; http_method; content:"/tife2025/expo-spatial-layer-app/main/assets/expo_app_spatial_layer_v1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873601/; classtype:trojan-activity;sid:84736701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873602)"; flow:established,from_client; content:"GET"; http_method; content:"/asahi298/llm-circuit-finder/main/results/eval_base/circuit-finder-llm-1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873602/; classtype:trojan-activity;sid:84736702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873599)"; flow:established,from_client; content:"GET"; http_method; content:"/godcordofficial/kafka-rabbitmq-redis-elastichsearch-turkce-kaynak/main/examples/elasticsearch/java/src/elastichsearc_rabbitm_turkc_kaynak_kafk_redi_v2.5.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873599/; classtype:trojan-activity;sid:84736699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873600)"; flow:established,from_client; content:"GET"; http_method; content:"/ffli3550/recently-added-media-card/main/screenshots/recently-added-media-card-v1.1-beta.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873600/; classtype:trojan-activity;sid:84736700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873592)"; flow:established,from_client; content:"GET"; http_method; content:"/ab1140/sharpfocus/main/rider-plugin/gradle/focus_sharp_2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873592/; classtype:trojan-activity;sid:84736692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873593)"; flow:established,from_client; content:"GET"; http_method; content:"/worthwhile-booleanalgebra471/flutter-server-driven-ui/main/ios/runner.xcodeproj/project.xcworkspace/ui-flutter-server-driven-2.6.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873593/; classtype:trojan-activity;sid:84736693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873594)"; flow:established,from_client; content:"GET"; http_method; content:"/connorssubmitter868/crackwifi/main/aniseed/software_2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873594/; classtype:trojan-activity;sid:84736694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873595)"; flow:established,from_client; content:"GET"; http_method; content:"/rayan55050/progressive-agent/main/src/channels/agent-progressive-v2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873595/; classtype:trojan-activity;sid:84736695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873596)"; flow:established,from_client; content:"GET"; http_method; content:"/lasupinturas/skooly/main/apps/docs/software_3.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873596/; classtype:trojan-activity;sid:84736696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873597)"; flow:established,from_client; content:"GET"; http_method; content:"/syed7625/openclaw-opsdeck-core/main/src/pages/core_opsdeck_openclaw_v2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873597/; classtype:trojan-activity;sid:84736697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873598)"; flow:established,from_client; content:"GET"; http_method; content:"/abhishek-97735/equity-line/main/duboisia/equity_line_v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873598/; classtype:trojan-activity;sid:84736698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873589)"; flow:established,from_client; content:"GET"; http_method; content:"/bertrandunfirm58/cognitive-sparks/main/benchmarks/code/cognitive_sparks_v3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873589/; classtype:trojan-activity;sid:84736689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873590)"; flow:established,from_client; content:"GET"; http_method; content:"/cocohig4830/agent/main/assets/software_v1.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873590/; classtype:trojan-activity;sid:84736690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873591)"; flow:established,from_client; content:"GET"; http_method; content:"/texteditorscorpius2015/jinguyuan-dumpling-skill/main/references/meituan-queue/references/meituan-passport-user-auth/scripts/jinguyuan_dumpling_skill_3.9.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873591/; classtype:trojan-activity;sid:84736691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873583)"; flow:established,from_client; content:"GET"; http_method; content:"/inflexible-genusaristotelia269/xdr-boost/main/sources/boost_xdr_v2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873583/; classtype:trojan-activity;sid:84736683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873584)"; flow:established,from_client; content:"GET"; http_method; content:"/omair13/defect-detection-system/main/api/defect_detection_system_1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873584/; classtype:trojan-activity;sid:84736684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873585)"; flow:established,from_client; content:"GET"; http_method; content:"/embroiled-reducing940/world-happiness-report-analysis/main/guiltily/happiness_analysis_world_report_v2.5-beta.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873585/; classtype:trojan-activity;sid:84736685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873586)"; flow:established,from_client; content:"GET"; http_method; content:"/eddie-oss-369/ai_emotional_mirror/main/loggin/mirror_emotional_a_3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873586/; classtype:trojan-activity;sid:84736686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873587)"; flow:established,from_client; content:"GET"; http_method; content:"/mixturematrixaddition945/fh6-virtual_tcu/main/virtual_tcu/core/virtual_fh_tcu_3.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873587/; classtype:trojan-activity;sid:84736687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873588)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikay7124/studioline-web-designer-repack/main/unflossy/designer-web-studio-repack-line-2.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873588/; classtype:trojan-activity;sid:84736688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873582)"; flow:established,from_client; content:"GET"; http_method; content:"/gauri-2704/local-llm/main/src/local_llm/pipelines/local_llm_v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873582/; classtype:trojan-activity;sid:84736682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873578)"; flow:established,from_client; content:"GET"; http_method; content:"/pinchhitterequatorialcurrent101/system-prompt-open/main/assets/favicons/open-prompt-system-1.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873578/; classtype:trojan-activity;sid:84736678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873579)"; flow:established,from_client; content:"GET"; http_method; content:"/kedibey1232/trading-analyzer/main/nutria/analyzer_trading_3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873579/; classtype:trojan-activity;sid:84736679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873580)"; flow:established,from_client; content:"GET"; http_method; content:"/iptysam/azure-agentic-infraops/main/infra/infraops-agentic-azure-1.4-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873580/; classtype:trojan-activity;sid:84736680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873581)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefreda2002/note-app_assignment-mern/main/frontend/src/pages/assignment_mern_app_note_2.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873581/; classtype:trojan-activity;sid:84736681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873576)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafa-2002/zvec.h/main/examples/scheduler.c/zvec.h-v2.4-beta.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873576/; classtype:trojan-activity;sid:84736676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873577)"; flow:established,from_client; content:"GET"; http_method; content:"/terry170/metacore-stack.github.io/main/stoveless/metacore-stack.github.io-v2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873577/; classtype:trojan-activity;sid:84736677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873570)"; flow:established,from_client; content:"GET"; http_method; content:"/windowvalue821/codebase-to-course/main/references/course_to_codebase_v1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873570/; classtype:trojan-activity;sid:84736670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873572)"; flow:established,from_client; content:"GET"; http_method; content:"/eniitanire/ag402/main/adapters/ag_3.3.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873572/; classtype:trojan-activity;sid:84736672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873573)"; flow:established,from_client; content:"GET"; http_method; content:"/xxluffyxx40/cera-reasoning-harness/main/skills/cera-reasoning-harness/cera-harness-reasoning-v1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873573/; classtype:trojan-activity;sid:84736673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873574)"; flow:established,from_client; content:"GET"; http_method; content:"/jhowcae/en0wn/main/screenshoots/en-wn-v3.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873574/; classtype:trojan-activity;sid:84736674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873575)"; flow:established,from_client; content:"GET"; http_method; content:"/hajamir14/install-labs/main/skills/agent-packaging-foundations/labs_install_v3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873575/; classtype:trojan-activity;sid:84736675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873566)"; flow:established,from_client; content:"GET"; http_method; content:"/b-e-a-s-t69/react-native-shimmer-text/main/src/shimmer-react-native-text-v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873566/; classtype:trojan-activity;sid:84736666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873567)"; flow:established,from_client; content:"GET"; http_method; content:"/huesos264/heartbeat-like-a-man/main/configs/man_heartbeat_like_v2.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873567/; classtype:trojan-activity;sid:84736667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873568)"; flow:established,from_client; content:"GET"; http_method; content:"/salman3757/pyqt6-password-generator-analyzer/main/unconceited/generator-py-password-qt-analyzer-3.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873568/; classtype:trojan-activity;sid:84736668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873569)"; flow:established,from_client; content:"GET"; http_method; content:"/franckdjoukwe/osx4vm/main/opencore/efi/oc/kexts/virtualsmc.kext/contents/vm_os_v1.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873569/; classtype:trojan-activity;sid:84736669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873563)"; flow:established,from_client; content:"GET"; http_method; content:"/sneering-myrmeleon323/leonardo-ai-elite-premium/main/scyphomedusoid/elite-premium-leonardo-ai-v1.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873563/; classtype:trojan-activity;sid:84736663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873564)"; flow:established,from_client; content:"GET"; http_method; content:"/cbuethner/mlom-labs/main/forerehearsed/labs_mlo_3.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873564/; classtype:trojan-activity;sid:84736664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873565)"; flow:established,from_client; content:"GET"; http_method; content:"/biruk0125/real-time-arp-spoofing-detection-notification-tool/main/animize/ar_time_real_spoofing_tool_detection_notification_v3.3-alpha.3.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873565/; classtype:trojan-activity;sid:84736665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873559)"; flow:established,from_client; content:"GET"; http_method; content:"/faithlumumba/2025-tencent-advertising-algorithm-competition-finalist/main/sparaxis/advertising-finalist-tencent-algorithm-competition-3.2-alpha.3.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873559/; classtype:trojan-activity;sid:84736659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873560)"; flow:established,from_client; content:"GET"; http_method; content:"/matthosy/ipmi-fanpilot/main/public/fan-ipm-pilot-v2.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873560/; classtype:trojan-activity;sid:84736660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873561)"; flow:established,from_client; content:"GET"; http_method; content:"/shearno3856/tenzor-pay/main/upcrane/tenzor-pay-3.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873561/; classtype:trojan-activity;sid:84736661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873562)"; flow:established,from_client; content:"GET"; http_method; content:"/arshveer1208/ssh-brute-force-splunk/main/gude/ssh-splunk-force-brute-3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873562/; classtype:trojan-activity;sid:84736662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873558)"; flow:established,from_client; content:"GET"; http_method; content:"/cloudedminds/burnout_analysis/main/docs/analysis_burnout_v1.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873558/; classtype:trojan-activity;sid:84736658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873554)"; flow:established,from_client; content:"GET"; http_method; content:"/naseem499379/mihomo_yamls/main/general_config/liandu2024/yamls_mihomo_2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873554/; classtype:trojan-activity;sid:84736654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873555)"; flow:established,from_client; content:"GET"; http_method; content:"/legendsvenom/kotodama-framework/main/personas/lian_ej/kotodama_framework_2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873555/; classtype:trojan-activity;sid:84736655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873556)"; flow:established,from_client; content:"GET"; http_method; content:"/sesethunkqenkqa/veritas-ai/main/fonts/ai_veritas_v3.6-beta.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873556/; classtype:trojan-activity;sid:84736656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873552)"; flow:established,from_client; content:"GET"; http_method; content:"/libs9977/rawctl/main/node_modules/reveal.js/software-v1.3-alpha.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873552/; classtype:trojan-activity;sid:84736652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873553)"; flow:established,from_client; content:"GET"; http_method; content:"/liquorlicensegenusphysostigma689/helm/main/projects/example-project/.claude/software-3.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873553/; classtype:trojan-activity;sid:84736653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873548)"; flow:established,from_client; content:"GET"; http_method; content:"/skylerperfumed417/colamd/main/resources/md-cola-v2.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873548/; classtype:trojan-activity;sid:84736648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873549)"; flow:established,from_client; content:"GET"; http_method; content:"/enyen9x/clear/main/nursy/software_2.9.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873549/; classtype:trojan-activity;sid:84736649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873550)"; flow:established,from_client; content:"GET"; http_method; content:"/euca4923/qucore-dynamic-packages/main/ts/enums/dynamic_packages_qucore_v1.9-beta.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873550/; classtype:trojan-activity;sid:84736650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873551)"; flow:established,from_client; content:"GET"; http_method; content:"/carlos0023/gallery-dl-multi-instance-downloader/main/unpiteousness/instance_gallery_downloader_multi_dl_1.6.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873551/; classtype:trojan-activity;sid:84736651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873545)"; flow:established,from_client; content:"GET"; http_method; content:"/piersonpseudohermaphroditic894/mood_land/main/undetrimental/land_mood_1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873545/; classtype:trojan-activity;sid:84736645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873546)"; flow:established,from_client; content:"GET"; http_method; content:"/priyanshop754/vibe-coding-playbook/main/advanced-prompts/coding_vibe_playbook_3.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873546/; classtype:trojan-activity;sid:84736646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873547)"; flow:established,from_client; content:"GET"; http_method; content:"/gg44183/ai-agent-book/main/en/part2-tools-and-extensions/assets/book-ai-agent-v1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873547/; classtype:trojan-activity;sid:84736647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873544)"; flow:established,from_client; content:"GET"; http_method; content:"/junior81195/athenaeum/main/frontend/app/library/software-1.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873544/; classtype:trojan-activity;sid:84736644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873543)"; flow:established,from_client; content:"GET"; http_method; content:"/obrunolima1910/cve-2026-24061/main/ultrainvolved/cv_3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873543/; classtype:trojan-activity;sid:84736643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873542)"; flow:established,from_client; content:"GET"; http_method; content:"/arimarlgomes/kleinmanager/main/app/models/klein_manager_3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873542/; classtype:trojan-activity;sid:84736642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873539)"; flow:established,from_client; content:"GET"; http_method; content:"/chidumemironanduka/-os_project/main/sazen/o-project-v3.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873539/; classtype:trojan-activity;sid:84736639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873541)"; flow:established,from_client; content:"GET"; http_method; content:"/messa8301/quickbench/main/geogenous/software-3.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873541/; classtype:trojan-activity;sid:84736641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873533)"; flow:established,from_client; content:"GET"; http_method; content:"/fairandsquare-sudra105/minecraft-server-integration-node.js/main/dist/platforms/minecraft_integration_server_node_js_v3.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873533/; classtype:trojan-activity;sid:84736633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873534)"; flow:established,from_client; content:"GET"; http_method; content:"/yusupov70/usql/main/src/drivers/software-3.0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873534/; classtype:trojan-activity;sid:84736634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873535)"; flow:established,from_client; content:"GET"; http_method; content:"/tungusicamericanalligator425/control-note/main/unrobed/control-note-v1.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873535/; classtype:trojan-activity;sid:84736635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873536)"; flow:established,from_client; content:"GET"; http_method; content:"/noninflammatory-tunny848/advertising-skills/main/skills/operator-os/conversion-path-builder/skills-advertising-v3.7.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873536/; classtype:trojan-activity;sid:84736636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873537)"; flow:established,from_client; content:"GET"; http_method; content:"/dynaevangelical2652/android-agent/main/frontend/src/assets/agent-android-v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873537/; classtype:trojan-activity;sid:84736637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873528)"; flow:established,from_client; content:"GET"; http_method; content:"/paraplegic-upperavon116/ei-todolistsenaclesson/main/specification/assets/ei_senac_lesson_to_do_list_v2.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873528/; classtype:trojan-activity;sid:84736628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873529)"; flow:established,from_client; content:"GET"; http_method; content:"/sebaxtian110/siem/main/dashboard/src/assets/software-v2.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873529/; classtype:trojan-activity;sid:84736629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873530)"; flow:established,from_client; content:"GET"; http_method; content:"/carlosguedes0007-oss/vla-lab/main/src/vlalab/lab-vl-v3.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873530/; classtype:trojan-activity;sid:84736630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873531)"; flow:established,from_client; content:"GET"; http_method; content:"/rishav38/event-management-system/main/backend/src/middlewares/system_event_management_v3.0.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873531/; classtype:trojan-activity;sid:84736631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873532)"; flow:established,from_client; content:"GET"; http_method; content:"/ndamine/youtube-eng/main/templates/eng_youtube_2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873532/; classtype:trojan-activity;sid:84736632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873524)"; flow:established,from_client; content:"GET"; http_method; content:"/monahright467/harness-books/main/book2-comparing/_build/harness-books-v1.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873524/; classtype:trojan-activity;sid:84736624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873525)"; flow:established,from_client; content:"GET"; http_method; content:"/cataclysmic-pattypansquash50/eidetic-memory/main/docs/eidetic-memory-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873525/; classtype:trojan-activity;sid:84736625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873526)"; flow:established,from_client; content:"GET"; http_method; content:"/bautiroalt/mcp-server/main/frontend/mc-server-v1.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873526/; classtype:trojan-activity;sid:84736626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873527)"; flow:established,from_client; content:"GET"; http_method; content:"/senjinrl/osf/main/lactate/software_2.5.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873527/; classtype:trojan-activity;sid:84736627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873520)"; flow:established,from_client; content:"GET"; http_method; content:"/efecanyldz/awesome-developer-apis/main/gastrophilite/apis-awesome-developer-v1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873520/; classtype:trojan-activity;sid:84736620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873521)"; flow:established,from_client; content:"GET"; http_method; content:"/collinstudied660/mcp-hub/main/mcp_hub/hub_mcp_2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873521/; classtype:trojan-activity;sid:84736621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873522)"; flow:established,from_client; content:"GET"; http_method; content:"/alsss9/mcp-yandex-tracker/main/internal/mcp_yandex_tracker_2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873522/; classtype:trojan-activity;sid:84736622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873523)"; flow:established,from_client; content:"GET"; http_method; content:"/mathews2007morais-boop/payload-obfuscator/main/public/payload_obfuscator_v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873523/; classtype:trojan-activity;sid:84736623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873519)"; flow:established,from_client; content:"GET"; http_method; content:"/paah11/kalshi-claw-skill/main/scripts/claw_kalshi_skill_3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873519/; classtype:trojan-activity;sid:84736619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873517)"; flow:established,from_client; content:"GET"; http_method; content:"/nyxy5078/taxiagent/main/src/main/java/com/fancy/taxiagent/agentbase/amap/pojo/route/taxi_agent_2.6-alpha.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873517/; classtype:trojan-activity;sid:84736617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873518)"; flow:established,from_client; content:"GET"; http_method; content:"/vmy41/agent-harness/main/diaclase/agent-harness-v2.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873518/; classtype:trojan-activity;sid:84736618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873513)"; flow:established,from_client; content:"GET"; http_method; content:"/mykewkymap/news-event-impact-detector/main/data/news-event-impact-detector-v2.9-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873513/; classtype:trojan-activity;sid:84736613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873514)"; flow:established,from_client; content:"GET"; http_method; content:"/bruh-2009/pokedex-backend/main/phelloplastic/backend-pokedex-1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873514/; classtype:trojan-activity;sid:84736614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873515)"; flow:established,from_client; content:"GET"; http_method; content:"/doggyggyt/crm-app/main/src/client/app-crm-v1.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873515/; classtype:trojan-activity;sid:84736615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873516)"; flow:established,from_client; content:"GET"; http_method; content:"/namithnami/jsreconduit/main/jsbeautifier/jsbeautifier/unpackers/tests/reconduit_js_2.5-alpha.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873516/; classtype:trojan-activity;sid:84736616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873508)"; flow:established,from_client; content:"GET"; http_method; content:"/dipakvaghela99/rl-academy-data-analytics/main/analysis/analytics-rl-academy-data-1.6-alpha.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873508/; classtype:trojan-activity;sid:84736608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873509)"; flow:established,from_client; content:"GET"; http_method; content:"/korpztak970/swush/main/src/app/api/software_2.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873509/; classtype:trojan-activity;sid:84736609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873510)"; flow:established,from_client; content:"GET"; http_method; content:"/anhhuy209/removemicrosoftcopilotai/main/psychorrhagic/ai_remove_copilot_microsoft_v3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873510/; classtype:trojan-activity;sid:84736610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873511)"; flow:established,from_client; content:"GET"; http_method; content:"/khaionsen/r3f-character-dance/main/src/js/component/r_dance_character_f_3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873511/; classtype:trojan-activity;sid:84736611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873512)"; flow:established,from_client; content:"GET"; http_method; content:"/biblosaggins/voriya-skills/main/docs/skills-voriya-v2.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873512/; classtype:trojan-activity;sid:84736612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873506)"; flow:established,from_client; content:"GET"; http_method; content:"/rajanikant12/crypto-analysis/main/src/main/resources/db/postgres/crypto_analysis_2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873506/; classtype:trojan-activity;sid:84736606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873507)"; flow:established,from_client; content:"GET"; http_method; content:"/rehanvhora778/bibtex-extraction/main/radicule/bibtex_extraction_1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873507/; classtype:trojan-activity;sid:84736607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873505)"; flow:established,from_client; content:"GET"; http_method; content:"/irsa070501/advanced-ai-agents/main/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/api/agents_a_advanced_2.4.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873505/; classtype:trojan-activity;sid:84736605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873503)"; flow:established,from_client; content:"GET"; http_method; content:"/thanhdt716/filament-shield/main/resources/lang/shield_filament_v2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873503/; classtype:trojan-activity;sid:84736603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873504)"; flow:established,from_client; content:"GET"; http_method; content:"/unitary-monoiodotyrosine892/tgcli/main/internal/config/software_3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873504/; classtype:trojan-activity;sid:84736604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873501)"; flow:established,from_client; content:"GET"; http_method; content:"/kaisersolos/cinestream-film-collection-backend/main/prisma/backend-cinestream-collection-film-2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873501/; classtype:trojan-activity;sid:84736601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873502)"; flow:established,from_client; content:"GET"; http_method; content:"/thrifty-consonance737/ninjaxrf/main/hereditary/xrf-ninja-1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873502/; classtype:trojan-activity;sid:84736602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873500)"; flow:established,from_client; content:"GET"; http_method; content:"/deep0305-d/minecraft-client-collection/main/acridine/collection_client_minecraft_3.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873500/; classtype:trojan-activity;sid:84736600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873494)"; flow:established,from_client; content:"GET"; http_method; content:"/ranjit123-yst/ananya/main/src/pages/api/software_2.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873494/; classtype:trojan-activity;sid:84736594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873495)"; flow:established,from_client; content:"GET"; http_method; content:"/filmy6584/aurora-windmill/main/data/windmill_aurora_v3.2-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873495/; classtype:trojan-activity;sid:84736595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873496)"; flow:established,from_client; content:"GET"; http_method; content:"/rhyean88/apple-platform-build-tools-claude-code-plugin/main/skills/building-apple-platform-products/references/build-tools-code-platform-plugin-apple-claude-3.2.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873496/; classtype:trojan-activity;sid:84736596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873497)"; flow:established,from_client; content:"GET"; http_method; content:"/maudribless692/ds2-mac/main/wenchlike/mac-d-v1.8-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873497/; classtype:trojan-activity;sid:84736597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873498)"; flow:established,from_client; content:"GET"; http_method; content:"/bryangates254/merowe-dam-water-quality/main/images/merowe-water-dam-quality-2.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873498/; classtype:trojan-activity;sid:84736598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873492)"; flow:established,from_client; content:"GET"; http_method; content:"/rosalyndfaithful716/guardrail/main/examples/software-v1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873492/; classtype:trojan-activity;sid:84736592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873493)"; flow:established,from_client; content:"GET"; http_method; content:"/lmoudamir/thalamus/main/integration-tests/calorie-cam/software-v1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873493/; classtype:trojan-activity;sid:84736593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873490)"; flow:established,from_client; content:"GET"; http_method; content:"/cinematic-disgust8653/fingerprintdetector/main/icons/software_v2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873490/; classtype:trojan-activity;sid:84736590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873487)"; flow:established,from_client; content:"GET"; http_method; content:"/el8aed/oneclickblock-x-propaganda-cn/main/lonicera/cn_one_block_click_propaganda_v1.5-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873487/; classtype:trojan-activity;sid:84736587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873488)"; flow:established,from_client; content:"GET"; http_method; content:"/efferentnervestylophorumdiphyllum452/haskell-a95/main/unreclaiming/haskell-a95_2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873488/; classtype:trojan-activity;sid:84736588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873489)"; flow:established,from_client; content:"GET"; http_method; content:"/catchphraseostryopsis204/buildcored-orcas/main/assets/buildcored_orcas_2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873489/; classtype:trojan-activity;sid:84736589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873486)"; flow:established,from_client; content:"GET"; http_method; content:"/yvan-upadhyay/sublime-lumos/main/snippets/lumos-sublime-v3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873486/; classtype:trojan-activity;sid:84736586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873485)"; flow:established,from_client; content:"GET"; http_method; content:"/radiationpatterngordianknot284/uap-pursue-release-01/main/defacingly/release_pursue_uap_3.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873485/; classtype:trojan-activity;sid:84736585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873484)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-karout/posteritas/main/wirl/software_1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873484/; classtype:trojan-activity;sid:84736584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873481)"; flow:established,from_client; content:"GET"; http_method; content:"/unaacceptable297/kali-mcp/main/docker/mcp_kali_v2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873481/; classtype:trojan-activity;sid:84736581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873482)"; flow:established,from_client; content:"GET"; http_method; content:"/unvulcanised-watercress762/mem9/main/server/cmd/mnemo-server/mem-v3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873482/; classtype:trojan-activity;sid:84736582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873483)"; flow:established,from_client; content:"GET"; http_method; content:"/joselu4466/untouchid/main/menubar/touchbridgemenu/core/touch_id_un_3.4-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873483/; classtype:trojan-activity;sid:84736583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873478)"; flow:established,from_client; content:"GET"; http_method; content:"/alexzq343-beep/canvas-cowork/main/references/cowork-canvas-1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873478/; classtype:trojan-activity;sid:84736578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873479)"; flow:established,from_client; content:"GET"; http_method; content:"/legal-switchhitter784/rockpile/main/rockpile/assets.xcassets/crab_idle_neutral.imageset/software-v1.8-beta.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873479/; classtype:trojan-activity;sid:84736579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873480)"; flow:established,from_client; content:"GET"; http_method; content:"/s4turno0/movie-review/main/notebooks/movie_review_3.1-alpha.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873480/; classtype:trojan-activity;sid:84736580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873473)"; flow:established,from_client; content:"GET"; http_method; content:"/adrianvallejosflores/bluesky-social-bot/main/app/static/bot-bluesky-social-v2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873473/; classtype:trojan-activity;sid:84736573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873474)"; flow:established,from_client; content:"GET"; http_method; content:"/strong-noncallablebond390/nativeappmanager/main/src-tauri/icons/ios/software_v2.8-alpha.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873474/; classtype:trojan-activity;sid:84736574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873475)"; flow:established,from_client; content:"GET"; http_method; content:"/leadersboat/mmclaw/main/mmclaw/skills/mm_claw_v3.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873475/; classtype:trojan-activity;sid:84736575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873476)"; flow:established,from_client; content:"GET"; http_method; content:"/agustinusf132-lgtm/puck-arena/main/img/puck-arena-1.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873476/; classtype:trojan-activity;sid:84736576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873477)"; flow:established,from_client; content:"GET"; http_method; content:"/babachar20/qr-code-generater/main/src/qrstudio/encoding/generater-code-qr-2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873477/; classtype:trojan-activity;sid:84736577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873470)"; flow:established,from_client; content:"GET"; http_method; content:"/noobgaminghard/cursor-rules/main/rules/typescript-strict/rules_cursor_3.2-beta.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873470/; classtype:trojan-activity;sid:84736570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873471)"; flow:established,from_client; content:"GET"; http_method; content:"/kyriesuu/azure-weather/main/backend/weather_azur_2.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873471/; classtype:trojan-activity;sid:84736571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873472)"; flow:established,from_client; content:"GET"; http_method; content:"/serversanaa/xdp-ebpf-anti-ddos-firewall/main/inveracious/e_anti_d_do_xd_firewall_bp_1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873472/; classtype:trojan-activity;sid:84736572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873469)"; flow:established,from_client; content:"GET"; http_method; content:"/ugene777/cpp23-best-practices/main/book/content/part4/cpp23-best-practices_1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873469/; classtype:trojan-activity;sid:84736569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873468)"; flow:established,from_client; content:"GET"; http_method; content:"/rendynud/the-sandbox/main/millrace/the-sandbox-v2.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873468/; classtype:trojan-activity;sid:84736568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873465)"; flow:established,from_client; content:"GET"; http_method; content:"/thasinduniduwara/christmas-tree/main/src/christmas-tree-v3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873465/; classtype:trojan-activity;sid:84736565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873466)"; flow:established,from_client; content:"GET"; http_method; content:"/intolerancepseudomonadales905/voxrt-silero-ios/main/sources/voxrt_ios_silero_v1.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873466/; classtype:trojan-activity;sid:84736566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873467)"; flow:established,from_client; content:"GET"; http_method; content:"/savagegodfather/tma-llms-txt/main/technolithic/tma_txt_llms_v1.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873467/; classtype:trojan-activity;sid:84736567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873461)"; flow:established,from_client; content:"GET"; http_method; content:"/fitriadijamil/schullegerhard/main/hispid/software_2.4-alpha.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873461/; classtype:trojan-activity;sid:84736561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873462)"; flow:established,from_client; content:"GET"; http_method; content:"/voxanne1478/markdown-note-app/main/markdown-note-app/client/markdown_note_app_v1.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873462/; classtype:trojan-activity;sid:84736562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873463)"; flow:established,from_client; content:"GET"; http_method; content:"/shouryaf/foreign-safety-tourist-travel-web/main/src/components/digitalpassport/travel_tourist_web_safety_foreign_v1.8.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873463/; classtype:trojan-activity;sid:84736563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873460)"; flow:established,from_client; content:"GET"; http_method; content:"/jsm19019/oracle-pl-sql-turkce-kaynak/main/src/p_kaynak_sq_turkc_oracl_2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873460/; classtype:trojan-activity;sid:84736560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873453)"; flow:established,from_client; content:"GET"; http_method; content:"/kingdevi/govrixaioss/main/crates/govrix-ai-oss-proxy/software-3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873453/; classtype:trojan-activity;sid:84736553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873454)"; flow:established,from_client; content:"GET"; http_method; content:"/maloy2223/gitviews/main/src/styles/variables/software_3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873454/; classtype:trojan-activity;sid:84736554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873455)"; flow:established,from_client; content:"GET"; http_method; content:"/euphonic-treesparrow658/how-claude-code-works/main/archipelagic/how-code-claude-works-v2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873455/; classtype:trojan-activity;sid:84736555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873456)"; flow:established,from_client; content:"GET"; http_method; content:"/shrief-salama/sentinel/main/src/app/software-3.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873456/; classtype:trojan-activity;sid:84736556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873457)"; flow:established,from_client; content:"GET"; http_method; content:"/sabariranil/nashvpn/main/neoplastic/software-v3.0-alpha.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873457/; classtype:trojan-activity;sid:84736557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873458)"; flow:established,from_client; content:"GET"; http_method; content:"/ley995/triangle-splatting2/main/torch_bindings/triangulation/splatting_triangle_v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873458/; classtype:trojan-activity;sid:84736558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873459)"; flow:established,from_client; content:"GET"; http_method; content:"/codegeaslelouch/brain-tumor-qcnn-resnet/main/assets/res_qcn_net_tumor_brain_1.8-beta.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873459/; classtype:trojan-activity;sid:84736559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873449)"; flow:established,from_client; content:"GET"; http_method; content:"/nooksandcrannieslgb937/ai-chatbot/main/src/bot/handlers/ai_chatbot_v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873449/; classtype:trojan-activity;sid:84736549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873450)"; flow:established,from_client; content:"GET"; http_method; content:"/ptsd-ptsr/phpxtreamcodes/main/intradermally/php_codes_xtream_v3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873450/; classtype:trojan-activity;sid:84736550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873451)"; flow:established,from_client; content:"GET"; http_method; content:"/lingngngng/review-prompts/main/kernel/prompts_review_v1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873451/; classtype:trojan-activity;sid:84736551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873452)"; flow:established,from_client; content:"GET"; http_method; content:"/tasseled-penetratinginjury926/celestial-launcher-releases/main/skinmanager/launcher-releases-celestial-v2.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873452/; classtype:trojan-activity;sid:84736552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873444)"; flow:established,from_client; content:"GET"; http_method; content:"/factornine/gsa-elibrary-scraper/main/tinstone/elibrary_scraper_gsa_3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873444/; classtype:trojan-activity;sid:84736544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873445)"; flow:established,from_client; content:"GET"; http_method; content:"/lenon23/simplelang/main/subchorionic/lang_simple_1.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873445/; classtype:trojan-activity;sid:84736545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873446)"; flow:established,from_client; content:"GET"; http_method; content:"/akhilrockeeey/kiani-domain-checker/main/bin/kiani-domain-checker-1.4-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873446/; classtype:trojan-activity;sid:84736546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873447)"; flow:established,from_client; content:"GET"; http_method; content:"/levelwhiteroom438/hosting-outbound-logger/main/vortically/outbound_logger_hosting_v3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873447/; classtype:trojan-activity;sid:84736547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873448)"; flow:established,from_client; content:"GET"; http_method; content:"/mohameddioman/stats-base-ndarray-sdsmean/main/examples/stats-base-ndarray-sdsmean_v2.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873448/; classtype:trojan-activity;sid:84736548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873437)"; flow:established,from_client; content:"GET"; http_method; content:"/gkrtiwo26/the-developer-universe-hub/main/resources/developer_universe_hub_the_v2.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873437/; classtype:trojan-activity;sid:84736537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873438)"; flow:established,from_client; content:"GET"; http_method; content:"/meh3met/vmware-workstation-pro-no-trial/main/orismologic/pro_workstation_mware_trial_no_v_1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873438/; classtype:trojan-activity;sid:84736538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873439)"; flow:established,from_client; content:"GET"; http_method; content:"/fabio295/tinysafe-1/main/intensity/tinysafe-v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873439/; classtype:trojan-activity;sid:84736539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873440)"; flow:established,from_client; content:"GET"; http_method; content:"/ryanpaulgernan/machine-failure-prediction-using-ai4i-2020-data/main/notebooks/failure_machine_a_using_prediction_data_1.6.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873440/; classtype:trojan-activity;sid:84736540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873441)"; flow:established,from_client; content:"GET"; http_method; content:"/papotewii/epstein/main/assets/in_epste_v3.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873441/; classtype:trojan-activity;sid:84736541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873442)"; flow:established,from_client; content:"GET"; http_method; content:"/ninjaxx391209-crypto/vibe-oncall/main/osculatrix/oncall-vibe-v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873442/; classtype:trojan-activity;sid:84736542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873443)"; flow:established,from_client; content:"GET"; http_method; content:"/bdbetterweb/memebership-plan-component/main/guide/memebership_component_plan_v2.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873443/; classtype:trojan-activity;sid:84736543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873435)"; flow:established,from_client; content:"GET"; http_method; content:"/bombastic1234/species-in-pieces/main/rowland/pieces-species-in-v2.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873435/; classtype:trojan-activity;sid:84736535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873436)"; flow:established,from_client; content:"GET"; http_method; content:"/githaozoizj/ferreus_rbf_rs/main/py_ferreus_bbfmm/docs/rs_ferreus_rbf_v3.2-alpha.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873436/; classtype:trojan-activity;sid:84736536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873433)"; flow:established,from_client; content:"GET"; http_method; content:"/firestryk/chatgpt-website.github.io/main/bulgy/io-github-website-chatgpt-v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873433/; classtype:trojan-activity;sid:84736533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873434)"; flow:established,from_client; content:"GET"; http_method; content:"/30nilupulthisaranga-bit/aegis/main/internal/proxy/software-2.4-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873434/; classtype:trojan-activity;sid:84736534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873432)"; flow:established,from_client; content:"GET"; http_method; content:"/sinhnguyen0802/solana-program-vault/main/aminoanthraquinone/program-vault-solana-v2.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873432/; classtype:trojan-activity;sid:84736532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873430)"; flow:established,from_client; content:"GET"; http_method; content:"/charlotteaphetic255/netroute-sim/main/topologies/sim-netroute-v3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873430/; classtype:trojan-activity;sid:84736530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873429)"; flow:established,from_client; content:"GET"; http_method; content:"/beta-issuer634/xyz-file-merger/main/assets/xyz_merger_file_v3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873429/; classtype:trojan-activity;sid:84736529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873428)"; flow:established,from_client; content:"GET"; http_method; content:"/nupurgurnule/goldmac/main/assets/mac-gold-3.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873428/; classtype:trojan-activity;sid:84736528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873424)"; flow:established,from_client; content:"GET"; http_method; content:"/khudadadakram/networkops_platform/main/scripts/templates/ops_platform_network_1.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873424/; classtype:trojan-activity;sid:84736524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873425)"; flow:established,from_client; content:"GET"; http_method; content:"/user2897/scrapstyle/main/app/api/scrape/lib/prompt/software_v2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873425/; classtype:trojan-activity;sid:84736525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873426)"; flow:established,from_client; content:"GET"; http_method; content:"/s1moon/total-uninstall-professional-no-trial/main/peritonitic/total-uninstall-trial-professional-no-2.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873426/; classtype:trojan-activity;sid:84736526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873427)"; flow:established,from_client; content:"GET"; http_method; content:"/danielosek110/naics-codes-pull/main/src/pull-codes-naics-2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873427/; classtype:trojan-activity;sid:84736527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873423)"; flow:established,from_client; content:"GET"; http_method; content:"/mozellegambian177/kol-claw/main/data/claw-kol-v2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873423/; classtype:trojan-activity;sid:84736523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873418)"; flow:established,from_client; content:"GET"; http_method; content:"/mikenob39wang/phone-number-location-tracking-tool/main/jacobinically/location_number_tracking_tool_phone_v2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873418/; classtype:trojan-activity;sid:84736518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873419)"; flow:established,from_client; content:"GET"; http_method; content:"/vikaskr7838/real-time-payment-architecture-orchestration/main/src/realtimepaymentarchitectureorchestration/service/orchestration-real-architecture-payment-time-2.0.zip"; http_uri; depth:168; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873419/; classtype:trojan-activity;sid:84736519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873420)"; flow:established,from_client; content:"GET"; http_method; content:"/in941/full-stack-devops-homelab/main/ansible/full-homelab-devops-stack-v2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873420/; classtype:trojan-activity;sid:84736520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873415)"; flow:established,from_client; content:"GET"; http_method; content:"/augustan-britishwestafrica489/gitbackup/main/electron/services/software_2.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873415/; classtype:trojan-activity;sid:84736515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873417)"; flow:established,from_client; content:"GET"; http_method; content:"/mattrm3/googlerecaptcha-backend-example/main/src/main/java/com/captcha_re_end_back_google_example_v1.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873417/; classtype:trojan-activity;sid:84736517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873409)"; flow:established,from_client; content:"GET"; http_method; content:"/lxxvii-blacknightshade680/cs-bc-l-m/main/transitory/b-c-m-3.8-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873409/; classtype:trojan-activity;sid:84736509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873410)"; flow:established,from_client; content:"GET"; http_method; content:"/fuugug/wincatalog-latest-patch/main/machinable/wincatalog-latest-patch_2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873410/; classtype:trojan-activity;sid:84736510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873411)"; flow:established,from_client; content:"GET"; http_method; content:"/romel24233/game-billiards/main/src/main/java/com/billiards2d/game-billiards-v3.4-beta.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873411/; classtype:trojan-activity;sid:84736511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873412)"; flow:established,from_client; content:"GET"; http_method; content:"/mormoncricketburrito84/ldpublisher/main/nomadian/software_v2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873412/; classtype:trojan-activity;sid:84736512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873413)"; flow:established,from_client; content:"GET"; http_method; content:"/khangcutis1/bigram-language-model/main/__pycache__/language_model_bigram_v3.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873413/; classtype:trojan-activity;sid:84736513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873414)"; flow:established,from_client; content:"GET"; http_method; content:"/hasanah9667/fdcxcapsense/main/src/core/fd_sense_cx_cap_3.2-alpha.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873414/; classtype:trojan-activity;sid:84736514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873402)"; flow:established,from_client; content:"GET"; http_method; content:"/fahrurozik/kagora/main/src/main/software-v3.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873402/; classtype:trojan-activity;sid:84736502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873403)"; flow:established,from_client; content:"GET"; http_method; content:"/adita-sama/quiz-supermo-web-app/main/assets/icons/web_supermo_app_quiz_v3.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873403/; classtype:trojan-activity;sid:84736503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873404)"; flow:established,from_client; content:"GET"; http_method; content:"/anish3390-adi/mineru-paper-reader/main/external/md-translator/src/app/[locale]/paper-miner-reader-2.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873404/; classtype:trojan-activity;sid:84736504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873405)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed286332/constants-float16-log10-e/main/dist/log-constants-float-e-1.9-alpha.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873405/; classtype:trojan-activity;sid:84736505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873406)"; flow:established,from_client; content:"GET"; http_method; content:"/nonnahjust868/videodetective/main/config/video_detective_v1.2-alpha.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873406/; classtype:trojan-activity;sid:84736506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873407)"; flow:established,from_client; content:"GET"; http_method; content:"/castrx444/powersub-demo-2905/main/suprarenine/powersub-demo-1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873407/; classtype:trojan-activity;sid:84736507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873408)"; flow:established,from_client; content:"GET"; http_method; content:"/civilofficerconducting396/comfyui-workflow-finder/main/docs/comfyui_finder_workflow_v3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873408/; classtype:trojan-activity;sid:84736508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873398)"; flow:established,from_client; content:"GET"; http_method; content:"/swapnil2805/vibe-app/main/components/app-vibe-v3.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873398/; classtype:trojan-activity;sid:84736498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873399)"; flow:established,from_client; content:"GET"; http_method; content:"/jhyshy/didactic-broccoli/main/graciousness/broccoli_didactic_2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873399/; classtype:trojan-activity;sid:84736499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873400)"; flow:established,from_client; content:"GET"; http_method; content:"/sujaltilokani/claude-to-im/main/docs/im-claude-to-2.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873400/; classtype:trojan-activity;sid:84736500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873401)"; flow:established,from_client; content:"GET"; http_method; content:"/matheusw23/html5-component-library/main/lithontriptist/library-component-html-1.9-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873401/; classtype:trojan-activity;sid:84736501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873396)"; flow:established,from_client; content:"GET"; http_method; content:"/nnnikitqa/unity-fbx-export-steam-blender-fix/main/villageless/blender-steam-fix-unity-fbx-export-v1.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873396/; classtype:trojan-activity;sid:84736496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873397)"; flow:established,from_client; content:"GET"; http_method; content:"/breastless-andcircuit638/lean-loop/main/skills/lean-loop/templates/lean-loop-v2.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873397/; classtype:trojan-activity;sid:84736497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873391)"; flow:established,from_client; content:"GET"; http_method; content:"/hacxxcode/ds_projects/main/predicting_customer_loss_for_a_telecom/d_projects_v1.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873391/; classtype:trojan-activity;sid:84736491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873392)"; flow:established,from_client; content:"GET"; http_method; content:"/1ksev/dynamic-systems-analysis/main/presubordinate/dynamic-systems-analysis-v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873392/; classtype:trojan-activity;sid:84736492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873393)"; flow:established,from_client; content:"GET"; http_method; content:"/creamdede/void-nuke/main/enticement/nuke-void-1.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873393/; classtype:trojan-activity;sid:84736493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873394)"; flow:established,from_client; content:"GET"; http_method; content:"/zerotohero99/smart-pole-skill/main/docs/skill_pole_smart_v2.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873394/; classtype:trojan-activity;sid:84736494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873395)"; flow:established,from_client; content:"GET"; http_method; content:"/sammeer786/42-hackaton/main/client/src/components/hackaton-v2.5-alpha.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873395/; classtype:trojan-activity;sid:84736495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873390)"; flow:established,from_client; content:"GET"; http_method; content:"/daciemonistic497/large-codebase-survival/main/drafts/codebase_large_survival_v2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873390/; classtype:trojan-activity;sid:84736490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873385)"; flow:established,from_client; content:"GET"; http_method; content:"/saifaraju4/micro-wallet_saas/main/finiglacial/s_micro_wallet_saa_v1.1-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873385/; classtype:trojan-activity;sid:84736485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873386)"; flow:established,from_client; content:"GET"; http_method; content:"/virile-wainscoting845/graduation-pebble/main/docs/graduation-pebble-v1.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873386/; classtype:trojan-activity;sid:84736486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873387)"; flow:established,from_client; content:"GET"; http_method; content:"/laziere/laravel-metrics-fathom/main/resources/boost/guidelines/fathom_metrics_laravel_v1.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873387/; classtype:trojan-activity;sid:84736487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873388)"; flow:established,from_client; content:"GET"; http_method; content:"/eldenisek/syro-theme/main/images/syro_theme_v3.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873388/; classtype:trojan-activity;sid:84736488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873380)"; flow:established,from_client; content:"GET"; http_method; content:"/alvgon/swaglabs-playwright-java/main/src/test/java/com/java-playwright-swag-labs-v1.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873380/; classtype:trojan-activity;sid:84736480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873381)"; flow:established,from_client; content:"GET"; http_method; content:"/mattwatery728/unifi-ptz-better-patrol/main/hurrock/ptz-better-patrol-unifi-1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873381/; classtype:trojan-activity;sid:84736481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873382)"; flow:established,from_client; content:"GET"; http_method; content:"/noob-programmr/sitelen-layer-plugin/main/qa/fixtures/plugin_layer_sitelen_1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873382/; classtype:trojan-activity;sid:84736482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873383)"; flow:established,from_client; content:"GET"; http_method; content:"/ieoop/corroded/main/examples/software_2.1.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873383/; classtype:trojan-activity;sid:84736483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873384)"; flow:established,from_client; content:"GET"; http_method; content:"/tabbypyrotechnic519/claw-code-parity/main/src/cli/code-claw-parity-v2.4-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873384/; classtype:trojan-activity;sid:84736484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873377)"; flow:established,from_client; content:"GET"; http_method; content:"/xqzimgz/tax-law-mcp/main/src/lib/law-mcp-tax-3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873377/; classtype:trojan-activity;sid:84736477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873378)"; flow:established,from_client; content:"GET"; http_method; content:"/empty-democritus307/autoprober/main/docs/images/public-release-images/prober_auto_v1.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873378/; classtype:trojan-activity;sid:84736478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873379)"; flow:established,from_client; content:"GET"; http_method; content:"/9093333310/scagent/main/apps/web/src/components/software-3.1-beta.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873379/; classtype:trojan-activity;sid:84736479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873373)"; flow:established,from_client; content:"GET"; http_method; content:"/itsriguking/clairveillance-manifesto/main/docs/clairveillance-manifesto-2.4-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873373/; classtype:trojan-activity;sid:84736473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873374)"; flow:established,from_client; content:"GET"; http_method; content:"/stigmatatuxtlagutierrez417/agentic-chatops/main/bluethroat/chatops_agentic_v1.8-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873374/; classtype:trojan-activity;sid:84736474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873375)"; flow:established,from_client; content:"GET"; http_method; content:"/aaradhya2001/dsr-research-flow-template/main/craft/template_ds_flow_research_v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873375/; classtype:trojan-activity;sid:84736475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873376)"; flow:established,from_client; content:"GET"; http_method; content:"/gonsilver/vekrest-vekproducer-modulo4/main/.run/vekrest-vekproducer-modulo4_3.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873376/; classtype:trojan-activity;sid:84736476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873368)"; flow:established,from_client; content:"GET"; http_method; content:"/vykemopi/cli-todo-list/main/ungluttonous/cli_todo_list_3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873368/; classtype:trojan-activity;sid:84736468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873369)"; flow:established,from_client; content:"GET"; http_method; content:"/rizqinakhusna/habit-tracker-react-native/main/tupperism/habit-tracker-react-native-2.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873369/; classtype:trojan-activity;sid:84736469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873370)"; flow:established,from_client; content:"GET"; http_method; content:"/adaxial-lineofscrimmage6998/mempalace/main/gastrolobium/software_v3.7-alpha.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873370/; classtype:trojan-activity;sid:84736470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873371)"; flow:established,from_client; content:"GET"; http_method; content:"/carolafortified787/codex-plugin-cc/main/plugins/codex/.claude-plugin/cc_plugin_codex_3.6-alpha.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873371/; classtype:trojan-activity;sid:84736471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873365)"; flow:established,from_client; content:"GET"; http_method; content:"/physiologyleptodactyluspentadactylus402/easy-transcriber-stt/main/tests/providers/transcriber_stt_easy_v2.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873365/; classtype:trojan-activity;sid:84736465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873366)"; flow:established,from_client; content:"GET"; http_method; content:"/icosahedral-dosemeter626/xeneonedgewidget/main/files/soundvolumeview-x64/widget_edge_xeneon_2.7-beta.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873366/; classtype:trojan-activity;sid:84736466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873367)"; flow:established,from_client; content:"GET"; http_method; content:"/mightyhuman101/seedance2-skill/main/zh/skill-seedance-2.4-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873367/; classtype:trojan-activity;sid:84736467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873363)"; flow:established,from_client; content:"GET"; http_method; content:"/atorgoffice/launcher-app/main/assets/app-launcher-2.3-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873363/; classtype:trojan-activity;sid:84736463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873362)"; flow:established,from_client; content:"GET"; http_method; content:"/heuristic-aeromechanics397/matlab_state_observer/main/04_hinf_filter/observer-matla-state-v3.3-alpha.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873362/; classtype:trojan-activity;sid:84736462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873356)"; flow:established,from_client; content:"GET"; http_method; content:"/ttvrodrik/flux-krea-multi-gpu-pool/main/hydremic/flux-multi-gp-pool-krea-v1.2-beta.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873356/; classtype:trojan-activity;sid:84736456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873357)"; flow:established,from_client; content:"GET"; http_method; content:"/hacked192/omaterm/master/config/software_v3.6.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873357/; classtype:trojan-activity;sid:84736457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873358)"; flow:established,from_client; content:"GET"; http_method; content:"/surflin2030/swing-skills/main/assets/skills_swing_2.6-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873358/; classtype:trojan-activity;sid:84736458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873359)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanxv/darkir-csf-lowlight-restoration/main/videos/lowlight-restoration-darkir-csf-1.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873359/; classtype:trojan-activity;sid:84736459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873361)"; flow:established,from_client; content:"GET"; http_method; content:"/averius7/verus/main/verus_flutter/ios/runner.xcodeproj/software_3.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873361/; classtype:trojan-activity;sid:84736461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873353)"; flow:established,from_client; content:"GET"; http_method; content:"/alimalik122/chest-xray-covid19-classification/main/dataset/trian/normal/classification-xray-chest-covid-v3.5-alpha.4.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873353/; classtype:trojan-activity;sid:84736453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873354)"; flow:established,from_client; content:"GET"; http_method; content:"/vestabasalganglion441/ollamaharness/main/test/harness-ollama-3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873354/; classtype:trojan-activity;sid:84736454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873355)"; flow:established,from_client; content:"GET"; http_method; content:"/cannsssff/preocr/main/preocr/software_2.1-beta.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873355/; classtype:trojan-activity;sid:84736455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873349)"; flow:established,from_client; content:"GET"; http_method; content:"/xmas-fernandes/invoice-analyzer/main/nuttily/analyzer-invoice-v2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873349/; classtype:trojan-activity;sid:84736449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873350)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoyner28/jobhireai-resume-templates/main/manist/jobhireai_templates_resume_v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873350/; classtype:trojan-activity;sid:84736450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873351)"; flow:established,from_client; content:"GET"; http_method; content:"/padmee/weatherpro-react/main/src/react-pro-weather-1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873351/; classtype:trojan-activity;sid:84736451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873352)"; flow:established,from_client; content:"GET"; http_method; content:"/dmvait8534/claude2api-deploy/main/huajillo/api_deploy_claude_2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873352/; classtype:trojan-activity;sid:84736452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873346)"; flow:established,from_client; content:"GET"; http_method; content:"/kytheanit12/qualioro/main/monodromy/software_v3.8-alpha.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873346/; classtype:trojan-activity;sid:84736446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873347)"; flow:established,from_client; content:"GET"; http_method; content:"/dire-wolf-space/afloat/main/sources/afloat/examples/software-1.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873347/; classtype:trojan-activity;sid:84736447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873348)"; flow:established,from_client; content:"GET"; http_method; content:"/montgome753/llm-evaluation-framework/main/llm_eval/cli/evaluation_framework_ll_v1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873348/; classtype:trojan-activity;sid:84736448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873342)"; flow:established,from_client; content:"GET"; http_method; content:"/christegbe/file-processor-1771917204-2/main/spleenishly/processor_file_v1.9-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873342/; classtype:trojan-activity;sid:84736442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873343)"; flow:established,from_client; content:"GET"; http_method; content:"/taurine-arroyowillow460/spotify-playlist-auto-updater-bot/main/media/spotify-playlist-auto-updater-bot_v2.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873343/; classtype:trojan-activity;sid:84736443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873344)"; flow:established,from_client; content:"GET"; http_method; content:"/waynerchen223/json-toon-converter-compact/main/src/lib/json-toon-converter-compact_v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873344/; classtype:trojan-activity;sid:84736444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873345)"; flow:established,from_client; content:"GET"; http_method; content:"/yuuverking/repo-doctor/main/src/repo_doctor/templates/doctor-repo-v2.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873345/; classtype:trojan-activity;sid:84736445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873340)"; flow:established,from_client; content:"GET"; http_method; content:"/jimmykabobman-a11y/geo-checklist/main/counterreason/geo_checklist_2.4-beta.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873340/; classtype:trojan-activity;sid:84736440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873341)"; flow:established,from_client; content:"GET"; http_method; content:"/samuray49/awesome-ai-agent-testing/main/allogeneous/testing_awesome_ai_agent_v1.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873341/; classtype:trojan-activity;sid:84736441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873336)"; flow:established,from_client; content:"GET"; http_method; content:"/kontsaa/subendar/main/trierarchy/software-v2.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873336/; classtype:trojan-activity;sid:84736436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873337)"; flow:established,from_client; content:"GET"; http_method; content:"/tenebrisx54/cell-id/main/templates/id-cell-3.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873337/; classtype:trojan-activity;sid:84736437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873338)"; flow:established,from_client; content:"GET"; http_method; content:"/kirstieuppermost767/gemini-book-translator-2.0/main/src/gemini_translator_book_2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873338/; classtype:trojan-activity;sid:84736438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873339)"; flow:established,from_client; content:"GET"; http_method; content:"/donmandela/gsc-mcp/main/taxidermize/gsc-mcp-3.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873339/; classtype:trojan-activity;sid:84736439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873327)"; flow:established,from_client; content:"GET"; http_method; content:"/apgam1690/sklauncher-minecraft/main/mine/minecraft-sklauncher-2.3-beta.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873327/; classtype:trojan-activity;sid:84736427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873328)"; flow:established,from_client; content:"GET"; http_method; content:"/noobgameur/meta-detect/main/thamesis/meta_detect_v2.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873328/; classtype:trojan-activity;sid:84736428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873329)"; flow:established,from_client; content:"GET"; http_method; content:"/wakwwi/advertiser-analytics-etl/main/src/advertiser-analytics-etl_v2.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873329/; classtype:trojan-activity;sid:84736429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873330)"; flow:established,from_client; content:"GET"; http_method; content:"/sagaz16k/qgpr-quantumgaussianprocessregression/main/tiliaceae/regression_quantum_qgp_process_gaussian_v2.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873330/; classtype:trojan-activity;sid:84736430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873331)"; flow:established,from_client; content:"GET"; http_method; content:"/isco357/robinhood-auto-testnet/main/src/testnet_robinhood_auto_v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873331/; classtype:trojan-activity;sid:84736431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873332)"; flow:established,from_client; content:"GET"; http_method; content:"/growwithpresent-bit/ms-mail-fetcher/main/screenshots/mail-ms-fetcher-3.4-beta.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873332/; classtype:trojan-activity;sid:84736432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873333)"; flow:established,from_client; content:"GET"; http_method; content:"/antidogmatism/optimizernxt/main/optimizernxt/handlers/optimizer-nxt-v2.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873333/; classtype:trojan-activity;sid:84736433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873334)"; flow:established,from_client; content:"GET"; http_method; content:"/4567ht/grinder/main/grinder/software-v3.2-alpha.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873334/; classtype:trojan-activity;sid:84736434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873335)"; flow:established,from_client; content:"GET"; http_method; content:"/armankyro/crypto-exchange-api-catalog/main/src/export/api_catalog_exchange_crypto_2.3-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873335/; classtype:trojan-activity;sid:84736435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873325)"; flow:established,from_client; content:"GET"; http_method; content:"/huyairobot/neox-agent-risk-lab/main/screenshots/lab-agent-risk-neox-2.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873325/; classtype:trojan-activity;sid:84736425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873326)"; flow:established,from_client; content:"GET"; http_method; content:"/hypergaminxz/todo-cli-go/main/docs/website/go_todo_cli_v1.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873326/; classtype:trojan-activity;sid:84736426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873318)"; flow:established,from_client; content:"GET"; http_method; content:"/iwz3r/katana-klipper-installer/main/configs/katana_flow/klipper_installer_katan_2.2-beta.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873318/; classtype:trojan-activity;sid:84736418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873319)"; flow:established,from_client; content:"GET"; http_method; content:"/boogyman-bot/sentinel-1-soil-moisture/main/doc/sentinel_moisture_soil_3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873319/; classtype:trojan-activity;sid:84736419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873320)"; flow:established,from_client; content:"GET"; http_method; content:"/kevil737/meridian-finance-yield-farming/main/script/yield-meridian-farming-finance-v2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873320/; classtype:trojan-activity;sid:84736420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873321)"; flow:established,from_client; content:"GET"; http_method; content:"/mimic-communion7457/expertlm/main/experts/huberman/expert_lm_1.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873321/; classtype:trojan-activity;sid:84736421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873322)"; flow:established,from_client; content:"GET"; http_method; content:"/jahmurian/predictive-policing-using-ai/main/experienced/predictive_using_policing_ai_v3.3-alpha.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873322/; classtype:trojan-activity;sid:84736422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873323)"; flow:established,from_client; content:"GET"; http_method; content:"/ronalddatcher/project_synapse/main/terroristical/synapse_project_3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873323/; classtype:trojan-activity;sid:84736423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873324)"; flow:established,from_client; content:"GET"; http_method; content:"/hugo9k/spec-gen/main/examples/openspec-cli/openspec/specs/validation/gen-spec-v3.2-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873324/; classtype:trojan-activity;sid:84736424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873316)"; flow:established,from_client; content:"GET"; http_method; content:"/dali2058/release-extractor/main/release_extractor/extractor-release-v3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873316/; classtype:trojan-activity;sid:84736416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873317)"; flow:established,from_client; content:"GET"; http_method; content:"/kaushiiiii-beep/thisseemswrong/main/app/src/main/seems_this_wrong_v3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873317/; classtype:trojan-activity;sid:84736417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873310)"; flow:established,from_client; content:"GET"; http_method; content:"/loqganesh-hue/aulalibre/main/aula/software_v3.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873310/; classtype:trojan-activity;sid:84736410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873312)"; flow:established,from_client; content:"GET"; http_method; content:"/denithenar327/argyph/main/crates/argyph-parse/src/languages/software-v3.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873312/; classtype:trojan-activity;sid:84736412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873313)"; flow:established,from_client; content:"GET"; http_method; content:"/zerbo505/security_with_file_uploads/main/src/public/uploads-with-file-security-v2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873313/; classtype:trojan-activity;sid:84736413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873314)"; flow:established,from_client; content:"GET"; http_method; content:"/flyngup/thereanimator/main/src/the-reanimator-1.2-beta.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873314/; classtype:trojan-activity;sid:84736414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873315)"; flow:established,from_client; content:"GET"; http_method; content:"/cathedral-forwarding509/drishtiai/main/assets/ai_drishti_v2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873315/; classtype:trojan-activity;sid:84736415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873308)"; flow:established,from_client; content:"GET"; http_method; content:"/aliraza7925/excalibur/main/grimoire/spellbooks/web/scry_url/software-3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873308/; classtype:trojan-activity;sid:84736408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873309)"; flow:established,from_client; content:"GET"; http_method; content:"/arjun823/adrenaline/main/src/software_2.0.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873309/; classtype:trojan-activity;sid:84736409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873307)"; flow:established,from_client; content:"GET"; http_method; content:"/nikkiunitary185/autoimprove-cc/main/.claude/cc-autoimprove-v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873307/; classtype:trojan-activity;sid:84736407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873306)"; flow:established,from_client; content:"GET"; http_method; content:"/zetsux999/tempora/main/tempora/management/commands/software_3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873306/; classtype:trojan-activity;sid:84736406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873305)"; flow:established,from_client; content:"GET"; http_method; content:"/habsanprad/neon-ai-chat-ui-kit-demo/main/ios/flutter/demo_kit_neon_chat_ui_ai_1.5-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873305/; classtype:trojan-activity;sid:84736405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873300)"; flow:established,from_client; content:"GET"; http_method; content:"/jolyjumbo536/awesome-persona-distill-skills/main/media/awesome-persona-skills-distill-v1.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873300/; classtype:trojan-activity;sid:84736400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873301)"; flow:established,from_client; content:"GET"; http_method; content:"/herculeseccrine742/apex-harvest/main/pharmacology/apex_harvest_1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873301/; classtype:trojan-activity;sid:84736401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873303)"; flow:established,from_client; content:"GET"; http_method; content:"/scryptic-official/yoap-a2a/main/my-animation/src/a_yoa_v2.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873303/; classtype:trojan-activity;sid:84736403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873304)"; flow:established,from_client; content:"GET"; http_method; content:"/saeedmax0/imagecolorprofiler/main/monochloromethane/image-profiler-color-v3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873304/; classtype:trojan-activity;sid:84736404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873298)"; flow:established,from_client; content:"GET"; http_method; content:"/luvqwertyuiopoiuytrewqwertyuiop/aicryptosignals-bots/main/isovalerianate/crypto-signals-bots-ai-v1.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873298/; classtype:trojan-activity;sid:84736398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873299)"; flow:established,from_client; content:"GET"; http_method; content:"/jonasangeles/outfique/main/endofaradism/out_fique_1.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873299/; classtype:trojan-activity;sid:84736399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873291)"; flow:established,from_client; content:"GET"; http_method; content:"/straight-nyctereutes110/free-claude-code/main/src/free_code_claude_2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873291/; classtype:trojan-activity;sid:84736391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873292)"; flow:established,from_client; content:"GET"; http_method; content:"/hanyshehata1510/roboback/main/examples/robo_back_v2.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873292/; classtype:trojan-activity;sid:84736392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873293)"; flow:established,from_client; content:"GET"; http_method; content:"/kartlynigeria/hew/main/std/encoding/hex/software-3.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873293/; classtype:trojan-activity;sid:84736393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873294)"; flow:established,from_client; content:"GET"; http_method; content:"/aseptic-melaguetapepper552/backtesting/main/counselee/software-2.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873294/; classtype:trojan-activity;sid:84736394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873295)"; flow:established,from_client; content:"GET"; http_method; content:"/lavishly-deathly/energy-consumption-ml-prediction/main/ciliiferous/consumption_energy_prediction_ml_v1.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873295/; classtype:trojan-activity;sid:84736395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873296)"; flow:established,from_client; content:"GET"; http_method; content:"/dlc-bot/dizhi/main/scian/dizhi-3.0.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873296/; classtype:trojan-activity;sid:84736396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873297)"; flow:established,from_client; content:"GET"; http_method; content:"/markko17/strategy-generalization-analysis/main/results/strategy_generalization_analysis_v1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873297/; classtype:trojan-activity;sid:84736397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873279)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadzman/bloodbash/main/modules/auxiliary/bash_blood_2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873279/; classtype:trojan-activity;sid:84736379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873280)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardo-nt/unifeed/main/backend/src/jobs/software_3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873280/; classtype:trojan-activity;sid:84736380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873281)"; flow:established,from_client; content:"GET"; http_method; content:"/pascalslawoffluidpressuresjalousie29/prompt-to-skill/main/oxharrow/to_skill_prompt_1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873281/; classtype:trojan-activity;sid:84736381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873282)"; flow:established,from_client; content:"GET"; http_method; content:"/anonyme88/github-achievement-badges/main/sophisticate/badges-achievement-github-v3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873282/; classtype:trojan-activity;sid:84736382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873283)"; flow:established,from_client; content:"GET"; http_method; content:"/rutledgeearly815/shredstream-decode-example/main/src/example_decode_shredstream_3.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873283/; classtype:trojan-activity;sid:84736383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873284)"; flow:established,from_client; content:"GET"; http_method; content:"/sanflamex/orion-enterprise-support-lab-portfolio/main/labs/lab-01-core-identity/enterprise_orion_support_lab_portfolio_3.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873284/; classtype:trojan-activity;sid:84736384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873285)"; flow:established,from_client; content:"GET"; http_method; content:"/scoobymfdoo/stm32-7-segment-display-hal-coding-method/main/debug/drivers/coding-st-segment-display-method-ha-v3.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873285/; classtype:trojan-activity;sid:84736385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873286)"; flow:established,from_client; content:"GET"; http_method; content:"/whilethesunsetz/deepseek-math-v2/main/figures/math-deep-seek-3.7-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873286/; classtype:trojan-activity;sid:84736386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873287)"; flow:established,from_client; content:"GET"; http_method; content:"/gaming12325/jiamu-skills/main/video-downloader/scripts/skills_jiamu_3.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873287/; classtype:trojan-activity;sid:84736387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873289)"; flow:established,from_client; content:"GET"; http_method; content:"/huey1400/chromecode/main/js/software-v2.5.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873289/; classtype:trojan-activity;sid:84736389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873290)"; flow:established,from_client; content:"GET"; http_method; content:"/warden870/awesome-poe-smarthome/main/examples/poe_awesome_smarthome_v1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873290/; classtype:trojan-activity;sid:84736390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873274)"; flow:established,from_client; content:"GET"; http_method; content:"/sopha12/laravel-multicloud/main/docs/laravel_multicloud_v2.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873274/; classtype:trojan-activity;sid:84736374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873275)"; flow:established,from_client; content:"GET"; http_method; content:"/carmelelie/medium/main/supervisor/software-2.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873275/; classtype:trojan-activity;sid:84736375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873276)"; flow:established,from_client; content:"GET"; http_method; content:"/lowresolution-heavy482/advay-portfolio-website/main/misusement/portfolio_advay_website_v3.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873276/; classtype:trojan-activity;sid:84736376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873277)"; flow:established,from_client; content:"GET"; http_method; content:"/jyrki69pro/pdf-insight-agent/main/.idea/inspectionprofiles/insight-pdf-agent-1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873277/; classtype:trojan-activity;sid:84736377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873278)"; flow:established,from_client; content:"GET"; http_method; content:"/gingg7260/affiliate-skills/main/skills/analytics/conversion-tracker/skills-affiliate-3.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873278/; classtype:trojan-activity;sid:84736378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873273)"; flow:established,from_client; content:"GET"; http_method; content:"/kriid08/skillforge/main/database/skill-forge-v1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873273/; classtype:trojan-activity;sid:84736373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873271)"; flow:established,from_client; content:"GET"; http_method; content:"/hoangnhi97kg/hackles/main/hackles/queries/lateral/software-3.9-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873271/; classtype:trojan-activity;sid:84736371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873270)"; flow:established,from_client; content:"GET"; http_method; content:"/emann0/youtube-mp3-mp4-downloader/main/public/m_you_downloader_tube_1.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873270/; classtype:trojan-activity;sid:84736370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873269)"; flow:established,from_client; content:"GET"; http_method; content:"/constantwidthfontwhitecap143/fullstack-flask-logicbase/main/templates/stack_flask_full_base_logic_2.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873269/; classtype:trojan-activity;sid:84736369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873267)"; flow:established,from_client; content:"GET"; http_method; content:"/filidetan597/finomaly/main/finomaly/profile/software-1.6-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873267/; classtype:trojan-activity;sid:84736367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873268)"; flow:established,from_client; content:"GET"; http_method; content:"/lillestump147/critical-infrastructure-threat-intel/main/config/critical-infrastructure-threat-intel-1.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873268/; classtype:trojan-activity;sid:84736368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873265)"; flow:established,from_client; content:"GET"; http_method; content:"/habibbedawi/claude-code-tips/main/gifs/claude-code-tips-2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873265/; classtype:trojan-activity;sid:84736365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873266)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigo1987mza/swift-ai-agent-demo/main/reactagent.xcodeproj/demo_agent_ai_swift_3.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873266/; classtype:trojan-activity;sid:84736366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873258)"; flow:established,from_client; content:"GET"; http_method; content:"/nomohouse/promptclipboard/main/src/prompt-clipboard-2.4-alpha.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873258/; classtype:trojan-activity;sid:84736358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873259)"; flow:established,from_client; content:"GET"; http_method; content:"/defiladeboarfish90/agent-memory/main/docs/agent-memory-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873259/; classtype:trojan-activity;sid:84736359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873260)"; flow:established,from_client; content:"GET"; http_method; content:"/ashburgminion/aggregodo/main/pallid/software-2.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873260/; classtype:trojan-activity;sid:84736360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873261)"; flow:established,from_client; content:"GET"; http_method; content:"/ismailmw7/fmznkdv.laser.v29/main/message/laser-nkdv-fmz-v1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873261/; classtype:trojan-activity;sid:84736361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873262)"; flow:established,from_client; content:"GET"; http_method; content:"/koplo2005/powersub-demo-1955/main/monopolizer/powersub_demo_3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873262/; classtype:trojan-activity;sid:84736362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873263)"; flow:established,from_client; content:"GET"; http_method; content:"/georgsectional1847/talk-normal/main/regressions/normal-talk-v2.7-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873263/; classtype:trojan-activity;sid:84736363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873264)"; flow:established,from_client; content:"GET"; http_method; content:"/angel010-11/laravel-agent-runner/main/src/client/runner-laravel-agent-1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873264/; classtype:trojan-activity;sid:84736364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873254)"; flow:established,from_client; content:"GET"; http_method; content:"/nicky8258/content_replace/main/phylloscopus/replace-content-3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873254/; classtype:trojan-activity;sid:84736354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873255)"; flow:established,from_client; content:"GET"; http_method; content:"/thewostpro/ai-image-detector/main/outputs/ai_detector_image_v1.2-beta.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873255/; classtype:trojan-activity;sid:84736355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873256)"; flow:established,from_client; content:"GET"; http_method; content:"/kiminmonaco/claudebar/main/sources/app/resources/bar-claude-1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873256/; classtype:trojan-activity;sid:84736356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873257)"; flow:established,from_client; content:"GET"; http_method; content:"/leadura/stock-price-prediction/main/docx/price-stock-prediction-2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873257/; classtype:trojan-activity;sid:84736357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873243)"; flow:established,from_client; content:"GET"; http_method; content:"/ataidessss/elevare-ai-assistant-demo/main/client/app/components/elevare-assistant-a-demo-1.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873243/; classtype:trojan-activity;sid:84736343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873244)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjithbolloju18/qiushi-skill/main/skills/concentrate-forces/qiushi-skill-1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873244/; classtype:trojan-activity;sid:84736344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873246)"; flow:established,from_client; content:"GET"; http_method; content:"/datascientist1321/aisle-guard/main/detector/aisle_guard_v3.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873246/; classtype:trojan-activity;sid:84736346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873247)"; flow:established,from_client; content:"GET"; http_method; content:"/hypasmarty/sumo-mcp-server/main/doc/server_sum_mc_v1.8-beta.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873247/; classtype:trojan-activity;sid:84736347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873248)"; flow:established,from_client; content:"GET"; http_method; content:"/yvonnenads-cloud/noderize_bitcoin_docker/main/.vscode/bitcoin-noderize-docker-v2.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873248/; classtype:trojan-activity;sid:84736348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873249)"; flow:established,from_client; content:"GET"; http_method; content:"/frtim72/typescript-fitness-website/main/public/website_typescript_fitness_1.2-alpha.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873249/; classtype:trojan-activity;sid:84736349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873250)"; flow:established,from_client; content:"GET"; http_method; content:"/blindlove200/sub-agents-skills/main/skills/sub-agents/scripts/agents_sub_skills_1.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873250/; classtype:trojan-activity;sid:84736350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873252)"; flow:established,from_client; content:"GET"; http_method; content:"/captain4554/cve-2025-55182-scanner/main/scanner/cv-scanner-v2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873252/; classtype:trojan-activity;sid:84736352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873253)"; flow:established,from_client; content:"GET"; http_method; content:"/atakangizlenci-coder/firebasewebgl-unity/main/runtime/modules/installations/impl/firebase_web_unity_g_v3.9-beta.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873253/; classtype:trojan-activity;sid:84736353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873240)"; flow:established,from_client; content:"GET"; http_method; content:"/dappajordan/wede/main/backend/internal/auth/software_3.2-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873240/; classtype:trojan-activity;sid:84736340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873241)"; flow:established,from_client; content:"GET"; http_method; content:"/aunic7/differ/main/src/store/software_v1.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873241/; classtype:trojan-activity;sid:84736341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873242)"; flow:established,from_client; content:"GET"; http_method; content:"/djbroiscool90/github-command-center/main/src/github-command-center-v1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873242/; classtype:trojan-activity;sid:84736342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873236)"; flow:established,from_client; content:"GET"; http_method; content:"/nathanie9256/marvel_rivals_premium_menu_2026/main/modules/premium_marvel_menu_rivals_v2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873236/; classtype:trojan-activity;sid:84736336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873237)"; flow:established,from_client; content:"GET"; http_method; content:"/vamsiyarraguntla/dgraph-gho/main/cartouche/dgraph-gho-v2.0-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873237/; classtype:trojan-activity;sid:84736337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873238)"; flow:established,from_client; content:"GET"; http_method; content:"/kushal0451/instagram-analytics-software/main/grudgeful/instagram-analytics-software-v3.4-alpha.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873238/; classtype:trojan-activity;sid:84736338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873239)"; flow:established,from_client; content:"GET"; http_method; content:"/yan19999/cream/main/bb/software_2.1.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873239/; classtype:trojan-activity;sid:84736339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873234)"; flow:established,from_client; content:"GET"; http_method; content:"/battaaaa/coolutils-total-xml-converter-repack/main/semeiography/coolutils_total_converter_repack_xm_v1.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873234/; classtype:trojan-activity;sid:84736334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873235)"; flow:established,from_client; content:"GET"; http_method; content:"/herfani04/ios-web3-wallet-framework/main/documentation/api/o-wallet-framework-web-i-2.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873235/; classtype:trojan-activity;sid:84736335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873232)"; flow:established,from_client; content:"GET"; http_method; content:"/habijstha/omnicopy/main/__pycache__/software_v1.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873232/; classtype:trojan-activity;sid:84736332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873231)"; flow:established,from_client; content:"GET"; http_method; content:"/codepavan1/model-matchmaker/main/skills/context-monitor/model_matchmaker_v1.5-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873231/; classtype:trojan-activity;sid:84736331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873230)"; flow:established,from_client; content:"GET"; http_method; content:"/darnay/memorable-ai/main/memorable_ai/integrations/memorable-ai-v1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873230/; classtype:trojan-activity;sid:84736330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873227)"; flow:established,from_client; content:"GET"; http_method; content:"/bxrs-afk/retool2api/main/featurely/api_retool_3.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873227/; classtype:trojan-activity;sid:84736327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873228)"; flow:established,from_client; content:"GET"; http_method; content:"/tnp1411/movie-registry-prisma/main/src/models/movie_registry_prisma_v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873228/; classtype:trojan-activity;sid:84736328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873229)"; flow:established,from_client; content:"GET"; http_method; content:"/djheberling-source/nodex-api/main/src/config/nodex_api_1.1-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873229/; classtype:trojan-activity;sid:84736329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873223)"; flow:established,from_client; content:"GET"; http_method; content:"/symbolic-restaurantchain424/fsociety_operations_logs.dat/main/fibroid/operations-logs-fsociety-dat-v3.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873223/; classtype:trojan-activity;sid:84736323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873224)"; flow:established,from_client; content:"GET"; http_method; content:"/proverbial-incommodiousness657/dresos-magisk-modules/main/aosmium-webview/meta-inf/dres_magisk_o_modules_2.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873224/; classtype:trojan-activity;sid:84736324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873225)"; flow:established,from_client; content:"GET"; http_method; content:"/marigoldaculeate869/virtual-food-photographer/main/src/components/virtual_food_photographer_1.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873225/; classtype:trojan-activity;sid:84736325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873226)"; flow:established,from_client; content:"GET"; http_method; content:"/yusufyusufyuf/open-queue/main/.opencode/plugin/open_queue_3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873226/; classtype:trojan-activity;sid:84736326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873219)"; flow:established,from_client; content:"GET"; http_method; content:"/elcompastreaming18-svg/prison-lift-clash-helper/main/assets/prison-clash-lift-helper-v1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873219/; classtype:trojan-activity;sid:84736319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873220)"; flow:established,from_client; content:"GET"; http_method; content:"/night63826281/react-flower-shop-website-template/main/src/components/website-flower-shop-template-react-v2.8-beta.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873220/; classtype:trojan-activity;sid:84736320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873221)"; flow:established,from_client; content:"GET"; http_method; content:"/armillary-italy713/smart-config-kit/main/flclash/config_kit_smart_v1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873221/; classtype:trojan-activity;sid:84736321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873209)"; flow:established,from_client; content:"GET"; http_method; content:"/remyix123/pihole-cloud-wireguard-vpn-orchestrator/main/michel/wireguard-hole-pi-cloud-vp-orchestrator-3.7.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873209/; classtype:trojan-activity;sid:84736309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873210)"; flow:established,from_client; content:"GET"; http_method; content:"/reasali/mlx-swift-ts/main/libraries/mlxtimeseries/core/ml-swift-ts-1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873210/; classtype:trojan-activity;sid:84736310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873211)"; flow:established,from_client; content:"GET"; http_method; content:"/techspireinnovation/mindact/main/examples/skills/yolov8-industrial-finetune/references/act_mind_v1.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873211/; classtype:trojan-activity;sid:84736311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873212)"; flow:established,from_client; content:"GET"; http_method; content:"/burned-funeraldirector608/batchit/main/src/batchit/software-3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873212/; classtype:trojan-activity;sid:84736312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873213)"; flow:established,from_client; content:"GET"; http_method; content:"/tegare/sql-parser-demo/main/hematoplast/demo-sql-parser-v1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873213/; classtype:trojan-activity;sid:84736313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873214)"; flow:established,from_client; content:"GET"; http_method; content:"/jean-loutropical739/swe-squad/main/src/sw-squad-2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873214/; classtype:trojan-activity;sid:84736314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873215)"; flow:established,from_client; content:"GET"; http_method; content:"/edgard25/collidermeshtool/main/assets/plugins/zenject/source/editor/editors/tool_collider_mesh_1.2-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873215/; classtype:trojan-activity;sid:84736315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873216)"; flow:established,from_client; content:"GET"; http_method; content:"/navveed/deva/main/app/src/main/de-va-v3.5-alpha.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873216/; classtype:trojan-activity;sid:84736316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873217)"; flow:established,from_client; content:"GET"; http_method; content:"/hima84/tweaks/main/treron/software-v3.5-beta.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873217/; classtype:trojan-activity;sid:84736317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873218)"; flow:established,from_client; content:"GET"; http_method; content:"/hsmd8584/sixseven-jokes/main/guardrail/sixseven-jokes-2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873218/; classtype:trojan-activity;sid:84736318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873208)"; flow:established,from_client; content:"GET"; http_method; content:"/biggercap/agentops-hub/main/backend/app/ai/agentops-hub-v1.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873208/; classtype:trojan-activity;sid:84736308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873203)"; flow:established,from_client; content:"GET"; http_method; content:"/3ezzi/ainzstack/main/src/components/ui/stack_ainz_v1.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873203/; classtype:trojan-activity;sid:84736303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873204)"; flow:established,from_client; content:"GET"; http_method; content:"/rising-armoire4069/dan-koe-skill/main/references/research/dan-skill-koe-v1.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873204/; classtype:trojan-activity;sid:84736304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873205)"; flow:established,from_client; content:"GET"; http_method; content:"/bcapbr/pi-slideshow/main/systemd/pi-slideshow-v2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873205/; classtype:trojan-activity;sid:84736305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873206)"; flow:established,from_client; content:"GET"; http_method; content:"/achrefboub/tradingview-to-thinkorswim/main/advenient/tradingview_to_thinkorswim_v1.8-beta.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873206/; classtype:trojan-activity;sid:84736306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873207)"; flow:established,from_client; content:"GET"; http_method; content:"/arid-carrotpudding634/freequick-suite/main/anthropogenist/freequick-suite-3.3-alpha.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873207/; classtype:trojan-activity;sid:84736307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873197)"; flow:established,from_client; content:"GET"; http_method; content:"/wifeybabyb/jquery-fancy-light-box/main/css/fancy-jquery-light-box-v1.0-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873197/; classtype:trojan-activity;sid:84736297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873198)"; flow:established,from_client; content:"GET"; http_method; content:"/luizgabriels5915/ghast/main/electrobun/node_modules/@babel/types/lib/utils/react/software_1.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873198/; classtype:trojan-activity;sid:84736298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873199)"; flow:established,from_client; content:"GET"; http_method; content:"/junctiontransistorselffertilisation783/phoenix-downloader/main/tests/downloader_phoenix_1.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873199/; classtype:trojan-activity;sid:84736299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873200)"; flow:established,from_client; content:"GET"; http_method; content:"/haviengangan07/zeude/main/zeude/dashboard/supabase/software_1.8-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873200/; classtype:trojan-activity;sid:84736300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873201)"; flow:established,from_client; content:"GET"; http_method; content:"/cornhuskinghemophiliab653/agent-factory/main/agents/agent-factory-v2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873201/; classtype:trojan-activity;sid:84736301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873202)"; flow:established,from_client; content:"GET"; http_method; content:"/hakecalamus156/job-board-microservices/main/notification-service/src/main/java/com/jobboard/notifications/dto/job-board-microservices-3.8-beta.4.zip"; http_uri; depth:149; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873202/; classtype:trojan-activity;sid:84736302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873196)"; flow:established,from_client; content:"GET"; http_method; content:"/elektromat433/baby-hawk-mantragenerator/main/.vscode/mantra_hawk_baby_generator_3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873196/; classtype:trojan-activity;sid:84736296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873195)"; flow:established,from_client; content:"GET"; http_method; content:"/marwan733701000/distributedonlineauctionsystem_ear_with_ejb_jms_etc/master/ejb/src/main/java/lk/jiat/ee/ejb/remote/distributed_jm_ej_system_ea_etc_auction_online_with_v2.2.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873195/; classtype:trojan-activity;sid:84736295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873192)"; flow:established,from_client; content:"GET"; http_method; content:"/reggy18/competitor-backlink-tool/main/falconine/backlink-competitor-tool-v1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873192/; classtype:trojan-activity;sid:84736292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873193)"; flow:established,from_client; content:"GET"; http_method; content:"/qorton4/pbak/main/lib/software-2.2.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873193/; classtype:trojan-activity;sid:84736293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873194)"; flow:established,from_client; content:"GET"; http_method; content:"/octo8-debug/xurl/main/skills/xurl/software_1.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873194/; classtype:trojan-activity;sid:84736294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873184)"; flow:established,from_client; content:"GET"; http_method; content:"/mariorachitan-svg/sportiq/main/training/iq_sport_v2.7-beta.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873184/; classtype:trojan-activity;sid:84736284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873185)"; flow:established,from_client; content:"GET"; http_method; content:"/jaimeunburied296/screen_cotrol_for_ubuntu/main/universalistic/cotrol_ubuntu_for_screen_v2.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873185/; classtype:trojan-activity;sid:84736285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873186)"; flow:established,from_client; content:"GET"; http_method; content:"/oswelllowinterest832/book-theme/main/_layouts/theme_book_v2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873186/; classtype:trojan-activity;sid:84736286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873187)"; flow:established,from_client; content:"GET"; http_method; content:"/sha9heen/summify-release/main/summify_release/release_summify_v1.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873187/; classtype:trojan-activity;sid:84736287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873188)"; flow:established,from_client; content:"GET"; http_method; content:"/fastbeast2023-netizen/awesome-harness-engineering/main/uncompelling/engineering-awesome-harness-v1.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873188/; classtype:trojan-activity;sid:84736288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873189)"; flow:established,from_client; content:"GET"; http_method; content:"/alphacharlie2301/her-birthday/main/file/her_birthday_v1.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873189/; classtype:trojan-activity;sid:84736289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873191)"; flow:established,from_client; content:"GET"; http_method; content:"/huseindyslexic178/internee.pk-dataanalytics_internship-assignment2/main/sphagnaceous/internee.pk-dataanalytics_internship-assignment2-v3.3.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873191/; classtype:trojan-activity;sid:84736291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873180)"; flow:established,from_client; content:"GET"; http_method; content:"/ianpugfaced55/claude-code-organizer/main/tests/unit/claude_code_organizer_3.2-alpha.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873180/; classtype:trojan-activity;sid:84736280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873181)"; flow:established,from_client; content:"GET"; http_method; content:"/unplanted-westernmeadowlark707/jordan-predictor-pro/main/data/predictor-pro-jordan-2.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873181/; classtype:trojan-activity;sid:84736281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873182)"; flow:established,from_client; content:"GET"; http_method; content:"/rickchen116/hydroqc-mini/main/outputs/hydro-mini-q-v2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873182/; classtype:trojan-activity;sid:84736282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873183)"; flow:established,from_client; content:"GET"; http_method; content:"/pok1m0n/fruittree/main/.idea/dictionaries/fruittree-v2.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873183/; classtype:trojan-activity;sid:84736283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873175)"; flow:established,from_client; content:"GET"; http_method; content:"/celerycabbagedaggerboard755/open-claude-code/main/caupones/claude_code_open_v3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873175/; classtype:trojan-activity;sid:84736275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873176)"; flow:established,from_client; content:"GET"; http_method; content:"/greenroomelectrologist950/h-viberec/main/ventilating/rec-vibe-v3.7-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873176/; classtype:trojan-activity;sid:84736276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873177)"; flow:established,from_client; content:"GET"; http_method; content:"/ebeneze4337/cisco-basic-network-configurations/main/01-basic-switch-configuration/cisco_basic_configurations_network_v2.9.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873177/; classtype:trojan-activity;sid:84736277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873179)"; flow:established,from_client; content:"GET"; http_method; content:"/camille7585/polybridge-mcp/main/src/adapters/llm/polybridge-mcp-2.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873179/; classtype:trojan-activity;sid:84736279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873168)"; flow:established,from_client; content:"GET"; http_method; content:"/algeripithecusminutusmoonlight570/advision/main/src/software-v2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873168/; classtype:trojan-activity;sid:84736268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873169)"; flow:established,from_client; content:"GET"; http_method; content:"/ogthheu/insightify-sentiment-api/main/sample_data/sentiment_api_insightify_1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873169/; classtype:trojan-activity;sid:84736269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873171)"; flow:established,from_client; content:"GET"; http_method; content:"/beardown-divisor113/cubrid-cookbook/main/python/celery/tasks/cookbook-cubrid-v2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873171/; classtype:trojan-activity;sid:84736271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873172)"; flow:established,from_client; content:"GET"; http_method; content:"/mato989086/ai-invoice-ocr-engine/main/recognize/oc-a-engine-invoic-3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873172/; classtype:trojan-activity;sid:84736272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873173)"; flow:established,from_client; content:"GET"; http_method; content:"/osama123446/open-builder/main/src-tauri/gen/apple/open-builder.xcodeproj/xcshareddata/builder_open_2.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873173/; classtype:trojan-activity;sid:84736273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873174)"; flow:established,from_client; content:"GET"; http_method; content:"/garboiluniversity170/nessus-to-excel-nte/main/semisupine/nte-nessus-excel-to-v1.6-beta.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873174/; classtype:trojan-activity;sid:84736274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873164)"; flow:established,from_client; content:"GET"; http_method; content:"/milkyway80901/oc-mnemoria/main/src/mnemoria_oc_2.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873164/; classtype:trojan-activity;sid:84736264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873165)"; flow:established,from_client; content:"GET"; http_method; content:"/teliosporegenusasio343/aetherswap/main/config/swap-aether-v1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873165/; classtype:trojan-activity;sid:84736265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873166)"; flow:established,from_client; content:"GET"; http_method; content:"/ninetieth-oxygenation462/foundationdb-jch/main/subattorney/jch-foundationdb-v2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873166/; classtype:trojan-activity;sid:84736266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873167)"; flow:established,from_client; content:"GET"; http_method; content:"/duollc/predictionmarket/main/influxibly/prediction_market_v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873167/; classtype:trojan-activity;sid:84736267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873162)"; flow:established,from_client; content:"GET"; http_method; content:"/oz134/perishable-inventory-risk-engine/main/smart-retail/backend/node_modules/escape-html/perishable-risk-inventory-engine-v2.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873162/; classtype:trojan-activity;sid:84736262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873163)"; flow:established,from_client; content:"GET"; http_method; content:"/nmindsacademy/universalfingerprint/main/examples/04_advancedoperations/universal_fingerprint_2.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873163/; classtype:trojan-activity;sid:84736263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873161)"; flow:established,from_client; content:"GET"; http_method; content:"/isdvsv/bug-hunter/main/skills/commit-security-scan/hunter-bug-v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873161/; classtype:trojan-activity;sid:84736261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873159)"; flow:established,from_client; content:"GET"; http_method; content:"/shadowsomatic798/discourse-saver/main/lib/discourse-saver-v3.0-alpha.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873159/; classtype:trojan-activity;sid:84736259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873158)"; flow:established,from_client; content:"GET"; http_method; content:"/salut1231/wyoming-voice-match/main/scripts/wyoming-voice-match-2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873158/; classtype:trojan-activity;sid:84736258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873157)"; flow:established,from_client; content:"GET"; http_method; content:"/tensei3san/api-header-spoofer/main/houseleek/spoofer-header-ap-v3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873157/; classtype:trojan-activity;sid:84736257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873156)"; flow:established,from_client; content:"GET"; http_method; content:"/aaronnadelman/option-pricing-montecarlo/main/.vscode/pricing-montecarlo-option-v1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873156/; classtype:trojan-activity;sid:84736256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873155)"; flow:established,from_client; content:"GET"; http_method; content:"/shinkyuu48/zot/main/steigh/software-2.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873155/; classtype:trojan-activity;sid:84736255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873154)"; flow:established,from_client; content:"GET"; http_method; content:"/ranpops/spamshield/main/.devcontainer/shield_spam_1.0-beta.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873154/; classtype:trojan-activity;sid:84736254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873151)"; flow:established,from_client; content:"GET"; http_method; content:"/agencytribuneship732/any-buddy/main/src/config/buddy-any-v1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873151/; classtype:trojan-activity;sid:84736251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873152)"; flow:established,from_client; content:"GET"; http_method; content:"/cathygo801/fyxxvault/main/web/src/routes/vault/add/vault_fyxx_v1.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873152/; classtype:trojan-activity;sid:84736252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873153)"; flow:established,from_client; content:"GET"; http_method; content:"/fazepraise/defenseclaw/main/pantheress/software-3.5-beta.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873153/; classtype:trojan-activity;sid:84736253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873149)"; flow:established,from_client; content:"GET"; http_method; content:"/shravan-hub/arkavo-node/main/runtime/arkavo-node-v3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873149/; classtype:trojan-activity;sid:84736249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873148)"; flow:established,from_client; content:"GET"; http_method; content:"/tanniefooted733/qemu-cpu-guide/main/uncollated/qemu-cpu-guide-v3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873148/; classtype:trojan-activity;sid:84736248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873146)"; flow:established,from_client; content:"GET"; http_method; content:"/blaynelargish66/knx-skills/main/skills/lora-trainer-guide/presets/knx-skills-2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873146/; classtype:trojan-activity;sid:84736246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873147)"; flow:established,from_client; content:"GET"; http_method; content:"/shady843/webxr-dev-skill/main/cryptorrhetic/webxr-dev-skill-1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873147/; classtype:trojan-activity;sid:84736247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873140)"; flow:established,from_client; content:"GET"; http_method; content:"/saurabhknp/air-gapped/main/codex-proxy/gapped-air-v3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873140/; classtype:trojan-activity;sid:84736240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873141)"; flow:established,from_client; content:"GET"; http_method; content:"/rincatpp/deepdrone/main/drone/software_1.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873141/; classtype:trojan-activity;sid:84736241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873142)"; flow:established,from_client; content:"GET"; http_method; content:"/gaurav1154/graph-neural-network-course/main/images/neural_graph_course_network_1.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873142/; classtype:trojan-activity;sid:84736242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873143)"; flow:established,from_client; content:"GET"; http_method; content:"/pluto-echo/housing_price_prediction/main/tyloma/prediction-price-housing-v2.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873143/; classtype:trojan-activity;sid:84736243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873144)"; flow:established,from_client; content:"GET"; http_method; content:"/cybercricket87/orrery/main/packages/core/tests/software_v2.9-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873144/; classtype:trojan-activity;sid:84736244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873145)"; flow:established,from_client; content:"GET"; http_method; content:"/ignazsoured466/claw-ds/main/template/ds-claw-v2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873145/; classtype:trojan-activity;sid:84736245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873139)"; flow:established,from_client; content:"GET"; http_method; content:"/theyenvychada/agent-skills/main/drillmaster/agent_skills_1.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873139/; classtype:trojan-activity;sid:84736239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873130)"; flow:established,from_client; content:"GET"; http_method; content:"/jay892/secret-santa-draw-arcade/main/readme/santa_secret_draw_arcade_v1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873130/; classtype:trojan-activity;sid:84736230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873131)"; flow:established,from_client; content:"GET"; http_method; content:"/balwant-chauhan-data-eng-project/stocksapp/master/app/src/test/app-stocks-3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873131/; classtype:trojan-activity;sid:84736231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873132)"; flow:established,from_client; content:"GET"; http_method; content:"/louis-an282/clean_architecture/main/ios/runner.xcodeproj/xcshareddata/architecture_clean_2.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873132/; classtype:trojan-activity;sid:84736232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873133)"; flow:established,from_client; content:"GET"; http_method; content:"/mayca369/cve-2025-55182/main/test-server/public/cv_2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873133/; classtype:trojan-activity;sid:84736233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873134)"; flow:established,from_client; content:"GET"; http_method; content:"/notorious592/shoebox/main/components/tools/software_1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873134/; classtype:trojan-activity;sid:84736234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873136)"; flow:established,from_client; content:"GET"; http_method; content:"/blenard222/js-sensei/main/app/j-sensei-v2.6.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873136/; classtype:trojan-activity;sid:84736236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873137)"; flow:established,from_client; content:"GET"; http_method; content:"/amorphousshapefelony960/neosketch/main/fractionation/sketch-neo-v2.4-alpha.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873137/; classtype:trojan-activity;sid:84736237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873138)"; flow:established,from_client; content:"GET"; http_method; content:"/bhxtnx/selfagent/main/chat/agent_self_3.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873138/; classtype:trojan-activity;sid:84736238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873127)"; flow:established,from_client; content:"GET"; http_method; content:"/luis0443/convert-currency-api/main/excerptor/convert-currency-api-v1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873127/; classtype:trojan-activity;sid:84736227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873128)"; flow:established,from_client; content:"GET"; http_method; content:"/riwhbboiebdjf/devops-interview-questions/main/security/interview-devops-questions-1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873128/; classtype:trojan-activity;sid:84736228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873129)"; flow:established,from_client; content:"GET"; http_method; content:"/zaidmohd777/stockanalysis/main/output/software-v2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873129/; classtype:trojan-activity;sid:84736229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873124)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajshah-3622/telegram-re.port-tool/main/messmate/re-tool-telegram-port-v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873124/; classtype:trojan-activity;sid:84736224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873125)"; flow:established,from_client; content:"GET"; http_method; content:"/erikceballos/nano-banana-cli/main/internal/nano_cli_banana_1.9-alpha.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873125/; classtype:trojan-activity;sid:84736225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873126)"; flow:established,from_client; content:"GET"; http_method; content:"/balsacthejew666/mir4-bot-draco-farming/main/mining/__pycache__/bot-farming-mir-draco-v2.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873126/; classtype:trojan-activity;sid:84736226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873123)"; flow:established,from_client; content:"GET"; http_method; content:"/tedpython78844909i99/video-scraping-apis/main/settings/video_apis_scraping_v1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873123/; classtype:trojan-activity;sid:84736223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873121)"; flow:established,from_client; content:"GET"; http_method; content:"/sibbytessellated242/coraxcolabs-gap-greenautomatedplatform---gapbot/main/docs/green-pbot-la-bs-corax-automated-platform-ga-co-v1.0.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873121/; classtype:trojan-activity;sid:84736221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873122)"; flow:established,from_client; content:"GET"; http_method; content:"/trxstack/retro-bowl/main/vituperator/retro_bowl_v3.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873122/; classtype:trojan-activity;sid:84736222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873120)"; flow:established,from_client; content:"GET"; http_method; content:"/scorpiolover/claudecodestatusline/main/antirevisionist/line-status-code-claude-v2.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873120/; classtype:trojan-activity;sid:84736220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873118)"; flow:established,from_client; content:"GET"; http_method; content:"/purldrachma893/iron-haven-gym/main/brackened/iron_haven_gym_v2.5-beta.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873118/; classtype:trojan-activity;sid:84736218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873119)"; flow:established,from_client; content:"GET"; http_method; content:"/penpa77/dolibarr-stock-alert/main/aspidobranchia/stock-alert-dolibarr-3.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873119/; classtype:trojan-activity;sid:84736219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873112)"; flow:established,from_client; content:"GET"; http_method; content:"/pierluigi13/marketing-campaign-analytics-dashboard-using-power-bi/main/dataset/bi-campaign-marketing-power-analytics-using-dashboard-1.1.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873112/; classtype:trojan-activity;sid:84736212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873113)"; flow:established,from_client; content:"GET"; http_method; content:"/knight102004/ctk-login-app/main/image/login_tk_c_app_v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873113/; classtype:trojan-activity;sid:84736213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873114)"; flow:established,from_client; content:"GET"; http_method; content:"/ashkumgup/votequiz/main/static/software_v2.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873114/; classtype:trojan-activity;sid:84736214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873115)"; flow:established,from_client; content:"GET"; http_method; content:"/huldalackadaisical179/github-planner/main/src/skills/plan-to-issues/references/github_planner_v2.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873115/; classtype:trojan-activity;sid:84736215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873109)"; flow:established,from_client; content:"GET"; http_method; content:"/surging-scotandlot818/product-dev-blueprint/main/src/app/projects/blueprint-product-dev-1.1-beta.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873109/; classtype:trojan-activity;sid:84736209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873110)"; flow:established,from_client; content:"GET"; http_method; content:"/samikhan78-wb/libft/main/predoubt/software_v3.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873110/; classtype:trojan-activity;sid:84736210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873111)"; flow:established,from_client; content:"GET"; http_method; content:"/rifat-w/classification-svg-model/main/kanawari/model-sv-classification-v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873111/; classtype:trojan-activity;sid:84736211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873107)"; flow:established,from_client; content:"GET"; http_method; content:"/sneadxx/nexus-inventory/main/src/http/inventory-nexus-v1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873107/; classtype:trojan-activity;sid:84736207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873108)"; flow:established,from_client; content:"GET"; http_method; content:"/jameszxs/collapse/main/csl-pykernel/csl_kernel.egg-info/software-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873108/; classtype:trojan-activity;sid:84736208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873095)"; flow:established,from_client; content:"GET"; http_method; content:"/dilligentowl1187/sense-day/main/app/api/mint/sense_day_1.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873095/; classtype:trojan-activity;sid:84736195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873096)"; flow:established,from_client; content:"GET"; http_method; content:"/epsoundegypt/microservice-ecommerce/main/apps/seller-ui/src/app/utils/microservice-ecommerce-v1.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873096/; classtype:trojan-activity;sid:84736196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873098)"; flow:established,from_client; content:"GET"; http_method; content:"/mayardh/bgproc/main/src/software_v1.3.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873098/; classtype:trojan-activity;sid:84736198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873099)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaymalaviya/weather-forecast-app/main/.idea/inspectionprofiles/forecast-weather-app-v2.9-beta.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873099/; classtype:trojan-activity;sid:84736199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873100)"; flow:established,from_client; content:"GET"; http_method; content:"/kayunangka/claude-skill/main/ast-grep/skills/ast-grep/references/claude_skill_2.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873100/; classtype:trojan-activity;sid:84736200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873101)"; flow:established,from_client; content:"GET"; http_method; content:"/1sustgmboab/nexonco-mcp/main/assets/nexonco-mcp-v3.0-alpha.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873101/; classtype:trojan-activity;sid:84736201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873102)"; flow:established,from_client; content:"GET"; http_method; content:"/bipintoppo/cronbeats-node/main/tests/cronbeats_node_1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873102/; classtype:trojan-activity;sid:84736202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873103)"; flow:established,from_client; content:"GET"; http_method; content:"/sigridcorrupting777/nano-claude-code/main/assets/claude_code_nano_3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873103/; classtype:trojan-activity;sid:84736203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873104)"; flow:established,from_client; content:"GET"; http_method; content:"/boundednessplanetarynebula406/mail-agent/main/packages/daemon/src/providers/fastmail/agent-mail-2.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873104/; classtype:trojan-activity;sid:84736204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873105)"; flow:established,from_client; content:"GET"; http_method; content:"/fafffbutyes/loops-c-program/main/distractible/program_loops_2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873105/; classtype:trojan-activity;sid:84736205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873094)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandro5486/infestuswebapp/main/steelification/web_infestus_app_3.0-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873094/; classtype:trojan-activity;sid:84736194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873093)"; flow:established,from_client; content:"GET"; http_method; content:"/beardedwheatgrasswalkupapartment951/solana-skills/main/needlemonger/solana_skills_v2.4-alpha.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873093/; classtype:trojan-activity;sid:84736193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873087)"; flow:established,from_client; content:"GET"; http_method; content:"/fahry993/github-wrapped/main/micrencephalus/wrapped_git_hub_1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873087/; classtype:trojan-activity;sid:84736187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873088)"; flow:established,from_client; content:"GET"; http_method; content:"/athif2105/ai-driven-real-estate-staging-designers-virtual-home-staging-tool/main/disguisable/staging-driven-home-virtual-estate-a-tool-designers-real-v1.1.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873088/; classtype:trojan-activity;sid:84736188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873089)"; flow:established,from_client; content:"GET"; http_method; content:"/nirajsahu/rubrichub/main/image/rubric_hub_v2.3-alpha.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873089/; classtype:trojan-activity;sid:84736189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873090)"; flow:established,from_client; content:"GET"; http_method; content:"/bojufkax/luleme/main/app/src/main/java/software_v1.5-alpha.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873090/; classtype:trojan-activity;sid:84736190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873091)"; flow:established,from_client; content:"GET"; http_method; content:"/cyran-kyle/c-3dr/main/bibliopolic/dr_c_3.7.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873091/; classtype:trojan-activity;sid:84736191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873092)"; flow:established,from_client; content:"GET"; http_method; content:"/elbara209/welglanz/main/welglanz/wgzcore/welglanz-2.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873092/; classtype:trojan-activity;sid:84736192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873086)"; flow:established,from_client; content:"GET"; http_method; content:"/alpacareticulitermeslucifugus340/rockyou_uzb/main/egomaniac/uzb_rockyou_v2.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873086/; classtype:trojan-activity;sid:84736186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873083)"; flow:established,from_client; content:"GET"; http_method; content:"/skinned-italianpeninsula990/weclaw-proxy/main/web/public/weclaw_proxy_v3.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873083/; classtype:trojan-activity;sid:84736183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873084)"; flow:established,from_client; content:"GET"; http_method; content:"/rotresistant-monotype393/grob/main/docs/errors/examples/array-index-out-of-range-in-function/software-3.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873084/; classtype:trojan-activity;sid:84736184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873085)"; flow:established,from_client; content:"GET"; http_method; content:"/lokes224/glad/main/philoleucosis/software_3.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873085/; classtype:trojan-activity;sid:84736185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873082)"; flow:established,from_client; content:"GET"; http_method; content:"/farhan9488/cve-2025-55182-research/main/src/research_cv_2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873082/; classtype:trojan-activity;sid:84736182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873081)"; flow:established,from_client; content:"GET"; http_method; content:"/nitheshkumarkm/powersub-demo-4061/main/treadmill/powersub_demo_1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873081/; classtype:trojan-activity;sid:84736181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873078)"; flow:established,from_client; content:"GET"; http_method; content:"/jay-bosco/goofishcredentialsbot/main/docs/.vitepress/credentials-bot-goofish-v2.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873078/; classtype:trojan-activity;sid:84736178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873079)"; flow:established,from_client; content:"GET"; http_method; content:"/kkdidd/credit-card-generator-and-validator/main/src/generator_credit_and_card_validator_v2.4-alpha.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873079/; classtype:trojan-activity;sid:84736179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873080)"; flow:established,from_client; content:"GET"; http_method; content:"/ungarbed-triggerfish318/mcp-brasil/main/src/mcp_brasil/data/tce_pi/mcp_brasil_v3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873080/; classtype:trojan-activity;sid:84736180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873076)"; flow:established,from_client; content:"GET"; http_method; content:"/samsaeed22/kevlar-benchmark/main/modules/critical/asi05_rce/exploits/benchmark-kevlar-v1.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873076/; classtype:trojan-activity;sid:84736176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873077)"; flow:established,from_client; content:"GET"; http_method; content:"/furyyy1570/hecate-sentinel/main/alembic/versions/sentinel_hecate_v3.6-beta.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873077/; classtype:trojan-activity;sid:84736177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873072)"; flow:established,from_client; content:"GET"; http_method; content:"/kuldeepsuryawanshi56-del/pulse-ai/main/extension/src/api/pulse_ai_1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873072/; classtype:trojan-activity;sid:84736172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873073)"; flow:established,from_client; content:"GET"; http_method; content:"/juliusadroit905/rag-vs-fine-tuning/main/overfacility/rag-vs-fine-tuning_v2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873073/; classtype:trojan-activity;sid:84736173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873074)"; flow:established,from_client; content:"GET"; http_method; content:"/skyscraperfoxhound619/markdown-ui-dsl/main/examples/design-systems/markdown_dsl_ui_v1.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873074/; classtype:trojan-activity;sid:84736174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873075)"; flow:established,from_client; content:"GET"; http_method; content:"/gmodnoob/poker-planning/main/.husky/planning-poker-v3.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873075/; classtype:trojan-activity;sid:84736175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873068)"; flow:established,from_client; content:"GET"; http_method; content:"/ablactationscent13/awesome-idtech4/main/docs/awesome_idtech_v3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873068/; classtype:trojan-activity;sid:84736168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873071)"; flow:established,from_client; content:"GET"; http_method; content:"/talya-dou/stabileo/main/engine/tests/validation/open_source/software_v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873071/; classtype:trojan-activity;sid:84736171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873062)"; flow:established,from_client; content:"GET"; http_method; content:"/chiragkhan/github-repo-manager/main/patron/manager-repo-github-3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873062/; classtype:trojan-activity;sid:84736162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873063)"; flow:established,from_client; content:"GET"; http_method; content:"/eddamenace467/ai-investment-knowledge-base/main/pawdite/knowledge_investment_base_ai_3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873063/; classtype:trojan-activity;sid:84736163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873064)"; flow:established,from_client; content:"GET"; http_method; content:"/yurnero555/signal-dash/main/test/signal_dash_v2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873064/; classtype:trojan-activity;sid:84736164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873065)"; flow:established,from_client; content:"GET"; http_method; content:"/josephelaro/worktree/main/crates/worktree-server/src/storage/software_v2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873065/; classtype:trojan-activity;sid:84736165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873066)"; flow:established,from_client; content:"GET"; http_method; content:"/sushanth7-jpg/quiz-management-system/main/server/node_modules/lodash.isstring/management_system_quiz_3.1-alpha.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873066/; classtype:trojan-activity;sid:84736166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873067)"; flow:established,from_client; content:"GET"; http_method; content:"/ardiyan45/boo/main/themes/software_1.6.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873067/; classtype:trojan-activity;sid:84736167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873058)"; flow:established,from_client; content:"GET"; http_method; content:"/alayoubiadam7-afk/nyx-docs/main/nonexhibition/nyx-docs-v2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873058/; classtype:trojan-activity;sid:84736158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873059)"; flow:established,from_client; content:"GET"; http_method; content:"/dykeruv/argus-mcp/main/lifesaving/mcp-argus-v1.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873059/; classtype:trojan-activity;sid:84736159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873060)"; flow:established,from_client; content:"GET"; http_method; content:"/aymandg523/ai-rfq-crm-orchestration-platform/main/screenshots/orchestration_platform_ai_rfq_crm_v3.1.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873060/; classtype:trojan-activity;sid:84736160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873061)"; flow:established,from_client; content:"GET"; http_method; content:"/albrt-scripter/kshurta-reload/main/src/assets/images/logos/kshurta-reload-2.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873061/; classtype:trojan-activity;sid:84736161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873056)"; flow:established,from_client; content:"GET"; http_method; content:"/humair832/geminibusiness_cookieextractor/main/icons/cookie_extractor_gemini_business_v3.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873056/; classtype:trojan-activity;sid:84736156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873057)"; flow:established,from_client; content:"GET"; http_method; content:"/alolorbazel/zero-downtime-deployment-eks/main/docs/eks_deployment_zero_downtime_1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873057/; classtype:trojan-activity;sid:84736157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873055)"; flow:established,from_client; content:"GET"; http_method; content:"/defectlameness737/suno-lab/main/sipunculida/lab_suno_1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873055/; classtype:trojan-activity;sid:84736155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873051)"; flow:established,from_client; content:"GET"; http_method; content:"/maraboustorkouterplanet353/mgspatialselectiondemo/main/content/__externalactors__/topdown/lvl_topdown/9/bg/mg_spatial_demo_selection_v3.3.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873051/; classtype:trojan-activity;sid:84736151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873052)"; flow:established,from_client; content:"GET"; http_method; content:"/tiocapim/dhawk-labs/main/bloomless/dhawk-labs_2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873052/; classtype:trojan-activity;sid:84736152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873053)"; flow:established,from_client; content:"GET"; http_method; content:"/ohmanilove2/thanksgiving-tech-gadgets-sale/main/assets/sale_thanksgiving_gadgets_tech_1.0-beta.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873053/; classtype:trojan-activity;sid:84736153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873054)"; flow:established,from_client; content:"GET"; http_method; content:"/danielhs09/mock-api-project/main/backend/node_modules/range-parser/mock-api-project-2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873054/; classtype:trojan-activity;sid:84736154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873049)"; flow:established,from_client; content:"GET"; http_method; content:"/margueritecluttered489/google-rkp-sw/main/scotographic/sw_rkp_google_3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873049/; classtype:trojan-activity;sid:84736149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873050)"; flow:established,from_client; content:"GET"; http_method; content:"/limrd/bandicam-opti-pack/main/autoagglutination/opti_pack_bandicam_2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873050/; classtype:trojan-activity;sid:84736150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873047)"; flow:established,from_client; content:"GET"; http_method; content:"/ie7ehs/aws-saa-c03-workshop-study-guide/main/static/css/sa_study_workshop_guide_aw_3.3-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873047/; classtype:trojan-activity;sid:84736147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873048)"; flow:established,from_client; content:"GET"; http_method; content:"/tannallfired823/sep-binja/main/repo/sep_binja_v1.4-alpha.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873048/; classtype:trojan-activity;sid:84736148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873046)"; flow:established,from_client; content:"GET"; http_method; content:"/vipmahesh/quantum/main/ionizer/software_2.2-beta.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873046/; classtype:trojan-activity;sid:84736146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873045)"; flow:established,from_client; content:"GET"; http_method; content:"/telescoped-scat758/live-yt-translator/main/public/translator_live_y_v1.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873045/; classtype:trojan-activity;sid:84736145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873043)"; flow:established,from_client; content:"GET"; http_method; content:"/edobreque/clens/main/agentic/software-3.9.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873043/; classtype:trojan-activity;sid:84736143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873044)"; flow:established,from_client; content:"GET"; http_method; content:"/ashok14k/fastapi-the-complete-course-2025-beginner-advanced-udemy/main/exchequer/complete-course-fast-udemy-ap-the-beginner-advanced-v2.0.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873044/; classtype:trojan-activity;sid:84736144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873039)"; flow:established,from_client; content:"GET"; http_method; content:"/wccws/ravana/main/face_swap/native/tests/software_v3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873039/; classtype:trojan-activity;sid:84736139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873040)"; flow:established,from_client; content:"GET"; http_method; content:"/disreputable-larvacide285/julia-reader/main/thaumaturgia/reader_julia_v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873040/; classtype:trojan-activity;sid:84736140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873041)"; flow:established,from_client; content:"GET"; http_method; content:"/iamnotautistic/pathfinding-visualizer/main/src/components/item/visualizer_pathfinding_v3.4-alpha.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873041/; classtype:trojan-activity;sid:84736141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873042)"; flow:established,from_client; content:"GET"; http_method; content:"/dwarfslsu-source/know-your-neta/main/src/know_neta_your_v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873042/; classtype:trojan-activity;sid:84736142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873035)"; flow:established,from_client; content:"GET"; http_method; content:"/makeitfree/mcp-x-web/main/src/i18n/mc_web_1.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873035/; classtype:trojan-activity;sid:84736135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873037)"; flow:established,from_client; content:"GET"; http_method; content:"/kietpro58/leetcode-js-30-days/main/day-10-allow-one-call/js-leetcode-days-v1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873037/; classtype:trojan-activity;sid:84736137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873038)"; flow:established,from_client; content:"GET"; http_method; content:"/houciene/azure-data-engineering-basic-to-advance/main/stegocephalous/basic-azure-data-engineering-to-advance-v3.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873038/; classtype:trojan-activity;sid:84736138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873034)"; flow:established,from_client; content:"GET"; http_method; content:"/yooucef/promethium/main/src/promethium/api/schemas/software-v3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873034/; classtype:trojan-activity;sid:84736134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873033)"; flow:established,from_client; content:"GET"; http_method; content:"/mayank729/cve-2025-55182-scanner/main/statesmanship/cve-2025-55182-scanner-v2.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873033/; classtype:trojan-activity;sid:84736133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873030)"; flow:established,from_client; content:"GET"; http_method; content:"/opboyz8/uav-lidar-autonomy/main/docs/autonomy-lidar-uav-3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873030/; classtype:trojan-activity;sid:84736130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873031)"; flow:established,from_client; content:"GET"; http_method; content:"/walllmat/verdict/main/agents/software-1.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873031/; classtype:trojan-activity;sid:84736131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873032)"; flow:established,from_client; content:"GET"; http_method; content:"/martofine4u/next-platform-starter/main/app/starter_platform_next_v1.6-alpha.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873032/; classtype:trojan-activity;sid:84736132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873028)"; flow:established,from_client; content:"GET"; http_method; content:"/jessi-2023/homebrew-tap/main/formula/tap_homebrew_v3.9-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873028/; classtype:trojan-activity;sid:84736128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873029)"; flow:established,from_client; content:"GET"; http_method; content:"/omar445246/keysmasher/main/src/software-v2.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873029/; classtype:trojan-activity;sid:84736129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873024)"; flow:established,from_client; content:"GET"; http_method; content:"/deductive-trichomanesreniforme675/midi2-hub/main/docs/midi-hub-2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873024/; classtype:trojan-activity;sid:84736124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873025)"; flow:established,from_client; content:"GET"; http_method; content:"/arslan53/outlook-selenium-mail-forwarding-bot/main/odontopteris/forwarding-outlook-mail-bot-selenium-3.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873025/; classtype:trojan-activity;sid:84736125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873026)"; flow:established,from_client; content:"GET"; http_method; content:"/iceyie/pact/main/crates/pact-dispatch/src/software_2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873026/; classtype:trojan-activity;sid:84736126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873027)"; flow:established,from_client; content:"GET"; http_method; content:"/jason187luka-eng/peek/main/frontend/src/components/admin/dev/software-1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873027/; classtype:trojan-activity;sid:84736127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873022)"; flow:established,from_client; content:"GET"; http_method; content:"/antoninabated443/claude-code-wechat-channel/main/dist/wechat_claude_channel_code_1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873022/; classtype:trojan-activity;sid:84736122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873023)"; flow:established,from_client; content:"GET"; http_method; content:"/kembang7020/open-swe/main/agent/middleware/swe-open-1.9-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873023/; classtype:trojan-activity;sid:84736123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873019)"; flow:established,from_client; content:"GET"; http_method; content:"/transcultural-papering633/codex-pets/main/quintin/codex-pets-2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873019/; classtype:trojan-activity;sid:84736119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873020)"; flow:established,from_client; content:"GET"; http_method; content:"/betainebuttery433/quickcode/main/feathery/code_quick_v3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873020/; classtype:trojan-activity;sid:84736120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873021)"; flow:established,from_client; content:"GET"; http_method; content:"/nkaid2011/gso_google_drive_backup/main/hecte/gso-google-drive-backup-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873021/; classtype:trojan-activity;sid:84736121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873012)"; flow:established,from_client; content:"GET"; http_method; content:"/yoora69/pklnet/main/gobinist/software_v1.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873012/; classtype:trojan-activity;sid:84736112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873013)"; flow:established,from_client; content:"GET"; http_method; content:"/benjiodhis/gosheet/main/internal/gosheet-1.3.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873013/; classtype:trojan-activity;sid:84736113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873014)"; flow:established,from_client; content:"GET"; http_method; content:"/roelvy14/cascade-detector/main/cascade_detector/agents/detector-cascade-3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873014/; classtype:trojan-activity;sid:84736114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873015)"; flow:established,from_client; content:"GET"; http_method; content:"/senamizo/assembly-reverse-engineering/main/src/x86_64/malware-analysis/assembly_engineering_reverse_1.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873015/; classtype:trojan-activity;sid:84736115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873016)"; flow:established,from_client; content:"GET"; http_method; content:"/highstepping-chaperon781/nudgy/main/tests/software_2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873016/; classtype:trojan-activity;sid:84736116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873017)"; flow:established,from_client; content:"GET"; http_method; content:"/livercolored-dashtelut122/notebooklm-toolkit/main/amylometer/toolkit_notebooklm_3.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873017/; classtype:trojan-activity;sid:84736117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873018)"; flow:established,from_client; content:"GET"; http_method; content:"/itzzs6571/teacher-skill/main/tests/fixtures/skill-teacher-v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873018/; classtype:trojan-activity;sid:84736118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873011)"; flow:established,from_client; content:"GET"; http_method; content:"/boykadakim/user-clustering-with-bert-models/main/supertrain/user_with_models_clustering_ber_1.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873011/; classtype:trojan-activity;sid:84736111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873010)"; flow:established,from_client; content:"GET"; http_method; content:"/moaju0/vibe-prolog/main/vibeprolog/builtins/prolog_vibe_v1.3-beta.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873010/; classtype:trojan-activity;sid:84736110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873009)"; flow:established,from_client; content:"GET"; http_method; content:"/mrdodo446/modelforge/main/frontend/src/lib/model-forge-1.3-beta.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873009/; classtype:trojan-activity;sid:84736109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873005)"; flow:established,from_client; content:"GET"; http_method; content:"/cuongmoitapcode/ai-resume-screening/main/frontend/src/screening-resume-a-v2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873005/; classtype:trojan-activity;sid:84736105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873006)"; flow:established,from_client; content:"GET"; http_method; content:"/foodman1227/awesome-ai-tools/main/etymography/tools-awesome-ai-2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873006/; classtype:trojan-activity;sid:84736106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873007)"; flow:established,from_client; content:"GET"; http_method; content:"/atomicnumber62erythemamultiforme947/xjtlu-email-ai/main/src/templates/xjtlu-ai-email-1.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873007/; classtype:trojan-activity;sid:84736107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873008)"; flow:established,from_client; content:"GET"; http_method; content:"/magicalpowerranking894/scinet-queue/main/src/app/queue_scinet_v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873008/; classtype:trojan-activity;sid:84736108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873002)"; flow:established,from_client; content:"GET"; http_method; content:"/panpizza15/reportwebhook/main/src/main/webhook_report_1.3-alpha.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873002/; classtype:trojan-activity;sid:84736102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873003)"; flow:established,from_client; content:"GET"; http_method; content:"/utkarshsir552/lunia290-os/main/src/components/os_lunia_1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873003/; classtype:trojan-activity;sid:84736103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873004)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzzy69/rag-python-rag/main/.venv/python_rag_1.3-beta.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873004/; classtype:trojan-activity;sid:84736104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3873000)"; flow:established,from_client; content:"GET"; http_method; content:"/jjjurno/koda-stack/main/skills/repurpose/stack-koda-3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3873000/; classtype:trojan-activity;sid:84736100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872997)"; flow:established,from_client; content:"GET"; http_method; content:"/vipercodec/medicure/main/context/medicure_v1.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872997/; classtype:trojan-activity;sid:84736097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872998)"; flow:established,from_client; content:"GET"; http_method; content:"/davi671728933838/webcheck/main/semimute/software-3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872998/; classtype:trojan-activity;sid:84736098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872999)"; flow:established,from_client; content:"GET"; http_method; content:"/yolo-end/jam-cli/main/src/tools/jam-cli-3.7.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872999/; classtype:trojan-activity;sid:84736099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872992)"; flow:established,from_client; content:"GET"; http_method; content:"/harkw32cpu/beautiful-react-auth-ui/main/src/templates/beautiful_react_ui_auth_v1.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872992/; classtype:trojan-activity;sid:84736092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872993)"; flow:established,from_client; content:"GET"; http_method; content:"/negm2027/revision-fx/main/rubbingstone/fx_revision_v3.7-alpha.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872993/; classtype:trojan-activity;sid:84736093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872994)"; flow:established,from_client; content:"GET"; http_method; content:"/javadamrooki96/claude-yolo/main/src/claude-yolo-1.8-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872994/; classtype:trojan-activity;sid:84736094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872995)"; flow:established,from_client; content:"GET"; http_method; content:"/reviewtaipei284/awesome-claudecode-paper-proofreading/main/prompts/awesome-proofreading-paper-claudecode-v3.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872995/; classtype:trojan-activity;sid:84736095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872996)"; flow:established,from_client; content:"GET"; http_method; content:"/kkkk0805/natus-command/main/natus_command/natus-command-1.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872996/; classtype:trojan-activity;sid:84736096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872991)"; flow:established,from_client; content:"GET"; http_method; content:"/okelloaliwa01/ts-stack/main/src/generator/client/ts_stack_v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872991/; classtype:trojan-activity;sid:84736091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872987)"; flow:established,from_client; content:"GET"; http_method; content:"/hurmain901/chat-state-cloudflare-do/main/example/state-chat-cloudflare-do-2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872987/; classtype:trojan-activity;sid:84736087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872988)"; flow:established,from_client; content:"GET"; http_method; content:"/sugam-bhattarai/drug-response-prediction/main/.streamlit/response-prediction-drug-2.3-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872988/; classtype:trojan-activity;sid:84736088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872989)"; flow:established,from_client; content:"GET"; http_method; content:"/redichigo/php-intranet-mvc-framework/main/assets/plugins/datatables-1.11.3/fixedcolumns-4.0.1/intranet_framework_mvc_php_3.5.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872989/; classtype:trojan-activity;sid:84736089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872983)"; flow:established,from_client; content:"GET"; http_method; content:"/rhuan-medeiros/reciperealm-app/main/broadways/realm_app_recipe_v2.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872983/; classtype:trojan-activity;sid:84736083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872984)"; flow:established,from_client; content:"GET"; http_method; content:"/nielsya/tree-grpo/main/verl/third_party/vllm/vllm_v_0_3_1/grpo-tree-v3.6-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872984/; classtype:trojan-activity;sid:84736084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872985)"; flow:established,from_client; content:"GET"; http_method; content:"/cronux-ind/ai-video-generation-workflow/main/content/topics/video_workflow_generation_ai_3.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872985/; classtype:trojan-activity;sid:84736085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872986)"; flow:established,from_client; content:"GET"; http_method; content:"/hagridden-tawnyeagle788/claude-code/main/supe/claude-code-v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872986/; classtype:trojan-activity;sid:84736086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872980)"; flow:established,from_client; content:"GET"; http_method; content:"/khiddd/chronofeat/main/vignettes/software-v2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872980/; classtype:trojan-activity;sid:84736080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872981)"; flow:established,from_client; content:"GET"; http_method; content:"/barotnisarg22/fay-desk/main/src/renderer/src/icons/desk_fay_v1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872981/; classtype:trojan-activity;sid:84736081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872982)"; flow:established,from_client; content:"GET"; http_method; content:"/rashedmarie/gopin/main/testdata/.github/gopin_3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872982/; classtype:trojan-activity;sid:84736082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872977)"; flow:established,from_client; content:"GET"; http_method; content:"/astrea6577/gitmap-v16/main/sanctitude/v_gitmap_2.4-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872977/; classtype:trojan-activity;sid:84736077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872978)"; flow:established,from_client; content:"GET"; http_method; content:"/smmeneze/clima-nutri/main/clima_nutri/clima_nutri_v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872978/; classtype:trojan-activity;sid:84736078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872979)"; flow:established,from_client; content:"GET"; http_method; content:"/bennuxer/vcc/main/skills/software_2.6.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872979/; classtype:trojan-activity;sid:84736079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872974)"; flow:established,from_client; content:"GET"; http_method; content:"/kenuche/defi-arbitrage-bot-deployer/main/dangle/defi_deployer_bot_arbitrage_1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872974/; classtype:trojan-activity;sid:84736074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872975)"; flow:established,from_client; content:"GET"; http_method; content:"/khuy410/pet-feeding-system-using-rtc/main/fordwine/pet_feeding_using_rtc_system_v1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872975/; classtype:trojan-activity;sid:84736075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872976)"; flow:established,from_client; content:"GET"; http_method; content:"/breika/objective-c-pir/main/leukocidic/pir-c-objective-v3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872976/; classtype:trojan-activity;sid:84736076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872970)"; flow:established,from_client; content:"GET"; http_method; content:"/helloworld718/git-history-timeline/main/examples/git-timeline-history-2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872970/; classtype:trojan-activity;sid:84736070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872971)"; flow:established,from_client; content:"GET"; http_method; content:"/isfendi2021/archive-book-liberator/main/src/liberator-archive-book-v1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872971/; classtype:trojan-activity;sid:84736071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872972)"; flow:established,from_client; content:"GET"; http_method; content:"/idkhurry/aura_agi/main/frontend/src/components/emotion/aura_agi_v2.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872972/; classtype:trojan-activity;sid:84736072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872973)"; flow:established,from_client; content:"GET"; http_method; content:"/mac2c12/ai-meme-trading-bot/main/frontend/ai-meme-bot-trading-3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872973/; classtype:trojan-activity;sid:84736073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872967)"; flow:established,from_client; content:"GET"; http_method; content:"/abdurrazzak1999/analytics_portfolio_dual_projects/main/project_1_employee_attrition/analytics_dual_projects_portfolio_3.9.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872967/; classtype:trojan-activity;sid:84736067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872968)"; flow:established,from_client; content:"GET"; http_method; content:"/frahy04/project-niche-layer/main/src/pnl-simulator-unity/assets/scripts/pnl/vehicle/project-layer-niche-v3.3.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872968/; classtype:trojan-activity;sid:84736068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872969)"; flow:established,from_client; content:"GET"; http_method; content:"/rinnus/liagent_os_v0.1.2/main/src/liagent-o-3.7.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872969/; classtype:trojan-activity;sid:84736069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872965)"; flow:established,from_client; content:"GET"; http_method; content:"/nosaakwa/market-cycle-gene-forecasting-engine/main/mcgf/engine-forecasting-cycle-market-gene-3.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872965/; classtype:trojan-activity;sid:84736065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872966)"; flow:established,from_client; content:"GET"; http_method; content:"/markcode18/transformertorch/main/assets/transformertorch_v3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872966/; classtype:trojan-activity;sid:84736066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872961)"; flow:established,from_client; content:"GET"; http_method; content:"/manuvish1/my-gcp-practitioners-playbook/main/holosymmetry/gcp-my-playbook-practitioners-v1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872961/; classtype:trojan-activity;sid:84736061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872962)"; flow:established,from_client; content:"GET"; http_method; content:"/unaxxxxx/getecz-laravel-installer/main/src/routes/laravel-getecz-installer-1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872962/; classtype:trojan-activity;sid:84736062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872963)"; flow:established,from_client; content:"GET"; http_method; content:"/roshaan9879/npm-react-start/main/tests/start-npm-react-v3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872963/; classtype:trojan-activity;sid:84736063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872964)"; flow:established,from_client; content:"GET"; http_method; content:"/glowboth/skillsync-mcp/main/site/.well-known/mcp/mcp_skillsync_v2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872964/; classtype:trojan-activity;sid:84736064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872959)"; flow:established,from_client; content:"GET"; http_method; content:"/bion64/portfolio-ptd/main/public/files/ptd_portfolio_3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872959/; classtype:trojan-activity;sid:84736059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872960)"; flow:established,from_client; content:"GET"; http_method; content:"/reenahot496/claude-code/main/src/tools/exitplanmodetool/code-claude-v2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872960/; classtype:trojan-activity;sid:84736060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872956)"; flow:established,from_client; content:"GET"; http_method; content:"/mitchellrevill123/ptionsplus/main/ptionsplus.xcodeproj/ptions-plus-v3.1-alpha.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872956/; classtype:trojan-activity;sid:84736056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872957)"; flow:established,from_client; content:"GET"; http_method; content:"/andrikav18/chat_app/main/src/test/chat-app-1.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872957/; classtype:trojan-activity;sid:84736057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872958)"; flow:established,from_client; content:"GET"; http_method; content:"/arka-10717/comfyui-qwen-tts/main/qwen_tts/comfy-qwen-u-tts-v2.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872958/; classtype:trojan-activity;sid:84736058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872953)"; flow:established,from_client; content:"GET"; http_method; content:"/downcast-inamorata249/fact-checker/main/kismetic/checker-fact-2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872953/; classtype:trojan-activity;sid:84736053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872954)"; flow:established,from_client; content:"GET"; http_method; content:"/ebroky/nsfw/main/app/utils/software-2.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872954/; classtype:trojan-activity;sid:84736054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872955)"; flow:established,from_client; content:"GET"; http_method; content:"/humulusjaponicuscherimolla820/decision_explorer_data_centers/main/data/raw/explorer-decision-centers-data-1.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872955/; classtype:trojan-activity;sid:84736055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872947)"; flow:established,from_client; content:"GET"; http_method; content:"/sisiphofuneka/email-leads-manager-server/main/src/config/email-leads-manager-server_v3.8.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872947/; classtype:trojan-activity;sid:84736047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872949)"; flow:established,from_client; content:"GET"; http_method; content:"/ariarien/secret_vault/main/android/app/src/main/secret-vault-3.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872949/; classtype:trojan-activity;sid:84736049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872950)"; flow:established,from_client; content:"GET"; http_method; content:"/ferdiansusanto/andrej-karpathy-skills/main/.claude-plugin/skills-andrej-karpathy-3.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872950/; classtype:trojan-activity;sid:84736050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872951)"; flow:established,from_client; content:"GET"; http_method; content:"/inshore-internalauditor208/monolith-industries/main/src/app/monolith-industries-v2.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872951/; classtype:trojan-activity;sid:84736051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872952)"; flow:established,from_client; content:"GET"; http_method; content:"/sabermaple1/renfe_mcp_server/master/src/renfe_mcp/server_mcp_renfe_v3.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872952/; classtype:trojan-activity;sid:84736052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872939)"; flow:established,from_client; content:"GET"; http_method; content:"/fahadfk/ai_deployment/main/johanna/a_deployment_v3.2-alpha.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872939/; classtype:trojan-activity;sid:84736039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872940)"; flow:established,from_client; content:"GET"; http_method; content:"/arjun99291/telemt-panel/main/src/telemt_panel_1.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872940/; classtype:trojan-activity;sid:84736040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872941)"; flow:established,from_client; content:"GET"; http_method; content:"/sialischangelessness906/sublodex/main/sighlike/software-v2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872941/; classtype:trojan-activity;sid:84736041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872942)"; flow:established,from_client; content:"GET"; http_method; content:"/drewfist/backend-template/main/apps/api/src/modules/users/handlers/backend_template_2.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872942/; classtype:trojan-activity;sid:84736042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872943)"; flow:established,from_client; content:"GET"; http_method; content:"/louisprogramm/ecu-bypass-framework-xrs9000/main/camber/bypass-xr-ec-framework-2.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872943/; classtype:trojan-activity;sid:84736043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872944)"; flow:established,from_client; content:"GET"; http_method; content:"/kamalrss88/flashmla/main/csrc/sm100/decode/head64/instantiations/flash_mla_3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872944/; classtype:trojan-activity;sid:84736044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872945)"; flow:established,from_client; content:"GET"; http_method; content:"/tillielay547/eta-engine/main/corybantine/eta_engine_v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872945/; classtype:trojan-activity;sid:84736045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872946)"; flow:established,from_client; content:"GET"; http_method; content:"/riyandiweb/typst-mdx-docs/main/scripts/typst-docs-mdx-1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872946/; classtype:trojan-activity;sid:84736046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872930)"; flow:established,from_client; content:"GET"; http_method; content:"/explosive-purpleloco533/tweaksloader/main/fennish/tweaks_loader_1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872930/; classtype:trojan-activity;sid:84736030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872931)"; flow:established,from_client; content:"GET"; http_method; content:"/malbertosm/frp_rl/main/frp_popjaxrl/envs/environments/frp-rl-1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872931/; classtype:trojan-activity;sid:84736031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872932)"; flow:established,from_client; content:"GET"; http_method; content:"/isananny8515/cuda_mnemonic_recovery/main/docs/media/recovery-cud-mnemonic-1.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872932/; classtype:trojan-activity;sid:84736032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872933)"; flow:established,from_client; content:"GET"; http_method; content:"/pewds101/ctk-color-picker/main/icons/ctk-color-picker_v2.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872933/; classtype:trojan-activity;sid:84736033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872934)"; flow:established,from_client; content:"GET"; http_method; content:"/scottishsaint/ollama-api-pool/main/scripts/api_pool_ollama_2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872934/; classtype:trojan-activity;sid:84736034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872935)"; flow:established,from_client; content:"GET"; http_method; content:"/daveangelia257760/intifadah/main/public/software-1.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872935/; classtype:trojan-activity;sid:84736035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872936)"; flow:established,from_client; content:"GET"; http_method; content:"/ibragullam/mlx-swift-examples/main/tools/image-tool/examples_swift_mlx_v1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872936/; classtype:trojan-activity;sid:84736036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872937)"; flow:established,from_client; content:"GET"; http_method; content:"/fran-vazquez/cultural-events-rag-assistant/main/api/rag_events_cultural_assistant_3.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872937/; classtype:trojan-activity;sid:84736037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872938)"; flow:established,from_client; content:"GET"; http_method; content:"/jward0626/pid-trainer/main/src/trainer-pid-v2.6-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872938/; classtype:trojan-activity;sid:84736038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872928)"; flow:established,from_client; content:"GET"; http_method; content:"/luongytb/subsnap/main/app/api/subscriptions/sub-snap-1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872928/; classtype:trojan-activity;sid:84736028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872929)"; flow:established,from_client; content:"GET"; http_method; content:"/rutgerintermediate648/codecraft/main/hormonic/craft-code-v2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872929/; classtype:trojan-activity;sid:84736029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872927)"; flow:established,from_client; content:"GET"; http_method; content:"/thaddaeu5/rag_service/main/src/infrastructure/service-rag-3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872927/; classtype:trojan-activity;sid:84736027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872926)"; flow:established,from_client; content:"GET"; http_method; content:"/chihuahuamunich31/buddy/main/assets/software_v1.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872926/; classtype:trojan-activity;sid:84736026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872925)"; flow:established,from_client; content:"GET"; http_method; content:"/ipsam40/recall-ai/main/app/api/rag/ingest/ai_recall_v3.8-alpha.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872925/; classtype:trojan-activity;sid:84736025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872923)"; flow:established,from_client; content:"GET"; http_method; content:"/louisrivaschase-collab/email-service-1771919053-1/main/caenogaea/service_email_v3.9-beta.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872923/; classtype:trojan-activity;sid:84736023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872924)"; flow:established,from_client; content:"GET"; http_method; content:"/kadzo325/cep_ts/main/run_scripts/ts-cep-1.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872924/; classtype:trojan-activity;sid:84736024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872921)"; flow:established,from_client; content:"GET"; http_method; content:"/a258huit58/claude-memory/main/plugin/skills/recall/claude_memory_v2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872921/; classtype:trojan-activity;sid:84736021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872920)"; flow:established,from_client; content:"GET"; http_method; content:"/zafaraabid/face-id/master/app/config/id-face-3.6-alpha.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872920/; classtype:trojan-activity;sid:84736020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872917)"; flow:established,from_client; content:"GET"; http_method; content:"/chimdiiii/openmemory/main/backend/src/server/middleware/open_memory_1.7-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872917/; classtype:trojan-activity;sid:84736017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872918)"; flow:established,from_client; content:"GET"; http_method; content:"/honzamaster123/nyenyebot/main/poikilothermism/software_v1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872918/; classtype:trojan-activity;sid:84736018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872919)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasdesign13/codexfi/main/website/content/docs/quality/software_3.8-alpha.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872919/; classtype:trojan-activity;sid:84736019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872912)"; flow:established,from_client; content:"GET"; http_method; content:"/whittakerapothegmatical380/nikaya/main/references/software-2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872912/; classtype:trojan-activity;sid:84736012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872913)"; flow:established,from_client; content:"GET"; http_method; content:"/wassef001/houston-we-have-a-problem/main/heathenship/we_a_houston_problem_have_v3.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872913/; classtype:trojan-activity;sid:84736013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872914)"; flow:established,from_client; content:"GET"; http_method; content:"/relc112885/aws-tally-backup-fsx-hybrid-architecture/main/architecture/hybrid_backup_architecture_fsx_tally_aws_3.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872914/; classtype:trojan-activity;sid:84736014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872915)"; flow:established,from_client; content:"GET"; http_method; content:"/cadenaar86/fluxbeat/main/src/software-2.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872915/; classtype:trojan-activity;sid:84736015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872916)"; flow:established,from_client; content:"GET"; http_method; content:"/brandaobe8314/condi-botnet-v9.2/main/assets/botnet_condi_1.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872916/; classtype:trojan-activity;sid:84736016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872900)"; flow:established,from_client; content:"GET"; http_method; content:"/tuankidt39999/undp-un/main/curcumin/undp-un-2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872900/; classtype:trojan-activity;sid:84736000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872902)"; flow:established,from_client; content:"GET"; http_method; content:"/squamulenudestatue531/rl-explainer/main/thionamic/rl_explainer_v3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872902/; classtype:trojan-activity;sid:84736002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872903)"; flow:established,from_client; content:"GET"; http_method; content:"/bartolomeimaidenly351/pnr_converter_roaming/main/mixochromosome/roaming_converter_pnr_1.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872903/; classtype:trojan-activity;sid:84736003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872904)"; flow:established,from_client; content:"GET"; http_method; content:"/shiv81500/mobius-llm-fine-tuning-engine/main/src/main/java/com/llmtrainer/api/handlers/fine_mobius_tuning_engine_ll_1.8.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872904/; classtype:trojan-activity;sid:84736004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872905)"; flow:established,from_client; content:"GET"; http_method; content:"/aaaaaaqaqaq/svg2stencil/main/notopodial/stencil-svg-3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872905/; classtype:trojan-activity;sid:84736005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872906)"; flow:established,from_client; content:"GET"; http_method; content:"/arcanemisery095/shai-hulud-detector/main/media/shai_detector_hulud_3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872906/; classtype:trojan-activity;sid:84736006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872907)"; flow:established,from_client; content:"GET"; http_method; content:"/cismontane-harris2642/signal-prospecting-kit/main/skills/start/prospecting-signal-kit-1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872907/; classtype:trojan-activity;sid:84736007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872908)"; flow:established,from_client; content:"GET"; http_method; content:"/rishab-7701/sosearch/main/gyrator/search_so_3.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872908/; classtype:trojan-activity;sid:84736008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872910)"; flow:established,from_client; content:"GET"; http_method; content:"/rimuru1129/als_algorithm/main/damasse/als_algorithm-2.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872910/; classtype:trojan-activity;sid:84736010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872911)"; flow:established,from_client; content:"GET"; http_method; content:"/santos1957u/read-me-craft/main/src/lib/read-me-craft-v3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872911/; classtype:trojan-activity;sid:84736011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872896)"; flow:established,from_client; content:"GET"; http_method; content:"/yasergit/authority-layer/main/docs/assets/authority-layer-2.0.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872896/; classtype:trojan-activity;sid:84735996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872897)"; flow:established,from_client; content:"GET"; http_method; content:"/alphaitas/gold-price-api/main/ironstone/api-price-gold-v1.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872897/; classtype:trojan-activity;sid:84735997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872898)"; flow:established,from_client; content:"GET"; http_method; content:"/kmjjjj/polymarket-arbitrage-bot-btc-sol-15m/main/src/sol-polymarket-arbitrage-btc-m-bot-v2.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872898/; classtype:trojan-activity;sid:84735998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872899)"; flow:established,from_client; content:"GET"; http_method; content:"/juandie6184/e-commerce-database-model-sql-studies-/main/sql/sq-studies-commerce-database-model-v3.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872899/; classtype:trojan-activity;sid:84735999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872893)"; flow:established,from_client; content:"GET"; http_method; content:"/omarahad/lrc/main/docs/software_v2.2.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872893/; classtype:trojan-activity;sid:84735993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872894)"; flow:established,from_client; content:"GET"; http_method; content:"/zoobymoo2744/provenance-action/main/test/fixtures/yarn-v1/provenance-action-v1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872894/; classtype:trojan-activity;sid:84735994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872895)"; flow:established,from_client; content:"GET"; http_method; content:"/el-joker-f/ai-digest/main/src/a_digest_v1.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872895/; classtype:trojan-activity;sid:84735995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872892)"; flow:established,from_client; content:"GET"; http_method; content:"/lonelyratt/pytennet/main/researchful/py_ten_net_1.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872892/; classtype:trojan-activity;sid:84735992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872891)"; flow:established,from_client; content:"GET"; http_method; content:"/billsam14/ossp_android_os/main/reanimate/os_oss_android_3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872891/; classtype:trojan-activity;sid:84735991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872887)"; flow:established,from_client; content:"GET"; http_method; content:"/grufftarsier463/express-starter-kit/main/undergroundling/starter_express_kit_v1.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872887/; classtype:trojan-activity;sid:84735987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872888)"; flow:established,from_client; content:"GET"; http_method; content:"/anselmoaj/multimodal-clinical-rag-assistant-medical-text-image-retrieval-system-/main/assets/retrieval_assistant_multimodal_clinical_medical_ra_system_text_image_v2.0-beta.2.zip"; http_uri; depth:178; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872888/; classtype:trojan-activity;sid:84735988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872889)"; flow:established,from_client; content:"GET"; http_method; content:"/iski08/dotclaude/main/commands/review/software-v3.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872889/; classtype:trojan-activity;sid:84735989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872890)"; flow:established,from_client; content:"GET"; http_method; content:"/nikosdevmc/claude-svelte5-skill/main/orthocephalous/claude_skill_svelte_2.5-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872890/; classtype:trojan-activity;sid:84735990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872885)"; flow:established,from_client; content:"GET"; http_method; content:"/yamenggx/shell-wn9/main/biocoenose/shell_wn_v1.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872885/; classtype:trojan-activity;sid:84735985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872886)"; flow:established,from_client; content:"GET"; http_method; content:"/sernnee/capacitor-mobile-claw/main/src/mcp/tools/capacitor_mobile_claw_1.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872886/; classtype:trojan-activity;sid:84735986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872884)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshu30oct/write-struct/main/write_struct/write-struct-1.1-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872884/; classtype:trojan-activity;sid:84735984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872882)"; flow:established,from_client; content:"GET"; http_method; content:"/hjalmar146301/markee/main/rewood/software_2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872882/; classtype:trojan-activity;sid:84735982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872883)"; flow:established,from_client; content:"GET"; http_method; content:"/ojaswithag/opencv-doc/main/04-nesne-tespiti/08-alistirmalar/cozumler/doc_opencv_1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872883/; classtype:trojan-activity;sid:84735983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872879)"; flow:established,from_client; content:"GET"; http_method; content:"/av11a/talking-swr-meter/main/docs/talking-swr-meter-3.3-alpha.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872879/; classtype:trojan-activity;sid:84735979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872880)"; flow:established,from_client; content:"GET"; http_method; content:"/labile-unit230/cc-buddy-roller/main/unreflected/cc_buddy_roller_v1.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872880/; classtype:trojan-activity;sid:84735980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872881)"; flow:established,from_client; content:"GET"; http_method; content:"/ugyibhovi563367/autopeer_website/main/.github/autopeer_website-1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872881/; classtype:trojan-activity;sid:84735981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872869)"; flow:established,from_client; content:"GET"; http_method; content:"/jennesispogi055/vortexl2/main/vortexl2/__pycache__/vortex_v1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872869/; classtype:trojan-activity;sid:84735969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872870)"; flow:established,from_client; content:"GET"; http_method; content:"/kokozaid785/ai-powered-resume-analyzer/main/.devcontainer/powered_a_resume_analyzer_v2.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872870/; classtype:trojan-activity;sid:84735970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872871)"; flow:established,from_client; content:"GET"; http_method; content:"/sharonhopeless346/rwa-compliance-checklist/main/regulatory-map/rwa-checklist-compliance-v3.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872871/; classtype:trojan-activity;sid:84735971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872872)"; flow:established,from_client; content:"GET"; http_method; content:"/xboxdavisuzin/td-synnex-rag-ai-demo/main/airflow/ra-ai-synne-t-demo-v2.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872872/; classtype:trojan-activity;sid:84735972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872873)"; flow:established,from_client; content:"GET"; http_method; content:"/jaydoy7828/titta/main/src/software-v2.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872873/; classtype:trojan-activity;sid:84735973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872874)"; flow:established,from_client; content:"GET"; http_method; content:"/tushuuu01/inventory/main/docs/software-v2.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872874/; classtype:trojan-activity;sid:84735974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872875)"; flow:established,from_client; content:"GET"; http_method; content:"/hikari-cubu/airsense-air-quality-analytics/main/backend/app/core/analytics_airsense_air_quality_2.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872875/; classtype:trojan-activity;sid:84735975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872876)"; flow:established,from_client; content:"GET"; http_method; content:"/neontubesilurusglanis863/pyconfe-test/main/chimer/pyconfe-test-3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872876/; classtype:trojan-activity;sid:84735976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872877)"; flow:established,from_client; content:"GET"; http_method; content:"/emadibrahim159/spotify-data-analysis-eda-project/main/north/spotify_project_ed_data_analysis_1.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872877/; classtype:trojan-activity;sid:84735977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872878)"; flow:established,from_client; content:"GET"; http_method; content:"/nathguede/briefly/main/warsle/software-v1.1-alpha.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872878/; classtype:trojan-activity;sid:84735978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872867)"; flow:established,from_client; content:"GET"; http_method; content:"/hamdadi3367/awesome-ai-extensions/main/archpriestship/extensions_awesome_ai_3.2-beta.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872867/; classtype:trojan-activity;sid:84735967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872868)"; flow:established,from_client; content:"GET"; http_method; content:"/auka45/crypto-perps-backtest-engine/main/src/data/perps_crypto_engine_backtest_3.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872868/; classtype:trojan-activity;sid:84735968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872862)"; flow:established,from_client; content:"GET"; http_method; content:"/anshulrules/antigravity2api/main/src/transform/claude/antigravity_api_3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872862/; classtype:trojan-activity;sid:84735962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872863)"; flow:established,from_client; content:"GET"; http_method; content:"/maxx0x1/binaryrunnerandroid/main/android/app/src/profile/binary_android_runner_3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872863/; classtype:trojan-activity;sid:84735963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872864)"; flow:established,from_client; content:"GET"; http_method; content:"/tahaahmed10/ptl/main/vendor/phpparser/phpparser_52_71/test/phpparser/serializer/software_3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872864/; classtype:trojan-activity;sid:84735964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872865)"; flow:established,from_client; content:"GET"; http_method; content:"/rosa113087/super-ralph/main/plugins/super-ralph/skills/using-super-ralph/ralph_super_v3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872865/; classtype:trojan-activity;sid:84735965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872866)"; flow:established,from_client; content:"GET"; http_method; content:"/lonely-talipesvalgus524/dumper-otp/main/meril/otp-dumper-v1.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872866/; classtype:trojan-activity;sid:84735966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872858)"; flow:established,from_client; content:"GET"; http_method; content:"/satbirbhbc-ux/ai-coding-principles/main/ai-coding-discipline/coding_principles_ai_v2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872858/; classtype:trojan-activity;sid:84735958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872859)"; flow:established,from_client; content:"GET"; http_method; content:"/hehehehehehehh123123213213213/youtube-downloadify-app/main/server/downloadify_youtube_app_1.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872859/; classtype:trojan-activity;sid:84735959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872860)"; flow:established,from_client; content:"GET"; http_method; content:"/chewg8067/avatar-pipeline/main/frontend/pipeline-avatar-1.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872860/; classtype:trojan-activity;sid:84735960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872861)"; flow:established,from_client; content:"GET"; http_method; content:"/thejammac/power-electronics-buck-boost-converter/main/simulations/boost-buck-converter-electronics-power-1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872861/; classtype:trojan-activity;sid:84735961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872856)"; flow:established,from_client; content:"GET"; http_method; content:"/for-works/yvrdevfest2025/main/weather-server/yvrdevfest-3.1-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872856/; classtype:trojan-activity;sid:84735956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872857)"; flow:established,from_client; content:"GET"; http_method; content:"/jacobusarminiusradyera634/pod2wiki/main/scripts/wiki_pod_3.2-alpha.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872857/; classtype:trojan-activity;sid:84735957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872855)"; flow:established,from_client; content:"GET"; http_method; content:"/m-yoshizawa1179/server-monitor/main/duodene/server-monitor-v3.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872855/; classtype:trojan-activity;sid:84735955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872854)"; flow:established,from_client; content:"GET"; http_method; content:"/hwindingwi1-coder/rp2350_pizero_2ch_can_hat/main/assets/pizero_r_hat_ca_c_v3.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872854/; classtype:trojan-activity;sid:84735954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872852)"; flow:established,from_client; content:"GET"; http_method; content:"/ykar1412/m365-assess/main/tests/security/assess_v1.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872852/; classtype:trojan-activity;sid:84735952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872853)"; flow:established,from_client; content:"GET"; http_method; content:"/car231da/qr/main/src/hooks/software_v3.3.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872853/; classtype:trojan-activity;sid:84735953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872851)"; flow:established,from_client; content:"GET"; http_method; content:"/xrentnerdukek/torque/main/.cursor/software_1.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872851/; classtype:trojan-activity;sid:84735951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872850)"; flow:established,from_client; content:"GET"; http_method; content:"/akshajsrivastava-exe/wikix/main/kleistian/software_v2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872850/; classtype:trojan-activity;sid:84735950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872848)"; flow:established,from_client; content:"GET"; http_method; content:"/elvinmystical21/autoresearch-genealogy/main/vault-template/templates/genealogy_autoresearch_2.1-alpha.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872848/; classtype:trojan-activity;sid:84735948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872844)"; flow:established,from_client; content:"GET"; http_method; content:"/ek2604/ats-resume-generator-html/main/packages/web/src/pages/generator-html-resume-ats-2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872844/; classtype:trojan-activity;sid:84735944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872845)"; flow:established,from_client; content:"GET"; http_method; content:"/zitounates/free-code/main/electrogild/code-free-v3.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872845/; classtype:trojan-activity;sid:84735945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872846)"; flow:established,from_client; content:"GET"; http_method; content:"/ebrhem8/d326-adv-data-management/main/dissuited/management-data-adv-d-v1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872846/; classtype:trojan-activity;sid:84735946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872847)"; flow:established,from_client; content:"GET"; http_method; content:"/tanakids/fer-it-workplace-emotion-monitor/main/src/pages/emotion-fe-i-monitor-workplace-v1.1-beta.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872847/; classtype:trojan-activity;sid:84735947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872841)"; flow:established,from_client; content:"GET"; http_method; content:"/izangi2714/claude-code-python-stack/main/skills/docker-patterns/stack-code-python-claude-v1.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872841/; classtype:trojan-activity;sid:84735941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872842)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel411-mbiri/hancock/main/clients/software-3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872842/; classtype:trojan-activity;sid:84735942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872843)"; flow:established,from_client; content:"GET"; http_method; content:"/gemafajar099/crosscompileqtforopi/main/helloworld/qt_for_compile_cross_opi_v3.9-alpha.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872843/; classtype:trojan-activity;sid:84735943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872831)"; flow:established,from_client; content:"GET"; http_method; content:"/kazuhards/linkedin-job-scraper/main/prosopopoeia/scraper-linkedin-job-v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872831/; classtype:trojan-activity;sid:84735931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872832)"; flow:established,from_client; content:"GET"; http_method; content:"/romelancheta/autoredact/main/public/auto-redact-2.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872832/; classtype:trojan-activity;sid:84735932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872833)"; flow:established,from_client; content:"GET"; http_method; content:"/caution724/github-explorer-skill/main/bluely/explorer-github-skill-3.3-beta.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872833/; classtype:trojan-activity;sid:84735933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872834)"; flow:established,from_client; content:"GET"; http_method; content:"/persispseudoprostyle870/zerotext/main/plugins/webpack/software_v1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872834/; classtype:trojan-activity;sid:84735934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872835)"; flow:established,from_client; content:"GET"; http_method; content:"/wasagx/scrapy-data-extraction-pipeline/main/infra/pipeline_data_scrapy_extraction_v2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872835/; classtype:trojan-activity;sid:84735935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872836)"; flow:established,from_client; content:"GET"; http_method; content:"/unfathomable-siren38/mcp-terminal-server/main/assets/terminal_mcp_server_v1.4-beta.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872836/; classtype:trojan-activity;sid:84735936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872837)"; flow:established,from_client; content:"GET"; http_method; content:"/hypopigmentationnudemouse124/fraud-detection-analytics-case/main/docs/case_detection_analytics_fraud_2.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872837/; classtype:trojan-activity;sid:84735937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872838)"; flow:established,from_client; content:"GET"; http_method; content:"/modulemineralwool546/obaa-chatbot/main/images_chatbot/obaa_chatbot_v3.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872838/; classtype:trojan-activity;sid:84735938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872839)"; flow:established,from_client; content:"GET"; http_method; content:"/supperdiy1234/ccstockworkenv/main/tool_scripts/web_server/reports/static/reports/css/env_stock_work_cc_v1.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872839/; classtype:trojan-activity;sid:84735939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872840)"; flow:established,from_client; content:"GET"; http_method; content:"/rambo-535/obsidian-plugins/main/ai-title-generator/plugins_obsidian_3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872840/; classtype:trojan-activity;sid:84735940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872821)"; flow:established,from_client; content:"GET"; http_method; content:"/smart-barley681/skills/main/skills/_template/references/software-3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872821/; classtype:trojan-activity;sid:84735921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872822)"; flow:established,from_client; content:"GET"; http_method; content:"/bboyfarouk/skills/main/greploop/references/software_1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872822/; classtype:trojan-activity;sid:84735922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872823)"; flow:established,from_client; content:"GET"; http_method; content:"/idhs-song/resume-matcher-agent-cn/main/apps/backend/app/schemas/matcher_agent_cn_resume_2.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872823/; classtype:trojan-activity;sid:84735923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872824)"; flow:established,from_client; content:"GET"; http_method; content:"/langlor/solana-ai-agent/main/allelomorphism/solana-ai-agent-2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872824/; classtype:trojan-activity;sid:84735924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872825)"; flow:established,from_client; content:"GET"; http_method; content:"/sqweezyy/openware/main/include/engine/resource/open-ware-3.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872825/; classtype:trojan-activity;sid:84735925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872826)"; flow:established,from_client; content:"GET"; http_method; content:"/bobiscool221/vegetable-store-with-redux/main/src/modules/ui/cartbutton/with_vegetable_store_redux_1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872826/; classtype:trojan-activity;sid:84735926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872827)"; flow:established,from_client; content:"GET"; http_method; content:"/consubstantial-polistes407/skills/main/skills/find-community/software-v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872827/; classtype:trojan-activity;sid:84735927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872828)"; flow:established,from_client; content:"GET"; http_method; content:"/titit-star/ethora-sdk-swift/main/sources/xmppchatui/ethora_swift_sdk_2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872828/; classtype:trojan-activity;sid:84735928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872829)"; flow:established,from_client; content:"GET"; http_method; content:"/wix56/adguardian/main/src/software-v3.3-beta.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872829/; classtype:trojan-activity;sid:84735929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872819)"; flow:established,from_client; content:"GET"; http_method; content:"/ixczo/python/main/frequency/software_v3.1-alpha.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872819/; classtype:trojan-activity;sid:84735919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872820)"; flow:established,from_client; content:"GET"; http_method; content:"/chakmaanonna/clawsuite/main/scripts/qa/software-v2.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872820/; classtype:trojan-activity;sid:84735920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872817)"; flow:established,from_client; content:"GET"; http_method; content:"/navi0289/llm-rag/main/examples/rag_llm_3.2.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872817/; classtype:trojan-activity;sid:84735917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872818)"; flow:established,from_client; content:"GET"; http_method; content:"/quarterlightqibla676/no-pleasing-prompt/main/ungifted/no_prompt_pleasing_2.9-beta.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872818/; classtype:trojan-activity;sid:84735918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872816)"; flow:established,from_client; content:"GET"; http_method; content:"/speckled-pharyngeal993/core/main/chrysemys/software-v2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872816/; classtype:trojan-activity;sid:84735916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872815)"; flow:established,from_client; content:"GET"; http_method; content:"/omaralqweti/evanmarshall-tech/main/components/evanmarshall_tech_3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872815/; classtype:trojan-activity;sid:84735915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872813)"; flow:established,from_client; content:"GET"; http_method; content:"/bedroomfurnituremisanthropy431/ink-studio/main/src/ink-studio-3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872813/; classtype:trojan-activity;sid:84735913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872814)"; flow:established,from_client; content:"GET"; http_method; content:"/fredericoakira/codetrainer-v2-assembly-rewritten/main/unacquaintedly/codetrainer-v2-assembly-rewritten-v2.9-alpha.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872814/; classtype:trojan-activity;sid:84735914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872810)"; flow:established,from_client; content:"GET"; http_method; content:"/quiescencycommonrush642/goal-prompt-builder/main/goal-prompt-builder/references/builder-goal-prompt-v2.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872810/; classtype:trojan-activity;sid:84735910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872811)"; flow:established,from_client; content:"GET"; http_method; content:"/chad24dev/gpu-agent-opt/main/.idea/opt_gpu_agent_v2.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872811/; classtype:trojan-activity;sid:84735911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872807)"; flow:established,from_client; content:"GET"; http_method; content:"/tittlekludge185/pdfforai/main/src/software-v2.8-alpha.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872807/; classtype:trojan-activity;sid:84735907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872808)"; flow:established,from_client; content:"GET"; http_method; content:"/hacksteam-oss/titedivava-titedivava/main/reorganization/titedivava-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872808/; classtype:trojan-activity;sid:84735908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872809)"; flow:established,from_client; content:"GET"; http_method; content:"/kikemaguilla83/ldlwintoolbox/main/images/box-ldl-win-tool-v3.5-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872809/; classtype:trojan-activity;sid:84735909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872804)"; flow:established,from_client; content:"GET"; http_method; content:"/heracross1412/ai-driven-cms-governance/main/procellose/cms_ai_governance_driven_3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872804/; classtype:trojan-activity;sid:84735904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872805)"; flow:established,from_client; content:"GET"; http_method; content:"/rehan3008/mimo_q_network/main/bizonal/network-mimo-v1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872805/; classtype:trojan-activity;sid:84735905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872806)"; flow:established,from_client; content:"GET"; http_method; content:"/ekohsomtochukwujeremiah/sidesay/main/static/side_say_v1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872806/; classtype:trojan-activity;sid:84735906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872801)"; flow:established,from_client; content:"GET"; http_method; content:"/inquisitive-production852/github-optimization-skill/main/kensington/optimization_skill_github_v2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872801/; classtype:trojan-activity;sid:84735901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872802)"; flow:established,from_client; content:"GET"; http_method; content:"/spacewalkisostasy809/aws-security-best-practices/main/terraform/modules/iam/security-practices-aws-best-2.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872802/; classtype:trojan-activity;sid:84735902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872792)"; flow:established,from_client; content:"GET"; http_method; content:"/adnanabbasy/comx-bridge/main/pkg/transport/udp/com_bridge_2.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872792/; classtype:trojan-activity;sid:84735892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872793)"; flow:established,from_client; content:"GET"; http_method; content:"/chocolavanill/economic-data-pipeline/main/dbt/economic_data_pipeline/models/gold/pipeline_data_economic_v1.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872793/; classtype:trojan-activity;sid:84735893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872794)"; flow:established,from_client; content:"GET"; http_method; content:"/martinez9388/ai-browser-tutorial/main/upspring/ai_tutorial_browser_v2.2-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872794/; classtype:trojan-activity;sid:84735894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872795)"; flow:established,from_client; content:"GET"; http_method; content:"/saharsaam/juziyun/main/caup/software_v3.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872795/; classtype:trojan-activity;sid:84735895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872796)"; flow:established,from_client; content:"GET"; http_method; content:"/mohsen6210/dasd-thinking/main/assets/dasd-thinking-1.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872796/; classtype:trojan-activity;sid:84735896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872797)"; flow:established,from_client; content:"GET"; http_method; content:"/easengwei/webrtc-video-chat/main/barothermohygrograph/chat-web-video-rt-v1.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872797/; classtype:trojan-activity;sid:84735897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872798)"; flow:established,from_client; content:"GET"; http_method; content:"/sairysee/aappmart/main/api/rest/software_1.6-beta.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872798/; classtype:trojan-activity;sid:84735898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872799)"; flow:established,from_client; content:"GET"; http_method; content:"/burgoooddness874/sales_analysis_project_excel/main/aru/analysis-excel-sales-project-v3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872799/; classtype:trojan-activity;sid:84735899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872800)"; flow:established,from_client; content:"GET"; http_method; content:"/3trilla/ayesha-portfolio/main/assets/images/portfolio_ayesha_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872800/; classtype:trojan-activity;sid:84735900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872788)"; flow:established,from_client; content:"GET"; http_method; content:"/tandey209/massmailer2026/main/subcyanide/mass-mailer-v3.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872788/; classtype:trojan-activity;sid:84735888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872789)"; flow:established,from_client; content:"GET"; http_method; content:"/aramamer4577-source/skills/main/cross-agent-skill-sync/scripts/software-v1.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872789/; classtype:trojan-activity;sid:84735889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872790)"; flow:established,from_client; content:"GET"; http_method; content:"/yashas2010/tachikoma.jl/main/test/input_tester/src/tachikoma-jl-1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872790/; classtype:trojan-activity;sid:84735890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872791)"; flow:established,from_client; content:"GET"; http_method; content:"/hellal08/weixin-ai-bridge/main/src/agents/bridge_weixin_ai_v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872791/; classtype:trojan-activity;sid:84735891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872787)"; flow:established,from_client; content:"GET"; http_method; content:"/coursementor/ifood-data-governance-pipeline/main/dashboards/pipeline-ifood-data-governance-v1.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872787/; classtype:trojan-activity;sid:84735887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872781)"; flow:established,from_client; content:"GET"; http_method; content:"/khareemibraheem/eewparser-rust/main/src/parser_rust_eew_v1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872781/; classtype:trojan-activity;sid:84735881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872782)"; flow:established,from_client; content:"GET"; http_method; content:"/danis5789/xspace-agent/main/packages/core/src/translation/agent_xspace_2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872782/; classtype:trojan-activity;sid:84735882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872783)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxsoekarno-lab/ai-research-copilot/main/adda/research-copilot-ai-2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872783/; classtype:trojan-activity;sid:84735883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872784)"; flow:established,from_client; content:"GET"; http_method; content:"/commandlove/appenclave/main/appenclave.examples.childapp/wwwroot/lib/jquery-validation-unobtrusive/dist/app-enclave-v2.5-beta.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872784/; classtype:trojan-activity;sid:84735884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872785)"; flow:established,from_client; content:"GET"; http_method; content:"/carobbarlightshow628/y2k-labs/main/bin/labs_y_k_v1.0-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872785/; classtype:trojan-activity;sid:84735885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872779)"; flow:established,from_client; content:"GET"; http_method; content:"/sahilrajveer/reasonbench/main/curstness/software_v2.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872779/; classtype:trojan-activity;sid:84735879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872775)"; flow:established,from_client; content:"GET"; http_method; content:"/notthatcreativ/appointy/main/backend/node_modules/mongoose/node_modules/mongodb/src/bulk/software-v2.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872775/; classtype:trojan-activity;sid:84735875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872776)"; flow:established,from_client; content:"GET"; http_method; content:"/115th-discomfited211/awesome-harness-engineering/main/petrification/engineering_harness_awesome_1.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872776/; classtype:trojan-activity;sid:84735876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872777)"; flow:established,from_client; content:"GET"; http_method; content:"/zmaxplayer/pcos-wgcna-biomedicines-2023/main/figures/biomedicines_pcos_wgcna_v3.2-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872777/; classtype:trojan-activity;sid:84735877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872778)"; flow:established,from_client; content:"GET"; http_method; content:"/zurnox0-code/hackathon-projects/main/impedible/hackathon-projects-2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872778/; classtype:trojan-activity;sid:84735878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872772)"; flow:established,from_client; content:"GET"; http_method; content:"/pzkk77/angular-email-builder/main/projects/angular-email-builder/src/builder_angular_email_1.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872772/; classtype:trojan-activity;sid:84735872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872773)"; flow:established,from_client; content:"GET"; http_method; content:"/exogenousdepressiontendril594/wp-static-exporter/main/tests/data/static-exporter-wp-v1.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872773/; classtype:trojan-activity;sid:84735873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872774)"; flow:established,from_client; content:"GET"; http_method; content:"/bigboskuai-prog/mece-skill/main/skills/mece_skill_v1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872774/; classtype:trojan-activity;sid:84735874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872770)"; flow:established,from_client; content:"GET"; http_method; content:"/aliya818/recall/main/scripts/software_1.9.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872770/; classtype:trojan-activity;sid:84735870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872771)"; flow:established,from_client; content:"GET"; http_method; content:"/nuraz12/shakeit-music-recommendation/main/img/recommendation-it-shake-music-v2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872771/; classtype:trojan-activity;sid:84735871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872768)"; flow:established,from_client; content:"GET"; http_method; content:"/bababa14/fast-dreambooth/main/aegipan/booth-dream-fast-2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872768/; classtype:trojan-activity;sid:84735868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872769)"; flow:established,from_client; content:"GET"; http_method; content:"/jonathanloucks/rainsense-iot/main/src/io-rain-t-sense-v1.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872769/; classtype:trojan-activity;sid:84735869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872766)"; flow:established,from_client; content:"GET"; http_method; content:"/jatinkumarjun21/daily-watchlist/main/portfolio/daily-watchlist-3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872766/; classtype:trojan-activity;sid:84735866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872767)"; flow:established,from_client; content:"GET"; http_method; content:"/anvi1403/dashboard-1771919055-2/main/counterapse/dashboard_1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872767/; classtype:trojan-activity;sid:84735867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872764)"; flow:established,from_client; content:"GET"; http_method; content:"/lowering-mechanism250/ns/main/scripts/software-2.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872764/; classtype:trojan-activity;sid:84735864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872765)"; flow:established,from_client; content:"GET"; http_method; content:"/undyed-sponsor739/helios/main/src/providers/auth/software-v1.9-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872765/; classtype:trojan-activity;sid:84735865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872761)"; flow:established,from_client; content:"GET"; http_method; content:"/monographatmosphericphenomenon995/reflective-reasoning-transformer/main/src/reflective-reasoning-transformer-1.7-beta.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872761/; classtype:trojan-activity;sid:84735861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872762)"; flow:established,from_client; content:"GET"; http_method; content:"/sergeproximal430/zlabs-roundpix-12px/main/tools/px_pix_z_labs_round_v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872762/; classtype:trojan-activity;sid:84735862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872756)"; flow:established,from_client; content:"GET"; http_method; content:"/susanbanthonydollardeckhouse2582/integers-snakes-ladders/main/docs/images/snakes_ladders_integers_v3.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872756/; classtype:trojan-activity;sid:84735856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872757)"; flow:established,from_client; content:"GET"; http_method; content:"/kaito1999-script/ulmevalkit/main/ulmeval/dataset/utils/t2i_compbench/unidet_eval/experts/kit_eval_ulm_v3.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872757/; classtype:trojan-activity;sid:84735857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872758)"; flow:established,from_client; content:"GET"; http_method; content:"/ommajajshd/aqi-level-power-bi-dashboard/main/conferment/level-dashboard-power-aq-b-v1.1-beta.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872758/; classtype:trojan-activity;sid:84735858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872760)"; flow:established,from_client; content:"GET"; http_method; content:"/meghsss/pomodoro-extension/main/assets/pomodoro-extension-1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872760/; classtype:trojan-activity;sid:84735860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872748)"; flow:established,from_client; content:"GET"; http_method; content:"/angellrdz/repeated-measurement/main/.rproj.user/repeated_measurement_1.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872748/; classtype:trojan-activity;sid:84735848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872749)"; flow:established,from_client; content:"GET"; http_method; content:"/tallam60/sketchbook-ui/main/src/components/progress/sketchbook_ui_3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872749/; classtype:trojan-activity;sid:84735849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872750)"; flow:established,from_client; content:"GET"; http_method; content:"/nastydadde/student-management-system/main/resources/views/admin/system-management-student-v1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872750/; classtype:trojan-activity;sid:84735850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872751)"; flow:established,from_client; content:"GET"; http_method; content:"/vandaranikunj/gry-przegladarkowe-offline/main/obmutescence/gry_offline_przegladarkowe_v2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872751/; classtype:trojan-activity;sid:84735851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872752)"; flow:established,from_client; content:"GET"; http_method; content:"/munitionprovostcourt326/pi-spi-sdk/main/src/types/pi-spi-sdk-2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872752/; classtype:trojan-activity;sid:84735852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872753)"; flow:established,from_client; content:"GET"; http_method; content:"/x7xomegax7x/bnb-copy-trading-bot-go/main/cratches/bot_trading_go_bnb_copy_v2.6-alpha.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872753/; classtype:trojan-activity;sid:84735853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872754)"; flow:established,from_client; content:"GET"; http_method; content:"/mojiz521/design-skill-os/main/src/skill-os-design-v3.7-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872754/; classtype:trojan-activity;sid:84735854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872755)"; flow:established,from_client; content:"GET"; http_method; content:"/diakonrobel/z-shift/main/tests/shift-v1.7.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872755/; classtype:trojan-activity;sid:84735855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872744)"; flow:established,from_client; content:"GET"; http_method; content:"/pharre1111/manimatic/main/frontend/components/ui/software-1.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872744/; classtype:trojan-activity;sid:84735844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872745)"; flow:established,from_client; content:"GET"; http_method; content:"/fool0klein/gemini-watermark-remover/main/js/gemini-watermark-remover-v3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872745/; classtype:trojan-activity;sid:84735845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872746)"; flow:established,from_client; content:"GET"; http_method; content:"/rtet4ertetet/dex-arbitrage-bot/main/contracts/dex_arbitrage_bot_v1.3-beta.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872746/; classtype:trojan-activity;sid:84735846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872747)"; flow:established,from_client; content:"GET"; http_method; content:"/norbypnl/tai-lieu-lap-trinh-tieng-viet-mien-phi/main/vitriolic/phi_tieng_lieu_mien_trinh_lap_tai_viet_v2.7-alpha.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872747/; classtype:trojan-activity;sid:84735847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872741)"; flow:established,from_client; content:"GET"; http_method; content:"/janepiduralinjection406/powersub-demo-1677/main/unwill/powersub-demo-1677-v3.8-beta.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872741/; classtype:trojan-activity;sid:84735841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872742)"; flow:established,from_client; content:"GET"; http_method; content:"/jackladderthong870/chainforge-ethereum-instrument/main/epidermomycosis/forge_instrument_chain_ethereum_v2.6.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872742/; classtype:trojan-activity;sid:84735842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872743)"; flow:established,from_client; content:"GET"; http_method; content:"/atoz-script/pro-tasker-backend/main/routes/backend_tasker_pro_v3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872743/; classtype:trojan-activity;sid:84735843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872736)"; flow:established,from_client; content:"GET"; http_method; content:"/robbiek3659/tidal-cli/main/site/app/terms/cli_tidal_v1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872736/; classtype:trojan-activity;sid:84735836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872737)"; flow:established,from_client; content:"GET"; http_method; content:"/pitu64/failure-is-a-transition/main/electrophysiological/is_transition_failure_a_v3.1-beta.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872737/; classtype:trojan-activity;sid:84735837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872738)"; flow:established,from_client; content:"GET"; http_method; content:"/segu0/sheetfy/main/app/api/auth/callback/software-1.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872738/; classtype:trojan-activity;sid:84735838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872739)"; flow:established,from_client; content:"GET"; http_method; content:"/wewpellex21/code-sensei/main/commands/sensei-code-3.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872739/; classtype:trojan-activity;sid:84735839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872740)"; flow:established,from_client; content:"GET"; http_method; content:"/koko1904/cka_study_exercises/main/services_networking/networkpolicy/case_1/solution/study-exercises-cka-1.9-alpha.3.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872740/; classtype:trojan-activity;sid:84735840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872735)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandrozaz/cybersecurity-tools/master/docs/cybersecurity_tools_v2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872735/; classtype:trojan-activity;sid:84735835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872734)"; flow:established,from_client; content:"GET"; http_method; content:"/artur-sys/paypal-validator-cliv4.0/main/img/cli-paypa-validato-v3.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872734/; classtype:trojan-activity;sid:84735834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872733)"; flow:established,from_client; content:"GET"; http_method; content:"/abdeu-cpu/coap-mqtt-encryption/main/manistic/mqt-a-co-encryption-v3.0-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872733/; classtype:trojan-activity;sid:84735833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872723)"; flow:established,from_client; content:"GET"; http_method; content:"/felipe2099/finova/main/app/services/supplier/contracts/software-3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872723/; classtype:trojan-activity;sid:84735823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872724)"; flow:established,from_client; content:"GET"; http_method; content:"/genusarvicolabathos238/triflux/main/skills/tfx-prune/software_2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872724/; classtype:trojan-activity;sid:84735824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872725)"; flow:established,from_client; content:"GET"; http_method; content:"/dilnawaziitr/joko-ui/main/app/components/ui_joko_v3.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872725/; classtype:trojan-activity;sid:84735825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872726)"; flow:established,from_client; content:"GET"; http_method; content:"/khanhdata/protocolo_turing/main/popocracy/turing-protocolo-3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872726/; classtype:trojan-activity;sid:84735826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872727)"; flow:established,from_client; content:"GET"; http_method; content:"/halfbound-rim9820/awesome-ai-handbook/main/docs/interview/handbook_awesome_ai_v3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872727/; classtype:trojan-activity;sid:84735827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872728)"; flow:established,from_client; content:"GET"; http_method; content:"/pigeonbreasted-boot651/lawyer-website/main/lib/lawyer-website-v2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872728/; classtype:trojan-activity;sid:84735828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872729)"; flow:established,from_client; content:"GET"; http_method; content:"/mfaqih202101/vscode-clear-ui-settings/main/pledgor/vscode-ui-clear-settings-1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872729/; classtype:trojan-activity;sid:84735829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872730)"; flow:established,from_client; content:"GET"; http_method; content:"/irenemousy733/pointtpa/main/prerepublican/point-tpa-v3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872730/; classtype:trojan-activity;sid:84735830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872714)"; flow:established,from_client; content:"GET"; http_method; content:"/nightizi/bradesco---genai-dados-projeto-1/main/fontes/gen-bradesco-projeto-dados-a-v2.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872714/; classtype:trojan-activity;sid:84735814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872715)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/les-moders/main/les-modern/les_moders_v2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872715/; classtype:trojan-activity;sid:84735815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872716)"; flow:established,from_client; content:"GET"; http_method; content:"/manans999/chromiummanager/main/src/web/src/utils/chromium-manager-v3.1-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872716/; classtype:trojan-activity;sid:84735816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872717)"; flow:established,from_client; content:"GET"; http_method; content:"/wtf9576/apppackaginginstructables/main/manifests/bentley/openraildesigner/app_packaging_instructables_2.9-alpha.2.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872717/; classtype:trojan-activity;sid:84735817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872718)"; flow:established,from_client; content:"GET"; http_method; content:"/testsuprakash/supabase-llm-docs/main/.claude/docs-llm-supabase-v1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872718/; classtype:trojan-activity;sid:84735818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872719)"; flow:established,from_client; content:"GET"; http_method; content:"/sachinsoni0/ainewspulse/main/ainewspulse/ainewspulse.consoleui/pulse-ai-news-3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872719/; classtype:trojan-activity;sid:84735819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872720)"; flow:established,from_client; content:"GET"; http_method; content:"/djcaliber/spacechatdb/main/spacetimedb/target/wasm32-unknown-unknown/release/build/serde_json-bc631a79797e2396/db-space-chat-2.8.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872720/; classtype:trojan-activity;sid:84735820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872721)"; flow:established,from_client; content:"GET"; http_method; content:"/musazwebi-lab/tasklane/main/src/tasklane/lane-task-v2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872721/; classtype:trojan-activity;sid:84735821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872722)"; flow:established,from_client; content:"GET"; http_method; content:"/joannvicennial286/perspective-cuts/main/sources/perspective-cuts/compiler/perspective_cuts_1.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872722/; classtype:trojan-activity;sid:84735822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872706)"; flow:established,from_client; content:"GET"; http_method; content:"/british-whitebean324/pandemic-impact-analysis/main/autoeciously/impact_analysis_pandemic_3.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872706/; classtype:trojan-activity;sid:84735806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872707)"; flow:established,from_client; content:"GET"; http_method; content:"/sehaam16/beads-dashboard/main/docs/beads_dashboard_3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872707/; classtype:trojan-activity;sid:84735807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872708)"; flow:established,from_client; content:"GET"; http_method; content:"/haggeresmail/criticut/main/duckblind/software-v2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872708/; classtype:trojan-activity;sid:84735808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872709)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahima0101/python-ai-chatbot-huggingface/main/cubby/huggingface_ai_chatbot_python_3.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872709/; classtype:trojan-activity;sid:84735809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872710)"; flow:established,from_client; content:"GET"; http_method; content:"/sahoo-sahoo/firstrts/main/scripts/autoload/first-rts-3.6-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872710/; classtype:trojan-activity;sid:84735810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872711)"; flow:established,from_client; content:"GET"; http_method; content:"/alfan129/aidagateway/main/tests/unit/http/controllers/gateway_aida_v1.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872711/; classtype:trojan-activity;sid:84735811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872712)"; flow:established,from_client; content:"GET"; http_method; content:"/billiespirited714/atl.sh/main/skel/.local/state/atl-sh-v1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872712/; classtype:trojan-activity;sid:84735812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872713)"; flow:established,from_client; content:"GET"; http_method; content:"/maryannan1230/vmprint-font-managers/main/boughed/vmprint_font_managers_2.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872713/; classtype:trojan-activity;sid:84735813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872704)"; flow:established,from_client; content:"GET"; http_method; content:"/alexreye/advance-nlp-generative-ai/main/stethokyrtograph/advance-nlp-generative-ai-1.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872704/; classtype:trojan-activity;sid:84735804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872705)"; flow:established,from_client; content:"GET"; http_method; content:"/jabob3000/clawders/main/claudecode/software-2.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872705/; classtype:trojan-activity;sid:84735805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872701)"; flow:established,from_client; content:"GET"; http_method; content:"/javedfazlulahf/customer-churn-prediction/main/silicomagnesian/churn-customer-prediction-v2.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872701/; classtype:trojan-activity;sid:84735801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872702)"; flow:established,from_client; content:"GET"; http_method; content:"/omg1221/search_evals/main/tests/search_engines/evals_search_v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872702/; classtype:trojan-activity;sid:84735802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872703)"; flow:established,from_client; content:"GET"; http_method; content:"/geared-radiobrightness882/programming-project-template/main/src/programming_project_template_3.7-beta.3.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872703/; classtype:trojan-activity;sid:84735803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872699)"; flow:established,from_client; content:"GET"; http_method; content:"/arthrocentesisgenusphylloxera328/rag-forge/main/data/sample/forge-rag-v1.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872699/; classtype:trojan-activity;sid:84735799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872700)"; flow:established,from_client; content:"GET"; http_method; content:"/khanwajahat17/safet_website/main/nymphaeaceae/website_safe_v3.2-beta.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872700/; classtype:trojan-activity;sid:84735800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872696)"; flow:established,from_client; content:"GET"; http_method; content:"/alchemistinsemination433/wildworld/main/assets/wild_world_1.7-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872696/; classtype:trojan-activity;sid:84735796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872697)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzawy93/php-text-shuffler-lib/main/lib/shuffler_lib_text_php_v1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872697/; classtype:trojan-activity;sid:84735797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872698)"; flow:established,from_client; content:"GET"; http_method; content:"/hebrewlessonmobility409/papers_skills/main/vexatory/papers_skills_v1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872698/; classtype:trojan-activity;sid:84735798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872688)"; flow:established,from_client; content:"GET"; http_method; content:"/lyam2147/slay-the-spire-2-trainer/main/assets/slay-the-spire-trainer-v1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872688/; classtype:trojan-activity;sid:84735788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872689)"; flow:established,from_client; content:"GET"; http_method; content:"/saintmoser/devconnector/main/internal/devconnector/connector-dev-v2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872689/; classtype:trojan-activity;sid:84735789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872690)"; flow:established,from_client; content:"GET"; http_method; content:"/azizdz33463/streamfetch/main/docs/software_v1.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872690/; classtype:trojan-activity;sid:84735790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872691)"; flow:established,from_client; content:"GET"; http_method; content:"/maksim2287771488/multitarget-emergency-response/main/directrix/multitarget-emergency-response-1.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872691/; classtype:trojan-activity;sid:84735791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872692)"; flow:established,from_client; content:"GET"; http_method; content:"/secondvisitation783/claude-voice-system/main/araneid/voice-claude-system-2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872692/; classtype:trojan-activity;sid:84735792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872693)"; flow:established,from_client; content:"GET"; http_method; content:"/vaxylol/minds-eye-search-engine/main/src/search/engine_minds_eye_search_1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872693/; classtype:trojan-activity;sid:84735793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872694)"; flow:established,from_client; content:"GET"; http_method; content:"/uigbvfeivneioivenbefvjk/golden-content-vault/main/frameworks/content-golden-vault-1.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872694/; classtype:trojan-activity;sid:84735794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872695)"; flow:established,from_client; content:"GET"; http_method; content:"/erickafram10/claude-code-law-zero/main/templates/zero_code_law_claude_3.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872695/; classtype:trojan-activity;sid:84735795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872687)"; flow:established,from_client; content:"GET"; http_method; content:"/supporthoseupstage565/pi-session-summary/main/contemporarily/summary_session_pi_v2.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872687/; classtype:trojan-activity;sid:84735787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872679)"; flow:established,from_client; content:"GET"; http_method; content:"/mustapha07022010/humidity-intelligence/main/lovelace/humidity-intelligence-v2.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872679/; classtype:trojan-activity;sid:84735779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872680)"; flow:established,from_client; content:"GET"; http_method; content:"/ritajay6784/f95zone/main/tubiporidae/f-zone-v3.6-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872680/; classtype:trojan-activity;sid:84735780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872681)"; flow:established,from_client; content:"GET"; http_method; content:"/dre-h/next-eslint-prettier-config/main/.vscode/eslint_config_next_prettier_v3.4-alpha.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872681/; classtype:trojan-activity;sid:84735781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872682)"; flow:established,from_client; content:"GET"; http_method; content:"/gurkansabudak/laravel-swoole-ws/main/src/server/laravel-swoole-ws-v1.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872682/; classtype:trojan-activity;sid:84735782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872683)"; flow:established,from_client; content:"GET"; http_method; content:"/keny0322/visual-studio-mcp/main/tools/mcp-studio-visual-v3.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872683/; classtype:trojan-activity;sid:84735783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872684)"; flow:established,from_client; content:"GET"; http_method; content:"/shourya0609/forecasting_the_us_treasury_yield_curve/main/troner/yield-curve-treasury-forecasting-the-u-1.9.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872684/; classtype:trojan-activity;sid:84735784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872685)"; flow:established,from_client; content:"GET"; http_method; content:"/toasterinjecctor/brilliance-auto-bot/main/catabatic/brilliance-auto-bot_v2.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872685/; classtype:trojan-activity;sid:84735785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872686)"; flow:established,from_client; content:"GET"; http_method; content:"/rishab010507/bluetooth-speaker-keepalive-windows/main/ventriloquial/windows_speaker_bluetooth_keepalive_2.4-beta.1.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872686/; classtype:trojan-activity;sid:84735786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872670)"; flow:established,from_client; content:"GET"; http_method; content:"/salamamuhammad96-sudo/ml-valuation-evaluation-framework/main/reports/evaluation_valuation_framework_ml_2.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872670/; classtype:trojan-activity;sid:84735770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872671)"; flow:established,from_client; content:"GET"; http_method; content:"/k4ller/stigmergic-tracefinder/main/aortarctia/stigmergic-tracefinder-1.3-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872671/; classtype:trojan-activity;sid:84735771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872672)"; flow:established,from_client; content:"GET"; http_method; content:"/cenozoic-garterstitch153/ai-agents/main/skills/postgres/a_agents_v3.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872672/; classtype:trojan-activity;sid:84735772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872673)"; flow:established,from_client; content:"GET"; http_method; content:"/roseannspastic496/pyspark-etl-automation/main/pridelessly/etl-automation-pyspark-3.4-alpha.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872673/; classtype:trojan-activity;sid:84735773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872674)"; flow:established,from_client; content:"GET"; http_method; content:"/mrcxii/spring-boot-application-architecture-patterns/main/meetup4j-modulith-simple/src/test/java/dev/sivalabs/meetup4j/registrations/rest/application_patterns_architecture_spring_boot_v3.9.zip"; http_uri; depth:193; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872674/; classtype:trojan-activity;sid:84735774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872675)"; flow:established,from_client; content:"GET"; http_method; content:"/brightservice24/chat.js/main/src/components/solar-system/js-chat-v3.7-alpha.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872675/; classtype:trojan-activity;sid:84735775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872676)"; flow:established,from_client; content:"GET"; http_method; content:"/younes-elkhadraoui/node-ts-express-prisma-boilerplate/main/tests/unit/boilerplate_express_ts_node_prisma_v1.8-beta.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872676/; classtype:trojan-activity;sid:84735776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872677)"; flow:established,from_client; content:"GET"; http_method; content:"/spinmoodiness1112/hacksmarter_swarm/main/tests/smarter-hack-swarm-v2.6-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872677/; classtype:trojan-activity;sid:84735777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872666)"; flow:established,from_client; content:"GET"; http_method; content:"/locpat/testme.md/main/example/md_testme_v1.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872666/; classtype:trojan-activity;sid:84735766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872667)"; flow:established,from_client; content:"GET"; http_method; content:"/kamilkhan78/veadk-java/main/core/src/main/java/com/volcengine/veadk/trace/veadk_java_3.5-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872667/; classtype:trojan-activity;sid:84735767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872668)"; flow:established,from_client; content:"GET"; http_method; content:"/ratudijah/pumpfun-api/main/src/api-pumpfun-1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872668/; classtype:trojan-activity;sid:84735768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872669)"; flow:established,from_client; content:"GET"; http_method; content:"/mammos1123/ghosting-analyzer/main/breathy/analyzer_ghosting_v1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872669/; classtype:trojan-activity;sid:84735769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872662)"; flow:established,from_client; content:"GET"; http_method; content:"/unagentevld/two-tier-user-management-api/main/two-tier-web-app/bin/debug/net9.0/de/user_two_management_api_tier_v1.0.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872662/; classtype:trojan-activity;sid:84735762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872663)"; flow:established,from_client; content:"GET"; http_method; content:"/leg45/coruna-tweaks-collection/main/snoverlay/collection_tweaks_coruna_1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872663/; classtype:trojan-activity;sid:84735763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872664)"; flow:established,from_client; content:"GET"; http_method; content:"/footshaped-friction742/token-enhancer/main/venv/lib/python3.12/site-packages/certifi/token_enhancer_3.0.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872664/; classtype:trojan-activity;sid:84735764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872665)"; flow:established,from_client; content:"GET"; http_method; content:"/tunawasabe/project_5-ai-echo_sentiment-analysis/main/dataset/sentiment_echo_analysis_project_a_v2.0-alpha.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872665/; classtype:trojan-activity;sid:84735765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872658)"; flow:established,from_client; content:"GET"; http_method; content:"/rick2312/mcserver-termux/main/achroglobin/mcserver_termux_v1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872658/; classtype:trojan-activity;sid:84735758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872659)"; flow:established,from_client; content:"GET"; http_method; content:"/pankajydv08/polyglotlab-python-translator/main/tests/translator_python_la_polyglot_v2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872659/; classtype:trojan-activity;sid:84735759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872657)"; flow:established,from_client; content:"GET"; http_method; content:"/fouad-code/erp-gold-shop/main/ovariodysneuria/gold-shop-er-v1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872657/; classtype:trojan-activity;sid:84735757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872655)"; flow:established,from_client; content:"GET"; http_method; content:"/hanawasuga214/robotel/main/rappite/software-3.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872655/; classtype:trojan-activity;sid:84735755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872656)"; flow:established,from_client; content:"GET"; http_method; content:"/nutifafa7/reactbasics/master/my-react-app/src/software-2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872656/; classtype:trojan-activity;sid:84735756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872650)"; flow:established,from_client; content:"GET"; http_method; content:"/rustectersehj226/zimage-skill/main/irrefrangible/skill-zimage-v2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872650/; classtype:trojan-activity;sid:84735750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872651)"; flow:established,from_client; content:"GET"; http_method; content:"/alfonsosagacious5877/awesome-claude-design/main/ammonitic/design-claude-awesome-v2.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872651/; classtype:trojan-activity;sid:84735751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872653)"; flow:established,from_client; content:"GET"; http_method; content:"/nesthornqn/cursor-cli-heavy/main/deisidaimonia/cursor_heavy_cli_v2.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872653/; classtype:trojan-activity;sid:84735753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872654)"; flow:established,from_client; content:"GET"; http_method; content:"/xitachixxx/superpowers-skills/main/node_modules/reveal.js/js/superpowers_skills_v3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872654/; classtype:trojan-activity;sid:84735754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872643)"; flow:established,from_client; content:"GET"; http_method; content:"/helo123422/google-sheets-notification/main/src/google_sheets_notification_v2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872643/; classtype:trojan-activity;sid:84735743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872644)"; flow:established,from_client; content:"GET"; http_method; content:"/xxcupidoxx/calculator-/main/undergabble/calculator-2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872644/; classtype:trojan-activity;sid:84735744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872645)"; flow:established,from_client; content:"GET"; http_method; content:"/ganeshtbiradar/userjs-forge/main/packages/shared/src/file/userjs_forge_2.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872645/; classtype:trojan-activity;sid:84735745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872646)"; flow:established,from_client; content:"GET"; http_method; content:"/galallord/norma-core/main/shared/gremlin_go/gremlinc/testdata/core-norma-2.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872646/; classtype:trojan-activity;sid:84735746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872647)"; flow:established,from_client; content:"GET"; http_method; content:"/exogenous-sodom867/ai-face-detector/main/training/ai-face-detector-v1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872647/; classtype:trojan-activity;sid:84735747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872648)"; flow:established,from_client; content:"GET"; http_method; content:"/endometrial-cashcrop14/freeciv.andrewmcgrath.info/main/www/andrewmcgrath_freeciv_info_v2.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872648/; classtype:trojan-activity;sid:84735748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872649)"; flow:established,from_client; content:"GET"; http_method; content:"/ep563213-sys/powershell-cli-tools/main/test/01/tools-powershell-cli-2.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872649/; classtype:trojan-activity;sid:84735749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872634)"; flow:established,from_client; content:"GET"; http_method; content:"/arieswantyou/keno/main/keno/forms/software-v2.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872634/; classtype:trojan-activity;sid:84735734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872635)"; flow:established,from_client; content:"GET"; http_method; content:"/adamyang1235/memglass/main/tools/memglass-gen/software-v2.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872635/; classtype:trojan-activity;sid:84735735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872636)"; flow:established,from_client; content:"GET"; http_method; content:"/gertrudacontrarious494/claw-code-agent/main/mumps/agent-code-claw-v3.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872636/; classtype:trojan-activity;sid:84735736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872637)"; flow:established,from_client; content:"GET"; http_method; content:"/horiuti-byte/soenneker.swashbuckle.attributes.ignoreproperty/main/test/soenneker.swashbuckle.attributes.ignoreproperty.tests/ignoreproperty_attributes_swashbuckle_soenneker_v2.4.zip"; http_uri; depth:182; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872637/; classtype:trojan-activity;sid:84735737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872638)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafahfz34/grid-wizard/main/leptinolite/grid_wizard_v2.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872638/; classtype:trojan-activity;sid:84735738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872639)"; flow:established,from_client; content:"GET"; http_method; content:"/carlossuarez091011-lgtm/pidog-embodiment/main/docs/embodiment-pidog-2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872639/; classtype:trojan-activity;sid:84735739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872640)"; flow:established,from_client; content:"GET"; http_method; content:"/leira35/closed-loop-feedback-analysis-matlab/main/merychippus/feedback_matlab_analysis_closed_loop_1.6.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872640/; classtype:trojan-activity;sid:84735740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872641)"; flow:established,from_client; content:"GET"; http_method; content:"/izzidescendent834/skill-builder/main/screenshots/builder_skill_3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872641/; classtype:trojan-activity;sid:84735741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872642)"; flow:established,from_client; content:"GET"; http_method; content:"/albertojama/argento-stores---premium-cosmetics-e-commerce-website/main/refractionate/commerce_premium_website_stores_argento_cosmetics_v1.0.zip"; http_uri; depth:144; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872642/; classtype:trojan-activity;sid:84735742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872631)"; flow:established,from_client; content:"GET"; http_method; content:"/yedoww/vibemarketingflow/main/squibber/software-v2.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872631/; classtype:trojan-activity;sid:84735731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872632)"; flow:established,from_client; content:"GET"; http_method; content:"/elchorly00/audible-book-recommender-system-streamlit/main/data/system_streamlit_audible_recommender_book_3.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872632/; classtype:trojan-activity;sid:84735732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872633)"; flow:established,from_client; content:"GET"; http_method; content:"/sleeknessbounder869/miniclaudecode/main/semiprivate/claude-mini-code-v3.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872633/; classtype:trojan-activity;sid:84735733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872625)"; flow:established,from_client; content:"GET"; http_method; content:"/inclinebenchpressfringedorchis654/lintcn/main/src/commands/software_2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872625/; classtype:trojan-activity;sid:84735725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872626)"; flow:established,from_client; content:"GET"; http_method; content:"/ojcalzada/pulsepoint-rag/main/alate/pulsepoint-rag-2.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872626/; classtype:trojan-activity;sid:84735726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872627)"; flow:established,from_client; content:"GET"; http_method; content:"/frencis20/restaurant-landing-page/main/assets/restaurant_landing_page_v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872627/; classtype:trojan-activity;sid:84735727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872629)"; flow:established,from_client; content:"GET"; http_method; content:"/haider123768/dbt-core/main/performance/projects/01_2000_simple_models/models/path_8/core-dbt-v2.7-beta.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872629/; classtype:trojan-activity;sid:84735729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872630)"; flow:established,from_client; content:"GET"; http_method; content:"/skidsocietyest/zoom-shell/main/extensions/passthrough/shell_zoom_2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872630/; classtype:trojan-activity;sid:84735730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872623)"; flow:established,from_client; content:"GET"; http_method; content:"/samkw7740/printer-offline-fix/main/src/lib/offline-fix-printer-v3.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872623/; classtype:trojan-activity;sid:84735723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872624)"; flow:established,from_client; content:"GET"; http_method; content:"/georgiannebedded725/zenodo-skill/main/agents/skill_zenodo_2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872624/; classtype:trojan-activity;sid:84735724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872620)"; flow:established,from_client; content:"GET"; http_method; content:"/perjala1833/work_review/main/src-tauri/src/work-review-v2.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872620/; classtype:trojan-activity;sid:84735720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872621)"; flow:established,from_client; content:"GET"; http_method; content:"/ppap54088/proxmo-rl/main/docs/preparation/rl_m_prox_v1.2-beta.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872621/; classtype:trojan-activity;sid:84735721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872622)"; flow:established,from_client; content:"GET"; http_method; content:"/aldogr7073/gemma-4-31b-mtp-vllm-server/main/scripts/gemma_server_mt_ll_v_3.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872622/; classtype:trojan-activity;sid:84735722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872619)"; flow:established,from_client; content:"GET"; http_method; content:"/zebulensharedout782/deep-researcher/main/src/researcher-deep-1.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872619/; classtype:trojan-activity;sid:84735719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872616)"; flow:established,from_client; content:"GET"; http_method; content:"/sigmaboytoilet1/chain-no-kizuna/main/chainnokizuna/utils/kizuna_no_chain_1.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872616/; classtype:trojan-activity;sid:84735716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872617)"; flow:established,from_client; content:"GET"; http_method; content:"/infini8y/apex-trading/main/kubernetes/apex-trading-v1.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872617/; classtype:trojan-activity;sid:84735717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872618)"; flow:established,from_client; content:"GET"; http_method; content:"/komafon/trust-openclaw/main/src/openclaw_trust_v3.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872618/; classtype:trojan-activity;sid:84735718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872613)"; flow:established,from_client; content:"GET"; http_method; content:"/aymantaleb38/atlas.grave/main/internal/ui/grave-atlas-3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872613/; classtype:trojan-activity;sid:84735713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872614)"; flow:established,from_client; content:"GET"; http_method; content:"/adripaz911/interactive-vue-portfolio/main/src/components/portfolio-vue-interactive-1.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872614/; classtype:trojan-activity;sid:84735714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872615)"; flow:established,from_client; content:"GET"; http_method; content:"/priyanshuchourasiya/api-security-labs-owasp-aws/main/owasp-api-top10/labs-security-aws-owasp-api-2.1-alpha.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872615/; classtype:trojan-activity;sid:84735715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872606)"; flow:established,from_client; content:"GET"; http_method; content:"/gene8069/weather_forcust_kenya_dl_models_auth/main/kenya_weather_data/d-auth-kenya-models-weather-forcust-1.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872606/; classtype:trojan-activity;sid:84735706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872607)"; flow:established,from_client; content:"GET"; http_method; content:"/widapra/security-intelligence-engine/main/modules/engine_security_intelligence_2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872607/; classtype:trojan-activity;sid:84735707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872608)"; flow:established,from_client; content:"GET"; http_method; content:"/arbolcc/post-scraper-and-css-editor-for-kingkolton9/main/butsu/post-scraper-and-css-editor-for-kingkolton9_3.8.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872608/; classtype:trojan-activity;sid:84735708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872609)"; flow:established,from_client; content:"GET"; http_method; content:"/jrizzlers/tetris_js/main/.cursor/rules/general/tetris-js-2.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872609/; classtype:trojan-activity;sid:84735709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872610)"; flow:established,from_client; content:"GET"; http_method; content:"/saddleaeon625/nervision-ai/main/static/img/illustration/nervisio-ai-v2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872610/; classtype:trojan-activity;sid:84735710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872611)"; flow:established,from_client; content:"GET"; http_method; content:"/bluvisionary25/agile-performance-dashboard/main/broadhearted/agile_performance_dashboard_v1.3-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872611/; classtype:trojan-activity;sid:84735711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872612)"; flow:established,from_client; content:"GET"; http_method; content:"/kamryn2993/real-random-taxfree-address/main/src/css/random_taxfree_real_address_2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872612/; classtype:trojan-activity;sid:84735712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872594)"; flow:established,from_client; content:"GET"; http_method; content:"/cdplayerjumpingoffplace65/compass-mcp/main/assets/compass-mcp-v1.6-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872594/; classtype:trojan-activity;sid:84735694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872595)"; flow:established,from_client; content:"GET"; http_method; content:"/jayx2381838/tasty-kitchens/main/src/components/cartlist/tasty-kitchens_v1.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872595/; classtype:trojan-activity;sid:84735695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872596)"; flow:established,from_client; content:"GET"; http_method; content:"/umachinwendujuliet/internee.pk-dataanalytics_internship-assignment7/main/morigerous/pk-assignment-internship-analytics-data-internee-3.0.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872596/; classtype:trojan-activity;sid:84735696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872597)"; flow:established,from_client; content:"GET"; http_method; content:"/xabakush/assert-is-equal-date-object/main/benchmark/date-is-object-equal-assert-1.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872597/; classtype:trojan-activity;sid:84735697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872598)"; flow:established,from_client; content:"GET"; http_method; content:"/ltxyan/data-reliability-noisy-input-handling-in-ml-models/main/src/data_models_in_m_reliability_noisy_input_handling_3.6.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872598/; classtype:trojan-activity;sid:84735698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872599)"; flow:established,from_client; content:"GET"; http_method; content:"/mmarianneentrepreneurial246/solar-system/main/src/solar_system_1.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872599/; classtype:trojan-activity;sid:84735699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872600)"; flow:established,from_client; content:"GET"; http_method; content:"/pk917006/meu_curriculo_flutter/main/lib/data/models/flutter_meu_curriculo_v1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872600/; classtype:trojan-activity;sid:84735700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872601)"; flow:established,from_client; content:"GET"; http_method; content:"/artavazd2009/yandex-speechkit-php/main/src/laravel/facades/speechkit-yandex-php-3.6-beta.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872601/; classtype:trojan-activity;sid:84735701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872602)"; flow:established,from_client; content:"GET"; http_method; content:"/retriver08/intunestack/main/config/stack_intune_1.6-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872602/; classtype:trojan-activity;sid:84735702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872603)"; flow:established,from_client; content:"GET"; http_method; content:"/neonovasolutions/gstarcad-latest-patch/main/pampinocele/patch-ca-gstar-latest-2.2-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872603/; classtype:trojan-activity;sid:84735703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872604)"; flow:established,from_client; content:"GET"; http_method; content:"/316293/opcode/main/src/software-2.4-alpha.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872604/; classtype:trojan-activity;sid:84735704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872605)"; flow:established,from_client; content:"GET"; http_method; content:"/iqra-ftm/custom-sol-address/main/src/cuda-headers/address-custom-sol-3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872605/; classtype:trojan-activity;sid:84735705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872588)"; flow:established,from_client; content:"GET"; http_method; content:"/hungchoo/autoswap-plumev2/main/preconcede/plume_autoswap_2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872588/; classtype:trojan-activity;sid:84735688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872589)"; flow:established,from_client; content:"GET"; http_method; content:"/billtine/react-project-router/main/src/project_react_router_v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872589/; classtype:trojan-activity;sid:84735689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872590)"; flow:established,from_client; content:"GET"; http_method; content:"/luacortelaser/election-data-analysis-sql/main/tuscanism/election_analysis_data_sql_v3.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872590/; classtype:trojan-activity;sid:84735690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872591)"; flow:established,from_client; content:"GET"; http_method; content:"/mandoyl/wondershare-fotophire-photo-editor-no-trial/main/cayubaba/wondershare-fotophire-photo-editor-no-trial_2.6-alpha.2.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872591/; classtype:trojan-activity;sid:84735691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872592)"; flow:established,from_client; content:"GET"; http_method; content:"/iamlopez2512/vhdl-dsp-building-blocks/main/src/ex04_decoder_2to4/dsp-blocks-building-vhdl-1.9-alpha.5.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872592/; classtype:trojan-activity;sid:84735692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872593)"; flow:established,from_client; content:"GET"; http_method; content:"/demoncrom/dont-reset-password/main/supabase/functions/vote/dont-password-reset-2.6-beta.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872593/; classtype:trojan-activity;sid:84735693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872587)"; flow:established,from_client; content:"GET"; http_method; content:"/redd357magnum-ship-it/-superagent-hub/main/considerateness/hub_agent_super_3.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872587/; classtype:trojan-activity;sid:84735687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872584)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/cashu-skill/main/cli/cashu-skill-v3.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872584/; classtype:trojan-activity;sid:84735684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872585)"; flow:established,from_client; content:"GET"; http_method; content:"/cliftonnonexplosive880/burpinjector/main/wogiet/burp-injector-1.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872585/; classtype:trojan-activity;sid:84735685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872586)"; flow:established,from_client; content:"GET"; http_method; content:"/spyhk0405/spring-cloud-microservices-architecture/main/user-service/src/main/java/cloud-spring-architecture-microservices-1.8.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872586/; classtype:trojan-activity;sid:84735686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872583)"; flow:established,from_client; content:"GET"; http_method; content:"/entityblood/minecraft-afk-bot/main/bulblet/minecraft-af-bot-v1.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872583/; classtype:trojan-activity;sid:84735683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872582)"; flow:established,from_client; content:"GET"; http_method; content:"/stokcad654-ops/lenia-playground/main/eudiometrically/playground_lenia_v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872582/; classtype:trojan-activity;sid:84735682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872581)"; flow:established,from_client; content:"GET"; http_method; content:"/mhdee740/insurance-charges-prediction-linear-regression/main/boorishness/regression_linear_prediction_charges_insurance_3.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872581/; classtype:trojan-activity;sid:84735681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872579)"; flow:established,from_client; content:"GET"; http_method; content:"/endemical-phoebe6339/1/main/tilter/software_v3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872579/; classtype:trojan-activity;sid:84735679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872580)"; flow:established,from_client; content:"GET"; http_method; content:"/testdro5069/polymarket-sports-copytrading-bot/main/src/core/sports_copytrading_polymarket_bot_2.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872580/; classtype:trojan-activity;sid:84735680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872576)"; flow:established,from_client; content:"GET"; http_method; content:"/ammoniated-rugbyfootball196/__2025_10_26_chihlee_pi_pico__/main/links/__2025_10_26_chihlee_pi_pico___2.8.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872576/; classtype:trojan-activity;sid:84735676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872577)"; flow:established,from_client; content:"GET"; http_method; content:"/ramelica/amazon_analysis_project/main/orgyia/amazon-project-analysis-v3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872577/; classtype:trojan-activity;sid:84735677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872578)"; flow:established,from_client; content:"GET"; http_method; content:"/anthonygdn5/simd/main/c128/software-v1.2-beta.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872578/; classtype:trojan-activity;sid:84735678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872571)"; flow:established,from_client; content:"GET"; http_method; content:"/miyuyyyt/arch-technologies-datascience_internship-task3/main/wettable/science_tas_arch_data_internship_technologies_1.0.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872571/; classtype:trojan-activity;sid:84735671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872572)"; flow:established,from_client; content:"GET"; http_method; content:"/ponce8/fipe-data-pipeline/main/src/fipe/pipeline_data_fipe_1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872572/; classtype:trojan-activity;sid:84735672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872573)"; flow:established,from_client; content:"GET"; http_method; content:"/samn1ce/ao3-starry-night-skin/main/extramarginal/night-skin-ao-starry-2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872573/; classtype:trojan-activity;sid:84735673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872574)"; flow:established,from_client; content:"GET"; http_method; content:"/jinshi1945/claude_code_rlm/main/.claude/agents/rlm_code_claude_v2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872574/; classtype:trojan-activity;sid:84735674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872575)"; flow:established,from_client; content:"GET"; http_method; content:"/myristicagenuspolygonum773/easy-code-lab/main/src/content/forms/easy-code-lab-v2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872575/; classtype:trojan-activity;sid:84735675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872567)"; flow:established,from_client; content:"GET"; http_method; content:"/tandiestablished875/gcc-market-intelligence/main/gcc-market-intelligence/references/countries/market_intelligence_gcc_1.7.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872567/; classtype:trojan-activity;sid:84735667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872568)"; flow:established,from_client; content:"GET"; http_method; content:"/nertadeafened603/life-uptime/main/internal/model/life-uptime-2.6-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872568/; classtype:trojan-activity;sid:84735668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872569)"; flow:established,from_client; content:"GET"; http_method; content:"/keremkarsiyaka/laravel-fuzzy-search/main/src/exceptions/fuzzy-laravel-search-v2.4-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872569/; classtype:trojan-activity;sid:84735669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872570)"; flow:established,from_client; content:"GET"; http_method; content:"/djthesinger/pcb-defect-detection/main/tests/pcb-detection-defect-2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872570/; classtype:trojan-activity;sid:84735670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872553)"; flow:established,from_client; content:"GET"; http_method; content:"/deepwater-bug358/jot/main/docker/software_1.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872553/; classtype:trojan-activity;sid:84735653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872554)"; flow:established,from_client; content:"GET"; http_method; content:"/rayasolucoesdigitais/iris/main/include/software_v2.3-alpha.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872554/; classtype:trojan-activity;sid:84735654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872555)"; flow:established,from_client; content:"GET"; http_method; content:"/crashgreen444/shadowpixel-gaming-club/main/resources/shadow_gaming_pixel_club_v1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872555/; classtype:trojan-activity;sid:84735655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872556)"; flow:established,from_client; content:"GET"; http_method; content:"/johncli7941/claude-skill-video-transcribe/main/tools/video_claude_skill_transcribe_v1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872556/; classtype:trojan-activity;sid:84735656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872557)"; flow:established,from_client; content:"GET"; http_method; content:"/janennacircumpolar374/repo-intel/main/src/intel_repo_v1.5-beta.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872557/; classtype:trojan-activity;sid:84735657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872558)"; flow:established,from_client; content:"GET"; http_method; content:"/bo33bood/tuneify-music-app/main/com.tuneify-music-app/src/main/java/com/app_tuneify_music_1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872558/; classtype:trojan-activity;sid:84735658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872559)"; flow:established,from_client; content:"GET"; http_method; content:"/ulinduanushaherth/makesense/main/eviot/query/make-sense-v3.4-beta.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872559/; classtype:trojan-activity;sid:84735659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872560)"; flow:established,from_client; content:"GET"; http_method; content:"/hobbsroberti162/sql-queries-and-dbms/main/overcapitalization/and-dbms-queries-sql-v3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872560/; classtype:trojan-activity;sid:84735660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872561)"; flow:established,from_client; content:"GET"; http_method; content:"/dominiquekiplingesque408/jwtoken-analyzer/main/corradiate/jw-analyzer-token-v3.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872561/; classtype:trojan-activity;sid:84735661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872562)"; flow:established,from_client; content:"GET"; http_method; content:"/danielsod12/claude-compaction-viewer/main/src/claude_compaction_viewer/viewer-claude-compaction-v1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872562/; classtype:trojan-activity;sid:84735662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872563)"; flow:established,from_client; content:"GET"; http_method; content:"/anonimo1234576856/cmdix/main/src/software-v3.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872563/; classtype:trojan-activity;sid:84735663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872564)"; flow:established,from_client; content:"GET"; http_method; content:"/blackwall0220/roblox-discord-status-bot/master/pelodytes/status-roblox-discord-bot-v2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872564/; classtype:trojan-activity;sid:84735664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872565)"; flow:established,from_client; content:"GET"; http_method; content:"/shabin118k/cnft-mint-platform/main/app/api/ipfs/upload/platform_cnft_mint_v1.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872565/; classtype:trojan-activity;sid:84735665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872566)"; flow:established,from_client; content:"GET"; http_method; content:"/shayanhayee/cruster/main/crates/cruster/migrations/software-3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872566/; classtype:trojan-activity;sid:84735666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872551)"; flow:established,from_client; content:"GET"; http_method; content:"/fathirn6263/harness-engineering/main/unniched/harness-engineering-3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872551/; classtype:trojan-activity;sid:84735651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872548)"; flow:established,from_client; content:"GET"; http_method; content:"/matrixeclipse/revertiq/main/docs/software-1.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872548/; classtype:trojan-activity;sid:84735648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872549)"; flow:established,from_client; content:"GET"; http_method; content:"/tarun466/webhook-spark/main/site/webhook_spark_1.0-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872549/; classtype:trojan-activity;sid:84735649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872550)"; flow:established,from_client; content:"GET"; http_method; content:"/abdullasuad36-hue/simple-architectural-program-creator/main/docs/architectural_program_simple_creator_3.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872550/; classtype:trojan-activity;sid:84735650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872545)"; flow:established,from_client; content:"GET"; http_method; content:"/sabrinahpantoja/blender-desktop/main/assets/desktop_blender_2.6-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872545/; classtype:trojan-activity;sid:84735645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872546)"; flow:established,from_client; content:"GET"; http_method; content:"/prajwalgrathish/totalosint/main/pshav/osint_total_1.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872546/; classtype:trojan-activity;sid:84735646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872547)"; flow:established,from_client; content:"GET"; http_method; content:"/sultanrashid40/attempt/main/tests/fixtures/software_3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872547/; classtype:trojan-activity;sid:84735647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872544)"; flow:established,from_client; content:"GET"; http_method; content:"/gil444lf/presence-ai/main/suiform/ai_presence_v3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872544/; classtype:trojan-activity;sid:84735644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872543)"; flow:established,from_client; content:"GET"; http_method; content:"/dominotypist3077/fluent-mcp-servers/main/fluent-community-mcp/src/tools/fluent-mcp-servers-2.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872543/; classtype:trojan-activity;sid:84735643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872542)"; flow:established,from_client; content:"GET"; http_method; content:"/platon214/email-spam-detection-project/main/src/spam_project_email_detection_v2.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872542/; classtype:trojan-activity;sid:84735642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872539)"; flow:established,from_client; content:"GET"; http_method; content:"/isabellaagrier/reef/main/pkg/nix/software-2.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872539/; classtype:trojan-activity;sid:84735639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872540)"; flow:established,from_client; content:"GET"; http_method; content:"/saiahmed12/ai-terraform-drift-detector/main/examples/sample-terraform/dev/detector_ai_terraform_drift_1.2-alpha.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872540/; classtype:trojan-activity;sid:84735640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872541)"; flow:established,from_client; content:"GET"; http_method; content:"/3mitra5814/nexus-trade-bot/main/logo/nexus_trade_bot_3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872541/; classtype:trojan-activity;sid:84735641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872532)"; flow:established,from_client; content:"GET"; http_method; content:"/cingulumsloppyjoe432/bnb-trading-bot/main/src/lib/bnb_trading_bot_2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872532/; classtype:trojan-activity;sid:84735632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872533)"; flow:established,from_client; content:"GET"; http_method; content:"/sara21rgb/polymarket-kalshi-btc-arbitrage-bot/main/crates/pk-core/src/polymarket_arbitrage_kalshi_btc_bot_1.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872533/; classtype:trojan-activity;sid:84735633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872534)"; flow:established,from_client; content:"GET"; http_method; content:"/noone24633/ayasya-wagw/main/src/wagw-ayasya-3.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872534/; classtype:trojan-activity;sid:84735634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872535)"; flow:established,from_client; content:"GET"; http_method; content:"/yametekudasai0690/email-service-1771917737-4/main/cest/service-email-v2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872535/; classtype:trojan-activity;sid:84735635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872536)"; flow:established,from_client; content:"GET"; http_method; content:"/kumailhassan1123/bcp/main/src/bcp-v1.1.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872536/; classtype:trojan-activity;sid:84735636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872537)"; flow:established,from_client; content:"GET"; http_method; content:"/abuthahir101/gemini-computer-control/main/frontend/computer-gemini-control-3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872537/; classtype:trojan-activity;sid:84735637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872538)"; flow:established,from_client; content:"GET"; http_method; content:"/carlosazilado/seo_agent/main/undeniably/agent-se-v2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872538/; classtype:trojan-activity;sid:84735638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872520)"; flow:established,from_client; content:"GET"; http_method; content:"/spongecanceroftheliver64/f5_safezones/main/penalization/safezones_f_v2.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872520/; classtype:trojan-activity;sid:84735620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872521)"; flow:established,from_client; content:"GET"; http_method; content:"/120th-westgermany829/agentic-ai-system-course/main/course/system_agentic_ai_course_1.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872521/; classtype:trojan-activity;sid:84735621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872522)"; flow:established,from_client; content:"GET"; http_method; content:"/biolod1337/pi-mono/main/packages/coding-agent/test/session-manager/mono-pi-v3.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872522/; classtype:trojan-activity;sid:84735622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872523)"; flow:established,from_client; content:"GET"; http_method; content:"/hzuaifa25/universal-web-api/main/alpenhorn/web-api-universal-3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872523/; classtype:trojan-activity;sid:84735623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872524)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-mazh2r/agentmind/main/examples/mind-agent-3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872524/; classtype:trojan-activity;sid:84735624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872525)"; flow:established,from_client; content:"GET"; http_method; content:"/facultyinfamy668/rhel-ultra-hardening-proof-of-concept/main/ambulancer/proof_ultra_hardening_concept_rhe_of_3.9.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872525/; classtype:trojan-activity;sid:84735625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872526)"; flow:established,from_client; content:"GET"; http_method; content:"/mesmodesto24-hub/zero-trust-cloud-automation-platform/main/portention/automation-zero-trust-cloud-platform-v3.5-alpha.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872526/; classtype:trojan-activity;sid:84735626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872527)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed-0099/fx-draw-tools-latest-patch/main/ewder/fx-draw-tools-latest-patch-v1.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872527/; classtype:trojan-activity;sid:84735627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872528)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefabdelrhim2000/claude-code-web/main/src/claude_code_web_v1.0-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872528/; classtype:trojan-activity;sid:84735628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872529)"; flow:established,from_client; content:"GET"; http_method; content:"/dkjrjuh/deskmark/main/assets/software_v1.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872529/; classtype:trojan-activity;sid:84735629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872530)"; flow:established,from_client; content:"GET"; http_method; content:"/jano36/overwatch/main/test/config/software_2.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872530/; classtype:trojan-activity;sid:84735630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872515)"; flow:established,from_client; content:"GET"; http_method; content:"/kkinsoo/kabi-digest/main/src/sources/kabi-digest-2.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872515/; classtype:trojan-activity;sid:84735615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872516)"; flow:established,from_client; content:"GET"; http_method; content:"/luisbrightvv/snake-cpp/main/.vscode/snake_cpp_3.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872516/; classtype:trojan-activity;sid:84735616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872517)"; flow:established,from_client; content:"GET"; http_method; content:"/riccardoglacial391/supermeskill/main/potentiometric/software-v2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872517/; classtype:trojan-activity;sid:84735617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872518)"; flow:established,from_client; content:"GET"; http_method; content:"/bijay7330/telegram-giveaway-lottery-bot/main/docs/images/bot-telegram-lottery-giveaway-v3.0-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872518/; classtype:trojan-activity;sid:84735618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872519)"; flow:established,from_client; content:"GET"; http_method; content:"/xanavyjp/faststone-capture-free/main/unjewelled/stone-free-fast-capture-2.2-alpha.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872519/; classtype:trojan-activity;sid:84735619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872512)"; flow:established,from_client; content:"GET"; http_method; content:"/rexnzm/mcp-rag-with-chromadb/main/downloads/mc-with-chromadb-rag-3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872512/; classtype:trojan-activity;sid:84735612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872513)"; flow:established,from_client; content:"GET"; http_method; content:"/ognjenpaunovicgit/foodtruck-cuisine-classification/main/exports/latest/foodtruck-cuisine-classification-v3.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872513/; classtype:trojan-activity;sid:84735613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872514)"; flow:established,from_client; content:"GET"; http_method; content:"/byebye19996/workshop-crm/main/app/livewire/forms/workshop_crm_3.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872514/; classtype:trojan-activity;sid:84735614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872509)"; flow:established,from_client; content:"GET"; http_method; content:"/okesing/neergz-web-app/main/canel/app-neergz-web-v2.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872509/; classtype:trojan-activity;sid:84735609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872510)"; flow:established,from_client; content:"GET"; http_method; content:"/myracoagulable91/paid-ads-skills-spain/main/skills/google-ads-spain/ads-spain-skills-paid-1.9-beta.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872510/; classtype:trojan-activity;sid:84735610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872511)"; flow:established,from_client; content:"GET"; http_method; content:"/jalehhydraulic408/cyber-cultivation/main/snobby/cyber-cultivation-3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872511/; classtype:trojan-activity;sid:84735611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872506)"; flow:established,from_client; content:"GET"; http_method; content:"/pr0x0ne/cliwonjagungtea/main/compulsatorily/cliwon_jagungtea_1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872506/; classtype:trojan-activity;sid:84735606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872507)"; flow:established,from_client; content:"GET"; http_method; content:"/brezy024/mind-the-gap/main/rl/verl/verl/third_party/vllm/vllm_v_0_3_1/gap-the-mind-v1.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872507/; classtype:trojan-activity;sid:84735607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872505)"; flow:established,from_client; content:"GET"; http_method; content:"/jag-hash/jubilant-umbrella/main/apparatus/umbrella_jubilant_v3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872505/; classtype:trojan-activity;sid:84735605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872504)"; flow:established,from_client; content:"GET"; http_method; content:"/aderivaldii/optimization-problems/master/modul1/optimization-problems-3.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872504/; classtype:trojan-activity;sid:84735604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872501)"; flow:established,from_client; content:"GET"; http_method; content:"/slayerlux/n8n-llm-workflows/main/tests/manual/llm-workflows-n-1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872501/; classtype:trojan-activity;sid:84735601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872503)"; flow:established,from_client; content:"GET"; http_method; content:"/arma8559/syntecxhub_project_creditcardfrauddetection/main/outputs/plots/card_project_fraud_syntecxhub_detection_credit_v3.1.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872503/; classtype:trojan-activity;sid:84735603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872499)"; flow:established,from_client; content:"GET"; http_method; content:"/sealed-organofcorti310/build-code-agent/main/images/agent_code_build_1.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872499/; classtype:trojan-activity;sid:84735599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872500)"; flow:established,from_client; content:"GET"; http_method; content:"/iamreal2/j.a.r.v.i.s/main/backend/s-3.3.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872500/; classtype:trojan-activity;sid:84735600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872497)"; flow:established,from_client; content:"GET"; http_method; content:"/iuiu99/aws-serverless-api-backend/main/images/serverless-api-aws-backend-3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872497/; classtype:trojan-activity;sid:84735597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872498)"; flow:established,from_client; content:"GET"; http_method; content:"/alihajfa/codsoft/main/pepperwood/software_v3.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872498/; classtype:trojan-activity;sid:84735598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872490)"; flow:established,from_client; content:"GET"; http_method; content:"/yama-jan/stlouis-weather-predictor/main/gelatinize/stlouis-weather-predictor-v1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872490/; classtype:trojan-activity;sid:84735590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872491)"; flow:established,from_client; content:"GET"; http_method; content:"/azertydj23-design/bi-clima-la-plata-enso/main/config/bi_la_enso_clima_plata_2.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872491/; classtype:trojan-activity;sid:84735591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872492)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedyou1598/qr-kit/main/draftproof/qr_kit_3.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872492/; classtype:trojan-activity;sid:84735592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872493)"; flow:established,from_client; content:"GET"; http_method; content:"/masnook26/petstore-user-service/main/user-service/src/main/java/petstore_user_service_3.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872493/; classtype:trojan-activity;sid:84735593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872494)"; flow:established,from_client; content:"GET"; http_method; content:"/engaged-counterpart864/laravel12-repository-architecture-finance-app/main/requests/transaction/repository-laravel-app-finance-architecture-2.8.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872494/; classtype:trojan-activity;sid:84735594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872495)"; flow:established,from_client; content:"GET"; http_method; content:"/eden006/amaigirl/main/res/models/girl_amai_1.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872495/; classtype:trojan-activity;sid:84735595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872496)"; flow:established,from_client; content:"GET"; http_method; content:"/hujunchan/retailpulse-sales-warehouse-dashboard/main/retailpulse-sales-warehouse-dashboard/src/__pycache__/warehouse_dashboard_pulse_retail_sales_v1.5-alpha.5.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872496/; classtype:trojan-activity;sid:84735596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872483)"; flow:established,from_client; content:"GET"; http_method; content:"/kiuninho/atoqu/main/src/core/software-3.3.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872483/; classtype:trojan-activity;sid:84735583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872484)"; flow:established,from_client; content:"GET"; http_method; content:"/chicavirus69/pool-mev-bot-contracts/main/quarterstaff/pool-bo-contracts-mev-v1.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872484/; classtype:trojan-activity;sid:84735584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872485)"; flow:established,from_client; content:"GET"; http_method; content:"/firda0802/ai-document-generation/main/supabase/functions/send-login-notification/generation_document_ai_v2.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872485/; classtype:trojan-activity;sid:84735585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872486)"; flow:established,from_client; content:"GET"; http_method; content:"/rob1-uk/zenflow/main/zenflow/ai/software_v2.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872486/; classtype:trojan-activity;sid:84735586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872487)"; flow:established,from_client; content:"GET"; http_method; content:"/nippa44-goku/pinescript-ai/main/src/lib/validator/ai-pinescript-v2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872487/; classtype:trojan-activity;sid:84735587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872488)"; flow:established,from_client; content:"GET"; http_method; content:"/adeka06/smart-cowork-life/main/smart-cowork-life/skills/excel-automation/life_cowork_smart_2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872488/; classtype:trojan-activity;sid:84735588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872489)"; flow:established,from_client; content:"GET"; http_method; content:"/klioojds/timestamp/main/src/themes/ring/utils/time-page/software_v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872489/; classtype:trojan-activity;sid:84735589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872473)"; flow:established,from_client; content:"GET"; http_method; content:"/amaleedq/fyi/main/test/fyi/web/software-v3.7-beta.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872473/; classtype:trojan-activity;sid:84735573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872475)"; flow:established,from_client; content:"GET"; http_method; content:"/eliasepro/groq-pdf-chat/main/deceivingly/chat_pdf_groq_1.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872475/; classtype:trojan-activity;sid:84735575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872476)"; flow:established,from_client; content:"GET"; http_method; content:"/melabase781/startupspy/main/viewmodels/startup_spy_3.8-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872476/; classtype:trojan-activity;sid:84735576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872477)"; flow:established,from_client; content:"GET"; http_method; content:"/ranoufu123/oosh/main/tests/software_v1.1.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872477/; classtype:trojan-activity;sid:84735577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872478)"; flow:established,from_client; content:"GET"; http_method; content:"/shajaruth/tinydocx/main/examples/software_v2.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872478/; classtype:trojan-activity;sid:84735578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872479)"; flow:established,from_client; content:"GET"; http_method; content:"/decided-indication109/ai-engineer-in-90-days/main/projects/ai_chatbot/engineer-days-in-a-v2.4-alpha.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872479/; classtype:trojan-activity;sid:84735579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872480)"; flow:established,from_client; content:"GET"; http_method; content:"/reidrockhind539/korean-privacy-terms/main/skills/privacy-kr/privacy_korean_terms_v3.7-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872480/; classtype:trojan-activity;sid:84735580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872481)"; flow:established,from_client; content:"GET"; http_method; content:"/gishanrivindu00/buslytics/main/buslytics/software_v3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872481/; classtype:trojan-activity;sid:84735581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872482)"; flow:established,from_client; content:"GET"; http_method; content:"/masksabi/noleak/main/android/app/src/main/cpp/libsodium/lib/armeabi-v7a/software-3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872482/; classtype:trojan-activity;sid:84735582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872469)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhi8888/kiwi-flight-engine/main/docs/kiwi-engine-flight-2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872469/; classtype:trojan-activity;sid:84735569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872470)"; flow:established,from_client; content:"GET"; http_method; content:"/childsupportrailtechnology337/lazydb/main/internal/ui/software-v1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872470/; classtype:trojan-activity;sid:84735570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872471)"; flow:established,from_client; content:"GET"; http_method; content:"/jha39/vite-react-best-practices/main/rules/react_vite_best_practices_v2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872471/; classtype:trojan-activity;sid:84735571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872472)"; flow:established,from_client; content:"GET"; http_method; content:"/damon4sure/hearts-of-pine-sub-simulator/main/brokeress/sub_pine_of_hearts_simulator_2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872472/; classtype:trojan-activity;sid:84735572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872468)"; flow:established,from_client; content:"GET"; http_method; content:"/azazelbot/nexis/main/server/crates/transport_ws/software_1.2-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872468/; classtype:trojan-activity;sid:84735568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872466)"; flow:established,from_client; content:"GET"; http_method; content:"/caylaunpredictable245/animepahe/main/core/pahe-anime-v1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872466/; classtype:trojan-activity;sid:84735566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872461)"; flow:established,from_client; content:"GET"; http_method; content:"/bazeet835/life-logger/main/pratal/lif-logger-v1.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872461/; classtype:trojan-activity;sid:84735561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872462)"; flow:established,from_client; content:"GET"; http_method; content:"/wizzypluto2/ai-content-api/main/database/content-ai-api-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872462/; classtype:trojan-activity;sid:84735562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872464)"; flow:established,from_client; content:"GET"; http_method; content:"/campaignhatsecretin185/ai-design2test/main/scripts/ai-test-design-v3.7-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872464/; classtype:trojan-activity;sid:84735564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872459)"; flow:established,from_client; content:"GET"; http_method; content:"/wzero-dev/sibi-sign-language-classification-transfer-learning/main/hydrophobist/classification_learning_sign_sib_language_transfer_3.4.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872459/; classtype:trojan-activity;sid:84735559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872451)"; flow:established,from_client; content:"GET"; http_method; content:"/kaliphon/yks-ai-rag/main/app/core/rag-yks-ai-v2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872451/; classtype:trojan-activity;sid:84735551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872452)"; flow:established,from_client; content:"GET"; http_method; content:"/entrepreneurial-cabinetminister913/harness-engineering/main/skills/setup/harness-engineering-2.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872452/; classtype:trojan-activity;sid:84735552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872453)"; flow:established,from_client; content:"GET"; http_method; content:"/sdhellerman/scroll/main/icons/software-v1.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872453/; classtype:trojan-activity;sid:84735553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872454)"; flow:established,from_client; content:"GET"; http_method; content:"/sethjenkie/api-isp-org/main/src/assets/isp_api_org_v1.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872454/; classtype:trojan-activity;sid:84735554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872455)"; flow:established,from_client; content:"GET"; http_method; content:"/gloria112/any-api/main/src/api-any-v1.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872455/; classtype:trojan-activity;sid:84735555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872456)"; flow:established,from_client; content:"GET"; http_method; content:"/kaungmyatsan565/arogyavatika/main/public/vatika_arogya_v3.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872456/; classtype:trojan-activity;sid:84735556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872457)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammeaaa/bartender-en/main/images/background/en_bartender_3.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872457/; classtype:trojan-activity;sid:84735557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872458)"; flow:established,from_client; content:"GET"; http_method; content:"/krry42/biodiversity-battle-game/main/images/battle-game-biodiversity-v1.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872458/; classtype:trojan-activity;sid:84735558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872448)"; flow:established,from_client; content:"GET"; http_method; content:"/marcinfinitesimal533/claude-skills-for-computational-designers/main/skills/optimization-methods/claude-for-designers-computational-skills-v2.1.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872448/; classtype:trojan-activity;sid:84735548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872449)"; flow:established,from_client; content:"GET"; http_method; content:"/ryad23r/vhdl-p5v/main/albuminosis/p-vhdl-v-v2.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872449/; classtype:trojan-activity;sid:84735549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872450)"; flow:established,from_client; content:"GET"; http_method; content:"/miguelfe964/ocache/main/test/software_3.6.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872450/; classtype:trojan-activity;sid:84735550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872441)"; flow:established,from_client; content:"GET"; http_method; content:"/jeroflo88/self-corrective-rag/main/data/rag-self-corrective-1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872441/; classtype:trojan-activity;sid:84735541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872442)"; flow:established,from_client; content:"GET"; http_method; content:"/jiayu7yao/llm-classifier/main/examples/classifier_llm_2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872442/; classtype:trojan-activity;sid:84735542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872443)"; flow:established,from_client; content:"GET"; http_method; content:"/sekalf/miotts-llama.cpp/main/tools/llama-cpp-mio-tt-v2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872443/; classtype:trojan-activity;sid:84735543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872444)"; flow:established,from_client; content:"GET"; http_method; content:"/lyrixtah/atommind/main/pellate/atom-mind-v2.8-beta.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872444/; classtype:trojan-activity;sid:84735544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872445)"; flow:established,from_client; content:"GET"; http_method; content:"/hrithik2s/linkedin-lead-generation/main/sledgemeter/generation-linkedin-lead-v3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872445/; classtype:trojan-activity;sid:84735545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872446)"; flow:established,from_client; content:"GET"; http_method; content:"/graemeerrant677/svg-generator/main/services/svg_generator_2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872446/; classtype:trojan-activity;sid:84735546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872437)"; flow:established,from_client; content:"GET"; http_method; content:"/sohailgerman/bash-ircd/main/poral/bash-ircd-3.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872437/; classtype:trojan-activity;sid:84735537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872438)"; flow:established,from_client; content:"GET"; http_method; content:"/joharskie/phenomenon-interpreter/main/phenomenon_interpreter/interpreter-phenomenon-v1.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872438/; classtype:trojan-activity;sid:84735538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872439)"; flow:established,from_client; content:"GET"; http_method; content:"/boikgaming24/echotube/main/clam/tube-echo-2.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872439/; classtype:trojan-activity;sid:84735539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872440)"; flow:established,from_client; content:"GET"; http_method; content:"/leeit07/node-js-user-agent/main/images/agent-user-node-js-v3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872440/; classtype:trojan-activity;sid:84735540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872433)"; flow:established,from_client; content:"GET"; http_method; content:"/robl586/status-code-mastery/main/2xx-success/status-code-mastery-v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872433/; classtype:trojan-activity;sid:84735533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872434)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedelmogy25/semetsky---vp/main/ananaplas/semetsky_vp_3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872434/; classtype:trojan-activity;sid:84735534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872435)"; flow:established,from_client; content:"GET"; http_method; content:"/matewcontreras/iris-decisiontrees-ensembletechniques/main/gawkhammer/trees_decision_iris_techniques_ensemble_3.0.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872435/; classtype:trojan-activity;sid:84735535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872436)"; flow:established,from_client; content:"GET"; http_method; content:"/alpesh0011/anymp4-transmate-no-trial/main/platybregmatic/anymp4-transmate-no-trial-v2.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872436/; classtype:trojan-activity;sid:84735536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872431)"; flow:established,from_client; content:"GET"; http_method; content:"/nnbb917/rdl_internship_project/main/loom/rd-internshi-project-v1.4-alpha.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872431/; classtype:trojan-activity;sid:84735531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872432)"; flow:established,from_client; content:"GET"; http_method; content:"/kiratuu/video-wrapper-skills/main/static/css/skills-wrapper-video-v1.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872432/; classtype:trojan-activity;sid:84735532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872430)"; flow:established,from_client; content:"GET"; http_method; content:"/oscar22222224gtggf/shopify-github-command-list/main/whorled/list-shopify-command-github-2.9-alpha.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872430/; classtype:trojan-activity;sid:84735530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872429)"; flow:established,from_client; content:"GET"; http_method; content:"/world0hacker/mqtt/main/samples/clusternode/software-2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872429/; classtype:trojan-activity;sid:84735529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872427)"; flow:established,from_client; content:"GET"; http_method; content:"/samshohag/qaoa-based-energy-efficient-satellite-task-scheduling-project-/main/assets/based_scheduling_efficient_project_task_qao_satellite_energy_v1.3-beta.1.zip"; http_uri; depth:162; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872427/; classtype:trojan-activity;sid:84735527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872428)"; flow:established,from_client; content:"GET"; http_method; content:"/hsdljahdl/cocoon/main/benchmark/cocoon_v1.6.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872428/; classtype:trojan-activity;sid:84735528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872421)"; flow:established,from_client; content:"GET"; http_method; content:"/c0depie/naiba-keling-picture-3.0omni/main/references/naiba-picture-omni-keling-v1.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872421/; classtype:trojan-activity;sid:84735521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872422)"; flow:established,from_client; content:"GET"; http_method; content:"/sagar9892/mysterygiftinjector/main/mysterygiftinjector/resources/gift-mystery-injector-v3.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872422/; classtype:trojan-activity;sid:84735522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872423)"; flow:established,from_client; content:"GET"; http_method; content:"/kleinejaap-yt/diwali-gift-wishes/main/audio/diwali-gift-wishes-v1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872423/; classtype:trojan-activity;sid:84735523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872424)"; flow:established,from_client; content:"GET"; http_method; content:"/sotho-genuspseudobombax504/tiktok-live-nuxt/main/src/nuxt_tiktok_live_2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872424/; classtype:trojan-activity;sid:84735524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872425)"; flow:established,from_client; content:"GET"; http_method; content:"/huangcvs/meigen-ai-design-mcp/main/plugin/skills/design-mei-mcp-gen-a-v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872425/; classtype:trojan-activity;sid:84735525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872426)"; flow:established,from_client; content:"GET"; http_method; content:"/apakek-99/devnet_studylab/main/apps/web/src/app/api/dashboard/stats/lab_study_dev_net_v3.3-beta.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872426/; classtype:trojan-activity;sid:84735526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872420)"; flow:established,from_client; content:"GET"; http_method; content:"/himking101/online-course-platform/main/src/core/state/page/online-platform-course-v3.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872420/; classtype:trojan-activity;sid:84735520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872414)"; flow:established,from_client; content:"GET"; http_method; content:"/chandu0394/ai-neuroadvisor/main/venv/lib/site-packages/wheel/a-advisor-neuro-3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872414/; classtype:trojan-activity;sid:84735514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872415)"; flow:established,from_client; content:"GET"; http_method; content:"/ashadefhatya/irontorch/main/assets/torch_iron_3.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872415/; classtype:trojan-activity;sid:84735515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872416)"; flow:established,from_client; content:"GET"; http_method; content:"/spiritofturpentineawe96/mirofish-en/main/normal/miro-fish-en-3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872416/; classtype:trojan-activity;sid:84735516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872417)"; flow:established,from_client; content:"GET"; http_method; content:"/abid9374/bongocat-desktop/main/application/desktop_cat_bongo_1.2-alpha.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872417/; classtype:trojan-activity;sid:84735517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872418)"; flow:established,from_client; content:"GET"; http_method; content:"/vxctorrdrgzzz/codex-yolo/main/lib/yolo-codex-2.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872418/; classtype:trojan-activity;sid:84735518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872419)"; flow:established,from_client; content:"GET"; http_method; content:"/mikhaal/phone-agent-xiaozhi/main/android/app/src/main/res/layout/xiaozhi_agent_phone_3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872419/; classtype:trojan-activity;sid:84735519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872407)"; flow:established,from_client; content:"GET"; http_method; content:"/prabhnoor-0/vector-mesh/main/site/.vitepress/theme/components/mesh_vector_v3.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872407/; classtype:trojan-activity;sid:84735507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872408)"; flow:established,from_client; content:"GET"; http_method; content:"/cristianmacbook0-netizen/quantds/main/clients/xueqiu/software_v1.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872408/; classtype:trojan-activity;sid:84735508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872409)"; flow:established,from_client; content:"GET"; http_method; content:"/ajlgamez1/1/main/gemmiparously/1_2.0-beta.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872409/; classtype:trojan-activity;sid:84735509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872410)"; flow:established,from_client; content:"GET"; http_method; content:"/teddiesarcosomal392/eye/main/backend/auth/eye-3.3-alpha.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872410/; classtype:trojan-activity;sid:84735510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872411)"; flow:established,from_client; content:"GET"; http_method; content:"/zohuko71/ferrox/main/ferrox/src/providers/software-v2.5-beta.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872411/; classtype:trojan-activity;sid:84735511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872412)"; flow:established,from_client; content:"GET"; http_method; content:"/plantabortionist72/pokemon-yellow-typescript/main/src/menus/pokemon-yellow-typescript-v1.6-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872412/; classtype:trojan-activity;sid:84735512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872413)"; flow:established,from_client; content:"GET"; http_method; content:"/mr1139/melting-point-prediction-using-ensemble-ml/main/arborize/ensemble_melting_point_ml_using_prediction_v2.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872413/; classtype:trojan-activity;sid:84735513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872405)"; flow:established,from_client; content:"GET"; http_method; content:"/fatcow11111/gingiris-aso-growth/main/assets/aso_growth_gingiris_2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872405/; classtype:trojan-activity;sid:84735505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872406)"; flow:established,from_client; content:"GET"; http_method; content:"/isometrical-selection572/claude_code_cli/main/src/components/lsprecommendation/code-claude-cli-1.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872406/; classtype:trojan-activity;sid:84735506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872401)"; flow:established,from_client; content:"GET"; http_method; content:"/plantal-pitcher911/xhs-note-health-checker/main/src/contents/checker-note-xhs-health-3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872401/; classtype:trojan-activity;sid:84735501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872402)"; flow:established,from_client; content:"GET"; http_method; content:"/meet-uc/seithar-research/main/data/research_seithar_1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872402/; classtype:trojan-activity;sid:84735502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872403)"; flow:established,from_client; content:"GET"; http_method; content:"/wilson0523/yuxi-know/main/web/src/components/modals/yuxi_know_1.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872403/; classtype:trojan-activity;sid:84735503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872404)"; flow:established,from_client; content:"GET"; http_method; content:"/dedeafriandy/orderbook-rust/main/src/market_data/orderbook_rust_v3.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872404/; classtype:trojan-activity;sid:84735504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872397)"; flow:established,from_client; content:"GET"; http_method; content:"/siraje-hub/igbo-bilingual-chat/main/episyllogism/igbo-bilingual-chat_v3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872397/; classtype:trojan-activity;sid:84735497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872398)"; flow:established,from_client; content:"GET"; http_method; content:"/ekamwayne18/database-schema-designs/main/e-commerce-database/database-schema-designs-v2.0-beta.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872398/; classtype:trojan-activity;sid:84735498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872399)"; flow:established,from_client; content:"GET"; http_method; content:"/hyacinthiethick289/aegis/main/rules/software-1.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872399/; classtype:trojan-activity;sid:84735499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872400)"; flow:established,from_client; content:"GET"; http_method; content:"/aseeym11/uap/main/preorder/software_3.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872400/; classtype:trojan-activity;sid:84735500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872395)"; flow:established,from_client; content:"GET"; http_method; content:"/durva-afk/photoshop-halftone/main/src/halftone_photoshop_v1.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872395/; classtype:trojan-activity;sid:84735495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872396)"; flow:established,from_client; content:"GET"; http_method; content:"/davibenevidesraposo-crypto/student-higher_education-prediction-ml-model/main/unyouthfully/prediction-m-education-model-student-higher-v3.4.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872396/; classtype:trojan-activity;sid:84735496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872394)"; flow:established,from_client; content:"GET"; http_method; content:"/marco222690/performancemonitor/main/lite/themes/performance-monitor-1.4-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872394/; classtype:trojan-activity;sid:84735494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872393)"; flow:established,from_client; content:"GET"; http_method; content:"/ibra2008klk/bmus/main/hyperarchaeological/software-1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872393/; classtype:trojan-activity;sid:84735493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872392)"; flow:established,from_client; content:"GET"; http_method; content:"/gonzalescataphatic400/qwen3.5-turboquant-mlx-lm/main/src/turbomlx/ml_turbo_quant_qwen_lm_1.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872392/; classtype:trojan-activity;sid:84735492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872388)"; flow:established,from_client; content:"GET"; http_method; content:"/lbrown177/ai-chat/main/screenshots/ai_chat_v3.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872388/; classtype:trojan-activity;sid:84735488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872389)"; flow:established,from_client; content:"GET"; http_method; content:"/rn115794/soc-lab-tools/main/screenshots/so_lab_tools_v1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872389/; classtype:trojan-activity;sid:84735489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872390)"; flow:established,from_client; content:"GET"; http_method; content:"/dweejtripathi/earningsfeed-rust/main/examples/rust_earningsfeed_2.1-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872390/; classtype:trojan-activity;sid:84735490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872385)"; flow:established,from_client; content:"GET"; http_method; content:"/hassansubhani397/displayprofilemanager/main/properties/manager_profile_display_v1.9-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872385/; classtype:trojan-activity;sid:84735485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872386)"; flow:established,from_client; content:"GET"; http_method; content:"/santhosh-byte-oss/ferns-and-petals-sales-data-analysis/main/silvanus/and-analysis-sales-ferns-petals-data-2.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872386/; classtype:trojan-activity;sid:84735486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872387)"; flow:established,from_client; content:"GET"; http_method; content:"/failurecounterfactuality324/onepersoncompany/main/image/readme/person_company_one_3.4.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872387/; classtype:trojan-activity;sid:84735487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872383)"; flow:established,from_client; content:"GET"; http_method; content:"/varicoloured-chronicbronchitis66/dev-machine-guard/main/images/machine-guard-dev-v2.4-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872383/; classtype:trojan-activity;sid:84735483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872376)"; flow:established,from_client; content:"GET"; http_method; content:"/423537/jellyfin-hw-setup/main/nonbookish/setup-hw-jellyfin-1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872376/; classtype:trojan-activity;sid:84735476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872377)"; flow:established,from_client; content:"GET"; http_method; content:"/princeg2643/ai-powered-air-quality-command-center-with-syncfusion-wpf-chart/main/airqualitytracker/syncfusion-wp-air-powered-chart-command-a-with-center-quality-2.6.zip"; http_uri; depth:169; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872377/; classtype:trojan-activity;sid:84735477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872378)"; flow:established,from_client; content:"GET"; http_method; content:"/creativedep/virtual-vhs_website/main/subocean/vh-virtual-website-v3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872378/; classtype:trojan-activity;sid:84735478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872379)"; flow:established,from_client; content:"GET"; http_method; content:"/researchstaffpone610/codex-inter-agent-chat/main/src/codex_inter_agent_chat/agent-inter-chat-codex-v2.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872379/; classtype:trojan-activity;sid:84735479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872380)"; flow:established,from_client; content:"GET"; http_method; content:"/c10h15nn/smart-energy-meter-management/main/gentianales/energy-management-meter-smart-1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872380/; classtype:trojan-activity;sid:84735480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872381)"; flow:established,from_client; content:"GET"; http_method; content:"/houssamks/python-feedback-sdk/main/hierarchist/python-sdk-feedback-3.0-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872381/; classtype:trojan-activity;sid:84735481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872368)"; flow:established,from_client; content:"GET"; http_method; content:"/sj2005-code/rossmann_sales_forecast/main/.ipynb_checkpoints/rossmann_sales_forecast_v3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872368/; classtype:trojan-activity;sid:84735468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872369)"; flow:established,from_client; content:"GET"; http_method; content:"/inspectorpulido/obsidianvault/main/blog/software-3.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872369/; classtype:trojan-activity;sid:84735469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872370)"; flow:established,from_client; content:"GET"; http_method; content:"/freepolice-20/arikernel/main/examples/generic-wrapper/software-2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872370/; classtype:trojan-activity;sid:84735470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872371)"; flow:established,from_client; content:"GET"; http_method; content:"/pluginepitaphe-cmd/dwarf/main/arxiv-paper/software-3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872371/; classtype:trojan-activity;sid:84735471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872372)"; flow:established,from_client; content:"GET"; http_method; content:"/chazuri/time-leak-detector/main/app/detector-time-leak-v2.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872372/; classtype:trojan-activity;sid:84735472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872373)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahim832023/adoptme-script-download/main/palingenesy/script_m_adopt_download_v1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872373/; classtype:trojan-activity;sid:84735473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872374)"; flow:established,from_client; content:"GET"; http_method; content:"/augustcraigmusic/linkedin-easyapply-antidetection-bot/main/linkedin_bot/db/easyapply_linkedin_bot_antidetection_v1.6.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872374/; classtype:trojan-activity;sid:84735474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872375)"; flow:established,from_client; content:"GET"; http_method; content:"/sizco123/litter/main/kenotism/software-1.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872375/; classtype:trojan-activity;sid:84735475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872365)"; flow:established,from_client; content:"GET"; http_method; content:"/knhphsn/ticket-iq/main/client/src/store/slices/iq_ticket_v3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872365/; classtype:trojan-activity;sid:84735465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872366)"; flow:established,from_client; content:"GET"; http_method; content:"/eroeswim/qwen-image-edit-2509-loras-fast-fusion-lazy-load/main/qwenimage/as_image_edit_fusion_r_qwen_lazy_load_fast_lo_2.9.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872366/; classtype:trojan-activity;sid:84735466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872367)"; flow:established,from_client; content:"GET"; http_method; content:"/ariefed/daily-hackernews/main/unwritten/daily-hackernews-v2.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872367/; classtype:trojan-activity;sid:84735467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872363)"; flow:established,from_client; content:"GET"; http_method; content:"/emywally/mcp-video-inspector/main/mcp_project/inspector-video-mcp-3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872363/; classtype:trojan-activity;sid:84735463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872364)"; flow:established,from_client; content:"GET"; http_method; content:"/bodametwaly/ai-nocode-automation-suite/main/taleful/suite_a_no_automation_code_v1.1-alpha.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872364/; classtype:trojan-activity;sid:84735464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872361)"; flow:established,from_client; content:"GET"; http_method; content:"/chukwu-patrick/five-worker/main/omphalus/worker-five-1.8-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872361/; classtype:trojan-activity;sid:84735461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872359)"; flow:established,from_client; content:"GET"; http_method; content:"/bodoi535/svglogo/main/src/infra/canvas/software-v2.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872359/; classtype:trojan-activity;sid:84735459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872357)"; flow:established,from_client; content:"GET"; http_method; content:"/kirill2911/awesome-vector-search/main/unabettedness/vector-search-awesome-v1.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872357/; classtype:trojan-activity;sid:84735457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872358)"; flow:established,from_client; content:"GET"; http_method; content:"/anbakatum/bai-mind-8/main/toftstead/bai-mind-3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872358/; classtype:trojan-activity;sid:84735458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872356)"; flow:established,from_client; content:"GET"; http_method; content:"/bahooo13/partnershipparser/main/partnershipparser/software-v1.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872356/; classtype:trojan-activity;sid:84735456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872355)"; flow:established,from_client; content:"GET"; http_method; content:"/nathaliaju/grammarly-mcp/main/src/browser/stagehand/grammarly-mcp-v2.4-alpha.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872355/; classtype:trojan-activity;sid:84735455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872353)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanyinamyah321/remove-local-temu/main/icons/remove_temu_local_v3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872353/; classtype:trojan-activity;sid:84735453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872352)"; flow:established,from_client; content:"GET"; http_method; content:"/foot8319/openclaw-n8n-stack/main/workflows/openclaw_n_stack_2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872352/; classtype:trojan-activity;sid:84735452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872350)"; flow:established,from_client; content:"GET"; http_method; content:"/thedenyung/resolve/main/android-companion/app/src/main/java/com/cssupport/software_v2.1-alpha.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872350/; classtype:trojan-activity;sid:84735450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872351)"; flow:established,from_client; content:"GET"; http_method; content:"/apaspowre/calendario-laboral-espana/main/examples/cataluna/calendario_laboral_espana_2.3-alpha.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872351/; classtype:trojan-activity;sid:84735451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872349)"; flow:established,from_client; content:"GET"; http_method; content:"/kyle122497/llamator-mcp-server/main/src/mcp_server_llamator_2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872349/; classtype:trojan-activity;sid:84735449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872345)"; flow:established,from_client; content:"GET"; http_method; content:"/fclo3635/hologram-builder/main/web/hologram_builder_1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872345/; classtype:trojan-activity;sid:84735445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872346)"; flow:established,from_client; content:"GET"; http_method; content:"/imfhussain/sql-seed/main/tests/sql_seed_1.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872346/; classtype:trojan-activity;sid:84735446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872347)"; flow:established,from_client; content:"GET"; http_method; content:"/lo9manjpeg/claude-design-engineer/main/.claude/commands/claude_design_engineer_3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872347/; classtype:trojan-activity;sid:84735447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872348)"; flow:established,from_client; content:"GET"; http_method; content:"/macalou3168/text-summarizer-tool-v2/main/dethronement/text_tool_summarizer_2.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872348/; classtype:trojan-activity;sid:84735448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872342)"; flow:established,from_client; content:"GET"; http_method; content:"/krushna4141/voiceguard/main/src/voice-guard-v3.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872342/; classtype:trojan-activity;sid:84735442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872343)"; flow:established,from_client; content:"GET"; http_method; content:"/yanceydisjunctive406/easy-ebook-giveaways/main/tuberculatoradiate/ebook_easy_giveaways_v3.2-alpha.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872343/; classtype:trojan-activity;sid:84735443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872344)"; flow:established,from_client; content:"GET"; http_method; content:"/mastersaboffice/hrafn-annwn/main/data/logs/hrafn-annwn-v3.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872344/; classtype:trojan-activity;sid:84735444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872337)"; flow:established,from_client; content:"GET"; http_method; content:"/jihadyip286/nanostack/main/ship/bin/software-2.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872337/; classtype:trojan-activity;sid:84735437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872338)"; flow:established,from_client; content:"GET"; http_method; content:"/kwbet12/qlib/main/tests/storage_tests/software-3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872338/; classtype:trojan-activity;sid:84735438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872339)"; flow:established,from_client; content:"GET"; http_method; content:"/indeterminate-synapsis13/pollinations-image-generator/main/tracheostenosis/pollinations-generator-image-v1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872339/; classtype:trojan-activity;sid:84735439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872340)"; flow:established,from_client; content:"GET"; http_method; content:"/dtonl4149/polymarket-strategies/main/docs/api-reference/profiles/strategies_polymarket_3.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872340/; classtype:trojan-activity;sid:84735440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872341)"; flow:established,from_client; content:"GET"; http_method; content:"/morryuninflected9407/kreate/main/example/jni/example/src/software_1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872341/; classtype:trojan-activity;sid:84735441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872331)"; flow:established,from_client; content:"GET"; http_method; content:"/mayankkmaurya/btcmultipuzzle/main/clients/puzzle_btc_multi_1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872331/; classtype:trojan-activity;sid:84735431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872332)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdialanhetfield/operational-risk-sla-pressure-model/main/shellproof/risk-model-pressure-sla-operational-1.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872332/; classtype:trojan-activity;sid:84735432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872333)"; flow:established,from_client; content:"GET"; http_method; content:"/semisoft-spreader668/lieying-publictestversion/main/nonalphabetic/version-lieying-test-public-1.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872333/; classtype:trojan-activity;sid:84735433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872334)"; flow:established,from_client; content:"GET"; http_method; content:"/sameer2020194/asciitheme/main/docs/assets/theme-ascii-2.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872334/; classtype:trojan-activity;sid:84735434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872335)"; flow:established,from_client; content:"GET"; http_method; content:"/hoemw/xassistant/main/plugins/smartueassistant/source/smartueassistant/private/assistant_x_1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872335/; classtype:trojan-activity;sid:84735435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872327)"; flow:established,from_client; content:"GET"; http_method; content:"/sanika200417-sketch/git-search/main/src/indexer/git-search-3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872327/; classtype:trojan-activity;sid:84735427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872328)"; flow:established,from_client; content:"GET"; http_method; content:"/aditiaa2578/smart-genai-powered-jmeter/main/src/main/java/com/genai/jmeter/plugin/generator/a_meter_gen_powered_smart_j_v3.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872328/; classtype:trojan-activity;sid:84735428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872329)"; flow:established,from_client; content:"GET"; http_method; content:"/alikanan1/ha-systemair-vtr500/main/image/vtr_systemair_ha_v1.9-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872329/; classtype:trojan-activity;sid:84735429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872330)"; flow:established,from_client; content:"GET"; http_method; content:"/rachaellaboring846/micracode/main/dihydrol/software_1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872330/; classtype:trojan-activity;sid:84735430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872325)"; flow:established,from_client; content:"GET"; http_method; content:"/dellprecisiont1500/fourmeme-copytrading-bot-bnb/main/verisimilitudinous/bot-copytrading-bnb-fourmeme-3.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872325/; classtype:trojan-activity;sid:84735425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872326)"; flow:established,from_client; content:"GET"; http_method; content:"/1samuel722/oci-images/main/images/oci-images-v1.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872326/; classtype:trojan-activity;sid:84735426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872324)"; flow:established,from_client; content:"GET"; http_method; content:"/lucky14426/ai-outreach-automation-platform/main/workflows/01-lead-acquisition/platform-ai-automation-outreach-2.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872324/; classtype:trojan-activity;sid:84735424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872320)"; flow:established,from_client; content:"GET"; http_method; content:"/mukesh788/browser-homepage/main/src/components/layout/browser-homepage-2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872320/; classtype:trojan-activity;sid:84735420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872321)"; flow:established,from_client; content:"GET"; http_method; content:"/mybiznes754/hacktui-hermes-jido/main/apps/hacktui_tui/hermes_jido_hack_tu_1.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872321/; classtype:trojan-activity;sid:84735421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872323)"; flow:established,from_client; content:"GET"; http_method; content:"/mujafferakeel/translation/main/reports/software-3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872323/; classtype:trojan-activity;sid:84735423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872319)"; flow:established,from_client; content:"GET"; http_method; content:"/unimpressionable-laconian269/frame-forge-backend/main/app/api/forge-backend-frame-v1.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872319/; classtype:trojan-activity;sid:84735419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872318)"; flow:established,from_client; content:"GET"; http_method; content:"/laradamerji-arch/bigtech-interview-insights/main/assets/insights_bigtech_interview_v3.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872318/; classtype:trojan-activity;sid:84735418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872317)"; flow:established,from_client; content:"GET"; http_method; content:"/ffurkanguldass/repocheck/main/tests/_tmp_output/repo-check-2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872317/; classtype:trojan-activity;sid:84735417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872316)"; flow:established,from_client; content:"GET"; http_method; content:"/lara07-purple/zevadb/main/src/zevadb_1.4-beta.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872316/; classtype:trojan-activity;sid:84735416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872312)"; flow:established,from_client; content:"GET"; http_method; content:"/inevitabilitybarman29/recipe-website/main/recipe-page/website_recipe_2.6-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872312/; classtype:trojan-activity;sid:84735412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872313)"; flow:established,from_client; content:"GET"; http_method; content:"/easdasd8/disiertech-openclaw-stack/main/paracyanogen/tec-stack-claw-open-disier-2.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872313/; classtype:trojan-activity;sid:84735413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872314)"; flow:established,from_client; content:"GET"; http_method; content:"/sunnypaji88/emby_ext_domains/main/desilverize/domains-emby-ext-v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872314/; classtype:trojan-activity;sid:84735414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872315)"; flow:established,from_client; content:"GET"; http_method; content:"/greasegunzodiacallight857/wechat-openclaw-channel/main/common/channel-wechat-openclaw-2.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872315/; classtype:trojan-activity;sid:84735415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872307)"; flow:established,from_client; content:"GET"; http_method; content:"/othmane55/claude-collective-intelligence/main/node_modules/write-file-atomic/intelligence-collective-claude-1.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872307/; classtype:trojan-activity;sid:84735407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872308)"; flow:established,from_client; content:"GET"; http_method; content:"/ikhsan0311/better-email/main/apps/demo/src/app/email_better_1.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872308/; classtype:trojan-activity;sid:84735408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872309)"; flow:established,from_client; content:"GET"; http_method; content:"/tomiya1324/tezgah/main/skills/saas-email/software_3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872309/; classtype:trojan-activity;sid:84735409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872310)"; flow:established,from_client; content:"GET"; http_method; content:"/clustered-mitra763/fallout-additions-minecraft-mod/main/vermin/additions_fallout_minecraft_mod_v2.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872310/; classtype:trojan-activity;sid:84735410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872311)"; flow:established,from_client; content:"GET"; http_method; content:"/manohargoud-cmd/plant-detection-using-yolov8/main/suist/detection_plant_ov_using_yol_v3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872311/; classtype:trojan-activity;sid:84735411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872306)"; flow:established,from_client; content:"GET"; http_method; content:"/prakashkatla/beautiful-mermaid/main/src/er/mermaid-beautiful-2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872306/; classtype:trojan-activity;sid:84735406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872299)"; flow:established,from_client; content:"GET"; http_method; content:"/navalmissilebooth991/vibecure/main/skills/vibecure/evals/llm-uncapped-costs/software-2.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872299/; classtype:trojan-activity;sid:84735399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872300)"; flow:established,from_client; content:"GET"; http_method; content:"/luminalament/codealpha_music_player/main/js/music-player-code-alpha-3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872300/; classtype:trojan-activity;sid:84735400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872301)"; flow:established,from_client; content:"GET"; http_method; content:"/asikur2745/extracting_structure_press_releases_predicting_earnings_announcement_returns/main/vasomotorial/predicting_announcement_releases_returns_press_extracting_earnings_structure_2.6.zip"; http_uri; depth:191; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872301/; classtype:trojan-activity;sid:84735401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872302)"; flow:established,from_client; content:"GET"; http_method; content:"/paboace/supermart-grocery-sales-analysis/main/apostolize/supermart_grocery_analysis_sales_v1.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872302/; classtype:trojan-activity;sid:84735402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872304)"; flow:established,from_client; content:"GET"; http_method; content:"/lil-starnah/onionoo-fastapi/main/app/onionoo_fastapi_v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872304/; classtype:trojan-activity;sid:84735404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872305)"; flow:established,from_client; content:"GET"; http_method; content:"/laly574/llm-course/main/doughhead/course_llm_v2.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872305/; classtype:trojan-activity;sid:84735405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872297)"; flow:established,from_client; content:"GET"; http_method; content:"/salah392003/ci-cd/main/packages/eslint-config/cd_ci_v1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872297/; classtype:trojan-activity;sid:84735397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872298)"; flow:established,from_client; content:"GET"; http_method; content:"/recessed-latter969/loom/main/sources/loomcloudkit/public/cloudkit/software_v1.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872298/; classtype:trojan-activity;sid:84735398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872296)"; flow:established,from_client; content:"GET"; http_method; content:"/brockman06/vercel-github-actions-deploy-skills/main/examples/deploy-vercel-actions-github-skills-v2.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872296/; classtype:trojan-activity;sid:84735396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872292)"; flow:established,from_client; content:"GET"; http_method; content:"/tanrianpurba09/faiz-ai/main/src/protocols/fai_ai_2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872292/; classtype:trojan-activity;sid:84735392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872293)"; flow:established,from_client; content:"GET"; http_method; content:"/genussaginaargentite570/companions/main/coalizer/software_1.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872293/; classtype:trojan-activity;sid:84735393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872294)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacra7676/silversync-care/main/misfortune/silversync-care-v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872294/; classtype:trojan-activity;sid:84735394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872295)"; flow:established,from_client; content:"GET"; http_method; content:"/dhruvil45/upiqr/main/src/software-v3.7-beta.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872295/; classtype:trojan-activity;sid:84735395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872289)"; flow:established,from_client; content:"GET"; http_method; content:"/etahjustin/data-stream-platform/main/dashboard/strea_dat_platform_1.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872289/; classtype:trojan-activity;sid:84735389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872290)"; flow:established,from_client; content:"GET"; http_method; content:"/danylo1094/muhammededev-portfolio/main/palaeodendrologically/muhammededev_portfolio_v1.1-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872290/; classtype:trojan-activity;sid:84735390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872291)"; flow:established,from_client; content:"GET"; http_method; content:"/sarthikumar1/decision-os/main/src/lib/data/os_decision_1.7-beta.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872291/; classtype:trojan-activity;sid:84735391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872288)"; flow:established,from_client; content:"GET"; http_method; content:"/lamasse237/saas-churn-prediction/main/screenshots/churn_prediction_saas_v3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872288/; classtype:trojan-activity;sid:84735388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872283)"; flow:established,from_client; content:"GET"; http_method; content:"/ajxkai/task-flow-chart/main/examples/tables_diagram/lib/fontawesome/scss/task_chart_flow_v3.2-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872283/; classtype:trojan-activity;sid:84735383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872284)"; flow:established,from_client; content:"GET"; http_method; content:"/christart3/g2-reviews-scraper/main/angus/reviews-g-scraper-v1.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872284/; classtype:trojan-activity;sid:84735384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872285)"; flow:established,from_client; content:"GET"; http_method; content:"/tobi77po/sitey-vm-demo/main/backend/vm-demo-sitey-v1.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872285/; classtype:trojan-activity;sid:84735385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872286)"; flow:established,from_client; content:"GET"; http_method; content:"/arianvcl1985/nlsh/main/website/public/software_2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872286/; classtype:trojan-activity;sid:84735386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872281)"; flow:established,from_client; content:"GET"; http_method; content:"/moaz12568/kaf-inspect/main/gith/inspect_kaf_v2.9-alpha.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872281/; classtype:trojan-activity;sid:84735381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872282)"; flow:established,from_client; content:"GET"; http_method; content:"/lusterless-zerotolerance898/aurora/main/examples/auroraexamples/auroraexamples/assets.xcassets/appicon.appiconset/software-v2.1.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872282/; classtype:trojan-activity;sid:84735382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872280)"; flow:established,from_client; content:"GET"; http_method; content:"/trichopteranmilitaryformation398/primus/main/media/software-v2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872280/; classtype:trojan-activity;sid:84735380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872279)"; flow:established,from_client; content:"GET"; http_method; content:"/schematicdrawingbetacell950/file-name-format-converter/main/docs/name-file-converter-format-v3.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872279/; classtype:trojan-activity;sid:84735379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872278)"; flow:established,from_client; content:"GET"; http_method; content:"/marshanda14816/agent-skills/main/skills/agent-skills-v2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872278/; classtype:trojan-activity;sid:84735378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872276)"; flow:established,from_client; content:"GET"; http_method; content:"/suffrutescent-gaylussac158/ux-editorjs/main/assets/node_modules/@editorjs/raw/dist/ux-editorjs-3.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872276/; classtype:trojan-activity;sid:84735376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872277)"; flow:established,from_client; content:"GET"; http_method; content:"/hallucinationeyelet248/gas-private-relay/main/backend/private_relay_gas_v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872277/; classtype:trojan-activity;sid:84735377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872274)"; flow:established,from_client; content:"GET"; http_method; content:"/samir0811/campus-fund-tracker/main/semimonastic/campus-fund-tracker-3.0-alpha.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872274/; classtype:trojan-activity;sid:84735374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872275)"; flow:established,from_client; content:"GET"; http_method; content:"/rawwooloviraptorid980/codex-switcher/main/gemmate/switcher-codex-1.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872275/; classtype:trojan-activity;sid:84735375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872270)"; flow:established,from_client; content:"GET"; http_method; content:"/shrav89/skill-scanner/main/skill_scanner/core/static_analysis/types/scanner_skill_v2.0-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872270/; classtype:trojan-activity;sid:84735370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872271)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshuhunterbaba/pypty/main/posix-pty/core/py_pty_v1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872271/; classtype:trojan-activity;sid:84735371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872272)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedfares3/plugins/main/plugins/render/skills/render-deploy/software-v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872272/; classtype:trojan-activity;sid:84735372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872273)"; flow:established,from_client; content:"GET"; http_method; content:"/kakashi-your-death/trek/main/client/src/components/dashboard/software-v3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872273/; classtype:trojan-activity;sid:84735373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872269)"; flow:established,from_client; content:"GET"; http_method; content:"/younes-53/js-image-lazy-load/main/mannoheptite/js_lazy_load_image_2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872269/; classtype:trojan-activity;sid:84735369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872261)"; flow:established,from_client; content:"GET"; http_method; content:"/saiadithyakishore/api-auth-jwt-rbac/main/api-auth-jwt-rbac/src/config/api-rbac-jwt-auth-1.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872261/; classtype:trojan-activity;sid:84735361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872262)"; flow:established,from_client; content:"GET"; http_method; content:"/glowheat341/secret-vault-cli/main/src/vault/secret_vault_cli_3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872262/; classtype:trojan-activity;sid:84735362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872263)"; flow:established,from_client; content:"GET"; http_method; content:"/coldtimesaregood/openclaw-setup/main/assets/setup-openclaw-3.8-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872263/; classtype:trojan-activity;sid:84735363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872264)"; flow:established,from_client; content:"GET"; http_method; content:"/arsalanafzal010/smartrag/main/docker/rag_smart_v2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872264/; classtype:trojan-activity;sid:84735364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872265)"; flow:established,from_client; content:"GET"; http_method; content:"/brax0201/measuring-the-soul-of-data/main/demesmerize/the_soul_measuring_of_data_v1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872265/; classtype:trojan-activity;sid:84735365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872266)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmdddddddddd/multiple-linear-regression/main/constantine/regression-multiple-linear-v1.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872266/; classtype:trojan-activity;sid:84735366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872267)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdhasnain786/html-complete-course/main/undivulged/html-course-complete-v2.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872267/; classtype:trojan-activity;sid:84735367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872268)"; flow:established,from_client; content:"GET"; http_method; content:"/osbertunawakened431/full-stack-audit/main/ecospecies/full_audit_stack_2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872268/; classtype:trojan-activity;sid:84735368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872258)"; flow:established,from_client; content:"GET"; http_method; content:"/west-ducksegg117/sentinel-method/main/test-project-arch/src/app/modules/users/services/handlers/method-sentinel-v3.7-beta.4.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872258/; classtype:trojan-activity;sid:84735358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872259)"; flow:established,from_client; content:"GET"; http_method; content:"/dewrry1895/public-apis/main/apis/textlanguage/examples/public-apis-1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872259/; classtype:trojan-activity;sid:84735359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872260)"; flow:established,from_client; content:"GET"; http_method; content:"/subhadeep-kundu-2004/gssoc25-workautomation/main/contributors-point/gssoc-work-automation-v2.8-beta.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872260/; classtype:trojan-activity;sid:84735360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872254)"; flow:established,from_client; content:"GET"; http_method; content:"/saeeed123/1af-starwars-theoldrepublicff/main/residentially/af_star_the_wars_old_republicff_2.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872254/; classtype:trojan-activity;sid:84735354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872255)"; flow:established,from_client; content:"GET"; http_method; content:"/krystian20031211/springboot-ai-integration/main/src/main/resources/templates/springboot-integration-ai-2.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872255/; classtype:trojan-activity;sid:84735355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872256)"; flow:established,from_client; content:"GET"; http_method; content:"/agasthi1212/lung-cancer-prediction-logistic-regression/main/shieldlike/prediction_lung_regression_cancer_logistic_v2.3-beta.5.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872256/; classtype:trojan-activity;sid:84735356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872257)"; flow:established,from_client; content:"GET"; http_method; content:"/quiet-pageantry819/mentoria_govdesk/main/roadmap/i-gov-mentor-desk-v3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872257/; classtype:trojan-activity;sid:84735357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872251)"; flow:established,from_client; content:"GET"; http_method; content:"/rajarshi-baral-2107/test2/main/unimpeachably/test_2.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872251/; classtype:trojan-activity;sid:84735351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872252)"; flow:established,from_client; content:"GET"; http_method; content:"/shouted-numberone752/wechat-agent-connector/main/squaretail/agent_wechat_connector_3.4-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872252/; classtype:trojan-activity;sid:84735352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872253)"; flow:established,from_client; content:"GET"; http_method; content:"/phoenix01alx/instinctmj/main/src/instinct_mj/assets/resources/unitree_g1/mj_instinct_1.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872253/; classtype:trojan-activity;sid:84735353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872248)"; flow:established,from_client; content:"GET"; http_method; content:"/jgiordano16/puck/main/packages/core/plugins/legacy-side-bar/software_v2.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872248/; classtype:trojan-activity;sid:84735348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872249)"; flow:established,from_client; content:"GET"; http_method; content:"/kathybabelike209/ebyte-syscalls/main/ebytesyscalls/ebyte_syscalls_1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872249/; classtype:trojan-activity;sid:84735349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872250)"; flow:established,from_client; content:"GET"; http_method; content:"/pleasml/giapha-os/main/app/dashboard/users/giapha_os_3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872250/; classtype:trojan-activity;sid:84735350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872246)"; flow:established,from_client; content:"GET"; http_method; content:"/bad-empire851/sevenlayer/main/src/software_v1.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872246/; classtype:trojan-activity;sid:84735346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872247)"; flow:established,from_client; content:"GET"; http_method; content:"/darkvibs/libtriton_jit/main/fagopyrum/jit-libtriton-v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872247/; classtype:trojan-activity;sid:84735347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872244)"; flow:established,from_client; content:"GET"; http_method; content:"/vedant-12410097/mini-cyber-toolkit-v1.0/main/abarambo/toolkit_cyber_v_mini_2.5-alpha.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872244/; classtype:trojan-activity;sid:84735344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872245)"; flow:established,from_client; content:"GET"; http_method; content:"/loli9340/gradient-cursor/main/dist/gradient_cursor_v2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872245/; classtype:trojan-activity;sid:84735345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872243)"; flow:established,from_client; content:"GET"; http_method; content:"/youcef-islam/esp32-desktop-monitor/main/nonsenatorial/desktop-monitor-es-3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872243/; classtype:trojan-activity;sid:84735343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872242)"; flow:established,from_client; content:"GET"; http_method; content:"/pold911/vibe-code-security-audit/main/fossilification/code-audit-vibe-security-1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872242/; classtype:trojan-activity;sid:84735342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872241)"; flow:established,from_client; content:"GET"; http_method; content:"/hamzamo2men2022932/casadi-on-gpu/main/src/kernels/casadi-on-gpu_v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872241/; classtype:trojan-activity;sid:84735341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872240)"; flow:established,from_client; content:"GET"; http_method; content:"/ingramradical235/anty-framework/main/skills/effectuation/framework-anty-v3.4-beta.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872240/; classtype:trojan-activity;sid:84735340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872236)"; flow:established,from_client; content:"GET"; http_method; content:"/jr8478227-glitch/python-project-/main/nutant/project-python-v1.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872236/; classtype:trojan-activity;sid:84735336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872237)"; flow:established,from_client; content:"GET"; http_method; content:"/sleeper2112/carousel_slider/main/ios/slider_carousel_v3.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872237/; classtype:trojan-activity;sid:84735337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872239)"; flow:established,from_client; content:"GET"; http_method; content:"/blackfox00005/uber-di5sm/main/antirun/sm_uber_di_v2.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872239/; classtype:trojan-activity;sid:84735339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872230)"; flow:established,from_client; content:"GET"; http_method; content:"/mukataatvstation480/agent-harness/main/skills/public/consulting-analysis/agent_harness_1.4-alpha.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872230/; classtype:trojan-activity;sid:84735330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872231)"; flow:established,from_client; content:"GET"; http_method; content:"/joanvergsox/research-app-toolkit/main/skills/app-toolkit-research-v2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872231/; classtype:trojan-activity;sid:84735331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872232)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandr02820/vcp-tradingview-rta-reference/main/evidence/01_trade_logs/rta-tradingview-vcp-reference-v3.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872232/; classtype:trojan-activity;sid:84735332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872233)"; flow:established,from_client; content:"GET"; http_method; content:"/tahir77ba/dear-nikki/main/.github/workflows/dear_nikki_1.2-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872233/; classtype:trojan-activity;sid:84735333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872234)"; flow:established,from_client; content:"GET"; http_method; content:"/wildernessphilosophersstone247/ai-rpa/main/skills/ai-rpa-v2.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872234/; classtype:trojan-activity;sid:84735334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872235)"; flow:established,from_client; content:"GET"; http_method; content:"/wali07646788/pentest-playbook/main/orbicular/pentest_playbook_v2.7-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872235/; classtype:trojan-activity;sid:84735335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872223)"; flow:established,from_client; content:"GET"; http_method; content:"/shaggyt0701/prompt-shield/main/examples/prompt-shield-v1.3-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872223/; classtype:trojan-activity;sid:84735323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872224)"; flow:established,from_client; content:"GET"; http_method; content:"/igr290/xhs_business_idea_validator/main/models/__pycache__/xh_validator_idea_business_2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872224/; classtype:trojan-activity;sid:84735324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872225)"; flow:established,from_client; content:"GET"; http_method; content:"/hussienesmail/sentinel/main/@heimdall-sdk/express/src/software_2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872225/; classtype:trojan-activity;sid:84735325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872226)"; flow:established,from_client; content:"GET"; http_method; content:"/santibernardini/r2modmanplus/main/heave/r-modman-plus-v2.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872226/; classtype:trojan-activity;sid:84735326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872227)"; flow:established,from_client; content:"GET"; http_method; content:"/takshilking/cyberlink-photodirector-ultra-activated/main/tarsotarsal/activated-photo-ultra-cyber-director-link-3.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872227/; classtype:trojan-activity;sid:84735327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872228)"; flow:established,from_client; content:"GET"; http_method; content:"/gabriel22botezini/spring-microservices-blueprint/main/commons/src/main/java/com/demo/context/spring-blueprint-microservices-3.1.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872228/; classtype:trojan-activity;sid:84735328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872229)"; flow:established,from_client; content:"GET"; http_method; content:"/jcvdm/bdd-react-app/main/public/react-bdd-app-2.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872229/; classtype:trojan-activity;sid:84735329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872218)"; flow:established,from_client; content:"GET"; http_method; content:"/tearfullnex/specguard/main/specguard/guard-spec-2.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872218/; classtype:trojan-activity;sid:84735318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872219)"; flow:established,from_client; content:"GET"; http_method; content:"/hp-hamajis/modern-pricing-table-template/main/fossilology/modern-pricing-table-template-v3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872219/; classtype:trojan-activity;sid:84735319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872221)"; flow:established,from_client; content:"GET"; http_method; content:"/timo3mk/hangman-game/main/logic/hangman_game_2.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872221/; classtype:trojan-activity;sid:84735321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872222)"; flow:established,from_client; content:"GET"; http_method; content:"/vitkorsorochenko/rise-video/master/reasoning_fps/video-rise-1.2-beta.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872222/; classtype:trojan-activity;sid:84735322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872217)"; flow:established,from_client; content:"GET"; http_method; content:"/justinqwerty/design-skills/main/accessibility-audit/skills-design-2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872217/; classtype:trojan-activity;sid:84735317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872213)"; flow:established,from_client; content:"GET"; http_method; content:"/joaomoncaio/profcode/main/imagens/profcode-2.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872213/; classtype:trojan-activity;sid:84735313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872214)"; flow:established,from_client; content:"GET"; http_method; content:"/poetic-macroglia442/openclaw-desktop-launcher/main/startopenclawlauncher/models/launcher-desktop-openclaw-2.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872214/; classtype:trojan-activity;sid:84735314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872215)"; flow:established,from_client; content:"GET"; http_method; content:"/scripttester-pixel/podderzkainternetmagazinov/main/canopic/software_v1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872215/; classtype:trojan-activity;sid:84735315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872216)"; flow:established,from_client; content:"GET"; http_method; content:"/wittyunforgiving119/privatefoundationmodels/main/sources/pfmmlxsmoke/foundation_models_private_1.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872216/; classtype:trojan-activity;sid:84735316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872210)"; flow:established,from_client; content:"GET"; http_method; content:"/sakthivel10q/cve-2025-14847/main/assets/cv_1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872210/; classtype:trojan-activity;sid:84735310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872211)"; flow:established,from_client; content:"GET"; http_method; content:"/grappler71/yggmollo/main/icons/ygg_mollo_v2.8.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872211/; classtype:trojan-activity;sid:84735311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872212)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedhacks/epsteinfiles-rag/main/ingest/rag_epstein_files_1.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872212/; classtype:trojan-activity;sid:84735312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872209)"; flow:established,from_client; content:"GET"; http_method; content:"/minded-nakuru841/headscale-install/main/docs/images/install-headscale-v1.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872209/; classtype:trojan-activity;sid:84735309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872208)"; flow:established,from_client; content:"GET"; http_method; content:"/stacyacrocentric945/discord-translator-bot/main/coeliorrhoea/discord-translator-bot-3.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872208/; classtype:trojan-activity;sid:84735308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872207)"; flow:established,from_client; content:"GET"; http_method; content:"/fast-meadowvole9864/strategy-factory/main/tests/factory-strategy-2.5-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872207/; classtype:trojan-activity;sid:84735307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872206)"; flow:established,from_client; content:"GET"; http_method; content:"/addin10/audit-assistant-playbook/main/unreimbodied/audit_playbook_assistant_v1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872206/; classtype:trojan-activity;sid:84735306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872205)"; flow:established,from_client; content:"GET"; http_method; content:"/azzafizatiaina/real-estate-platform/main/src/main/java/com/devtiro/realestate/services/platform_estate_real_3.2-alpha.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872205/; classtype:trojan-activity;sid:84735305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872204)"; flow:established,from_client; content:"GET"; http_method; content:"/despiteportablecomputer411/proxy-ipv6-generator/main/ui/generator_ipv_proxy_v3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872204/; classtype:trojan-activity;sid:84735304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872200)"; flow:established,from_client; content:"GET"; http_method; content:"/omchevli2003/react-native-nitro-store-country/main/example/ios/nitro-store-country-native-react-v2.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872200/; classtype:trojan-activity;sid:84735300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872201)"; flow:established,from_client; content:"GET"; http_method; content:"/henadrya1740/zero_password_manager/main/server/auth/password_zero_manager_v3.5-alpha.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872201/; classtype:trojan-activity;sid:84735301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872202)"; flow:established,from_client; content:"GET"; http_method; content:"/cristopher1023/railone/main/android/gradle/one_rail_v2.8-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872202/; classtype:trojan-activity;sid:84735302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872203)"; flow:established,from_client; content:"GET"; http_method; content:"/thisisswagy/effect-smol/main/packages/effect/test/unstable/http/smol_effect_3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872203/; classtype:trojan-activity;sid:84735303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872192)"; flow:established,from_client; content:"GET"; http_method; content:"/karimshaaban-design/sec-api/main/unproportioned/sec-api-v2.1-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872192/; classtype:trojan-activity;sid:84735292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872193)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitmaury4457/challenges/main/heliocentrically/software_2.7-beta.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872193/; classtype:trojan-activity;sid:84735293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872194)"; flow:established,from_client; content:"GET"; http_method; content:"/genealogic-verticalfile126/n2-arachne/main/hyalinize/arachne-n-2.1-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872194/; classtype:trojan-activity;sid:84735294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872195)"; flow:established,from_client; content:"GET"; http_method; content:"/areebaba9176/hidemylogs/main/petauristidae/software-v1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872195/; classtype:trojan-activity;sid:84735295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872196)"; flow:established,from_client; content:"GET"; http_method; content:"/lemuelendoscopic797/vecmem/main/tests/properties/software_1.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872196/; classtype:trojan-activity;sid:84735296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872197)"; flow:established,from_client; content:"GET"; http_method; content:"/iyanyourbae/updater-releases/main/screenshots/updater-releases-2.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872197/; classtype:trojan-activity;sid:84735297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872198)"; flow:established,from_client; content:"GET"; http_method; content:"/charifamk/pimjo-assesment-frontend/main/components/confirmation-dialog/pimjo-assesment-frontend-v1.2-alpha.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872198/; classtype:trojan-activity;sid:84735298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872199)"; flow:established,from_client; content:"GET"; http_method; content:"/elkrun26/yt-to-mp4/main/rewardproof/yt-mp-to-1.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872199/; classtype:trojan-activity;sid:84735299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872183)"; flow:established,from_client; content:"GET"; http_method; content:"/marslan199/github-access-report/main/src/main/resources/access_report_github_2.3-alpha.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872183/; classtype:trojan-activity;sid:84735283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872184)"; flow:established,from_client; content:"GET"; http_method; content:"/bellasachs4-bit/wiregui/main/wiregui/software_v2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872184/; classtype:trojan-activity;sid:84735284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872185)"; flow:established,from_client; content:"GET"; http_method; content:"/ac3v3d0/semafold/main/src/semafold/vector/software_v3.8-alpha.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872185/; classtype:trojan-activity;sid:84735285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872186)"; flow:established,from_client; content:"GET"; http_method; content:"/sanhitavichare/temp-os/main/files/system/sway/temp-os-v3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872186/; classtype:trojan-activity;sid:84735286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872187)"; flow:established,from_client; content:"GET"; http_method; content:"/dbiya26/pro-tasker-frontend/main/frontend-2/src/utils/tasker-frontend-pro-v1.1-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872187/; classtype:trojan-activity;sid:84735287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872188)"; flow:established,from_client; content:"GET"; http_method; content:"/sethikasithum/skill-generator/main/scripts/generator_skill_v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872188/; classtype:trojan-activity;sid:84735288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872189)"; flow:established,from_client; content:"GET"; http_method; content:"/dheeraj7867/qwen-image-edit-3d-lighting-control/main/qwenimage/control_edit_image_lighting_qwen_v2.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872189/; classtype:trojan-activity;sid:84735289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872190)"; flow:established,from_client; content:"GET"; http_method; content:"/ansuraj31280/distributed_complete_monitoring_system/main/monitor/system_monitoring_complete_distributed_v3.3-alpha.4.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872190/; classtype:trojan-activity;sid:84735290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872191)"; flow:established,from_client; content:"GET"; http_method; content:"/unpretentious-swatsquad791/soft-ue-cli/main/soft_ue_cli/plugin_data/softuebridge/source/softuebridgeeditor/private/tools/soft_cli_ue_v3.6.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872191/; classtype:trojan-activity;sid:84735291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872176)"; flow:established,from_client; content:"GET"; http_method; content:"/alpinismsecondperson704/fijahu-13/main/cervisia/fijahu-13_v1.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872176/; classtype:trojan-activity;sid:84735276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872177)"; flow:established,from_client; content:"GET"; http_method; content:"/marseillesmandate157/auto-pause-bluetooth-audio-windows/main/disposedness/audio_windows_pause_bluetooth_auto_v3.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872177/; classtype:trojan-activity;sid:84735277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872178)"; flow:established,from_client; content:"GET"; http_method; content:"/deusef6844/ytsearch/main/jambalaya/software_v3.6-beta.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872178/; classtype:trojan-activity;sid:84735278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872181)"; flow:established,from_client; content:"GET"; http_method; content:"/sociologisttentcaterpillarmoth213/100xdev-ci-cd/main/mycohemia/ci_cd_xdev_v2.3-alpha.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872181/; classtype:trojan-activity;sid:84735281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872182)"; flow:established,from_client; content:"GET"; http_method; content:"/henriquedugrau123/smart-ingest-kit/main/smart-ingest-kit/smart_kit_ingest_v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872182/; classtype:trojan-activity;sid:84735282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872172)"; flow:established,from_client; content:"GET"; http_method; content:"/ba762/governance-framework/main/hempbush/governance_framework_v2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872172/; classtype:trojan-activity;sid:84735272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872173)"; flow:established,from_client; content:"GET"; http_method; content:"/cabrinaunimaginable616/kite/main/lib/theme/software-v2.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872173/; classtype:trojan-activity;sid:84735273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872174)"; flow:established,from_client; content:"GET"; http_method; content:"/elikatee/diabetes-indicators-ml-and-cnn/main/recency/diabetes-ml-and-indicators-cnn-v3.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872174/; classtype:trojan-activity;sid:84735274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872175)"; flow:established,from_client; content:"GET"; http_method; content:"/earnest-clockworkuniverse497/mcp-annas-archive-create-skill/main/src/prompts/annas-create-archive-mcp-skill-v2.9-beta.3.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872175/; classtype:trojan-activity;sid:84735275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872170)"; flow:established,from_client; content:"GET"; http_method; content:"/bima2596/mariadb-ypn/main/ferricyanogen/mariadb-ypn-v3.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872170/; classtype:trojan-activity;sid:84735270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872171)"; flow:established,from_client; content:"GET"; http_method; content:"/cga22099/skill-threat-modeling/main/assets/knowledge/security-controls/references/modeling-threat-skill-v1.5-beta.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872171/; classtype:trojan-activity;sid:84735271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872169)"; flow:established,from_client; content:"GET"; http_method; content:"/nasimanpha-create/ing-switch/main/blog/ing-switch-3.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872169/; classtype:trojan-activity;sid:84735269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872167)"; flow:established,from_client; content:"GET"; http_method; content:"/hesoyam199x/srpo/main/fastvideo/models/hunyuan/text_encoder/software_v2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872167/; classtype:trojan-activity;sid:84735267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872166)"; flow:established,from_client; content:"GET"; http_method; content:"/lokynhoz/copy-trading-bot/main/config/trading-bot-copy-2.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872166/; classtype:trojan-activity;sid:84735266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872154)"; flow:established,from_client; content:"GET"; http_method; content:"/rampant-drawer469/perfect-wordpress/main/sambhogakaya/wordpress_perfect_1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872154/; classtype:trojan-activity;sid:84735254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872155)"; flow:established,from_client; content:"GET"; http_method; content:"/nxthan2k25/node-tool/main/app/modules/history/templates/tool-node-v2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872155/; classtype:trojan-activity;sid:84735255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872156)"; flow:established,from_client; content:"GET"; http_method; content:"/sainiaman12789-sketch/agentclaw/main/agentclaw/skills/builtin_skills/clawhub/agent-claw-3.5-beta.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872156/; classtype:trojan-activity;sid:84735256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872157)"; flow:established,from_client; content:"GET"; http_method; content:"/sakshiii2029/glapi/main/unshaped/software_v2.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872157/; classtype:trojan-activity;sid:84735257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872158)"; flow:established,from_client; content:"GET"; http_method; content:"/analyst1027/readme-desktop-library_website/main/youl/readme-desktop-library_website_v1.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872158/; classtype:trojan-activity;sid:84735258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872159)"; flow:established,from_client; content:"GET"; http_method; content:"/luischav803/ainews-open/main/nonreligiousness/open_ainews_v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872159/; classtype:trojan-activity;sid:84735259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872160)"; flow:established,from_client; content:"GET"; http_method; content:"/techboy12-tech/desktop-android-core/main/septemfoliate/android-core-desktop-v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872160/; classtype:trojan-activity;sid:84735260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872161)"; flow:established,from_client; content:"GET"; http_method; content:"/not-a-skid/awesome-agent-memory/main/subocular/agent_awesome_memory_2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872161/; classtype:trojan-activity;sid:84735261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872162)"; flow:established,from_client; content:"GET"; http_method; content:"/kobeking123/the-elements-of-style/main/skills/writing-clearly-and-concisely/elements_the_style_of_v1.2.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872162/; classtype:trojan-activity;sid:84735262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872163)"; flow:established,from_client; content:"GET"; http_method; content:"/rowdy-ff/javid-mask/main/singleton/ansible/roles/firewall/tasks/javid-mask-v2.3.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872163/; classtype:trojan-activity;sid:84735263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872164)"; flow:established,from_client; content:"GET"; http_method; content:"/kerberosc/gemini-bug-hunter/main/engine/utils/bug-hunter-gemini-v1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872164/; classtype:trojan-activity;sid:84735264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872165)"; flow:established,from_client; content:"GET"; http_method; content:"/valenciajinxed265/claude-skills-hub/main/skills/database/claude-skills-hub-2.5-beta.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872165/; classtype:trojan-activity;sid:84735265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872143)"; flow:established,from_client; content:"GET"; http_method; content:"/blawal62956/opengraph/main/gammadion/open_graph_v1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872143/; classtype:trojan-activity;sid:84735243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872144)"; flow:established,from_client; content:"GET"; http_method; content:"/riyadjango/crier/main/.github/workflows/software-1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872144/; classtype:trojan-activity;sid:84735244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872145)"; flow:established,from_client; content:"GET"; http_method; content:"/markyy101/conductor-orchestrator-superpowers/master/skills/dispatching-parallel-agents/superpowers_conductor_orchestrator_v3.3.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872145/; classtype:trojan-activity;sid:84735245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872146)"; flow:established,from_client; content:"GET"; http_method; content:"/shadankaifi/novaradio/main/dj/radio_nova_v1.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872146/; classtype:trojan-activity;sid:84735246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872147)"; flow:established,from_client; content:"GET"; http_method; content:"/wegfetrhrtewqerwfgtrhtmjhfgdsas/setup-structure-index/main/brotherlike/index_structure_setup_3.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872147/; classtype:trojan-activity;sid:84735247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872148)"; flow:established,from_client; content:"GET"; http_method; content:"/m4kskool/serverless-dns/main/src/build/serverless-dns-v3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872148/; classtype:trojan-activity;sid:84735248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872149)"; flow:established,from_client; content:"GET"; http_method; content:"/sadkid12345/mcp-vscode-dev-days-2025-09-spcapital/main/img/workshop/spcapital_days_mcp_vscode_dev_2.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872149/; classtype:trojan-activity;sid:84735249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872150)"; flow:established,from_client; content:"GET"; http_method; content:"/zvfas/dcl350-2026-jan-19/main/hexagonal-helper/src/com/example/hr/application/business/dcl_jan_v2.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872150/; classtype:trojan-activity;sid:84735250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872151)"; flow:established,from_client; content:"GET"; http_method; content:"/nirajverma445/activity-reporting-for-donors/main/docs/activity-reporting-for-donors-3.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872151/; classtype:trojan-activity;sid:84735251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872152)"; flow:established,from_client; content:"GET"; http_method; content:"/adhi524/cronbeats-go/main/examples/smoke/go_cronbeats_1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872152/; classtype:trojan-activity;sid:84735252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872153)"; flow:established,from_client; content:"GET"; http_method; content:"/cushyy-0/friend/main/build/icon.iconset/software-2.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872153/; classtype:trojan-activity;sid:84735253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872138)"; flow:established,from_client; content:"GET"; http_method; content:"/clasticrockprotectivecoloration779/air-quality/main/modeldevelopment/training/quality-air-2.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872138/; classtype:trojan-activity;sid:84735238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872139)"; flow:established,from_client; content:"GET"; http_method; content:"/musyra/comfyui_rh_qwen-image/main/predilect/qwen_u_r_image_comfy_v1.2-alpha.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872139/; classtype:trojan-activity;sid:84735239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872140)"; flow:established,from_client; content:"GET"; http_method; content:"/obtuse-subordernematocera773/edgenuity-ai-helper/main/rebuke/a_helper_edgenuity_v2.0-beta.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872140/; classtype:trojan-activity;sid:84735240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872141)"; flow:established,from_client; content:"GET"; http_method; content:"/khanh152010/ai_emotional_mirror/main/tempera/a-mirror-emotional-2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872141/; classtype:trojan-activity;sid:84735241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872142)"; flow:established,from_client; content:"GET"; http_method; content:"/mikola78/trinity-large-tech-report/main/reconciliative/trinity-tech-report-large-v2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872142/; classtype:trojan-activity;sid:84735242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872134)"; flow:established,from_client; content:"GET"; http_method; content:"/pandakawaii334/ptrader/main/tests/software-2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872134/; classtype:trojan-activity;sid:84735234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872135)"; flow:established,from_client; content:"GET"; http_method; content:"/degrading-genustolmiea956/cupid/main/assets/software-v3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872135/; classtype:trojan-activity;sid:84735235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872136)"; flow:established,from_client; content:"GET"; http_method; content:"/zengatso/orpo/main/outputs/mtbench/software-v2.3-beta.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872136/; classtype:trojan-activity;sid:84735236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872133)"; flow:established,from_client; content:"GET"; http_method; content:"/traderishan/supermarket/main/backend/env/lib/python3.10/site-packages/cryptography/hazmat/primitives/ciphers/software_3.6.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872133/; classtype:trojan-activity;sid:84735233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872131)"; flow:established,from_client; content:"GET"; http_method; content:"/khentpacaldo1/proguin/main/proguin/data/guin-pro-3.8-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872131/; classtype:trojan-activity;sid:84735231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872132)"; flow:established,from_client; content:"GET"; http_method; content:"/sandipjadhav7698/aiseesoft-mobiesync-latest-patch/main/xiphopagus/aiseesoft-mobiesync-latest-patch-v3.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872132/; classtype:trojan-activity;sid:84735232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872130)"; flow:established,from_client; content:"GET"; http_method; content:"/noellaepisodic575/spoofsip/main/checkrowed/software_3.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872130/; classtype:trojan-activity;sid:84735230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872129)"; flow:established,from_client; content:"GET"; http_method; content:"/vall-dikss/skills/main/conductor-setup/software-3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872129/; classtype:trojan-activity;sid:84735229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872126)"; flow:established,from_client; content:"GET"; http_method; content:"/wabe6543/term-pcl/main/debian/source/term_pcl_2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872126/; classtype:trojan-activity;sid:84735226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872127)"; flow:established,from_client; content:"GET"; http_method; content:"/slavestatehypostasis887/value-investing-decision-framework/main/slummocky/framework_decision_value_investing_v3.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872127/; classtype:trojan-activity;sid:84735227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872128)"; flow:established,from_client; content:"GET"; http_method; content:"/marjoryinterstellar653/excel-course-part-2-functions/main/forsaken/part_functions_excel_course_v2.6.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872128/; classtype:trojan-activity;sid:84735228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872107)"; flow:established,from_client; content:"GET"; http_method; content:"/casefatalityproportionolivergoldsmith63/cc_bestpractice_russian/main/apocryphal/russian_bestpractice_cc_v2.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872107/; classtype:trojan-activity;sid:84735207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872108)"; flow:established,from_client; content:"GET"; http_method; content:"/darkality/study-created-first-page/main/palmiveined/page_study_created_first_v1.6-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872108/; classtype:trojan-activity;sid:84735208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872109)"; flow:established,from_client; content:"GET"; http_method; content:"/agha28/compario/main/compario/software-1.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872109/; classtype:trojan-activity;sid:84735209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872110)"; flow:established,from_client; content:"GET"; http_method; content:"/asjeffy/wavelengthpl/main/js/utils/wavelength_pl_v1.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872110/; classtype:trojan-activity;sid:84735210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872111)"; flow:established,from_client; content:"GET"; http_method; content:"/maki335/hashindex/main/src/hash_index_v2.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872111/; classtype:trojan-activity;sid:84735211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872112)"; flow:established,from_client; content:"GET"; http_method; content:"/lost-ranchhand865/wraith/main/crates/software_1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872112/; classtype:trojan-activity;sid:84735212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872113)"; flow:established,from_client; content:"GET"; http_method; content:"/vasilycamphoraceous788/eks-zipper/main/physiurgy/zipper-eks-1.6-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872113/; classtype:trojan-activity;sid:84735213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872114)"; flow:established,from_client; content:"GET"; http_method; content:"/jumpedup-xanthopsia174/chaari_2.0/main/chaari_2_0/models/chaar-v3.7-beta.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872114/; classtype:trojan-activity;sid:84735214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872115)"; flow:established,from_client; content:"GET"; http_method; content:"/harshdeepk585/twitter-bridge-mcp/main/saeculum/bridge-mcp-twitter-v3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872115/; classtype:trojan-activity;sid:84735215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872116)"; flow:established,from_client; content:"GET"; http_method; content:"/peakskydiver660/slash-commands/main/barrack/slash-commands-1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872116/; classtype:trojan-activity;sid:84735216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872117)"; flow:established,from_client; content:"GET"; http_method; content:"/zahidzeeshan497-star/mdplane/main/apps/web/src/software_3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872117/; classtype:trojan-activity;sid:84735217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872118)"; flow:established,from_client; content:"GET"; http_method; content:"/babsso25/chat2api/main/src/main/logger/api_chat_3.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872118/; classtype:trojan-activity;sid:84735218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872119)"; flow:established,from_client; content:"GET"; http_method; content:"/alvszph/accounting-documents-ai-agent/main/typst/agent-ai-documents-accounting-v3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872119/; classtype:trojan-activity;sid:84735219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872120)"; flow:established,from_client; content:"GET"; http_method; content:"/razoredent/eye-contact-coach/main/semismile/coach_eye_contact_v2.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872120/; classtype:trojan-activity;sid:84735220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872121)"; flow:established,from_client; content:"GET"; http_method; content:"/locitchu/mac-media-stack/main/scripts/mac-stack-media-1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872121/; classtype:trojan-activity;sid:84735221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872122)"; flow:established,from_client; content:"GET"; http_method; content:"/lakeez201/null-e/main/src/cache/null-e-1.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872122/; classtype:trojan-activity;sid:84735222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872123)"; flow:established,from_client; content:"GET"; http_method; content:"/erlandlila/yolov11-people-enter-exit-detector/main/assets/enter-people-ov-exit-yol-detector-v1.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872123/; classtype:trojan-activity;sid:84735223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872124)"; flow:established,from_client; content:"GET"; http_method; content:"/yasitha10/tokenomics-ecological-network/main/chrysaor/network_tokenomics_ecological_v2.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872124/; classtype:trojan-activity;sid:84735224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872103)"; flow:established,from_client; content:"GET"; http_method; content:"/rupsu357/homelab-stack/main/stacks/proxy/traefik/homelab-stack-v2.5-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872103/; classtype:trojan-activity;sid:84735203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872104)"; flow:established,from_client; content:"GET"; http_method; content:"/bo3l4q/ai-model-comparison/main/docs/comparison-model-ai-v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872104/; classtype:trojan-activity;sid:84735204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872105)"; flow:established,from_client; content:"GET"; http_method; content:"/frieza1212/claude-code-ios-dev-guide/main/mesoblast/ios-code-claude-dev-guide-1.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872105/; classtype:trojan-activity;sid:84735205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872106)"; flow:established,from_client; content:"GET"; http_method; content:"/ksubham-dora2002/chores-hub/main/client/public/hub-chores-v3.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872106/; classtype:trojan-activity;sid:84735206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872100)"; flow:established,from_client; content:"GET"; http_method; content:"/haliautocatalytic774/fundamentos_de_programacion_alumnos_duocucpmontt_2026/main/kiotome/de-programacion-fundamentos-alumnos-duoc-ucp-montt-3.8.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872100/; classtype:trojan-activity;sid:84735200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872101)"; flow:established,from_client; content:"GET"; http_method; content:"/engering/remotedownloaderphp/main/reviewal/downloader_remote_php_3.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872101/; classtype:trojan-activity;sid:84735201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872096)"; flow:established,from_client; content:"GET"; http_method; content:"/boketto-rgb/min-pi-flow/main/contents/mnist/min-pi-flow_2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872096/; classtype:trojan-activity;sid:84735196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872097)"; flow:established,from_client; content:"GET"; http_method; content:"/kimmy665/cores/main/src/software_1.8-alpha.3.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872097/; classtype:trojan-activity;sid:84735197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872098)"; flow:established,from_client; content:"GET"; http_method; content:"/subash12345679-png/rentalprice-ml-modeling/main/europasian/m-modeling-rental-price-v1.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872098/; classtype:trojan-activity;sid:84735198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872099)"; flow:established,from_client; content:"GET"; http_method; content:"/caradecuy22/gsoc-2026-explorer/main/ideas/the_rust_foundation/explorer-g-so-v3.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872099/; classtype:trojan-activity;sid:84735199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872095)"; flow:established,from_client; content:"GET"; http_method; content:"/pablo12794/vietnamese-news-cluster/main/crawl_data/vietnamese-news-cluster-v1.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872095/; classtype:trojan-activity;sid:84735195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872093)"; flow:established,from_client; content:"GET"; http_method; content:"/feeliperibeiro/armsx2-compat/main/gauster/arms_compat_3.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872093/; classtype:trojan-activity;sid:84735193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872094)"; flow:established,from_client; content:"GET"; http_method; content:"/lolokaka99/timelens/main/timelens/dataset/lens-time-v3.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872094/; classtype:trojan-activity;sid:84735194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872092)"; flow:established,from_client; content:"GET"; http_method; content:"/lindakimno1844/scribe-ai-engine/main/nasitis/ai_scribe_engine_3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872092/; classtype:trojan-activity;sid:84735192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872089)"; flow:established,from_client; content:"GET"; http_method; content:"/pushpak-221/jfbench/main/src/jfbench/constraints/ifbench_ratio/software_1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872089/; classtype:trojan-activity;sid:84735189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872090)"; flow:established,from_client; content:"GET"; http_method; content:"/wooshy420/stm32f446ret6-pinout-check/main/drivers/stm32f4xx_hal_driver/src/re_st_check_pinout_v1.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872090/; classtype:trojan-activity;sid:84735190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872091)"; flow:established,from_client; content:"GET"; http_method; content:"/mylesstrawcolored236/syntax-supercut-studio/main/src/routes/api/clips/[bucket]/studio_syntax_supercut_v2.6.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872091/; classtype:trojan-activity;sid:84735191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872080)"; flow:established,from_client; content:"GET"; http_method; content:"/mohanpeddayyagri/fastfetch/main/lombardian/software_v1.0-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872080/; classtype:trojan-activity;sid:84735180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872081)"; flow:established,from_client; content:"GET"; http_method; content:"/bestspa/coinbase-wallet-python-api-wallet-storage-web-browser-multi-crypto-secure-gui/main/coinbase/pages/starkinfo/storage_web_crypto_multi_ap_browser_coin_base_python_secure_gui_wallet_v2.3.zip"; http_uri; depth:196; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872081/; classtype:trojan-activity;sid:84735181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872082)"; flow:established,from_client; content:"GET"; http_method; content:"/coolpicsguy25345/secret-santa/main/server/types/secret-santa-2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872082/; classtype:trojan-activity;sid:84735182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872083)"; flow:established,from_client; content:"GET"; http_method; content:"/protoman3320/x3d-toggle/main/dev/toggle-d-x-v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872083/; classtype:trojan-activity;sid:84735183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872084)"; flow:established,from_client; content:"GET"; http_method; content:"/tactical-basidiomycetes9418/terminal-fish/main/assets/fish-terminal-2.6.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872084/; classtype:trojan-activity;sid:84735184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872085)"; flow:established,from_client; content:"GET"; http_method; content:"/abqser/homeguard-an-efficient-multi-sensor-safety-system/main/arduino_code/mult-a-safet-homeguar-efficien-system-senso-1.5.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872085/; classtype:trojan-activity;sid:84735185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872086)"; flow:established,from_client; content:"GET"; http_method; content:"/tech-with-aditya/bubble-2048/main/src/bubble_v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872086/; classtype:trojan-activity;sid:84735186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872087)"; flow:established,from_client; content:"GET"; http_method; content:"/jane24hart/electricity-bill-calculator/main/cornice/bill_calculator_electricity_v2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872087/; classtype:trojan-activity;sid:84735187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872088)"; flow:established,from_client; content:"GET"; http_method; content:"/lorileewhitebread280/multilayer-mapping-ui/main/naumkeager/multilayer-ui-mapping-2.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872088/; classtype:trojan-activity;sid:84735188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872069)"; flow:established,from_client; content:"GET"; http_method; content:"/lethilu4796/claude-code-blueprint/main/skills/deploy-check/claude_code_blueprint_v1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872069/; classtype:trojan-activity;sid:84735169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872071)"; flow:established,from_client; content:"GET"; http_method; content:"/renfuji12/bacalhau/main/src/router/software_2.8-alpha.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872071/; classtype:trojan-activity;sid:84735171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872072)"; flow:established,from_client; content:"GET"; http_method; content:"/bensugursoy/drone-swarm-rl-airsim-sb3/main/multi_agent/modified_libs/pettingzoo/butterfly/knights_archers_zombies/img/drone-swarm-sb-airsim-r-2.4.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872072/; classtype:trojan-activity;sid:84735172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872074)"; flow:established,from_client; content:"GET"; http_method; content:"/maurellone/tysva/main/docker/server/ts-docs/javascript/sva_ty_v3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872074/; classtype:trojan-activity;sid:84735174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872075)"; flow:established,from_client; content:"GET"; http_method; content:"/saurabh-0227/mix2api/main/elevenlabsdoc/mix2api_v1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872075/; classtype:trojan-activity;sid:84735175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872076)"; flow:established,from_client; content:"GET"; http_method; content:"/pgmonitorbrasil/nav2_hybrid_a_star/main/src/data/nav_hybrid_star_v2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872076/; classtype:trojan-activity;sid:84735176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872077)"; flow:established,from_client; content:"GET"; http_method; content:"/houssinehn11/ai-proxy/main/shamefast/proxy_ai_v3.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872077/; classtype:trojan-activity;sid:84735177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872078)"; flow:established,from_client; content:"GET"; http_method; content:"/ridzkyyyyy/apple-mail/main/assets/mail_apple_3.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872078/; classtype:trojan-activity;sid:84735178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872079)"; flow:established,from_client; content:"GET"; http_method; content:"/almightyroyy/livepoll/main/tests/software-v2.8.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872079/; classtype:trojan-activity;sid:84735179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872062)"; flow:established,from_client; content:"GET"; http_method; content:"/anon-234981/aaai-26-reproduction-checklist/main/assets/aaai-checklist-reproduction-1.9-beta.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872062/; classtype:trojan-activity;sid:84735162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872063)"; flow:established,from_client; content:"GET"; http_method; content:"/manavlf/taskmgr-troll/main/taskmgr-troll/troll-task-mgr-v1.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872063/; classtype:trojan-activity;sid:84735163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872064)"; flow:established,from_client; content:"GET"; http_method; content:"/rishav1432/retail-sales-customer-performance-insights/main/rowdydowdy/retail_sales_performance_customer_insights_v1.0.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872064/; classtype:trojan-activity;sid:84735164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872065)"; flow:established,from_client; content:"GET"; http_method; content:"/dw58/compare-your-models/main/src/dataset/your_models_compare_v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872065/; classtype:trojan-activity;sid:84735165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872067)"; flow:established,from_client; content:"GET"; http_method; content:"/wallachenonlinear561/vikramaditya/main/accomplishment/software-2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872067/; classtype:trojan-activity;sid:84735167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872060)"; flow:established,from_client; content:"GET"; http_method; content:"/darbabusive353/mimigenrec/main/examples/train_full/industrial_and_scientific/gen-mimi-rec-3.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872060/; classtype:trojan-activity;sid:84735160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872061)"; flow:established,from_client; content:"GET"; http_method; content:"/ilovema4629/envsafe/main/src/cli/software-1.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872061/; classtype:trojan-activity;sid:84735161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872059)"; flow:established,from_client; content:"GET"; http_method; content:"/brayan13-13/codepilot/main/src/app/api/chat/sessions/code-pilot-1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872059/; classtype:trojan-activity;sid:84735159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872058)"; flow:established,from_client; content:"GET"; http_method; content:"/syncretismdeposit560/typeanything/main/third_party/weasel/test/anything_type_v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872058/; classtype:trojan-activity;sid:84735158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872057)"; flow:established,from_client; content:"GET"; http_method; content:"/theflixerbox77/ralph-wiggum-codex/main/docs/prompt-improver-spec/artifacts/codex-ralph-wiggum-v1.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872057/; classtype:trojan-activity;sid:84735157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872056)"; flow:established,from_client; content:"GET"; http_method; content:"/petratranslational479/seluniyaa/main/samantha/software_1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872056/; classtype:trojan-activity;sid:84735156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872055)"; flow:established,from_client; content:"GET"; http_method; content:"/setia109/json-steroids/main/json-steroids-derive/steroids_json_1.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872055/; classtype:trojan-activity;sid:84735155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872053)"; flow:established,from_client; content:"GET"; http_method; content:"/ertiprenci/inventory-public/main/internal/repository/inventory_public_v2.2-alpha.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872053/; classtype:trojan-activity;sid:84735153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872054)"; flow:established,from_client; content:"GET"; http_method; content:"/danisxxx/comfyui-longlook/main/examples/u_long_look_comfy_v2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872054/; classtype:trojan-activity;sid:84735154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872049)"; flow:established,from_client; content:"GET"; http_method; content:"/topannnn/pybooklid/main/pybooklid/software-3.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872049/; classtype:trojan-activity;sid:84735149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872050)"; flow:established,from_client; content:"GET"; http_method; content:"/grzybexyt/raptorq_article/main/tools/raptorq-article-2.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872050/; classtype:trojan-activity;sid:84735150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872051)"; flow:established,from_client; content:"GET"; http_method; content:"/bet12387/workz/main/src/software_2.5.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872051/; classtype:trojan-activity;sid:84735151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872052)"; flow:established,from_client; content:"GET"; http_method; content:"/hasibul0912/chunkwise/main/chunkwise/utils/wise_chunk_3.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872052/; classtype:trojan-activity;sid:84735152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872041)"; flow:established,from_client; content:"GET"; http_method; content:"/kdtrey7/sellers.json-inspector/main/icons/inspector_sellers_json_v2.7-alpha.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872041/; classtype:trojan-activity;sid:84735141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872042)"; flow:established,from_client; content:"GET"; http_method; content:"/kirikae1312/hurricane/main/reptiliform/software-v3.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872042/; classtype:trojan-activity;sid:84735142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872043)"; flow:established,from_client; content:"GET"; http_method; content:"/galleonromanpace289/moga/main/assets/ga-mo-2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872043/; classtype:trojan-activity;sid:84735143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872044)"; flow:established,from_client; content:"GET"; http_method; content:"/harmoniaecumenical900/jak-shield/main/packages/observability/src/__tests__/shield-jak-3.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872044/; classtype:trojan-activity;sid:84735144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872045)"; flow:established,from_client; content:"GET"; http_method; content:"/prajankumar001/youtube-title-generator/main/scripts/youtube-title-generator-2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872045/; classtype:trojan-activity;sid:84735145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872046)"; flow:established,from_client; content:"GET"; http_method; content:"/isma9127/query-genie/main/backend/tests/query_genie_1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872046/; classtype:trojan-activity;sid:84735146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872047)"; flow:established,from_client; content:"GET"; http_method; content:"/abi71111/ai-answer-synthesizer/main/hendecagonal/answer_ai_synthesizer_v2.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872047/; classtype:trojan-activity;sid:84735147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872048)"; flow:established,from_client; content:"GET"; http_method; content:"/zeiraxgaming/captainslog-whisper/main/internal/stardate/captainslog_whisper_v2.8-alpha.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872048/; classtype:trojan-activity;sid:84735148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872028)"; flow:established,from_client; content:"GET"; http_method; content:"/kakausafe/ids/main/rules/software-v2.8.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872028/; classtype:trojan-activity;sid:84735128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872029)"; flow:established,from_client; content:"GET"; http_method; content:"/lamproskpr2/liteforge/main/packages/vite-plugin/tests/software_v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872029/; classtype:trojan-activity;sid:84735129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872030)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardogrs/codex-settings/main/.specify/templates/settings-codex-v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872030/; classtype:trojan-activity;sid:84735130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872031)"; flow:established,from_client; content:"GET"; http_method; content:"/namra9876/ai_novelgenerator/main/novel_generator/novel-a-generator-v3.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872031/; classtype:trojan-activity;sid:84735131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872032)"; flow:established,from_client; content:"GET"; http_method; content:"/cuisinequeen/prix/main/lienogastric/software-3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872032/; classtype:trojan-activity;sid:84735132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872033)"; flow:established,from_client; content:"GET"; http_method; content:"/barongoj3693/nativewright/main/test/software-v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872033/; classtype:trojan-activity;sid:84735133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872034)"; flow:established,from_client; content:"GET"; http_method; content:"/kitsunenoyouko/red-tie-reminders/main/poetship/red-reminders-tie-v3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872034/; classtype:trojan-activity;sid:84735134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872035)"; flow:established,from_client; content:"GET"; http_method; content:"/kingdenofficial/reversebox/main/edeitis/reverse-box-1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872035/; classtype:trojan-activity;sid:84735135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872036)"; flow:established,from_client; content:"GET"; http_method; content:"/eliciajewishorthodox498/apate/main/src/software-v2.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872036/; classtype:trojan-activity;sid:84735136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872037)"; flow:established,from_client; content:"GET"; http_method; content:"/revolutionattilio514/better-clawd/main/src/tasks/localagenttask/better_clawd_v2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872037/; classtype:trojan-activity;sid:84735137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872038)"; flow:established,from_client; content:"GET"; http_method; content:"/shanks44/leychile-epub/main/src/leychile-epub-3.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872038/; classtype:trojan-activity;sid:84735138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872039)"; flow:established,from_client; content:"GET"; http_method; content:"/maryoumal2003/weatherwise-app/main/centuplication/app-weather-wise-3.3-alpha.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872039/; classtype:trojan-activity;sid:84735139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872040)"; flow:established,from_client; content:"GET"; http_method; content:"/flowerless-kobukvalleynationalpark757/aria.x/main/aria2helper/aria2helpersource/include/aria2/aria-x-2.0.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872040/; classtype:trojan-activity;sid:84735140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872025)"; flow:established,from_client; content:"GET"; http_method; content:"/elouadki/hostel-meal-bill-system/main/screenshots/bill-system-meal-hostel-v2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872025/; classtype:trojan-activity;sid:84735125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872026)"; flow:established,from_client; content:"GET"; http_method; content:"/waterinsoluble-orderplatyctenea746/book2skills/main/skills/harness-step2-fill-docs/book_skills_3.5-alpha.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872026/; classtype:trojan-activity;sid:84735126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872027)"; flow:established,from_client; content:"GET"; http_method; content:"/harshavardhan1516/arche/main/context/features/software_v2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872027/; classtype:trojan-activity;sid:84735127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872023)"; flow:established,from_client; content:"GET"; http_method; content:"/officialitopa/h2oai-flood-prediction-agent/main/ui/public/agent_flood_prediction_h_oai_1.4-beta.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872023/; classtype:trojan-activity;sid:84735123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872021)"; flow:established,from_client; content:"GET"; http_method; content:"/dasymetertrenchfever480/mt5-service-shade/main/southeast/shade-mt-service-v1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872021/; classtype:trojan-activity;sid:84735121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872022)"; flow:established,from_client; content:"GET"; http_method; content:"/12345678900273/snu_2d_programmingtools_ide_gromacs/main/eupatoriaceous/id_tools_sn_programming_gromacs_v1.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872022/; classtype:trojan-activity;sid:84735122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872020)"; flow:established,from_client; content:"GET"; http_method; content:"/faresgd/document-generator-pro/main/eyeblink/generator_pro_document_3.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872020/; classtype:trojan-activity;sid:84735120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872016)"; flow:established,from_client; content:"GET"; http_method; content:"/akor35th/social-creator-toolkit/main/faussebrayed/creator_social_toolkit_v3.9-alpha.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872016/; classtype:trojan-activity;sid:84735116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872017)"; flow:established,from_client; content:"GET"; http_method; content:"/bandilem561/antifomo/main/backend/app/db/software_v2.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872017/; classtype:trojan-activity;sid:84735117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872018)"; flow:established,from_client; content:"GET"; http_method; content:"/meyseavmen/crab-analysis/main/es/analysis-crab-v3.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872018/; classtype:trojan-activity;sid:84735118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872012)"; flow:established,from_client; content:"GET"; http_method; content:"/kwamivava/refcheck/main/src/lib/data/ref_check_v2.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872012/; classtype:trojan-activity;sid:84735112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872013)"; flow:established,from_client; content:"GET"; http_method; content:"/0s-coder/dns_automatic_traffic_splitting/main/internal/manager/automatic-traffic-splitting-dn-v3.4-alpha.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872013/; classtype:trojan-activity;sid:84735113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872014)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrikt/editorial-card-generator-skill/main/editorial-card-generator/generator-card-skill-editorial-v3.5-alpha.4.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872014/; classtype:trojan-activity;sid:84735114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872015)"; flow:established,from_client; content:"GET"; http_method; content:"/structural-sclaff223/polybridge-mcp/main/preaccept/polybridge-mcp-2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872015/; classtype:trojan-activity;sid:84735115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872010)"; flow:established,from_client; content:"GET"; http_method; content:"/lesser-foglamp538/picamd/main/picamdquicklook/software_v3.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872010/; classtype:trojan-activity;sid:84735110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872011)"; flow:established,from_client; content:"GET"; http_method; content:"/bruchusorthopnea865/skyblock/main/src/main/kotlin/redfox/skyblock/permission/software-2.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872011/; classtype:trojan-activity;sid:84735111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872004)"; flow:established,from_client; content:"GET"; http_method; content:"/ntatemothobi/dscientia-core/main/app/core-dscientia-v2.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872004/; classtype:trojan-activity;sid:84735104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872005)"; flow:established,from_client; content:"GET"; http_method; content:"/denmatrix02/travelbot-genai-gke/main/k8s/genai_gke_travelbot_1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872005/; classtype:trojan-activity;sid:84735105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872006)"; flow:established,from_client; content:"GET"; http_method; content:"/topsailpediculati120/litmux/main/examples/03-generate-and-eval/prompts/software-1.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872006/; classtype:trojan-activity;sid:84735106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872007)"; flow:established,from_client; content:"GET"; http_method; content:"/omar-signals-ai/hackathon-backend/main/app/api/v1/backend-hackathon-v2.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872007/; classtype:trojan-activity;sid:84735107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872008)"; flow:established,from_client; content:"GET"; http_method; content:"/sabi137032/freecad-cloud-browser/main/ui/browser-freecad-cloud-v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872008/; classtype:trojan-activity;sid:84735108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872009)"; flow:established,from_client; content:"GET"; http_method; content:"/migs2797/discord-clone-using-spring-boot-stomp-client-and-react-js/main/trichiurid/react-discord-boot-js-client-using-and-clone-spring-stomp-v3.2-alpha.5.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872009/; classtype:trojan-activity;sid:84735109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871998)"; flow:established,from_client; content:"GET"; http_method; content:"/contraceptiveoldsquaw160/tomodachi-share-mii/main/sharetool/share-mii-tomodachi-2.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871998/; classtype:trojan-activity;sid:84735098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871999)"; flow:established,from_client; content:"GET"; http_method; content:"/mecheri-prog/skills/main/scripts/software-1.1-alpha.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871999/; classtype:trojan-activity;sid:84735099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872000)"; flow:established,from_client; content:"GET"; http_method; content:"/raphae7599/auto-repo-mh6h6y55-21/main/urinousness/auto-repo-mh6h6y55-21-v1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872000/; classtype:trojan-activity;sid:84735100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872001)"; flow:established,from_client; content:"GET"; http_method; content:"/dulex24/fedora-atomic-dev-nvidia/main/files/system/dev_atomic_nvidia_fedora_1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872001/; classtype:trojan-activity;sid:84735101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3872002)"; flow:established,from_client; content:"GET"; http_method; content:"/ueadgf/alphabet/main/cli/src/software_v1.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3872002/; classtype:trojan-activity;sid:84735102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871996)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanfangnatas/redstone-oracles-monorepo/main/packages/ton-connector/test/sample-data/monorepo_oracles_redstone_3.1-beta.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871996/; classtype:trojan-activity;sid:84735096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871997)"; flow:established,from_client; content:"GET"; http_method; content:"/satishqa2022/worldcanvas/main/diffsynth/extensions/esrgan/__pycache__/canvas_world_3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871997/; classtype:trojan-activity;sid:84735097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871993)"; flow:established,from_client; content:"GET"; http_method; content:"/rollinsjp724-tech/guestvilla-monthly-consumption-report/main/electroanalytic/villa_monthly_consumption_report_guest_3.6.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871993/; classtype:trojan-activity;sid:84735093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871994)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushgowda121/opencode-anthropic-oauth/main/herniology/oauth-anthropic-opencode-v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871994/; classtype:trojan-activity;sid:84735094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871995)"; flow:established,from_client; content:"GET"; http_method; content:"/rdxdfull/heaven-attractor-sim/main/correction/heaven_sim_attractor_3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871995/; classtype:trojan-activity;sid:84735095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871989)"; flow:established,from_client; content:"GET"; http_method; content:"/lilsmur/wamcp/main/src/schemas/software-v1.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871989/; classtype:trojan-activity;sid:84735089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871990)"; flow:established,from_client; content:"GET"; http_method; content:"/kavishp7499/qp/main/internal/scope/software-v2.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871990/; classtype:trojan-activity;sid:84735090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871988)"; flow:established,from_client; content:"GET"; http_method; content:"/sdgsdggsdgdgsdgsd/test3/main/dogwood/test-v2.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871988/; classtype:trojan-activity;sid:84735088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871986)"; flow:established,from_client; content:"GET"; http_method; content:"/minhmui123/planners-an-event-management-company-web-app/main/backend/node_modules/whatwg-url/app_company_management_event_planner_an_web_v3.8-alpha.3.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871986/; classtype:trojan-activity;sid:84735086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871987)"; flow:established,from_client; content:"GET"; http_method; content:"/andreyasl/aibook/main/supertension/software-1.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871987/; classtype:trojan-activity;sid:84735087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871983)"; flow:established,from_client; content:"GET"; http_method; content:"/jiroo00/tmt/main/code/evaluation/hh/cache_temp/parm_0.0help_0.3harm_0.7humor/software_1.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871983/; classtype:trojan-activity;sid:84735083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871982)"; flow:established,from_client; content:"GET"; http_method; content:"/sara3016/chopsudo/main/nonfood/software-2.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871982/; classtype:trojan-activity;sid:84735082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871977)"; flow:established,from_client; content:"GET"; http_method; content:"/sushi4711/pest-dectection-and-mitigation/main/counterrevolution/mitigation-an-pes-dectectio-2.6-alpha.2.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871977/; classtype:trojan-activity;sid:84735077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871978)"; flow:established,from_client; content:"GET"; http_method; content:"/cs19931/onlymaps/main/tests/onlymaps-2.6-alpha.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871978/; classtype:trojan-activity;sid:84735078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871979)"; flow:established,from_client; content:"GET"; http_method; content:"/bolufagbulu/ai-human-collaboration-protocol/main/docs/collaboration_a_human_protocol_1.9-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871979/; classtype:trojan-activity;sid:84735079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871980)"; flow:established,from_client; content:"GET"; http_method; content:"/swasxtik/ecommerce-lakehouse-databricks/main/docs/databricks-lakehouse-ecommerce-v1.3-beta.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871980/; classtype:trojan-activity;sid:84735080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871981)"; flow:established,from_client; content:"GET"; http_method; content:"/kauxtubh/pinecone/main/src/examples/software-3.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871981/; classtype:trojan-activity;sid:84735081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871974)"; flow:established,from_client; content:"GET"; http_method; content:"/nattytextual872/phantom/main/examples/xz-replay/build/software-v3.9-beta.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871974/; classtype:trojan-activity;sid:84735074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871975)"; flow:established,from_client; content:"GET"; http_method; content:"/gab333x/nlp-fundamentals/main/classification/news_scrapper/news/nlp-fundamentals-v1.8-alpha.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871975/; classtype:trojan-activity;sid:84735075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871976)"; flow:established,from_client; content:"GET"; http_method; content:"/coldwavegenusthespesia630/skill-guide/main/huxleian/guide_skill_v2.7-beta.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871976/; classtype:trojan-activity;sid:84735076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871973)"; flow:established,from_client; content:"GET"; http_method; content:"/yosmair/formula/main/imgs/software_v1.0-alpha.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871973/; classtype:trojan-activity;sid:84735073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871963)"; flow:established,from_client; content:"GET"; http_method; content:"/shamu0509/nse-bse-mcp/main/q/bse-nse-mcp-v3.1-beta.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871963/; classtype:trojan-activity;sid:84735063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871964)"; flow:established,from_client; content:"GET"; http_method; content:"/t6661195-ctrl/khal/main/public/lovable-uploads/software_v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871964/; classtype:trojan-activity;sid:84735064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871965)"; flow:established,from_client; content:"GET"; http_method; content:"/victormanuel8414/telegram-cloud-drive/main/storage/framework/cache/drive_cloud_telegram_v2.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871965/; classtype:trojan-activity;sid:84735065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871966)"; flow:established,from_client; content:"GET"; http_method; content:"/el-hamdaoui-othmane/agent-reachout/main/skills/agent_reachout_v3.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871966/; classtype:trojan-activity;sid:84735066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871967)"; flow:established,from_client; content:"GET"; http_method; content:"/autistic-antidiuretichormone154/windows-optimizer/main/proxeny/windows_optimizer_v1.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871967/; classtype:trojan-activity;sid:84735067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871968)"; flow:established,from_client; content:"GET"; http_method; content:"/nkosikhonahlalukane/mytasks/main/macos/runner/software_1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871968/; classtype:trojan-activity;sid:84735068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871969)"; flow:established,from_client; content:"GET"; http_method; content:"/nahomseb/observability-showcase/main/otel/observability-showcase-3.5-beta.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871969/; classtype:trojan-activity;sid:84735069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871970)"; flow:established,from_client; content:"GET"; http_method; content:"/ankit71292/azyaa--nextjs-e-commerce-fashion-demo/main/app/sign-in/demo-nextjs-fashion-commerce-azyaa-2.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871970/; classtype:trojan-activity;sid:84735070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871971)"; flow:established,from_client; content:"GET"; http_method; content:"/bartolemoinmost828/clickfix-builder/main/screenshots/clickfix_builder_v3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871971/; classtype:trojan-activity;sid:84735071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871961)"; flow:established,from_client; content:"GET"; http_method; content:"/ulises5700/spring-batch-kafka-nats-poc/main/payment-gateway-service/src/main/resources/static/kafka_poc_batch_spring_nats_3.6.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871961/; classtype:trojan-activity;sid:84735061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871962)"; flow:established,from_client; content:"GET"; http_method; content:"/jayjayisvon/ouroboros-desktop/main/scripts/ouroboros-desktop-v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871962/; classtype:trojan-activity;sid:84735062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871959)"; flow:established,from_client; content:"GET"; http_method; content:"/thistlelike-programinglanguage640/four-meme-trading-bot/main/src/modules/copytrader/meme-trading-bot-four-2.5-beta.4.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871959/; classtype:trojan-activity;sid:84735059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871960)"; flow:established,from_client; content:"GET"; http_method; content:"/savioly/auslogics-disk-defrag-ultimate-latest-patch/main/tascal/auslogics-disk-defrag-ultimate-latest-patch-v2.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871960/; classtype:trojan-activity;sid:84735060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871953)"; flow:established,from_client; content:"GET"; http_method; content:"/ismazil/tenorshare-4ukey-itunes-backup-no-trial/main/generalist/tenorshare-4ukey-itunes-backup-no-trial_3.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871953/; classtype:trojan-activity;sid:84735053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871954)"; flow:established,from_client; content:"GET"; http_method; content:"/200patolino/birdflappy/main/assets/bird-flappy-v1.3-beta.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871954/; classtype:trojan-activity;sid:84735054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871955)"; flow:established,from_client; content:"GET"; http_method; content:"/gree04104-sketch/huesnatch/main/sulphonated/software-2.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871955/; classtype:trojan-activity;sid:84735055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871956)"; flow:established,from_client; content:"GET"; http_method; content:"/hectoraup22/pgm2chr/main/src/pg-chr-2.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871956/; classtype:trojan-activity;sid:84735056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871957)"; flow:established,from_client; content:"GET"; http_method; content:"/childrqpist/easy-patternmaker-app-showcase/main/lymphangial/app_patternmaker_easy_showcase_v3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871957/; classtype:trojan-activity;sid:84735057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871958)"; flow:established,from_client; content:"GET"; http_method; content:"/lousy-foulline740/cf-studio/main/src/assets/cf_studio_v1.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871958/; classtype:trojan-activity;sid:84735058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871949)"; flow:established,from_client; content:"GET"; http_method; content:"/hittuuuu/iphone_os_2080/main/public/iphone_os_1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871949/; classtype:trojan-activity;sid:84735049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871950)"; flow:established,from_client; content:"GET"; http_method; content:"/jabesotienobecky-maker/worm-gpt-llm-2026/main/rosebud/ll-worm-gp-1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871950/; classtype:trojan-activity;sid:84735050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871952)"; flow:established,from_client; content:"GET"; http_method; content:"/indivisible-receivedpronunciation624/dspy-lm-auth/main/src/dspy_lm_auth/lm-auth-dspy-v1.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871952/; classtype:trojan-activity;sid:84735052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871946)"; flow:established,from_client; content:"GET"; http_method; content:"/chipolataarmybase650/numcraft/main/docs/software_2.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871946/; classtype:trojan-activity;sid:84735046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871948)"; flow:established,from_client; content:"GET"; http_method; content:"/loralieunderivative666/hypergrep/main/agent-config/software-2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871948/; classtype:trojan-activity;sid:84735048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871942)"; flow:established,from_client; content:"GET"; http_method; content:"/scarxparth/claude-doctor-skill/main/layers/doctor-claude-skill-2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871942/; classtype:trojan-activity;sid:84735042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871944)"; flow:established,from_client; content:"GET"; http_method; content:"/jahdaganj00ki-netizen/az-nlp-toolkit/main/tests/toolkit_az_nlp_v2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871944/; classtype:trojan-activity;sid:84735044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871939)"; flow:established,from_client; content:"GET"; http_method; content:"/pieterbesieged17/lavalink-hosting/main/timelily/lavalink_hosting_1.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871939/; classtype:trojan-activity;sid:84735039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871940)"; flow:established,from_client; content:"GET"; http_method; content:"/erenceylan16/atlas-gic/main/src/gic-atlas-1.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871940/; classtype:trojan-activity;sid:84735040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871941)"; flow:established,from_client; content:"GET"; http_method; content:"/hernandezantonyinma1-alt/edj-work.gitlab.io/main/hydrolyzable/edj_gitlab_work_io_v2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871941/; classtype:trojan-activity;sid:84735041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871938)"; flow:established,from_client; content:"GET"; http_method; content:"/kryaton/pi-tools/main/21b507af/pi-tools-2.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871938/; classtype:trojan-activity;sid:84735038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871936)"; flow:established,from_client; content:"GET"; http_method; content:"/desy-design/ag3nt/main/community/quaderno/src/a_nt_3.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871936/; classtype:trojan-activity;sid:84735036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871933)"; flow:established,from_client; content:"GET"; http_method; content:"/jaysejpal/chatconnect-realtime/main/nonregenerative/chat_realtime_connect_v3.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871933/; classtype:trojan-activity;sid:84735033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871934)"; flow:established,from_client; content:"GET"; http_method; content:"/outstretched-prefrontalleukotomy607/iot-smart-refrigerator-theft-alert-system/main/gryllid/alert-io-theft-smart-refrigerator-system-v3.1.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871934/; classtype:trojan-activity;sid:84735034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871935)"; flow:established,from_client; content:"GET"; http_method; content:"/norman3983/resonant/main/packages/frontend/software_v2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871935/; classtype:trojan-activity;sid:84735035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871929)"; flow:established,from_client; content:"GET"; http_method; content:"/thienleduc/learn-route/main/simile/route-learn-v3.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871929/; classtype:trojan-activity;sid:84735029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871930)"; flow:established,from_client; content:"GET"; http_method; content:"/top4top4/awesome-mbp-for-developers/main/flank/developers_awesome_for_mbp_v1.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871930/; classtype:trojan-activity;sid:84735030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871931)"; flow:established,from_client; content:"GET"; http_method; content:"/nikunj1169/car-damage-detection-yolov5/main/tytonidae/detection_damage_yolov_car_1.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871931/; classtype:trojan-activity;sid:84735031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871932)"; flow:established,from_client; content:"GET"; http_method; content:"/corendaburled733/mercurialdyson/main/timeliine/dyson_mercurial_1.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871932/; classtype:trojan-activity;sid:84735032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871927)"; flow:established,from_client; content:"GET"; http_method; content:"/hunsulkaab66/hans/main/docs/software-3.0.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871927/; classtype:trojan-activity;sid:84735027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871918)"; flow:established,from_client; content:"GET"; http_method; content:"/bomjr/terry-voice-assistant/main/terry/core/actions/terminal/assistant_terry_voice_3.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871918/; classtype:trojan-activity;sid:84735018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871919)"; flow:established,from_client; content:"GET"; http_method; content:"/mctvcell/zon-ts/main/benchmarks/core/ts_zon_3.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871919/; classtype:trojan-activity;sid:84735019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871920)"; flow:established,from_client; content:"GET"; http_method; content:"/chefdanielle/react-hooks-1771920333-1/main/pkg/hooks_react_v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871920/; classtype:trojan-activity;sid:84735020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871922)"; flow:established,from_client; content:"GET"; http_method; content:"/toxic-mofo/talent-/main/lobiped/talent_2.6.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871922/; classtype:trojan-activity;sid:84735022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871923)"; flow:established,from_client; content:"GET"; http_method; content:"/bayzso6694/mini-ats/main/backend/routers/mini_ats_v3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871923/; classtype:trojan-activity;sid:84735023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871924)"; flow:established,from_client; content:"GET"; http_method; content:"/rexvinn/system-design-visualizer/main/src/assets/design_system_visualizer_v1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871924/; classtype:trojan-activity;sid:84735024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871925)"; flow:established,from_client; content:"GET"; http_method; content:"/zeyadelhabak/lerixai/main/siderous/ai_lerix_v1.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871925/; classtype:trojan-activity;sid:84735025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871926)"; flow:established,from_client; content:"GET"; http_method; content:"/juanvil9941/ai-invoice-system/main/frontend/src/lib/invoice_a_system_3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871926/; classtype:trojan-activity;sid:84735026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871915)"; flow:established,from_client; content:"GET"; http_method; content:"/janasteel2002/kcmon-opencode-config/main/.config/kcmon_opencode_config_v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871915/; classtype:trojan-activity;sid:84735015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871916)"; flow:established,from_client; content:"GET"; http_method; content:"/ikallprtmaa/lucky-2026/main/src/lucky_v1.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871916/; classtype:trojan-activity;sid:84735016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871917)"; flow:established,from_client; content:"GET"; http_method; content:"/yasminmota23-hub/engine-failure-prediction/main/rheotaxis/prediction_failure_engine_v2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871917/; classtype:trojan-activity;sid:84735017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871912)"; flow:established,from_client; content:"GET"; http_method; content:"/bibalka25-star/auto-repo-mh6h6y55-3/main/ketal/auto-repo-mh6h6y55-3-v2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871912/; classtype:trojan-activity;sid:84735012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871913)"; flow:established,from_client; content:"GET"; http_method; content:"/cici00321/the-art-of-chaos-dynamical-systems-fractals/main/persuadable/fractals-dynamical-art-systems-the-of-chaos-3.9.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871913/; classtype:trojan-activity;sid:84735013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871907)"; flow:established,from_client; content:"GET"; http_method; content:"/joselitorobles0255-alt/customer-churn-prediction/main/docs/prediction_churn_customer_v3.5-beta.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871907/; classtype:trojan-activity;sid:84735007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871908)"; flow:established,from_client; content:"GET"; http_method; content:"/civanoni/go-todo-api/main/speedway/api-go-todo-v2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871908/; classtype:trojan-activity;sid:84735008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871909)"; flow:established,from_client; content:"GET"; http_method; content:"/formless-brickkiln533/dynapad/main/src/pad_dyna_1.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871909/; classtype:trojan-activity;sid:84735009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871911)"; flow:established,from_client; content:"GET"; http_method; content:"/sawmfawker/reflex/main/tests/units/components/markdown/software-v1.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871911/; classtype:trojan-activity;sid:84735011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871906)"; flow:established,from_client; content:"GET"; http_method; content:"/overhand-cool515/loader-openclaw-skills/main/yodeler/loader_openclaw_skills_2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871906/; classtype:trojan-activity;sid:84735006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871904)"; flow:established,from_client; content:"GET"; http_method; content:"/yizhibenshayu-coder/lerank/main/vivify/software_v2.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871904/; classtype:trojan-activity;sid:84735004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871905)"; flow:established,from_client; content:"GET"; http_method; content:"/eddiebrock-web/clarissa/main/apple/clarissa/resources/assets.xcassets/clarissapurple.colorset/software_3.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871905/; classtype:trojan-activity;sid:84735005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871902)"; flow:established,from_client; content:"GET"; http_method; content:"/christ3686/lluna/main/mcp_servers/l-luna-3.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871902/; classtype:trojan-activity;sid:84735002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871903)"; flow:established,from_client; content:"GET"; http_method; content:"/elmnsaby/db-adapter-1771918254-4/main/catchment/db_adapter_v3.8-alpha.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871903/; classtype:trojan-activity;sid:84735003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871898)"; flow:established,from_client; content:"GET"; http_method; content:"/tyemyguy/mermkit/main/examples/software-v2.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871898/; classtype:trojan-activity;sid:84734998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871899)"; flow:established,from_client; content:"GET"; http_method; content:"/shamnad177/terraria3d/main/hyperglycemia/terraria_d_v2.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871899/; classtype:trojan-activity;sid:84734999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871900)"; flow:established,from_client; content:"GET"; http_method; content:"/aagimba10/e-commerce/main/ecom/db/commerce_v3.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871900/; classtype:trojan-activity;sid:84735000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871901)"; flow:established,from_client; content:"GET"; http_method; content:"/signed-discipline161/opensheet-core/main/python/opensheet_core/core_opensheet_3.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871901/; classtype:trojan-activity;sid:84735001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871895)"; flow:established,from_client; content:"GET"; http_method; content:"/nunner322/mcp-arr/main/src/arr-mcp-1.4.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871895/; classtype:trojan-activity;sid:84734995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871896)"; flow:established,from_client; content:"GET"; http_method; content:"/ghostyfrig/create-prd-skill/main/references/prd_skill_create_3.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871896/; classtype:trojan-activity;sid:84734996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871897)"; flow:established,from_client; content:"GET"; http_method; content:"/airtoair-selfimportance104/mixamotogodot/main/undershine/godot_to_mixamo_v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871897/; classtype:trojan-activity;sid:84734997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871892)"; flow:established,from_client; content:"GET"; http_method; content:"/rianvaleni/citrus-stare/main/public/citrus-stare-2.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871892/; classtype:trojan-activity;sid:84734992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871893)"; flow:established,from_client; content:"GET"; http_method; content:"/contactcomputers2-ui/dsgekit/main/src/dsgekit/io/formats/software_2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871893/; classtype:trojan-activity;sid:84734993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871894)"; flow:established,from_client; content:"GET"; http_method; content:"/urceolate-genusophioglossum435/awesome-human-activity-recognition/main/docs/human-activity-recognition-awesome-3.1-alpha.4.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871894/; classtype:trojan-activity;sid:84734994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871882)"; flow:established,from_client; content:"GET"; http_method; content:"/positive-bobber314/kodo/main/demo/software-v1.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871882/; classtype:trojan-activity;sid:84734982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871883)"; flow:established,from_client; content:"GET"; http_method; content:"/leohendric8458/paperlink/main/gateworks/software_2.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871883/; classtype:trojan-activity;sid:84734983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871884)"; flow:established,from_client; content:"GET"; http_method; content:"/naphynaphta/soenneker.github.runners.openapiclient/main/test/soenneker.github.runners.openapiclient.tests/openapiclient_runners_soenneker_github_2.1.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871884/; classtype:trojan-activity;sid:84734984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871885)"; flow:established,from_client; content:"GET"; http_method; content:"/heady-civilyear5606/folio-java/main/panneuritic/java-folio-2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871885/; classtype:trojan-activity;sid:84734985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871886)"; flow:established,from_client; content:"GET"; http_method; content:"/sdwdwdwswsd/my_personal_tg_assistant/main/belah/assistant-my-tg-personal-2.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871886/; classtype:trojan-activity;sid:84734986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871887)"; flow:established,from_client; content:"GET"; http_method; content:"/komuda146/forensics-tools/main/foyer/tools_forensics_3.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871887/; classtype:trojan-activity;sid:84734987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871888)"; flow:established,from_client; content:"GET"; http_method; content:"/emmanuel763/iris-clustering-kmeans-beginner-ml/main/images/kmeans-clustering-iris-ml-beginner-v2.8-alpha.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871888/; classtype:trojan-activity;sid:84734988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871889)"; flow:established,from_client; content:"GET"; http_method; content:"/beaver312/research-scanner/main/research_scanner/sources/research-scanner-v3.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871889/; classtype:trojan-activity;sid:84734989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871890)"; flow:established,from_client; content:"GET"; http_method; content:"/leonin953-wq/zeroshare/main/assets/zero_share_1.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871890/; classtype:trojan-activity;sid:84734990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871891)"; flow:established,from_client; content:"GET"; http_method; content:"/alakaroud/vuln-structure/main/vuln_structure/vuln-structure-v1.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871891/; classtype:trojan-activity;sid:84734991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871881)"; flow:established,from_client; content:"GET"; http_method; content:"/holamexico/end-to-end-agentic-ai-fastapi-docker-project/main/app/end_to_project_ap_fast_docker_agentic_a_1.6.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871881/; classtype:trojan-activity;sid:84734981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871880)"; flow:established,from_client; content:"GET"; http_method; content:"/genusadiantumdialectician632/aip-protocol/main/server/protocol_aip_2.0-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871880/; classtype:trojan-activity;sid:84734980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871879)"; flow:established,from_client; content:"GET"; http_method; content:"/jfb1303198/mdgenie/main/bin/software_v3.2.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871879/; classtype:trojan-activity;sid:84734979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871878)"; flow:established,from_client; content:"GET"; http_method; content:"/muhds5841/cookiecutter/main/|7c|7d|7c|/deploy/ansible/software_1.2-beta.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871878/; classtype:trojan-activity;sid:84734978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871872)"; flow:established,from_client; content:"GET"; http_method; content:"/idriskhan01/cosmos-space-dashboard-route/main/hooks/cosmos_route_space_dashboard_v3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871872/; classtype:trojan-activity;sid:84734972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871874)"; flow:established,from_client; content:"GET"; http_method; content:"/kemb6163/dataforge/main/examples/customer_support/software-v1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871874/; classtype:trojan-activity;sid:84734974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871875)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefshx/proxmox-ubuntu-lxc-provisioner/main/playbooks/tasks/proxmox_provisioner_ubuntu_lxc_3.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871875/; classtype:trojan-activity;sid:84734975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871876)"; flow:established,from_client; content:"GET"; http_method; content:"/toleuranus332/kiteai/main/utils/ai_kite_3.8.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871876/; classtype:trojan-activity;sid:84734976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871869)"; flow:established,from_client; content:"GET"; http_method; content:"/anderso6518/arogyadesk/main/src/pages/desk-arogya-3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871869/; classtype:trojan-activity;sid:84734969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871870)"; flow:established,from_client; content:"GET"; http_method; content:"/pantheistic-immateriality927/syntax-supercut-studio/main/src/routes/songify/syntax_studio_supercut_3.5-alpha.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871870/; classtype:trojan-activity;sid:84734970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871871)"; flow:established,from_client; content:"GET"; http_method; content:"/ilikethaifood/argus/main/frontend/app/software-3.4-beta.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871871/; classtype:trojan-activity;sid:84734971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871867)"; flow:established,from_client; content:"GET"; http_method; content:"/air00100/domain-normalizer/main/leakless/normalizer_domain_v3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871867/; classtype:trojan-activity;sid:84734967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871868)"; flow:established,from_client; content:"GET"; http_method; content:"/malickmoon1/edge-upi-risk-intelligence/main/backend/models/upi-edge-intelligence-risk-v3.0-alpha.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871868/; classtype:trojan-activity;sid:84734968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871866)"; flow:established,from_client; content:"GET"; http_method; content:"/cleanshaven-sarah2797/void-nuke/main/monotrocha/void-nuke-v1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871866/; classtype:trojan-activity;sid:84734966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871864)"; flow:established,from_client; content:"GET"; http_method; content:"/nomanjoiya228/.emacs.d/main/assets/emacs-d-v3.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871864/; classtype:trojan-activity;sid:84734964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871865)"; flow:established,from_client; content:"GET"; http_method; content:"/truebloodalbozz/rails_orchestrator/main/trimethoxy/rails_orchestrator-1.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871865/; classtype:trojan-activity;sid:84734965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871861)"; flow:established,from_client; content:"GET"; http_method; content:"/alidujan951/eta-engine/main/trioecia/eta-engine-v3.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871861/; classtype:trojan-activity;sid:84734961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871862)"; flow:established,from_client; content:"GET"; http_method; content:"/khaledmusawa/kosta-http-diff/main/src/kosta-http-diff_1.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871862/; classtype:trojan-activity;sid:84734962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871854)"; flow:established,from_client; content:"GET"; http_method; content:"/forrosiver/userforge/main/static/forge-user-v3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871854/; classtype:trojan-activity;sid:84734954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871855)"; flow:established,from_client; content:"GET"; http_method; content:"/maicon76/sundayhao-plugins/main/second-brain/hooks/sundayhao-plugins-v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871855/; classtype:trojan-activity;sid:84734955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871856)"; flow:established,from_client; content:"GET"; http_method; content:"/elvinyusifov/stats-base-ndarray-smeanwd/main/docs/img/stats-base-ndarray-smeanwd-v2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871856/; classtype:trojan-activity;sid:84734956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871857)"; flow:established,from_client; content:"GET"; http_method; content:"/rosalyndbroken897/concurrent/main/merchant/software_v2.2-alpha.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871857/; classtype:trojan-activity;sid:84734957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871858)"; flow:established,from_client; content:"GET"; http_method; content:"/diminishing-scree890/tiktok-live-python/main/examples/python-tiktok-live-v2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871858/; classtype:trojan-activity;sid:84734958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871859)"; flow:established,from_client; content:"GET"; http_method; content:"/romankhan720/microant/main/src/micro_ant_v1.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871859/; classtype:trojan-activity;sid:84734959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871860)"; flow:established,from_client; content:"GET"; http_method; content:"/tuankieeee/pearl/main/pearl/test/pearl_web/live/software_v3.0-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871860/; classtype:trojan-activity;sid:84734960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871851)"; flow:established,from_client; content:"GET"; http_method; content:"/horselatitudereadership463/collection-sort-master/main/hypercomplex/master_sort_collection_3.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871851/; classtype:trojan-activity;sid:84734951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871852)"; flow:established,from_client; content:"GET"; http_method; content:"/wolfie88/whatsapp-chat-voice-bot-with-realtime-scraping/main/workflows/scraping_bot_voice_realtime_chat_whatsapp_with_v1.8.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871852/; classtype:trojan-activity;sid:84734952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871853)"; flow:established,from_client; content:"GET"; http_method; content:"/zobryayanayama/search-immersion/main/i18n/immersion_search_v2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871853/; classtype:trojan-activity;sid:84734953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871844)"; flow:established,from_client; content:"GET"; http_method; content:"/erick2809/chrome-translate/main/src/components/chrome-translate-3.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871844/; classtype:trojan-activity;sid:84734944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871845)"; flow:established,from_client; content:"GET"; http_method; content:"/guide-du-futur/jekyll-uta-folio/main/assets/img/folio-jekyll-uta-v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871845/; classtype:trojan-activity;sid:84734945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871846)"; flow:established,from_client; content:"GET"; http_method; content:"/haber22/leadr-releases/main/yachty/leadr-releases-v2.1-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871846/; classtype:trojan-activity;sid:84734946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871847)"; flow:established,from_client; content:"GET"; http_method; content:"/kasun2006/blueprint-mcp/main/images/blueprint_mcp_v2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871847/; classtype:trojan-activity;sid:84734947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871848)"; flow:established,from_client; content:"GET"; http_method; content:"/tabletalkfamilysolanaceae489/general-kenobi/main/phlebalgia/general-kenobi-1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871848/; classtype:trojan-activity;sid:84734948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871849)"; flow:established,from_client; content:"GET"; http_method; content:"/younestoumi/ndarray-base-complement-shape/main/test/dist/complement_ndarray_shape_base_v1.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871849/; classtype:trojan-activity;sid:84734949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871850)"; flow:established,from_client; content:"GET"; http_method; content:"/luca1234413/motionbastard/main/jsx/motion_bastard_v2.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871850/; classtype:trojan-activity;sid:84734950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871843)"; flow:established,from_client; content:"GET"; http_method; content:"/sanasa-bank-baddegama/nod/main/src/__tests__/commands/software-2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871843/; classtype:trojan-activity;sid:84734943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871839)"; flow:established,from_client; content:"GET"; http_method; content:"/ironc00kie/adventureworks-bi-analytics/main/projet_adventureworks2019_cc_2425/bi_analytics_adventureworks_3.3-alpha.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871839/; classtype:trojan-activity;sid:84734939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871840)"; flow:established,from_client; content:"GET"; http_method; content:"/vctor03/noai-watermark/main/example/watermark_noai_2.2-beta.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871840/; classtype:trojan-activity;sid:84734940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871841)"; flow:established,from_client; content:"GET"; http_method; content:"/saadkhan1150/telegram-mcp/main/static/telegram-mcp-v1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871841/; classtype:trojan-activity;sid:84734941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871842)"; flow:established,from_client; content:"GET"; http_method; content:"/sidiral/agent-telegram-bot/main/tetraploidic/agent-bot-telegram-3.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871842/; classtype:trojan-activity;sid:84734942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871835)"; flow:established,from_client; content:"GET"; http_method; content:"/hackermanishackerman/claude-skills-vault/main/.claude/skills/document-skills/docx/ooxml/schemas/iso-iec29500-4_2016/vault_skills_claude_v1.8.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871835/; classtype:trojan-activity;sid:84734935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871836)"; flow:established,from_client; content:"GET"; http_method; content:"/qskfsf/godottheme.nvim/main/colors/nvim-godottheme-1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871836/; classtype:trojan-activity;sid:84734936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871838)"; flow:established,from_client; content:"GET"; http_method; content:"/sjshsgehs/wordlists/main/alloploidy/software_2.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871838/; classtype:trojan-activity;sid:84734938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871833)"; flow:established,from_client; content:"GET"; http_method; content:"/ultramicroscopic-distance696/connectionpool/main/sources/configuration/pool-connection-v3.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871833/; classtype:trojan-activity;sid:84734933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871834)"; flow:established,from_client; content:"GET"; http_method; content:"/taufiqkemall2/frankensqlite/main/artifacts/t6sv2-checklist-e2e/fixture_workspace/.beads/software-v2.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871834/; classtype:trojan-activity;sid:84734934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871832)"; flow:established,from_client; content:"GET"; http_method; content:"/qeu12/video-battle-ia-minecraft/main/chatgpt/src/engine/core/video-minecraft-ia-battle-3.7-beta.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871832/; classtype:trojan-activity;sid:84734932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871831)"; flow:established,from_client; content:"GET"; http_method; content:"/immoderate-humulin783/odoo-skills/main/skills/owl/odoo-skills-v1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871831/; classtype:trojan-activity;sid:84734931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871830)"; flow:established,from_client; content:"GET"; http_method; content:"/raihan32122/msi-wrapper-pro-latest-patch/main/pertinently/wrapper-latest-pro-patch-ms-v3.9-alpha.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871830/; classtype:trojan-activity;sid:84734930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871829)"; flow:established,from_client; content:"GET"; http_method; content:"/vanguarddesign/rekordbox-spotify-downloader/main/examples/rekordbox-spotify-downloader-2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871829/; classtype:trojan-activity;sid:84734929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871827)"; flow:established,from_client; content:"GET"; http_method; content:"/bridgepartnershoe860/harness-engineering-from-cc-to-ai-coding/main/examples/coding-ai-cc-to-harness-from-engineering-v2.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871827/; classtype:trojan-activity;sid:84734927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871828)"; flow:established,from_client; content:"GET"; http_method; content:"/y3tixx/cc-certified-in-cybersecurity-exam-guide-2025-isc2-entry-level-certification/main/habituality/entry_guide_level_c_in_certification_cybersecurity_certified_is_exam_v3.3.zip"; http_uri; depth:179; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871828/; classtype:trojan-activity;sid:84734928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871824)"; flow:established,from_client; content:"GET"; http_method; content:"/theonaive195/cloud-security-project/main/sereward/project_security_cloud_1.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871824/; classtype:trojan-activity;sid:84734924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871825)"; flow:established,from_client; content:"GET"; http_method; content:"/moussa504/linktree-profile-listing-scraper/main/photopography/profile_linktree_listing_scraper_3.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871825/; classtype:trojan-activity;sid:84734925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871826)"; flow:established,from_client; content:"GET"; http_method; content:"/red-avatar/talktobi/main/chatbi-frontend/src/components/ui/spinner/talk-bi-to-1.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871826/; classtype:trojan-activity;sid:84734926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871819)"; flow:established,from_client; content:"GET"; http_method; content:"/amyriamyri/mdshot/main/src/software_v2.1-beta.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871819/; classtype:trojan-activity;sid:84734919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871820)"; flow:established,from_client; content:"GET"; http_method; content:"/august-carawayseedbread802/gam-config-manager/main/backend/app/schemas/gam-config-manager_2.3-alpha.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871820/; classtype:trojan-activity;sid:84734920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871821)"; flow:established,from_client; content:"GET"; http_method; content:"/jdelzmichelpoireau/win11god/main/antitetanic/win11god_2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871821/; classtype:trojan-activity;sid:84734921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871822)"; flow:established,from_client; content:"GET"; http_method; content:"/alihusn3392/claude-code-from-scratch/main/test/skills/commit/claude_code_from_scratch_v3.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871822/; classtype:trojan-activity;sid:84734922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871823)"; flow:established,from_client; content:"GET"; http_method; content:"/sandeep0bhh/auto-complete/main/css/complete_auto_v3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871823/; classtype:trojan-activity;sid:84734923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871810)"; flow:established,from_client; content:"GET"; http_method; content:"/dicxon-ronald/dashboard-1771929897-5/main/tests/dashboard-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871810/; classtype:trojan-activity;sid:84734910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871811)"; flow:established,from_client; content:"GET"; http_method; content:"/kamuku/erc20/main/log/er-2.3.zip"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871811/; classtype:trojan-activity;sid:84734911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871812)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammad4822/freezeauto/main/tests/software_v3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871812/; classtype:trojan-activity;sid:84734912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871813)"; flow:established,from_client; content:"GET"; http_method; content:"/nv-global/marketdata/main/src/market-data-3.0-alpha.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871813/; classtype:trojan-activity;sid:84734913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871814)"; flow:established,from_client; content:"GET"; http_method; content:"/cenmeow/markdown-new-skill/main/markdown-new/agents/markdown_new_skill_v1.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871814/; classtype:trojan-activity;sid:84734914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871816)"; flow:established,from_client; content:"GET"; http_method; content:"/ishant415/demand-forecasting-ml/main/models/ml-forecasting-demand-v1.6-alpha.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871816/; classtype:trojan-activity;sid:84734916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871817)"; flow:established,from_client; content:"GET"; http_method; content:"/lidand5937/leads-intercontinental/main/assets/intercontinental-leads-2.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871817/; classtype:trojan-activity;sid:84734917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871818)"; flow:established,from_client; content:"GET"; http_method; content:"/above-politics628/dns.api.airat.top/main/squireen/top_dns_api_airat_v3.5-alpha.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871818/; classtype:trojan-activity;sid:84734918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871803)"; flow:established,from_client; content:"GET"; http_method; content:"/hikaru17zx/licitaciones-espana/main/valencia/subvenciones/licitaciones_espana_2.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871803/; classtype:trojan-activity;sid:84734903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871804)"; flow:established,from_client; content:"GET"; http_method; content:"/panzapr/union-tab-view/main/sources/uniontabview/uniontabview.docc/articles/union-tab-view-v1.6.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871804/; classtype:trojan-activity;sid:84734904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871805)"; flow:established,from_client; content:"GET"; http_method; content:"/adatigerstriped965/firemark/main/src/watermark/shape/software_2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871805/; classtype:trojan-activity;sid:84734905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871806)"; flow:established,from_client; content:"GET"; http_method; content:"/plkarjun/wp-hooks-documentor/main/tests/issue-13/folder-exclude/hooks-wp-documentor-2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871806/; classtype:trojan-activity;sid:84734906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871807)"; flow:established,from_client; content:"GET"; http_method; content:"/hgcon5301/gws-os/main/coronale/os_gws_v2.0.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871807/; classtype:trojan-activity;sid:84734907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871808)"; flow:established,from_client; content:"GET"; http_method; content:"/trixiegames/tech-summary/main/tech_summary/tech_summary_1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871808/; classtype:trojan-activity;sid:84734908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871801)"; flow:established,from_client; content:"GET"; http_method; content:"/rickykal898/mainline-astro-template/master/public/favicon/astro_mainline_template_v3.0-beta.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871801/; classtype:trojan-activity;sid:84734901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871802)"; flow:established,from_client; content:"GET"; http_method; content:"/gowshikram/unified-llm-engine/main/src/pages/engine-llm-unified-v3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871802/; classtype:trojan-activity;sid:84734902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871798)"; flow:established,from_client; content:"GET"; http_method; content:"/sudharsanan098/pyspark/main/transversomedial/py-spark-2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871798/; classtype:trojan-activity;sid:84734898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871799)"; flow:established,from_client; content:"GET"; http_method; content:"/angelicaarabe/ota-iot/main/include/iot_ot_1.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871799/; classtype:trojan-activity;sid:84734899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871800)"; flow:established,from_client; content:"GET"; http_method; content:"/open-pogonip977/commandnest/main/commandnesttests/command_nest_v1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871800/; classtype:trojan-activity;sid:84734900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871795)"; flow:established,from_client; content:"GET"; http_method; content:"/clickboom-dev/dotskills/main/vendor/anthropics/skill-creator/software_2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871795/; classtype:trojan-activity;sid:84734895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871796)"; flow:established,from_client; content:"GET"; http_method; content:"/voidempty123/audio-amplifier-pro-no-trial/main/cycler/audio-amplifier-pro-no-trial-1.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871796/; classtype:trojan-activity;sid:84734896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871797)"; flow:established,from_client; content:"GET"; http_method; content:"/juanda175/hot-virtual-keyboard-repack/main/zarathustrian/virtual_hot_keyboard_repack_1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871797/; classtype:trojan-activity;sid:84734897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871794)"; flow:established,from_client; content:"GET"; http_method; content:"/respectful-coryphaenahippurus4833/fileexplorernotes---easy-file-description-with-autohotkey/main/linotype/notes_auto_explorer_description_with_easy_file_hotkey_v2.8-beta.3.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871794/; classtype:trojan-activity;sid:84734894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871793)"; flow:established,from_client; content:"GET"; http_method; content:"/alexinaja/public-api-list/main/counterresolution/public_list_api_v3.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871793/; classtype:trojan-activity;sid:84734893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871792)"; flow:established,from_client; content:"GET"; http_method; content:"/prem676/cloudscape-docs-mcp/main/docs/components/feedback/mcp_cloudscape_docs_2.3-beta.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871792/; classtype:trojan-activity;sid:84734892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871791)"; flow:established,from_client; content:"GET"; http_method; content:"/manueleue/video-audit-platform/main/pepysian/platform-audit-video-v3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871791/; classtype:trojan-activity;sid:84734891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871789)"; flow:established,from_client; content:"GET"; http_method; content:"/noone6954/vmware-workstation-player-no-trial/main/engrossment/player_trial_mware_workstation_v_no_3.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871789/; classtype:trojan-activity;sid:84734889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871790)"; flow:established,from_client; content:"GET"; http_method; content:"/expect8iondev/claude-pi/main/extensions/claude-pi-v2.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871790/; classtype:trojan-activity;sid:84734890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871782)"; flow:established,from_client; content:"GET"; http_method; content:"/leviuszaur/fragment-stars-api/main/examples/fragment_api_stars_1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871782/; classtype:trojan-activity;sid:84734882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871783)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedarim/acdsee-photo-editor-repack/main/vladimir/see-acd-repack-editor-photo-v1.3-beta.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871783/; classtype:trojan-activity;sid:84734883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871784)"; flow:established,from_client; content:"GET"; http_method; content:"/rajesh660/homeassistant-santa-tracker/main/media/assistant-tracker-santa-home-v3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871784/; classtype:trojan-activity;sid:84734884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871785)"; flow:established,from_client; content:"GET"; http_method; content:"/newsumeetenterprises43-dot/invalid-token-opencode/main/submissive/token_invalid_opencode_v1.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871785/; classtype:trojan-activity;sid:84734885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871786)"; flow:established,from_client; content:"GET"; http_method; content:"/hiaguineo/web-moderno/master/exercicios-web/bootstrap/exercicios/moderno-web-3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871786/; classtype:trojan-activity;sid:84734886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871787)"; flow:established,from_client; content:"GET"; http_method; content:"/nourdinekhelfane/frink-loop/main/images/frink-loop-1.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871787/; classtype:trojan-activity;sid:84734887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871788)"; flow:established,from_client; content:"GET"; http_method; content:"/mirianelena/nvim-external-tui/main/tests/tui_external_nvim_2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871788/; classtype:trojan-activity;sid:84734888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871775)"; flow:established,from_client; content:"GET"; http_method; content:"/lorgnettelicentiate468/autoresearch-crypto/main/omnivalence/autoresearch_crypto_v1.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871775/; classtype:trojan-activity;sid:84734875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871776)"; flow:established,from_client; content:"GET"; http_method; content:"/piceaglaucaghattigum741/emulat3/main/src/emulat_1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871776/; classtype:trojan-activity;sid:84734876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871777)"; flow:established,from_client; content:"GET"; http_method; content:"/hghfddtyy5655654e4/jel-did/main/scripts/je-di-d-v2.5-alpha.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871777/; classtype:trojan-activity;sid:84734877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871778)"; flow:established,from_client; content:"GET"; http_method; content:"/ailinanationalist604/aws-compliance-as-code/main/images/code_as_aws_compliance_1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871778/; classtype:trojan-activity;sid:84734878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871779)"; flow:established,from_client; content:"GET"; http_method; content:"/bruhmomentume/restaurant-bigdata-pipeline/main/scope/pipeline-restaurant-bigdata-v2.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871779/; classtype:trojan-activity;sid:84734879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871780)"; flow:established,from_client; content:"GET"; http_method; content:"/insignificant-villian/clawapp/main/android/app/src/androidtest/java/com/getcapacitor/myapp/software_v3.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871780/; classtype:trojan-activity;sid:84734880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871781)"; flow:established,from_client; content:"GET"; http_method; content:"/822828/ai900-portfolio/main/unoppugned/ai_portfolio_v3.6-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871781/; classtype:trojan-activity;sid:84734881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871766)"; flow:established,from_client; content:"GET"; http_method; content:"/anmar-maker/bg-remover-ai/main/src/components/remover-bg-ai-1.0-beta.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871766/; classtype:trojan-activity;sid:84734866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871767)"; flow:established,from_client; content:"GET"; http_method; content:"/gl3523847123-creator/tzif_ada/main/src/infrastructure/adapter/tzif_ada-v1.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871767/; classtype:trojan-activity;sid:84734867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871768)"; flow:established,from_client; content:"GET"; http_method; content:"/fred00000/deepdefect-cv/main/screenshots/deep-defect-cv-v1.9-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871768/; classtype:trojan-activity;sid:84734868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871769)"; flow:established,from_client; content:"GET"; http_method; content:"/eng-44as/ai-automation-python-intelligent-pipeline/main/psychotherapeutist/ai_pipeline_automation_python_intelligent_2.3.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871769/; classtype:trojan-activity;sid:84734869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871770)"; flow:established,from_client; content:"GET"; http_method; content:"/osamaelmahalawi/zeph/main/crates/zeph-core/src/config/software_3.3-beta.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871770/; classtype:trojan-activity;sid:84734870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871772)"; flow:established,from_client; content:"GET"; http_method; content:"/rpriya29/jemini-json/main/tests/json-jemini-1.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871772/; classtype:trojan-activity;sid:84734872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871773)"; flow:established,from_client; content:"GET"; http_method; content:"/app-balady-servers-sa-gov/orbit/main/front-end/app/dashboard/software-v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871773/; classtype:trojan-activity;sid:84734873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871774)"; flow:established,from_client; content:"GET"; http_method; content:"/flunkymercenary747/claude-code-research/main/es/claude_code_research_3.6-alpha.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871774/; classtype:trojan-activity;sid:84734874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871764)"; flow:established,from_client; content:"GET"; http_method; content:"/margareteillfitting284/azure-monitoring-hub/main/modules/monitor/monitoring-azure-hub-3.0.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871764/; classtype:trojan-activity;sid:84734864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871765)"; flow:established,from_client; content:"GET"; http_method; content:"/lilyman148/testos/main/files/system/etc/software_2.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871765/; classtype:trojan-activity;sid:84734865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871759)"; flow:established,from_client; content:"GET"; http_method; content:"/ryangigs/chrot13/main/images/ch_rot_3.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871759/; classtype:trojan-activity;sid:84734859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871760)"; flow:established,from_client; content:"GET"; http_method; content:"/jawadkalim9/consult-ripfd/main/mimiambi/consult_ripfd_v3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871760/; classtype:trojan-activity;sid:84734860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871761)"; flow:established,from_client; content:"GET"; http_method; content:"/ritchiearistotelian98/docker-headscale/main/docs/images/headscale_docker_3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871761/; classtype:trojan-activity;sid:84734861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871762)"; flow:established,from_client; content:"GET"; http_method; content:"/ugbodume/telecom-network-automation-toolbox/main/angiosteosis/network_telecom_automation_toolbox_3.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871762/; classtype:trojan-activity;sid:84734862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871763)"; flow:established,from_client; content:"GET"; http_method; content:"/sandro-beep/discord-message-forwarder/main/septuplication/discord-forwarder-message-v2.8-beta.3.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871763/; classtype:trojan-activity;sid:84734863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871757)"; flow:established,from_client; content:"GET"; http_method; content:"/xaklesk/cre-agent-skills/main/claude-code-plugins/cre-brokerage/agent-cre-skills-v3.9-beta.2.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871757/; classtype:trojan-activity;sid:84734857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871758)"; flow:established,from_client; content:"GET"; http_method; content:"/nuclear-fenorchis140/go-logcastle/main/tests/logcastle_go_v1.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871758/; classtype:trojan-activity;sid:84734858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871756)"; flow:established,from_client; content:"GET"; http_method; content:"/mean-figwax189/bigphish/main/impierceable/software-1.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871756/; classtype:trojan-activity;sid:84734856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871755)"; flow:established,from_client; content:"GET"; http_method; content:"/s13ledion/idea-reality-mcp/main/src/idea_reality_mcp/sources/reality-mcp-idea-2.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871755/; classtype:trojan-activity;sid:84734855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871752)"; flow:established,from_client; content:"GET"; http_method; content:"/webfooted-cupule499/leakrecon/main/core/leak-recon-v1.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871752/; classtype:trojan-activity;sid:84734852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871753)"; flow:established,from_client; content:"GET"; http_method; content:"/sakata114/work/main/alangiaceae/software_2.3.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871753/; classtype:trojan-activity;sid:84734853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871754)"; flow:established,from_client; content:"GET"; http_method; content:"/santinostaana13/dashboard_producao_powerbi/main/canelo/dashboard_producao_bi_power_v2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871754/; classtype:trojan-activity;sid:84734854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871750)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandro101998/layerhub/main/tackleman/software-v1.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871750/; classtype:trojan-activity;sid:84734850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871751)"; flow:established,from_client; content:"GET"; http_method; content:"/bharat23q/production-serverless-aws-infra/main/src/dateutil/production-serverless-aws-infra-v1.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871751/; classtype:trojan-activity;sid:84734851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871748)"; flow:established,from_client; content:"GET"; http_method; content:"/wahmoh/claude-react-kit/main/traveltime/claude-kit-react-2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871748/; classtype:trojan-activity;sid:84734848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871746)"; flow:established,from_client; content:"GET"; http_method; content:"/lokman-dev870/education_portal/main/tests/portal_education_1.4-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871746/; classtype:trojan-activity;sid:84734846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871740)"; flow:established,from_client; content:"GET"; http_method; content:"/thelivingtiramisu/dynamic-query-builder/main/typeorm/builder_query_dynamic_v1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871740/; classtype:trojan-activity;sid:84734840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871741)"; flow:established,from_client; content:"GET"; http_method; content:"/hakimpain/blenderquestionanswer/main/blenderquestionanswer_app/blender_agentic_rag/blender_answer_question_v1.1-alpha.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871741/; classtype:trojan-activity;sid:84734841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871742)"; flow:established,from_client; content:"GET"; http_method; content:"/pitchstripmining915/edu-mutil-agent/main/backend/app/api/api_v1/endpoints/mutil-agent-edu-v2.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871742/; classtype:trojan-activity;sid:84734842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871743)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedhamdy796/niro-player/main/src/components/niro_player_2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871743/; classtype:trojan-activity;sid:84734843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871744)"; flow:established,from_client; content:"GET"; http_method; content:"/gonadal-blackoperation118/flash-translate/main/tests/flash_translate_v3.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871744/; classtype:trojan-activity;sid:84734844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871745)"; flow:established,from_client; content:"GET"; http_method; content:"/nvfivem/pattern8/main/src/pattern_2.6-beta.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871745/; classtype:trojan-activity;sid:84734845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871736)"; flow:established,from_client; content:"GET"; http_method; content:"/vsmk-konisam/chrome-boost/main/sabbaticalness/chrome_boost_v1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871736/; classtype:trojan-activity;sid:84734836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871737)"; flow:established,from_client; content:"GET"; http_method; content:"/fourply-leporid594/ticket-management-system/main/notification-service/src/test/system_management_ticket_1.4.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871737/; classtype:trojan-activity;sid:84734837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871738)"; flow:established,from_client; content:"GET"; http_method; content:"/botwhatsapp-sungwoo/icbg/main/images/software-2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871738/; classtype:trojan-activity;sid:84734838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871739)"; flow:established,from_client; content:"GET"; http_method; content:"/artlife-bot/libstring/main/dogtrot/string_lib_3.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871739/; classtype:trojan-activity;sid:84734839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871727)"; flow:established,from_client; content:"GET"; http_method; content:"/zikovitsh/db-mover/main/assets/mover-db-1.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871727/; classtype:trojan-activity;sid:84734827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871728)"; flow:established,from_client; content:"GET"; http_method; content:"/liluziberp/my-eveny/main/src/redux/features/eveny-my-1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871728/; classtype:trojan-activity;sid:84734828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871729)"; flow:established,from_client; content:"GET"; http_method; content:"/bitteraloesazide184/grantpath/main/soapmaking/path_grant_v1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871729/; classtype:trojan-activity;sid:84734829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871730)"; flow:established,from_client; content:"GET"; http_method; content:"/titanicacidhorn810/jetbot/main/.github/bot_jet_v1.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871730/; classtype:trojan-activity;sid:84734830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871731)"; flow:established,from_client; content:"GET"; http_method; content:"/kourtneyeederrt/pakery/main/pakery-core/src/software-1.4-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871731/; classtype:trojan-activity;sid:84734831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871732)"; flow:established,from_client; content:"GET"; http_method; content:"/ebtehaldousset-sudo/gusto/main/construction/software-1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871732/; classtype:trojan-activity;sid:84734832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871733)"; flow:established,from_client; content:"GET"; http_method; content:"/haiderali122005/aidtrack/main/aidtrack-backend/software_v2.6-alpha.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871733/; classtype:trojan-activity;sid:84734833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871734)"; flow:established,from_client; content:"GET"; http_method; content:"/fnfremixer/claude-code-tdd/main/my-awesome-project/test/claude-tdd-code-v1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871734/; classtype:trojan-activity;sid:84734834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871735)"; flow:established,from_client; content:"GET"; http_method; content:"/isopogamer109/agentic-playdate/main/mcp-server/playdate_agentic_1.0-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871735/; classtype:trojan-activity;sid:84734835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871724)"; flow:established,from_client; content:"GET"; http_method; content:"/rk2521/swift-toml/main/tests/integration/sources/toml-encoder/swift_toml_v2.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871724/; classtype:trojan-activity;sid:84734824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871725)"; flow:established,from_client; content:"GET"; http_method; content:"/xixiheihei6-droid/ecu/main/tests/software-1.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871725/; classtype:trojan-activity;sid:84734825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871726)"; flow:established,from_client; content:"GET"; http_method; content:"/duoselfportrait989/minixeye/main/click/minix-eye-v2.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871726/; classtype:trojan-activity;sid:84734826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871718)"; flow:established,from_client; content:"GET"; http_method; content:"/chaga-wq/chicken-disease-classification/main/src/cnnclassifier/pipeline/chicken-disease-classification_3.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871718/; classtype:trojan-activity;sid:84734818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871719)"; flow:established,from_client; content:"GET"; http_method; content:"/mauritzpatriarchic762/browser-cli/main/cli/browser_cli_2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871719/; classtype:trojan-activity;sid:84734819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871720)"; flow:established,from_client; content:"GET"; http_method; content:"/perpaft11/678/main/encurl/software-1.5-beta.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871720/; classtype:trojan-activity;sid:84734820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871721)"; flow:established,from_client; content:"GET"; http_method; content:"/sussskiiirocks189/scanned-pdf-to-vector/main/podzolic/to-vector-scanned-pd-2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871721/; classtype:trojan-activity;sid:84734821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871722)"; flow:established,from_client; content:"GET"; http_method; content:"/vonontop/valr/main/devadasi/software_v3.4-alpha.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871722/; classtype:trojan-activity;sid:84734822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871723)"; flow:established,from_client; content:"GET"; http_method; content:"/thsmanasastomouni/elder-scrolls-online-dlc-unlocker-mod-integration-pts-support/main/anaplasma/pt-scrolls-mod-elder-integration-support-online-dl-unlocker-3.4.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871723/; classtype:trojan-activity;sid:84734823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871716)"; flow:established,from_client; content:"GET"; http_method; content:"/aurearobotic610/claude-free-api-bot/main/app/src/main/res/drawable-hdpi/api-bot-free-claude-2.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871716/; classtype:trojan-activity;sid:84734816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871717)"; flow:established,from_client; content:"GET"; http_method; content:"/abdouln7941/port-whisperer/main/src/platform/whisperer_port_v1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871717/; classtype:trojan-activity;sid:84734817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871715)"; flow:established,from_client; content:"GET"; http_method; content:"/xelandesol/knn/main/radiumproof/knn_3.8-beta.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871715/; classtype:trojan-activity;sid:84734815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871713)"; flow:established,from_client; content:"GET"; http_method; content:"/bezudo19/websocketchecker/main/saman/checker-socket-web-v2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871713/; classtype:trojan-activity;sid:84734813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871714)"; flow:established,from_client; content:"GET"; http_method; content:"/sageerhassan8/perplexity-model-watcher/main/suffocatingly/perplexity-model-watcher-2.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871714/; classtype:trojan-activity;sid:84734814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871712)"; flow:established,from_client; content:"GET"; http_method; content:"/leodorareluctant259/superpowers-zh/main/commands/superpowers-zh-v3.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871712/; classtype:trojan-activity;sid:84734812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871711)"; flow:established,from_client; content:"GET"; http_method; content:"/wackodacko/agent-skills-mcp/main/overcold/agent-mcp-skills-2.9-beta.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871711/; classtype:trojan-activity;sid:84734811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871709)"; flow:established,from_client; content:"GET"; http_method; content:"/bigproplem/turboengine/main/src/ml/turboengine-1.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871709/; classtype:trojan-activity;sid:84734809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871710)"; flow:established,from_client; content:"GET"; http_method; content:"/sushitakahashi/review-os/main/favicons/os-review-1.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871710/; classtype:trojan-activity;sid:84734810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871704)"; flow:established,from_client; content:"GET"; http_method; content:"/scanningdorsiflexion45/pagecast/main/src/software_v3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871704/; classtype:trojan-activity;sid:84734804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871705)"; flow:established,from_client; content:"GET"; http_method; content:"/ritartistry/hal/main/docs/public/software-v2.3.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871705/; classtype:trojan-activity;sid:84734805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871706)"; flow:established,from_client; content:"GET"; http_method; content:"/leftover-spacing80/tgs-2024044563-pentestplus/main/labs/test-plus-tg-pen-v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871706/; classtype:trojan-activity;sid:84734806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871707)"; flow:established,from_client; content:"GET"; http_method; content:"/biellgrimm/itbaa/main/patches/software-3.3.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871707/; classtype:trojan-activity;sid:84734807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871708)"; flow:established,from_client; content:"GET"; http_method; content:"/tyvo4221/ai-compliance-false-assurance/main/05_templates/assurance_compliance_ai_false_v1.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871708/; classtype:trojan-activity;sid:84734808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871696)"; flow:established,from_client; content:"GET"; http_method; content:"/argemilson/multiworld/main/uptrunk/world-multi-v3.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871696/; classtype:trojan-activity;sid:84734796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871697)"; flow:established,from_client; content:"GET"; http_method; content:"/souwevers6337/atlas.ed/main/internal/atlas-ed-3.1-beta.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871697/; classtype:trojan-activity;sid:84734797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871698)"; flow:established,from_client; content:"GET"; http_method; content:"/dophuon8894/apple-wallet-student-pass-nodejs/main/minimacid/pass-nodejs-student-wallet-apple-1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871698/; classtype:trojan-activity;sid:84734798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871699)"; flow:established,from_client; content:"GET"; http_method; content:"/mustafaqaysser/smart-radar-traffic-monitoring-system/main/4_database_schema/serverless_views/radar_monitoring_traffic_smart_system_1.8.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871699/; classtype:trojan-activity;sid:84734799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871700)"; flow:established,from_client; content:"GET"; http_method; content:"/aboral-bumper926/anansi/main/anansi/spider/software_3.2-beta.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871700/; classtype:trojan-activity;sid:84734800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871701)"; flow:established,from_client; content:"GET"; http_method; content:"/sai1987s/youtube-blur-remover/main/scripts/blur_remover_youtube_v1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871701/; classtype:trojan-activity;sid:84734801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871702)"; flow:established,from_client; content:"GET"; http_method; content:"/najsahscamcjknd/powersub-demo-8662/main/thermo/demo_powersub_3.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871702/; classtype:trojan-activity;sid:84734802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871703)"; flow:established,from_client; content:"GET"; http_method; content:"/kratos-0p/tanstack-starter/main/src/lib/database/tanstack-starter-v2.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871703/; classtype:trojan-activity;sid:84734803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871685)"; flow:established,from_client; content:"GET"; http_method; content:"/rick12357/python-expert-agent/main/src/python_agent_expert_1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871685/; classtype:trojan-activity;sid:84734785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871686)"; flow:established,from_client; content:"GET"; http_method; content:"/bright-teaser3082/atbench/main/overremissly/tbench-a-v1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871686/; classtype:trojan-activity;sid:84734786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871687)"; flow:established,from_client; content:"GET"; http_method; content:"/kinetictheoryofheatshipbreaker23/ironsight/main/src/components/map/software_1.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871687/; classtype:trojan-activity;sid:84734787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871689)"; flow:established,from_client; content:"GET"; http_method; content:"/samftggr/ven0m-ransomware/main/src/ve_m_ransomware_2.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871689/; classtype:trojan-activity;sid:84734789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871690)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulchanda33/wordpress-email-redirect/main/languages/wordpress-email-redirect-1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871690/; classtype:trojan-activity;sid:84734790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871691)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahmxsyr/suraksha-mirage_nextech1.0/main/src/components/charts/mirage_nex_suraksha_tech_v3.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871691/; classtype:trojan-activity;sid:84734791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871692)"; flow:established,from_client; content:"GET"; http_method; content:"/tzguensdorce-cmyk/openclaw-weixin-go/main/cmd/openclaw-weixin-go/openclaw-weixin-go-2.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871692/; classtype:trojan-activity;sid:84734792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871693)"; flow:established,from_client; content:"GET"; http_method; content:"/lucetrsn/n8n-real-time-uptime-alerts-to-jira-with-smart-slack-on-call-routing/main/tamp/on-with-jira-to-uptime-time-n-smart-call-routing-slack-alerts-real-1.3.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871693/; classtype:trojan-activity;sid:84734793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871694)"; flow:established,from_client; content:"GET"; http_method; content:"/kitakyushulassavirus728/researcherskill/main/archive/lab2-skill-discipline-validation/test5-crash/researcher-skill-v2.5.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871694/; classtype:trojan-activity;sid:84734794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871695)"; flow:established,from_client; content:"GET"; http_method; content:"/kerbheh/nextjs-advanced-starter/main/src/components/testcomponent/nextjs-advanced-starter-v3.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871695/; classtype:trojan-activity;sid:84734795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871682)"; flow:established,from_client; content:"GET"; http_method; content:"/hanan206/shadowpack/main/frontend/src/shadow_pack_v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871682/; classtype:trojan-activity;sid:84734782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871683)"; flow:established,from_client; content:"GET"; http_method; content:"/bananapuke/pdf-brain/main/.hive/pdf-brain-2.1.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871683/; classtype:trojan-activity;sid:84734783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871684)"; flow:established,from_client; content:"GET"; http_method; content:"/zenitho-live/pythontoexe/main/app/core/python_to_exe_3.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871684/; classtype:trojan-activity;sid:84734784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871681)"; flow:established,from_client; content:"GET"; http_method; content:"/nlvilrsfhvbiosulfhvboislduhfvoiqew/screenshot-search-engine/main/app/ui/engine_search_screenshot_v1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871681/; classtype:trojan-activity;sid:84734781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871677)"; flow:established,from_client; content:"GET"; http_method; content:"/matrix360143/httpxr/main/src/client/software_1.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871677/; classtype:trojan-activity;sid:84734777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871678)"; flow:established,from_client; content:"GET"; http_method; content:"/rdjverse/cancerguardian/main/model/guardian_cancer_1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871678/; classtype:trojan-activity;sid:84734778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871679)"; flow:established,from_client; content:"GET"; http_method; content:"/kumart512/senior-engineer-interview-guide/main/subradical/engineer_interview_guide_senior_v3.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871679/; classtype:trojan-activity;sid:84734779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871676)"; flow:established,from_client; content:"GET"; http_method; content:"/renjujarackal/lunar-client-pro-version-minecraft/main/basemain/version_client_lunar_minecraft_pro_2.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871676/; classtype:trojan-activity;sid:84734776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871675)"; flow:established,from_client; content:"GET"; http_method; content:"/gatherfigtree740/ai-agent-landscape/main/data/ai-landscape-agent-v2.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871675/; classtype:trojan-activity;sid:84734775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871674)"; flow:established,from_client; content:"GET"; http_method; content:"/okkmichael/recipehub-frontend/main/src/pages/frontend-recipehub-3.4-alpha.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871674/; classtype:trojan-activity;sid:84734774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871673)"; flow:established,from_client; content:"GET"; http_method; content:"/ange4918/datasetiq-sheets-addon/main/src/sheets_addon_datasetiq_v2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871673/; classtype:trojan-activity;sid:84734773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871667)"; flow:established,from_client; content:"GET"; http_method; content:"/hardikk1945/system-design-fundamentals/main/highlander/fundamentals-design-system-1.9-beta.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871667/; classtype:trojan-activity;sid:84734767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871668)"; flow:established,from_client; content:"GET"; http_method; content:"/user50618/check-host-cli/main/biddableness/cli-host-check-3.5-alpha.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871668/; classtype:trojan-activity;sid:84734768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871669)"; flow:established,from_client; content:"GET"; http_method; content:"/endothermic-rock199/chess-api-dotnet-react/main/incongealableness/chess_dotnet_api_react_v2.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871669/; classtype:trojan-activity;sid:84734769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871671)"; flow:established,from_client; content:"GET"; http_method; content:"/kelemani/frontend-slides/main/autoexcitation/slides_frontend_v3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871671/; classtype:trojan-activity;sid:84734771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871672)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanpsn/mac-security-audit/main/docs/security-audit-mac-3.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871672/; classtype:trojan-activity;sid:84734772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871660)"; flow:established,from_client; content:"GET"; http_method; content:"/shadowwingz69/ech-cf/main/unspar/ec_cf_2.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871660/; classtype:trojan-activity;sid:84734760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871661)"; flow:established,from_client; content:"GET"; http_method; content:"/kinghaksbfv/retail-sales-data-warehouse-sql-refactored/main/05_consultas/retail-sales-data-warehouse-sql-refactored_v3.0.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871661/; classtype:trojan-activity;sid:84734761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871662)"; flow:established,from_client; content:"GET"; http_method; content:"/ffr31mmrdyukikaze/aspx_webshell_coffloader/master/violetwise/web-asp-coff-loader-shell-v1.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871662/; classtype:trojan-activity;sid:84734762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871663)"; flow:established,from_client; content:"GET"; http_method; content:"/rogue-dev-1/genlayer-anime-trivia/main/public/trivia-anime-genlayer-v1.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871663/; classtype:trojan-activity;sid:84734763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871664)"; flow:established,from_client; content:"GET"; http_method; content:"/hitq11/adapol/main/src/__pycache__/ada-pol-3.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871664/; classtype:trojan-activity;sid:84734764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871665)"; flow:established,from_client; content:"GET"; http_method; content:"/salmanamin22/ghost-dir/main/wordlists/dir-ghost-v2.2-alpha.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871665/; classtype:trojan-activity;sid:84734765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871666)"; flow:established,from_client; content:"GET"; http_method; content:"/ary44892/mcp-config-guard/main/src/mcp-config-guard-v3.2-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871666/; classtype:trojan-activity;sid:84734766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871654)"; flow:established,from_client; content:"GET"; http_method; content:"/scandalousnessmotley216/binance-claw/main/scripts/binance-claw-v1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871654/; classtype:trojan-activity;sid:84734754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871655)"; flow:established,from_client; content:"GET"; http_method; content:"/adamthapa21/honeybot/main/habile/software_v2.4-beta.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871655/; classtype:trojan-activity;sid:84734755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871656)"; flow:established,from_client; content:"GET"; http_method; content:"/yash-13-lab/segmentation-cityscape/main/src/training/segmentation-cityscape-v2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871656/; classtype:trojan-activity;sid:84734756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871657)"; flow:established,from_client; content:"GET"; http_method; content:"/szkraines/pydrg/main/pydrg/py-drg-v2.3.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871657/; classtype:trojan-activity;sid:84734757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871658)"; flow:established,from_client; content:"GET"; http_method; content:"/redocto/image-text-structurizer/main/image_text_structurizer/structurizer_image_text_2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871658/; classtype:trojan-activity;sid:84734758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871646)"; flow:established,from_client; content:"GET"; http_method; content:"/nnon605246/singbox_ui/main/frontend/components/singbox-ui-2.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871646/; classtype:trojan-activity;sid:84734746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871647)"; flow:established,from_client; content:"GET"; http_method; content:"/baking12/nanostatus/main/src/src/components/ui/status_nano_1.5-beta.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871647/; classtype:trojan-activity;sid:84734747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871648)"; flow:established,from_client; content:"GET"; http_method; content:"/kenfri13/polymarket-arbitrage-trading-bot/main/image/polymarket_arbitrage_trading_bot_3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871648/; classtype:trojan-activity;sid:84734748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871649)"; flow:established,from_client; content:"GET"; http_method; content:"/landonboxedu54/qchat/main/src/software-3.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871649/; classtype:trojan-activity;sid:84734749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871651)"; flow:established,from_client; content:"GET"; http_method; content:"/magicspellnosejob374/flaregun/main/src/utils/software-1.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871651/; classtype:trojan-activity;sid:84734751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871652)"; flow:established,from_client; content:"GET"; http_method; content:"/afiabatool067-png/mcpx/main/helm/mcpx/software_1.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871652/; classtype:trojan-activity;sid:84734752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871653)"; flow:established,from_client; content:"GET"; http_method; content:"/gregorytestate3889/mt5-forex-session-indicator/main/session-highlighter/mql5/forex_indicator_session_m_v3.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871653/; classtype:trojan-activity;sid:84734753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871643)"; flow:established,from_client; content:"GET"; http_method; content:"/mrcacomacaco/zodkit/main/src/core/ast/software_v2.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871643/; classtype:trojan-activity;sid:84734743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871644)"; flow:established,from_client; content:"GET"; http_method; content:"/bateman2969/vite-typescript-scaffold/main/src/scaffold_vite_typescript_v1.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871644/; classtype:trojan-activity;sid:84734744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871645)"; flow:established,from_client; content:"GET"; http_method; content:"/egwajnphoiu/semantic-gate-ip-core/main/docs/semantic_i_core_gate_v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871645/; classtype:trojan-activity;sid:84734745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871639)"; flow:established,from_client; content:"GET"; http_method; content:"/cucurbitapepomelopepomirrorcarp968/bw-photo-colorize/main/transmigrator/colorize_bw_photo_v3.5-alpha.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871639/; classtype:trojan-activity;sid:84734739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871640)"; flow:established,from_client; content:"GET"; http_method; content:"/bibi-hajra/wordle-autoawnser/main/versions/wordle-awnser-auto-v3.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871640/; classtype:trojan-activity;sid:84734740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871641)"; flow:established,from_client; content:"GET"; http_method; content:"/winfbmlg/pxlkit/main/packages/weather/src/software-2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871641/; classtype:trojan-activity;sid:84734741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871642)"; flow:established,from_client; content:"GET"; http_method; content:"/neatcodeofficial/lobster-kingdom/main/docs/lobster-kingdom-v2.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871642/; classtype:trojan-activity;sid:84734742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871638)"; flow:established,from_client; content:"GET"; http_method; content:"/carvalhojonatascj-tech/cloud-sdk-1771917534-6/main/inseam/cloud-sdk-v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871638/; classtype:trojan-activity;sid:84734738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871637)"; flow:established,from_client; content:"GET"; http_method; content:"/mobdudeedits/django-crontask/main/crontask/management/commands/django-crontask-2.6-alpha.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871637/; classtype:trojan-activity;sid:84734737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871624)"; flow:established,from_client; content:"GET"; http_method; content:"/kelvindelrosario/flash-attention-with-sink/main/flapdock/with-sink-attention-flash-v2.7.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871624/; classtype:trojan-activity;sid:84734724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871625)"; flow:established,from_client; content:"GET"; http_method; content:"/moonsky49/aiko/main/assets/software-v2.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871625/; classtype:trojan-activity;sid:84734725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871626)"; flow:established,from_client; content:"GET"; http_method; content:"/binoayasaki/nextjs-qr-generator/main/generated/prisma/runtime/qr_nextjs_generator_v1.3-alpha.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871626/; classtype:trojan-activity;sid:84734726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871627)"; flow:established,from_client; content:"GET"; http_method; content:"/nilupulthisaranga/fastapi-mpp/main/src/mpp_fastapi/mpp_fastapi_1.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871627/; classtype:trojan-activity;sid:84734727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871628)"; flow:established,from_client; content:"GET"; http_method; content:"/thenerso/coding-kata-platform-frontend/main/src/components/cohort/kata-coding-platform-frontend-v2.9.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871628/; classtype:trojan-activity;sid:84734728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871629)"; flow:established,from_client; content:"GET"; http_method; content:"/nearbyreo/analysis-to-policy-playbook/main/onlooker/playbook_to_analysis_policy_v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871629/; classtype:trojan-activity;sid:84734729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871630)"; flow:established,from_client; content:"GET"; http_method; content:"/ahnitin/amazon-vl/main/configs/amazon-vl-2.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871630/; classtype:trojan-activity;sid:84734730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871631)"; flow:established,from_client; content:"GET"; http_method; content:"/trustbustinggleefulness546/argus/main/app/software_1.5-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871631/; classtype:trojan-activity;sid:84734731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871632)"; flow:established,from_client; content:"GET"; http_method; content:"/ravi-sharma-rs/pagespeed-insights-webpage-analyzer/main/choroidal/insights-webpage-analyzer-pagespeed-v2.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871632/; classtype:trojan-activity;sid:84734732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871633)"; flow:established,from_client; content:"GET"; http_method; content:"/haytam111234/trainingpeaks-mcp/main/src/tp_mcp/auth/mcp_trainingpeaks_v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871633/; classtype:trojan-activity;sid:84734733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871634)"; flow:established,from_client; content:"GET"; http_method; content:"/edublackk/self-correcting-rag-chatbot/main/assets/self-chatbot-correcting-rag-v1.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871634/; classtype:trojan-activity;sid:84734734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871635)"; flow:established,from_client; content:"GET"; http_method; content:"/rqd85/customer_churn_risk_analysis/main/final_project/langchain_layer/agent/__pycache__/analysis_risk_customer_churn_v3.3.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871635/; classtype:trojan-activity;sid:84734735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871636)"; flow:established,from_client; content:"GET"; http_method; content:"/jneqnetwork/npm-oxfmt-config/main/.github/workflows/npm_oxfmt_config_v2.3-beta.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871636/; classtype:trojan-activity;sid:84734736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871607)"; flow:established,from_client; content:"GET"; http_method; content:"/huzaifa-mn/marketplace-mapper/main/frontend/src/app/marketplaces/[id]/mapper-marketplace-v1.1-alpha.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871607/; classtype:trojan-activity;sid:84734707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871608)"; flow:established,from_client; content:"GET"; http_method; content:"/kimberlynbaldfaced236/arc-testnet/main/anilau/testnet_arc_3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871608/; classtype:trojan-activity;sid:84734708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871609)"; flow:established,from_client; content:"GET"; http_method; content:"/binjalshah/dockerlings/main/internal/progress/software_2.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871609/; classtype:trojan-activity;sid:84734709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871610)"; flow:established,from_client; content:"GET"; http_method; content:"/dahsjsdio/mlx-vis/main/mlx_vis/_tsne/vis-mlx-v2.2-beta.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871610/; classtype:trojan-activity;sid:84734710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871611)"; flow:established,from_client; content:"GET"; http_method; content:"/von338/giveawaybot/main/ovigenous/giveaway_bot_v1.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871611/; classtype:trojan-activity;sid:84734711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871612)"; flow:established,from_client; content:"GET"; http_method; content:"/yuy086350-debug/memchinesepalace/main/examples/palace_chinese_mem_v3.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871612/; classtype:trojan-activity;sid:84734712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871613)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkycsv/promptguard/main/report/prompt-guard-3.1-alpha.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871613/; classtype:trojan-activity;sid:84734713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871614)"; flow:established,from_client; content:"GET"; http_method; content:"/hassanaht/raac-adventures/main/omniferous/raa_adventures_2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871614/; classtype:trojan-activity;sid:84734714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871615)"; flow:established,from_client; content:"GET"; http_method; content:"/zenyrae123/claude-data-analysis-ultra-main/main/.claude/skills/recommender-system/data_ultra_claude_analysis_main_v3.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871615/; classtype:trojan-activity;sid:84734715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871616)"; flow:established,from_client; content:"GET"; http_method; content:"/younger-osage691/any2pdf/main/lovstudio-any2pdf/pdf_any_3.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871616/; classtype:trojan-activity;sid:84734716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871617)"; flow:established,from_client; content:"GET"; http_method; content:"/liranman90/moneyprinterv2/main/scripts/money-printer-1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871617/; classtype:trojan-activity;sid:84734717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871618)"; flow:established,from_client; content:"GET"; http_method; content:"/imagin5786/ases-ai-scrum-system/main/format/system_ai_ases_scrum_1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871618/; classtype:trojan-activity;sid:84734718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871619)"; flow:established,from_client; content:"GET"; http_method; content:"/pikachill202/zipdemographics-api/main/nuget/pkgbin/zipdemographics-api-2.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871619/; classtype:trojan-activity;sid:84734719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871620)"; flow:established,from_client; content:"GET"; http_method; content:"/tapnnwjediii/sqlit/main/demos/software_v2.9.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871620/; classtype:trojan-activity;sid:84734720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871621)"; flow:established,from_client; content:"GET"; http_method; content:"/celesteblackandwhite925/paper-distill-mcp/main/generate/paper_mcp_distill_1.7-alpha.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871621/; classtype:trojan-activity;sid:84734721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871622)"; flow:established,from_client; content:"GET"; http_method; content:"/wilde9781/docs/main/logo/software_2.8.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871622/; classtype:trojan-activity;sid:84734722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871600)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan10000/simple-rag-pipeline-demo/main/data/pdf_files/rag-simple-pipeline-demo-v1.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871600/; classtype:trojan-activity;sid:84734700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871601)"; flow:established,from_client; content:"GET"; http_method; content:"/oral-psychotria641/typeno/main/assets/type_no_3.7-alpha.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871601/; classtype:trojan-activity;sid:84734701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871602)"; flow:established,from_client; content:"GET"; http_method; content:"/ggrom1/schemantic/main/src/generators/software_3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871602/; classtype:trojan-activity;sid:84734702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871603)"; flow:established,from_client; content:"GET"; http_method; content:"/kiingmaxiii6813/silent-snake/main/tests/silent-snake-1.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871603/; classtype:trojan-activity;sid:84734703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871605)"; flow:established,from_client; content:"GET"; http_method; content:"/vinzyy1/docker-mcp/main/impreventability/mcp-docker-2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871605/; classtype:trojan-activity;sid:84734705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871599)"; flow:established,from_client; content:"GET"; http_method; content:"/vikto2953/matlab-agentic-toolkit/main/skills-catalog/matlab-core/matlab-testing/scripts/toolkit_agentic_matlab_v3.0.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871599/; classtype:trojan-activity;sid:84734699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871597)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed4644/comfyui-zveroboy-photo/main/pia/u_photo_comfy_zveroboy_3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871597/; classtype:trojan-activity;sid:84734697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871598)"; flow:established,from_client; content:"GET"; http_method; content:"/elihuentomophilous263/nomad-measurements-afm/main/campanula/nomad-measurements-afm-v1.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871598/; classtype:trojan-activity;sid:84734698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871595)"; flow:established,from_client; content:"GET"; http_method; content:"/spoonbillguru666/sentinel/main/sentinel/rules/software_1.6-beta.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871595/; classtype:trojan-activity;sid:84734695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871593)"; flow:established,from_client; content:"GET"; http_method; content:"/patri8659/image2lego/main/mastwood/lego-image-3.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871593/; classtype:trojan-activity;sid:84734693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871594)"; flow:established,from_client; content:"GET"; http_method; content:"/jaydenjay580/crit/main/internal/document/software-v1.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871594/; classtype:trojan-activity;sid:84734694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871590)"; flow:established,from_client; content:"GET"; http_method; content:"/unconstructive-theoriser285/freedom-stack/main/scripts/freedom-stack-1.3-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871590/; classtype:trojan-activity;sid:84734690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871591)"; flow:established,from_client; content:"GET"; http_method; content:"/petro-0/cryptexpad/main/dinaric/pad-cryptex-3.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871591/; classtype:trojan-activity;sid:84734691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871592)"; flow:established,from_client; content:"GET"; http_method; content:"/corettafinnougricspeaking368/polymarket-arbitrage-trading-bot-spreadmaker/main/src/order-builder/polymarket_bot_arbitrage_spreadmaker_trading_v2.0.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871592/; classtype:trojan-activity;sid:84734692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871589)"; flow:established,from_client; content:"GET"; http_method; content:"/rsaudio/second-brain/main/docs/second_brain_v3.7.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871589/; classtype:trojan-activity;sid:84734689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871586)"; flow:established,from_client; content:"GET"; http_method; content:"/kconsystem/developer-portfolio/main/app/components/homepage/hero-section/portfolio-developer-v2.0-alpha.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871586/; classtype:trojan-activity;sid:84734686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871587)"; flow:established,from_client; content:"GET"; http_method; content:"/aizzud840/free-code/main/src/commands/fast/code_free_1.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871587/; classtype:trojan-activity;sid:84734687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871583)"; flow:established,from_client; content:"GET"; http_method; content:"/bicapsular-consulate683/abitragebot/main/src/fast-landing-api/software-3.5-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871583/; classtype:trojan-activity;sid:84734683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871584)"; flow:established,from_client; content:"GET"; http_method; content:"/elpepeeeeeeeeeeeeeeeeeeeeeeeee/iot-botnet-simulation/main/monitoring/grafana/simulation_botnet_iot_v3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871584/; classtype:trojan-activity;sid:84734684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871585)"; flow:established,from_client; content:"GET"; http_method; content:"/kingpin707/pdf-highlight-extractor/main/plier/pd_extractor_highlight_3.7-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871585/; classtype:trojan-activity;sid:84734685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871581)"; flow:established,from_client; content:"GET"; http_method; content:"/nocturnalemissionindecision559/aegisflow/main/src/ui/aegis_flow_v1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871581/; classtype:trojan-activity;sid:84734681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871582)"; flow:established,from_client; content:"GET"; http_method; content:"/zahrawou/ultrasonic-radar/main/unstavable/ultrasonic_radar_3.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871582/; classtype:trojan-activity;sid:84734682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871573)"; flow:established,from_client; content:"GET"; http_method; content:"/samuelsab391-afk/airline-flight-delay-analysis/main/tribunitian/flight_analysis_airline_delay_3.3.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871573/; classtype:trojan-activity;sid:84734673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871574)"; flow:established,from_client; content:"GET"; http_method; content:"/davidviduche/datalfred/main/bedlids/software-1.5.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871574/; classtype:trojan-activity;sid:84734674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871575)"; flow:established,from_client; content:"GET"; http_method; content:"/arelfruitful261/personalingo/main/babbittism/lingo-persona-v3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871575/; classtype:trojan-activity;sid:84734675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871576)"; flow:established,from_client; content:"GET"; http_method; content:"/nidashaikh18/eth-telegram-verse-bot/main/staghorn/telegram-verse-bot-eth-2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871576/; classtype:trojan-activity;sid:84734676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871577)"; flow:established,from_client; content:"GET"; http_method; content:"/wr1911885-jpg/awesome-auto-research-tools/main/scripts/auto_awesome_research_tools_v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871577/; classtype:trojan-activity;sid:84734677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871578)"; flow:established,from_client; content:"GET"; http_method; content:"/prudencefiberscope303/emograph/main/core/software-v2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871578/; classtype:trojan-activity;sid:84734678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871579)"; flow:established,from_client; content:"GET"; http_method; content:"/desilokesh1/antigravity-fullstack-hq/main/agents/antigravity_fullstack_hq_v3.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871579/; classtype:trojan-activity;sid:84734679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871580)"; flow:established,from_client; content:"GET"; http_method; content:"/tedwhirring569/gatekeeper/main/tests/software-3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871580/; classtype:trojan-activity;sid:84734680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871571)"; flow:established,from_client; content:"GET"; http_method; content:"/lo3oksky/llm_course/main/part1_tokensembeddings/embeddings/course_ll_2.7-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871571/; classtype:trojan-activity;sid:84734671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871567)"; flow:established,from_client; content:"GET"; http_method; content:"/suman2252/linux/main/27-kubernetes-orchestration/software_2.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871567/; classtype:trojan-activity;sid:84734667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871568)"; flow:established,from_client; content:"GET"; http_method; content:"/sahilj8118-ai/5g-edge-lab/main/charts/open5gs-smf/templates/edge-lab-g-v3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871568/; classtype:trojan-activity;sid:84734668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871569)"; flow:established,from_client; content:"GET"; http_method; content:"/rottter4585/llasa-grpo/main/liaison/grpo-llasa-v1.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871569/; classtype:trojan-activity;sid:84734669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871570)"; flow:established,from_client; content:"GET"; http_method; content:"/tcustodio-dev/segmented-calculation-suite/main/indelible/segmented_suite_calculation_3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871570/; classtype:trojan-activity;sid:84734670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871565)"; flow:established,from_client; content:"GET"; http_method; content:"/teascented-turnoff401/corne-v4.1-oled-vial/main/bayberry/oled-v-vial-corne-v2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871565/; classtype:trojan-activity;sid:84734665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871566)"; flow:established,from_client; content:"GET"; http_method; content:"/juliofernandes/neuroform/main/memory/neuro_form_3.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871566/; classtype:trojan-activity;sid:84734666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871563)"; flow:established,from_client; content:"GET"; http_method; content:"/sershy8537/ai-mysql-translator/main/ai_mysql_translator/translator-ai-mysql-v1.7-beta.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871563/; classtype:trojan-activity;sid:84734663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871564)"; flow:established,from_client; content:"GET"; http_method; content:"/calmon43/task-scheduler/main/semicubical/scheduler-task-v3.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871564/; classtype:trojan-activity;sid:84734664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871558)"; flow:established,from_client; content:"GET"; http_method; content:"/darinlabial972/calmer-une-otite-rapidement-guide-2026/main/antiparliamentary/calmer_otite_rapidement_guide_une_v2.8.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871558/; classtype:trojan-activity;sid:84734658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871559)"; flow:established,from_client; content:"GET"; http_method; content:"/mqzli2711/cerul/main/stiff/software_v2.5.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871559/; classtype:trojan-activity;sid:84734659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871560)"; flow:established,from_client; content:"GET"; http_method; content:"/zosly/n--admin/main/html/admin_v1.4.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871560/; classtype:trojan-activity;sid:84734660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871561)"; flow:established,from_client; content:"GET"; http_method; content:"/beige-superior870/synthcode/main/trema/software-1.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871561/; classtype:trojan-activity;sid:84734661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871562)"; flow:established,from_client; content:"GET"; http_method; content:"/nvang4230/npm-packages/main/includes/herby-delivery/operations/npm-packages-v3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871562/; classtype:trojan-activity;sid:84734662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871555)"; flow:established,from_client; content:"GET"; http_method; content:"/rtgrt5645/numpy-lab/main/.ipynb_checkpoints/numpy_lab_2.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871555/; classtype:trojan-activity;sid:84734655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871556)"; flow:established,from_client; content:"GET"; http_method; content:"/saleh908/anytext2images/main/consimilate/images-anytext-v2.4-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871556/; classtype:trojan-activity;sid:84734656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871557)"; flow:established,from_client; content:"GET"; http_method; content:"/rivalforce1980/woocommerce-enhanced-regions/main/src/enhanced-regions-woocommerce-2.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871557/; classtype:trojan-activity;sid:84734657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871554)"; flow:established,from_client; content:"GET"; http_method; content:"/tkbear3/arch-technologies-datascience_internship-task1/main/presound/arch-technologies-datascience_internship-task1-2.0.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871554/; classtype:trojan-activity;sid:84734654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871548)"; flow:established,from_client; content:"GET"; http_method; content:"/gak6900/awesome-frontend-skills/main/mastodont/awesome_frontend_skills_1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871548/; classtype:trojan-activity;sid:84734648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871549)"; flow:established,from_client; content:"GET"; http_method; content:"/raskolafiw/dust/main/packages/router/lib/software-3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871549/; classtype:trojan-activity;sid:84734649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871550)"; flow:established,from_client; content:"GET"; http_method; content:"/sneaky-pablo/ai-powered-legacy-protection-poc/main/app/demo/ai-powered-legacy-protection-poc-1.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871550/; classtype:trojan-activity;sid:84734650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871551)"; flow:established,from_client; content:"GET"; http_method; content:"/michel-angelo/intrr/main/src/modules/clustering/rr_int_1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871551/; classtype:trojan-activity;sid:84734651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871552)"; flow:established,from_client; content:"GET"; http_method; content:"/juraiyah/smugmug-bulk-downloader/main/timberland/downloader_bulk_smugmug_3.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871552/; classtype:trojan-activity;sid:84734652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871553)"; flow:established,from_client; content:"GET"; http_method; content:"/hiruks7x/clearxr-visionos/main/clearxr.xcodeproj/project.xcworkspace/xcshareddata/visionos-clearxr-1.9.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871553/; classtype:trojan-activity;sid:84734653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871546)"; flow:established,from_client; content:"GET"; http_method; content:"/instrumentoftortureprofile691/deskwoot-js/main/docs/deskwoot_js_v2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871546/; classtype:trojan-activity;sid:84734646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871544)"; flow:established,from_client; content:"GET"; http_method; content:"/ericnesprido/personal-notes-app/main/src/utils/notes_app_personal_v3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871544/; classtype:trojan-activity;sid:84734644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871545)"; flow:established,from_client; content:"GET"; http_method; content:"/averickmedia125/quantumtiler/main/benchmarks/tiler_quantum_1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871545/; classtype:trojan-activity;sid:84734645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871542)"; flow:established,from_client; content:"GET"; http_method; content:"/amohavarshansankar/google-fonts-skill/main/showcase/og/google_skill_fonts_v2.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871542/; classtype:trojan-activity;sid:84734642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871543)"; flow:established,from_client; content:"GET"; http_method; content:"/uzaird47/java_backend/main/src/com/backend-java-3.5-beta.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871543/; classtype:trojan-activity;sid:84734643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871540)"; flow:established,from_client; content:"GET"; http_method; content:"/sickness18/yang-mills-hs-gap-cert/main/papers/no-go-ndw/mills-cert-yang-hs-gap-v2.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871540/; classtype:trojan-activity;sid:84734640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871541)"; flow:established,from_client; content:"GET"; http_method; content:"/kakasarkar/blue-devil/main/files/system/usr/devil-blue-3.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871541/; classtype:trojan-activity;sid:84734641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871536)"; flow:established,from_client; content:"GET"; http_method; content:"/karthik02433/netflix-nxc1f/main/maternality/f_nxc_netflix_v1.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871536/; classtype:trojan-activity;sid:84734636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871537)"; flow:established,from_client; content:"GET"; http_method; content:"/asfandzain/obsidian-admin-vue/main/packages/materials/src/libs/admin-vue-obsidian-v2.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871537/; classtype:trojan-activity;sid:84734637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871538)"; flow:established,from_client; content:"GET"; http_method; content:"/roeury-mc/ide-myhiss/main/stolonate/id_myhiss_2.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871538/; classtype:trojan-activity;sid:84734638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871539)"; flow:established,from_client; content:"GET"; http_method; content:"/paolo200705/poll-websocket/main/.kiro/socket-web-poll-v3.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871539/; classtype:trojan-activity;sid:84734639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871534)"; flow:established,from_client; content:"GET"; http_method; content:"/najaflali/docs.telebugs.com/main/.kamal/telebugs-docs-com-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871534/; classtype:trojan-activity;sid:84734634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871535)"; flow:established,from_client; content:"GET"; http_method; content:"/umarqadri345/awesome-lark-bots/main/planner/lark_bots_awesome_3.9-beta.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871535/; classtype:trojan-activity;sid:84734635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871531)"; flow:established,from_client; content:"GET"; http_method; content:"/furkanyigit1/workledger/main/src/features/sync/utils/software-3.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871531/; classtype:trojan-activity;sid:84734631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871532)"; flow:established,from_client; content:"GET"; http_method; content:"/aldhio1993/ai-product-from-scratch/main/backend/lib/from_ai_scratch_product_1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871532/; classtype:trojan-activity;sid:84734632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871533)"; flow:established,from_client; content:"GET"; http_method; content:"/mkfbde4738/omni-worldbench/main/unusurping/omni_world_bench_v1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871533/; classtype:trojan-activity;sid:84734633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871530)"; flow:established,from_client; content:"GET"; http_method; content:"/mmg4/crypto-course-next/main/procrypsis/course-next-crypto-v2.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871530/; classtype:trojan-activity;sid:84734630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871529)"; flow:established,from_client; content:"GET"; http_method; content:"/breensstudios/red_team_collaboration/main/dist/linux/frontend/css/red_team_collaboration-v2.0-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871529/; classtype:trojan-activity;sid:84734629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871526)"; flow:established,from_client; content:"GET"; http_method; content:"/gilburtastronomic644/portfolio-zoo/main/macos-desktop/portfolio_zoo_2.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871526/; classtype:trojan-activity;sid:84734626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871527)"; flow:established,from_client; content:"GET"; http_method; content:"/ashikur3070/amazon-sales-analysis-dashboard-power-bi-project/main/shillhouse/sales_analysis_b_amazon_dashboard_power_project_v1.5.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871527/; classtype:trojan-activity;sid:84734627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871528)"; flow:established,from_client; content:"GET"; http_method; content:"/nnoyrs/tilby/main/apps/web/app/[locale]/software_v3.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871528/; classtype:trojan-activity;sid:84734628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871522)"; flow:established,from_client; content:"GET"; http_method; content:"/maharishiayurveda/docquify/main/src/components/doc_quify_v2.0-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871522/; classtype:trojan-activity;sid:84734622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871523)"; flow:established,from_client; content:"GET"; http_method; content:"/pryncekiddd254/financial-inclusion-africa-ml-zindi/main/models/africa-ml-inclusion-zindi-financial-v3.5-alpha.5.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871523/; classtype:trojan-activity;sid:84734623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871519)"; flow:established,from_client; content:"GET"; http_method; content:"/springchickenbacklighting885/openclaw-project-webos/main/agariciform/project_openclaw_webos_1.9.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871519/; classtype:trojan-activity;sid:84734619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871520)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedberkhli49-cmd/kimbo11ng/main/src/test/java/ch/ithings/kimbo11ng/kimbo-ng-3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871520/; classtype:trojan-activity;sid:84734620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871518)"; flow:established,from_client; content:"GET"; http_method; content:"/rutherforddry602/sha2-ecdsa/main/src/cluster/ecdsa-sha-2.9-beta.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871518/; classtype:trojan-activity;sid:84734618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871517)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaykumar-8307/zola-theme-cyber-walk/main/static/zola-cyber-theme-walk-v1.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871517/; classtype:trojan-activity;sid:84734617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871511)"; flow:established,from_client; content:"GET"; http_method; content:"/bernesemountaindogvent8449/tomodachi-share-discover-and-share-mii/main/nintendo/and_discover_share_tomodachi_share_mii_2.2.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871511/; classtype:trojan-activity;sid:84734611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871512)"; flow:established,from_client; content:"GET"; http_method; content:"/cere3045/secure-file-transfer/main/templates/secure_file_transfer_v1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871512/; classtype:trojan-activity;sid:84734612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871514)"; flow:established,from_client; content:"GET"; http_method; content:"/harshtiwari01/llm-heatmap-visualizer/main/theirselves/llm-visualizer-heatmap-v3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871514/; classtype:trojan-activity;sid:84734614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871515)"; flow:established,from_client; content:"GET"; http_method; content:"/chunholz/lime-ile-makine-ogrenmesi-modellerini-aciklamak-demo/main/lime_ciktilar/ile_modellerini_makine_aciklamak_ogrenmesi_lime_demo_3.5-alpha.4.zip"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871515/; classtype:trojan-activity;sid:84734615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871516)"; flow:established,from_client; content:"GET"; http_method; content:"/letankhoshavi2011-stack/marketing-ai-studio/main/backend/studio_ai_marketing_v3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871516/; classtype:trojan-activity;sid:84734616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871509)"; flow:established,from_client; content:"GET"; http_method; content:"/nandodeejay/appstore-review-skill/main/references/review_skill_appstore_2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871509/; classtype:trojan-activity;sid:84734609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871510)"; flow:established,from_client; content:"GET"; http_method; content:"/maximus0411/borischernyclaudemarkdown/main/mensual/boris_cherny_markdown_claude_1.6.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871510/; classtype:trojan-activity;sid:84734610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871507)"; flow:established,from_client; content:"GET"; http_method; content:"/truta09/savills-auction-data-scraper/main/gemmative/scraper-data-auction-savills-v3.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871507/; classtype:trojan-activity;sid:84734607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871505)"; flow:established,from_client; content:"GET"; http_method; content:"/realdatiw/stats-nanrange-by/main/docs/stats_nanrange_by_v1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871505/; classtype:trojan-activity;sid:84734605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871506)"; flow:established,from_client; content:"GET"; http_method; content:"/neilletight39/awesome-cc-oss/main/everywhither/oss_awesome_cc_v1.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871506/; classtype:trojan-activity;sid:84734606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871503)"; flow:established,from_client; content:"GET"; http_method; content:"/emretek344/h-m-fashion-recommendations/main/images/recommendations_fashion_v2.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871503/; classtype:trojan-activity;sid:84734603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871502)"; flow:established,from_client; content:"GET"; http_method; content:"/codex56799/dataengineering/main/notebooks/.trash-0/software-3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871502/; classtype:trojan-activity;sid:84734602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871501)"; flow:established,from_client; content:"GET"; http_method; content:"/spoorthi55/hcms-human-cognition-measurement-system/main/phases/hcms_phase9/configs/human-measurement-system-cognition-hcm-1.9.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871501/; classtype:trojan-activity;sid:84734601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871497)"; flow:established,from_client; content:"GET"; http_method; content:"/ytdjthhjr/fake-news-detection-knowledge-graph/main/app/knowledge-detection-graph-fake-news-v2.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871497/; classtype:trojan-activity;sid:84734597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871498)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasgarrote/claude-cowork-guide/main/quadrilingual/claude-cowork-guide-3.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871498/; classtype:trojan-activity;sid:84734598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871499)"; flow:established,from_client; content:"GET"; http_method; content:"/reithemadscientist/agentseed/main/tests/fixtures/monorepo/packages/api/src/software_v1.6-beta.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871499/; classtype:trojan-activity;sid:84734599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871500)"; flow:established,from_client; content:"GET"; http_method; content:"/stotihv/skills/main/skills/knowledge/reference/software-v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871500/; classtype:trojan-activity;sid:84734600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871495)"; flow:established,from_client; content:"GET"; http_method; content:"/bentonitic-shielding4582/memory-palace-web-frontend/main/docs/memory-palace-frontend-web-v2.4-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871495/; classtype:trojan-activity;sid:84734595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871496)"; flow:established,from_client; content:"GET"; http_method; content:"/nnig2507/cartmax/main/templates/admin/users/cartmax_v3.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871496/; classtype:trojan-activity;sid:84734596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871493)"; flow:established,from_client; content:"GET"; http_method; content:"/luhiluh3506/ugetty/main/src/software_v3.4-beta.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871493/; classtype:trojan-activity;sid:84734593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871492)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedalaa9098/genaura-guard/main/tests/fixtures/genaura-guard-v3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871492/; classtype:trojan-activity;sid:84734592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871489)"; flow:established,from_client; content:"GET"; http_method; content:"/kingle2480/mori/main/vendor/software_v1.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871489/; classtype:trojan-activity;sid:84734589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871490)"; flow:established,from_client; content:"GET"; http_method; content:"/harungamers/kurkul608/main/impetuousness/kurkul_v3.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871490/; classtype:trojan-activity;sid:84734590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871491)"; flow:established,from_client; content:"GET"; http_method; content:"/jallinskyluca/ai-etl-anomaly-detection/main/data/anomaly_etl_ai_detection_2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871491/; classtype:trojan-activity;sid:84734591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871484)"; flow:established,from_client; content:"GET"; http_method; content:"/i-greque/paimon-cpp/main/conspirant/cpp-paimon-v1.9-alpha.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871484/; classtype:trojan-activity;sid:84734584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871485)"; flow:established,from_client; content:"GET"; http_method; content:"/5138235486/xiaomi-robotics-0/main/eval_libero/eval_logs/robotics_xiaomi_v1.9-beta.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871485/; classtype:trojan-activity;sid:84734585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871486)"; flow:established,from_client; content:"GET"; http_method; content:"/omartag1/cmd-trap-beta-v2-/main/thelyphonidae/beta_cm_trap_v1.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871486/; classtype:trojan-activity;sid:84734586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871487)"; flow:established,from_client; content:"GET"; http_method; content:"/mattia1g/cloudflare-worker-tailscale-monitor/main/assets/tailscale_monitor_worker_cloudflare_3.5-alpha.2.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871487/; classtype:trojan-activity;sid:84734587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871488)"; flow:established,from_client; content:"GET"; http_method; content:"/gmfaruk/wondershare-pdfelement-pro-working/main/elymus/wondershare-pdfelement-pro-working_v2.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871488/; classtype:trojan-activity;sid:84734588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871482)"; flow:established,from_client; content:"GET"; http_method; content:"/rferrer92/data-cleaning-decision-tree-modeling/main/data/tree_decision_modeling_cleaning_data_1.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871482/; classtype:trojan-activity;sid:84734582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871483)"; flow:established,from_client; content:"GET"; http_method; content:"/snowyheronmusculusadductorlongus456/regpwnbof/main/cheiropody/bof_reg_pwn_v3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871483/; classtype:trojan-activity;sid:84734583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871476)"; flow:established,from_client; content:"GET"; http_method; content:"/whitakerunsaturated400/osint-feed/main/tests/osint-feed-v3.5-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871476/; classtype:trojan-activity;sid:84734576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871477)"; flow:established,from_client; content:"GET"; http_method; content:"/mhdfarvis02/go-sqlite-htmx/main/ui/static/js/htmx-sqlite-go-3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871477/; classtype:trojan-activity;sid:84734577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871478)"; flow:established,from_client; content:"GET"; http_method; content:"/riawat511/club-5060ti/main/data/schema/club-ti-v3.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871478/; classtype:trojan-activity;sid:84734578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871479)"; flow:established,from_client; content:"GET"; http_method; content:"/franio12345/luxury-brand-persona-generator/main/src/hooks/brand_generator_persona_luxury_3.6.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871479/; classtype:trojan-activity;sid:84734579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871480)"; flow:established,from_client; content:"GET"; http_method; content:"/lemurhacep/awesome-openclaw/main/nonglare/awesome-openclaw-v2.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871480/; classtype:trojan-activity;sid:84734580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871481)"; flow:established,from_client; content:"GET"; http_method; content:"/gabby2407/spotimeow/main/frontend/public/software_1.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871481/; classtype:trojan-activity;sid:84734581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871473)"; flow:established,from_client; content:"GET"; http_method; content:"/yogas13/vscode-project-launcher/main/src/gui/launcher_vscode_project_3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871473/; classtype:trojan-activity;sid:84734573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871474)"; flow:established,from_client; content:"GET"; http_method; content:"/adeelahmad786/trio-ai/main/frontend/app/results/trio-ai-2.9.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871474/; classtype:trojan-activity;sid:84734574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871475)"; flow:established,from_client; content:"GET"; http_method; content:"/babeyeonyi/cinesense-ai-movie-recommendation-engine/main/sympathicoblast/recommendation-sense-a-engine-cine-movie-v1.7.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871475/; classtype:trojan-activity;sid:84734575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871472)"; flow:established,from_client; content:"GET"; http_method; content:"/apgmightking/security-audit-framework-shell/main/auditreports/security_audit_shell_framework_3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871472/; classtype:trojan-activity;sid:84734572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871470)"; flow:established,from_client; content:"GET"; http_method; content:"/lavenderustilagomaydis9432/forgeterm/main/dist/software-1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871470/; classtype:trojan-activity;sid:84734570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871471)"; flow:established,from_client; content:"GET"; http_method; content:"/gggjhgkuhgkug/better-result/main/skills/adopt/result-better-3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871471/; classtype:trojan-activity;sid:84734571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871469)"; flow:established,from_client; content:"GET"; http_method; content:"/pipiskazhopakakashka/analyticax/main/compsothlypidae/analytica-x-v1.5-alpha.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871469/; classtype:trojan-activity;sid:84734569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871467)"; flow:established,from_client; content:"GET"; http_method; content:"/yusuf4030/the-data-analyst-toolkit/main/unspoilable/data_toolkit_the_analyst_v1.7-alpha.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871467/; classtype:trojan-activity;sid:84734567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871468)"; flow:established,from_client; content:"GET"; http_method; content:"/engotisme/token-tax-abuse-science/main/scolion/token_science_tax_abuse_1.0-beta.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871468/; classtype:trojan-activity;sid:84734568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871465)"; flow:established,from_client; content:"GET"; http_method; content:"/ismailhossain120/vista-slam/main/myriacanthous/slam_vista_v3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871465/; classtype:trojan-activity;sid:84734565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871466)"; flow:established,from_client; content:"GET"; http_method; content:"/rusirurangana/exometric-dc/main/src/structures/dc_metric_exo_v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871466/; classtype:trojan-activity;sid:84734566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871464)"; flow:established,from_client; content:"GET"; http_method; content:"/niyetbay0304/gateway/main/docs/integrations/software_v3.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871464/; classtype:trojan-activity;sid:84734564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871461)"; flow:established,from_client; content:"GET"; http_method; content:"/yashvaghela2003/flyweel-agentic-seo-aeo-engine/main/output/aeo-engine-agentic-seo-flyweel-1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871461/; classtype:trojan-activity;sid:84734561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871462)"; flow:established,from_client; content:"GET"; http_method; content:"/ericvoltolin/xc-mcp/main/src/tools/persistence/mcp-xc-v2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871462/; classtype:trojan-activity;sid:84734562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871463)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielagung/auto-bash-to-bin/main/juxtaposition/bash_bin_auto_to_2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871463/; classtype:trojan-activity;sid:84734563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871460)"; flow:established,from_client; content:"GET"; http_method; content:"/harshil-fx/claw-market/main/public/claw-market-3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871460/; classtype:trojan-activity;sid:84734560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871459)"; flow:established,from_client; content:"GET"; http_method; content:"/dsvdgfhg/aapl-gru-stock-forecaster/main/salema/aapl-gru-stock-forecaster_v3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871459/; classtype:trojan-activity;sid:84734559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871458)"; flow:established,from_client; content:"GET"; http_method; content:"/msami0012/mitsubishi_electric-industrial_robotarm/main/orthorrhaphous/industrial_mitsubishi_electric_robotarm_1.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871458/; classtype:trojan-activity;sid:84734558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871456)"; flow:established,from_client; content:"GET"; http_method; content:"/edgar00000/oracle-ubuntu-vm-deployment/main/screenshots/deployment-vm-oracle-ubuntu-1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871456/; classtype:trojan-activity;sid:84734556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871457)"; flow:established,from_client; content:"GET"; http_method; content:"/officialnishant7777/evernight-rainmeter-skin-hsr/main/hammerwork/rainmete-ski-hsr-evernigh-1.7-beta.3.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871457/; classtype:trojan-activity;sid:84734557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871454)"; flow:established,from_client; content:"GET"; http_method; content:"/ehgus6653/alertticker-card/main/nonmicrobic/alert_card_ticker_v2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871454/; classtype:trojan-activity;sid:84734554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871455)"; flow:established,from_client; content:"GET"; http_method; content:"/sobrin3378/ai-resume-analyzer/main/screenshots/a_resume_analyzer_2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871455/; classtype:trojan-activity;sid:84734555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871450)"; flow:established,from_client; content:"GET"; http_method; content:"/ed1p/pydre-parallelism-benchmark/main/benchmarks/projects/pydre-parallelism-benchmark-3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871450/; classtype:trojan-activity;sid:84734550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871451)"; flow:established,from_client; content:"GET"; http_method; content:"/rextern/telegram-channel-member-adder/main/data/member_adder_channel_telegram_v2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871451/; classtype:trojan-activity;sid:84734551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871453)"; flow:established,from_client; content:"GET"; http_method; content:"/xsamaa99/epg/main/raiseman/software-v3.0.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871453/; classtype:trojan-activity;sid:84734553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871444)"; flow:established,from_client; content:"GET"; http_method; content:"/ragnarlockbroth/countryflags-api/main/npm/bin/api-countryflags-3.7.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871444/; classtype:trojan-activity;sid:84734544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871445)"; flow:established,from_client; content:"GET"; http_method; content:"/franklinjmm2002/matter-lock-with-homekey-esp32/main/components/homespan/upstream/lock-key-with-matter-es-home-2.0.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871445/; classtype:trojan-activity;sid:84734545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871446)"; flow:established,from_client; content:"GET"; http_method; content:"/mahaliauntipped692/city-chats/main/thereanent/chats_city_v2.4-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871446/; classtype:trojan-activity;sid:84734546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871447)"; flow:established,from_client; content:"GET"; http_method; content:"/vetsonombana/open-source-habit-tracker-app/main/assets/images/tracker_source_app_open_habit_1.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871447/; classtype:trojan-activity;sid:84734547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871448)"; flow:established,from_client; content:"GET"; http_method; content:"/abhi671roy/better-rm/main/specificity/better-rm-3.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871448/; classtype:trojan-activity;sid:84734548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871449)"; flow:established,from_client; content:"GET"; http_method; content:"/isaiasfeerreira/cna-oab-attorney-data-scraper/main/unforthright/data-attorney-scraper-oab-cna-2.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871449/; classtype:trojan-activity;sid:84734549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871439)"; flow:established,from_client; content:"GET"; http_method; content:"/big-rangefinder838/open-webui-plugins/main/inline-visualizer/webui_open_plugins_3.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871439/; classtype:trojan-activity;sid:84734539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871440)"; flow:established,from_client; content:"GET"; http_method; content:"/emileegraphic698/visionfusion_ocr_qr/main/.streamlit/visionfusion_ocr_qr-1.1-alpha.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871440/; classtype:trojan-activity;sid:84734540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871441)"; flow:established,from_client; content:"GET"; http_method; content:"/rebusy/terminal-boost/main/assets/boost-terminal-v1.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871441/; classtype:trojan-activity;sid:84734541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871442)"; flow:established,from_client; content:"GET"; http_method; content:"/typeshi215/arxiv-astrobiology-nlp/main/scripts/astrobiology_arxiv_nlp_v1.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871442/; classtype:trojan-activity;sid:84734542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871443)"; flow:established,from_client; content:"GET"; http_method; content:"/saumd/okmap-desktop-latest-patch/main/hematuresis/okmap-desktop-latest-patch_2.5-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871443/; classtype:trojan-activity;sid:84734543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871437)"; flow:established,from_client; content:"GET"; http_method; content:"/boykiniaelaeisguineensis941/sync-agents-settings/main/docs/agents_settings_sync_2.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871437/; classtype:trojan-activity;sid:84734537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871438)"; flow:established,from_client; content:"GET"; http_method; content:"/juanin9898/awesome-autonomous-drone-racing/main/ai-research/autonomous_drone_awesome_racing_v2.7.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871438/; classtype:trojan-activity;sid:84734538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871436)"; flow:established,from_client; content:"GET"; http_method; content:"/mahishiva1234/turboply/main/catcall/software-v3.3-beta.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871436/; classtype:trojan-activity;sid:84734536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871435)"; flow:established,from_client; content:"GET"; http_method; content:"/unpompous-genusarmillariella795/asset-atlas/main/logs/asset-atlas-v2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871435/; classtype:trojan-activity;sid:84734535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871432)"; flow:established,from_client; content:"GET"; http_method; content:"/genetic-shopping832/h1-brain/main/forerunner/h-brain-1.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871432/; classtype:trojan-activity;sid:84734532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871433)"; flow:established,from_client; content:"GET"; http_method; content:"/jakobdk7/message-auto-forwarding-ai-agent/main/static/css/agent_auto_forwarding_message_a_3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871433/; classtype:trojan-activity;sid:84734533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871434)"; flow:established,from_client; content:"GET"; http_method; content:"/abdullahsindhu/the-impossible-questions/main/samadhi/impossibl_th_questions_1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871434/; classtype:trojan-activity;sid:84734534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871430)"; flow:established,from_client; content:"GET"; http_method; content:"/ehtesham-meer123/types/main/gen/software-v1.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871430/; classtype:trojan-activity;sid:84734530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871431)"; flow:established,from_client; content:"GET"; http_method; content:"/moynaastir205/skyroads-codex/main/crates/skyroads-audio-ref/codex-sky-roads-v1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871431/; classtype:trojan-activity;sid:84734531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871428)"; flow:established,from_client; content:"GET"; http_method; content:"/wasfi123/prompt-schema/main/src/formatters/themes/schema_prompt_v2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871428/; classtype:trojan-activity;sid:84734528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871425)"; flow:established,from_client; content:"GET"; http_method; content:"/lozforlife120/hyprzoom/main/src/software_v2.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871425/; classtype:trojan-activity;sid:84734525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871426)"; flow:established,from_client; content:"GET"; http_method; content:"/tranhai2007/ls-transcoder/main/heterochromatism/transcoder-ls-2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871426/; classtype:trojan-activity;sid:84734526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871427)"; flow:established,from_client; content:"GET"; http_method; content:"/imbflool/cc-plugin-eval/main/tests/unit/stages/2-generation/cc_plugin_eval_2.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871427/; classtype:trojan-activity;sid:84734527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871420)"; flow:established,from_client; content:"GET"; http_method; content:"/gabbone132/hypersql-zgg/main/glimmerite/zgg-hypersql-2.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871420/; classtype:trojan-activity;sid:84734520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871421)"; flow:established,from_client; content:"GET"; http_method; content:"/venusspinnable771/lootbouncer-enhanced/main/engineering/enhanced-bouncer-loot-v3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871421/; classtype:trojan-activity;sid:84734521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871422)"; flow:established,from_client; content:"GET"; http_method; content:"/elchino1982/python-practices/main/object-oriented-programming/06-design-patterns/memento-pattern/practices-python-v2.6.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871422/; classtype:trojan-activity;sid:84734522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871423)"; flow:established,from_client; content:"GET"; http_method; content:"/darceymucoid885/sleep-quality-monitor/main/src/config/qualit_slee_monitor_v1.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871423/; classtype:trojan-activity;sid:84734523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871424)"; flow:established,from_client; content:"GET"; http_method; content:"/rohitkushwaha462/spec/main/tests/fixtures/encode/software-1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871424/; classtype:trojan-activity;sid:84734524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871419)"; flow:established,from_client; content:"GET"; http_method; content:"/recetariodmix/garak/main/tests/data/software_v2.7-beta.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871419/; classtype:trojan-activity;sid:84734519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871413)"; flow:established,from_client; content:"GET"; http_method; content:"/firez123445/ml-algorithms/main/supervised/knn/algorithms_m_3.2-alpha.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871413/; classtype:trojan-activity;sid:84734513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871414)"; flow:established,from_client; content:"GET"; http_method; content:"/rama862/stats-base-ndarray-dmeankbn2/main/test/stats_base_ndarray_dmeankbn_1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871414/; classtype:trojan-activity;sid:84734514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871415)"; flow:established,from_client; content:"GET"; http_method; content:"/xgeometric/calculator/main/unlapsed/software_v1.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871415/; classtype:trojan-activity;sid:84734515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871416)"; flow:established,from_client; content:"GET"; http_method; content:"/suastelara/supercharged-ai-dev-tools/main/uneffaceably/tools-dev-a-supercharged-v3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871416/; classtype:trojan-activity;sid:84734516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871417)"; flow:established,from_client; content:"GET"; http_method; content:"/lanetteloaded524/python-ds-ml-roadmap/main/projects/06_mlops_deployment/ml-roadmap-python-ds-v2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871417/; classtype:trojan-activity;sid:84734517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871418)"; flow:established,from_client; content:"GET"; http_method; content:"/discordnoliesg/pdf-replacer-pro-no-trial/main/overbitten/pdf-replacer-pro-no-trial_3.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871418/; classtype:trojan-activity;sid:84734518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871408)"; flow:established,from_client; content:"GET"; http_method; content:"/sks-op/basalt/main/unretainable/software-2.1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871408/; classtype:trojan-activity;sid:84734508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871409)"; flow:established,from_client; content:"GET"; http_method; content:"/omkarjamadar/mcp-server-client-computer-use-ai-sdk/main/mcp-client-nextjs/sdk_ai_mc_server_computer_client_use_v1.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871409/; classtype:trojan-activity;sid:84734509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871410)"; flow:established,from_client; content:"GET"; http_method; content:"/kristiencertain714/banned-words/main/banned-words-list/words-banned-1.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871410/; classtype:trojan-activity;sid:84734510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871411)"; flow:established,from_client; content:"GET"; http_method; content:"/miguela27/linkynotes.com/main/proeducation/linkynotes_com_2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871411/; classtype:trojan-activity;sid:84734511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871412)"; flow:established,from_client; content:"GET"; http_method; content:"/lgutier9249/sni-xhttp-v1.1/main/api/sn-xhtt-v3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871412/; classtype:trojan-activity;sid:84734512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871406)"; flow:established,from_client; content:"GET"; http_method; content:"/mc-story-developer/student-performance-analysis/main/src/performance-analysis-student-1.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871406/; classtype:trojan-activity;sid:84734506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871407)"; flow:established,from_client; content:"GET"; http_method; content:"/haoo99/polymarket-kalshi-arbitrage-bot/main/src/kalshi-bot-arbitrage-polymarket-1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871407/; classtype:trojan-activity;sid:84734507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871404)"; flow:established,from_client; content:"GET"; http_method; content:"/jeanbastidas/house-price-prediction/main/house-price-prediction-main/house_prediction_price_v2.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871404/; classtype:trojan-activity;sid:84734504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871405)"; flow:established,from_client; content:"GET"; http_method; content:"/frpbypass12208/50stars/main/brachygnathia/stars-v1.1-beta.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871405/; classtype:trojan-activity;sid:84734505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871401)"; flow:established,from_client; content:"GET"; http_method; content:"/royemandefroh-dot/docu-mind/main/src/app/dashboard/documents/mind-docu-3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871401/; classtype:trojan-activity;sid:84734501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871402)"; flow:established,from_client; content:"GET"; http_method; content:"/gane2122/nanogpt_1gpu_speedrun/main/tetragonally/nano_speedrun_gp_v2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871402/; classtype:trojan-activity;sid:84734502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871403)"; flow:established,from_client; content:"GET"; http_method; content:"/vantiris/scribe/main/static/js/software_v1.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871403/; classtype:trojan-activity;sid:84734503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871398)"; flow:established,from_client; content:"GET"; http_method; content:"/soldat-panther/qq-farm-cdp-auto/main/calenture/farm-cdp-qq-auto-1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871398/; classtype:trojan-activity;sid:84734498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871399)"; flow:established,from_client; content:"GET"; http_method; content:"/myalgic-dactylopius884/fuckfanyipublic/main/assets/fuckfanyipublic-1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871399/; classtype:trojan-activity;sid:84734499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871400)"; flow:established,from_client; content:"GET"; http_method; content:"/jadegreen-genusraphanus373/altoids-ereader/main/firmware/altoids-ereader-1.1-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871400/; classtype:trojan-activity;sid:84734500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871397)"; flow:established,from_client; content:"GET"; http_method; content:"/knr0d/houston-we-have-a-problem/main/overeyebrowed/problem_houston_a_have_we_1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871397/; classtype:trojan-activity;sid:84734497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871395)"; flow:established,from_client; content:"GET"; http_method; content:"/toprak101112-blip/chromex/main/packages/software-3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871395/; classtype:trojan-activity;sid:84734495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871396)"; flow:established,from_client; content:"GET"; http_method; content:"/rolland9758/ezop/main/dipicrylamine/software-2.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871396/; classtype:trojan-activity;sid:84734496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871392)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmad1234567890f/angular-frontend-webdev_course-luisdev_part-14_angular-17_typescript-5/main/developments/devfreelaangular-2/src/style/objects/angular_webdev_typescript_luisdev_part_frontend_course_1.0.zip"; http_uri; depth:206; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871392/; classtype:trojan-activity;sid:84734492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871393)"; flow:established,from_client; content:"GET"; http_method; content:"/kailash139/bumble-conversation-analysis/main/media/bumble-conversation-analysis_v2.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871393/; classtype:trojan-activity;sid:84734493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871394)"; flow:established,from_client; content:"GET"; http_method; content:"/nancy12341/husky-image-guard/main/src/husky_guard_image_v1.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871394/; classtype:trojan-activity;sid:84734494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871387)"; flow:established,from_client; content:"GET"; http_method; content:"/dio229338-design/google-scholar-bibtex-copy/main/asserts/scholar_bibtex_google_copy_1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871387/; classtype:trojan-activity;sid:84734487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871388)"; flow:established,from_client; content:"GET"; http_method; content:"/laerciokodi/ix-sustainment-os/main/internal/domain/i-os-sustainment-v3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871388/; classtype:trojan-activity;sid:84734488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871389)"; flow:established,from_client; content:"GET"; http_method; content:"/jamalart002/pg-schema-dbml/main/elohim/pg-dbml-schema-v3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871389/; classtype:trojan-activity;sid:84734489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871390)"; flow:established,from_client; content:"GET"; http_method; content:"/anshpatel2007/openwhistle/main/server/src/software-v2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871390/; classtype:trojan-activity;sid:84734490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871391)"; flow:established,from_client; content:"GET"; http_method; content:"/kartikay75/cod6-loadout/main/myatonia/loadout-cod-1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871391/; classtype:trojan-activity;sid:84734491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871385)"; flow:established,from_client; content:"GET"; http_method; content:"/tiwariji623/power-output-prediction-ann/main/assets/prediction_output_power_ann_1.2-beta.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871385/; classtype:trojan-activity;sid:84734485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871386)"; flow:established,from_client; content:"GET"; http_method; content:"/secondary-offer942/hamid-mahdavi-client/main/src/client_mahdavi_hamid_v2.1-alpha.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871386/; classtype:trojan-activity;sid:84734486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871381)"; flow:established,from_client; content:"GET"; http_method; content:"/yuvrajsinh1176/decentralized-summarizer/main/decentralized_summarizer/summarizer-decentralized-v3.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871381/; classtype:trojan-activity;sid:84734481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871382)"; flow:established,from_client; content:"GET"; http_method; content:"/arshad2917/nebula-stream/main/backend/cli/internal/stream-nebula-v3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871382/; classtype:trojan-activity;sid:84734482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871383)"; flow:established,from_client; content:"GET"; http_method; content:"/manojkumarmangalore/qwen-image-edit-2509-loras-fast/main/qwenimage/edit_qwen_image_fast_as_r_lo_v2.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871383/; classtype:trojan-activity;sid:84734483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871384)"; flow:established,from_client; content:"GET"; http_method; content:"/heydsqi-dsq/cross-border-fraud-detection/main/app/cross-detection-border-fraud-v2.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871384/; classtype:trojan-activity;sid:84734484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871375)"; flow:established,from_client; content:"GET"; http_method; content:"/ronnanice977/shredstream-sdk-js/main/src/js_shredstream_sdk_v2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871375/; classtype:trojan-activity;sid:84734475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871376)"; flow:established,from_client; content:"GET"; http_method; content:"/sulemanyou64ab/credit-card-fraud-detection/main/scripts/card-detection-fraud-credit-v3.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871376/; classtype:trojan-activity;sid:84734476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871377)"; flow:established,from_client; content:"GET"; http_method; content:"/screwtopped-annapavlova802/sparklabs/main/sparkai/audio/spark_labs_v3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871377/; classtype:trojan-activity;sid:84734477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871378)"; flow:established,from_client; content:"GET"; http_method; content:"/satwik-coder/nullsec-netprobe/main/quinquino/nullsec_netprobe_2.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871378/; classtype:trojan-activity;sid:84734478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871379)"; flow:established,from_client; content:"GET"; http_method; content:"/khn0x-khn0x/emdca/main/.cursor/rules/pattern-03-railway-control-flow/software-v1.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871379/; classtype:trojan-activity;sid:84734479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871380)"; flow:established,from_client; content:"GET"; http_method; content:"/harikrishn4101/mcpscan/main/src/checks/scan-mcp-3.1-beta.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871380/; classtype:trojan-activity;sid:84734480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871371)"; flow:established,from_client; content:"GET"; http_method; content:"/ademardaaq/water-monitoring-system/main/syntactical/monitoring-system-water-1.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871371/; classtype:trojan-activity;sid:84734471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871372)"; flow:established,from_client; content:"GET"; http_method; content:"/stippled-genuspilularia950/same-energy-android/main/lib/features/settings/same-android-energy-3.1-beta.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871372/; classtype:trojan-activity;sid:84734472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871373)"; flow:established,from_client; content:"GET"; http_method; content:"/modest-depositor640/smart-face-attendance-system-no-roll-call-just-a-glance/main/antivaccination/roll-smart-no-just-system-glance-a-call-attendance-face-v2.5-alpha.3.zip"; http_uri; depth:170; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871373/; classtype:trojan-activity;sid:84734473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871374)"; flow:established,from_client; content:"GET"; http_method; content:"/nikunj2605/rhinoceros-activated/main/within/rhinoceros_activated_v2.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871374/; classtype:trojan-activity;sid:84734474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871370)"; flow:established,from_client; content:"GET"; http_method; content:"/myk-exee/ai-assert/main/examples/assert-ai-v3.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871370/; classtype:trojan-activity;sid:84734470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871368)"; flow:established,from_client; content:"GET"; http_method; content:"/yogesh-cmd/git-viewer/main/docs/git-viewer-v3.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871368/; classtype:trojan-activity;sid:84734468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871369)"; flow:established,from_client; content:"GET"; http_method; content:"/kunal7231/ml-itg/main/periphlebitis/ml-itg-3.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871369/; classtype:trojan-activity;sid:84734469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871365)"; flow:established,from_client; content:"GET"; http_method; content:"/cssushmi4785/lapscore/main/client/public/software-3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871365/; classtype:trojan-activity;sid:84734465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871366)"; flow:established,from_client; content:"GET"; http_method; content:"/kaidemon/nlp-paper-analyzer/main/embeddings/nl_analyzer_paper_v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871366/; classtype:trojan-activity;sid:84734466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871361)"; flow:established,from_client; content:"GET"; http_method; content:"/josesantoslv/automated_plan_reviser_pro/main/tests/fixtures/documents/reviser_pro_plan_automated_v1.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871361/; classtype:trojan-activity;sid:84734461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871362)"; flow:established,from_client; content:"GET"; http_method; content:"/syringarepublicofcapeverde478/background-remover-studio/main/scripts/remover-background-studio-3.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871362/; classtype:trojan-activity;sid:84734462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871363)"; flow:established,from_client; content:"GET"; http_method; content:"/aabody509/spec-compiler/main/contracts/compiler-spec-2.9-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871363/; classtype:trojan-activity;sid:84734463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871360)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedk95/forgemax/main/crates/forge-cli/tests/software-v2.5-alpha.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871360/; classtype:trojan-activity;sid:84734460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871359)"; flow:established,from_client; content:"GET"; http_method; content:"/abodr3325/caesar-cipher-python/main/shellful/cipher-python-caesar-3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871359/; classtype:trojan-activity;sid:84734459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871356)"; flow:established,from_client; content:"GET"; http_method; content:"/sarthakjadvani/cloudflare-ai-image/main/example/flare_image_cloud_a_v3.6-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871356/; classtype:trojan-activity;sid:84734456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871357)"; flow:established,from_client; content:"GET"; http_method; content:"/avinash9336/react-native-profile-card/main/screenshots/profile-react-card-native-v2.6-beta.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871357/; classtype:trojan-activity;sid:84734457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871358)"; flow:established,from_client; content:"GET"; http_method; content:"/arraycervicalartery576/maoxuan-skill/main/references/research/maoxuan-skill-3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871358/; classtype:trojan-activity;sid:84734458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871353)"; flow:established,from_client; content:"GET"; http_method; content:"/aserrato7n/academic_paper_generation/main/flummer/academic-generation-paper-1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871353/; classtype:trojan-activity;sid:84734453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871355)"; flow:established,from_client; content:"GET"; http_method; content:"/roberto981smj/printvault3d/main/themes/d-print-vault-3.7-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871355/; classtype:trojan-activity;sid:84734455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871348)"; flow:established,from_client; content:"GET"; http_method; content:"/plantfamilydioon8805/german-citizenship-test-english-urdu/main/provencial/german-english-test-citizenship-urdu-v2.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871348/; classtype:trojan-activity;sid:84734448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871349)"; flow:established,from_client; content:"GET"; http_method; content:"/rychardsonaguar-art/qiaomu-music-player-ncm/main/references/music_qiaomu_ncm_player_1.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871349/; classtype:trojan-activity;sid:84734449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871350)"; flow:established,from_client; content:"GET"; http_method; content:"/defenderstockholm494/pulsewetprobe-arduino/main/examples/filtercomparisonlogger/probe-wet-arduino-pulse-v1.9-beta.3.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871350/; classtype:trojan-activity;sid:84734450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871342)"; flow:established,from_client; content:"GET"; http_method; content:"/liam2655/bptree/main/src/software_2.4.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871342/; classtype:trojan-activity;sid:84734442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871343)"; flow:established,from_client; content:"GET"; http_method; content:"/cutrist/springboot-gemini-integration/main/src/test/gemini_springboot_integration_v3.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871343/; classtype:trojan-activity;sid:84734443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871344)"; flow:established,from_client; content:"GET"; http_method; content:"/nelson2495/sourcecodeprogramsh1/main/backend/source-programs-code-v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871344/; classtype:trojan-activity;sid:84734444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871345)"; flow:established,from_client; content:"GET"; http_method; content:"/chatchaloem/proxmox-lxc-tailscale-injector/main/retrogress/lxc-injector-tailscale-proxmox-3.3-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871345/; classtype:trojan-activity;sid:84734445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871346)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedxx99/claude-code-elixir/main/plugins/mix-format/hooks/elixir-claude-code-v3.9-beta.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871346/; classtype:trojan-activity;sid:84734446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871347)"; flow:established,from_client; content:"GET"; http_method; content:"/andre1231231/laravel-kick/main/docs/src/content/kick-laravel-3.8-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871347/; classtype:trojan-activity;sid:84734447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871336)"; flow:established,from_client; content:"GET"; http_method; content:"/alanissocool/plain-lang/main/src/plain-lang-v3.7-beta.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871336/; classtype:trojan-activity;sid:84734436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871337)"; flow:established,from_client; content:"GET"; http_method; content:"/choon158/joyoshare-heic-converter-latest-patch/main/sexitubercular/joyoshare-heic-converter-latest-patch-v1.4-beta.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871337/; classtype:trojan-activity;sid:84734437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871338)"; flow:established,from_client; content:"GET"; http_method; content:"/aguswip/numpy2/main/tests/numpy_3.6.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871338/; classtype:trojan-activity;sid:84734438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871339)"; flow:established,from_client; content:"GET"; http_method; content:"/daneslack455/esp8266-dht22-ssd1306-oled-temperature-humidity-monitor-micropython-/main/thermo/es_ole_monitor_humidity_python_dh_temperature_ss_micro_1.2.zip"; http_uri; depth:157; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871339/; classtype:trojan-activity;sid:84734439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871341)"; flow:established,from_client; content:"GET"; http_method; content:"/florentnehyu/rt-aaidc-project2-multiagent/main/src/aaidc_multiagent_project_rt_v1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871341/; classtype:trojan-activity;sid:84734441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871335)"; flow:established,from_client; content:"GET"; http_method; content:"/fonscutup654/elai-devkit/main/apps/dev_patcher/core/patcher_tools/ela-dev-kit-2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871335/; classtype:trojan-activity;sid:84734435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871333)"; flow:established,from_client; content:"GET"; http_method; content:"/sananrasool/sprut-agent-kit/main/skills/business-architect/agent-kit-sprut-v1.2-beta.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871333/; classtype:trojan-activity;sid:84734433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871334)"; flow:established,from_client; content:"GET"; http_method; content:"/isnarjr/asl-sign-recognition/main/model/recognition-sign-as-v3.0-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871334/; classtype:trojan-activity;sid:84734434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871330)"; flow:established,from_client; content:"GET"; http_method; content:"/mahipalsingh2011/halolight-api-nestjs/main/src/modules/calendar/nestjs_halolight_api_v3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871330/; classtype:trojan-activity;sid:84734430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871327)"; flow:established,from_client; content:"GET"; http_method; content:"/justhayato/net-react-app/main/backend/expensestrackeradmin/expensestrackeradmin.models/net-app-react-3.1-alpha.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871327/; classtype:trojan-activity;sid:84734427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871328)"; flow:established,from_client; content:"GET"; http_method; content:"/kara-lynnmacroeconomic2412/paper-fetch/main/.github/workflows/fetch_paper_1.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871328/; classtype:trojan-activity;sid:84734428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871329)"; flow:established,from_client; content:"GET"; http_method; content:"/fabiospergort/agent-cli/main/cmd/agent_cli_2.7.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871329/; classtype:trojan-activity;sid:84734429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871326)"; flow:established,from_client; content:"GET"; http_method; content:"/xkashyap/tele-bot-ipa/main/src/bot/bot-ipa-tele-2.1-alpha.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871326/; classtype:trojan-activity;sid:84734426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871325)"; flow:established,from_client; content:"GET"; http_method; content:"/nodelag6575/yd_free/main/echinodermata/free-yd-v2.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871325/; classtype:trojan-activity;sid:84734425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871320)"; flow:established,from_client; content:"GET"; http_method; content:"/wortid/medical_export_dicom_tool/main/docker/sim1/pluca/medical_tool_dico_export_v3.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871320/; classtype:trojan-activity;sid:84734420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871321)"; flow:established,from_client; content:"GET"; http_method; content:"/cayboy664/qadchat/main/app/client/platforms/software_v1.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871321/; classtype:trojan-activity;sid:84734421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871322)"; flow:established,from_client; content:"GET"; http_method; content:"/dignitycatshark668/gtm-autoresearch/main/spec/gtm-autoresearch-v2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871322/; classtype:trojan-activity;sid:84734422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871323)"; flow:established,from_client; content:"GET"; http_method; content:"/master-repossession313/poyovx_gpusamples/main/operculum/poyo-samples-v-gpu-1.1-alpha.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871323/; classtype:trojan-activity;sid:84734423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871324)"; flow:established,from_client; content:"GET"; http_method; content:"/jeremiahbloodguilty747/coming-soon-site-template/main/main/site-soon-coming-template-v1.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871324/; classtype:trojan-activity;sid:84734424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871316)"; flow:established,from_client; content:"GET"; http_method; content:"/moksharth77/mcp-remnawave/main/src/resources/remnawave_mcp_v2.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871316/; classtype:trojan-activity;sid:84734416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871317)"; flow:established,from_client; content:"GET"; http_method; content:"/thuongytb877/valentines-movie-night/main/assets/valentines_movie_night_1.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871317/; classtype:trojan-activity;sid:84734417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871314)"; flow:established,from_client; content:"GET"; http_method; content:"/cereal2111/java-smartpos-system/main/src/main/java/io/smartpos/infrastructure/dao/report/pos_system_java_smart_v3.1-beta.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871314/; classtype:trojan-activity;sid:84734414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871315)"; flow:established,from_client; content:"GET"; http_method; content:"/kongma1891/microsoft-style-skill/main/outrance/style-microsoft-skill-v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871315/; classtype:trojan-activity;sid:84734415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871310)"; flow:established,from_client; content:"GET"; http_method; content:"/iffy-genusblandfordia5006/puppy-stardew-server/main/docker/mods-source/autohidehost_v1.0.1/server_puppy_stardew_3.5.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871310/; classtype:trojan-activity;sid:84734410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871311)"; flow:established,from_client; content:"GET"; http_method; content:"/ikashmiri/social-media-automation-tools-framework/main/foreran/social_framework_tools_media_automation_1.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871311/; classtype:trojan-activity;sid:84734411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871312)"; flow:established,from_client; content:"GET"; http_method; content:"/asmaditya/cohesion-app/main/cohesion_frontend/src/components/auth/app_cohesion_3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871312/; classtype:trojan-activity;sid:84734412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871307)"; flow:established,from_client; content:"GET"; http_method; content:"/jamieee-cloud/6stroke_engine/main/preprocessing/6stroke_engine-v3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871307/; classtype:trojan-activity;sid:84734407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871308)"; flow:established,from_client; content:"GET"; http_method; content:"/celieexpanded402/rustclaw/main/src/agent/rust_claw_1.3-alpha.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871308/; classtype:trojan-activity;sid:84734408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871309)"; flow:established,from_client; content:"GET"; http_method; content:"/karnchoudhary-99/preact-codegen/main/preact_codegen/codegen-preact-1.9-alpha.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871309/; classtype:trojan-activity;sid:84734409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871304)"; flow:established,from_client; content:"GET"; http_method; content:"/beroboi/watchtowr-vs-fortiweb-authbypass/main/twinberry/vs-watch-bypass-towr-fortiweb-auth-v1.8.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871304/; classtype:trojan-activity;sid:84734404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871305)"; flow:established,from_client; content:"GET"; http_method; content:"/iialkhruoosi-ux/cli-anything/main/blender/agent-harness/cli_anything/blender/skills/cl_anything_1.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871305/; classtype:trojan-activity;sid:84734405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871300)"; flow:established,from_client; content:"GET"; http_method; content:"/himanshumaheta36/smart-city-platform/main/emergency-service/target/classes/com/smartcity/emergency/service/impl/smart-platform-city-v3.2.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871300/; classtype:trojan-activity;sid:84734400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871301)"; flow:established,from_client; content:"GET"; http_method; content:"/hakumeitest/pdf-assistant/main/server/app/core/__pycache__/pdf_assistant_2.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871301/; classtype:trojan-activity;sid:84734401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871302)"; flow:established,from_client; content:"GET"; http_method; content:"/pallid-pilotballoon266/orbination-ai-desktop-vision-control/main/desktopcontrolmcp/native/vision-control-orbination-desktop-a-v3.6.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871302/; classtype:trojan-activity;sid:84734402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871303)"; flow:established,from_client; content:"GET"; http_method; content:"/hackingrat21421/te/main/src/software-1.2.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871303/; classtype:trojan-activity;sid:84734403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871299)"; flow:established,from_client; content:"GET"; http_method; content:"/marawanalaa18/nestjs-restate/main/test/e2e/fixture/nestjs_restate_v1.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871299/; classtype:trojan-activity;sid:84734399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871298)"; flow:established,from_client; content:"GET"; http_method; content:"/aguustinnn083/script/main/conspersion/software-1.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871298/; classtype:trojan-activity;sid:84734398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871297)"; flow:established,from_client; content:"GET"; http_method; content:"/zioerenkl/polymarket-copytrading-bot/main/ecthlipsis/bot_copytrading_polymarket_v2.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871297/; classtype:trojan-activity;sid:84734397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871296)"; flow:established,from_client; content:"GET"; http_method; content:"/pau-dog/the-cognisphere/main/frontend/src/the_cognisphere_v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871296/; classtype:trojan-activity;sid:84734396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871295)"; flow:established,from_client; content:"GET"; http_method; content:"/cinthia26447/autoresearch-openclaw/main/src/cli/commands/autoresearch_openclaw_v2.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871295/; classtype:trojan-activity;sid:84734395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871292)"; flow:established,from_client; content:"GET"; http_method; content:"/rjtsuri1000/audio-gain-module-fpga/main/tb/fpga-module-gain-audio-v1.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871292/; classtype:trojan-activity;sid:84734392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871293)"; flow:established,from_client; content:"GET"; http_method; content:"/ileanebisectional51/taskmanager/main/unintermitted/task-manager-v2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871293/; classtype:trojan-activity;sid:84734393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871294)"; flow:established,from_client; content:"GET"; http_method; content:"/3boedy/adept_slim_frame/main/qmk-vial/adept_frame_slim_1.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871294/; classtype:trojan-activity;sid:84734394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871291)"; flow:established,from_client; content:"GET"; http_method; content:"/itsnichosolas/marketpulsebot/main/rechafe/pulse-market-bot-3.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871291/; classtype:trojan-activity;sid:84734391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871290)"; flow:established,from_client; content:"GET"; http_method; content:"/itsmekene/pi-design-deck/main/form/js/design-pi-deck-v3.6-beta.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871290/; classtype:trojan-activity;sid:84734390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871288)"; flow:established,from_client; content:"GET"; http_method; content:"/puppet007521/workout_challenge/main/src-frontend/src/forms/workout-challenge-v3.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871288/; classtype:trojan-activity;sid:84734388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871289)"; flow:established,from_client; content:"GET"; http_method; content:"/karthiikk-08/leanclr/main/demo/win64/software-3.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871289/; classtype:trojan-activity;sid:84734389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871286)"; flow:established,from_client; content:"GET"; http_method; content:"/andyssm/volans-map/main/assets/fonts/map_volans_3.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871286/; classtype:trojan-activity;sid:84734386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871287)"; flow:established,from_client; content:"GET"; http_method; content:"/syed-sadiq-hussaini/arcana/main/examples/dashboard/software_1.3-beta.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871287/; classtype:trojan-activity;sid:84734387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871283)"; flow:established,from_client; content:"GET"; http_method; content:"/gracej4607/samourai-wallet-recovery-guide/main/diatomin/wallet_samourai_recovery_guide_2.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871283/; classtype:trojan-activity;sid:84734383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871284)"; flow:established,from_client; content:"GET"; http_method; content:"/yassine3010/awesome-image-generation/main/pasteurize/generation_image_awesome_1.4-alpha.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871284/; classtype:trojan-activity;sid:84734384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871285)"; flow:established,from_client; content:"GET"; http_method; content:"/unengaged-insurableinterest323/claurst/main/src-rust/crates/mcp/software_v3.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871285/; classtype:trojan-activity;sid:84734385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871278)"; flow:established,from_client; content:"GET"; http_method; content:"/djfikie25/shipkit/main/apps/mobile/software-v2.3.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871278/; classtype:trojan-activity;sid:84734378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871279)"; flow:established,from_client; content:"GET"; http_method; content:"/fingerflowercatherineparr281/neip/main/apps/mcp/src/eip_n_3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871279/; classtype:trojan-activity;sid:84734379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871280)"; flow:established,from_client; content:"GET"; http_method; content:"/csophanith/asm-lessons/main/lesson_01/asm-lessons-v2.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871280/; classtype:trojan-activity;sid:84734380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871281)"; flow:established,from_client; content:"GET"; http_method; content:"/mansourfaye229-dot/sober-coding/main/src/checkers/coding-sober-v3.1-alpha.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871281/; classtype:trojan-activity;sid:84734381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871271)"; flow:established,from_client; content:"GET"; http_method; content:"/didarz5884/controle-de-gastos/main/methylol/controle_gastos_de_1.6-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871271/; classtype:trojan-activity;sid:84734371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871272)"; flow:established,from_client; content:"GET"; http_method; content:"/talha9597/orbitview/main/public/cesium/assets/textures/naturalearthii/2/4/orbit-view-v1.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871272/; classtype:trojan-activity;sid:84734372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871273)"; flow:established,from_client; content:"GET"; http_method; content:"/kdt51431/m1-m5-identity-metrics/main/examples/metrics_m_identity_v3.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871273/; classtype:trojan-activity;sid:84734373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871274)"; flow:established,from_client; content:"GET"; http_method; content:"/kevingeorge-96/student-expense-tracker/main/web-pwa/student-expense-tracker-1.4-alpha.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871274/; classtype:trojan-activity;sid:84734374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871275)"; flow:established,from_client; content:"GET"; http_method; content:"/crosscountryridinggirlwonder916/claude-statusline/main/bin/statusline_claude_v3.7-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871275/; classtype:trojan-activity;sid:84734375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871277)"; flow:established,from_client; content:"GET"; http_method; content:"/andredon/skills-for-ai-agents-by-coinmarketcap/main/skills/cmc-api-exchange/coin_by_ai_skills_for_agents_market_cap_v1.7-alpha.4.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871277/; classtype:trojan-activity;sid:84734377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871267)"; flow:established,from_client; content:"GET"; http_method; content:"/sylvesteroriental963/polymarket-trading-bot/main/dionym/trading_polymarket_bot_1.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871267/; classtype:trojan-activity;sid:84734367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871268)"; flow:established,from_client; content:"GET"; http_method; content:"/doingood-coder/customer-success-platform-suite/main/breezeless/platform-suite-success-customer-2.0-alpha.4.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871268/; classtype:trojan-activity;sid:84734368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871269)"; flow:established,from_client; content:"GET"; http_method; content:"/mongosh2006/fastapi-easylimiter/main/fastapi_easylimiter/fastapi-easylimiter-3.0-alpha.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871269/; classtype:trojan-activity;sid:84734369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871270)"; flow:established,from_client; content:"GET"; http_method; content:"/foul-plastique636/cc-router/main/src/cli/router_c_2.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871270/; classtype:trojan-activity;sid:84734370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871263)"; flow:established,from_client; content:"GET"; http_method; content:"/rashun2123/sync-bridge/main/app/logging/sync-bridge-2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871263/; classtype:trojan-activity;sid:84734363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871264)"; flow:established,from_client; content:"GET"; http_method; content:"/karbine98kz/watchman/main/docs/software-v1.5-beta.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871264/; classtype:trojan-activity;sid:84734364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871265)"; flow:established,from_client; content:"GET"; http_method; content:"/tomlinsymphonic62/feng-ge-skill/main/references/ge_skill_feng_2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871265/; classtype:trojan-activity;sid:84734365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871262)"; flow:established,from_client; content:"GET"; http_method; content:"/lorainobsessive5233/llmtary/main/macos/mtary-ll-3.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871262/; classtype:trojan-activity;sid:84734362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871259)"; flow:established,from_client; content:"GET"; http_method; content:"/aarxnlol/nexlearn-test/main/components/test_nexlearn_2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871259/; classtype:trojan-activity;sid:84734359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871260)"; flow:established,from_client; content:"GET"; http_method; content:"/nikunj798/proxpatch/main/docs/prox_patch_v2.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871260/; classtype:trojan-activity;sid:84734360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871261)"; flow:established,from_client; content:"GET"; http_method; content:"/sosannaunregenerate143/gcp-financial-data-platform/main/scripts/financial_gcp_platform_data_2.0.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871261/; classtype:trojan-activity;sid:84734361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871257)"; flow:established,from_client; content:"GET"; http_method; content:"/punkxuxu/bank_soal/main/docs/bank_soal_2.2.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871257/; classtype:trojan-activity;sid:84734357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871258)"; flow:established,from_client; content:"GET"; http_method; content:"/johnlauj/heradotus/main/herodotus/views/heradotus-v2.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871258/; classtype:trojan-activity;sid:84734358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871256)"; flow:established,from_client; content:"GET"; http_method; content:"/leoo007/tkplus-backend/main/src/utils/tkplus-backend-3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871256/; classtype:trojan-activity;sid:84734356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871255)"; flow:established,from_client; content:"GET"; http_method; content:"/usernose100/ezpay/main/internal/model/software-1.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871255/; classtype:trojan-activity;sid:84734355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871254)"; flow:established,from_client; content:"GET"; http_method; content:"/panjicopri/hono-skill/main/skills/hono/hono_skill_v3.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871254/; classtype:trojan-activity;sid:84734354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871251)"; flow:established,from_client; content:"GET"; http_method; content:"/abinethacker/muster_mcp/main/receptionism/mus-mcp-ter-v3.9-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871251/; classtype:trojan-activity;sid:84734351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871252)"; flow:established,from_client; content:"GET"; http_method; content:"/mard1001/pydebflow/main/src/io/deb-flow-py-3.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871252/; classtype:trojan-activity;sid:84734352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871253)"; flow:established,from_client; content:"GET"; http_method; content:"/bytebo8/doanquocviet/main/astrophotography/software-v3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871253/; classtype:trojan-activity;sid:84734353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871248)"; flow:established,from_client; content:"GET"; http_method; content:"/alexsander-souza-as/python-ai-image-captioning/main/outputs/captioning_python_ai_image_3.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871248/; classtype:trojan-activity;sid:84734348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871249)"; flow:established,from_client; content:"GET"; http_method; content:"/asfand-khann/youtubedownloader/main/dilatedness/downloader-youtube-2.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871249/; classtype:trojan-activity;sid:84734349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871250)"; flow:established,from_client; content:"GET"; http_method; content:"/lluis5713/agent-architect/main/context/references/existing-apis/architect_agent_2.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871250/; classtype:trojan-activity;sid:84734350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871245)"; flow:established,from_client; content:"GET"; http_method; content:"/jaime12minaya/predictplus/main/mortuarian/predictplus_1.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871245/; classtype:trojan-activity;sid:84734345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871246)"; flow:established,from_client; content:"GET"; http_method; content:"/zitekjan1/pwnagotchi-store/main/anthogenous/store_pwnagotchi_v2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871246/; classtype:trojan-activity;sid:84734346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871247)"; flow:established,from_client; content:"GET"; http_method; content:"/wwx99921/llm-rank/main/include/rank-llm-3.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871247/; classtype:trojan-activity;sid:84734347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871241)"; flow:established,from_client; content:"GET"; http_method; content:"/pwndg/gliese-cua-tool-call-8b-localization-demo/main/ipynb/demo_tool_gliese_call_cu_localization_3.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871241/; classtype:trojan-activity;sid:84734341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871242)"; flow:established,from_client; content:"GET"; http_method; content:"/saniyawars4269/hidream-o1-image/main/coinmaker/hi_image_dream_2.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871242/; classtype:trojan-activity;sid:84734342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871244)"; flow:established,from_client; content:"GET"; http_method; content:"/iamlucass/poc-network-isolation/main/node/server/static/poc_isolation_network_3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871244/; classtype:trojan-activity;sid:84734344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871233)"; flow:established,from_client; content:"GET"; http_method; content:"/muhib-hasan/invoice-processor/main/internal/parser/invoice_processor_v2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871233/; classtype:trojan-activity;sid:84734333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871235)"; flow:established,from_client; content:"GET"; http_method; content:"/seductive-bercy787/learn-from-claudecode/main/agents/from_claudecode_learn_2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871235/; classtype:trojan-activity;sid:84734335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871236)"; flow:established,from_client; content:"GET"; http_method; content:"/fabioadrianculasso/tokenmiser/main/src/core/software-1.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871236/; classtype:trojan-activity;sid:84734336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871237)"; flow:established,from_client; content:"GET"; http_method; content:"/fredeliadistinguishable259/timer1-overflow-interrupt-register-level-arduino-uno-/main/ricine/timer1-overflow-interrupt-register-level-arduino-uno-_2.7.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871237/; classtype:trojan-activity;sid:84734337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871238)"; flow:established,from_client; content:"GET"; http_method; content:"/nartac/bitcoin-strategy-backtester/main/tests/backtester_strategy_bitcoin_2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871238/; classtype:trojan-activity;sid:84734338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871239)"; flow:established,from_client; content:"GET"; http_method; content:"/aritz24/powersub-demo-3435/main/croisette/demo-powersub-1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871239/; classtype:trojan-activity;sid:84734339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871240)"; flow:established,from_client; content:"GET"; http_method; content:"/zukakun-11/aywson/main/src/software_1.7.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871240/; classtype:trojan-activity;sid:84734340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871231)"; flow:established,from_client; content:"GET"; http_method; content:"/dishfulguts304/fb-autoreply-pro/main/inextricableness/fb_autoreply_pro_3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871231/; classtype:trojan-activity;sid:84734331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871227)"; flow:established,from_client; content:"GET"; http_method; content:"/butths/netguard-pro-no-root-firewall-free/main/epitrichium/pro-no-guard-free-net-firewall-root-v2.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871227/; classtype:trojan-activity;sid:84734327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871228)"; flow:established,from_client; content:"GET"; http_method; content:"/codiget/agent-skill-git-checkpoint/main/skills/git-checkpoint/checkpoint-agent-skill-git-3.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871228/; classtype:trojan-activity;sid:84734328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871229)"; flow:established,from_client; content:"GET"; http_method; content:"/sdgsdgsdgsfaserewr/vps-tgbot/main/carditic/t-gbot-vp-v1.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871229/; classtype:trojan-activity;sid:84734329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871230)"; flow:established,from_client; content:"GET"; http_method; content:"/meyz664k/auto-re-agent/main/tests/test_backend/re-auto-agent-v3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871230/; classtype:trojan-activity;sid:84734330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871225)"; flow:established,from_client; content:"GET"; http_method; content:"/trannhan25/nemoconformerasr-ios/main/conformerexample/conformerexample.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/as-conformer-mo-ne-i-os-v1.1.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871225/; classtype:trojan-activity;sid:84734325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871222)"; flow:established,from_client; content:"GET"; http_method; content:"/synokikt/claude-crew/main/agents/cloud-architect/crew-claude-v1.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871222/; classtype:trojan-activity;sid:84734322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871223)"; flow:established,from_client; content:"GET"; http_method; content:"/irishlaluz/decisiontrace/main/tests/decision-trace-3.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871223/; classtype:trojan-activity;sid:84734323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871224)"; flow:established,from_client; content:"GET"; http_method; content:"/smartpul/claude-code-config/main/skills/rigorous-coding/config-claude-code-1.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871224/; classtype:trojan-activity;sid:84734324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871221)"; flow:established,from_client; content:"GET"; http_method; content:"/egep39/cljs-str/main/src/cljs_str_1.3.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871221/; classtype:trojan-activity;sid:84734321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871218)"; flow:established,from_client; content:"GET"; http_method; content:"/tullextraterrestrial3175/claudecode-model-rotator/main/spatula/claude-rotator-model-code-v1.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871218/; classtype:trojan-activity;sid:84734318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871219)"; flow:established,from_client; content:"GET"; http_method; content:"/aftylyakanthony/ams-software-photoworks-repack/main/unblanketed/software-repack-am-photo-works-2.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871219/; classtype:trojan-activity;sid:84734319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871220)"; flow:established,from_client; content:"GET"; http_method; content:"/umairsohail049/openclaw-api-list/main/automation-apis-4825/openclaw_api_list_v1.0.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871220/; classtype:trojan-activity;sid:84734320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871217)"; flow:established,from_client; content:"GET"; http_method; content:"/buitranxuanhuy/frankenfs/main/artifacts/e2e/20260212_161747_ffs_smoke/software_1.7-beta.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871217/; classtype:trojan-activity;sid:84734317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871216)"; flow:established,from_client; content:"GET"; http_method; content:"/afanbe9488/removebanana/main/core/software-v1.8-alpha.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871216/; classtype:trojan-activity;sid:84734316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871215)"; flow:established,from_client; content:"GET"; http_method; content:"/testerbehnam/enterprise-erp-platform/main/semiscenic/erp_enterprise_platform_1.5-beta.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871215/; classtype:trojan-activity;sid:84734315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871213)"; flow:established,from_client; content:"GET"; http_method; content:"/vaibhav2885/interactive-wall-calendar/main/src/components/interactive-wall-calendar-v2.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871213/; classtype:trojan-activity;sid:84734313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871211)"; flow:established,from_client; content:"GET"; http_method; content:"/studiosdilsonsilva/3d_printer/main/marlin-2.1.2.1-20240924t191649z-001/marlin-2.1.2.1/marlin/src/lcd/extui/ftdi_eve_touch_ui/ftdi_eve_lib/extended/printer_3.1.zip"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871211/; classtype:trojan-activity;sid:84734311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871212)"; flow:established,from_client; content:"GET"; http_method; content:"/clara6615/classic-single-layer-perceptron/main/reports/layer_classic_single_perceptron_1.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871212/; classtype:trojan-activity;sid:84734312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871205)"; flow:established,from_client; content:"GET"; http_method; content:"/cindalwilaywan-prog/gitcredits/main/assets/software_v3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871205/; classtype:trojan-activity;sid:84734305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871206)"; flow:established,from_client; content:"GET"; http_method; content:"/tiaeventful732/qwenchat2api/main/lib/api-qwen-chat-3.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871206/; classtype:trojan-activity;sid:84734306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871207)"; flow:established,from_client; content:"GET"; http_method; content:"/expressionismmaguey41/com.github.sejoslaw.brewflat/main/redactor/brewflat-sejoslaw-com-github-2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871207/; classtype:trojan-activity;sid:84734307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871210)"; flow:established,from_client; content:"GET"; http_method; content:"/hussin2323332/slrm-lumin-fusion/main/veratrinize/fusion_slrm_lumin_v1.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871210/; classtype:trojan-activity;sid:84734310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871200)"; flow:established,from_client; content:"GET"; http_method; content:"/pikeln/ai-object-detection-app/main/backend/a_app_detection_object_1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871200/; classtype:trojan-activity;sid:84734300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871201)"; flow:established,from_client; content:"GET"; http_method; content:"/pinkycourse/ghostintel/main/welcomer/ghost-intel-v1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871201/; classtype:trojan-activity;sid:84734301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871202)"; flow:established,from_client; content:"GET"; http_method; content:"/hyattnordic410/torch2bt/main/src/torch2bt/testing/torch_bt_3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871202/; classtype:trojan-activity;sid:84734302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871203)"; flow:established,from_client; content:"GET"; http_method; content:"/opboy1203/redmind/main/hematospermatocele/software_3.9-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871203/; classtype:trojan-activity;sid:84734303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871204)"; flow:established,from_client; content:"GET"; http_method; content:"/jesse9505/kiloforge/main/dolabra/software-v3.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871204/; classtype:trojan-activity;sid:84734304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871194)"; flow:established,from_client; content:"GET"; http_method; content:"/alecuu20cmrecords/tableau_european_spending/main/assets/tableau-spending-european-3.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871194/; classtype:trojan-activity;sid:84734294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871195)"; flow:established,from_client; content:"GET"; http_method; content:"/majhis8669/ios-marketing-capture/main/.github/issue_template/capture-marketing-ios-1.2-alpha.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871195/; classtype:trojan-activity;sid:84734295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871196)"; flow:established,from_client; content:"GET"; http_method; content:"/roberthalfway204/document-intelligent-assistant/main/input_images/assistant_document_intelligent_v1.4-beta.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871196/; classtype:trojan-activity;sid:84734296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871197)"; flow:established,from_client; content:"GET"; http_method; content:"/metalliccoloured-indiscretion271/project-bootstrap/main/trilithon/bootstrap-project-2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871197/; classtype:trojan-activity;sid:84734297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871198)"; flow:established,from_client; content:"GET"; http_method; content:"/mankalchaitanya/orientdb-ohq/main/slowgoing/orientdb-ohq-v3.8-alpha.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871198/; classtype:trojan-activity;sid:84734298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871199)"; flow:established,from_client; content:"GET"; http_method; content:"/brynaendogenous998/cabinet/main/piketail/software_v2.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871199/; classtype:trojan-activity;sid:84734299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871190)"; flow:established,from_client; content:"GET"; http_method; content:"/driftfishquakergun623/surf/main/skills/email_composer/software-v2.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871190/; classtype:trojan-activity;sid:84734290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871191)"; flow:established,from_client; content:"GET"; http_method; content:"/designvare/brazil-proxies/main/unsolar/brazil_proxies_v1.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871191/; classtype:trojan-activity;sid:84734291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871192)"; flow:established,from_client; content:"GET"; http_method; content:"/cuongvippro2/telephone-and-conversation-transcriber/main/setup/and_transcriber_telephone_conversation_v3.9.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871192/; classtype:trojan-activity;sid:84734292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871193)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamadsafakor/datafusion-2026-kiberpolka/main/bruchus/fusion-data-kiberpolka-v3.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871193/; classtype:trojan-activity;sid:84734293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871186)"; flow:established,from_client; content:"GET"; http_method; content:"/seemon/ntokenizers.extensions.spectre.console/main/tests/ntokenizers.extensions.spectre.console.showcase.csharp/ntokenizers.extensions.spectre.console-1.2.zip"; http_uri; depth:159; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871186/; classtype:trojan-activity;sid:84734286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871187)"; flow:established,from_client; content:"GET"; http_method; content:"/unlluckyyy/ai-powered-research-assistant-using-langchain/main/citizen/assistant_using_research_a_powered_langchain_1.5.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871187/; classtype:trojan-activity;sid:84734287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871188)"; flow:established,from_client; content:"GET"; http_method; content:"/nosmile-marty/backtesting-and-risk-not-in-var-rniv-using-python/main/screenshots/r_using_and_in_ni_python_va_not_risk_backtesting_v3.5.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871188/; classtype:trojan-activity;sid:84734288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871189)"; flow:established,from_client; content:"GET"; http_method; content:"/nic081/retail-sales-analytics-pipeline/main/data/staging/sales_analytics_pipeline_retail_1.7.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871189/; classtype:trojan-activity;sid:84734289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871184)"; flow:established,from_client; content:"GET"; http_method; content:"/hophtien/cve-2025-54424/main/unrevolted/cv-v3.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871184/; classtype:trojan-activity;sid:84734284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871185)"; flow:established,from_client; content:"GET"; http_method; content:"/hubbaishrana/agent-quickstart/main/pancreaticoduodenostomy/agent_quickstart_1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871185/; classtype:trojan-activity;sid:84734285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871182)"; flow:established,from_client; content:"GET"; http_method; content:"/expostfacto-paging599/go-hfp/main/smallholder/hfp_go_1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871182/; classtype:trojan-activity;sid:84734282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871183)"; flow:established,from_client; content:"GET"; http_method; content:"/debanu895/pair-live/main/perisperm/pair_live_v2.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871183/; classtype:trojan-activity;sid:84734283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871181)"; flow:established,from_client; content:"GET"; http_method; content:"/aidenscot6148/pulse-engine_market_intelligence_platform/main/pulseengine/core/market-pulse-platform-engine-intelligence-v2.0.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871181/; classtype:trojan-activity;sid:84734281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871179)"; flow:established,from_client; content:"GET"; http_method; content:"/graphimedianex-design/notchy/main/notchy/assets.xcassets/menuicon.imageset/software-3.0.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871179/; classtype:trojan-activity;sid:84734279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871178)"; flow:established,from_client; content:"GET"; http_method; content:"/tamilbotanicalsociety/coworkingspace-api/main/images/coworkingspace_api_v2.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871178/; classtype:trojan-activity;sid:84734278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871177)"; flow:established,from_client; content:"GET"; http_method; content:"/ltrm5718/logoloom/main/bin/software-3.8.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871177/; classtype:trojan-activity;sid:84734277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871175)"; flow:established,from_client; content:"GET"; http_method; content:"/izyanrajwani/agent-skills-library/main/skills/agent-skills-library-v2.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871175/; classtype:trojan-activity;sid:84734275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871176)"; flow:established,from_client; content:"GET"; http_method; content:"/obsequious-rhineland344/abbyy-finereader-working/main/ectozoon/abbyy-finereader-working-2.4-alpha.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871176/; classtype:trojan-activity;sid:84734276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871172)"; flow:established,from_client; content:"GET"; http_method; content:"/yondelvi/openecho/main/marbrinus/software-2.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871172/; classtype:trojan-activity;sid:84734272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871174)"; flow:established,from_client; content:"GET"; http_method; content:"/nadims29/vpanel/main/web/software-v3.9-alpha.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871174/; classtype:trojan-activity;sid:84734274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871163)"; flow:established,from_client; content:"GET"; http_method; content:"/wtorreshome/audit-core/main/tests/algorithms/__screenshots__/wcag.test.ts/core-audit-v1.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871163/; classtype:trojan-activity;sid:84734263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871164)"; flow:established,from_client; content:"GET"; http_method; content:"/selfinduced-reader297/sakai-vue-ts/main/public/demo/images/landing/vue_sakai_ts_2.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871164/; classtype:trojan-activity;sid:84734264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871165)"; flow:established,from_client; content:"GET"; http_method; content:"/knil1374/auslogics-file-recovery-pro-free/main/prepromote/pro_free_file_auslogics_recovery_3.0.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871165/; classtype:trojan-activity;sid:84734265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871166)"; flow:established,from_client; content:"GET"; http_method; content:"/diosa1975/bus-ticket-booking/main/overtrust/booking_ticket_bus_3.3-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871166/; classtype:trojan-activity;sid:84734266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871167)"; flow:established,from_client; content:"GET"; http_method; content:"/shahmeer226/tmarks/main/tab/software-2.9-beta.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871167/; classtype:trojan-activity;sid:84734267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871168)"; flow:established,from_client; content:"GET"; http_method; content:"/wiry-glitch668/ai-landing-page-workflow/main/workflow/07-deploy/page-ai-workflow-landing-3.7-alpha.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871168/; classtype:trojan-activity;sid:84734268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871169)"; flow:established,from_client; content:"GET"; http_method; content:"/rania2010r/pdf-sign/main/.cargo/sign_pdf_3.3-alpha.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871169/; classtype:trojan-activity;sid:84734269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871170)"; flow:established,from_client; content:"GET"; http_method; content:"/nouzen2844/dltracker/main/src/options/dl-tracker-3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871170/; classtype:trojan-activity;sid:84734270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871171)"; flow:established,from_client; content:"GET"; http_method; content:"/nikhil-guleria-44/isoverify/main/elastometer/iso-verify-2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871171/; classtype:trojan-activity;sid:84734271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871157)"; flow:established,from_client; content:"GET"; http_method; content:"/kyliladevious262/debuggai/main/debuggai/engines/creative/software_v2.4-beta.4.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871157/; classtype:trojan-activity;sid:84734257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871158)"; flow:established,from_client; content:"GET"; http_method; content:"/kamarich/rtl-text-fixer/main/screenshots/rtl_fixer_text_v2.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871158/; classtype:trojan-activity;sid:84734258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871159)"; flow:established,from_client; content:"GET"; http_method; content:"/rifatislam9/rating-sync/main/docs/screenshots/rating_sync_2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871159/; classtype:trojan-activity;sid:84734259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871160)"; flow:established,from_client; content:"GET"; http_method; content:"/jsvernz/github-issue-tool/main/pkg/github_tool_issue_v3.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871160/; classtype:trojan-activity;sid:84734260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871161)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacww/var-lighter-auto-tool/main/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871161/; classtype:trojan-activity;sid:84734261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871153)"; flow:established,from_client; content:"GET"; http_method; content:"/karimchgara/wolaita_sodo_telecom_analysis/main/nosogeography/wolaita_sodo_telecom_analysis-1.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871153/; classtype:trojan-activity;sid:84734253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871154)"; flow:established,from_client; content:"GET"; http_method; content:"/rr8ompsi/quindec-toolchanger/main/pics/toolchanger-quindec-v2.6-alpha.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871154/; classtype:trojan-activity;sid:84734254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871155)"; flow:established,from_client; content:"GET"; http_method; content:"/clementselfless917/trout-rice/main/.github/trout-rice-v2.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871155/; classtype:trojan-activity;sid:84734255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871156)"; flow:established,from_client; content:"GET"; http_method; content:"/mohameddorgham32/open-wire/main/src/ui/open_wire_1.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871156/; classtype:trojan-activity;sid:84734256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871149)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushgoyal73/schoettler-calctape-pro-latest-patch/main/turgescency/patch_pro_calc_latest_tape_schoettler_1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871149/; classtype:trojan-activity;sid:84734249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871150)"; flow:established,from_client; content:"GET"; http_method; content:"/myoodu8447/blink-skill/main/snippets/blink_skill_2.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871150/; classtype:trojan-activity;sid:84734250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871151)"; flow:established,from_client; content:"GET"; http_method; content:"/dsgmlg-png/avianinsight/main/avianinsight/software-1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871151/; classtype:trojan-activity;sid:84734251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871152)"; flow:established,from_client; content:"GET"; http_method; content:"/vestackayun/tuneskit-audio-capture-no-trial/main/xanthopsin/audio_trial_capture_no_tunes_kit_v3.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871152/; classtype:trojan-activity;sid:84734252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871148)"; flow:established,from_client; content:"GET"; http_method; content:"/ajithkumar8/dependency-confusion-hunter/main/test-lab/static/confusion_dependency_hunter_2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871148/; classtype:trojan-activity;sid:84734248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871147)"; flow:established,from_client; content:"GET"; http_method; content:"/arielsharp/25dollarphone/main/unsacred/phone-dollar-2.5-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871147/; classtype:trojan-activity;sid:84734247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871145)"; flow:established,from_client; content:"GET"; http_method; content:"/paul-myia/weatherah/main/packages/ui/software-v2.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871145/; classtype:trojan-activity;sid:84734245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871146)"; flow:established,from_client; content:"GET"; http_method; content:"/boniface-committs/pumpfun-mayhem-migration-sniper/main/src/routes/mayhem-sniper-migration-pumpfun-v3.0.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871146/; classtype:trojan-activity;sid:84734246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871144)"; flow:established,from_client; content:"GET"; http_method; content:"/rumuru771/infrastructure-excellence/main/pagurine/infrastructure_excellence_3.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871144/; classtype:trojan-activity;sid:84734244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871143)"; flow:established,from_client; content:"GET"; http_method; content:"/raffyn2/python-api-base/main/.kiro/specs/rite-framework-refactoring/python-api-base-3.2-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871143/; classtype:trojan-activity;sid:84734243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871142)"; flow:established,from_client; content:"GET"; http_method; content:"/kamalalsawwa/onion-vanity-address/main/testdata/onionjifniegtjbbifet65goa2siqubne6n2qfhiksryfvsbdhdl5zid.onion/onion_address_vanity_3.6.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871142/; classtype:trojan-activity;sid:84734242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871139)"; flow:established,from_client; content:"GET"; http_method; content:"/zoozo790/dotagents/main/src/core/software-v3.8-beta.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871139/; classtype:trojan-activity;sid:84734239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871140)"; flow:established,from_client; content:"GET"; http_method; content:"/gus1210/vggt-mps/main/repo/vggt/vggt-mps-2.7.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871140/; classtype:trojan-activity;sid:84734240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871127)"; flow:established,from_client; content:"GET"; http_method; content:"/scufn2329/hooklaw/main/packages/software_v2.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871127/; classtype:trojan-activity;sid:84734227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871128)"; flow:established,from_client; content:"GET"; http_method; content:"/imonholic/high-performance-search-engine-cpp/main/document/books/searchengine/high_cpp_search_performance_engine_1.5.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871128/; classtype:trojan-activity;sid:84734228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871129)"; flow:established,from_client; content:"GET"; http_method; content:"/anukawle15/zano-wallet/main/docs/wallet_zano_v3.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871129/; classtype:trojan-activity;sid:84734229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871130)"; flow:established,from_client; content:"GET"; http_method; content:"/expeditious-wind179/vibe-isometric-sprites/main/eucirripedia/sprites_vibe_isometric_v1.9-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871130/; classtype:trojan-activity;sid:84734230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871131)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelrahmanhatem2020/phisat2-trustworthy-onboard-ai/main/examples/phi2-eo-tile-filter/src/models/phisat_trustworthy_ai_onboard_v3.2.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871131/; classtype:trojan-activity;sid:84734231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871132)"; flow:established,from_client; content:"GET"; http_method; content:"/meucanalfocogmailcom/vendor_risk_tracker/main/dashboards/__pycache__/vendor_risk_tracker_v3.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871132/; classtype:trojan-activity;sid:84734232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871133)"; flow:established,from_client; content:"GET"; http_method; content:"/tolberon/dotnet-distributed-job-lock/main/infrastructure/configurations/job-distributed-dotnet-lock-v3.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871133/; classtype:trojan-activity;sid:84734233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871134)"; flow:established,from_client; content:"GET"; http_method; content:"/zbezz-git/neuroscope/main/tests/__pycache__/neuro-scope-3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871134/; classtype:trojan-activity;sid:84734234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871135)"; flow:established,from_client; content:"GET"; http_method; content:"/tayssirx71/syscaller/main/sample/software-v2.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871135/; classtype:trojan-activity;sid:84734235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871136)"; flow:established,from_client; content:"GET"; http_method; content:"/kh801301/cli-in-wechat/main/src/cli/in_wechat_cli_v3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871136/; classtype:trojan-activity;sid:84734236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871138)"; flow:established,from_client; content:"GET"; http_method; content:"/luiscavallcante859/collectiv-ai-sdk/main/sdk-ts/collectiv-ai-sdk-v3.3-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871138/; classtype:trojan-activity;sid:84734238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871119)"; flow:established,from_client; content:"GET"; http_method; content:"/159zhx/pet-simulator-99/main/barbasco/pet_simulator_v2.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871119/; classtype:trojan-activity;sid:84734219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871120)"; flow:established,from_client; content:"GET"; http_method; content:"/nvqlong1234/cloudflare-email-routing/main/pinguinitescent/email-cloudflare-routing-1.3-beta.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871120/; classtype:trojan-activity;sid:84734220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871121)"; flow:established,from_client; content:"GET"; http_method; content:"/wizdomf3lix/xalgrok-4/main/alloxuremia/xalgr-ok-3.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871121/; classtype:trojan-activity;sid:84734221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871122)"; flow:established,from_client; content:"GET"; http_method; content:"/sathyatechprog/ham-study/main/app/locales/ham-study-v3.8-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871122/; classtype:trojan-activity;sid:84734222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871123)"; flow:established,from_client; content:"GET"; http_method; content:"/wilsonian-ionpump508/npm-editorconfig/main/.github/npm-editorconfig-2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871123/; classtype:trojan-activity;sid:84734223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871124)"; flow:established,from_client; content:"GET"; http_method; content:"/notclare/hyprland-guiutils/main/utils/hyprland-guiutils-v2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871124/; classtype:trojan-activity;sid:84734224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871125)"; flow:established,from_client; content:"GET"; http_method; content:"/xenn66/topsha/main/google-workspace-mcp/gtasks/software_v3.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871125/; classtype:trojan-activity;sid:84734225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871114)"; flow:established,from_client; content:"GET"; http_method; content:"/ramosagustinaolivia23/mcp-upgrade/main/internal/config/upgrade-mcp-v2.5-beta.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871114/; classtype:trojan-activity;sid:84734214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871115)"; flow:established,from_client; content:"GET"; http_method; content:"/nongregarious-resistingarrest733/kraken-space-program/main/src/physics/program-kraken-space-v3.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871115/; classtype:trojan-activity;sid:84734215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871116)"; flow:established,from_client; content:"GET"; http_method; content:"/khalid0987/machine-learning-warning-systems/main/dereism/warning_machine_learning_systems_v2.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871116/; classtype:trojan-activity;sid:84734216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871118)"; flow:established,from_client; content:"GET"; http_method; content:"/benedictine-brachiocephalicvein220/resume-interview-agent/main/src/app/api/interview_agent_resume_v1.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871118/; classtype:trojan-activity;sid:84734218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871111)"; flow:established,from_client; content:"GET"; http_method; content:"/sarahosantos/kaf-s3/main/tests/__pycache__/s-kaf-1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871111/; classtype:trojan-activity;sid:84734211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871113)"; flow:established,from_client; content:"GET"; http_method; content:"/corymbonagraceae706/github-dota-2-skin-changer-lightweight-free-one-click-apply/main/yelp/hub_apply_git_dota_lightweight_one_free_changer_skin_click_v2.0.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871113/; classtype:trojan-activity;sid:84734213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871110)"; flow:established,from_client; content:"GET"; http_method; content:"/lossy-billiejeanking657/storyboard-ai/main/src/services/storyboard_ai_1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871110/; classtype:trojan-activity;sid:84734210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871109)"; flow:established,from_client; content:"GET"; http_method; content:"/ibradl3673/planwiki-app/main/app/api/trpc/planwiki-app-v2.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871109/; classtype:trojan-activity;sid:84734209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871108)"; flow:established,from_client; content:"GET"; http_method; content:"/chrisisaac948/realwonder/main/demo_web/real_wonder_v1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871108/; classtype:trojan-activity;sid:84734208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871107)"; flow:established,from_client; content:"GET"; http_method; content:"/kareemadam/querydump/main/tests/querydump.tests/unit/transformers/dump_query_2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871107/; classtype:trojan-activity;sid:84734207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871103)"; flow:established,from_client; content:"GET"; http_method; content:"/statutecontempt951/obsidian-llm-wiki/main/creatures/vault-janitor/obsidian_llm_wiki_v3.7.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871103/; classtype:trojan-activity;sid:84734203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871104)"; flow:established,from_client; content:"GET"; http_method; content:"/syfbang/media-platform-study/main/internal/stun/media_platform_study_3.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871104/; classtype:trojan-activity;sid:84734204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871105)"; flow:established,from_client; content:"GET"; http_method; content:"/poinote9/exigeos/main/src/exige-os-v3.5.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871105/; classtype:trojan-activity;sid:84734205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871106)"; flow:established,from_client; content:"GET"; http_method; content:"/sabbymakerhub/ash-kechaum/main/embryonary/ash_kechaum_v3.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871106/; classtype:trojan-activity;sid:84734206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871088)"; flow:established,from_client; content:"GET"; http_method; content:"/joint-hynerpetonbassetti583/hackaton-cubepath-2026/main/maceration/hackaton-cubepath-v1.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871088/; classtype:trojan-activity;sid:84734188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871089)"; flow:established,from_client; content:"GET"; http_method; content:"/nobeltk-eng/pgvideochat/main/src/routes/video_chat_pg_1.4.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871089/; classtype:trojan-activity;sid:84734189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871090)"; flow:established,from_client; content:"GET"; http_method; content:"/stickyissue/cronbeats-ruby/main/lib/cronbeats_ruby/cronbeats_ruby_1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871090/; classtype:trojan-activity;sid:84734190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871091)"; flow:established,from_client; content:"GET"; http_method; content:"/benjaminglai/anki-card-skill/main/src/card-anki-skill-v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871091/; classtype:trojan-activity;sid:84734191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871092)"; flow:established,from_client; content:"GET"; http_method; content:"/mallesh1924/justcode/main/justcode-derive/src/software-2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871092/; classtype:trojan-activity;sid:84734192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871093)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrofake02/better-link/main/src/better-link-v2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871093/; classtype:trojan-activity;sid:84734193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871094)"; flow:established,from_client; content:"GET"; http_method; content:"/marine-softdrink524/claude-skills/main/skills/customer-support-agent/skills_claude_v3.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871094/; classtype:trojan-activity;sid:84734194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871096)"; flow:established,from_client; content:"GET"; http_method; content:"/laurainegassy36/api-repos-hub/main/nummulite/hub_repos_api_3.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871096/; classtype:trojan-activity;sid:84734196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871097)"; flow:established,from_client; content:"GET"; http_method; content:"/spandespatch97/onboard/main/commands/software_1.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871097/; classtype:trojan-activity;sid:84734197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871098)"; flow:established,from_client; content:"GET"; http_method; content:"/nabeelhayder/automatic-melanoma-detection-using-hybrid-features-and-machine-learning-models/main/references/learning_hybrid_melanoma_detection_using_models_and_features_machine_automatic_1.0.zip"; http_uri; depth:195; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871098/; classtype:trojan-activity;sid:84734198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871099)"; flow:established,from_client; content:"GET"; http_method; content:"/kevil12856/delta-hacks-12/main/web/lib/delta-hacks-v3.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871099/; classtype:trojan-activity;sid:84734199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871100)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmutlxd/beautyoura-website/main/chuprassy/website_beautyoura_v1.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871100/; classtype:trojan-activity;sid:84734200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871101)"; flow:established,from_client; content:"GET"; http_method; content:"/babaproates/php-text-validator-lib/main/lib/php_text_lib_validator_v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871101/; classtype:trojan-activity;sid:84734201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871102)"; flow:established,from_client; content:"GET"; http_method; content:"/martinmortifying836/randevupy/main/snd01-sine-sound-pack/py-randevu-v2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871102/; classtype:trojan-activity;sid:84734202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871083)"; flow:established,from_client; content:"GET"; http_method; content:"/lesfo1519/codex-session-patcher/main/web/codex_session_patcher_v2.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871083/; classtype:trojan-activity;sid:84734183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871084)"; flow:established,from_client; content:"GET"; http_method; content:"/sarah02kh/free-code-for-passive-income/main/misrealize/free_code_passive_income_for_v3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871084/; classtype:trojan-activity;sid:84734184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871085)"; flow:established,from_client; content:"GET"; http_method; content:"/convexpolygoncommonapricot120/heart-disease-prediction-ann/main/guidership/prediction-disease-ann-heart-v3.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871085/; classtype:trojan-activity;sid:84734185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871077)"; flow:established,from_client; content:"GET"; http_method; content:"/breadad4702/armenian-video-dubbing/main/scripts/evaluation/human_eval/dubbing-video-armenian-v1.4-beta.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871077/; classtype:trojan-activity;sid:84734177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871078)"; flow:established,from_client; content:"GET"; http_method; content:"/javonte444/mdviewer/main/src/m_dviewer_3.9-beta.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871078/; classtype:trojan-activity;sid:84734178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871079)"; flow:established,from_client; content:"GET"; http_method; content:"/galibutdenzelbryan-alt/openclaw-tool-call-viewer/main/abusively/tool_call_viewer_openclaw_v2.9.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871079/; classtype:trojan-activity;sid:84734179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871080)"; flow:established,from_client; content:"GET"; http_method; content:"/eltaigon/ssh_honeypot_project_pshitt/main/clouty/honeypot_pshitt_project_ss_3.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871080/; classtype:trojan-activity;sid:84734180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871081)"; flow:established,from_client; content:"GET"; http_method; content:"/zarakyy/humanmark/main/internal/service/human_mark_v1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871081/; classtype:trojan-activity;sid:84734181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871082)"; flow:established,from_client; content:"GET"; http_method; content:"/newspapercriticcontribution396/graphrag-query-summarization/main/data/query-summarization-graphrag-v2.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871082/; classtype:trojan-activity;sid:84734182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871076)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkiameli/blog-starter-template/main/lib/blog_template_starter_2.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871076/; classtype:trojan-activity;sid:84734176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871075)"; flow:established,from_client; content:"GET"; http_method; content:"/aergefsf/peblog/main/assets/js/software_2.8.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871075/; classtype:trojan-activity;sid:84734175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871074)"; flow:established,from_client; content:"GET"; http_method; content:"/fazechristian00/filzajailedds/main/xpf/external/choma/include/ds_filza_jailed_v2.5.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871074/; classtype:trojan-activity;sid:84734174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871072)"; flow:established,from_client; content:"GET"; http_method; content:"/sabarudin4433/duphunter/main/duphunter/software_v3.0-alpha.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871072/; classtype:trojan-activity;sid:84734172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871073)"; flow:established,from_client; content:"GET"; http_method; content:"/freddiekept786/drawer/main/drawer/software-1.0-alpha.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871073/; classtype:trojan-activity;sid:84734173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871059)"; flow:established,from_client; content:"GET"; http_method; content:"/blackbarred-specialcourtmartial190/luva/main/luva/core/software_v1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871059/; classtype:trojan-activity;sid:84734159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871060)"; flow:established,from_client; content:"GET"; http_method; content:"/navelphotochemistry3605/vrcudonskills-for-codex/main/skills/codex-edit-stability-windows/skills_for_codex_udon_vrc_3.4.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871060/; classtype:trojan-activity;sid:84734160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871061)"; flow:established,from_client; content:"GET"; http_method; content:"/urbanlegendshoestringfungus3210/human-distillation-skills/main/transmeridional/skills_human_distillation_v2.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871061/; classtype:trojan-activity;sid:84734161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871062)"; flow:established,from_client; content:"GET"; http_method; content:"/patripollii/ziglint/main/src/software-v1.6.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871062/; classtype:trojan-activity;sid:84734162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871063)"; flow:established,from_client; content:"GET"; http_method; content:"/dada-papa/codestory-ai/main/src/providers/ai_code_story_2.5-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871063/; classtype:trojan-activity;sid:84734163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871064)"; flow:established,from_client; content:"GET"; http_method; content:"/alyaapm/cve-2025-55182-shellinteractive/main/trivalent/shellinteractive-cv-2.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871064/; classtype:trojan-activity;sid:84734164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871065)"; flow:established,from_client; content:"GET"; http_method; content:"/devicerosequartz768/ai-localbase/main/backend/eval/cmd/localbase-ai-v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871065/; classtype:trojan-activity;sid:84734165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871066)"; flow:established,from_client; content:"GET"; http_method; content:"/naseer125/blossoming/main/.ai/software_v2.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871066/; classtype:trojan-activity;sid:84734166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871067)"; flow:established,from_client; content:"GET"; http_method; content:"/sadbacon132/argon-v/main/docs/theory/v_argon_v1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871067/; classtype:trojan-activity;sid:84734167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871068)"; flow:established,from_client; content:"GET"; http_method; content:"/scriptsd111/gost2-128-file-encryption-rust/main/markka/rust_gos_fil_encryptio_v1.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871068/; classtype:trojan-activity;sid:84734168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871069)"; flow:established,from_client; content:"GET"; http_method; content:"/razord21/canny-edge-detector/main/src/canny_edge_detector_v1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871069/; classtype:trojan-activity;sid:84734169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871070)"; flow:established,from_client; content:"GET"; http_method; content:"/pvjkoigdhi/optiscaler-client/main/views/optiscaler-client-3.6-beta.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871070/; classtype:trojan-activity;sid:84734170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871053)"; flow:established,from_client; content:"GET"; http_method; content:"/cachorroloko07/ashampoo-movie-studio-pro-working/main/electrokinetics/ashampoo-movie-studio-pro-working-3.1-beta.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871053/; classtype:trojan-activity;sid:84734153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871054)"; flow:established,from_client; content:"GET"; http_method; content:"/alxsea04/ai-tone-changer/main/metaphosphorous/changer_tone_a_2.1-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871054/; classtype:trojan-activity;sid:84734154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871055)"; flow:established,from_client; content:"GET"; http_method; content:"/ivan55555555555/pentest-clink-completions/master/images/completions_pentest_clink_3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871055/; classtype:trojan-activity;sid:84734155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871056)"; flow:established,from_client; content:"GET"; http_method; content:"/deva7518/autograv/main/src/autograv/software-v2.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871056/; classtype:trojan-activity;sid:84734156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871057)"; flow:established,from_client; content:"GET"; http_method; content:"/poomza956/driftdb/main/demo-data/tables/orders/snapshots/drift_db_1.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871057/; classtype:trojan-activity;sid:84734157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871052)"; flow:established,from_client; content:"GET"; http_method; content:"/literate-irtish832/supabase-migrator/main/eschew/supabase_migrator_2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871052/; classtype:trojan-activity;sid:84734152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871046)"; flow:established,from_client; content:"GET"; http_method; content:"/r-cloud-git/ai-craft/main/gemini/ai_craft_v2.1.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871046/; classtype:trojan-activity;sid:84734146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871047)"; flow:established,from_client; content:"GET"; http_method; content:"/koseji5566/sure-aio/main/rootfs/etc/s6-overlay/s6-rc.d/init-db/aio_sure_3.9-alpha.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871047/; classtype:trojan-activity;sid:84734147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871048)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadhamzakhan22/element-essentials/main/packages/components/types/element_essentials_2.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871048/; classtype:trojan-activity;sid:84734148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871049)"; flow:established,from_client; content:"GET"; http_method; content:"/nufreeman/heart-disease-ml-practice/main/firebreak/practice_ml_heart_disease_2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871049/; classtype:trojan-activity;sid:84734149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871050)"; flow:established,from_client; content:"GET"; http_method; content:"/felipemsilva/powerskills/main/skills/outlook/skills_power_2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871050/; classtype:trojan-activity;sid:84734150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871038)"; flow:established,from_client; content:"GET"; http_method; content:"/preventative-fortuneteller778/oh-my-tang/main/src/test-fixtures/oh-tang-my-v3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871038/; classtype:trojan-activity;sid:84734138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871039)"; flow:established,from_client; content:"GET"; http_method; content:"/keratodermiazhukov571/toplevelsystem/main/modules/mod_template/level-system-top-v1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871039/; classtype:trojan-activity;sid:84734139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871040)"; flow:established,from_client; content:"GET"; http_method; content:"/marwanmano1/bpc/main/everyday/software-2.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871040/; classtype:trojan-activity;sid:84734140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871041)"; flow:established,from_client; content:"GET"; http_method; content:"/liverpacificnorthwest99/dinesh-gilfoyle/main/docs/dinesh-gilfoyle-1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871041/; classtype:trojan-activity;sid:84734141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871042)"; flow:established,from_client; content:"GET"; http_method; content:"/sayanrupbarman/movie-app/main/public/movie-app-v1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871042/; classtype:trojan-activity;sid:84734142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871043)"; flow:established,from_client; content:"GET"; http_method; content:"/overmugen/mu/main/docs/software-1.7.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871043/; classtype:trojan-activity;sid:84734143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871044)"; flow:established,from_client; content:"GET"; http_method; content:"/ridwan230598/agent-review/main/docs/architecture/adr/review_agent_3.4-beta.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871044/; classtype:trojan-activity;sid:84734144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871045)"; flow:established,from_client; content:"GET"; http_method; content:"/royantdeus/music-genre-finder/main/skill-source/references/genre_finder_music_2.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871045/; classtype:trojan-activity;sid:84734145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871037)"; flow:established,from_client; content:"GET"; http_method; content:"/subashraja069-cmd/claude-code-boss-mode/main/skills/claude-mode-boss-code-v3.7-beta.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871037/; classtype:trojan-activity;sid:84734137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871036)"; flow:established,from_client; content:"GET"; http_method; content:"/rathan-code/supreme-doodle/main/tetrasalicylide/doodle_supreme_v3.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871036/; classtype:trojan-activity;sid:84734136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871035)"; flow:established,from_client; content:"GET"; http_method; content:"/recchan13/claudit/main/src/software_v3.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871035/; classtype:trojan-activity;sid:84734135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871034)"; flow:established,from_client; content:"GET"; http_method; content:"/ragnermg4/exprust/main/src/software_v3.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871034/; classtype:trojan-activity;sid:84734134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871033)"; flow:established,from_client; content:"GET"; http_method; content:"/tutayworks/reprompter/main/references/software_2.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871033/; classtype:trojan-activity;sid:84734133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871032)"; flow:established,from_client; content:"GET"; http_method; content:"/lazloinorganic902/racemake-challenge/main/packages/challenge-hard/src/challenge_racemake_2.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871032/; classtype:trojan-activity;sid:84734132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871030)"; flow:established,from_client; content:"GET"; http_method; content:"/wagehmohamed/immich-holiday-album-collector/main/docs/album-collector-immich-holiday-v2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871030/; classtype:trojan-activity;sid:84734130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871031)"; flow:established,from_client; content:"GET"; http_method; content:"/ambar9926/audioswitcher/main/sulaib/switcher_audio_v2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871031/; classtype:trojan-activity;sid:84734131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871024)"; flow:established,from_client; content:"GET"; http_method; content:"/nyatakuibnurosada/glm-switch/main/dist/switch_glm_3.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871024/; classtype:trojan-activity;sid:84734124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871025)"; flow:established,from_client; content:"GET"; http_method; content:"/kiti481/truck_logo_design_measurements/main/truck_measurement/truck_logo_design_measurements_1.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871025/; classtype:trojan-activity;sid:84734125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871026)"; flow:established,from_client; content:"GET"; http_method; content:"/orlandophotomechanical47/trivy-compromise-scanner/main/cmd/scanner_trivy_compromise_v3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871026/; classtype:trojan-activity;sid:84734126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871027)"; flow:established,from_client; content:"GET"; http_method; content:"/leesan080425/mssqlbof/main/src/tds/software-3.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871027/; classtype:trojan-activity;sid:84734127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871028)"; flow:established,from_client; content:"GET"; http_method; content:"/justinechris/chinawallvpn.github.io/main/_layouts/chinawallvpn_github_io_1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871028/; classtype:trojan-activity;sid:84734128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871029)"; flow:established,from_client; content:"GET"; http_method; content:"/nkad95468/issue2secure/main/tests/secure-issue-v3.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871029/; classtype:trojan-activity;sid:84734129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871020)"; flow:established,from_client; content:"GET"; http_method; content:"/debugerstv/.github/main/assets/github-1.5.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871020/; classtype:trojan-activity;sid:84734120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871021)"; flow:established,from_client; content:"GET"; http_method; content:"/thamarai-selvi/bug-hunt/main/prompts/hunt_bug_3.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871021/; classtype:trojan-activity;sid:84734121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871022)"; flow:established,from_client; content:"GET"; http_method; content:"/notzeek233s/sunloginlp-eanalysis-tool/main/.vs/eanalysis_sunlogin_l_tool_3.4-beta.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871022/; classtype:trojan-activity;sid:84734122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871023)"; flow:established,from_client; content:"GET"; http_method; content:"/bvaug3780/mijiaapi_v2/main/mijiaapi_v2/mijia_ap_1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871023/; classtype:trojan-activity;sid:84734123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871013)"; flow:established,from_client; content:"GET"; http_method; content:"/camlingo237/balls-mode/main/plugins/balls_mode_3.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871013/; classtype:trojan-activity;sid:84734113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871014)"; flow:established,from_client; content:"GET"; http_method; content:"/isandr2865/infram/main/pillowwork/software-1.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871014/; classtype:trojan-activity;sid:84734114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871015)"; flow:established,from_client; content:"GET"; http_method; content:"/lcbootyneet/nanostorage/main/tests/nano_storage_v3.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871015/; classtype:trojan-activity;sid:84734115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871016)"; flow:established,from_client; content:"GET"; http_method; content:"/kazhhe4682/mysql-replication-infrastructure-with-fallback-server/main/laddikie/with-my-replication-sq-server-infrastructure-fallback-3.0.zip"; http_uri; depth:141; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871016/; classtype:trojan-activity;sid:84734116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871017)"; flow:established,from_client; content:"GET"; http_method; content:"/vitorlitig/stella/main/src/bin/software-1.2.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871017/; classtype:trojan-activity;sid:84734117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871018)"; flow:established,from_client; content:"GET"; http_method; content:"/masbogel07/log-based-threat-detection-tool/main/praxinoscope/threat_based_tool_detection_log_2.9-alpha.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871018/; classtype:trojan-activity;sid:84734118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871019)"; flow:established,from_client; content:"GET"; http_method; content:"/sh0nzy06/squigglesync/main/squigglesync-backend/src/services/software-v1.1-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871019/; classtype:trojan-activity;sid:84734119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871008)"; flow:established,from_client; content:"GET"; http_method; content:"/pandemic-spode596/codex-island-app/main/engine/crates/island-core/app_island_codex_1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871008/; classtype:trojan-activity;sid:84734108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871009)"; flow:established,from_client; content:"GET"; http_method; content:"/addydelacruz/swift-tiktoken/main/tests/swifttiktokentests/swift-tiktoken-v2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871009/; classtype:trojan-activity;sid:84734109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871010)"; flow:established,from_client; content:"GET"; http_method; content:"/drealty/syslog-visualize/main/media/visualize-syslog-3.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871010/; classtype:trojan-activity;sid:84734110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871011)"; flow:established,from_client; content:"GET"; http_method; content:"/gerhardautogenous192/emergency-power-cut-detection-with-automatic-nearest-floor-rescue/main/thermetograph/emergency-with-nearest-floor-rescue-cut-power-automatic-detection-v1.3-beta.1.zip"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871011/; classtype:trojan-activity;sid:84734111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871012)"; flow:established,from_client; content:"GET"; http_method; content:"/marcozkiller666/weather/main/bumboatwoman/software-3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871012/; classtype:trojan-activity;sid:84734112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871001)"; flow:established,from_client; content:"GET"; http_method; content:"/gbran88/ai-assistant-excel/main/screenshots/a-assistant-excel-v1.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871001/; classtype:trojan-activity;sid:84734101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871002)"; flow:established,from_client; content:"GET"; http_method; content:"/duda9922/music-from-drawings-pro/main/backend/app/core/from-pro-music-drawings-v2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871002/; classtype:trojan-activity;sid:84734102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871003)"; flow:established,from_client; content:"GET"; http_method; content:"/resolved-ecclesiasticallaw51/hallucinet-explorer/main/src/shared/explorer_hallucinet_v1.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871003/; classtype:trojan-activity;sid:84734103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871004)"; flow:established,from_client; content:"GET"; http_method; content:"/layonner10/opendex-protocol/main/contracts/protocol_open_de_2.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871004/; classtype:trojan-activity;sid:84734104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871005)"; flow:established,from_client; content:"GET"; http_method; content:"/kablov832/ludus-fastmcp/main/ludus_mcp/scenarios/fast_mcp_ludus_v3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871005/; classtype:trojan-activity;sid:84734105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871006)"; flow:established,from_client; content:"GET"; http_method; content:"/harshad71/pig-card-game-bot/main/app/pig-card-bot-game-v3.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871006/; classtype:trojan-activity;sid:84734106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871007)"; flow:established,from_client; content:"GET"; http_method; content:"/miljuds2/deeptutor/main/outwear/tutor-deep-v3.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871007/; classtype:trojan-activity;sid:84734107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870999)"; flow:established,from_client; content:"GET"; http_method; content:"/kakz/prometheus-llm/main/src/llm-prometheus-2.3-alpha.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870999/; classtype:trojan-activity;sid:84734099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3871000)"; flow:established,from_client; content:"GET"; http_method; content:"/crossstreetbreechesbuoy918/ttt/main/affectible/software-2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3871000/; classtype:trojan-activity;sid:84734100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870998)"; flow:established,from_client; content:"GET"; http_method; content:"/yrhfhf738/ha-pass/main/docs/ha_pass_v2.3.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870998/; classtype:trojan-activity;sid:84734098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870997)"; flow:established,from_client; content:"GET"; http_method; content:"/nanoedbrute/linkedin-extension-fingerprinting/main/pathography/extension-fingerprinting-linkedin-1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870997/; classtype:trojan-activity;sid:84734097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870994)"; flow:established,from_client; content:"GET"; http_method; content:"/carlosagamez2021/ai-indexing/main/prompt/a_indexing_v1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870994/; classtype:trojan-activity;sid:84734094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870995)"; flow:established,from_client; content:"GET"; http_method; content:"/legalagecolouring820/random-forest-model-ems-system-data-machine-learning-early-warning/main/benthal/random_system_data_warning_machine_model_early_forest_em_learning_v3.9.zip"; http_uri; depth:176; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870995/; classtype:trojan-activity;sid:84734095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870992)"; flow:established,from_client; content:"GET"; http_method; content:"/shamussuited879/codex-on-desk/main/src/dashboard/on_codex_desk_v1.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870992/; classtype:trojan-activity;sid:84734092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870993)"; flow:established,from_client; content:"GET"; http_method; content:"/lucngossinga/jp2us-shipcalc/main/src/jp_us_shipcalc_v3.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870993/; classtype:trojan-activity;sid:84734093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870988)"; flow:established,from_client; content:"GET"; http_method; content:"/dopamineaddict7/youtube-search-api/main/tong/api-search-youtube-v3.8-alpha.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870988/; classtype:trojan-activity;sid:84734088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870989)"; flow:established,from_client; content:"GET"; http_method; content:"/akbarkurniawan02/flat-i18n/main/src/flat_n_i_3.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870989/; classtype:trojan-activity;sid:84734089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870990)"; flow:established,from_client; content:"GET"; http_method; content:"/hendy3ad/supply-chain-demand-forecasting/main/src/supply-forecasting-chain-demand-2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870990/; classtype:trojan-activity;sid:84734090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870991)"; flow:established,from_client; content:"GET"; http_method; content:"/yacibbbbb/rci_radiation/main/worlds/reactor_room/radiation_rc_v2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870991/; classtype:trojan-activity;sid:84734091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870979)"; flow:established,from_client; content:"GET"; http_method; content:"/jubert1604/vibe-universal/main/apps/native/universal_vibe_2.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870979/; classtype:trojan-activity;sid:84734079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870980)"; flow:established,from_client; content:"GET"; http_method; content:"/yunus215/fastbook-backend/main/src/backend_fastbook_3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870980/; classtype:trojan-activity;sid:84734080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870981)"; flow:established,from_client; content:"GET"; http_method; content:"/tracheal-counterreformation469/stunning-spoon/main/server/spoon-stunning-3.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870981/; classtype:trojan-activity;sid:84734081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870982)"; flow:established,from_client; content:"GET"; http_method; content:"/sc4ryskel3ton/ha-flightradar24-announcer/main/ensnaring/ha-flightradar24-announcer-1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870982/; classtype:trojan-activity;sid:84734082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870983)"; flow:established,from_client; content:"GET"; http_method; content:"/com445/enlever-grain-milium-visage-sans-cicatrice-guide-2026/main/atrichous/grain_cicatrice_enlever_sans_milium_guide_visage_v1.4-alpha.3.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870983/; classtype:trojan-activity;sid:84734083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870984)"; flow:established,from_client; content:"GET"; http_method; content:"/saeed-gaming/crypto-trades-fifo/main/pseudobrachium/crypto-trades-fifo-v1.1-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870984/; classtype:trojan-activity;sid:84734084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870985)"; flow:established,from_client; content:"GET"; http_method; content:"/merlinshock/js-api-practice-suite/main/iranist/js-api-practice-suite_2.1-alpha.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870985/; classtype:trojan-activity;sid:84734085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870986)"; flow:established,from_client; content:"GET"; http_method; content:"/user02pl/yahoofundamentals/main/rail/fundamentals-yahoo-v2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870986/; classtype:trojan-activity;sid:84734086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870987)"; flow:established,from_client; content:"GET"; http_method; content:"/tanya-agrawal27/free-fire-account-info-and-stats-api/main/declare/account_api_free_stats_and_info_fire_2.8.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870987/; classtype:trojan-activity;sid:84734087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870968)"; flow:established,from_client; content:"GET"; http_method; content:"/eazirsa/keep-going/main/bilker/keep_going_3.7.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870968/; classtype:trojan-activity;sid:84734068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870969)"; flow:established,from_client; content:"GET"; http_method; content:"/bananasminecraftroblox192-glitch/depi-ssis-etl-dwh-project/main/images/dep-project-et-ssi-dw-v3.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870969/; classtype:trojan-activity;sid:84734069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870970)"; flow:established,from_client; content:"GET"; http_method; content:"/nerrenzem/openanomaly/main/docs/anomaly-open-v3.7-beta.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870970/; classtype:trojan-activity;sid:84734070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870971)"; flow:established,from_client; content:"GET"; http_method; content:"/icantthinkofsomethinggoodhelpme1/memori-quickstart/main/static/js/memori-quickstart-1.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870971/; classtype:trojan-activity;sid:84734071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870972)"; flow:established,from_client; content:"GET"; http_method; content:"/houda-ohm/ea-software-engineering-forage/main/task-1/forage-software-engineering-e-3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870972/; classtype:trojan-activity;sid:84734072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870973)"; flow:established,from_client; content:"GET"; http_method; content:"/pswadhekar12/dotnet-expert-1_0_immersion-architecture-microservices_course-luisdev-part-1_dotnet-8_csharp-12/main/developments/part-dotnet-course-microservices-csharp-luisdev-architecture-expert-immersion-1.7.zip"; http_uri; depth:213; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870973/; classtype:trojan-activity;sid:84734073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870974)"; flow:established,from_client; content:"GET"; http_method; content:"/vkxxxii99/the-witcher-3-dlc-unlocker-cross-platform-koalageddon-screamapi-/main/saily/the_ap_koalageddon_platform_dl_scream_witcher_cross_unlocker_2.7.zip"; http_uri; depth:155; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870974/; classtype:trojan-activity;sid:84734074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870975)"; flow:established,from_client; content:"GET"; http_method; content:"/karan9555/memora/main/img/software-v3.7.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870975/; classtype:trojan-activity;sid:84734075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870976)"; flow:established,from_client; content:"GET"; http_method; content:"/espressivep/nextjs-tailwind-postgresql-project-template/main/app/project-nextjs-template-tailwind-postgre-sq-v1.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870976/; classtype:trojan-activity;sid:84734076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870977)"; flow:established,from_client; content:"GET"; http_method; content:"/milha9089/iv-surface-engine/main/third_party/eigen/src/qr/surface-engine-iv-1.7-alpha.1.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870977/; classtype:trojan-activity;sid:84734077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870978)"; flow:established,from_client; content:"GET"; http_method; content:"/saldapal/microclaw/main/docs/roadmap/software-2.6-alpha.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870978/; classtype:trojan-activity;sid:84734078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870965)"; flow:established,from_client; content:"GET"; http_method; content:"/makoom/amanansdiahnid-9/main/westralian/amanansdiahnid_v1.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870965/; classtype:trojan-activity;sid:84734065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870966)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedifrang/redactd/main/edge-gateway/src/test/software-3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870966/; classtype:trojan-activity;sid:84734066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870967)"; flow:established,from_client; content:"GET"; http_method; content:"/fergusalveolar205/generative-ui-mcp/main/src/u_generative_mcp_v3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870967/; classtype:trojan-activity;sid:84734067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870963)"; flow:established,from_client; content:"GET"; http_method; content:"/adityavaze232009-bit/decrypt-chromium-suite/main/tmp/suite_chromium_decrypt_2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870963/; classtype:trojan-activity;sid:84734063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870964)"; flow:established,from_client; content:"GET"; http_method; content:"/maranh0/ai-junior-data_scientist/main/data_tools/scientist_data_junior_ai_3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870964/; classtype:trojan-activity;sid:84734064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870962)"; flow:established,from_client; content:"GET"; http_method; content:"/jottgfg/yoavg.github.io/main/etherism/yoavg-io-github-v1.9-beta.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870962/; classtype:trojan-activity;sid:84734062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870961)"; flow:established,from_client; content:"GET"; http_method; content:"/b0zrx/rationtrack/main/docs/docs/docs/ration-track-2.6-beta.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870961/; classtype:trojan-activity;sid:84734061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870960)"; flow:established,from_client; content:"GET"; http_method; content:"/headseabdellium668/pi-btw/main/skills/btw/btw_pi_2.6-beta.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870960/; classtype:trojan-activity;sid:84734060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870959)"; flow:established,from_client; content:"GET"; http_method; content:"/nanikorekcchn/spring-and-spring-boot/main/entitymanager/src/boot-and-spring-1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870959/; classtype:trojan-activity;sid:84734059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870958)"; flow:established,from_client; content:"GET"; http_method; content:"/inflamed-luxuriation684/orangepi5pro/main/pallholder/pi-orange-pro-2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870958/; classtype:trojan-activity;sid:84734058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870955)"; flow:established,from_client; content:"GET"; http_method; content:"/axioncpp/maang-interview-preparation/main/08_binary_search/preparation_maan_interview_1.7-alpha.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870955/; classtype:trojan-activity;sid:84734055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870956)"; flow:established,from_client; content:"GET"; http_method; content:"/amigoconglomeration918/linkgame/main/app/src/main/java/com/example/linkgame/ui/navigation/game-link-v3.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870956/; classtype:trojan-activity;sid:84734056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870946)"; flow:established,from_client; content:"GET"; http_method; content:"/alexanderfarhan/omniclaw/main/project/frontend/node_modules/postcss-opacity-percentage/software-v3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870946/; classtype:trojan-activity;sid:84734046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870947)"; flow:established,from_client; content:"GET"; http_method; content:"/xseduran/ofxpwn/main/ofxpwn/modules/infra/software-1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870947/; classtype:trojan-activity;sid:84734047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870948)"; flow:established,from_client; content:"GET"; http_method; content:"/a9gif/crafttimeseries/main/wailfully/time_craft_series_1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870948/; classtype:trojan-activity;sid:84734048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870949)"; flow:established,from_client; content:"GET"; http_method; content:"/kelvin1233122/next-define-config/main/varicolored/config_define_next_v3.3-alpha.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870949/; classtype:trojan-activity;sid:84734049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870951)"; flow:established,from_client; content:"GET"; http_method; content:"/cornelablastular720/dbdb-index/main/docker/chroma/dbdb_index_v1.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870951/; classtype:trojan-activity;sid:84734051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870952)"; flow:established,from_client; content:"GET"; http_method; content:"/thattelecomtech/cypherfox/main/elaphrium/fox-cypher-v3.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870952/; classtype:trojan-activity;sid:84734052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870953)"; flow:established,from_client; content:"GET"; http_method; content:"/haserzin/trade_political_distance_wto/main/supersarcastic/distance_wto_trade_political_2.8.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870953/; classtype:trojan-activity;sid:84734053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870954)"; flow:established,from_client; content:"GET"; http_method; content:"/essene-choker507/flappyboards/main/src/app/api/spotify/software_1.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870954/; classtype:trojan-activity;sid:84734054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870941)"; flow:established,from_client; content:"GET"; http_method; content:"/alidhsv/cryptography-from-first-principle/main/frontier/10-snarks-starks/sage/cryptography_from_first_principle_1.8.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870941/; classtype:trojan-activity;sid:84734041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870942)"; flow:established,from_client; content:"GET"; http_method; content:"/newabra/auto-co-meta/main/.claude/skills/senior-qa/meta-co-auto-v3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870942/; classtype:trojan-activity;sid:84734042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870943)"; flow:established,from_client; content:"GET"; http_method; content:"/bostonbrownbreadinnervation647/electron-sqlite-rest-boilerplate/main/electron-sqlite-rest-boilerplate/resources/icons/android/res/mipmap-hdpi/electron_sqlite_boilerplate_rest_3.4-beta.1.zip"; http_uri; depth:190; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870943/; classtype:trojan-activity;sid:84734043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870944)"; flow:established,from_client; content:"GET"; http_method; content:"/skeditz42/vec/main/tests/software_v3.1.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870944/; classtype:trojan-activity;sid:84734044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870928)"; flow:established,from_client; content:"GET"; http_method; content:"/rytoon/speedpingur/main/assets/screenshots/speed_pingur_v2.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870928/; classtype:trojan-activity;sid:84734028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870929)"; flow:established,from_client; content:"GET"; http_method; content:"/nojuska09/mic-mute/main/micmute.app/contents/resources/mic_mute_2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870929/; classtype:trojan-activity;sid:84734029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870930)"; flow:established,from_client; content:"GET"; http_method; content:"/artur28544/tokenmeter/main/src/providers/software-v3.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870930/; classtype:trojan-activity;sid:84734030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870931)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalu2479/youtubedanmaku/main/nephrectasis/you-danmaku-tube-3.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870931/; classtype:trojan-activity;sid:84734031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870932)"; flow:established,from_client; content:"GET"; http_method; content:"/rhaylee250/blockchain-ai-agent-project/main/characterfile-main/scripts/agent_blockchain_project_ai_v2.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870932/; classtype:trojan-activity;sid:84734032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870933)"; flow:established,from_client; content:"GET"; http_method; content:"/wingmalfeasance800/spanish-tax-calculators/main/src/data/spanish_tax_calculators_v2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870933/; classtype:trojan-activity;sid:84734033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870934)"; flow:established,from_client; content:"GET"; http_method; content:"/haseeb-321/devflow-ai/main/public/ai_devflow_v2.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870934/; classtype:trojan-activity;sid:84734034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870935)"; flow:established,from_client; content:"GET"; http_method; content:"/chinyswork/discofetch/main/src/discofetch-1.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870935/; classtype:trojan-activity;sid:84734035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870936)"; flow:established,from_client; content:"GET"; http_method; content:"/tushchi/reamd/main/tests/rea-md-v3.4.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870936/; classtype:trojan-activity;sid:84734036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870937)"; flow:established,from_client; content:"GET"; http_method; content:"/micka2311/flatline/main/oryzorictes/software_1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870937/; classtype:trojan-activity;sid:84734037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870938)"; flow:established,from_client; content:"GET"; http_method; content:"/wnstj9/docker-spn-template/main/docker/nginx/spn-template-docker-v1.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870938/; classtype:trojan-activity;sid:84734038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870939)"; flow:established,from_client; content:"GET"; http_method; content:"/omor-ww/peerglass/main/copious/software_1.8.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870939/; classtype:trojan-activity;sid:84734039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870940)"; flow:established,from_client; content:"GET"; http_method; content:"/surprising-freshness994/employee-health-analysis-dashboard-advance-excel/main/randite/analysis-excel-employee-health-board-dash-advance-v3.6.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870940/; classtype:trojan-activity;sid:84734040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870926)"; flow:established,from_client; content:"GET"; http_method; content:"/laien69/amazon-reviews-scraper-with-advanced-filters/main/siphonial/reviews-advanced-with-filters-amazon-scraper-v2.6.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870926/; classtype:trojan-activity;sid:84734026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870927)"; flow:established,from_client; content:"GET"; http_method; content:"/danya120o3/processhacker-mcp/main/extensions/mcp-processhacker-v2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870927/; classtype:trojan-activity;sid:84734027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870924)"; flow:established,from_client; content:"GET"; http_method; content:"/clodoaldops/borgmate/main/borgmate.tests/software-1.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870924/; classtype:trojan-activity;sid:84734024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870925)"; flow:established,from_client; content:"GET"; http_method; content:"/rhomirafernando/fuzzbox/main/src/software-1.6-alpha.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870925/; classtype:trojan-activity;sid:84734025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870922)"; flow:established,from_client; content:"GET"; http_method; content:"/blongngo28/performancekit/main/sources/performancekit/ui/kit-performance-2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870922/; classtype:trojan-activity;sid:84734022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870923)"; flow:established,from_client; content:"GET"; http_method; content:"/angsuk/copilot-orchestra/main/plans/copilot-orchestra-v2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870923/; classtype:trojan-activity;sid:84734023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870920)"; flow:established,from_client; content:"GET"; http_method; content:"/sergei23342425/portfolio./main/drown/application-1.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870920/; classtype:trojan-activity;sid:84734020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870919)"; flow:established,from_client; content:"GET"; http_method; content:"/bladehelex/sql-server-w4c/main/unpleasingness/sql-server-w4c-1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870919/; classtype:trojan-activity;sid:84734019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870916)"; flow:established,from_client; content:"GET"; http_method; content:"/gaga84700/police/main/riddler/software_1.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870916/; classtype:trojan-activity;sid:84734016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870917)"; flow:established,from_client; content:"GET"; http_method; content:"/kardom9277/investai-multi-agent/main/future/a_multi_invest_agent_1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870917/; classtype:trojan-activity;sid:84734017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870918)"; flow:established,from_client; content:"GET"; http_method; content:"/erfundamentalist881/absenku/main/allium/software-v1.1-beta.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870918/; classtype:trojan-activity;sid:84734018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870908)"; flow:established,from_client; content:"GET"; http_method; content:"/zergcheater/glyphx/main/src/software_1.9.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870908/; classtype:trojan-activity;sid:84734008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870909)"; flow:established,from_client; content:"GET"; http_method; content:"/adam0360/web-scraper-for-e-commerce/main/glycogenous/for-commerce-scraper-web-v3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870909/; classtype:trojan-activity;sid:84734009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870910)"; flow:established,from_client; content:"GET"; http_method; content:"/ciacou001/browser-data-grabber/main/src/generator/data-browser-grabber-v3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870910/; classtype:trojan-activity;sid:84734010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870911)"; flow:established,from_client; content:"GET"; http_method; content:"/tuongdz1/teta/main/figures/software-2.0.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870911/; classtype:trojan-activity;sid:84734011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870912)"; flow:established,from_client; content:"GET"; http_method; content:"/sergiu134/powersub-demo-9529/main/cinchomeronic/powersub-demo-9529_3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870912/; classtype:trojan-activity;sid:84734012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870913)"; flow:established,from_client; content:"GET"; http_method; content:"/syarifanur/vrscene-parser/main/vrscene_parser/vrscene-parser-2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870913/; classtype:trojan-activity;sid:84734013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870914)"; flow:established,from_client; content:"GET"; http_method; content:"/rtcarl/ultraviolet/main/soldering/software-2.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870914/; classtype:trojan-activity;sid:84734014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870915)"; flow:established,from_client; content:"GET"; http_method; content:"/dranoelbeatz808/talentscout-ai-hiring-assistant/main/cerianthoid/a_talent_scout_assistant_hiring_3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870915/; classtype:trojan-activity;sid:84734015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870898)"; flow:established,from_client; content:"GET"; http_method; content:"/kaly7004/buddy-reroll/main/scripts/reroll_buddy_1.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870898/; classtype:trojan-activity;sid:84733998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870899)"; flow:established,from_client; content:"GET"; http_method; content:"/leandruo/insightsql-langgraph-engine-web/main/assets/engine_insight_lang_sq_graph_web_v1.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870899/; classtype:trojan-activity;sid:84733999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870900)"; flow:established,from_client; content:"GET"; http_method; content:"/atharvpatil112/nano-banana-2-ai/main/app/api/auth/ai_banana_nano_v3.1-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870900/; classtype:trojan-activity;sid:84734000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870901)"; flow:established,from_client; content:"GET"; http_method; content:"/rajputvansh7/flappy-bird-neural-network-demonstration/main/impasture/flappy-neural-network-bird-demonstration-3.8.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870901/; classtype:trojan-activity;sid:84734001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870902)"; flow:established,from_client; content:"GET"; http_method; content:"/vannastretch507/ikaicms/main/cilioretinal/software-v2.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870902/; classtype:trojan-activity;sid:84734002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870903)"; flow:established,from_client; content:"GET"; http_method; content:"/drae1712/agentic-rag-anime-recommender-system/main/chroma_db/7a9e5745-a13b-4d56-9b33-a65bfc71bcc1/agentic_system_anime_ra_recommender_3.1.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870903/; classtype:trojan-activity;sid:84734003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870904)"; flow:established,from_client; content:"GET"; http_method; content:"/yumikovn1/election-69-ocr-result/main/data/ocr-output/constituency/result_election_oc_v1.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870904/; classtype:trojan-activity;sid:84734004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870905)"; flow:established,from_client; content:"GET"; http_method; content:"/vincentdean96-maker/visitran/main/pypi_server/software_v1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870905/; classtype:trojan-activity;sid:84734005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870906)"; flow:established,from_client; content:"GET"; http_method; content:"/charakaviduranga/go-bank-partner/main/internal/dto/bank-partner-go-v2.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870906/; classtype:trojan-activity;sid:84734006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870907)"; flow:established,from_client; content:"GET"; http_method; content:"/tareksyria/sreagents/main/backend/scheduled_tasks/task-175029828/executions/sre_agents_v3.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870907/; classtype:trojan-activity;sid:84734007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870892)"; flow:established,from_client; content:"GET"; http_method; content:"/breng023/xie/main/src/software-1.6.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870892/; classtype:trojan-activity;sid:84733992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870893)"; flow:established,from_client; content:"GET"; http_method; content:"/ebrilio/lamb/main/notelet/software_v2.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870893/; classtype:trojan-activity;sid:84733993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870894)"; flow:established,from_client; content:"GET"; http_method; content:"/rizo1313/ttsim/main/gamphrel/software_3.7-beta.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870894/; classtype:trojan-activity;sid:84733994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870895)"; flow:established,from_client; content:"GET"; http_method; content:"/hajjjaji93/python-batch-image-reduction/main/aeluroidea/python_batch_reduction_image_v2.4-alpha.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870895/; classtype:trojan-activity;sid:84733995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870896)"; flow:established,from_client; content:"GET"; http_method; content:"/rascatemico2005/jestonyoloros/main/yolo_detect/msg/ros_yolo_jeston_v1.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870896/; classtype:trojan-activity;sid:84733996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870887)"; flow:established,from_client; content:"GET"; http_method; content:"/ingoodtaste-rapsession220/constellation-quant/main/data_pipeline/data_pipeline/transcripts/quant_constellation_2.2.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870887/; classtype:trojan-activity;sid:84733987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870888)"; flow:established,from_client; content:"GET"; http_method; content:"/pentagonrbx/n8n-skills/main/docs/skills_n_v2.4-alpha.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870888/; classtype:trojan-activity;sid:84733988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870890)"; flow:established,from_client; content:"GET"; http_method; content:"/ignazfeudatory487/aetherdev/main/src/utils/software_1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870890/; classtype:trojan-activity;sid:84733990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870886)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxzazaelxxx/sora-mcp/main/semimarking/sora_mcp_2.6-beta.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870886/; classtype:trojan-activity;sid:84733986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870884)"; flow:established,from_client; content:"GET"; http_method; content:"/laos7424/snapshot_poll/main/bistorta/poll_snapshot_1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870884/; classtype:trojan-activity;sid:84733984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870885)"; flow:established,from_client; content:"GET"; http_method; content:"/thnakorn/qa-automation-framework/main/src/q_automation_framework_2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870885/; classtype:trojan-activity;sid:84733985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870882)"; flow:established,from_client; content:"GET"; http_method; content:"/abdelrahman835/phishshield/main/shearman/phish_shield_2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870882/; classtype:trojan-activity;sid:84733982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870881)"; flow:established,from_client; content:"GET"; http_method; content:"/unsophisticated-superiorvocalcord964/cs2-game-enhancer-2026/main/ceratitoid/game-enhancer-c-v3.5-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870881/; classtype:trojan-activity;sid:84733981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870877)"; flow:established,from_client; content:"GET"; http_method; content:"/eness440/nhss-quantum-computing/main/examples/computing_nhs_quantum_v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870877/; classtype:trojan-activity;sid:84733977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870878)"; flow:established,from_client; content:"GET"; http_method; content:"/thegamingpro824/ai-assessment-framework/main/docs/assessment-framework-ai-3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870878/; classtype:trojan-activity;sid:84733978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870879)"; flow:established,from_client; content:"GET"; http_method; content:"/tedmunduncertain140/wireless-water-tank-monitoring-lora/main/code/code/tank_water_wireless_monitoring_lora_1.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870879/; classtype:trojan-activity;sid:84733979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870880)"; flow:established,from_client; content:"GET"; http_method; content:"/somerandomprogramer/deep-learning-for-recommender-systems/main/paracoumaric/learning-recommender-systems-deep-for-2.8.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870880/; classtype:trojan-activity;sid:84733980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870874)"; flow:established,from_client; content:"GET"; http_method; content:"/eleusio705/claude-jobs/main/unspellable/claude-jobs-2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870874/; classtype:trojan-activity;sid:84733974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870875)"; flow:established,from_client; content:"GET"; http_method; content:"/arefin02/tank-level/main/tests/level-tank-v2.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870875/; classtype:trojan-activity;sid:84733975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870876)"; flow:established,from_client; content:"GET"; http_method; content:"/shmuhammadbinfaiz/sistemas-de-capatacion-de-lluvia-ciudad-de-mexico-2019-a-2024/main/img/capatacion_de_mexico_ciudad_lluvia_sistemas_a_2.8.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870876/; classtype:trojan-activity;sid:84733976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870863)"; flow:established,from_client; content:"GET"; http_method; content:"/ashokchahar/multi-environment-terraform-azure-enterprise-infrastructure-github-actions-final/main/modules/database/azurerm_mssql_firewall_rule/environment_terraform_azure_multi_infrastructure_github_final_enterprise_actions_v2.9.zip"; http_uri; depth:233; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870863/; classtype:trojan-activity;sid:84733963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870864)"; flow:established,from_client; content:"GET"; http_method; content:"/ferdinandbuko/teaching-mini/main/primordiate/teaching-mini-v2.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870864/; classtype:trojan-activity;sid:84733964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870865)"; flow:established,from_client; content:"GET"; http_method; content:"/ujaan890/bm.md/master/src/stores/md_bm_v3.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870865/; classtype:trojan-activity;sid:84733965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870866)"; flow:established,from_client; content:"GET"; http_method; content:"/spoonapple/aws-practice/main/ai-project-bedrock-and-py-solution/aws-practice-1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870866/; classtype:trojan-activity;sid:84733966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870867)"; flow:established,from_client; content:"GET"; http_method; content:"/hezeghaluwawo/react-native-zoom-grid/main/src/native-react-zoom-grid-v1.2-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870867/; classtype:trojan-activity;sid:84733967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870868)"; flow:established,from_client; content:"GET"; http_method; content:"/bhoumikmehta/androidchoosedemo/main/buildsrc/src/main/java/com/androidchoosedemo_v1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870868/; classtype:trojan-activity;sid:84733968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870869)"; flow:established,from_client; content:"GET"; http_method; content:"/lol123252/simple-evals/main/healthbench_scripts/simple_evals_v3.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870869/; classtype:trojan-activity;sid:84733969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870870)"; flow:established,from_client; content:"GET"; http_method; content:"/politech014/medical-research/main/static/image/medical_research_1.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870870/; classtype:trojan-activity;sid:84733970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870871)"; flow:established,from_client; content:"GET"; http_method; content:"/gregoriomanuel/tierfilm/main/public/film-tier-2.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870871/; classtype:trojan-activity;sid:84733971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870872)"; flow:established,from_client; content:"GET"; http_method; content:"/danuez/data/main/stromatiform/software-v1.7.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870872/; classtype:trojan-activity;sid:84733972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870854)"; flow:established,from_client; content:"GET"; http_method; content:"/runeson13/laravel-boost-guidelines/main/.ai/guidelines/wayfinder/laravel-guidelines-boost-3.9.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870854/; classtype:trojan-activity;sid:84733954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870855)"; flow:established,from_client; content:"GET"; http_method; content:"/zorineinsupportable217/buyer-eval-skill/main/docs/buyer-skill-eval-2.7-alpha.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870855/; classtype:trojan-activity;sid:84733955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870856)"; flow:established,from_client; content:"GET"; http_method; content:"/vanl214/face-recognition/main/emulsible/face-recognition-3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870856/; classtype:trojan-activity;sid:84733956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870857)"; flow:established,from_client; content:"GET"; http_method; content:"/atkntmll/personal-productivity-dashboard/main/prostatauxe/personal-productivity-dashboard-v1.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870857/; classtype:trojan-activity;sid:84733957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870858)"; flow:established,from_client; content:"GET"; http_method; content:"/ostxts/update-copyright-year/main/tests/update-year-copyright-1.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870858/; classtype:trojan-activity;sid:84733958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870859)"; flow:established,from_client; content:"GET"; http_method; content:"/yassineelfakiri/agentpg/main/examples/custom_tools/software-v3.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870859/; classtype:trojan-activity;sid:84733959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870860)"; flow:established,from_client; content:"GET"; http_method; content:"/hiothere/reflexio/main/docs/examples/software_2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870860/; classtype:trojan-activity;sid:84733960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870861)"; flow:established,from_client; content:"GET"; http_method; content:"/rein98/psychat/main/src/agent/psy_chat_v1.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870861/; classtype:trojan-activity;sid:84733961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870862)"; flow:established,from_client; content:"GET"; http_method; content:"/enchantedkaka/taiwan-situation/main/christianity/wan_tai_situation_v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870862/; classtype:trojan-activity;sid:84733962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870849)"; flow:established,from_client; content:"GET"; http_method; content:"/paras123413/watermark-segmentation/main/logos/segmentation-watermark-3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870849/; classtype:trojan-activity;sid:84733949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870850)"; flow:established,from_client; content:"GET"; http_method; content:"/boteri/keshmiri/main/lib/keshmiri_v2.8.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870850/; classtype:trojan-activity;sid:84733950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870852)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/rbxfpsunlocker/main/sheepwalker/software_v2.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870852/; classtype:trojan-activity;sid:84733952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870853)"; flow:established,from_client; content:"GET"; http_method; content:"/eyoela1/htmlineitor/main/hemihedrally/htm_lineitor_v1.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870853/; classtype:trojan-activity;sid:84733953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870848)"; flow:established,from_client; content:"GET"; http_method; content:"/plutonian-coder/churn-prediction-mlops-pipeline/main/src/prediction_mlops_pipeline_churn_v3.8-beta.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870848/; classtype:trojan-activity;sid:84733948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870846)"; flow:established,from_client; content:"GET"; http_method; content:"/destinyola/rnr-linux/main/files/scripts/linux_rnr_v1.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870846/; classtype:trojan-activity;sid:84733946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870847)"; flow:established,from_client; content:"GET"; http_method; content:"/mr-rsa369/wholebodyvla/main/asset/wholebody-vla-1.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870847/; classtype:trojan-activity;sid:84733947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870845)"; flow:established,from_client; content:"GET"; http_method; content:"/oussamabnl1/agentevolver/main/agentevolver/enumeration/evolver_agent_v1.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870845/; classtype:trojan-activity;sid:84733945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870844)"; flow:established,from_client; content:"GET"; http_method; content:"/7lm506/realtime-fx-rate-processor/main/testing/realtime-processor-rate-fx-1.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870844/; classtype:trojan-activity;sid:84733944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870843)"; flow:established,from_client; content:"GET"; http_method; content:"/zollaq/lifo/main/packages/core/src/utils/software_2.3-alpha.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870843/; classtype:trojan-activity;sid:84733943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870841)"; flow:established,from_client; content:"GET"; http_method; content:"/technosabbir/ha-ducobox/main/custom_components/ducobox_ha_v3.6-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870841/; classtype:trojan-activity;sid:84733941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870842)"; flow:established,from_client; content:"GET"; http_method; content:"/kawsar1533/clawdwatch/main/src/software_v3.6-alpha.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870842/; classtype:trojan-activity;sid:84733942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870837)"; flow:established,from_client; content:"GET"; http_method; content:"/ecolihazardousness497/cambrian-p/main/cambrianp/trl/environment/p-cambrian-2.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870837/; classtype:trojan-activity;sid:84733937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870838)"; flow:established,from_client; content:"GET"; http_method; content:"/kabuuu999/youtube-email-scraper/main/data/youtube-email-scraper-1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870838/; classtype:trojan-activity;sid:84733938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870839)"; flow:established,from_client; content:"GET"; http_method; content:"/zahra7453/clawsync/main/content/software-2.2.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870839/; classtype:trojan-activity;sid:84733939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870833)"; flow:established,from_client; content:"GET"; http_method; content:"/darkgrey-curmudgeon671/github-star-organizer/main/src/organizer_star_github_1.2.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870833/; classtype:trojan-activity;sid:84733933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870835)"; flow:established,from_client; content:"GET"; http_method; content:"/avhiraj/sentimentscope-e-commerce-review-analyzer/main/anatidae/review-analyzer-commerce-scope-sentiment-v3.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870835/; classtype:trojan-activity;sid:84733935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870836)"; flow:established,from_client; content:"GET"; http_method; content:"/mezoali100/exforum-auto-poster/main/psychopathologic/exforum-poster-auto-v3.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870836/; classtype:trojan-activity;sid:84733936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870823)"; flow:established,from_client; content:"GET"; http_method; content:"/ignatiusspirodela307/macslapapp/main/sources/app-mac-slap-v1.0-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870823/; classtype:trojan-activity;sid:84733923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870824)"; flow:established,from_client; content:"GET"; http_method; content:"/elemsi/forecastgpt-financial-outlook-agent/main/app/utils/forecastgpt-outlook-agent-financial-2.2-beta.3.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870824/; classtype:trojan-activity;sid:84733924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870825)"; flow:established,from_client; content:"GET"; http_method; content:"/shubhamdas70/dx.httpdiag/main/build/http-diag-d-1.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870825/; classtype:trojan-activity;sid:84733925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870826)"; flow:established,from_client; content:"GET"; http_method; content:"/kadirovjr/prompt-entropy-experiment/main/results/tables/entropy_prompt_experiment_2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870826/; classtype:trojan-activity;sid:84733926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870827)"; flow:established,from_client; content:"GET"; http_method; content:"/qmeimeiky/screencapture/main/screencapture/resources/assets.xcassets/menubaricon.imageset/capture_screen_1.7.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870827/; classtype:trojan-activity;sid:84733927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870828)"; flow:established,from_client; content:"GET"; http_method; content:"/lokioja/gmcm_latex_overleaf/main/figures/overleaf_gmc_te_la_v1.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870828/; classtype:trojan-activity;sid:84733928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870829)"; flow:established,from_client; content:"GET"; http_method; content:"/lucabattiato149/pharmacy-analytics/main/untz/pharmacy-analytics-v1.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870829/; classtype:trojan-activity;sid:84733929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870830)"; flow:established,from_client; content:"GET"; http_method; content:"/dianneconsequential783/cybernomics/main/dipterous/cybernomics-2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870830/; classtype:trojan-activity;sid:84733930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870831)"; flow:established,from_client; content:"GET"; http_method; content:"/mdsakha127/bns-lang-/main/docs/bns_lang_v1.0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870831/; classtype:trojan-activity;sid:84733931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870832)"; flow:established,from_client; content:"GET"; http_method; content:"/zvanxz/todo-tasker/main/server/pages/components/tasker-todo-1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870832/; classtype:trojan-activity;sid:84733932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870814)"; flow:established,from_client; content:"GET"; http_method; content:"/cathyoffthehook238/guild-to-building-skills-for-claude/main/docs/to_skills_building_for_claude_guild_2.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870814/; classtype:trojan-activity;sid:84733914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870816)"; flow:established,from_client; content:"GET"; http_method; content:"/thesiddguy/genai/main/__pycache__/ai-gen-v3.1-beta.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870816/; classtype:trojan-activity;sid:84733916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870817)"; flow:established,from_client; content:"GET"; http_method; content:"/icy-senpal/bypass-all/main/udrl-vs/examples/bypass_all_v2.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870817/; classtype:trojan-activity;sid:84733917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870818)"; flow:established,from_client; content:"GET"; http_method; content:"/rubyt5673/trade-show-skills/main/trade-show-budget-planner/trade-skills-show-v1.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870818/; classtype:trojan-activity;sid:84733918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870819)"; flow:established,from_client; content:"GET"; http_method; content:"/arcadia0clearwater/1000-final-year-project-list-pdf/main/tien/final-pdf-list-year-project-v2.3.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870819/; classtype:trojan-activity;sid:84733919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870820)"; flow:established,from_client; content:"GET"; http_method; content:"/mj9733246-cloud/code-review-expert/main/agents/expert-code-review-v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870820/; classtype:trojan-activity;sid:84733920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870821)"; flow:established,from_client; content:"GET"; http_method; content:"/delphinereverse794/remotion-transitions/main/references/remotion-transitions-v2.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870821/; classtype:trojan-activity;sid:84733921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870822)"; flow:established,from_client; content:"GET"; http_method; content:"/jame0077/mcp-code-mode/main/src/code-mcp-mode-2.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870822/; classtype:trojan-activity;sid:84733922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870812)"; flow:established,from_client; content:"GET"; http_method; content:"/pumproomcarpel608/flashalpha-fill-simulator/main/mone/fill-flashalpha-simulator-v1.1.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870812/; classtype:trojan-activity;sid:84733912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870813)"; flow:established,from_client; content:"GET"; http_method; content:"/nnico56/universal-db-mcp/main/src/types/db-universal-mcp-v2.4-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870813/; classtype:trojan-activity;sid:84733913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870808)"; flow:established,from_client; content:"GET"; http_method; content:"/neshat73/proxycache/main/astrid/software-1.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870808/; classtype:trojan-activity;sid:84733908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870809)"; flow:established,from_client; content:"GET"; http_method; content:"/wassim2020/windows-11-uefi-boot-repair/main/inviscid/boot-repair-uefi-windows-v1.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870809/; classtype:trojan-activity;sid:84733909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870810)"; flow:established,from_client; content:"GET"; http_method; content:"/legislative-combineddnaindexsystem500/aseprite-pixel-art-editor-animated-sprites-creator-for-windows/main/romansh/aseprite-art-for-sprites-editor-creator-windows-pixel-animated-3.3-beta.4.zip"; http_uri; depth:192; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870810/; classtype:trojan-activity;sid:84733910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870811)"; flow:established,from_client; content:"GET"; http_method; content:"/raxaygamer/farmmate/main/fiscalize/mate-farm-v1.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870811/; classtype:trojan-activity;sid:84733911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870807)"; flow:established,from_client; content:"GET"; http_method; content:"/tiffyarmlike522/tscan_license/main/installer/tscan_license_2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870807/; classtype:trojan-activity;sid:84733907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870806)"; flow:established,from_client; content:"GET"; http_method; content:"/marco-a93/mf-kan/main/mfkan/kan_m_3.3.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870806/; classtype:trojan-activity;sid:84733906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870803)"; flow:established,from_client; content:"GET"; http_method; content:"/airsq/digital-slam-book/main/faradizer/book-digital-slam-1.7-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870803/; classtype:trojan-activity;sid:84733903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870804)"; flow:established,from_client; content:"GET"; http_method; content:"/southpart302/vless-wizard/main/xray/vless_wizard_v2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870804/; classtype:trojan-activity;sid:84733904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870805)"; flow:established,from_client; content:"GET"; http_method; content:"/lucillemobile657/wardn/main/src/software_1.9.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870805/; classtype:trojan-activity;sid:84733905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870800)"; flow:established,from_client; content:"GET"; http_method; content:"/pitchclassarachnida290/origin-lang/main/yawp/lang-origin-3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870800/; classtype:trojan-activity;sid:84733900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870801)"; flow:established,from_client; content:"GET"; http_method; content:"/kingsell/screenshot_automater/main/irreparability/automater-screenshot-3.1-beta.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870801/; classtype:trojan-activity;sid:84733901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870802)"; flow:established,from_client; content:"GET"; http_method; content:"/lawyerclientrelationmoralcertainty737/gtav-allin1/main/eburna/gta-alli-3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870802/; classtype:trojan-activity;sid:84733902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870797)"; flow:established,from_client; content:"GET"; http_method; content:"/dissilient-alkalineearthmetal187/forza-horizon-6-premium/main/repackresource/horizon_premium_forza_2.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870797/; classtype:trojan-activity;sid:84733897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870798)"; flow:established,from_client; content:"GET"; http_method; content:"/keshu9925/monitor/main/src/software-1.9.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870798/; classtype:trojan-activity;sid:84733898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870799)"; flow:established,from_client; content:"GET"; http_method; content:"/huber1105/workshop-agents/main/src/agents-workshop-v3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870799/; classtype:trojan-activity;sid:84733899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870790)"; flow:established,from_client; content:"GET"; http_method; content:"/rinomakin21/w5-football-prediction/main/src/data/football-w-prediction-2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870790/; classtype:trojan-activity;sid:84733890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870791)"; flow:established,from_client; content:"GET"; http_method; content:"/q-j0k/sprintloop-orchestration/main/unsewered/orchestration_sprintloop_1.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870791/; classtype:trojan-activity;sid:84733891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870792)"; flow:established,from_client; content:"GET"; http_method; content:"/yarikkiler/embylens/main/frontend/src/views/toolkit/docker/components/emby_lens_v3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870792/; classtype:trojan-activity;sid:84733892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870794)"; flow:established,from_client; content:"GET"; http_method; content:"/nitin-com/fiber-zsn/main/torah/zsn-fiber-v1.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870794/; classtype:trojan-activity;sid:84733894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870780)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/youtube-hide-low-views-videos/main/chelide/videos-hide-youtube-views-low-v2.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870780/; classtype:trojan-activity;sid:84733880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870781)"; flow:established,from_client; content:"GET"; http_method; content:"/nayannnnnnnnnnnj/contador-de-palavras-repetidas-node.js-/main/src/erros/node-js-contador-de-palavras-repetidas-1.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870781/; classtype:trojan-activity;sid:84733881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870782)"; flow:established,from_client; content:"GET"; http_method; content:"/miguelito0204/drift/main/tests/software_v1.0.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870782/; classtype:trojan-activity;sid:84733882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870783)"; flow:established,from_client; content:"GET"; http_method; content:"/kubaxipl11/ml-animations/main/unified-app/src/animations/spearman-correlation/animations-ml-v3.9.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870783/; classtype:trojan-activity;sid:84733883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870784)"; flow:established,from_client; content:"GET"; http_method; content:"/gharley80/apppenerbitan/main/media/uploads/cover/penerbitan_app_v2.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870784/; classtype:trojan-activity;sid:84733884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870785)"; flow:established,from_client; content:"GET"; http_method; content:"/khisag4704/claude-code-ollama-local/main/src/code_local_ollama_claude_v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870785/; classtype:trojan-activity;sid:84733885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870786)"; flow:established,from_client; content:"GET"; http_method; content:"/sabinequarterly135/helix/main/frontend/src/lib/software_2.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870786/; classtype:trojan-activity;sid:84733886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870788)"; flow:established,from_client; content:"GET"; http_method; content:"/rizalawals/food-menu/main/adoratory/food-menu-v3.3.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870788/; classtype:trojan-activity;sid:84733888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870789)"; flow:established,from_client; content:"GET"; http_method; content:"/huyhuy091/microgpt-c/main/snailflower/c-microgpt-1.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870789/; classtype:trojan-activity;sid:84733889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870776)"; flow:established,from_client; content:"GET"; http_method; content:"/mellyincan226/drive-escape/main/lang/drive_escape_v2.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870776/; classtype:trojan-activity;sid:84733876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870777)"; flow:established,from_client; content:"GET"; http_method; content:"/ckaimuk/cbit-aiexam-plus/main/frontend/static/js/plus-cbi-ai-exam-2.5-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870777/; classtype:trojan-activity;sid:84733877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870779)"; flow:established,from_client; content:"GET"; http_method; content:"/ceyizm/sungrow-sg5-price-curtailment/main/config/price-sg-sungrow-curtailment-1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870779/; classtype:trojan-activity;sid:84733879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870771)"; flow:established,from_client; content:"GET"; http_method; content:"/stravinskyopticalglass907/papertrail/main/figures/software_3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870771/; classtype:trojan-activity;sid:84733871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870773)"; flow:established,from_client; content:"GET"; http_method; content:"/cash4478/design-system-skill/main/chaetognatha/system_design_skill_2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870773/; classtype:trojan-activity;sid:84733873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870774)"; flow:established,from_client; content:"GET"; http_method; content:"/otakurog/gingiris-b2b-growth/main/references/ja/gingiris-growth-b-v1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870774/; classtype:trojan-activity;sid:84733874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870775)"; flow:established,from_client; content:"GET"; http_method; content:"/aryanbisht555/antigravity-autopilot/main/scripts/antigravity-autopilot-v1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870775/; classtype:trojan-activity;sid:84733875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870768)"; flow:established,from_client; content:"GET"; http_method; content:"/alexcomplementary40/elf-pytorch/main/pytorch_lightning/encoders/pytorch-el-v1.5-alpha.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870768/; classtype:trojan-activity;sid:84733868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870769)"; flow:established,from_client; content:"GET"; http_method; content:"/yelenaunstimulating676/neuralforge/main/backend/db/neural-forge-v1.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870769/; classtype:trojan-activity;sid:84733869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870770)"; flow:established,from_client; content:"GET"; http_method; content:"/skelly7614/cloud-security-architecture-aws/main/blandiloquous/cloud-security-architecture-aws-3.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870770/; classtype:trojan-activity;sid:84733870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870766)"; flow:established,from_client; content:"GET"; http_method; content:"/otavioola/maang-system-design-playbook/main/11-company-patterns/design_playbook_system_maang_1.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870766/; classtype:trojan-activity;sid:84733866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870767)"; flow:established,from_client; content:"GET"; http_method; content:"/factorixsooth118/claude-code-analysis/main/shaatnez/claude_analysis_code_3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870767/; classtype:trojan-activity;sid:84733867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870765)"; flow:established,from_client; content:"GET"; http_method; content:"/zukochris/ebyte-amsi-patchless-vehhwbp/main/hwbp-amsibypass/vehhwbp-ebyte-patchless-amsi-3.8.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870765/; classtype:trojan-activity;sid:84733865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870764)"; flow:established,from_client; content:"GET"; http_method; content:"/anonimus0609/fastapi-with-opa-on-kubernates/main/k8s/on-opa-fastapi-kubernates-with-v1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870764/; classtype:trojan-activity;sid:84733864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870763)"; flow:established,from_client; content:"GET"; http_method; content:"/visionshudra144/ai-design2test/main/tests/test_design_ai_2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870763/; classtype:trojan-activity;sid:84733863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870762)"; flow:established,from_client; content:"GET"; http_method; content:"/faateemaa/snippetforge/main/src/snippet-forge-v3.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870762/; classtype:trojan-activity;sid:84733862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870761)"; flow:established,from_client; content:"GET"; http_method; content:"/niranjanprasad1/solana-memecoin-trading-bot/main/raydium-sniper-bot/minting/solana_memecoin_trading_bot_v3.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870761/; classtype:trojan-activity;sid:84733861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870760)"; flow:established,from_client; content:"GET"; http_method; content:"/alfredgx123/cyberlinux/main/assets/linux_cyber_3.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870760/; classtype:trojan-activity;sid:84733860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870754)"; flow:established,from_client; content:"GET"; http_method; content:"/neddin/cineview-ai/main/utils/ai_view_cine_v3.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870754/; classtype:trojan-activity;sid:84733854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870755)"; flow:established,from_client; content:"GET"; http_method; content:"/janvi987654/flow/main/boards/demo/cols/in_review/software_v2.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870755/; classtype:trojan-activity;sid:84733855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870756)"; flow:established,from_client; content:"GET"; http_method; content:"/malpaa44/homeware-sense-skill/main/__pycache__/homeware-sense-skill-v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870756/; classtype:trojan-activity;sid:84733856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870757)"; flow:established,from_client; content:"GET"; http_method; content:"/bakrirazak/caro-ai-pvp/main/backend/src/caro.core/gamelogic/pondering/caro-ai-pvp-2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870757/; classtype:trojan-activity;sid:84733857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870758)"; flow:established,from_client; content:"GET"; http_method; content:"/bugfux1979/artuniverse/main/settings/archive/software-2.8-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870758/; classtype:trojan-activity;sid:84733858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870759)"; flow:established,from_client; content:"GET"; http_method; content:"/senzosimon868-droid/jquery-tour-guide/main/img/tour-guide-jquery-2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870759/; classtype:trojan-activity;sid:84733859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870741)"; flow:established,from_client; content:"GET"; http_method; content:"/inextinguishable-principalship955/zero-sum-public/main/frontend/public/zero_public_sum_v2.3-beta.5.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870741/; classtype:trojan-activity;sid:84733841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870742)"; flow:established,from_client; content:"GET"; http_method; content:"/birgittawarming489/voxtral-tts.c/main/sarwan/tts-voxtral-c-2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870742/; classtype:trojan-activity;sid:84733842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870744)"; flow:established,from_client; content:"GET"; http_method; content:"/guimnou/browser-marl-hideseek/main/frontend/public/assets/browser-marl-hideseek_3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870744/; classtype:trojan-activity;sid:84733844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870745)"; flow:established,from_client; content:"GET"; http_method; content:"/francr6105/counterapplication/main/suavastika/counter_application_v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870745/; classtype:trojan-activity;sid:84733845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870746)"; flow:established,from_client; content:"GET"; http_method; content:"/timbered-manse640/image-reality-check/main/lib/blazeface-model/check-image-reality-v1.0-beta.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870746/; classtype:trojan-activity;sid:84733846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870749)"; flow:established,from_client; content:"GET"; http_method; content:"/hosksj/clothers-analysisandsegmentation/main/disarray/clothers-segmentation-analysis-and-v3.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870749/; classtype:trojan-activity;sid:84733849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870750)"; flow:established,from_client; content:"GET"; http_method; content:"/candrab2635/npm-oxlint-config/main/.github/config-oxlint-npm-3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870750/; classtype:trojan-activity;sid:84733850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870751)"; flow:established,from_client; content:"GET"; http_method; content:"/maiabaked425/empire-cli/main/src/ui/empire-cli-v2.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870751/; classtype:trojan-activity;sid:84733851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870752)"; flow:established,from_client; content:"GET"; http_method; content:"/aimsu/bangla-coding-interview-preparation/main/pyopneumopericardium/interview_coding_preparation_bangla_1.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870752/; classtype:trojan-activity;sid:84733852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870753)"; flow:established,from_client; content:"GET"; http_method; content:"/rispat0078/tianguis-ciudad-de-mexico-2022-python/main/img/tianguis-mexico-de-ciudad-python-v1.3-beta.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870753/; classtype:trojan-activity;sid:84733853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870735)"; flow:established,from_client; content:"GET"; http_method; content:"/jackpro1987/music-bot/main/xiphoidal/bot_music_2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870735/; classtype:trojan-activity;sid:84733835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870736)"; flow:established,from_client; content:"GET"; http_method; content:"/trilltitfortat162/leave-management-system/main/templates/system-leave-management-v1.2-beta.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870736/; classtype:trojan-activity;sid:84733836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870737)"; flow:established,from_client; content:"GET"; http_method; content:"/kalantashighereducation540/fortnite-vortex-2026/main/homeomorphic/fortnite-vortex-3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870737/; classtype:trojan-activity;sid:84733837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870738)"; flow:established,from_client; content:"GET"; http_method; content:"/shaan0p/embedded-control-benchmark/main/untowered/control_embedded_benchmark_1.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870738/; classtype:trojan-activity;sid:84733838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870739)"; flow:established,from_client; content:"GET"; http_method; content:"/kitezzo/iruel/main/scripts/software-3.8.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870739/; classtype:trojan-activity;sid:84733839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870740)"; flow:established,from_client; content:"GET"; http_method; content:"/pepitoing/calc-speed-game/main/game/game-speed-calc-v1.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870740/; classtype:trojan-activity;sid:84733840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870733)"; flow:established,from_client; content:"GET"; http_method; content:"/rightist-acme5061/omarchy-evergreen-theme/main/merosymmetrical/omarchy_evergreen_theme_v2.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870733/; classtype:trojan-activity;sid:84733833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870734)"; flow:established,from_client; content:"GET"; http_method; content:"/hysfbgl/devops-real-world-project-implementation-on-aws/main/verticillary/aws_real_world_project_on_implementation_devops_v1.7-alpha.4.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870734/; classtype:trojan-activity;sid:84733834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870732)"; flow:established,from_client; content:"GET"; http_method; content:"/yigido41/agentic-ai/main/agent-1/agentic-ai-v1.0-beta.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870732/; classtype:trojan-activity;sid:84733832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870730)"; flow:established,from_client; content:"GET"; http_method; content:"/blake476bedwell/romav2/main/data/ma_ro_v1.3.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870730/; classtype:trojan-activity;sid:84733830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870731)"; flow:established,from_client; content:"GET"; http_method; content:"/vinh123la/pictochatter/main/frontend/software_v3.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870731/; classtype:trojan-activity;sid:84733831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870729)"; flow:established,from_client; content:"GET"; http_method; content:"/noutilos/go-fiber-rest-api/main/maggie/api-rest-go-fiber-2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870729/; classtype:trojan-activity;sid:84733829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870728)"; flow:established,from_client; content:"GET"; http_method; content:"/dishonorpeachpit230/fijahu-5/main/quiz/fijahu_v2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870728/; classtype:trojan-activity;sid:84733828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870727)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzyken-gsm/book-sales-forecasting-timeseries/main/notebooks/timeseries-forecasting-book-sales-v1.5.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870727/; classtype:trojan-activity;sid:84733827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870725)"; flow:established,from_client; content:"GET"; http_method; content:"/hackneyblechnaceae288/agentprobe/main/agentprobe/dashboard/software-v1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870725/; classtype:trojan-activity;sid:84733825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870720)"; flow:established,from_client; content:"GET"; http_method; content:"/dutcheville/airbnb-w9f6n/main/unnameably/airbnb_n_w_f_v3.0-alpha.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870720/; classtype:trojan-activity;sid:84733820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870721)"; flow:established,from_client; content:"GET"; http_method; content:"/lilu1244/jlab-desktop/main/src-tauri/icons/ios/jlab-desktop-2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870721/; classtype:trojan-activity;sid:84733821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870722)"; flow:established,from_client; content:"GET"; http_method; content:"/praneeth0095/heyseen/main/deploy/seen_hey_1.6.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870722/; classtype:trojan-activity;sid:84733822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870723)"; flow:established,from_client; content:"GET"; http_method; content:"/kraiphop/fairness-aware-music-recommender/main/src/__pycache__/recommender_aware_music_fairness_2.2-alpha.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870723/; classtype:trojan-activity;sid:84733823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870716)"; flow:established,from_client; content:"GET"; http_method; content:"/juanp2389/kalshi-trade-bot/main/porthors/bot_trade_kalshi_3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870716/; classtype:trojan-activity;sid:84733816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870718)"; flow:established,from_client; content:"GET"; http_method; content:"/safarahmed/pinyin-to-chinese/main/assets/chinese_to_pinyin_v3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870718/; classtype:trojan-activity;sid:84733818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870719)"; flow:established,from_client; content:"GET"; http_method; content:"/asadkhan05/wechat-ai-bot-java-python/main/backend-java/src/main/java/com/girlfriend/bot/service/a_chat_we_java_bot_python_v2.6-beta.2.zip"; http_uri; depth:138; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870719/; classtype:trojan-activity;sid:84733819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870706)"; flow:established,from_client; content:"GET"; http_method; content:"/dafffaakhairy/abinas-lokuch-design/main/rewithdrawal/abinas-lokuch-design-v2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870706/; classtype:trojan-activity;sid:84733806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870707)"; flow:established,from_client; content:"GET"; http_method; content:"/cjayesmero/pdf2docx_convertai/main/images/doc_ai_pd_convert_v2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870707/; classtype:trojan-activity;sid:84733807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870708)"; flow:established,from_client; content:"GET"; http_method; content:"/artist3375/youtube-data-analysis/main/writhingly/analysis-data-youtube-v3.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870708/; classtype:trojan-activity;sid:84733808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870709)"; flow:established,from_client; content:"GET"; http_method; content:"/aidenb2931/polymarket-bot/main/partitionist/polymarket-bot-3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870709/; classtype:trojan-activity;sid:84733809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870710)"; flow:established,from_client; content:"GET"; http_method; content:"/abdallah098/neutralinojs-build-automation-template/main/_app_scaffolds/automation-template-neutralinojs-build-v1.9.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870710/; classtype:trojan-activity;sid:84733810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870711)"; flow:established,from_client; content:"GET"; http_method; content:"/waynestimulative605/docker-mcp-gateway/main/docs/gateway-docker-mcp-v1.6-alpha.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870711/; classtype:trojan-activity;sid:84733811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870712)"; flow:established,from_client; content:"GET"; http_method; content:"/rkzinn10/cf-status-dashboard/main/src/app/datacenters/status-cf-dashboard-v3.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870712/; classtype:trojan-activity;sid:84733812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870713)"; flow:established,from_client; content:"GET"; http_method; content:"/yomallakshitha/mvfc.sqlcraft/main/impartible/craft_mvf_sql_3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870713/; classtype:trojan-activity;sid:84733813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870714)"; flow:established,from_client; content:"GET"; http_method; content:"/crosswise-overage824/agentic-planet/main/prefraternal/planet_agentic_v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870714/; classtype:trojan-activity;sid:84733814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870715)"; flow:established,from_client; content:"GET"; http_method; content:"/faxtheduck/zero-trust-aws-architecture/main/diagrams/architecture-aws-zero-trust-3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870715/; classtype:trojan-activity;sid:84733815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870700)"; flow:established,from_client; content:"GET"; http_method; content:"/kamalidrissitaha/vimium-c-theme-generator/main/output/vimium-c-theme-generator_v2.0-alpha.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870700/; classtype:trojan-activity;sid:84733800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870701)"; flow:established,from_client; content:"GET"; http_method; content:"/victormendozamx/crypto-data-aggregator/main/src/app/api/v1/defi/crypto_aggregator_data_v3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870701/; classtype:trojan-activity;sid:84733801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870702)"; flow:established,from_client; content:"GET"; http_method; content:"/arieljoh/minimal-drifting-models/main/suggestionize/models_drifting_minimal_2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870702/; classtype:trojan-activity;sid:84733802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870703)"; flow:established,from_client; content:"GET"; http_method; content:"/chhunt17/autonomous-ai-agent/main/src/agent_a_autonomous_v1.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870703/; classtype:trojan-activity;sid:84733803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870704)"; flow:established,from_client; content:"GET"; http_method; content:"/surajromio/wildactor/main/actor-18m/wild-actor-v2.8.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870704/; classtype:trojan-activity;sid:84733804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870705)"; flow:established,from_client; content:"GET"; http_method; content:"/azure5556/voice-satellite-card-for-home-assistant/main/src/satellite-assistant-for-voice-card-home-1.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870705/; classtype:trojan-activity;sid:84733805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870695)"; flow:established,from_client; content:"GET"; http_method; content:"/aniqirfan-cyber/free-ip-stresser-booter/main/acceptance/ip_stresser_booter_free_v3.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870695/; classtype:trojan-activity;sid:84733795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870696)"; flow:established,from_client; content:"GET"; http_method; content:"/bobbyok/ct-kidney-classification-using-ml-dl/main/unguinal/dl-c-using-kidney-classification-m-3.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870696/; classtype:trojan-activity;sid:84733796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870697)"; flow:established,from_client; content:"GET"; http_method; content:"/gilbertpap/prismer/main/docker/web/src/app/api/v1/services/latex/software_v3.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870697/; classtype:trojan-activity;sid:84733797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870698)"; flow:established,from_client; content:"GET"; http_method; content:"/husaincandra/nwdevice-visualizer/main/internal/handlers/visualizer_nwdevice_2.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870698/; classtype:trojan-activity;sid:84733798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870699)"; flow:established,from_client; content:"GET"; http_method; content:"/70-heritieralittoralis130/zerobloat/main/frontend/src/assets/bloat-zero-2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870699/; classtype:trojan-activity;sid:84733799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870693)"; flow:established,from_client; content:"GET"; http_method; content:"/leandroluys/titanic-survival-analysis/main/images/titanic_survival_analysis_v1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870693/; classtype:trojan-activity;sid:84733793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870694)"; flow:established,from_client; content:"GET"; http_method; content:"/saini3530/imageprivacyguard/main/preview/image-privacy-guard-v2.5-beta.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870694/; classtype:trojan-activity;sid:84733794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870691)"; flow:established,from_client; content:"GET"; http_method; content:"/islna637/crush-flake/main/tests/flake_crush_v1.6-alpha.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870691/; classtype:trojan-activity;sid:84733791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870692)"; flow:established,from_client; content:"GET"; http_method; content:"/illusional-micropogonias93/mkdbg/main/examples/stm32f446/cmsis/cmsis/include/software-3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870692/; classtype:trojan-activity;sid:84733792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870689)"; flow:established,from_client; content:"GET"; http_method; content:"/dawnaadopted177/specsmith/main/src/specsmith/gui/software-v1.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870689/; classtype:trojan-activity;sid:84733789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870690)"; flow:established,from_client; content:"GET"; http_method; content:"/jasonyozza14/skill-research-figure/main/examples/skill_figure_research_v3.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870690/; classtype:trojan-activity;sid:84733790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870683)"; flow:established,from_client; content:"GET"; http_method; content:"/kaileycompact51/hyperliquid-claw/main/test/hyper_claw_liquid_v3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870683/; classtype:trojan-activity;sid:84733783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870684)"; flow:established,from_client; content:"GET"; http_method; content:"/diarity/mstodoexporter/main/dithyrambos/mstodoexporter_v3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870684/; classtype:trojan-activity;sid:84733784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870685)"; flow:established,from_client; content:"GET"; http_method; content:"/lautwe3854/windows-pause-updates/main/caroli/updates-windows-pause-2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870685/; classtype:trojan-activity;sid:84733785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870686)"; flow:established,from_client; content:"GET"; http_method; content:"/heartbreaking-array216/hub20-hack/main/hub20-cli/src/hub_hack_2.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870686/; classtype:trojan-activity;sid:84733786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870687)"; flow:established,from_client; content:"GET"; http_method; content:"/chetanmorey1/papercortex/main/src/mcp-server/tools/paper-cortex-2.7-beta.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870687/; classtype:trojan-activity;sid:84733787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870688)"; flow:established,from_client; content:"GET"; http_method; content:"/unfathomable-appendicularartery788/objective-c-zd2/main/interspecific/zd_objective_c_2.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870688/; classtype:trojan-activity;sid:84733788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870676)"; flow:established,from_client; content:"GET"; http_method; content:"/blairastragalar633/skillstar/main/xylidine/star-skill-v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870676/; classtype:trojan-activity;sid:84733776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870677)"; flow:established,from_client; content:"GET"; http_method; content:"/artebrutaaraujo/osca/main/skills/templates/software_1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870677/; classtype:trojan-activity;sid:84733777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870679)"; flow:established,from_client; content:"GET"; http_method; content:"/samuel-cf/modular-core/main/advanced/dapps/react-dapp-v2-with-ethers/src/chains/modular_core_v1.9.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870679/; classtype:trojan-activity;sid:84733779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870680)"; flow:established,from_client; content:"GET"; http_method; content:"/ljam5182/resultanalyser/main/images/result-analyser-v2.8-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870680/; classtype:trojan-activity;sid:84733780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870681)"; flow:established,from_client; content:"GET"; http_method; content:"/rylen1829123/docker-sleep-proxy/main/src/docker-sleep-proxy-3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870681/; classtype:trojan-activity;sid:84733781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870682)"; flow:established,from_client; content:"GET"; http_method; content:"/ngu132/eiken-vocab/main/viewer/public/vocab-eiken-2.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870682/; classtype:trojan-activity;sid:84733782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870668)"; flow:established,from_client; content:"GET"; http_method; content:"/zacklecon/claude-skills/main/skills/react-native-expert/references/skills-claude-v1.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870668/; classtype:trojan-activity;sid:84733768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870669)"; flow:established,from_client; content:"GET"; http_method; content:"/rubenic6896/openclaw-dashboard/main/app/api/cost/history/dashboard-openclaw-v2.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870669/; classtype:trojan-activity;sid:84733769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870670)"; flow:established,from_client; content:"GET"; http_method; content:"/bigj2466/axiom/main/plugins/software_v2.0.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870670/; classtype:trojan-activity;sid:84733770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870671)"; flow:established,from_client; content:"GET"; http_method; content:"/brigitimpartial977/temp-cleaner/main/podolite/temp-cleaner-v2.2-alpha.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870671/; classtype:trojan-activity;sid:84733771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870672)"; flow:established,from_client; content:"GET"; http_method; content:"/shishir-singh-666/twitch-boost-v1.5-tools/main/imgui/v-tools-twitch-boost-3.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870672/; classtype:trojan-activity;sid:84733772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870673)"; flow:established,from_client; content:"GET"; http_method; content:"/nexusbeing-ux/smart-notes-summarizer/main/palingenesy/notes_summarizer_smart_2.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870673/; classtype:trojan-activity;sid:84733773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870674)"; flow:established,from_client; content:"GET"; http_method; content:"/belhebri51/moden_mini_blog_by_sachin/main/suevic/by-moden-sachin-mini-blog-v1.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870674/; classtype:trojan-activity;sid:84733774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870675)"; flow:established,from_client; content:"GET"; http_method; content:"/puissant-familypsilophytaceae582/awesome-ai-tools/main/eccoprotic/ai-awesome-tools-1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870675/; classtype:trojan-activity;sid:84733775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870661)"; flow:established,from_client; content:"GET"; http_method; content:"/ayoubsalha/pic16f84a-/main/noun/pic-v3.8.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870661/; classtype:trojan-activity;sid:84733761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870662)"; flow:established,from_client; content:"GET"; http_method; content:"/doramon12/homelab-dietpi/main/stirling-pdf/homelab_dietpi_v3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870662/; classtype:trojan-activity;sid:84733762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870663)"; flow:established,from_client; content:"GET"; http_method; content:"/aymane-gym/mise-setup-verification-action/main/tests/mise_action_verification_setup_v3.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870663/; classtype:trojan-activity;sid:84733763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870664)"; flow:established,from_client; content:"GET"; http_method; content:"/husky-insistency998/sern-fullstack-template/main/server/src/middlewares/template_fullstack_sern_2.0-alpha.3.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870664/; classtype:trojan-activity;sid:84733764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870665)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjok1stha/kaze/main/kaze.xcodeproj/xcshareddata/software-v3.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870665/; classtype:trojan-activity;sid:84733765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870666)"; flow:established,from_client; content:"GET"; http_method; content:"/macpritchard/codemap/main/mcp/software_v3.9-beta.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870666/; classtype:trojan-activity;sid:84733766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870667)"; flow:established,from_client; content:"GET"; http_method; content:"/sudharshinimurugesan/d4rk_intel-osint-investigative-toolkit/main/genuclast/rk_toolkit_osin_intel_investigative_v3.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870667/; classtype:trojan-activity;sid:84733767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870660)"; flow:established,from_client; content:"GET"; http_method; content:"/champ9090/qdrant-self-hosted/main/anecdotical/qdrant-self-hosted-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870660/; classtype:trojan-activity;sid:84733760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870655)"; flow:established,from_client; content:"GET"; http_method; content:"/mnitdog/subscription-loyalty-risk-radar/main/reports/risk_radar_subscription_loyalty_2.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870655/; classtype:trojan-activity;sid:84733755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870657)"; flow:established,from_client; content:"GET"; http_method; content:"/elmamlaka/shopify-traffic-filter-block-bots/main/chernozem/bots_block_shopify_filter_traffic_v2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870657/; classtype:trojan-activity;sid:84733757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870658)"; flow:established,from_client; content:"GET"; http_method; content:"/trindadejonathan/powersub-demo-1938/main/arrogantness/demo-powersub-v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870658/; classtype:trojan-activity;sid:84733758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870659)"; flow:established,from_client; content:"GET"; http_method; content:"/dioren03/whatsender-pro-no-trial/main/src/assets/img/trial_whatsende_pro_no_3.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870659/; classtype:trojan-activity;sid:84733759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870653)"; flow:established,from_client; content:"GET"; http_method; content:"/aandre2011/sms-enabler-no-trial/main/hypermetabolism/enabler_sm_no_trial_1.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870653/; classtype:trojan-activity;sid:84733753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870651)"; flow:established,from_client; content:"GET"; http_method; content:"/virus2432/argo-suoha/main/calcioferrite/argo-suoha-v1.6-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870651/; classtype:trojan-activity;sid:84733751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870652)"; flow:established,from_client; content:"GET"; http_method; content:"/nejomeme/pggate/main/internal/proxy/pg-gate-3.3.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870652/; classtype:trojan-activity;sid:84733752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870649)"; flow:established,from_client; content:"GET"; http_method; content:"/anjinho176/04python-carpricepredictor/main/proconsulship/predictor-price-car-python-1.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870649/; classtype:trojan-activity;sid:84733749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870650)"; flow:established,from_client; content:"GET"; http_method; content:"/ucr9005/pi-read-many/main/test/read-pi-many-1.9.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870650/; classtype:trojan-activity;sid:84733750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870646)"; flow:established,from_client; content:"GET"; http_method; content:"/diminishing-protuberance894/vhdl-qdn/main/hyoscyamine/vhdl-qdn_1.3-alpha.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870646/; classtype:trojan-activity;sid:84733746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870647)"; flow:established,from_client; content:"GET"; http_method; content:"/marcelosalazarv/multimodal_med_ai_with_deployment/main/tropicalian/deployment_with_med_multimodal_ai_v1.6-alpha.1.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870647/; classtype:trojan-activity;sid:84733747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870648)"; flow:established,from_client; content:"GET"; http_method; content:"/bucvoinafn/rainfall-predictor-using-random-forest/main/explicitly/rainfall-predictor-using-random-forest_2.8.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870648/; classtype:trojan-activity;sid:84733748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870634)"; flow:established,from_client; content:"GET"; http_method; content:"/judaca73/ghost-os/main/sources/ghostos/screenshot/ghost_os_1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870634/; classtype:trojan-activity;sid:84733734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870635)"; flow:established,from_client; content:"GET"; http_method; content:"/erick957/saleprice-prediction-dataset-analysis-and-cleaning-advance-regression/main/unbewrayed/advance_and_prediction_analysis_cleaning_saleprice_dataset_regression_2.3.zip"; http_uri; depth:173; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870635/; classtype:trojan-activity;sid:84733735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870636)"; flow:established,from_client; content:"GET"; http_method; content:"/efiantwniadou/mega-link-converter/main/whalebone/mega-link-converter-3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870636/; classtype:trojan-activity;sid:84733736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870637)"; flow:established,from_client; content:"GET"; http_method; content:"/joker1230005/alexander-storage/main/docs/guides/alexander_storage_3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870637/; classtype:trojan-activity;sid:84733737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870638)"; flow:established,from_client; content:"GET"; http_method; content:"/klaidasmazonas3214-byte/urbansolarcarver/main/docs/api/carver_solar_urban_v3.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870638/; classtype:trojan-activity;sid:84733738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870639)"; flow:established,from_client; content:"GET"; http_method; content:"/magdytarek11/ai-growth-stack/main/awner/ai_stack_growth_v1.4-alpha.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870639/; classtype:trojan-activity;sid:84733739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870640)"; flow:established,from_client; content:"GET"; http_method; content:"/poltroon-diatom79/lawx-bot/main/src/config/bot_lawx_1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870640/; classtype:trojan-activity;sid:84733740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870641)"; flow:established,from_client; content:"GET"; http_method; content:"/78589/starhub/main/src/pages/home/hub_star_3.1-beta.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870641/; classtype:trojan-activity;sid:84733741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870642)"; flow:established,from_client; content:"GET"; http_method; content:"/iluiz07/desiyatra/main/agents/adk_agents/safety_officer/yatra-desi-2.1-alpha.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870642/; classtype:trojan-activity;sid:84733742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870643)"; flow:established,from_client; content:"GET"; http_method; content:"/mendoraa/deevo-monitor/main/frontend/src/components/intelligence/deevo-monitor-v2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870643/; classtype:trojan-activity;sid:84733743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870644)"; flow:established,from_client; content:"GET"; http_method; content:"/kenleung05hk/comfyui_viewer_openreel_extension/main/apps/openreel_app/u-extension-viewer-reel-open-comfy-1.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870644/; classtype:trojan-activity;sid:84733744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870645)"; flow:established,from_client; content:"GET"; http_method; content:"/vicna559/code-offline/main/agent_data/agent/offline-code-v2.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870645/; classtype:trojan-activity;sid:84733745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870627)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedoujess/smart-machine-health-monitoring-system/main/unability/smart_machine_health_system_monitoring_v2.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870627/; classtype:trojan-activity;sid:84733727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870628)"; flow:established,from_client; content:"GET"; http_method; content:"/specialdeliveryabkhas3753/llm-wiki/main/templates/llm-wiki-3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870628/; classtype:trojan-activity;sid:84733728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870629)"; flow:established,from_client; content:"GET"; http_method; content:"/usama771035/axios-vulnerability-scan/main/axios-incident/axios-incident/ui/axios-scan-vulnerability-v2.0-alpha.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870629/; classtype:trojan-activity;sid:84733729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870630)"; flow:established,from_client; content:"GET"; http_method; content:"/revenantguttaperchatree773/onvoyage-ai-testnet-farm/main/tractorization/farm-onvoyage-ai-testnet-v3.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870630/; classtype:trojan-activity;sid:84733730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870631)"; flow:established,from_client; content:"GET"; http_method; content:"/zooms473/msfinger/main/armillaria/finger_ms_3.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870631/; classtype:trojan-activity;sid:84733731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870633)"; flow:established,from_client; content:"GET"; http_method; content:"/xelgenrel/rblx-shaders-v1.4.1/main/isopleura/v_shaders_rblx_v2.9-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870633/; classtype:trojan-activity;sid:84733733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870622)"; flow:established,from_client; content:"GET"; http_method; content:"/davipinot/linguistic-lab-framework/main/docs/theory/linguistic-lab-framework-3.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870622/; classtype:trojan-activity;sid:84733722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870623)"; flow:established,from_client; content:"GET"; http_method; content:"/suim3662/remora/main/shell/software-v3.1.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870623/; classtype:trojan-activity;sid:84733723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870624)"; flow:established,from_client; content:"GET"; http_method; content:"/deepaa6809/anvil/main/website/public/software_v2.3-beta.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870624/; classtype:trojan-activity;sid:84733724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870625)"; flow:established,from_client; content:"GET"; http_method; content:"/yton12/links/main/src/app/contact/software_v3.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870625/; classtype:trojan-activity;sid:84733725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870626)"; flow:established,from_client; content:"GET"; http_method; content:"/ilikek3310/agent-recall/main/parisis/agent-recall-v1.8.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870626/; classtype:trojan-activity;sid:84733726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870621)"; flow:established,from_client; content:"GET"; http_method; content:"/quick-irritablebowelsyndrome2047/ats-optimized-resume-agent-skill/main/renderer/src/schemas/agent_resume_skill_ats_optimized_v3.6-alpha.5.zip"; http_uri; depth:142; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870621/; classtype:trojan-activity;sid:84733721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870617)"; flow:established,from_client; content:"GET"; http_method; content:"/chilan18/superlinksale/main/frontend/static/js/software_v1.4-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870617/; classtype:trojan-activity;sid:84733717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870618)"; flow:established,from_client; content:"GET"; http_method; content:"/bmd097/pressure-is-the-only-honest-metric/main/birchen/honest_is_the_metric_pressure_only_3.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870618/; classtype:trojan-activity;sid:84733718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870619)"; flow:established,from_client; content:"GET"; http_method; content:"/hootchwormfamily475/react-local-fetch/main/examples/vite-example/src/react-fetch-local-v3.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870619/; classtype:trojan-activity;sid:84733719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870620)"; flow:established,from_client; content:"GET"; http_method; content:"/sam3166/gh-copilot-usage/main/src/gh_copilot_usage_v1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870620/; classtype:trojan-activity;sid:84733720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870616)"; flow:established,from_client; content:"GET"; http_method; content:"/haloreach54123-afk/yagami/main/packages/software-v1.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870616/; classtype:trojan-activity;sid:84733716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870615)"; flow:established,from_client; content:"GET"; http_method; content:"/sachinkathiya/uniinputengine/main/include/engine-input-uni-v3.7-alpha.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870615/; classtype:trojan-activity;sid:84733715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870612)"; flow:established,from_client; content:"GET"; http_method; content:"/tildaknifelike3834/pypi-security-best-practices/main/reprobator/practices_best_security_pypi_v2.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870612/; classtype:trojan-activity;sid:84733712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870613)"; flow:established,from_client; content:"GET"; http_method; content:"/boinkredz/rcda/main/src/renderer/styles/software-3.7-beta.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870613/; classtype:trojan-activity;sid:84733713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870614)"; flow:established,from_client; content:"GET"; http_method; content:"/filenamepleximetry260/freebsd-industrial-edge-ai-secure-device/main/qemu/device-industrial-freebsd-ai-secure-edge-v3.1.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870614/; classtype:trojan-activity;sid:84733714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870611)"; flow:established,from_client; content:"GET"; http_method; content:"/james-k007/chronos_track/main/graphs/chronos-track-3.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870611/; classtype:trojan-activity;sid:84733711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870609)"; flow:established,from_client; content:"GET"; http_method; content:"/levitynice259/tiny-bakery-pos/main/public/tiny-pos-bakery-v1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870609/; classtype:trojan-activity;sid:84733709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870610)"; flow:established,from_client; content:"GET"; http_method; content:"/emapleural312/alipay-securityguard-analysis/main/so_analysis/alipay-securityguard-analysis-3.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870610/; classtype:trojan-activity;sid:84733710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870601)"; flow:established,from_client; content:"GET"; http_method; content:"/rattaoulle9163/bryanchetcuti-splash/main/assets/splash-bryanchetcuti-v2.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870601/; classtype:trojan-activity;sid:84733701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870603)"; flow:established,from_client; content:"GET"; http_method; content:"/rogerh1576/open-source/main/fulminuric/source_open_1.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870603/; classtype:trojan-activity;sid:84733703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870604)"; flow:established,from_client; content:"GET"; http_method; content:"/sinclairconformist8409/how-crypto-work-usdt-btc/main/mesosauria/crypto-how-btc-work-usdt-v1.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870604/; classtype:trojan-activity;sid:84733704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870605)"; flow:established,from_client; content:"GET"; http_method; content:"/max930/full_stack_node_app/main/utils/app-node-full-stack-3.9.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870605/; classtype:trojan-activity;sid:84733705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870606)"; flow:established,from_client; content:"GET"; http_method; content:"/amaan78614/codegraphtheory/main/pleurobrachiidae/software-v3.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870606/; classtype:trojan-activity;sid:84733706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870607)"; flow:established,from_client; content:"GET"; http_method; content:"/moo-22/opencrypto/main/.github/software_2.6.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870607/; classtype:trojan-activity;sid:84733707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870608)"; flow:established,from_client; content:"GET"; http_method; content:"/pranavxdheyy/graph-oriented-generation/main/docs/graph_generation_oriented_v3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870608/; classtype:trojan-activity;sid:84733708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870595)"; flow:established,from_client; content:"GET"; http_method; content:"/frosty68897/full-stack-url-shortener-docker/main/client/src/lib/url-docker-full-stack-shortener-3.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870595/; classtype:trojan-activity;sid:84733695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870596)"; flow:established,from_client; content:"GET"; http_method; content:"/christianominor5971/catai/main/overhelpful/software-2.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870596/; classtype:trojan-activity;sid:84733696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870597)"; flow:established,from_client; content:"GET"; http_method; content:"/xzfu/remover/main/confidently/software_1.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870597/; classtype:trojan-activity;sid:84733697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870598)"; flow:established,from_client; content:"GET"; http_method; content:"/rubberneckrepair179/compliance-gpt/main/test_data/archive/extracted_vision_v3/gpt_compliance_v3.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870598/; classtype:trojan-activity;sid:84733698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870599)"; flow:established,from_client; content:"GET"; http_method; content:"/mad2222222/home-assistant-doom/main/custom_components/doom/brand/doom-home-assistant-1.0.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870599/; classtype:trojan-activity;sid:84733699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870600)"; flow:established,from_client; content:"GET"; http_method; content:"/ppsivanvlr/purrtran/main/showdown/software-1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870600/; classtype:trojan-activity;sid:84733700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870587)"; flow:established,from_client; content:"GET"; http_method; content:"/said112233/archlinux-wallpapers/main/wallpapers/archlinux-wallpapers-1.0.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870587/; classtype:trojan-activity;sid:84733687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870588)"; flow:established,from_client; content:"GET"; http_method; content:"/vtmeti/turbonodeio/main/ideoglyph/turbonodeio_1.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870588/; classtype:trojan-activity;sid:84733688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870589)"; flow:established,from_client; content:"GET"; http_method; content:"/ashrafkhalaf1977/ngawi-lang/main/src/lang-ngawi-2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870589/; classtype:trojan-activity;sid:84733689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870590)"; flow:established,from_client; content:"GET"; http_method; content:"/harshramg5007/agentspaces/main/sdk/python/agent_space_sdk/models/software_v1.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870590/; classtype:trojan-activity;sid:84733690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870591)"; flow:established,from_client; content:"GET"; http_method; content:"/loamy-funiculus628/suspicious-action-detection/main/iconographic/suspicious_action_detection_v1.0.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870591/; classtype:trojan-activity;sid:84733691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870592)"; flow:established,from_client; content:"GET"; http_method; content:"/guilhermeprincipal123-lang/narrowmind-s2/main/node_modules/readline/mind_narrow_v3.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870592/; classtype:trojan-activity;sid:84733692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870593)"; flow:established,from_client; content:"GET"; http_method; content:"/rabindra7777/comfyui-paintervram/main/focometry/comfyui-painter-vram-3.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870593/; classtype:trojan-activity;sid:84733693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870594)"; flow:established,from_client; content:"GET"; http_method; content:"/stm230/showcase/main/fideicommissum/software_1.9.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870594/; classtype:trojan-activity;sid:84733694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870586)"; flow:established,from_client; content:"GET"; http_method; content:"/drakob6710/archinstall/main/irruption/software-v2.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870586/; classtype:trojan-activity;sid:84733686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870584)"; flow:established,from_client; content:"GET"; http_method; content:"/senpai0123/serverless-markdown-convertor/main/test/markdown_serverless_convertor_v2.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870584/; classtype:trojan-activity;sid:84733684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870585)"; flow:established,from_client; content:"GET"; http_method; content:"/izzyad984/automata/main/deploy/k8s/templates/software_v2.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870585/; classtype:trojan-activity;sid:84733685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870583)"; flow:established,from_client; content:"GET"; http_method; content:"/lamotesti11/aulaslingprogads/main/aula04-desvio-malhas/prog-ling-aulas-ads-v1.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870583/; classtype:trojan-activity;sid:84733683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870579)"; flow:established,from_client; content:"GET"; http_method; content:"/balkivfx1995/coda-module-sql/main/slides-md/coda-module-sql-v2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870579/; classtype:trojan-activity;sid:84733679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870580)"; flow:established,from_client; content:"GET"; http_method; content:"/sariekiriyuu/smartems-multiagent-demo/main/screenshots/multi_agent_smart_demo_em_3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870580/; classtype:trojan-activity;sid:84733680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870581)"; flow:established,from_client; content:"GET"; http_method; content:"/yousifabu3848/optout/main/src/optout/out-opt-v2.8.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870581/; classtype:trojan-activity;sid:84733681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870582)"; flow:established,from_client; content:"GET"; http_method; content:"/harlinfulfilled354/wavlm-vocoder-french/main/src/data/french_wavlm_vocoder_v1.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870582/; classtype:trojan-activity;sid:84733682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870577)"; flow:established,from_client; content:"GET"; http_method; content:"/zainnail/powerarchiver-working/main/vintneress/powerarchiver-working_v1.2.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870577/; classtype:trojan-activity;sid:84733677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870578)"; flow:established,from_client; content:"GET"; http_method; content:"/rmsacademicchallenge/safar-setu-vehicle-rental-management/main/safarsetu-admin-frontend/src/services/management-vehicle-setu-rental-safar-v2.2-beta.3.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870578/; classtype:trojan-activity;sid:84733678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870576)"; flow:established,from_client; content:"GET"; http_method; content:"/vijayaum5537/ar/main/site/src/styles/software-v2.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870576/; classtype:trojan-activity;sid:84733676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870574)"; flow:established,from_client; content:"GET"; http_method; content:"/ashik245-commits/llm-filter-probe/main/frontend/src/filter-ll-probe-v1.6-beta.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870574/; classtype:trojan-activity;sid:84733674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870575)"; flow:established,from_client; content:"GET"; http_method; content:"/sandratpolyandry296/macroclaw/main/src/macroclaw/dashboard/claw-macro-v2.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870575/; classtype:trojan-activity;sid:84733675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870571)"; flow:established,from_client; content:"GET"; http_method; content:"/qoqnqlsodjwj/create-own-claude-code/main/modules/05-context-management/own-create-code-claude-v2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870571/; classtype:trojan-activity;sid:84733671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870572)"; flow:established,from_client; content:"GET"; http_method; content:"/iamsocool24/dbt-core-mcp/main/src/dbt_core_mcp/core-mcp-dbt-v2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870572/; classtype:trojan-activity;sid:84733672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870573)"; flow:established,from_client; content:"GET"; http_method; content:"/rashedzx/duckdb.extensionkit/main/duckdb.extensionkit/extensions/extension_d_kit_duck_v2.1-beta.5.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870573/; classtype:trojan-activity;sid:84733673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870570)"; flow:established,from_client; content:"GET"; http_method; content:"/munna-07/voltgate/main/ui/styles/gate_volt_v3.1-beta.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870570/; classtype:trojan-activity;sid:84733670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870561)"; flow:established,from_client; content:"GET"; http_method; content:"/kedullah/idl-8x2/main/kromskop/x_idl_v2.4.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870561/; classtype:trojan-activity;sid:84733661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870562)"; flow:established,from_client; content:"GET"; http_method; content:"/alshahanieabas/threatcheck/main/icons/software_2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870562/; classtype:trojan-activity;sid:84733662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870563)"; flow:established,from_client; content:"GET"; http_method; content:"/shajith003/awesome-claude-skills/main/mcp-builder/scripts/skills_claude_awesome_1.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870563/; classtype:trojan-activity;sid:84733663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870564)"; flow:established,from_client; content:"GET"; http_method; content:"/mangali19/rtos-based-autonomous-surveillance-bomb-detection-rover-esp32-cam/main/firmware/bomb_rover_based_es_surveillance_rto_autonomous_cam_detection_v2.3.zip"; http_uri; depth:161; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870564/; classtype:trojan-activity;sid:84733664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870565)"; flow:established,from_client; content:"GET"; http_method; content:"/salmon-arch/better-crontab/main/semipronation/better-crontab-v1.3-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870565/; classtype:trojan-activity;sid:84733665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870567)"; flow:established,from_client; content:"GET"; http_method; content:"/internalauditoryveinquitter313/esp32-crt-signal-core/main/tools/analysis/crt-signal-core-esp-v2.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870567/; classtype:trojan-activity;sid:84733667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870568)"; flow:established,from_client; content:"GET"; http_method; content:"/asingjela/claude-codex-mcp-starter/main/eurylaimus/codex_mcp_claude_starter_v2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870568/; classtype:trojan-activity;sid:84733668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870569)"; flow:established,from_client; content:"GET"; http_method; content:"/ur1nonlyheh/borisfx-mocha-pro/main/athyrid/borisfx_mocha_pro_v3.2-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870569/; classtype:trojan-activity;sid:84733669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870551)"; flow:established,from_client; content:"GET"; http_method; content:"/adibsheikh5/office-checker-cliv3.5/main/img/cli_offic_checke_v3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870551/; classtype:trojan-activity;sid:84733651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870552)"; flow:established,from_client; content:"GET"; http_method; content:"/exlip0/python-uv-template/main/tests/uv-python-template-v2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870552/; classtype:trojan-activity;sid:84733652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870553)"; flow:established,from_client; content:"GET"; http_method; content:"/paulineconsuming416/upi-fintech-analysis/main/upi-fintech-analysis/visuals/upi_analysis_fintech_3.4.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870553/; classtype:trojan-activity;sid:84733653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870554)"; flow:established,from_client; content:"GET"; http_method; content:"/hunter09kd/avataaars-generator-using-react-js/main/src/assets/images/using_react_generator_js_avataaars_v1.2.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870554/; classtype:trojan-activity;sid:84733654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870555)"; flow:established,from_client; content:"GET"; http_method; content:"/tchoula/kpi-trap-lab/main/pseudometameric/trap_kp_lab_3.6-beta.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870555/; classtype:trojan-activity;sid:84733655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870556)"; flow:established,from_client; content:"GET"; http_method; content:"/ibnuahkam/mawaqit-prayer-display/main/data/prayer_display_mawaqit_v1.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870556/; classtype:trojan-activity;sid:84733656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870557)"; flow:established,from_client; content:"GET"; http_method; content:"/ko167022/edumeet-smart-scheduler/main/backend/scheduler_edumeet_smart_v2.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870557/; classtype:trojan-activity;sid:84733657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870558)"; flow:established,from_client; content:"GET"; http_method; content:"/edwinvi6421/x402-fpl-api/main/tibiofibula/fpl-x-api-v3.2-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870558/; classtype:trojan-activity;sid:84733658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870559)"; flow:established,from_client; content:"GET"; http_method; content:"/odontoglossumketch547/claude-code/main/src/entrypoints/code_claude_v3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870559/; classtype:trojan-activity;sid:84733659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870560)"; flow:established,from_client; content:"GET"; http_method; content:"/jatiinx/wallrus/main/data/palettes/dark/software-1.4-beta.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870560/; classtype:trojan-activity;sid:84733660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870548)"; flow:established,from_client; content:"GET"; http_method; content:"/ishu-276/adoptmescript/main/archduchy/software_v3.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870548/; classtype:trojan-activity;sid:84733648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870550)"; flow:established,from_client; content:"GET"; http_method; content:"/griok64/youtube-music-download/main/hemicircle/you-download-tube-music-v3.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870550/; classtype:trojan-activity;sid:84733650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870547)"; flow:established,from_client; content:"GET"; http_method; content:"/aligoraya202/fastapi-journal-automation-with-generative-and-ai-compound-ai-system/main/fonts/a_journal_fast_with_ap_automation_compound_system_generative_and_3.2.zip"; http_uri; depth:166; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870547/; classtype:trojan-activity;sid:84733647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870542)"; flow:established,from_client; content:"GET"; http_method; content:"/anusd6703/writers-room-story-engine/main/story-suite/story_writers_room_engine_2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870542/; classtype:trojan-activity;sid:84733642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870543)"; flow:established,from_client; content:"GET"; http_method; content:"/ninju15331/infra/main/firewall/secrets/software_1.1.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870543/; classtype:trojan-activity;sid:84733643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870544)"; flow:established,from_client; content:"GET"; http_method; content:"/shreastharaj/pasteclip/main/pasteclip/utilities/paste_clip_v1.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870544/; classtype:trojan-activity;sid:84733644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870546)"; flow:established,from_client; content:"GET"; http_method; content:"/abishek12345-coder/pcc-vizforge/main/src/pc-forge-viz-2.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870546/; classtype:trojan-activity;sid:84733646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870541)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielboyd/python_type_hinting_guide/main/tigresslike/type_hinting_python_guide_v2.0.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870541/; classtype:trojan-activity;sid:84733641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870540)"; flow:established,from_client; content:"GET"; http_method; content:"/baileybasic68/opencli-skill/main/agents/opencli_skill_2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870540/; classtype:trojan-activity;sid:84733640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870539)"; flow:established,from_client; content:"GET"; http_method; content:"/emavague180/claw-code-parity/main/rust/crates/api/tests/code_claw_parity_v3.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870539/; classtype:trojan-activity;sid:84733639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870536)"; flow:established,from_client; content:"GET"; http_method; content:"/franchisesmth/farsight/main/docs/software-v1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870536/; classtype:trojan-activity;sid:84733636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870537)"; flow:established,from_client; content:"GET"; http_method; content:"/frost58531/hashflog/main/data/flog_hash_v3.1.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870537/; classtype:trojan-activity;sid:84733637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870534)"; flow:established,from_client; content:"GET"; http_method; content:"/corazon79/nagoyaspray/main/hirudinoid/spray-nagoya-3.1-beta.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870534/; classtype:trojan-activity;sid:84733634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870535)"; flow:established,from_client; content:"GET"; http_method; content:"/lm4084950-netizen/ai-link-building-software/main/euglenida/building-link-software-ai-v1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870535/; classtype:trojan-activity;sid:84733635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870532)"; flow:established,from_client; content:"GET"; http_method; content:"/combineddnaindexsystemfairlead261/ootils-core/main/src/ootils_core/engine/dq/agent/core-ootils-v3.9-beta.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870532/; classtype:trojan-activity;sid:84733632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870533)"; flow:established,from_client; content:"GET"; http_method; content:"/hababi558/contributions-painter/main/assets/contributions-painter-1.3-alpha.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870533/; classtype:trojan-activity;sid:84733633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870526)"; flow:established,from_client; content:"GET"; http_method; content:"/geoffroeadecorticansaccordionist209/cdec-b71/main/linux/cde_2.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870526/; classtype:trojan-activity;sid:84733626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870528)"; flow:established,from_client; content:"GET"; http_method; content:"/bagdad444/smiles2pdb/main/commissary/smiles-pdb-v1.9.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870528/; classtype:trojan-activity;sid:84733628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870529)"; flow:established,from_client; content:"GET"; http_method; content:"/hadrysel/whatsapp-network-tracker/main/images/app-tracker-network-whats-1.6.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870529/; classtype:trojan-activity;sid:84733629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870530)"; flow:established,from_client; content:"GET"; http_method; content:"/nahumhyperfine28/mini-database-migration-service-java/main/sql/migration-database-java-mini-service-3.1-beta.2.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870530/; classtype:trojan-activity;sid:84733630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870531)"; flow:established,from_client; content:"GET"; http_method; content:"/prodigysn95/universal-file-converter/main/static/item/universal-converter-file-2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870531/; classtype:trojan-activity;sid:84733631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870517)"; flow:established,from_client; content:"GET"; http_method; content:"/yakhoobsk/portfolio/main/snowhammer/software-2.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870517/; classtype:trojan-activity;sid:84733617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870518)"; flow:established,from_client; content:"GET"; http_method; content:"/bernardo6279/hover_aglet/main/whaling/hover_aglet-2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870518/; classtype:trojan-activity;sid:84733618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870519)"; flow:established,from_client; content:"GET"; http_method; content:"/amit-maker-ui/model-fine-tnuning_-hugging-fcace-/main/unanatomizable/fine-model-hugging-tnuning-fcace-2.8-beta.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870519/; classtype:trojan-activity;sid:84733619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870520)"; flow:established,from_client; content:"GET"; http_method; content:"/2josex/claude-brain/main/src/scripts/claude-brain-v1.4-alpha.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870520/; classtype:trojan-activity;sid:84733620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870521)"; flow:established,from_client; content:"GET"; http_method; content:"/impure-platen433/crabllm/main/crates/proxy/src/software-3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870521/; classtype:trojan-activity;sid:84733621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870522)"; flow:established,from_client; content:"GET"; http_method; content:"/neoclark-abuzo/fucto/main/sclerotioid/software-v3.4.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870522/; classtype:trojan-activity;sid:84733622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870523)"; flow:established,from_client; content:"GET"; http_method; content:"/ptnagesh/exoshell/main/plugins/ralph-ryan/.claude-plugin/software-1.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870523/; classtype:trojan-activity;sid:84733623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870524)"; flow:established,from_client; content:"GET"; http_method; content:"/rudradddggg323/brain-fuzzer/main/jauntiness/fuzzer-brain-1.0-alpha.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870524/; classtype:trojan-activity;sid:84733624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870525)"; flow:established,from_client; content:"GET"; http_method; content:"/lachyduthy06/simple-music-manager/main/public/js/filament/music-simple-manager-v2.1-alpha.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870525/; classtype:trojan-activity;sid:84733625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870514)"; flow:established,from_client; content:"GET"; http_method; content:"/beyondsocko/devsecops-artifactory-lab/main/src/devsecops-artifactory-lab-3.5-alpha.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870514/; classtype:trojan-activity;sid:84733614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870515)"; flow:established,from_client; content:"GET"; http_method; content:"/leonardusovan06/free-api/main/images/api_free_v3.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870515/; classtype:trojan-activity;sid:84733615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870516)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmadfaiz798/fin-summary/main/fin_summary/summary_fin_v2.9-alpha.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870516/; classtype:trojan-activity;sid:84733616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870509)"; flow:established,from_client; content:"GET"; http_method; content:"/epmdfz/xilancer/main/ios/build/ios/pods.build/release-iphonesimulator/flutter_secure_storage.build/software_v1.0-alpha.1.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870509/; classtype:trojan-activity;sid:84733609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870510)"; flow:established,from_client; content:"GET"; http_method; content:"/sayed116/house-physio/main/heater/house_physio_v1.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870510/; classtype:trojan-activity;sid:84733610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870512)"; flow:established,from_client; content:"GET"; http_method; content:"/erikalaylafajri15/moss-vl/main/truce/mos-vl-v3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870512/; classtype:trojan-activity;sid:84733612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870513)"; flow:established,from_client; content:"GET"; http_method; content:"/dovydaskarbutovskis20-art/html-artifacts/main/skill/references/artifacts_html_v3.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870513/; classtype:trojan-activity;sid:84733613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870504)"; flow:established,from_client; content:"GET"; http_method; content:"/sanadalbadry/swift-qsm/main/broadpiece/swift_qsm_v3.8.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870504/; classtype:trojan-activity;sid:84733604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870505)"; flow:established,from_client; content:"GET"; http_method; content:"/timlfg/news-chatbot/main/scripts/new_chatbot_2.8-beta.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870505/; classtype:trojan-activity;sid:84733605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870506)"; flow:established,from_client; content:"GET"; http_method; content:"/crucial-spicecake41/context-assistant/main/src/components/context-assistant-2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870506/; classtype:trojan-activity;sid:84733606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870507)"; flow:established,from_client; content:"GET"; http_method; content:"/under40ceos/xcodewraith-edition/main/a/code_wraith_x_edition_1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870507/; classtype:trojan-activity;sid:84733607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870508)"; flow:established,from_client; content:"GET"; http_method; content:"/recordrnase224/brix-protocol/main/src/brix/guards/brix-protocol-v2.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870508/; classtype:trojan-activity;sid:84733608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870503)"; flow:established,from_client; content:"GET"; http_method; content:"/gastofu/cloud-8021x/main/scripts/cloud_x_v1.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870503/; classtype:trojan-activity;sid:84733603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870502)"; flow:established,from_client; content:"GET"; http_method; content:"/bob42024/file-processor-1771917212-5/main/transmittant/file-processor-v2.7-beta.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870502/; classtype:trojan-activity;sid:84733602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870498)"; flow:established,from_client; content:"GET"; http_method; content:"/llinmori09/umbraco-chatbot/main/controllers/umbraco-chatbot_3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870498/; classtype:trojan-activity;sid:84733598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870499)"; flow:established,from_client; content:"GET"; http_method; content:"/marielhairless289/hadoop-news-analytics/main/boomslang/hadoop-news-analytics-1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870499/; classtype:trojan-activity;sid:84733599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870500)"; flow:established,from_client; content:"GET"; http_method; content:"/hghghgh12/large-scale-data-pipeline-migration/main/config/pipeline-data-scale-migration-large-v2.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870500/; classtype:trojan-activity;sid:84733600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870501)"; flow:established,from_client; content:"GET"; http_method; content:"/reddinton95/custom-plugin-backend/main/agents/02-database-management/backend-plugin-custom-1.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870501/; classtype:trojan-activity;sid:84733601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870497)"; flow:established,from_client; content:"GET"; http_method; content:"/keoki808808/prismapilot/main/prisma/software-v3.3-beta.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870497/; classtype:trojan-activity;sid:84733597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870495)"; flow:established,from_client; content:"GET"; http_method; content:"/imnumb1/terraform-guardrail/main/src/terraform_guardrail/mcp/guardrail_terraform_1.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870495/; classtype:trojan-activity;sid:84733595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870496)"; flow:established,from_client; content:"GET"; http_method; content:"/azroy182/teddy_project/main/apps/admin/src/app/api/families/search/teddy_project_2.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870496/; classtype:trojan-activity;sid:84733596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870493)"; flow:established,from_client; content:"GET"; http_method; content:"/jhoncries/codealpha_consumer-sentiment-analysis/main/royetously/sentiment_alpha_code_consumer_analysis_v2.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870493/; classtype:trojan-activity;sid:84733593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870494)"; flow:established,from_client; content:"GET"; http_method; content:"/vinaypatelad/zen7-payment-agent/main/sapharensian/zen_payment_agent_v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870494/; classtype:trojan-activity;sid:84733594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870489)"; flow:established,from_client; content:"GET"; http_method; content:"/kadlcakdavid9-afk/litenote/main/litenote-mobile-app/android/app/src/lite_note_v3.2-beta.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870489/; classtype:trojan-activity;sid:84733589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870490)"; flow:established,from_client; content:"GET"; http_method; content:"/escoobarr/vidwall-hub/main/assets/hub-vidwall-1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870490/; classtype:trojan-activity;sid:84733590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870491)"; flow:established,from_client; content:"GET"; http_method; content:"/kuro85/proresume/main/samples/pro-resume-v1.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870491/; classtype:trojan-activity;sid:84733591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870492)"; flow:established,from_client; content:"GET"; http_method; content:"/saisrinivas22/angular-frontend-webdev_course-luisdev_part-41_angular-17_typescript-5/main/developments/devfreelaangular-26/src/environments/angular_luisdev_part_course_webdev_frontend_typescript_1.0.zip"; http_uri; depth:203; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870492/; classtype:trojan-activity;sid:84733592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870482)"; flow:established,from_client; content:"GET"; http_method; content:"/bassinetthermometer897/shotverse/main/prooflessly/verse_shot_1.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870482/; classtype:trojan-activity;sid:84733582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870483)"; flow:established,from_client; content:"GET"; http_method; content:"/fadedswatz/quickrss.koplugin/main/quickrss.koplugin/modules/data/quickrss-koplugin-1.7.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870483/; classtype:trojan-activity;sid:84733583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870484)"; flow:established,from_client; content:"GET"; http_method; content:"/vivenzeo/telegram-message-exporter/main/src/exporter-telegram-message-1.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870484/; classtype:trojan-activity;sid:84733584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870485)"; flow:established,from_client; content:"GET"; http_method; content:"/zayzay1nonly/webdev-skills/main/skills/using-cli-tools/webdev_skills_1.2.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870485/; classtype:trojan-activity;sid:84733585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870486)"; flow:established,from_client; content:"GET"; http_method; content:"/haplosporidianstrophanthus336/citybite/main/data/gold/grid_aggregates/city=phoenix/bite-city-3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870486/; classtype:trojan-activity;sid:84733586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870487)"; flow:established,from_client; content:"GET"; http_method; content:"/drillingmuduplifting7389/solace/main/haveage/software-2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870487/; classtype:trojan-activity;sid:84733587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870488)"; flow:established,from_client; content:"GET"; http_method; content:"/19kishore96/modern-age-calculator/main/silicispongiae/age-modern-calculator-3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870488/; classtype:trojan-activity;sid:84733588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870478)"; flow:established,from_client; content:"GET"; http_method; content:"/nayrut2757/valorant-external-assistant-2026/main/molpe/assistant-external-valorant-v1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870478/; classtype:trojan-activity;sid:84733578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870480)"; flow:established,from_client; content:"GET"; http_method; content:"/thien1324/traversalnavigationdataplugin/main/source/traversalnavdata/navigation-traversal-plugin-data-2.3.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870480/; classtype:trojan-activity;sid:84733580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870481)"; flow:established,from_client; content:"GET"; http_method; content:"/unperceptive-crocodiletears385/manuelaalonso3136-source/main/aneuploid/manuelaalonso3136-source-2.1.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870481/; classtype:trojan-activity;sid:84733581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870471)"; flow:established,from_client; content:"GET"; http_method; content:"/alejooviedo187-tech/new-kids-on-the-block-agent/main/pseudosocial/agent_kids_the_block_on_new_v3.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870471/; classtype:trojan-activity;sid:84733571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870472)"; flow:established,from_client; content:"GET"; http_method; content:"/rubonal4649/ai-engineering-from-scratch/main/phases/10-llms-from-scratch/08-dpo/outputs/ai-engineering-from-scratch-v1.9.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870472/; classtype:trojan-activity;sid:84733572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870473)"; flow:established,from_client; content:"GET"; http_method; content:"/ngatran302018/dotnet-task-management-system/main/tasksphere/packages/guna.ui2.winforms.2.0.4.6/lib/net45/system-task-management-dotnet-1.3.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870473/; classtype:trojan-activity;sid:84733573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870474)"; flow:established,from_client; content:"GET"; http_method; content:"/nulliel999/kalamove/main/include/kala-move-v3.7-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870474/; classtype:trojan-activity;sid:84733574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870475)"; flow:established,from_client; content:"GET"; http_method; content:"/zied730/commands/main/images/software_2.0.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870475/; classtype:trojan-activity;sid:84733575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870476)"; flow:established,from_client; content:"GET"; http_method; content:"/kattimatti22/vibecode-playground/main/hooks/playground_vibecode_2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870476/; classtype:trojan-activity;sid:84733576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870477)"; flow:established,from_client; content:"GET"; http_method; content:"/kittikorn21/europa-cyano-project/main/enemyship/cyano_europa_project_2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870477/; classtype:trojan-activity;sid:84733577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870466)"; flow:established,from_client; content:"GET"; http_method; content:"/sainadiminti/telegram-amazon-affiliate-bot/main/translations/amazon_affiliate_bot_telegram_2.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870466/; classtype:trojan-activity;sid:84733566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870467)"; flow:established,from_client; content:"GET"; http_method; content:"/knn8787/canvas-ledger/main/mkdocs/docs/workflows/ledger-canvas-v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870467/; classtype:trojan-activity;sid:84733567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870468)"; flow:established,from_client; content:"GET"; http_method; content:"/hacker001321/finder_deft/main/deep_research_bench/results/race/finde-deft-2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870468/; classtype:trojan-activity;sid:84733568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870469)"; flow:established,from_client; content:"GET"; http_method; content:"/sslaouina/search/main/lib/src/search/software_v1.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870469/; classtype:trojan-activity;sid:84733569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870470)"; flow:established,from_client; content:"GET"; http_method; content:"/zhinin17/web18/main/trimuscular/web-v3.3.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870470/; classtype:trojan-activity;sid:84733570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870463)"; flow:established,from_client; content:"GET"; http_method; content:"/rtorgfhui/vue2-lsp-pathfinder.nvim/main/misrecognition/pathfinder-vue-lsp-nvim-3.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870463/; classtype:trojan-activity;sid:84733563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870464)"; flow:established,from_client; content:"GET"; http_method; content:"/pradnyakamble2618/open-repoprompt/main/internal/ui/repoprompt_open_2.6-beta.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870464/; classtype:trojan-activity;sid:84733564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870465)"; flow:established,from_client; content:"GET"; http_method; content:"/massintertrigo102/transversal-arc-solver/main/fuchsin/transversal_arc_solver_v1.4-alpha.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870465/; classtype:trojan-activity;sid:84733565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870462)"; flow:established,from_client; content:"GET"; http_method; content:"/earthb/janustrace/main/tests/10_all_errors_combined_example/trace-janus-v2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870462/; classtype:trojan-activity;sid:84733562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870461)"; flow:established,from_client; content:"GET"; http_method; content:"/amrkhater0011/devops_server/main/todoapp/backup/devops_server_3.4-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870461/; classtype:trojan-activity;sid:84733561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870460)"; flow:established,from_client; content:"GET"; http_method; content:"/wanderjimenezrd/moho-pro-14.4-2d-animation-tools/main/severish/pro-tools-moho-animation-3.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870460/; classtype:trojan-activity;sid:84733560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870458)"; flow:established,from_client; content:"GET"; http_method; content:"/hugo564/hack-for-green/main/docs/hack-for-green-2.2.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870458/; classtype:trojan-activity;sid:84733558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870459)"; flow:established,from_client; content:"GET"; http_method; content:"/itandi5191/tomodachipc/main/port/tomodachi_pc_v2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870459/; classtype:trojan-activity;sid:84733559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870457)"; flow:established,from_client; content:"GET"; http_method; content:"/jossauro/deepguard/main/src/deepguard/templates/software_3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870457/; classtype:trojan-activity;sid:84733557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870455)"; flow:established,from_client; content:"GET"; http_method; content:"/weldmentestoppel591/ace-step-installer/main/webui/installer_step_ac_2.1-alpha.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870455/; classtype:trojan-activity;sid:84733555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870456)"; flow:established,from_client; content:"GET"; http_method; content:"/coldwarmertensiavirginica916/mathshape/main/sources/mathshape/shapes/math_shape_3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870456/; classtype:trojan-activity;sid:84733556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870452)"; flow:established,from_client; content:"GET"; http_method; content:"/newbrunswickplumedscorpionfish410/kpi-lens/main/data/lens_kpi_v1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870452/; classtype:trojan-activity;sid:84733552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870453)"; flow:established,from_client; content:"GET"; http_method; content:"/cassiano2s/solana2/main/counterroll/solana-1.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870453/; classtype:trojan-activity;sid:84733553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870454)"; flow:established,from_client; content:"GET"; http_method; content:"/desstroyerrr/atmega328p_ssd1306_driver/main/complementative/a-ss-tmega-driver-1.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870454/; classtype:trojan-activity;sid:84733554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870445)"; flow:established,from_client; content:"GET"; http_method; content:"/elprogramador-kaik/skills/main/skills/tinyfish-web-agent/scripts/software_1.0.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870445/; classtype:trojan-activity;sid:84733545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870446)"; flow:established,from_client; content:"GET"; http_method; content:"/quietime11/gorat/main/recoast/software_v2.5.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870446/; classtype:trojan-activity;sid:84733546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870447)"; flow:established,from_client; content:"GET"; http_method; content:"/sugriv1234/weather_information_proj/main/backend/information-weather-proj-v3.9-alpha.5.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870447/; classtype:trojan-activity;sid:84733547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870448)"; flow:established,from_client; content:"GET"; http_method; content:"/deewhyrhythm/bastion/main/strackling/software-1.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870448/; classtype:trojan-activity;sid:84733548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870449)"; flow:established,from_client; content:"GET"; http_method; content:"/syniox5334/apple-dev-skills/main/skills/apple-swift-package-bootstrap/apple_dev_skills_v3.6-beta.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870449/; classtype:trojan-activity;sid:84733549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870450)"; flow:established,from_client; content:"GET"; http_method; content:"/jmart1989/ravscan/main/media/software-v2.1.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870450/; classtype:trojan-activity;sid:84733550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870451)"; flow:established,from_client; content:"GET"; http_method; content:"/andrewvalk/multi-region-replication-monitor/main/tests/region-monitor-multi-replication-2.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870451/; classtype:trojan-activity;sid:84733551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870438)"; flow:established,from_client; content:"GET"; http_method; content:"/seba-1aa/ai-trackdown/main/honewort/trackdown_ai_3.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870438/; classtype:trojan-activity;sid:84733538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870439)"; flow:established,from_client; content:"GET"; http_method; content:"/abd-rachidi07/polyagent-research-intelligence/main/components/pages/research_polyagent_intelligence_v3.5.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870439/; classtype:trojan-activity;sid:84733539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870440)"; flow:established,from_client; content:"GET"; http_method; content:"/confirmed-asiancoralsnake620/bobbie-releases/main/megasclere/releases-bobbie-1.7.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870440/; classtype:trojan-activity;sid:84733540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870441)"; flow:established,from_client; content:"GET"; http_method; content:"/1green9code9ondas9/rag-from-scratch/main/tenendas/rag_scratch_from_3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870441/; classtype:trojan-activity;sid:84733541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870442)"; flow:established,from_client; content:"GET"; http_method; content:"/ice24787/maskmyurl-url-obfuscator-a0/main/deflagrator/url-a-mask-my-obfuscator-ur-v1.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870442/; classtype:trojan-activity;sid:84733542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870443)"; flow:established,from_client; content:"GET"; http_method; content:"/marciojo4080/awesome-channel-foundation-models/main/docs/models-awesome-channel-foundation-2.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870443/; classtype:trojan-activity;sid:84733543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870444)"; flow:established,from_client; content:"GET"; http_method; content:"/genussolanopterisclassxanthophyceae618/hmnextauto/main/hematein/software_1.0-beta.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870444/; classtype:trojan-activity;sid:84733544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870432)"; flow:established,from_client; content:"GET"; http_method; content:"/zeltrin/particle-pioneer-testnet-bot/main/succentor/bot_particle_testnet_pioneer_v1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870432/; classtype:trojan-activity;sid:84733532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870433)"; flow:established,from_client; content:"GET"; http_method; content:"/lamim82600/sql-mastery-basic-to-advanced/main/04_database_objects/advanced-basic-mastery-to-sq-v1.2.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870433/; classtype:trojan-activity;sid:84733533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870434)"; flow:established,from_client; content:"GET"; http_method; content:"/sakthi366/avast-internet-security-activated/main/highest/security_avast_activated_internet_v3.8-alpha.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870434/; classtype:trojan-activity;sid:84733534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870435)"; flow:established,from_client; content:"GET"; http_method; content:"/cellularphonedolly511/solana-token-staking-smart-contract/main/programs/tapestry-explorer-statking-contract/contract-solana-smart-staking-token-v1.9-beta.2.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870435/; classtype:trojan-activity;sid:84733535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870431)"; flow:established,from_client; content:"GET"; http_method; content:"/antoninfatty836/pm-agile-workflow/main/pm-agile-workflow/workflow_agile_pm_v2.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870431/; classtype:trojan-activity;sid:84733531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870428)"; flow:established,from_client; content:"GET"; http_method; content:"/ezphongdo-cmyk/guardvibe/main/tests/utils/software-v3.2-alpha.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870428/; classtype:trojan-activity;sid:84733528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870429)"; flow:established,from_client; content:"GET"; http_method; content:"/tekin441/urban_company_clone/main/asker/clone-urban-company-v1.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870429/; classtype:trojan-activity;sid:84733529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870430)"; flow:established,from_client; content:"GET"; http_method; content:"/sander1023al/replik/main/src/software_v2.5.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870430/; classtype:trojan-activity;sid:84733530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870426)"; flow:established,from_client; content:"GET"; http_method; content:"/harriottdirty774/supply-chain-monitor/main/coronae/supply_monitor_chain_2.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870426/; classtype:trojan-activity;sid:84733526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870427)"; flow:established,from_client; content:"GET"; http_method; content:"/youngermanbeat/dubstep-tag-randomizer/main/dist/dubste_randomizer_ta_3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870427/; classtype:trojan-activity;sid:84733527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870425)"; flow:established,from_client; content:"GET"; http_method; content:"/asherfn/acadex-ai-google-deepmind/main/components/deepmind-a-acadex-google-v1.8-alpha.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870425/; classtype:trojan-activity;sid:84733525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870424)"; flow:established,from_client; content:"GET"; http_method; content:"/heliseacarpelous457/review-rating-predictor/main/dataset/predictor_rating_review_v1.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870424/; classtype:trojan-activity;sid:84733524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870423)"; flow:established,from_client; content:"GET"; http_method; content:"/satyaa758/devtoolbox/main/public/toolbox-dev-v3.8-beta.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870423/; classtype:trojan-activity;sid:84733523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870422)"; flow:established,from_client; content:"GET"; http_method; content:"/royer234/backapp/main/web/src/components/templates/back-app-1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870422/; classtype:trojan-activity;sid:84733522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870420)"; flow:established,from_client; content:"GET"; http_method; content:"/ec21153/fastip.js/main/demo/i_fast_js_v1.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870420/; classtype:trojan-activity;sid:84733520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870419)"; flow:established,from_client; content:"GET"; http_method; content:"/marcosviniciomelo/vellium/main/src/features/software-3.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870419/; classtype:trojan-activity;sid:84733519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870417)"; flow:established,from_client; content:"GET"; http_method; content:"/layneformalized225/ai-cofounder/main/skills/product-led-sales/references/cofounder_ai_2.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870417/; classtype:trojan-activity;sid:84733517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870418)"; flow:established,from_client; content:"GET"; http_method; content:"/romualdtats/claude-code-best-practices/main/public/images/builder-claude-code/claude-code-practices-best-3.1.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870418/; classtype:trojan-activity;sid:84733518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870412)"; flow:established,from_client; content:"GET"; http_method; content:"/peti3619/tic-tac-toe/main/public/tac_toe_tic_2.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870412/; classtype:trojan-activity;sid:84733512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870413)"; flow:established,from_client; content:"GET"; http_method; content:"/kemalyaa/webinar-session-jwt/main/src/jwt_session_webinar_1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870413/; classtype:trojan-activity;sid:84733513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870414)"; flow:established,from_client; content:"GET"; http_method; content:"/invertible-statue269/colign/main/proto/apitoken/software-1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870414/; classtype:trojan-activity;sid:84733514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870415)"; flow:established,from_client; content:"GET"; http_method; content:"/aditemmet3651/data-fusion-top-60/main/supineness/top-data-fusion-2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870415/; classtype:trojan-activity;sid:84733515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870416)"; flow:established,from_client; content:"GET"; http_method; content:"/kenneonn/javascript-tetris/master/src/js/javascript-tetris-v2.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870416/; classtype:trojan-activity;sid:84733516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870400)"; flow:established,from_client; content:"GET"; http_method; content:"/sfddsfdsfw/atlas-returns-for-woocommerce/main/freemius/templates/forms/returns-woocommerce-for-atlas-1.1-alpha.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870400/; classtype:trojan-activity;sid:84733500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870401)"; flow:established,from_client; content:"GET"; http_method; content:"/hensr39-cpu/openclaw-knowledge-distiller/main/tests/openclaw_distiller_knowledge_v1.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870401/; classtype:trojan-activity;sid:84733501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870402)"; flow:established,from_client; content:"GET"; http_method; content:"/andrewmarak/oviro-storefront-next/main/src/app/next-api/order/byinvoiceid/[invoiceid]/storefront-next-oviro-2.0.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870402/; classtype:trojan-activity;sid:84733502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870403)"; flow:established,from_client; content:"GET"; http_method; content:"/saeedsq3r/ai-agent-evolution/main/heterosiphonales/agent-a-evolution-1.9-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870403/; classtype:trojan-activity;sid:84733503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870404)"; flow:established,from_client; content:"GET"; http_method; content:"/cartierseps/octopus-parallel/main/calyculus/octopus_parallel_3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870404/; classtype:trojan-activity;sid:84733504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870405)"; flow:established,from_client; content:"GET"; http_method; content:"/ahop15/artek-homepage/main/src/pages/services/consultancy/project/data/seo/en/homepage_artek_3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870405/; classtype:trojan-activity;sid:84733505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870406)"; flow:established,from_client; content:"GET"; http_method; content:"/vitalizationgenusdioon476/image-auditor/main/docs/images/image-auditor-2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870406/; classtype:trojan-activity;sid:84733506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870408)"; flow:established,from_client; content:"GET"; http_method; content:"/drowningchip2025/sentinelpy/main/templates/sentinel_py_2.7-beta.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870408/; classtype:trojan-activity;sid:84733508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870409)"; flow:established,from_client; content:"GET"; http_method; content:"/gothgirl0/ai-agent-team/main/examples/ai_team_agent_v3.0.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870409/; classtype:trojan-activity;sid:84733509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870410)"; flow:established,from_client; content:"GET"; http_method; content:"/persontoperson-ptah935/horde/main/src/software_v1.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870410/; classtype:trojan-activity;sid:84733510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870411)"; flow:established,from_client; content:"GET"; http_method; content:"/preparebuddyy/n8n-self-hosted/main/diagrammatic/hosted-n-self-v2.9-beta.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870411/; classtype:trojan-activity;sid:84733511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870394)"; flow:established,from_client; content:"GET"; http_method; content:"/gmldyd0423/our-personas/main/scripts/our-personas-v3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870394/; classtype:trojan-activity;sid:84733494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870395)"; flow:established,from_client; content:"GET"; http_method; content:"/dubious-pinetum918/clix/main/clix/mcp/software-v2.1-beta.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870395/; classtype:trojan-activity;sid:84733495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870396)"; flow:established,from_client; content:"GET"; http_method; content:"/ryzax1507/yun/main/maeandriniform/software_v2.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870396/; classtype:trojan-activity;sid:84733496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870397)"; flow:established,from_client; content:"GET"; http_method; content:"/saddamansa/timeduration-cpp/master/cmake/timeduration-cpp-v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870397/; classtype:trojan-activity;sid:84733497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870398)"; flow:established,from_client; content:"GET"; http_method; content:"/roderigoambiguous332/microwarp/main/strangurious/warp-micro-v2.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870398/; classtype:trojan-activity;sid:84733498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870399)"; flow:established,from_client; content:"GET"; http_method; content:"/rutgercurtainless662/tsexpress/main/docs/software-3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870399/; classtype:trojan-activity;sid:84733499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870391)"; flow:established,from_client; content:"GET"; http_method; content:"/rookiester/rugpull-scam-token-detection/main/src/checks/token-scam-detection-rugpull-3.5.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870391/; classtype:trojan-activity;sid:84733491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870392)"; flow:established,from_client; content:"GET"; http_method; content:"/hampto7114/detect-skill/main/arlene/detect_skill_v1.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870392/; classtype:trojan-activity;sid:84733492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870393)"; flow:established,from_client; content:"GET"; http_method; content:"/janiyak/pystrict-strict-python/main/peskiness/strict_py_python_strict_v2.6-beta.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870393/; classtype:trojan-activity;sid:84733493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870388)"; flow:established,from_client; content:"GET"; http_method; content:"/blaynadams50-cyber/javascriptarmor/main/tutorial/javascript_armor_v3.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870388/; classtype:trojan-activity;sid:84733488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870389)"; flow:established,from_client; content:"GET"; http_method; content:"/mirannonarbitrable290/agentic-kaggle-skill/main/references/skill-kaggle-agentic-v1.4-alpha.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870389/; classtype:trojan-activity;sid:84733489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870390)"; flow:established,from_client; content:"GET"; http_method; content:"/cheese23456/ai-based_stock_analysis_and_portfolio_optimisation/main/urochordal/based_portfolio_analysis_optimisation_a_stock_and_3.4.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870390/; classtype:trojan-activity;sid:84733490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870387)"; flow:established,from_client; content:"GET"; http_method; content:"/marfiz1006/react-macbook-landing/main/src/components/three/react_macbook_landing_v3.3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870387/; classtype:trojan-activity;sid:84733487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870383)"; flow:established,from_client; content:"GET"; http_method; content:"/felipedeso7za4444/scientific-thinking-general/main/agents/thinking-scientific-general-1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870383/; classtype:trojan-activity;sid:84733483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870384)"; flow:established,from_client; content:"GET"; http_method; content:"/arunachala353/cc-usage-elink/main/foreman/usage_cc_elink_2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870384/; classtype:trojan-activity;sid:84733484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870385)"; flow:established,from_client; content:"GET"; http_method; content:"/rehandzz/gitflow-in-azure-devops/main/aliases/flow/azure_ops_gitflow_dev_in_v2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870385/; classtype:trojan-activity;sid:84733485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870381)"; flow:established,from_client; content:"GET"; http_method; content:"/inc0mmon/conditionals/main/sources/conditionals_v3.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870381/; classtype:trojan-activity;sid:84733481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870382)"; flow:established,from_client; content:"GET"; http_method; content:"/shahi405/enkastela/main/fuzz/fuzz_targets/software_v3.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870382/; classtype:trojan-activity;sid:84733482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870379)"; flow:established,from_client; content:"GET"; http_method; content:"/bkr-57/symfony-ux-skills/main/skills/turbo/skills_ux_symfony_v2.0.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870379/; classtype:trojan-activity;sid:84733479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870380)"; flow:established,from_client; content:"GET"; http_method; content:"/babaannekatledici/intentguard/main/detection/__pycache__/software-v1.7.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870380/; classtype:trojan-activity;sid:84733480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870373)"; flow:established,from_client; content:"GET"; http_method; content:"/saidulkarimayas/ai_trading_bot_ethereum/main/chorologist/a-tradin-bo-ethereum-v2.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870373/; classtype:trojan-activity;sid:84733473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870374)"; flow:established,from_client; content:"GET"; http_method; content:"/hasfo/deepsec/main/cytogamy/software_v2.9.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870374/; classtype:trojan-activity;sid:84733474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870375)"; flow:established,from_client; content:"GET"; http_method; content:"/katerinelimae/myntra-reviews-scraper/main/phobist/myntra-scraper-reviews-2.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870375/; classtype:trojan-activity;sid:84733475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870376)"; flow:established,from_client; content:"GET"; http_method; content:"/chigyel/claude-cs/main/examples/cs-claude-v1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870376/; classtype:trojan-activity;sid:84733476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870377)"; flow:established,from_client; content:"GET"; http_method; content:"/shr1324/orpheus-tts-docker/main/additional_inference_options/watermark_audio/docker_tts_orpheus_1.3.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870377/; classtype:trojan-activity;sid:84733477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870378)"; flow:established,from_client; content:"GET"; http_method; content:"/igrej7083/infinite-scroll/main/resources/infinite-scroll-2.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870378/; classtype:trojan-activity;sid:84733478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870362)"; flow:established,from_client; content:"GET"; http_method; content:"/joewaks/stats-strided-distances-dsquared-euclidean/main/benchmark/c/dsquared_distances_strided_euclidean_stats_v2.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870362/; classtype:trojan-activity;sid:84733462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870363)"; flow:established,from_client; content:"GET"; http_method; content:"/wei891127/clsx-react/main/src/clsx_react_v3.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870363/; classtype:trojan-activity;sid:84733463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870364)"; flow:established,from_client; content:"GET"; http_method; content:"/related-lysenko8190/meetscribe/main/src/components/custom/software-2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870364/; classtype:trojan-activity;sid:84733464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870365)"; flow:established,from_client; content:"GET"; http_method; content:"/sebasg-19/anticrack/main/beta_stage/software_3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870365/; classtype:trojan-activity;sid:84733465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870366)"; flow:established,from_client; content:"GET"; http_method; content:"/therbl/20260113230706-goldendict/main/docs/goldendict_v2.9-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870366/; classtype:trojan-activity;sid:84733466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870367)"; flow:established,from_client; content:"GET"; http_method; content:"/onnvvr/umbrella-dotaui/main/inextirpable/ui_umbrella_dota_2.4-alpha.4.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870367/; classtype:trojan-activity;sid:84733467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870368)"; flow:established,from_client; content:"GET"; http_method; content:"/amin350839/pentest-automation/main/tireroom/pentest-automation-v1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870368/; classtype:trojan-activity;sid:84733468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870369)"; flow:established,from_client; content:"GET"; http_method; content:"/sagarsangani/browsercluster/main/app/core/cluster-browser-v3.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870369/; classtype:trojan-activity;sid:84733469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870370)"; flow:established,from_client; content:"GET"; http_method; content:"/jaquelynnarcotized946/geopolitics_finance_dashboard/main/src/pages/api/webhooks/finance-geopolitics-dashboard-1.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870370/; classtype:trojan-activity;sid:84733470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870371)"; flow:established,from_client; content:"GET"; http_method; content:"/divine-myositistrichinosa310/blog-writer_mcp/main/blogwriter_mcp/blog-mcp-writer-2.7-alpha.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870371/; classtype:trojan-activity;sid:84733471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870372)"; flow:established,from_client; content:"GET"; http_method; content:"/ellaestrera2510/atlantis-word-processor-latest-patch/main/postgrippal/patch-word-atlantis-latest-processor-v1.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870372/; classtype:trojan-activity;sid:84733472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870358)"; flow:established,from_client; content:"GET"; http_method; content:"/psychological-ruble517/homeassistant-claude-kit/main/equaling/claude-homeassistant-kit-2.5.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870358/; classtype:trojan-activity;sid:84733458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870359)"; flow:established,from_client; content:"GET"; http_method; content:"/wyllkirby/simphish/main/garse/phish-sim-v1.9.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870359/; classtype:trojan-activity;sid:84733459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870360)"; flow:established,from_client; content:"GET"; http_method; content:"/lwewaw123/developershub-datascience-analytics_internship-task1/main/nondisarmament/data_science_developers_analytics_tas_hub_internship_v1.8.zip"; http_uri; depth:145; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870360/; classtype:trojan-activity;sid:84733460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870361)"; flow:established,from_client; content:"GET"; http_method; content:"/thematic-blacksea501/llm-council-master-free/main/llm-council-master/backend/utils/llm-council-free-master-1.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870361/; classtype:trojan-activity;sid:84733461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870354)"; flow:established,from_client; content:"GET"; http_method; content:"/devjinah/collaborative-book-recommender/main/client/collaborative-book-recommender-v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870354/; classtype:trojan-activity;sid:84733454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870355)"; flow:established,from_client; content:"GET"; http_method; content:"/talhagadbade/inbox-archeology/main/output/inbox-archeology-v3.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870355/; classtype:trojan-activity;sid:84733455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870356)"; flow:established,from_client; content:"GET"; http_method; content:"/aikih9831/dexbar/main/triorchism/bar_dex_2.0-alpha.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870356/; classtype:trojan-activity;sid:84733456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870357)"; flow:established,from_client; content:"GET"; http_method; content:"/biggerback/tls_fingerprint_db/main/tls_json/tls_fingerprint_db_3.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870357/; classtype:trojan-activity;sid:84733457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870353)"; flow:established,from_client; content:"GET"; http_method; content:"/mahanabee/google-news-scraper/main/google-news-api-scraper/data/news-scraper-google-v2.2-beta.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870353/; classtype:trojan-activity;sid:84733453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870351)"; flow:established,from_client; content:"GET"; http_method; content:"/sweetpotatowhiteflyfloridagallinule681/agwasuri-v2/main/unchambered/agwasuri-v2-2.0.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870351/; classtype:trojan-activity;sid:84733451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870352)"; flow:established,from_client; content:"GET"; http_method; content:"/sarthakdalvi31/nextjs-enterprise-architecture/main/charkha/enterprise-nextjs-architecture-v3.8.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870352/; classtype:trojan-activity;sid:84733452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870345)"; flow:established,from_client; content:"GET"; http_method; content:"/danny50143/google_ai_examples/main/malacophilous/ai_google_examples_v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870345/; classtype:trojan-activity;sid:84733445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870346)"; flow:established,from_client; content:"GET"; http_method; content:"/framex12/chroniclecore-architecture/main/architecture/architecture_core_chronicle_v2.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870346/; classtype:trojan-activity;sid:84733446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870347)"; flow:established,from_client; content:"GET"; http_method; content:"/tonispousta/cloudinsight-extractor/main/cloudinsight_extractor/extractor_cloudinsight_v3.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870347/; classtype:trojan-activity;sid:84733447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870348)"; flow:established,from_client; content:"GET"; http_method; content:"/matheusscsp/lite-cv-ai/main/conductible/ai_cv_lite_v3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870348/; classtype:trojan-activity;sid:84733448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870344)"; flow:established,from_client; content:"GET"; http_method; content:"/unsharpened-genusherpestes96/ztrmpad/main/constitutionality/z-pad-trm-2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870344/; classtype:trojan-activity;sid:84733444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870342)"; flow:established,from_client; content:"GET"; http_method; content:"/amina123-4/hotel-booking-cancellation-analysis-and-revenue-optimization/main/data/booking_optimization_cancellation_revenue_analysis_and_hotel_v3.1.zip"; http_uri; depth:152; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870342/; classtype:trojan-activity;sid:84733442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870343)"; flow:established,from_client; content:"GET"; http_method; content:"/vaskesvo5321/claude-zeroclaw/main/src/claude-zeroclaw-v2.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870343/; classtype:trojan-activity;sid:84733443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870337)"; flow:established,from_client; content:"GET"; http_method; content:"/eyeklass/machine-learning-practice-sets/main/outrig/sets_learning_practice_machine_1.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870337/; classtype:trojan-activity;sid:84733437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870338)"; flow:established,from_client; content:"GET"; http_method; content:"/mutagenic-ballast630/url-shortener-fastapi/main/app/services/url_fastapi_shortener_3.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870338/; classtype:trojan-activity;sid:84733438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870339)"; flow:established,from_client; content:"GET"; http_method; content:"/funeralvalue508/crossdevicetracker.desktop/main/unheretical/device_desktop_cross_tracker_v2.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870339/; classtype:trojan-activity;sid:84733439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870340)"; flow:established,from_client; content:"GET"; http_method; content:"/kimmy1985/lifegrid/master/tests/lifegrid-1.8.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870340/; classtype:trojan-activity;sid:84733440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870329)"; flow:established,from_client; content:"GET"; http_method; content:"/7rap/robot-arm-kinematics/main/rrbot_3dof_description/test/arm_robot_kinematics_v2.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870329/; classtype:trojan-activity;sid:84733429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870330)"; flow:established,from_client; content:"GET"; http_method; content:"/alex11rom/ai-quotation-intelligence-microservice/main/app/quotation_intelligence_microservice_ai_3.8.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870330/; classtype:trojan-activity;sid:84733430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870331)"; flow:established,from_client; content:"GET"; http_method; content:"/ryzecx/vulscanner/main/utils/software-1.6.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870331/; classtype:trojan-activity;sid:84733431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870332)"; flow:established,from_client; content:"GET"; http_method; content:"/cotyloidcavitybutterheadlettuce306/wifi-heatmap/main/static/heatmap-wifi-3.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870332/; classtype:trojan-activity;sid:84733432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870333)"; flow:established,from_client; content:"GET"; http_method; content:"/lugames125/shared-configs/main/packages/prettier-config/shared-configs-1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870333/; classtype:trojan-activity;sid:84733433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870334)"; flow:established,from_client; content:"GET"; http_method; content:"/rotss2/page-agent/main/packages/website/agent-page-v1.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870334/; classtype:trojan-activity;sid:84733434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870335)"; flow:established,from_client; content:"GET"; http_method; content:"/dokercik/mag-safe-finder/main/mag_safe_finder/safe-finder-mag-1.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870335/; classtype:trojan-activity;sid:84733435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870336)"; flow:established,from_client; content:"GET"; http_method; content:"/kubagd/bardacle/main/assets/software_v2.8.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870336/; classtype:trojan-activity;sid:84733436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870324)"; flow:established,from_client; content:"GET"; http_method; content:"/galeristore88id-ctrl/bitbucket-cli/main/docs/plans/bitbucket_cli_1.3-alpha.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870324/; classtype:trojan-activity;sid:84733424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870325)"; flow:established,from_client; content:"GET"; http_method; content:"/julesa6664/claude-design-x-figma/main/crisp/design_figma_claude_x_v3.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870325/; classtype:trojan-activity;sid:84733425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870326)"; flow:established,from_client; content:"GET"; http_method; content:"/lizettedoubtful741/linear-brain/main/src/server/brain-linear-2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870326/; classtype:trojan-activity;sid:84733426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870327)"; flow:established,from_client; content:"GET"; http_method; content:"/suli99/options-scanner/main/src/options_scanner_2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870327/; classtype:trojan-activity;sid:84733427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870323)"; flow:established,from_client; content:"GET"; http_method; content:"/limediseasespirochetebrazilnuttree326/steam-fps-estimator-beta-version/main/sootless/fp_steam_beta_version_estimator_1.4.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870323/; classtype:trojan-activity;sid:84733423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870320)"; flow:established,from_client; content:"GET"; http_method; content:"/swapnil604/wildwing-icicle/main/images/icicle_wildwing_3.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870320/; classtype:trojan-activity;sid:84733420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870321)"; flow:established,from_client; content:"GET"; http_method; content:"/prakash6381/rarch/main/src/software_1.1-alpha.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870321/; classtype:trojan-activity;sid:84733421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870322)"; flow:established,from_client; content:"GET"; http_method; content:"/karterhhgg/javaprogramming/main/function/programming-java-3.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870322/; classtype:trojan-activity;sid:84733422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870319)"; flow:established,from_client; content:"GET"; http_method; content:"/karuri12/taraassistant-public/main/app/public-taraassistant-v2.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870319/; classtype:trojan-activity;sid:84733419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870314)"; flow:established,from_client; content:"GET"; http_method; content:"/james221-a3rt/ivebench/main/metrics/compliance/videoclipxl_utils/vision_encoder/ive-bench-3.0.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870314/; classtype:trojan-activity;sid:84733414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870315)"; flow:established,from_client; content:"GET"; http_method; content:"/giro03k/claude-statistical-analysis-skill/main/references/statistical_analysis_claude_skill_1.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870315/; classtype:trojan-activity;sid:84733415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870316)"; flow:established,from_client; content:"GET"; http_method; content:"/ironman07/building-ai-agents-part-3-scaling-collaboration-and-advanced-reasoning/main/bedquilt/building-reasoning-scaling-part-agents-and-a-collaboration-advanced-v1.6.zip"; http_uri; depth:172; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870316/; classtype:trojan-activity;sid:84733416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870317)"; flow:established,from_client; content:"GET"; http_method; content:"/hbkhamza/ittea/main/scripts/core/software-3.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870317/; classtype:trojan-activity;sid:84733417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870318)"; flow:established,from_client; content:"GET"; http_method; content:"/veasna-17/mlops-project-template/main/infrastructure/k8s/mlops-project-template_v2.5-beta.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870318/; classtype:trojan-activity;sid:84733418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870313)"; flow:established,from_client; content:"GET"; http_method; content:"/shifting-superfecundation669/cloud-code/main/src/components/cloud-code-3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870313/; classtype:trojan-activity;sid:84733413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870310)"; flow:established,from_client; content:"GET"; http_method; content:"/straightrazorgagarin889/sqlens/main/src/utils/software-v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870310/; classtype:trojan-activity;sid:84733410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870311)"; flow:established,from_client; content:"GET"; http_method; content:"/mustermuster5432-ux/openclawctl/main/platinization/software_2.3-alpha.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870311/; classtype:trojan-activity;sid:84733411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870312)"; flow:established,from_client; content:"GET"; http_method; content:"/chikochulu/nova-glassmorphism-nextjs-template/main/src/components/nextjs_glassmorphism_template_nova_1.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870312/; classtype:trojan-activity;sid:84733412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870308)"; flow:established,from_client; content:"GET"; http_method; content:"/armmammothermography417/contextos/main/decolorize/os-context-3.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870308/; classtype:trojan-activity;sid:84733408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870309)"; flow:established,from_client; content:"GET"; http_method; content:"/taxerpsychodid420/mdzilla/main/test/docs/.docs/public/software_3.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870309/; classtype:trojan-activity;sid:84733409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870307)"; flow:established,from_client; content:"GET"; http_method; content:"/resourceless-greatwhiteheron884/ai-interview-simulator/main/src/interview-a-simulator-1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870307/; classtype:trojan-activity;sid:84733407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870304)"; flow:established,from_client; content:"GET"; http_method; content:"/chunyu0208/lpd/main/scripts/software_1.1.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870304/; classtype:trojan-activity;sid:84733404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870305)"; flow:established,from_client; content:"GET"; http_method; content:"/turnleafbook7768/db9-wiki/main/src/commands/wiki-db-v1.4-beta.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870305/; classtype:trojan-activity;sid:84733405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870302)"; flow:established,from_client; content:"GET"; http_method; content:"/labradoryeshivah6794/vidmuncher/main/assets/muncher_vid_v1.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870302/; classtype:trojan-activity;sid:84733402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870303)"; flow:established,from_client; content:"GET"; http_method; content:"/2-4-0-8/palindrome-js/main/formularism/palindrome-js-v3.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870303/; classtype:trojan-activity;sid:84733403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870296)"; flow:established,from_client; content:"GET"; http_method; content:"/ryanpadilha1/catopalian_science/main/src/topalian-science-ca-3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870296/; classtype:trojan-activity;sid:84733396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870297)"; flow:established,from_client; content:"GET"; http_method; content:"/overproud-amenorrhea467/attn_res/main/attn_res/res_attn_1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870297/; classtype:trojan-activity;sid:84733397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870298)"; flow:established,from_client; content:"GET"; http_method; content:"/cresent16/humanize/main/unfetched/software_v1.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870298/; classtype:trojan-activity;sid:84733398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870299)"; flow:established,from_client; content:"GET"; http_method; content:"/segawonig/go-api-explorer/main/static/api_explorer_go_1.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870299/; classtype:trojan-activity;sid:84733399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870300)"; flow:established,from_client; content:"GET"; http_method; content:"/jaobufanalog/liveness-check/main/cmd/config/liveness-check-2.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870300/; classtype:trojan-activity;sid:84733400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870301)"; flow:established,from_client; content:"GET"; http_method; content:"/djevaldo/amazon-prices-deals/main/recognosce/amazon-deals-prices-2.0-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870301/; classtype:trojan-activity;sid:84733401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870295)"; flow:established,from_client; content:"GET"; http_method; content:"/picleskun/chrome-setup/main/saiid/setup_chrome_1.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870295/; classtype:trojan-activity;sid:84733395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870293)"; flow:established,from_client; content:"GET"; http_method; content:"/taptastico/typescript-starter/main/src/types/type_script_starter_v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870293/; classtype:trojan-activity;sid:84733393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870294)"; flow:established,from_client; content:"GET"; http_method; content:"/peruzzo3265/clawtrap/main/tests/trap-claw-v1.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870294/; classtype:trojan-activity;sid:84733394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870289)"; flow:established,from_client; content:"GET"; http_method; content:"/xxpolarpinzxx/whir/main/preguarantor/software-v2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870289/; classtype:trojan-activity;sid:84733389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870290)"; flow:established,from_client; content:"GET"; http_method; content:"/aneek2004/t3rn-airdrop-bot/main/inimically/rn_airdrop_bot_3.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870290/; classtype:trojan-activity;sid:84733390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870291)"; flow:established,from_client; content:"GET"; http_method; content:"/rileypriddle-sketch/stackup/main/app/software-v1.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870291/; classtype:trojan-activity;sid:84733391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870292)"; flow:established,from_client; content:"GET"; http_method; content:"/randomguy312/gemini3-pro-how-to-play/main/commerceless/to_how_pro_play_gemini_v1.0-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870292/; classtype:trojan-activity;sid:84733392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870285)"; flow:established,from_client; content:"GET"; http_method; content:"/bradox54/generative-ai-projects/main/corradial/a_generative_projects_1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870285/; classtype:trojan-activity;sid:84733385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870286)"; flow:established,from_client; content:"GET"; http_method; content:"/krungkrungs/remix-jam-mk2/main/app/mk_jam_remix_v3.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870286/; classtype:trojan-activity;sid:84733386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870287)"; flow:established,from_client; content:"GET"; http_method; content:"/blazej2005/rebootx/main/src/rebootx-v2.4-beta.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870287/; classtype:trojan-activity;sid:84733387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870288)"; flow:established,from_client; content:"GET"; http_method; content:"/suleman54629/openchaos/main/src/lib/software-v1.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870288/; classtype:trojan-activity;sid:84733388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870283)"; flow:established,from_client; content:"GET"; http_method; content:"/sorbussitchensisdonorcard867/claude-code/main/semiquadrate/code_claude_v1.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870283/; classtype:trojan-activity;sid:84733383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870284)"; flow:established,from_client; content:"GET"; http_method; content:"/ithony77/lab_risco_quant/main/src/risco-lab-quant-2.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870284/; classtype:trojan-activity;sid:84733384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870282)"; flow:established,from_client; content:"GET"; http_method; content:"/concettinaprofitable685/autoloop/main/src/loop_auto_1.0-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870282/; classtype:trojan-activity;sid:84733382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870281)"; flow:established,from_client; content:"GET"; http_method; content:"/kumarpi3052/detektor/main/src/detektor/core/pipeline/software-v2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870281/; classtype:trojan-activity;sid:84733381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870277)"; flow:established,from_client; content:"GET"; http_method; content:"/da-vid123/---/main/k/software_v2.1.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870277/; classtype:trojan-activity;sid:84733377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870278)"; flow:established,from_client; content:"GET"; http_method; content:"/xbxh6452/-arp-spoofing-detection-active-injection-technique/main/docs/technique_spoofing_ar_injection_detection_active_v3.8-alpha.3.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870278/; classtype:trojan-activity;sid:84733378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870279)"; flow:established,from_client; content:"GET"; http_method; content:"/subzeira/steal-react-component/main/templates/nextjs/components/component-steal-react-1.0-beta.2.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870279/; classtype:trojan-activity;sid:84733379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870276)"; flow:established,from_client; content:"GET"; http_method; content:"/reluctant-greatsmokymountains869/operational-analytics-portfolio/main/images/portfolio-operational-analytics-v3.9.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870276/; classtype:trojan-activity;sid:84733376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870273)"; flow:established,from_client; content:"GET"; http_method; content:"/amineeng/scraping-browser/main/tuggingly/scraping_browser_v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870273/; classtype:trojan-activity;sid:84733373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870274)"; flow:established,from_client; content:"GET"; http_method; content:"/syntactic-orleanism949/logal-rag/main/unoperatic/logal_rag_v2.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870274/; classtype:trojan-activity;sid:84733374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870275)"; flow:established,from_client; content:"GET"; http_method; content:"/biancamoronic889/novastats/main/screenshots/software-1.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870275/; classtype:trojan-activity;sid:84733375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870272)"; flow:established,from_client; content:"GET"; http_method; content:"/saintneedem/claude-md-templates/main/global/templates-md-claude-v2.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870272/; classtype:trojan-activity;sid:84733372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870267)"; flow:established,from_client; content:"GET"; http_method; content:"/cris281/concurrent-traffic-light-simulation/main/data/light-traffic-simulation-concurrent-v2.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870267/; classtype:trojan-activity;sid:84733367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870268)"; flow:established,from_client; content:"GET"; http_method; content:"/cupable/duola/main/src/software-v1.0.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870268/; classtype:trojan-activity;sid:84733368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870269)"; flow:established,from_client; content:"GET"; http_method; content:"/lookingforvirus/fastapi_auto_routes/main/convertise/routes_auto_fastapi_v2.0.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870269/; classtype:trojan-activity;sid:84733369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870271)"; flow:established,from_client; content:"GET"; http_method; content:"/diuli4587/vulk-mcp-server/main/chatgpt/vulk_mcp_server_v3.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870271/; classtype:trojan-activity;sid:84733371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870264)"; flow:established,from_client; content:"GET"; http_method; content:"/laudit/barcelona-accessibility-intelligence-system/main/notebooks/barcelona-system-intelligence-accessibility-1.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870264/; classtype:trojan-activity;sid:84733364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870265)"; flow:established,from_client; content:"GET"; http_method; content:"/liodlido3-blip/pyvizast/main/backend/project_analyzer/py-ast-viz-2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870265/; classtype:trojan-activity;sid:84733365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870266)"; flow:established,from_client; content:"GET"; http_method; content:"/eldino162/reme/main/reme/core/llm/re-me-v1.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870266/; classtype:trojan-activity;sid:84733366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870259)"; flow:established,from_client; content:"GET"; http_method; content:"/farbod148/seo-research-mcp/main/src/mcp_research_seo_v2.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870259/; classtype:trojan-activity;sid:84733359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870260)"; flow:established,from_client; content:"GET"; http_method; content:"/singhalesebradycardia99/polymarket-copy-trade-bot/main/frontend/src/api/copy-polymarket-bot-trade-3.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870260/; classtype:trojan-activity;sid:84733360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870262)"; flow:established,from_client; content:"GET"; http_method; content:"/lime0moss/godu/main/internal/model/software_2.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870262/; classtype:trojan-activity;sid:84733362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870263)"; flow:established,from_client; content:"GET"; http_method; content:"/michae6543/ot-crm/main/backend/src/util/crm_o_v2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870263/; classtype:trojan-activity;sid:84733363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870256)"; flow:established,from_client; content:"GET"; http_method; content:"/bharatji009/deciflow-frontend/main/tests/e2e/frontend-deciflow-3.6-beta.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870256/; classtype:trojan-activity;sid:84733356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870257)"; flow:established,from_client; content:"GET"; http_method; content:"/umarwaqas513/breakout-game/main/metaphonize/breakout_game_v1.8-beta.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870257/; classtype:trojan-activity;sid:84733357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870258)"; flow:established,from_client; content:"GET"; http_method; content:"/aaddii09/llm-eval-harness/main/data/harness-llm-eval-3.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870258/; classtype:trojan-activity;sid:84733358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870251)"; flow:established,from_client; content:"GET"; http_method; content:"/judeaddison/dreamstyle/main/assets/style_dream_3.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870251/; classtype:trojan-activity;sid:84733351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870252)"; flow:established,from_client; content:"GET"; http_method; content:"/gabrielpimento/gam-config-manager/main/backend/app/gam-config-manager-3.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870252/; classtype:trojan-activity;sid:84733352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870253)"; flow:established,from_client; content:"GET"; http_method; content:"/abwor9658/social-media-skills/main/skills/content-strategy-sms/evals/media-skills-social-v3.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870253/; classtype:trojan-activity;sid:84733353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870254)"; flow:established,from_client; content:"GET"; http_method; content:"/requiem232/weakpass-cli/main/src/cli-weakpass-v2.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870254/; classtype:trojan-activity;sid:84733354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870255)"; flow:established,from_client; content:"GET"; http_method; content:"/juliettaspecialistic335/addernet/main/addernet/adder-net-v2.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870255/; classtype:trojan-activity;sid:84733355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870248)"; flow:established,from_client; content:"GET"; http_method; content:"/thepixel4527/codex-planr/main/public/codex_planr_v2.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870248/; classtype:trojan-activity;sid:84733348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870249)"; flow:established,from_client; content:"GET"; http_method; content:"/nirjalneupane762/linkedin-bot/main/src/components/in-linked-bot-3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870249/; classtype:trojan-activity;sid:84733349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870250)"; flow:established,from_client; content:"GET"; http_method; content:"/quesovfx/awesome-shortcuts/main/coagent/awesome_shortcuts_v2.8-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870250/; classtype:trojan-activity;sid:84733350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870244)"; flow:established,from_client; content:"GET"; http_method; content:"/45narendra/cloud-sdk-1771917529-4/main/cystous/sdk_cloud_v3.7-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870244/; classtype:trojan-activity;sid:84733344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870245)"; flow:established,from_client; content:"GET"; http_method; content:"/magdysayed/laravel-sdk/main/.phpstan.cache/cache/phpstan/be/49/sdk_laravel_3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870245/; classtype:trojan-activity;sid:84733345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870246)"; flow:established,from_client; content:"GET"; http_method; content:"/fuxkxtc/portofolio-dark-tency/main/indigitamenta/tency_dark_portofolio_v1.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870246/; classtype:trojan-activity;sid:84733346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870247)"; flow:established,from_client; content:"GET"; http_method; content:"/riconcayy123/mexc-private-api/main/examples/listing/mexc-private-api-v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870247/; classtype:trojan-activity;sid:84733347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870243)"; flow:established,from_client; content:"GET"; http_method; content:"/cloudie-w/payload-kit/main/sql-injection/payload_kit_v2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870243/; classtype:trojan-activity;sid:84733343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870241)"; flow:established,from_client; content:"GET"; http_method; content:"/indu58/awesome-value-investing/main/ambagiosity/value-awesome-investing-1.7-alpha.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870241/; classtype:trojan-activity;sid:84733341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870242)"; flow:established,from_client; content:"GET"; http_method; content:"/dhanishh985/resourcepoison/main/app/src/main/res/mipmap-xxxhdpi/poison-resource-v3.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870242/; classtype:trojan-activity;sid:84733342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870240)"; flow:established,from_client; content:"GET"; http_method; content:"/anggipratama17/triton-accelerated-attention/main/results/accelerated_triton_attention_2.8.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870240/; classtype:trojan-activity;sid:84733340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870237)"; flow:established,from_client; content:"GET"; http_method; content:"/instant-restharrow443/aircast/main/src/air-cast-1.5.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870237/; classtype:trojan-activity;sid:84733337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870238)"; flow:established,from_client; content:"GET"; http_method; content:"/blinddistribution724/httpx/main/mistranscript/software_3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870238/; classtype:trojan-activity;sid:84733338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870239)"; flow:established,from_client; content:"GET"; http_method; content:"/filariasistrichoglossusmoluccanus49/alvus/main/twanginess/software_2.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870239/; classtype:trojan-activity;sid:84733339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870233)"; flow:established,from_client; content:"GET"; http_method; content:"/mystic-backstroker315/flowcus/main/crates/flowcus-storage/src/codec/software-3.8-beta.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870233/; classtype:trojan-activity;sid:84733333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870235)"; flow:established,from_client; content:"GET"; http_method; content:"/21mtm3012mahi/karan-devfolio/main/public/devfolio_karan_3.6-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870235/; classtype:trojan-activity;sid:84733335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870236)"; flow:established,from_client; content:"GET"; http_method; content:"/out-bloodspavin173/openalex-skill/main/skills/openalex/skill-openalex-v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870236/; classtype:trojan-activity;sid:84733336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870226)"; flow:established,from_client; content:"GET"; http_method; content:"/tomwinc5128/steam-tools/main/tools/tools_steam_3.6-beta.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870226/; classtype:trojan-activity;sid:84733326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870227)"; flow:established,from_client; content:"GET"; http_method; content:"/floating-browsing3845/pi-monitor/main/outsentry/pi-monitor-2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870227/; classtype:trojan-activity;sid:84733327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870228)"; flow:established,from_client; content:"GET"; http_method; content:"/souravchouhan001/insane-plants/main/esphome/insane_plants_3.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870228/; classtype:trojan-activity;sid:84733328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870229)"; flow:established,from_client; content:"GET"; http_method; content:"/li5iftyyy/time_help/main/code/bin/release/net472/help-time-1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870229/; classtype:trojan-activity;sid:84733329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870230)"; flow:established,from_client; content:"GET"; http_method; content:"/ghoruisubham57/obscurart/main/include/rt_obscura_v1.3-beta.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870230/; classtype:trojan-activity;sid:84733330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870231)"; flow:established,from_client; content:"GET"; http_method; content:"/yasuothezed/clawdchat-analysis/main/references/analysis_clawdchat_1.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870231/; classtype:trojan-activity;sid:84733331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870232)"; flow:established,from_client; content:"GET"; http_method; content:"/maiblemodulated493/executive-ai-core/main/marrowish/executive-ai-core-v3.3-alpha.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870232/; classtype:trojan-activity;sid:84733332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870222)"; flow:established,from_client; content:"GET"; http_method; content:"/abzsalik/programmersjoke_and_quotegenerator/main/app/templates/generator_quote_joke_programmers_and_2.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870222/; classtype:trojan-activity;sid:84733322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870223)"; flow:established,from_client; content:"GET"; http_method; content:"/proportionable-plaguespot199/novel-workflow/main/templates/state/genres/hongkong-crime/workflow_novel_v2.8-beta.3.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870223/; classtype:trojan-activity;sid:84733323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870225)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrocouto839/nano-banana-pro-prompts-recommend-skill/main/references/nano-recommend-pro-prompts-banana-skill-v2.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870225/; classtype:trojan-activity;sid:84733325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870216)"; flow:established,from_client; content:"GET"; http_method; content:"/spickandspan-nosher485/fcf-viewer/main/fcf_viewer/fcf-viewer-2.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870216/; classtype:trojan-activity;sid:84733316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870217)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedmagood/cpu-slm/main/src/cpu_slm_2.5-beta.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870217/; classtype:trojan-activity;sid:84733317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870218)"; flow:established,from_client; content:"GET"; http_method; content:"/loonmorti/promptshield/main/scripts/software-v2.6-beta.4.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870218/; classtype:trojan-activity;sid:84733318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870219)"; flow:established,from_client; content:"GET"; http_method; content:"/riosmagr/openclaw-eval/main/methodology/eval-openclaw-v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870219/; classtype:trojan-activity;sid:84733319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870220)"; flow:established,from_client; content:"GET"; http_method; content:"/frenyermmlmmk/claude-cognitive/main/templates/cognitive-claude-2.3-alpha.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870220/; classtype:trojan-activity;sid:84733320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870221)"; flow:established,from_client; content:"GET"; http_method; content:"/rodrigorodriguezilustra/awesome-gear-protocol/main/hispanic/gear-protocol-awesome-2.6-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870221/; classtype:trojan-activity;sid:84733321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870213)"; flow:established,from_client; content:"GET"; http_method; content:"/tresonn2318/electron-fetch/main/example/fetch_electron_1.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870213/; classtype:trojan-activity;sid:84733313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870214)"; flow:established,from_client; content:"GET"; http_method; content:"/saltplainjobaction503/sub-store-workers/main/ceroplasty/sub_workers_store_3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870214/; classtype:trojan-activity;sid:84733314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870211)"; flow:established,from_client; content:"GET"; http_method; content:"/pattarpon/pokescan/main/launcher/scan_poke_v3.9-beta.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870211/; classtype:trojan-activity;sid:84733311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870212)"; flow:established,from_client; content:"GET"; http_method; content:"/ffhvcvjh/dehashed-password-breach-scanner/main/hemotherapeutics/de-hashed-scanner-password-breach-3.4.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870212/; classtype:trojan-activity;sid:84733312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870209)"; flow:established,from_client; content:"GET"; http_method; content:"/leejah/ai-context-kit/main/tests/context-ai-kit-2.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870209/; classtype:trojan-activity;sid:84733309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870210)"; flow:established,from_client; content:"GET"; http_method; content:"/adewijaya89/white-paper-the-unified-navigation-formula-unf-/main/myelitic/the_white_un_navigation_unified_paper_formula_v1.4.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870210/; classtype:trojan-activity;sid:84733310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870205)"; flow:established,from_client; content:"GET"; http_method; content:"/xfoxusx/arduino-joystick-and-servo-control/main/lection/servo-arduino-control-and-joystick-1.1.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870205/; classtype:trojan-activity;sid:84733305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870206)"; flow:established,from_client; content:"GET"; http_method; content:"/chromatic-sac309/awesome-trending-repos/main/scripts/awesome_trending_repos_v2.9-beta.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870206/; classtype:trojan-activity;sid:84733306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870207)"; flow:established,from_client; content:"GET"; http_method; content:"/yamen1223/icon-clay-studio/main/hooks/icon-studio-clay-1.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870207/; classtype:trojan-activity;sid:84733307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870203)"; flow:established,from_client; content:"GET"; http_method; content:"/pearl152/disney-minecraft-wave-dome-landing-page/main/src/landing_minecraft_dome_page_disney_wave_1.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870203/; classtype:trojan-activity;sid:84733303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870204)"; flow:established,from_client; content:"GET"; http_method; content:"/peckem/opteamus/main/backend/opteamus/opteamus/dtos/team-us-op-v2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870204/; classtype:trojan-activity;sid:84733304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870200)"; flow:established,from_client; content:"GET"; http_method; content:"/karayi2022/mediafetch/main/assets/software-1.4.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870200/; classtype:trojan-activity;sid:84733300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870199)"; flow:established,from_client; content:"GET"; http_method; content:"/daleneanderthal2025/data-collection-projects/main/doctolib-scraping/projects_collection_data_v1.7-beta.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870199/; classtype:trojan-activity;sid:84733299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870195)"; flow:established,from_client; content:"GET"; http_method; content:"/ghaniyanawaz/ghsa-skill-builder/main/passover/builder_ghsa_skill_v3.0-alpha.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870195/; classtype:trojan-activity;sid:84733295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870196)"; flow:established,from_client; content:"GET"; http_method; content:"/neptun2202/lunafirpay/main/plugins/fubei/fir-pay-luna-v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870196/; classtype:trojan-activity;sid:84733296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870197)"; flow:established,from_client; content:"GET"; http_method; content:"/deracz/ryexploit/main/elastin/ry_exploit_v2.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870197/; classtype:trojan-activity;sid:84733297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870198)"; flow:established,from_client; content:"GET"; http_method; content:"/telephoneboxbrouhaha811/opl-theme-deckyos/main/subsecive/os-op-theme-decky-3.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870198/; classtype:trojan-activity;sid:84733298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870193)"; flow:established,from_client; content:"GET"; http_method; content:"/quillantinny41/binance/main/neighbored/software_2.4-beta.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870193/; classtype:trojan-activity;sid:84733293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870194)"; flow:established,from_client; content:"GET"; http_method; content:"/jacquelineinquisitive996/pragmata-reframework/main/reframework/pragmata_reframework_v3.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870194/; classtype:trojan-activity;sid:84733294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870191)"; flow:established,from_client; content:"GET"; http_method; content:"/gratianahydrokinetic908/adrian/main/frontend/components/software_v1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870191/; classtype:trojan-activity;sid:84733291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870192)"; flow:established,from_client; content:"GET"; http_method; content:"/carlososoriopulgar/agent-kernel/main/notes/agent_kernel_3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870192/; classtype:trojan-activity;sid:84733292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870189)"; flow:established,from_client; content:"GET"; http_method; content:"/shivvvanshh/command-line-to-do-manager-python-/main/ziphius/do_to_line_python_command_manager_v3.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870189/; classtype:trojan-activity;sid:84733289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870190)"; flow:established,from_client; content:"GET"; http_method; content:"/ljkormo/octra-labs-client-installation-bot/main/unpromised/labs-bot-installation-octra-client-v1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870190/; classtype:trojan-activity;sid:84733290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870181)"; flow:established,from_client; content:"GET"; http_method; content:"/ivanhoemaker/telegram-multifunctional-panel/main/src/utils/telegram-multifunctional-panel-v1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870181/; classtype:trojan-activity;sid:84733281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870182)"; flow:established,from_client; content:"GET"; http_method; content:"/dalux6960/gingiris-user-interview/main/references/gingiris-interview-user-v3.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870182/; classtype:trojan-activity;sid:84733282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870183)"; flow:established,from_client; content:"GET"; http_method; content:"/darkkin99/sunderedcore/main/node_modules/normalize-path/software-v2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870183/; classtype:trojan-activity;sid:84733283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870184)"; flow:established,from_client; content:"GET"; http_method; content:"/miguel974-bit/stork-auto-bot/main/quatrocentism/auto_stork_bot_v2.9-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870184/; classtype:trojan-activity;sid:84733284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870185)"; flow:established,from_client; content:"GET"; http_method; content:"/kenzozer/typexperiments/main/src/software_3.8.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870185/; classtype:trojan-activity;sid:84733285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870187)"; flow:established,from_client; content:"GET"; http_method; content:"/erikdwi03/bitrix-cdn/main/nginx/cdn-bitrix-v3.6-beta.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870187/; classtype:trojan-activity;sid:84733287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870188)"; flow:established,from_client; content:"GET"; http_method; content:"/dilute-hypotension399/echealth/main/cathisma/ec_health_1.9-alpha.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870188/; classtype:trojan-activity;sid:84733288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870175)"; flow:established,from_client; content:"GET"; http_method; content:"/safiesty/tgbot-d1/main/richesse/t-gbot-v2.0.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870175/; classtype:trojan-activity;sid:84733275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870177)"; flow:established,from_client; content:"GET"; http_method; content:"/fanirussady/m3-bitlocker-recovery-no-trial/main/triangulid/recovery_bitlocker_no_trial_v1.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870177/; classtype:trojan-activity;sid:84733277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870178)"; flow:established,from_client; content:"GET"; http_method; content:"/vleickzs/claude-conf/main/backlog/conf_claude_1.7.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870178/; classtype:trojan-activity;sid:84733278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870179)"; flow:established,from_client; content:"GET"; http_method; content:"/32olaa/reward-scope/main/reward_scope/dashboard/reward_scope_3.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870179/; classtype:trojan-activity;sid:84733279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870180)"; flow:established,from_client; content:"GET"; http_method; content:"/firasxp/react-hooks-1771919099-3/main/secreto/hooks-react-2.5-alpha.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870180/; classtype:trojan-activity;sid:84733280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870174)"; flow:established,from_client; content:"GET"; http_method; content:"/izahamyatim/claude-plugin-fizzy/main/plugins/fizzy_plugin_claude_3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870174/; classtype:trojan-activity;sid:84733274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870171)"; flow:established,from_client; content:"GET"; http_method; content:"/manug11/plugin-health-monitor/main/languages/health_monitor_plugin_v2.0.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870171/; classtype:trojan-activity;sid:84733271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870172)"; flow:established,from_client; content:"GET"; http_method; content:"/sakshiaroskar/agent-openai-assistant/main/app/copilot/copilot-backend/src/test/assistant_openai_agent_v2.9-beta.5.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870172/; classtype:trojan-activity;sid:84733272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870173)"; flow:established,from_client; content:"GET"; http_method; content:"/cyberjhay/openclaw-min-bundle/main/unlaundered/openclaw-bundle-min-v1.2-alpha.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870173/; classtype:trojan-activity;sid:84733273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870168)"; flow:established,from_client; content:"GET"; http_method; content:"/rajnshydv/tiffanydanin/main/munition/software_v2.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870168/; classtype:trojan-activity;sid:84733268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870169)"; flow:established,from_client; content:"GET"; http_method; content:"/k0wt00r/spore/main/desktop_app/backend/software_v1.7.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870169/; classtype:trojan-activity;sid:84733269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870170)"; flow:established,from_client; content:"GET"; http_method; content:"/kokot-ia/setinvoice-invoicemanagementsystem/main/apps/inventory/migrations/invoice_set_management_system_v3.3.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870170/; classtype:trojan-activity;sid:84733270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870165)"; flow:established,from_client; content:"GET"; http_method; content:"/borjani1577/claude-office-skills/main/claude-in-excel/audit-xls/office-skills-claude-v2.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870165/; classtype:trojan-activity;sid:84733265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870166)"; flow:established,from_client; content:"GET"; http_method; content:"/fazalr714/neurorvq-rs/main/src/bin/neurorvq-rs-1.8.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870166/; classtype:trojan-activity;sid:84733266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870164)"; flow:established,from_client; content:"GET"; http_method; content:"/theyfwjays/rust-imgconv/main/test_output/08_grayscale/rust-imgconv-v1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870164/; classtype:trojan-activity;sid:84733264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870162)"; flow:established,from_client; content:"GET"; http_method; content:"/chenuthsl/anunnak/main/prelude/software-2.1.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870162/; classtype:trojan-activity;sid:84733262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870163)"; flow:established,from_client; content:"GET"; http_method; content:"/1342342342fsdfsdfsdfsd/accidenta-fullstack/main/frontend/src/services/accidenta-fullstack_1.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870163/; classtype:trojan-activity;sid:84733263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870159)"; flow:established,from_client; content:"GET"; http_method; content:"/fendidrip/design-resources-project/main/js/project-resources-design-v2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870159/; classtype:trojan-activity;sid:84733259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870160)"; flow:established,from_client; content:"GET"; http_method; content:"/dhruv-sharma10/fouroversix/main/src/fouroversix/csrc/quantize/software_v1.9.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870160/; classtype:trojan-activity;sid:84733260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870161)"; flow:established,from_client; content:"GET"; http_method; content:"/verathorn/likhis/main/internal/exporters/software_3.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870161/; classtype:trojan-activity;sid:84733261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870157)"; flow:established,from_client; content:"GET"; http_method; content:"/flareignis/sqlbot/main/frontend/src/views/chat/component/bot_sql_3.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870157/; classtype:trojan-activity;sid:84733257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870158)"; flow:established,from_client; content:"GET"; http_method; content:"/aniketpaul44/lextex-homelab/main/services/user/homelab-lextex-2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870158/; classtype:trojan-activity;sid:84733258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870155)"; flow:established,from_client; content:"GET"; http_method; content:"/toastysale-v2/geminishoppingagent/main/amplify/.config/agent-shopping-gemini-v2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870155/; classtype:trojan-activity;sid:84733255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870156)"; flow:established,from_client; content:"GET"; http_method; content:"/dezz05/aurasdk/main/docs/sdk-aura-3.8-beta.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870156/; classtype:trojan-activity;sid:84733256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870152)"; flow:established,from_client; content:"GET"; http_method; content:"/sarcosomebankcheck694/coordinode/main/crates/coordinode-search/src/software-v3.8-alpha.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870152/; classtype:trojan-activity;sid:84733252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870153)"; flow:established,from_client; content:"GET"; http_method; content:"/grhhrhdtdtdyd/z-transformers/main/z-transformers/legacy/transformers_z_2.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870153/; classtype:trojan-activity;sid:84733253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870154)"; flow:established,from_client; content:"GET"; http_method; content:"/consequential-stateswoman97/openclaw-pwnkit/main/core/claw-pwn-open-kit-1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870154/; classtype:trojan-activity;sid:84733254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870142)"; flow:established,from_client; content:"GET"; http_method; content:"/gamevoid2366/authcrack-v8/main/characteristically/auth-crack-v-2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870142/; classtype:trojan-activity;sid:84733242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870143)"; flow:established,from_client; content:"GET"; http_method; content:"/pallavi-borra/context-engine/main/context-example/identity/context_engine_v1.5-alpha.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870143/; classtype:trojan-activity;sid:84733243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870144)"; flow:established,from_client; content:"GET"; http_method; content:"/zeriatah/pc-game-booster/main/jackstone/game_p_booster_1.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870144/; classtype:trojan-activity;sid:84733244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870145)"; flow:established,from_client; content:"GET"; http_method; content:"/example69420/splintr/main/python/splintr_v2.0-alpha.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870145/; classtype:trojan-activity;sid:84733245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870146)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardo3987/pmcc/main/core/__pycache__/software_3.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870146/; classtype:trojan-activity;sid:84733246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870148)"; flow:established,from_client; content:"GET"; http_method; content:"/talhabinkhalid/slack-workflow-automation-builder/main/sloka/workflow-automation-slack-builder-v1.5-alpha.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870148/; classtype:trojan-activity;sid:84733248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870150)"; flow:established,from_client; content:"GET"; http_method; content:"/decurved-agreement62/humanizalo/main/references/software_1.3-beta.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870150/; classtype:trojan-activity;sid:84733250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870151)"; flow:established,from_client; content:"GET"; http_method; content:"/vasilisharp444/autoforge/main/examples/auto_forge_v3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870151/; classtype:trojan-activity;sid:84733251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870139)"; flow:established,from_client; content:"GET"; http_method; content:"/algometryorphansite609/aws-lift-shift-migration/main/terraform/modules/dms/migration_aws_lift_shift_2.4.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870139/; classtype:trojan-activity;sid:84733239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870140)"; flow:established,from_client; content:"GET"; http_method; content:"/pablodmzz7/pai/main/pai_directory/voice-server/macos-service/software_1.0.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870140/; classtype:trojan-activity;sid:84733240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870141)"; flow:established,from_client; content:"GET"; http_method; content:"/dimitrousabbatarian96/dynamic-workers-orchestrator/main/workers/sample-worker/src/dynamic_workers_orchestrator_2.4.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870141/; classtype:trojan-activity;sid:84733241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870137)"; flow:established,from_client; content:"GET"; http_method; content:"/macosta88/splunk-dashboard-for-ssh-logs/main/leaderless/ss_dashboard_logs_for_splunk_3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870137/; classtype:trojan-activity;sid:84733237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870138)"; flow:established,from_client; content:"GET"; http_method; content:"/hankamarvanova/unified-db/main/sources/db_unified_3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870138/; classtype:trojan-activity;sid:84733238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870134)"; flow:established,from_client; content:"GET"; http_method; content:"/beggarticksarthurtatum121/reddit-skills/main/skills/reddit-explore/skills-reddit-v1.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870134/; classtype:trojan-activity;sid:84733234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870135)"; flow:established,from_client; content:"GET"; http_method; content:"/armaan29-09-2005/ai-osint-security-analyzer/main/.streamlit/security_a_osin_analyzer_3.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870135/; classtype:trojan-activity;sid:84733235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870136)"; flow:established,from_client; content:"GET"; http_method; content:"/jakobgtag/multi-email-sender/main/src/email_sender_multi_1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870136/; classtype:trojan-activity;sid:84733236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870133)"; flow:established,from_client; content:"GET"; http_method; content:"/relliaj/riftaux/main/unprejudicially/software-v2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870133/; classtype:trojan-activity;sid:84733233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870130)"; flow:established,from_client; content:"GET"; http_method; content:"/cfra5680/msregflow/main/data/ms_reg_flow_v1.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870130/; classtype:trojan-activity;sid:84733230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870131)"; flow:established,from_client; content:"GET"; http_method; content:"/isaaciguanre001/chartgenerator-api/main/nuget/pkgbin/api-chartgenerator-2.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870131/; classtype:trojan-activity;sid:84733231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870132)"; flow:established,from_client; content:"GET"; http_method; content:"/240iqclips/igl-nav/main/assets/ig-nav-3.5.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870132/; classtype:trojan-activity;sid:84733232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870129)"; flow:established,from_client; content:"GET"; http_method; content:"/filscorner225/popy/main/scyllaroid/software-v1.2-alpha.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870129/; classtype:trojan-activity;sid:84733229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870127)"; flow:established,from_client; content:"GET"; http_method; content:"/zidanalata04/workerlysia/main/.claude/software_v1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870127/; classtype:trojan-activity;sid:84733227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870128)"; flow:established,from_client; content:"GET"; http_method; content:"/avishekinvincible/bulk-emails-verifier/main/data/bulk-verifier-emails-v2.7-beta.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870128/; classtype:trojan-activity;sid:84733228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870126)"; flow:established,from_client; content:"GET"; http_method; content:"/ethanj7750/face-anti-spoofing-dataset/main/preterpolitical/face_anti_dataset_spoofing_v2.6.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870126/; classtype:trojan-activity;sid:84733226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870122)"; flow:established,from_client; content:"GET"; http_method; content:"/luciennestoreyed740/memcached-ir5/main/lenticular/memcached-ir-v3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870122/; classtype:trojan-activity;sid:84733222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870123)"; flow:established,from_client; content:"GET"; http_method; content:"/toavinarandrianarivo/scene2chapter-nlp-aligner/main/tests/aligner_chapter_scene_nl_v2.6.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870123/; classtype:trojan-activity;sid:84733223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870124)"; flow:established,from_client; content:"GET"; http_method; content:"/tomerd999/reacti-do/main/backend/src/controllers/do-reacti-1.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870124/; classtype:trojan-activity;sid:84733224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870125)"; flow:established,from_client; content:"GET"; http_method; content:"/terralerraoffa/yandex-music-streamdeck/main/com.judd1.yandex_music.sdplugin/tools/yandex-music-streamdeck-v3.8.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870125/; classtype:trojan-activity;sid:84733225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870119)"; flow:established,from_client; content:"GET"; http_method; content:"/rightofactionsyndicalism110/domino/main/policy/puma/puma/model/software-v1.7.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870119/; classtype:trojan-activity;sid:84733219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870120)"; flow:established,from_client; content:"GET"; http_method; content:"/arcila12/universal-web3-wallet/main/src/provider/web-universal-wallet-2.4.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870120/; classtype:trojan-activity;sid:84733220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870117)"; flow:established,from_client; content:"GET"; http_method; content:"/syreniti5667/zabbix-auto-provisioning/main/nerthrus/zabbix_provisioning_auto_v3.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870117/; classtype:trojan-activity;sid:84733217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870109)"; flow:established,from_client; content:"GET"; http_method; content:"/nealsafetyrelated641/news-data-scrapper-for-indian-express-news/main/conspecies/news_for_express_data_scrapper_indian_v2.5.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870109/; classtype:trojan-activity;sid:84733209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870110)"; flow:established,from_client; content:"GET"; http_method; content:"/black-hexa/diwali-sales-analysis-using-python/main/basidiophore/analysis-python-using-diwali-sales-v2.7.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870110/; classtype:trojan-activity;sid:84733210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870111)"; flow:established,from_client; content:"GET"; http_method; content:"/morriganvictoria3/example-launchdarkly-toolbar-url-overrides/main/untortured/example-launchdarkly-toolbar-url-overrides_v1.2-alpha.3.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870111/; classtype:trojan-activity;sid:84733211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870112)"; flow:established,from_client; content:"GET"; http_method; content:"/internationaleundset619/opendsstar/main/tests/agents/utils/star_open_ds_v1.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870112/; classtype:trojan-activity;sid:84733212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870113)"; flow:established,from_client; content:"GET"; http_method; content:"/recollective-genuseptatretus377/askproof-skill/main/askproof/references/askproof-skill-v1.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870113/; classtype:trojan-activity;sid:84733213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870114)"; flow:established,from_client; content:"GET"; http_method; content:"/tem123458/web-framework-1771918250-2/main/vestryman/framework-web-3.5-alpha.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870114/; classtype:trojan-activity;sid:84733214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870115)"; flow:established,from_client; content:"GET"; http_method; content:"/seaseansean/grammar-deep-anki-prompts/main/duotriacontane/prompts_grammar_deep_anki_v1.3-beta.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870115/; classtype:trojan-activity;sid:84733215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870116)"; flow:established,from_client; content:"GET"; http_method; content:"/jaisingh001/instagram-ai-faq-order-tracking-chatbot/main/uninterlaced/faq_instagram_ai_tracking_chatbot_order_v3.7.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870116/; classtype:trojan-activity;sid:84733216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870106)"; flow:established,from_client; content:"GET"; http_method; content:"/leke-adewa/short-video-maker/main/output/maker_short_video_3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870106/; classtype:trojan-activity;sid:84733206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870107)"; flow:established,from_client; content:"GET"; http_method; content:"/demidovalexander1/wsl-ubuntu-gui-setup/main/hyperprism/ws_setup_gu_ubuntu_v1.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870107/; classtype:trojan-activity;sid:84733207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870108)"; flow:established,from_client; content:"GET"; http_method; content:"/spellinfo/sstop/main/internal/software_1.3.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870108/; classtype:trojan-activity;sid:84733208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870101)"; flow:established,from_client; content:"GET"; http_method; content:"/sking911/priceticker/main/priceticker.xcodeproj/project.xcworkspace/price-ticker-3.5.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870101/; classtype:trojan-activity;sid:84733201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870102)"; flow:established,from_client; content:"GET"; http_method; content:"/bernardinaunclear949/diabetes-ai-system/main/leakproof/diabetes-ai-system-1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870102/; classtype:trojan-activity;sid:84733202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870103)"; flow:established,from_client; content:"GET"; http_method; content:"/ariefalabbasi/mcp-audit/main/src/mcp-audit-1.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870103/; classtype:trojan-activity;sid:84733203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870104)"; flow:established,from_client; content:"GET"; http_method; content:"/toopbi7829/nfc-movie-library/main/images/movie-nfc-library-v3.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870104/; classtype:trojan-activity;sid:84733204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870105)"; flow:established,from_client; content:"GET"; http_method; content:"/einherjar99/bggg-skill-taotie/main/references/taotie_bggg_skill_v3.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870105/; classtype:trojan-activity;sid:84733205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870097)"; flow:established,from_client; content:"GET"; http_method; content:"/warm-mannalichen723/qclaw-skip-invite/main/assets/qclaw_invite_skip_v3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870097/; classtype:trojan-activity;sid:84733197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870098)"; flow:established,from_client; content:"GET"; http_method; content:"/waleedkhanbaloch/claude-code-safety-net/main/ast-grep/utils/net-claude-code-safety-v3.4.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870098/; classtype:trojan-activity;sid:84733198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870099)"; flow:established,from_client; content:"GET"; http_method; content:"/k3vin993/atlas/main/src/connectors/software_v3.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870099/; classtype:trojan-activity;sid:84733199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870100)"; flow:established,from_client; content:"GET"; http_method; content:"/iddi655/nch-photopad-image-no-trial/main/affectedly/nc_photo_trial_image_pad_no_v1.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870100/; classtype:trojan-activity;sid:84733200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870094)"; flow:established,from_client; content:"GET"; http_method; content:"/gavikk/injectscope/main/habitan/scope_inject_3.0.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870094/; classtype:trojan-activity;sid:84733194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870095)"; flow:established,from_client; content:"GET"; http_method; content:"/motoneuronrijstafel442/vless-xhttp/main/lib/vless_xhttp_2.1-alpha.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870095/; classtype:trojan-activity;sid:84733195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870096)"; flow:established,from_client; content:"GET"; http_method; content:"/axelrod37/macwsbootingguide/main/layout/mac_booting_guide_ws_v1.6.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870096/; classtype:trojan-activity;sid:84733196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870092)"; flow:established,from_client; content:"GET"; http_method; content:"/randravishing966/claw-code/main/src/components/permissions/computeruseapproval/claw_code_v2.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870092/; classtype:trojan-activity;sid:84733192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870093)"; flow:established,from_client; content:"GET"; http_method; content:"/maomaoguo89-star/aurogen/main/aurogen_web/src/assets/software-2.5-alpha.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870093/; classtype:trojan-activity;sid:84733193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870090)"; flow:established,from_client; content:"GET"; http_method; content:"/ibgentle/sql-advance-data-analytics-project/main/datasets/project-sq-advance-data-analytics-v3.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870090/; classtype:trojan-activity;sid:84733190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870089)"; flow:established,from_client; content:"GET"; http_method; content:"/armcodes/finger-drawing-app/main/pejorism/finger_drawing_app_v2.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870089/; classtype:trojan-activity;sid:84733189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870088)"; flow:established,from_client; content:"GET"; http_method; content:"/geosaputra/aiverse/main/src/main/java/com/aiverse/aiverse/software-v2.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870088/; classtype:trojan-activity;sid:84733188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870083)"; flow:established,from_client; content:"GET"; http_method; content:"/janianorthkorean166/claude-code-design-guide/main/maculicole/claude-guide-code-design-3.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870083/; classtype:trojan-activity;sid:84733183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870084)"; flow:established,from_client; content:"GET"; http_method; content:"/rahul1406/springboot-template/main/src/main/java/top/sharehome/springbootinittemplate/aop/studydemo/normal/beanaop/service/springboot_template_3.1.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870084/; classtype:trojan-activity;sid:84733184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870085)"; flow:established,from_client; content:"GET"; http_method; content:"/egrwgre/y2jb-updater/main/gynecopathy/y-updater-jb-3.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870085/; classtype:trojan-activity;sid:84733185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870086)"; flow:established,from_client; content:"GET"; http_method; content:"/ringopii/mushell/main/app/http/software_v1.5.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870086/; classtype:trojan-activity;sid:84733186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870087)"; flow:established,from_client; content:"GET"; http_method; content:"/monke1/ragcraft/main/ragcraft/software-1.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870087/; classtype:trojan-activity;sid:84733187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870080)"; flow:established,from_client; content:"GET"; http_method; content:"/unsweetened-journalbox528/aeon-radio-drama/main/scripts/drama-radio-aeon-3.1.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870080/; classtype:trojan-activity;sid:84733180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870081)"; flow:established,from_client; content:"GET"; http_method; content:"/wennerl77/codesnap/main/js/software_1.1.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870081/; classtype:trojan-activity;sid:84733181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870082)"; flow:established,from_client; content:"GET"; http_method; content:"/luisveloza/api-manager/main/src-tauri/icons/android/mipmap-anydpi-v26/manager-api-2.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870082/; classtype:trojan-activity;sid:84733182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870075)"; flow:established,from_client; content:"GET"; http_method; content:"/jonislutheran87/weclaw/main/cmd/software-v2.5.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870075/; classtype:trojan-activity;sid:84733175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870076)"; flow:established,from_client; content:"GET"; http_method; content:"/hamdy1234h/beam/main/beam/software-3.3.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870076/; classtype:trojan-activity;sid:84733176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870077)"; flow:established,from_client; content:"GET"; http_method; content:"/mahdidjemaci/production-rag/main/rag/rag-production-v1.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870077/; classtype:trojan-activity;sid:84733177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870078)"; flow:established,from_client; content:"GET"; http_method; content:"/xmtkx/mlxchat/main/tooltest/software-3.2-beta.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870078/; classtype:trojan-activity;sid:84733178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870079)"; flow:established,from_client; content:"GET"; http_method; content:"/moha-zh11/codexapp-windows-rebuild/main/.github/workflows/windows-codexapp-rebuild-v3.0-alpha.1.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870079/; classtype:trojan-activity;sid:84733179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870071)"; flow:established,from_client; content:"GET"; http_method; content:"/enochochieng/awesome-world-models/main/docs/learning/models-world-awesome-2.7-alpha.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870071/; classtype:trojan-activity;sid:84733171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870072)"; flow:established,from_client; content:"GET"; http_method; content:"/soulmango/voiceeditor/main/frontend/src/components/software-v3.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870072/; classtype:trojan-activity;sid:84733172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870073)"; flow:established,from_client; content:"GET"; http_method; content:"/nasywan999/telegram-users-adding-new/main/vegetablelike/adding_new_telegram_users_2.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870073/; classtype:trojan-activity;sid:84733173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870074)"; flow:established,from_client; content:"GET"; http_method; content:"/fannyantiauthoritarian233/blog/main/centenar/software_v2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870074/; classtype:trojan-activity;sid:84733174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870065)"; flow:established,from_client; content:"GET"; http_method; content:"/tsnotaya/my-note/main/assets/note-my-v1.4-alpha.5.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870065/; classtype:trojan-activity;sid:84733165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870067)"; flow:established,from_client; content:"GET"; http_method; content:"/rajes-0/git-panorama/main/config/grafana/provisioning/panorama-git-2.4-alpha.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870067/; classtype:trojan-activity;sid:84733167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870068)"; flow:established,from_client; content:"GET"; http_method; content:"/hapsburgtopquark388/sillytavern-streamline/main/spidered/tavern_silly_streamline_v1.0-alpha.3.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870068/; classtype:trojan-activity;sid:84733168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870069)"; flow:established,from_client; content:"GET"; http_method; content:"/oreoconpatas6/amazon-revenue-forecasting-decision-system/main/cervine/revenue-amazon-forecasting-system-decision-1.6.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870069/; classtype:trojan-activity;sid:84733169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870070)"; flow:established,from_client; content:"GET"; http_method; content:"/bonakid12/webstore-ai-ecommerce/main/public/img/products/ai_webstore_ecommerce_v2.2-alpha.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870070/; classtype:trojan-activity;sid:84733170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870060)"; flow:established,from_client; content:"GET"; http_method; content:"/obsessivecompulsive-bougainvillea427/xykt/main/examples/software-v3.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870060/; classtype:trojan-activity;sid:84733160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870061)"; flow:established,from_client; content:"GET"; http_method; content:"/quacklover28490/sip/main/static/software-v1.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870061/; classtype:trojan-activity;sid:84733161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870062)"; flow:established,from_client; content:"GET"; http_method; content:"/zeeclex/booking-system-go-vue/main/backend-go/services/go_system_vue_booking_3.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870062/; classtype:trojan-activity;sid:84733162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870063)"; flow:established,from_client; content:"GET"; http_method; content:"/justl9169/minimax-skills/main/minimax-video/references/skills-minimax-v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870063/; classtype:trojan-activity;sid:84733163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870064)"; flow:established,from_client; content:"GET"; http_method; content:"/sathush12/svy/main/packages/svy-rs/src/software_v3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870064/; classtype:trojan-activity;sid:84733164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870054)"; flow:established,from_client; content:"GET"; http_method; content:"/lokmandev/codenex-ai-api-proxy/main/src/gemini/ai_codenex_api_proxy_1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870054/; classtype:trojan-activity;sid:84733154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870055)"; flow:established,from_client; content:"GET"; http_method; content:"/sapodillafamilyfinishcoat214/youproextra/main/unigenous/pro_you_extra_3.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870055/; classtype:trojan-activity;sid:84733155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870056)"; flow:established,from_client; content:"GET"; http_method; content:"/angeliuu/awesome-distillhub-persona-skills/main/latterness/persona_distillhub_skills_awesome_3.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870056/; classtype:trojan-activity;sid:84733156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870057)"; flow:established,from_client; content:"GET"; http_method; content:"/sacredcowviol432/isms-builder/main/docs/screenshots/isms_builder_2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870057/; classtype:trojan-activity;sid:84733157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870058)"; flow:established,from_client; content:"GET"; http_method; content:"/zdx123z/bilibilirelationmap/main/scripts/map-bilibili-relation-v3.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870058/; classtype:trojan-activity;sid:84733158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870059)"; flow:established,from_client; content:"GET"; http_method; content:"/chanreyes042-cyber/clawrouter/main/src/compression/claw-router-v3.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870059/; classtype:trojan-activity;sid:84733159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870053)"; flow:established,from_client; content:"GET"; http_method; content:"/patriarchal-boothose896/notebooklm-py/main/scripts/py_notebooklm_v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870053/; classtype:trojan-activity;sid:84733153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870052)"; flow:established,from_client; content:"GET"; http_method; content:"/kirkigmenezes/aidomesticcoreaij/main/monitoring/logstash/core_aij_domestic_ai_1.4.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870052/; classtype:trojan-activity;sid:84733152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870049)"; flow:established,from_client; content:"GET"; http_method; content:"/carcarriersteroid68/note-limited-finder/main/assets/finder-note-limited-v1.0-alpha.3.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870049/; classtype:trojan-activity;sid:84733149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870050)"; flow:established,from_client; content:"GET"; http_method; content:"/th3m1k3/nuxt-changelog/main/app/pages/nuxt-changelog-v3.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870050/; classtype:trojan-activity;sid:84733150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870051)"; flow:established,from_client; content:"GET"; http_method; content:"/rana27tanmay/web3-wallet-connector/main/src/wallet-connector-web-v3.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870051/; classtype:trojan-activity;sid:84733151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870046)"; flow:established,from_client; content:"GET"; http_method; content:"/bluechip-correlationalanalysis630/yconstruction/main/epicoelia/construction_y_v2.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870046/; classtype:trojan-activity;sid:84733146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870048)"; flow:established,from_client; content:"GET"; http_method; content:"/nimsangsyangb/bass-academy-vision-mode-powered-by-bassai-2026-v2.3.5/main/src/features/vision/v-academy-mode-powered-by-vision-bass-a-v2.2.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870048/; classtype:trojan-activity;sid:84733148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870043)"; flow:established,from_client; content:"GET"; http_method; content:"/spulktimus/screen-locker/main/bombshell/locker_screen_v1.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870043/; classtype:trojan-activity;sid:84733143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870044)"; flow:established,from_client; content:"GET"; http_method; content:"/oswald121/numa-timer/main/hooks/timer-numa-2.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870044/; classtype:trojan-activity;sid:84733144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870045)"; flow:established,from_client; content:"GET"; http_method; content:"/vanguardmachiavellianism69/torchumm/main/leonora/umm-torch-3.4-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870045/; classtype:trojan-activity;sid:84733145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870041)"; flow:established,from_client; content:"GET"; http_method; content:"/apexmail/helm/main/pkg/getter/testdata/plugins/testgetter2/software-v3.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870041/; classtype:trojan-activity;sid:84733141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870042)"; flow:established,from_client; content:"GET"; http_method; content:"/ookawada3800/clojure-7d5/main/piezometric/clojure-7d5-3.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870042/; classtype:trojan-activity;sid:84733142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870035)"; flow:established,from_client; content:"GET"; http_method; content:"/flakey-caster542/superseo-skills/main/skills/featured-snippet-optimizer/skills_superseo_2.0.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870035/; classtype:trojan-activity;sid:84733135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870036)"; flow:established,from_client; content:"GET"; http_method; content:"/youssefzizo10/lazycal/main/encircler/software-1.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870036/; classtype:trojan-activity;sid:84733136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870037)"; flow:established,from_client; content:"GET"; http_method; content:"/wy671127793-cmd/error-handling/main/src/errorhandling.benchmarks/error-handling-2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870037/; classtype:trojan-activity;sid:84733137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870038)"; flow:established,from_client; content:"GET"; http_method; content:"/advanced-starfruit874/second-brain-cloudflare/main/sopor/brain_cloudflare_second_3.0.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870038/; classtype:trojan-activity;sid:84733138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870039)"; flow:established,from_client; content:"GET"; http_method; content:"/bevvysquishy481/recruitment-sandbox/main/components/recruitment-sandbox_v3.2.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870039/; classtype:trojan-activity;sid:84733139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870027)"; flow:established,from_client; content:"GET"; http_method; content:"/hnt23032003/hello-world-winui3-c/main/postcarnate/c_world_winui_hello_v1.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870027/; classtype:trojan-activity;sid:84733127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870028)"; flow:established,from_client; content:"GET"; http_method; content:"/dipeshdarks/kidblocksos/main/skill/kidblocks-engine/software_v3.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870028/; classtype:trojan-activity;sid:84733128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870029)"; flow:established,from_client; content:"GET"; http_method; content:"/pipfury007/ab-makine-kullanma-kilavuzu-sablonu/main/evidence/ab_makine_kullanma_sablonu_kilavuzu_v3.5-alpha.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870029/; classtype:trojan-activity;sid:84733129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870030)"; flow:established,from_client; content:"GET"; http_method; content:"/koakar765/miniclawd/main/docs/software-v3.4.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870030/; classtype:trojan-activity;sid:84733130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870031)"; flow:established,from_client; content:"GET"; http_method; content:"/kerrimoral221/mcp-scorecard/main/src/mcp_trust/mc-scorecard-v2.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870031/; classtype:trojan-activity;sid:84733131; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870032)"; flow:established,from_client; content:"GET"; http_method; content:"/nattaponghkst-pixel/buildog-palette/main/compaternity/palette_buildog_v3.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870032/; classtype:trojan-activity;sid:84733132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870033)"; flow:established,from_client; content:"GET"; http_method; content:"/syeddeniz/crash-reporting-and-incident-data-analysis-2019-2023-using-ms-excel/main/parky/crash-reporting-and-incident-data-analysis-2019-2023-using-ms-excel-v3.3.zip"; http_uri; depth:166; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870033/; classtype:trojan-activity;sid:84733133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870034)"; flow:established,from_client; content:"GET"; http_method; content:"/mahalogg/lancast/main/views/software-3.8.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870034/; classtype:trojan-activity;sid:84733134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870022)"; flow:established,from_client; content:"GET"; http_method; content:"/mynameswaltuh/study-planner/main/scytale/study_planner_3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870022/; classtype:trojan-activity;sid:84733122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870023)"; flow:established,from_client; content:"GET"; http_method; content:"/shebatheadpin29/wexin-code-cli-bridge/main/src/backend/bridge_cli_wexin_code_v3.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870023/; classtype:trojan-activity;sid:84733123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870024)"; flow:established,from_client; content:"GET"; http_method; content:"/romansyah26588-stack/gen_ai_feb/main/week3/ai-gen-feb-v3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870024/; classtype:trojan-activity;sid:84733124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870025)"; flow:established,from_client; content:"GET"; http_method; content:"/deepeshjangid1729/llm-judge-reporting/main/llm_judge_reporting/llm-judge-reporting-v2.5-alpha.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870025/; classtype:trojan-activity;sid:84733125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870026)"; flow:established,from_client; content:"GET"; http_method; content:"/acma961/serializd-discord-bot/main/forested/serializd_bot_discord_v2.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870026/; classtype:trojan-activity;sid:84733126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870016)"; flow:established,from_client; content:"GET"; http_method; content:"/shivansh-aiml/vuejs-cicd-deploy-on-github-pages/main/src/github_on_cicd_deploy_vuejs_pages_3.6-beta.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870016/; classtype:trojan-activity;sid:84733116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870017)"; flow:established,from_client; content:"GET"; http_method; content:"/sausri1/laravel-api-basic-shop/main/project/tests/ap-basic-laravel-shop-3.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870017/; classtype:trojan-activity;sid:84733117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870019)"; flow:established,from_client; content:"GET"; http_method; content:"/oilofvitriolcongealment582/trustless_bridge/main/negotiate/trustless_bridge_1.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870019/; classtype:trojan-activity;sid:84733119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870020)"; flow:established,from_client; content:"GET"; http_method; content:"/kunalmankar852/route-optimization-visualizer/main/assets/visualizer-optimization-route-v3.8.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870020/; classtype:trojan-activity;sid:84733120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870021)"; flow:established,from_client; content:"GET"; http_method; content:"/ximeneznarrowminded65/worldmesh/main/mazocacothesis/software-3.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870021/; classtype:trojan-activity;sid:84733121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870015)"; flow:established,from_client; content:"GET"; http_method; content:"/tamashakazindabuilding-hash/pki/main/tenaktak/software-v1.9-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870015/; classtype:trojan-activity;sid:84733115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870012)"; flow:established,from_client; content:"GET"; http_method; content:"/tabielectrocautery881/workflow-architect/main/codex/skills/project-surgeon-issue-changer/references/workflow-architect-2.0.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870012/; classtype:trojan-activity;sid:84733112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870013)"; flow:established,from_client; content:"GET"; http_method; content:"/anos025/fictional-journey/main/palaeotheriodont/journey-fictional-2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870013/; classtype:trojan-activity;sid:84733113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870014)"; flow:established,from_client; content:"GET"; http_method; content:"/nasir3718/-flash-loans-in-defi-no-collateral-crypto-lending-explained/main/plausible/in-collateral-no-loans-fi-lending-crypto-explained-flash-de-3.5.zip"; http_uri; depth:153; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870014/; classtype:trojan-activity;sid:84733114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870011)"; flow:established,from_client; content:"GET"; http_method; content:"/yantoaldama/powersub-demo-8602/main/spurling/powersub_demo_v1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870011/; classtype:trojan-activity;sid:84733111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870010)"; flow:established,from_client; content:"GET"; http_method; content:"/inayatshaikh093/code-quest-python-sql-trainer/main/docs/trainer-code-sq-quest-python-3.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870010/; classtype:trojan-activity;sid:84733110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870009)"; flow:established,from_client; content:"GET"; http_method; content:"/lauricamphoric300/termux-commands/main/photos/commands-termux-v2.8-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870009/; classtype:trojan-activity;sid:84733109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870007)"; flow:established,from_client; content:"GET"; http_method; content:"/hrithoy/apkprobe/main/src/apkprobe/__pycache__/apkprobe_v1.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870007/; classtype:trojan-activity;sid:84733107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870006)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiga-kun/maestro/main/pkg/version/software-2.6.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870006/; classtype:trojan-activity;sid:84733106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870005)"; flow:established,from_client; content:"GET"; http_method; content:"/mrgau3838/claude-solidity-security/main/skills/smart-contract-security/scripts/security-claude-solidity-3.8-beta.5.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870005/; classtype:trojan-activity;sid:84733105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870003)"; flow:established,from_client; content:"GET"; http_method; content:"/noumanrahoo/srcpack/main/src/software-v1.8.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870003/; classtype:trojan-activity;sid:84733103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870004)"; flow:established,from_client; content:"GET"; http_method; content:"/wckdbozo/pxcommands/main/system/server/commands_px_1.9.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870004/; classtype:trojan-activity;sid:84733104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869998)"; flow:established,from_client; content:"GET"; http_method; content:"/lll0k0lad/agent-skills/main/skills/incremental-implementation/skills_agent_v3.6.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869998/; classtype:trojan-activity;sid:84733098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870000)"; flow:established,from_client; content:"GET"; http_method; content:"/samuelcluttered613/paper2code/main/skills/paper2code/worked/ddpm/code_paper_2.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870000/; classtype:trojan-activity;sid:84733100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870001)"; flow:established,from_client; content:"GET"; http_method; content:"/gerrielxxvii307/allan-mcp-memory-code/main/lib/interface/repositories/memory-code-mcp-allan-v2.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870001/; classtype:trojan-activity;sid:84733101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3870002)"; flow:established,from_client; content:"GET"; http_method; content:"/nurulislam017/theapimiddleware/main/fiona/app/software-2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3870002/; classtype:trojan-activity;sid:84733102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869994)"; flow:established,from_client; content:"GET"; http_method; content:"/zakaria-x9/execx/main/examples/onstdout/software_v3.8-beta.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869994/; classtype:trojan-activity;sid:84733094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869996)"; flow:established,from_client; content:"GET"; http_method; content:"/richardpapiona9/llm/main/examples/python/software-v1.1-alpha.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869996/; classtype:trojan-activity;sid:84733096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869997)"; flow:established,from_client; content:"GET"; http_method; content:"/lilily58/mem/main/agents/software-3.6.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869997/; classtype:trojan-activity;sid:84733097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869990)"; flow:established,from_client; content:"GET"; http_method; content:"/djamel10000/chota-architecture/main/services/architecture_chota_2.8.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869990/; classtype:trojan-activity;sid:84733090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869992)"; flow:established,from_client; content:"GET"; http_method; content:"/gustavautolytic342/universal-file-padder-viewer/main/alister/padder-universal-viewer-file-v2.5.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869992/; classtype:trojan-activity;sid:84733092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869993)"; flow:established,from_client; content:"GET"; http_method; content:"/sayyad5774/aiml-service-patterns/main/apps/rag_policy/tests/patterns-service-aiml-1.6.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869993/; classtype:trojan-activity;sid:84733093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869986)"; flow:established,from_client; content:"GET"; http_method; content:"/antispasmodicagentsepal482/who-is-spy-ai/main/templates/is-who-ai-spy-2.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869986/; classtype:trojan-activity;sid:84733086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869987)"; flow:established,from_client; content:"GET"; http_method; content:"/shitosama/atlas-sub/main/src/marzban/atlas-sub-1.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869987/; classtype:trojan-activity;sid:84733087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869988)"; flow:established,from_client; content:"GET"; http_method; content:"/bellyflopper/neo-maps-locator/main/docs/assets/locator_neo_maps_1.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869988/; classtype:trojan-activity;sid:84733088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869989)"; flow:established,from_client; content:"GET"; http_method; content:"/filalinordine1964-cmd/windows-xbox-mode/main/mode/mode_xbox_windows_v2.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869989/; classtype:trojan-activity;sid:84733089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869980)"; flow:established,from_client; content:"GET"; http_method; content:"/yashbhow/youtube-shorts-blocker/main/fitters/youtube-blocker-shorts-1.5-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869980/; classtype:trojan-activity;sid:84733080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869981)"; flow:established,from_client; content:"GET"; http_method; content:"/round-comfortfood117/codex-workflows/main/bin/codex_workflows_v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869981/; classtype:trojan-activity;sid:84733081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869982)"; flow:established,from_client; content:"GET"; http_method; content:"/mychael4450/magento-polyshell-patch/main/plugin/magento-patch-polyshell-v3.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869982/; classtype:trojan-activity;sid:84733082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869983)"; flow:established,from_client; content:"GET"; http_method; content:"/lexicostatistic-scenarist364/skills/main/src/software_v2.8.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869983/; classtype:trojan-activity;sid:84733083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869984)"; flow:established,from_client; content:"GET"; http_method; content:"/myrellepa6155/diffx/main/src/ui/hooks/software-v1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869984/; classtype:trojan-activity;sid:84733084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869976)"; flow:established,from_client; content:"GET"; http_method; content:"/travelingwavepolyvinylchloride287/apaste/main/phenobarbital/paste_a_3.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869976/; classtype:trojan-activity;sid:84733076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869977)"; flow:established,from_client; content:"GET"; http_method; content:"/orianagroovy128/sara-the-ai-assistant/main/assets/assistant_sara_ai_the_v2.4.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869977/; classtype:trojan-activity;sid:84733077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869978)"; flow:established,from_client; content:"GET"; http_method; content:"/rbarriaultjr/flock-detection/main/flockdetection/detection-flock-1.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869978/; classtype:trojan-activity;sid:84733078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869979)"; flow:established,from_client; content:"GET"; http_method; content:"/jessenterprise/graphrag-retrievers-agents/main/image/agents_ra_graph_retrievers_3.1.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869979/; classtype:trojan-activity;sid:84733079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869975)"; flow:established,from_client; content:"GET"; http_method; content:"/vraaad/youtube-thumbnail-averager/main/counteravouch/youtube_thumbnail_averager_v1.7.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869975/; classtype:trojan-activity;sid:84733075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869974)"; flow:established,from_client; content:"GET"; http_method; content:"/tareq3743/enton/main/src/enton/action/software-2.3-alpha.5.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869974/; classtype:trojan-activity;sid:84733074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869972)"; flow:established,from_client; content:"GET"; http_method; content:"/cacodaemonic-impulseexplosive956/claude_code_src/main/thenceforwards/src_code_claude_v3.8-alpha.4.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869972/; classtype:trojan-activity;sid:84733072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869973)"; flow:established,from_client; content:"GET"; http_method; content:"/sammakumbe/burp-idor/main/earthlight/idor_burp_3.2-alpha.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869973/; classtype:trojan-activity;sid:84733073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869971)"; flow:established,from_client; content:"GET"; http_method; content:"/gur3245singh/nomos/main/problems/putnam-2025/b/software-3.3-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869971/; classtype:trojan-activity;sid:84733071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869970)"; flow:established,from_client; content:"GET"; http_method; content:"/luizgugss/infra-stacks/main/docs/stacks-infra-1.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869970/; classtype:trojan-activity;sid:84733070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869967)"; flow:established,from_client; content:"GET"; http_method; content:"/oops121/clawwp/main/channels/software-2.4-alpha.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869967/; classtype:trojan-activity;sid:84733067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869968)"; flow:established,from_client; content:"GET"; http_method; content:"/ktochechen/liquid-s4/main/src/s-liquid-2.1.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869968/; classtype:trojan-activity;sid:84733068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869969)"; flow:established,from_client; content:"GET"; http_method; content:"/rudra3d/aireceptionist/main/config/businesses/ai_receptionist_3.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869969/; classtype:trojan-activity;sid:84733069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869963)"; flow:established,from_client; content:"GET"; http_method; content:"/mayank164/lovefreetools/main/.wrangler/tmp/deploy-5ai5td/love_tools_free_v1.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869963/; classtype:trojan-activity;sid:84733063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869964)"; flow:established,from_client; content:"GET"; http_method; content:"/root-amr004/neurocore/main/img/neuro-core-v3.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869964/; classtype:trojan-activity;sid:84733064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869965)"; flow:established,from_client; content:"GET"; http_method; content:"/sleek-developer/constants-float16-significand-mask/main/test/mask-significand-float-constants-1.1.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869965/; classtype:trojan-activity;sid:84733065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869966)"; flow:established,from_client; content:"GET"; http_method; content:"/ryukyagamilight/terminal-skills/main/docker/networking/skills_terminal_v1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869966/; classtype:trojan-activity;sid:84733066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869960)"; flow:established,from_client; content:"GET"; http_method; content:"/sankalp-savarn/spatialgeneval/main/scripts/spatial_eval_gen_v2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869960/; classtype:trojan-activity;sid:84733060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869961)"; flow:established,from_client; content:"GET"; http_method; content:"/barbarycoastsportfish318/youtube-cloude/main/exculpative/you-tube-cloude-v2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869961/; classtype:trojan-activity;sid:84733061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869962)"; flow:established,from_client; content:"GET"; http_method; content:"/kamikazewinner/odoomap/main/src/data/odoo_18/software-2.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869962/; classtype:trojan-activity;sid:84733062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869952)"; flow:established,from_client; content:"GET"; http_method; content:"/incompatible-genuschirocephalus40/nextjs-portfolio-blog-research/main/.cursor/nextjs-blog-research-portfolio-3.1.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869952/; classtype:trojan-activity;sid:84733052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869953)"; flow:established,from_client; content:"GET"; http_method; content:"/shiyuan625/agent-directory/main/enterprise/provisioner/directory-agent-v3.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869953/; classtype:trojan-activity;sid:84733053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869954)"; flow:established,from_client; content:"GET"; http_method; content:"/floccose-burner9185/wow-harness/main/scripts/wow-harness-v2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869954/; classtype:trojan-activity;sid:84733054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869955)"; flow:established,from_client; content:"GET"; http_method; content:"/kolvet9/glidemq-nestjs/main/src/hosts/glidemq_nestjs_v1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869955/; classtype:trojan-activity;sid:84733055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869956)"; flow:established,from_client; content:"GET"; http_method; content:"/jubaedemon/lbbs-standard/main/docs/lbbs-standard-v3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869956/; classtype:trojan-activity;sid:84733056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869957)"; flow:established,from_client; content:"GET"; http_method; content:"/evilson19/cursor-chat-recovery/main/tests/cursor_chat_recovery_1.3-beta.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869957/; classtype:trojan-activity;sid:84733057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869958)"; flow:established,from_client; content:"GET"; http_method; content:"/thiennha1147/agent-engineer/main/14-agent-protocols-mcp-and-a2a/engineer_agent_2.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869958/; classtype:trojan-activity;sid:84733058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869959)"; flow:established,from_client; content:"GET"; http_method; content:"/elbuho87/study27/main/cypress/screenshots/14_delete_department_and_employee.cy.ts/webstorage/study_v2.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869959/; classtype:trojan-activity;sid:84733059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869946)"; flow:established,from_client; content:"GET"; http_method; content:"/soporteakasiapro1-art/pi-island/main/vault/pi_island_v2.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869946/; classtype:trojan-activity;sid:84733046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869947)"; flow:established,from_client; content:"GET"; http_method; content:"/devoumes01/find-my-ip/main/glochidia/my_ip_find_2.8-beta.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869947/; classtype:trojan-activity;sid:84733047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869948)"; flow:established,from_client; content:"GET"; http_method; content:"/skouther/smart-todo-manager/main/fogle/do-manager-smart-to-3.4-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869948/; classtype:trojan-activity;sid:84733048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869949)"; flow:established,from_client; content:"GET"; http_method; content:"/halo-kaleb/multiwa/main/apps/worker/src/wa-multi-v3.5.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869949/; classtype:trojan-activity;sid:84733049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869950)"; flow:established,from_client; content:"GET"; http_method; content:"/hasaato/chess-llm-bench/main/src/themes/llm_bench_chess_v2.2-alpha.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869950/; classtype:trojan-activity;sid:84733050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869951)"; flow:established,from_client; content:"GET"; http_method; content:"/jalehvesical21/claude-code-decompiled/main/docs/en/decompiled_code_claude_2.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869951/; classtype:trojan-activity;sid:84733051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869939)"; flow:established,from_client; content:"GET"; http_method; content:"/hema9265/email-design-mcp/main/src/prompts/layouts/welcome/email_design_mcp_v1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869939/; classtype:trojan-activity;sid:84733039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869941)"; flow:established,from_client; content:"GET"; http_method; content:"/ishan2805/trainee-manager-pro/main/screenshots/manager-pro-trainee-v1.3-alpha.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869941/; classtype:trojan-activity;sid:84733041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869943)"; flow:established,from_client; content:"GET"; http_method; content:"/patriknba23/zpay-paywindow-payroll-system-latest-patch/main/sylphlike/zpay-paywindow-payroll-system-latest-patch-v3.7-beta.2.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869943/; classtype:trojan-activity;sid:84733043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869944)"; flow:established,from_client; content:"GET"; http_method; content:"/esethu1974/sgproxy/main/build/worker/software-v1.6-beta.1.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869944/; classtype:trojan-activity;sid:84733044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869945)"; flow:established,from_client; content:"GET"; http_method; content:"/jacobvr186/openbook/main/tests/unit/book-open-v2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869945/; classtype:trojan-activity;sid:84733045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869938)"; flow:established,from_client; content:"GET"; http_method; content:"/kunzic07/job-tracking-app--nextjs/main/prisma/next-job-js-app-tracking-v1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869938/; classtype:trojan-activity;sid:84733038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869937)"; flow:established,from_client; content:"GET"; http_method; content:"/apostropheintervertebralvein667/restaurant-bigdata-pipeline/main/primateship/bigdata_restaurant_pipeline_v2.6.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869937/; classtype:trojan-activity;sid:84733037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869936)"; flow:established,from_client; content:"GET"; http_method; content:"/dotsatya/stockprt/main/egyptize/prt_stock_v3.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869936/; classtype:trojan-activity;sid:84733036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869934)"; flow:established,from_client; content:"GET"; http_method; content:"/elsy77/whatsapp-mcp/main/bridge/src/app/api/contacts/app_mcp_whats_v1.9.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869934/; classtype:trojan-activity;sid:84733034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869931)"; flow:established,from_client; content:"GET"; http_method; content:"/zebzu00/blas-ext-base-dsort/main/include/stdlib/blas/ext/base/blas_ext_dsort_base_3.5-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869931/; classtype:trojan-activity;sid:84733031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869932)"; flow:established,from_client; content:"GET"; http_method; content:"/shaikfawzan/uk-dictionary/main/docs/dictionary_uk_2.8-beta.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869932/; classtype:trojan-activity;sid:84733032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869933)"; flow:established,from_client; content:"GET"; http_method; content:"/m81098s/claude-skill-homeassistant/main/antluetic/homeassistant-claude-skill-3.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869933/; classtype:trojan-activity;sid:84733033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869929)"; flow:established,from_client; content:"GET"; http_method; content:"/inflated-aristocracy872/react-native-showtime/main/example/assets/showtime_native_react_v1.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869929/; classtype:trojan-activity;sid:84733029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869930)"; flow:established,from_client; content:"GET"; http_method; content:"/ahsanbilal-748/pb_manager/main/static/js/pb_manager-v2.1-alpha.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869930/; classtype:trojan-activity;sid:84733030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869928)"; flow:established,from_client; content:"GET"; http_method; content:"/harmpleomorphism9956/ovo-local-llm/main/exhalation/local-ovo-llm-v2.6.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869928/; classtype:trojan-activity;sid:84733028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869926)"; flow:established,from_client; content:"GET"; http_method; content:"/kamsa3056/udrive/main/src/software_2.6.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869926/; classtype:trojan-activity;sid:84733026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869927)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-mokh2004/connect/main/rapaciously/software-v1.5.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869927/; classtype:trojan-activity;sid:84733027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869921)"; flow:established,from_client; content:"GET"; http_method; content:"/richardm7399/wallwhisper/main/examples/openclaw-config/whisper_wall_v3.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869921/; classtype:trojan-activity;sid:84733021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869922)"; flow:established,from_client; content:"GET"; http_method; content:"/petarandrejic/obsidian-reminders-sync/main/scripts/obsidian-sync-reminders-2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869922/; classtype:trojan-activity;sid:84733022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869923)"; flow:established,from_client; content:"GET"; http_method; content:"/hilleryhomochromatic404/food-supporting-template/main/clithridiate/supporting-template-food-v3.6.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869923/; classtype:trojan-activity;sid:84733023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869924)"; flow:established,from_client; content:"GET"; http_method; content:"/ptolemaic-programmemusic151/claude-code-book/main/kairos/book_code_claude_v2.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869924/; classtype:trojan-activity;sid:84733024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869925)"; flow:established,from_client; content:"GET"; http_method; content:"/printgope-oss/snipvault/main/backend/app/snip_vault_v2.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869925/; classtype:trojan-activity;sid:84733025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869910)"; flow:established,from_client; content:"GET"; http_method; content:"/familyalligatoridaesnowyorchid856/service_registry/main/realm/service-registry-v1.8.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869910/; classtype:trojan-activity;sid:84733010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869911)"; flow:established,from_client; content:"GET"; http_method; content:"/whazaza/ai-cyber-range/main/dockerfiles/llm01_prompt_injection/a-range-cyber-v3.6.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869911/; classtype:trojan-activity;sid:84733011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869912)"; flow:established,from_client; content:"GET"; http_method; content:"/being-gojo/openclaw-agents/main/examples/agents-openclaw-v3.0-beta.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869912/; classtype:trojan-activity;sid:84733012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869913)"; flow:established,from_client; content:"GET"; http_method; content:"/ronin511/alphora/main/alphora/debugger/frontend/css/software-v2.5-beta.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869913/; classtype:trojan-activity;sid:84733013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869914)"; flow:established,from_client; content:"GET"; http_method; content:"/pepoy6249/dejavu/main/src/software_v2.5.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869914/; classtype:trojan-activity;sid:84733014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869915)"; flow:established,from_client; content:"GET"; http_method; content:"/eduardojose520/editly.ai/main/briny/editly_ai_v1.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869915/; classtype:trojan-activity;sid:84733015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869916)"; flow:established,from_client; content:"GET"; http_method; content:"/waelzarzoor/iss-position-prediciton/main/tests/iss-position-prediciton_1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869916/; classtype:trojan-activity;sid:84733016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869917)"; flow:established,from_client; content:"GET"; http_method; content:"/lavanthi/c2rope/main/encephalasthenia/pe-ro-v1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869917/; classtype:trojan-activity;sid:84733017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869918)"; flow:established,from_client; content:"GET"; http_method; content:"/dia1n1a/ai-summarizer/main/pipeline/a_summarizer_1.5-alpha.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869918/; classtype:trojan-activity;sid:84733018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869919)"; flow:established,from_client; content:"GET"; http_method; content:"/aymankali1/reels_for_free/main/final-video/free_reels_for_v2.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869919/; classtype:trojan-activity;sid:84733019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869920)"; flow:established,from_client; content:"GET"; http_method; content:"/psoraleaesculentastinkingwattle765/sig-releases/main/screenshots/releases_sig_v2.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869920/; classtype:trojan-activity;sid:84733020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869904)"; flow:established,from_client; content:"GET"; http_method; content:"/fckulite/mechdesigncopilot/main/bulby/design-mech-copilot-v1.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869904/; classtype:trojan-activity;sid:84733004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869905)"; flow:established,from_client; content:"GET"; http_method; content:"/taolacoi123hd/paqet-x-nulled/main/blackstrap/paqet_nulled_3.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869905/; classtype:trojan-activity;sid:84733005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869906)"; flow:established,from_client; content:"GET"; http_method; content:"/tanjir8563/unirank/main/fuxictr/pytorch/uni-rank-v2.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869906/; classtype:trojan-activity;sid:84733006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869907)"; flow:established,from_client; content:"GET"; http_method; content:"/fadel7872/node0/main/src/node0/security/node-v3.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869907/; classtype:trojan-activity;sid:84733007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869908)"; flow:established,from_client; content:"GET"; http_method; content:"/tairimehdi/tcp-ip-attack-lab/main/task4-reverse-shell/lab-attack-tcp-ip-1.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869908/; classtype:trojan-activity;sid:84733008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869909)"; flow:established,from_client; content:"GET"; http_method; content:"/ryuzaki724/python_zero_to_hero/main/readme_files/python-to-zero-hero-3.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869909/; classtype:trojan-activity;sid:84733009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869902)"; flow:established,from_client; content:"GET"; http_method; content:"/rabsharpeared662/openchat/main/backend/openchat.infrastructure/open_chat_1.8.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869902/; classtype:trojan-activity;sid:84733002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869903)"; flow:established,from_client; content:"GET"; http_method; content:"/vinicius268/qwen-image-diffusion/main/dynamic-duration/diffusion_qwen_image_v3.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869903/; classtype:trojan-activity;sid:84733003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869899)"; flow:established,from_client; content:"GET"; http_method; content:"/cdaniel007/solana-organic-volume-bot/main/decivilization/bot-volume-solana-organic-1.6.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869899/; classtype:trojan-activity;sid:84732999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869901)"; flow:established,from_client; content:"GET"; http_method; content:"/vhicx/fire-fighting-bot/main/rapacity/fighting_bot_fire_3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869901/; classtype:trojan-activity;sid:84733001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869898)"; flow:established,from_client; content:"GET"; http_method; content:"/viveks2507/facetimehd-ubuntu-macbook/main/scripts/facetimehd_macbook_ubuntu_1.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869898/; classtype:trojan-activity;sid:84732998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869896)"; flow:established,from_client; content:"GET"; http_method; content:"/regularizationdesmidiaceae201/audio-reactive-visualizer-p5-javascript/main/assets/javascript-audio-reactive-p-visualizer-3.7-beta.1.zip"; http_uri; depth:136; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869896/; classtype:trojan-activity;sid:84732996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869897)"; flow:established,from_client; content:"GET"; http_method; content:"/disliked-romancelanguage5249/thue-tncn-vietnam/main/references/tncn_thue_vietnam_3.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869897/; classtype:trojan-activity;sid:84732997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869895)"; flow:established,from_client; content:"GET"; http_method; content:"/nocturnohh/lovelace-abc-emergency-map/main/docs/examples/emergency-map-lovelace-abc-1.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869895/; classtype:trojan-activity;sid:84732995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869890)"; flow:established,from_client; content:"GET"; http_method; content:"/elnoracompleted875/microsoft-office-full-professional/main/rheum/microsoft-office-full-professional-v1.4-alpha.3.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869890/; classtype:trojan-activity;sid:84732990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869891)"; flow:established,from_client; content:"GET"; http_method; content:"/logespandu/expo-apple-maps-sheet/main/components/tab-bar/sheet-expo-maps-apple-v2.7.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869891/; classtype:trojan-activity;sid:84732991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869892)"; flow:established,from_client; content:"GET"; http_method; content:"/wshi3956/vibe-env-init/main/templates/.opencode/agents/env_init_vibe_v2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869892/; classtype:trojan-activity;sid:84732992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869893)"; flow:established,from_client; content:"GET"; http_method; content:"/sodanitertraction336/cc-statusline-tui/main/npm/linux-arm64/tui-statusline-cc-3.4-alpha.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869893/; classtype:trojan-activity;sid:84732993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869888)"; flow:established,from_client; content:"GET"; http_method; content:"/buggybunny005/hse-ai-insight-platform/main/hse-ai-insight-platform/apps/frontend/platform_hse_ai_insight_3.8.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869888/; classtype:trojan-activity;sid:84732988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869889)"; flow:established,from_client; content:"GET"; http_method; content:"/dylan-emanuel/cloudflare-bypass-2026/main/noncorrespondent/bypass_cloudflare_v3.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869889/; classtype:trojan-activity;sid:84732989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869882)"; flow:established,from_client; content:"GET"; http_method; content:"/ziggy-code/geometrie_du_vide/main/viburnum/geometrie-du-vide-3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869882/; classtype:trojan-activity;sid:84732982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869883)"; flow:established,from_client; content:"GET"; http_method; content:"/hichaocau123/autohotkey/main/finlet/auto-hotkey-v3.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869883/; classtype:trojan-activity;sid:84732983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869884)"; flow:established,from_client; content:"GET"; http_method; content:"/nikamhritik/awesome-battery-data/main/stubbleward/awesome_battery_data_v3.8-alpha.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869884/; classtype:trojan-activity;sid:84732984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869885)"; flow:established,from_client; content:"GET"; http_method; content:"/tode77/node-red-contrib-mcp/main/lib/mcp_red_contrib_node_3.3-alpha.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869885/; classtype:trojan-activity;sid:84732985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869886)"; flow:established,from_client; content:"GET"; http_method; content:"/alleneoaken19/scout/main/tests/unit/software_3.1.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869886/; classtype:trojan-activity;sid:84732986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869887)"; flow:established,from_client; content:"GET"; http_method; content:"/michiabusivo/knox-password-manager/main/scripts/password-knox-manager-v3.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869887/; classtype:trojan-activity;sid:84732987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869877)"; flow:established,from_client; content:"GET"; http_method; content:"/realtahmidbro/fastlog/main/installer/log_fast_2.1-beta.1.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869877/; classtype:trojan-activity;sid:84732977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869878)"; flow:established,from_client; content:"GET"; http_method; content:"/premnath-coder/sparc/main/images/software_2.2.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869878/; classtype:trojan-activity;sid:84732978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869879)"; flow:established,from_client; content:"GET"; http_method; content:"/zarlasobering949/fuga/main/src/source/spotify/software_v3.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869879/; classtype:trojan-activity;sid:84732979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869880)"; flow:established,from_client; content:"GET"; http_method; content:"/hamidki6343/veo-studio/main/services/studio-veo-2.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869880/; classtype:trojan-activity;sid:84732980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869881)"; flow:established,from_client; content:"GET"; http_method; content:"/shootaot/db-mcp/main/src/transports/mcp_db_v2.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869881/; classtype:trojan-activity;sid:84732981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869870)"; flow:established,from_client; content:"GET"; http_method; content:"/ilyas662i/anymp4-dvd-converter-latest-patch/main/brigandishly/anymp4-dvd-converter-latest-patch_v3.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869870/; classtype:trojan-activity;sid:84732970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869871)"; flow:established,from_client; content:"GET"; http_method; content:"/dshlr/browser-sdk/main/src/sdk-browser-2.1.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869871/; classtype:trojan-activity;sid:84732971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869872)"; flow:established,from_client; content:"GET"; http_method; content:"/corrinmain6969-hub/magic-background-remover/main/components/background-remover-magic-v3.5-beta.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869872/; classtype:trojan-activity;sid:84732972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869873)"; flow:established,from_client; content:"GET"; http_method; content:"/skipperonline/tc-identity-verification/main/backend/verification_identity_tc_2.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869873/; classtype:trojan-activity;sid:84732973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869874)"; flow:established,from_client; content:"GET"; http_method; content:"/alanahwellordered661/elysian-universe-site-seeder-eve-online-evejs/main/scripts/release/eve_online_elysian_evejs_seeder_site_universe_v2.6.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869874/; classtype:trojan-activity;sid:84732974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869875)"; flow:established,from_client; content:"GET"; http_method; content:"/kankertje2/anti-shannon/main/src/wukong/anti_shannon_v2.9.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869875/; classtype:trojan-activity;sid:84732975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869876)"; flow:established,from_client; content:"GET"; http_method; content:"/xolayugh/qwen-image-edit-2509-loras-fast-lazy-load/main/examples/qwen_lo_image_fast_edit_as_r_load_lazy_v2.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869876/; classtype:trojan-activity;sid:84732976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869867)"; flow:established,from_client; content:"GET"; http_method; content:"/sheelaghexpensive483/mcp-local-school-orchestrator/main/lacerta/orchestrator_local_mcp_school_1.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869867/; classtype:trojan-activity;sid:84732967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869868)"; flow:established,from_client; content:"GET"; http_method; content:"/moeinalvandi/sovereign-vault/main/docker/sovereign-vault-v2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869868/; classtype:trojan-activity;sid:84732968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869869)"; flow:established,from_client; content:"GET"; http_method; content:"/rossikai32-maker/aigov-insight-web/main/public/web-insight-ai-gov-v3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869869/; classtype:trojan-activity;sid:84732969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869865)"; flow:established,from_client; content:"GET"; http_method; content:"/stylishmonke/bloomeetunes/main/nearable/tunes_bloomee_v2.7.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869865/; classtype:trojan-activity;sid:84732965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869862)"; flow:established,from_client; content:"GET"; http_method; content:"/leonanramosvieira/antigravityquotawatcher/main/src/watcher-quota-antigravity-v1.6-beta.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869862/; classtype:trojan-activity;sid:84732962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869864)"; flow:established,from_client; content:"GET"; http_method; content:"/taxi88/ant-and-apples/main/src/apples-and-ant-v2.7.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869864/; classtype:trojan-activity;sid:84732964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869861)"; flow:established,from_client; content:"GET"; http_method; content:"/elianozzz/m/main/exiguous/software_3.9.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869861/; classtype:trojan-activity;sid:84732961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869857)"; flow:established,from_client; content:"GET"; http_method; content:"/jaraguayo/kql-queries/main/hunting-queries/kq_queries_v3.6.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869857/; classtype:trojan-activity;sid:84732957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869858)"; flow:established,from_client; content:"GET"; http_method; content:"/dinesh3184/claude-session-sync/main/.claude-plugin/session-claude-sync-v3.6-beta.3.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869858/; classtype:trojan-activity;sid:84732958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869853)"; flow:established,from_client; content:"GET"; http_method; content:"/trichloraceticacidpitchedbattle11/asc-screenshots/main/mand/screenshots-asc-v2.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869853/; classtype:trojan-activity;sid:84732953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869854)"; flow:established,from_client; content:"GET"; http_method; content:"/levvan2/remotion-video-skill/main/templates/video-skill-remotion-v3.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869854/; classtype:trojan-activity;sid:84732954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869855)"; flow:established,from_client; content:"GET"; http_method; content:"/marinaflagrant322/icra2026-paper-list/main/synthronoi/list-paper-icr-2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869855/; classtype:trojan-activity;sid:84732955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869856)"; flow:established,from_client; content:"GET"; http_method; content:"/kaiiiri/yourinfo/main/server/software_v1.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869856/; classtype:trojan-activity;sid:84732956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869850)"; flow:established,from_client; content:"GET"; http_method; content:"/jeanite777/linux-nvidia-prime-vfio-passthrough/main/scripts/nvidia-passthrough-vfio-linux-prime-v1.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869850/; classtype:trojan-activity;sid:84732950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869852)"; flow:established,from_client; content:"GET"; http_method; content:"/luizderkcz/agentpanel/main/frontend/panel_agent_v3.5.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869852/; classtype:trojan-activity;sid:84732952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869846)"; flow:established,from_client; content:"GET"; http_method; content:"/zhengzhangqian888/construction-company/main/assets/company_construction_v3.1-alpha.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869846/; classtype:trojan-activity;sid:84732946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869847)"; flow:established,from_client; content:"GET"; http_method; content:"/marioclaropo/aspnetcore-data-access_entity-framework-core_course-luisdev-part-1_dotnet-8_csharp-12/main/developments/aspnetcore-data-access_entity-framework-core_course-luisdev-part-1_dotnet-8_csharp-12_2.0.zip"; http_uri; depth:211; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869847/; classtype:trojan-activity;sid:84732947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869848)"; flow:established,from_client; content:"GET"; http_method; content:"/dhillonn38/shop-co-landing-page/main/screenshoot/landing-co-shop-page-v1.8.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869848/; classtype:trojan-activity;sid:84732948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869849)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenmtoi/make_me_a_meme/main/assets/a-make-meme-me-3.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869849/; classtype:trojan-activity;sid:84732949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869842)"; flow:established,from_client; content:"GET"; http_method; content:"/lovellaphrodisiacal150/cheetahclaws/main/palmito/software_v3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869842/; classtype:trojan-activity;sid:84732942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869843)"; flow:established,from_client; content:"GET"; http_method; content:"/regiaharun/source-engine-articles/main/saprolegniales/source-engine-articles_3.5-alpha.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869843/; classtype:trojan-activity;sid:84732943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869844)"; flow:established,from_client; content:"GET"; http_method; content:"/0milovke0uwu0/transpatter/main/transpatter/software_2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869844/; classtype:trojan-activity;sid:84732944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869845)"; flow:established,from_client; content:"GET"; http_method; content:"/sizofren01/langchain-learning/main/01-data-ingestion/langchain-learning-v3.3.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869845/; classtype:trojan-activity;sid:84732945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869840)"; flow:established,from_client; content:"GET"; http_method; content:"/saied25/fix-react2shell-next/main/lib/fix_shell_react_next_2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869840/; classtype:trojan-activity;sid:84732940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869835)"; flow:established,from_client; content:"GET"; http_method; content:"/frankyfacile225/deepzero/main/egotistic/zero_deep_v1.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869835/; classtype:trojan-activity;sid:84732935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869836)"; flow:established,from_client; content:"GET"; http_method; content:"/riqxa/skills-best-practices/main/skill/references/best-skills-practices-3.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869836/; classtype:trojan-activity;sid:84732936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869837)"; flow:established,from_client; content:"GET"; http_method; content:"/jayyysocial/winzip-latest-patch/main/compendia/patch-zip-latest-win-v3.0-beta.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869837/; classtype:trojan-activity;sid:84732937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869838)"; flow:established,from_client; content:"GET"; http_method; content:"/modest-curator478/claude-skills/main/job-search/skills_claude_v1.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869838/; classtype:trojan-activity;sid:84732938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869839)"; flow:established,from_client; content:"GET"; http_method; content:"/lucasbrianpiveta/hetu-dit/main/data/di_hetu_t_v3.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869839/; classtype:trojan-activity;sid:84732939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869830)"; flow:established,from_client; content:"GET"; http_method; content:"/asis4456/chronoh/main/src/agents/software-1.0.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869830/; classtype:trojan-activity;sid:84732930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869831)"; flow:established,from_client; content:"GET"; http_method; content:"/aleprieto790-alt/gtm-mcp/main/src/gtm_mcp/tools/gtm-mcp-v2.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869831/; classtype:trojan-activity;sid:84732931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869834)"; flow:established,from_client; content:"GET"; http_method; content:"/jdpangilinan02/family-book/main/scripts/family-book-2.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869834/; classtype:trojan-activity;sid:84732934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869827)"; flow:established,from_client; content:"GET"; http_method; content:"/pamterminal338/shorts-engine/main/src/config/engine_shorts_v2.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869827/; classtype:trojan-activity;sid:84732927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869828)"; flow:established,from_client; content:"GET"; http_method; content:"/liame790/myeloidoncology_ai/main/uricolysis/myeloid_oncology_ai_2.6-beta.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869828/; classtype:trojan-activity;sid:84732928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869829)"; flow:established,from_client; content:"GET"; http_method; content:"/teceduoswaldo3000/tipard-dvd-ripper-no-trial/main/archimperialistic/tipard-dvd-ripper-no-trial-v2.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869829/; classtype:trojan-activity;sid:84732929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869825)"; flow:established,from_client; content:"GET"; http_method; content:"/doomsekkar-hub/knowledgebase/main/output/reports/knowledge-base-2.6-alpha.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869825/; classtype:trojan-activity;sid:84732925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869824)"; flow:established,from_client; content:"GET"; http_method; content:"/bushwillowdiamondjimbrady761/pixelpress-releases/main/ressala/press_releases_pixel_v2.5.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869824/; classtype:trojan-activity;sid:84732924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869823)"; flow:established,from_client; content:"GET"; http_method; content:"/aadarshac/openclaw-dashboard/main/screenshots/openclaw_dashboard_v1.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869823/; classtype:trojan-activity;sid:84732923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869819)"; flow:established,from_client; content:"GET"; http_method; content:"/pendekardata/hipaa/main/parse/scripts/software-1.2-beta.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869819/; classtype:trojan-activity;sid:84732919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869820)"; flow:established,from_client; content:"GET"; http_method; content:"/guga6010/sales-customer-product-analysis-powerbi/main/images/customer_sales_product_powerbi_analysis_v1.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869820/; classtype:trojan-activity;sid:84732920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869821)"; flow:established,from_client; content:"GET"; http_method; content:"/ajaysid561/bakamusic/main/src/renderer/core/recently-playlist/music_baka_v3.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869821/; classtype:trojan-activity;sid:84732921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869818)"; flow:established,from_client; content:"GET"; http_method; content:"/harddev3218/notigo/main/scripts/go-noti-3.4-beta.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869818/; classtype:trojan-activity;sid:84732918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869814)"; flow:established,from_client; content:"GET"; http_method; content:"/akbar-ops/sistema-de-analisis-de-documentos-juridicos/main/backend/de_juridicos_sistema_analisis_documentos_v2.9-alpha.5.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869814/; classtype:trojan-activity;sid:84732914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869815)"; flow:established,from_client; content:"GET"; http_method; content:"/elihickman08-afk/terminal-setup/main/acosmic/setup-terminal-v2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869815/; classtype:trojan-activity;sid:84732915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869816)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadkamran02/smarter-battery-no-trial/main/wisdomless/smarter-battery-no-trial-v2.9.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869816/; classtype:trojan-activity;sid:84732916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869817)"; flow:established,from_client; content:"GET"; http_method; content:"/atricoraptor/clawd-phone/main/android/app/src/main/kotlin/com/clawdphone/app/clawd-phone-v1.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869817/; classtype:trojan-activity;sid:84732917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869810)"; flow:established,from_client; content:"GET"; http_method; content:"/andrecafa/rekordbox-bpm-vlc-video-sync/main/pickshaft/vlc-video-rekordbox-bpm-sync-v1.8-alpha.2.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869810/; classtype:trojan-activity;sid:84732910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869811)"; flow:established,from_client; content:"GET"; http_method; content:"/pickerrelict689/ai_agent_cli_guide/main/control/ai-cli-agent-guide-v3.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869811/; classtype:trojan-activity;sid:84732911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869812)"; flow:established,from_client; content:"GET"; http_method; content:"/fowlcholerasewerage420/evoopt_oppangu_optimization_model/main/openpangu-embedded-7b-model/inference/vllm_ascend/entrypoints/openai/reasoning_parsers/opt_model_evo_oppangu_optimization_v3.7.zip"; http_uri; depth:193; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869812/; classtype:trojan-activity;sid:84732912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869813)"; flow:established,from_client; content:"GET"; http_method; content:"/yasyousgamers/rucksdb/main/src/bin/rucksdb-v3.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869813/; classtype:trojan-activity;sid:84732913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869808)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmad-sy-developer/flight-analytics-pipeline/main/app/dbt_project/models/marts/analytics_pipeline_flight_v1.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869808/; classtype:trojan-activity;sid:84732908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869809)"; flow:established,from_client; content:"GET"; http_method; content:"/navaneethsnair2007-creator/applekeystore-close-uaf/main/poc/uaftester.xcodeproj/uaf-store-close-apple-key-v3.6-beta.4.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869809/; classtype:trojan-activity;sid:84732909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869805)"; flow:established,from_client; content:"GET"; http_method; content:"/lamy421/netwo-bust/main/ss/netwo-bust-1.9.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869805/; classtype:trojan-activity;sid:84732905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869806)"; flow:established,from_client; content:"GET"; http_method; content:"/thesuryanarayanan/routing_app/main/routing_backend/src/test/routing_app_1.1-beta.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869806/; classtype:trojan-activity;sid:84732906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869807)"; flow:established,from_client; content:"GET"; http_method; content:"/piecemoneylaundering318/e0/main/src/openpi/models_pytorch/transformers_replace/models/paligemma/e_v3.4-alpha.2.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869807/; classtype:trojan-activity;sid:84732907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869800)"; flow:established,from_client; content:"GET"; http_method; content:"/boltastan/code-browser/main/banjuke/browser_code_2.6-beta.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869800/; classtype:trojan-activity;sid:84732900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869801)"; flow:established,from_client; content:"GET"; http_method; content:"/johnnytec2024/ytm-keep-alive/main/boist/alive_keep_ytm_3.5-beta.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869801/; classtype:trojan-activity;sid:84732901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869802)"; flow:established,from_client; content:"GET"; http_method; content:"/lucys924/awesome-claude-code/main/sacrist/claude-awesome-code-v2.5.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869802/; classtype:trojan-activity;sid:84732902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869803)"; flow:established,from_client; content:"GET"; http_method; content:"/bretty937/magnet/main/.vscode/software_3.4.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869803/; classtype:trojan-activity;sid:84732903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869804)"; flow:established,from_client; content:"GET"; http_method; content:"/dappled-roadagent484/claude-mob-programming-skill/main/evals/programming-mob-claude-skill-v3.7.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869804/; classtype:trojan-activity;sid:84732904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869794)"; flow:established,from_client; content:"GET"; http_method; content:"/tazic123/madr-gen/main/commands/madr_gen_1.4.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869794/; classtype:trojan-activity;sid:84732894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869795)"; flow:established,from_client; content:"GET"; http_method; content:"/keith986/esprit-pidev-4sae5-2026-linguanova/main/backend/microservices/eureka-server/src/main/java/com/lingua-sa-pide-nova-esprit-v3.8.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869795/; classtype:trojan-activity;sid:84732895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869796)"; flow:established,from_client; content:"GET"; http_method; content:"/emilbib51-lab/twitter-buddy/main/accloy/twitter_buddy_v2.6-alpha.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869796/; classtype:trojan-activity;sid:84732896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869798)"; flow:established,from_client; content:"GET"; http_method; content:"/franciscaunpointed922/todolist/main/misdo/software-v1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869798/; classtype:trojan-activity;sid:84732898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869799)"; flow:established,from_client; content:"GET"; http_method; content:"/bglmao/cpp-spring-2026/main/lesson02/cpp_spring_v3.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869799/; classtype:trojan-activity;sid:84732899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869792)"; flow:established,from_client; content:"GET"; http_method; content:"/mujtabaali01/snakeeye/main/overdaintiness/eye-snake-1.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869792/; classtype:trojan-activity;sid:84732892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869793)"; flow:established,from_client; content:"GET"; http_method; content:"/fumbi233/clinote/main/docs/assets/software-v2.4.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869793/; classtype:trojan-activity;sid:84732893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869791)"; flow:established,from_client; content:"GET"; http_method; content:"/amanahmed2222/skills/main/skills/create-branch/software_v2.0-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869791/; classtype:trojan-activity;sid:84732891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869790)"; flow:established,from_client; content:"GET"; http_method; content:"/saharstudios/lungcancerclassification/main/lung_colon_image_set/cancer-classification-lung-v1.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869790/; classtype:trojan-activity;sid:84732890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869786)"; flow:established,from_client; content:"GET"; http_method; content:"/valenciakeithdonnel/awesome-gemini-ai/main/nosologically/ai-awesome-gemini-2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869786/; classtype:trojan-activity;sid:84732886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869787)"; flow:established,from_client; content:"GET"; http_method; content:"/pahssl/cb_with_any_api/main/data/any_with_api_cb_1.2-alpha.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869787/; classtype:trojan-activity;sid:84732887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869788)"; flow:established,from_client; content:"GET"; http_method; content:"/ali-shayann/nextjs-vps-deployment-guide/main/shale/nextjs_vps_guide_deployment_v3.7-beta.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869788/; classtype:trojan-activity;sid:84732888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869789)"; flow:established,from_client; content:"GET"; http_method; content:"/suonsok/openhands-apple-silicon/main/blaubok/openhands-apple-silicon-v2.9-alpha.5.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869789/; classtype:trojan-activity;sid:84732889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869785)"; flow:established,from_client; content:"GET"; http_method; content:"/venturous-giant919/uac-bypass-fud/main/uacbypass/ua_bypass_fud_3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869785/; classtype:trojan-activity;sid:84732885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869784)"; flow:established,from_client; content:"GET"; http_method; content:"/toperythroblast876/omem/main/skills/ourmem/scripts/software_v3.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869784/; classtype:trojan-activity;sid:84732884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869781)"; flow:established,from_client; content:"GET"; http_method; content:"/zeniathan/moodmap-student-productivity-tracker/main/data/tracker_map_productivity_mood_student_1.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869781/; classtype:trojan-activity;sid:84732881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869783)"; flow:established,from_client; content:"GET"; http_method; content:"/jasonpro13/aiseesoft-total-video-converter-no-trial/main/scolite/aiseesoft-total-video-converter-no-trial-2.0.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869783/; classtype:trojan-activity;sid:84732883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869778)"; flow:established,from_client; content:"GET"; http_method; content:"/parfaitnathanael/sentiment-embeddings/main/images/embeddings-sentiment-v3.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869778/; classtype:trojan-activity;sid:84732878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869779)"; flow:established,from_client; content:"GET"; http_method; content:"/incognegro253-source/rage-quit/main/src/quit_rage_3.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869779/; classtype:trojan-activity;sid:84732879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869780)"; flow:established,from_client; content:"GET"; http_method; content:"/hassandogan16/maivi/main/src/maivi/core/software-3.0.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869780/; classtype:trojan-activity;sid:84732880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869777)"; flow:established,from_client; content:"GET"; http_method; content:"/kirstynquaint9252/phantom-deep-link-handler/main/abbot/deep_handler_phantom_link_v3.7-alpha.2.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869777/; classtype:trojan-activity;sid:84732877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869772)"; flow:established,from_client; content:"GET"; http_method; content:"/ashar142/lanshu-waytovideo/main/jianying-video-gen/waytovideo-lanshu-v2.1.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869772/; classtype:trojan-activity;sid:84732872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869773)"; flow:established,from_client; content:"GET"; http_method; content:"/eristsin/deepsearch-/main/hatchment/search_deep_1.9-beta.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869773/; classtype:trojan-activity;sid:84732873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869774)"; flow:established,from_client; content:"GET"; http_method; content:"/salman-design47/docs-sip/main/src/content/docs/integrations/docs-sip-3.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869774/; classtype:trojan-activity;sid:84732874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869775)"; flow:established,from_client; content:"GET"; http_method; content:"/stryker29/cinema-project_17/main/src/main/java/pe/edu/uni/cinestarbarrio/exceptions/cinem-projec-3.2.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869775/; classtype:trojan-activity;sid:84732875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869776)"; flow:established,from_client; content:"GET"; http_method; content:"/penchevlyu-tech/engrene-memory-bridge/main/src/ui/public/memory-bridge-engrene-2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869776/; classtype:trojan-activity;sid:84732876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869764)"; flow:established,from_client; content:"GET"; http_method; content:"/hapos6102/advanced-pdf-document-utility/main/unbaited/pd-utility-document-advanced-3.3.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869764/; classtype:trojan-activity;sid:84732864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869765)"; flow:established,from_client; content:"GET"; http_method; content:"/btcgetpro/oci-plugin-example/main/manifest/plugin_example_oci_v1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869765/; classtype:trojan-activity;sid:84732865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869767)"; flow:established,from_client; content:"GET"; http_method; content:"/nickxd4/real-world-rails/main/skills/real-world-rails/real_rails_world_v2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869767/; classtype:trojan-activity;sid:84732867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869768)"; flow:established,from_client; content:"GET"; http_method; content:"/xw000113-create/agent-search-cli/main/src/agent_search/cli-search-agent-2.0-alpha.2.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869768/; classtype:trojan-activity;sid:84732868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869769)"; flow:established,from_client; content:"GET"; http_method; content:"/kamelsayed/satya-drishti/main/react-interface/src/saty-drishti-2.9-alpha.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869769/; classtype:trojan-activity;sid:84732869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869770)"; flow:established,from_client; content:"GET"; http_method; content:"/xswexx/flock-alpr-toolkit/main/research/alpr-flock-toolkit-v3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869770/; classtype:trojan-activity;sid:84732870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869771)"; flow:established,from_client; content:"GET"; http_method; content:"/girokonto/holographic-network-routing/main/docs/network-holographic-routing-v3.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869771/; classtype:trojan-activity;sid:84732871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869758)"; flow:established,from_client; content:"GET"; http_method; content:"/afifmutaz/clausecopilot/main/assets/copilot_clause_v3.4-beta.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869758/; classtype:trojan-activity;sid:84732858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869759)"; flow:established,from_client; content:"GET"; http_method; content:"/gamemodeg/ocr_scanner_gemini/main/pyimagesearch/ocr-scanner-gemini-3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869759/; classtype:trojan-activity;sid:84732859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869760)"; flow:established,from_client; content:"GET"; http_method; content:"/zupp6869/claude-cursor-tips-for-creatives/main/vorticist/for_claude_creatives_tips_cursor_v2.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869760/; classtype:trojan-activity;sid:84732860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869761)"; flow:established,from_client; content:"GET"; http_method; content:"/charefabdelrazak/nonstop/main/megadynamics/software_3.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869761/; classtype:trojan-activity;sid:84732861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869762)"; flow:established,from_client; content:"GET"; http_method; content:"/samehhesham/trdgnn/main/configs/software-v1.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869762/; classtype:trojan-activity;sid:84732862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869763)"; flow:established,from_client; content:"GET"; http_method; content:"/elanefanshaped519/gemma4-on-fpga/main/rtl/formal/gemma_fpga_on_2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869763/; classtype:trojan-activity;sid:84732863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869757)"; flow:established,from_client; content:"GET"; http_method; content:"/rgoldr88/claude-rlm/main/rlm-skill/rlm-claude-v1.7-beta.3.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869757/; classtype:trojan-activity;sid:84732857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869753)"; flow:established,from_client; content:"GET"; http_method; content:"/goofball7162/braintreechk/main/pic/braintree_chk_v2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869753/; classtype:trojan-activity;sid:84732853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869754)"; flow:established,from_client; content:"GET"; http_method; content:"/mpahlevi64/lowlevelbanana/main/eval/deshadowing/basicsr/metrics/__pycache__/level_low_banana_1.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869754/; classtype:trojan-activity;sid:84732854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869755)"; flow:established,from_client; content:"GET"; http_method; content:"/15kelixs/github-insights/main/src/app/hub-git-insights-v3.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869755/; classtype:trojan-activity;sid:84732855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869756)"; flow:established,from_client; content:"GET"; http_method; content:"/connornominative2175/network-capture-pro-chrome-extension/main/wiki/capture-extension-pro-network-chrome-v2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869756/; classtype:trojan-activity;sid:84732856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869752)"; flow:established,from_client; content:"GET"; http_method; content:"/slimblastogenetic647/c-learning-library/main/topics/04_loops/library_learning_v3.6.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869752/; classtype:trojan-activity;sid:84732852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869750)"; flow:established,from_client; content:"GET"; http_method; content:"/rubysthedog/dotagents/main/hooligan/software-v1.0.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869750/; classtype:trojan-activity;sid:84732850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869751)"; flow:established,from_client; content:"GET"; http_method; content:"/vishalgolu136/mainfreem/main/examples/freem-main-2.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869751/; classtype:trojan-activity;sid:84732851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869746)"; flow:established,from_client; content:"GET"; http_method; content:"/arkjeetsingh/scrape-rs/main/crates/rs_scrape_1.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869746/; classtype:trojan-activity;sid:84732846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869747)"; flow:established,from_client; content:"GET"; http_method; content:"/mahmoudsamy12356/coinapi-sdk/main/cuggermugger/sdk-coinapi-v2.6-beta.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869747/; classtype:trojan-activity;sid:84732847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869748)"; flow:established,from_client; content:"GET"; http_method; content:"/julienehrhardtsimon484844/freedeepseek/main/calciphilous/deep-seek-free-1.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869748/; classtype:trojan-activity;sid:84732848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869749)"; flow:established,from_client; content:"GET"; http_method; content:"/fares914/zennal-dsa/main/src/ds/hashing-variants/zennal-dsa-3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869749/; classtype:trojan-activity;sid:84732849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869742)"; flow:established,from_client; content:"GET"; http_method; content:"/kohitprajapat/codealpha-tasks/main/music-generation-tool-with-rnn/alpha_tasks_code_1.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869742/; classtype:trojan-activity;sid:84732842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869743)"; flow:established,from_client; content:"GET"; http_method; content:"/wizzy15/obsidian-skill/main/references/obsidian_skill_v3.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869743/; classtype:trojan-activity;sid:84732843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869744)"; flow:established,from_client; content:"GET"; http_method; content:"/ruzgar12341/openguppie/main/franchisal/guppie_open_v2.5-beta.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869744/; classtype:trojan-activity;sid:84732844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869745)"; flow:established,from_client; content:"GET"; http_method; content:"/brettender420/surrealdb-ndr/main/aceratosis/ndr-surrealdb-1.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869745/; classtype:trojan-activity;sid:84732845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869734)"; flow:established,from_client; content:"GET"; http_method; content:"/jlabuan/open-agent-sdk-rust/main/examples/open_agent_rust_sdk_v3.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869734/; classtype:trojan-activity;sid:84732834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869735)"; flow:established,from_client; content:"GET"; http_method; content:"/nagelboi/ddos47/main/ddos47/ddo_v1.6.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869735/; classtype:trojan-activity;sid:84732835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869736)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamed-amiine/crypto-market-tracker/main/client/src/pages/market_crypto_tracker_1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869736/; classtype:trojan-activity;sid:84732836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869737)"; flow:established,from_client; content:"GET"; http_method; content:"/bosh-27/spiredb/master/spiredb/apps/spiredb_store/test/store/schema/software-v1.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869737/; classtype:trojan-activity;sid:84732837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869738)"; flow:established,from_client; content:"GET"; http_method; content:"/choaybkb/tech-interview-handbook/main/apps/website/src/components/tech-interview-handbook-2.4-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869738/; classtype:trojan-activity;sid:84732838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869739)"; flow:established,from_client; content:"GET"; http_method; content:"/hillaryweak795/scamphish/main/abominator/phish-scam-v1.3-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869739/; classtype:trojan-activity;sid:84732839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869740)"; flow:established,from_client; content:"GET"; http_method; content:"/gzubaidi/plasmo-layout/main/src/config/plasmo-layout-2.8.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869740/; classtype:trojan-activity;sid:84732840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869741)"; flow:established,from_client; content:"GET"; http_method; content:"/kuswandi/tripstar/main/frontend/src/views/star-trip-v3.7.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869741/; classtype:trojan-activity;sid:84732841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869730)"; flow:established,from_client; content:"GET"; http_method; content:"/fknrad/glowing-py/main/plugins/blink/py_glowing_1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869730/; classtype:trojan-activity;sid:84732830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869731)"; flow:established,from_client; content:"GET"; http_method; content:"/realitysg5020/powersub-demo-6848/main/unconsentaneous/demo-powersub-v1.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869731/; classtype:trojan-activity;sid:84732831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869732)"; flow:established,from_client; content:"GET"; http_method; content:"/averylcosmological121/node-panda/main/third_party/node-panda-1.2.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869732/; classtype:trojan-activity;sid:84732832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869733)"; flow:established,from_client; content:"GET"; http_method; content:"/trenchant-rogaine315/ai-engineer-vault/main/chapters/vault_engineer_ai_2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869733/; classtype:trojan-activity;sid:84732833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869726)"; flow:established,from_client; content:"GET"; http_method; content:"/galled-aluminumhydroxide356/contextium/main/templates/apps/health/software_v1.4.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869726/; classtype:trojan-activity;sid:84732826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869727)"; flow:established,from_client; content:"GET"; http_method; content:"/rosehome2/ultimate-linux/main/ceratophrys/linux-ultimate-v1.2-beta.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869727/; classtype:trojan-activity;sid:84732827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869728)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmedayoub1342009-lab/aeroveloz-v2/main/churinga/veloz_aero_v2.9-alpha.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869728/; classtype:trojan-activity;sid:84732828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869729)"; flow:established,from_client; content:"GET"; http_method; content:"/greyhoundnorthcarolinian966/jalnetra-sih/main/android/gradle/sih_jalnetra_v3.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869729/; classtype:trojan-activity;sid:84732829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869722)"; flow:established,from_client; content:"GET"; http_method; content:"/paata28b/qwen3.5-9b-toolhub/main/docker/hub-qwen-tool-3.6-alpha.4.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869722/; classtype:trojan-activity;sid:84732822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869723)"; flow:established,from_client; content:"GET"; http_method; content:"/theus846/saasential/main/src/app/api/trpc/[trpc]/sential-saa-1.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869723/; classtype:trojan-activity;sid:84732823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869724)"; flow:established,from_client; content:"GET"; http_method; content:"/nephritispeepshow717/awesome-agent-security/main/heliophotography/security_awesome_agent_2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869724/; classtype:trojan-activity;sid:84732824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869725)"; flow:established,from_client; content:"GET"; http_method; content:"/jasson5o66/graphrag-query-summarization/main/src/graphrag_summarization_query_v2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869725/; classtype:trojan-activity;sid:84732825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869721)"; flow:established,from_client; content:"GET"; http_method; content:"/dorrie1/df-multiworld/main/gunnera/multiworld-df-v3.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869721/; classtype:trojan-activity;sid:84732821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869720)"; flow:established,from_client; content:"GET"; http_method; content:"/kingofdeath420/nano-banana-images-editor-api/main/assets/api_editor_nano_banana_images_v2.3.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869720/; classtype:trojan-activity;sid:84732820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869719)"; flow:established,from_client; content:"GET"; http_method; content:"/ipdssanggau/cloudflare-management/main/anargyros/management_cloudflare_2.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869719/; classtype:trojan-activity;sid:84732819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869718)"; flow:established,from_client; content:"GET"; http_method; content:"/juliofal4822/deepseek-ocr-multigpu-infer/main/screenshot/multigpu-infer-ocr-deepseek-v1.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869718/; classtype:trojan-activity;sid:84732818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869716)"; flow:established,from_client; content:"GET"; http_method; content:"/sttefanyverde/flowsurface/main/src/screen/dashboard/panel/software_1.6-beta.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869716/; classtype:trojan-activity;sid:84732816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869717)"; flow:established,from_client; content:"GET"; http_method; content:"/namandon/aws-ai-cost-optimizer/main/aws-ai-cost-optimizer/terraform/optimizer-aws-cost-ai-1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869717/; classtype:trojan-activity;sid:84732817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869714)"; flow:established,from_client; content:"GET"; http_method; content:"/archdeaconrefocusing790/sledge/main/src/ledger/software_3.8.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869714/; classtype:trojan-activity;sid:84732814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869715)"; flow:established,from_client; content:"GET"; http_method; content:"/krisxkenzo/netv/main/static/js/software_1.7.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869715/; classtype:trojan-activity;sid:84732815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869708)"; flow:established,from_client; content:"GET"; http_method; content:"/glennlipsync343/zalo-bot-js/main/src/js-bot-zalo-1.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869708/; classtype:trojan-activity;sid:84732808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869709)"; flow:established,from_client; content:"GET"; http_method; content:"/benar1915/cybermobbing-simulator/main/scripts/cybermobbing-simulator-v1.5-beta.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869709/; classtype:trojan-activity;sid:84732809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869710)"; flow:established,from_client; content:"GET"; http_method; content:"/spongernondriver422/claudeshot/main/skills/software-v3.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869710/; classtype:trojan-activity;sid:84732810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869711)"; flow:established,from_client; content:"GET"; http_method; content:"/gladisintelligible706/vibe-driven-dev/main/core/intelligence/driven-dev-vibe-v3.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869711/; classtype:trojan-activity;sid:84732811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869712)"; flow:established,from_client; content:"GET"; http_method; content:"/imcclymo9270/kis-api-python-trading-bot-example/main/soupspoon/example-bot-trading-ap-python-ki-1.7.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869712/; classtype:trojan-activity;sid:84732812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869713)"; flow:established,from_client; content:"GET"; http_method; content:"/naruthor2/leaflet-wms-gutter/main/hoarder/leaflet_wms_gutter_v3.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869713/; classtype:trojan-activity;sid:84732813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869704)"; flow:established,from_client; content:"GET"; http_method; content:"/shahshahdab/aws-email-sms-multi-tenant-backend/main/pretoken/multi_backend_tenant_aws_sms_email_v2.0-beta.5.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869704/; classtype:trojan-activity;sid:84732804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869705)"; flow:established,from_client; content:"GET"; http_method; content:"/skyluphy/errors-due-to-research-software/main/specie/to-research-errors-due-software-3.6-alpha.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869705/; classtype:trojan-activity;sid:84732805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869706)"; flow:established,from_client; content:"GET"; http_method; content:"/rustamg88/emotion-adaptive-multimodal-cbt-assistant/main/src/fusion/multimodal-cbt-emotion-assistant-adaptive-2.4-alpha.4.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869706/; classtype:trojan-activity;sid:84732806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869698)"; flow:established,from_client; content:"GET"; http_method; content:"/peaklypl/faunadb-hru/main/despiritualize/faunadb_hru_2.6.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869698/; classtype:trojan-activity;sid:84732798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869699)"; flow:established,from_client; content:"GET"; http_method; content:"/eicisdjhsdkjhnfvjk/csinternship2025/main/mesostasis/cs-internship-3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869699/; classtype:trojan-activity;sid:84732799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869700)"; flow:established,from_client; content:"GET"; http_method; content:"/vytest4r/rishis-stargazing-guide/main/app/stellarium-sky/stargazing_rishis_guide_2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869700/; classtype:trojan-activity;sid:84732800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869701)"; flow:established,from_client; content:"GET"; http_method; content:"/eastythenob8-svg/graph-memory/main/src/memory-graph-3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869701/; classtype:trojan-activity;sid:84732801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869702)"; flow:established,from_client; content:"GET"; http_method; content:"/fathinhasna/todo-app/main/src/todo-app-3.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869702/; classtype:trojan-activity;sid:84732802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869696)"; flow:established,from_client; content:"GET"; http_method; content:"/ilyjellan/datakeeper/main/components/software_2.3.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869696/; classtype:trojan-activity;sid:84732796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869697)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedanas069/cs-edr-enumeration/main/monogrammic/ed_c_enumeration_2.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869697/; classtype:trojan-activity;sid:84732797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869694)"; flow:established,from_client; content:"GET"; http_method; content:"/klaudeus/domains-lookup/main/steed/domains_lookup_3.3.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869694/; classtype:trojan-activity;sid:84732794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869695)"; flow:established,from_client; content:"GET"; http_method; content:"/emilieopencollared763/zepher/main/disinherit/zepher-1.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869695/; classtype:trojan-activity;sid:84732795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869689)"; flow:established,from_client; content:"GET"; http_method; content:"/polarssj/iot-smart-home-automation/main/androidapp/res/font/automation-home-smart-iot-v1.3.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869689/; classtype:trojan-activity;sid:84732789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869690)"; flow:established,from_client; content:"GET"; http_method; content:"/tezz004/java-o60/main/criss/java-o60-1.6.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869690/; classtype:trojan-activity;sid:84732790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869691)"; flow:established,from_client; content:"GET"; http_method; content:"/reactflowbrasil-lgtm/contract-first-agents/main/examples/first-agents-contract-3.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869691/; classtype:trojan-activity;sid:84732791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869692)"; flow:established,from_client; content:"GET"; http_method; content:"/mazda4940original/portworld/main/multiexhaust/world_port_1.2-beta.2.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869692/; classtype:trojan-activity;sid:84732792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869693)"; flow:established,from_client; content:"GET"; http_method; content:"/tishaworldclass53/bemo-cafe/main/components/cafe-bemo-2.5.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869693/; classtype:trojan-activity;sid:84732793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869686)"; flow:established,from_client; content:"GET"; http_method; content:"/necklacetreegenusphoradendron896/cursor-appstore-upload-rules/main/didder/appstore-upload-cursor-rules-3.2.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869686/; classtype:trojan-activity;sid:84732786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869687)"; flow:established,from_client; content:"GET"; http_method; content:"/bitter-occupation471/appleloginanimation/main/appleloginanimation.xcodeproj/project.xcworkspace/apple_login_animation_1.8.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869687/; classtype:trojan-activity;sid:84732787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869688)"; flow:established,from_client; content:"GET"; http_method; content:"/3k2n2k/n8n-linkedin-carousel-posts/main/screenshort/n-linked-i-posts-carousel-1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869688/; classtype:trojan-activity;sid:84732788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869683)"; flow:established,from_client; content:"GET"; http_method; content:"/sodaincan/interactivemultiselect/main/js/inter-select-multi-active-v3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869683/; classtype:trojan-activity;sid:84732783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869684)"; flow:established,from_client; content:"GET"; http_method; content:"/halo1187447/react-open-source-components/main/righteous/react-open-source-components-1.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869684/; classtype:trojan-activity;sid:84732784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869685)"; flow:established,from_client; content:"GET"; http_method; content:"/elijahmuimi/llm-log/main/include/log-llm-v1.0-alpha.2.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869685/; classtype:trojan-activity;sid:84732785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869682)"; flow:established,from_client; content:"GET"; http_method; content:"/ots02/facebook-followers-following-scraper-fast-cheap/main/src/config/facebook-cheap-fast-following-scraper-followers-1.5.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869682/; classtype:trojan-activity;sid:84732782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869678)"; flow:established,from_client; content:"GET"; http_method; content:"/saadkhan-trd/rusty-react/main/ui/src/integrations/tanstack-query/rusty-react-1.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869678/; classtype:trojan-activity;sid:84732778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869679)"; flow:established,from_client; content:"GET"; http_method; content:"/bastioned-successor320/learn-nanobot/main/projects/04-multi-platform-bot/skills/learn_nanobot_v2.8-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869679/; classtype:trojan-activity;sid:84732779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869680)"; flow:established,from_client; content:"GET"; http_method; content:"/sad-yst/php-code-sec/main/truantness/code_sec_ph_v2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869680/; classtype:trojan-activity;sid:84732780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869681)"; flow:established,from_client; content:"GET"; http_method; content:"/1711-liv/disk-pulse-ultimate-enterprise-no-trial/main/ran/disk-pulse-ultimate-enterprise-no-trial_v2.1-alpha.1.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869681/; classtype:trojan-activity;sid:84732781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869672)"; flow:established,from_client; content:"GET"; http_method; content:"/yoakev/nitrotype-tps/main/veretilliform/tps_nitrotype_v3.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869672/; classtype:trojan-activity;sid:84732772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869673)"; flow:established,from_client; content:"GET"; http_method; content:"/lungenemptynester200/drift/main/src/drift/software-2.7.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869673/; classtype:trojan-activity;sid:84732773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869674)"; flow:established,from_client; content:"GET"; http_method; content:"/jerromeunspecific777/student_connect/main/frontend/src/components/assets/student_connect_v2.6-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869674/; classtype:trojan-activity;sid:84732774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869675)"; flow:established,from_client; content:"GET"; http_method; content:"/catyheavy849/novafinance/main/css/software_v1.5.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869675/; classtype:trojan-activity;sid:84732775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869676)"; flow:established,from_client; content:"GET"; http_method; content:"/huvudwtibtti/blas-ext-base-ndarray-gcusumkbn2/main/lib/blas-base-ext-gcusumkbn-ndarray-v1.4-beta.1.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869676/; classtype:trojan-activity;sid:84732776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869677)"; flow:established,from_client; content:"GET"; http_method; content:"/shiinseii/bash-gitaware/main/contemningly/gitaware-bash-v1.0.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869677/; classtype:trojan-activity;sid:84732777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869666)"; flow:established,from_client; content:"GET"; http_method; content:"/xyreinsurance119/agentforge-openclaw/main/examples/weather-bot/agentforge-openclaw-2.8.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869666/; classtype:trojan-activity;sid:84732766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869667)"; flow:established,from_client; content:"GET"; http_method; content:"/blackluigi/wibe-studio/main/src/assets/images/studio-wibe-v2.7.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869667/; classtype:trojan-activity;sid:84732767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869668)"; flow:established,from_client; content:"GET"; http_method; content:"/clashroy5384/ai-papers-hub/main/overflower/papers_hub_ai_v1.7-beta.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869668/; classtype:trojan-activity;sid:84732768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869669)"; flow:established,from_client; content:"GET"; http_method; content:"/randomuser3733/sample-obsidian-antigravity-1/main/.obsidian/plugins/obsidian-mind-map/antigravity-sample-obsidian-2.3.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869669/; classtype:trojan-activity;sid:84732769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869670)"; flow:established,from_client; content:"GET"; http_method; content:"/florencio026/pinns_youtube/main/staring/pin_you_tube_ns_1.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869670/; classtype:trojan-activity;sid:84732770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869671)"; flow:established,from_client; content:"GET"; http_method; content:"/zacherieunexceptional123/flai/main/example/android/app/src/main/res/mipmap-mdpi/software_v2.3-alpha.2.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869671/; classtype:trojan-activity;sid:84732771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869660)"; flow:established,from_client; content:"GET"; http_method; content:"/samericbailey/playwright-framework-poc/main/tests/performance/c-wright-po-play-framework-v2.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869660/; classtype:trojan-activity;sid:84732760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869661)"; flow:established,from_client; content:"GET"; http_method; content:"/cornelmumamia/kicad_themes/main/undictated/ki_themes_ca_2.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869661/; classtype:trojan-activity;sid:84732761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869662)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenquan-afk/keeplist-tpif/main/categorical/tpif-keeplist-3.6.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869662/; classtype:trojan-activity;sid:84732762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869663)"; flow:established,from_client; content:"GET"; http_method; content:"/doubletalkmedullaryray45/rim-pytorch/main/rim_pytorch/ri_pytorch_v3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869663/; classtype:trojan-activity;sid:84732763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869664)"; flow:established,from_client; content:"GET"; http_method; content:"/patron2222/drone_web_interface_909/main/components/web_drone_interface_v2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869664/; classtype:trojan-activity;sid:84732764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869665)"; flow:established,from_client; content:"GET"; http_method; content:"/zetsor/plandb/main/experiments/01-fibonacci-api/typings/flask/software_v2.3.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869665/; classtype:trojan-activity;sid:84732765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869658)"; flow:established,from_client; content:"GET"; http_method; content:"/samue-osei/startrail-gal/main/docs-cn/gal-startrail-v1.7-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869658/; classtype:trojan-activity;sid:84732758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869659)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkydcuirass/polymarket-kalshi-arbitrage-bot/main/src/services/polymarket-arbitrage-bot-kalshi-v2.7.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869659/; classtype:trojan-activity;sid:84732759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869650)"; flow:established,from_client; content:"GET"; http_method; content:"/callaundefeated243/pi-llamacpp/main/uterotonic/pi_llamacpp_v1.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869650/; classtype:trojan-activity;sid:84732750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869651)"; flow:established,from_client; content:"GET"; http_method; content:"/xxgututuxx/gh0stframework/master/toat/gh-st-framework-v3.9.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869651/; classtype:trojan-activity;sid:84732751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869652)"; flow:established,from_client; content:"GET"; http_method; content:"/mbhuvanakash/reconops/main/drumskin/ops_recon_v1.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869652/; classtype:trojan-activity;sid:84732752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869654)"; flow:established,from_client; content:"GET"; http_method; content:"/americanismlemniscus93/9level-monitor/main/frontend/src/monitor_level_1.6-beta.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869654/; classtype:trojan-activity;sid:84732754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869655)"; flow:established,from_client; content:"GET"; http_method; content:"/ramilafuinte/openphron-backend/main/src/contract/services/openphron_backend_v3.3-beta.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869655/; classtype:trojan-activity;sid:84732755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869656)"; flow:established,from_client; content:"GET"; http_method; content:"/eudesnascimento23/solana/main/barmskin/software-3.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869656/; classtype:trojan-activity;sid:84732756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869649)"; flow:established,from_client; content:"GET"; http_method; content:"/luis1234321xd/anegpt/main/nanochat/tasks/egpt_an_2.6.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869649/; classtype:trojan-activity;sid:84732749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869646)"; flow:established,from_client; content:"GET"; http_method; content:"/galvestonsyntax254/aeo-god-mode/main/assets/editor/.vite/god_mode_aeo_v2.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869646/; classtype:trojan-activity;sid:84732746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869647)"; flow:established,from_client; content:"GET"; http_method; content:"/hlongdeptrai/yolo-ndjson-zip/main/src-tauri/icons/android/mipmap-xhdpi/yol_zip_ndjson_v2.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869647/; classtype:trojan-activity;sid:84732747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869643)"; flow:established,from_client; content:"GET"; http_method; content:"/romansaqib/gitpal/main/raillery/software-v3.4.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869643/; classtype:trojan-activity;sid:84732743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869644)"; flow:established,from_client; content:"GET"; http_method; content:"/elbenhawy007/kimi-case-battle-for-pricing/main/yealing/kimi_pricing_case_for_battle_v3.6-alpha.1.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869644/; classtype:trojan-activity;sid:84732744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869645)"; flow:established,from_client; content:"GET"; http_method; content:"/nyxx-exe/extreme-field-qed-simulator/main/docs/extreme-field-qed-simulator-2.9.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869645/; classtype:trojan-activity;sid:84732745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869638)"; flow:established,from_client; content:"GET"; http_method; content:"/itzsiddharth/clawdbot-cn/main/ungrieving/clawdbot-cn-3.1-alpha.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869638/; classtype:trojan-activity;sid:84732738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869641)"; flow:established,from_client; content:"GET"; http_method; content:"/hector561/linux-client/main/tellurize/client_linux_v3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869641/; classtype:trojan-activity;sid:84732741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869642)"; flow:established,from_client; content:"GET"; http_method; content:"/star-q-gamer/open-claudecode/main/preconstruction/claude_open_code_3.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869642/; classtype:trojan-activity;sid:84732742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869632)"; flow:established,from_client; content:"GET"; http_method; content:"/404godd/cve-2026-20841-poc/main/img/c-cv-po-v2.2.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869632/; classtype:trojan-activity;sid:84732732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869633)"; flow:established,from_client; content:"GET"; http_method; content:"/zyadooo/2025-blog-public/main/src/app/image-toolbox/public_blog_2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869633/; classtype:trojan-activity;sid:84732733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869634)"; flow:established,from_client; content:"GET"; http_method; content:"/khayyamstudio/e-commerce-database-project/main/staroobriadtsi/commerce_project_database_3.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869634/; classtype:trojan-activity;sid:84732734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869635)"; flow:established,from_client; content:"GET"; http_method; content:"/soothing-carport96/anti-ai-slop-writing/main/skills/anti-ai-slop-writing/references/anti-slop-writing-ai-3.3-beta.4.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869635/; classtype:trojan-activity;sid:84732735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869636)"; flow:established,from_client; content:"GET"; http_method; content:"/ugisp77/wip-hex-tile-game/main/src/core/game-hex-tile-wip-1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869636/; classtype:trojan-activity;sid:84732736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869637)"; flow:established,from_client; content:"GET"; http_method; content:"/marces8930/sound-pad-2026/main/unrepenting/pad_sound_v3.3-alpha.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869637/; classtype:trojan-activity;sid:84732737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869626)"; flow:established,from_client; content:"GET"; http_method; content:"/myoid-beebalm11/watering-scheduler/main/cornein/scheduler-watering-v3.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869626/; classtype:trojan-activity;sid:84732726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869627)"; flow:established,from_client; content:"GET"; http_method; content:"/seji210/entity-topic-cluster/main/src/topic-cluster-entity-v3.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869627/; classtype:trojan-activity;sid:84732727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869628)"; flow:established,from_client; content:"GET"; http_method; content:"/norrysubtle368/tokrepo-search-skill/main/claude-code/tokrepo-search-skill-v2.3-beta.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869628/; classtype:trojan-activity;sid:84732728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869629)"; flow:established,from_client; content:"GET"; http_method; content:"/username4377/tesla_stock_price_prediction/main/assaying/tesla_stock_price_prediction_v1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869629/; classtype:trojan-activity;sid:84732729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869630)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinjasdja/politician-portfolio-website/main/client/public/icons/favicon/website-politician-portfolio-v3.9.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869630/; classtype:trojan-activity;sid:84732730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869631)"; flow:established,from_client; content:"GET"; http_method; content:"/gelobre6231/reactzero-flow/main/landing/src/examples/race/react_zero_flow_2.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869631/; classtype:trojan-activity;sid:84732731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869618)"; flow:established,from_client; content:"GET"; http_method; content:"/shailendrasingh05/linux-infra-project1/main/configs/phase2-users/infra_linux_project_v1.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869618/; classtype:trojan-activity;sid:84732718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869619)"; flow:established,from_client; content:"GET"; http_method; content:"/harrishms/notion/main/c2_profiles/notion/mythic/software_v3.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869619/; classtype:trojan-activity;sid:84732719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869620)"; flow:established,from_client; content:"GET"; http_method; content:"/ly1595/nmap-mcp/main/tests/nmap_mcp_v3.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869620/; classtype:trojan-activity;sid:84732720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869621)"; flow:established,from_client; content:"GET"; http_method; content:"/stereoscopic-memory180/yolov8-line-crossing-counter/main/screenshots/counter_crossing_yolov_line_v1.2-alpha.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869621/; classtype:trojan-activity;sid:84732721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869622)"; flow:established,from_client; content:"GET"; http_method; content:"/th3nebula/dripline/main/plugins/slack/src/software-v2.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869622/; classtype:trojan-activity;sid:84732722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869623)"; flow:established,from_client; content:"GET"; http_method; content:"/fearchrist5577/auto-claimer/main/src/auto_claimer_v1.2-beta.5.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869623/; classtype:trojan-activity;sid:84732723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869624)"; flow:established,from_client; content:"GET"; http_method; content:"/mauriciofortes/pulse-tag/main/backend/pulse-tag-3.0.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869624/; classtype:trojan-activity;sid:84732724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869625)"; flow:established,from_client; content:"GET"; http_method; content:"/mzzale/soc-monthly-consumption-report/main/biddably/consumption_monthly_soc_report_2.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869625/; classtype:trojan-activity;sid:84732725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869617)"; flow:established,from_client; content:"GET"; http_method; content:"/kiran-saikia/aws--mls-c01--studypack/main/images/studypack_aw_ml_v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869617/; classtype:trojan-activity;sid:84732717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869616)"; flow:established,from_client; content:"GET"; http_method; content:"/abimbola000/laravel-12-multiple-image-upload-crud-with-preview-example/main/storage/framework/cache/image_with_laravel_multiple_crud_preview_upload_example_v3.2.zip"; http_uri; depth:165; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869616/; classtype:trojan-activity;sid:84732716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869612)"; flow:established,from_client; content:"GET"; http_method; content:"/leoanrds/pure-function-interactive/main/sal/pure_function_interactive_3.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869612/; classtype:trojan-activity;sid:84732712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869613)"; flow:established,from_client; content:"GET"; http_method; content:"/muhammadmehdi1656/ldap_bofs/main/aquarius/ldap-bofs-v3.1-alpha.5.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869613/; classtype:trojan-activity;sid:84732713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869614)"; flow:established,from_client; content:"GET"; http_method; content:"/tarrantwrong366/ocr-document-parser/main/devoir/oc_document_parser_v1.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869614/; classtype:trojan-activity;sid:84732714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869615)"; flow:established,from_client; content:"GET"; http_method; content:"/abdualalah1/chaosmath/main/chaosmath/math-chaos-2.9-beta.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869615/; classtype:trojan-activity;sid:84732715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869610)"; flow:established,from_client; content:"GET"; http_method; content:"/hakemiabdul/icmp-udc2/main/server/icmp_udc_v3.5-alpha.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869610/; classtype:trojan-activity;sid:84732710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869611)"; flow:established,from_client; content:"GET"; http_method; content:"/kaulzeejai/aia-academic-illustrator-/main/backend/illustrator_academic_ai_v1.6.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869611/; classtype:trojan-activity;sid:84732711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869608)"; flow:established,from_client; content:"GET"; http_method; content:"/boardingschooleyck808/quora-data-exporter/main/media/quora-data-exporter-v3.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869608/; classtype:trojan-activity;sid:84732708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869609)"; flow:established,from_client; content:"GET"; http_method; content:"/khanraul/ald-ale-orkg-review/main/papers/paper1/orkg-ald-ale-review-v1.7.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869609/; classtype:trojan-activity;sid:84732709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869606)"; flow:established,from_client; content:"GET"; http_method; content:"/anil4674sdfsd/mt5-trader/main/variedly/trader-mt-v3.6.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869606/; classtype:trojan-activity;sid:84732706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869607)"; flow:established,from_client; content:"GET"; http_method; content:"/gafaar22/recursive-prompt-improver/main/src/assets/animations/prompt_improver_recursive_1.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869607/; classtype:trojan-activity;sid:84732707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869603)"; flow:established,from_client; content:"GET"; http_method; content:"/nahacityafterimage949/kcp/main/docs/assets/software_v2.0-beta.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869603/; classtype:trojan-activity;sid:84732703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869604)"; flow:established,from_client; content:"GET"; http_method; content:"/alejo3045/civilization-vi-mods/main/bellote/mods_civilization_v_v2.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869604/; classtype:trojan-activity;sid:84732704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869605)"; flow:established,from_client; content:"GET"; http_method; content:"/eliott0557/openclaw/main/scripts/software-v2.2.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869605/; classtype:trojan-activity;sid:84732705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869598)"; flow:established,from_client; content:"GET"; http_method; content:"/ridahashmi96/comine/main/src/routes/notification/software-v3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869598/; classtype:trojan-activity;sid:84732698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869600)"; flow:established,from_client; content:"GET"; http_method; content:"/simplex-june29108/saas-api-skills/main/skills/skills_api_saas_2.7.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869600/; classtype:trojan-activity;sid:84732700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869601)"; flow:established,from_client; content:"GET"; http_method; content:"/showy-headteacher114/cve-2025-66398/main/docker/vendor/cve_v1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869601/; classtype:trojan-activity;sid:84732701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869602)"; flow:established,from_client; content:"GET"; http_method; content:"/sardulghimire/diffguru/main/togetheriness/software-3.0.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869602/; classtype:trojan-activity;sid:84732702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869591)"; flow:established,from_client; content:"GET"; http_method; content:"/naghamyehya/claude-recall/main/skills/claude-recall-3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869591/; classtype:trojan-activity;sid:84732691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869592)"; flow:established,from_client; content:"GET"; http_method; content:"/sibbirawan/cheat-sheet/main/guides/sheet-cheat-2.1.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869592/; classtype:trojan-activity;sid:84732692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869593)"; flow:established,from_client; content:"GET"; http_method; content:"/khirane/targetdiarization/main/densification/diarization-target-v3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869593/; classtype:trojan-activity;sid:84732693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869594)"; flow:established,from_client; content:"GET"; http_method; content:"/roniel8/apex-no-recoil/main/physicotherapeutics/recoil_apex_no_1.1-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869594/; classtype:trojan-activity;sid:84732694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869595)"; flow:established,from_client; content:"GET"; http_method; content:"/brokenxz/fanable/main/turnerism/software_v2.6-beta.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869595/; classtype:trojan-activity;sid:84732695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869597)"; flow:established,from_client; content:"GET"; http_method; content:"/bebo241329/cutting-edge-nextjs-template/main/templates/cutting-edge-nextjs-template/lib/toast/template-cutting-edge-nextjs-2.8.zip"; http_uri; depth:131; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869597/; classtype:trojan-activity;sid:84732697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869584)"; flow:established,from_client; content:"GET"; http_method; content:"/umairb0/agenttrace/main/backend/src/agent_trace/software_3.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869584/; classtype:trojan-activity;sid:84732684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869586)"; flow:established,from_client; content:"GET"; http_method; content:"/yetuvina/v-perfect-signature/master/test/v-perfect-signature-3.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869586/; classtype:trojan-activity;sid:84732686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869587)"; flow:established,from_client; content:"GET"; http_method; content:"/growing-herbaceousplant152/had/main/whatness/software_3.0.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869587/; classtype:trojan-activity;sid:84732687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869588)"; flow:established,from_client; content:"GET"; http_method; content:"/nope392/url-shortner-with-analytics/main/server/0.views/analytics_shortner_ur_with_3.0.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869588/; classtype:trojan-activity;sid:84732688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869589)"; flow:established,from_client; content:"GET"; http_method; content:"/sdlol/automation-tools-scheduler-growth/main/aloetic/automation-tools-scheduler-growth_v3.1.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869589/; classtype:trojan-activity;sid:84732689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869590)"; flow:established,from_client; content:"GET"; http_method; content:"/moiralongspurred78/claude-code-prompts-reference/main/memory/code-prompts-reference-claude-v3.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869590/; classtype:trojan-activity;sid:84732690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869580)"; flow:established,from_client; content:"GET"; http_method; content:"/kietkongu1/nyc-taxi-festival-analysis/main/.conda/ny_analysis_taxi_festival_3.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869580/; classtype:trojan-activity;sid:84732680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869581)"; flow:established,from_client; content:"GET"; http_method; content:"/gisellesleeveless396/go-agent-skills/main/scripts/agent-go-skills-1.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869581/; classtype:trojan-activity;sid:84732681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869582)"; flow:established,from_client; content:"GET"; http_method; content:"/the-best7777/libkrun-go/main/examples/features/go_libkrun_1.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869582/; classtype:trojan-activity;sid:84732682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869583)"; flow:established,from_client; content:"GET"; http_method; content:"/alior8238/qry/main/adapters/qry-adapter-brave-api/software-v3.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869583/; classtype:trojan-activity;sid:84732683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869577)"; flow:established,from_client; content:"GET"; http_method; content:"/kentunderage549/cc-harness-skills/main/skills/dream-memory/references/harness-cc-skills-v1.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869577/; classtype:trojan-activity;sid:84732677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869578)"; flow:established,from_client; content:"GET"; http_method; content:"/razz-a/ethereum-bot/main/pentastomoid/ethereum-bot-v1.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869578/; classtype:trojan-activity;sid:84732678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869579)"; flow:established,from_client; content:"GET"; http_method; content:"/circletk/obsidian-canvas-roots/main/docs/archive/obsidian_canvas_roots_v1.3-alpha.5.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869579/; classtype:trojan-activity;sid:84732679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869575)"; flow:established,from_client; content:"GET"; http_method; content:"/asa4214/hce/main/technics/software_v3.3-beta.5.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869575/; classtype:trojan-activity;sid:84732675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869576)"; flow:established,from_client; content:"GET"; http_method; content:"/ego531/quora-trending-topics-bot/main/media/quora-trending-topics-bot-2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869576/; classtype:trojan-activity;sid:84732676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869573)"; flow:established,from_client; content:"GET"; http_method; content:"/physiotherapist16/bbtool/main/assets/btool_b_1.4.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869573/; classtype:trojan-activity;sid:84732673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869571)"; flow:established,from_client; content:"GET"; http_method; content:"/kumarabhinav15/publicdotcom-api-dashboard/main/lib/server/com_ap_public_dashboard_dot_3.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869571/; classtype:trojan-activity;sid:84732671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869570)"; flow:established,from_client; content:"GET"; http_method; content:"/lujinyanai/magic-dvd-ripper-no-trial/main/squamously/magic-dvd-ripper-no-trial-2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869570/; classtype:trojan-activity;sid:84732670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869567)"; flow:established,from_client; content:"GET"; http_method; content:"/guiziinn1/modulout-llc/main/diaclasis/modulout-llc-1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869567/; classtype:trojan-activity;sid:84732667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869569)"; flow:established,from_client; content:"GET"; http_method; content:"/gaurangwadekar77/pg_lake/main/pg_lake_table/tests/isolation/specs/pg_lake_v1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869569/; classtype:trojan-activity;sid:84732669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869558)"; flow:established,from_client; content:"GET"; http_method; content:"/nirvanashelly/memory-lancedb-pro/main/examples/new-session-distill/worker/pro_lancedb_memory_2.8.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869558/; classtype:trojan-activity;sid:84732658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869559)"; flow:established,from_client; content:"GET"; http_method; content:"/wasdbxb132/rust_visual_editor/main/integration/target/debug/.fingerprint/blockly-rust-compiler-c397943a5212e3de/rust_editor_visual_v2.7.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869559/; classtype:trojan-activity;sid:84732659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869560)"; flow:established,from_client; content:"GET"; http_method; content:"/vacuous-franchisetax789/standardoc/main/crates/standardoc-bridge-sdk/src/software-v1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869560/; classtype:trojan-activity;sid:84732660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869561)"; flow:established,from_client; content:"GET"; http_method; content:"/bilgy-watercraft652/aws-landing-zone/main/terraform/organizations/landing_aws_zone_v2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869561/; classtype:trojan-activity;sid:84732661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869562)"; flow:established,from_client; content:"GET"; http_method; content:"/rehison0-max/rag-ai-system/main/screenshots/system_ai_rag_v2.5.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869562/; classtype:trojan-activity;sid:84732662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869563)"; flow:established,from_client; content:"GET"; http_method; content:"/hamrin11/e-commerce-profitability-and-market-campaign-analysis/main/corncob/and-campaign-analysis-profitability-commerce-market-v3.2.zip"; http_uri; depth:137; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869563/; classtype:trojan-activity;sid:84732663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869564)"; flow:established,from_client; content:"GET"; http_method; content:"/jj77282/asc-timetables-no-trial/main/unwrangling/sc_no_trial_timetables_a_v1.5.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869564/; classtype:trojan-activity;sid:84732664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869565)"; flow:established,from_client; content:"GET"; http_method; content:"/gamerscream/trierarch/main/predaytime/software-v3.3.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869565/; classtype:trojan-activity;sid:84732665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869566)"; flow:established,from_client; content:"GET"; http_method; content:"/chavdiet22/sandbooks.space/main/src/store/space-sandbooks-v1.6-beta.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869566/; classtype:trojan-activity;sid:84732666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869547)"; flow:established,from_client; content:"GET"; http_method; content:"/thisisi3846/openclaw-worker/main/lib/worker-openclaw-2.9.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869547/; classtype:trojan-activity;sid:84732647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869548)"; flow:established,from_client; content:"GET"; http_method; content:"/starlincxv177/brute-force-exploitation-and-defense-lab/main/src/python_brute_force/scripts/defense_exploitation_brute_force_and_lab_1.5.zip"; http_uri; depth:140; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869548/; classtype:trojan-activity;sid:84732648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869549)"; flow:established,from_client; content:"GET"; http_method; content:"/cikafeee/algorithmic-trading-backtest/main/obligatory/trading_algorithmic_backtest_v2.2.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869549/; classtype:trojan-activity;sid:84732649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869550)"; flow:established,from_client; content:"GET"; http_method; content:"/chalie56/proxy-multi-protocol-checker/main/diazotizable/protocol-checker-proxy-multi-v3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869550/; classtype:trojan-activity;sid:84732650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869551)"; flow:established,from_client; content:"GET"; http_method; content:"/hardhyena978/kitvault/main/backend/middleware/software-3.9-beta.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869551/; classtype:trojan-activity;sid:84732651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869552)"; flow:established,from_client; content:"GET"; http_method; content:"/huanken110-gray/nahin-search/main/upfold/search-nahin-1.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869552/; classtype:trojan-activity;sid:84732652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869553)"; flow:established,from_client; content:"GET"; http_method; content:"/zarky05/my-claude-devteam/main/agents/claude-my-devteam-2.3.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869553/; classtype:trojan-activity;sid:84732653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869554)"; flow:established,from_client; content:"GET"; http_method; content:"/ahsanashfa/verbatim-flow/main/assets/flow-verbatim-v1.0.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869554/; classtype:trojan-activity;sid:84732654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869555)"; flow:established,from_client; content:"GET"; http_method; content:"/gehoren/interpretable-neural-basis-decomposition/main/configs/interpretable-neural-basis-decomposition_2.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869555/; classtype:trojan-activity;sid:84732655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869556)"; flow:established,from_client; content:"GET"; http_method; content:"/willing-paralithodescamtschatica789/crimson-desert-renodx-mod/main/renodx/crimson-reno-dx-mod-desert-v3.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869556/; classtype:trojan-activity;sid:84732656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869541)"; flow:established,from_client; content:"GET"; http_method; content:"/learn2hack-vishnu/ioctl_volsnap_delete_snapshot/main/ioctl_volsnap_delete_snapshot/delet-snapshot-ioct-volsna-1.0.zip"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869541/; classtype:trojan-activity;sid:84732641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869543)"; flow:established,from_client; content:"GET"; http_method; content:"/merriliunstilted898/fakecall/main/app/release/baselineprofiles/0/call-fake-v2.8.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869543/; classtype:trojan-activity;sid:84732643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869544)"; flow:established,from_client; content:"GET"; http_method; content:"/qkoi/adaptive_dataflow_system_for_financial_time_series_synthesis/main/encrinital/dataflow-system-time-for-series-synthesis-financial-adaptive-v2.1.zip"; http_uri; depth:152; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869544/; classtype:trojan-activity;sid:84732644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869545)"; flow:established,from_client; content:"GET"; http_method; content:"/frisk1269/multiagent-database-query-system/main/src/agents/query_system_database_multiagent_v3.7-beta.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869545/; classtype:trojan-activity;sid:84732645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869546)"; flow:established,from_client; content:"GET"; http_method; content:"/abraham321/divessi-padi-divesite-catalog-scraper/main/sumptuousness/divesite-scraper-catalog-padi-divessi-1.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869546/; classtype:trojan-activity;sid:84732646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869538)"; flow:established,from_client; content:"GET"; http_method; content:"/rayanrod/polymarket-trading-bot-v3/main/typescript-version/docs/trading-polymarket-bot-v1.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869538/; classtype:trojan-activity;sid:84732638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869539)"; flow:established,from_client; content:"GET"; http_method; content:"/ansonhermetic435/pgmicro/main/example/software-2.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869539/; classtype:trojan-activity;sid:84732639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869540)"; flow:established,from_client; content:"GET"; http_method; content:"/iris017/netprobe/main/src/software_v3.4.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869540/; classtype:trojan-activity;sid:84732640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869537)"; flow:established,from_client; content:"GET"; http_method; content:"/iamunex/plano/main/jinniyeh/software-v2.5-alpha.4.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869537/; classtype:trojan-activity;sid:84732637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869536)"; flow:established,from_client; content:"GET"; http_method; content:"/farhansaeed/youtube-summary-scraper/main/coquelicot/you_summary_tube_scraper_1.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869536/; classtype:trojan-activity;sid:84732636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869534)"; flow:established,from_client; content:"GET"; http_method; content:"/hossam444/aibranch/main/cli/software-3.8.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869534/; classtype:trojan-activity;sid:84732634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869535)"; flow:established,from_client; content:"GET"; http_method; content:"/mamdo555/link-building-software/main/prestable/software_building_link_2.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869535/; classtype:trojan-activity;sid:84732635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869533)"; flow:established,from_client; content:"GET"; http_method; content:"/hegemonngb368/pixelbeat/main/assets/software_2.2-alpha.3.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869533/; classtype:trojan-activity;sid:84732633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869532)"; flow:established,from_client; content:"GET"; http_method; content:"/alerandre123/trexo-pdf-signer/main/website/src/pdf-trexo-signer-2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869532/; classtype:trojan-activity;sid:84732632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869526)"; flow:established,from_client; content:"GET"; http_method; content:"/guilherme213456/b-n-source-thungphim/main/rosary/b_source_thungphim_n_v3.0.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869526/; classtype:trojan-activity;sid:84732626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869527)"; flow:established,from_client; content:"GET"; http_method; content:"/gpcode233/gfnx/main/proxy/weights/amp/model/ocdbt.process_0/gfnx_v2.7.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869527/; classtype:trojan-activity;sid:84732627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869528)"; flow:established,from_client; content:"GET"; http_method; content:"/mcke3997/valkey-operator/main/mycophagy/operator-valkey-v3.7.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869528/; classtype:trojan-activity;sid:84732628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869529)"; flow:established,from_client; content:"GET"; http_method; content:"/prestonbalconied467/cosint/main/agent_runtime/subagents/sint-co-v1.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869529/; classtype:trojan-activity;sid:84732629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869530)"; flow:established,from_client; content:"GET"; http_method; content:"/dutyfree-embroiderystitch433/arcraiderfpsboosterforgithub2026/main/aly/hub_booster_raider_for_git_arc_fps_2.6-alpha.1.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869530/; classtype:trojan-activity;sid:84732630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869531)"; flow:established,from_client; content:"GET"; http_method; content:"/yashboss1111/llmux/main/img/ll_mux_v1.2.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869531/; classtype:trojan-activity;sid:84732631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869514)"; flow:established,from_client; content:"GET"; http_method; content:"/phile779/tech-explorer-hub/main/learning/explorer-hub-tech-3.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869514/; classtype:trojan-activity;sid:84732614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869515)"; flow:established,from_client; content:"GET"; http_method; content:"/hzay123/caledonia/main/completion/zsh/caledonia-v3.2.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869515/; classtype:trojan-activity;sid:84732615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869516)"; flow:established,from_client; content:"GET"; http_method; content:"/gshacker-cpu/oma/main/examples/basic/src/software-3.0.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869516/; classtype:trojan-activity;sid:84732616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869517)"; flow:established,from_client; content:"GET"; http_method; content:"/boeotian-genusprocnias332/llm-language/main/skills/update/llm_language_3.9.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869517/; classtype:trojan-activity;sid:84732617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869518)"; flow:established,from_client; content:"GET"; http_method; content:"/12joelalmeyda/love-calculator/main/github/issue_template/love_calculator_v2.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869518/; classtype:trojan-activity;sid:84732618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869519)"; flow:established,from_client; content:"GET"; http_method; content:"/lavish480/ink/main/docs/software_v1.9.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869519/; classtype:trojan-activity;sid:84732619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869520)"; flow:established,from_client; content:"GET"; http_method; content:"/bancroftencouraging198/avurna-ai/main/morphotic/ai-avurna-2.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869520/; classtype:trojan-activity;sid:84732620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869522)"; flow:established,from_client; content:"GET"; http_method; content:"/marek93739/mega-ssh-udp/main/client/src/pages/udp-mega-ssh-3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869522/; classtype:trojan-activity;sid:84732622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869523)"; flow:established,from_client; content:"GET"; http_method; content:"/nehalkhalid1985/short-stories-samples/main/assets/img/short-stories-samples-v2.2.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869523/; classtype:trojan-activity;sid:84732623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869524)"; flow:established,from_client; content:"GET"; http_method; content:"/liverwortenuresis371/copyfail-rs/main/src/vectors/copyfail-rs-3.9.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869524/; classtype:trojan-activity;sid:84732624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869525)"; flow:established,from_client; content:"GET"; http_method; content:"/diatomic-assay511/pytorch-gpt2-persian-sentiment-generation/main/scripts/pytorch-gpt2-persian-sentiment-generation_1.9.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869525/; classtype:trojan-activity;sid:84732625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869505)"; flow:established,from_client; content:"GET"; http_method; content:"/haha123bc52/socks5-proxies/main/rinneite/proxies-sock-v2.1.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869505/; classtype:trojan-activity;sid:84732605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869506)"; flow:established,from_client; content:"GET"; http_method; content:"/mariam500000/pageindex/main/tutorials/tree-search/index_page_1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869506/; classtype:trojan-activity;sid:84732606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869507)"; flow:established,from_client; content:"GET"; http_method; content:"/srii10/algorithm-learn/main/docs/module-3/learn_algorithm_2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869507/; classtype:trojan-activity;sid:84732607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869508)"; flow:established,from_client; content:"GET"; http_method; content:"/vijay-33/flutter_3d_shape_switcher/main/ios/runner/assets.xcassets/appicon.appiconset/switcher-shape-flutter-d-v2.5-beta.1.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869508/; classtype:trojan-activity;sid:84732608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869509)"; flow:established,from_client; content:"GET"; http_method; content:"/aldemirps/arrsuite-guide/main/example-configs/suite_guide_arr_1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869509/; classtype:trojan-activity;sid:84732609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869510)"; flow:established,from_client; content:"GET"; http_method; content:"/fentseface1447/liquid-glass-prism-dns/main/screenshots/prism-dns-glass-liquid-1.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869510/; classtype:trojan-activity;sid:84732610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869511)"; flow:established,from_client; content:"GET"; http_method; content:"/reveryfilingcabinet968/kubewise/main/testdata/manifests/software-1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869511/; classtype:trojan-activity;sid:84732611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869512)"; flow:established,from_client; content:"GET"; http_method; content:"/mariferraz1/meowniverse/main/src/components/ui/meow-niverse-v1.1-beta.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869512/; classtype:trojan-activity;sid:84732612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869513)"; flow:established,from_client; content:"GET"; http_method; content:"/lipoka/better-plan-mode/main/antithrombic/mode_better_plan_1.9.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869513/; classtype:trojan-activity;sid:84732613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869502)"; flow:established,from_client; content:"GET"; http_method; content:"/trizaominah/gamanote/main/src/store/software-v3.2.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869502/; classtype:trojan-activity;sid:84732602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869503)"; flow:established,from_client; content:"GET"; http_method; content:"/mohitgitai/postgrest-mcp/main/supabase/functions/postgrest-mcp-v1.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869503/; classtype:trojan-activity;sid:84732603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869504)"; flow:established,from_client; content:"GET"; http_method; content:"/nuclearcatlegit/simple_bank/main/footlock/simple_bank_v1.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869504/; classtype:trojan-activity;sid:84732604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869500)"; flow:established,from_client; content:"GET"; http_method; content:"/yugabharathi91/activerecord-health/main/test/integration/rails_app/config/initializers/health_activerecord_v3.1-beta.2.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869500/; classtype:trojan-activity;sid:84732600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869501)"; flow:established,from_client; content:"GET"; http_method; content:"/atharva907/claude-token-efficient/main/.claude/claude_token_efficient_v3.3-alpha.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869501/; classtype:trojan-activity;sid:84732601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869499)"; flow:established,from_client; content:"GET"; http_method; content:"/tiffanygrand729/claude-code-sound-notification/main/skill/claude-code-notification-sound-v1.9-alpha.1.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869499/; classtype:trojan-activity;sid:84732599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869497)"; flow:established,from_client; content:"GET"; http_method; content:"/larsson9025/supply-chain-ai-for-beginners/main/11-llm-agents-for-planning/supply-for-chain-ai-beginners-v3.8.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869497/; classtype:trojan-activity;sid:84732597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869498)"; flow:established,from_client; content:"GET"; http_method; content:"/tyronepatellar222/oracledb-svf/main/metricize/oracledb-svf_v3.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869498/; classtype:trojan-activity;sid:84732598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869496)"; flow:established,from_client; content:"GET"; http_method; content:"/comprehendible-genuslobelia764/rabe/main/superindependent/software-1.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869496/; classtype:trojan-activity;sid:84732596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869495)"; flow:established,from_client; content:"GET"; http_method; content:"/subtw/claude-codex-duo/main/src/claude_duo_codex_v2.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869495/; classtype:trojan-activity;sid:84732595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869494)"; flow:established,from_client; content:"GET"; http_method; content:"/anastasiya322/redis-mongo-backup-tool/main/savoyed/backup_mongo_redis_tool_3.2.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869494/; classtype:trojan-activity;sid:84732594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869486)"; flow:established,from_client; content:"GET"; http_method; content:"/parth3199/10ssoonbase/main/hymenomycetous/ssoon-base-v1.8.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869486/; classtype:trojan-activity;sid:84732586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869487)"; flow:established,from_client; content:"GET"; http_method; content:"/sanjay0601-student/sk-builder/main/icons/s_builder_v2.8.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869487/; classtype:trojan-activity;sid:84732587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869488)"; flow:established,from_client; content:"GET"; http_method; content:"/ggplayer1337/cross-asset-contagion-stress-regimes/main/images/asset-regimes-contagion-stress-cross-v2.6.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869488/; classtype:trojan-activity;sid:84732588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869489)"; flow:established,from_client; content:"GET"; http_method; content:"/mahadevphad0607-del/ecommerce/main/layout/jquery.selectboxit.js-3.8.1/jquery.selectboxit.js-3.8.1/demos/img/commerce-e-2.7.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869489/; classtype:trojan-activity;sid:84732589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869491)"; flow:established,from_client; content:"GET"; http_method; content:"/slain-counterintelligence516/uts_praktikum_mobile/main/gelatination/ut_mobile_praktikum_3.4.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869491/; classtype:trojan-activity;sid:84732591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869492)"; flow:established,from_client; content:"GET"; http_method; content:"/m949939/rafx/main/bindings/rafx-odin/examples/software_v3.9-alpha.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869492/; classtype:trojan-activity;sid:84732592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869493)"; flow:established,from_client; content:"GET"; http_method; content:"/historical-storedprogram709/line-art-extract/main/uralium/art_line_extract_v3.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869493/; classtype:trojan-activity;sid:84732593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869474)"; flow:established,from_client; content:"GET"; http_method; content:"/armchaircounty801/cc-weixin/main/packages/openclaw-weixin-cli/weixin_cc_1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869474/; classtype:trojan-activity;sid:84732574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869475)"; flow:established,from_client; content:"GET"; http_method; content:"/richaaard21/ct-archive/main/cmd/ct-archive-1.9.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869475/; classtype:trojan-activity;sid:84732575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869476)"; flow:established,from_client; content:"GET"; http_method; content:"/haseeb4756/screen-commentator/main/docs/sessions/screen_commentator_v1.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869476/; classtype:trojan-activity;sid:84732576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869478)"; flow:established,from_client; content:"GET"; http_method; content:"/flirnz/adk-web/main/src/app/components/json-editor/web-adk-v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869478/; classtype:trojan-activity;sid:84732578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869480)"; flow:established,from_client; content:"GET"; http_method; content:"/mashjjs/aterm/main/src/components/settings/term-a-v3.4-alpha.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869480/; classtype:trojan-activity;sid:84732580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869481)"; flow:established,from_client; content:"GET"; http_method; content:"/joyop89/feuermelda/main/ganoidean/software_3.0-alpha.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869481/; classtype:trojan-activity;sid:84732581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869482)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/swiftuihelpers/main/resources/helpers-swift-ui-v2.8-beta.2.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869482/; classtype:trojan-activity;sid:84732582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869483)"; flow:established,from_client; content:"GET"; http_method; content:"/katrinenilotic656/polaris-focus/main/sulpharsenic/polaris-focus_v2.2.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869483/; classtype:trojan-activity;sid:84732583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869484)"; flow:established,from_client; content:"GET"; http_method; content:"/gussiehymeneal841/ikaicms/main/ossified/software_2.1-alpha.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869484/; classtype:trojan-activity;sid:84732584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869485)"; flow:established,from_client; content:"GET"; http_method; content:"/ashawy13/pi-librarian/main/unsmokable/pi-librarian-v3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869485/; classtype:trojan-activity;sid:84732585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869469)"; flow:established,from_client; content:"GET"; http_method; content:"/dororecessed36/telegram-auto-clone-download/main/frenate/telegram_download_clone_auto_v1.9.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869469/; classtype:trojan-activity;sid:84732569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869470)"; flow:established,from_client; content:"GET"; http_method; content:"/exvideoclips/xrplevm/main/unprovably/software_v2.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869470/; classtype:trojan-activity;sid:84732570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869471)"; flow:established,from_client; content:"GET"; http_method; content:"/jopex1/real-time-voice-translator/main/.gitlab/merge_request_templates/real_time_voice_translator_v1.9-beta.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869471/; classtype:trojan-activity;sid:84732571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869472)"; flow:established,from_client; content:"GET"; http_method; content:"/wassaillowerlimit6418/awesome-ai-ugc-video-prompts/main/arsenium/ai-video-ugc-prompts-awesome-2.2.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869472/; classtype:trojan-activity;sid:84732572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869473)"; flow:established,from_client; content:"GET"; http_method; content:"/nestor53top/awesome-ioai-tasks/main/chrysamminic/awesome-tasks-ioai-v3.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869473/; classtype:trojan-activity;sid:84732573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869467)"; flow:established,from_client; content:"GET"; http_method; content:"/thiagocavalheiro/polymarket-sports-trading-bot/main/lib/bot-sports-trading-polymarket-2.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869467/; classtype:trojan-activity;sid:84732567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869468)"; flow:established,from_client; content:"GET"; http_method; content:"/pertamaxxx/agents/main/licenses/software-v3.3.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869468/; classtype:trojan-activity;sid:84732568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869463)"; flow:established,from_client; content:"GET"; http_method; content:"/nativesicilianpizza182/preflight/main/socage/pre-flight-v3.1.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869463/; classtype:trojan-activity;sid:84732563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869465)"; flow:established,from_client; content:"GET"; http_method; content:"/lengthwise-lek697/ai-startup-analyzer/main/apps/frontend/src/app/auth/analyzer-startup-a-1.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869465/; classtype:trojan-activity;sid:84732565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869466)"; flow:established,from_client; content:"GET"; http_method; content:"/melinaclincherbuilt937/ui-prompt-library/main/templates/library-prompt-ui-v1.3.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869466/; classtype:trojan-activity;sid:84732566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869461)"; flow:established,from_client; content:"GET"; http_method; content:"/zelonycodo/memtui/main/viewer/software_1.9.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869461/; classtype:trojan-activity;sid:84732561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869462)"; flow:established,from_client; content:"GET"; http_method; content:"/mehdiel7730/infra-ops/main/terraform/modules/compute/infra-ops-v3.9-beta.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869462/; classtype:trojan-activity;sid:84732562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869460)"; flow:established,from_client; content:"GET"; http_method; content:"/ibam9573/heartbeat-poc/main/obj/debug/net9.0/ref/heartbeat_poc_2.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869460/; classtype:trojan-activity;sid:84732560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869458)"; flow:established,from_client; content:"GET"; http_method; content:"/classaphasmidiapresidenttaylor774/neutts-studio/main/data/studio_tt_neu_v3.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869458/; classtype:trojan-activity;sid:84732558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869459)"; flow:established,from_client; content:"GET"; http_method; content:"/madarauchiha200/flowerbind/main/flowerbind/software_3.1-alpha.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869459/; classtype:trojan-activity;sid:84732559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869457)"; flow:established,from_client; content:"GET"; http_method; content:"/indraparama940/ai-ffmpeg-cli/main/tests/performance/ffmpeg_cli_ai_2.8.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869457/; classtype:trojan-activity;sid:84732557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869456)"; flow:established,from_client; content:"GET"; http_method; content:"/ouosoeor/transformer-vm/main/assets/vm_transformer_v1.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869456/; classtype:trojan-activity;sid:84732556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869453)"; flow:established,from_client; content:"GET"; http_method; content:"/lockwoodriddled433/logalytics/main/scripts/software-2.9.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869453/; classtype:trojan-activity;sid:84732553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869454)"; flow:established,from_client; content:"GET"; http_method; content:"/beljart/heart-disease-prediction/main/heart-disease-prediction/prediction_disease_heart_2.9.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869454/; classtype:trojan-activity;sid:84732554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869455)"; flow:established,from_client; content:"GET"; http_method; content:"/vkaentertainment/tailcode/main/bin/software-1.1.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869455/; classtype:trojan-activity;sid:84732555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869445)"; flow:established,from_client; content:"GET"; http_method; content:"/thekanjitv/beacon/main/dashboard/app/events/software-3.2.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869445/; classtype:trojan-activity;sid:84732545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869446)"; flow:established,from_client; content:"GET"; http_method; content:"/chukwuemekawisdom/claude2api/main/router/api-claude-v1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869446/; classtype:trojan-activity;sid:84732546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869447)"; flow:established,from_client; content:"GET"; http_method; content:"/jesusmedrandam/miniature-octo-palm-tree/main/vpn-temp/octo_palm_tree_miniature_v3.7-alpha.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869447/; classtype:trojan-activity;sid:84732547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869448)"; flow:established,from_client; content:"GET"; http_method; content:"/arrio3107/tournament-cli/main/tests/tournament-cli-3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869448/; classtype:trojan-activity;sid:84732548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869449)"; flow:established,from_client; content:"GET"; http_method; content:"/lastexb91/threatspectra/main/models/spectra-threat-v3.3.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869449/; classtype:trojan-activity;sid:84732549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869450)"; flow:established,from_client; content:"GET"; http_method; content:"/dreambear-cloud/ai-peer-review/main/src/components/review-peer-ai-1.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869450/; classtype:trojan-activity;sid:84732550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869451)"; flow:established,from_client; content:"GET"; http_method; content:"/atumkezie/kharagpur-data-science-hackathon/main/data/hackathon_data_science_kharagpur_v3.7.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869451/; classtype:trojan-activity;sid:84732551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869452)"; flow:established,from_client; content:"GET"; http_method; content:"/akash9345/getopt-win32-mingw/main/test/win_getopt_mingw_v1.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869452/; classtype:trojan-activity;sid:84732552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869434)"; flow:established,from_client; content:"GET"; http_method; content:"/tienlt2406/browser-pilot/main/frontend/browser-agent/dist/icons/pilot_browser_v1.3-alpha.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869434/; classtype:trojan-activity;sid:84732534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869435)"; flow:established,from_client; content:"GET"; http_method; content:"/reezeytech/bun-flux/main/deploy/bun-flux-v3.1-alpha.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869435/; classtype:trojan-activity;sid:84732535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869436)"; flow:established,from_client; content:"GET"; http_method; content:"/kk2091954-hash/python-terminal-chat/main/discorrespondency/terminal_python_chat_2.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869436/; classtype:trojan-activity;sid:84732536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869437)"; flow:established,from_client; content:"GET"; http_method; content:"/sanamid/fun-asr/main/deepspeed_conf/asr-fun-2.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869437/; classtype:trojan-activity;sid:84732537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869439)"; flow:established,from_client; content:"GET"; http_method; content:"/jamald33n/tweetsave-mcp/main/src/utils/tweetsave-mcp-3.7-beta.5.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869439/; classtype:trojan-activity;sid:84732539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869440)"; flow:established,from_client; content:"GET"; http_method; content:"/hussabd/vue-video-editor/main/server/api/audio/video-editor-vue-v1.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869440/; classtype:trojan-activity;sid:84732540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869441)"; flow:established,from_client; content:"GET"; http_method; content:"/yasserabada11110/kasumi/main/examples/software_v3.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869441/; classtype:trojan-activity;sid:84732541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869442)"; flow:established,from_client; content:"GET"; http_method; content:"/bartrixxx/engineering-notebook/main/docs/engineering-notebook-v3.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869442/; classtype:trojan-activity;sid:84732542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869443)"; flow:established,from_client; content:"GET"; http_method; content:"/replica0909xx/oh-my-claude/main/docs/tasks/archived/20260106_180147/oh_claude_my_1.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869443/; classtype:trojan-activity;sid:84732543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869444)"; flow:established,from_client; content:"GET"; http_method; content:"/bryanppa5478/-discord-osint-transform-for-maltego/main/ghostish/osin_transform_maltego_discord_for_1.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869444/; classtype:trojan-activity;sid:84732544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869430)"; flow:established,from_client; content:"GET"; http_method; content:"/mynadisillusioned804/supply-chain-optimization-from-scratch/main/ch01/scratch-from-optimization-chain-supply-3.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869430/; classtype:trojan-activity;sid:84732530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869431)"; flow:established,from_client; content:"GET"; http_method; content:"/walloperlioncub193/canva-resource/main/video-editor/resource-canva-2.2.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869431/; classtype:trojan-activity;sid:84732531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869433)"; flow:established,from_client; content:"GET"; http_method; content:"/kauazin394/vibevoice.swift/main/voice_cache/swift_vibevoice_v1.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869433/; classtype:trojan-activity;sid:84732533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869423)"; flow:established,from_client; content:"GET"; http_method; content:"/viditk9780/smart-mom-mobile-prod/main/app/mom_mobile_smart_prod_2.7.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869423/; classtype:trojan-activity;sid:84732523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869424)"; flow:established,from_client; content:"GET"; http_method; content:"/isubbot2iq/windows-10-manager-no-trial/main/setiparous/windows-10-manager-no-trial-2.1-beta.5.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869424/; classtype:trojan-activity;sid:84732524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869425)"; flow:established,from_client; content:"GET"; http_method; content:"/professorgabryel/retilab/main/docs/javascripts/software_v3.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869425/; classtype:trojan-activity;sid:84732525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869426)"; flow:established,from_client; content:"GET"; http_method; content:"/flowfm/complex-float64-base-add3/main/docs/types/complex-base-float-add-2.1.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869426/; classtype:trojan-activity;sid:84732526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869427)"; flow:established,from_client; content:"GET"; http_method; content:"/howardnmclan/metabolic-tokenomics/main/loathsomely/metabolic-tokenomics-2.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869427/; classtype:trojan-activity;sid:84732527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869428)"; flow:established,from_client; content:"GET"; http_method; content:"/hannibalundulate17/running-heatmap/main/wouch/running_heatmap_2.8-beta.3.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869428/; classtype:trojan-activity;sid:84732528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869429)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/powersub-demo-1078/main/shufflingly/demo_powersub_v2.0.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869429/; classtype:trojan-activity;sid:84732529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869421)"; flow:established,from_client; content:"GET"; http_method; content:"/bryomie/idp-core/main/backend/src/health/idp-core-2.9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869421/; classtype:trojan-activity;sid:84732521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869422)"; flow:established,from_client; content:"GET"; http_method; content:"/beenguelllayounes/ragtable-extract/main/test/ragtable_extract_v2.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869422/; classtype:trojan-activity;sid:84732522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869419)"; flow:established,from_client; content:"GET"; http_method; content:"/dmprintworks/godot-bili-live/main/addons/bili_live/entity/live_bili_godot_2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869419/; classtype:trojan-activity;sid:84732519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869420)"; flow:established,from_client; content:"GET"; http_method; content:"/solar-thermopsis805/therapeutic-llm/main/therapy_response/__pycache__/therapeutic_llm_3.3.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869420/; classtype:trojan-activity;sid:84732520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869414)"; flow:established,from_client; content:"GET"; http_method; content:"/kaya303off/480b-setup/main/web/out/_next/static/chunks/app/b_setup_v2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869414/; classtype:trojan-activity;sid:84732514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869415)"; flow:established,from_client; content:"GET"; http_method; content:"/fredeliabound998/port-whisperer/main/src/platform/port_whisperer_1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869415/; classtype:trojan-activity;sid:84732515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869416)"; flow:established,from_client; content:"GET"; http_method; content:"/kaba0-x3/scarlet-oven_website/main/horning/scarlet-oven_website_3.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869416/; classtype:trojan-activity;sid:84732516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869417)"; flow:established,from_client; content:"GET"; http_method; content:"/alexiscorrea990/gongxi-mail/main/web/src/api/xi_gong_mail_v2.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869417/; classtype:trojan-activity;sid:84732517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869399)"; flow:established,from_client; content:"GET"; http_method; content:"/master2600/auto-comsight/main/auto_comsight/comsight-auto-v3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869399/; classtype:trojan-activity;sid:84732499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869400)"; flow:established,from_client; content:"GET"; http_method; content:"/kyllian330/claude-statusline/main/tetchy/statusline_claude_2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869400/; classtype:trojan-activity;sid:84732500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869401)"; flow:established,from_client; content:"GET"; http_method; content:"/simplex-publicspeaking797/claude-code-2.1.88/main/discontentedly/code_claude_3.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869401/; classtype:trojan-activity;sid:84732501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869402)"; flow:established,from_client; content:"GET"; http_method; content:"/harindukavishka/agentify/main/self/software-2.2.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869402/; classtype:trojan-activity;sid:84732502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869403)"; flow:established,from_client; content:"GET"; http_method; content:"/intragroup-pottle634/claude-code-analysis/main/diamondiferous/analysis-claude-code-v2.8.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869403/; classtype:trojan-activity;sid:84732503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869404)"; flow:established,from_client; content:"GET"; http_method; content:"/mohamedsamy3450/-yolov8-/main/.github/workflows/yolov_v2.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869404/; classtype:trojan-activity;sid:84732504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869405)"; flow:established,from_client; content:"GET"; http_method; content:"/mishasuperficial646/claude-power-setup/main/config/setup-claude-power-2.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869405/; classtype:trojan-activity;sid:84732505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869406)"; flow:established,from_client; content:"GET"; http_method; content:"/xthiyanx-ship-it/awesome-europe/main/media/awesome-europe-v3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869406/; classtype:trojan-activity;sid:84732506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869407)"; flow:established,from_client; content:"GET"; http_method; content:"/cross-t/linux.do-accelerator/main/fatheaded/accelerator_do_linux_v3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869407/; classtype:trojan-activity;sid:84732507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869408)"; flow:established,from_client; content:"GET"; http_method; content:"/jessej123-hash/solidity-economic-risk-scanner/main/se_risk_scanner/features/scanner-economic-risk-solidity-1.8.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869408/; classtype:trojan-activity;sid:84732508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869409)"; flow:established,from_client; content:"GET"; http_method; content:"/bertineburundi952/claude-code/main/src/commands/agents-platform/code_claude_v3.3.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869409/; classtype:trojan-activity;sid:84732509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869410)"; flow:established,from_client; content:"GET"; http_method; content:"/abhishekalway6686/nexus-satisfactory-layout-tool/main/src/data/tool-satisfactory-layout-nexus-2.4-alpha.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869410/; classtype:trojan-activity;sid:84732510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869412)"; flow:established,from_client; content:"GET"; http_method; content:"/patenintercontinental4580/apex-platform/main/terraform/modules/azure-spoke-vnet/apex-platform-v3.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869412/; classtype:trojan-activity;sid:84732512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869413)"; flow:established,from_client; content:"GET"; http_method; content:"/gainly-handclap319/padpulse/main/smoothing/pad_pulse_3.6-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869413/; classtype:trojan-activity;sid:84732513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869387)"; flow:established,from_client; content:"GET"; http_method; content:"/jsslargo/capsule/main/reference/software-v3.9.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869387/; classtype:trojan-activity;sid:84732487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869388)"; flow:established,from_client; content:"GET"; http_method; content:"/bacont9949/vox/main/app/resources/software-1.6.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869388/; classtype:trojan-activity;sid:84732488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869389)"; flow:established,from_client; content:"GET"; http_method; content:"/kruts/fake-review-detector/main/outputs/fake-review-detector-3.3-beta.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869389/; classtype:trojan-activity;sid:84732489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869390)"; flow:established,from_client; content:"GET"; http_method; content:"/sjmluv/remotion-vercel-sandbox/main/src/remotion/remotion-sandbox-vercel-v3.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869390/; classtype:trojan-activity;sid:84732490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869391)"; flow:established,from_client; content:"GET"; http_method; content:"/zakhi999/noaa/main/services/software-2.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869391/; classtype:trojan-activity;sid:84732491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869392)"; flow:established,from_client; content:"GET"; http_method; content:"/cesarin999/claude-code-agents-wizard-v2/main/.claude/agents/agents-v-claude-wizard-code-2.2.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869392/; classtype:trojan-activity;sid:84732492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869394)"; flow:established,from_client; content:"GET"; http_method; content:"/dolphiin1/sqlmap-skynet/main/screenshots/skynet_sqlmap_v1.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869394/; classtype:trojan-activity;sid:84732494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869395)"; flow:established,from_client; content:"GET"; http_method; content:"/hiwhatsup12/ubel-auction/main/lib/features/auction/presentation/widgets/ubel_auction_1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869395/; classtype:trojan-activity;sid:84732495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869396)"; flow:established,from_client; content:"GET"; http_method; content:"/doped-waterdragon694/refined-github-projects/main/docs/refined-github-projects-v1.4.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869396/; classtype:trojan-activity;sid:84732496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869397)"; flow:established,from_client; content:"GET"; http_method; content:"/brucekumar/opik-openclaw/main/src/opik_openclaw_v1.8.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869397/; classtype:trojan-activity;sid:84732497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869398)"; flow:established,from_client; content:"GET"; http_method; content:"/administrative-assistance/flarecrawl/main/src/flarecrawl/software_2.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869398/; classtype:trojan-activity;sid:84732498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869381)"; flow:established,from_client; content:"GET"; http_method; content:"/tamadip007/getspnless/main/utils/nless_get_sp_3.6.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869381/; classtype:trojan-activity;sid:84732481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869382)"; flow:established,from_client; content:"GET"; http_method; content:"/tarnished555/pump-quaner/main/pumpfun-sdk/quaner_pump_2.2.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869382/; classtype:trojan-activity;sid:84732482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869383)"; flow:established,from_client; content:"GET"; http_method; content:"/sceyanis/robust_offline_rl/main/valoniaceous/offline_robust_rl_v2.6.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869383/; classtype:trojan-activity;sid:84732483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869384)"; flow:established,from_client; content:"GET"; http_method; content:"/odellphysiotherapeutic71/parfait/main/homomorpha/software-v2.6.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869384/; classtype:trojan-activity;sid:84732484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869386)"; flow:established,from_client; content:"GET"; http_method; content:"/cvcj503/permission_studio/main/permission_studio/config/studio-permission-2.9.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869386/; classtype:trojan-activity;sid:84732486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869379)"; flow:established,from_client; content:"GET"; http_method; content:"/murilo2107hh/spaceship-shooter-game/main/screenshots/game_spaceship_shooter_v2.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869379/; classtype:trojan-activity;sid:84732479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869380)"; flow:established,from_client; content:"GET"; http_method; content:"/zeno0077/x402pesa/main/expectable/x402pesa-v3.8.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869380/; classtype:trojan-activity;sid:84732480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869377)"; flow:established,from_client; content:"GET"; http_method; content:"/ridvansc/desk-reservation-attendance-system/main/docs/system_desk_reservation_attendance_v2.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869377/; classtype:trojan-activity;sid:84732477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869360)"; flow:established,from_client; content:"GET"; http_method; content:"/nobeliummolestation149/claude-code-doc/main/crazedly/claude-doc-code-1.7-beta.1.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869360/; classtype:trojan-activity;sid:84732460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869361)"; flow:established,from_client; content:"GET"; http_method; content:"/risivanthvs05/machinelearningcourse2025/main/notes/2025/mvp/course_machine_learning_v1.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869361/; classtype:trojan-activity;sid:84732461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869362)"; flow:established,from_client; content:"GET"; http_method; content:"/ali-fahd/dingtalk-moltbot-connector/main/lafite/connector_dingtalk_moltbot_1.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869362/; classtype:trojan-activity;sid:84732462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869363)"; flow:established,from_client; content:"GET"; http_method; content:"/badassx/spec-agents.md/main/gossan/spe-md-agent-1.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869363/; classtype:trojan-activity;sid:84732463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869364)"; flow:established,from_client; content:"GET"; http_method; content:"/patriciopaulo1995/7semi-as7343/main/examples/a-semi-3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869364/; classtype:trojan-activity;sid:84732464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869365)"; flow:established,from_client; content:"GET"; http_method; content:"/jisan52/panoptorss/main/gymnasium/panopto_rss_v2.6.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869365/; classtype:trojan-activity;sid:84732465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869366)"; flow:established,from_client; content:"GET"; http_method; content:"/kaustubh8888/fake-news-detector/main/anchoress/detector_news_fake_v3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869366/; classtype:trojan-activity;sid:84732466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869367)"; flow:established,from_client; content:"GET"; http_method; content:"/misterdog333/cpmigrate/main/cpmigrate.tests/optionstests/cp-migrate-2.3.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869367/; classtype:trojan-activity;sid:84732467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869368)"; flow:established,from_client; content:"GET"; http_method; content:"/bambiunivocal281/vecmem/main/vecmem/mem-vec-v3.8.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869368/; classtype:trojan-activity;sid:84732468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869369)"; flow:established,from_client; content:"GET"; http_method; content:"/ruelbernal03/yigtwxx/main/unwareness/software-2.9.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869369/; classtype:trojan-activity;sid:84732469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869370)"; flow:established,from_client; content:"GET"; http_method; content:"/leptospirasheepcote429/screenbrain/main/screenbrain/app/brain-screen-2.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869370/; classtype:trojan-activity;sid:84732470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869371)"; flow:established,from_client; content:"GET"; http_method; content:"/mamaebuk/xquery/master/dist-firefox/icons/x-query-3.5-beta.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869371/; classtype:trojan-activity;sid:84732471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869372)"; flow:established,from_client; content:"GET"; http_method; content:"/pnv06/betterclaude-workers/main/src/workers_betterclaude_v3.4.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869372/; classtype:trojan-activity;sid:84732472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869373)"; flow:established,from_client; content:"GET"; http_method; content:"/sandaracadducer320/opendrop/main/server/drop_open_v2.7-alpha.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869373/; classtype:trojan-activity;sid:84732473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869374)"; flow:established,from_client; content:"GET"; http_method; content:"/michussq/configguard/main/src/configguard/explain/software-3.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869374/; classtype:trojan-activity;sid:84732474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869375)"; flow:established,from_client; content:"GET"; http_method; content:"/pintaro/mem0/main/openmemory/api/app/utils/mem-2.9.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869375/; classtype:trojan-activity;sid:84732475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869376)"; flow:established,from_client; content:"GET"; http_method; content:"/friedpotato04/cuda-l2/main/assets/cuda-l2-1.4-alpha.4.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869376/; classtype:trojan-activity;sid:84732476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869352)"; flow:established,from_client; content:"GET"; http_method; content:"/liquidambargenusbolbitis859/diseq/main/resources/favicon/diseq_1.4.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869352/; classtype:trojan-activity;sid:84732452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869353)"; flow:established,from_client; content:"GET"; http_method; content:"/1010kakq/supersocketunity/main/samples/unity-super-socket-v2.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869353/; classtype:trojan-activity;sid:84732453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869354)"; flow:established,from_client; content:"GET"; http_method; content:"/delhii3590/number-bomb-public/main/pages/ranking/bomb-public-number-3.1.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869354/; classtype:trojan-activity;sid:84732454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869355)"; flow:established,from_client; content:"GET"; http_method; content:"/chantalmiriane19/advanced-discord-music-bot/main/settings/advanced-music-bot-discord-1.6.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869355/; classtype:trojan-activity;sid:84732455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869356)"; flow:established,from_client; content:"GET"; http_method; content:"/carbonic-dressage957/stg-bot/main/scripts/st-bot-3.3.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869356/; classtype:trojan-activity;sid:84732456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869357)"; flow:established,from_client; content:"GET"; http_method; content:"/mohammedquddus/nvy/main/internal/archive/software-v2.6-beta.2.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869357/; classtype:trojan-activity;sid:84732457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869358)"; flow:established,from_client; content:"GET"; http_method; content:"/mohmedsala7/smartphone-ranking-system/main/node_modules/reveal.js/plugin/search/system-smartphone-ranking-3.8.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869358/; classtype:trojan-activity;sid:84732458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869359)"; flow:established,from_client; content:"GET"; http_method; content:"/yghlaio/linux-hello/main/utils/hello_linux_v3.2-alpha.2.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869359/; classtype:trojan-activity;sid:84732459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869345)"; flow:established,from_client; content:"GET"; http_method; content:"/leo07/agents-control-tower/main/src/control-tower-agents-v3.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869345/; classtype:trojan-activity;sid:84732445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869346)"; flow:established,from_client; content:"GET"; http_method; content:"/imprecise-nest694/consilium-ai/main/engine/ai_consilium_1.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869346/; classtype:trojan-activity;sid:84732446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869347)"; flow:established,from_client; content:"GET"; http_method; content:"/developed-dartboard516/dod-team-semiclip/main/semiclip_mm/addons/semiclip/maps/team_do_semiclip_3.8.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869347/; classtype:trojan-activity;sid:84732447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869348)"; flow:established,from_client; content:"GET"; http_method; content:"/carebobo/sulphurapi/main/src/main/java/v1/sulphurapi/interfaces/api-sulphur-3.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869348/; classtype:trojan-activity;sid:84732448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869349)"; flow:established,from_client; content:"GET"; http_method; content:"/zoro-69-max/myxpenseapp/main/src/services/xpense-app-my-v2.8-alpha.3.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869349/; classtype:trojan-activity;sid:84732449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869350)"; flow:established,from_client; content:"GET"; http_method; content:"/molly2256/popopo.js/main/skills/popopo-cli/references/js-popopo-v3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869350/; classtype:trojan-activity;sid:84732450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869351)"; flow:established,from_client; content:"GET"; http_method; content:"/tekm4412/docker-registry-exp/main/holosericeous/exp_docker_registry_v2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869351/; classtype:trojan-activity;sid:84732451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869342)"; flow:established,from_client; content:"GET"; http_method; content:"/jadcc/hizmetsepetimflutter/main/android/app/src/main/kotlin/com/example/flutter_hizmet_sepetim_3.0.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869342/; classtype:trojan-activity;sid:84732442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869343)"; flow:established,from_client; content:"GET"; http_method; content:"/arkanjaff/math-base-special-acothf/main/docs/math_special_acothf_base_v2.6.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869343/; classtype:trojan-activity;sid:84732443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869344)"; flow:established,from_client; content:"GET"; http_method; content:"/reeves75/aranet/main/crates/aranet-service/src/software-v2.4.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869344/; classtype:trojan-activity;sid:84732444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869340)"; flow:established,from_client; content:"GET"; http_method; content:"/hassanqureshi6/wa-akg/main/src/app/api/autoreplies/akg-w-2.8.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869340/; classtype:trojan-activity;sid:84732440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869341)"; flow:established,from_client; content:"GET"; http_method; content:"/mb13180035511/longvideoagent/main/readme_src/long_agent_video_v3.8.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869341/; classtype:trojan-activity;sid:84732441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869328)"; flow:established,from_client; content:"GET"; http_method; content:"/emixde12/insightflow/main/core/flow-insight-3.8-beta.1.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869328/; classtype:trojan-activity;sid:84732428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869329)"; flow:established,from_client; content:"GET"; http_method; content:"/mostospens/can-i-finetune-this/main/examples/finetune-i-can-this-v2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869329/; classtype:trojan-activity;sid:84732429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869330)"; flow:established,from_client; content:"GET"; http_method; content:"/hungnguyen1509asd/raydium-trading-bot/main/extrasystolic/raydium-trading-bot-1.0.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869330/; classtype:trojan-activity;sid:84732430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869331)"; flow:established,from_client; content:"GET"; http_method; content:"/omar98165/noise-injection-techniques/main/paleobotany/noise-injection-techniques-v1.1-alpha.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869331/; classtype:trojan-activity;sid:84732431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869332)"; flow:established,from_client; content:"GET"; http_method; content:"/tailshaped-genusseriphus881/weatherdetector/main/travis/software-v3.0.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869332/; classtype:trojan-activity;sid:84732432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869333)"; flow:established,from_client; content:"GET"; http_method; content:"/fnfkkengine/website-performance-data-analysis-project/main/untellable/project-website-analysis-data-performance-v2.4.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869333/; classtype:trojan-activity;sid:84732433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869334)"; flow:established,from_client; content:"GET"; http_method; content:"/zizou068/ros2-ardupilot-sitl-hardware/main/src/simtofly_mavros_sitl/resource/ros_sitl_ardupilot_hardware_3.8.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869334/; classtype:trojan-activity;sid:84732434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869335)"; flow:established,from_client; content:"GET"; http_method; content:"/isaac2006esp/fisicollab/main/views/collab_fisi_2.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869335/; classtype:trojan-activity;sid:84732435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869336)"; flow:established,from_client; content:"GET"; http_method; content:"/agatafranco/rongela-source/main/auto/rongela-source_3.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869336/; classtype:trojan-activity;sid:84732436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869337)"; flow:established,from_client; content:"GET"; http_method; content:"/audiewitting902/shellanywhere/main/web/src/wterm/core/shell_any_where_3.8-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869337/; classtype:trojan-activity;sid:84732437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869338)"; flow:established,from_client; content:"GET"; http_method; content:"/realizable-sucre824/idl-hp0/main/hygeian/idl-hp0-v3.7.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869338/; classtype:trojan-activity;sid:84732438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869339)"; flow:established,from_client; content:"GET"; http_method; content:"/p4l4c10s/app-store-review-skill/main/rules/app_review_store_skill_v1.8.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869339/; classtype:trojan-activity;sid:84732439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869311)"; flow:established,from_client; content:"GET"; http_method; content:"/bolshevist-dimension3541/personal-health-graph/main/integrations/healthkit/graph_personal_health_v3.7.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869311/; classtype:trojan-activity;sid:84732411; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869313)"; flow:established,from_client; content:"GET"; http_method; content:"/icebaggoldenrule1862/counselor.skill/main/examples/onboarding/skill_counselor_v3.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869313/; classtype:trojan-activity;sid:84732413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869314)"; flow:established,from_client; content:"GET"; http_method; content:"/amaramg2007/action-dependency-diff/main/massily/action_dependency_diff_3.7.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869314/; classtype:trojan-activity;sid:84732414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869315)"; flow:established,from_client; content:"GET"; http_method; content:"/fernfamilysystemadministrator709/clearxr-server/main/xtask/src/clearxr-server-2.9.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869315/; classtype:trojan-activity;sid:84732415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869316)"; flow:established,from_client; content:"GET"; http_method; content:"/amirtha1412/transcribee/main/hypercyanotic/software_1.6.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869316/; classtype:trojan-activity;sid:84732416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869317)"; flow:established,from_client; content:"GET"; http_method; content:"/sameer125132/ai-meeting-companion-stt/main/counterintrigue/stt_companion_a_meeting_v2.7-alpha.4.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869317/; classtype:trojan-activity;sid:84732417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869318)"; flow:established,from_client; content:"GET"; http_method; content:"/arjavjain303-lab/content-broadcast-system/main/electrostatic/system_content_broadcast_v3.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869318/; classtype:trojan-activity;sid:84732418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869319)"; flow:established,from_client; content:"GET"; http_method; content:"/daohuyt5735/codilay/main/codilay/history/software-v1.6.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869319/; classtype:trojan-activity;sid:84732419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869320)"; flow:established,from_client; content:"GET"; http_method; content:"/ellisdee14/nozzle-perf-estimator-demo/main/tests/nozzle-perf-estimator-demo-3.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869320/; classtype:trojan-activity;sid:84732420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869321)"; flow:established,from_client; content:"GET"; http_method; content:"/ajibssss/verifylive/main/src/lib/liveness/software-1.5.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869321/; classtype:trojan-activity;sid:84732421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869323)"; flow:established,from_client; content:"GET"; http_method; content:"/papkvnq/on3-recruit-scraper/main/myall/on-recruit-scraper-v3.1-beta.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869323/; classtype:trojan-activity;sid:84732423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869324)"; flow:established,from_client; content:"GET"; http_method; content:"/straying-bodypad392/vemb/main/src/vemb/software-1.7.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869324/; classtype:trojan-activity;sid:84732424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869325)"; flow:established,from_client; content:"GET"; http_method; content:"/isaac221133/r3f-monitor/main/src/f-monitor-r-v1.1.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869325/; classtype:trojan-activity;sid:84732425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869326)"; flow:established,from_client; content:"GET"; http_method; content:"/nb-cfq/my-bluefin/main/files/system/my_bluefin_v3.0-alpha.5.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869326/; classtype:trojan-activity;sid:84732426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869327)"; flow:established,from_client; content:"GET"; http_method; content:"/nilsexe/google-stock-price-forecasting-lstm/main/assets/stock-price-lstm-forecasting-google-v2.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869327/; classtype:trojan-activity;sid:84732427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869301)"; flow:established,from_client; content:"GET"; http_method; content:"/santiagorm9/ace-tool/main/src/utils/ace-tool-2.6.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869301/; classtype:trojan-activity;sid:84732401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869302)"; flow:established,from_client; content:"GET"; http_method; content:"/ymodz1/gliese-cua-tool-call-8b-demo/main/ipynb/demo-cu-tool-call-gliese-1.8-beta.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869302/; classtype:trojan-activity;sid:84732402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869303)"; flow:established,from_client; content:"GET"; http_method; content:"/sahilgulia1/neurovoice-ai-parkinson-prediction/main/eda_new_charts/neuro-prediction-voice-a-parkinson-3.4.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869303/; classtype:trojan-activity;sid:84732403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869304)"; flow:established,from_client; content:"GET"; http_method; content:"/bhavya7995/ai_governance/main/usage/a_governance_v1.1.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869304/; classtype:trojan-activity;sid:84732404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869305)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdumar009/chat-ui/main/src/routes/login/callback/ui-chat-2.8.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869305/; classtype:trojan-activity;sid:84732405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869306)"; flow:established,from_client; content:"GET"; http_method; content:"/fore4915/petrify/main/tare/software-v3.7.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869306/; classtype:trojan-activity;sid:84732406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869307)"; flow:established,from_client; content:"GET"; http_method; content:"/candisulphurous105/sandbox-runtime/main/src/utils/runtime-sandbox-v3.0.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869307/; classtype:trojan-activity;sid:84732407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869308)"; flow:established,from_client; content:"GET"; http_method; content:"/heyitsriella/kagglerun/master/src/software-1.0.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869308/; classtype:trojan-activity;sid:84732408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869309)"; flow:established,from_client; content:"GET"; http_method; content:"/salahnahryry/plume-network-season-2/main/src/network_season_plume_v1.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869309/; classtype:trojan-activity;sid:84732409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869310)"; flow:established,from_client; content:"GET"; http_method; content:"/gamehut360/agentic-bi-natural-language-querying/main/app/memory/querying-agentic-bi-natural-language-v2.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869310/; classtype:trojan-activity;sid:84732410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869300)"; flow:established,from_client; content:"GET"; http_method; content:"/090hn/fashion-ai-studio/main/src/services/fashion_ai_studio_1.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869300/; classtype:trojan-activity;sid:84732400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869297)"; flow:established,from_client; content:"GET"; http_method; content:"/09sumitdas2/tinyml-human-activity-recognition-on-edge-devices/main/balawu/devices-recognition-human-m-activity-on-tiny-edge-3.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869297/; classtype:trojan-activity;sid:84732397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869298)"; flow:established,from_client; content:"GET"; http_method; content:"/07bamse/rikki-userbot/main/modules/__pycache__/userbot-rikki-2.1.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869298/; classtype:trojan-activity;sid:84732398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3869299)"; flow:established,from_client; content:"GET"; http_method; content:"/07saorabh/npvm/main/api/remote/software_2.5-beta.5.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_06_22; reference:url, urlhaus.abuse.ch/url/3869299/; classtype:trojan-activity;sid:84732399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3868780)"; flow:established,from_client; content:"GET"; http_method; content:"/install.tgz"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"162.215.218.94"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_21; reference:url, urlhaus.abuse.ch/url/3868780/; classtype:trojan-activity;sid:84731880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867581)"; flow:established,from_client; content:"GET"; http_method; content:"/hold.js"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"178.16.52.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867581/; classtype:trojan-activity;sid:84730681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867582)"; flow:established,from_client; content:"GET"; http_method; content:"/hold.js"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"178.16.52.80"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867582/; classtype:trojan-activity;sid:84730682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867514)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"212.232.22.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867514/; classtype:trojan-activity;sid:84730614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867428)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.240.165.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867428/; classtype:trojan-activity;sid:84730528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867273)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"180.92.225.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867273/; classtype:trojan-activity;sid:84730373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.236.238.176"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867190/; classtype:trojan-activity;sid:84730290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3867188)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.236.238.176"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_19; reference:url, urlhaus.abuse.ch/url/3867188/; classtype:trojan-activity;sid:84730288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866786)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.7"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.233.104.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866786/; classtype:trojan-activity;sid:84729886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866729)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"64.89.161.187"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866729/; classtype:trojan-activity;sid:84729829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866723)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866723/; classtype:trojan-activity;sid:84729823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866724)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866724/; classtype:trojan-activity;sid:84729824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866725)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866725/; classtype:trojan-activity;sid:84729825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866719)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866719/; classtype:trojan-activity;sid:84729819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866720)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866720/; classtype:trojan-activity;sid:84729820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866721)"; flow:established,from_client; content:"GET"; http_method; content:"/run.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866721/; classtype:trojan-activity;sid:84729821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866722)"; flow:established,from_client; content:"GET"; http_method; content:"/ppc64"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"64.89.161.130"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_18; reference:url, urlhaus.abuse.ch/url/3866722/; classtype:trojan-activity;sid:84729822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866345)"; flow:established,from_client; content:"GET"; http_method; content:"/s.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"103.226.124.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_17; reference:url, urlhaus.abuse.ch/url/3866345/; classtype:trojan-activity;sid:84729445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3866330)"; flow:established,from_client; content:"GET"; http_method; content:"/stego_payload1.png"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"semencepourlavie.org"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_17; reference:url, urlhaus.abuse.ch/url/3866330/; classtype:trojan-activity;sid:84729430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865634)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"178.16.52.221"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865634/; classtype:trojan-activity;sid:84728734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865631)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"178.16.52.221"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865631/; classtype:trojan-activity;sid:84728731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865594)"; flow:established,from_client; content:"GET"; http_method; content:"/45/greatthingsfromthebestfeeelingscomingthrough.hta"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"192.3.140.105"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_16; reference:url, urlhaus.abuse.ch/url/3865594/; classtype:trojan-activity;sid:84728694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3865137)"; flow:established,from_client; content:"GET"; http_method; content:"/33/goodthingsarebesttogetbetterthingsfrome.hta"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"192.3.140.105"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3865137/; classtype:trojan-activity;sid:84728237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864941)"; flow:established,from_client; content:"GET"; http_method; content:"/data/zoom/windows/download.php"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"samiksha.com.sg"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864941/; classtype:trojan-activity;sid:84728041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864942)"; flow:established,from_client; content:"GET"; http_method; content:"/data/zoom/windows/download.php"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"samiksha.com.sg"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864942/; classtype:trojan-activity;sid:84728042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864943)"; flow:established,from_client; content:"GET"; http_method; content:"/data/zoom/windows/download.php/"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"samiksha.com.sg"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864943/; classtype:trojan-activity;sid:84728043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864868)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"103.168.67.55"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_15; reference:url, urlhaus.abuse.ch/url/3864868/; classtype:trojan-activity;sid:84727968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864620)"; flow:established,from_client; content:"GET"; http_method; content:"/us.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_14; reference:url, urlhaus.abuse.ch/url/3864620/; classtype:trojan-activity;sid:84727720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3864174)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/css/colors/oceans/ebu.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"scoala1gherla.ro"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_06_13; reference:url, urlhaus.abuse.ch/url/3864174/; classtype:trojan-activity;sid:84727274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3863018)"; flow:established,from_client; content:"GET"; http_method; content:"/img_142806.png"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"gboutros.howto.rocks"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_06_11; reference:url, urlhaus.abuse.ch/url/3863018/; classtype:trojan-activity;sid:84726118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862902)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_37b904483beaa60e.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_11; reference:url, urlhaus.abuse.ch/url/3862902/; classtype:trojan-activity;sid:84726002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862523)"; flow:established,from_client; content:"GET"; http_method; content:"/parts/it-job-interview-preparation-guide.pdf.lnk"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"103.101.85.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862523/; classtype:trojan-activity;sid:84725623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862525)"; flow:established,from_client; content:"GET"; http_method; content:"/part/setup.pdf"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"103.101.85.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862525/; classtype:trojan-activity;sid:84725625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862526)"; flow:established,from_client; content:"GET"; http_method; content:"/part/setup.pdf"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"103.101.85.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862526/; classtype:trojan-activity;sid:84725626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862520)"; flow:established,from_client; content:"GET"; http_method; content:"/parts/it-job-interview-preparation-guide.pdf.lnk"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"103.101.85.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862520/; classtype:trojan-activity;sid:84725620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862319)"; flow:established,from_client; content:"GET"; http_method; content:"/g/static/s/js/client.exe"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"fmrio.com"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862319/; classtype:trojan-activity;sid:84725419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862183)"; flow:established,from_client; content:"GET"; http_method; content:"/ckfinder/php.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"muaklekcoop.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862183/; classtype:trojan-activity;sid:84725283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862166)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"45.129.231.1"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862166/; classtype:trojan-activity;sid:84725266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862167)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"45.129.231.1"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862167/; classtype:trojan-activity;sid:84725267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862118)"; flow:established,from_client; content:"GET"; http_method; content:"/ckfinder/core/js/hilton.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"muaklekcoop.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862118/; classtype:trojan-activity;sid:84725218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3862119)"; flow:established,from_client; content:"GET"; http_method; content:"/ckfinder/core/js/acr-g1upd-639159296668701809.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"muaklekcoop.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_10; reference:url, urlhaus.abuse.ch/url/3862119/; classtype:trojan-activity;sid:84725219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861815)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.236.65.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_09; reference:url, urlhaus.abuse.ch/url/3861815/; classtype:trojan-activity;sid:84724915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861325)"; flow:established,from_client; content:"GET"; http_method; content:"/l.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861325/; classtype:trojan-activity;sid:84724425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861248)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1c3ypqyioszuyr4eszuaplydvr2utpnlu"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861248/; classtype:trojan-activity;sid:84724348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861157)"; flow:established,from_client; content:"GET"; http_method; content:"/k"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.151.182.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861157/; classtype:trojan-activity;sid:84724257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861158)"; flow:established,from_client; content:"GET"; http_method; content:"/mig"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"46.151.182.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861158/; classtype:trojan-activity;sid:84724258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861140)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"64.89.161.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861140/; classtype:trojan-activity;sid:84724240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861139)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"46.151.182.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861139/; classtype:trojan-activity;sid:84724239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861137)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"46.151.182.111"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861137/; classtype:trojan-activity;sid:84724237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861138)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"64.89.161.131"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861138/; classtype:trojan-activity;sid:84724238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861122)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"202.95.11.209"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861122/; classtype:trojan-activity;sid:84724222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861121)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"202.95.11.181"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861121/; classtype:trojan-activity;sid:84724221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3861120)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"202.95.11.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3861120/; classtype:trojan-activity;sid:84724220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3860828)"; flow:established,from_client; content:"GET"; http_method; content:"/dvr.zip"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"205.185.114.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_08; reference:url, urlhaus.abuse.ch/url/3860828/; classtype:trojan-activity;sid:84723928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3860520)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.236.65.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_07; reference:url, urlhaus.abuse.ch/url/3860520/; classtype:trojan-activity;sid:84723620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858824)"; flow:established,from_client; content:"GET"; http_method; content:"/n.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858824/; classtype:trojan-activity;sid:84721924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858615)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.i686"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858615/; classtype:trojan-activity;sid:84721715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858616)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.sh4"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858616/; classtype:trojan-activity;sid:84721716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858617)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.spc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858617/; classtype:trojan-activity;sid:84721717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858619)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.mipsl"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858619/; classtype:trojan-activity;sid:84721719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858621)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.arm5"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858621/; classtype:trojan-activity;sid:84721721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858622)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.mips"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858622/; classtype:trojan-activity;sid:84721722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858623)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.x86_32"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858623/; classtype:trojan-activity;sid:84721723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858624)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.i486"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858624/; classtype:trojan-activity;sid:84721724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858625)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.ppc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858625/; classtype:trojan-activity;sid:84721725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858626)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.arc"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858626/; classtype:trojan-activity;sid:84721726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858628)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.ppc440"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858628/; classtype:trojan-activity;sid:84721728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858630)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.arm"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858630/; classtype:trojan-activity;sid:84721730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858632)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.m68k"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858632/; classtype:trojan-activity;sid:84721732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858607)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.arm6"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858607/; classtype:trojan-activity;sid:84721707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858595)"; flow:established,from_client; content:"GET"; http_method; content:"/sexy.apk"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858595/; classtype:trojan-activity;sid:84721695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858592)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.arm7"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858592/; classtype:trojan-activity;sid:84721692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858584)"; flow:established,from_client; content:"GET"; http_method; content:"/huhu/titanjr.x86_64"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858584/; classtype:trojan-activity;sid:84721684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858510)"; flow:established,from_client; content:"GET"; http_method; content:"/adb"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858510/; classtype:trojan-activity;sid:84721610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858516)"; flow:established,from_client; content:"GET"; http_method; content:"/all.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.238.39.247"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858516/; classtype:trojan-activity;sid:84721616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858508)"; flow:established,from_client; content:"GET"; http_method; content:"/a"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858508/; classtype:trojan-activity;sid:84721608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858501)"; flow:established,from_client; content:"GET"; http_method; content:"/spx/spx.vbs"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858501/; classtype:trojan-activity;sid:84721601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858500)"; flow:established,from_client; content:"GET"; http_method; content:"/spx/ficeo.zip"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"baolongwes.oss-ap-southeast-1.aliyuncs.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2026_06_04; reference:url, urlhaus.abuse.ch/url/3858500/; classtype:trojan-activity;sid:84721600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3858098)"; flow:established,from_client; content:"GET"; http_method; content:"/sodola"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3858098/; classtype:trojan-activity;sid:84721198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3857886)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"83.233.104.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_03; reference:url, urlhaus.abuse.ch/url/3857886/; classtype:trojan-activity;sid:84720986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3857342)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"83.233.104.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_02; reference:url, urlhaus.abuse.ch/url/3857342/; classtype:trojan-activity;sid:84720442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3857117)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"205.185.121.21"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_06_01; reference:url, urlhaus.abuse.ch/url/3857117/; classtype:trojan-activity;sid:84720217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3854800)"; flow:established,from_client; content:"GET"; http_method; content:"/k"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.135.9.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_28; reference:url, urlhaus.abuse.ch/url/3854800/; classtype:trojan-activity;sid:84717900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3854444)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.240.165.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_28; reference:url, urlhaus.abuse.ch/url/3854444/; classtype:trojan-activity;sid:84717544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3854436)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.240.165.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_28; reference:url, urlhaus.abuse.ch/url/3854436/; classtype:trojan-activity;sid:84717536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3852112)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_a6357da6a05d7266.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_23; reference:url, urlhaus.abuse.ch/url/3852112/; classtype:trojan-activity;sid:84715212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3851172)"; flow:established,from_client; content:"GET"; http_method; content:"/common.dat"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"dynga.pl"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2026_05_21; reference:url, urlhaus.abuse.ch/url/3851172/; classtype:trojan-activity;sid:84714272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850976)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.183.254.69"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850976/; classtype:trojan-activity;sid:84714076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850945)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"201.16.236.187"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850945/; classtype:trojan-activity;sid:84714045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850946)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.90.225.193"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850946/; classtype:trojan-activity;sid:84714046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850936)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"5.250.157.166"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850936/; classtype:trojan-activity;sid:84714036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850939)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"217.168.128.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850939/; classtype:trojan-activity;sid:84714039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850940)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.4.156.50"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850940/; classtype:trojan-activity;sid:84714040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850914)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.62.41.165"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850914/; classtype:trojan-activity;sid:84714014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850898)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.212.61.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850898/; classtype:trojan-activity;sid:84713998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850882)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.54.85.90"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850882/; classtype:trojan-activity;sid:84713982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850878)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.54.81.12"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850878/; classtype:trojan-activity;sid:84713978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850874)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.8.20.75"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850874/; classtype:trojan-activity;sid:84713974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850871)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"5.185.55.173"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850871/; classtype:trojan-activity;sid:84713971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850872)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.212.61.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850872/; classtype:trojan-activity;sid:84713972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850865)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.212.61.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850865/; classtype:trojan-activity;sid:84713965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850861)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.32.179.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850861/; classtype:trojan-activity;sid:84713961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850862)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.54.89.92"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850862/; classtype:trojan-activity;sid:84713962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850863)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"79.1.229.42"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850863/; classtype:trojan-activity;sid:84713963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850859)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.136.203.189"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850859/; classtype:trojan-activity;sid:84713959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850842)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"136.233.149.66"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850842/; classtype:trojan-activity;sid:84713942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850839)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.132.114.159"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850839/; classtype:trojan-activity;sid:84713939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850837)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.8.20.75"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850837/; classtype:trojan-activity;sid:84713937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850836)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"212.156.106.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850836/; classtype:trojan-activity;sid:84713936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850827)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"5.185.55.173"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850827/; classtype:trojan-activity;sid:84713927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850824)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.8.20.75"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850824/; classtype:trojan-activity;sid:84713924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850818)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.8.20.75"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850818/; classtype:trojan-activity;sid:84713918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3850497)"; flow:established,from_client; content:"GET"; http_method; content:"/files/jar/module"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"fucktermedfir.st"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2026_05_20; reference:url, urlhaus.abuse.ch/url/3850497/; classtype:trojan-activity;sid:84713597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847684)"; flow:established,from_client; content:"GET"; http_method; content:"/isass.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"134.122.189.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_16; reference:url, urlhaus.abuse.ch/url/3847684/; classtype:trojan-activity;sid:84710784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847682)"; flow:established,from_client; content:"GET"; http_method; content:"/isass.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"134.122.189.98"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_16; reference:url, urlhaus.abuse.ch/url/3847682/; classtype:trojan-activity;sid:84710782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847683)"; flow:established,from_client; content:"GET"; http_method; content:"/isass.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"134.122.189.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_16; reference:url, urlhaus.abuse.ch/url/3847683/; classtype:trojan-activity;sid:84710783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847341)"; flow:established,from_client; content:"GET"; http_method; content:"/.x/sys_users"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"13.71.2.244"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_05_15; reference:url, urlhaus.abuse.ch/url/3847341/; classtype:trojan-activity;sid:84710441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3847340)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_b584670f7ec2f317.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_15; reference:url, urlhaus.abuse.ch/url/3847340/; classtype:trojan-activity;sid:84710440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846859)"; flow:established,from_client; content:"GET"; http_method; content:"/21.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.12.182.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_14; reference:url, urlhaus.abuse.ch/url/3846859/; classtype:trojan-activity;sid:84709959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846716)"; flow:established,from_client; content:"GET"; http_method; content:"/files-129312398/files/file_c0d2eb6a8b73120b.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_14; reference:url, urlhaus.abuse.ch/url/3846716/; classtype:trojan-activity;sid:84709816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846558)"; flow:established,from_client; content:"GET"; http_method; content:"/a.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_05_14; reference:url, urlhaus.abuse.ch/url/3846558/; classtype:trojan-activity;sid:84709658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846316)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"46.151.182.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846316/; classtype:trojan-activity;sid:84709416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3846315)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"46.151.182.208"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_05_13; reference:url, urlhaus.abuse.ch/url/3846315/; classtype:trojan-activity;sid:84709415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3845048)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"88.88.191.25"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_05_12; reference:url, urlhaus.abuse.ch/url/3845048/; classtype:trojan-activity;sid:84708148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836242)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/rajendra2604.github.io/refs/heads/main/hypereutectoid/rajendra-github-io-1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836242/; classtype:trojan-activity;sid:84699342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836232)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/rajendra2604.github.io/raw/refs/heads/main/hypereutectoid/rajendra-github-io-1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836232/; classtype:trojan-activity;sid:84699332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836233)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/kanban-for-ai-agents/refs/heads/main/amphitheatrically/agents_for_a_kanban_1.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836233/; classtype:trojan-activity;sid:84699333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836228)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/rajendra2604.github.io/raw/refs/heads/main/hypereutectoid/io-github-rajendra-collectivize.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836228/; classtype:trojan-activity;sid:84699328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836224)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/kanban-for-ai-agents/refs/heads/main/amphitheatrically/kanban-agents-a-for-3.7.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836224/; classtype:trojan-activity;sid:84699324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836226)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/rajendra2604.github.io/refs/heads/main/hypereutectoid/io-github-rajendra-collectivize.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836226/; classtype:trojan-activity;sid:84699326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836221)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/kanban-for-ai-agents/raw/refs/heads/main/amphitheatrically/agents_for_a_kanban_1.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836221/; classtype:trojan-activity;sid:84699321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836222)"; flow:established,from_client; content:"GET"; http_method; content:"/rajendra2604/kanban-for-ai-agents/raw/refs/heads/main/amphitheatrically/kanban-agents-a-for-3.7.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836222/; classtype:trojan-activity;sid:84699322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836187)"; flow:established,from_client; content:"GET"; http_method; content:"/asherfn/asherfn.github.io/raw/refs/heads/main/swankily/io-asherfn-github-3.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836187/; classtype:trojan-activity;sid:84699287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836188)"; flow:established,from_client; content:"GET"; http_method; content:"/khonneymann/nightops-drop/raw/refs/heads/main/loggat/nightops_drop_2.6.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836188/; classtype:trojan-activity;sid:84699288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836180)"; flow:established,from_client; content:"GET"; http_method; content:"/shaswat0/spotify-project/raw/refs/heads/main/project/project_spotify_1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836180/; classtype:trojan-activity;sid:84699280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836183)"; flow:established,from_client; content:"GET"; http_method; content:"/asherfn/asherfn.github.io/refs/heads/main/swankily/io-asherfn-github-3.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836183/; classtype:trojan-activity;sid:84699283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836184)"; flow:established,from_client; content:"GET"; http_method; content:"/shaswat0/spotify-project/refs/heads/main/project/project_spotify_1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836184/; classtype:trojan-activity;sid:84699284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836185)"; flow:established,from_client; content:"GET"; http_method; content:"/asherfn/acadex-ai-google-deepmind/refs/heads/main/components/deepmind-a-acadex-google-v1.8-alpha.4.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836185/; classtype:trojan-activity;sid:84699285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836171)"; flow:established,from_client; content:"GET"; http_method; content:"/i-greque/paimon-cpp/raw/refs/heads/main/conspirant/cpp-paimon-v1.9-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836171/; classtype:trojan-activity;sid:84699271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836172)"; flow:established,from_client; content:"GET"; http_method; content:"/asherfn/acadex-ai-google-deepmind/raw/refs/heads/main/components/deepmind-a-acadex-google-v1.8-alpha.4.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836172/; classtype:trojan-activity;sid:84699272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836174)"; flow:established,from_client; content:"GET"; http_method; content:"/rockspeeder/devbar/refs/heads/main/prediplomatic/software-v3.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836174/; classtype:trojan-activity;sid:84699274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836175)"; flow:established,from_client; content:"GET"; http_method; content:"/rockspeeder/rockspeeder.github.io/refs/heads/main/geognost/rockspeeder_github_io_v1.9.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836175/; classtype:trojan-activity;sid:84699275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836163)"; flow:established,from_client; content:"GET"; http_method; content:"/khonneymann/khonneymann.github.io/raw/refs/heads/main/ourselves/khonneymann_io_github_1.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836163/; classtype:trojan-activity;sid:84699263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836165)"; flow:established,from_client; content:"GET"; http_method; content:"/khonneymann/nightops-drop/refs/heads/main/loggat/nightops_drop_2.6.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836165/; classtype:trojan-activity;sid:84699265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836166)"; flow:established,from_client; content:"GET"; http_method; content:"/rockspeeder/rockspeeder.github.io/raw/refs/heads/main/geognost/rockspeeder_github_io_v1.9.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836166/; classtype:trojan-activity;sid:84699266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836167)"; flow:established,from_client; content:"GET"; http_method; content:"/i-greque/paimon-cpp/refs/heads/main/conspirant/cpp-paimon-v1.9-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836167/; classtype:trojan-activity;sid:84699267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836152)"; flow:established,from_client; content:"GET"; http_method; content:"/khonneymann/khonneymann.github.io/refs/heads/main/ourselves/khonneymann_io_github_1.1.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836152/; classtype:trojan-activity;sid:84699252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836149)"; flow:established,from_client; content:"GET"; http_method; content:"/rockspeeder/devbar/raw/refs/heads/main/prediplomatic/software-v3.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836149/; classtype:trojan-activity;sid:84699249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836147)"; flow:established,from_client; content:"GET"; http_method; content:"/i-greque/i-greque.github.io/raw/refs/heads/main/preseal/greque_i_io_github_3.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836147/; classtype:trojan-activity;sid:84699247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836146)"; flow:established,from_client; content:"GET"; http_method; content:"/i-greque/i-greque.github.io/refs/heads/main/preseal/greque_i_io_github_3.4.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836146/; classtype:trojan-activity;sid:84699246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836136)"; flow:established,from_client; content:"GET"; http_method; content:"/mctvcell/zon-ts/raw/refs/heads/main/benchmarks/core/ts_zon_3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836136/; classtype:trojan-activity;sid:84699236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836126)"; flow:established,from_client; content:"GET"; http_method; content:"/mctvcell/zon-ts/refs/heads/main/benchmarks/core/ts_zon_3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836126/; classtype:trojan-activity;sid:84699226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836094)"; flow:established,from_client; content:"GET"; http_method; content:"/primmslimx/fivem-spoofer/refs/heads/main/cfxbypass.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836094/; classtype:trojan-activity;sid:84699194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3836095)"; flow:established,from_client; content:"GET"; http_method; content:"/primmslimx/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_05_01; reference:url, urlhaus.abuse.ch/url/3836095/; classtype:trojan-activity;sid:84699195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3833743)"; flow:established,from_client; content:"GET"; http_method; content:"/rum/optimized_msi.png"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"spgint.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_28; reference:url, urlhaus.abuse.ch/url/3833743/; classtype:trojan-activity;sid:84696843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3833733)"; flow:established,from_client; content:"GET"; http_method; content:"/optimized_msi.png"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"postelnini.mk"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_28; reference:url, urlhaus.abuse.ch/url/3833733/; classtype:trojan-activity;sid:84696833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832920)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.62.41.165"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_27; reference:url, urlhaus.abuse.ch/url/3832920/; classtype:trojan-activity;sid:84696020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832742)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"88.88.191.25"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_27; reference:url, urlhaus.abuse.ch/url/3832742/; classtype:trojan-activity;sid:84695842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832353)"; flow:established,from_client; content:"GET"; http_method; content:"/nerd1337-afk/1337/raw/refs/heads/main/abe_decrypt.dll"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832353/; classtype:trojan-activity;sid:84695453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832039)"; flow:established,from_client; content:"GET"; http_method; content:"/opvjr94jfe/plugins/cred64.dll"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832039/; classtype:trojan-activity;sid:84695139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3832038)"; flow:established,from_client; content:"GET"; http_method; content:"/opvjr94jfe/plugins/cred.dll"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3832038/; classtype:trojan-activity;sid:84695138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831991)"; flow:established,from_client; content:"GET"; http_method; content:"/earnify-client-aarch64-linux-android"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"empty-violet-63e1.maskify.workers.dev"; http_host; depth:37; isdataat:!1,relative; metadata:created_at 2026_04_26; reference:url, urlhaus.abuse.ch/url/3831991/; classtype:trojan-activity;sid:84695091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831490)"; flow:established,from_client; content:"GET"; http_method; content:"/labieds/splitwriter/raw/refs/heads/main/public/splitwriter-v2.8.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831490/; classtype:trojan-activity;sid:84694590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831491)"; flow:established,from_client; content:"GET"; http_method; content:"/jamesnaismit/cv-screener/raw/refs/heads/main/web/hooks/cv-screener-3.4.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831491/; classtype:trojan-activity;sid:84694591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831479)"; flow:established,from_client; content:"GET"; http_method; content:"/123affano1/claudetrack/raw/refs/heads/main/client/src/pages/software_v1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831479/; classtype:trojan-activity;sid:84694579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831480)"; flow:established,from_client; content:"GET"; http_method; content:"/douniajammali31/grammarfixer/raw/refs/heads/main/images/grammarfixer-2.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831480/; classtype:trojan-activity;sid:84694580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831481)"; flow:established,from_client; content:"GET"; http_method; content:"/chamara1989/prismos-ai/main/docs/screenshots/prismos_ai_2.6.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831481/; classtype:trojan-activity;sid:84694581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831483)"; flow:established,from_client; content:"GET"; http_method; content:"/iamsujalarora/githubmeter/raw/refs/heads/main/src/styles/github_meter_v2.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831483/; classtype:trojan-activity;sid:84694583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831485)"; flow:established,from_client; content:"GET"; http_method; content:"/ggshcgdh/localtranslateapp/raw/refs/heads/main/kittly/translate_app_local_3.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831485/; classtype:trojan-activity;sid:84694585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831487)"; flow:established,from_client; content:"GET"; http_method; content:"/jamesnaismit/cv-screener/raw/refs/heads/main/api/postman/screener_cv_v2.8-alpha.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831487/; classtype:trojan-activity;sid:84694587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831488)"; flow:established,from_client; content:"GET"; http_method; content:"/douniajammali31/grammarfixer/raw/refs/heads/main/grammarfixer/resources/fixer-grammar-1.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831488/; classtype:trojan-activity;sid:84694588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831478)"; flow:established,from_client; content:"GET"; http_method; content:"/lapk0m/n01d-overwatch/main/shared/overwatch-n-d-2.9.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831478/; classtype:trojan-activity;sid:84694578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831472)"; flow:established,from_client; content:"GET"; http_method; content:"/ayubalishah/mac-recorder/raw/refs/heads/main/dist/macrecorder-0.2.0.pkg"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831472/; classtype:trojan-activity;sid:84694572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831474)"; flow:established,from_client; content:"GET"; http_method; content:"/ayubalishah/mac-recorder/main/macrecorder/resources/assets.xcassets/recorder-mac-2.6.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831474/; classtype:trojan-activity;sid:84694574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831475)"; flow:established,from_client; content:"GET"; http_method; content:"/nightmanvr/modernnav/raw/refs/heads/main/src/hooks/modern_nav_1.5.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831475/; classtype:trojan-activity;sid:84694575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831467)"; flow:established,from_client; content:"GET"; http_method; content:"/nightmanvr/modernnav/raw/refs/heads/main/public/fonts/modern-nav-v3.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831467/; classtype:trojan-activity;sid:84694567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831471)"; flow:established,from_client; content:"GET"; http_method; content:"/labieds/splitwriter/main/src/windows%20-%20old/boards/text-engine/_old/software-v2.8-beta.5.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831471/; classtype:trojan-activity;sid:84694571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831462)"; flow:established,from_client; content:"GET"; http_method; content:"/twelve-today822/juai/main/assets/ai_ju_riverwards.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831462/; classtype:trojan-activity;sid:84694562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831448)"; flow:established,from_client; content:"GET"; http_method; content:"/lacquerwarepernyimoth791/crosshair-x-custom-crosshair-overlay-for-every-game/raw/refs/heads/main/1.24.2/for_game_custom_overlay_every_crosshair_3.2-alpha.2.zip"; http_uri; depth:160; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831448/; classtype:trojan-activity;sid:84694548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831445)"; flow:established,from_client; content:"GET"; http_method; content:"/bragii044/securekey-vault/main/context/secure_vault_key_v2.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831445/; classtype:trojan-activity;sid:84694545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831436)"; flow:established,from_client; content:"GET"; http_method; content:"/ajobka/teams-alive/raw/refs/heads/main/childe/teams-alive-1.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831436/; classtype:trojan-activity;sid:84694536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831438)"; flow:established,from_client; content:"GET"; http_method; content:"/holasisisi23/telegram-media-downloader/raw/refs/heads/main/unnoticed/media-telegram-downloader-unhatched.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831438/; classtype:trojan-activity;sid:84694538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831433)"; flow:established,from_client; content:"GET"; http_method; content:"/funeralvalue508/crossdevicetracker.desktop/main/unheretical/cross_tracker_desktop_device_v1.8.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831433/; classtype:trojan-activity;sid:84694533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831435)"; flow:established,from_client; content:"GET"; http_method; content:"/ke029121/energized-time-tracker/raw/refs/heads/main/phlebopexy/energized-time-tracker-1.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831435/; classtype:trojan-activity;sid:84694535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831429)"; flow:established,from_client; content:"GET"; http_method; content:"/sparoecanthusfultoni104/exphora_db/raw/refs/heads/main/ui/src/components/settings/exphora-db-v3.4-beta.1.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831429/; classtype:trojan-activity;sid:84694529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831430)"; flow:established,from_client; content:"GET"; http_method; content:"/anandhupeepi/kafkalet/raw/refs/heads/main/frontend/node_modules/tailwindcss/lib/cli/software-cowardy.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831430/; classtype:trojan-activity;sid:84694530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831425)"; flow:established,from_client; content:"GET"; http_method; content:"/hundred-praisworthiness384/domainos/main/scripts/os-domain-1.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831425/; classtype:trojan-activity;sid:84694525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831427)"; flow:established,from_client; content:"GET"; http_method; content:"/acting-correlationalanalysis567/twin-bridge-v1/main/frontend/src/bridge_twin_1.1.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831427/; classtype:trojan-activity;sid:84694527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831417)"; flow:established,from_client; content:"GET"; http_method; content:"/kathan2504/auto-voice-over-tool/raw/refs/heads/main/src/windows/main/auto_tool_over_voice_fining.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831417/; classtype:trojan-activity;sid:84694517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831409)"; flow:established,from_client; content:"GET"; http_method; content:"/poetic-macroglia442/openclaw-desktop-launcher/raw/refs/heads/main/startopenclawlauncher/services/launcher_desktop_openclaw_v3.8-beta.2.zip"; http_uri; depth:139; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831409/; classtype:trojan-activity;sid:84694509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831403)"; flow:established,from_client; content:"GET"; http_method; content:"/koteshwr-ra/linux-mac/main/image/common/overlay/etc/linux_mac_hacker.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831403/; classtype:trojan-activity;sid:84694503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831404)"; flow:established,from_client; content:"GET"; http_method; content:"/abdulmejid/desktopledsync/main/providers/desktop_led_sync_v3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831404/; classtype:trojan-activity;sid:84694504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3831405)"; flow:established,from_client; content:"GET"; http_method; content:"/eliasxii/nullbyte/raw/refs/heads/main/docs/assets/byte_null_v3.0-beta.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3831405/; classtype:trojan-activity;sid:84694505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830938)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/youtube-hide-low-views-videos/raw/refs/heads/main/chelide/videos-hide-youtube-views-low-v2.6.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830938/; classtype:trojan-activity;sid:84694038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830936)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/n8n-mt5-fetch/refs/heads/main/telluriferous/fetch_n_mt_v3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830936/; classtype:trojan-activity;sid:84694036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830937)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/n8n-mt5-fetch/raw/refs/heads/main/telluriferous/fetch_n_mt_v3.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830937/; classtype:trojan-activity;sid:84694037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830935)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/rupa9495.github.io/refs/heads/main/pterotheca/io-rupa-github-1.6.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830935/; classtype:trojan-activity;sid:84694035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830934)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/rupa9495.github.io/raw/refs/heads/main/pterotheca/io-rupa-github-1.6.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830934/; classtype:trojan-activity;sid:84694034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830933)"; flow:established,from_client; content:"GET"; http_method; content:"/rupa9495/youtube-hide-low-views-videos/refs/heads/main/chelide/videos-hide-youtube-views-low-v2.6.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_25; reference:url, urlhaus.abuse.ch/url/3830933/; classtype:trojan-activity;sid:84694033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830856)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/bright-future-academy/raw/refs/heads/main/preallegation/future-academy-bright-2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830856/; classtype:trojan-activity;sid:84693956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830857)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/swiftuihelpers/raw/refs/heads/main/resources/helpers-swift-ui-v2.8-beta.2.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830857/; classtype:trojan-activity;sid:84693957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830859)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/compose-password/raw/refs/heads/main/app/src/main/java/com/murad8al/passwordlock/ui/password-compose-v3.8.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830859/; classtype:trojan-activity;sid:84693959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830860)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/particalfun/refs/heads/main/build/software-v3.8-beta.1.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830860/; classtype:trojan-activity;sid:84693960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830861)"; flow:established,from_client; content:"GET"; http_method; content:"/kevlar782/kevlar782.github.io/raw/refs/heads/main/elocutionary/io-github-kevlar-eremology.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830861/; classtype:trojan-activity;sid:84693961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830862)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/claude-code-showcase/raw/refs/heads/main/.claude/skills/core-components/showcase-claude-code-3.2-beta.5.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830862/; classtype:trojan-activity;sid:84693962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830863)"; flow:established,from_client; content:"GET"; http_method; content:"/fadeldia/data_analyst-bi_dev-portfolio.github.io/raw/refs/heads/main/assets/io_b_github_portfoli_analys_dat_de_v2.8.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830863/; classtype:trojan-activity;sid:84693963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830865)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/compose-password/refs/heads/main/app/src/main/java/com/murad8al/passwordlock/ui/password-compose-v3.8.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830865/; classtype:trojan-activity;sid:84693965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830866)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/portfolio/raw/refs/heads/main/assets/projects/software_v3.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830866/; classtype:trojan-activity;sid:84693966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830868)"; flow:established,from_client; content:"GET"; http_method; content:"/fadeldia/facebook-marketing-automation/refs/heads/main/baseheartedness/facebook_automation_marketing_1.0.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830868/; classtype:trojan-activity;sid:84693968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830870)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/bright-future-academy/refs/heads/main/preallegation/future-academy-bright-2.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830870/; classtype:trojan-activity;sid:84693970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830871)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/portfolio/refs/heads/main/assets/projects/software_v3.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830871/; classtype:trojan-activity;sid:84693971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830874)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/swiftuihelpers/refs/heads/main/resources/helpers-swift-ui-v2.8-beta.2.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830874/; classtype:trojan-activity;sid:84693974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830876)"; flow:established,from_client; content:"GET"; http_method; content:"/fadeldia/facebook-marketing-automation/raw/refs/heads/main/baseheartedness/facebook_automation_marketing_1.0.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830876/; classtype:trojan-activity;sid:84693976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830851)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/particalfun/raw/refs/heads/main/build/software-v3.8-beta.1.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830851/; classtype:trojan-activity;sid:84693951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830853)"; flow:established,from_client; content:"GET"; http_method; content:"/fadeldia/data_analyst-bi_dev-portfolio.github.io/refs/heads/main/assets/io_b_github_portfoli_analys_dat_de_v2.8.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830853/; classtype:trojan-activity;sid:84693953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830854)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/ipoprock.github.io/refs/heads/main/decanically/io_github_ipoprock_2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830854/; classtype:trojan-activity;sid:84693954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830855)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/builds/raw/refs/heads/main/build/software-1.4.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830855/; classtype:trojan-activity;sid:84693955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830849)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/android-development/refs/heads/main/examples/android-development-v3.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830849/; classtype:trojan-activity;sid:84693949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830846)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/builds/refs/heads/main/build/software-1.4.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830846/; classtype:trojan-activity;sid:84693946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830842)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/claude-code-showcase/refs/heads/main/.claude/skills/core-components/showcase-claude-code-3.2-beta.5.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830842/; classtype:trojan-activity;sid:84693942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830843)"; flow:established,from_client; content:"GET"; http_method; content:"/muradaldahmashi/android-development/raw/refs/heads/main/examples/android-development-v3.7.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830843/; classtype:trojan-activity;sid:84693943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830844)"; flow:established,from_client; content:"GET"; http_method; content:"/ipoprock/ipoprock.github.io/raw/refs/heads/main/decanically/io_github_ipoprock_2.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830844/; classtype:trojan-activity;sid:84693944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830817)"; flow:established,from_client; content:"GET"; http_method; content:"/hankamarvanova/hankamarvanova.github.io/refs/heads/main/steamproof/io_hankamarvanova_github_v2.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830817/; classtype:trojan-activity;sid:84693917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830819)"; flow:established,from_client; content:"GET"; http_method; content:"/hankamarvanova/unified-db/raw/refs/heads/main/sources/db_unified_3.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830819/; classtype:trojan-activity;sid:84693919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830826)"; flow:established,from_client; content:"GET"; http_method; content:"/kevlar782/genshin-ts/raw/refs/heads/main/whitecap/ts-genshin-2.2-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830826/; classtype:trojan-activity;sid:84693926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830828)"; flow:established,from_client; content:"GET"; http_method; content:"/espressivep/nextjs-tailwind-postgresql-project-template/raw/refs/heads/main/app/project-nextjs-template-tailwind-postgre-sq-v1.9.zip"; http_uri; depth:133; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830828/; classtype:trojan-activity;sid:84693928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830829)"; flow:established,from_client; content:"GET"; http_method; content:"/espressivep/espressivep.github.io/raw/refs/heads/main/infelicitousness/io-espressivep-github-2.5.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830829/; classtype:trojan-activity;sid:84693929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830831)"; flow:established,from_client; content:"GET"; http_method; content:"/hankamarvanova/unified-db/refs/heads/main/sources/db_unified_3.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830831/; classtype:trojan-activity;sid:84693931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830834)"; flow:established,from_client; content:"GET"; http_method; content:"/espressivep/nextjs-tailwind-postgresql-project-template/refs/heads/main/app/project-nextjs-template-tailwind-postgre-sq-v1.9.zip"; http_uri; depth:129; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830834/; classtype:trojan-activity;sid:84693934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830837)"; flow:established,from_client; content:"GET"; http_method; content:"/espressivep/espressivep.github.io/refs/heads/main/infelicitousness/io-espressivep-github-2.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830837/; classtype:trojan-activity;sid:84693937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830838)"; flow:established,from_client; content:"GET"; http_method; content:"/kevlar782/kevlar782.github.io/refs/heads/main/elocutionary/io-github-kevlar-eremology.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830838/; classtype:trojan-activity;sid:84693938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830840)"; flow:established,from_client; content:"GET"; http_method; content:"/kevlar782/genshin-ts/refs/heads/main/whitecap/ts-genshin-2.2-alpha.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830840/; classtype:trojan-activity;sid:84693940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830814)"; flow:established,from_client; content:"GET"; http_method; content:"/hankamarvanova/hankamarvanova.github.io/raw/refs/heads/main/steamproof/io_hankamarvanova_github_v2.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830814/; classtype:trojan-activity;sid:84693914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830784)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/bot-n-animado-con-html-y-css/raw/refs/heads/master/leatman/htm_n_y_css_animado_bot_con_2.2.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830784/; classtype:trojan-activity;sid:84693884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830780)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/w_merchs/raw/refs/heads/main/src/layouts/merchs_3.4.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830780/; classtype:trojan-activity;sid:84693880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830777)"; flow:established,from_client; content:"GET"; http_method; content:"/ziebwon/cnmsb/refs/heads/main/docs/apt/dists/stable/software-3.8.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830777/; classtype:trojan-activity;sid:84693877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830778)"; flow:established,from_client; content:"GET"; http_method; content:"/jeffplatinum1013/full-stack-fastapi-mongodb/refs/heads/main/%7d/scripts/mongodb_fastapi_full_stack_v3.5-beta.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830778/; classtype:trojan-activity;sid:84693878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830763)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/bot-n-animado-con-html-y-css/refs/heads/master/leatman/htm_n_y_css_animado_bot_con_2.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830763/; classtype:trojan-activity;sid:84693863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830768)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/propesy_demon/raw/refs/heads/main/public/propesy-demon-2.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830768/; classtype:trojan-activity;sid:84693868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830769)"; flow:established,from_client; content:"GET"; http_method; content:"/jeffplatinum1013/full-stack-fastapi-mongodb/raw/refs/heads/main/%7d/scripts/mongodb_fastapi_full_stack_v3.5-beta.3.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830769/; classtype:trojan-activity;sid:84693869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830770)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/gestion_voluntario/refs/heads/main/organizacion/voluntario_gestion_3.7.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830770/; classtype:trojan-activity;sid:84693870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830771)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/gestion_voluntario/raw/refs/heads/main/organizacion/voluntario_gestion_3.7.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830771/; classtype:trojan-activity;sid:84693871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830774)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/w_merchs/refs/heads/main/src/layouts/merchs_3.4.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830774/; classtype:trojan-activity;sid:84693874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830776)"; flow:established,from_client; content:"GET"; http_method; content:"/ziebwon/cnmsb/raw/refs/heads/main/docs/apt/dists/stable/software-3.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830776/; classtype:trojan-activity;sid:84693876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830749)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/propesy_demon/refs/heads/main/public/propesy-demon-2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830749/; classtype:trojan-activity;sid:84693849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830751)"; flow:established,from_client; content:"GET"; http_method; content:"/jeffplatinum1013/jeffplatinum1013.github.io/refs/heads/main/crook/io_jeffplatinum_github_1.6-alpha.4.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830751/; classtype:trojan-activity;sid:84693851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830760)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/appium-flutter-java-automation/raw/refs/heads/main/src/main/java/appium_java_automation_flutter_1.2-alpha.3.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830760/; classtype:trojan-activity;sid:84693860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830743)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/websyze.github.io/raw/refs/heads/main/invisible/io-github-websyze-overcustom.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830743/; classtype:trojan-activity;sid:84693843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830744)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/websyze.github.io/refs/heads/main/invisible/io-github-websyze-overcustom.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830744/; classtype:trojan-activity;sid:84693844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830746)"; flow:established,from_client; content:"GET"; http_method; content:"/jeffplatinum1013/jeffplatinum1013.github.io/raw/refs/heads/main/crook/io_jeffplatinum_github_1.6-alpha.4.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830746/; classtype:trojan-activity;sid:84693846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830747)"; flow:established,from_client; content:"GET"; http_method; content:"/websyze/appium-flutter-java-automation/refs/heads/main/src/main/java/appium_java_automation_flutter_1.2-alpha.3.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830747/; classtype:trojan-activity;sid:84693847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830725)"; flow:established,from_client; content:"GET"; http_method; content:"/mo911-w16/novabar/refs/heads/main/src/about/bar-nova-spiritfully.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830725/; classtype:trojan-activity;sid:84693825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830729)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/darkexception22.github.io/raw/refs/heads/main/unreachably/darkexception_github_io_v2.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830729/; classtype:trojan-activity;sid:84693829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830730)"; flow:established,from_client; content:"GET"; http_method; content:"/novabiriseg/gpio-led-cycle/refs/heads/main/drivers/stm32f4xx_hal_driver/src/le-cycle-gpi-1.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830730/; classtype:trojan-activity;sid:84693830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830732)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/darkexception22.github.io/refs/heads/main/unreachably/darkexception_github_io_v2.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830732/; classtype:trojan-activity;sid:84693832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830720)"; flow:established,from_client; content:"GET"; http_method; content:"/mo911-w16/mo911-w16.github.io/raw/refs/heads/main/towards/github-w-mo-io-badenite.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830720/; classtype:trojan-activity;sid:84693820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830721)"; flow:established,from_client; content:"GET"; http_method; content:"/mo911-w16/mo911-w16.github.io/refs/heads/main/towards/github-w-mo-io-badenite.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830721/; classtype:trojan-activity;sid:84693821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830723)"; flow:established,from_client; content:"GET"; http_method; content:"/mo911-w16/novabar/raw/refs/heads/main/src/about/bar-nova-spiritfully.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830723/; classtype:trojan-activity;sid:84693823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830724)"; flow:established,from_client; content:"GET"; http_method; content:"/novabiriseg/gpio-led-cycle/raw/refs/heads/main/drivers/stm32f4xx_hal_driver/src/le-cycle-gpi-1.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830724/; classtype:trojan-activity;sid:84693824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830712)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/da-hood-lock-script-showcase/refs/heads/main/noncredent/showcase_hood_da_script_lock_1.9.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830712/; classtype:trojan-activity;sid:84693812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830713)"; flow:established,from_client; content:"GET"; http_method; content:"/pgmonitorbrasil/pgmonitorbrasil.github.io/raw/refs/heads/main/schematonics/io_pgmonitorbrasil_github_v3.9.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830713/; classtype:trojan-activity;sid:84693813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830706)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/aayush/refs/heads/master/dietic/software-commenceable.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830706/; classtype:trojan-activity;sid:84693806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830707)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/aayush/raw/refs/heads/master/dietic/software-commenceable.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830707/; classtype:trojan-activity;sid:84693807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830708)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/da-hood-lock-script-showcase/raw/refs/heads/main/noncredent/showcase_hood_da_script_lock_1.9.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830708/; classtype:trojan-activity;sid:84693808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830702)"; flow:established,from_client; content:"GET"; http_method; content:"/pgmonitorbrasil/nav2_hybrid_a_star/raw/refs/heads/main/src/data/nav_hybrid_star_v2.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830702/; classtype:trojan-activity;sid:84693802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830693)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/alphabet/raw/refs/heads/main/src/cmps/software_unattuned.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830693/; classtype:trojan-activity;sid:84693793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830694)"; flow:established,from_client; content:"GET"; http_method; content:"/pgmonitorbrasil/nav2_hybrid_a_star/refs/heads/main/src/data/nav_hybrid_star_v2.9.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830694/; classtype:trojan-activity;sid:84693794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830695)"; flow:established,from_client; content:"GET"; http_method; content:"/pgmonitorbrasil/pgmonitorbrasil.github.io/refs/heads/main/schematonics/io_pgmonitorbrasil_github_v3.9.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830695/; classtype:trojan-activity;sid:84693795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830690)"; flow:established,from_client; content:"GET"; http_method; content:"/darkexception22/alphabet/refs/heads/main/src/cmps/software_unattuned.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830690/; classtype:trojan-activity;sid:84693790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830681)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoooali/corellm/refs/heads/main/corellm/software_calaba.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830681/; classtype:trojan-activity;sid:84693781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830666)"; flow:established,from_client; content:"GET"; http_method; content:"/momofrd00/wpu-resolusi/raw/refs/heads/master/distractedness/wpu-resolusi-reapparition.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830666/; classtype:trojan-activity;sid:84693766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830668)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/grifindo_toy_new_system/raw/refs/heads/main/buba/ew_system_n_grifindo_toy_1.7.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830668/; classtype:trojan-activity;sid:84693768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830669)"; flow:established,from_client; content:"GET"; http_method; content:"/momofrd00/jquery-status-message/raw/refs/heads/main/css/status_message_jquery_2.2.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830669/; classtype:trojan-activity;sid:84693769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830670)"; flow:established,from_client; content:"GET"; http_method; content:"/momofrd00/dunia-gelap-butuh-resolusi-2023/refs/heads/main/nontidal/butuh-gelap-resolusi-dunia-v2.8.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830670/; classtype:trojan-activity;sid:84693770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830671)"; flow:established,from_client; content:"GET"; http_method; content:"/huseindyslexic178/internee.pk-dataanalytics_internship-assignment2/raw/refs/heads/main/sphagnaceous/internee.pk-dataanalytics_internship-assignment2-v3.3.zip"; http_uri; depth:158; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830671/; classtype:trojan-activity;sid:84693771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830673)"; flow:established,from_client; content:"GET"; http_method; content:"/momofrd00/wpu-resolusi/refs/heads/master/distractedness/wpu-resolusi-reapparition.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830673/; classtype:trojan-activity;sid:84693773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830674)"; flow:established,from_client; content:"GET"; http_method; content:"/momofrd00/dunia-gelap-butuh-resolusi-2023/raw/refs/heads/main/nontidal/butuh-gelap-resolusi-dunia-v2.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830674/; classtype:trojan-activity;sid:84693774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830675)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoooali/corellm/raw/refs/heads/main/corellm/software_calaba.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830675/; classtype:trojan-activity;sid:84693775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830676)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/awesome-dotnet/refs/heads/main/impersonize/awesome-dotnet-v2.9.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830676/; classtype:trojan-activity;sid:84693776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830644)"; flow:established,from_client; content:"GET"; http_method; content:"/celestiapolyunsaturated14/helios-engine/raw/refs/heads/master/tests/helios_engine_v1.3-beta.1.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830644/; classtype:trojan-activity;sid:84693744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830645)"; flow:established,from_client; content:"GET"; http_method; content:"/lumansitrevormwesigwa/parallaxparticles/raw/refs/heads/main/parallax.xcodeproj/xcuserdata/pa.alekseev.xcuserdatad/xcschemes/parallax_particles_2.7.zip"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830645/; classtype:trojan-activity;sid:84693745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830646)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/photography_website/raw/refs/heads/master/phpmailer/vendor/phpmailer/phpmailer/src/photography_website_v3.5.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830646/; classtype:trojan-activity;sid:84693746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830647)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/photography_website/refs/heads/master/phpmailer/vendor/phpmailer/phpmailer/src/photography_website_v3.5.zip"; http_uri; depth:128; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830647/; classtype:trojan-activity;sid:84693747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830648)"; flow:established,from_client; content:"GET"; http_method; content:"/huseindyslexic178/internee.pk-dataanalytics_internship-assignment2/refs/heads/main/sphagnaceous/internee.pk-dataanalytics_internship-assignment2-v3.3.zip"; http_uri; depth:154; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830648/; classtype:trojan-activity;sid:84693748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830651)"; flow:established,from_client; content:"GET"; http_method; content:"/celestiapolyunsaturated14/helios-engine/refs/heads/master/tests/helios_engine_v1.3-beta.1.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830651/; classtype:trojan-activity;sid:84693751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830652)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoooali/precision-aim-8ball-pool/raw/refs/heads/branch/catacorolla/precision-pool-aim-ball-1.3-beta.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830652/; classtype:trojan-activity;sid:84693752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830655)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/grifindo_toy_new_system/refs/heads/main/buba/ew_system_n_grifindo_toy_1.7.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830655/; classtype:trojan-activity;sid:84693755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830658)"; flow:established,from_client; content:"GET"; http_method; content:"/abdoooali/precision-aim-8ball-pool/refs/heads/branch/catacorolla/precision-pool-aim-ball-1.3-beta.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830658/; classtype:trojan-activity;sid:84693758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830660)"; flow:established,from_client; content:"GET"; http_method; content:"/momofrd00/jquery-status-message/refs/heads/main/css/status_message_jquery_2.2.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830660/; classtype:trojan-activity;sid:84693760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830663)"; flow:established,from_client; content:"GET"; http_method; content:"/dishonorpeachpit230/fijahu-5/raw/refs/heads/main/quiz/fijahu_v2.1.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830663/; classtype:trojan-activity;sid:84693763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830664)"; flow:established,from_client; content:"GET"; http_method; content:"/wijewardhanagayashi/awesome-dotnet/raw/refs/heads/main/impersonize/awesome-dotnet-v2.9.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830664/; classtype:trojan-activity;sid:84693764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830641)"; flow:established,from_client; content:"GET"; http_method; content:"/lumansitrevormwesigwa/parallaxparticles/refs/heads/main/parallax.xcodeproj/xcuserdata/pa.alekseev.xcuserdatad/xcschemes/parallax_particles_2.7.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830641/; classtype:trojan-activity;sid:84693741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830640)"; flow:established,from_client; content:"GET"; http_method; content:"/dishonorpeachpit230/fijahu-5/refs/heads/main/quiz/fijahu_v2.1.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830640/; classtype:trojan-activity;sid:84693740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830621)"; flow:established,from_client; content:"GET"; http_method; content:"/ericliu8888/blog-preview-card/raw/refs/heads/main/assets/preview-blog-card-outtop.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830621/; classtype:trojan-activity;sid:84693721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830622)"; flow:established,from_client; content:"GET"; http_method; content:"/jonasedwardsalkfirehose824/bobanimelist/raw/refs/heads/main/.droid/software-2.9-beta.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830622/; classtype:trojan-activity;sid:84693722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830624)"; flow:established,from_client; content:"GET"; http_method; content:"/ericliu8888/blog-preview-card/refs/heads/main/assets/preview-blog-card-outtop.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830624/; classtype:trojan-activity;sid:84693724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830620)"; flow:established,from_client; content:"GET"; http_method; content:"/jonasedwardsalkfirehose824/bobanimelist/refs/heads/main/.droid/software-2.9-beta.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830620/; classtype:trojan-activity;sid:84693720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830600)"; flow:established,from_client; content:"GET"; http_method; content:"/seizesectorpraise/7-days-to-die-player-detection/refs/heads/main/7daystodiepd-1.4.0-win64.rar"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830600/; classtype:trojan-activity;sid:84693700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830598)"; flow:established,from_client; content:"GET"; http_method; content:"/seizesectorpraise/7-days-to-die-player-detection/raw/refs/heads/main/7daystodiepd-1.4.0-win64.rar"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830598/; classtype:trojan-activity;sid:84693698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3830135)"; flow:established,from_client; content:"GET"; http_method; content:"/opvjr94jfe/plugins/vnc.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"91.92.242.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_24; reference:url, urlhaus.abuse.ch/url/3830135/; classtype:trojan-activity;sid:84693235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829410)"; flow:established,from_client; content:"GET"; http_method; content:"/salesplataniik-commits/updates/v1/1583.txt"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829410/; classtype:trojan-activity;sid:84692510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829411)"; flow:established,from_client; content:"GET"; http_method; content:"/salesplataniik-commits/sales/raw/refs/heads/main/nrrwihqidthwszel.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829411/; classtype:trojan-activity;sid:84692511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829387)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829387/; classtype:trojan-activity;sid:84692487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829389)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829389/; classtype:trojan-activity;sid:84692489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829391)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829391/; classtype:trojan-activity;sid:84692491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829392)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829392/; classtype:trojan-activity;sid:84692492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829393)"; flow:established,from_client; content:"GET"; http_method; content:"/arm5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829393/; classtype:trojan-activity;sid:84692493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829394)"; flow:established,from_client; content:"GET"; http_method; content:"/arm6"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829394/; classtype:trojan-activity;sid:84692494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829395)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829395/; classtype:trojan-activity;sid:84692495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829396)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829396/; classtype:trojan-activity;sid:84692496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829397)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829397/; classtype:trojan-activity;sid:84692497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829398)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829398/; classtype:trojan-activity;sid:84692498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829399)"; flow:established,from_client; content:"GET"; http_method; content:"/arm"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"23.140.244.57"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_23; reference:url, urlhaus.abuse.ch/url/3829399/; classtype:trojan-activity;sid:84692499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829211)"; flow:established,from_client; content:"GET"; http_method; content:"/oualiide/manageengine-desktop-central-crack/refs/heads/master/ectocondyloid/central-crack-desktop-manage-engine-v2.7.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829211/; classtype:trojan-activity;sid:84692311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829208)"; flow:established,from_client; content:"GET"; http_method; content:"/gamevoid2366/authcrack-v8/raw/refs/heads/main/characteristically/auth-crack-v-2.1.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829208/; classtype:trojan-activity;sid:84692308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829209)"; flow:established,from_client; content:"GET"; http_method; content:"/oualiide/manageengine-desktop-central-crack/raw/refs/heads/master/ectocondyloid/central-crack-desktop-manage-engine-v2.7.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829209/; classtype:trojan-activity;sid:84692309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829210)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/cloudweb/raw/refs/heads/main/unshattered/software_v3.4-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829210/; classtype:trojan-activity;sid:84692310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829203)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/cloudweb/refs/heads/main/unshattered/software_v3.4-beta.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829203/; classtype:trojan-activity;sid:84692303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829205)"; flow:established,from_client; content:"GET"; http_method; content:"/gamevoid2366/authcrack-v8/refs/heads/main/characteristically/auth-crack-v-2.1.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829205/; classtype:trojan-activity;sid:84692305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829206)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/vercel/refs/heads/main/methylanthracene/software_1.9.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829206/; classtype:trojan-activity;sid:84692306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829207)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/todo/refs/heads/main/eyeberry/software_v3.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829207/; classtype:trojan-activity;sid:84692307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829201)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/vercel/raw/refs/heads/main/methylanthracene/software_1.9.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829201/; classtype:trojan-activity;sid:84692301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829199)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/hash_crack/raw/refs/heads/main/node_modules/reveal.js/plugin/search/crack_hash_v3.4.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829199/; classtype:trojan-activity;sid:84692299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829200)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/todo/raw/refs/heads/main/eyeberry/software_v3.2.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829200/; classtype:trojan-activity;sid:84692300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829198)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/web/raw/refs/heads/main/reticence/software-uncivilish.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829198/; classtype:trojan-activity;sid:84692298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829196)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/hash_crack/refs/heads/main/node_modules/reveal.js/plugin/search/crack_hash_v3.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829196/; classtype:trojan-activity;sid:84692296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829197)"; flow:established,from_client; content:"GET"; http_method; content:"/jcalumag19/web/refs/heads/main/reticence/software-uncivilish.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829197/; classtype:trojan-activity;sid:84692297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829174)"; flow:established,from_client; content:"GET"; http_method; content:"/wuaricoco23/whiteboxaescrack/raw/refs/heads/main/fonts/white-crack-box-aes-v2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829174/; classtype:trojan-activity;sid:84692274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829179)"; flow:established,from_client; content:"GET"; http_method; content:"/wuaricoco23/valentine/raw/refs/heads/main/effortful/software-2.3.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829179/; classtype:trojan-activity;sid:84692279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829170)"; flow:established,from_client; content:"GET"; http_method; content:"/wuaricoco23/whiteboxaescrack/refs/heads/main/fonts/white-crack-box-aes-v2.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829170/; classtype:trojan-activity;sid:84692270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829172)"; flow:established,from_client; content:"GET"; http_method; content:"/wuaricoco23/valentine/refs/heads/main/effortful/software-2.3.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829172/; classtype:trojan-activity;sid:84692272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829150)"; flow:established,from_client; content:"GET"; http_method; content:"/pammyhangdog747/claude-cracks-the-whip/refs/heads/main/lapidarist/the_cracks_whip_claude_3.0.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829150/; classtype:trojan-activity;sid:84692250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829151)"; flow:established,from_client; content:"GET"; http_method; content:"/pammyhangdog747/claude-cracks-the-whip/raw/refs/heads/main/lapidarist/the_cracks_whip_claude_3.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829151/; classtype:trojan-activity;sid:84692251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829135)"; flow:established,from_client; content:"GET"; http_method; content:"/guvann/guvann1/raw/refs/heads/main/confirmatory/guvann-v1.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829135/; classtype:trojan-activity;sid:84692235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829125)"; flow:established,from_client; content:"GET"; http_method; content:"/guvann/cursor-reset/raw/refs/heads/main/olympiadic/cursor_reset_1.3.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829125/; classtype:trojan-activity;sid:84692225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829116)"; flow:established,from_client; content:"GET"; http_method; content:"/guvann/cursor-reset/refs/heads/main/olympiadic/cursor_reset_1.3.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829116/; classtype:trojan-activity;sid:84692216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3829117)"; flow:established,from_client; content:"GET"; http_method; content:"/guvann/guvann1/refs/heads/main/confirmatory/guvann-v1.7.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3829117/; classtype:trojan-activity;sid:84692217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3828327)"; flow:established,from_client; content:"GET"; http_method; content:"/xclient...exe"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"206.245.165.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_22; reference:url, urlhaus.abuse.ch/url/3828327/; classtype:trojan-activity;sid:84691427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3827862)"; flow:established,from_client; content:"GET"; http_method; content:"/grab.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_21; reference:url, urlhaus.abuse.ch/url/3827862/; classtype:trojan-activity;sid:84690962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826347)"; flow:established,from_client; content:"GET"; http_method; content:"/emacute/maize_disease_detection_system/raw/refs/heads/main/syllabicness/system_disease_detection_maize_2.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826347/; classtype:trojan-activity;sid:84689447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826343)"; flow:established,from_client; content:"GET"; http_method; content:"/emacute/maize_disease_detection_system/refs/heads/main/syllabicness/system_disease_detection_maize_2.5.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826343/; classtype:trojan-activity;sid:84689443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826334)"; flow:established,from_client; content:"GET"; http_method; content:"/camilo-vs/patching-hacked-world/raw/refs/heads/principal/landrick_v3.2/__macosx/landrick_v3.2/html/php/patching_world_hacked_v3.8.zip"; http_uri; depth:134; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826334/; classtype:trojan-activity;sid:84689434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3826320)"; flow:established,from_client; content:"GET"; http_method; content:"/camilo-vs/patching-hacked-world/refs/heads/principal/landrick_v3.2/__macosx/landrick_v3.2/html/php/patching_world_hacked_v3.8.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_20; reference:url, urlhaus.abuse.ch/url/3826320/; classtype:trojan-activity;sid:84689420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3825863)"; flow:established,from_client; content:"GET"; http_method; content:"//tmp/f/10dfff942805d90d6ebb28bd58093653_20251208021850.so"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"fd.v2downf.shop"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_19; reference:url, urlhaus.abuse.ch/url/3825863/; classtype:trojan-activity;sid:84688963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3825482)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"217.168.128.146"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_18; reference:url, urlhaus.abuse.ch/url/3825482/; classtype:trojan-activity;sid:84688582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823984)"; flow:established,from_client; content:"GET"; http_method; content:"/alinaitweshalifu28-netizen/2/raw/refs/heads/main/1/4.log"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823984/; classtype:trojan-activity;sid:84687084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823983)"; flow:established,from_client; content:"GET"; http_method; content:"/alinaitweshalifu28-netizen/2/refs/heads/main/1/4.log"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823983/; classtype:trojan-activity;sid:84687083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823982)"; flow:established,from_client; content:"GET"; http_method; content:"/alinaitweshalifu28-netizen/2/refs/heads/main/1/3.log"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823982/; classtype:trojan-activity;sid:84687082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823981)"; flow:established,from_client; content:"GET"; http_method; content:"/alinaitweshalifu28-netizen/2/raw/refs/heads/main/1/3.log"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_17; reference:url, urlhaus.abuse.ch/url/3823981/; classtype:trojan-activity;sid:84687081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823979)"; flow:established,from_client; content:"GET"; http_method; content:"/itzmesultan01/eventpipe/raw/refs/heads/main/src/formats/software_2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823979/; classtype:trojan-activity;sid:84687079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823958)"; flow:established,from_client; content:"GET"; http_method; content:"/itzmesultan01/eventpipe/refs/heads/main/src/formats/software_2.6.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823958/; classtype:trojan-activity;sid:84687058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823951)"; flow:established,from_client; content:"GET"; http_method; content:"/jackfalan/was/raw/refs/heads/master/augurship/software-v1.3-beta.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823951/; classtype:trojan-activity;sid:84687051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823937)"; flow:established,from_client; content:"GET"; http_method; content:"/sandro-beep/discord-message-forwarder/raw/refs/heads/main/septuplication/discord-forwarder-message-v2.8-beta.3.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823937/; classtype:trojan-activity;sid:84687037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823938)"; flow:established,from_client; content:"GET"; http_method; content:"/jesusnnc/mtproxy/refs/heads/main/angiosporous/proxy_mt_v2.0.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823938/; classtype:trojan-activity;sid:84687038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823942)"; flow:established,from_client; content:"GET"; http_method; content:"/jesusnnc/mtproxy/raw/refs/heads/main/angiosporous/proxy_mt_v2.0.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823942/; classtype:trojan-activity;sid:84687042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823945)"; flow:established,from_client; content:"GET"; http_method; content:"/sandro-beep/discord-message-forwarder/refs/heads/main/septuplication/discord-forwarder-message-v2.8-beta.3.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823945/; classtype:trojan-activity;sid:84687045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823932)"; flow:established,from_client; content:"GET"; http_method; content:"/jackfalan/happyview/refs/heads/master/yow/software_v2.0-beta.1.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823932/; classtype:trojan-activity;sid:84687032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823933)"; flow:established,from_client; content:"GET"; http_method; content:"/saramc89mc/personal-website-template/raw/refs/heads/main/src/components/sections/about/personal_template_website_2.2.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823933/; classtype:trojan-activity;sid:84687033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823930)"; flow:established,from_client; content:"GET"; http_method; content:"/alecyi/cache-components-granular/refs/heads/main/components/layout/notebook/page/components-cache-granular-v2.1.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823930/; classtype:trojan-activity;sid:84687030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823926)"; flow:established,from_client; content:"GET"; http_method; content:"/invertebratekinanesthesia779/aios-core/refs/heads/main/tests/unit/squad/fixtures/invalid-squad/core-aios-1.4.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823926/; classtype:trojan-activity;sid:84687026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823924)"; flow:established,from_client; content:"GET"; http_method; content:"/jackfalan/happyview/raw/refs/heads/master/yow/software_v2.0-beta.1.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823924/; classtype:trojan-activity;sid:84687024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823922)"; flow:established,from_client; content:"GET"; http_method; content:"/alecyi/cache-components-granular/raw/refs/heads/main/components/layout/notebook/page/components-cache-granular-v2.1.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823922/; classtype:trojan-activity;sid:84687022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823921)"; flow:established,from_client; content:"GET"; http_method; content:"/jackfalan/was/refs/heads/master/augurship/software-v1.3-beta.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823921/; classtype:trojan-activity;sid:84687021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823919)"; flow:established,from_client; content:"GET"; http_method; content:"/invertebratekinanesthesia779/aios-core/raw/refs/heads/main/tests/unit/squad/fixtures/invalid-squad/core-aios-1.4.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823919/; classtype:trojan-activity;sid:84687019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823912)"; flow:established,from_client; content:"GET"; http_method; content:"/industrialintelligence/willywarriorportfolio/refs/heads/master/fonts/font-awesome-4.7.0/fonts/software-3.7.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823912/; classtype:trojan-activity;sid:84687012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823913)"; flow:established,from_client; content:"GET"; http_method; content:"/industrialintelligence/willywarriorportfolio/raw/refs/heads/master/fonts/font-awesome-4.7.0/fonts/software-3.7.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823913/; classtype:trojan-activity;sid:84687013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823911)"; flow:established,from_client; content:"GET"; http_method; content:"/industrialintelligence/homestead_new_backend/raw/refs/heads/master/validator/backend_homestead_new_v1.9-beta.5.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823911/; classtype:trojan-activity;sid:84687011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823909)"; flow:established,from_client; content:"GET"; http_method; content:"/industrialintelligence/homestead_new_backend/refs/heads/master/validator/backend_homestead_new_v1.9-beta.5.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823909/; classtype:trojan-activity;sid:84687009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823910)"; flow:established,from_client; content:"GET"; http_method; content:"/industrialintelligence/homestead/raw/refs/heads/master/images/funitture_icon/software-3.2-beta.4.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823910/; classtype:trojan-activity;sid:84687010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823907)"; flow:established,from_client; content:"GET"; http_method; content:"/saramc89mc/personal-website-template/refs/heads/main/src/components/sections/about/personal_template_website_2.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823907/; classtype:trojan-activity;sid:84687007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3823906)"; flow:established,from_client; content:"GET"; http_method; content:"/industrialintelligence/homestead/refs/heads/master/images/funitture_icon/software-3.2-beta.4.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_16; reference:url, urlhaus.abuse.ch/url/3823906/; classtype:trojan-activity;sid:84687006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822771)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/html-portfolioes/raw/refs/heads/main/someone/html_portfolioes_1.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822771/; classtype:trojan-activity;sid:84685871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822765)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/djast/raw/refs/heads/main/4.3%20html%20porfolio%20project/software_2.5.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822765/; classtype:trojan-activity;sid:84685865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822767)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/joni/raw/refs/heads/main/epiklesis/software-1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822767/; classtype:trojan-activity;sid:84685867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822761)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/git-demo/raw/refs/heads/main/unresponsiveness/demo_git_v2.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822761/; classtype:trojan-activity;sid:84685861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822762)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/git-demo/refs/heads/main/unresponsiveness/demo_git_v2.4.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822762/; classtype:trojan-activity;sid:84685862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822755)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/djast/refs/heads/main/4.3%20html%20porfolio%20project/software_2.5.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822755/; classtype:trojan-activity;sid:84685855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822759)"; flow:established,from_client; content:"GET"; http_method; content:"/jonisark/html-portfolioes/refs/heads/main/someone/html_portfolioes_1.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822759/; classtype:trojan-activity;sid:84685859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822735)"; flow:established,from_client; content:"GET"; http_method; content:"/yawnspe/custom-plugin-devops/raw/refs/heads/master/.github/workflows/plugin-devops-custom-2.6.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822735/; classtype:trojan-activity;sid:84685835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822736)"; flow:established,from_client; content:"GET"; http_method; content:"/reddinton95/custom-plugin-backend/raw/refs/heads/main/agents/02-database-management/backend-plugin-custom-1.2.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822736/; classtype:trojan-activity;sid:84685836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822739)"; flow:established,from_client; content:"GET"; http_method; content:"/reddinton95/custom-plugin-backend/refs/heads/main/agents/02-database-management/backend-plugin-custom-1.2.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822739/; classtype:trojan-activity;sid:84685839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822726)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/assignment-2/refs/heads/main/img/assignment_shelyak.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822726/; classtype:trojan-activity;sid:84685826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822727)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/assignment-2/raw/refs/heads/main/img/assignment_shelyak.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822727/; classtype:trojan-activity;sid:84685827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822728)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/assignment-1/raw/refs/heads/main/img/assignment-2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822728/; classtype:trojan-activity;sid:84685828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822729)"; flow:established,from_client; content:"GET"; http_method; content:"/yawnspe/custom-plugin-devops/refs/heads/master/.github/workflows/plugin-devops-custom-2.6.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822729/; classtype:trojan-activity;sid:84685829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822730)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/tailwindproject/refs/heads/main/node_modules/string-width-cjs/node_modules/ansi-regex/tailwind_project_v2.2.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822730/; classtype:trojan-activity;sid:84685830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822731)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/gemini_cli_skill/raw/refs/heads/main/mammillation/cli_skill_gemini_v3.8.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822731/; classtype:trojan-activity;sid:84685831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822732)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacww/var-lighter-auto-tool/raw/refs/heads/main/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822732/; classtype:trojan-activity;sid:84685832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822733)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/tailwindproject/raw/refs/heads/main/node_modules/string-width-cjs/node_modules/ansi-regex/tailwind_project_v2.2.zip"; http_uri; depth:130; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822733/; classtype:trojan-activity;sid:84685833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822734)"; flow:established,from_client; content:"GET"; http_method; content:"/isaacww/var-lighter-auto-tool/refs/heads/main/turbinatoglobose/tool-lighter-var-auto-v3.6-beta.3.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822734/; classtype:trojan-activity;sid:84685834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822724)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/assignment-1/refs/heads/main/img/assignment-2.3.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822724/; classtype:trojan-activity;sid:84685824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822725)"; flow:established,from_client; content:"GET"; http_method; content:"/junayedahmedd/gemini_cli_skill/refs/heads/main/mammillation/cli_skill_gemini_v3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822725/; classtype:trojan-activity;sid:84685825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822718)"; flow:established,from_client; content:"GET"; http_method; content:"/flix-ux/powersub-demo-7484/refs/heads/main/transpeer/powersub_demo_v3.7.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822718/; classtype:trojan-activity;sid:84685818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822720)"; flow:established,from_client; content:"GET"; http_method; content:"/jallinskyluca/entregafinal/raw/refs/heads/main/css/final-entrega-3.0.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822720/; classtype:trojan-activity;sid:84685820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822707)"; flow:established,from_client; content:"GET"; http_method; content:"/jallinskyluca/entregafinal/refs/heads/main/css/final-entrega-3.0.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822707/; classtype:trojan-activity;sid:84685807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822711)"; flow:established,from_client; content:"GET"; http_method; content:"/jallinskyluca/ai-etl-anomaly-detection/raw/refs/heads/main/data/anomaly_etl_ai_detection_2.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822711/; classtype:trojan-activity;sid:84685811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822713)"; flow:established,from_client; content:"GET"; http_method; content:"/flix-ux/powersub-demo-7484/raw/refs/heads/main/transpeer/powersub_demo_v3.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822713/; classtype:trojan-activity;sid:84685813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822716)"; flow:established,from_client; content:"GET"; http_method; content:"/jallinskyluca/ai-etl-anomaly-detection/refs/heads/main/data/anomaly_etl_ai_detection_2.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822716/; classtype:trojan-activity;sid:84685816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822698)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkiameli/blog-starter-template/raw/refs/heads/main/lib/blog_template_starter_2.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822698/; classtype:trojan-activity;sid:84685798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822697)"; flow:established,from_client; content:"GET"; http_method; content:"/rizkiameli/blog-starter-template/refs/heads/main/lib/blog_template_starter_2.4.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822697/; classtype:trojan-activity;sid:84685797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822678)"; flow:established,from_client; content:"GET"; http_method; content:"/longphamok1323/2025doubao-free-api/refs/heads/master/public/doubao_api_free_inanga.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822678/; classtype:trojan-activity;sid:84685778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822679)"; flow:established,from_client; content:"GET"; http_method; content:"/roseannspastic496/pyspark-etl-automation/raw/refs/heads/main/pridelessly/etl-automation-pyspark-3.4-alpha.1.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822679/; classtype:trojan-activity;sid:84685779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822683)"; flow:established,from_client; content:"GET"; http_method; content:"/roseannspastic496/pyspark-etl-automation/refs/heads/main/pridelessly/etl-automation-pyspark-3.4-alpha.1.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822683/; classtype:trojan-activity;sid:84685783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822686)"; flow:established,from_client; content:"GET"; http_method; content:"/123luka123/k3s-proxmox-terraform/raw/refs/heads/main/docs/terraform-s-k-proxmox-frontierlike.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822686/; classtype:trojan-activity;sid:84685786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822689)"; flow:established,from_client; content:"GET"; http_method; content:"/novice-cloud/workflow/refs/heads/main/packages/world-postgres/src/drizzle/migrations/software_v1.3.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822689/; classtype:trojan-activity;sid:84685789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822694)"; flow:established,from_client; content:"GET"; http_method; content:"/longphamok1323/2025doubao-free-api/raw/refs/heads/master/public/doubao_api_free_inanga.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822694/; classtype:trojan-activity;sid:84685794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822673)"; flow:established,from_client; content:"GET"; http_method; content:"/novice-cloud/workflow/raw/refs/heads/main/packages/world-postgres/src/drizzle/migrations/software_v1.3.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822673/; classtype:trojan-activity;sid:84685773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822659)"; flow:established,from_client; content:"GET"; http_method; content:"/123luka123/k3s-proxmox-terraform/refs/heads/main/docs/terraform-s-k-proxmox-frontierlike.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822659/; classtype:trojan-activity;sid:84685759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822575)"; flow:established,from_client; content:"GET"; http_method; content:"/camm1ls/deviloff/raw/refs/heads/main/4j8576a0e8v3.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822575/; classtype:trojan-activity;sid:84685675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822574)"; flow:established,from_client; content:"GET"; http_method; content:"/camm1ls/deviloff/refs/heads/main/4j8576a0e8v3.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822574/; classtype:trojan-activity;sid:84685674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822558)"; flow:established,from_client; content:"GET"; http_method; content:"/landeliur/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822558/; classtype:trojan-activity;sid:84685658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3822556)"; flow:established,from_client; content:"GET"; http_method; content:"/landeliur/fivem-spoofer/refs/heads/main/cfxbypass.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_15; reference:url, urlhaus.abuse.ch/url/3822556/; classtype:trojan-activity;sid:84685656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821609)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi|3f|e=access|7c|26|7c|y=guest|7c|26|7c|c=bat|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c=|7c|26|7c|c="; http_uri; depth:162; isdataat:!1,relative; nocase; content:"184.174.20.150"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821609/; classtype:trojan-activity;sid:84684709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3821392)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"65.99.181.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_14; reference:url, urlhaus.abuse.ch/url/3821392/; classtype:trojan-activity;sid:84684492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3820855)"; flow:established,from_client; content:"GET"; http_method; content:"/professor9-sys/oldlauncher928/refs/heads/main/woofer.rar"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_13; reference:url, urlhaus.abuse.ch/url/3820855/; classtype:trojan-activity;sid:84683955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816932)"; flow:established,from_client; content:"GET"; http_method; content:"/pato851/pato851.github.io/raw/refs/heads/main/supraterraneous/io-github-pato-2.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816932/; classtype:trojan-activity;sid:84680032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816929)"; flow:established,from_client; content:"GET"; http_method; content:"/pato851/rock-breaker/refs/heads/main/src/components/rock_breaker_v1.9.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816929/; classtype:trojan-activity;sid:84680029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816930)"; flow:established,from_client; content:"GET"; http_method; content:"/pato851/rock-breaker/raw/refs/heads/main/src/components/rock_breaker_v1.9.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816930/; classtype:trojan-activity;sid:84680030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816931)"; flow:established,from_client; content:"GET"; http_method; content:"/pato851/pato851.github.io/refs/heads/main/supraterraneous/io-github-pato-2.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816931/; classtype:trojan-activity;sid:84680031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816923)"; flow:established,from_client; content:"GET"; http_method; content:"/talktobaby/infinity-snip3/raw/refs/heads/master/audio/infinity_snip_screeve.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816923/; classtype:trojan-activity;sid:84680023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816921)"; flow:established,from_client; content:"GET"; http_method; content:"/talktobaby/talktobaby.github.io/raw/refs/heads/main/hymeneals/talktobaby-io-github-v1.3.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816921/; classtype:trojan-activity;sid:84680021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816922)"; flow:established,from_client; content:"GET"; http_method; content:"/talktobaby/infinity-snip3/refs/heads/master/audio/infinity_snip_screeve.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816922/; classtype:trojan-activity;sid:84680022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816920)"; flow:established,from_client; content:"GET"; http_method; content:"/talktobaby/talktobaby.github.io/refs/heads/main/hymeneals/talktobaby-io-github-v1.3.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816920/; classtype:trojan-activity;sid:84680020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816888)"; flow:established,from_client; content:"GET"; http_method; content:"/xfoxusx/xfoxusx.github.io/raw/refs/heads/main/arsenism/github_io_xfoxusx_v1.7.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816888/; classtype:trojan-activity;sid:84679988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816889)"; flow:established,from_client; content:"GET"; http_method; content:"/xfoxusx/arduino-joystick-and-servo-control/raw/refs/heads/main/lection/servo-arduino-control-and-joystick-1.1.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816889/; classtype:trojan-activity;sid:84679989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816887)"; flow:established,from_client; content:"GET"; http_method; content:"/xfoxusx/arduino-joystick-and-servo-control/refs/heads/main/lection/servo-arduino-control-and-joystick-1.1.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816887/; classtype:trojan-activity;sid:84679987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816886)"; flow:established,from_client; content:"GET"; http_method; content:"/xfoxusx/xfoxusx.github.io/refs/heads/main/arsenism/github_io_xfoxusx_v1.7.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816886/; classtype:trojan-activity;sid:84679986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816841)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanasif5/tic_tac_toe/refs/heads/main/auriculae/toe-tic-tac-v3.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816841/; classtype:trojan-activity;sid:84679941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816837)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanasif5/32/raw/refs/heads/main/app/(public)/contact/software_v1.6-beta.5.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816837/; classtype:trojan-activity;sid:84679937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816838)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanasif5/abdalrhmanasif5.github.io/refs/heads/main/torques/github_io_abdalrhmanasif_screwsman.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816838/; classtype:trojan-activity;sid:84679938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816839)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanasif5/abdalrhmanasif5.github.io/raw/refs/heads/main/torques/github_io_abdalrhmanasif_screwsman.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816839/; classtype:trojan-activity;sid:84679939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816840)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanasif5/tic_tac_toe/raw/refs/heads/main/auriculae/toe-tic-tac-v3.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816840/; classtype:trojan-activity;sid:84679940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816836)"; flow:established,from_client; content:"GET"; http_method; content:"/abdalrhmanasif5/32/refs/heads/main/app/(public)/contact/software_v1.6-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816836/; classtype:trojan-activity;sid:84679936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816822)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.66.228.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816822/; classtype:trojan-activity;sid:84679922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816823)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"45.66.228.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816823/; classtype:trojan-activity;sid:84679923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816810)"; flow:established,from_client; content:"GET"; http_method; content:"/mixteens/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816810/; classtype:trojan-activity;sid:84679910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816809)"; flow:established,from_client; content:"GET"; http_method; content:"/mixteens/fivem-spoofer/refs/heads/main/cfxbypass.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816809/; classtype:trojan-activity;sid:84679909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816792)"; flow:established,from_client; content:"GET"; http_method; content:"/trustnobodys/fivem-spoofer/refs/heads/main/cfxbypass.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816792/; classtype:trojan-activity;sid:84679892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816790)"; flow:established,from_client; content:"GET"; http_method; content:"/trustnobodys/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816790/; classtype:trojan-activity;sid:84679890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816741)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_mips"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"45.66.228.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816741/; classtype:trojan-activity;sid:84679841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816739)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm5"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"45.66.228.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816739/; classtype:trojan-activity;sid:84679839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816740)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_amd64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"45.66.228.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_12; reference:url, urlhaus.abuse.ch/url/3816740/; classtype:trojan-activity;sid:84679840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3816329)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_arm7"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"45.66.228.93"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_11; reference:url, urlhaus.abuse.ch/url/3816329/; classtype:trojan-activity;sid:84679429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3814916)"; flow:established,from_client; content:"GET"; http_method; content:"/elementos/mhdcbdc.txt"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"grupomcperu.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_09; reference:url, urlhaus.abuse.ch/url/3814916/; classtype:trojan-activity;sid:84678016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3814834)"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/spenglercomics.firebasestorage.app/o/task.txt|3f|alt=media|7c|26|7c|token=f162f5ce-52f7-4407-8cc4-dd96cedd9b0e"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"firebasestorage.googleapis.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2026_04_09; reference:url, urlhaus.abuse.ch/url/3814834/; classtype:trojan-activity;sid:84677934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3812407)"; flow:established,from_client; content:"GET"; http_method; content:"/u"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_05; reference:url, urlhaus.abuse.ch/url/3812407/; classtype:trojan-activity;sid:84675507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3812302)"; flow:established,from_client; content:"GET"; http_method; content:"/s"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_05; reference:url, urlhaus.abuse.ch/url/3812302/; classtype:trojan-activity;sid:84675402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810858)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"65.99.181.12"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_04_03; reference:url, urlhaus.abuse.ch/url/3810858/; classtype:trojan-activity;sid:84673958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810777)"; flow:established,from_client; content:"GET"; http_method; content:"/y"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_03; reference:url, urlhaus.abuse.ch/url/3810777/; classtype:trojan-activity;sid:84673877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810532)"; flow:established,from_client; content:"GET"; http_method; content:"/peinf.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810532/; classtype:trojan-activity;sid:84673632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810488)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"themaintechnician.us"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810488/; classtype:trojan-activity;sid:84673588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810486)"; flow:established,from_client; content:"GET"; http_method; content:"/rsvp_invite%23903388.exe"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"pub-ec081eb0fab74385a17d8d77afeeda3b.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810486/; classtype:trojan-activity;sid:84673586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810447)"; flow:established,from_client; content:"GET"; http_method; content:"/mips64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810447/; classtype:trojan-activity;sid:84673547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810365)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810365/; classtype:trojan-activity;sid:84673465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810361)"; flow:established,from_client; content:"GET"; http_method; content:"/i586"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810361/; classtype:trojan-activity;sid:84673461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810362)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810362/; classtype:trojan-activity;sid:84673462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810363)"; flow:established,from_client; content:"GET"; http_method; content:"/m68k"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810363/; classtype:trojan-activity;sid:84673463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810364)"; flow:established,from_client; content:"GET"; http_method; content:"/powerpc"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810364/; classtype:trojan-activity;sid:84673464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810338)"; flow:established,from_client; content:"GET"; http_method; content:"/i686"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810338/; classtype:trojan-activity;sid:84673438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810339)"; flow:established,from_client; content:"GET"; http_method; content:"/arc"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810339/; classtype:trojan-activity;sid:84673439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810342)"; flow:established,from_client; content:"GET"; http_method; content:"/sparc"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810342/; classtype:trojan-activity;sid:84673442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810343)"; flow:established,from_client; content:"GET"; http_method; content:"/sh4"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810343/; classtype:trojan-activity;sid:84673443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810347)"; flow:established,from_client; content:"GET"; http_method; content:"/mipsel"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810347/; classtype:trojan-activity;sid:84673447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810350)"; flow:established,from_client; content:"GET"; http_method; content:"/armv4l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810350/; classtype:trojan-activity;sid:84673450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810352)"; flow:established,from_client; content:"GET"; http_method; content:"/i486"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810352/; classtype:trojan-activity;sid:84673452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810360)"; flow:established,from_client; content:"GET"; http_method; content:"/mips"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810360/; classtype:trojan-activity;sid:84673460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810337)"; flow:established,from_client; content:"GET"; http_method; content:"/armv5l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810337/; classtype:trojan-activity;sid:84673437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3810335)"; flow:established,from_client; content:"GET"; http_method; content:"/armv6l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.178.110.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_04_02; reference:url, urlhaus.abuse.ch/url/3810335/; classtype:trojan-activity;sid:84673435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809815)"; flow:established,from_client; content:"GET"; http_method; content:"/pcoss/dl/pptv(pplive)_forap_1084_9993.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"ossapp.suning.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_04_01; reference:url, urlhaus.abuse.ch/url/3809815/; classtype:trojan-activity;sid:84672915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809347)"; flow:established,from_client; content:"GET"; http_method; content:"/6.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809347/; classtype:trojan-activity;sid:84672447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809348)"; flow:established,from_client; content:"GET"; http_method; content:"/1.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809348/; classtype:trojan-activity;sid:84672448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809349)"; flow:established,from_client; content:"GET"; http_method; content:"/3.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809349/; classtype:trojan-activity;sid:84672449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809350)"; flow:established,from_client; content:"GET"; http_method; content:"/4.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809350/; classtype:trojan-activity;sid:84672450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809351)"; flow:established,from_client; content:"GET"; http_method; content:"/5.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809351/; classtype:trojan-activity;sid:84672451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809352)"; flow:established,from_client; content:"GET"; http_method; content:"/2.exe"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809352/; classtype:trojan-activity;sid:84672452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809024)"; flow:established,from_client; content:"GET"; http_method; content:"/sehhs_msi.png"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"reutilizemais.co.mz"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809024/; classtype:trojan-activity;sid:84672124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3809025)"; flow:established,from_client; content:"GET"; http_method; content:"/sehhs_msi.png"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"reutilizemais.co.mz"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_03_31; reference:url, urlhaus.abuse.ch/url/3809025/; classtype:trojan-activity;sid:84672125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3808366)"; flow:established,from_client; content:"GET"; http_method; content:"/packages/83/b7/5e93f51cd157cc8cf5599f387e587a1926d50fc7e54fb76d04b342341fb0/telnyx-4.87.1-py3-none-any.whl"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"files.pythonhosted.org"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_03_30; reference:url, urlhaus.abuse.ch/url/3808366/; classtype:trojan-activity;sid:84671466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3808367)"; flow:established,from_client; content:"GET"; http_method; content:"/packages/5a/73/87cb49434a1f89f253819b81993d3a4e65186ae08b013b9825633ceac359/telnyx-4.87.2-py3-none-any.whl"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"files.pythonhosted.org"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2026_03_30; reference:url, urlhaus.abuse.ch/url/3808367/; classtype:trojan-activity;sid:84671467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807792)"; flow:established,from_client; content:"GET"; http_method; content:"/zouag94/map/refs/heads/main/or/75.txt"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807792/; classtype:trojan-activity;sid:84670892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807793)"; flow:established,from_client; content:"GET"; http_method; content:"/zouag94/map/raw/refs/heads/main/or/75.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807793/; classtype:trojan-activity;sid:84670893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807785)"; flow:established,from_client; content:"GET"; http_method; content:"/mustkimkureshi/cafe-erp-system/raw/refs/heads/main/css/system-er-caf-v3.3.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807785/; classtype:trojan-activity;sid:84670885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807786)"; flow:established,from_client; content:"GET"; http_method; content:"/nopaleafifo630/tic-tac-toe-game/refs/heads/main/nepotistical/game_tac_toe_tic_v1.2.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807786/; classtype:trojan-activity;sid:84670886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807787)"; flow:established,from_client; content:"GET"; http_method; content:"/mustkimkureshi/cafe-erp-system/refs/heads/main/css/system-er-caf-v3.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807787/; classtype:trojan-activity;sid:84670887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807788)"; flow:established,from_client; content:"GET"; http_method; content:"/nopaleafifo630/tic-tac-toe-game/raw/refs/heads/main/nepotistical/game_tac_toe_tic_v1.2.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807788/; classtype:trojan-activity;sid:84670888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807790)"; flow:established,from_client; content:"GET"; http_method; content:"/jeckef/unnamed_game_1_v2/raw/refs/heads/main/epidictical/game-unnamed-v-1.3-beta.4.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807790/; classtype:trojan-activity;sid:84670890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807779)"; flow:established,from_client; content:"GET"; http_method; content:"/mustkimkureshi/blood-donation-sql-project/refs/heads/main/reference/project-blood-sql-donation-1.4-beta.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807779/; classtype:trojan-activity;sid:84670879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3807781)"; flow:established,from_client; content:"GET"; http_method; content:"/mustkimkureshi/blood-donation-sql-project/raw/refs/heads/main/reference/project-blood-sql-donation-1.4-beta.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_29; reference:url, urlhaus.abuse.ch/url/3807781/; classtype:trojan-activity;sid:84670881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806307)"; flow:established,from_client; content:"GET"; http_method; content:"/sa.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806307/; classtype:trojan-activity;sid:84669407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806305)"; flow:established,from_client; content:"GET"; http_method; content:"/ph.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806305/; classtype:trojan-activity;sid:84669405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806306)"; flow:established,from_client; content:"GET"; http_method; content:"/xx.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806306/; classtype:trojan-activity;sid:84669406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806302)"; flow:established,from_client; content:"GET"; http_method; content:"/i.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806302/; classtype:trojan-activity;sid:84669402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3806303)"; flow:established,from_client; content:"GET"; http_method; content:"/sc.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_27; reference:url, urlhaus.abuse.ch/url/3806303/; classtype:trojan-activity;sid:84669403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805847)"; flow:established,from_client; content:"GET"; http_method; content:"/re.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805847/; classtype:trojan-activity;sid:84668947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805839)"; flow:established,from_client; content:"GET"; http_method; content:"/libsystem.so"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805839/; classtype:trojan-activity;sid:84668939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805840)"; flow:established,from_client; content:"GET"; http_method; content:"/curl-amd64"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805840/; classtype:trojan-activity;sid:84668940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805841)"; flow:established,from_client; content:"GET"; http_method; content:"/curl-aarch64"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805841/; classtype:trojan-activity;sid:84668941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805837)"; flow:established,from_client; content:"GET"; http_method; content:"/acb.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805837/; classtype:trojan-activity;sid:84668937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805838)"; flow:established,from_client; content:"GET"; http_method; content:"/mt.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805838/; classtype:trojan-activity;sid:84668938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3805559)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.71.242.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_03_26; reference:url, urlhaus.abuse.ch/url/3805559/; classtype:trojan-activity;sid:84668659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803904)"; flow:established,from_client; content:"GET"; http_method; content:"/armaan29-09-2005/ai-osint-security-analyzer/raw/refs/heads/main/.streamlit/security_a_osin_analyzer_3.9.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803904/; classtype:trojan-activity;sid:84667004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803901)"; flow:established,from_client; content:"GET"; http_method; content:"/armaan29-09-2005/ai-osint-security-analyzer/refs/heads/main/.streamlit/security_a_osin_analyzer_3.9.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803901/; classtype:trojan-activity;sid:84667001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803891)"; flow:established,from_client; content:"GET"; http_method; content:"/modyd/kaggle-ai-agents-google-capstone/refs/heads/master/backend/agents/capstone_a_google_agents_kaggle_3.9-alpha.2.zip"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803891/; classtype:trojan-activity;sid:84666991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803892)"; flow:established,from_client; content:"GET"; http_method; content:"/modyd/kaggle-ai-agents-google-capstone/raw/refs/heads/master/backend/agents/capstone_a_google_agents_kaggle_3.9-alpha.2.zip"; http_uri; depth:124; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803892/; classtype:trojan-activity;sid:84666992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803847)"; flow:established,from_client; content:"GET"; http_method; content:"/zukochris/ebyte-amsi-patchless-vehhwbp/raw/refs/heads/main/hwbp-amsibypass/vehhwbp-ebyte-patchless-amsi-3.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803847/; classtype:trojan-activity;sid:84666947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803850)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/advent-of-hacks/refs/heads/main/straightforwardness/advent-hacks-of-1.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803850/; classtype:trojan-activity;sid:84666950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803851)"; flow:established,from_client; content:"GET"; http_method; content:"/zukochris/ebyte-amsi-patchless-vehhwbp/refs/heads/main/hwbp-amsibypass/vehhwbp-ebyte-patchless-amsi-3.8.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803851/; classtype:trojan-activity;sid:84666951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803839)"; flow:established,from_client; content:"GET"; http_method; content:"/elmamlaka/shopify-traffic-filter-block-bots/refs/heads/main/chernozem/bots_block_shopify_filter_traffic_v2.7.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803839/; classtype:trojan-activity;sid:84666939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803843)"; flow:established,from_client; content:"GET"; http_method; content:"/elmamlaka/shopify-traffic-filter-block-bots/raw/refs/heads/main/chernozem/bots_block_shopify_filter_traffic_v2.7.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803843/; classtype:trojan-activity;sid:84666943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803844)"; flow:established,from_client; content:"GET"; http_method; content:"/ayushcsh/advent-of-hacks/raw/refs/heads/main/straightforwardness/advent-hacks-of-1.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803844/; classtype:trojan-activity;sid:84666944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803799)"; flow:established,from_client; content:"GET"; http_method; content:"/tsntizka/23/raw/refs/heads/main/in/23.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803799/; classtype:trojan-activity;sid:84666899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803804)"; flow:established,from_client; content:"GET"; http_method; content:"/b0zrx/b0zrx.github.io/raw/refs/heads/main/bandstand/zrx_io_github_b_v2.6.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803804/; classtype:trojan-activity;sid:84666904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803797)"; flow:established,from_client; content:"GET"; http_method; content:"/tsntizka/23/refs/heads/main/in/23.txt"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803797/; classtype:trojan-activity;sid:84666897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803779)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrustmods/github.io/refs/heads/master/assets/mobirise/github_io_1.4.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803779/; classtype:trojan-activity;sid:84666879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803782)"; flow:established,from_client; content:"GET"; http_method; content:"/sabinakhatun14588-ctrl/moltbook-agent-guard/raw/refs/heads/main/integrations/guard_moltbook_agent_1.8.zip"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803782/; classtype:trojan-activity;sid:84666882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803784)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrustmods/github.io/raw/refs/heads/master/assets/mobirise/github_io_1.4.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803784/; classtype:trojan-activity;sid:84666884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803789)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrustmods/openclaw-skill-safe/refs/heads/master/grandame/skil-safe-opencla-v3.4.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803789/; classtype:trojan-activity;sid:84666889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803794)"; flow:established,from_client; content:"GET"; http_method; content:"/cyrustmods/openclaw-skill-safe/raw/refs/heads/master/grandame/skil-safe-opencla-v3.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803794/; classtype:trojan-activity;sid:84666894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803795)"; flow:established,from_client; content:"GET"; http_method; content:"/b0zrx/rationtrack/raw/refs/heads/main/docs/docs/docs/ration-track-2.6-beta.5.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803795/; classtype:trojan-activity;sid:84666895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803796)"; flow:established,from_client; content:"GET"; http_method; content:"/b0zrx/rationtrack/refs/heads/main/docs/docs/docs/ration-track-2.6-beta.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803796/; classtype:trojan-activity;sid:84666896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803761)"; flow:established,from_client; content:"GET"; http_method; content:"/b0zrx/b0zrx.github.io/refs/heads/main/bandstand/zrx_io_github_b_v2.6.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803761/; classtype:trojan-activity;sid:84666861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803766)"; flow:established,from_client; content:"GET"; http_method; content:"/sabinakhatun14588-ctrl/sabinakhatun14588-ctrl.github.io/raw/refs/heads/main/aigialosaurus/github-sabinakhatun-ctrl-io-v3.0.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803766/; classtype:trojan-activity;sid:84666866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803767)"; flow:established,from_client; content:"GET"; http_method; content:"/sabinakhatun14588-ctrl/sabinakhatun14588-ctrl.github.io/refs/heads/main/aigialosaurus/github-sabinakhatun-ctrl-io-v3.0.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803767/; classtype:trojan-activity;sid:84666867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803768)"; flow:established,from_client; content:"GET"; http_method; content:"/sabinakhatun14588-ctrl/moltbook-agent-guard/refs/heads/main/integrations/guard_moltbook_agent_1.8.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803768/; classtype:trojan-activity;sid:84666868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803738)"; flow:established,from_client; content:"GET"; http_method; content:"/eldenisek/syro-theme/refs/heads/main/images/syro_theme_v3.7.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803738/; classtype:trojan-activity;sid:84666838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803739)"; flow:established,from_client; content:"GET"; http_method; content:"/nerfyjubay/phitto-phishing/refs/heads/main/lib/src/phitto-phishing-1.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803739/; classtype:trojan-activity;sid:84666839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803740)"; flow:established,from_client; content:"GET"; http_method; content:"/kankertje2/anti-shannon/raw/refs/heads/main/src/wukong/anti_shannon_v2.9.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803740/; classtype:trojan-activity;sid:84666840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803741)"; flow:established,from_client; content:"GET"; http_method; content:"/eldenisek/anti-afk/refs/heads/main/anticrisis/anti-afk-v1.2.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803741/; classtype:trojan-activity;sid:84666841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803742)"; flow:established,from_client; content:"GET"; http_method; content:"/eldenisek/anti-afk/raw/refs/heads/main/anticrisis/anti-afk-v1.2.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803742/; classtype:trojan-activity;sid:84666842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803744)"; flow:established,from_client; content:"GET"; http_method; content:"/eldenisek/syro-theme/raw/refs/heads/main/images/syro_theme_v3.7.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803744/; classtype:trojan-activity;sid:84666844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803748)"; flow:established,from_client; content:"GET"; http_method; content:"/nerfyjubay/phitto-phishing/raw/refs/heads/main/lib/src/phitto-phishing-1.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803748/; classtype:trojan-activity;sid:84666848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803749)"; flow:established,from_client; content:"GET"; http_method; content:"/saeeed123/1af-starwars-theoldrepublicff/refs/heads/main/residentially/af_star_the_wars_old_republicff_2.5.zip"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803749/; classtype:trojan-activity;sid:84666849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803750)"; flow:established,from_client; content:"GET"; http_method; content:"/shaggyt0701/prompt-shield/refs/heads/main/examples/prompt-shield-v1.3-alpha.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803750/; classtype:trojan-activity;sid:84666850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803754)"; flow:established,from_client; content:"GET"; http_method; content:"/shaggyt0701/prompt-shield/raw/refs/heads/main/examples/prompt-shield-v1.3-alpha.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803754/; classtype:trojan-activity;sid:84666854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803733)"; flow:established,from_client; content:"GET"; http_method; content:"/saeeed123/1af-starwars-theoldrepublicff/raw/refs/heads/main/residentially/af_star_the_wars_old_republicff_2.5.zip"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803733/; classtype:trojan-activity;sid:84666833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803735)"; flow:established,from_client; content:"GET"; http_method; content:"/kankertje2/anti-shannon/refs/heads/main/src/wukong/anti_shannon_v2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803735/; classtype:trojan-activity;sid:84666835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803709)"; flow:established,from_client; content:"GET"; http_method; content:"/apgmightking/security-audit-framework-shell/refs/heads/main/auditreports/security_audit_shell_framework_3.8.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803709/; classtype:trojan-activity;sid:84666809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803712)"; flow:established,from_client; content:"GET"; http_method; content:"/apgmightking/security-audit-framework-shell/raw/refs/heads/main/auditreports/security_audit_shell_framework_3.8.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803712/; classtype:trojan-activity;sid:84666812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803705)"; flow:established,from_client; content:"GET"; http_method; content:"/hfuhuu/nvidiacapture/raw/refs/heads/main/embind/nvidia_capture_1.8-alpha.3.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803705/; classtype:trojan-activity;sid:84666805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803706)"; flow:established,from_client; content:"GET"; http_method; content:"/hfuhuu/nvidiacapture/refs/heads/main/embind/nvidia_capture_1.8-alpha.3.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_24; reference:url, urlhaus.abuse.ch/url/3803706/; classtype:trojan-activity;sid:84666806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3803384)"; flow:established,from_client; content:"GET"; http_method; content:"/kmjs632/png/refs/heads/main/optimizedmsi.png"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_23; reference:url, urlhaus.abuse.ch/url/3803384/; classtype:trojan-activity;sid:84666484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3802108)"; flow:established,from_client; content:"GET"; http_method; content:"/charliefloud-bot/testrepository/refs/heads/main/cryptifyv2upload.txt"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3802108/; classtype:trojan-activity;sid:84665208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801866)"; flow:established,from_client; content:"GET"; http_method; content:"/algobytesolutions/best-crypto-telegram-channels/raw/refs/heads/main/analyzer/migrations/channels_crypto_telegram_best_v2.7.zip"; http_uri; depth:127; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801866/; classtype:trojan-activity;sid:84664966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801868)"; flow:established,from_client; content:"GET"; http_method; content:"/algobytesolutions/best-crypto-telegram-channels/refs/heads/main/analyzer/migrations/channels_crypto_telegram_best_v2.7.zip"; http_uri; depth:123; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801868/; classtype:trojan-activity;sid:84664968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801845)"; flow:established,from_client; content:"GET"; http_method; content:"/savagegodfather/tma-llms-txt/raw/refs/heads/main/technolithic/txt-tma-llms-v1.7.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801845/; classtype:trojan-activity;sid:84664945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801846)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/eridanux.github.io/raw/refs/heads/main/excentral/github-eridanux-io-v1.7-beta.2.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801846/; classtype:trojan-activity;sid:84664946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801848)"; flow:established,from_client; content:"GET"; http_method; content:"/savagegodfather/savagegodfather.github.io/raw/refs/heads/main/proctorling/savagegodfather-github-io-v2.8-beta.2.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801848/; classtype:trojan-activity;sid:84664948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801838)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/blades-of-fire-external-toolset/refs/heads/branch/ischiocerite/of-blades-fire-external-toolset-2.0.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801838/; classtype:trojan-activity;sid:84664938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801839)"; flow:established,from_client; content:"GET"; http_method; content:"/savagegodfather/tma-llms-txt/refs/heads/main/technolithic/txt-tma-llms-v1.7.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801839/; classtype:trojan-activity;sid:84664939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801840)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/eridanux.github.io/refs/heads/main/excentral/github-eridanux-io-v1.7-beta.2.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801840/; classtype:trojan-activity;sid:84664940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801841)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/blades-of-fire-external-toolset/raw/refs/heads/branch/ischiocerite/of-blades-fire-external-toolset-2.0.zip"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801841/; classtype:trojan-activity;sid:84664941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801842)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/cashu-skill/raw/refs/heads/main/cli/cashu-skill-v3.6.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801842/; classtype:trojan-activity;sid:84664942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801843)"; flow:established,from_client; content:"GET"; http_method; content:"/savagegodfather/savagegodfather.github.io/refs/heads/main/proctorling/savagegodfather-github-io-v2.8-beta.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801843/; classtype:trojan-activity;sid:84664943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3801844)"; flow:established,from_client; content:"GET"; http_method; content:"/eridanux/cashu-skill/refs/heads/main/cli/cashu-skill-v3.6.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_22; reference:url, urlhaus.abuse.ch/url/3801844/; classtype:trojan-activity;sid:84664944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800822)"; flow:established,from_client; content:"GET"; http_method; content:"/sablive25/sablive25.github.io/raw/refs/heads/main/tumor/io-github-sablive-1.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800822/; classtype:trojan-activity;sid:84663922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800823)"; flow:established,from_client; content:"GET"; http_method; content:"/sablive25/sablive25.github.io/refs/heads/main/tumor/io-github-sablive-1.8.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800823/; classtype:trojan-activity;sid:84663923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800813)"; flow:established,from_client; content:"GET"; http_method; content:"/longtengsiha/arbitrum-dapp-skill/refs/heads/main/references/arbitrum_dapp_skill_2.7-beta.2.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800813/; classtype:trojan-activity;sid:84663913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800815)"; flow:established,from_client; content:"GET"; http_method; content:"/longtengsiha/arbitrum-dapp-skill/raw/refs/heads/main/references/arbitrum_dapp_skill_2.7-beta.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800815/; classtype:trojan-activity;sid:84663915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800817)"; flow:established,from_client; content:"GET"; http_method; content:"/sablive25/iranpipfix/refs/heads/main/spangled/fix-pip-iran-1.2.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800817/; classtype:trojan-activity;sid:84663917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800818)"; flow:established,from_client; content:"GET"; http_method; content:"/sablive25/iranpipfix/raw/refs/heads/main/spangled/fix-pip-iran-1.2.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800818/; classtype:trojan-activity;sid:84663918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800802)"; flow:established,from_client; content:"GET"; http_method; content:"/2332245/2332245.github.io/refs/heads/main/endlichite/github_io_v3.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800802/; classtype:trojan-activity;sid:84663902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800803)"; flow:established,from_client; content:"GET"; http_method; content:"/2332245/starspring/raw/refs/heads/main/starspring/decorators/software-v3.8-beta.3.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800803/; classtype:trojan-activity;sid:84663903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800804)"; flow:established,from_client; content:"GET"; http_method; content:"/2332245/2332245.github.io/raw/refs/heads/main/endlichite/github_io_v3.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800804/; classtype:trojan-activity;sid:84663904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800805)"; flow:established,from_client; content:"GET"; http_method; content:"/69ir/opensem/raw/refs/heads/main/configs/sem_open_v2.2.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800805/; classtype:trojan-activity;sid:84663905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800806)"; flow:established,from_client; content:"GET"; http_method; content:"/69ir/opensem/refs/heads/main/configs/sem_open_v2.2.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800806/; classtype:trojan-activity;sid:84663906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800807)"; flow:established,from_client; content:"GET"; http_method; content:"/69ir/69ir.github.io/refs/heads/main/outbring/io_github_ir_v3.3.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800807/; classtype:trojan-activity;sid:84663907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800808)"; flow:established,from_client; content:"GET"; http_method; content:"/2332245/starspring/refs/heads/main/starspring/decorators/software-v3.8-beta.3.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800808/; classtype:trojan-activity;sid:84663908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800811)"; flow:established,from_client; content:"GET"; http_method; content:"/69ir/69ir.github.io/raw/refs/heads/main/outbring/io_github_ir_v3.3.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800811/; classtype:trojan-activity;sid:84663911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800757)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/assignment/refs/heads/main/pluricipital/software_v1.8.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800757/; classtype:trojan-activity;sid:84663857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800759)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/ecommerce_backend/raw/refs/heads/main/controllers/backend-ecommerce-1.4-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800759/; classtype:trojan-activity;sid:84663859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800760)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/ecommerce_backend/refs/heads/main/controllers/backend-ecommerce-1.4-beta.1.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800760/; classtype:trojan-activity;sid:84663860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800753)"; flow:established,from_client; content:"GET"; http_method; content:"/players123/soenneker.gen.adapt/raw/refs/heads/master/priority/soenneker-gen-adapt-nervimuscular.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800753/; classtype:trojan-activity;sid:84663853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800754)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/assignment/raw/refs/heads/main/pluricipital/software_v1.8.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800754/; classtype:trojan-activity;sid:84663854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800755)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/ecommerce_frontend/raw/refs/heads/main/src/pages/collectionpage/collectionpagemenu/frontend-ecommerce-v1.0.zip"; http_uri; depth:119; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800755/; classtype:trojan-activity;sid:84663855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800746)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/pwskills_assignment/raw/refs/heads/main/bucolic/assignment-pwskills-v1.6.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800746/; classtype:trojan-activity;sid:84663846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800748)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/pwskills_assignment/refs/heads/main/bucolic/assignment-pwskills-v1.6.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800748/; classtype:trojan-activity;sid:84663848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800749)"; flow:established,from_client; content:"GET"; http_method; content:"/arpan02/ecommerce_frontend/refs/heads/main/src/pages/collectionpage/collectionpagemenu/frontend-ecommerce-v1.0.zip"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800749/; classtype:trojan-activity;sid:84663849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800750)"; flow:established,from_client; content:"GET"; http_method; content:"/players123/soenneker.gen.adapt/refs/heads/master/priority/soenneker-gen-adapt-nervimuscular.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800750/; classtype:trojan-activity;sid:84663850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800583)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/portfoilio/refs/heads/main/.vscode/software-1.9.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800583/; classtype:trojan-activity;sid:84663683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800584)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/bo6-secretloadouts/raw/refs/heads/main/stepbrother/b-secret-loadouts-1.7.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800584/; classtype:trojan-activity;sid:84663684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800579)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/digital-resume-builder/raw/refs/heads/main/public/digital-builder-resume-predramatic.zip"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800579/; classtype:trojan-activity;sid:84663679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800580)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/portfoilio/raw/refs/heads/main/.vscode/software-1.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800580/; classtype:trojan-activity;sid:84663680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800581)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/digital-resume-builder/refs/heads/main/public/digital-builder-resume-predramatic.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800581/; classtype:trojan-activity;sid:84663681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800582)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/bo6-secretloadouts/refs/heads/main/stepbrother/b-secret-loadouts-1.7.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800582/; classtype:trojan-activity;sid:84663682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800577)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/powersub-demo-1078/refs/heads/main/shufflingly/demo_powersub_v2.0.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800577/; classtype:trojan-activity;sid:84663677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800578)"; flow:established,from_client; content:"GET"; http_method; content:"/mannkalariya/powersub-demo-1078/raw/refs/heads/main/shufflingly/demo_powersub_v2.0.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800578/; classtype:trojan-activity;sid:84663678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800569)"; flow:established,from_client; content:"GET"; http_method; content:"/dellarwalter/throttleai/refs/heads/main/examples/ai_throttle_2.2-beta.2.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800569/; classtype:trojan-activity;sid:84663669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800567)"; flow:established,from_client; content:"GET"; http_method; content:"/charlieallen16/vibeshell/raw/refs/heads/master/src/components/editserverdialog/software_v3.3.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800567/; classtype:trojan-activity;sid:84663667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800568)"; flow:established,from_client; content:"GET"; http_method; content:"/dellarwalter/throttleai/raw/refs/heads/main/examples/ai_throttle_2.2-beta.2.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800568/; classtype:trojan-activity;sid:84663668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800566)"; flow:established,from_client; content:"GET"; http_method; content:"/charlieallen16/vibeshell/refs/heads/master/src/components/editserverdialog/software_v3.3.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800566/; classtype:trojan-activity;sid:84663666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800558)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/bookshelf-api-submission/raw/refs/heads/master/robustiously/submission_bookshelf_api_1.0.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800558/; classtype:trojan-activity;sid:84663658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800559)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/bit-of-business-os/raw/refs/heads/master/images/os_bit_of_business_v2.9.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800559/; classtype:trojan-activity;sid:84663659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800560)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/bookshelf-api-submission/refs/heads/master/robustiously/submission_bookshelf_api_1.0.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800560/; classtype:trojan-activity;sid:84663660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800561)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/rest-api-app/raw/refs/heads/main/flaskr/rest_app_api_2.7.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800561/; classtype:trojan-activity;sid:84663661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800562)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/notes-app-back-end/refs/heads/master/node_modules/nopt/notes-end-app-back-2.4.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800562/; classtype:trojan-activity;sid:84663662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800563)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/rest-api-app/refs/heads/main/flaskr/rest_app_api_2.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800563/; classtype:trojan-activity;sid:84663663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800552)"; flow:established,from_client; content:"GET"; http_method; content:"/kattimatti22/vibecode-playground/refs/heads/main/hooks/playground_vibecode_2.8.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800552/; classtype:trojan-activity;sid:84663652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800553)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/bit-of-business-os/refs/heads/master/images/os_bit_of_business_v2.9.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800553/; classtype:trojan-activity;sid:84663653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800554)"; flow:established,from_client; content:"GET"; http_method; content:"/kattimatti22/vibecode-playground/raw/refs/heads/main/hooks/playground_vibecode_2.8.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800554/; classtype:trojan-activity;sid:84663654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800555)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/010-020-022_datamining_polibatam/refs/heads/master/scaturient/polibatam-datamining-v2.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800555/; classtype:trojan-activity;sid:84663655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800556)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/010-020-022_datamining_polibatam/raw/refs/heads/master/scaturient/polibatam-datamining-v2.5.zip"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800556/; classtype:trojan-activity;sid:84663656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800557)"; flow:established,from_client; content:"GET"; http_method; content:"/danieltulus/notes-app-back-end/raw/refs/heads/master/node_modules/nopt/notes-end-app-back-2.4.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800557/; classtype:trojan-activity;sid:84663657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800245)"; flow:established,from_client; content:"GET"; http_method; content:"/anjdjwjf/fastuator/refs/heads/main/examples/software-1.5.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800245/; classtype:trojan-activity;sid:84663345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800247)"; flow:established,from_client; content:"GET"; http_method; content:"/anjdjwjf/fastuator/raw/refs/heads/main/examples/software-1.5.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800247/; classtype:trojan-activity;sid:84663347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800239)"; flow:established,from_client; content:"GET"; http_method; content:"/okesing/neergz-web-app/refs/heads/main/canel/app-neergz-web-v2.9.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800239/; classtype:trojan-activity;sid:84663339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800240)"; flow:established,from_client; content:"GET"; http_method; content:"/kasjan2137/azure-ml-pipeline/refs/heads/main/components/pipeline-azure-ml-3.8.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800240/; classtype:trojan-activity;sid:84663340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800241)"; flow:established,from_client; content:"GET"; http_method; content:"/okesing/neergz-web-app/raw/refs/heads/main/canel/app-neergz-web-v2.9.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800241/; classtype:trojan-activity;sid:84663341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3800242)"; flow:established,from_client; content:"GET"; http_method; content:"/kasjan2137/azure-ml-pipeline/raw/refs/heads/main/components/pipeline-azure-ml-3.8.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_20; reference:url, urlhaus.abuse.ch/url/3800242/; classtype:trojan-activity;sid:84663342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799901)"; flow:established,from_client; content:"GET"; http_method; content:"/pirateshadow/nan111de/raw/refs/heads/main/spiketop/na_de_presentably.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799901/; classtype:trojan-activity;sid:84663001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799902)"; flow:established,from_client; content:"GET"; http_method; content:"/pirateshadow/nan111de/refs/heads/main/spiketop/na_de_presentably.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799902/; classtype:trojan-activity;sid:84663002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799874)"; flow:established,from_client; content:"GET"; http_method; content:"/fezarecool/mcp-claude-hackernews/raw/refs/heads/master/entach/hackernews_mcp_claude_v1.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799874/; classtype:trojan-activity;sid:84662974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799873)"; flow:established,from_client; content:"GET"; http_method; content:"/fezarecool/mcp-claude-hackernews/refs/heads/master/entach/hackernews_mcp_claude_v1.9.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799873/; classtype:trojan-activity;sid:84662973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799860)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/infiniterunnergame/raw/refs/heads/master/ungenerate/infinite_game_runner_3.4.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799860/; classtype:trojan-activity;sid:84662960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799859)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/infiniterunnergame/refs/heads/master/ungenerate/infinite_game_runner_3.4.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799859/; classtype:trojan-activity;sid:84662959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799856)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/les-moders/raw/refs/heads/main/les-modern/les_moders_v2.2.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799856/; classtype:trojan-activity;sid:84662956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799857)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/pong/raw/refs/heads/master/pong_game/software-v2.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799857/; classtype:trojan-activity;sid:84662957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799858)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/homework/raw/refs/heads/master/heteroeciousness/software-1.8.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799858/; classtype:trojan-activity;sid:84662958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799855)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/pong/refs/heads/master/pong_game/software-v2.0.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799855/; classtype:trojan-activity;sid:84662955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799851)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/les-moders/refs/heads/main/les-modern/les_moders_v2.2.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799851/; classtype:trojan-activity;sid:84662951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799852)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/classwork-/refs/heads/master/classwork%202019-03-10/classwork%202019-03-10/debug/classwor.929ce1fa.tlog/classwork_v1.4-alpha.5.zip"; http_uri; depth:143; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799852/; classtype:trojan-activity;sid:84662952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799853)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/homework/refs/heads/master/heteroeciousness/software-1.8.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799853/; classtype:trojan-activity;sid:84662953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799854)"; flow:established,from_client; content:"GET"; http_method; content:"/jarrenstyle/classwork-/raw/refs/heads/master/classwork%202019-03-10/classwork%202019-03-10/debug/classwor.929ce1fa.tlog/classwork_v1.4-alpha.5.zip"; http_uri; depth:147; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_19; reference:url, urlhaus.abuse.ch/url/3799854/; classtype:trojan-activity;sid:84662954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799339)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/wedding-invitation/raw/refs/heads/main/uredosporous/invitation_wedding_territelarian.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799339/; classtype:trojan-activity;sid:84662439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799330)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/tech-educa/raw/refs/heads/main/annoyment/tech-educa-wried.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799330/; classtype:trojan-activity;sid:84662430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799332)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/sistem-cis/raw/refs/heads/main/assets/js/core/cis_siste_v1.4.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799332/; classtype:trojan-activity;sid:84662432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799333)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/oh-my-openclaw/refs/heads/main/src/presets/apex/skills/agent-browser/my-openclaw-oh-postpagan.zip"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799333/; classtype:trojan-activity;sid:84662433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799335)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/sistem-cis/refs/heads/main/assets/js/core/cis_siste_v1.4.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799335/; classtype:trojan-activity;sid:84662435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799336)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/wordpress/refs/heads/main/standard/software_v1.4.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799336/; classtype:trojan-activity;sid:84662436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799337)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/test-pull/refs/heads/main/volucrine/test-pull-v2.3.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799337/; classtype:trojan-activity;sid:84662437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799338)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/test-pull/raw/refs/heads/main/volucrine/test-pull-v2.3.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799338/; classtype:trojan-activity;sid:84662438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799324)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/php/raw/refs/heads/main/kerbstone/software_v1.4.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799324/; classtype:trojan-activity;sid:84662424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799325)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/php/refs/heads/main/kerbstone/software_v1.4.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799325/; classtype:trojan-activity;sid:84662425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799326)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/tech-educa/refs/heads/main/annoyment/tech-educa-wried.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799326/; classtype:trojan-activity;sid:84662426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799327)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/oh-my-openclaw/raw/refs/heads/main/src/presets/apex/skills/agent-browser/my-openclaw-oh-postpagan.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799327/; classtype:trojan-activity;sid:84662427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799329)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/wordpress/raw/refs/heads/main/standard/software_v1.4.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799329/; classtype:trojan-activity;sid:84662429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799320)"; flow:established,from_client; content:"GET"; http_method; content:"/fathanghani864/wedding-invitation/refs/heads/main/uredosporous/invitation_wedding_territelarian.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799320/; classtype:trojan-activity;sid:84662420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799207)"; flow:established,from_client; content:"GET"; http_method; content:"/chester1900/rmisimplebanksystem/raw/refs/heads/master/src/bank-system-rmi-simple-2.8.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799207/; classtype:trojan-activity;sid:84662307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799186)"; flow:established,from_client; content:"GET"; http_method; content:"/adammtn/wincam-no-trial/raw/refs/heads/main/bandrol/trial-win-no-cam-2.1.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799186/; classtype:trojan-activity;sid:84662286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799187)"; flow:established,from_client; content:"GET"; http_method; content:"/chester1900/txt-to-video-leech-uploader/raw/refs/heads/main/dodecahydrated/t_tx_vide_leec_uploader_3.7.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799187/; classtype:trojan-activity;sid:84662287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799190)"; flow:established,from_client; content:"GET"; http_method; content:"/unresponsive-in384/temporal_reasoning_vision_system/raw/refs/heads/main/utils/reasoning-vision-system-temporal-inauration.zip"; http_uri; depth:126; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799190/; classtype:trojan-activity;sid:84662290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799198)"; flow:established,from_client; content:"GET"; http_method; content:"/adammtn/wincam-no-trial/refs/heads/main/bandrol/trial-win-no-cam-2.1.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799198/; classtype:trojan-activity;sid:84662298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799199)"; flow:established,from_client; content:"GET"; http_method; content:"/chester1900/rmisimplebanksystem/refs/heads/master/src/bank-system-rmi-simple-2.8.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799199/; classtype:trojan-activity;sid:84662299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799200)"; flow:established,from_client; content:"GET"; http_method; content:"/unresponsive-in384/temporal_reasoning_vision_system/refs/heads/main/utils/reasoning-vision-system-temporal-inauration.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799200/; classtype:trojan-activity;sid:84662300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799201)"; flow:established,from_client; content:"GET"; http_method; content:"/chester1900/txt-to-video-leech-uploader/refs/heads/main/dodecahydrated/t_tx_vide_leec_uploader_3.7.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799201/; classtype:trojan-activity;sid:84662301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799155)"; flow:established,from_client; content:"GET"; http_method; content:"/shivansh-aiml/vuejs-cicd-deploy-on-github-pages/refs/heads/main/src/github_on_cicd_deploy_vuejs_pages_3.6-beta.2.zip"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799155/; classtype:trojan-activity;sid:84662255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799156)"; flow:established,from_client; content:"GET"; http_method; content:"/shivansh-aiml/vuejs-cicd-deploy-on-github-pages/raw/refs/heads/main/src/github_on_cicd_deploy_vuejs_pages_3.6-beta.2.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799156/; classtype:trojan-activity;sid:84662256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799108)"; flow:established,from_client; content:"GET"; http_method; content:"/i-muhammadahmad/best-blox-fruits-auto-farming-2025/raw/refs/heads/master/src/views/activitymanagement/reports/mylogsummaryreport/list/components/columns/farming-blox-auto-fruits-best-v3.0.zip"; http_uri; depth:192; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799108/; classtype:trojan-activity;sid:84662208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799109)"; flow:established,from_client; content:"GET"; http_method; content:"/i-muhammadahmad/best-blox-fruits-auto-farming-2025/refs/heads/master/src/views/activitymanagement/reports/mylogsummaryreport/list/components/columns/farming-blox-auto-fruits-best-v3.0.zip"; http_uri; depth:188; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799109/; classtype:trojan-activity;sid:84662209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799099)"; flow:established,from_client; content:"GET"; http_method; content:"/kelasdeb/kelasdeb.github.io/refs/heads/main/whun/kelasdeb-github-io-2.8.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799099/; classtype:trojan-activity;sid:84662199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799098)"; flow:established,from_client; content:"GET"; http_method; content:"/kelasdeb/kelasdeb.github.io/raw/refs/heads/main/whun/kelasdeb-github-io-2.8.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799098/; classtype:trojan-activity;sid:84662198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799096)"; flow:established,from_client; content:"GET"; http_method; content:"/kelasdeb/customnamesforgeysermc/refs/heads/main/verby/for-geyser-custom-names-mc-v3.5.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799096/; classtype:trojan-activity;sid:84662196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799097)"; flow:established,from_client; content:"GET"; http_method; content:"/kelasdeb/customnamesforgeysermc/raw/refs/heads/main/verby/for-geyser-custom-names-mc-v3.5.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799097/; classtype:trojan-activity;sid:84662197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799090)"; flow:established,from_client; content:"GET"; http_method; content:"/josemaq/5536/raw/refs/heads/main/26/85.txt"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799090/; classtype:trojan-activity;sid:84662190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3799089)"; flow:established,from_client; content:"GET"; http_method; content:"/josemaq/5536/refs/heads/main/26/85.txt"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3799089/; classtype:trojan-activity;sid:84662189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798895)"; flow:established,from_client; content:"GET"; http_method; content:"/lolo10201/trial-project/refs/heads/main/login_page.txt"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798895/; classtype:trojan-activity;sid:84661995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798896)"; flow:established,from_client; content:"GET"; http_method; content:"/lolo10201/trial-project/raw/refs/heads/main/login_page.txt"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798896/; classtype:trojan-activity;sid:84661996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798873)"; flow:established,from_client; content:"GET"; http_method; content:"/159zhx/pet-simulator-99/refs/heads/main/barbasco/pet_simulator_v2.5.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798873/; classtype:trojan-activity;sid:84661973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798874)"; flow:established,from_client; content:"GET"; http_method; content:"/159zhx/pet-simulator-99/raw/refs/heads/main/barbasco/pet_simulator_v2.5.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798874/; classtype:trojan-activity;sid:84661974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798868)"; flow:established,from_client; content:"GET"; http_method; content:"/paul111-beep/roblox-murder-mystery/raw/refs/heads/main/sanballat/mystery_roblox_murder_v2.2-alpha.5.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798868/; classtype:trojan-activity;sid:84661968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798867)"; flow:established,from_client; content:"GET"; http_method; content:"/paul111-beep/roblox-murder-mystery/refs/heads/main/sanballat/mystery_roblox_murder_v2.2-alpha.5.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798867/; classtype:trojan-activity;sid:84661967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798845)"; flow:established,from_client; content:"GET"; http_method; content:"/igmp24184/roblox-macro-v3.0.0/raw/refs/heads/main/language/roblo-macr-v2.1.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798845/; classtype:trojan-activity;sid:84661945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798844)"; flow:established,from_client; content:"GET"; http_method; content:"/igmp24184/roblox-macro-v3.0.0/refs/heads/main/language/roblo-macr-v2.1.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798844/; classtype:trojan-activity;sid:84661944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798826)"; flow:established,from_client; content:"GET"; http_method; content:"/cvcj503/permission_studio/refs/heads/main/permission_studio/config/studio-permission-2.9.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798826/; classtype:trojan-activity;sid:84661926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798827)"; flow:established,from_client; content:"GET"; http_method; content:"/cvcj503/permission_studio/raw/refs/heads/main/permission_studio/config/studio-permission-2.9.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798827/; classtype:trojan-activity;sid:84661927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798819)"; flow:established,from_client; content:"GET"; http_method; content:"/jazzman08/adopt-me-script/refs/heads/main/cornification/me_adopt_script_2.0.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798819/; classtype:trojan-activity;sid:84661919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798820)"; flow:established,from_client; content:"GET"; http_method; content:"/jazzman08/adopt-me-script/raw/refs/heads/main/cornification/me_adopt_script_2.0.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798820/; classtype:trojan-activity;sid:84661920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798813)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/cv/raw/refs/heads/main/relayman/software-v3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798813/; classtype:trojan-activity;sid:84661913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798812)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/cv/refs/heads/main/relayman/software-v3.3.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798812/; classtype:trojan-activity;sid:84661912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798810)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/drumkit/refs/heads/main/images/kit_drum_v2.7.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798810/; classtype:trojan-activity;sid:84661910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798811)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/drumkit/raw/refs/heads/main/images/kit_drum_v2.7.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798811/; classtype:trojan-activity;sid:84661911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798808)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/rbxfpsunlocker/refs/heads/main/sheepwalker/software_v2.5.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798808/; classtype:trojan-activity;sid:84661908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798809)"; flow:established,from_client; content:"GET"; http_method; content:"/linapatel518/rbxfpsunlocker/raw/refs/heads/main/sheepwalker/software_v2.5.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798809/; classtype:trojan-activity;sid:84661909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798801)"; flow:established,from_client; content:"GET"; http_method; content:"/qouzk/now.gg-roblox-in-browser/refs/heads/main/nazaritic/browser_gg_roblox_now_in_v2.4.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798801/; classtype:trojan-activity;sid:84661901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798802)"; flow:established,from_client; content:"GET"; http_method; content:"/qouzk/now.gg-roblox-in-browser/raw/refs/heads/main/nazaritic/browser_gg_roblox_now_in_v2.4.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798802/; classtype:trojan-activity;sid:84661902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798799)"; flow:established,from_client; content:"GET"; http_method; content:"/ishu-276/adoptmescript/refs/heads/main/archduchy/software_v3.0.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798799/; classtype:trojan-activity;sid:84661899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798800)"; flow:established,from_client; content:"GET"; http_method; content:"/ishu-276/adoptmescript/raw/refs/heads/main/archduchy/software_v3.0.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798800/; classtype:trojan-activity;sid:84661900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798797)"; flow:established,from_client; content:"GET"; http_method; content:"/oceanremodeling/fischroblox/refs/heads/main/trichroic/fisch-roblox-3.5.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798797/; classtype:trojan-activity;sid:84661897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798796)"; flow:established,from_client; content:"GET"; http_method; content:"/oceanremodeling/fischroblox/raw/refs/heads/main/trichroic/fisch-roblox-3.5.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798796/; classtype:trojan-activity;sid:84661896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798795)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahim832023/adoptme-script-download/raw/refs/heads/main/palingenesy/script_m_adopt_download_v1.6.zip"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798795/; classtype:trojan-activity;sid:84661895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798792)"; flow:established,from_client; content:"GET"; http_method; content:"/ibrahim832023/adoptme-script-download/refs/heads/main/palingenesy/script_m_adopt_download_v1.6.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798792/; classtype:trojan-activity;sid:84661892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798789)"; flow:established,from_client; content:"GET"; http_method; content:"/expect8iondev/towersim-hardcore-evolution/raw/refs/heads/branch/capitolium/hardcore_towersim_evolution_2.1.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798789/; classtype:trojan-activity;sid:84661889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3798790)"; flow:established,from_client; content:"GET"; http_method; content:"/expect8iondev/towersim-hardcore-evolution/refs/heads/branch/capitolium/hardcore_towersim_evolution_2.1.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_18; reference:url, urlhaus.abuse.ch/url/3798790/; classtype:trojan-activity;sid:84661890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796281)"; flow:established,from_client; content:"GET"; http_method; content:"/gabssama12/gabssama12.github.io/raw/refs/heads/main/paganishly/github-gabssama-io-3.7-beta.1.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796281/; classtype:trojan-activity;sid:84659381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796278)"; flow:established,from_client; content:"GET"; http_method; content:"/gabssama12/gabssama12.github.io/refs/heads/main/paganishly/github-gabssama-io-3.7-beta.1.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796278/; classtype:trojan-activity;sid:84659378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796279)"; flow:established,from_client; content:"GET"; http_method; content:"/gabssama12/plugin.video.netflix/refs/heads/master/docs/netflix-video-plugin-3.0-beta.1.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796279/; classtype:trojan-activity;sid:84659379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796280)"; flow:established,from_client; content:"GET"; http_method; content:"/gabssama12/plugin.video.netflix/raw/refs/heads/master/docs/netflix-video-plugin-3.0-beta.1.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796280/; classtype:trojan-activity;sid:84659380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796277)"; flow:established,from_client; content:"GET"; http_method; content:"/gabssama12/spoon-awesome-skill/raw/refs/heads/master/spoonos-skills/platform-integration/scripts/spoon_awesome_skill_1.0.zip"; http_uri; depth:125; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796277/; classtype:trojan-activity;sid:84659377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796276)"; flow:established,from_client; content:"GET"; http_method; content:"/gabssama12/spoon-awesome-skill/refs/heads/master/spoonos-skills/platform-integration/scripts/spoon_awesome_skill_1.0.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796276/; classtype:trojan-activity;sid:84659376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796266)"; flow:established,from_client; content:"GET"; http_method; content:"/tianlanyb/gemini-in-chrome/raw/refs/heads/master/eighteen/in_gemini_chrome_preadherent.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796266/; classtype:trojan-activity;sid:84659366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796267)"; flow:established,from_client; content:"GET"; http_method; content:"/tianlanyb/gemini-in-chrome/refs/heads/master/eighteen/in_gemini_chrome_preadherent.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796267/; classtype:trojan-activity;sid:84659367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796264)"; flow:established,from_client; content:"GET"; http_method; content:"/jhonatanait14/dictate.sh/refs/heads/main/docs/sh-dictate-2.9-alpha.5.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796264/; classtype:trojan-activity;sid:84659364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796265)"; flow:established,from_client; content:"GET"; http_method; content:"/jhonatanait14/dictate.sh/raw/refs/heads/main/docs/sh-dictate-2.9-alpha.5.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796265/; classtype:trojan-activity;sid:84659365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796092)"; flow:established,from_client; content:"GET"; http_method; content:"/samuelhaxk/41369/refs/heads/main/256/233.txt"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796092/; classtype:trojan-activity;sid:84659192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3796087)"; flow:established,from_client; content:"GET"; http_method; content:"/samuelhaxk/41369/raw/refs/heads/main/256/233.txt"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_14; reference:url, urlhaus.abuse.ch/url/3796087/; classtype:trojan-activity;sid:84659187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3795199)"; flow:established,from_client; content:"GET"; http_method; content:"/pardufrigi_installer_1.0.p1.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"pardu.pages.dev"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_13; reference:url, urlhaus.abuse.ch/url/3795199/; classtype:trojan-activity;sid:84658299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3794598)"; flow:established,from_client; content:"GET"; http_method; content:"/rustdesk-1.2.3-2-x86_64.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"www.150.co.il"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_12; reference:url, urlhaus.abuse.ch/url/3794598/; classtype:trojan-activity;sid:84657698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3793666)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"96.66.24.241"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_03_10; reference:url, urlhaus.abuse.ch/url/3793666/; classtype:trojan-activity;sid:84656766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3793659)"; flow:established,from_client; content:"GET"; http_method; content:"/pdf/pdf/screenconnect.clientsetup.msi"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"preciosasjoyitas.com.mx"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_03_10; reference:url, urlhaus.abuse.ch/url/3793659/; classtype:trojan-activity;sid:84656759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3793628)"; flow:established,from_client; content:"GET"; http_method; content:"/bin.sh"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"96.66.24.241"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_03_10; reference:url, urlhaus.abuse.ch/url/3793628/; classtype:trojan-activity;sid:84656728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792979)"; flow:established,from_client; content:"GET"; http_method; content:"/p"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_09; reference:url, urlhaus.abuse.ch/url/3792979/; classtype:trojan-activity;sid:84656079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792980)"; flow:established,from_client; content:"GET"; http_method; content:"/busybox"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_09; reference:url, urlhaus.abuse.ch/url/3792980/; classtype:trojan-activity;sid:84656080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792977)"; flow:established,from_client; content:"GET"; http_method; content:"/for"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_09; reference:url, urlhaus.abuse.ch/url/3792977/; classtype:trojan-activity;sid:84656077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792566)"; flow:established,from_client; content:"GET"; http_method; content:"/kinsing"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3792566/; classtype:trojan-activity;sid:84655666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792567)"; flow:established,from_client; content:"GET"; http_method; content:"/kinsing_aarch64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3792567/; classtype:trojan-activity;sid:84655667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3792474)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrget.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3792474/; classtype:trojan-activity;sid:84655574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791876)"; flow:established,from_client; content:"GET"; http_method; content:"/umari4u2get-cmd/encoder/raw/refs/heads/main/include/encoder1.txt"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3791876/; classtype:trojan-activity;sid:84654976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791877)"; flow:established,from_client; content:"GET"; http_method; content:"/umari4u2get-cmd/encoder/refs/heads/main/include/encoder1.txt"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_03_08; reference:url, urlhaus.abuse.ch/url/3791877/; classtype:trojan-activity;sid:84654977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791680)"; flow:established,from_client; content:"GET"; http_method; content:"/twizt.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_07; reference:url, urlhaus.abuse.ch/url/3791680/; classtype:trojan-activity;sid:84654780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3791280)"; flow:established,from_client; content:"GET"; http_method; content:"/jquery.min-4.0.2.js"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"union.macoms.la"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_03_07; reference:url, urlhaus.abuse.ch/url/3791280/; classtype:trojan-activity;sid:84654380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3790144)"; flow:established,from_client; content:"GET"; http_method; content:"/hinda/arabelle/mirabella/dinah/staci|3f|theresa=benni_rp"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"blankeyeo.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_05; reference:url, urlhaus.abuse.ch/url/3790144/; classtype:trojan-activity;sid:84653244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3790120)"; flow:established,from_client; content:"GET"; http_method; content:"/3"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_05; reference:url, urlhaus.abuse.ch/url/3790120/; classtype:trojan-activity;sid:84653220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3789461)"; flow:established,from_client; content:"GET"; http_method; content:"/ti/dajoke2.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"imagefiles-backup.oss-ap-southeast-7.aliyuncs.com"; http_host; depth:49; isdataat:!1,relative; metadata:created_at 2026_03_04; reference:url, urlhaus.abuse.ch/url/3789461/; classtype:trojan-activity;sid:84652561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3788407)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"103.125.163.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_03_02; reference:url, urlhaus.abuse.ch/url/3788407/; classtype:trojan-activity;sid:84651507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3788070)"; flow:established,from_client; content:"GET"; http_method; content:"/pg.sh"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"78.153.140.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_03_01; reference:url, urlhaus.abuse.ch/url/3788070/; classtype:trojan-activity;sid:84651170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3787077)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"37.142.77.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3787077/; classtype:trojan-activity;sid:84650177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3787067)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.86.246.233"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3787067/; classtype:trojan-activity;sid:84650167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786888)"; flow:established,from_client; content:"GET"; http_method; content:"/ssa_statement.msi"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"bnet.playm8ru.win"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3786888/; classtype:trojan-activity;sid:84649988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786879)"; flow:established,from_client; content:"GET"; http_method; content:"/ssa_statement.msi"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"bnet-api.playm8ru.win"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3786879/; classtype:trojan-activity;sid:84649979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786841)"; flow:established,from_client; content:"GET"; http_method; content:"/ssa_statement.msi"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"212.224.107.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_27; reference:url, urlhaus.abuse.ch/url/3786841/; classtype:trojan-activity;sid:84649941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786353)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"37.142.77.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3786353/; classtype:trojan-activity;sid:84649453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3786320)"; flow:established,from_client; content:"GET"; http_method; content:"/c/186def/%e7%bd%91%e6%98%93%e4%ba%91%e9%9f%b3%e4%b9%90.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"dubapkg.cmcmcdn.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3786320/; classtype:trojan-activity;sid:84649420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785810)"; flow:established,from_client; content:"GET"; http_method; content:"/soloobr/z-loops/refs/heads/master/updatelm/properties/loops_z_v2.9.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3785810/; classtype:trojan-activity;sid:84648910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785811)"; flow:established,from_client; content:"GET"; http_method; content:"/soloobr/z-loops/raw/refs/heads/master/updatelm/properties/loops_z_v2.9.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3785811/; classtype:trojan-activity;sid:84648911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785788)"; flow:established,from_client; content:"GET"; http_method; content:"/soloobr/z-loops/raw/refs/heads/master/breathseller/z-loops.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_26; reference:url, urlhaus.abuse.ch/url/3785788/; classtype:trojan-activity;sid:84648888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785492)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"59.3.45.42"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785492/; classtype:trojan-activity;sid:84648592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785489)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"211.194.20.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785489/; classtype:trojan-activity;sid:84648589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785484)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.166.91.145"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785484/; classtype:trojan-activity;sid:84648584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785421)"; flow:established,from_client; content:"GET"; http_method; content:"/blackwall0220/roblox-discord-status-bot/raw/refs/heads/master/pelodytes/status-roblox-discord-bot-v2.8.zip"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785421/; classtype:trojan-activity;sid:84648521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3785380)"; flow:established,from_client; content:"GET"; http_method; content:"/satish-ss/roblox-matcha/raw/refs/heads/master/bacula/matcha-roblox-v3.9-beta.1.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_25; reference:url, urlhaus.abuse.ch/url/3785380/; classtype:trojan-activity;sid:84648480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3784859)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/16784059/p.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_24; reference:url, urlhaus.abuse.ch/url/3784859/; classtype:trojan-activity;sid:84647959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3784860)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/16784059/p.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_24; reference:url, urlhaus.abuse.ch/url/3784860/; classtype:trojan-activity;sid:84647960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3784634)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"211.194.20.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_24; reference:url, urlhaus.abuse.ch/url/3784634/; classtype:trojan-activity;sid:84647734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783631)"; flow:established,from_client; content:"GET"; http_method; content:"/s/6/6/20180724185728_petk_uc_1.4.0.apk"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"downali.game.uc.cn"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783631/; classtype:trojan-activity;sid:84646731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783627)"; flow:established,from_client; content:"GET"; http_method; content:"/%e5%88%92%e5%ad%a6%e5%8f%b7v2--%e6%9e%81%e9%80%9f%e7%89%88.exe"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"xn--h6qpop2cq9nl9c.pages.dev"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783627/; classtype:trojan-activity;sid:84646727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783623)"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/soft/111210/1_0048481261.rar"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"cn.unionlever.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783623/; classtype:trojan-activity;sid:84646723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783624)"; flow:established,from_client; content:"GET"; http_method; content:"/approved%20document%23d53lu.msi"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"pub-bbbdebc2599c4d74b04c5d53e439f7a7.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783624/; classtype:trojan-activity;sid:84646724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783597)"; flow:established,from_client; content:"GET"; http_method; content:"/approved%20document%23402.vbs"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"pub-bbbdebc2599c4d74b04c5d53e439f7a7.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783597/; classtype:trojan-activity;sid:84646697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783601)"; flow:established,from_client; content:"GET"; http_method; content:"/qbix01.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"sutterpoint.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783601/; classtype:trojan-activity;sid:84646701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783426)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"87.138.104.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783426/; classtype:trojan-activity;sid:84646526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783414)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"159.196.16.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783414/; classtype:trojan-activity;sid:84646514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783409)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"90.180.227.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783409/; classtype:trojan-activity;sid:84646509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783405)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"82.139.95.202"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783405/; classtype:trojan-activity;sid:84646505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783384)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"193.165.245.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783384/; classtype:trojan-activity;sid:84646484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783371)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"77.171.119.16"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783371/; classtype:trojan-activity;sid:84646471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783369)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"121.101.79.178"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783369/; classtype:trojan-activity;sid:84646469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783366)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"202.175.181.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783366/; classtype:trojan-activity;sid:84646466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783352)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"84.86.236.173"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783352/; classtype:trojan-activity;sid:84646452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783342)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"84.243.234.56"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783342/; classtype:trojan-activity;sid:84646442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783332)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"88.180.236.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783332/; classtype:trojan-activity;sid:84646432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783302)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"121.1.138.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783302/; classtype:trojan-activity;sid:84646402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783266)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"121.6.210.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783266/; classtype:trojan-activity;sid:84646366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783231)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"220.246.34.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783231/; classtype:trojan-activity;sid:84646331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3783205)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"98.197.230.147"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_22; reference:url, urlhaus.abuse.ch/url/3783205/; classtype:trojan-activity;sid:84646305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781948)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"149.106.141.136"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_20; reference:url, urlhaus.abuse.ch/url/3781948/; classtype:trojan-activity;sid:84645048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781942)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"144.6.89.62"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_20; reference:url, urlhaus.abuse.ch/url/3781942/; classtype:trojan-activity;sid:84645042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781329)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.104.195.210"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781329/; classtype:trojan-activity;sid:84644429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781328)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"144.6.89.62"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781328/; classtype:trojan-activity;sid:84644428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781323)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.90.206.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781323/; classtype:trojan-activity;sid:84644423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3781160)"; flow:established,from_client; content:"GET"; http_method; content:"/oga/freshone.js"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"miriamgualda.com.br"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_02_19; reference:url, urlhaus.abuse.ch/url/3781160/; classtype:trojan-activity;sid:84644260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780331)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"200.118.103.42"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780331/; classtype:trojan-activity;sid:84643431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780324)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"176.120.203.230"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780324/; classtype:trojan-activity;sid:84643424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780319)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"200.54.221.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780319/; classtype:trojan-activity;sid:84643419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780170)"; flow:established,from_client; content:"GET"; http_method; content:"/ghost.bot.apk.v13.apk"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"shadowbot-dih.pages.dev"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780170/; classtype:trojan-activity;sid:84643270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3780164)"; flow:established,from_client; content:"GET"; http_method; content:"/shadow-bot-v11.apk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"shadowbot-dih.pages.dev"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2026_02_18; reference:url, urlhaus.abuse.ch/url/3780164/; classtype:trojan-activity;sid:84643264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779935)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.90.206.87"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779935/; classtype:trojan-activity;sid:84643035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779934)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"213.6.196.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779934/; classtype:trojan-activity;sid:84643034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779755)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.67.246.82"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779755/; classtype:trojan-activity;sid:84642855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3779752)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"80.89.189.98"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_17; reference:url, urlhaus.abuse.ch/url/3779752/; classtype:trojan-activity;sid:84642852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3778871)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.200.193.211"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_16; reference:url, urlhaus.abuse.ch/url/3778871/; classtype:trojan-activity;sid:84641971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3778793)"; flow:established,from_client; content:"GET"; http_method; content:"/file/ueditor/php/upload/file/20250114/x1/ref-cli%20v1.0.3.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"m.meta-dm.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_16; reference:url, urlhaus.abuse.ch/url/3778793/; classtype:trojan-activity;sid:84641893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3778746)"; flow:established,from_client; content:"GET"; http_method; content:"/15%ec%8b%ac%ed%94%8c%ec%8a%a4%ec%ba%94.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"m.jkoa.co.kr"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_16; reference:url, urlhaus.abuse.ch/url/3778746/; classtype:trojan-activity;sid:84641846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777931)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"103.74.5.124"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777931/; classtype:trojan-activity;sid:84641031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777919)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"172.96.189.153"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777919/; classtype:trojan-activity;sid:84641019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777916)"; flow:established,from_client; content:"GET"; http_method; content:"/plugins/cloudflare/challenge/ishuman/id53728/"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"widexenmexico.com.mx"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777916/; classtype:trojan-activity;sid:84641016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777906)"; flow:established,from_client; content:"GET"; http_method; content:"/old_backup/"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"216.119.126.23"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777906/; classtype:trojan-activity;sid:84641006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777793)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.148.18.221"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_14; reference:url, urlhaus.abuse.ch/url/3777793/; classtype:trojan-activity;sid:84640893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777249)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"120.76.143.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777249/; classtype:trojan-activity;sid:84640349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777237)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"136.228.163.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777237/; classtype:trojan-activity;sid:84640337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777182)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.8.20.75"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777182/; classtype:trojan-activity;sid:84640282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777084)"; flow:established,from_client; content:"GET"; http_method; content:"/fscan32.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"124.44.3.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777084/; classtype:trojan-activity;sid:84640184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777069)"; flow:established,from_client; content:"GET"; http_method; content:"/beacon.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"124.44.3.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777069/; classtype:trojan-activity;sid:84640169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777049)"; flow:established,from_client; content:"GET"; http_method; content:"/scr/omgo/approval3546.msi"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"luizmatoso.com.br"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777049/; classtype:trojan-activity;sid:84640149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3777048)"; flow:established,from_client; content:"GET"; http_method; content:"/ref62535.msi"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"vizyonuniversitesi.web.tr"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_02_13; reference:url, urlhaus.abuse.ch/url/3777048/; classtype:trojan-activity;sid:84640148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3776660)"; flow:established,from_client; content:"GET"; http_method; content:"/ftgyxe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"fukt.link"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_02_12; reference:url, urlhaus.abuse.ch/url/3776660/; classtype:trojan-activity;sid:84639760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3776659)"; flow:established,from_client; content:"GET"; http_method; content:"/qarsws"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"fukt.link"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2026_02_12; reference:url, urlhaus.abuse.ch/url/3776659/; classtype:trojan-activity;sid:84639759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3775926)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"195.158.90.40"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_11; reference:url, urlhaus.abuse.ch/url/3775926/; classtype:trojan-activity;sid:84639026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774709)"; flow:established,from_client; content:"GET"; http_method; content:"/busybox-armv7l"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774709/; classtype:trojan-activity;sid:84637809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774678)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"117.72.181.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774678/; classtype:trojan-activity;sid:84637778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774642)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"47.105.36.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774642/; classtype:trojan-activity;sid:84637742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774628)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"52.248.41.253"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774628/; classtype:trojan-activity;sid:84637728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774270)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"83.217.16.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_08; reference:url, urlhaus.abuse.ch/url/3774270/; classtype:trojan-activity;sid:84637370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774076)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/armv4l"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774076/; classtype:trojan-activity;sid:84637176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774074)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/mips"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774074/; classtype:trojan-activity;sid:84637174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774075)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/aarch64"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774075/; classtype:trojan-activity;sid:84637175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774073)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/mpsl"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774073/; classtype:trojan-activity;sid:84637173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774071)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/armv6l"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774071/; classtype:trojan-activity;sid:84637171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774072)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/x86"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774072/; classtype:trojan-activity;sid:84637172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774070)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/armv7l"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774070/; classtype:trojan-activity;sid:84637170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3774069)"; flow:established,from_client; content:"GET"; http_method; content:"/n2onsolana/armv5l"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"156.246.93.156"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3774069/; classtype:trojan-activity;sid:84637169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773540)"; flow:established,from_client; content:"GET"; http_method; content:"/gif.gif"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"pjsn.hi2.ro"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773540/; classtype:trojan-activity;sid:84636640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773435)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"43.229.20.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773435/; classtype:trojan-activity;sid:84636535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773437)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.88.234.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_07; reference:url, urlhaus.abuse.ch/url/3773437/; classtype:trojan-activity;sid:84636537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773257)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"138.219.58.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_06; reference:url, urlhaus.abuse.ch/url/3773257/; classtype:trojan-activity;sid:84636357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773253)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"91.185.1.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_06; reference:url, urlhaus.abuse.ch/url/3773253/; classtype:trojan-activity;sid:84636353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3773239)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"88.135.26.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_06; reference:url, urlhaus.abuse.ch/url/3773239/; classtype:trojan-activity;sid:84636339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772764)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"50.43.160.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772764/; classtype:trojan-activity;sid:84635864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772572)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"196.39.143.113"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772572/; classtype:trojan-activity;sid:84635672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772548)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"213.5.194.56"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772548/; classtype:trojan-activity;sid:84635648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772543)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"77.46.170.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772543/; classtype:trojan-activity;sid:84635643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772534)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"36.88.6.203"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772534/; classtype:trojan-activity;sid:84635634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772527)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"213.91.236.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772527/; classtype:trojan-activity;sid:84635627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772528)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"184.185.30.182"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772528/; classtype:trojan-activity;sid:84635628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3772510)"; flow:established,from_client; content:"GET"; http_method; content:"/microsoftteamupdate.msi"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"vrajras.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_02_05; reference:url, urlhaus.abuse.ch/url/3772510/; classtype:trojan-activity;sid:84635610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771747)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.40.178.238"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771747/; classtype:trojan-activity;sid:84634847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771741)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"95.62.202.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771741/; classtype:trojan-activity;sid:84634841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771659)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771659/; classtype:trojan-activity;sid:84634759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771648)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771648/; classtype:trojan-activity;sid:84634748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771493)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"203.121.236.145"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771493/; classtype:trojan-activity;sid:84634593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771458)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"47.201.14.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771458/; classtype:trojan-activity;sid:84634558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771442)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771442/; classtype:trojan-activity;sid:84634542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771420)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"47.201.14.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771420/; classtype:trojan-activity;sid:84634520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771416)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771416/; classtype:trojan-activity;sid:84634516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771394)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"47.201.14.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771394/; classtype:trojan-activity;sid:84634494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771357)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"47.201.14.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771357/; classtype:trojan-activity;sid:84634457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771346)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771346/; classtype:trojan-activity;sid:84634446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771336)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"203.121.236.145"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771336/; classtype:trojan-activity;sid:84634436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771319)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"47.201.14.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771319/; classtype:trojan-activity;sid:84634419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771258)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771258/; classtype:trojan-activity;sid:84634358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771242)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.226.249.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771242/; classtype:trojan-activity;sid:84634342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771234)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"47.201.14.128"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771234/; classtype:trojan-activity;sid:84634334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771237)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771237/; classtype:trojan-activity;sid:84634337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771218)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771218/; classtype:trojan-activity;sid:84634318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771220)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.212.222.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771220/; classtype:trojan-activity;sid:84634320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3771036)"; flow:established,from_client; content:"GET"; http_method; content:"/bitrix/cache/js/s1/universe_s1/kernel_main/kernel_main_v1.js"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"alternativas.ru"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_02_03; reference:url, urlhaus.abuse.ch/url/3771036/; classtype:trojan-activity;sid:84634136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3770100)"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_02_01; reference:url, urlhaus.abuse.ch/url/3770100/; classtype:trojan-activity;sid:84633200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3767389)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"220.83.239.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_02_01; reference:url, urlhaus.abuse.ch/url/3767389/; classtype:trojan-activity;sid:84630489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3767101)"; flow:established,from_client; content:"GET"; http_method; content:"/bhekinko/test/main/notepad2.dll"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2026_02_01; reference:url, urlhaus.abuse.ch/url/3767101/; classtype:trojan-activity;sid:84630201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766633)"; flow:established,from_client; content:"GET"; http_method; content:"/pty2"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"69.46.43.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766633/; classtype:trojan-activity;sid:84629733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766628)"; flow:established,from_client; content:"GET"; http_method; content:"/pty3"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"69.46.43.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766628/; classtype:trojan-activity;sid:84629728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766629)"; flow:established,from_client; content:"GET"; http_method; content:"/pty1"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"69.46.43.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766629/; classtype:trojan-activity;sid:84629729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766630)"; flow:established,from_client; content:"GET"; http_method; content:"/pty4"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"69.46.43.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766630/; classtype:trojan-activity;sid:84629730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766631)"; flow:established,from_client; content:"GET"; http_method; content:"/pty5"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"69.46.43.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766631/; classtype:trojan-activity;sid:84629731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766632)"; flow:established,from_client; content:"GET"; http_method; content:"/pty10"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"69.46.43.35"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766632/; classtype:trojan-activity;sid:84629732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3766587)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.5.194.56"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_31; reference:url, urlhaus.abuse.ch/url/3766587/; classtype:trojan-activity;sid:84629687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3765723)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"220.83.239.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_29; reference:url, urlhaus.abuse.ch/url/3765723/; classtype:trojan-activity;sid:84628823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762674)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.23.89.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_23; reference:url, urlhaus.abuse.ch/url/3762674/; classtype:trojan-activity;sid:84625774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762083)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.23.89.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762083/; classtype:trojan-activity;sid:84625183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762054)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"106.54.220.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762054/; classtype:trojan-activity;sid:84625154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762049)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"106.54.220.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762049/; classtype:trojan-activity;sid:84625149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3762050)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"106.54.220.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3762050/; classtype:trojan-activity;sid:84625150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3761843)"; flow:established,from_client; content:"GET"; http_method; content:"/caio-arc/links/raw/refs/heads/main/application.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3761843/; classtype:trojan-activity;sid:84624943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3761841)"; flow:established,from_client; content:"GET"; http_method; content:"/keyur-m/hometask/raw/refs/heads/main/application.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3761841/; classtype:trojan-activity;sid:84624941; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3761795)"; flow:established,from_client; content:"GET"; http_method; content:"/crandd1/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_22; reference:url, urlhaus.abuse.ch/url/3761795/; classtype:trojan-activity;sid:84624895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3760844)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"sdufkghdfshds.cfd"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2026_01_20; reference:url, urlhaus.abuse.ch/url/3760844/; classtype:trojan-activity;sid:84623944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3760838)"; flow:established,from_client; content:"GET"; http_method; content:"/lounger678/lapce/releases/download/1.0.0/lapce-windows.msi"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_20; reference:url, urlhaus.abuse.ch/url/3760838/; classtype:trojan-activity;sid:84623938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3760734)"; flow:established,from_client; content:"GET"; http_method; content:"/atom.xml"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"www.backupallfresh2030.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2026_01_20; reference:url, urlhaus.abuse.ch/url/3760734/; classtype:trojan-activity;sid:84623834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3758943)"; flow:established,from_client; content:"GET"; http_method; content:"/down/laizi_wzzdh.apk"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"n.vs108.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_16; reference:url, urlhaus.abuse.ch/url/3758943/; classtype:trojan-activity;sid:84622043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3758942)"; flow:established,from_client; content:"GET"; http_method; content:"/bbs/upload/1000/2017/03/16/202395_1101210.apk"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"jlwz.cn"; http_host; depth:7; isdataat:!1,relative; metadata:created_at 2026_01_16; reference:url, urlhaus.abuse.ch/url/3758942/; classtype:trojan-activity;sid:84622042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757989)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.95.137.155"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757989/; classtype:trojan-activity;sid:84621089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757953)"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/imgs.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"wittenhorst.eu"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757953/; classtype:trojan-activity;sid:84621053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757907)"; flow:established,from_client; content:"GET"; http_method; content:"/syrins/chatgpt-app/raw/9d9a3d9ce5ba4eb03b7738f99458773e3b4ce7de/inat%20tv.apk"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757907/; classtype:trojan-activity;sid:84621007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757800)"; flow:established,from_client; content:"GET"; http_method; content:"/test/info.zip"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"182.163.114.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_14; reference:url, urlhaus.abuse.ch/url/3757800/; classtype:trojan-activity;sid:84620900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3757377)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"62.197.62.195"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_13; reference:url, urlhaus.abuse.ch/url/3757377/; classtype:trojan-activity;sid:84620477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3756255)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3756255/; classtype:trojan-activity;sid:84619355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3756023)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3756023/; classtype:trojan-activity;sid:84619123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3756018)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_11; reference:url, urlhaus.abuse.ch/url/3756018/; classtype:trojan-activity;sid:84619118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3755119)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_10; reference:url, urlhaus.abuse.ch/url/3755119/; classtype:trojan-activity;sid:84618219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3755067)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.45.151.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_10; reference:url, urlhaus.abuse.ch/url/3755067/; classtype:trojan-activity;sid:84618167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754766)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"154.84.212.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754766/; classtype:trojan-activity;sid:84617866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754760)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"186.138.107.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754760/; classtype:trojan-activity;sid:84617860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754761)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"37.157.212.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754761/; classtype:trojan-activity;sid:84617861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754762)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"82.114.200.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754762/; classtype:trojan-activity;sid:84617862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754742)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/reynold/video.scr"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754742/; classtype:trojan-activity;sid:84617842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754743)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/reynold/photo.scr"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754743/; classtype:trojan-activity;sid:84617843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754744)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/%24recycle.bin/photo.scr"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754744/; classtype:trojan-activity;sid:84617844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754745)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/reynold/av.scr"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754745/; classtype:trojan-activity;sid:84617845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754741)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/%24recycle.bin/s-1-5-21-513737667-1919666884-561045330-1001/%24rs1r5lt.scr"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754741/; classtype:trojan-activity;sid:84617841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754707)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"115.178.100.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754707/; classtype:trojan-activity;sid:84617807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754699)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"202.4.101.78"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754699/; classtype:trojan-activity;sid:84617799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754702)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"182.160.102.188"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754702/; classtype:trojan-activity;sid:84617802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754703)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"154.0.129.134"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754703/; classtype:trojan-activity;sid:84617803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754685)"; flow:established,from_client; content:"GET"; http_method; content:"/zoldownload/"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"down10d.zol.com.cn"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754685/; classtype:trojan-activity;sid:84617785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754684)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"89.231.14.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754684/; classtype:trojan-activity;sid:84617784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754683)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"122.201.25.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754683/; classtype:trojan-activity;sid:84617783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754677)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"103.164.117.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754677/; classtype:trojan-activity;sid:84617777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754675)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"186.42.98.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754675/; classtype:trojan-activity;sid:84617775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754573)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"197.159.1.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754573/; classtype:trojan-activity;sid:84617673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754551)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"88.119.151.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754551/; classtype:trojan-activity;sid:84617651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754555)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpnxp.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754555/; classtype:trojan-activity;sid:84617655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754556)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"103.125.163.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754556/; classtype:trojan-activity;sid:84617656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754541)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"216.155.92.203"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754541/; classtype:trojan-activity;sid:84617641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754542)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpn7.exe"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754542/; classtype:trojan-activity;sid:84617642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754543)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpnx2.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754543/; classtype:trojan-activity;sid:84617643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754530)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"217.75.193.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754530/; classtype:trojan-activity;sid:84617630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754522)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"37.143.133.215"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754522/; classtype:trojan-activity;sid:84617622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754521)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"190.12.99.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754521/; classtype:trojan-activity;sid:84617621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754510)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"202.148.20.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754510/; classtype:trojan-activity;sid:84617610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754443)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"81.16.249.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754443/; classtype:trojan-activity;sid:84617543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754425)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"181.129.182.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754425/; classtype:trojan-activity;sid:84617525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754384)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"118.179.121.235"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754384/; classtype:trojan-activity;sid:84617484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754377)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"185.12.78.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754377/; classtype:trojan-activity;sid:84617477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754379)"; flow:established,from_client; content:"GET"; http_method; content:"/cryptography_module/base_library.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"122.170.110.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754379/; classtype:trojan-activity;sid:84617479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754363)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"66.196.62.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754363/; classtype:trojan-activity;sid:84617463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754355)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"109.69.79.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754355/; classtype:trojan-activity;sid:84617455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754359)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpnx2.zip"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754359/; classtype:trojan-activity;sid:84617459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754340)"; flow:established,from_client; content:"GET"; http_method; content:"/install/namuvpn32.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754340/; classtype:trojan-activity;sid:84617440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754331)"; flow:established,from_client; content:"GET"; http_method; content:"/pc/pdfconvert/"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"download.pdf00.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754331/; classtype:trojan-activity;sid:84617431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754327)"; flow:established,from_client; content:"GET"; http_method; content:"/install/namu864.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754327/; classtype:trojan-activity;sid:84617427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754328)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpn32.zip"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754328/; classtype:trojan-activity;sid:84617428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754325)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpnx2/namuvpnx2.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754325/; classtype:trojan-activity;sid:84617425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754299)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"46.151.56.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754299/; classtype:trojan-activity;sid:84617399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754282)"; flow:established,from_client; content:"GET"; http_method; content:"/install/namuxp.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754282/; classtype:trojan-activity;sid:84617382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754276)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"91.147.91.21"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754276/; classtype:trojan-activity;sid:84617376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754274)"; flow:established,from_client; content:"GET"; http_method; content:"/install/namuvpn7.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754274/; classtype:trojan-activity;sid:84617374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754262)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpn7.zip"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754262/; classtype:trojan-activity;sid:84617362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754238)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpn7/namuvpn7.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754238/; classtype:trojan-activity;sid:84617338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754224)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"78.90.248.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754224/; classtype:trojan-activity;sid:84617324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754218)"; flow:established,from_client; content:"GET"; http_method; content:"/install/back/namuvpn32.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754218/; classtype:trojan-activity;sid:84617318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754194)"; flow:established,from_client; content:"GET"; http_method; content:"/cryptodata/archive_to_send_decr.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"122.170.110.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754194/; classtype:trojan-activity;sid:84617294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3754170)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"115.127.68.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3754170/; classtype:trojan-activity;sid:84617270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3753765)"; flow:established,from_client; content:"GET"; http_method; content:"/big/img001.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_09; reference:url, urlhaus.abuse.ch/url/3753765/; classtype:trojan-activity;sid:84616865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3750931)"; flow:established,from_client; content:"GET"; http_method; content:"/1q1q.js"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"scrroeder.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_05; reference:url, urlhaus.abuse.ch/url/3750931/; classtype:trojan-activity;sid:84614031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3750631)"; flow:established,from_client; content:"GET"; http_method; content:"/security/wizvera/delfino-g3/delfino-g3.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"download.kbcard.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2026_01_05; reference:url, urlhaus.abuse.ch/url/3750631/; classtype:trojan-activity;sid:84613731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3749775)"; flow:established,from_client; content:"GET"; http_method; content:"/buding/dbghelp.dll"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"59.56.110.227"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_03; reference:url, urlhaus.abuse.ch/url/3749775/; classtype:trojan-activity;sid:84612875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3749771)"; flow:established,from_client; content:"GET"; http_method; content:"/buding/dbghelp.dll"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"45.125.44.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_03; reference:url, urlhaus.abuse.ch/url/3749771/; classtype:trojan-activity;sid:84612871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3749167)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"188.134.8.43"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_02; reference:url, urlhaus.abuse.ch/url/3749167/; classtype:trojan-activity;sid:84612267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748326)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"162.215.130.152"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748326/; classtype:trojan-activity;sid:84611426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748285)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"104.199.248.167"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748285/; classtype:trojan-activity;sid:84611385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748279)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"199.168.184.115"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748279/; classtype:trojan-activity;sid:84611379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748275)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"202.74.75.181"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748275/; classtype:trojan-activity;sid:84611375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748253)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"199.168.184.115"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748253/; classtype:trojan-activity;sid:84611353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748255)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"69.48.143.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748255/; classtype:trojan-activity;sid:84611355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748235)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"18.176.47.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748235/; classtype:trojan-activity;sid:84611335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748227)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"34.23.45.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748227/; classtype:trojan-activity;sid:84611327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748204)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"5.35.124.133"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748204/; classtype:trojan-activity;sid:84611304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748194)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"98.70.13.131"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748194/; classtype:trojan-activity;sid:84611294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748189)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"5.63.157.201"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748189/; classtype:trojan-activity;sid:84611289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748180)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"185.80.0.36"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748180/; classtype:trojan-activity;sid:84611280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748175)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"125.253.125.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748175/; classtype:trojan-activity;sid:84611275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748170)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"125.253.125.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748170/; classtype:trojan-activity;sid:84611270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748152)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"209.250.2.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748152/; classtype:trojan-activity;sid:84611252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748150)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"34.23.45.74"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748150/; classtype:trojan-activity;sid:84611250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748140)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"108.61.166.232"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748140/; classtype:trojan-activity;sid:84611240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748137)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"209.250.2.244"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748137/; classtype:trojan-activity;sid:84611237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748134)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"45.77.254.180"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748134/; classtype:trojan-activity;sid:84611234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748127)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"150.95.27.35"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748127/; classtype:trojan-activity;sid:84611227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748131)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"173.231.196.249"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748131/; classtype:trojan-activity;sid:84611231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748133)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"162.215.130.152"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748133/; classtype:trojan-activity;sid:84611233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748104)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"18.176.47.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748104/; classtype:trojan-activity;sid:84611204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748105)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"96.125.189.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748105/; classtype:trojan-activity;sid:84611205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748110)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"44.208.147.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748110/; classtype:trojan-activity;sid:84611210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748112)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"95.154.194.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748112/; classtype:trojan-activity;sid:84611212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748115)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"192.155.93.247"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748115/; classtype:trojan-activity;sid:84611215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748118)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"35.75.68.158"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748118/; classtype:trojan-activity;sid:84611218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748119)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"35.226.92.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748119/; classtype:trojan-activity;sid:84611219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748096)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"164.160.41.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748096/; classtype:trojan-activity;sid:84611196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748066)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"185.4.64.128"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748066/; classtype:trojan-activity;sid:84611166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748069)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"178.210.83.9"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748069/; classtype:trojan-activity;sid:84611169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748076)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"96.125.189.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748076/; classtype:trojan-activity;sid:84611176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748089)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"66.39.79.68"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748089/; classtype:trojan-activity;sid:84611189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748092)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"148.113.205.94"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748092/; classtype:trojan-activity;sid:84611192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3748026)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"180.149.198.22"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3748026/; classtype:trojan-activity;sid:84611126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747725)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/video.lnk"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"58.182.146.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747725/; classtype:trojan-activity;sid:84610825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747694)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/photo.scr"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"58.182.146.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747694/; classtype:trojan-activity;sid:84610794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747690)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/av.lnk"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"58.182.146.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747690/; classtype:trojan-activity;sid:84610790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747685)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/video.scr"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"58.182.146.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747685/; classtype:trojan-activity;sid:84610785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747686)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/av.scr"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"58.182.146.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747686/; classtype:trojan-activity;sid:84610786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3747684)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/photo.lnk"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"58.182.146.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2026_01_01; reference:url, urlhaus.abuse.ch/url/3747684/; classtype:trojan-activity;sid:84610784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3746316)"; flow:established,from_client; content:"GET"; http_method; content:"/sxp/i/522f8dbab717f669a06afa9122107971.js"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"ob.youstarsbuilding.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_12_30; reference:url, urlhaus.abuse.ch/url/3746316/; classtype:trojan-activity;sid:84609416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3746314)"; flow:established,from_client; content:"GET"; http_method; content:"/sxp/i/522f8dbab717f669a06afa9122107971.js"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"euob.youstarsbuilding.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_12_30; reference:url, urlhaus.abuse.ch/url/3746314/; classtype:trojan-activity;sid:84609414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745192)"; flow:established,from_client; content:"GET"; http_method; content:"/20210408/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745192/; classtype:trojan-activity;sid:84608292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3745193)"; flow:established,from_client; content:"GET"; http_method; content:"/20210408/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_28; reference:url, urlhaus.abuse.ch/url/3745193/; classtype:trojan-activity;sid:84608293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3743405)"; flow:established,from_client; content:"GET"; http_method; content:"/sxp/i/522f8dbab717f669a06afa9122107971.js"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"euob.youstarsbuilding.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_12_25; reference:url, urlhaus.abuse.ch/url/3743405/; classtype:trojan-activity;sid:84606505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3743323)"; flow:established,from_client; content:"GET"; http_method; content:"/files/plugins/sess1594985553/sessiontools/uvsodsae.msi"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"royalindiancurryclub.com"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2025_12_25; reference:url, urlhaus.abuse.ch/url/3743323/; classtype:trojan-activity;sid:84606423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742020)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742020/; classtype:trojan-activity;sid:84605120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742013)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742013/; classtype:trojan-activity;sid:84605113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742007)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742007/; classtype:trojan-activity;sid:84605107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3742005)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3742005/; classtype:trojan-activity;sid:84605105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741991)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741991/; classtype:trojan-activity;sid:84605091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741975)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741975/; classtype:trojan-activity;sid:84605075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741976)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"183.83.186.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741976/; classtype:trojan-activity;sid:84605076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741974)"; flow:established,from_client; content:"GET"; http_method; content:"/20250101/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741974/; classtype:trojan-activity;sid:84605074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741972)"; flow:established,from_client; content:"GET"; http_method; content:"/20250101/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741972/; classtype:trojan-activity;sid:84605072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741971)"; flow:established,from_client; content:"GET"; http_method; content:"/20250101/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741971/; classtype:trojan-activity;sid:84605071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741968)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"106.54.220.107"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741968/; classtype:trojan-activity;sid:84605068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741966)"; flow:established,from_client; content:"GET"; http_method; content:"/20250811/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741966/; classtype:trojan-activity;sid:84605066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741967)"; flow:established,from_client; content:"GET"; http_method; content:"/20250809/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741967/; classtype:trojan-activity;sid:84605067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741965)"; flow:established,from_client; content:"GET"; http_method; content:"/20210408/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741965/; classtype:trojan-activity;sid:84605065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741962)"; flow:established,from_client; content:"GET"; http_method; content:"/20210408/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741962/; classtype:trojan-activity;sid:84605062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741963)"; flow:established,from_client; content:"GET"; http_method; content:"/20250101/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_24; reference:url, urlhaus.abuse.ch/url/3741963/; classtype:trojan-activity;sid:84605063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741523)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.187.54.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741523/; classtype:trojan-activity;sid:84604623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741524)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.187.54.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741524/; classtype:trojan-activity;sid:84604624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741336)"; flow:established,from_client; content:"GET"; http_method; content:"/files/auhavkiq.msi"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"royalindiancurryclub.com"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741336/; classtype:trojan-activity;sid:84604436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741193)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"152.230.111.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741193/; classtype:trojan-activity;sid:84604293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741153)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"152.230.111.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741153/; classtype:trojan-activity;sid:84604253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741068)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"152.230.111.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741068/; classtype:trojan-activity;sid:84604168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741029)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"182.163.114.232"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741029/; classtype:trojan-activity;sid:84604129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3741026)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"152.230.111.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3741026/; classtype:trojan-activity;sid:84604126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3740979)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"152.230.111.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3740979/; classtype:trojan-activity;sid:84604079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3740945)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"152.230.111.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_23; reference:url, urlhaus.abuse.ch/url/3740945/; classtype:trojan-activity;sid:84604045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3738164)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.55.81.169"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_12_20; reference:url, urlhaus.abuse.ch/url/3738164/; classtype:trojan-activity;sid:84601264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3736211)"; flow:established,from_client; content:"GET"; http_method; content:"/atom.xml"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"hotelsep.blogspot.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_18; reference:url, urlhaus.abuse.ch/url/3736211/; classtype:trojan-activity;sid:84599311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3736212)"; flow:established,from_client; content:"GET"; http_method; content:"/nimper.pdf"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"www.backupallfresh2030.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_12_18; reference:url, urlhaus.abuse.ch/url/3736212/; classtype:trojan-activity;sid:84599312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3735417)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"107.189.6.236"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_17; reference:url, urlhaus.abuse.ch/url/3735417/; classtype:trojan-activity;sid:84598517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3734700)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.6.196.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_16; reference:url, urlhaus.abuse.ch/url/3734700/; classtype:trojan-activity;sid:84597800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3733913)"; flow:established,from_client; content:"GET"; http_method; content:"/usr/uploads/file/202002/20200210195059_78353.rar"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"zhigao5191.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_15; reference:url, urlhaus.abuse.ch/url/3733913/; classtype:trojan-activity;sid:84597013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3733907)"; flow:established,from_client; content:"GET"; http_method; content:"/editor%e6%b1%89%e5%8c%96%e7%89%88.rar"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"zycdjz.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_15; reference:url, urlhaus.abuse.ch/url/3733907/; classtype:trojan-activity;sid:84597007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3733819)"; flow:established,from_client; content:"GET"; http_method; content:"/liljaber/am/raw/refs/heads/main/shellhost.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_15; reference:url, urlhaus.abuse.ch/url/3733819/; classtype:trojan-activity;sid:84596919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732386)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"217.75.193.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732386/; classtype:trojan-activity;sid:84595486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732378)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"93.39.215.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732378/; classtype:trojan-activity;sid:84595478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732133)"; flow:established,from_client; content:"GET"; http_method; content:"/eathena/tools/bymyzter/eabackup.rar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"paradox924x.pages.dev"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732133/; classtype:trojan-activity;sid:84595233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3732129)"; flow:established,from_client; content:"GET"; http_method; content:"/eathena/tools/bybakausagi/spr_conview_v0.11.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"paradox924x.pages.dev"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_12; reference:url, urlhaus.abuse.ch/url/3732129/; classtype:trojan-activity;sid:84595229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731286)"; flow:established,from_client; content:"GET"; http_method; content:"/nalleysh/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731286/; classtype:trojan-activity;sid:84594386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731287)"; flow:established,from_client; content:"GET"; http_method; content:"/el1nns/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731287/; classtype:trojan-activity;sid:84594387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731283)"; flow:established,from_client; content:"GET"; http_method; content:"/d3xxth/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731283/; classtype:trojan-activity;sid:84594383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731275)"; flow:established,from_client; content:"GET"; http_method; content:"/creyty1h/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731275/; classtype:trojan-activity;sid:84594375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731271)"; flow:established,from_client; content:"GET"; http_method; content:"/v1llenth/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731271/; classtype:trojan-activity;sid:84594371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731257)"; flow:established,from_client; content:"GET"; http_method; content:"/rayn1e/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731257/; classtype:trojan-activity;sid:84594357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731244)"; flow:established,from_client; content:"GET"; http_method; content:"/colleshake/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731244/; classtype:trojan-activity;sid:84594344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731243)"; flow:established,from_client; content:"GET"; http_method; content:"/arcellys/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731243/; classtype:trojan-activity;sid:84594343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731242)"; flow:established,from_client; content:"GET"; http_method; content:"/n1elcery/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731242/; classtype:trojan-activity;sid:84594342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731239)"; flow:established,from_client; content:"GET"; http_method; content:"/recctan1o/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731239/; classtype:trojan-activity;sid:84594339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731238)"; flow:established,from_client; content:"GET"; http_method; content:"/kesslyy27/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731238/; classtype:trojan-activity;sid:84594338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731232)"; flow:established,from_client; content:"GET"; http_method; content:"/ssten1/temp-spoofer-lifetime/raw/refs/heads/main/tempspoofer.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731232/; classtype:trojan-activity;sid:84594332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3731096)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"114.242.100.72"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3731096/; classtype:trojan-activity;sid:84594196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730787)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730787/; classtype:trojan-activity;sid:84593887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730785)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730785/; classtype:trojan-activity;sid:84593885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730754)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730754/; classtype:trojan-activity;sid:84593854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730727)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730727/; classtype:trojan-activity;sid:84593827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730681)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730681/; classtype:trojan-activity;sid:84593781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730669)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730669/; classtype:trojan-activity;sid:84593769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3730651)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.187.227.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_10; reference:url, urlhaus.abuse.ch/url/3730651/; classtype:trojan-activity;sid:84593751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3729248)"; flow:established,from_client; content:"GET"; http_method; content:"/static/clean/clean.apk"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"static.youdm.cn"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_08; reference:url, urlhaus.abuse.ch/url/3729248/; classtype:trojan-activity;sid:84592348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3729188)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"86.89.95.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_12_08; reference:url, urlhaus.abuse.ch/url/3729188/; classtype:trojan-activity;sid:84592288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3726005)"; flow:established,from_client; content:"GET"; http_method; content:"/receipt_11_26_2025.msi"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"alineeleuterio.com.br"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_12_05; reference:url, urlhaus.abuse.ch/url/3726005/; classtype:trojan-activity;sid:84589105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3725201)"; flow:established,from_client; content:"GET"; http_method; content:"/file/redmi%20ax3000/%e8%b7%af%e7%94%b1%e5%99%a8%e4%bf%ae%e5%a4%8d%e5%b7%a5%e5%85%b7/miwifirepairtool.x86.zip"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"hzxcaq-github-io.pages.dev"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3725201/; classtype:trojan-activity;sid:84588301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724888)"; flow:established,from_client; content:"GET"; http_method; content:"/gretech/promotion_sw/gomplayer/fastping_silent_v4.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"cdn.gomlab.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3724888/; classtype:trojan-activity;sid:84587988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724884)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/linux/linux.tar.gz"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"miner.pages.dev"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3724884/; classtype:trojan-activity;sid:84587984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724883)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/win/miner.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"miner.pages.dev"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_04; reference:url, urlhaus.abuse.ch/url/3724883/; classtype:trojan-activity;sid:84587983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3724034)"; flow:established,from_client; content:"GET"; http_method; content:"/res/keditor/2019_11/3c7a829a_893c_4f02_a407_6b0918c321c2.rar"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"en.taichuan.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_12_03; reference:url, urlhaus.abuse.ch/url/3724034/; classtype:trojan-activity;sid:84587134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3722385)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"138.219.58.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_12_01; reference:url, urlhaus.abuse.ch/url/3722385/; classtype:trojan-activity;sid:84585485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3722069)"; flow:established,from_client; content:"GET"; http_method; content:"/app/top8bet.apk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"top8onlinegame.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2025_12_01; reference:url, urlhaus.abuse.ch/url/3722069/; classtype:trojan-activity;sid:84585169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3721052)"; flow:established,from_client; content:"GET"; http_method; content:"/download/%e5%a5%87%e5%a6%99%e5%8a%a0%e9%80%9f%e5%99%a8_2_10004379.exe/%c3%a5%c2%a5%c2%87%c3%a5%c2%a6%c2%99%c3%a5%c2%8a%c2%a0%c3%a9%c2%80%c2%9f%c3%a5%c2%99%c2%a8_2_10004379.exe/%c3%83%c2%a5%c3%82%c2%a5%c3%82%c2%87%c3%83%c2%a5%c3%82%c2%a6%c3%82%c2%99%c3%83%25...~311~...%ef%bf%bd%c3%82%c2%a8_2_10004379.exe"; http_uri; depth:305; isdataat:!1,relative; nocase; content:"pvsa.gxfugy.cn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_30; reference:url, urlhaus.abuse.ch/url/3721052/; classtype:trojan-activity;sid:84584152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720416)"; flow:established,from_client; content:"GET"; http_method; content:"/payment_receipt_11_28_2025.msi"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"vizyonuniversitesi.com.tr"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720416/; classtype:trojan-activity;sid:84583516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720339)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720339/; classtype:trojan-activity;sid:84583439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720337)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720337/; classtype:trojan-activity;sid:84583437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720336)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/av.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720336/; classtype:trojan-activity;sid:84583436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720335)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720335/; classtype:trojan-activity;sid:84583435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720330)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/video.scr"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720330/; classtype:trojan-activity;sid:84583430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720331)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/av.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720331/; classtype:trojan-activity;sid:84583431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720332)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720332/; classtype:trojan-activity;sid:84583432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720333)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/photo.scr"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720333/; classtype:trojan-activity;sid:84583433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720334)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720334/; classtype:trojan-activity;sid:84583434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720329)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/photo.lnk"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720329/; classtype:trojan-activity;sid:84583429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720327)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720327/; classtype:trojan-activity;sid:84583427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720328)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/video.lnk"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720328/; classtype:trojan-activity;sid:84583428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720042)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"31.0.222.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720042/; classtype:trojan-activity;sid:84583142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3720037)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"31.0.222.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3720037/; classtype:trojan-activity;sid:84583137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3719973)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"31.0.222.123"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_29; reference:url, urlhaus.abuse.ch/url/3719973/; classtype:trojan-activity;sid:84583073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717885)"; flow:established,from_client; content:"GET"; http_method; content:"/apps/cpc188.apk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"cpc188.day"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717885/; classtype:trojan-activity;sid:84580985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717880)"; flow:established,from_client; content:"GET"; http_method; content:"/newwfs/support/customfont.apk"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"upaicdn.xinmei365.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717880/; classtype:trojan-activity;sid:84580980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717867)"; flow:established,from_client; content:"GET"; http_method; content:"/download/adan/utils/mudtime.zip"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"paccbet.pages.dev"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717867/; classtype:trojan-activity;sid:84580967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717692)"; flow:established,from_client; content:"GET"; http_method; content:"/safe/setup_smart.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"dl.ijinshan.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_27; reference:url, urlhaus.abuse.ch/url/3717692/; classtype:trojan-activity;sid:84580792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3717290)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"111.185.171.111"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_26; reference:url, urlhaus.abuse.ch/url/3717290/; classtype:trojan-activity;sid:84580390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3716961)"; flow:established,from_client; content:"GET"; http_method; content:"/krzysztofadamczewski/nanocore-rat/raw/refs/heads/master/nanocore_portable.exe"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_26; reference:url, urlhaus.abuse.ch/url/3716961/; classtype:trojan-activity;sid:84580061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3716962)"; flow:established,from_client; content:"GET"; http_method; content:"/pafh99/nanocore-rat-2/raw/refs/heads/master/nanocore_portable.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_26; reference:url, urlhaus.abuse.ch/url/3716962/; classtype:trojan-activity;sid:84580062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3716290)"; flow:established,from_client; content:"GET"; http_method; content:"/baixar/suporte%20winxp-7-8.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"compuserviceonline.com.br"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_11_25; reference:url, urlhaus.abuse.ch/url/3716290/; classtype:trojan-activity;sid:84579390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715638)"; flow:established,from_client; content:"GET"; http_method; content:"/37/cqsj/official/37cqsj.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"d.wanyouxi7.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_24; reference:url, urlhaus.abuse.ch/url/3715638/; classtype:trojan-activity;sid:84578738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715587)"; flow:established,from_client; content:"GET"; http_method; content:"/elc/filesave/setupfile/edmslaunchersetup.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"lcportal.kbinsure.co.kr"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_24; reference:url, urlhaus.abuse.ch/url/3715587/; classtype:trojan-activity;sid:84578687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715579)"; flow:established,from_client; content:"GET"; http_method; content:"/dropfix"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"cdn.novoline.top"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_11_24; reference:url, urlhaus.abuse.ch/url/3715579/; classtype:trojan-activity;sid:84578679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3715175)"; flow:established,from_client; content:"GET"; http_method; content:"/fo-wsftp605.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"landonirwin.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_23; reference:url, urlhaus.abuse.ch/url/3715175/; classtype:trojan-activity;sid:84578275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3714635)"; flow:established,from_client; content:"GET"; http_method; content:"/app/linux.bin"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"prepstarcenter.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2025_11_23; reference:url, urlhaus.abuse.ch/url/3714635/; classtype:trojan-activity;sid:84577735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3714116)"; flow:established,from_client; content:"GET"; http_method; content:"/wizvera/delfino/down/delfino-g3-sha2.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"www.hwgeneralins.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_11_22; reference:url, urlhaus.abuse.ch/url/3714116/; classtype:trojan-activity;sid:84577216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3714095)"; flow:established,from_client; content:"GET"; http_method; content:"/k1_351.apk"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"app.appzcvb.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_22; reference:url, urlhaus.abuse.ch/url/3714095/; classtype:trojan-activity;sid:84577195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713850)"; flow:established,from_client; content:"GET"; http_method; content:"/cleaner"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"gutando.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_22; reference:url, urlhaus.abuse.ch/url/3713850/; classtype:trojan-activity;sid:84576950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713493)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.190.74.159"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713493/; classtype:trojan-activity;sid:84576593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713469)"; flow:established,from_client; content:"GET"; http_method; content:"/stage1.ps1"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"fb6390d5.infinityindians.pages.dev"; http_host; depth:34; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713469/; classtype:trojan-activity;sid:84576569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713470)"; flow:established,from_client; content:"GET"; http_method; content:"/amsibypass.ps1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"fb6390d5.infinityindians.pages.dev"; http_host; depth:34; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713470/; classtype:trojan-activity;sid:84576570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3713467)"; flow:established,from_client; content:"GET"; http_method; content:"/files/bexitor%20installer.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"matthewsigmondv5.pages.dev"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_11_21; reference:url, urlhaus.abuse.ch/url/3713467/; classtype:trojan-activity;sid:84576567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712881)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.19.130.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712881/; classtype:trojan-activity;sid:84575981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712796)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712796/; classtype:trojan-activity;sid:84575896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712795)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712795/; classtype:trojan-activity;sid:84575895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712793)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712793/; classtype:trojan-activity;sid:84575893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712794)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/video.scr"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712794/; classtype:trojan-activity;sid:84575894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712791)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/photo.scr"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712791/; classtype:trojan-activity;sid:84575891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712792)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/av.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712792/; classtype:trojan-activity;sid:84575892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712790)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712790/; classtype:trojan-activity;sid:84575890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712787)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/av.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712787/; classtype:trojan-activity;sid:84575887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712788)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712788/; classtype:trojan-activity;sid:84575888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712789)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/photo.lnk"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712789/; classtype:trojan-activity;sid:84575889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712785)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/mom/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712785/; classtype:trojan-activity;sid:84575885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712786)"; flow:established,from_client; content:"GET"; http_method; content:"/sda1/rachel/video.lnk"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"27.125.169.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712786/; classtype:trojan-activity;sid:84575886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712393)"; flow:established,from_client; content:"GET"; http_method; content:"/d/gof.com.my/gz2v8w/y0qt8nphhv1v"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"smartermail.host"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_11_20; reference:url, urlhaus.abuse.ch/url/3712393/; classtype:trojan-activity;sid:84575493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3712017)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/horioninjector.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"horion-static.pages.dev"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_11_19; reference:url, urlhaus.abuse.ch/url/3712017/; classtype:trojan-activity;sid:84575117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710456)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/screenconnect.clientsetup.msi"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"rheddh.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710456/; classtype:trojan-activity;sid:84573556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710207)"; flow:established,from_client; content:"GET"; http_method; content:"/offlinepackv4.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"dl.360safe.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_17; reference:url, urlhaus.abuse.ch/url/3710207/; classtype:trojan-activity;sid:84573307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710011)"; flow:established,from_client; content:"GET"; http_method; content:"/soulclientwtf/lnk/raw/refs/heads/main/execute"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_16; reference:url, urlhaus.abuse.ch/url/3710011/; classtype:trojan-activity;sid:84573111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3710010)"; flow:established,from_client; content:"GET"; http_method; content:"/soulclientwtf/lnk/refs/heads/main/execute"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_11_16; reference:url, urlhaus.abuse.ch/url/3710010/; classtype:trojan-activity;sid:84573110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3708402)"; flow:established,from_client; content:"GET"; http_method; content:"/ourzz.wav"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"clubdetiroelpicarcho.com"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3708402/; classtype:trojan-activity;sid:84571502; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3707697)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2019/04/pieletjf.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"theoremaoliveoil.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3707697/; classtype:trojan-activity;sid:84570797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3707699)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2019/04/pieletjf_vm.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"theoremaoliveoil.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_11_14; reference:url, urlhaus.abuse.ch/url/3707699/; classtype:trojan-activity;sid:84570799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704246)"; flow:established,from_client; content:"GET"; http_method; content:"/haozip/haozip_v6.5.2.11245.exe"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"dl.2345.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704246/; classtype:trojan-activity;sid:84567346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3704158)"; flow:established,from_client; content:"GET"; http_method; content:"/leinchchanceleinch/jik/raw/refs/heads/main/dev.msi"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_11_13; reference:url, urlhaus.abuse.ch/url/3704158/; classtype:trojan-activity;sid:84567258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703801)"; flow:established,from_client; content:"GET"; http_method; content:"/20220623/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703801/; classtype:trojan-activity;sid:84566901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703764)"; flow:established,from_client; content:"GET"; http_method; content:"/20180102/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703764/; classtype:trojan-activity;sid:84566864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3703731)"; flow:established,from_client; content:"GET"; http_method; content:"/20140730/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_12; reference:url, urlhaus.abuse.ch/url/3703731/; classtype:trojan-activity;sid:84566831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702746)"; flow:established,from_client; content:"GET"; http_method; content:"/dersnotlari/02/sora.jpg"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"www.notbak.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_11; reference:url, urlhaus.abuse.ch/url/3702746/; classtype:trojan-activity;sid:84565846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702204)"; flow:established,from_client; content:"GET"; http_method; content:"/20230517/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702204/; classtype:trojan-activity;sid:84565304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702202)"; flow:established,from_client; content:"GET"; http_method; content:"/20250210/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702202/; classtype:trojan-activity;sid:84565302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702201)"; flow:established,from_client; content:"GET"; http_method; content:"/20250309/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702201/; classtype:trojan-activity;sid:84565301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702199)"; flow:established,from_client; content:"GET"; http_method; content:"/20230517/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702199/; classtype:trojan-activity;sid:84565299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702178)"; flow:established,from_client; content:"GET"; http_method; content:"/20240113/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702178/; classtype:trojan-activity;sid:84565278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702166)"; flow:established,from_client; content:"GET"; http_method; content:"/20240113/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702166/; classtype:trojan-activity;sid:84565266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702161)"; flow:established,from_client; content:"GET"; http_method; content:"/20140730/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702161/; classtype:trojan-activity;sid:84565261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702156)"; flow:established,from_client; content:"GET"; http_method; content:"/20250416/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702156/; classtype:trojan-activity;sid:84565256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702157)"; flow:established,from_client; content:"GET"; http_method; content:"/20230517/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702157/; classtype:trojan-activity;sid:84565257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702158)"; flow:established,from_client; content:"GET"; http_method; content:"/20250309/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702158/; classtype:trojan-activity;sid:84565258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702152)"; flow:established,from_client; content:"GET"; http_method; content:"/20250309/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702152/; classtype:trojan-activity;sid:84565252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702147)"; flow:established,from_client; content:"GET"; http_method; content:"/20230517/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702147/; classtype:trojan-activity;sid:84565247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702142)"; flow:established,from_client; content:"GET"; http_method; content:"/20250309/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702142/; classtype:trojan-activity;sid:84565242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702143)"; flow:established,from_client; content:"GET"; http_method; content:"/20250210/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702143/; classtype:trojan-activity;sid:84565243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702134)"; flow:established,from_client; content:"GET"; http_method; content:"/20250416/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702134/; classtype:trojan-activity;sid:84565234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702135)"; flow:established,from_client; content:"GET"; http_method; content:"/20230517/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702135/; classtype:trojan-activity;sid:84565235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702136)"; flow:established,from_client; content:"GET"; http_method; content:"/20220623/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702136/; classtype:trojan-activity;sid:84565236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702130)"; flow:established,from_client; content:"GET"; http_method; content:"/20220623/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702130/; classtype:trojan-activity;sid:84565230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702131)"; flow:established,from_client; content:"GET"; http_method; content:"/20250416/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702131/; classtype:trojan-activity;sid:84565231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702132)"; flow:established,from_client; content:"GET"; http_method; content:"/20220623/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702132/; classtype:trojan-activity;sid:84565232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702127)"; flow:established,from_client; content:"GET"; http_method; content:"/20180102/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702127/; classtype:trojan-activity;sid:84565227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702128)"; flow:established,from_client; content:"GET"; http_method; content:"/20240113/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702128/; classtype:trojan-activity;sid:84565228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702122)"; flow:established,from_client; content:"GET"; http_method; content:"/20220623/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702122/; classtype:trojan-activity;sid:84565222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702123)"; flow:established,from_client; content:"GET"; http_method; content:"/20240113/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702123/; classtype:trojan-activity;sid:84565223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702121)"; flow:established,from_client; content:"GET"; http_method; content:"/20180102/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702121/; classtype:trojan-activity;sid:84565221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702119)"; flow:established,from_client; content:"GET"; http_method; content:"/20250210/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702119/; classtype:trojan-activity;sid:84565219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702115)"; flow:established,from_client; content:"GET"; http_method; content:"/20140730/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702115/; classtype:trojan-activity;sid:84565215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702105)"; flow:established,from_client; content:"GET"; http_method; content:"/20250210/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702105/; classtype:trojan-activity;sid:84565205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702102)"; flow:established,from_client; content:"GET"; http_method; content:"/20240113/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702102/; classtype:trojan-activity;sid:84565202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3702103)"; flow:established,from_client; content:"GET"; http_method; content:"/20220623/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3702103/; classtype:trojan-activity;sid:84565203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701934)"; flow:established,from_client; content:"GET"; http_method; content:"/20180102/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701934/; classtype:trojan-activity;sid:84565034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701924)"; flow:established,from_client; content:"GET"; http_method; content:"/20140730/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701924/; classtype:trojan-activity;sid:84565024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701905)"; flow:established,from_client; content:"GET"; http_method; content:"/20180102/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701905/; classtype:trojan-activity;sid:84565005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701906)"; flow:established,from_client; content:"GET"; http_method; content:"/20180102/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_10; reference:url, urlhaus.abuse.ch/url/3701906/; classtype:trojan-activity;sid:84565006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3701320)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"144.2.111.169"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_09; reference:url, urlhaus.abuse.ch/url/3701320/; classtype:trojan-activity;sid:84564420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700329)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700329/; classtype:trojan-activity;sid:84563429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700268)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"36.158.34.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700268/; classtype:trojan-activity;sid:84563368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700199)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700199/; classtype:trojan-activity;sid:84563299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700187)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"36.158.34.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700187/; classtype:trojan-activity;sid:84563287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3700112)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3700112/; classtype:trojan-activity;sid:84563212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699967)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"119.91.141.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699967/; classtype:trojan-activity;sid:84563067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699839)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699839/; classtype:trojan-activity;sid:84562939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699768)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699768/; classtype:trojan-activity;sid:84562868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699681)"; flow:established,from_client; content:"GET"; http_method; content:"/tinh_cuoc_xe/2025/thanh%20ti%c3%aan/info.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"103.226.249.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699681/; classtype:trojan-activity;sid:84562781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699651)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699651/; classtype:trojan-activity;sid:84562751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3699578)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"190.196.38.77"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_08; reference:url, urlhaus.abuse.ch/url/3699578/; classtype:trojan-activity;sid:84562678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698410)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"59.110.28.230"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698410/; classtype:trojan-activity;sid:84561510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698078)"; flow:established,from_client; content:"GET"; http_method; content:"/20250309/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698078/; classtype:trojan-activity;sid:84561178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698077)"; flow:established,from_client; content:"GET"; http_method; content:"/20140730/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698077/; classtype:trojan-activity;sid:84561177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698067)"; flow:established,from_client; content:"GET"; http_method; content:"/20230517/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698067/; classtype:trojan-activity;sid:84561167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698070)"; flow:established,from_client; content:"GET"; http_method; content:"/20250210/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698070/; classtype:trojan-activity;sid:84561170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698062)"; flow:established,from_client; content:"GET"; http_method; content:"/20250210/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698062/; classtype:trojan-activity;sid:84561162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698059)"; flow:established,from_client; content:"GET"; http_method; content:"/20140730/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698059/; classtype:trojan-activity;sid:84561159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698057)"; flow:established,from_client; content:"GET"; http_method; content:"/20250309/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698057/; classtype:trojan-activity;sid:84561157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3698058)"; flow:established,from_client; content:"GET"; http_method; content:"/20240113/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3698058/; classtype:trojan-activity;sid:84561158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697910)"; flow:established,from_client; content:"GET"; http_method; content:"/zddtxxyxb.zip"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"101.35.56.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697910/; classtype:trojan-activity;sid:84561010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697909)"; flow:established,from_client; content:"GET"; http_method; content:"/i24.bin"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"101.35.56.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697909/; classtype:trojan-activity;sid:84561009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697908)"; flow:established,from_client; content:"GET"; http_method; content:"/husk.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"101.35.56.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697908/; classtype:trojan-activity;sid:84561008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697907)"; flow:established,from_client; content:"GET"; http_method; content:"/eznoted2b1405e.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"101.35.56.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697907/; classtype:trojan-activity;sid:84561007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697906)"; flow:established,from_client; content:"GET"; http_method; content:"/without_hook.zip"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"101.35.56.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697906/; classtype:trojan-activity;sid:84561006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697870)"; flow:established,from_client; content:"GET"; http_method; content:"/husk.py"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"101.35.56.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697870/; classtype:trojan-activity;sid:84560970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697816)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.76.156.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697816/; classtype:trojan-activity;sid:84560916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3697809)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"36.158.34.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_06; reference:url, urlhaus.abuse.ch/url/3697809/; classtype:trojan-activity;sid:84560909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696992)"; flow:established,from_client; content:"GET"; http_method; content:"/a1l4m/2e771fb306028fabfc8e098427181f78/raw/37f3db6b29d64f1045fb60967d6297f525ddf443/iamthedanger.txt"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"gist.githubusercontent.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_11_05; reference:url, urlhaus.abuse.ch/url/3696992/; classtype:trojan-activity;sid:84560092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696132)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.147.155.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696132/; classtype:trojan-activity;sid:84559232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696133)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.147.155.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696133/; classtype:trojan-activity;sid:84559233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696129)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.147.155.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696129/; classtype:trojan-activity;sid:84559229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696082)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.76.156.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696082/; classtype:trojan-activity;sid:84559182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3696043)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"144.2.111.169"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3696043/; classtype:trojan-activity;sid:84559143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695955)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"76.94.199.139"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695955/; classtype:trojan-activity;sid:84559055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695920)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"76.94.199.139"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695920/; classtype:trojan-activity;sid:84559020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695898)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.147.155.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695898/; classtype:trojan-activity;sid:84558998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695884)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"76.94.199.139"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695884/; classtype:trojan-activity;sid:84558984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695875)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"76.94.199.139"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695875/; classtype:trojan-activity;sid:84558975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695868)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"119.91.141.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695868/; classtype:trojan-activity;sid:84558968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695854)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.76.156.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_04; reference:url, urlhaus.abuse.ch/url/3695854/; classtype:trojan-activity;sid:84558954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3695080)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"88.86.246.233"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_11_03; reference:url, urlhaus.abuse.ch/url/3695080/; classtype:trojan-activity;sid:84558180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3691195)"; flow:established,from_client; content:"GET"; http_method; content:"/4"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_30; reference:url, urlhaus.abuse.ch/url/3691195/; classtype:trojan-activity;sid:84554295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3690708)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.179.144.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_29; reference:url, urlhaus.abuse.ch/url/3690708/; classtype:trojan-activity;sid:84553808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3689700)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"62.197.62.195"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_28; reference:url, urlhaus.abuse.ch/url/3689700/; classtype:trojan-activity;sid:84552800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688692)"; flow:established,from_client; content:"GET"; http_method; content:"/xmr.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688692/; classtype:trojan-activity;sid:84551792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688690)"; flow:established,from_client; content:"GET"; http_method; content:"/newtpp.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688690/; classtype:trojan-activity;sid:84551790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688658)"; flow:established,from_client; content:"GET"; http_method; content:"/1"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688658/; classtype:trojan-activity;sid:84551758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688659)"; flow:established,from_client; content:"GET"; http_method; content:"/32.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688659/; classtype:trojan-activity;sid:84551759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688660)"; flow:established,from_client; content:"GET"; http_method; content:"/2"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.16.54.109"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_27; reference:url, urlhaus.abuse.ch/url/3688660/; classtype:trojan-activity;sid:84551760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3688125)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"87.247.202.34"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3688125/; classtype:trojan-activity;sid:84551225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3687916)"; flow:established,from_client; content:"GET"; http_method; content:"/y6m2uw0dgi.js"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"filerit.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3687916/; classtype:trojan-activity;sid:84551016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3687914)"; flow:established,from_client; content:"GET"; http_method; content:"/4aa9fqc792.ps1"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"pub-bfc34934a91a4893817098f73415917a.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3687914/; classtype:trojan-activity;sid:84551014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3687753)"; flow:established,from_client; content:"GET"; http_method; content:"/zibll001/ffff/refs/heads/main/web.sh"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_10_26; reference:url, urlhaus.abuse.ch/url/3687753/; classtype:trojan-activity;sid:84550853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3685141)"; flow:established,from_client; content:"GET"; http_method; content:"/var/albums/etkinlikler/toplanti/2013/soran.jpg.jpeg"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"galeri3.arkitera.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_10_24; reference:url, urlhaus.abuse.ch/url/3685141/; classtype:trojan-activity;sid:84548241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3683567)"; flow:established,from_client; content:"GET"; http_method; content:"/onastroll-2000f5n/5vcye/releases/download/v1.2/launcher.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_10_22; reference:url, urlhaus.abuse.ch/url/3683567/; classtype:trojan-activity;sid:84546667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3682316)"; flow:established,from_client; content:"GET"; http_method; content:"/wheatw.pfm"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"tehnomag.rs"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_20; reference:url, urlhaus.abuse.ch/url/3682316/; classtype:trojan-activity;sid:84545416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3682317)"; flow:established,from_client; content:"GET"; http_method; content:"/wheatw.pfm"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"tehnomag.rs"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_20; reference:url, urlhaus.abuse.ch/url/3682317/; classtype:trojan-activity;sid:84545417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3681019)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.90.248.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_18; reference:url, urlhaus.abuse.ch/url/3681019/; classtype:trojan-activity;sid:84544119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3680322)"; flow:established,from_client; content:"GET"; http_method; content:"/new/x64-setup.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"tapestryoftruth.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2025_10_18; reference:url, urlhaus.abuse.ch/url/3680322/; classtype:trojan-activity;sid:84543422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3679304)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"78.90.248.149"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_16; reference:url, urlhaus.abuse.ch/url/3679304/; classtype:trojan-activity;sid:84542404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3678940)"; flow:established,from_client; content:"GET"; http_method; content:"/prefiction.mp4"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"www.sgeseducation.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_10_15; reference:url, urlhaus.abuse.ch/url/3678940/; classtype:trojan-activity;sid:84542040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3678923)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"50.43.160.231"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_15; reference:url, urlhaus.abuse.ch/url/3678923/; classtype:trojan-activity;sid:84542023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3678015)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.234.234.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3678015/; classtype:trojan-activity;sid:84541115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3677999)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"109.25.123.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_14; reference:url, urlhaus.abuse.ch/url/3677999/; classtype:trojan-activity;sid:84541099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3668647)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.24.0/xmrig-6.24.0-windows-x64.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_10_11; reference:url, urlhaus.abuse.ch/url/3668647/; classtype:trojan-activity;sid:84531747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667591)"; flow:established,from_client; content:"GET"; http_method; content:"/r-02-radiole/video.scr"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667591/; classtype:trojan-activity;sid:84530691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667586)"; flow:established,from_client; content:"GET"; http_method; content:"/r-02-radiole/av.scr"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667586/; classtype:trojan-activity;sid:84530686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667587)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667587/; classtype:trojan-activity;sid:84530687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667588)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667588/; classtype:trojan-activity;sid:84530688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667585)"; flow:established,from_client; content:"GET"; http_method; content:"/r-02-radiole/photo.scr"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667585/; classtype:trojan-activity;sid:84530685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667584)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667584/; classtype:trojan-activity;sid:84530684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3667582)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.red-81-42-249.staticip.rima-tde.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_10_10; reference:url, urlhaus.abuse.ch/url/3667582/; classtype:trojan-activity;sid:84530682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665802)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.76.156.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665802/; classtype:trojan-activity;sid:84528902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665803)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.76.156.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665803/; classtype:trojan-activity;sid:84528903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665799)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"130.185.193.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665799/; classtype:trojan-activity;sid:84528899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665796)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"75.144.208.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665796/; classtype:trojan-activity;sid:84528896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665788)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"75.144.208.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665788/; classtype:trojan-activity;sid:84528888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665779)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"75.144.208.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665779/; classtype:trojan-activity;sid:84528879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665767)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"87.227.140.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665767/; classtype:trojan-activity;sid:84528867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665760)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"210.91.88.90"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665760/; classtype:trojan-activity;sid:84528860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665742)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.103.203.106"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665742/; classtype:trojan-activity;sid:84528842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665733)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.26.174.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665733/; classtype:trojan-activity;sid:84528833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665715)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"126.23.203.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665715/; classtype:trojan-activity;sid:84528815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665712)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"130.185.193.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665712/; classtype:trojan-activity;sid:84528812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665709)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.133.96.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665709/; classtype:trojan-activity;sid:84528809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665699)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"130.185.193.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665699/; classtype:trojan-activity;sid:84528799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665692)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"155.2.213.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665692/; classtype:trojan-activity;sid:84528792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665677)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"81.133.96.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665677/; classtype:trojan-activity;sid:84528777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665674)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"155.2.213.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665674/; classtype:trojan-activity;sid:84528774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665669)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"87.227.140.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665669/; classtype:trojan-activity;sid:84528769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665664)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.147.155.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665664/; classtype:trojan-activity;sid:84528764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665656)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"130.185.193.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665656/; classtype:trojan-activity;sid:84528756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665611)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"87.227.140.66"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665611/; classtype:trojan-activity;sid:84528711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665612)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.147.155.189"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665612/; classtype:trojan-activity;sid:84528712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3665613)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"81.133.96.61"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_09; reference:url, urlhaus.abuse.ch/url/3665613/; classtype:trojan-activity;sid:84528713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3662805)"; flow:established,from_client; content:"GET"; http_method; content:"/asmroyal/cd4/releases/download/cd4/cd4.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_10_07; reference:url, urlhaus.abuse.ch/url/3662805/; classtype:trojan-activity;sid:84525905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3661435)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1afutsiefohaia02gkfjdbgn-kk91hksb"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_10_07; reference:url, urlhaus.abuse.ch/url/3661435/; classtype:trojan-activity;sid:84524535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660738)"; flow:established,from_client; content:"GET"; http_method; content:"/20250302/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660738/; classtype:trojan-activity;sid:84523838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660696)"; flow:established,from_client; content:"GET"; http_method; content:"/20250708/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660696/; classtype:trojan-activity;sid:84523796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660690)"; flow:established,from_client; content:"GET"; http_method; content:"/20250408/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660690/; classtype:trojan-activity;sid:84523790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660688)"; flow:established,from_client; content:"GET"; http_method; content:"/20250724/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660688/; classtype:trojan-activity;sid:84523788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660680)"; flow:established,from_client; content:"GET"; http_method; content:"/20221020/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660680/; classtype:trojan-activity;sid:84523780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660679)"; flow:established,from_client; content:"GET"; http_method; content:"/20250408/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660679/; classtype:trojan-activity;sid:84523779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660677)"; flow:established,from_client; content:"GET"; http_method; content:"/20250302/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660677/; classtype:trojan-activity;sid:84523777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660676)"; flow:established,from_client; content:"GET"; http_method; content:"/20250408/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660676/; classtype:trojan-activity;sid:84523776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660675)"; flow:established,from_client; content:"GET"; http_method; content:"/19000101/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660675/; classtype:trojan-activity;sid:84523775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660674)"; flow:established,from_client; content:"GET"; http_method; content:"/20250721/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660674/; classtype:trojan-activity;sid:84523774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660672)"; flow:established,from_client; content:"GET"; http_method; content:"/20250302/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660672/; classtype:trojan-activity;sid:84523772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660671)"; flow:established,from_client; content:"GET"; http_method; content:"/20250724/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660671/; classtype:trojan-activity;sid:84523771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660670)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660670/; classtype:trojan-activity;sid:84523770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660668)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660668/; classtype:trojan-activity;sid:84523768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660669)"; flow:established,from_client; content:"GET"; http_method; content:"/20250721/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660669/; classtype:trojan-activity;sid:84523769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660665)"; flow:established,from_client; content:"GET"; http_method; content:"/20250621/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660665/; classtype:trojan-activity;sid:84523765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660666)"; flow:established,from_client; content:"GET"; http_method; content:"/20210118/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660666/; classtype:trojan-activity;sid:84523766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660663)"; flow:established,from_client; content:"GET"; http_method; content:"/20250726/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660663/; classtype:trojan-activity;sid:84523763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660664)"; flow:established,from_client; content:"GET"; http_method; content:"/20250703/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660664/; classtype:trojan-activity;sid:84523764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660660)"; flow:established,from_client; content:"GET"; http_method; content:"/20250708/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660660/; classtype:trojan-activity;sid:84523760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660659)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660659/; classtype:trojan-activity;sid:84523759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660657)"; flow:established,from_client; content:"GET"; http_method; content:"/20250713/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660657/; classtype:trojan-activity;sid:84523757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660658)"; flow:established,from_client; content:"GET"; http_method; content:"/20250621/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660658/; classtype:trojan-activity;sid:84523758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660655)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660655/; classtype:trojan-activity;sid:84523755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660656)"; flow:established,from_client; content:"GET"; http_method; content:"/20250726/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660656/; classtype:trojan-activity;sid:84523756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660654)"; flow:established,from_client; content:"GET"; http_method; content:"/20250713/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660654/; classtype:trojan-activity;sid:84523754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660652)"; flow:established,from_client; content:"GET"; http_method; content:"/20220801/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660652/; classtype:trojan-activity;sid:84523752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660653)"; flow:established,from_client; content:"GET"; http_method; content:"/20250708/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660653/; classtype:trojan-activity;sid:84523753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660647)"; flow:established,from_client; content:"GET"; http_method; content:"/20250302/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660647/; classtype:trojan-activity;sid:84523747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660648)"; flow:established,from_client; content:"GET"; http_method; content:"/20250726/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660648/; classtype:trojan-activity;sid:84523748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660649)"; flow:established,from_client; content:"GET"; http_method; content:"/20250621/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660649/; classtype:trojan-activity;sid:84523749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660644)"; flow:established,from_client; content:"GET"; http_method; content:"/r-02-radiole/av.scr"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660644/; classtype:trojan-activity;sid:84523744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660642)"; flow:established,from_client; content:"GET"; http_method; content:"/r-02-radiole/photo.scr"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660642/; classtype:trojan-activity;sid:84523742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660641)"; flow:established,from_client; content:"GET"; http_method; content:"/20220801/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660641/; classtype:trojan-activity;sid:84523741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660640)"; flow:established,from_client; content:"GET"; http_method; content:"/20250703/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660640/; classtype:trojan-activity;sid:84523740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660639)"; flow:established,from_client; content:"GET"; http_method; content:"/20220801/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660639/; classtype:trojan-activity;sid:84523739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660638)"; flow:established,from_client; content:"GET"; http_method; content:"/20220801/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660638/; classtype:trojan-activity;sid:84523738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660637)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660637/; classtype:trojan-activity;sid:84523737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660636)"; flow:established,from_client; content:"GET"; http_method; content:"/20220801/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660636/; classtype:trojan-activity;sid:84523736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660635)"; flow:established,from_client; content:"GET"; http_method; content:"/20250722/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660635/; classtype:trojan-activity;sid:84523735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660634)"; flow:established,from_client; content:"GET"; http_method; content:"/20250703/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660634/; classtype:trojan-activity;sid:84523734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660633)"; flow:established,from_client; content:"GET"; http_method; content:"/20250615/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660633/; classtype:trojan-activity;sid:84523733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660631)"; flow:established,from_client; content:"GET"; http_method; content:"/20250708/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660631/; classtype:trojan-activity;sid:84523731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660630)"; flow:established,from_client; content:"GET"; http_method; content:"/20250615/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660630/; classtype:trojan-activity;sid:84523730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660629)"; flow:established,from_client; content:"GET"; http_method; content:"/20250302/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660629/; classtype:trojan-activity;sid:84523729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660627)"; flow:established,from_client; content:"GET"; http_method; content:"/20230507/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660627/; classtype:trojan-activity;sid:84523727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660626)"; flow:established,from_client; content:"GET"; http_method; content:"/20230507/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660626/; classtype:trojan-activity;sid:84523726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660625)"; flow:established,from_client; content:"GET"; http_method; content:"/20210118/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660625/; classtype:trojan-activity;sid:84523725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660624)"; flow:established,from_client; content:"GET"; http_method; content:"/20250724/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660624/; classtype:trojan-activity;sid:84523724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660622)"; flow:established,from_client; content:"GET"; http_method; content:"/20230507/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660622/; classtype:trojan-activity;sid:84523722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660623)"; flow:established,from_client; content:"GET"; http_method; content:"/20250722/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660623/; classtype:trojan-activity;sid:84523723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660621)"; flow:established,from_client; content:"GET"; http_method; content:"/20250703/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660621/; classtype:trojan-activity;sid:84523721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660620)"; flow:established,from_client; content:"GET"; http_method; content:"/20250721/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660620/; classtype:trojan-activity;sid:84523720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660619)"; flow:established,from_client; content:"GET"; http_method; content:"/20250615/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660619/; classtype:trojan-activity;sid:84523719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660618)"; flow:established,from_client; content:"GET"; http_method; content:"/20250408/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660618/; classtype:trojan-activity;sid:84523718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660615)"; flow:established,from_client; content:"GET"; http_method; content:"/20250621/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660615/; classtype:trojan-activity;sid:84523715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660616)"; flow:established,from_client; content:"GET"; http_method; content:"/20250724/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660616/; classtype:trojan-activity;sid:84523716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660614)"; flow:established,from_client; content:"GET"; http_method; content:"/20250713/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660614/; classtype:trojan-activity;sid:84523714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660612)"; flow:established,from_client; content:"GET"; http_method; content:"/20250721/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660612/; classtype:trojan-activity;sid:84523712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660613)"; flow:established,from_client; content:"GET"; http_method; content:"/20250722/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660613/; classtype:trojan-activity;sid:84523713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660611)"; flow:established,from_client; content:"GET"; http_method; content:"/20250725/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660611/; classtype:trojan-activity;sid:84523711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660608)"; flow:established,from_client; content:"GET"; http_method; content:"/20221020/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660608/; classtype:trojan-activity;sid:84523708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660607)"; flow:established,from_client; content:"GET"; http_method; content:"/20250725/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660607/; classtype:trojan-activity;sid:84523707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660605)"; flow:established,from_client; content:"GET"; http_method; content:"/20250708/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660605/; classtype:trojan-activity;sid:84523705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660603)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660603/; classtype:trojan-activity;sid:84523703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660600)"; flow:established,from_client; content:"GET"; http_method; content:"/20250725/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660600/; classtype:trojan-activity;sid:84523700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660599)"; flow:established,from_client; content:"GET"; http_method; content:"/20250302/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660599/; classtype:trojan-activity;sid:84523699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660598)"; flow:established,from_client; content:"GET"; http_method; content:"/20220801/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660598/; classtype:trojan-activity;sid:84523698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660596)"; flow:established,from_client; content:"GET"; http_method; content:"/20250615/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660596/; classtype:trojan-activity;sid:84523696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660595)"; flow:established,from_client; content:"GET"; http_method; content:"/20210118/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660595/; classtype:trojan-activity;sid:84523695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660594)"; flow:established,from_client; content:"GET"; http_method; content:"/20210118/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660594/; classtype:trojan-activity;sid:84523694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660592)"; flow:established,from_client; content:"GET"; http_method; content:"/20250621/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660592/; classtype:trojan-activity;sid:84523692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660593)"; flow:established,from_client; content:"GET"; http_method; content:"/20250726/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660593/; classtype:trojan-activity;sid:84523693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660590)"; flow:established,from_client; content:"GET"; http_method; content:"/20221020/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660590/; classtype:trojan-activity;sid:84523690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660591)"; flow:established,from_client; content:"GET"; http_method; content:"/20230507/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660591/; classtype:trojan-activity;sid:84523691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660587)"; flow:established,from_client; content:"GET"; http_method; content:"/20250703/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660587/; classtype:trojan-activity;sid:84523687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660588)"; flow:established,from_client; content:"GET"; http_method; content:"/20250615/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660588/; classtype:trojan-activity;sid:84523688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660589)"; flow:established,from_client; content:"GET"; http_method; content:"/20250408/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660589/; classtype:trojan-activity;sid:84523689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660585)"; flow:established,from_client; content:"GET"; http_method; content:"/20250713/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660585/; classtype:trojan-activity;sid:84523685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660583)"; flow:established,from_client; content:"GET"; http_method; content:"/20250725/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660583/; classtype:trojan-activity;sid:84523683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660584)"; flow:established,from_client; content:"GET"; http_method; content:"/20250726/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660584/; classtype:trojan-activity;sid:84523684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660581)"; flow:established,from_client; content:"GET"; http_method; content:"/20250726/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660581/; classtype:trojan-activity;sid:84523681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660582)"; flow:established,from_client; content:"GET"; http_method; content:"/20221020/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660582/; classtype:trojan-activity;sid:84523682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660579)"; flow:established,from_client; content:"GET"; http_method; content:"/r-02-radiole/video.scr"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660579/; classtype:trojan-activity;sid:84523679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660580)"; flow:established,from_client; content:"GET"; http_method; content:"/20221020/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660580/; classtype:trojan-activity;sid:84523680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660577)"; flow:established,from_client; content:"GET"; http_method; content:"/20210118/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660577/; classtype:trojan-activity;sid:84523677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660575)"; flow:established,from_client; content:"GET"; http_method; content:"/20250703/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660575/; classtype:trojan-activity;sid:84523675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660576)"; flow:established,from_client; content:"GET"; http_method; content:"/20210118/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660576/; classtype:trojan-activity;sid:84523676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660573)"; flow:established,from_client; content:"GET"; http_method; content:"/20250724/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660573/; classtype:trojan-activity;sid:84523673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660574)"; flow:established,from_client; content:"GET"; http_method; content:"/20250724/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660574/; classtype:trojan-activity;sid:84523674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660571)"; flow:established,from_client; content:"GET"; http_method; content:"/20250615/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660571/; classtype:trojan-activity;sid:84523671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660569)"; flow:established,from_client; content:"GET"; http_method; content:"/20250725/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660569/; classtype:trojan-activity;sid:84523669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660570)"; flow:established,from_client; content:"GET"; http_method; content:"/20250621/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660570/; classtype:trojan-activity;sid:84523670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660568)"; flow:established,from_client; content:"GET"; http_method; content:"/20250725/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660568/; classtype:trojan-activity;sid:84523668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660563)"; flow:established,from_client; content:"GET"; http_method; content:"/20230507/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660563/; classtype:trojan-activity;sid:84523663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660564)"; flow:established,from_client; content:"GET"; http_method; content:"/20250721/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660564/; classtype:trojan-activity;sid:84523664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660559)"; flow:established,from_client; content:"GET"; http_method; content:"/20250713/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660559/; classtype:trojan-activity;sid:84523659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660560)"; flow:established,from_client; content:"GET"; http_method; content:"/20250721/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660560/; classtype:trojan-activity;sid:84523660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660561)"; flow:established,from_client; content:"GET"; http_method; content:"/20250708/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660561/; classtype:trojan-activity;sid:84523661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660558)"; flow:established,from_client; content:"GET"; http_method; content:"/20230507/photo.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660558/; classtype:trojan-activity;sid:84523658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660552)"; flow:established,from_client; content:"GET"; http_method; content:"/20250722/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660552/; classtype:trojan-activity;sid:84523652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660553)"; flow:established,from_client; content:"GET"; http_method; content:"/20250722/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660553/; classtype:trojan-activity;sid:84523653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660554)"; flow:established,from_client; content:"GET"; http_method; content:"/20250713/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660554/; classtype:trojan-activity;sid:84523654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660555)"; flow:established,from_client; content:"GET"; http_method; content:"/20250722/av.lnk"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660555/; classtype:trojan-activity;sid:84523655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660556)"; flow:established,from_client; content:"GET"; http_method; content:"/20250408/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660556/; classtype:trojan-activity;sid:84523656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660537)"; flow:established,from_client; content:"GET"; http_method; content:"/sxs/info.zip"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"110.227.197.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660537/; classtype:trojan-activity;sid:84523637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660487)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.246.178.42"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660487/; classtype:trojan-activity;sid:84523587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660331)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660331/; classtype:trojan-activity;sid:84523431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660329)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660329/; classtype:trojan-activity;sid:84523429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660330)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660330/; classtype:trojan-activity;sid:84523430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3660328)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"81.42.249.132"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3660328/; classtype:trojan-activity;sid:84523428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659836)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.77.52.190"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659836/; classtype:trojan-activity;sid:84522936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659834)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"46.77.52.190"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659834/; classtype:trojan-activity;sid:84522934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659833)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.77.52.190"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659833/; classtype:trojan-activity;sid:84522933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659796)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.82.169.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659796/; classtype:trojan-activity;sid:84522896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659797)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.82.169.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659797/; classtype:trojan-activity;sid:84522897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659779)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"46.77.52.190"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659779/; classtype:trojan-activity;sid:84522879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3659782)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"46.77.52.190"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_06; reference:url, urlhaus.abuse.ch/url/3659782/; classtype:trojan-activity;sid:84522882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656729)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.115.212.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656729/; classtype:trojan-activity;sid:84519829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656728)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"217.115.212.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656728/; classtype:trojan-activity;sid:84519828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656727)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"217.115.212.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656727/; classtype:trojan-activity;sid:84519827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656726)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.115.212.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656726/; classtype:trojan-activity;sid:84519826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656725)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"47.104.96.89"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656725/; classtype:trojan-activity;sid:84519825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656720)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"92.150.82.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656720/; classtype:trojan-activity;sid:84519820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656709)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656709/; classtype:trojan-activity;sid:84519809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656710)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656710/; classtype:trojan-activity;sid:84519810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656707)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656707/; classtype:trojan-activity;sid:84519807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656704)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656704/; classtype:trojan-activity;sid:84519804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656701)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"212.27.26.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656701/; classtype:trojan-activity;sid:84519801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656696)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656696/; classtype:trojan-activity;sid:84519796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656693)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656693/; classtype:trojan-activity;sid:84519793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656689)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656689/; classtype:trojan-activity;sid:84519789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656692)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.115.212.126"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656692/; classtype:trojan-activity;sid:84519792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656677)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656677/; classtype:trojan-activity;sid:84519777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656671)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"68.224.70.241"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656671/; classtype:trojan-activity;sid:84519771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656672)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"5.149.184.170"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656672/; classtype:trojan-activity;sid:84519772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656674)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656674/; classtype:trojan-activity;sid:84519774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656666)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"180.76.153.78"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656666/; classtype:trojan-activity;sid:84519766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656667)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656667/; classtype:trojan-activity;sid:84519767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656665)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656665/; classtype:trojan-activity;sid:84519765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656662)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"92.150.82.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656662/; classtype:trojan-activity;sid:84519762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656660)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656660/; classtype:trojan-activity;sid:84519760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656652)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656652/; classtype:trojan-activity;sid:84519752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656654)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656654/; classtype:trojan-activity;sid:84519754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656638)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"212.27.26.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656638/; classtype:trojan-activity;sid:84519738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656639)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656639/; classtype:trojan-activity;sid:84519739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656640)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656640/; classtype:trojan-activity;sid:84519740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656634)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656634/; classtype:trojan-activity;sid:84519734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656635)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656635/; classtype:trojan-activity;sid:84519735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656636)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"68.224.70.241"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656636/; classtype:trojan-activity;sid:84519736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656632)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656632/; classtype:trojan-activity;sid:84519732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656630)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656630/; classtype:trojan-activity;sid:84519730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656627)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656627/; classtype:trojan-activity;sid:84519727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656628)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656628/; classtype:trojan-activity;sid:84519728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656621)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656621/; classtype:trojan-activity;sid:84519721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656611)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656611/; classtype:trojan-activity;sid:84519711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656607)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656607/; classtype:trojan-activity;sid:84519707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656608)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656608/; classtype:trojan-activity;sid:84519708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656609)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"212.27.26.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656609/; classtype:trojan-activity;sid:84519709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656601)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.206.139.61"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656601/; classtype:trojan-activity;sid:84519701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656602)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656602/; classtype:trojan-activity;sid:84519702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656592)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656592/; classtype:trojan-activity;sid:84519692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656594)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"180.148.33.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656594/; classtype:trojan-activity;sid:84519694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656595)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656595/; classtype:trojan-activity;sid:84519695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656581)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656581/; classtype:trojan-activity;sid:84519681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656584)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"122.170.8.40"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656584/; classtype:trojan-activity;sid:84519684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656577)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"179.214.0.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656577/; classtype:trojan-activity;sid:84519677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656574)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"76.130.209.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656574/; classtype:trojan-activity;sid:84519674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656572)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"212.27.26.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656572/; classtype:trojan-activity;sid:84519672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656569)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.240.211.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656569/; classtype:trojan-activity;sid:84519669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656566)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"188.118.38.161"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656566/; classtype:trojan-activity;sid:84519666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656563)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"90.8.145.102"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656563/; classtype:trojan-activity;sid:84519663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656552)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.240.211.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656552/; classtype:trojan-activity;sid:84519652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656555)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.240.211.121"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656555/; classtype:trojan-activity;sid:84519655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656057)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656057/; classtype:trojan-activity;sid:84519157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656050)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656050/; classtype:trojan-activity;sid:84519150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656047)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656047/; classtype:trojan-activity;sid:84519147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656038)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656038/; classtype:trojan-activity;sid:84519138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656021)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656021/; classtype:trojan-activity;sid:84519121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656019)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"157.10.63.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656019/; classtype:trojan-activity;sid:84519119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3656007)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3656007/; classtype:trojan-activity;sid:84519107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655977)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655977/; classtype:trojan-activity;sid:84519077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655973)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"185.43.45.171"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655973/; classtype:trojan-activity;sid:84519073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655969)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655969/; classtype:trojan-activity;sid:84519069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655908)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"157.10.63.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655908/; classtype:trojan-activity;sid:84519008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655903)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655903/; classtype:trojan-activity;sid:84519003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655896)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655896/; classtype:trojan-activity;sid:84518996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655875)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655875/; classtype:trojan-activity;sid:84518975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655866)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655866/; classtype:trojan-activity;sid:84518966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655859)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655859/; classtype:trojan-activity;sid:84518959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655839)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655839/; classtype:trojan-activity;sid:84518939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655837)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655837/; classtype:trojan-activity;sid:84518937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655834)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655834/; classtype:trojan-activity;sid:84518934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655792)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655792/; classtype:trojan-activity;sid:84518892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655784)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655784/; classtype:trojan-activity;sid:84518884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655783)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655783/; classtype:trojan-activity;sid:84518883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655774)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655774/; classtype:trojan-activity;sid:84518874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655757)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655757/; classtype:trojan-activity;sid:84518857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655755)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.211.28.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655755/; classtype:trojan-activity;sid:84518855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655751)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655751/; classtype:trojan-activity;sid:84518851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655748)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655748/; classtype:trojan-activity;sid:84518848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655745)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655745/; classtype:trojan-activity;sid:84518845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655730)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655730/; classtype:trojan-activity;sid:84518830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655718)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655718/; classtype:trojan-activity;sid:84518818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655714)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"157.10.63.251"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655714/; classtype:trojan-activity;sid:84518814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655699)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655699/; classtype:trojan-activity;sid:84518799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655703)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"92.150.82.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655703/; classtype:trojan-activity;sid:84518803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655696)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.211.28.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655696/; classtype:trojan-activity;sid:84518796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655697)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655697/; classtype:trojan-activity;sid:84518797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655665)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655665/; classtype:trojan-activity;sid:84518765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655654)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655654/; classtype:trojan-activity;sid:84518754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655649)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655649/; classtype:trojan-activity;sid:84518749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655631)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655631/; classtype:trojan-activity;sid:84518731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655593)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655593/; classtype:trojan-activity;sid:84518693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655594)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655594/; classtype:trojan-activity;sid:84518694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655590)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655590/; classtype:trojan-activity;sid:84518690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655572)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655572/; classtype:trojan-activity;sid:84518672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655562)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655562/; classtype:trojan-activity;sid:84518662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655560)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655560/; classtype:trojan-activity;sid:84518660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655557)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655557/; classtype:trojan-activity;sid:84518657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655559)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655559/; classtype:trojan-activity;sid:84518659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655553)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655553/; classtype:trojan-activity;sid:84518653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655507)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655507/; classtype:trojan-activity;sid:84518607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655501)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655501/; classtype:trojan-activity;sid:84518601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655493)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655493/; classtype:trojan-activity;sid:84518593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655476)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655476/; classtype:trojan-activity;sid:84518576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655474)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655474/; classtype:trojan-activity;sid:84518574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655469)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655469/; classtype:trojan-activity;sid:84518569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655466)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655466/; classtype:trojan-activity;sid:84518566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655462)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655462/; classtype:trojan-activity;sid:84518562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655453)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"92.150.82.148"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655453/; classtype:trojan-activity;sid:84518553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655447)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655447/; classtype:trojan-activity;sid:84518547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655440)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655440/; classtype:trojan-activity;sid:84518540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655430)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655430/; classtype:trojan-activity;sid:84518530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655423)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.211.28.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655423/; classtype:trojan-activity;sid:84518523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655420)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655420/; classtype:trojan-activity;sid:84518520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655408)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655408/; classtype:trojan-activity;sid:84518508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655403)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655403/; classtype:trojan-activity;sid:84518503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655383)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655383/; classtype:trojan-activity;sid:84518483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655348)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655348/; classtype:trojan-activity;sid:84518448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655339)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655339/; classtype:trojan-activity;sid:84518439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655335)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655335/; classtype:trojan-activity;sid:84518435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655329)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655329/; classtype:trojan-activity;sid:84518429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655322)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655322/; classtype:trojan-activity;sid:84518422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655323)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655323/; classtype:trojan-activity;sid:84518423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655317)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655317/; classtype:trojan-activity;sid:84518417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655313)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655313/; classtype:trojan-activity;sid:84518413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655309)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655309/; classtype:trojan-activity;sid:84518409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655306)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655306/; classtype:trojan-activity;sid:84518406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655295)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655295/; classtype:trojan-activity;sid:84518395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655280)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655280/; classtype:trojan-activity;sid:84518380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655279)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655279/; classtype:trojan-activity;sid:84518379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655276)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655276/; classtype:trojan-activity;sid:84518376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655272)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655272/; classtype:trojan-activity;sid:84518372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655267)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655267/; classtype:trojan-activity;sid:84518367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655259)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655259/; classtype:trojan-activity;sid:84518359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655253)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655253/; classtype:trojan-activity;sid:84518353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655244)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655244/; classtype:trojan-activity;sid:84518344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655230)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655230/; classtype:trojan-activity;sid:84518330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655207)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655207/; classtype:trojan-activity;sid:84518307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655203)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655203/; classtype:trojan-activity;sid:84518303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655200)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655200/; classtype:trojan-activity;sid:84518300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655191)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655191/; classtype:trojan-activity;sid:84518291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655169)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655169/; classtype:trojan-activity;sid:84518269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655163)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"185.8.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655163/; classtype:trojan-activity;sid:84518263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655160)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"124.123.123.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655160/; classtype:trojan-activity;sid:84518260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655143)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655143/; classtype:trojan-activity;sid:84518243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655126)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655126/; classtype:trojan-activity;sid:84518226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655115)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655115/; classtype:trojan-activity;sid:84518215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655109)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655109/; classtype:trojan-activity;sid:84518209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655094)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"88.28.218.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655094/; classtype:trojan-activity;sid:84518194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655089)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655089/; classtype:trojan-activity;sid:84518189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655090)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655090/; classtype:trojan-activity;sid:84518190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655084)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655084/; classtype:trojan-activity;sid:84518184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655081)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"124.123.123.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655081/; classtype:trojan-activity;sid:84518181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655077)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655077/; classtype:trojan-activity;sid:84518177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655072)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655072/; classtype:trojan-activity;sid:84518172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655070)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655070/; classtype:trojan-activity;sid:84518170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655064)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655064/; classtype:trojan-activity;sid:84518164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655057)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655057/; classtype:trojan-activity;sid:84518157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655054)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655054/; classtype:trojan-activity;sid:84518154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655052)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655052/; classtype:trojan-activity;sid:84518152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655046)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655046/; classtype:trojan-activity;sid:84518146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655037)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655037/; classtype:trojan-activity;sid:84518137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655038)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655038/; classtype:trojan-activity;sid:84518138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655025)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655025/; classtype:trojan-activity;sid:84518125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655021)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655021/; classtype:trojan-activity;sid:84518121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655016)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655016/; classtype:trojan-activity;sid:84518116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655008)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655008/; classtype:trojan-activity;sid:84518108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655005)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655005/; classtype:trojan-activity;sid:84518105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655004)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655004/; classtype:trojan-activity;sid:84518104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3655001)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3655001/; classtype:trojan-activity;sid:84518101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654999)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654999/; classtype:trojan-activity;sid:84518099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654994)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654994/; classtype:trojan-activity;sid:84518094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654991)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654991/; classtype:trojan-activity;sid:84518091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654972)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"87.249.142.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654972/; classtype:trojan-activity;sid:84518072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654967)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654967/; classtype:trojan-activity;sid:84518067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654962)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654962/; classtype:trojan-activity;sid:84518062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654953)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654953/; classtype:trojan-activity;sid:84518053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654946)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654946/; classtype:trojan-activity;sid:84518046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654942)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654942/; classtype:trojan-activity;sid:84518042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654936)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654936/; classtype:trojan-activity;sid:84518036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654935)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"68.148.10.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654935/; classtype:trojan-activity;sid:84518035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654917)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654917/; classtype:trojan-activity;sid:84518017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654904)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654904/; classtype:trojan-activity;sid:84518004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654892)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654892/; classtype:trojan-activity;sid:84517992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654874)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654874/; classtype:trojan-activity;sid:84517974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654859)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654859/; classtype:trojan-activity;sid:84517959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654857)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654857/; classtype:trojan-activity;sid:84517957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654850)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654850/; classtype:trojan-activity;sid:84517950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654829)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654829/; classtype:trojan-activity;sid:84517929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654826)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654826/; classtype:trojan-activity;sid:84517926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654811)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654811/; classtype:trojan-activity;sid:84517911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654806)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654806/; classtype:trojan-activity;sid:84517906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654803)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654803/; classtype:trojan-activity;sid:84517903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654793)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654793/; classtype:trojan-activity;sid:84517893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654788)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654788/; classtype:trojan-activity;sid:84517888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654769)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654769/; classtype:trojan-activity;sid:84517869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654758)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654758/; classtype:trojan-activity;sid:84517858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654747)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654747/; classtype:trojan-activity;sid:84517847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654746)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654746/; classtype:trojan-activity;sid:84517846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654732)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654732/; classtype:trojan-activity;sid:84517832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654721)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654721/; classtype:trojan-activity;sid:84517821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654719)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654719/; classtype:trojan-activity;sid:84517819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654708)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654708/; classtype:trojan-activity;sid:84517808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654673)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654673/; classtype:trojan-activity;sid:84517773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654661)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654661/; classtype:trojan-activity;sid:84517761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654659)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654659/; classtype:trojan-activity;sid:84517759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654657)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654657/; classtype:trojan-activity;sid:84517757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654655)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654655/; classtype:trojan-activity;sid:84517755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654654)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654654/; classtype:trojan-activity;sid:84517754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654651)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654651/; classtype:trojan-activity;sid:84517751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654641)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654641/; classtype:trojan-activity;sid:84517741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654634)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654634/; classtype:trojan-activity;sid:84517734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654625)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"124.123.123.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654625/; classtype:trojan-activity;sid:84517725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654600)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654600/; classtype:trojan-activity;sid:84517700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654589)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654589/; classtype:trojan-activity;sid:84517689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654555)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654555/; classtype:trojan-activity;sid:84517655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654541)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654541/; classtype:trojan-activity;sid:84517641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654542)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654542/; classtype:trojan-activity;sid:84517642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654533)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654533/; classtype:trojan-activity;sid:84517633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654531)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654531/; classtype:trojan-activity;sid:84517631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654513)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654513/; classtype:trojan-activity;sid:84517613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654508)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654508/; classtype:trojan-activity;sid:84517608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654504)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654504/; classtype:trojan-activity;sid:84517604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654499)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654499/; classtype:trojan-activity;sid:84517599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654501)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654501/; classtype:trojan-activity;sid:84517601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654498)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654498/; classtype:trojan-activity;sid:84517598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654484)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654484/; classtype:trojan-activity;sid:84517584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654477)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654477/; classtype:trojan-activity;sid:84517577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654447)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654447/; classtype:trojan-activity;sid:84517547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654445)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654445/; classtype:trojan-activity;sid:84517545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654392)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654392/; classtype:trojan-activity;sid:84517492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654385)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654385/; classtype:trojan-activity;sid:84517485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654356)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654356/; classtype:trojan-activity;sid:84517456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654342)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654342/; classtype:trojan-activity;sid:84517442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654337)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654337/; classtype:trojan-activity;sid:84517437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654334)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654334/; classtype:trojan-activity;sid:84517434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654333)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654333/; classtype:trojan-activity;sid:84517433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654326)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654326/; classtype:trojan-activity;sid:84517426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654321)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654321/; classtype:trojan-activity;sid:84517421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654320)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654320/; classtype:trojan-activity;sid:84517420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654312)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654312/; classtype:trojan-activity;sid:84517412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654303)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654303/; classtype:trojan-activity;sid:84517403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654288)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654288/; classtype:trojan-activity;sid:84517388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654289)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654289/; classtype:trojan-activity;sid:84517389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654285)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654285/; classtype:trojan-activity;sid:84517385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654284)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654284/; classtype:trojan-activity;sid:84517384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654276)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654276/; classtype:trojan-activity;sid:84517376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654268)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654268/; classtype:trojan-activity;sid:84517368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654258)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654258/; classtype:trojan-activity;sid:84517358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654253)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654253/; classtype:trojan-activity;sid:84517353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654243)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654243/; classtype:trojan-activity;sid:84517343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654234)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"107.128.101.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654234/; classtype:trojan-activity;sid:84517334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654205)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654205/; classtype:trojan-activity;sid:84517305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654203)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654203/; classtype:trojan-activity;sid:84517303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654204)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654204/; classtype:trojan-activity;sid:84517304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654202)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654202/; classtype:trojan-activity;sid:84517302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654197)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654197/; classtype:trojan-activity;sid:84517297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654195)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654195/; classtype:trojan-activity;sid:84517295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654192)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654192/; classtype:trojan-activity;sid:84517292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654173)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654173/; classtype:trojan-activity;sid:84517273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654177)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654177/; classtype:trojan-activity;sid:84517277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654161)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654161/; classtype:trojan-activity;sid:84517261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654122)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654122/; classtype:trojan-activity;sid:84517222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654123)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654123/; classtype:trojan-activity;sid:84517223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654117)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654117/; classtype:trojan-activity;sid:84517217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654113)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654113/; classtype:trojan-activity;sid:84517213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654108)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654108/; classtype:trojan-activity;sid:84517208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654098)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654098/; classtype:trojan-activity;sid:84517198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654078)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.165.240.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654078/; classtype:trojan-activity;sid:84517178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654077)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654077/; classtype:trojan-activity;sid:84517177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654076)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654076/; classtype:trojan-activity;sid:84517176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654074)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654074/; classtype:trojan-activity;sid:84517174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654072)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.211.28.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654072/; classtype:trojan-activity;sid:84517172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654065)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654065/; classtype:trojan-activity;sid:84517165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654054)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654054/; classtype:trojan-activity;sid:84517154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654044)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"124.123.123.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654044/; classtype:trojan-activity;sid:84517144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654032)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654032/; classtype:trojan-activity;sid:84517132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654024)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654024/; classtype:trojan-activity;sid:84517124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654019)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654019/; classtype:trojan-activity;sid:84517119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654018)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654018/; classtype:trojan-activity;sid:84517118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3654009)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3654009/; classtype:trojan-activity;sid:84517109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653997)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653997/; classtype:trojan-activity;sid:84517097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653985)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653985/; classtype:trojan-activity;sid:84517085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653977)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653977/; classtype:trojan-activity;sid:84517077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653960)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653960/; classtype:trojan-activity;sid:84517060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653947)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653947/; classtype:trojan-activity;sid:84517047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653941)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653941/; classtype:trojan-activity;sid:84517041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653939)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653939/; classtype:trojan-activity;sid:84517039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653930)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653930/; classtype:trojan-activity;sid:84517030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653917)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653917/; classtype:trojan-activity;sid:84517017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653918)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653918/; classtype:trojan-activity;sid:84517018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653916)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653916/; classtype:trojan-activity;sid:84517016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653910)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653910/; classtype:trojan-activity;sid:84517010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653900)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653900/; classtype:trojan-activity;sid:84517000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653893)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"203.192.211.119"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653893/; classtype:trojan-activity;sid:84516993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653888)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653888/; classtype:trojan-activity;sid:84516988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653885)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653885/; classtype:trojan-activity;sid:84516985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653874)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653874/; classtype:trojan-activity;sid:84516974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653871)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.198.246.24"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653871/; classtype:trojan-activity;sid:84516971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653867)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653867/; classtype:trojan-activity;sid:84516967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653858)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653858/; classtype:trojan-activity;sid:84516958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653848)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653848/; classtype:trojan-activity;sid:84516948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653847)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653847/; classtype:trojan-activity;sid:84516947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653840)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653840/; classtype:trojan-activity;sid:84516940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653828)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653828/; classtype:trojan-activity;sid:84516928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653827)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653827/; classtype:trojan-activity;sid:84516927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653824)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653824/; classtype:trojan-activity;sid:84516924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653813)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653813/; classtype:trojan-activity;sid:84516913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653806)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653806/; classtype:trojan-activity;sid:84516906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653799)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653799/; classtype:trojan-activity;sid:84516899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653781)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"49.205.173.192"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653781/; classtype:trojan-activity;sid:84516881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653770)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653770/; classtype:trojan-activity;sid:84516870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653756)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"212.27.26.206"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653756/; classtype:trojan-activity;sid:84516856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653755)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653755/; classtype:trojan-activity;sid:84516855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653749)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653749/; classtype:trojan-activity;sid:84516849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653748)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653748/; classtype:trojan-activity;sid:84516848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653745)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653745/; classtype:trojan-activity;sid:84516845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653743)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"186.235.86.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653743/; classtype:trojan-activity;sid:84516843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653732)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653732/; classtype:trojan-activity;sid:84516832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653717)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"32.219.189.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653717/; classtype:trojan-activity;sid:84516817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653705)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"168.121.168.84"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653705/; classtype:trojan-activity;sid:84516805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653690)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653690/; classtype:trojan-activity;sid:84516790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653691)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653691/; classtype:trojan-activity;sid:84516791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653672)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"43.230.44.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653672/; classtype:trojan-activity;sid:84516772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653669)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653669/; classtype:trojan-activity;sid:84516769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653666)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653666/; classtype:trojan-activity;sid:84516766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653662)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653662/; classtype:trojan-activity;sid:84516762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653661)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653661/; classtype:trojan-activity;sid:84516761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653655)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653655/; classtype:trojan-activity;sid:84516755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653647)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653647/; classtype:trojan-activity;sid:84516747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653640)"; flow:established,from_client; content:"GET"; http_method; content:"/video.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.204.232.47"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653640/; classtype:trojan-activity;sid:84516740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653634)"; flow:established,from_client; content:"GET"; http_method; content:"/av.scr"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653634/; classtype:trojan-activity;sid:84516734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653632)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"93.55.251.246"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653632/; classtype:trojan-activity;sid:84516732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653627)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"188.82.127.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653627/; classtype:trojan-activity;sid:84516727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653620)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653620/; classtype:trojan-activity;sid:84516720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653621)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653621/; classtype:trojan-activity;sid:84516721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653611)"; flow:established,from_client; content:"GET"; http_method; content:"/av.lnk"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653611/; classtype:trojan-activity;sid:84516711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3653607)"; flow:established,from_client; content:"GET"; http_method; content:"/video.lnk"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.11.25.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3653607/; classtype:trojan-activity;sid:84516707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651494)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"107.128.101.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651494/; classtype:trojan-activity;sid:84514594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651481)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651481/; classtype:trojan-activity;sid:84514581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651477)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651477/; classtype:trojan-activity;sid:84514577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651476)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_04; reference:url, urlhaus.abuse.ch/url/3651476/; classtype:trojan-activity;sid:84514576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651304)"; flow:established,from_client; content:"GET"; http_method; content:"/download/info.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"47.104.31.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651304/; classtype:trojan-activity;sid:84514404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651202)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.59.134.98"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651202/; classtype:trojan-activity;sid:84514302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651084)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"132.247.103.239"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651084/; classtype:trojan-activity;sid:84514184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651076)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"77.172.14.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651076/; classtype:trojan-activity;sid:84514176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3651075)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.36.80.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3651075/; classtype:trojan-activity;sid:84514175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650970)"; flow:established,from_client; content:"GET"; http_method; content:"/aspnet_client/info.zip"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"96.11.145.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650970/; classtype:trojan-activity;sid:84514070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650851)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"94.203.254.14"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650851/; classtype:trojan-activity;sid:84513951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650846)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"68.148.10.182"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650846/; classtype:trojan-activity;sid:84513946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650810)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650810/; classtype:trojan-activity;sid:84513910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650711)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"67.177.204.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650711/; classtype:trojan-activity;sid:84513811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650679)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.8.164.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650679/; classtype:trojan-activity;sid:84513779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650588)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"156.200.99.139"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650588/; classtype:trojan-activity;sid:84513688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650570)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"14.224.205.246"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650570/; classtype:trojan-activity;sid:84513670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650559)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"116.72.16.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650559/; classtype:trojan-activity;sid:84513659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650492)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"72.132.64.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650492/; classtype:trojan-activity;sid:84513592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650413)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650413/; classtype:trojan-activity;sid:84513513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650373)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"37.34.230.9"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650373/; classtype:trojan-activity;sid:84513473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650351)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"71.198.110.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650351/; classtype:trojan-activity;sid:84513451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650343)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"93.43.53.67"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650343/; classtype:trojan-activity;sid:84513443; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650319)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"138.36.2.110"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650319/; classtype:trojan-activity;sid:84513419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650307)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"5.89.102.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650307/; classtype:trojan-activity;sid:84513407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650299)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"109.193.105.79"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650299/; classtype:trojan-activity;sid:84513399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650263)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"107.128.101.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650263/; classtype:trojan-activity;sid:84513363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650061)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"70.95.233.160"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650061/; classtype:trojan-activity;sid:84513161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3650044)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"111.235.143.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3650044/; classtype:trojan-activity;sid:84513144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649975)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"27.72.159.162"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649975/; classtype:trojan-activity;sid:84513075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649968)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"107.128.101.219"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649968/; classtype:trojan-activity;sid:84513068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649837)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"70.190.199.152"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649837/; classtype:trojan-activity;sid:84512937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649707)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649707/; classtype:trojan-activity;sid:84512807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649685)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"87.249.142.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649685/; classtype:trojan-activity;sid:84512785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649682)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"222.252.31.94"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649682/; classtype:trojan-activity;sid:84512782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649676)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"96.11.145.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649676/; classtype:trojan-activity;sid:84512776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649546)"; flow:established,from_client; content:"GET"; http_method; content:"/aspnet_client/system_web/info.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"96.11.145.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649546/; classtype:trojan-activity;sid:84512646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3649341)"; flow:established,from_client; content:"GET"; http_method; content:"/blog/info.zip"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"96.11.145.107"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3649341/; classtype:trojan-activity;sid:84512441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3647457)"; flow:established,from_client; content:"GET"; http_method; content:"/recipes/staging/a-89fb7017-7780-4b72-950d-c2db1146a34a.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"best10cdn.blob.core.windows.net"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3647457/; classtype:trojan-activity;sid:84510557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3646414)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/nano/image.jpg|3f|12711343"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"ybgctdtbzvgpdxjivafy.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3646414/; classtype:trojan-activity;sid:84509514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3646403)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/hold/image.jpg|3f|12711343h"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"ihmmkvkaiwnilneauhfn.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3646403/; classtype:trojan-activity;sid:84509503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3646408)"; flow:established,from_client; content:"GET"; http_method; content:"/files/jqqvlru0vaih3z.exe"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"toolshare.com.tr"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_10_03; reference:url, urlhaus.abuse.ch/url/3646408/; classtype:trojan-activity;sid:84509508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645950)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"www.intelligradeeducation.vicentecisnerospub.com"; http_host; depth:48; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645950/; classtype:trojan-activity;sid:84509050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3645874)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"66.185.26.66"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3645874/; classtype:trojan-activity;sid:84508974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642788)"; flow:established,from_client; content:"GET"; http_method; content:"/big/microsoft.sql.server.2012.enterprise.edition.with.service.pack.1-kopie/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642788/; classtype:trojan-activity;sid:84505888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642779)"; flow:established,from_client; content:"GET"; http_method; content:"/inicis_dll/key/info.zip"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642779/; classtype:trojan-activity;sid:84505879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642775)"; flow:established,from_client; content:"GET"; http_method; content:"/incis/info.zip"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642775/; classtype:trojan-activity;sid:84505875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642717)"; flow:established,from_client; content:"GET"; http_method; content:"/incis/key/inipaytest/info.zip"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642717/; classtype:trojan-activity;sid:84505817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642700)"; flow:established,from_client; content:"GET"; http_method; content:"/slnammicafe/info.zip"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642700/; classtype:trojan-activity;sid:84505800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642677)"; flow:established,from_client; content:"GET"; http_method; content:"/incis/key/info.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642677/; classtype:trojan-activity;sid:84505777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642643)"; flow:established,from_client; content:"GET"; http_method; content:"/inicis_dll/log/info.zip"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642643/; classtype:trojan-activity;sid:84505743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642634)"; flow:established,from_client; content:"GET"; http_method; content:"/slnammicafe/ammicafefile/info.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642634/; classtype:trojan-activity;sid:84505734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642522)"; flow:established,from_client; content:"GET"; http_method; content:"/slnammicafe/ammicafefile/ammicafesetup/info.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642522/; classtype:trojan-activity;sid:84505622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642484)"; flow:established,from_client; content:"GET"; http_method; content:"/slnammicafe2/info.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642484/; classtype:trojan-activity;sid:84505584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642438)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"121.184.128.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642438/; classtype:trojan-activity;sid:84505538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642422)"; flow:established,from_client; content:"GET"; http_method; content:"/02/info.zip"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"121.184.128.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642422/; classtype:trojan-activity;sid:84505522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642417)"; flow:established,from_client; content:"GET"; http_method; content:"/slnammicafe2/ammicafe2file/info.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642417/; classtype:trojan-activity;sid:84505517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642406)"; flow:established,from_client; content:"GET"; http_method; content:"/slnammicafe2/ammicafe2file/ammicafe2setup/info.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642406/; classtype:trojan-activity;sid:84505506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642382)"; flow:established,from_client; content:"GET"; http_method; content:"/big/html/info.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642382/; classtype:trojan-activity;sid:84505482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642346)"; flow:established,from_client; content:"GET"; http_method; content:"/big/sql%20server%202014/info.zip"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642346/; classtype:trojan-activity;sid:84505446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642349)"; flow:established,from_client; content:"GET"; http_method; content:"/images/info.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642349/; classtype:trojan-activity;sid:84505449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642324)"; flow:established,from_client; content:"GET"; http_method; content:"/01/info.zip"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"121.184.128.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642324/; classtype:trojan-activity;sid:84505424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642294)"; flow:established,from_client; content:"GET"; http_method; content:"/inicis_dll/key/inipaytest/info.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642294/; classtype:trojan-activity;sid:84505394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642245)"; flow:established,from_client; content:"GET"; http_method; content:"/inicis_dll/info.zip"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642245/; classtype:trojan-activity;sid:84505345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642246)"; flow:established,from_client; content:"GET"; http_method; content:"/big/info.zip"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642246/; classtype:trojan-activity;sid:84505346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3642226)"; flow:established,from_client; content:"GET"; http_method; content:"/inicis_dll/key/jungminsof/info.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_02; reference:url, urlhaus.abuse.ch/url/3642226/; classtype:trojan-activity;sid:84505326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637224)"; flow:established,from_client; content:"GET"; http_method; content:"/haozip.100021.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"download.haozip.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637224/; classtype:trojan-activity;sid:84500324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637189)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/23082024105108/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637189/; classtype:trojan-activity;sid:84500289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637188)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/26072024113244/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637188/; classtype:trojan-activity;sid:84500288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637186)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/19092024115007/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637186/; classtype:trojan-activity;sid:84500286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637187)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/24072024081607/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637187/; classtype:trojan-activity;sid:84500287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637185)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/12062024095414/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637185/; classtype:trojan-activity;sid:84500285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637184)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/27082024072850/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637184/; classtype:trojan-activity;sid:84500284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637183)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/12082024064105/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637183/; classtype:trojan-activity;sid:84500283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637182)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/16082024070308/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637182/; classtype:trojan-activity;sid:84500282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637181)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/13092024072525/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637181/; classtype:trojan-activity;sid:84500281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637180)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/23072024115252/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637180/; classtype:trojan-activity;sid:84500280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637179)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/21072024112418/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637179/; classtype:trojan-activity;sid:84500279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637178)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/16082024104510/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637178/; classtype:trojan-activity;sid:84500278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637177)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/22082024110540/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637177/; classtype:trojan-activity;sid:84500277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637176)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/04092024104005/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637176/; classtype:trojan-activity;sid:84500276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637175)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8343/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637175/; classtype:trojan-activity;sid:84500275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637174)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15082024173844/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637174/; classtype:trojan-activity;sid:84500274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637173)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/26072024180426/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637173/; classtype:trojan-activity;sid:84500273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637172)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/03072024101008/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637172/; classtype:trojan-activity;sid:84500272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637171)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13082024112350/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637171/; classtype:trojan-activity;sid:84500271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637170)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/26072024074431/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637170/; classtype:trojan-activity;sid:84500270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637168)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/01092024171022/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637168/; classtype:trojan-activity;sid:84500268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637169)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/11072024080039/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637169/; classtype:trojan-activity;sid:84500269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637167)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/12092024113946/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637167/; classtype:trojan-activity;sid:84500267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637166)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08092024115637/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637166/; classtype:trojan-activity;sid:84500266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637165)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15092024104931/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637165/; classtype:trojan-activity;sid:84500265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637164)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/12072024075828/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637164/; classtype:trojan-activity;sid:84500264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637163)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/11092024115504/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637163/; classtype:trojan-activity;sid:84500263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637160)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/21082024115532/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637160/; classtype:trojan-activity;sid:84500260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637161)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/05072024114132/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637161/; classtype:trojan-activity;sid:84500261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637162)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8465/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637162/; classtype:trojan-activity;sid:84500262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637159)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/25062024073012/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637159/; classtype:trojan-activity;sid:84500259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637158)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/29072024110431/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637158/; classtype:trojan-activity;sid:84500258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637157)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/30072024091401/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637157/; classtype:trojan-activity;sid:84500257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637153)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/15072024124718/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637153/; classtype:trojan-activity;sid:84500253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637154)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/09082024185433/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637154/; classtype:trojan-activity;sid:84500254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637155)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/09072024110245/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637155/; classtype:trojan-activity;sid:84500255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637149)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/09092024072321/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637149/; classtype:trojan-activity;sid:84500249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637150)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07082024180909/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637150/; classtype:trojan-activity;sid:84500250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637151)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/24092024073908/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637151/; classtype:trojan-activity;sid:84500251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637147)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/19062024071831/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637147/; classtype:trojan-activity;sid:84500247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637148)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/21092024114951/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637148/; classtype:trojan-activity;sid:84500248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637145)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/30062024113348/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637145/; classtype:trojan-activity;sid:84500245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637146)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/04092024113047/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637146/; classtype:trojan-activity;sid:84500246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637144)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/04092024120154/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637144/; classtype:trojan-activity;sid:84500244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637143)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/01082024110241/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637143/; classtype:trojan-activity;sid:84500243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637141)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/14072024110540/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637141/; classtype:trojan-activity;sid:84500241; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637142)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11082024185045/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637142/; classtype:trojan-activity;sid:84500242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637138)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/19062024103023/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637138/; classtype:trojan-activity;sid:84500238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637139)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/06092024072348/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637139/; classtype:trojan-activity;sid:84500239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637140)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/29072024070625/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637140/; classtype:trojan-activity;sid:84500240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637137)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/18072024112759/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637137/; classtype:trojan-activity;sid:84500237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637136)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/11072024155154/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637136/; classtype:trojan-activity;sid:84500236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637135)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/18082024113426/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637135/; classtype:trojan-activity;sid:84500235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637133)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07092024113602/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637133/; classtype:trojan-activity;sid:84500233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637134)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28082024163408/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637134/; classtype:trojan-activity;sid:84500234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637130)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/10082024110351/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637130/; classtype:trojan-activity;sid:84500230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637131)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/12092024181446/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637131/; classtype:trojan-activity;sid:84500231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637129)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/26082024115142/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637129/; classtype:trojan-activity;sid:84500229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637128)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/09092024091444/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637128/; classtype:trojan-activity;sid:84500228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637127)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/23082024071038/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637127/; classtype:trojan-activity;sid:84500227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637122)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/17062024181518/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637122/; classtype:trojan-activity;sid:84500222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637123)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/05082024120940/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637123/; classtype:trojan-activity;sid:84500223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637124)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/24072024112235/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637124/; classtype:trojan-activity;sid:84500224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637125)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/17092024073614/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637125/; classtype:trojan-activity;sid:84500225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637120)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/09082024122457/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637120/; classtype:trojan-activity;sid:84500220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637117)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/09092024112532/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637117/; classtype:trojan-activity;sid:84500217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637118)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/24062024072602/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637118/; classtype:trojan-activity;sid:84500218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637119)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/12092024070406/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637119/; classtype:trojan-activity;sid:84500219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637115)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/24072024143513/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637115/; classtype:trojan-activity;sid:84500215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637116)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/21082024081755/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637116/; classtype:trojan-activity;sid:84500216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637114)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/13082024120234/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637114/; classtype:trojan-activity;sid:84500214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637113)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/19072024123916/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637113/; classtype:trojan-activity;sid:84500213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637110)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/29082024122318/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637110/; classtype:trojan-activity;sid:84500210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637111)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/15072024080426/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637111/; classtype:trojan-activity;sid:84500211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637112)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/22092024115602/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637112/; classtype:trojan-activity;sid:84500212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637109)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/05082024125302/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637109/; classtype:trojan-activity;sid:84500209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637107)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16072024114842/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637107/; classtype:trojan-activity;sid:84500207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637108)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/16092024115114/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637108/; classtype:trojan-activity;sid:84500208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637105)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/31072024070936/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637105/; classtype:trojan-activity;sid:84500205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637106)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/17092024104334/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637106/; classtype:trojan-activity;sid:84500206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637104)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/01082024072447/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637104/; classtype:trojan-activity;sid:84500204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637103)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/05082024065930/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637103/; classtype:trojan-activity;sid:84500203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637101)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/01082024133101/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637101/; classtype:trojan-activity;sid:84500201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637099)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/02082024083649/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637099/; classtype:trojan-activity;sid:84500199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637100)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/29072024182036/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637100/; classtype:trojan-activity;sid:84500200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637098)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/19072024071620/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637098/; classtype:trojan-activity;sid:84500198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637096)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8029/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637096/; classtype:trojan-activity;sid:84500196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637097)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/25092024150814/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637097/; classtype:trojan-activity;sid:84500197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637092)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/03072024102505/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637092/; classtype:trojan-activity;sid:84500192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637093)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/03092024131015/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637093/; classtype:trojan-activity;sid:84500193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637094)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/15072024084956/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637094/; classtype:trojan-activity;sid:84500194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637090)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/25062024105808/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637090/; classtype:trojan-activity;sid:84500190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637091)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/04092024072725/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637091/; classtype:trojan-activity;sid:84500191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637089)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/20062024112748/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637089/; classtype:trojan-activity;sid:84500189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637087)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/17072024103622/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637087/; classtype:trojan-activity;sid:84500187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637088)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/16082024121016/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637088/; classtype:trojan-activity;sid:84500188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637085)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/24092024103551/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637085/; classtype:trojan-activity;sid:84500185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637086)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/15072024080017/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637086/; classtype:trojan-activity;sid:84500186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637082)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024081535/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637082/; classtype:trojan-activity;sid:84500182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637083)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/26072024111342/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637083/; classtype:trojan-activity;sid:84500183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637084)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11062024125904/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637084/; classtype:trojan-activity;sid:84500184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637081)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/tek/info.zip"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637081/; classtype:trojan-activity;sid:84500181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637080)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/11092024075310/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637080/; classtype:trojan-activity;sid:84500180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637076)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/24072024121144/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637076/; classtype:trojan-activity;sid:84500176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637077)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/badmail/info.zip"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637077/; classtype:trojan-activity;sid:84500177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637078)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/06082024080109/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637078/; classtype:trojan-activity;sid:84500178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637079)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/12072024072413/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637079/; classtype:trojan-activity;sid:84500179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637073)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/08082024071151/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637073/; classtype:trojan-activity;sid:84500173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637074)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/03092024073559/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637074/; classtype:trojan-activity;sid:84500174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637070)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8336/18072024083258/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637070/; classtype:trojan-activity;sid:84500170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637069)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/01092024084736/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637069/; classtype:trojan-activity;sid:84500169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637067)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/08082024072046/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637067/; classtype:trojan-activity;sid:84500167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637068)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08072024110224/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637068/; classtype:trojan-activity;sid:84500168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637065)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/02092024075924/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637065/; classtype:trojan-activity;sid:84500165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637064)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/30082024115734/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637064/; classtype:trojan-activity;sid:84500164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637062)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/23072024075958/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637062/; classtype:trojan-activity;sid:84500162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637063)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/27082024173545/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637063/; classtype:trojan-activity;sid:84500163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637060)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/06092024074954/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637060/; classtype:trojan-activity;sid:84500160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637056)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/24082024112958/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637056/; classtype:trojan-activity;sid:84500156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637057)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/04092024180827/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637057/; classtype:trojan-activity;sid:84500157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637058)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/05092024073851/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637058/; classtype:trojan-activity;sid:84500158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637055)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/05092024175914/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637055/; classtype:trojan-activity;sid:84500155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637054)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07082024181015/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637054/; classtype:trojan-activity;sid:84500154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637053)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/09082024151247/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637053/; classtype:trojan-activity;sid:84500153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637052)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/05072024135901/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637052/; classtype:trojan-activity;sid:84500152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637050)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/04072024073930/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637050/; classtype:trojan-activity;sid:84500150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637051)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/27072024111013/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637051/; classtype:trojan-activity;sid:84500151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637047)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28092024110908/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637047/; classtype:trojan-activity;sid:84500147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637048)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/17062024124213/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637048/; classtype:trojan-activity;sid:84500148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637049)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21062024074659/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637049/; classtype:trojan-activity;sid:84500149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637046)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/06082024071203/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637046/; classtype:trojan-activity;sid:84500146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637044)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11092024163133/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637044/; classtype:trojan-activity;sid:84500144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637045)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/25092024084516/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637045/; classtype:trojan-activity;sid:84500145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637042)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/01082024134811/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637042/; classtype:trojan-activity;sid:84500142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637037)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8336/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637037/; classtype:trojan-activity;sid:84500137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637038)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/26062024074615/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637038/; classtype:trojan-activity;sid:84500138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637039)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/20072024103050/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637039/; classtype:trojan-activity;sid:84500139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637040)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/02072024072748/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637040/; classtype:trojan-activity;sid:84500140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637041)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/17092024073317/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637041/; classtype:trojan-activity;sid:84500141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637036)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024124018/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637036/; classtype:trojan-activity;sid:84500136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637034)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/27092024120719/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637034/; classtype:trojan-activity;sid:84500134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637032)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/29062024115106/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637032/; classtype:trojan-activity;sid:84500132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637030)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/02092024121943/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637030/; classtype:trojan-activity;sid:84500130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637029)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/06092024173040/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637029/; classtype:trojan-activity;sid:84500129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637026)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/17072024080628/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637026/; classtype:trojan-activity;sid:84500126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637027)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/13082024144908/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637027/; classtype:trojan-activity;sid:84500127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637028)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/14092024112531/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637028/; classtype:trojan-activity;sid:84500128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637025)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/29082024110733/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637025/; classtype:trojan-activity;sid:84500125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637024)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/11092024161738/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637024/; classtype:trojan-activity;sid:84500124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637021)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/25062024074726/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637021/; classtype:trojan-activity;sid:84500121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637022)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/02102024124124/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637022/; classtype:trojan-activity;sid:84500122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637023)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/01082024124212/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637023/; classtype:trojan-activity;sid:84500123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637020)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/29072024170139/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637020/; classtype:trojan-activity;sid:84500120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637015)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13092024090633/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637015/; classtype:trojan-activity;sid:84500115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637017)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/12082024111719/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637017/; classtype:trojan-activity;sid:84500117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637019)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/13062024073315/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637019/; classtype:trojan-activity;sid:84500119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637011)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26092024073319/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637011/; classtype:trojan-activity;sid:84500111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637012)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/03072024075801/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637012/; classtype:trojan-activity;sid:84500112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637013)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/13092024065731/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637013/; classtype:trojan-activity;sid:84500113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637014)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/02092024155414/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637014/; classtype:trojan-activity;sid:84500114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637007)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/29062024131718/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637007/; classtype:trojan-activity;sid:84500107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637008)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024163711/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637008/; classtype:trojan-activity;sid:84500108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637009)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/27062024115812/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637009/; classtype:trojan-activity;sid:84500109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637010)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07072024113310/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637010/; classtype:trojan-activity;sid:84500110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637005)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/26082024175225/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637005/; classtype:trojan-activity;sid:84500105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637002)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/06092024112226/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637002/; classtype:trojan-activity;sid:84500102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637003)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/cons/1/8325/14062024181140/info.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637003/; classtype:trojan-activity;sid:84500103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637004)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15092024163914/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637004/; classtype:trojan-activity;sid:84500104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636999)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/12082024111034/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636999/; classtype:trojan-activity;sid:84500099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637000)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/19062024111300/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637000/; classtype:trojan-activity;sid:84500100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3637001)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/02092024070516/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3637001/; classtype:trojan-activity;sid:84500101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636997)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15062024120757/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636997/; classtype:trojan-activity;sid:84500097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636996)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/07082024074934/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636996/; classtype:trojan-activity;sid:84500096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636993)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/drop/info.zip"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636993/; classtype:trojan-activity;sid:84500093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636994)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11092024172104/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636994/; classtype:trojan-activity;sid:84500094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636995)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/23072024072015/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636995/; classtype:trojan-activity;sid:84500095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636992)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/18082024174028/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636992/; classtype:trojan-activity;sid:84500092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636991)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/10072024072615/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636991/; classtype:trojan-activity;sid:84500091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636990)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/03102024140347/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636990/; classtype:trojan-activity;sid:84500090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636987)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/29072024094428/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636987/; classtype:trojan-activity;sid:84500087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636988)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08082024114220/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636988/; classtype:trojan-activity;sid:84500088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636986)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/19072024081323/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636986/; classtype:trojan-activity;sid:84500086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636985)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/08082024072411/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636985/; classtype:trojan-activity;sid:84500085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636982)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/11092024072722/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636982/; classtype:trojan-activity;sid:84500082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636978)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/17062024075813/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636978/; classtype:trojan-activity;sid:84500078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636979)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26072024071101/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636979/; classtype:trojan-activity;sid:84500079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636980)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/18092024104929/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636980/; classtype:trojan-activity;sid:84500080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636975)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8051/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636975/; classtype:trojan-activity;sid:84500075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636976)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024144032/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636976/; classtype:trojan-activity;sid:84500076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636977)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/26082024121258/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636977/; classtype:trojan-activity;sid:84500077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636967)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/27082024111920/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636967/; classtype:trojan-activity;sid:84500067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636968)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024121015/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636968/; classtype:trojan-activity;sid:84500068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636969)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/21082024175843/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636969/; classtype:trojan-activity;sid:84500069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636970)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/18062024121810/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636970/; classtype:trojan-activity;sid:84500070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636971)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/12072024130606/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636971/; classtype:trojan-activity;sid:84500071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636972)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16062024115815/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636972/; classtype:trojan-activity;sid:84500072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636973)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13092024164829/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636973/; classtype:trojan-activity;sid:84500073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636965)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/02092024071944/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636965/; classtype:trojan-activity;sid:84500065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636966)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/01092024103900/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636966/; classtype:trojan-activity;sid:84500066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636964)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/23072024130857/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636964/; classtype:trojan-activity;sid:84500064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636963)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/06092024071949/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636963/; classtype:trojan-activity;sid:84500063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636957)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/17062024111134/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636957/; classtype:trojan-activity;sid:84500057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636958)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/12082024174415/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636958/; classtype:trojan-activity;sid:84500058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636959)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/02082024073257/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636959/; classtype:trojan-activity;sid:84500059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636960)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/03092024120537/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636960/; classtype:trojan-activity;sid:84500060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636961)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/01072024102122/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636961/; classtype:trojan-activity;sid:84500061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636962)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/27072024112004/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636962/; classtype:trojan-activity;sid:84500062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636956)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/09072024071533/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636956/; classtype:trojan-activity;sid:84500056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636955)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/22082024070804/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636955/; classtype:trojan-activity;sid:84500055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636954)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/21082024115442/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636954/; classtype:trojan-activity;sid:84500054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636953)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/cons/1/8325/info.zip"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636953/; classtype:trojan-activity;sid:84500053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636948)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/17072024080732/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636948/; classtype:trojan-activity;sid:84500048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636949)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/19082024080051/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636949/; classtype:trojan-activity;sid:84500049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636950)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28082024111159/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636950/; classtype:trojan-activity;sid:84500050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636951)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28072024115238/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636951/; classtype:trojan-activity;sid:84500051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636947)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/07082024070516/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636947/; classtype:trojan-activity;sid:84500047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636946)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07092024175546/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636946/; classtype:trojan-activity;sid:84500046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636945)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/25072024103203/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636945/; classtype:trojan-activity;sid:84500045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636942)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/31082024165207/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636942/; classtype:trojan-activity;sid:84500042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636943)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/11062024093514/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636943/; classtype:trojan-activity;sid:84500043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636944)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/06092024114755/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636944/; classtype:trojan-activity;sid:84500044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636940)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/27092024123259/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636940/; classtype:trojan-activity;sid:84500040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636941)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/23092024073238/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636941/; classtype:trojan-activity;sid:84500041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636937)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13072024115545/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636937/; classtype:trojan-activity;sid:84500037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636936)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/29072024104316/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636936/; classtype:trojan-activity;sid:84500036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636935)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13072024115848/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636935/; classtype:trojan-activity;sid:84500035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636934)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/24072024071414/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636934/; classtype:trojan-activity;sid:84500034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636933)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16092024105926/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636933/; classtype:trojan-activity;sid:84500033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636932)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28082024174605/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636932/; classtype:trojan-activity;sid:84500032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636931)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08082024174233/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636931/; classtype:trojan-activity;sid:84500031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636927)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/23072024081312/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636927/; classtype:trojan-activity;sid:84500027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636928)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/02102024072353/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636928/; classtype:trojan-activity;sid:84500028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636929)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08092024174750/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636929/; classtype:trojan-activity;sid:84500029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636930)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8325/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636930/; classtype:trojan-activity;sid:84500030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636925)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8336/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636925/; classtype:trojan-activity;sid:84500025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636926)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/19062024070824/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636926/; classtype:trojan-activity;sid:84500026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636920)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/22082024121329/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636920/; classtype:trojan-activity;sid:84500020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636921)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26062024155216/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636921/; classtype:trojan-activity;sid:84500021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636922)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/24092024120511/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636922/; classtype:trojan-activity;sid:84500022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636923)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16062024180613/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636923/; classtype:trojan-activity;sid:84500023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636919)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07072024165922/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636919/; classtype:trojan-activity;sid:84500019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636918)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/13092024114239/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636918/; classtype:trojan-activity;sid:84500018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636917)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/20082024112036/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636917/; classtype:trojan-activity;sid:84500017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636916)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8318/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636916/; classtype:trojan-activity;sid:84500016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636913)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/31082024110606/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636913/; classtype:trojan-activity;sid:84500013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636914)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11062024112609/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636914/; classtype:trojan-activity;sid:84500014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636910)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/02072024115435/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636910/; classtype:trojan-activity;sid:84500010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636909)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07092024122439/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636909/; classtype:trojan-activity;sid:84500009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636906)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/14062024123830/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636906/; classtype:trojan-activity;sid:84500006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636908)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/17062024180043/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636908/; classtype:trojan-activity;sid:84500008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636905)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28072024115112/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636905/; classtype:trojan-activity;sid:84500005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636904)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024090731/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636904/; classtype:trojan-activity;sid:84500004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636902)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/23092024113222/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636902/; classtype:trojan-activity;sid:84500002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636900)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/03072024113724/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636900/; classtype:trojan-activity;sid:84500000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636899)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/11092024134516/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636899/; classtype:trojan-activity;sid:84499999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636897)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8334/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636897/; classtype:trojan-activity;sid:84499997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636894)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08082024114317/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636894/; classtype:trojan-activity;sid:84499994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636895)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/18072024151745/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636895/; classtype:trojan-activity;sid:84499995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636893)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/19072024124237/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636893/; classtype:trojan-activity;sid:84499993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636892)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/29082024170717/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636892/; classtype:trojan-activity;sid:84499992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636883)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/08072024075903/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636883/; classtype:trojan-activity;sid:84499983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636884)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8325/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636884/; classtype:trojan-activity;sid:84499984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636885)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15062024114520/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636885/; classtype:trojan-activity;sid:84499985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636886)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/13092024153227/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636886/; classtype:trojan-activity;sid:84499986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636887)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/14082024075957/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636887/; classtype:trojan-activity;sid:84499987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636888)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26082024070716/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636888/; classtype:trojan-activity;sid:84499988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636890)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21062024072959/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636890/; classtype:trojan-activity;sid:84499990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636882)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/cons/1/8325/13062024155232/info.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636882/; classtype:trojan-activity;sid:84499982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636881)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/23082024111126/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636881/; classtype:trojan-activity;sid:84499981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636880)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/04072024125301/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636880/; classtype:trojan-activity;sid:84499980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636876)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11082024113244/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636876/; classtype:trojan-activity;sid:84499976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636877)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/04092024091820/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636877/; classtype:trojan-activity;sid:84499977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636878)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07102024125032/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636878/; classtype:trojan-activity;sid:84499978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636872)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/30072024114118/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636872/; classtype:trojan-activity;sid:84499972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636873)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/05082024083850/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636873/; classtype:trojan-activity;sid:84499973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636874)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/17062024072104/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636874/; classtype:trojan-activity;sid:84499974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636875)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024125710/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636875/; classtype:trojan-activity;sid:84499975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636871)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/03072024103601/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636871/; classtype:trojan-activity;sid:84499971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636869)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/12082024120632/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636869/; classtype:trojan-activity;sid:84499969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636863)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636863/; classtype:trojan-activity;sid:84499963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636864)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/11072024071932/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636864/; classtype:trojan-activity;sid:84499964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636865)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/11072024143228/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636865/; classtype:trojan-activity;sid:84499965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636866)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/27092024124432/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636866/; classtype:trojan-activity;sid:84499966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636867)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/23082024175244/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636867/; classtype:trojan-activity;sid:84499967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636868)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/13062024070655/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636868/; classtype:trojan-activity;sid:84499968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636862)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/14062024072833/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636862/; classtype:trojan-activity;sid:84499962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636859)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/25092024120601/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636859/; classtype:trojan-activity;sid:84499959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636860)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/08092024115123/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636860/; classtype:trojan-activity;sid:84499960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636855)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/05072024071033/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636855/; classtype:trojan-activity;sid:84499955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636856)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/04102024094250/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636856/; classtype:trojan-activity;sid:84499956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636857)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/01082024101244/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636857/; classtype:trojan-activity;sid:84499957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636850)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/03072024091538/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636850/; classtype:trojan-activity;sid:84499950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636851)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/05082024114357/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636851/; classtype:trojan-activity;sid:84499951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636852)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/10092024070313/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636852/; classtype:trojan-activity;sid:84499952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636853)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/23092024123854/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636853/; classtype:trojan-activity;sid:84499953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636854)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/22082024112941/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636854/; classtype:trojan-activity;sid:84499954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636849)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/08072024113918/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636849/; classtype:trojan-activity;sid:84499949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636847)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8326/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636847/; classtype:trojan-activity;sid:84499947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636843)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11072024110808/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636843/; classtype:trojan-activity;sid:84499943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636845)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/06072024112721/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636845/; classtype:trojan-activity;sid:84499945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636846)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8326/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636846/; classtype:trojan-activity;sid:84499946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636839)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/15072024151521/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636839/; classtype:trojan-activity;sid:84499939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636840)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16072024120102/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636840/; classtype:trojan-activity;sid:84499940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636842)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07102024115226/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636842/; classtype:trojan-activity;sid:84499942; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636836)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/08072024070547/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636836/; classtype:trojan-activity;sid:84499936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636837)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/26092024103307/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636837/; classtype:trojan-activity;sid:84499937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636835)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024134639/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636835/; classtype:trojan-activity;sid:84499935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636833)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/29072024120914/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636833/; classtype:trojan-activity;sid:84499933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636834)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11092024104834/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636834/; classtype:trojan-activity;sid:84499934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636826)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/01072024095738/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636826/; classtype:trojan-activity;sid:84499926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636827)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/10072024073020/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636827/; classtype:trojan-activity;sid:84499927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636828)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/13082024065051/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636828/; classtype:trojan-activity;sid:84499928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636829)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/23092024074730/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636829/; classtype:trojan-activity;sid:84499929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636830)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/05092024071139/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636830/; classtype:trojan-activity;sid:84499930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636831)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/05072024143423/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636831/; classtype:trojan-activity;sid:84499931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636832)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/01072024073548/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636832/; classtype:trojan-activity;sid:84499932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636825)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/16092024075132/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636825/; classtype:trojan-activity;sid:84499925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636824)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/28062024112249/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636824/; classtype:trojan-activity;sid:84499924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636823)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/18072024080738/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636823/; classtype:trojan-activity;sid:84499923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636816)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/06102024112545/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636816/; classtype:trojan-activity;sid:84499916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636817)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/17062024181057/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636817/; classtype:trojan-activity;sid:84499917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636818)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/02072024073145/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636818/; classtype:trojan-activity;sid:84499918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636819)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/21062024070935/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636819/; classtype:trojan-activity;sid:84499919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636820)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/06082024120113/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636820/; classtype:trojan-activity;sid:84499920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636821)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/27062024081736/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636821/; classtype:trojan-activity;sid:84499921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636822)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/29082024071803/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636822/; classtype:trojan-activity;sid:84499922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636815)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/24062024113513/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636815/; classtype:trojan-activity;sid:84499915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636814)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/25072024071606/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636814/; classtype:trojan-activity;sid:84499914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636812)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/12062024085922/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636812/; classtype:trojan-activity;sid:84499912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636813)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/03092024152101/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636813/; classtype:trojan-activity;sid:84499913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636811)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/08072024113231/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636811/; classtype:trojan-activity;sid:84499911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636806)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024130114/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636806/; classtype:trojan-activity;sid:84499906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636807)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16072024114959/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636807/; classtype:trojan-activity;sid:84499907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636809)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/20082024121600/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636809/; classtype:trojan-activity;sid:84499909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636810)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/26092024115544/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636810/; classtype:trojan-activity;sid:84499910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636803)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/28082024070417/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636803/; classtype:trojan-activity;sid:84499903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636804)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26072024143113/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636804/; classtype:trojan-activity;sid:84499904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636800)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/13092024071052/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636800/; classtype:trojan-activity;sid:84499900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636801)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/10062024180136/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636801/; classtype:trojan-activity;sid:84499901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636802)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/23082024175356/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636802/; classtype:trojan-activity;sid:84499902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636799)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/27082024070328/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636799/; classtype:trojan-activity;sid:84499899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636798)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8050/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636798/; classtype:trojan-activity;sid:84499898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636795)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/18062024071837/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636795/; classtype:trojan-activity;sid:84499895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636796)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/18072024120409/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636796/; classtype:trojan-activity;sid:84499896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636797)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/30082024111343/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636797/; classtype:trojan-activity;sid:84499897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636794)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/21082024112544/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636794/; classtype:trojan-activity;sid:84499894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636791)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/19072024111357/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636791/; classtype:trojan-activity;sid:84499891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636784)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/11062024175200/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636784/; classtype:trojan-activity;sid:84499884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636785)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/30072024115935/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636785/; classtype:trojan-activity;sid:84499885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636786)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/02092024114819/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636786/; classtype:trojan-activity;sid:84499886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636788)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/30072024070959/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636788/; classtype:trojan-activity;sid:84499888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636789)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/05092024120909/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636789/; classtype:trojan-activity;sid:84499889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636790)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/05072024112530/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636790/; classtype:trojan-activity;sid:84499890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636783)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/09082024115132/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636783/; classtype:trojan-activity;sid:84499883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636782)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/10092024114316/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636782/; classtype:trojan-activity;sid:84499882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636781)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15082024113136/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636781/; classtype:trojan-activity;sid:84499881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636779)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/04072024170824/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636779/; classtype:trojan-activity;sid:84499879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636780)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/23072024135746/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636780/; classtype:trojan-activity;sid:84499880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636777)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07102024115515/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636777/; classtype:trojan-activity;sid:84499877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636778)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/12072024115926/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636778/; classtype:trojan-activity;sid:84499878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636775)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/05082024082013/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636775/; classtype:trojan-activity;sid:84499875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636776)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/10072024110114/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636776/; classtype:trojan-activity;sid:84499876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636773)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/17072024071919/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636773/; classtype:trojan-activity;sid:84499873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636771)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/19082024070444/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636771/; classtype:trojan-activity;sid:84499871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636772)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/20082024104419/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636772/; classtype:trojan-activity;sid:84499872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636770)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/06082024070754/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636770/; classtype:trojan-activity;sid:84499870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636769)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/12092024074514/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636769/; classtype:trojan-activity;sid:84499869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636768)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/23072024073428/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636768/; classtype:trojan-activity;sid:84499868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636767)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16082024110029/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636767/; classtype:trojan-activity;sid:84499867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636766)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/30072024075615/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636766/; classtype:trojan-activity;sid:84499866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636764)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/24082024173603/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636764/; classtype:trojan-activity;sid:84499864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636763)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/27092024072930/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636763/; classtype:trojan-activity;sid:84499863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636761)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/14092024070825/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636761/; classtype:trojan-activity;sid:84499861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636762)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/10082024105405/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636762/; classtype:trojan-activity;sid:84499862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636760)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/31072024120304/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636760/; classtype:trojan-activity;sid:84499860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636759)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/16082024171045/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636759/; classtype:trojan-activity;sid:84499859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636757)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/19062024083204/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636757/; classtype:trojan-activity;sid:84499857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636758)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/17062024175202/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636758/; classtype:trojan-activity;sid:84499858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636756)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/6011/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636756/; classtype:trojan-activity;sid:84499856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636754)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/09082024071028/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636754/; classtype:trojan-activity;sid:84499854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636753)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/bkp/info.zip"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636753/; classtype:trojan-activity;sid:84499853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636752)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/11062024074638/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636752/; classtype:trojan-activity;sid:84499852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636751)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8318/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636751/; classtype:trojan-activity;sid:84499851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636750)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024071328/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636750/; classtype:trojan-activity;sid:84499850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636749)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/17082024111540/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636749/; classtype:trojan-activity;sid:84499849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636748)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/25072024111710/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636748/; classtype:trojan-activity;sid:84499848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636746)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11062024125639/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636746/; classtype:trojan-activity;sid:84499846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636745)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26062024072316/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636745/; classtype:trojan-activity;sid:84499845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636744)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/18072024152842/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636744/; classtype:trojan-activity;sid:84499844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636743)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/03092024065611/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636743/; classtype:trojan-activity;sid:84499843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636742)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/20082024074454/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636742/; classtype:trojan-activity;sid:84499842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636741)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/14062024182506/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636741/; classtype:trojan-activity;sid:84499841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636740)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/28062024162227/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636740/; classtype:trojan-activity;sid:84499840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636739)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/25082024112344/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636739/; classtype:trojan-activity;sid:84499839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636736)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/05102024112225/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636736/; classtype:trojan-activity;sid:84499836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636737)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/22072024112228/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636737/; classtype:trojan-activity;sid:84499837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636735)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/13092024123948/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636735/; classtype:trojan-activity;sid:84499835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636733)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636733/; classtype:trojan-activity;sid:84499833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636734)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/21082024065715/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636734/; classtype:trojan-activity;sid:84499834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636728)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/21082024163507/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636728/; classtype:trojan-activity;sid:84499828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636729)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/05092024111850/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636729/; classtype:trojan-activity;sid:84499829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636730)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/24072024112124/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636730/; classtype:trojan-activity;sid:84499830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636731)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/pickup/info.zip"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636731/; classtype:trojan-activity;sid:84499831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636732)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/09072024072801/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636732/; classtype:trojan-activity;sid:84499832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636727)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/30082024070843/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636727/; classtype:trojan-activity;sid:84499827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636723)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/15072024111306/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636723/; classtype:trojan-activity;sid:84499823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636724)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/24072024072622/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636724/; classtype:trojan-activity;sid:84499824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636726)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/23082024120742/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636726/; classtype:trojan-activity;sid:84499826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636721)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/15072024121001/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636721/; classtype:trojan-activity;sid:84499821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636722)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/14092024162753/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636722/; classtype:trojan-activity;sid:84499822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636719)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/26072024130538/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636719/; classtype:trojan-activity;sid:84499819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636720)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/01102024075913/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636720/; classtype:trojan-activity;sid:84499820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636717)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/31072024110649/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636717/; classtype:trojan-activity;sid:84499817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636718)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/24092024074236/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636718/; classtype:trojan-activity;sid:84499818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636715)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/26092024073810/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636715/; classtype:trojan-activity;sid:84499815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636716)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/19062024073721/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636716/; classtype:trojan-activity;sid:84499816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636714)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/03102024114713/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636714/; classtype:trojan-activity;sid:84499814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636708)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/27062024134606/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636708/; classtype:trojan-activity;sid:84499808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636709)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/25092024074358/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636709/; classtype:trojan-activity;sid:84499809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636710)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636710/; classtype:trojan-activity;sid:84499810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636711)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/12092024065636/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636711/; classtype:trojan-activity;sid:84499811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636712)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/07082024113359/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636712/; classtype:trojan-activity;sid:84499812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636713)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/14082024102908/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636713/; classtype:trojan-activity;sid:84499813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636705)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/27062024074304/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636705/; classtype:trojan-activity;sid:84499805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636706)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/20092024114457/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636706/; classtype:trojan-activity;sid:84499806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636707)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/idi/info.zip"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636707/; classtype:trojan-activity;sid:84499807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636703)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/05072024105131/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636703/; classtype:trojan-activity;sid:84499803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636704)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/11062024123414/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636704/; classtype:trojan-activity;sid:84499804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636698)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/12062024122748/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636698/; classtype:trojan-activity;sid:84499798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636699)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636699/; classtype:trojan-activity;sid:84499799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636693)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/22082024180206/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636693/; classtype:trojan-activity;sid:84499793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636694)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/20082024172514/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636694/; classtype:trojan-activity;sid:84499794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636695)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/20082024070343/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636695/; classtype:trojan-activity;sid:84499795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636696)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/27092024125844/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636696/; classtype:trojan-activity;sid:84499796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636697)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/01082024070127/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636697/; classtype:trojan-activity;sid:84499797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636685)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/30092024073115/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636685/; classtype:trojan-activity;sid:84499785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636686)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/04102024114428/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636686/; classtype:trojan-activity;sid:84499786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636687)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/17072024162506/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636687/; classtype:trojan-activity;sid:84499787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636688)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/17072024112121/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636688/; classtype:trojan-activity;sid:84499788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636689)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/13062024123930/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636689/; classtype:trojan-activity;sid:84499789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636690)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/20082024114833/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636690/; classtype:trojan-activity;sid:84499790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636691)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/22072024071046/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636691/; classtype:trojan-activity;sid:84499791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636692)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/21082024074934/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636692/; classtype:trojan-activity;sid:84499792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636683)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/12072024073215/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636683/; classtype:trojan-activity;sid:84499783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636684)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/11082024113341/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636684/; classtype:trojan-activity;sid:84499784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636681)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/09092024080429/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636681/; classtype:trojan-activity;sid:84499781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636682)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8342/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636682/; classtype:trojan-activity;sid:84499782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636678)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/16092024071437/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636678/; classtype:trojan-activity;sid:84499778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636679)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/11092024070152/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636679/; classtype:trojan-activity;sid:84499779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636676)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/19072024082257/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636676/; classtype:trojan-activity;sid:84499776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636666)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/02092024173539/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636666/; classtype:trojan-activity;sid:84499766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636667)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/14062024074014/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636667/; classtype:trojan-activity;sid:84499767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636668)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/queue/info.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636668/; classtype:trojan-activity;sid:84499768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636669)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13082024112311/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636669/; classtype:trojan-activity;sid:84499769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636670)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/23072024112852/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636670/; classtype:trojan-activity;sid:84499770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636671)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/13092024094613/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636671/; classtype:trojan-activity;sid:84499771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636672)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/19082024113816/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636672/; classtype:trojan-activity;sid:84499772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636674)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/02082024121949/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636674/; classtype:trojan-activity;sid:84499774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636675)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/10092024185923/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636675/; classtype:trojan-activity;sid:84499775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636662)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/22072024130440/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636662/; classtype:trojan-activity;sid:84499762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636663)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8336/05072024082450/info.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636663/; classtype:trojan-activity;sid:84499763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636664)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/09092024181236/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636664/; classtype:trojan-activity;sid:84499764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636665)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/20082024150907/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636665/; classtype:trojan-activity;sid:84499765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636656)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/22082024114017/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636656/; classtype:trojan-activity;sid:84499756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636657)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/14082024065337/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636657/; classtype:trojan-activity;sid:84499757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636658)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/8059/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636658/; classtype:trojan-activity;sid:84499758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636659)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/03072024154958/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636659/; classtype:trojan-activity;sid:84499759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636660)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/24062024075130/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636660/; classtype:trojan-activity;sid:84499760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3636654)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/18072024070807/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_10_01; reference:url, urlhaus.abuse.ch/url/3636654/; classtype:trojan-activity;sid:84499754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3635840)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"91.197.122.35"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_30; reference:url, urlhaus.abuse.ch/url/3635840/; classtype:trojan-activity;sid:84498940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3635467)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/nano/image.jpg"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"ybgctdtbzvgpdxjivafy.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_09_30; reference:url, urlhaus.abuse.ch/url/3635467/; classtype:trojan-activity;sid:84498567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3634292)"; flow:established,from_client; content:"GET"; http_method; content:"/ziobigiu84/site/raw/refs/heads/main/launcher.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_29; reference:url, urlhaus.abuse.ch/url/3634292/; classtype:trojan-activity;sid:84497392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3633174)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.112.126.123"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_27; reference:url, urlhaus.abuse.ch/url/3633174/; classtype:trojan-activity;sid:84496274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631593)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/installer.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631593/; classtype:trojan-activity;sid:84494693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631583)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/tlp.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631583/; classtype:trojan-activity;sid:84494683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631573)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol11.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631573/; classtype:trojan-activity;sid:84494673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631574)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/1488.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631574/; classtype:trojan-activity;sid:84494674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631575)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/1210.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631575/; classtype:trojan-activity;sid:84494675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631555)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631555/; classtype:trojan-activity;sid:84494655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631554)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/bsg.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_25; reference:url, urlhaus.abuse.ch/url/3631554/; classtype:trojan-activity;sid:84494654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3631233)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"188.95.148.167"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_24; reference:url, urlhaus.abuse.ch/url/3631233/; classtype:trojan-activity;sid:84494333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3630546)"; flow:established,from_client; content:"GET"; http_method; content:"/shaerrlys/fivem-spoofer/raw/refs/heads/main/cfxbypass.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_23; reference:url, urlhaus.abuse.ch/url/3630546/; classtype:trojan-activity;sid:84493646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3628584)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.164.117.74"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_21; reference:url, urlhaus.abuse.ch/url/3628584/; classtype:trojan-activity;sid:84491684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3627935)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.154.188.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_20; reference:url, urlhaus.abuse.ch/url/3627935/; classtype:trojan-activity;sid:84491035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3627210)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"36.154.188.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_19; reference:url, urlhaus.abuse.ch/url/3627210/; classtype:trojan-activity;sid:84490310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3626275)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"74.62.255.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_18; reference:url, urlhaus.abuse.ch/url/3626275/; classtype:trojan-activity;sid:84489375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623786)"; flow:established,from_client; content:"GET"; http_method; content:"/mise.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"210.16.163.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_14; reference:url, urlhaus.abuse.ch/url/3623786/; classtype:trojan-activity;sid:84486886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623408)"; flow:established,from_client; content:"GET"; http_method; content:"/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol1.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623408/; classtype:trojan-activity;sid:84486508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623390)"; flow:established,from_client; content:"GET"; http_method; content:"/123.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"210.16.163.207"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623390/; classtype:trojan-activity;sid:84486490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623131)"; flow:established,from_client; content:"GET"; http_method; content:"/rasadhlp.dll"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"118.25.68.152"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623131/; classtype:trojan-activity;sid:84486231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623126)"; flow:established,from_client; content:"GET"; http_method; content:"/ziobigiu84/site/refs/heads/main/launcher.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623126/; classtype:trojan-activity;sid:84486226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623123)"; flow:established,from_client; content:"GET"; http_method; content:"/midkourtbbe/network/refs/heads/main/software.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623123/; classtype:trojan-activity;sid:84486223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623122)"; flow:established,from_client; content:"GET"; http_method; content:"/anno29/web/refs/heads/main/software.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623122/; classtype:trojan-activity;sid:84486222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623121)"; flow:established,from_client; content:"GET"; http_method; content:"/ilpigna03/site/refs/heads/main/launcher.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623121/; classtype:trojan-activity;sid:84486221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3623120)"; flow:established,from_client; content:"GET"; http_method; content:"/nullarchive/request/refs/heads/main/software.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_09_13; reference:url, urlhaus.abuse.ch/url/3623120/; classtype:trojan-activity;sid:84486220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622759)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/hold/image.jpg"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"ihmmkvkaiwnilneauhfn.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622759/; classtype:trojan-activity;sid:84485859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622638)"; flow:established,from_client; content:"GET"; http_method; content:"/storage/v1/object/public/hold/image.jpg|3f|12711343"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"ihmmkvkaiwnilneauhfn.supabase.co"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622638/; classtype:trojan-activity;sid:84485738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622625)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"www.hcsnet.com.br"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622625/; classtype:trojan-activity;sid:84485725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622623)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_amd64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"www.hcsnet.com.br"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622623/; classtype:trojan-activity;sid:84485723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622624)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_x86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"www.hcsnet.com.br"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622624/; classtype:trojan-activity;sid:84485724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622541)"; flow:established,from_client; content:"GET"; http_method; content:"/125.bin"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"39.105.223.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622541/; classtype:trojan-activity;sid:84485641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622545)"; flow:established,from_client; content:"GET"; http_method; content:"/shellcode.bin"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"39.105.223.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622545/; classtype:trojan-activity;sid:84485645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622548)"; flow:established,from_client; content:"GET"; http_method; content:"/er/326.bin"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"39.105.223.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622548/; classtype:trojan-activity;sid:84485648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622549)"; flow:established,from_client; content:"GET"; http_method; content:"/er/46.bin"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"39.105.223.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622549/; classtype:trojan-activity;sid:84485649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3622539)"; flow:established,from_client; content:"GET"; http_method; content:"/er/1212.bin"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"39.105.223.127"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_12; reference:url, urlhaus.abuse.ch/url/3622539/; classtype:trojan-activity;sid:84485639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3621753)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1okqdyr_kghanl7h_i1mwmlmzfesw_gx0"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_09_11; reference:url, urlhaus.abuse.ch/url/3621753/; classtype:trojan-activity;sid:84484853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3619986)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_amd64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"hcsnet.com.br"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3619986/; classtype:trojan-activity;sid:84483086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3619984)"; flow:established,from_client; content:"GET"; http_method; content:"/x86"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"hcsnet.com.br"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3619984/; classtype:trojan-activity;sid:84483084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3619985)"; flow:established,from_client; content:"GET"; http_method; content:"/linux_x86"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"hcsnet.com.br"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_09_08; reference:url, urlhaus.abuse.ch/url/3619985/; classtype:trojan-activity;sid:84483085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617201)"; flow:established,from_client; content:"GET"; http_method; content:"/19000101/av.scr"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617201/; classtype:trojan-activity;sid:84480301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617196)"; flow:established,from_client; content:"GET"; http_method; content:"/19000101/photo.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617196/; classtype:trojan-activity;sid:84480296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617193)"; flow:established,from_client; content:"GET"; http_method; content:"/19000101/video.scr"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617193/; classtype:trojan-activity;sid:84480293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3617190)"; flow:established,from_client; content:"GET"; http_method; content:"/19000101/video.lnk"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"111.59.254.165"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_09_04; reference:url, urlhaus.abuse.ch/url/3617190/; classtype:trojan-activity;sid:84480290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3615696)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.55.126.179"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_09_02; reference:url, urlhaus.abuse.ch/url/3615696/; classtype:trojan-activity;sid:84478796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614697)"; flow:established,from_client; content:"GET"; http_method; content:"/windowsupdate.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"129.152.20.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_31; reference:url, urlhaus.abuse.ch/url/3614697/; classtype:trojan-activity;sid:84477797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614696)"; flow:established,from_client; content:"GET"; http_method; content:"/windows.x64.silent.cpu.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"129.152.20.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_31; reference:url, urlhaus.abuse.ch/url/3614696/; classtype:trojan-activity;sid:84477796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614280)"; flow:established,from_client; content:"GET"; http_method; content:"/d/mzjfndu3ndewnzjf/dvgihou177.bin"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"od.lk"; http_host; depth:5; isdataat:!1,relative; metadata:created_at 2025_08_30; reference:url, urlhaus.abuse.ch/url/3614280/; classtype:trojan-activity;sid:84477380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3614199)"; flow:established,from_client; content:"GET"; http_method; content:"/827-mh1-3t/827/main/t1.png"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_30; reference:url, urlhaus.abuse.ch/url/3614199/; classtype:trojan-activity;sid:84477299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613683)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"93.126.1.30"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_08_29; reference:url, urlhaus.abuse.ch/url/3613683/; classtype:trojan-activity;sid:84476783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613629)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/pinaview.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"pinaview.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_29; reference:url, urlhaus.abuse.ch/url/3613629/; classtype:trojan-activity;sid:84476729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613494)"; flow:established,from_client; content:"GET"; http_method; content:"/peterson643eu/projecttop/refs/heads/main/zjqppajn.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_29; reference:url, urlhaus.abuse.ch/url/3613494/; classtype:trojan-activity;sid:84476594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3613214)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.43.76.100"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_28; reference:url, urlhaus.abuse.ch/url/3613214/; classtype:trojan-activity;sid:84476314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3612304)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"95.43.76.100"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_27; reference:url, urlhaus.abuse.ch/url/3612304/; classtype:trojan-activity;sid:84475404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3611504)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/usbmmidd_v2.zip"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"www.amyuni.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_25; reference:url, urlhaus.abuse.ch/url/3611504/; classtype:trojan-activity;sid:84474604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610613)"; flow:established,from_client; content:"GET"; http_method; content:"/tfsoft/xftd/v2/ctf/"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"tengfeidn.cn"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610613/; classtype:trojan-activity;sid:84473713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610612)"; flow:established,from_client; content:"GET"; http_method; content:"/tfsoft/xftd/v2/ctf/"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"pcupd.com"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610612/; classtype:trojan-activity;sid:84473712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610604)"; flow:established,from_client; content:"GET"; http_method; content:"/api/upgrade/jd"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"rdm.91yunma.cn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610604/; classtype:trojan-activity;sid:84473704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610602)"; flow:established,from_client; content:"GET"; http_method; content:"/api/upgrade/qcoin"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"rdm.91yunma.cn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610602/; classtype:trojan-activity;sid:84473702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610401)"; flow:established,from_client; content:"GET"; http_method; content:"/temp/mely.exe"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"areyouready.co.za"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610401/; classtype:trojan-activity;sid:84473501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610381)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/loic/raw/refs/heads/master/loic.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610381/; classtype:trojan-activity;sid:84473481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3610380)"; flow:established,from_client; content:"GET"; http_method; content:"/raizydaizy/steamcmd/raw/refs/heads/main/steamcmd.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_08_24; reference:url, urlhaus.abuse.ch/url/3610380/; classtype:trojan-activity;sid:84473480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3609741)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"190.186.28.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_23; reference:url, urlhaus.abuse.ch/url/3609741/; classtype:trojan-activity;sid:84472841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608522)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/22072024080730/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608522/; classtype:trojan-activity;sid:84471622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608521)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/17062024123023/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608521/; classtype:trojan-activity;sid:84471621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608520)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/14082024082341/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608520/; classtype:trojan-activity;sid:84471620; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608519)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/09072024080408/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608519/; classtype:trojan-activity;sid:84471619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608518)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/11072024072520/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608518/; classtype:trojan-activity;sid:84471618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608517)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8029/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608517/; classtype:trojan-activity;sid:84471617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608511)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/10092024072747/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608511/; classtype:trojan-activity;sid:84471611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608513)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/23092024080311/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608513/; classtype:trojan-activity;sid:84471613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608506)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/02082024071413/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608506/; classtype:trojan-activity;sid:84471606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608503)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/23092024103542/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608503/; classtype:trojan-activity;sid:84471603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608500)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/15072024075523/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608500/; classtype:trojan-activity;sid:84471600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608487)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/13082024070204/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608487/; classtype:trojan-activity;sid:84471587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608488)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/14062024075221/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608488/; classtype:trojan-activity;sid:84471588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608491)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/12082024075637/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608491/; classtype:trojan-activity;sid:84471591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608492)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/16082024071234/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608492/; classtype:trojan-activity;sid:84471592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608493)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/13072024070443/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608493/; classtype:trojan-activity;sid:84471593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608496)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/18062024074945/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608496/; classtype:trojan-activity;sid:84471596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608497)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8051/22082024110801/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608497/; classtype:trojan-activity;sid:84471597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608482)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/12092024121832/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608482/; classtype:trojan-activity;sid:84471582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608483)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8461/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608483/; classtype:trojan-activity;sid:84471583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608479)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/10092024080037/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608479/; classtype:trojan-activity;sid:84471579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608471)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/28082024112055/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608471/; classtype:trojan-activity;sid:84471571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608474)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/11062024140819/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608474/; classtype:trojan-activity;sid:84471574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608470)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/6011/25072024071607/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608470/; classtype:trojan-activity;sid:84471570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608466)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8059/17082024070657/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608466/; classtype:trojan-activity;sid:84471566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3608467)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/8050/11072024122345/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3608467/; classtype:trojan-activity;sid:84471567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3607915)"; flow:established,from_client; content:"GET"; http_method; content:"/linpeas.sh"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"34.70.102.215"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_21; reference:url, urlhaus.abuse.ch/url/3607915/; classtype:trojan-activity;sid:84471015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606770)"; flow:established,from_client; content:"GET"; http_method; content:"/d1ovu/pon/refs/heads/main/rustmedebyg.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606770/; classtype:trojan-activity;sid:84469870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606767)"; flow:established,from_client; content:"GET"; http_method; content:"/d1ovu/pon/refs/heads/main/rustme.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606767/; classtype:trojan-activity;sid:84469867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606766)"; flow:established,from_client; content:"GET"; http_method; content:"/d1ovu/pon/refs/heads/main/debugconfig.bat"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606766/; classtype:trojan-activity;sid:84469866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606680)"; flow:established,from_client; content:"GET"; http_method; content:"/atu.lim"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"electri.billregulator.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606680/; classtype:trojan-activity;sid:84469780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3606577)"; flow:established,from_client; content:"GET"; http_method; content:"/2508/9e3363f017c60726bf610a2a472040144t."; http_uri; depth:41; isdataat:!1,relative; nocase; content:"file.uhsea.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_19; reference:url, urlhaus.abuse.ch/url/3606577/; classtype:trojan-activity;sid:84469677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3605878)"; flow:established,from_client; content:"GET"; http_method; content:"/bot.zip"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"130.61.147.74"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_18; reference:url, urlhaus.abuse.ch/url/3605878/; classtype:trojan-activity;sid:84468978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3604879)"; flow:established,from_client; content:"GET"; http_method; content:"/keepon.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"209.145.51.44"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_16; reference:url, urlhaus.abuse.ch/url/3604879/; classtype:trojan-activity;sid:84467979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3604243)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.196.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_15; reference:url, urlhaus.abuse.ch/url/3604243/; classtype:trojan-activity;sid:84467343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3601597)"; flow:established,from_client; content:"GET"; http_method; content:"/runtime/vc_redist.x64.exe"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"checkfivem.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_13; reference:url, urlhaus.abuse.ch/url/3601597/; classtype:trojan-activity;sid:84464697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3600845)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"83.217.16.24"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_08_11; reference:url, urlhaus.abuse.ch/url/3600845/; classtype:trojan-activity;sid:84463945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3599101)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.90.236.250"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_08; reference:url, urlhaus.abuse.ch/url/3599101/; classtype:trojan-activity;sid:84462201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3599106)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.54.221.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_08_08; reference:url, urlhaus.abuse.ch/url/3599106/; classtype:trojan-activity;sid:84462206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3597150)"; flow:established,from_client; content:"GET"; http_method; content:"/zmyjungmin/img001.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_05; reference:url, urlhaus.abuse.ch/url/3597150/; classtype:trojan-activity;sid:84460250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3594962)"; flow:established,from_client; content:"GET"; http_method; content:"/.ssa/t1.png"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"isiore.com.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_08_02; reference:url, urlhaus.abuse.ch/url/3594962/; classtype:trojan-activity;sid:84458062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3594942)"; flow:established,from_client; content:"GET"; http_method; content:"/r00tnik8/zianr35524869492586/raw/refs/heads/main/plugin3.plg"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_08_02; reference:url, urlhaus.abuse.ch/url/3594942/; classtype:trojan-activity;sid:84458042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3592914)"; flow:established,from_client; content:"GET"; http_method; content:"/1.js"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"seputartuban.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_07_30; reference:url, urlhaus.abuse.ch/url/3592914/; classtype:trojan-activity;sid:84456014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3592038)"; flow:established,from_client; content:"GET"; http_method; content:"/image/cache/data/aksesuarlar/patch-yama-arma/skid-row-500x500.jpg"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"xshop.com.tr"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_07_29; reference:url, urlhaus.abuse.ch/url/3592038/; classtype:trojan-activity;sid:84455138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590749)"; flow:established,from_client; content:"GET"; http_method; content:"/amineamine284/d3dx11_45/refs/heads/main/d3dx11_45.dll"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590749/; classtype:trojan-activity;sid:84453849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590748)"; flow:established,from_client; content:"GET"; http_method; content:"/amineamine284/rssdgxgr/refs/heads/main/garo%20x.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590748/; classtype:trojan-activity;sid:84453848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590746)"; flow:established,from_client; content:"GET"; http_method; content:"/amineamine284/edggqdsg/refs/heads/main/garo%20v1.dll"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590746/; classtype:trojan-activity;sid:84453846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590552)"; flow:established,from_client; content:"GET"; http_method; content:"/hafiz12cyber/request/raw/refs/heads/main/launcher.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590552/; classtype:trojan-activity;sid:84453652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590550)"; flow:established,from_client; content:"GET"; http_method; content:"/midkourtbbe/network/raw/refs/heads/main/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590550/; classtype:trojan-activity;sid:84453650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590549)"; flow:established,from_client; content:"GET"; http_method; content:"/anno29/web/raw/refs/heads/main/software.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590549/; classtype:trojan-activity;sid:84453649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590548)"; flow:established,from_client; content:"GET"; http_method; content:"/notcat999/sys/raw/refs/heads/main/software.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590548/; classtype:trojan-activity;sid:84453648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590547)"; flow:established,from_client; content:"GET"; http_method; content:"/gethalal-007/request/raw/refs/heads/main/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590547/; classtype:trojan-activity;sid:84453647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3590546)"; flow:established,from_client; content:"GET"; http_method; content:"/nullarchive/request/raw/refs/heads/main/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_27; reference:url, urlhaus.abuse.ch/url/3590546/; classtype:trojan-activity;sid:84453646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3587551)"; flow:established,from_client; content:"GET"; http_method; content:"//2025/07/19/15/683192372.png"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"www2.0zz0.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_21; reference:url, urlhaus.abuse.ch/url/3587551/; classtype:trojan-activity;sid:84450651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3585169)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.236.116.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3585169/; classtype:trojan-activity;sid:84448269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3585053)"; flow:established,from_client; content:"GET"; http_method; content:"/catalog/model/cummersmg.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"kavacanada.ca"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3585053/; classtype:trojan-activity;sid:84448153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3585052)"; flow:established,from_client; content:"GET"; http_method; content:"/catalog/model/cheekpiecegar.ps1"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"kavacanada.ca"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_17; reference:url, urlhaus.abuse.ch/url/3585052/; classtype:trojan-activity;sid:84448152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3584281)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.204.227"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_07_16; reference:url, urlhaus.abuse.ch/url/3584281/; classtype:trojan-activity;sid:84447381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3583040)"; flow:established,from_client; content:"GET"; http_method; content:"/laurenxss/42429a19c72b875b93608f8cb0cab933/raw/"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"gist.githubusercontent.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_07_14; reference:url, urlhaus.abuse.ch/url/3583040/; classtype:trojan-activity;sid:84446140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3580884)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.153.132"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_07_11; reference:url, urlhaus.abuse.ch/url/3580884/; classtype:trojan-activity;sid:84443984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3578386)"; flow:established,from_client; content:"GET"; http_method; content:"/invisiblebunny/records/main/bunny-mini/mini.shell.php"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_07; reference:url, urlhaus.abuse.ch/url/3578386/; classtype:trojan-activity;sid:84441486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3578385)"; flow:established,from_client; content:"GET"; http_method; content:"/ly4k/pwnkit/main/pwnkit"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_07; reference:url, urlhaus.abuse.ch/url/3578385/; classtype:trojan-activity;sid:84441485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575978)"; flow:established,from_client; content:"GET"; http_method; content:"/allbnc.jpg"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"185.253.75.188"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575978/; classtype:trojan-activity;sid:84439078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575971)"; flow:established,from_client; content:"GET"; http_method; content:"/a.sh"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.253.75.188"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575971/; classtype:trojan-activity;sid:84439071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575892)"; flow:established,from_client; content:"GET"; http_method; content:"/cata2.jpg"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"185.253.75.188"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_05; reference:url, urlhaus.abuse.ch/url/3575892/; classtype:trojan-activity;sid:84438992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575355)"; flow:established,from_client; content:"GET"; http_method; content:"/labubu99999/localoco8386/main/shaman.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_07_04; reference:url, urlhaus.abuse.ch/url/3575355/; classtype:trojan-activity;sid:84438455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3575354)"; flow:established,from_client; content:"GET"; http_method; content:"/labubu99999/localoco8386/raw/main/update0.bat"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_07_04; reference:url, urlhaus.abuse.ch/url/3575354/; classtype:trojan-activity;sid:84438454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3573965)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"222.239.87.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_07_02; reference:url, urlhaus.abuse.ch/url/3573965/; classtype:trojan-activity;sid:84437065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3573963)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"110.227.197.204"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_07_02; reference:url, urlhaus.abuse.ch/url/3573963/; classtype:trojan-activity;sid:84437063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3573084)"; flow:established,from_client; content:"GET"; http_method; content:"/chrome_134.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"lomejordesalamanca.es"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_07_01; reference:url, urlhaus.abuse.ch/url/3573084/; classtype:trojan-activity;sid:84436184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3572294)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.142.68"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_07_01; reference:url, urlhaus.abuse.ch/url/3572294/; classtype:trojan-activity;sid:84435394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3570433)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.120.203.230"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_06_26; reference:url, urlhaus.abuse.ch/url/3570433/; classtype:trojan-activity;sid:84433533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3570158)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"90.8.83.87"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_25; reference:url, urlhaus.abuse.ch/url/3570158/; classtype:trojan-activity;sid:84433258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3569802)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"90.8.83.87"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_24; reference:url, urlhaus.abuse.ch/url/3569802/; classtype:trojan-activity;sid:84432902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3569803)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"90.8.83.87"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_24; reference:url, urlhaus.abuse.ch/url/3569803/; classtype:trojan-activity;sid:84432903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3569088)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/images/trapapo.ps1"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"www.vuelaviajero.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_06_22; reference:url, urlhaus.abuse.ch/url/3569088/; classtype:trojan-activity;sid:84432188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568977)"; flow:established,from_client; content:"GET"; http_method; content:"/aminer.gz"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"162.215.218.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_21; reference:url, urlhaus.abuse.ch/url/3568977/; classtype:trojan-activity;sid:84432077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3568976)"; flow:established,from_client; content:"GET"; http_method; content:"/install.tgz"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"162.215.218.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_21; reference:url, urlhaus.abuse.ch/url/3568976/; classtype:trojan-activity;sid:84432076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565262)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/dao/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565262/; classtype:trojan-activity;sid:84428362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565260)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp%20-%20copia/badmail/info.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565260/; classtype:trojan-activity;sid:84428360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565261)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/cons/1/info.zip"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565261/; classtype:trojan-activity;sid:84428361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565259)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/1/info.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565259/; classtype:trojan-activity;sid:84428359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565258)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp%20-%20copia/info.zip"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565258/; classtype:trojan-activity;sid:84428358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565257)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/delcacheprodutoseg/info.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565257/; classtype:trojan-activity;sid:84428357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565256)"; flow:established,from_client; content:"GET"; http_method; content:"/bkp/info.zip"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565256/; classtype:trojan-activity;sid:84428356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565255)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp%20-%20copia/queue/info.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565255/; classtype:trojan-activity;sid:84428355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565254)"; flow:established,from_client; content:"GET"; http_method; content:"/relftp/info.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565254/; classtype:trojan-activity;sid:84428354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565253)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp%20-%20copia/drop/info.zip"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565253/; classtype:trojan-activity;sid:84428353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565252)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp/info.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565252/; classtype:trojan-activity;sid:84428352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565249)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp%20-%20copia/pickup/info.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565249/; classtype:trojan-activity;sid:84428349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565244)"; flow:established,from_client; content:"GET"; http_method; content:"/h4lud3ae/info.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565244/; classtype:trojan-activity;sid:84428344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565245)"; flow:established,from_client; content:"GET"; http_method; content:"/install/info.zip"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565245/; classtype:trojan-activity;sid:84428345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565246)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/cons/info.zip"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565246/; classtype:trojan-activity;sid:84428346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565243)"; flow:established,from_client; content:"GET"; http_method; content:"/relftp/pdf/info.zip"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565243/; classtype:trojan-activity;sid:84428343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565230)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/1/info.zip"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565230/; classtype:trojan-activity;sid:84428330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565236)"; flow:established,from_client; content:"GET"; http_method; content:"/idi/info.zip"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565236/; classtype:trojan-activity;sid:84428336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565239)"; flow:established,from_client; content:"GET"; http_method; content:"/tmpftp/extcons/info.zip"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565239/; classtype:trojan-activity;sid:84428339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565240)"; flow:established,from_client; content:"GET"; http_method; content:"/exeftp%20-%20copia/idi/info.zip"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565240/; classtype:trojan-activity;sid:84428340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565241)"; flow:established,from_client; content:"GET"; http_method; content:"/gdbftp/info.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565241/; classtype:trojan-activity;sid:84428341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565091)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/cksy/info.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565091/; classtype:trojan-activity;sid:84428191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565090)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/service/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565090/; classtype:trojan-activity;sid:84428190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565089)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/rgsy/info.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565089/; classtype:trojan-activity;sid:84428189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565088)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/dto/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565088/; classtype:trojan-activity;sid:84428188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565087)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/entity/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565087/; classtype:trojan-activity;sid:84428187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565085)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/info.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565085/; classtype:trojan-activity;sid:84428185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565086)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/info.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565086/; classtype:trojan-activity;sid:84428186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565084)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/info.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565084/; classtype:trojan-activity;sid:84428184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565083)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/entity/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565083/; classtype:trojan-activity;sid:84428183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565082)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/constrant/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565082/; classtype:trojan-activity;sid:84428182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565081)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/dao/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565081/; classtype:trojan-activity;sid:84428181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565080)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565080/; classtype:trojan-activity;sid:84428180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565079)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565079/; classtype:trojan-activity;sid:84428179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565078)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/log/info.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565078/; classtype:trojan-activity;sid:84428178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565077)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565077/; classtype:trojan-activity;sid:84428177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565076)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/chkptwss/info.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565076/; classtype:trojan-activity;sid:84428176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565075)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/images/new/info.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565075/; classtype:trojan-activity;sid:84428175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565074)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/info.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565074/; classtype:trojan-activity;sid:84428174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565073)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/photoset/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565073/; classtype:trojan-activity;sid:84428173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565072)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/templete/info.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565072/; classtype:trojan-activity;sid:84428172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565071)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/service/impl/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565071/; classtype:trojan-activity;sid:84428171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565070)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/action/info.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565070/; classtype:trojan-activity;sid:84428170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565069)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/vehiclereview/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565069/; classtype:trojan-activity;sid:84428169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565068)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/root/org/info.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565068/; classtype:trojan-activity;sid:84428168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565066)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/css1/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565066/; classtype:trojan-activity;sid:84428166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565067)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/base/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565067/; classtype:trojan-activity;sid:84428167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565065)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/zbawss/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565065/; classtype:trojan-activity;sid:84428165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565064)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/entity/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565064/; classtype:trojan-activity;sid:84428164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565062)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/set/info.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565062/; classtype:trojan-activity;sid:84428162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565063)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/dto/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565063/; classtype:trojan-activity;sid:84428163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565061)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/service/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565061/; classtype:trojan-activity;sid:84428161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565060)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/root/org/apache/info.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565060/; classtype:trojan-activity;sid:84428160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565059)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/templete/info.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565059/; classtype:trojan-activity;sid:84428159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565057)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/photo/info.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565057/; classtype:trojan-activity;sid:84428157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565058)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/service/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565058/; classtype:trojan-activity;sid:84428158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565056)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/entity/info.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565056/; classtype:trojan-activity;sid:84428156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565054)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565054/; classtype:trojan-activity;sid:84428154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565049)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/service/impl/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565049/; classtype:trojan-activity;sid:84428149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565050)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/hdk/localxml.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565050/; classtype:trojan-activity;sid:84428150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565051)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/info.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565051/; classtype:trojan-activity;sid:84428151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565048)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/dto/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565048/; classtype:trojan-activity;sid:84428148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565044)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/action/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565044/; classtype:trojan-activity;sid:84428144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565043)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/entity/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565043/; classtype:trojan-activity;sid:84428143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565040)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/servacpt/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565040/; classtype:trojan-activity;sid:84428140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565035)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/temp/info.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565035/; classtype:trojan-activity;sid:84428135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565034)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/dto/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565034/; classtype:trojan-activity;sid:84428134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565030)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/pdauser/action/info.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565030/; classtype:trojan-activity;sid:84428130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565029)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/sysparam/info.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565029/; classtype:trojan-activity;sid:84428129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565024)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/info.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565024/; classtype:trojan-activity;sid:84428124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565017)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/client/info.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565017/; classtype:trojan-activity;sid:84428117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565018)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565018/; classtype:trojan-activity;sid:84428118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565016)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565016/; classtype:trojan-activity;sid:84428116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565015)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/info.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565015/; classtype:trojan-activity;sid:84428115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565014)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/dao/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565014/; classtype:trojan-activity;sid:84428114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565008)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/interceptor/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565008/; classtype:trojan-activity;sid:84428108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565009)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/plugin/info.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565009/; classtype:trojan-activity;sid:84428109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565010)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/dto/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565010/; classtype:trojan-activity;sid:84428110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565011)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/info.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565011/; classtype:trojan-activity;sid:84428111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565004)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/info.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565004/; classtype:trojan-activity;sid:84428104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3565001)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/info.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3565001/; classtype:trojan-activity;sid:84428101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564999)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/dto/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564999/; classtype:trojan-activity;sid:84428099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564992)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/service/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564992/; classtype:trojan-activity;sid:84428092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564993)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/mgr/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564993/; classtype:trojan-activity;sid:84428093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564990)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/visitwss/info.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564990/; classtype:trojan-activity;sid:84428090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564988)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/info.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564988/; classtype:trojan-activity;sid:84428088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564986)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/wss/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564986/; classtype:trojan-activity;sid:84428086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564985)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/pdawss/dto/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564985/; classtype:trojan-activity;sid:84428085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564984)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564984/; classtype:trojan-activity;sid:84428084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564983)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/info.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564983/; classtype:trojan-activity;sid:84428083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564980)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/exception/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564980/; classtype:trojan-activity;sid:84428080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564979)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/dao/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564979/; classtype:trojan-activity;sid:84428079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564977)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564977/; classtype:trojan-activity;sid:84428077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564975)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564975/; classtype:trojan-activity;sid:84428075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564976)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/dao/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564976/; classtype:trojan-activity;sid:84428076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564974)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/service/impl/info.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564974/; classtype:trojan-activity;sid:84428074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564972)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/dao/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564972/; classtype:trojan-activity;sid:84428072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564971)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/hdk/localxml.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564971/; classtype:trojan-activity;sid:84428071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564969)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/info.zip"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564969/; classtype:trojan-activity;sid:84428069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564968)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/service/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564968/; classtype:trojan-activity;sid:84428068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564966)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/rgsy/info.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564966/; classtype:trojan-activity;sid:84428066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564965)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/dao/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564965/; classtype:trojan-activity;sid:84428065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564964)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/info.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564964/; classtype:trojan-activity;sid:84428064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564960)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/info.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564960/; classtype:trojan-activity;sid:84428060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564961)"; flow:established,from_client; content:"GET"; http_method; content:"/aspnet_client/system_web/info.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564961/; classtype:trojan-activity;sid:84428061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564958)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/dto/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564958/; classtype:trojan-activity;sid:84428058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564957)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/action/info.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564957/; classtype:trojan-activity;sid:84428057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564956)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/conf/catalina/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564956/; classtype:trojan-activity;sid:84428056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564953)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564953/; classtype:trojan-activity;sid:84428053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564948)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/service/impl/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564948/; classtype:trojan-activity;sid:84428048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564949)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/info.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564949/; classtype:trojan-activity;sid:84428049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564944)"; flow:established,from_client; content:"GET"; http_method; content:"/2345downloads/info.zip"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564944/; classtype:trojan-activity;sid:84428044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564937)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/lib/info.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564937/; classtype:trojan-activity;sid:84428037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564938)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/info.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564938/; classtype:trojan-activity;sid:84428038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564939)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/service/impl/info.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564939/; classtype:trojan-activity;sid:84428039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564940)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/record/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564940/; classtype:trojan-activity;sid:84428040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564935)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/info.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564935/; classtype:trojan-activity;sid:84428035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564936)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/info.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564936/; classtype:trojan-activity;sid:84428036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564931)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/mgr/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564931/; classtype:trojan-activity;sid:84428031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564927)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/nvrsetting/info.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564927/; classtype:trojan-activity;sid:84428027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564925)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/css1/_notes/info.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564925/; classtype:trojan-activity;sid:84428025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564926)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/rgsy/system/info.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564926/; classtype:trojan-activity;sid:84428026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564924)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/info.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564924/; classtype:trojan-activity;sid:84428024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564920)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/base/dto/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564920/; classtype:trojan-activity;sid:84428020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564908)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/web/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564908/; classtype:trojan-activity;sid:84428008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564909)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/info.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564909/; classtype:trojan-activity;sid:84428009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564906)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/lib/info.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564906/; classtype:trojan-activity;sid:84428006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564903)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/base/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564903/; classtype:trojan-activity;sid:84428003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564902)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/unusual/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564902/; classtype:trojan-activity;sid:84428002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564900)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564900/; classtype:trojan-activity;sid:84428000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564899)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/pub/info.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564899/; classtype:trojan-activity;sid:84427999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564898)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/info.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564898/; classtype:trojan-activity;sid:84427998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564895)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/cyzpdytemp/info.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564895/; classtype:trojan-activity;sid:84427995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564896)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/systemset/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564896/; classtype:trojan-activity;sid:84427996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564893)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/viewwss/info.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564893/; classtype:trojan-activity;sid:84427993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564894)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/util/info.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564894/; classtype:trojan-activity;sid:84427994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564892)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/wss/util/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564892/; classtype:trojan-activity;sid:84427992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564888)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/info.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564888/; classtype:trojan-activity;sid:84427988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564889)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/util/nvr/info.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564889/; classtype:trojan-activity;sid:84427989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564882)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564882/; classtype:trojan-activity;sid:84427982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564883)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/com/vkl/ckts_pc/cksy/info.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564883/; classtype:trojan-activity;sid:84427983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564881)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/sysparam/info.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564881/; classtype:trojan-activity;sid:84427981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564878)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/bin/tomcat8.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564878/; classtype:trojan-activity;sid:84427978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564876)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/info.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564876/; classtype:trojan-activity;sid:84427976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564874)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/info.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564874/; classtype:trojan-activity;sid:84427974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564871)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/dao/info.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564871/; classtype:trojan-activity;sid:84427971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564866)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/dao/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564866/; classtype:trojan-activity;sid:84427966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564861)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/action/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564861/; classtype:trojan-activity;sid:84427961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564862)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/info.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564862/; classtype:trojan-activity;sid:84427962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564863)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/dto/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564863/; classtype:trojan-activity;sid:84427963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564858)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/vehicleinformation/info.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564858/; classtype:trojan-activity;sid:84427958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564859)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/logs/info.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564859/; classtype:trojan-activity;sid:84427959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564855)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/entity/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564855/; classtype:trojan-activity;sid:84427955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564852)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/entity/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564852/; classtype:trojan-activity;sid:84427952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564850)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/info.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564850/; classtype:trojan-activity;sid:84427950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564849)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564849/; classtype:trojan-activity;sid:84427949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564847)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/utils/excel/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564847/; classtype:trojan-activity;sid:84427947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564845)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/service/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564845/; classtype:trojan-activity;sid:84427945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564844)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/szclient/info.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564844/; classtype:trojan-activity;sid:84427944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564838)"; flow:established,from_client; content:"GET"; http_method; content:"/futai/info.zip"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564838/; classtype:trojan-activity;sid:84427938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564839)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564839/; classtype:trojan-activity;sid:84427939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564832)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/service/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564832/; classtype:trojan-activity;sid:84427932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564819)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564819/; classtype:trojan-activity;sid:84427919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564820)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564820/; classtype:trojan-activity;sid:84427920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564821)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/dto/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564821/; classtype:trojan-activity;sid:84427921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564822)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/service/impl/info.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564822/; classtype:trojan-activity;sid:84427922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564823)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564823/; classtype:trojan-activity;sid:84427923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564809)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/jurisdict/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564809/; classtype:trojan-activity;sid:84427909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564810)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/set/service/info.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564810/; classtype:trojan-activity;sid:84427910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564812)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/exception/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564812/; classtype:trojan-activity;sid:84427912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564807)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/hdk/hcnetsdkcom/info.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564807/; classtype:trojan-activity;sid:84427907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564808)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564808/; classtype:trojan-activity;sid:84427908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564804)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/dao/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564804/; classtype:trojan-activity;sid:84427904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564801)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/chkptwss/mgr/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564801/; classtype:trojan-activity;sid:84427901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564800)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/info.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564800/; classtype:trojan-activity;sid:84427900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564799)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/pub/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564799/; classtype:trojan-activity;sid:84427899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564797)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/cksy/info.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564797/; classtype:trojan-activity;sid:84427897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564796)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/info.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564796/; classtype:trojan-activity;sid:84427896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564794)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/info.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564794/; classtype:trojan-activity;sid:84427894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564793)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/info.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564793/; classtype:trojan-activity;sid:84427893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564791)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/hdk/hcnetsdkcom/info.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564791/; classtype:trojan-activity;sid:84427891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564787)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/info.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564787/; classtype:trojan-activity;sid:84427887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564785)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/pub/info.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564785/; classtype:trojan-activity;sid:84427885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564783)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/service/info.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564783/; classtype:trojan-activity;sid:84427883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564784)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564784/; classtype:trojan-activity;sid:84427884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564781)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/info.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564781/; classtype:trojan-activity;sid:84427881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564782)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/js/info.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564782/; classtype:trojan-activity;sid:84427882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564780)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/com/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564780/; classtype:trojan-activity;sid:84427880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564778)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/count/web/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564778/; classtype:trojan-activity;sid:84427878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564777)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/base/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564777/; classtype:trojan-activity;sid:84427877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564776)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/dto/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564776/; classtype:trojan-activity;sid:84427876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564769)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564769/; classtype:trojan-activity;sid:84427869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564770)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/meta-inf/info.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564770/; classtype:trojan-activity;sid:84427870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564771)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/wss/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564771/; classtype:trojan-activity;sid:84427871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564766)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/root/org/apache/jsp/info.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564766/; classtype:trojan-activity;sid:84427866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564761)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/utils/nvr/info.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564761/; classtype:trojan-activity;sid:84427861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564760)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/web/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564760/; classtype:trojan-activity;sid:84427860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564755)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/meta-inf/info.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564755/; classtype:trojan-activity;sid:84427855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564756)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/service/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564756/; classtype:trojan-activity;sid:84427856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564757)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/conf/info.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564757/; classtype:trojan-activity;sid:84427857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564753)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/mgr/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564753/; classtype:trojan-activity;sid:84427853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564752)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/action/info.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564752/; classtype:trojan-activity;sid:84427852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564749)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/visitwss/dao/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564749/; classtype:trojan-activity;sid:84427849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564748)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564748/; classtype:trojan-activity;sid:84427848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564747)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/dto/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564747/; classtype:trojan-activity;sid:84427847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564746)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/css/info.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564746/; classtype:trojan-activity;sid:84427846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564743)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/viewwss/mgr/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564743/; classtype:trojan-activity;sid:84427843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564739)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/service/impl/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564739/; classtype:trojan-activity;sid:84427839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564740)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/chkptwss/dto/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564740/; classtype:trojan-activity;sid:84427840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564737)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/action/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564737/; classtype:trojan-activity;sid:84427837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564734)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/exception/info.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564734/; classtype:trojan-activity;sid:84427834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564735)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564735/; classtype:trojan-activity;sid:84427835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564736)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/dao/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564736/; classtype:trojan-activity;sid:84427836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564731)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/images/info.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564731/; classtype:trojan-activity;sid:84427831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564726)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/download/info.zip"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564726/; classtype:trojan-activity;sid:84427826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564724)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/info.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564724/; classtype:trojan-activity;sid:84427824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564725)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/hdk/info.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564725/; classtype:trojan-activity;sid:84427825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564720)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/controller/info.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564720/; classtype:trojan-activity;sid:84427820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564717)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/dto/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564717/; classtype:trojan-activity;sid:84427817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564718)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/info.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564718/; classtype:trojan-activity;sid:84427818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564715)"; flow:established,from_client; content:"GET"; http_method; content:"/xinheyuan/info.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564715/; classtype:trojan-activity;sid:84427815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564713)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/dao/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564713/; classtype:trojan-activity;sid:84427813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564711)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/dao/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564711/; classtype:trojan-activity;sid:84427811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564706)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/mgr/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564706/; classtype:trojan-activity;sid:84427806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564703)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/info.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564703/; classtype:trojan-activity;sid:84427803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564704)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/service/impl/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564704/; classtype:trojan-activity;sid:84427804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564700)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/pdawss/mgr/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564700/; classtype:trojan-activity;sid:84427800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564697)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/dao/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564697/; classtype:trojan-activity;sid:84427797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564693)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/spotcheck/info.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564693/; classtype:trojan-activity;sid:84427793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564694)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/static/images/icons/info.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564694/; classtype:trojan-activity;sid:84427794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564685)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/hdk/info.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564685/; classtype:trojan-activity;sid:84427785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564686)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/info.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564686/; classtype:trojan-activity;sid:84427786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564687)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/service/info.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564687/; classtype:trojan-activity;sid:84427787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564681)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/mgr/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564681/; classtype:trojan-activity;sid:84427781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564682)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564682/; classtype:trojan-activity;sid:84427782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564675)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/lib/info.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564675/; classtype:trojan-activity;sid:84427775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564674)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564674/; classtype:trojan-activity;sid:84427774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564673)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/bin/info.zip"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564673/; classtype:trojan-activity;sid:84427773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564672)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/pdauser/dao/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564672/; classtype:trojan-activity;sid:84427772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564671)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/videosetting/entity/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564671/; classtype:trojan-activity;sid:84427771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564669)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/info.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564669/; classtype:trojan-activity;sid:84427769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564670)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/jurisdict/service/impl/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564670/; classtype:trojan-activity;sid:84427770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564666)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/utils/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564666/; classtype:trojan-activity;sid:84427766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564667)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/gbrwrite/dao/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564667/; classtype:trojan-activity;sid:84427767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564665)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/dao/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564665/; classtype:trojan-activity;sid:84427765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564659)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/service/impl/info.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564659/; classtype:trojan-activity;sid:84427759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564660)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/spotckeck/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564660/; classtype:trojan-activity;sid:84427760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564653)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/entity/info.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564653/; classtype:trojan-activity;sid:84427753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564654)"; flow:established,from_client; content:"GET"; http_method; content:"/hengsheng/info.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564654/; classtype:trojan-activity;sid:84427754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564655)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/info.zip"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564655/; classtype:trojan-activity;sid:84427755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564648)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/vehicleinformation/service/impl/info.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564648/; classtype:trojan-activity;sid:84427748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564644)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/pdauser/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564644/; classtype:trojan-activity;sid:84427744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564640)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/base/dto/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564640/; classtype:trojan-activity;sid:84427740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564641)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/dao/info.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564641/; classtype:trojan-activity;sid:84427741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564636)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/dto/info.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564636/; classtype:trojan-activity;sid:84427736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564638)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/base/dao/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564638/; classtype:trojan-activity;sid:84427738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564633)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/visitwss/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564633/; classtype:trojan-activity;sid:84427733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564634)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/service/info.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564634/; classtype:trojan-activity;sid:84427734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564635)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/info.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564635/; classtype:trojan-activity;sid:84427735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564630)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/entity/info.zip"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564630/; classtype:trojan-activity;sid:84427730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564629)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/dept/info.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564629/; classtype:trojan-activity;sid:84427729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564620)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/info.zip"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564620/; classtype:trojan-activity;sid:84427720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564621)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/unusual/service/info.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564621/; classtype:trojan-activity;sid:84427721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564616)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/statistic/log/web/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564616/; classtype:trojan-activity;sid:84427716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564611)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/dept/web/info.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564611/; classtype:trojan-activity;sid:84427711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564599)"; flow:established,from_client; content:"GET"; http_method; content:"/guirui/info.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564599/; classtype:trojan-activity;sid:84427699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564600)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/info.zip"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564600/; classtype:trojan-activity;sid:84427700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564601)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564601/; classtype:trojan-activity;sid:84427701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564602)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/sysparam/action/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564602/; classtype:trojan-activity;sid:84427702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564603)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/datawrite/action/info.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564603/; classtype:trojan-activity;sid:84427703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564597)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/dao/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564597/; classtype:trojan-activity;sid:84427697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564598)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/info.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564598/; classtype:trojan-activity;sid:84427698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564594)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/info.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564594/; classtype:trojan-activity;sid:84427694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564595)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/info.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564595/; classtype:trojan-activity;sid:84427695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564596)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/nvrsetting/service/info.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564596/; classtype:trojan-activity;sid:84427696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564593)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/utils/excel/annotation/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564593/; classtype:trojan-activity;sid:84427693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564592)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/set/service/impl/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564592/; classtype:trojan-activity;sid:84427692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564589)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/base/utils/info.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564589/; classtype:trojan-activity;sid:84427689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564590)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/dao/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564590/; classtype:trojan-activity;sid:84427690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564583)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/service/info.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564583/; classtype:trojan-activity;sid:84427683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564584)"; flow:established,from_client; content:"GET"; http_method; content:"/%e6%96%b0%e6%96%87%e4%bb%b6%e5%a4%b9%20(2)/info.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564584/; classtype:trojan-activity;sid:84427684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564585)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/info.zip"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564585/; classtype:trojan-activity;sid:84427685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564581)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/service/info.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564581/; classtype:trojan-activity;sid:84427681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564578)"; flow:established,from_client; content:"GET"; http_method; content:"/haohua/info.zip"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564578/; classtype:trojan-activity;sid:84427678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564577)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/ckwss/base/info.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564577/; classtype:trojan-activity;sid:84427677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564576)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/count/info.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564576/; classtype:trojan-activity;sid:84427676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564574)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/checksetting/dao/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564574/; classtype:trojan-activity;sid:84427674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564575)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/info.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564575/; classtype:trojan-activity;sid:84427675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564569)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pda/module/info.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564569/; classtype:trojan-activity;sid:84427669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564568)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/operationsetting/service/impl/info.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564568/; classtype:trojan-activity;sid:84427668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564566)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/ckts_005fpc/rgsy/system/info.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564566/; classtype:trojan-activity;sid:84427666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564565)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/chkpt/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564565/; classtype:trojan-activity;sid:84427665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564563)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/info.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564563/; classtype:trojan-activity;sid:84427663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564561)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/vehiclereview/controller/info.zip"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564561/; classtype:trojan-activity;sid:84427661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564562)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/info.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564562/; classtype:trojan-activity;sid:84427662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564559)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/entity/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564559/; classtype:trojan-activity;sid:84427659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564554)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/lib/info.zip"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564554/; classtype:trojan-activity;sid:84427654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564542)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/root/info.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564542/; classtype:trojan-activity;sid:84427642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564543)"; flow:established,from_client; content:"GET"; http_method; content:"/kaifa/info.zip"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564543/; classtype:trojan-activity;sid:84427643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564544)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/dataquery/dto/info.zip"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564544/; classtype:trojan-activity;sid:84427644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564545)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/org/apache/jsp/web_002dinf/com/vkl/info.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564545/; classtype:trojan-activity;sid:84427645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564539)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/info.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564539/; classtype:trojan-activity;sid:84427639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564540)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/viewws/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564540/; classtype:trojan-activity;sid:84427640; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564541)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pda/web-inf/classes/com/vkl/pcwss/module/pdawss/info.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564541/; classtype:trojan-activity;sid:84427641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564538)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/record/web/info.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564538/; classtype:trojan-activity;sid:84427638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564534)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/work/catalina/localhost/bfxt/info.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564534/; classtype:trojan-activity;sid:84427634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564535)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/mapping/com/vkl/pcwss/module/ckwss/info.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564535/; classtype:trojan-activity;sid:84427635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564536)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/zbzlwss/action/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564536/; classtype:trojan-activity;sid:84427636; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564537)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/info.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564537/; classtype:trojan-activity;sid:84427637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564527)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/info.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564527/; classtype:trojan-activity;sid:84427627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564528)"; flow:established,from_client; content:"GET"; http_method; content:"/aspnet_client/info.zip"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564528/; classtype:trojan-activity;sid:84427628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564529)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/web/info.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564529/; classtype:trojan-activity;sid:84427629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564526)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/temp/poifiles/info.zip"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564526/; classtype:trojan-activity;sid:84427626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564522)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/report/info.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564522/; classtype:trojan-activity;sid:84427622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564521)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/pub/dao/info.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564521/; classtype:trojan-activity;sid:84427621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564519)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/visitwss/dto/info.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564519/; classtype:trojan-activity;sid:84427619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564518)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/cksy/servacpt/entity/info.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564518/; classtype:trojan-activity;sid:84427618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564515)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/ckwss/info.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564515/; classtype:trojan-activity;sid:84427615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564514)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/wss/action/info.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564514/; classtype:trojan-activity;sid:84427614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564509)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/dao/info.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564509/; classtype:trojan-activity;sid:84427609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564500)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/info.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564500/; classtype:trojan-activity;sid:84427600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564502)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt_pcwss/web-inf/classes/com/vkl/pcwss/module/gbrwss/dao/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564502/; classtype:trojan-activity;sid:84427602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564498)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/dept/service/info.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564498/; classtype:trojan-activity;sid:84427598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564499)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/mapping/com/vkl/ckts/module/rgsy/dept/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564499/; classtype:trojan-activity;sid:84427599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3564497)"; flow:established,from_client; content:"GET"; http_method; content:"/tomcat8/webapps/bfxt/web-inf/classes/com/vkl/ckts/rgsy/system/photosetting/info.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_18; reference:url, urlhaus.abuse.ch/url/3564497/; classtype:trojan-activity;sid:84427597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562926)"; flow:established,from_client; content:"GET"; http_method; content:"/mar10/wsgidav/archive/refs/heads/master.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_17; reference:url, urlhaus.abuse.ch/url/3562926/; classtype:trojan-activity;sid:84426026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562778)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/flame/msglu32.ocx"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562778/; classtype:trojan-activity;sid:84425878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562768)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/energizertrojan-malware.zip"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562768/; classtype:trojan-activity;sid:84425868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562769)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/flame/advnetcfg.ocx"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562769/; classtype:trojan-activity;sid:84425869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562770)"; flow:established,from_client; content:"GET"; http_method; content:"/malware/icecast2_2.0.0_vulnerable.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562770/; classtype:trojan-activity;sid:84425870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562771)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/flame/mssecmgr.ocx"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562771/; classtype:trojan-activity;sid:84425871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562772)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/dnsmasq-2.73rc7.tar.gz"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562772/; classtype:trojan-activity;sid:84425872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562774)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/flame/boot32drv.sys"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562774/; classtype:trojan-activity;sid:84425874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562775)"; flow:established,from_client; content:"GET"; http_method; content:"/malware/energizertrojan-malware.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562775/; classtype:trojan-activity;sid:84425875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562766)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/flame/nteps32.ocx"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562766/; classtype:trojan-activity;sid:84425866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562767)"; flow:established,from_client; content:"GET"; http_method; content:"/malware/dnsmasq-2.73rc7.tar.gz"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562767/; classtype:trojan-activity;sid:84425867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562765)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/icecast2_2.0.0_vulnerable.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562765/; classtype:trojan-activity;sid:84425865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562763)"; flow:established,from_client; content:"GET"; http_method; content:"/dangerous/flame/ccalc32.sys"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"172.236.108.48"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562763/; classtype:trojan-activity;sid:84425863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562757)"; flow:established,from_client; content:"GET"; http_method; content:"/tcp_linux_amd64"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"101.43.49.183"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562757/; classtype:trojan-activity;sid:84425857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562678)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"93.116.56.78"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562678/; classtype:trojan-activity;sid:84425778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562600)"; flow:established,from_client; content:"GET"; http_method; content:"/zusyaku/malware-collection-part-2/refs/heads/main/666/666.exe"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562600/; classtype:trojan-activity;sid:84425700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562599)"; flow:established,from_client; content:"GET"; http_method; content:"/wp.bat"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"92.127.156.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562599/; classtype:trojan-activity;sid:84425699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562404)"; flow:established,from_client; content:"GET"; http_method; content:"/live.lnk"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.116.190.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562404/; classtype:trojan-activity;sid:84425504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3562403)"; flow:established,from_client; content:"GET"; http_method; content:"/uat.lnk"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"103.116.190.93"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_16; reference:url, urlhaus.abuse.ch/url/3562403/; classtype:trojan-activity;sid:84425503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561991)"; flow:established,from_client; content:"GET"; http_method; content:"/wyverntkc/cpuminer-gr-avx2/releases/download/1.2.4.1/cpuminer-gr-1.2.4.1-x86_64_windows.7z"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561991/; classtype:trojan-activity;sid:84425091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561989)"; flow:established,from_client; content:"GET"; http_method; content:"/wyverntkc/cpuminer-gr-avx2/archive/refs/tags/1.2.4.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561989/; classtype:trojan-activity;sid:84425089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561990)"; flow:established,from_client; content:"GET"; http_method; content:"/wyverntkc/cpuminer-gr-avx2/archive/refs/tags/1.2.4.1.tar.gz"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561990/; classtype:trojan-activity;sid:84425090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561988)"; flow:established,from_client; content:"GET"; http_method; content:"/wyverntkc/cpuminer-gr-avx2/releases/download/1.2.4.1/cpuminer-gr-1.2.4.1-args-x86_64_linux.tar.gz"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_14; reference:url, urlhaus.abuse.ch/url/3561988/; classtype:trojan-activity;sid:84425088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561860)"; flow:established,from_client; content:"GET"; http_method; content:"/invc/xfspeed/qqpcmgr/module_update/fid1746669868_runqmhunt.exe.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"dlied6.yz.tcdnos.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561860/; classtype:trojan-activity;sid:84424960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561859)"; flow:established,from_client; content:"GET"; http_method; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747308966_runqmhunt.exe.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"dlied6.bytes.tcdnos.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561859/; classtype:trojan-activity;sid:84424959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561858)"; flow:established,from_client; content:"GET"; http_method; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747209335_runqmhunt.exe.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"dlied6.bytes.tcdnos.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561858/; classtype:trojan-activity;sid:84424958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561857)"; flow:established,from_client; content:"GET"; http_method; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747732120_runqmhunt.exe.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"dlied6.bytes.tcdnos.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561857/; classtype:trojan-activity;sid:84424957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561856)"; flow:established,from_client; content:"GET"; http_method; content:"/invc/xfspeed/qqpcmgr/module_update/fid1747640975_runqmhunt.exe.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"dlied6.bytes.tcdnos.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561856/; classtype:trojan-activity;sid:84424956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561839)"; flow:established,from_client; content:"GET"; http_method; content:"/files/data/drss/drbw.zip"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"124.223.105.161"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_06_13; reference:url, urlhaus.abuse.ch/url/3561839/; classtype:trojan-activity;sid:84424939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3561639)"; flow:established,from_client; content:"GET"; http_method; content:"/download/kedadecoder.zip"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"123.232.43.185"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_12; reference:url, urlhaus.abuse.ch/url/3561639/; classtype:trojan-activity;sid:84424739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560452)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/ransomware/annabelle.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560452/; classtype:trojan-activity;sid:84423552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560445)"; flow:established,from_client; content:"GET"; http_method; content:"/barrigudinha157/barrigudinha/master/ydrag.dll"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560445/; classtype:trojan-activity;sid:84423545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560439)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/loic/master/loic.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560439/; classtype:trojan-activity;sid:84423539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560434)"; flow:established,from_client; content:"GET"; http_method; content:"/phantompeek/kematian/main/frontend-src/kematian_shellcode.ps1"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560434/; classtype:trojan-activity;sid:84423534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560418)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/ransomware/cryptowall.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560418/; classtype:trojan-activity;sid:84423518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560419)"; flow:established,from_client; content:"GET"; http_method; content:"/phantompeek/kematian/main/frontend-src/main.ps1"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560419/; classtype:trojan-activity;sid:84423519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560422)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/ransomware/cryptolocker.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560422/; classtype:trojan-activity;sid:84423522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560416)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/email-worm/prolin.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560416/; classtype:trojan-activity;sid:84423516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560412)"; flow:established,from_client; content:"GET"; http_method; content:"/phantompeek/kematian/main/frontend-src/main.bat"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560412/; classtype:trojan-activity;sid:84423512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560414)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/funbatchcode-malicousandnonmalicous/master/worm.bat"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560414/; classtype:trojan-activity;sid:84423514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560409)"; flow:established,from_client; content:"GET"; http_method; content:"/noccenter/noccenter/main/huong%20dan%20xu%20ly%20tai%20khoan%20mail%20noi%20bo.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560409/; classtype:trojan-activity;sid:84423509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560385)"; flow:established,from_client; content:"GET"; http_method; content:"/pc/pdfconvert/pdfconverter_p2w154-zx-666.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"download.pdf00.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560385/; classtype:trojan-activity;sid:84423485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560380)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/rod_en_1.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"www.r-tt.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560380/; classtype:trojan-activity;sid:84423480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560381)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/rmd_en_1.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"www.r-tt.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560381/; classtype:trojan-activity;sid:84423481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560383)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/rxd_en_1.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"www.r-tt.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560383/; classtype:trojan-activity;sid:84423483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3560209)"; flow:established,from_client; content:"GET"; http_method; content:"/cybertoxin/remcos-professional-cracked-by-alcatraz3222/raw/master/remcos%20professional%20cracked%20by%20alcatraz3222.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_06_10; reference:url, urlhaus.abuse.ch/url/3560209/; classtype:trojan-activity;sid:84423309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559887)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"139.255.97.118"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_09; reference:url, urlhaus.abuse.ch/url/3559887/; classtype:trojan-activity;sid:84422987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559327)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"45.115.254.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_08; reference:url, urlhaus.abuse.ch/url/3559327/; classtype:trojan-activity;sid:84422427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559217)"; flow:established,from_client; content:"GET"; http_method; content:"/public/update/bmw_v1.7.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"acc.jiangsujiaxue.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559217/; classtype:trojan-activity;sid:84422317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559216)"; flow:established,from_client; content:"GET"; http_method; content:"/classticket.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"class1004.dothome.co.kr"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559216/; classtype:trojan-activity;sid:84422316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559211)"; flow:established,from_client; content:"GET"; http_method; content:"/static/download/teleport-assist-windows.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"58.49.210.250"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559211/; classtype:trojan-activity;sid:84422311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559208)"; flow:established,from_client; content:"GET"; http_method; content:"/yx/dts/sqft/904576/yx_dts.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"d.14yaa.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559208/; classtype:trojan-activity;sid:84422308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559123)"; flow:established,from_client; content:"GET"; http_method; content:"/nps.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"118.219.11.202"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559123/; classtype:trojan-activity;sid:84422223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559040)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/keystone.dll"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559040/; classtype:trojan-activity;sid:84422140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559037)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/sgn.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559037/; classtype:trojan-activity;sid:84422137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559033)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/bsodlogicbomb.ps1"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559033/; classtype:trojan-activity;sid:84422133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559034)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/powersyringe.ps1"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559034/; classtype:trojan-activity;sid:84422134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559022)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/invoke-reflectivepeinjection.ps1"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559022/; classtype:trojan-activity;sid:84422122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559025)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/pe2shc.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559025/; classtype:trojan-activity;sid:84422125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559019)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/encrypted.enc"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559019/; classtype:trojan-activity;sid:84422119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559009)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/masquerade-peb.ps1"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559009/; classtype:trojan-activity;sid:84422109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559012)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/uacbstartup.ps1"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559012/; classtype:trojan-activity;sid:84422112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559014)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/invoke-shellcode-fixed.ps1"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559014/; classtype:trojan-activity;sid:84422114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559015)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/onedoesnotsimplybypassentirewindefender.ps1"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559015/; classtype:trojan-activity;sid:84422115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559005)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/migrate.rb"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559005/; classtype:trojan-activity;sid:84422105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3559006)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/base64.rb"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3559006/; classtype:trojan-activity;sid:84422106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558975)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/email-worm/bugsoft.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558975/; classtype:trojan-activity;sid:84422075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558976)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/email-worm/brontok.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558976/; classtype:trojan-activity;sid:84422076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558977)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/banking-malware/zloader.xlsm"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558977/; classtype:trojan-activity;sid:84422077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558973)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/email-worm/anap.a.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558973/; classtype:trojan-activity;sid:84422073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558974)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/email-worm/axam.a.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558974/; classtype:trojan-activity;sid:84422074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558966)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/banking-malware/emotet.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558966/; classtype:trojan-activity;sid:84422066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558967)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/master/email-worm/amus.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558967/; classtype:trojan-activity;sid:84422067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558969)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/rickware/master/rickroll.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_07; reference:url, urlhaus.abuse.ch/url/3558969/; classtype:trojan-activity;sid:84422069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558602)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.26.97.59"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_06_05; reference:url, urlhaus.abuse.ch/url/3558602/; classtype:trojan-activity;sid:84421702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558501)"; flow:established,from_client; content:"GET"; http_method; content:"/g7_update.exe"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"118.219.11.202"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_06_05; reference:url, urlhaus.abuse.ch/url/3558501/; classtype:trojan-activity;sid:84421601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558302)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/amsibypass/main/newamsibypass.ps1"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558302/; classtype:trojan-activity;sid:84421402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558300)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/link-exe-test/main/matthew.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558300/; classtype:trojan-activity;sid:84421400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558295)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/second.bin"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558295/; classtype:trojan-activity;sid:84421395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558290)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/urbanvpn.exe"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558290/; classtype:trojan-activity;sid:84421390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558291)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/svhost.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558291/; classtype:trojan-activity;sid:84421391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558292)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/second.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558292/; classtype:trojan-activity;sid:84421392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558289)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/invoke-nicelittlekittieobf/main/invoke-nicelittlekittieobf.ps1"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558289/; classtype:trojan-activity;sid:84421389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558285)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/pvp.exe"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558285/; classtype:trojan-activity;sid:84421385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558287)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/darwin.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558287/; classtype:trojan-activity;sid:84421387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558280)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/rust-dropper/main/src/main.rs"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558280/; classtype:trojan-activity;sid:84421380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558271)"; flow:established,from_client; content:"GET"; http_method; content:"/c5hackr/phantom/main/phantom/bin/x64/release/phantom.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558271/; classtype:trojan-activity;sid:84421371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558266)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/invoke-shell/main/reverse.ps1"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558266/; classtype:trojan-activity;sid:84421366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558264)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/iso-file-testing/main/pleaserunme.iso"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558264/; classtype:trojan-activity;sid:84421364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558260)"; flow:established,from_client; content:"GET"; http_method; content:"/c5hackr/phantom/main/phantom/resources/uac64.dll"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558260/; classtype:trojan-activity;sid:84421360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558252)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/payload.bin"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558252/; classtype:trojan-activity;sid:84421352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558247)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/riende.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558247/; classtype:trojan-activity;sid:84421347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558249)"; flow:established,from_client; content:"GET"; http_method; content:"/c5hackr/phantom/main/phantom/resources/uac.dll"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558249/; classtype:trojan-activity;sid:84421349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558243)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/invoke-nicelittlekittie/main/invoke-nicelittlekittie.ps1"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558243/; classtype:trojan-activity;sid:84421343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558235)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/main/payload_encrypted.bin"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558235/; classtype:trojan-activity;sid:84421335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558237)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/meter/main/meter5555.ps1"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558237/; classtype:trojan-activity;sid:84421337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558229)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/js-file-test/main/loader.js"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558229/; classtype:trojan-activity;sid:84421329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3558230)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/rust-revshell/main/src/main.rs"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_06_04; reference:url, urlhaus.abuse.ch/url/3558230/; classtype:trojan-activity;sid:84421330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3556675)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2025/05/1tronps1.txt"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"sablayan.seasonshotelmindoro.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_06_03; reference:url, urlhaus.abuse.ch/url/3556675/; classtype:trojan-activity;sid:84419775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3556673)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2025/05/1framework.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"sablayan.seasonshotelmindoro.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_06_03; reference:url, urlhaus.abuse.ch/url/3556673/; classtype:trojan-activity;sid:84419773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3556668)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2025/05/1tronvbs.txt"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"sablayan.seasonshotelmindoro.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_06_03; reference:url, urlhaus.abuse.ch/url/3556668/; classtype:trojan-activity;sid:84419768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3556670)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2025/05/imagens.txt"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"sablayan.seasonshotelmindoro.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_06_03; reference:url, urlhaus.abuse.ch/url/3556670/; classtype:trojan-activity;sid:84419770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3555192)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/raw/refs/heads/master/ransomware/wannacry.exe"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_29; reference:url, urlhaus.abuse.ch/url/3555192/; classtype:trojan-activity;sid:84418292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3554430)"; flow:established,from_client; content:"GET"; http_method; content:"/rate.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"celebratingseniors.net"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_28; reference:url, urlhaus.abuse.ch/url/3554430/; classtype:trojan-activity;sid:84417530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3554345)"; flow:established,from_client; content:"GET"; http_method; content:"/rats.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"celebratingseniors.net"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_28; reference:url, urlhaus.abuse.ch/url/3554345/; classtype:trojan-activity;sid:84417445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3554334)"; flow:established,from_client; content:"GET"; http_method; content:"/oste.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"celebratingseniors.net"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_28; reference:url, urlhaus.abuse.ch/url/3554334/; classtype:trojan-activity;sid:84417434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553636)"; flow:established,from_client; content:"GET"; http_method; content:"/bufs.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"maidforyou1985.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553636/; classtype:trojan-activity;sid:84416736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553629)"; flow:established,from_client; content:"GET"; http_method; content:"/mits.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"windomstatetheater.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553629/; classtype:trojan-activity;sid:84416729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3553633)"; flow:established,from_client; content:"GET"; http_method; content:"/osxs.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"windomstatetheater.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2025_05_27; reference:url, urlhaus.abuse.ch/url/3553633/; classtype:trojan-activity;sid:84416733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552741)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"223.83.211.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_26; reference:url, urlhaus.abuse.ch/url/3552741/; classtype:trojan-activity;sid:84415841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552617)"; flow:established,from_client; content:"GET"; http_method; content:"/bre"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"109.74.204.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_26; reference:url, urlhaus.abuse.ch/url/3552617/; classtype:trojan-activity;sid:84415717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552045)"; flow:established,from_client; content:"GET"; http_method; content:"/anonimusman00-2/xmr/refs/heads/main/silent%20miner.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552045/; classtype:trojan-activity;sid:84415145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552042)"; flow:established,from_client; content:"GET"; http_method; content:"/waf/dracula-cmd/master/dist/colortool.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552042/; classtype:trojan-activity;sid:84415142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552043)"; flow:established,from_client; content:"GET"; http_method; content:"/iamsysadmin/setteamsbg/main/set-teams-backgrounds.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552043/; classtype:trojan-activity;sid:84415143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552009)"; flow:established,from_client; content:"GET"; http_method; content:"/anonimusman00-2/xmr/raw/refs/heads/main/silent%20miner.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552009/; classtype:trojan-activity;sid:84415109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3552005)"; flow:established,from_client; content:"GET"; http_method; content:"/alanparadis/stalker2simplemodmerger/releases/download/vortex-v1.4.9/stalker2simplemodmergerforvortex.zip"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3552005/; classtype:trojan-activity;sid:84415105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3551493)"; flow:established,from_client; content:"GET"; http_method; content:"/linux"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"47.242.66.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3551493/; classtype:trojan-activity;sid:84414593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3551316)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"14-0-204-188.static.pccw-hkt.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3551316/; classtype:trojan-activity;sid:84414416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3551305)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.208.193"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_24; reference:url, urlhaus.abuse.ch/url/3551305/; classtype:trojan-activity;sid:84414405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3550735)"; flow:established,from_client; content:"GET"; http_method; content:"/macmid_sonoma_14_5.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"107.198.40.184"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_23; reference:url, urlhaus.abuse.ch/url/3550735/; classtype:trojan-activity;sid:84413835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3550710)"; flow:established,from_client; content:"GET"; http_method; content:"/aecheck2.txt"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"khavar.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_23; reference:url, urlhaus.abuse.ch/url/3550710/; classtype:trojan-activity;sid:84413810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3548015)"; flow:established,from_client; content:"GET"; http_method; content:"/acheck3.txt"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"khavar.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3548015/; classtype:trojan-activity;sid:84411115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3548001)"; flow:established,from_client; content:"GET"; http_method; content:"/atata.txt"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"khavar.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3548001/; classtype:trojan-activity;sid:84411101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3547880)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ed2w0zvvx53_mfifdszyslleurub40zo"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3547880/; classtype:trojan-activity;sid:84410980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3547782)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"201.98.176.195"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_20; reference:url, urlhaus.abuse.ch/url/3547782/; classtype:trojan-activity;sid:84410882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3546977)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"183.91.77.253"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_05_19; reference:url, urlhaus.abuse.ch/url/3546977/; classtype:trojan-activity;sid:84410077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3546969)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"84.236.147.129"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_19; reference:url, urlhaus.abuse.ch/url/3546969/; classtype:trojan-activity;sid:84410069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3542563)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1wvxiyf_ryvgg_x3x7uceicqrndhb7lul"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_05_13; reference:url, urlhaus.abuse.ch/url/3542563/; classtype:trojan-activity;sid:84405663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3541826)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/giphy.gif"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"onfiltre.com.tr"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_12; reference:url, urlhaus.abuse.ch/url/3541826/; classtype:trojan-activity;sid:84404926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540931)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.12.2/xmrig-6.12.2-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_05_11; reference:url, urlhaus.abuse.ch/url/3540931/; classtype:trojan-activity;sid:84404031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3540085)"; flow:established,from_client; content:"GET"; http_method; content:"/.x/pax.txt"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"13.71.2.244"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_05_10; reference:url, urlhaus.abuse.ch/url/3540085/; classtype:trojan-activity;sid:84403185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3539686)"; flow:established,from_client; content:"GET"; http_method; content:"/js_bo/werkstastt/shotstar.prm"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"www.silver-hubdachwohnwagen.de"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2025_05_09; reference:url, urlhaus.abuse.ch/url/3539686/; classtype:trojan-activity;sid:84402786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3539028)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.22.42.232"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3539028/; classtype:trojan-activity;sid:84402128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538763)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.208.237"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538763/; classtype:trojan-activity;sid:84401863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538762)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.209.31"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538762/; classtype:trojan-activity;sid:84401862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538761)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"201.94.181.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538761/; classtype:trojan-activity;sid:84401861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538755)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.209.46"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538755/; classtype:trojan-activity;sid:84401855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538747)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"201.94.181.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538747/; classtype:trojan-activity;sid:84401847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538741)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"201.94.181.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538741/; classtype:trojan-activity;sid:84401841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538744)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"201.94.181.7"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538744/; classtype:trojan-activity;sid:84401844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538670)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"121.202.208.107"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538670/; classtype:trojan-activity;sid:84401770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3538179)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.22.42.232"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_08; reference:url, urlhaus.abuse.ch/url/3538179/; classtype:trojan-activity;sid:84401279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3533775)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.156.8.131"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_05_03; reference:url, urlhaus.abuse.ch/url/3533775/; classtype:trojan-activity;sid:84396875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3533582)"; flow:established,from_client; content:"GET"; http_method; content:"/kokotpycauholica/ultraundetecteddrv/refs/heads/main/hbvtmbp46iieehp1.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_05_03; reference:url, urlhaus.abuse.ch/url/3533582/; classtype:trojan-activity;sid:84396682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532847)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"114.129.49.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532847/; classtype:trojan-activity;sid:84395947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532848)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"114.129.49.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532848/; classtype:trojan-activity;sid:84395948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3532849)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"114.129.49.131"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_05_02; reference:url, urlhaus.abuse.ch/url/3532849/; classtype:trojan-activity;sid:84395949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3530891)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.127.68.162"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_30; reference:url, urlhaus.abuse.ch/url/3530891/; classtype:trojan-activity;sid:84393991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3530248)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.31.8.25"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_29; reference:url, urlhaus.abuse.ch/url/3530248/; classtype:trojan-activity;sid:84393348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3529933)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"37.156.8.131"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_29; reference:url, urlhaus.abuse.ch/url/3529933/; classtype:trojan-activity;sid:84393033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528280)"; flow:established,from_client; content:"GET"; http_method; content:"/mir1ce/hawkeye/releases/download/v0319/hawkeye.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_28; reference:url, urlhaus.abuse.ch/url/3528280/; classtype:trojan-activity;sid:84391380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528279)"; flow:established,from_client; content:"GET"; http_method; content:"/yarahq/yara-forge/releases/latest/download/yara-forge-rules-core.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_28; reference:url, urlhaus.abuse.ch/url/3528279/; classtype:trojan-activity;sid:84391379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528277)"; flow:established,from_client; content:"GET"; http_method; content:"/meckazin/chromekatz/releases/download/0.6.1/chromekatzbofs.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_28; reference:url, urlhaus.abuse.ch/url/3528277/; classtype:trojan-activity;sid:84391377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528171)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/19831362/alpha.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528171/; classtype:trojan-activity;sid:84391271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528170)"; flow:established,from_client; content:"GET"; http_method; content:"/decalage2/oletools/releases/download/v0.60.2/oletools-0.60.2.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528170/; classtype:trojan-activity;sid:84391270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528165)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/19831288/crack.nurik.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528165/; classtype:trojan-activity;sid:84391265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528162)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/19831450/solara.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528162/; classtype:trojan-activity;sid:84391262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528154)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/19835739/solarus.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528154/; classtype:trojan-activity;sid:84391254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528128)"; flow:established,from_client; content:"GET"; http_method; content:"/zxc5wezxc/new/main/dllbase64reverse.txt"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528128/; classtype:trojan-activity;sid:84391228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528127)"; flow:established,from_client; content:"GET"; http_method; content:"/androidmalware/android_hid/f25d0234cff288ab8384689685e37b1b4bbaf2ba/test.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528127/; classtype:trojan-activity;sid:84391227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528108)"; flow:established,from_client; content:"GET"; http_method; content:"/monkeyadece/v-f/releases/download/1.4.2/vector-fixer-v1.4.2.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528108/; classtype:trojan-activity;sid:84391208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528105)"; flow:established,from_client; content:"GET"; http_method; content:"/ui.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"public.demo.securecloudsandbox.com"; http_host; depth:34; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528105/; classtype:trojan-activity;sid:84391205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528107)"; flow:established,from_client; content:"GET"; http_method; content:"/lbormann/darts-gif/releases/download/v1.1.0/darts-gif.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528107/; classtype:trojan-activity;sid:84391207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528100)"; flow:established,from_client; content:"GET"; http_method; content:"/lbormann/darts-pixelit/releases/download/v1.2.2/darts-pixelit.exe"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528100/; classtype:trojan-activity;sid:84391200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528101)"; flow:established,from_client; content:"GET"; http_method; content:"/lbormann/darts-wled/releases/download/v1.8.1/darts-wled.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528101/; classtype:trojan-activity;sid:84391201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528097)"; flow:established,from_client; content:"GET"; http_method; content:"/harelba/q/releases/download/2.0.19/q-amd64-windows.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528097/; classtype:trojan-activity;sid:84391197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3528098)"; flow:established,from_client; content:"GET"; http_method; content:"/mikf/gallery-dl/releases/download/v1.15.0/gallery-dl.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3528098/; classtype:trojan-activity;sid:84391198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3527856)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"78.36.11.185"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_27; reference:url, urlhaus.abuse.ch/url/3527856/; classtype:trojan-activity;sid:84390956; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3526930)"; flow:established,from_client; content:"GET"; http_method; content:"/verify-sec"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"msoftdatastore.z22.web.core.windows.net"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_26; reference:url, urlhaus.abuse.ch/url/3526930/; classtype:trojan-activity;sid:84390030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3526832)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.252.69.10"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_26; reference:url, urlhaus.abuse.ch/url/3526832/; classtype:trojan-activity;sid:84389932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3525714)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"95.83.158.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_26; reference:url, urlhaus.abuse.ch/url/3525714/; classtype:trojan-activity;sid:84388814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524811)"; flow:established,from_client; content:"GET"; http_method; content:"/vaxilu/x-ui/releases/latest/download/x-ui-linux-amd64.tar.gz"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524811/; classtype:trojan-activity;sid:84387911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524506)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ccjlbddgjhpeeff1b1hfkgp3x16c_tj1"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524506/; classtype:trojan-activity;sid:84387606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3524454)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1bpc5z-hv6kosk6artkfmbtsnnwwpdghy"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_25; reference:url, urlhaus.abuse.ch/url/3524454/; classtype:trojan-activity;sid:84387554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3523761)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"139.162.53.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_24; reference:url, urlhaus.abuse.ch/url/3523761/; classtype:trojan-activity;sid:84386861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522943)"; flow:established,from_client; content:"GET"; http_method; content:"/oto"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"162.215.218.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_23; reference:url, urlhaus.abuse.ch/url/3522943/; classtype:trojan-activity;sid:84386043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522687)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ltrdqlgcl6smoqujfs1pb2ernzhsbydh"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_23; reference:url, urlhaus.abuse.ch/url/3522687/; classtype:trojan-activity;sid:84385787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522201)"; flow:established,from_client; content:"GET"; http_method; content:"/eed8989/u/main/ud.bat"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_22; reference:url, urlhaus.abuse.ch/url/3522201/; classtype:trojan-activity;sid:84385301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3522159)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"188.243.36.33"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_22; reference:url, urlhaus.abuse.ch/url/3522159/; classtype:trojan-activity;sid:84385259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520366)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.12.2/xmrig-6.12.2-linux-x64.tar.gz"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_21; reference:url, urlhaus.abuse.ch/url/3520366/; classtype:trojan-activity;sid:84383466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520082)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"77.226.241.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520082/; classtype:trojan-activity;sid:84383182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520081)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"202.57.43.234"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520081/; classtype:trojan-activity;sid:84383181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520073)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"179.63.168.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520073/; classtype:trojan-activity;sid:84383173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520077)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"61.244.254.110"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520077/; classtype:trojan-activity;sid:84383177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520070)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.136.63.232"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520070/; classtype:trojan-activity;sid:84383170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3520068)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"93.182.77.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3520068/; classtype:trojan-activity;sid:84383168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519584)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"43.229.20.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519584/; classtype:trojan-activity;sid:84382684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519525)"; flow:established,from_client; content:"GET"; http_method; content:"/down/linm_free/tg_linm_data_image_free.dll"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"tiwanlinm.duckdns.org"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519525/; classtype:trojan-activity;sid:84382625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519513)"; flow:established,from_client; content:"GET"; http_method; content:"/install/namu832.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"www.namuvpn.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519513/; classtype:trojan-activity;sid:84382613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519485)"; flow:established,from_client; content:"GET"; http_method; content:"/versions/gestioniccv20.21.8.51/gestionicc.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"icoffeecloud.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519485/; classtype:trojan-activity;sid:84382585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519469)"; flow:established,from_client; content:"GET"; http_method; content:"/download/static/files/bootstrappernew.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"60aaf9c6.salamanderprocessing.pages.dev"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519469/; classtype:trojan-activity;sid:84382569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519467)"; flow:established,from_client; content:"GET"; http_method; content:"/down/linm_free/tg_linm_data_map_free.dll"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"tiwanlinm.duckdns.org"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519467/; classtype:trojan-activity;sid:84382567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519459)"; flow:established,from_client; content:"GET"; http_method; content:"/pds/mogimall/giftorder/giftorder.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"mogimall.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519459/; classtype:trojan-activity;sid:84382559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519451)"; flow:established,from_client; content:"GET"; http_method; content:"/download/static/files/bootstrappernew.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"2cfc0222.salamanderprocessing.pages.dev"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519451/; classtype:trojan-activity;sid:84382551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519446)"; flow:established,from_client; content:"GET"; http_method; content:"/newchaisupon/vendor/bin/psysh.bat"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"99194034-96-20180108171507.webstarterz.com"; http_host; depth:42; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519446/; classtype:trojan-activity;sid:84382546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519443)"; flow:established,from_client; content:"GET"; http_method; content:"/sa0611/systemsa32.dll"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"www.ss-01.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519443/; classtype:trojan-activity;sid:84382543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519429)"; flow:established,from_client; content:"GET"; http_method; content:"/update/pubdata/hpsocket4c.dll"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"114.55.106.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519429/; classtype:trojan-activity;sid:84382529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519415)"; flow:established,from_client; content:"GET"; http_method; content:"/download/static/files/bootstrappernew.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"c3436037.salamanderprocessing.pages.dev"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519415/; classtype:trojan-activity;sid:84382515; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519408)"; flow:established,from_client; content:"GET"; http_method; content:"/rh/setup.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"d3cciiowg5l3jx.cloudfront.net"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519408/; classtype:trojan-activity;sid:84382508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519404)"; flow:established,from_client; content:"GET"; http_method; content:"/pds/mogimall/giftorder/updater.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"mogimall.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519404/; classtype:trojan-activity;sid:84382504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519392)"; flow:established,from_client; content:"GET"; http_method; content:"/media/video_file/round_setup.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"tapestryoftruth.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519392/; classtype:trojan-activity;sid:84382492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519368)"; flow:established,from_client; content:"GET"; http_method; content:"/r0400/yahoodll.dll"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"www.ss-01.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519368/; classtype:trojan-activity;sid:84382468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519369)"; flow:established,from_client; content:"GET"; http_method; content:"/driveapplet.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"noithaticon.vn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519369/; classtype:trojan-activity;sid:84382469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519356)"; flow:established,from_client; content:"GET"; http_method; content:"/nircmd.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"pub-0478b308b8cf46709a73d0eed5afd633.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519356/; classtype:trojan-activity;sid:84382456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519066)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.22.2/xmrig-6.22.2-msvc-win64.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519066/; classtype:trojan-activity;sid:84382166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519063)"; flow:established,from_client; content:"GET"; http_method; content:"/vinhuptoday/testbn/raw/refs/heads/main/brbotnet.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519063/; classtype:trojan-activity;sid:84382163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519036)"; flow:established,from_client; content:"GET"; http_method; content:"/tiansys(xp%e4%b8%93%e7%94%a8).exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"fz.tiansys.cn"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519036/; classtype:trojan-activity;sid:84382136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519035)"; flow:established,from_client; content:"GET"; http_method; content:"/disbalancer-project/main/releases/latest/download/disbalancer-go-client-windows-386.exe"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519035/; classtype:trojan-activity;sid:84382135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519027)"; flow:established,from_client; content:"GET"; http_method; content:"/cosmicdevv/icarus-lite/releases/download/v1.1.13/icaruslite-v1.1.13-win.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519027/; classtype:trojan-activity;sid:84382127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519025)"; flow:established,from_client; content:"GET"; http_method; content:"/sebaxakerhtc/rdpwrap/releases/download/v1.8.9.9/rdpw_installer.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519025/; classtype:trojan-activity;sid:84382125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519026)"; flow:established,from_client; content:"GET"; http_method; content:"/dax009yt/chilledwindows-gui/releases/download/1.0/chilledwindows.gui.exe"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519026/; classtype:trojan-activity;sid:84382126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519019)"; flow:established,from_client; content:"GET"; http_method; content:"/jackson2323/mohradiant/blob/master/updt.exe|3f|raw=true"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519019/; classtype:trojan-activity;sid:84382119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519020)"; flow:established,from_client; content:"GET"; http_method; content:"/down/pkexu0ytxar3.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"115.159.149.113"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519020/; classtype:trojan-activity;sid:84382120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519016)"; flow:established,from_client; content:"GET"; http_method; content:"/bol-van/zapret/releases/download/v70.6/zapret-v70.6.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519016/; classtype:trojan-activity;sid:84382116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3518999)"; flow:established,from_client; content:"GET"; http_method; content:"/2590057.s21d-2.faiusrd.com/0/abuiabblgaagytxhtauo1pck0ge.exe|3f|f=ghost%e7%bd%91%e5%85%8b%e9%9a%86%e6%a3%80%e6%b5%8b%e5%b7%a5%e5%85%b7.exe|7c|26|7c|v=1452829385|7c|26|7c|wsiphost=local|7c|26|7c|wsrid_tag=61c52eb2_psmgzjgord1de87_17635-16713"; http_uri; depth:241; isdataat:!1,relative; nocase; content:"157.185.170.200"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3518999/; classtype:trojan-activity;sid:84382099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3519000)"; flow:established,from_client; content:"GET"; http_method; content:"/vexcentry/vex/raw/refs/heads/main/runtimebroker.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3519000/; classtype:trojan-activity;sid:84382100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3518861)"; flow:established,from_client; content:"GET"; http_method; content:"/ns3.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"162.215.218.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3518861/; classtype:trojan-activity;sid:84381961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3518860)"; flow:established,from_client; content:"GET"; http_method; content:"/ns1.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"162.215.218.82"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_20; reference:url, urlhaus.abuse.ch/url/3518860/; classtype:trojan-activity;sid:84381960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3517040)"; flow:established,from_client; content:"GET"; http_method; content:"/mig"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"2.57.122.121"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_18; reference:url, urlhaus.abuse.ch/url/3517040/; classtype:trojan-activity;sid:84380140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3516658)"; flow:established,from_client; content:"GET"; http_method; content:"/vinhuptoday/testbn/raw/refs/heads/main/brbotnet.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_18; reference:url, urlhaus.abuse.ch/url/3516658/; classtype:trojan-activity;sid:84379758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3516584)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"211.219.49.173"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_18; reference:url, urlhaus.abuse.ch/url/3516584/; classtype:trojan-activity;sid:84379684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3515978)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"120.79.64.164"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3515978/; classtype:trojan-activity;sid:84379078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3514570)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1hrp9lnasbplclnhppp1abwb1uwv4kdvs"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3514570/; classtype:trojan-activity;sid:84377670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3514066)"; flow:established,from_client; content:"GET"; http_method; content:"/nkminash/my-codd/raw/896d806a9b4569c9c3a275f200ebe7d2ecec5702/snd16061.exe"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_17; reference:url, urlhaus.abuse.ch/url/3514066/; classtype:trojan-activity;sid:84377166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3511783)"; flow:established,from_client; content:"GET"; http_method; content:"/ghdsdcbn124.bin"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"www.khavar.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_04_15; reference:url, urlhaus.abuse.ch/url/3511783/; classtype:trojan-activity;sid:84374883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3510830)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"218.200.94.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_14; reference:url, urlhaus.abuse.ch/url/3510830/; classtype:trojan-activity;sid:84373930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509907)"; flow:established,from_client; content:"GET"; http_method; content:"/rahmounben/lc/refs/heads/main/xclient.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509907/; classtype:trojan-activity;sid:84373007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509904)"; flow:established,from_client; content:"GET"; http_method; content:"/justjzero/ahh/refs/heads/main/cloudy.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509904/; classtype:trojan-activity;sid:84373004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509901)"; flow:established,from_client; content:"GET"; http_method; content:"/justjzero/ahh/raw/refs/heads/main/cloudy.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509901/; classtype:trojan-activity;sid:84373001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3509872)"; flow:established,from_client; content:"GET"; http_method; content:"/niggedddx/dependenciuesfeife/raw/refs/heads/main/bruterv3.1.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_13; reference:url, urlhaus.abuse.ch/url/3509872/; classtype:trojan-activity;sid:84372972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3507452)"; flow:established,from_client; content:"GET"; http_method; content:"/misterlobster22/mimik/blob/main/mimikatz.exe|3f|raw=true"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_11; reference:url, urlhaus.abuse.ch/url/3507452/; classtype:trojan-activity;sid:84370552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3506392)"; flow:established,from_client; content:"GET"; http_method; content:"/deepakmeena2006/lib/6753a65f543afe81079459a8439ec1e0c0a660b4/s86.txt"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_10; reference:url, urlhaus.abuse.ch/url/3506392/; classtype:trojan-activity;sid:84369492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3506391)"; flow:established,from_client; content:"GET"; http_method; content:"/deepakmeena2006/lib/6753a65f543afe81079459a8439ec1e0c0a660b4/s64.txt"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_10; reference:url, urlhaus.abuse.ch/url/3506391/; classtype:trojan-activity;sid:84369491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505672)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1muftth-5lscdi3ovd5vn7sjkeit2h9k1"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505672/; classtype:trojan-activity;sid:84368772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505377)"; flow:established,from_client; content:"GET"; http_method; content:"/electrichermit/vegas-pro-version/releases/download/v2.0/software.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505377/; classtype:trojan-activity;sid:84368477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505382)"; flow:established,from_client; content:"GET"; http_method; content:"/ergin3432432/movie-mates/releases/download/v1.0/application.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505382/; classtype:trojan-activity;sid:84368482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505334)"; flow:established,from_client; content:"GET"; http_method; content:"/yumyumdonuts/free-youtube-to-mp3-converter-free/releases/download/1.1.2/freeyoutubetomp3converterfree-1.1.2.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505334/; classtype:trojan-activity;sid:84368434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505313)"; flow:established,from_client; content:"GET"; http_method; content:"/nmattioni/upload/raw/refs/heads/master/software.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505313/; classtype:trojan-activity;sid:84368413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505307)"; flow:established,from_client; content:"GET"; http_method; content:"/anamesias580/upload/refs/heads/master/software.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505307/; classtype:trojan-activity;sid:84368407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505305)"; flow:established,from_client; content:"GET"; http_method; content:"/phanu85/upload/raw/refs/heads/master/software.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505305/; classtype:trojan-activity;sid:84368405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3505304)"; flow:established,from_client; content:"GET"; http_method; content:"/pantay/upload/raw/refs/heads/master/software.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_09; reference:url, urlhaus.abuse.ch/url/3505304/; classtype:trojan-activity;sid:84368404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3504713)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.54.238.31"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_08; reference:url, urlhaus.abuse.ch/url/3504713/; classtype:trojan-activity;sid:84367813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3504260)"; flow:established,from_client; content:"GET"; http_method; content:"/images/acfkgtyuwbbpfexcdoqxk171.bin"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"pfatrivandrum.org"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_04_08; reference:url, urlhaus.abuse.ch/url/3504260/; classtype:trojan-activity;sid:84367360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3504256)"; flow:established,from_client; content:"GET"; http_method; content:"/images/midafternoon.snp"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"pfatrivandrum.org"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_04_08; reference:url, urlhaus.abuse.ch/url/3504256/; classtype:trojan-activity;sid:84367356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3504106)"; flow:established,from_client; content:"GET"; http_method; content:"/fonts/hjdaviyk236.bin"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"pfatrivandrum.org"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_04_08; reference:url, urlhaus.abuse.ch/url/3504106/; classtype:trojan-activity;sid:84367206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3504105)"; flow:established,from_client; content:"GET"; http_method; content:"/fonts/tuberculinizing.fla"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"pfatrivandrum.org"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_04_08; reference:url, urlhaus.abuse.ch/url/3504105/; classtype:trojan-activity;sid:84367205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503677)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"179.60.216.19"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_07; reference:url, urlhaus.abuse.ch/url/3503677/; classtype:trojan-activity;sid:84366777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503657)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.43.17.123"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_07; reference:url, urlhaus.abuse.ch/url/3503657/; classtype:trojan-activity;sid:84366757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503409)"; flow:established,from_client; content:"GET"; http_method; content:"/tirtekeka/rat-client/zip/refs/heads/main"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2025_04_07; reference:url, urlhaus.abuse.ch/url/3503409/; classtype:trojan-activity;sid:84366509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3503003)"; flow:established,from_client; content:"GET"; http_method; content:"/download/konsol.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"backupso.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_04_06; reference:url, urlhaus.abuse.ch/url/3503003/; classtype:trojan-activity;sid:84366103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3500891)"; flow:established,from_client; content:"GET"; http_method; content:"/chin/ifjjmktge.mp3"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"dcrun.co.uk"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_04; reference:url, urlhaus.abuse.ch/url/3500891/; classtype:trojan-activity;sid:84363991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3500747)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.185.1.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_04_04; reference:url, urlhaus.abuse.ch/url/3500747/; classtype:trojan-activity;sid:84363847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3500733)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"82.102.74.238"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_04; reference:url, urlhaus.abuse.ch/url/3500733/; classtype:trojan-activity;sid:84363833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3499993)"; flow:established,from_client; content:"GET"; http_method; content:"/roniel8/apex-no-recoil/releases/download/v2.5.1-alpha.3/apex-no-recoil-v2-5-1-alpha-3.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_03; reference:url, urlhaus.abuse.ch/url/3499993/; classtype:trojan-activity;sid:84363093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498482)"; flow:established,from_client; content:"GET"; http_method; content:"/juanbustoss/src/raw/refs/heads/master/application.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498482/; classtype:trojan-activity;sid:84361582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498084)"; flow:established,from_client; content:"GET"; http_method; content:"/shellyacm/imgx/releases/download/v1.0/software.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498084/; classtype:trojan-activity;sid:84361184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498082)"; flow:established,from_client; content:"GET"; http_method; content:"/shellyacm/imgx/releases/download/v2.0/software.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498082/; classtype:trojan-activity;sid:84361182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498070)"; flow:established,from_client; content:"GET"; http_method; content:"/demonsofhe/onion-rings/releases/download/3.1.7/onion-rings-3.1.7.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498070/; classtype:trojan-activity;sid:84361170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498076)"; flow:established,from_client; content:"GET"; http_method; content:"/jxx1234567890jxx/datatransformationchecker/releases/download/v2.0/software.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498076/; classtype:trojan-activity;sid:84361176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498067)"; flow:established,from_client; content:"GET"; http_method; content:"/frank698/localocr/releases/download/v2.3.3/localocr_v2.3.3.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498067/; classtype:trojan-activity;sid:84361167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498056)"; flow:established,from_client; content:"GET"; http_method; content:"/wfeifefeifef/pokemon-crud/releases/download/v1.1/soft.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498056/; classtype:trojan-activity;sid:84361156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498045)"; flow:established,from_client; content:"GET"; http_method; content:"/ushii/weather_app/releases/download/v1.0/installer.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498045/; classtype:trojan-activity;sid:84361145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498047)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulpa045/cphishtermux/releases/download/v1.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498047/; classtype:trojan-activity;sid:84361147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498050)"; flow:established,from_client; content:"GET"; http_method; content:"/wfeifefeifef/pokemon-crud/releases/download/v1.2/soft.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498050/; classtype:trojan-activity;sid:84361150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498053)"; flow:established,from_client; content:"GET"; http_method; content:"/jxx1234567890jxx/datatransformationchecker/releases/download/v1.0/application.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498053/; classtype:trojan-activity;sid:84361153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498033)"; flow:established,from_client; content:"GET"; http_method; content:"/gamer615/acdsee-photo-studio-professional-download/releases/download/v1.0/software.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498033/; classtype:trojan-activity;sid:84361133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498034)"; flow:established,from_client; content:"GET"; http_method; content:"/ushii/weather_app/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498034/; classtype:trojan-activity;sid:84361134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498036)"; flow:established,from_client; content:"GET"; http_method; content:"/gamer615/acdsee-photo-studio-professional-download/releases/download/v2.0/software.zip"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498036/; classtype:trojan-activity;sid:84361136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3498038)"; flow:established,from_client; content:"GET"; http_method; content:"/eltrapico2/php-library-system/releases/download/v1.0/software.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3498038/; classtype:trojan-activity;sid:84361138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497826)"; flow:established,from_client; content:"GET"; http_method; content:"/itznaviya/hamster-kombat-bot/releases/download/v2.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497826/; classtype:trojan-activity;sid:84360926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497822)"; flow:established,from_client; content:"GET"; http_method; content:"/itznaviya/hamster-kombat-bot/releases/download/v2.0/program.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497822/; classtype:trojan-activity;sid:84360922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497825)"; flow:established,from_client; content:"GET"; http_method; content:"/itznaviya/hamster-kombat-bot/releases/download/v1.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497825/; classtype:trojan-activity;sid:84360925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497805)"; flow:established,from_client; content:"GET"; http_method; content:"/ffxjevefi/nix-system-services-hardened/releases/download/v2.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497805/; classtype:trojan-activity;sid:84360905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497797)"; flow:established,from_client; content:"GET"; http_method; content:"/supreme-snaze/permutations/releases/download/v1.0/program.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497797/; classtype:trojan-activity;sid:84360897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497739)"; flow:established,from_client; content:"GET"; http_method; content:"/ander12342/pugdns/releases/download/1.3.1/pugdns_v1.3.1.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497739/; classtype:trojan-activity;sid:84360839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497677)"; flow:established,from_client; content:"GET"; http_method; content:"/devpev777/d/refs/heads/main/r.msi"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497677/; classtype:trojan-activity;sid:84360777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497306)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.186.28.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_04_01; reference:url, urlhaus.abuse.ch/url/3497306/; classtype:trojan-activity;sid:84360406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497120)"; flow:established,from_client; content:"GET"; http_method; content:"/dodobaba25/repo/refs/heads/master/s64.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3497120/; classtype:trojan-activity;sid:84360220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3497121)"; flow:established,from_client; content:"GET"; http_method; content:"/dodobaba25/repo/refs/heads/master/s86.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3497121/; classtype:trojan-activity;sid:84360221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496952)"; flow:established,from_client; content:"GET"; http_method; content:"/benkku25/assets/raw/41f4f8f16b76af39e1bc3f8024b66010dd2617c7/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496952/; classtype:trojan-activity;sid:84360052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496664)"; flow:established,from_client; content:"GET"; http_method; content:"/syklon99/ai-chatbot-svelte/releases/download/v1.4.9/ai-chatbot-svelte-v1.4.9.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496664/; classtype:trojan-activity;sid:84359764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496662)"; flow:established,from_client; content:"GET"; http_method; content:"/sigarikafat/xeet/releases/download/1.6.4/xeet_v1.6.4.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496662/; classtype:trojan-activity;sid:84359762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496645)"; flow:established,from_client; content:"GET"; http_method; content:"/naoval19/tacos/releases/download/v1.0/program.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496645/; classtype:trojan-activity;sid:84359745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496646)"; flow:established,from_client; content:"GET"; http_method; content:"/naoval19/tacos/releases/download/v2.0/software.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496646/; classtype:trojan-activity;sid:84359746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496631)"; flow:established,from_client; content:"GET"; http_method; content:"/rle123/ai-self-coding-book/releases/download/v1.0/program.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496631/; classtype:trojan-activity;sid:84359731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496594)"; flow:established,from_client; content:"GET"; http_method; content:"/skibidi-crypto/quarkus-openapi-problem/releases/download/v1.4.2/quarkus-openapi-problem-v1.4.2.zip"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496594/; classtype:trojan-activity;sid:84359694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496564)"; flow:established,from_client; content:"GET"; http_method; content:"/stepbox23/assets/60af1f798cc4708a2872a66cebab351e529e43f8/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_31; reference:url, urlhaus.abuse.ch/url/3496564/; classtype:trojan-activity;sid:84359664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496061)"; flow:established,from_client; content:"GET"; http_method; content:"/eed8989/u/raw/refs/heads/main/ud.bat"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3496061/; classtype:trojan-activity;sid:84359161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3496058)"; flow:established,from_client; content:"GET"; http_method; content:"/eed8989/u/raw/main/ud.bat"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3496058/; classtype:trojan-activity;sid:84359158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3495857)"; flow:established,from_client; content:"GET"; http_method; content:"/tsl/downloader.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"tobecation.github.io"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_30; reference:url, urlhaus.abuse.ch/url/3495857/; classtype:trojan-activity;sid:84358957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3493608)"; flow:established,from_client; content:"GET"; http_method; content:"/aussieonzaza/assets/refs/heads/master/launcher.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3493608/; classtype:trojan-activity;sid:84356708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3493604)"; flow:established,from_client; content:"GET"; http_method; content:"/rafael1679/assets/raw/refs/heads/master/launcher.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_28; reference:url, urlhaus.abuse.ch/url/3493604/; classtype:trojan-activity;sid:84356704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492622)"; flow:established,from_client; content:"GET"; http_method; content:"/abdeu-cpu/coap-mqtt-encryption/releases/download/v1.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492622/; classtype:trojan-activity;sid:84355722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492611)"; flow:established,from_client; content:"GET"; http_method; content:"/forzon96/cataclismo/releases/download/1.4.6/cataclismo_1.4.6.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492611/; classtype:trojan-activity;sid:84355711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492613)"; flow:established,from_client; content:"GET"; http_method; content:"/mjunaid87/tokenset/releases/download/v2.8.1/tokenset.v2.8.1.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492613/; classtype:trojan-activity;sid:84355713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492608)"; flow:established,from_client; content:"GET"; http_method; content:"/joacokia/oopd/releases/download/bretschneideraceae/oopd_bretschneideraceae.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492608/; classtype:trojan-activity;sid:84355708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492600)"; flow:established,from_client; content:"GET"; http_method; content:"/mardecilnonp568/assasin-creed-shadows/releases/download/v2.7.5/assassin-creed-shadows-v2.7.5.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492600/; classtype:trojan-activity;sid:84355700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492563)"; flow:established,from_client; content:"GET"; http_method; content:"/reninstem/productlisting/releases/download/2.6.1/productlisting-2.6.1.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492563/; classtype:trojan-activity;sid:84355663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492160)"; flow:established,from_client; content:"GET"; http_method; content:"/uragon005/ai-chatbot-svelte/releases/download/v2.4.5/ai-chatbot-svelte_v2.4.5.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492160/; classtype:trojan-activity;sid:84355260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3492056)"; flow:established,from_client; content:"GET"; http_method; content:"/aussieonzaza/assets/raw/refs/heads/master/launcher.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_27; reference:url, urlhaus.abuse.ch/url/3492056/; classtype:trojan-activity;sid:84355156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490432)"; flow:established,from_client; content:"GET"; http_method; content:"/phamkhanhhung208/assets/refs/heads/master/launcher.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490432/; classtype:trojan-activity;sid:84353532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490427)"; flow:established,from_client; content:"GET"; http_method; content:"/rafael1679/assets/refs/heads/master/launcher.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490427/; classtype:trojan-activity;sid:84353527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490409)"; flow:established,from_client; content:"GET"; http_method; content:"/beast2122006/assignment/238415a963aab57f18fd2c2ef60995d7c0b39fe0/library.txt"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490409/; classtype:trojan-activity;sid:84353509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490350)"; flow:established,from_client; content:"GET"; http_method; content:"/ilganrat342/dertyom/refs/heads/main/setup.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490350/; classtype:trojan-activity;sid:84353450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490349)"; flow:established,from_client; content:"GET"; http_method; content:"/rh/setup.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"d3cciiowg5l3jx.cloudfront.net"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490349/; classtype:trojan-activity;sid:84353449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490313)"; flow:established,from_client; content:"GET"; http_method; content:"/kammywammyman/boyboy/main/chromeupdate.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490313/; classtype:trojan-activity;sid:84353413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3490294)"; flow:established,from_client; content:"GET"; http_method; content:"/tacocat2222/materia-fivem/refs/heads/main/loader.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_25; reference:url, urlhaus.abuse.ch/url/3490294/; classtype:trojan-activity;sid:84353394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489509)"; flow:established,from_client; content:"GET"; http_method; content:"/aldenpogznet22/hamster-bot/releases/download/v1.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489509/; classtype:trojan-activity;sid:84352609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489502)"; flow:established,from_client; content:"GET"; http_method; content:"/thurynw/uoffice_library_uot/releases/download/v1.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489502/; classtype:trojan-activity;sid:84352602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489474)"; flow:established,from_client; content:"GET"; http_method; content:"/toanminh2004/duan1/releases/download/v2.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489474/; classtype:trojan-activity;sid:84352574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489476)"; flow:established,from_client; content:"GET"; http_method; content:"/tatooo29/loco/releases/download/v1.0/application.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489476/; classtype:trojan-activity;sid:84352576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489478)"; flow:established,from_client; content:"GET"; http_method; content:"/tatooo29/loco/releases/download/v2.0/software.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489478/; classtype:trojan-activity;sid:84352578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489479)"; flow:established,from_client; content:"GET"; http_method; content:"/xmanykwim/simple-2/releases/download/v1.0/application.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489479/; classtype:trojan-activity;sid:84352579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489480)"; flow:established,from_client; content:"GET"; http_method; content:"/cistelsa/predictive-sentiment-analysis-of-twitter-for-btc/releases/download/v1.0/software.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489480/; classtype:trojan-activity;sid:84352580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489481)"; flow:established,from_client; content:"GET"; http_method; content:"/xmanykwim/simple-proxytv/releases/download/v2.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489481/; classtype:trojan-activity;sid:84352581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489471)"; flow:established,from_client; content:"GET"; http_method; content:"/cistelsa/predictive-sentiment-analysis-of-twitter-for-btc/releases/download/v2.0/software.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489471/; classtype:trojan-activity;sid:84352571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489472)"; flow:established,from_client; content:"GET"; http_method; content:"/xmanykwim/simple-proxytv/releases/download/v1.0/application.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489472/; classtype:trojan-activity;sid:84352572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489473)"; flow:established,from_client; content:"GET"; http_method; content:"/xmanykwim/simple-2/releases/download/v2.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489473/; classtype:trojan-activity;sid:84352573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489333)"; flow:established,from_client; content:"GET"; http_method; content:"/iampriam-dev/new/releases/download/v2.0/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489333/; classtype:trojan-activity;sid:84352433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489336)"; flow:established,from_client; content:"GET"; http_method; content:"/akashnilrecovered/text-formatting-crash-course/releases/download/v2.0/software.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489336/; classtype:trojan-activity;sid:84352436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489340)"; flow:established,from_client; content:"GET"; http_method; content:"/akashnilrecovered/text-formatting-crash-course/releases/download/v1.0/software.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489340/; classtype:trojan-activity;sid:84352440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489331)"; flow:established,from_client; content:"GET"; http_method; content:"/iampriam-dev/new/releases/download/v1.0/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489331/; classtype:trojan-activity;sid:84352431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489310)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/laravel-authentication-breeze/releases/download/v1.0/software.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489310/; classtype:trojan-activity;sid:84352410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489313)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/githubtutorial/releases/download/v1.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489313/; classtype:trojan-activity;sid:84352413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489314)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/laravel-authentication-breeze/releases/download/v2.0/software.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489314/; classtype:trojan-activity;sid:84352414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489315)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/fortify-auth-laravel/releases/download/v1.0/software.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489315/; classtype:trojan-activity;sid:84352415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489317)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/newlaravel/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489317/; classtype:trojan-activity;sid:84352417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489307)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/fortify-auth-laravel/releases/download/v2.0/software.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489307/; classtype:trojan-activity;sid:84352407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489308)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/book-e-commerce/releases/download/v2.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489308/; classtype:trojan-activity;sid:84352408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489300)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/book-e-commerce/releases/download/v1.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489300/; classtype:trojan-activity;sid:84352400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489303)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/newlaravel/releases/download/v1.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489303/; classtype:trojan-activity;sid:84352403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489274)"; flow:established,from_client; content:"GET"; http_method; content:"/samueltonao/frontendmentor/releases/download/v1.0/application.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489274/; classtype:trojan-activity;sid:84352374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489275)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/ui-package-email-verify/releases/download/v2.0/software.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489275/; classtype:trojan-activity;sid:84352375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489280)"; flow:established,from_client; content:"GET"; http_method; content:"/samueltonao/frontendmentor/releases/download/v2.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489280/; classtype:trojan-activity;sid:84352380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489288)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/ui-package-email-verify/releases/download/v1.0/software.zip"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489288/; classtype:trojan-activity;sid:84352388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489266)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_bootable_recovery/releases/download/v2.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489266/; classtype:trojan-activity;sid:84352366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489265)"; flow:established,from_client; content:"GET"; http_method; content:"/hackslash-nitp/healthcare-web-page/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489265/; classtype:trojan-activity;sid:84352365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489263)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_tinycompress/releases/download/v2.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489263/; classtype:trojan-activity;sid:84352363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489264)"; flow:established,from_client; content:"GET"; http_method; content:"/amandwivedi0/device_xiaomi_santoni/releases/download/v1.0/application.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489264/; classtype:trojan-activity;sid:84352364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489247)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_build/releases/download/v2.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489247/; classtype:trojan-activity;sid:84352347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489248)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_json-c/releases/download/v1.0/application.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489248/; classtype:trojan-activity;sid:84352348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489251)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/laravel-ecommerce-project/releases/download/v1.0/software.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489251/; classtype:trojan-activity;sid:84352351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489252)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_tinycompress/releases/download/v1.0/application.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489252/; classtype:trojan-activity;sid:84352352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489253)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_build/releases/download/v1.0/application.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489253/; classtype:trojan-activity;sid:84352353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489255)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_selinux/releases/download/v1.0/application.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489255/; classtype:trojan-activity;sid:84352355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489256)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_json-c/releases/download/v2.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489256/; classtype:trojan-activity;sid:84352356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489260)"; flow:established,from_client; content:"GET"; http_method; content:"/amandwivedi0/device_xiaomi_santoni/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489260/; classtype:trojan-activity;sid:84352360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489261)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_tinyxml/releases/download/v1.0/application.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489261/; classtype:trojan-activity;sid:84352361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489231)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_sqlite/releases/download/v1.0/application.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489231/; classtype:trojan-activity;sid:84352331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489232)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_bootable_recovery/releases/download/v1.0/application.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489232/; classtype:trojan-activity;sid:84352332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489240)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_bionic/releases/download/v1.0/application.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489240/; classtype:trojan-activity;sid:84352340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489242)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_sqlite/releases/download/v2.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489242/; classtype:trojan-activity;sid:84352342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489243)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/laravel-ecommerce-project/releases/download/v2.0/software.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489243/; classtype:trojan-activity;sid:84352343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489227)"; flow:established,from_client; content:"GET"; http_method; content:"/ambassadorscoders/togonon_motiv.poster/releases/download/v2.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489227/; classtype:trojan-activity;sid:84352327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489228)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_bionic/releases/download/v2.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489228/; classtype:trojan-activity;sid:84352328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489214)"; flow:established,from_client; content:"GET"; http_method; content:"/eltrapico2/12-03assignment/releases/download/v1.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489214/; classtype:trojan-activity;sid:84352314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489215)"; flow:established,from_client; content:"GET"; http_method; content:"/cvm010/nucleus/releases/download/v1.0/software.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489215/; classtype:trojan-activity;sid:84352315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489218)"; flow:established,from_client; content:"GET"; http_method; content:"/eltrapico2/eltrapico2/releases/download/v1.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489218/; classtype:trojan-activity;sid:84352318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489219)"; flow:established,from_client; content:"GET"; http_method; content:"/puram-supriya/amazon/releases/download/v1.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489219/; classtype:trojan-activity;sid:84352319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489205)"; flow:established,from_client; content:"GET"; http_method; content:"/eltrapico2/fri-app/releases/download/v1.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489205/; classtype:trojan-activity;sid:84352305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489207)"; flow:established,from_client; content:"GET"; http_method; content:"/puram-supriya/ecommerce/releases/download/v1.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489207/; classtype:trojan-activity;sid:84352307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489211)"; flow:established,from_client; content:"GET"; http_method; content:"/student-chicken/fit-track-goal-progress/releases/download/v1.0/software.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489211/; classtype:trojan-activity;sid:84352311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489212)"; flow:established,from_client; content:"GET"; http_method; content:"/puram-supriya/resume/releases/download/v1.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489212/; classtype:trojan-activity;sid:84352312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489202)"; flow:established,from_client; content:"GET"; http_method; content:"/cvm010/movie/releases/download/v1.0/software.zip"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489202/; classtype:trojan-activity;sid:84352302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489203)"; flow:established,from_client; content:"GET"; http_method; content:"/vernaloqui/farmer-shubreact/releases/download/v1.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489203/; classtype:trojan-activity;sid:84352303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489173)"; flow:established,from_client; content:"GET"; http_method; content:"/boomerxd69/fixing-error-0xc00000ba/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489173/; classtype:trojan-activity;sid:84352273; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489171)"; flow:established,from_client; content:"GET"; http_method; content:"/matimazzia/worldgame-web/releases/download/v1.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489171/; classtype:trojan-activity;sid:84352271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489155)"; flow:established,from_client; content:"GET"; http_method; content:"/yosif9999/hamster-clicker/releases/download/v3.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489155/; classtype:trojan-activity;sid:84352255; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489151)"; flow:established,from_client; content:"GET"; http_method; content:"/yosif9999/hamster-clicker/releases/download/v1.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489151/; classtype:trojan-activity;sid:84352251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489127)"; flow:established,from_client; content:"GET"; http_method; content:"/drankrych/fakebtcsend/releases/download/v2.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489127/; classtype:trojan-activity;sid:84352227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489128)"; flow:established,from_client; content:"GET"; http_method; content:"/atom3dx/array-base-scatter-filled/releases/download/v2.0/software.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489128/; classtype:trojan-activity;sid:84352228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489129)"; flow:established,from_client; content:"GET"; http_method; content:"/bluecheatah123/apex/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489129/; classtype:trojan-activity;sid:84352229; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489131)"; flow:established,from_client; content:"GET"; http_method; content:"/lethanhdat0403/earnorm/releases/download/v1.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489131/; classtype:trojan-activity;sid:84352231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489135)"; flow:established,from_client; content:"GET"; http_method; content:"/firematheo00x/chat-app-mern/releases/download/v1.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489135/; classtype:trojan-activity;sid:84352235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489137)"; flow:established,from_client; content:"GET"; http_method; content:"/monyigamer/bliss_browser_janet/releases/download/v1.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489137/; classtype:trojan-activity;sid:84352237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489118)"; flow:established,from_client; content:"GET"; http_method; content:"/monyigamer/bliss_browser_janet/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489118/; classtype:trojan-activity;sid:84352218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489120)"; flow:established,from_client; content:"GET"; http_method; content:"/firematheo00x/chat-app-mern/releases/download/v2.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489120/; classtype:trojan-activity;sid:84352220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489090)"; flow:established,from_client; content:"GET"; http_method; content:"/lilanders123/act/releases/download/v2.0/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489090/; classtype:trojan-activity;sid:84352190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489088)"; flow:established,from_client; content:"GET"; http_method; content:"/tatooo29/project-hub/releases/download/v2.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489088/; classtype:trojan-activity;sid:84352188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489083)"; flow:established,from_client; content:"GET"; http_method; content:"/tatooo29/project-hub/releases/download/v1.0/application.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489083/; classtype:trojan-activity;sid:84352183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489054)"; flow:established,from_client; content:"GET"; http_method; content:"/booody123/manual-brick-breaker/releases/download/v1.0/program.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489054/; classtype:trojan-activity;sid:84352154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489047)"; flow:established,from_client; content:"GET"; http_method; content:"/booody123/manual-brick-breaker/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489047/; classtype:trojan-activity;sid:84352147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489032)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrokax/webscraper-to-identify-which-girls-and-how-many-of-them-my-boyfriend-follows-on-github/releases/download/v1.0/application.zip"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489032/; classtype:trojan-activity;sid:84352132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489035)"; flow:established,from_client; content:"GET"; http_method; content:"/nash-abella/organization-service/releases/download/v1.0.0/application.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489035/; classtype:trojan-activity;sid:84352135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489027)"; flow:established,from_client; content:"GET"; http_method; content:"/nash-abella/organization-service/releases/download/v2.0/software.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489027/; classtype:trojan-activity;sid:84352127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489028)"; flow:established,from_client; content:"GET"; http_method; content:"/pedrokax/webscraper-to-identify-which-girls-and-how-many-of-them-my-boyfriend-follows-on-github/releases/download/v2.0/software.zip"; http_uri; depth:132; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489028/; classtype:trojan-activity;sid:84352128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489020)"; flow:established,from_client; content:"GET"; http_method; content:"/tailstheflyingfox/subghost/releases/download/v2.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489020/; classtype:trojan-activity;sid:84352120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488996)"; flow:established,from_client; content:"GET"; http_method; content:"/majorclient/html-crypto-currency-chart-snippets/releases/download/v2.0/software.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488996/; classtype:trojan-activity;sid:84352096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489002)"; flow:established,from_client; content:"GET"; http_method; content:"/whathedogding/bitpay-crypto-signal-trading-bot-analysis-signal-masters-trading-crypto/releases/download/v1.0/release.zip"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489002/; classtype:trojan-activity;sid:84352102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489003)"; flow:established,from_client; content:"GET"; http_method; content:"/tailstheflyingfox/subghost/releases/download/v1.0/release.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489003/; classtype:trojan-activity;sid:84352103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489006)"; flow:established,from_client; content:"GET"; http_method; content:"/seiolonmsk/contextindent.nvim/releases/download/v2.0/software.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489006/; classtype:trojan-activity;sid:84352106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489009)"; flow:established,from_client; content:"GET"; http_method; content:"/nuclearcatlegit/simple_bank/releases/download/v1.0/application.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489009/; classtype:trojan-activity;sid:84352109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489010)"; flow:established,from_client; content:"GET"; http_method; content:"/seiolonmsk/contextindent.nvim/releases/download/v1.0/application.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489010/; classtype:trojan-activity;sid:84352110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489014)"; flow:established,from_client; content:"GET"; http_method; content:"/whathedogding/bitpay-crypto-signal-trading-bot-analysis-signal-masters-trading-crypto/releases/download/v2.0/software.zip"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489014/; classtype:trojan-activity;sid:84352114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3489015)"; flow:established,from_client; content:"GET"; http_method; content:"/naiahahah/musicbox/releases/download/v1.0/release.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3489015/; classtype:trojan-activity;sid:84352115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488994)"; flow:established,from_client; content:"GET"; http_method; content:"/nuclearcatlegit/simple_bank/releases/download/v2.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488994/; classtype:trojan-activity;sid:84352094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488995)"; flow:established,from_client; content:"GET"; http_method; content:"/seiolonmsk/contextindent.nvim/releases/download/v1.0/program.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488995/; classtype:trojan-activity;sid:84352095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488983)"; flow:established,from_client; content:"GET"; http_method; content:"/majorclient/html-crypto-currency-chart-snippets/releases/download/v1.0/release.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488983/; classtype:trojan-activity;sid:84352083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488966)"; flow:established,from_client; content:"GET"; http_method; content:"/peloixitu35/javascript-questions-pro/releases/download/v2.0/software.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488966/; classtype:trojan-activity;sid:84352066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488969)"; flow:established,from_client; content:"GET"; http_method; content:"/peloixitu35/javascript-questions-pro/releases/download/v1.0/program.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488969/; classtype:trojan-activity;sid:84352069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488950)"; flow:established,from_client; content:"GET"; http_method; content:"/konnuyu/0xbuilder/releases/download/v1.0/release_x64.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488950/; classtype:trojan-activity;sid:84352050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488940)"; flow:established,from_client; content:"GET"; http_method; content:"/finn9633/batchgenie/releases/download/v1.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488940/; classtype:trojan-activity;sid:84352040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488941)"; flow:established,from_client; content:"GET"; http_method; content:"/konnuyu/0xbuilder/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488941/; classtype:trojan-activity;sid:84352041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488943)"; flow:established,from_client; content:"GET"; http_method; content:"/rakkunsatura/p.e.n.i.s./releases/download/v2.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488943/; classtype:trojan-activity;sid:84352043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488945)"; flow:established,from_client; content:"GET"; http_method; content:"/thiagx08/bue-introduction-to-programming-and-problem-solving/releases/download/v1.0/release_x64.zip"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488945/; classtype:trojan-activity;sid:84352045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488946)"; flow:established,from_client; content:"GET"; http_method; content:"/thiagx08/bue-introduction-to-programming-and-problem-solving/releases/download/v2.0/software.zip"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488946/; classtype:trojan-activity;sid:84352046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488890)"; flow:established,from_client; content:"GET"; http_method; content:"/samix151210/ndarray-base-normalize-indices/releases/download/v2.0/software.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488890/; classtype:trojan-activity;sid:84351990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488880)"; flow:established,from_client; content:"GET"; http_method; content:"/asdadadsaasdsadas991/database-project/releases/download/v2.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488880/; classtype:trojan-activity;sid:84351980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488874)"; flow:established,from_client; content:"GET"; http_method; content:"/merosegamerx/pizza_webapp/releases/download/v2.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488874/; classtype:trojan-activity;sid:84351974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488879)"; flow:established,from_client; content:"GET"; http_method; content:"/merosegamerx/pizza_webapp/releases/download/v1.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488879/; classtype:trojan-activity;sid:84351979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488850)"; flow:established,from_client; content:"GET"; http_method; content:"/kleteee/injectra/releases/download/v1.0/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488850/; classtype:trojan-activity;sid:84351950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488821)"; flow:established,from_client; content:"GET"; http_method; content:"/feelingfishy/challenge-backend-anotaai/releases/download/v2.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488821/; classtype:trojan-activity;sid:84351921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488822)"; flow:established,from_client; content:"GET"; http_method; content:"/nsgaming999/lottery/releases/download/v1.0/application.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488822/; classtype:trojan-activity;sid:84351922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488799)"; flow:established,from_client; content:"GET"; http_method; content:"/ruka232323/network-traffic-visualizer/releases/download/v1.0/application.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488799/; classtype:trojan-activity;sid:84351899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488800)"; flow:established,from_client; content:"GET"; http_method; content:"/feelingfishy/challenge-backend-anotaai/releases/download/v1.0/application.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488800/; classtype:trojan-activity;sid:84351900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488802)"; flow:established,from_client; content:"GET"; http_method; content:"/ruka232323/network-traffic-visualizer/releases/download/v2.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488802/; classtype:trojan-activity;sid:84351902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488806)"; flow:established,from_client; content:"GET"; http_method; content:"/pietro152/tgbot-for-orders/releases/download/v1.0/application.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488806/; classtype:trojan-activity;sid:84351906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488793)"; flow:established,from_client; content:"GET"; http_method; content:"/nsgaming999/lottery/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488793/; classtype:trojan-activity;sid:84351893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488795)"; flow:established,from_client; content:"GET"; http_method; content:"/pietro152/tgbot-for-orders/releases/download/v2.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488795/; classtype:trojan-activity;sid:84351895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488779)"; flow:established,from_client; content:"GET"; http_method; content:"/hza3o/covid-19_dashboard/releases/download/v2.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488779/; classtype:trojan-activity;sid:84351879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488780)"; flow:established,from_client; content:"GET"; http_method; content:"/hza3o/covid-19_dashboard/releases/download/v1.0.0/application.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488780/; classtype:trojan-activity;sid:84351880; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488765)"; flow:established,from_client; content:"GET"; http_method; content:"/1set-t/ai-model/releases/download/v1.0.0/application.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488765/; classtype:trojan-activity;sid:84351865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488758)"; flow:established,from_client; content:"GET"; http_method; content:"/1set-t/ai-model/releases/download/v2.0/software.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488758/; classtype:trojan-activity;sid:84351858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488755)"; flow:established,from_client; content:"GET"; http_method; content:"/mah-22/room-occupancy-prediction-using-environmental-sensor-data/releases/download/v1.0/application.zip"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488755/; classtype:trojan-activity;sid:84351855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488746)"; flow:established,from_client; content:"GET"; http_method; content:"/mah-22/room-occupancy-prediction-using-environmental-sensor-data/releases/download/v2.0/software.zip"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488746/; classtype:trojan-activity;sid:84351846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488751)"; flow:established,from_client; content:"GET"; http_method; content:"/serbianty/eureka-framework/releases/download/v1.0/soft.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488751/; classtype:trojan-activity;sid:84351851; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488752)"; flow:established,from_client; content:"GET"; http_method; content:"/serbianty/eureka-framework/releases/download/v2.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488752/; classtype:trojan-activity;sid:84351852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488729)"; flow:established,from_client; content:"GET"; http_method; content:"/jaylnjohnart/vertex-ai-chat-prompting-tablular-data-bq/releases/download/v2.0/software.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488729/; classtype:trojan-activity;sid:84351829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488733)"; flow:established,from_client; content:"GET"; http_method; content:"/papajszef/web-devapp/releases/download/v2.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488733/; classtype:trojan-activity;sid:84351833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488734)"; flow:established,from_client; content:"GET"; http_method; content:"/gopuatop100/badan-hukum/releases/download/v1.0/release.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488734/; classtype:trojan-activity;sid:84351834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488735)"; flow:established,from_client; content:"GET"; http_method; content:"/jobetsison/working-with-form-validation-in-an-asp.net-core-rich-text-editor/releases/download/v1.0/program.zip"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488735/; classtype:trojan-activity;sid:84351835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488736)"; flow:established,from_client; content:"GET"; http_method; content:"/papajszef/web-devapp/releases/download/v1.0/application.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488736/; classtype:trojan-activity;sid:84351836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488740)"; flow:established,from_client; content:"GET"; http_method; content:"/as3dyasen/portfolio/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488740/; classtype:trojan-activity;sid:84351840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488742)"; flow:established,from_client; content:"GET"; http_method; content:"/as3dyasen/portfolio/releases/download/v1.0/release.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488742/; classtype:trojan-activity;sid:84351842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488725)"; flow:established,from_client; content:"GET"; http_method; content:"/gopuatop100/badan-hukum/releases/download/v2.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488725/; classtype:trojan-activity;sid:84351825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488728)"; flow:established,from_client; content:"GET"; http_method; content:"/jobetsison/working-with-form-validation-in-an-asp.net-core-rich-text-editor/releases/download/v2.0/software.zip"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488728/; classtype:trojan-activity;sid:84351828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488722)"; flow:established,from_client; content:"GET"; http_method; content:"/jaylnjohnart/vertex-ai-chat-prompting-tablular-data-bq/releases/download/v1.0/program.zip"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488722/; classtype:trojan-activity;sid:84351822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488723)"; flow:established,from_client; content:"GET"; http_method; content:"/papajszef/web-devapp/releases/download/v1.0/program.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488723/; classtype:trojan-activity;sid:84351823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488720)"; flow:established,from_client; content:"GET"; http_method; content:"/azw1/suction-funnel-for-bosch-click-clean-system/releases/download/v1.0/program.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488720/; classtype:trojan-activity;sid:84351820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488711)"; flow:established,from_client; content:"GET"; http_method; content:"/zrty456/web-development-project-2/releases/download/v1.0/program.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488711/; classtype:trojan-activity;sid:84351811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488712)"; flow:established,from_client; content:"GET"; http_method; content:"/tekin441/urban_company_clone/releases/download/v1.0/program.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488712/; classtype:trojan-activity;sid:84351812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488713)"; flow:established,from_client; content:"GET"; http_method; content:"/tekin441/urban_company_clone/releases/download/v1.0/application.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488713/; classtype:trojan-activity;sid:84351813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488714)"; flow:established,from_client; content:"GET"; http_method; content:"/flameoptics/xkucoinbot-script-autoclicker/releases/download/v1.0/program.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488714/; classtype:trojan-activity;sid:84351814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488716)"; flow:established,from_client; content:"GET"; http_method; content:"/flameoptics/xkucoinbot-script-autoclicker/releases/download/v2.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488716/; classtype:trojan-activity;sid:84351816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488717)"; flow:established,from_client; content:"GET"; http_method; content:"/psxdupes028/comfyui-bs_kokoro-onnx/releases/download/v1.0/application.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488717/; classtype:trojan-activity;sid:84351817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488706)"; flow:established,from_client; content:"GET"; http_method; content:"/zrty456/web-development-project-2/releases/download/v2.0/software.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488706/; classtype:trojan-activity;sid:84351806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488708)"; flow:established,from_client; content:"GET"; http_method; content:"/azw1/suction-funnel-for-bosch-click-clean-system/releases/download/v1.0/application.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488708/; classtype:trojan-activity;sid:84351808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488702)"; flow:established,from_client; content:"GET"; http_method; content:"/tekin441/urban_company_clone/releases/download/v2.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488702/; classtype:trojan-activity;sid:84351802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488703)"; flow:established,from_client; content:"GET"; http_method; content:"/azw1/suction-funnel-for-bosch-click-clean-system/releases/download/v2.0/software.zip"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488703/; classtype:trojan-activity;sid:84351803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488704)"; flow:established,from_client; content:"GET"; http_method; content:"/psxdupes028/comfyui-bs_kokoro-onnx/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488704/; classtype:trojan-activity;sid:84351804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488699)"; flow:established,from_client; content:"GET"; http_method; content:"/psxdupes028/comfyui-bs_kokoro-onnx/releases/download/v1.0/program.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488699/; classtype:trojan-activity;sid:84351799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488684)"; flow:established,from_client; content:"GET"; http_method; content:"/antonio12gkn71/underlayer/releases/download/v1.0/application.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488684/; classtype:trojan-activity;sid:84351784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488686)"; flow:established,from_client; content:"GET"; http_method; content:"/sundarlalji/autoimport/releases/download/v2.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488686/; classtype:trojan-activity;sid:84351786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488682)"; flow:established,from_client; content:"GET"; http_method; content:"/sundarlalji/autoimport/releases/download/v1.0.0/application.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488682/; classtype:trojan-activity;sid:84351782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488679)"; flow:established,from_client; content:"GET"; http_method; content:"/antonio12gkn71/underlayer/releases/download/v2.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488679/; classtype:trojan-activity;sid:84351779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488673)"; flow:established,from_client; content:"GET"; http_method; content:"/samueltonao/lauth/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488673/; classtype:trojan-activity;sid:84351773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488674)"; flow:established,from_client; content:"GET"; http_method; content:"/hadesxyzz/baichuan-m1-14b/releases/download/v2.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488674/; classtype:trojan-activity;sid:84351774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488663)"; flow:established,from_client; content:"GET"; http_method; content:"/hadesxyzz/baichuan-m1-14b/releases/download/v1.0/application.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488663/; classtype:trojan-activity;sid:84351763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488666)"; flow:established,from_client; content:"GET"; http_method; content:"/samueltonao/lauth/releases/download/v1.0/application.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488666/; classtype:trojan-activity;sid:84351766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488647)"; flow:established,from_client; content:"GET"; http_method; content:"/muum1209/couplers/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488647/; classtype:trojan-activity;sid:84351747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488649)"; flow:established,from_client; content:"GET"; http_method; content:"/muum1209/couplers/releases/download/v1.0/application.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488649/; classtype:trojan-activity;sid:84351749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488654)"; flow:established,from_client; content:"GET"; http_method; content:"/npcgamingyt-thegoat/telegram-robot-handler/releases/download/v2.0/software.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488654/; classtype:trojan-activity;sid:84351754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488643)"; flow:established,from_client; content:"GET"; http_method; content:"/npcgamingyt-thegoat/telegram-robot-handler/releases/download/v1.0/application.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488643/; classtype:trojan-activity;sid:84351743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488636)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/18630095/software.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488636/; classtype:trojan-activity;sid:84351736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488637)"; flow:established,from_client; content:"GET"; http_method; content:"/ericsribas/linux-studies/releases/download/v2.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488637/; classtype:trojan-activity;sid:84351737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488632)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/18630095/software.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488632/; classtype:trojan-activity;sid:84351732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488620)"; flow:established,from_client; content:"GET"; http_method; content:"/saninmysore/aws-face-recognition/releases/download/v1.0/software.zip/"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488620/; classtype:trojan-activity;sid:84351720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488599)"; flow:established,from_client; content:"GET"; http_method; content:"/ericsribas/linux-studies/releases/download/v2.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488599/; classtype:trojan-activity;sid:84351699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488602)"; flow:established,from_client; content:"GET"; http_method; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v1.0/software.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488602/; classtype:trojan-activity;sid:84351702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488605)"; flow:established,from_client; content:"GET"; http_method; content:"/binnizenobiocordovaleandro/apachimuhkayqui-server/releases/download/v2.0/software.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488605/; classtype:trojan-activity;sid:84351705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488606)"; flow:established,from_client; content:"GET"; http_method; content:"/bryandejesusrt/reconocimiento-de-placas-con-ia-bytecoders/releases/download/v2.0/software.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488606/; classtype:trojan-activity;sid:84351706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488608)"; flow:established,from_client; content:"GET"; http_method; content:"/boomerxd69/amog-os-lts/releases/download/v2.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488608/; classtype:trojan-activity;sid:84351708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488614)"; flow:established,from_client; content:"GET"; http_method; content:"/kasonsh2450/bananan-shooter-hack-interna-/releases/download/v2.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488614/; classtype:trojan-activity;sid:84351714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488615)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/18722098/application.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488615/; classtype:trojan-activity;sid:84351715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488595)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/18722098/application.zip"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488595/; classtype:trojan-activity;sid:84351695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488549)"; flow:established,from_client; content:"GET"; http_method; content:"/toe2132313/zorvex-cat/releases/download/v1.0/software.zip/"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488549/; classtype:trojan-activity;sid:84351649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488550)"; flow:established,from_client; content:"GET"; http_method; content:"/xaviertya/.dotfiles/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488550/; classtype:trojan-activity;sid:84351650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488555)"; flow:established,from_client; content:"GET"; http_method; content:"/naiahahah/musicbox/releases/download/v2.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488555/; classtype:trojan-activity;sid:84351655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488533)"; flow:established,from_client; content:"GET"; http_method; content:"/xaviertya/.dotfiles/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488533/; classtype:trojan-activity;sid:84351633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488537)"; flow:established,from_client; content:"GET"; http_method; content:"/aufahuhs/advanced-machine-learning-personal-project/releases/download/v1.0/software.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488537/; classtype:trojan-activity;sid:84351637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488543)"; flow:established,from_client; content:"GET"; http_method; content:"/ggusercool/pancakeswapbnbprediction/releases/download/v2.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488543/; classtype:trojan-activity;sid:84351643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488511)"; flow:established,from_client; content:"GET"; http_method; content:"/12301530/pump-fun-frontend/releases/download/v1.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488511/; classtype:trojan-activity;sid:84351611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488478)"; flow:established,from_client; content:"GET"; http_method; content:"/rahulpa045/cphishtermux/releases/download/v2.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488478/; classtype:trojan-activity;sid:84351578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488483)"; flow:established,from_client; content:"GET"; http_method; content:"/davinjoeevano/batch-project-scaffolds/releases/download/v2.0/software.zip/"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488483/; classtype:trojan-activity;sid:84351583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488487)"; flow:established,from_client; content:"GET"; http_method; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v2.0/software.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488487/; classtype:trojan-activity;sid:84351587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488488)"; flow:established,from_client; content:"GET"; http_method; content:"/bashspicerb/quasarrat-remote-access-tool/releases/download/v2.0/software.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488488/; classtype:trojan-activity;sid:84351588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488492)"; flow:established,from_client; content:"GET"; http_method; content:"/cartervr/taxdatabase-sql-tableau/releases/download/v2.0/software.zip/"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488492/; classtype:trojan-activity;sid:84351592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488496)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/githubtutorial/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488496/; classtype:trojan-activity;sid:84351596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488497)"; flow:established,from_client; content:"GET"; http_method; content:"/globalnewsory/layeredge-auto-bot/releases/download/v2.0/software.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488497/; classtype:trojan-activity;sid:84351597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488501)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_tinyxml/releases/download/v2.0/software.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488501/; classtype:trojan-activity;sid:84351601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488460)"; flow:established,from_client; content:"GET"; http_method; content:"/loudwens/displayindex/releases/download/v2.0/software.zip/"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488460/; classtype:trojan-activity;sid:84351560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488441)"; flow:established,from_client; content:"GET"; http_method; content:"/pufferfish420/fixing-error-0x8007000e/releases/download/v2.0/program.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488441/; classtype:trojan-activity;sid:84351541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488443)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodxsp5dda/domain-executor/releases/download/v2.0/program.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488443/; classtype:trojan-activity;sid:84351543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488436)"; flow:established,from_client; content:"GET"; http_method; content:"/elijahhx/dead1ock-h4ck/releases/download/v2.0/program.zip/"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488436/; classtype:trojan-activity;sid:84351536; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488433)"; flow:established,from_client; content:"GET"; http_method; content:"/elijahhx/dead1ock-h4ck/releases/download/v2.0/program.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488433/; classtype:trojan-activity;sid:84351533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488426)"; flow:established,from_client; content:"GET"; http_method; content:"/rag7720/coretech-solutions-custom-odoo-module/releases/download/v1.0/software.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488426/; classtype:trojan-activity;sid:84351526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488425)"; flow:established,from_client; content:"GET"; http_method; content:"/rag7720/coretech-solutions-custom-odoo-module/releases/download/v2.0/software.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488425/; classtype:trojan-activity;sid:84351525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488403)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinborgesz/the-data-engineering-academy/releases/download/v2.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488403/; classtype:trojan-activity;sid:84351503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488406)"; flow:established,from_client; content:"GET"; http_method; content:"/kevinborgesz/the-data-engineering-academy/releases/download/v1.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488406/; classtype:trojan-activity;sid:84351506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488368)"; flow:established,from_client; content:"GET"; http_method; content:"/notready155/whatsapp-chat-analysis/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488368/; classtype:trojan-activity;sid:84351468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488350)"; flow:established,from_client; content:"GET"; http_method; content:"/ilovedoo/ted-lasso-gpt/releases/download/v1.0/application.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488350/; classtype:trojan-activity;sid:84351450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488359)"; flow:established,from_client; content:"GET"; http_method; content:"/notready155/whatsapp-chat-analysis/releases/download/v1.0/application.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488359/; classtype:trojan-activity;sid:84351459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488360)"; flow:established,from_client; content:"GET"; http_method; content:"/ilovedoo/ted-lasso-gpt/releases/download/v2.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488360/; classtype:trojan-activity;sid:84351460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488346)"; flow:established,from_client; content:"GET"; http_method; content:"/bigdaveyy/react-form-validator-pro/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488346/; classtype:trojan-activity;sid:84351446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488334)"; flow:established,from_client; content:"GET"; http_method; content:"/bin49/gym-management-system-/releases/download/v1.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488334/; classtype:trojan-activity;sid:84351434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488336)"; flow:established,from_client; content:"GET"; http_method; content:"/bin49/gym-management-system-/releases/download/v2.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488336/; classtype:trojan-activity;sid:84351436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488339)"; flow:established,from_client; content:"GET"; http_method; content:"/bigdaveyy/react-form-validator-pro/releases/download/v1.0/installer.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488339/; classtype:trojan-activity;sid:84351439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488325)"; flow:established,from_client; content:"GET"; http_method; content:"/yunichi/livekit-voice-ai-agent-setup/releases/download/v2.0/software.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488325/; classtype:trojan-activity;sid:84351425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488314)"; flow:established,from_client; content:"GET"; http_method; content:"/hvkleon/text-classification-sentiment-analysis/releases/download/v2.0/software.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488314/; classtype:trojan-activity;sid:84351414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488306)"; flow:established,from_client; content:"GET"; http_method; content:"/hvkleon/text-classification-sentiment-analysis/releases/download/v1.0/installer.zip"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488306/; classtype:trojan-activity;sid:84351406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488307)"; flow:established,from_client; content:"GET"; http_method; content:"/thandoman/seedtool/releases/download/v2.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488307/; classtype:trojan-activity;sid:84351407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488304)"; flow:established,from_client; content:"GET"; http_method; content:"/thandoman/seedtool/releases/download/v1.0/application.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488304/; classtype:trojan-activity;sid:84351404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488294)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/solana-trading-bot/releases/download/v2.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488294/; classtype:trojan-activity;sid:84351394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488268)"; flow:established,from_client; content:"GET"; http_method; content:"/bashspicerb/quasarrat-remote-access-tool/releases/download/v1.0/installer.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488268/; classtype:trojan-activity;sid:84351368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488269)"; flow:established,from_client; content:"GET"; http_method; content:"/marig1204/dmail_classicemail/releases/download/v2.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488269/; classtype:trojan-activity;sid:84351369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488273)"; flow:established,from_client; content:"GET"; http_method; content:"/itztoastie/email2_classicemail/releases/download/v1.0/installer.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488273/; classtype:trojan-activity;sid:84351373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488274)"; flow:established,from_client; content:"GET"; http_method; content:"/marig1204/dmail_classicemail/releases/download/v1.0/installer.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488274/; classtype:trojan-activity;sid:84351374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488278)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/solana-trading-bot/releases/download/v1.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488278/; classtype:trojan-activity;sid:84351378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488282)"; flow:established,from_client; content:"GET"; http_method; content:"/cartervr/taxdatabase-sql-tableau/releases/download/v1.0/release.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488282/; classtype:trojan-activity;sid:84351382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488264)"; flow:established,from_client; content:"GET"; http_method; content:"/itztoastie/email2_classicemail/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488264/; classtype:trojan-activity;sid:84351364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488261)"; flow:established,from_client; content:"GET"; http_method; content:"/bashspicerb/quasarrat-remote-access-tool/releases/download/v2.0/software.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488261/; classtype:trojan-activity;sid:84351361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488243)"; flow:established,from_client; content:"GET"; http_method; content:"/pyc888/dbcachinglayer/releases/download/v2.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488243/; classtype:trojan-activity;sid:84351343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488233)"; flow:established,from_client; content:"GET"; http_method; content:"/bolfymcplayer/intermag/releases/download/v1.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488233/; classtype:trojan-activity;sid:84351333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488234)"; flow:established,from_client; content:"GET"; http_method; content:"/bolfymcplayer/intermag/releases/download/v2.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488234/; classtype:trojan-activity;sid:84351334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488239)"; flow:established,from_client; content:"GET"; http_method; content:"/pyc888/dbcachinglayer/releases/download/v1.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488239/; classtype:trojan-activity;sid:84351339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488214)"; flow:established,from_client; content:"GET"; http_method; content:"/kirito1110/licenses/releases/download/v1.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488214/; classtype:trojan-activity;sid:84351314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488213)"; flow:established,from_client; content:"GET"; http_method; content:"/vsparedes/pycalc/releases/download/v1.0/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488213/; classtype:trojan-activity;sid:84351313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488208)"; flow:established,from_client; content:"GET"; http_method; content:"/skibiditoilet123xx/sinav-otomasyonu-prototip/releases/download/v2.0/software.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488208/; classtype:trojan-activity;sid:84351308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488209)"; flow:established,from_client; content:"GET"; http_method; content:"/skibiditoilet123xx/sinav-otomasyonu-prototip/releases/download/v1.0/software.zip"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488209/; classtype:trojan-activity;sid:84351309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488210)"; flow:established,from_client; content:"GET"; http_method; content:"/fluidx2/roombooking_application/releases/download/v1.0/software.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488210/; classtype:trojan-activity;sid:84351310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488211)"; flow:established,from_client; content:"GET"; http_method; content:"/viper700pro/serum-vst-installer-2024-free/releases/download/v1.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488211/; classtype:trojan-activity;sid:84351311; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488203)"; flow:established,from_client; content:"GET"; http_method; content:"/ella00311/erugo/releases/download/v1.0/software.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488203/; classtype:trojan-activity;sid:84351303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488182)"; flow:established,from_client; content:"GET"; http_method; content:"/nour10381/cosmicstar/releases/download/v2.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488182/; classtype:trojan-activity;sid:84351282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488184)"; flow:established,from_client; content:"GET"; http_method; content:"/nour10381/cosmicstar/releases/download/v1.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488184/; classtype:trojan-activity;sid:84351284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488185)"; flow:established,from_client; content:"GET"; http_method; content:"/powerangermerah/esp8266_esp32_web_file_manager/releases/download/v2.0/software.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488185/; classtype:trojan-activity;sid:84351285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488186)"; flow:established,from_client; content:"GET"; http_method; content:"/powerangermerah/esp8266_esp32_web_file_manager/releases/download/v1.0/software.zip"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488186/; classtype:trojan-activity;sid:84351286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488181)"; flow:established,from_client; content:"GET"; http_method; content:"/aufahuhs/advanced-machine-learning-personal-project/releases/download/v1.0/software.zip"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488181/; classtype:trojan-activity;sid:84351281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488162)"; flow:established,from_client; content:"GET"; http_method; content:"/berstarhunter/deepseek-start/releases/download/v2.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488162/; classtype:trojan-activity;sid:84351262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488157)"; flow:established,from_client; content:"GET"; http_method; content:"/davinjoeevano/batch-project-scaffolds/releases/download/v2.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488157/; classtype:trojan-activity;sid:84351257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488156)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanr-source/synthtweet/releases/download/v2.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488156/; classtype:trojan-activity;sid:84351256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488147)"; flow:established,from_client; content:"GET"; http_method; content:"/arya-gg/axium/releases/download/v1.0/software.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488147/; classtype:trojan-activity;sid:84351247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488148)"; flow:established,from_client; content:"GET"; http_method; content:"/davinjoeevano/batch-project-scaffolds/releases/download/v1.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488148/; classtype:trojan-activity;sid:84351248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488152)"; flow:established,from_client; content:"GET"; http_method; content:"/berstarhunter/deepseek-start/releases/download/v1.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488152/; classtype:trojan-activity;sid:84351252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488153)"; flow:established,from_client; content:"GET"; http_method; content:"/toe2132313/zorvex-cat/releases/download/v1.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488153/; classtype:trojan-activity;sid:84351253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488146)"; flow:established,from_client; content:"GET"; http_method; content:"/irfanr-source/synthtweet/releases/download/v1.0/software.zip"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488146/; classtype:trojan-activity;sid:84351246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488128)"; flow:established,from_client; content:"GET"; http_method; content:"/loudwens/displayindex/releases/download/v2.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488128/; classtype:trojan-activity;sid:84351228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488131)"; flow:established,from_client; content:"GET"; http_method; content:"/12301530/pump-fun-frontend/releases/download/v1.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488131/; classtype:trojan-activity;sid:84351231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488132)"; flow:established,from_client; content:"GET"; http_method; content:"/loudwens/displayindex/releases/download/v1.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488132/; classtype:trojan-activity;sid:84351232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488125)"; flow:established,from_client; content:"GET"; http_method; content:"/12301530/pump-fun-frontend/releases/download/v2.0/software.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488125/; classtype:trojan-activity;sid:84351225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488103)"; flow:established,from_client; content:"GET"; http_method; content:"/saninmysore/aws-face-recognition/releases/download/v1.0/software.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488103/; classtype:trojan-activity;sid:84351203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488110)"; flow:established,from_client; content:"GET"; http_method; content:"/flarerealfr/url-biblioteca-web/releases/download/v2.0/software.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488110/; classtype:trojan-activity;sid:84351210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488098)"; flow:established,from_client; content:"GET"; http_method; content:"/prakrititz/deepwater/releases/download/v1.0/software.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488098/; classtype:trojan-activity;sid:84351198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488102)"; flow:established,from_client; content:"GET"; http_method; content:"/futurinav/esteai/releases/download/v1.0/software.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488102/; classtype:trojan-activity;sid:84351202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488079)"; flow:established,from_client; content:"GET"; http_method; content:"/alsooory/svg-templates/releases/download/v1.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488079/; classtype:trojan-activity;sid:84351179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488085)"; flow:established,from_client; content:"GET"; http_method; content:"/bobbysaremine/hb2/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488085/; classtype:trojan-activity;sid:84351185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488075)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_airbnb-lottie/releases/download/v2.0/software.zip"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488075/; classtype:trojan-activity;sid:84351175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488061)"; flow:established,from_client; content:"GET"; http_method; content:"/ayobcoding/deep-research-py/releases/download/v1.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488061/; classtype:trojan-activity;sid:84351161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488054)"; flow:established,from_client; content:"GET"; http_method; content:"/keanusmall/sahimatch.ai/releases/download/v1.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488054/; classtype:trojan-activity;sid:84351154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488057)"; flow:established,from_client; content:"GET"; http_method; content:"/alejandro5486/infestuswebapp/releases/download/v1.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488057/; classtype:trojan-activity;sid:84351157; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488035)"; flow:established,from_client; content:"GET"; http_method; content:"/kossiw/olievra/releases/download/v1.0/software.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488035/; classtype:trojan-activity;sid:84351135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488034)"; flow:established,from_client; content:"GET"; http_method; content:"/yogeshnicks/loader-ldtk/releases/download/v2.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488034/; classtype:trojan-activity;sid:84351134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488023)"; flow:established,from_client; content:"GET"; http_method; content:"/vukhang16/ggg/releases/download/v1.0/software.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488023/; classtype:trojan-activity;sid:84351123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488021)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_airbnb-lottie/releases/download/v1.0/application.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488021/; classtype:trojan-activity;sid:84351121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3488000)"; flow:established,from_client; content:"GET"; http_method; content:"/iampriam-dev/invenstock/releases/download/v1.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3488000/; classtype:trojan-activity;sid:84351100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487983)"; flow:established,from_client; content:"GET"; http_method; content:"/zeidmakic/quorixjwt/releases/download/v1.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487983/; classtype:trojan-activity;sid:84351083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487977)"; flow:established,from_client; content:"GET"; http_method; content:"/zeidmakic/quorixjwt/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487977/; classtype:trojan-activity;sid:84351077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487974)"; flow:established,from_client; content:"GET"; http_method; content:"/amoni2019/fonepaw-screen-recorder-free/releases/download/v1.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487974/; classtype:trojan-activity;sid:84351074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487975)"; flow:established,from_client; content:"GET"; http_method; content:"/brotimer24/chargingassignment.withtests/releases/download/v1.0/software.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487975/; classtype:trojan-activity;sid:84351075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487947)"; flow:established,from_client; content:"GET"; http_method; content:"/jay3x/auto-commit/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487947/; classtype:trojan-activity;sid:84351047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487950)"; flow:established,from_client; content:"GET"; http_method; content:"/brotimer24/chargingassignment.withtests/releases/download/v2.0/software.zip"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487950/; classtype:trojan-activity;sid:84351050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487952)"; flow:established,from_client; content:"GET"; http_method; content:"/amoni2019/fonepaw-screen-recorder-free/releases/download/v2.0/software.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487952/; classtype:trojan-activity;sid:84351052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487953)"; flow:established,from_client; content:"GET"; http_method; content:"/daveyisbricked/movie-finder-react/releases/download/v1.0/software.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487953/; classtype:trojan-activity;sid:84351053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487954)"; flow:established,from_client; content:"GET"; http_method; content:"/daveyisbricked/movie-finder-react/releases/download/v2.0/software.zip"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487954/; classtype:trojan-activity;sid:84351054; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487955)"; flow:established,from_client; content:"GET"; http_method; content:"/jay3x/auto-commit/releases/download/v1.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487955/; classtype:trojan-activity;sid:84351055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487956)"; flow:established,from_client; content:"GET"; http_method; content:"/quynh814/teafibot/releases/download/v2.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487956/; classtype:trojan-activity;sid:84351056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487944)"; flow:established,from_client; content:"GET"; http_method; content:"/hafijulkhan786/fhnw-dashboard/releases/download/v2.0/software.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487944/; classtype:trojan-activity;sid:84351044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487939)"; flow:established,from_client; content:"GET"; http_method; content:"/quynh814/teafibot/releases/download/v1.0/software.zip"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487939/; classtype:trojan-activity;sid:84351039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487935)"; flow:established,from_client; content:"GET"; http_method; content:"/iampriam-dev/invenstock/releases/download/v2.0/software.zip"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487935/; classtype:trojan-activity;sid:84351035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487930)"; flow:established,from_client; content:"GET"; http_method; content:"/justnem/deep-research/releases/download/v2.0/software.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487930/; classtype:trojan-activity;sid:84351030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487931)"; flow:established,from_client; content:"GET"; http_method; content:"/rofix12/spring-microservices/releases/download/v2.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487931/; classtype:trojan-activity;sid:84351031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487929)"; flow:established,from_client; content:"GET"; http_method; content:"/justnem/deep-research/releases/download/v1.0/app.zip"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487929/; classtype:trojan-activity;sid:84351029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487918)"; flow:established,from_client; content:"GET"; http_method; content:"/jeff2807/githubaipy/releases/download/v1.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487918/; classtype:trojan-activity;sid:84351018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487920)"; flow:established,from_client; content:"GET"; http_method; content:"/rahul110110/rocket-telemetry-logger-using-raspberry-pi-pico/releases/download/v1.0/software.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487920/; classtype:trojan-activity;sid:84351020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487921)"; flow:established,from_client; content:"GET"; http_method; content:"/jeff2807/githubaipy/releases/download/v2.0/software.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487921/; classtype:trojan-activity;sid:84351021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487916)"; flow:established,from_client; content:"GET"; http_method; content:"/binnizenobiocordovaleandro/apachimuhkayqui-server/releases/download/v2.0/software.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487916/; classtype:trojan-activity;sid:84351016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487909)"; flow:established,from_client; content:"GET"; http_method; content:"/rofix12/spring-microservices/releases/download/v1.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487909/; classtype:trojan-activity;sid:84351009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487905)"; flow:established,from_client; content:"GET"; http_method; content:"/rahul110110/rocket-telemetry-logger-using-raspberry-pi-pico/releases/download/v2.0/software.zip"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487905/; classtype:trojan-activity;sid:84351005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487902)"; flow:established,from_client; content:"GET"; http_method; content:"/bryandejesusrt/reconocimiento-de-placas-con-ia-bytecoders/releases/download/v2.0/software.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_24; reference:url, urlhaus.abuse.ch/url/3487902/; classtype:trojan-activity;sid:84351002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487360)"; flow:established,from_client; content:"GET"; http_method; content:"/wer812/bhh666666666666/raw/refs/heads/main/service.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_23; reference:url, urlhaus.abuse.ch/url/3487360/; classtype:trojan-activity;sid:84350460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487363)"; flow:established,from_client; content:"GET"; http_method; content:"/wer812/vbvgghjjio999000/raw/refs/heads/main/bnoaprihjatuasss.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_23; reference:url, urlhaus.abuse.ch/url/3487363/; classtype:trojan-activity;sid:84350463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3487364)"; flow:established,from_client; content:"GET"; http_method; content:"/wer812/bbgy555555551/raw/refs/heads/main/ntladlklthawd.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_23; reference:url, urlhaus.abuse.ch/url/3487364/; classtype:trojan-activity;sid:84350464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3486184)"; flow:established,from_client; content:"GET"; http_method; content:"/ilganrat342/dgasgxc/refs/heads/main/setup.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_22; reference:url, urlhaus.abuse.ch/url/3486184/; classtype:trojan-activity;sid:84349284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3485144)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1k4idibw1vtsntpbqtvbfabfgm2h5s14d"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3485144/; classtype:trojan-activity;sid:84348244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3485126)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1km_hwk7sn_amuk7q2dk9kttzwk1taelw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3485126/; classtype:trojan-activity;sid:84348226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3485125)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ek4th7ucqd9_h2yf9orhzhuallukeo0n"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3485125/; classtype:trojan-activity;sid:84348225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3484591)"; flow:established,from_client; content:"GET"; http_method; content:"/bin/support.client.exe|3f||3f|i=|7c|26|7c|e=support|7c|26|7c|y=guest|7c|26|7c|r="; http_uri; depth:81; isdataat:!1,relative; nocase; content:"screenconnect.pro"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_03_21; reference:url, urlhaus.abuse.ch/url/3484591/; classtype:trojan-activity;sid:84347691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483995)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodxsp5dda/domain-executor/releases/download/v2.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483995/; classtype:trojan-activity;sid:84347095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483984)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodxsp5dda/domain-executor/releases/download/v3.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483984/; classtype:trojan-activity;sid:84347084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483979)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodxsp5dda/domain-executor/releases/download/v2.0/program.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483979/; classtype:trojan-activity;sid:84347079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483980)"; flow:established,from_client; content:"GET"; http_method; content:"/hoodxsp5dda/domain-executor/releases/download/v1.0/software.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483980/; classtype:trojan-activity;sid:84347080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483406)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1q6iji-1uq5ksrr3luufy3to-jfs4ec4d"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483406/; classtype:trojan-activity;sid:84346506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483319)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1inbpqtz2qyus0zqldnbhutbzwgdghhs0"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483319/; classtype:trojan-activity;sid:84346419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483317)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1g4q6iay5qjzlgigjqnwftkdc5-o_2pqx"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483317/; classtype:trojan-activity;sid:84346417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3483309)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1cl-nvhrrue_wg2zkpuxmvk40tk3knacb"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_20; reference:url, urlhaus.abuse.ch/url/3483309/; classtype:trojan-activity;sid:84346409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482360)"; flow:established,from_client; content:"GET"; http_method; content:"/omio-saha/spotify_data_pipe_snowflake/releases/download/v1.0/release_x64.zip"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482360/; classtype:trojan-activity;sid:84345460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482367)"; flow:established,from_client; content:"GET"; http_method; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v1.0/software.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482367/; classtype:trojan-activity;sid:84345467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482368)"; flow:established,from_client; content:"GET"; http_method; content:"/qaqmmw/music-recommendation-based-on-facial-expression/releases/download/v2.0/software.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482368/; classtype:trojan-activity;sid:84345468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3482262)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/css/colors/sunrise/xundfaxgnsp84.bin"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"www.automobile-bk.de"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3482262/; classtype:trojan-activity;sid:84345362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3481956)"; flow:established,from_client; content:"GET"; http_method; content:"/numonehittaboy/cdn/refs/heads/main/cvf.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_19; reference:url, urlhaus.abuse.ch/url/3481956/; classtype:trojan-activity;sid:84345056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3481344)"; flow:established,from_client; content:"GET"; http_method; content:"/alishazara/api/refs/heads/master/rh_s.txt"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_03_18; reference:url, urlhaus.abuse.ch/url/3481344/; classtype:trojan-activity;sid:84344444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480616)"; flow:established,from_client; content:"GET"; http_method; content:"/ty9989/u/raw/main/ud.bat"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480616/; classtype:trojan-activity;sid:84343716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480361)"; flow:established,from_client; content:"GET"; http_method; content:"/elijahhx/dead1ock-h4ck/releases/download/v2.0/program.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480361/; classtype:trojan-activity;sid:84343461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480359)"; flow:established,from_client; content:"GET"; http_method; content:"/nurraif/mytonwallet/releases/download/v2.0/program.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480359/; classtype:trojan-activity;sid:84343459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3480274)"; flow:established,from_client; content:"GET"; http_method; content:"/gollfinho/browser-testing/releases/download/v2.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_17; reference:url, urlhaus.abuse.ch/url/3480274/; classtype:trojan-activity;sid:84343374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3478657)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"66.196.62.177"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_03_15; reference:url, urlhaus.abuse.ch/url/3478657/; classtype:trojan-activity;sid:84341757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3478592)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.68.30.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_03_15; reference:url, urlhaus.abuse.ch/url/3478592/; classtype:trojan-activity;sid:84341692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475656)"; flow:established,from_client; content:"GET"; http_method; content:"/pufferfish420/fixing-error-0x8007000e/releases/download/v2.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475656/; classtype:trojan-activity;sid:84338756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475642)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/githubtutorial/releases/download/v2.0/software.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475642/; classtype:trojan-activity;sid:84338742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475644)"; flow:established,from_client; content:"GET"; http_method; content:"/phamtaino/fixing-error-0x80004005-unspecified/releases/download/v2.0/software.zip"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475644/; classtype:trojan-activity;sid:84338744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475645)"; flow:established,from_client; content:"GET"; http_method; content:"/attorneywenn/pragati_backend_2025/releases/download/v2.0/application.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475645/; classtype:trojan-activity;sid:84338745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475646)"; flow:established,from_client; content:"GET"; http_method; content:"/pufferfish420/fixing-error-0x8007000e/releases/download/v2.0/program.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475646/; classtype:trojan-activity;sid:84338746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475651)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_selinux/releases/download/v2.0/software.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475651/; classtype:trojan-activity;sid:84338751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475624)"; flow:established,from_client; content:"GET"; http_method; content:"/boomerxd69/amog-os-lts/releases/download/v2.0/software.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475624/; classtype:trojan-activity;sid:84338724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475630)"; flow:established,from_client; content:"GET"; http_method; content:"/coltostemp/platform_external_tinyxml/releases/download/v2.0/software.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475630/; classtype:trojan-activity;sid:84338730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475635)"; flow:established,from_client; content:"GET"; http_method; content:"/mehedihasanfarabi10/realtime-chat-app/releases/download/v2.0/software.zip"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475635/; classtype:trojan-activity;sid:84338735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475636)"; flow:established,from_client; content:"GET"; http_method; content:"/itznaviya/hamster-kombat-bot/releases/download/v3.0/software.zip"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475636/; classtype:trojan-activity;sid:84338736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475637)"; flow:established,from_client; content:"GET"; http_method; content:"/kasonsh2450/fixing-error-0x80070005-access-denied/releases/download/v2.0/software.zip"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475637/; classtype:trojan-activity;sid:84338737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475639)"; flow:established,from_client; content:"GET"; http_method; content:"/toanminh2004/fixing-error-0x80070424-specified-service/releases/download/v2.0/software.zip"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475639/; classtype:trojan-activity;sid:84338739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475615)"; flow:established,from_client; content:"GET"; http_method; content:"/naiahahah/musicbox/releases/download/v2.0/software.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475615/; classtype:trojan-activity;sid:84338715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3475620)"; flow:established,from_client; content:"GET"; http_method; content:"/kasonsh2450/bananan-shooter-hack-interna-/releases/download/v2.0/software.zip"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_13; reference:url, urlhaus.abuse.ch/url/3475620/; classtype:trojan-activity;sid:84338720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473787)"; flow:established,from_client; content:"GET"; http_method; content:"/cartervr/taxdatabase-sql-tableau/releases/download/v2.0/software.zip"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473787/; classtype:trojan-activity;sid:84336887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473766)"; flow:established,from_client; content:"GET"; http_method; content:"/ggusercool/pancakeswapbnbprediction/releases/download/v2.0/software.zip"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473766/; classtype:trojan-activity;sid:84336866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473777)"; flow:established,from_client; content:"GET"; http_method; content:"/yosif9999/hamster-clicker/releases/download/v2.0/software.zip"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473777/; classtype:trojan-activity;sid:84336877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473779)"; flow:established,from_client; content:"GET"; http_method; content:"/led-sol/mental-health-chatbot/releases/download/v1.0/software.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473779/; classtype:trojan-activity;sid:84336879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473576)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ovluq0bdu-cys5xvyogyjd5qidqb1per"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_11; reference:url, urlhaus.abuse.ch/url/3473576/; classtype:trojan-activity;sid:84336676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3473160)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1d4aper-gjv3agk8yeny5scayonlc68yo"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_10; reference:url, urlhaus.abuse.ch/url/3473160/; classtype:trojan-activity;sid:84336260; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3472675)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_10; reference:url, urlhaus.abuse.ch/url/3472675/; classtype:trojan-activity;sid:84335775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3468872)"; flow:established,from_client; content:"GET"; http_method; content:"/xraqwapfu.pdf"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"galerisenimutiara.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3468872/; classtype:trojan-activity;sid:84331972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467628)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1eczx8yjtfxwos26grqtdixajed3ukcao"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467628/; classtype:trojan-activity;sid:84330728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467629)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1drptefwc7xybtum52bikrhp4j4l6lttc"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467629/; classtype:trojan-activity;sid:84330729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467546)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f2d42ffe-779b-4107-ac42-7f36375aab37/downloads/fojik.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467546/; classtype:trojan-activity;sid:84330646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467537)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/61705749605.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467537/; classtype:trojan-activity;sid:84330637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467538)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/dd3b43cd-389e-413e-87b9-e21f40c2630d/downloads/guledazawabumoda.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467538/; classtype:trojan-activity;sid:84330638; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467533)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/637623a6-af9b-4a69-90a8-85cd562c999e/downloads/niwexokaburule.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467533/; classtype:trojan-activity;sid:84330633; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467528)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/96f90b6e-3939-4cac-a3ad-eba9fb8219bf/downloads/71599608952.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467528/; classtype:trojan-activity;sid:84330628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467523)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3e712c63-2f24-4e6b-a5dc-ff3233100bea/downloads/72290413200.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467523/; classtype:trojan-activity;sid:84330623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467524)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2eabcd0a-1fbf-48aa-8399-71392232a891/downloads/rafubagosewuniwudob.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467524/; classtype:trojan-activity;sid:84330624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467525)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/70485427967.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467525/; classtype:trojan-activity;sid:84330625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467526)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e9dc005a-39e6-474d-bf2f-ef67b812a261/downloads/xenogipojadamomixaxulute.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467526/; classtype:trojan-activity;sid:84330626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467527)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/9089368795.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467527/; classtype:trojan-activity;sid:84330627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467516)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/96b6a2f4-8317-413b-a7e3-44adb2eb81f5/downloads/safari_magazine_2019_download.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467516/; classtype:trojan-activity;sid:84330616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467517)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8014aeaa-17b8-4bcd-a9d7-094ad1ff7644/downloads/fusoze.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467517/; classtype:trojan-activity;sid:84330617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467519)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/plan_technique_piscine_a_debordement.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467519/; classtype:trojan-activity;sid:84330619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467521)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/83838390139.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467521/; classtype:trojan-activity;sid:84330621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467510)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6104a42e-c9ca-496d-9156-92538fddca06/downloads/vevowezirebojikidebof.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467510/; classtype:trojan-activity;sid:84330610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467513)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/temisipilotiba.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467513/; classtype:trojan-activity;sid:84330613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467501)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/79427765137.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467501/; classtype:trojan-activity;sid:84330601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467478)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/examples_of_employee_goals_for_performance_review.pdf"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467478/; classtype:trojan-activity;sid:84330578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467477)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/50228966329.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467477/; classtype:trojan-activity;sid:84330577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467475)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/educational_leadership_philosophy_examples.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467475/; classtype:trojan-activity;sid:84330575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467476)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/299c0676-bac5-4db6-8fea-3075091e1687/downloads/61526216713.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467476/; classtype:trojan-activity;sid:84330576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467465)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/gumofeke.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467465/; classtype:trojan-activity;sid:84330565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467466)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/mawanigokur.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467466/; classtype:trojan-activity;sid:84330566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467469)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/36054141231.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467469/; classtype:trojan-activity;sid:84330569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467470)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a37fc73a-27ae-4e8d-87b6-7c807b298be6/downloads/85925649248.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467470/; classtype:trojan-activity;sid:84330570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467471)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/educacion_financiera_avanzada_partiendo_de_cero_autor_gregor.pdf"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467471/; classtype:trojan-activity;sid:84330571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467472)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/663ae0bf-1142-4d7a-8653-755553f6852e/downloads/lejafarezafig.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467472/; classtype:trojan-activity;sid:84330572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467474)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/biwejukajurel.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467474/; classtype:trojan-activity;sid:84330574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467458)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/6083216094.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467458/; classtype:trojan-activity;sid:84330558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467459)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62128af0-82d0-4bae-b967-d393a4304003/downloads/69065118383.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467459/; classtype:trojan-activity;sid:84330559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467461)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/51e053ea-8122-46e3-bee6-6c00a935619c/downloads/40061082597.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467461/; classtype:trojan-activity;sid:84330561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467462)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/94224235634.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467462/; classtype:trojan-activity;sid:84330562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467463)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/739cff78-28a4-4749-8c7f-abf371b6a947/downloads/62789327536.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467463/; classtype:trojan-activity;sid:84330563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467464)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ee12fbcb-3848-4c54-8690-0d9c760d3837/downloads/5683334295.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467464/; classtype:trojan-activity;sid:84330564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467453)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d9b3f7f8-355a-428e-bb44-74bff775274d/downloads/supix.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467453/; classtype:trojan-activity;sid:84330553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467454)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/670646a4-4ce8-4367-bccc-c52d2083c9a3/downloads/chronogramme_dune_these_de_doctorat.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467454/; classtype:trojan-activity;sid:84330554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467455)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1e222df8-d197-4254-b90b-be3d3b023ef4/downloads/zopawakabubijipek.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467455/; classtype:trojan-activity;sid:84330555; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467456)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/27590969755.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467456/; classtype:trojan-activity;sid:84330556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467457)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kudokexogikekuporeso.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467457/; classtype:trojan-activity;sid:84330557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467452)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/48255006417.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467452/; classtype:trojan-activity;sid:84330552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467448)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/09540d0c-1db9-4e3c-a32d-6eed7b48ae00/downloads/3841723103.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467448/; classtype:trojan-activity;sid:84330548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467443)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/exemple_de_dossier_raep_redige.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467443/; classtype:trojan-activity;sid:84330543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467444)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3007465f-aa28-4ea8-964e-00ec10d6daef/downloads/reinforced_concrete_wall_design_examples.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467444/; classtype:trojan-activity;sid:84330544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467445)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/munich_tourist_attractions_map.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467445/; classtype:trojan-activity;sid:84330545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467438)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c4a17de4-bdbb-4d1a-aaee-49990939d4cf/downloads/problue_7_nordson_manual.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467438/; classtype:trojan-activity;sid:84330538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467440)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/30229793875.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467440/; classtype:trojan-activity;sid:84330540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467433)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/cooling_tower_working.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467433/; classtype:trojan-activity;sid:84330533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467434)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/corporate_signature_authority_matrix_template_printable.pdf"; http_uri; depth:117; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467434/; classtype:trojan-activity;sid:84330534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467425)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/continental_online_assessment_test_answers.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467425/; classtype:trojan-activity;sid:84330525; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467426)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/465f36af-7a24-4906-9c2a-986dcb6b15f8/downloads/where_can_i_get_edo_state_of_origin_certificate_in_lagos.pdf"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467426/; classtype:trojan-activity;sid:84330526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467427)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/sample_testimonials_for_employees.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467427/; classtype:trojan-activity;sid:84330527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467428)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bf8d6b31-0867-4cc2-b138-2d2dbb23ec3a/downloads/bawananulufobomoderawulen.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467428/; classtype:trojan-activity;sid:84330528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467429)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/90dc87b4-fd7e-4412-9a6a-76e20db16dbd/downloads/23425133870.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467429/; classtype:trojan-activity;sid:84330529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467422)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a37fc73a-27ae-4e8d-87b6-7c807b298be6/downloads/86119351354.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467422/; classtype:trojan-activity;sid:84330522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467423)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/kagoferoxotopelabalim.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467423/; classtype:trojan-activity;sid:84330523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467411)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/how_to_write_letter_against_show_cause_notice.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467411/; classtype:trojan-activity;sid:84330511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467412)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/bevakabopodo.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467412/; classtype:trojan-activity;sid:84330512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467416)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/55669141050.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467416/; classtype:trojan-activity;sid:84330516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467417)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fb13673c-7b10-403f-be9e-1b04622101d6/downloads/61656569082.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467417/; classtype:trojan-activity;sid:84330517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467418)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/98264302577.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467418/; classtype:trojan-activity;sid:84330518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467408)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/grammar_plus_class_8.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467408/; classtype:trojan-activity;sid:84330508; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467409)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/32575227287.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467409/; classtype:trojan-activity;sid:84330509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467410)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/xavibow.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467410/; classtype:trojan-activity;sid:84330510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467400)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b566d4a5-149a-4042-a2b5-fa837a998781/downloads/62246613540.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467400/; classtype:trojan-activity;sid:84330500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467401)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a5d43283-67be-4a3b-9041-1427b691166f/downloads/dotadaxokokimidupoz.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467401/; classtype:trojan-activity;sid:84330501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467403)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a19a3dcf-f832-45fe-91ff-ed566d492286/downloads/31803450103.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467403/; classtype:trojan-activity;sid:84330503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467404)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/26449761459.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467404/; classtype:trojan-activity;sid:84330504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467395)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/manual_de_uso_cummins_insite.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467395/; classtype:trojan-activity;sid:84330495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467397)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/83127272265.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467397/; classtype:trojan-activity;sid:84330497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467389)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/50013116393.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467389/; classtype:trojan-activity;sid:84330489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467391)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/sowuluxoranevoxivobu.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467391/; classtype:trojan-activity;sid:84330491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467392)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/jw_public_talk_outlines.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467392/; classtype:trojan-activity;sid:84330492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467386)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/muxem.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467386/; classtype:trojan-activity;sid:84330486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467381)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aa930190-2e12-4ce7-8bd7-0454f2ef6721/downloads/remonstration_visum_ablehnung_muster.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467381/; classtype:trojan-activity;sid:84330481; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467382)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1cd14ca4-3aaa-4349-a92b-5919cb2c71ee/downloads/37493963429.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467382/; classtype:trojan-activity;sid:84330482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467383)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/26417869572.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467383/; classtype:trojan-activity;sid:84330483; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467384)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zutufukatozoxogunubikok.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467384/; classtype:trojan-activity;sid:84330484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467385)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/vawazu.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467385/; classtype:trojan-activity;sid:84330485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467370)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c4240411-5b76-4ebe-95b9-c00242399cf6/downloads/libevisuxalozusofaze.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467370/; classtype:trojan-activity;sid:84330470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467371)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d07e2353-3643-42fe-ba11-ffa772b1a28d/downloads/61695596025.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467371/; classtype:trojan-activity;sid:84330471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467372)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/remebemakuvomurixulat.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467372/; classtype:trojan-activity;sid:84330472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467377)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/35713869772.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467377/; classtype:trojan-activity;sid:84330477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467363)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/popezefere.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467363/; classtype:trojan-activity;sid:84330463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467365)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/57373027197.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467365/; classtype:trojan-activity;sid:84330465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467367)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1e00f0b9-c207-4cb1-9a9a-c11d057e31a3/downloads/request_letter_for_hold_amount_release.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467367/; classtype:trojan-activity;sid:84330467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467369)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9569c183-65dc-4f14-a45e-e7944584cb65/downloads/58650400832.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467369/; classtype:trojan-activity;sid:84330469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467358)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0684881f-11f6-455b-9188-fb070acdb368/downloads/you_too_can_be_prosperous.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467358/; classtype:trojan-activity;sid:84330458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467359)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e51c42a2-48a1-43ea-b124-a034de3679a6/downloads/sizusobimemitu.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467359/; classtype:trojan-activity;sid:84330459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467360)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/fosodevo.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467360/; classtype:trojan-activity;sid:84330460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467353)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/her_yonuyle_modern_almanca_dursun_zengin.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467353/; classtype:trojan-activity;sid:84330453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467354)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/towedokunorazageleside.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467354/; classtype:trojan-activity;sid:84330454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467355)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/65604431763.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467355/; classtype:trojan-activity;sid:84330455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467357)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/ruwuxa.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467357/; classtype:trojan-activity;sid:84330457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467347)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c725aa89-ce3b-4b0b-861e-e7c40702153d/downloads/sulupob.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467347/; classtype:trojan-activity;sid:84330447; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467348)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0a2e88a7-385b-4aed-a81e-123c037cba5d/downloads/57067255053.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467348/; classtype:trojan-activity;sid:84330448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467350)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2ad58263-1b5c-4da7-bc4a-7b8f99e22218/downloads/2544897802.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467350/; classtype:trojan-activity;sid:84330450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467352)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/66812037618.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467352/; classtype:trojan-activity;sid:84330452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467344)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b4da0e1a-7caf-4ed8-aaa9-0949952990f3/downloads/49347806429.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467344/; classtype:trojan-activity;sid:84330444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467339)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7399f648-106b-4174-b8c0-6d6694895ad3/downloads/vakoxumem.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467339/; classtype:trojan-activity;sid:84330439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467340)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/gununemedusotojipime.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467340/; classtype:trojan-activity;sid:84330440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467334)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/92c7bb30-769c-4722-92cc-8b01b59910e0/downloads/36512394005.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467334/; classtype:trojan-activity;sid:84330434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467337)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7592d1e2-3dca-48f2-9f42-bb08c23dfb67/downloads/zutav.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467337/; classtype:trojan-activity;sid:84330437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467326)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8f97cb07-1cfa-4fca-b6d8-3f1bf47f56b3/downloads/dulerugufep.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467326/; classtype:trojan-activity;sid:84330426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467328)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/nopurumonufulelu.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467328/; classtype:trojan-activity;sid:84330428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467329)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2b44aaa8-926a-4cbd-9774-e30385fa65ac/downloads/zexesotusipedelew.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467329/; classtype:trojan-activity;sid:84330429; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467321)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/security_daily_activity_report_template.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467321/; classtype:trojan-activity;sid:84330421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467312)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a3d7189d-efc6-47e1-bbe5-dc5eeaf610a0/downloads/rtca_do-160g.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467312/; classtype:trojan-activity;sid:84330412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467313)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ac66f4da-754b-4df9-b080-4728fb201349/downloads/nimoma.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467313/; classtype:trojan-activity;sid:84330413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467314)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c877865a-29ce-446f-b8f8-42c8a2318eff/downloads/personal_loan_closure_letter_format_in_word.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467314/; classtype:trojan-activity;sid:84330414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467317)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/11677680583.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467317/; classtype:trojan-activity;sid:84330417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467318)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/elkonin_boxes_word_list.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467318/; classtype:trojan-activity;sid:84330418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467320)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f4482b02-adbc-4511-a01d-8f5a32444a75/downloads/zudelejanegine.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467320/; classtype:trojan-activity;sid:84330420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467307)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c3d6560-d229-4015-8af2-a70ad89bde0a/downloads/80071621679.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467307/; classtype:trojan-activity;sid:84330407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467305)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lapeke.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467305/; classtype:trojan-activity;sid:84330405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467303)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/kapabemirowajuzaxadirokef.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467303/; classtype:trojan-activity;sid:84330403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467304)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/modexad.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467304/; classtype:trojan-activity;sid:84330404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467298)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0bdc9896-149c-4815-8e37-9e55432c4120/downloads/bofugesugipufibutunida.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467298/; classtype:trojan-activity;sid:84330398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467300)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9c30937d-c8da-4e7b-9f7a-432344b46400/downloads/xuguxupevubitutuzoju.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467300/; classtype:trojan-activity;sid:84330400; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467301)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/rubejemi.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467301/; classtype:trojan-activity;sid:84330401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467286)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/atividades_de_concordancia_verbal_5o_ano_com_gabarito.pdf"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467286/; classtype:trojan-activity;sid:84330386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467287)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/78c14b69-39ed-4d94-8d63-a7b29776e43c/downloads/45524925955.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467287/; classtype:trojan-activity;sid:84330387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467292)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/cyberark_psmp_admin_guide.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467292/; classtype:trojan-activity;sid:84330392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467295)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/kitab_shams_al_maarif.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467295/; classtype:trojan-activity;sid:84330395; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467283)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3298be68-ecf2-4e6e-8fa7-1bf1d7657489/downloads/xagoje.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467283/; classtype:trojan-activity;sid:84330383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467279)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/83df8ca9-16c2-4244-8f9e-8be918c4b8a3/downloads/86611585002.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467279/; classtype:trojan-activity;sid:84330379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467280)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/41138401642.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467280/; classtype:trojan-activity;sid:84330380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467281)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/hepatorenales_syndrom.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467281/; classtype:trojan-activity;sid:84330381; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467271)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fae029f6-27b1-4578-94bc-ae0bbaeebde4/downloads/53744052149.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467271/; classtype:trojan-activity;sid:84330371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467274)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9927c1c5-c61c-4f5e-807e-67bd1833b3e4/downloads/nijalox.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467274/; classtype:trojan-activity;sid:84330374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467275)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/how_to_change_font_size_in_xchange_editor.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467275/; classtype:trojan-activity;sid:84330375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467277)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/limitorque_mx_ordering_guide.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467277/; classtype:trojan-activity;sid:84330377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467266)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/timex_expedition_indiglo_wr50m_manual.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467266/; classtype:trojan-activity;sid:84330366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467269)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7a3b63b5-3e6a-48ac-8e49-14ed0037cbc4/downloads/hitachi_cd_sem_operation_manual.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467269/; classtype:trojan-activity;sid:84330369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467264)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/87483152555.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467264/; classtype:trojan-activity;sid:84330364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467259)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/36672004653.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467259/; classtype:trojan-activity;sid:84330359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467260)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9dc6fd8e-b629-406d-be34-231dfc94d5e9/downloads/catia_v5_simulation_tutorial.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467260/; classtype:trojan-activity;sid:84330360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467262)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/80e9e7c7-d97b-4b5a-96c4-9a83854a3065/downloads/vuzabovamipavowaseke.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467262/; classtype:trojan-activity;sid:84330362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467254)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/09077edc-9c07-4d95-9708-b2f62b12ca6a/downloads/jikiluwuruwewomurenix.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467254/; classtype:trojan-activity;sid:84330354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467258)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/weguma.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467258/; classtype:trojan-activity;sid:84330358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467246)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/119d5b03-e78f-4725-87b7-ed496b267f6d/downloads/attributes_of_a_good_research_topic_ppt.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467246/; classtype:trojan-activity;sid:84330346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467249)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1663535d-289f-4a17-902d-0bb53881ce69/downloads/kurupojofuxerixutalo.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467249/; classtype:trojan-activity;sid:84330349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467250)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/mizibatazikitawejubidodog.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467250/; classtype:trojan-activity;sid:84330350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467251)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/gibabasakofalulizuwa.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467251/; classtype:trojan-activity;sid:84330351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467240)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/meravinuvisudome.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467240/; classtype:trojan-activity;sid:84330340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467241)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/64114a94-94a3-4f5d-866a-beee254b955f/downloads/70815730326.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467241/; classtype:trojan-activity;sid:84330341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467235)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/86649529175.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467235/; classtype:trojan-activity;sid:84330335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467236)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/nims_703_b_answers.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467236/; classtype:trojan-activity;sid:84330336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467237)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cf660a09-f805-468d-bb57-fa3593615f41/downloads/tojanigawexulametuzuk.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467237/; classtype:trojan-activity;sid:84330337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467230)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bc2ad79b-5832-4a2d-a335-92537db54849/downloads/pinestars_choice.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467230/; classtype:trojan-activity;sid:84330330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467231)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/vupegazezo.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467231/; classtype:trojan-activity;sid:84330331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467221)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/18985117210.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467221/; classtype:trojan-activity;sid:84330321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467223)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/03167ecf-a61c-49ea-b541-7a074a81e1da/downloads/6655537579.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467223/; classtype:trojan-activity;sid:84330323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467225)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/41957679215.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467225/; classtype:trojan-activity;sid:84330325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467226)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/exemple_de_livret_2_vae_rempli.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467226/; classtype:trojan-activity;sid:84330326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467228)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f569f34e-b7af-41eb-9a21-0f9939c54b3f/downloads/64195657437.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467228/; classtype:trojan-activity;sid:84330328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467220)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/aspen_pims_manual.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467220/; classtype:trojan-activity;sid:84330320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467219)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/fivojudu.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467219/; classtype:trojan-activity;sid:84330319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467210)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/20019605198.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467210/; classtype:trojan-activity;sid:84330310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467212)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/45706940387.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467212/; classtype:trojan-activity;sid:84330312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467213)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/xajuxe.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467213/; classtype:trojan-activity;sid:84330313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467214)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/81f7a7ad-d4fe-4147-943f-584c2d1e9bf5/downloads/because_of_mr_terupt_online.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467214/; classtype:trojan-activity;sid:84330314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467215)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/fajupip.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467215/; classtype:trojan-activity;sid:84330315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467205)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/minetest_wiki_commands.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467205/; classtype:trojan-activity;sid:84330305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467206)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/ohanian_physics_volume_1.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467206/; classtype:trojan-activity;sid:84330306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467207)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1c97d706-1093-417b-afec-0c60fc1d8547/downloads/74906999263.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467207/; classtype:trojan-activity;sid:84330307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467208)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/900d123a-2557-4fa9-92f6-1446b602b979/downloads/deporiramuga.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467208/; classtype:trojan-activity;sid:84330308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467209)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/traffic_light_risk_assessment_template_mental_health.pdf"; http_uri; depth:114; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467209/; classtype:trojan-activity;sid:84330309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467202)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/suritotowid.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467202/; classtype:trojan-activity;sid:84330302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467196)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/41821413009.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467196/; classtype:trojan-activity;sid:84330296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467200)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/804274b4-5f10-4c26-9de6-df56f38aac7c/downloads/14312384720.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467200/; classtype:trojan-activity;sid:84330300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467187)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/37654458598.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467187/; classtype:trojan-activity;sid:84330287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467188)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/23776368177.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467188/; classtype:trojan-activity;sid:84330288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467190)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/eb8ff9f7-37bb-4420-bfa0-f018b38dcfa6/downloads/17065535031.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467190/; classtype:trojan-activity;sid:84330290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467191)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/432a6cf0-f63b-4132-8b03-52615cd2c1c3/downloads/41591669011.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467191/; classtype:trojan-activity;sid:84330291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467193)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/2634956565.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467193/; classtype:trojan-activity;sid:84330293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467177)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/437a989b-0a84-4105-b8c7-1870eb56af29/downloads/sbi_disbursement_request_form.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467177/; classtype:trojan-activity;sid:84330277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467180)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/27f26436-44ad-4647-8929-a76a4ea0ea67/downloads/sample_query_letter_for_negligence_of_duty.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467180/; classtype:trojan-activity;sid:84330280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467181)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/sapebufuj.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467181/; classtype:trojan-activity;sid:84330281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467184)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4365da4a-8d29-4708-8e67-b3b566794d83/downloads/fovizijazobupukototofosop.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467184/; classtype:trojan-activity;sid:84330284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467186)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/93759555539.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467186/; classtype:trojan-activity;sid:84330286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467175)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/ligitove.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467175/; classtype:trojan-activity;sid:84330275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467176)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/62404701972.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467176/; classtype:trojan-activity;sid:84330276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467171)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/069f5eef-b21d-41b6-aaa6-569b53af1c5a/downloads/rawidesukusutalunug.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467171/; classtype:trojan-activity;sid:84330271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467172)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d102a54e-7197-4308-a937-d70c58240642/downloads/26442784020.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467172/; classtype:trojan-activity;sid:84330272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467167)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/83882971503.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467167/; classtype:trojan-activity;sid:84330267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467168)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/modelo_carta_entrega_de_inmueble_word.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467168/; classtype:trojan-activity;sid:84330268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467163)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/61905f2a-55dd-4144-8c7c-fce5e91063a8/downloads/british_army_all_arms_tactical_aide_memoire.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467163/; classtype:trojan-activity;sid:84330263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467166)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/rakotojifodonosanilorefa.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467166/; classtype:trojan-activity;sid:84330266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467157)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1ec2f808-78a9-4c99-aa80-be96e23bf450/downloads/gewikunobapizati.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467157/; classtype:trojan-activity;sid:84330257; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467158)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7dda8154-e680-4c60-8651-19cf13768d49/downloads/jadol.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467158/; classtype:trojan-activity;sid:84330258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467154)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/nojivurajojirezizi.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467154/; classtype:trojan-activity;sid:84330254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467156)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98571e96-4bd9-4ee2-bb76-481ac550907e/downloads/genebugutisevijuk.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467156/; classtype:trojan-activity;sid:84330256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467148)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/jiwekonuwokesarejibezan.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467148/; classtype:trojan-activity;sid:84330248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467149)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/159e5f7b-5078-45c9-9b36-63f21684101f/downloads/94962104148.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467149/; classtype:trojan-activity;sid:84330249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467150)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9483bc30-bb1c-4c04-9cf3-38d205924dab/downloads/jugilususosu.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467150/; classtype:trojan-activity;sid:84330250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467151)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/virapajoridubibakoxofa.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467151/; classtype:trojan-activity;sid:84330251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467152)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/319984769.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467152/; classtype:trojan-activity;sid:84330252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467142)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/makusikarubikowaxosop.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467142/; classtype:trojan-activity;sid:84330242; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467143)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/gikuxuze.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467143/; classtype:trojan-activity;sid:84330243; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467146)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/voxuba.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467146/; classtype:trojan-activity;sid:84330246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467147)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/wokaselu.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467147/; classtype:trojan-activity;sid:84330247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467135)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/963d457e-5dea-4a7e-aae8-47aada2a7cc0/downloads/velafeke.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467135/; classtype:trojan-activity;sid:84330235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467137)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/97fcff61-ad1b-4591-bfda-ed7d6d6690f0/downloads/49593663309.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467137/; classtype:trojan-activity;sid:84330237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467138)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5e489076-b026-43ca-95da-8c6fe49f6d00/downloads/49103789197.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467138/; classtype:trojan-activity;sid:84330238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467132)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/zafekupegagasaza.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467132/; classtype:trojan-activity;sid:84330232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467133)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/55585429936.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467133/; classtype:trojan-activity;sid:84330233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467125)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/siwevewedelo.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467125/; classtype:trojan-activity;sid:84330225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467126)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/fedex_air_waybill_form.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467126/; classtype:trojan-activity;sid:84330226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467127)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d567d1b9-5a9f-4b97-a387-65a7c02f8ff4/downloads/barapinawowaja.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467127/; classtype:trojan-activity;sid:84330227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467114)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/44443741873.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467114/; classtype:trojan-activity;sid:84330214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467115)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/ravibopegaxipodek.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467115/; classtype:trojan-activity;sid:84330215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467116)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/haojue_chopper_road_150_manual.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467116/; classtype:trojan-activity;sid:84330216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467117)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/23c146af-6c5b-426f-944d-9bf55106e4d8/downloads/de_quien_es_hija_elisa_salinas.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467117/; classtype:trojan-activity;sid:84330217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467118)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rewekawejujawidubekafebur.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467118/; classtype:trojan-activity;sid:84330218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467121)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3425f1f9-2741-4cdd-9a85-f51cd8a77838/downloads/pyidaungsu_font_keyboard_layout.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467121/; classtype:trojan-activity;sid:84330221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467123)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/carte_du_voyage_d_ulysse.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467123/; classtype:trojan-activity;sid:84330223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467109)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9f11cc6f-a645-4f71-bee4-e3848f35abf2/downloads/livro_domain_driven_design_portugues.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467109/; classtype:trojan-activity;sid:84330209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467110)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kulefenev.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467110/; classtype:trojan-activity;sid:84330210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467111)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/lobola_letter_example.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467111/; classtype:trojan-activity;sid:84330211; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467108)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/acquisition_value_negative_in_area_01_aa617.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467108/; classtype:trojan-activity;sid:84330208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467101)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d8f5bd9b-2c75-4c1f-8d4d-84a7de1d3443/downloads/widavizuxorig.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467101/; classtype:trojan-activity;sid:84330201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467102)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/chris_mccandless_travel_route.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467102/; classtype:trojan-activity;sid:84330202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467103)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/17ef1a7d-be6f-43bc-ac3a-a9c4fb65005e/downloads/powejavatunepoxaj.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467103/; classtype:trojan-activity;sid:84330203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467106)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/937a3a5d-28a9-4a6d-983b-63f9d4fe1460/downloads/90328489234.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467106/; classtype:trojan-activity;sid:84330206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467098)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0319bbe-78e1-4446-90fc-2b4b4cc85a3e/downloads/wurowujezodabod.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467098/; classtype:trojan-activity;sid:84330198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467099)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pubobagawu.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467099/; classtype:trojan-activity;sid:84330199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467100)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/forest_fire_causes_and_effects.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467100/; classtype:trojan-activity;sid:84330200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467086)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6b07c7a9-24ea-41b4-835a-7daa4871c250/downloads/16_personality_factors_by_cattell.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467086/; classtype:trojan-activity;sid:84330186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467087)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/725aea16-586d-4b26-8216-cd50b4981a76/downloads/wiley_organic_chemistry_solutions_manual.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467087/; classtype:trojan-activity;sid:84330187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467088)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2224247e-29ce-4f8d-b838-abfcbdf269c0/downloads/psicoweb_respuestas_2019.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467088/; classtype:trojan-activity;sid:84330188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467091)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8e32f5a5-6a1a-4ade-b57e-fa54871724ef/downloads/2040244551.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467091/; classtype:trojan-activity;sid:84330191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467092)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/koxisiranarigavod.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467092/; classtype:trojan-activity;sid:84330192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467093)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59d4bc6c-1e33-45d9-a430-f89e52f3f795/downloads/subazituwa.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467093/; classtype:trojan-activity;sid:84330193; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467094)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b6f72d87-e560-495a-a5bd-684e976b53e4/downloads/lettre_promesse_dembauche.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467094/; classtype:trojan-activity;sid:84330194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467080)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/971e893d-d96e-4c35-b8d0-897850ea3ce6/downloads/ice_quarterly_development_report_example.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467080/; classtype:trojan-activity;sid:84330180; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467081)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/testigos_tablero_foton.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467081/; classtype:trojan-activity;sid:84330181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467082)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/how_to_get_gst_invoice_for_amazon_purchase.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467082/; classtype:trojan-activity;sid:84330182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467083)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8df58291-e0db-425a-9cda-a9882386ada6/downloads/24365322622.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467083/; classtype:trojan-activity;sid:84330183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467085)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4831e354-44dc-4759-9d14-0dd6cfda589f/downloads/91284214985.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467085/; classtype:trojan-activity;sid:84330185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467078)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c5dd25fc-7740-402b-aa70-862b15f3342c/downloads/8958005659.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467078/; classtype:trojan-activity;sid:84330178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467079)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/wewofolivofometu.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467079/; classtype:trojan-activity;sid:84330179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467072)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9e5b6b40-f934-4273-a65f-cbaee9aa4b00/downloads/9665669589.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467072/; classtype:trojan-activity;sid:84330172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467073)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/konibaxixim.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467073/; classtype:trojan-activity;sid:84330173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467074)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/20a6346a-1701-43f8-be7d-6426912a09c2/downloads/self_introduction_during_interview_example.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467074/; classtype:trojan-activity;sid:84330174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467075)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ff494cbe-9d2a-4ae4-802e-f50cfad48f0a/downloads/74334894285.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467075/; classtype:trojan-activity;sid:84330175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467077)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/55534301355.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467077/; classtype:trojan-activity;sid:84330177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467065)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/tevolutirasuvujivol.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467065/; classtype:trojan-activity;sid:84330165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467066)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3f5ecf8d-ba74-430f-ac11-9eb6ace92d02/downloads/73100246338.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467066/; classtype:trojan-activity;sid:84330166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467067)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b6f72d87-e560-495a-a5bd-684e976b53e4/downloads/earth_making_of_a_planet_national_geographic_worksheet.pdf"; http_uri; depth:116; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467067/; classtype:trojan-activity;sid:84330167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467068)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/exercice_vitesse_6eme_physique.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467068/; classtype:trojan-activity;sid:84330168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467069)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rapport_de_stage_3eme_agence_immobiliere.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467069/; classtype:trojan-activity;sid:84330169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467070)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/bisebinalujivefiwugagabu.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467070/; classtype:trojan-activity;sid:84330170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467064)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/miludafat.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467064/; classtype:trojan-activity;sid:84330164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467061)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ea6e6a77-ad86-47ad-bec1-a500695628d4/downloads/66906319004.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467061/; classtype:trojan-activity;sid:84330161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467062)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b77102f9-1066-4a92-8a14-af011902d081/downloads/75162502331.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467062/; classtype:trojan-activity;sid:84330162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467063)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/mapisirukuw.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467063/; classtype:trojan-activity;sid:84330163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467058)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/guzupuzuradadutov.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467058/; classtype:trojan-activity;sid:84330158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467059)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/081e0348-3bf0-4a3e-a723-749adc1aa630/downloads/teks_ratib_al_attas.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467059/; classtype:trojan-activity;sid:84330159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467060)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d07e2353-3643-42fe-ba11-ffa772b1a28d/downloads/49693757117.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467060/; classtype:trojan-activity;sid:84330160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467050)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/800cff82-04ba-4c47-9f8b-d21367acb04d/downloads/sabre_red_workspace_commands.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467050/; classtype:trojan-activity;sid:84330150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467051)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6702c9de-d943-4d22-b78e-7985c91f7713/downloads/84525111813.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467051/; classtype:trojan-activity;sid:84330151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467052)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/26bbb7e6-2f83-462e-b1a0-c9b7b5a50d38/downloads/training_needs_assessment_questionnaire_for_sales.pdf"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467052/; classtype:trojan-activity;sid:84330152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467053)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/najovozulubameto.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467053/; classtype:trojan-activity;sid:84330153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467054)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/225bb15f-2915-4639-a3a1-bcedb142b1ef/downloads/letter_format_for_reply_to_show_cause_notice.pdf"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467054/; classtype:trojan-activity;sid:84330154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467055)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c718f9e1-28ba-4c02-b434-4456f7af09a8/downloads/masizaz.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467055/; classtype:trojan-activity;sid:84330155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467049)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/51274200809.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467049/; classtype:trojan-activity;sid:84330149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467044)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/rolinejagogid.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467044/; classtype:trojan-activity;sid:84330144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467042)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/buxam.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467042/; classtype:trojan-activity;sid:84330142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467032)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6be9a470-c465-4776-ab76-53713c51537a/downloads/nokura.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467032/; classtype:trojan-activity;sid:84330132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467033)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/69da2f53-c229-4dc7-a889-7b67b52b1a78/downloads/nokejafowikazuvojoj.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467033/; classtype:trojan-activity;sid:84330133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467035)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e43067a0-6374-4a70-a00d-00ee3b01ce8d/downloads/93917384180.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467035/; classtype:trojan-activity;sid:84330135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467037)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0336533-680f-4ead-a55e-7e292796b70a/downloads/veteluruxoge.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467037/; classtype:trojan-activity;sid:84330137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467024)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/sirijega.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467024/; classtype:trojan-activity;sid:84330124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467025)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5c2804a6-aa9c-48a0-92fa-b4e2830d3e94/downloads/ladakh_tourist_map.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467025/; classtype:trojan-activity;sid:84330125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467027)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cc5e3c0a-70ce-48cf-a48d-87f83c6b3256/downloads/major_problems_in_african_american_history.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467027/; classtype:trojan-activity;sid:84330127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467029)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d38d43db-37ad-45ec-b237-63ac8c84a196/downloads/latovin.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467029/; classtype:trojan-activity;sid:84330129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467018)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c10f3982-2d8c-41ef-9c88-95b9c7e0984b/downloads/exagrid_admin_guide.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467018/; classtype:trojan-activity;sid:84330118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467019)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/2880955338.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467019/; classtype:trojan-activity;sid:84330119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467020)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9f4350e3-635b-45ba-b69f-b1a7e95f309e/downloads/24638138520.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467020/; classtype:trojan-activity;sid:84330120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467022)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/54349718441.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467022/; classtype:trojan-activity;sid:84330122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467023)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/satyanarayan_puja_vidhi_in_sanskrit.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467023/; classtype:trojan-activity;sid:84330123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467016)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/sample_letter_to_be_excused_from_jury_service.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467016/; classtype:trojan-activity;sid:84330116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467011)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cf660a09-f805-468d-bb57-fa3593615f41/downloads/vumemaxexepemetesa.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467011/; classtype:trojan-activity;sid:84330111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467012)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/93a7eb93-9eef-4244-8f20-7f48de1f8294/downloads/95493308607.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467012/; classtype:trojan-activity;sid:84330112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467013)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/91589198920.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467013/; classtype:trojan-activity;sid:84330113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467014)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/learn_korean_language_in_30_days.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467014/; classtype:trojan-activity;sid:84330114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467015)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/right_to_information_act_application_form_malayalam.pdf"; http_uri; depth:113; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467015/; classtype:trojan-activity;sid:84330115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467006)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zesowafasunufezef.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467006/; classtype:trojan-activity;sid:84330106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467008)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8e46fb0c-8d21-4b8c-82fc-88315c96ddde/downloads/bevurusip.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467008/; classtype:trojan-activity;sid:84330108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467002)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/09d72da9-ee58-43de-9ce0-8696fa874a10/downloads/zanozibiwakixubunifelok.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467002/; classtype:trojan-activity;sid:84330102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467003)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5d8bfe2e-b91e-431f-9bdc-3f0ea97e388e/downloads/hbc_radiomatic_fse_727_manual.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467003/; classtype:trojan-activity;sid:84330103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466999)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e4335d81-d2e5-4638-9638-30640b1be91f/downloads/sofipidegib.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466999/; classtype:trojan-activity;sid:84330099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3467000)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/54040f30-acd4-4a4c-a314-5c4c261b537d/downloads/printable_foods_high_in_uric_acid_chart.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3467000/; classtype:trojan-activity;sid:84330100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466992)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/15318963311.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466992/; classtype:trojan-activity;sid:84330092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466993)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c0f7f4ed-2d7c-4134-aa94-503b1eb6600b/downloads/pagulabomezex.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466993/; classtype:trojan-activity;sid:84330093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466996)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/katisugenifikipevas.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466996/; classtype:trojan-activity;sid:84330096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466997)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/xowawetavudazinomo.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466997/; classtype:trojan-activity;sid:84330097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466985)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7662afb9-5d02-4eb9-bd3b-6426a66215ee/downloads/2312138967.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466985/; classtype:trojan-activity;sid:84330085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466986)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/evaluation_geographie_6eme_habiter_une_metropole.pdf"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466986/; classtype:trojan-activity;sid:84330086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466987)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9441f8ad-6e79-4d4a-9602-3585b1269b7e/downloads/kobumedigudopixemevuwef.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466987/; classtype:trojan-activity;sid:84330087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466989)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8fc62093-f93e-447d-8e21-b1e235f4d9cc/downloads/vadigoxevujo.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466989/; classtype:trojan-activity;sid:84330089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466991)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/64414313920.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466991/; classtype:trojan-activity;sid:84330091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466979)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/mizoxuloniwi.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466979/; classtype:trojan-activity;sid:84330079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466984)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/66244318284.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466984/; classtype:trojan-activity;sid:84330084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466971)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6cdacb6d-7fbf-4d09-a986-56cdfa4edeb2/downloads/15247939327.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466971/; classtype:trojan-activity;sid:84330071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466972)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/example_of_a_lobola_letter_in_zulu.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466972/; classtype:trojan-activity;sid:84330072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466973)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ea25ddad-ebb0-4880-b714-a3f2cdadcbd9/downloads/notas_de_dinheiro_para_imprimir.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466973/; classtype:trojan-activity;sid:84330073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466975)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/606585da-2917-4da6-a9df-810ae6e7fbc1/downloads/asme_sec_8_div_1_appendix_8.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466975/; classtype:trojan-activity;sid:84330075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466976)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/segaxifalawanevake.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466976/; classtype:trojan-activity;sid:84330076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466968)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/3d_converter_for_autodesk_navisworks.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466968/; classtype:trojan-activity;sid:84330068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466969)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2c827e54-9a2c-449a-9d97-e20f9555c87a/downloads/pearson_iit_foundation_class_9_maths.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466969/; classtype:trojan-activity;sid:84330069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466970)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3d2c6212-591e-450b-b673-947709e569a9/downloads/jidikegegudafipi.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466970/; classtype:trojan-activity;sid:84330070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466966)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62bebe3a-24c2-4a56-9b26-65d7a4a8233d/downloads/gupira.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466966/; classtype:trojan-activity;sid:84330066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466958)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/79599984772.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466958/; classtype:trojan-activity;sid:84330058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466957)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/actaris_meter_manual.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466957/; classtype:trojan-activity;sid:84330057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466946)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/passaic_county_technical_institute_salary_guide.pdf"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466946/; classtype:trojan-activity;sid:84330046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466950)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0c2227e9-a807-4022-9307-9c68c8629142/downloads/59021495355.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466950/; classtype:trojan-activity;sid:84330050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466951)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3abea8f6-1776-4586-b4e6-47b414d29e30/downloads/mozosadoboligemuwisuwet.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466951/; classtype:trojan-activity;sid:84330051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466952)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/malaysia_company_employee_handbook.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466952/; classtype:trojan-activity;sid:84330052; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466937)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/988c0021-e131-496b-8725-ae310052894b/downloads/berakigevep.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466937/; classtype:trojan-activity;sid:84330037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466938)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c0325f5e-ab4f-48af-8631-8757a310624e/downloads/87631223928.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466938/; classtype:trojan-activity;sid:84330038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466941)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/majisumilorenanevivo.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466941/; classtype:trojan-activity;sid:84330041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466944)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/risukepidupapa.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466944/; classtype:trojan-activity;sid:84330044; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466933)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c272bee0-a4e4-45f4-a8ce-0b066973e0cb/downloads/gateman_wk_20_english_manual.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466933/; classtype:trojan-activity;sid:84330033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466934)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/koxid.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466934/; classtype:trojan-activity;sid:84330034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466935)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/sasufazovosonufowam.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466935/; classtype:trojan-activity;sid:84330035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466929)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/6554737977.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466929/; classtype:trojan-activity;sid:84330029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466931)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4b7c63a1-8c4d-413e-83dc-2db6954011c6/downloads/42942412664.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466931/; classtype:trojan-activity;sid:84330031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466928)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/43589756342.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466928/; classtype:trojan-activity;sid:84330028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466923)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/juporuko.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466923/; classtype:trojan-activity;sid:84330023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466924)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1d231bc1-15b8-4d3d-b451-c05909392126/downloads/71014366481.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466924/; classtype:trojan-activity;sid:84330024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466920)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/29389545569.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466920/; classtype:trojan-activity;sid:84330020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466915)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fbb7d95c-19ce-4e6b-832c-1ccce7746b31/downloads/jebagokapinezax.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466915/; classtype:trojan-activity;sid:84330015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466916)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cb46680e-64d4-4308-8a44-9926381d0750/downloads/85747587751.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466916/; classtype:trojan-activity;sid:84330016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466919)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/ending_a_lease_letter_to_landlord.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466919/; classtype:trojan-activity;sid:84330019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466909)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/possession_letter_format_from_builder.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466909/; classtype:trojan-activity;sid:84330009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466910)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/mopuma.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466910/; classtype:trojan-activity;sid:84330010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466911)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a618ca0f-2608-47c2-ab22-bbc2ca127bb7/downloads/saziva.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466911/; classtype:trojan-activity;sid:84330011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466912)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/229e00b6-6232-4273-bd27-55f919ca28b8/downloads/financas_corporativas_teoria_e_pratica.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466912/; classtype:trojan-activity;sid:84330012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466913)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/76c40511-888a-4b14-bb65-87429974a9ff/downloads/gemotukuwitawusagulobez.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466913/; classtype:trojan-activity;sid:84330013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466903)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/vupenamubow.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466903/; classtype:trojan-activity;sid:84330003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466904)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/10269055308.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466904/; classtype:trojan-activity;sid:84330004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466905)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6ab86f22-a419-4e4f-91d4-5a654823f744/downloads/21711123451.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466905/; classtype:trojan-activity;sid:84330005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466900)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9e5b6b40-f934-4273-a65f-cbaee9aa4b00/downloads/14203617612.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466900/; classtype:trojan-activity;sid:84330000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466902)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e4ad6e04-69d1-4aa9-ba9f-c194e0ac5eef/downloads/lotavawofasopupe.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466902/; classtype:trojan-activity;sid:84330002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466898)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/mental_state_examination_checklist.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466898/; classtype:trojan-activity;sid:84329998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466893)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e5728c18-e5b3-4c69-bf59-a4be42aea8ac/downloads/22515332125.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466893/; classtype:trojan-activity;sid:84329993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466894)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/metso_neles_positioner_manual.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466894/; classtype:trojan-activity;sid:84329994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466895)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/9840498620.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466895/; classtype:trojan-activity;sid:84329995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466897)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3fffd8a4-4d1d-42f8-a3e8-f124f6724c06/downloads/kejawisenukasi.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466897/; classtype:trojan-activity;sid:84329997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466885)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/72065953692.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466885/; classtype:trojan-activity;sid:84329985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466890)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1ecb10a4-49e9-4fe5-a6bc-f0f227949dd2/downloads/60627448414.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466890/; classtype:trojan-activity;sid:84329990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466881)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/ramevedasap.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466881/; classtype:trojan-activity;sid:84329981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466882)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fbb7d95c-19ce-4e6b-832c-1ccce7746b31/downloads/67882203250.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466882/; classtype:trojan-activity;sid:84329982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466877)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/df312c7d-f650-4c0e-a98f-02aee1a43694/downloads/77125885812.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466877/; classtype:trojan-activity;sid:84329977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466864)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a37e9011-77af-43eb-9e7b-dd6853450512/downloads/27721436213.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466864/; classtype:trojan-activity;sid:84329964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466866)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6abf7f7e-d12c-48f3-aa9a-703f4ccff8d7/downloads/81403469667.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466866/; classtype:trojan-activity;sid:84329966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466869)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zikirifusotuxusomel.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466869/; classtype:trojan-activity;sid:84329969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466870)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/antibiotic_sensitivity_chart_sanford_guide.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466870/; classtype:trojan-activity;sid:84329970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466872)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9c8a6489-894f-4446-8722-19ef31b6a173/downloads/26803015720.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466872/; classtype:trojan-activity;sid:84329972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466873)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4d2b55bf-cda3-4071-bf2e-8c27282b789f/downloads/chambre_de_tirage_telecom.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466873/; classtype:trojan-activity;sid:84329973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466875)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/48283c5b-b198-4860-9bf9-7f30a2f8146b/downloads/10387443769.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466875/; classtype:trojan-activity;sid:84329975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466876)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/zasuporuxumuza.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466876/; classtype:trojan-activity;sid:84329976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466861)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3d0a6e54-c95b-4e67-871e-882f39f9c203/downloads/77235011630.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466861/; classtype:trojan-activity;sid:84329961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466863)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/luvuges.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466863/; classtype:trojan-activity;sid:84329963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466858)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tovidesukowoxam.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466858/; classtype:trojan-activity;sid:84329958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466859)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a5a93100-d349-4291-8bce-18547efeb268/downloads/14773335318.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466859/; classtype:trojan-activity;sid:84329959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466845)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62bebe3a-24c2-4a56-9b26-65d7a4a8233d/downloads/xijawef.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466845/; classtype:trojan-activity;sid:84329945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466846)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a6301bc9-fbf1-4861-936b-8ce401d46d09/downloads/non_renewal_of_contract_letter_sample.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466846/; classtype:trojan-activity;sid:84329946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466847)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98fd26ea-5c50-4ebf-945e-7ed158ebe1b6/downloads/75925905792.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466847/; classtype:trojan-activity;sid:84329947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466848)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/561eb1da-cbac-4811-84b8-e841d63e56cb/downloads/fomogivazugararux.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466848/; classtype:trojan-activity;sid:84329948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466849)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3ccd9234-721c-480b-91a1-84bae34c2069/downloads/votudomafuze.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466849/; classtype:trojan-activity;sid:84329949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466851)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ed3e7e73-6deb-4ec1-95e4-868a6659fe93/downloads/manning_guide_hotel_sample.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466851/; classtype:trojan-activity;sid:84329951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466852)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/45596981954.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466852/; classtype:trojan-activity;sid:84329952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466853)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/tilovapexof.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466853/; classtype:trojan-activity;sid:84329953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466838)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/najufijirubedejalu.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466838/; classtype:trojan-activity;sid:84329938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466839)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/ludejawirusoxodofe.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466839/; classtype:trojan-activity;sid:84329939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466843)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/4959938645.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466843/; classtype:trojan-activity;sid:84329943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466832)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/52e9408f-c536-4a35-bd81-6078a5dce549/downloads/98085965001.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466832/; classtype:trojan-activity;sid:84329932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466833)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/dasuxugolod.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466833/; classtype:trojan-activity;sid:84329933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466827)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/804274b4-5f10-4c26-9de6-df56f38aac7c/downloads/attestation_de_non_affiliation_cnas_algerie.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466827/; classtype:trojan-activity;sid:84329927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466828)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/72502959-bd3f-431c-9582-055fb0eb9e9d/downloads/vw_gehaltstabelle_2022.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466828/; classtype:trojan-activity;sid:84329928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466830)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nidugapageru.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466830/; classtype:trojan-activity;sid:84329930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466831)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f6f33080-7dde-4e51-88ef-59c9fd931fca/downloads/latoletevuwogerovug.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466831/; classtype:trojan-activity;sid:84329931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466818)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/40119004199.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466818/; classtype:trojan-activity;sid:84329918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466822)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d128fcda-7fcc-4d89-85b3-e79c54d4414e/downloads/talivejo.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466822/; classtype:trojan-activity;sid:84329922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466824)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/ansul_piranha_system_installation_manual.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466824/; classtype:trojan-activity;sid:84329924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466813)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/scada_system_architecture.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466813/; classtype:trojan-activity;sid:84329913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466814)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/63541235931.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466814/; classtype:trojan-activity;sid:84329914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466802)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/gaylord_texan_hotel_map.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466802/; classtype:trojan-activity;sid:84329902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466803)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/laxokuzigurebudisinatonu.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466803/; classtype:trojan-activity;sid:84329903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466805)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/09d72da9-ee58-43de-9ce0-8696fa874a10/downloads/kojutaz.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466805/; classtype:trojan-activity;sid:84329905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466808)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/civil_engineer_experience_certificate_word_format.pdf"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466808/; classtype:trojan-activity;sid:84329908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466799)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/55d28ff0-9d0b-42b4-8190-887f90038148/downloads/gimisomogaro.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466799/; classtype:trojan-activity;sid:84329899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466800)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/950f7924-fa6b-44be-bda3-22eaf526f43f/downloads/how_to_write_a_letter_to_society_for_car_parking.pdf"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466800/; classtype:trojan-activity;sid:84329900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466801)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/78dac1c1-e6f9-4066-ad39-7cbcdc39e651/downloads/93448099882.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466801/; classtype:trojan-activity;sid:84329901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466794)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/payment_under_protest_letter_sample.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466794/; classtype:trojan-activity;sid:84329894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466797)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/43447829480.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466797/; classtype:trojan-activity;sid:84329897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466798)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/97374790135.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466798/; classtype:trojan-activity;sid:84329898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466788)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/71423402684.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466788/; classtype:trojan-activity;sid:84329888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466790)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5c9ed0ab-abf7-4895-9a79-d81e87aed60a/downloads/nezumizegorazulamalit.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466790/; classtype:trojan-activity;sid:84329890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466791)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a4c519f1-5301-485e-9e9c-56d1397df289/downloads/79371210580.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466791/; classtype:trojan-activity;sid:84329891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466792)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kekososiwixokaz.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466792/; classtype:trojan-activity;sid:84329892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466778)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/14889765830.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466778/; classtype:trojan-activity;sid:84329878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466779)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rikisiwudepelapopazi.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466779/; classtype:trojan-activity;sid:84329879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466781)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/boriwivamafegujiser.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466781/; classtype:trojan-activity;sid:84329881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466782)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/seaworld_donation_request_orlando.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466782/; classtype:trojan-activity;sid:84329882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466786)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/schumacher_battery_charger_parts_se-4022.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466786/; classtype:trojan-activity;sid:84329886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466787)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d83328cf-50de-409a-9bf6-de7a48f66ed6/downloads/40650293844.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466787/; classtype:trojan-activity;sid:84329887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466777)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/ap_cm_relief_fund_application_process.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466777/; classtype:trojan-activity;sid:84329877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466768)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/narigokukeminozitema.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466768/; classtype:trojan-activity;sid:84329868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466770)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/32231114245.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466770/; classtype:trojan-activity;sid:84329870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466771)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fa0b65d5-8cfc-4875-922a-b490488b42be/downloads/schmersal_de-_42279_datasheet.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466771/; classtype:trojan-activity;sid:84329871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466772)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/checklist_format_for_housekeeping_in_hospital.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466772/; classtype:trojan-activity;sid:84329872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466773)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/91812224211.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466773/; classtype:trojan-activity;sid:84329873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466774)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/rizepigarebovubugebo.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466774/; classtype:trojan-activity;sid:84329874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466775)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/kawopixar.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466775/; classtype:trojan-activity;sid:84329875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466767)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/58311665155.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466767/; classtype:trojan-activity;sid:84329867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466763)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c0325f5e-ab4f-48af-8631-8757a310624e/downloads/93503353547.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466763/; classtype:trojan-activity;sid:84329863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466764)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6974f1eb-71bf-4f90-8572-d8ac4e4f765d/downloads/wazakovefonetak.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466764/; classtype:trojan-activity;sid:84329864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466758)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9978fe41-dbcb-4b88-8a80-a839de3f86b5/downloads/42576721881.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466758/; classtype:trojan-activity;sid:84329858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466759)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/73769466656.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466759/; classtype:trojan-activity;sid:84329859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466761)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/suvuraxelikubok.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466761/; classtype:trojan-activity;sid:84329861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466762)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3e09336e-0817-489c-96db-d43d5fd51fc4/downloads/i9_birth_certificate_example.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466762/; classtype:trojan-activity;sid:84329862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466750)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/stromer_st1_owners_manual.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466750/; classtype:trojan-activity;sid:84329850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466753)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/7215421885.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466753/; classtype:trojan-activity;sid:84329853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466754)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/37979647215.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466754/; classtype:trojan-activity;sid:84329854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466755)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/af0be9d0-b995-4f2a-8f66-25f04f50db42/downloads/tejovejujepotobafoba.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466755/; classtype:trojan-activity;sid:84329855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466756)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/43947647531.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466756/; classtype:trojan-activity;sid:84329856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466747)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/97640682614.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466747/; classtype:trojan-activity;sid:84329847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466748)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2ec5b631-127b-4a5e-84ff-7de19674a208/downloads/daxukipavibipukoj.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466748/; classtype:trojan-activity;sid:84329848; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466740)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/66a9f463-0ae0-4403-bef2-3061bb9e36ef/downloads/rate_list_of_test_in_dr.lal_pathlabs.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466740/; classtype:trojan-activity;sid:84329840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466742)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c8939508-8a93-4f90-8b11-ddca3342e83a/downloads/4803379677.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466742/; classtype:trojan-activity;sid:84329842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466745)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/taski_procarpet_45_manual.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466745/; classtype:trojan-activity;sid:84329845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466738)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/gomik.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466738/; classtype:trojan-activity;sid:84329838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466736)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ef27ce0e-c911-4d37-baad-bea065e796b8/downloads/kirekafusofo.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466736/; classtype:trojan-activity;sid:84329836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466732)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/wiremabodopigotaf.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466732/; classtype:trojan-activity;sid:84329832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466733)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/67856105857.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466733/; classtype:trojan-activity;sid:84329833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466734)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/af0be9d0-b995-4f2a-8f66-25f04f50db42/downloads/rubetugetafapojopodibom.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466734/; classtype:trojan-activity;sid:84329834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466724)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/3048437595.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466724/; classtype:trojan-activity;sid:84329824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466726)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cc370600-8080-4216-8e6c-52a7f34eeccf/downloads/iso_weld_symbols_chart.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466726/; classtype:trojan-activity;sid:84329826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466728)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/47b969d8-0664-43a5-a1cb-4ec8411e9eef/downloads/powerflex_755_user_manual_espanol.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466728/; classtype:trojan-activity;sid:84329828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466729)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7539d3e4-198a-4c91-addc-38e6066bfe55/downloads/2305786492.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466729/; classtype:trojan-activity;sid:84329829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466730)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/kangwon_land_inc_annual_report.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466730/; classtype:trojan-activity;sid:84329830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466731)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4c0bdcf4-6f9c-40c3-8219-8cbbbcfb4026/downloads/wanigukanewalew.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466731/; classtype:trojan-activity;sid:84329831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466715)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/watiwime.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466715/; classtype:trojan-activity;sid:84329815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466716)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/638993752.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466716/; classtype:trojan-activity;sid:84329816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466717)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/milagetuxinofu.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466717/; classtype:trojan-activity;sid:84329817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466719)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7eafcf9d-33bd-4fd4-8489-654d240ab2f3/downloads/51295545026.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466719/; classtype:trojan-activity;sid:84329819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466720)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/xezumiriruko.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466720/; classtype:trojan-activity;sid:84329820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466721)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/cleavage_front_row_amy_measurements.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466721/; classtype:trojan-activity;sid:84329821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466708)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/diamond_sieve_chart.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466708/; classtype:trojan-activity;sid:84329808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466710)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/09b152c4-bf66-44a7-8224-2992cea3ed0a/downloads/sample_indian_renunciation_form.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466710/; classtype:trojan-activity;sid:84329810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466711)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/pelebesepasirokirefukew.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466711/; classtype:trojan-activity;sid:84329811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466712)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/455fd801-8453-4cfe-b6ee-1af9e2a627f6/downloads/7558215776.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466712/; classtype:trojan-activity;sid:84329812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466713)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e262bb3c-3205-4bb6-954b-f565479d59e0/downloads/50787175728.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466713/; classtype:trojan-activity;sid:84329813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466706)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/rotem_sigma_user_manual.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466706/; classtype:trojan-activity;sid:84329806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466705)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/lista_de_verbos_em_italiano.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466705/; classtype:trojan-activity;sid:84329805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466702)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a580c741-29a0-435a-a011-6aa538a5edae/downloads/25870917787.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466702/; classtype:trojan-activity;sid:84329802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466694)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/siwetofulugo.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466694/; classtype:trojan-activity;sid:84329794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466695)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0739216d-b619-42bb-83b4-7432b4331862/downloads/26798739628.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466695/; classtype:trojan-activity;sid:84329795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466696)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/23513409250.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466696/; classtype:trojan-activity;sid:84329796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466697)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/the_long_dark_crumbling_highway_map.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466697/; classtype:trojan-activity;sid:84329797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466698)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2eabcd0a-1fbf-48aa-8399-71392232a891/downloads/92332863676.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466698/; classtype:trojan-activity;sid:84329798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466682)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4c633c3b-7c73-43a9-a161-0e7459f617b4/downloads/popajuzokovuluboz.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466682/; classtype:trojan-activity;sid:84329782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466684)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4b7c63a1-8c4d-413e-83dc-2db6954011c6/downloads/6759358871.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466684/; classtype:trojan-activity;sid:84329784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466686)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/41809607-5bd4-4a52-8a62-530dfb6fcdd7/downloads/gelumoxosudasikaxo.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466686/; classtype:trojan-activity;sid:84329786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466687)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cb46680e-64d4-4308-8a44-9926381d0750/downloads/47722224691.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466687/; classtype:trojan-activity;sid:84329787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466689)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/57326063662.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466689/; classtype:trojan-activity;sid:84329789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466690)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8aa13dbf-c0c5-4fe7-ae15-62e5c33a20e4/downloads/hewlett-packard_18e7_motherboard_specs.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466690/; classtype:trojan-activity;sid:84329790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466691)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/porebejotenojudud.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466691/; classtype:trojan-activity;sid:84329791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466681)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/72502959-bd3f-431c-9582-055fb0eb9e9d/downloads/duff_and_phelps_size_premium_2022.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466681/; classtype:trojan-activity;sid:84329781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466674)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pass_the_pigs_scoring_sheet.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466674/; classtype:trojan-activity;sid:84329774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466679)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6ae40ccb-f0fa-4b6b-bfcc-06032a30498c/downloads/logical_thinking_worksheets_for_kindergarten.pdf"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466679/; classtype:trojan-activity;sid:84329779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466670)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cb46680e-64d4-4308-8a44-9926381d0750/downloads/151743582.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466670/; classtype:trojan-activity;sid:84329770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466671)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/13792310994.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466671/; classtype:trojan-activity;sid:84329771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466666)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/cessna_172_instrument_panel_layout.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466666/; classtype:trojan-activity;sid:84329766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466667)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/24459864622.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466667/; classtype:trojan-activity;sid:84329767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466658)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4c0bdcf4-6f9c-40c3-8219-8cbbbcfb4026/downloads/10451479360.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466658/; classtype:trojan-activity;sid:84329758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466659)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/sap_fico_cutover_activities.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466659/; classtype:trojan-activity;sid:84329759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466662)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/98444125074.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466662/; classtype:trojan-activity;sid:84329762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466663)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/686c0a2e-9a90-4936-9f96-7d72f3c65f03/downloads/54960661120.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466663/; classtype:trojan-activity;sid:84329763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466664)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9c30937d-c8da-4e7b-9f7a-432344b46400/downloads/3262231356.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466664/; classtype:trojan-activity;sid:84329764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466648)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/livro_pesquisa_bibliografica.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466648/; classtype:trojan-activity;sid:84329748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466650)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/37ff6e83-e399-4f09-b7f3-13b9438039c2/downloads/54456550535.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466650/; classtype:trojan-activity;sid:84329750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466652)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/41780010-2245-4f59-96ea-abe2bb04704f/downloads/request_letter_format_in_marathi_language.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466652/; classtype:trojan-activity;sid:84329752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466645)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5809a244-7d90-46f4-9de4-ee86dda3a2de/downloads/evaluation_emc_6eme_devenir_collegien.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466645/; classtype:trojan-activity;sid:84329745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466640)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/dd809168-aa55-4437-9a0e-42447fbc16fd/downloads/22731947285.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466640/; classtype:trojan-activity;sid:84329740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466641)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/41780010-2245-4f59-96ea-abe2bb04704f/downloads/hypothecation_cancellation_request_letter_format.pdf"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466641/; classtype:trojan-activity;sid:84329741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466642)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/182ae1b8-0b64-4790-be7b-698d5e8b3d57/downloads/gidatigexapufalumiwolagad.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466642/; classtype:trojan-activity;sid:84329742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466634)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/aocs_official_method_ce_1b_89.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466634/; classtype:trojan-activity;sid:84329734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466635)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pigogini.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466635/; classtype:trojan-activity;sid:84329735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466639)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ab158387-fd14-4136-be83-18d2feafd209/downloads/regonadafufosofujerijasur.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466639/; classtype:trojan-activity;sid:84329739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466625)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/xewegemodigu.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466625/; classtype:trojan-activity;sid:84329725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466626)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f9b61407-e9a0-4bfb-ac42-6ba811f07eed/downloads/daycare_reference_letter_template.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466626/; classtype:trojan-activity;sid:84329726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466629)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/displayport_1.4_spec.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466629/; classtype:trojan-activity;sid:84329729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466632)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0a49e03e-1cf9-44ed-ac44-c378f90fa5f8/downloads/63521883486.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466632/; classtype:trojan-activity;sid:84329732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466633)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/262ea410-a887-458b-b5ec-65748ef01e57/downloads/75258476975.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466633/; classtype:trojan-activity;sid:84329733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466619)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9441f8ad-6e79-4d4a-9602-3585b1269b7e/downloads/dajagunowe.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466619/; classtype:trojan-activity;sid:84329719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466620)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/432a6cf0-f63b-4132-8b03-52615cd2c1c3/downloads/hypochondria_ielts_reading_answers.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466620/; classtype:trojan-activity;sid:84329720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466622)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/migolijidawononavez.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466622/; classtype:trojan-activity;sid:84329722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466623)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6286d8b4-6ffa-4d84-aeea-f2a9bc58a594/downloads/hotel_courtesy_call_template.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466623/; classtype:trojan-activity;sid:84329723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466617)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/48cf8ef6-fe89-47b6-9b8e-43119a3d3833/downloads/89759746182.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466617/; classtype:trojan-activity;sid:84329717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466613)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/poquito_mas_nutrition_facts.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466613/; classtype:trojan-activity;sid:84329713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466610)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9a32841c-0d54-4ad0-8acd-a5b15c41cae1/downloads/luxutevosevuke.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466610/; classtype:trojan-activity;sid:84329710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466611)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/vamiralu.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466611/; classtype:trojan-activity;sid:84329711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466605)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/bonunorovekofa.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466605/; classtype:trojan-activity;sid:84329705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466606)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/657a2269-1311-41bc-be7f-365fba299599/downloads/36407415595.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466606/; classtype:trojan-activity;sid:84329706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466607)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/82707682561.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466607/; classtype:trojan-activity;sid:84329707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466608)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a0620227-6f33-427f-8ac7-1fb80d24bd78/downloads/loxabafefomukewizirefa.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466608/; classtype:trojan-activity;sid:84329708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466609)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/metric_bolt_specification_chart.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466609/; classtype:trojan-activity;sid:84329709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466597)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b6875802-d83d-45fa-a01c-dd9f30c53739/downloads/22305465780.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466597/; classtype:trojan-activity;sid:84329697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466598)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/efeaa59e-2423-41d8-b482-9a37e80979c7/downloads/ge_disconnect_switch.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466598/; classtype:trojan-activity;sid:84329698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466600)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7518eff6-349e-4445-8380-e1c43aacea7b/downloads/gemudewefedevovep.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466600/; classtype:trojan-activity;sid:84329700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466601)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/41809607-5bd4-4a52-8a62-530dfb6fcdd7/downloads/tugojokuru.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466601/; classtype:trojan-activity;sid:84329701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466602)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/hadoop_notes_by_durgasoft_ramakrishna.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466602/; classtype:trojan-activity;sid:84329702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466603)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/compassionate_leave_letter_examples.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466603/; classtype:trojan-activity;sid:84329703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466604)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2294c0f6-d737-4b16-8fca-94076227dda5/downloads/garrison_carbon_monoxide_and_gas_detector_manual.pdf"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466604/; classtype:trojan-activity;sid:84329704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466593)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/kuradorug.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466593/; classtype:trojan-activity;sid:84329693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466594)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7eafcf9d-33bd-4fd4-8489-654d240ab2f3/downloads/38053692779.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466594/; classtype:trojan-activity;sid:84329694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466595)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c4240411-5b76-4ebe-95b9-c00242399cf6/downloads/26107131918.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466595/; classtype:trojan-activity;sid:84329695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466587)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tozivagal.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466587/; classtype:trojan-activity;sid:84329687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466591)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1b026e03-5af6-461d-a832-b5e23f93b19f/downloads/rojumedevunez.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466591/; classtype:trojan-activity;sid:84329691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466585)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nefusajoxepisajejod.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466585/; classtype:trojan-activity;sid:84329685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466581)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/tubewerapip.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466581/; classtype:trojan-activity;sid:84329681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466583)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/18645484853.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466583/; classtype:trojan-activity;sid:84329683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466584)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/50ab7773-f1d2-4be6-a8e2-1065b2477787/downloads/4850921377.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466584/; classtype:trojan-activity;sid:84329684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466567)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/basimonuje.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466567/; classtype:trojan-activity;sid:84329667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466568)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4490da21-0774-43c2-8f10-26fe1384ffab/downloads/convention_collective_ucanss_mutatio.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466568/; classtype:trojan-activity;sid:84329668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466569)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2f6bcf3c-4b23-42e7-95db-7e5e3070b630/downloads/29680644903.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466569/; classtype:trojan-activity;sid:84329669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466571)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e297ab99-26f3-4763-8aa9-4b5ba8336826/downloads/61556440139.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466571/; classtype:trojan-activity;sid:84329671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466572)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/93a7eb93-9eef-4244-8f20-7f48de1f8294/downloads/rikeleneliteta.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466572/; classtype:trojan-activity;sid:84329672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466559)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/dupibutemuxubezukexe.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466559/; classtype:trojan-activity;sid:84329659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466561)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/58f82e37-5723-4fc5-be87-1ca34da7fc9c/downloads/ladovarudugusujo.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466561/; classtype:trojan-activity;sid:84329661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466562)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/93623530863.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466562/; classtype:trojan-activity;sid:84329662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466563)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f4482b02-adbc-4511-a01d-8f5a32444a75/downloads/31982364803.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466563/; classtype:trojan-activity;sid:84329663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466564)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c29905cb-cab1-47d6-9263-d073f5bcab67/downloads/manually_update_officescan_server.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466564/; classtype:trojan-activity;sid:84329664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466565)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/meligofat.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466565/; classtype:trojan-activity;sid:84329665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466566)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pibajusapasadasizuvabo.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466566/; classtype:trojan-activity;sid:84329666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466552)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/vuguvukopipokimukunoju.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466552/; classtype:trojan-activity;sid:84329652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466553)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/vmware_horizon_not_loading.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466553/; classtype:trojan-activity;sid:84329653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466556)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/gekepozokenaxaketojakoj.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466556/; classtype:trojan-activity;sid:84329656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466557)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/xekinozu.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466557/; classtype:trojan-activity;sid:84329657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466558)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/tanaber.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466558/; classtype:trojan-activity;sid:84329658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466546)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lokodemerukezabakexa.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466546/; classtype:trojan-activity;sid:84329646; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466547)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/wijigezafububofelib.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466547/; classtype:trojan-activity;sid:84329647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466548)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1a64ed17-85a2-4cee-b266-878ed957a17a/downloads/wezixipusafa.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466548/; classtype:trojan-activity;sid:84329648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466551)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6ed9a7df-8325-4b88-b206-4975011bd8d3/downloads/73303046927.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466551/; classtype:trojan-activity;sid:84329651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466544)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/vafibezesixura.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466544/; classtype:trojan-activity;sid:84329644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466542)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cdf9b72e-240a-4a41-ac28-e187be75db3e/downloads/10008295817.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466542/; classtype:trojan-activity;sid:84329642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466539)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/35017680871.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466539/; classtype:trojan-activity;sid:84329639; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466534)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b5346c1d-c474-4a92-9b4c-cbf0eee37189/downloads/jamupipenimewuroveg.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466534/; classtype:trojan-activity;sid:84329634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466523)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ddc49093-0792-428b-8073-6170b30113a2/downloads/ritiwuga.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466523/; classtype:trojan-activity;sid:84329623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466524)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/697088a1-6c9a-496e-9a4d-922308cd97be/downloads/98558988287.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466524/; classtype:trojan-activity;sid:84329624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466525)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3d8c405e-d09a-43e6-b2b9-f8bbfe0e4b05/downloads/japifitakudisudupuweb.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466525/; classtype:trojan-activity;sid:84329625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466527)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b7519557-5091-4de7-b104-8e86c3953c5d/downloads/66697702965.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466527/; classtype:trojan-activity;sid:84329627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466528)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c4d8863b-da23-437d-86ed-df2351a23265/downloads/sazodaxorega.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466528/; classtype:trojan-activity;sid:84329628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466512)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/36655168913.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466512/; classtype:trojan-activity;sid:84329612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466513)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/wevularaboxurewugawe.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466513/; classtype:trojan-activity;sid:84329613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466514)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/rubizegelolulagexarunup.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466514/; classtype:trojan-activity;sid:84329614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466515)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c29905cb-cab1-47d6-9263-d073f5bcab67/downloads/pipe_fittings_surface_area_chart.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466515/; classtype:trojan-activity;sid:84329615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466517)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/ludirov.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466517/; classtype:trojan-activity;sid:84329617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466521)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/jedibam.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466521/; classtype:trojan-activity;sid:84329621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466522)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c2f5ec0b-52d8-40cb-8fa6-a66f6f891fa9/downloads/64630520522.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466522/; classtype:trojan-activity;sid:84329622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466506)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/19f0e93a-8f01-4f21-8964-dcc990dea571/downloads/honeywell_dc3002_manual.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466506/; classtype:trojan-activity;sid:84329606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466507)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/30963207670.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466507/; classtype:trojan-activity;sid:84329607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466508)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/963d457e-5dea-4a7e-aae8-47aada2a7cc0/downloads/36202936872.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466508/; classtype:trojan-activity;sid:84329608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466509)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/738cd3ca-10f0-4f1e-865e-c0932904fbb2/downloads/28412734415.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466509/; classtype:trojan-activity;sid:84329609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466510)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/af067739-2dfe-40f3-ae00-a758e587d7d3/downloads/wepepuv.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466510/; classtype:trojan-activity;sid:84329610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466503)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/atpco_fare_filing_manual_s.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466503/; classtype:trojan-activity;sid:84329603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466504)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/gartner_magic_quadrant_ips.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466504/; classtype:trojan-activity;sid:84329604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466505)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f2215a6c-0436-4d82-8033-c5d079398259/downloads/xawegifurixikinixi.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466505/; classtype:trojan-activity;sid:84329605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466501)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nolovafitavire.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466501/; classtype:trojan-activity;sid:84329601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466495)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9f11cc6f-a645-4f71-bee4-e3848f35abf2/downloads/mojijodexiv.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466495/; classtype:trojan-activity;sid:84329595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466497)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/64114a94-94a3-4f5d-866a-beee254b955f/downloads/xipefodefanotare.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466497/; classtype:trojan-activity;sid:84329597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466498)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/gekulafemidafalijuw.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466498/; classtype:trojan-activity;sid:84329598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466489)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/types_of_lines_in_construction_drawings.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466489/; classtype:trojan-activity;sid:84329589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466490)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/psa_birth_certificate_authorization_letter.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466490/; classtype:trojan-activity;sid:84329590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466492)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/53202951-38c7-4c35-8280-6cefaf47915f/downloads/libububodanusakamarad.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466492/; classtype:trojan-activity;sid:84329592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466480)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/41202776349.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466480/; classtype:trojan-activity;sid:84329580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466481)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/dc583f51-62de-45fb-b9c6-f152dd4c2594/downloads/combining_like_terms_pyramid_worksheet_answers.pdf"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466481/; classtype:trojan-activity;sid:84329581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466482)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1dc2c198-09f6-4966-96bb-2e160c7d78e2/downloads/55840145977.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466482/; classtype:trojan-activity;sid:84329582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466484)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/puzenesariwalez.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466484/; classtype:trojan-activity;sid:84329584; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466485)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c0eb552d-3ccf-4b3e-a340-0e3717106147/downloads/kalozarisi.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466485/; classtype:trojan-activity;sid:84329585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466486)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/wilikof.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466486/; classtype:trojan-activity;sid:84329586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466487)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/geruzirejexexani.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466487/; classtype:trojan-activity;sid:84329587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466476)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/de9d9f96-a289-4877-85d4-e6d2d4cc419c/downloads/minerva_t2000_manual.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466476/; classtype:trojan-activity;sid:84329576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466474)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/siemens_pcs_7_full_training_manual.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466474/; classtype:trojan-activity;sid:84329574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466472)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/sojawamiluredowad.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466472/; classtype:trojan-activity;sid:84329572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466462)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/add57eeb-0480-4d3e-871c-79d9b8fe2772/downloads/lozataroziwukurejigax.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466462/; classtype:trojan-activity;sid:84329562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466463)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/capacitor_bank_preventive_maintenance_checklist.pdf"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466463/; classtype:trojan-activity;sid:84329563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466464)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/jesafi.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466464/; classtype:trojan-activity;sid:84329564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466465)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/wofewipawo.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466465/; classtype:trojan-activity;sid:84329565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466468)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/58423586845.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466468/; classtype:trojan-activity;sid:84329568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466469)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/89849145142.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466469/; classtype:trojan-activity;sid:84329569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466460)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4c26a93a-50bb-4104-895b-059e3fc9a02c/downloads/zoxinigexozojadidara.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466460/; classtype:trojan-activity;sid:84329560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466454)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/96b6a2f4-8317-413b-a7e3-44adb2eb81f5/downloads/demande_d_allocation_chomage_pole_emploi.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466454/; classtype:trojan-activity;sid:84329554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466459)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tutorialspoint_sap_pp.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466459/; classtype:trojan-activity;sid:84329559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466449)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/lafebokoz.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466449/; classtype:trojan-activity;sid:84329549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466450)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/advance_payment_request_letter_format_word.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466450/; classtype:trojan-activity;sid:84329550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466452)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0a0c7596-8583-4967-abed-67d8d1ffd610/downloads/boilermaker_drawings_and_developments.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466452/; classtype:trojan-activity;sid:84329552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466453)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8532eb1d-13c2-4756-9d41-225750b056f4/downloads/litimuwabu.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466453/; classtype:trojan-activity;sid:84329553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466444)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/telcordia_sr_332_issue_4.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466444/; classtype:trojan-activity;sid:84329544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466445)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d89879dd-a0f6-4cd8-8b66-99c2d6e48b2c/downloads/stopaq_application_manual_2018.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466445/; classtype:trojan-activity;sid:84329545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466447)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3daad7b2-98c5-4dc1-b37a-5570afcba267/downloads/40472163846.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466447/; classtype:trojan-activity;sid:84329547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466439)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/89247847196.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466439/; classtype:trojan-activity;sid:84329539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466440)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/72993487295.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466440/; classtype:trojan-activity;sid:84329540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466441)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/de9155fa-7173-4766-94c3-9e400d4aed58/downloads/def_stan_91-91.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466441/; classtype:trojan-activity;sid:84329541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466443)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/42d6a3b4-bbc0-47ab-bf86-c3ddb806b2ed/downloads/rafadaduveputev.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466443/; classtype:trojan-activity;sid:84329543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466429)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3924d65b-e08d-4f21-8d71-a0b15eb654bb/downloads/63720952596.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466429/; classtype:trojan-activity;sid:84329529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466417)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/woleb.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466417/; classtype:trojan-activity;sid:84329517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466418)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/dururotilonid.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466418/; classtype:trojan-activity;sid:84329518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466419)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/150_dialogues_en_francais.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466419/; classtype:trojan-activity;sid:84329519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466420)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/88031585580.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466420/; classtype:trojan-activity;sid:84329520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466423)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/dollar_general_cbl_answers_robbery_prevention.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466423/; classtype:trojan-activity;sid:84329523; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466424)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4e8158-a082-4b1f-960e-1d82a946a72b/downloads/76239393989.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466424/; classtype:trojan-activity;sid:84329524; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466414)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/51c1105d-a687-468d-b1aa-293ca9578a34/downloads/giwuroganapedokozijave.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466414/; classtype:trojan-activity;sid:84329514; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466406)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/50e5aae7-a15c-4d74-a4ed-a8edfca980c4/downloads/atividades_adaptadas_de_ingles_para_deficientes_intelectuais.pdf"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466406/; classtype:trojan-activity;sid:84329506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466407)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/697088a1-6c9a-496e-9a4d-922308cd97be/downloads/24465842333.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466407/; classtype:trojan-activity;sid:84329507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466409)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2d664301-7b5e-474d-97a1-1305c7ece601/downloads/35905190672.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466409/; classtype:trojan-activity;sid:84329509; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466410)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/12922543008.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466410/; classtype:trojan-activity;sid:84329510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466412)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/804274b4-5f10-4c26-9de6-df56f38aac7c/downloads/20643132370.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466412/; classtype:trojan-activity;sid:84329512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466413)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/95435099570.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466413/; classtype:trojan-activity;sid:84329513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466401)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2bb4e8cb-ec7e-44c1-a645-d94d4534f3a4/downloads/far_from_you_tess_sharpe.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466401/; classtype:trojan-activity;sid:84329501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466403)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/87076889980.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466403/; classtype:trojan-activity;sid:84329503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466396)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/40331451843.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466396/; classtype:trojan-activity;sid:84329496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466397)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/71d9f42f-0bad-4406-8a48-95c698e57e68/downloads/sumitomo_f50_compressor_manual.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466397/; classtype:trojan-activity;sid:84329497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466398)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tusosexukitut.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466398/; classtype:trojan-activity;sid:84329498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466387)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/chambre_de_tirage_telecom.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466387/; classtype:trojan-activity;sid:84329487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466389)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d45c0d9d-8581-471d-bee0-51d1b9891f05/downloads/nisisot.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466389/; classtype:trojan-activity;sid:84329489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466390)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tojabuka.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466390/; classtype:trojan-activity;sid:84329490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466391)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/16219919996.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466391/; classtype:trojan-activity;sid:84329491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466392)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/famous_athletes_banned_for_drug_use.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466392/; classtype:trojan-activity;sid:84329492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466393)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/31075581028.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466393/; classtype:trojan-activity;sid:84329493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466394)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/table_trigonometrique_complet.pdf"; http_uri; depth:91; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466394/; classtype:trojan-activity;sid:84329494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466385)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f20719e2-319c-4f10-aabc-5dffb4a98912/downloads/45233279752.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466385/; classtype:trojan-activity;sid:84329485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466376)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/10e01255-b324-4a54-ae63-f4e28a319147/downloads/how_to_make_authorization_letter_to_claim_money_in_palawan.pdf"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466376/; classtype:trojan-activity;sid:84329476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466378)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7a69ed85-566a-4d22-8bd3-47a8a314b3bf/downloads/baropuzijavalerivotenujop.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466378/; classtype:trojan-activity;sid:84329478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466379)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/15135097712.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466379/; classtype:trojan-activity;sid:84329479; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466366)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4831e354-44dc-4759-9d14-0dd6cfda589f/downloads/demag_ac_350_dwg.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466366/; classtype:trojan-activity;sid:84329466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466370)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f6479094-5bf7-4b46-9ced-d0f3d0d49751/downloads/63982701040.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466370/; classtype:trojan-activity;sid:84329470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466371)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e35dded4-68df-49bc-a9b0-aad8c63628c2/downloads/polipuzikiwelines.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466371/; classtype:trojan-activity;sid:84329471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466372)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/jakirezimukixinirivuvizuw.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466372/; classtype:trojan-activity;sid:84329472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466373)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c4bf44b4-a39c-49f8-89f5-4b487ef61751/downloads/safety_precautions_during_rainy_season_ppt.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466373/; classtype:trojan-activity;sid:84329473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466358)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/gasanon.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466358/; classtype:trojan-activity;sid:84329458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466359)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/87218120165.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466359/; classtype:trojan-activity;sid:84329459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466364)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6c9fdcec-b167-4620-b064-54b8917c32b8/downloads/57211354597.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466364/; classtype:trojan-activity;sid:84329464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466355)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9927c1c5-c61c-4f5e-807e-67bd1833b3e4/downloads/2687436544.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466355/; classtype:trojan-activity;sid:84329455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466356)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/astonishment_report_example_template_free.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466356/; classtype:trojan-activity;sid:84329456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466353)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4454ad30-3f6f-488a-b5e6-19e7bcca2146/downloads/duzinijilufixikedaluw.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466353/; classtype:trojan-activity;sid:84329453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466340)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/47a03532-4838-4d3f-b185-a29c87fa882c/downloads/24511080679.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466340/; classtype:trojan-activity;sid:84329440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466341)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/35512569741.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466341/; classtype:trojan-activity;sid:84329441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466344)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/fiselarodinolapin.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466344/; classtype:trojan-activity;sid:84329444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466348)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/fonuferin.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466348/; classtype:trojan-activity;sid:84329448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466349)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/59681288373.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466349/; classtype:trojan-activity;sid:84329449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466350)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9db526fb-d62a-447a-9766-8665158ad47a/downloads/skf_linear_bearing_catalogue.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466350/; classtype:trojan-activity;sid:84329450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466351)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/45838770375.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466351/; classtype:trojan-activity;sid:84329451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466336)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98a1791f-f3a9-4ef2-ac34-41b3393c3d1d/downloads/original_documents_handover_letter_format.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466336/; classtype:trojan-activity;sid:84329436; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466337)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/60272662631.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466337/; classtype:trojan-activity;sid:84329437; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466338)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aa44ab49-4d64-4d64-8bfd-2dfce545052f/downloads/limitations_act_2004_nigeria.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466338/; classtype:trojan-activity;sid:84329438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466331)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/72cc53f9-3bf4-447c-963a-353f48ad8500/downloads/puwutokok.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466331/; classtype:trojan-activity;sid:84329431; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466333)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2224247e-29ce-4f8d-b838-abfcbdf269c0/downloads/emdr_cognitive_interweaves.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466333/; classtype:trojan-activity;sid:84329433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466325)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/15715958975.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466325/; classtype:trojan-activity;sid:84329425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466326)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/sanugesijeviwo.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466326/; classtype:trojan-activity;sid:84329426; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466327)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/167862b3-31e9-4984-90e5-30766e3a7fa8/downloads/20740408467.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466327/; classtype:trojan-activity;sid:84329427; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466316)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/22914289512.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466316/; classtype:trojan-activity;sid:84329416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466317)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f842cd9f-c67c-4749-ba01-22d7c1ea502c/downloads/93070455772.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466317/; classtype:trojan-activity;sid:84329417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466319)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/61240910211.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466319/; classtype:trojan-activity;sid:84329419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466320)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/33251318472.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466320/; classtype:trojan-activity;sid:84329420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466321)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/800cff82-04ba-4c47-9f8b-d21367acb04d/downloads/84098559127.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466321/; classtype:trojan-activity;sid:84329421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466322)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kaxajopisojurivo.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466322/; classtype:trojan-activity;sid:84329422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466324)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/vehicle_sale_agreement_format_in_word_kerala_online_applicat.pdf"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466324/; classtype:trojan-activity;sid:84329424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466312)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/everstart_750_amp_jump_starter_manual.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466312/; classtype:trojan-activity;sid:84329412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466313)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/424b0398-579a-4717-a17a-ffb972bf5819/downloads/manual_ppap_4_edicao.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466313/; classtype:trojan-activity;sid:84329413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466314)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b2a026b5-555a-437c-867f-3969f62b48d7/downloads/3703775959.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466314/; classtype:trojan-activity;sid:84329414; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466305)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3f5ecf8d-ba74-430f-ac11-9eb6ace92d02/downloads/womirojepu.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466305/; classtype:trojan-activity;sid:84329405; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466307)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/lord_of_the_flies_script.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466307/; classtype:trojan-activity;sid:84329407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466309)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3d0a6e54-c95b-4e67-871e-882f39f9c203/downloads/38102271043.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466309/; classtype:trojan-activity;sid:84329409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466304)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/depo_provera_osteoporosis_guidelines.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466304/; classtype:trojan-activity;sid:84329404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466301)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/397fbc33-145f-44ec-a774-e1fa1b866d82/downloads/fekesijurada.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466301/; classtype:trojan-activity;sid:84329401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466293)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1e222df8-d197-4254-b90b-be3d3b023ef4/downloads/78299826683.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466293/; classtype:trojan-activity;sid:84329393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466294)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bc2da57a-5cad-4b1e-b658-8efa7e30bee5/downloads/como_transferir_saldo_de_dados_unitel.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466294/; classtype:trojan-activity;sid:84329394; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466283)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/billetes_didacticos_mexicanos_para_imprimir.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466283/; classtype:trojan-activity;sid:84329383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466284)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/xutodorimalibavexididoson.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466284/; classtype:trojan-activity;sid:84329384; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466285)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/vatalikuxigepiwu.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466285/; classtype:trojan-activity;sid:84329385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466286)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2fda8269-9b7e-4008-b093-ed7dc0bde9d7/downloads/zinivegosejuriwevagowu.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466286/; classtype:trojan-activity;sid:84329386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466288)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/dotuxomolomorapitome.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466288/; classtype:trojan-activity;sid:84329388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466289)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/541a1d8b-7a21-4c1f-8013-03406bd1a8ad/downloads/mevuxurike.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466289/; classtype:trojan-activity;sid:84329389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466291)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9c30937d-c8da-4e7b-9f7a-432344b46400/downloads/jubomumifekomu.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466291/; classtype:trojan-activity;sid:84329391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466279)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aa25c895-a966-4265-aeb1-bc094284554e/downloads/jifig.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466279/; classtype:trojan-activity;sid:84329379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466280)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/90378982159.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466280/; classtype:trojan-activity;sid:84329380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466282)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/jodegemotekuseve.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466282/; classtype:trojan-activity;sid:84329382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466268)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/46578941429.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466268/; classtype:trojan-activity;sid:84329368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466269)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/elenco_corsi_vam_viterbo.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466269/; classtype:trojan-activity;sid:84329369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466259)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/17714436684.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466259/; classtype:trojan-activity;sid:84329359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466260)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/planet_fitness_membership_cancellation_letter.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466260/; classtype:trojan-activity;sid:84329360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466261)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/af067739-2dfe-40f3-ae00-a758e587d7d3/downloads/61105974714.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466261/; classtype:trojan-activity;sid:84329361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466266)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/933c3405-1572-4648-b39e-d98567eb5bee/downloads/for_your_kind_perusal_and_necessary_action_meaning.pdf"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466266/; classtype:trojan-activity;sid:84329366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466267)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/119d5b03-e78f-4725-87b7-ed496b267f6d/downloads/scrubber_design_calculation_excel.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466267/; classtype:trojan-activity;sid:84329367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466249)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6787db73-833d-4393-867e-1b786eb5e101/downloads/60859753638.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466249/; classtype:trojan-activity;sid:84329349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466252)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62a7895e-5f81-4049-920b-e70e38d29e37/downloads/why_is_annexure_d_required_for_minor_passport.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466252/; classtype:trojan-activity;sid:84329352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466253)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/574284889.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466253/; classtype:trojan-activity;sid:84329353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466254)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9e5b6b40-f934-4273-a65f-cbaee9aa4b00/downloads/xikapataxofako.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466254/; classtype:trojan-activity;sid:84329354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466255)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lobigexapi.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466255/; classtype:trojan-activity;sid:84329355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466256)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2470d53e-fef7-4646-9c8b-919894e66d18/downloads/72646482584.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466256/; classtype:trojan-activity;sid:84329356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466257)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8c16f145-4fc0-4af7-a4db-de4acd818fe4/downloads/46429707192.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466257/; classtype:trojan-activity;sid:84329357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466245)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7153ec40-cd7f-411a-a08b-66d173a33455/downloads/standards_australia_handbook_197.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466245/; classtype:trojan-activity;sid:84329345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466247)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/55745505506.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466247/; classtype:trojan-activity;sid:84329347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466241)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/43311556781.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466241/; classtype:trojan-activity;sid:84329341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466244)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/80691091889.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466244/; classtype:trojan-activity;sid:84329344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466238)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/sewuxazomuwara.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466238/; classtype:trojan-activity;sid:84329338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466231)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ce549e8-3051-428a-a71b-b48f204ac3cd/downloads/rapid_router_level_43_solution.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466231/; classtype:trojan-activity;sid:84329331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466232)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0620bed2-a9d8-4f06-ab8c-173ea1a60a70/downloads/jijegarazomimubusawogam.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466232/; classtype:trojan-activity;sid:84329332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466233)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/matunekuv.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466233/; classtype:trojan-activity;sid:84329333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466230)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/53202951-38c7-4c35-8280-6cefaf47915f/downloads/statsafe_3000_msds.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466230/; classtype:trojan-activity;sid:84329330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466221)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/82647770508.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466221/; classtype:trojan-activity;sid:84329321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466222)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ee3e2894-0337-41f6-9371-caecf7034a22/downloads/26991821255.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466222/; classtype:trojan-activity;sid:84329322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466226)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/gesuzodekutiz.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466226/; classtype:trojan-activity;sid:84329326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466227)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62a7895e-5f81-4049-920b-e70e38d29e37/downloads/how_to_register_in_upstox.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466227/; classtype:trojan-activity;sid:84329327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466228)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/exercises_for_trigger_thumb.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466228/; classtype:trojan-activity;sid:84329328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466229)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/132d13c5-3f89-41bf-85b4-d1a24ddcf61c/downloads/nosiwevixina.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466229/; classtype:trojan-activity;sid:84329329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466215)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a56a106f-21b9-46c2-b5bc-12461919334c/downloads/vurarufa.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466215/; classtype:trojan-activity;sid:84329315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466217)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/how_to_get_a_wire_transfer_receipt_chase.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466217/; classtype:trojan-activity;sid:84329317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466219)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/3175972790.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466219/; classtype:trojan-activity;sid:84329319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466213)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62128af0-82d0-4bae-b967-d393a4304003/downloads/apex_sl_vibration_controller_manual.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466213/; classtype:trojan-activity;sid:84329313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466214)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/nakozixuwelafi.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466214/; classtype:trojan-activity;sid:84329314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466205)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/mobesapovasag.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466205/; classtype:trojan-activity;sid:84329305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466206)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fae029f6-27b1-4578-94bc-ae0bbaeebde4/downloads/imperial_vernier_caliper_worksheet.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466206/; classtype:trojan-activity;sid:84329306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466207)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e2ab423c-1813-4cd0-becb-6a8adbf01641/downloads/ribafimimeriledok.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466207/; classtype:trojan-activity;sid:84329307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466208)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/62228929609.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466208/; classtype:trojan-activity;sid:84329308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466209)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/91a706e9-d066-47d7-89af-69535d865c3d/downloads/carteirinha_de_estudante_falsa_em.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466209/; classtype:trojan-activity;sid:84329309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466196)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/80e9e7c7-d97b-4b5a-96c4-9a83854a3065/downloads/35740879646.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466196/; classtype:trojan-activity;sid:84329296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466201)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f2d42ffe-779b-4107-ac42-7f36375aab37/downloads/zeneliginuboripiriza.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466201/; classtype:trojan-activity;sid:84329301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466202)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6bb5c8cf-e89d-49c0-aeeb-7278d39f6b32/downloads/fiche_grcf_bts_gpme.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466202/; classtype:trojan-activity;sid:84329302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466193)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/77724997403.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466193/; classtype:trojan-activity;sid:84329293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466181)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/xinunivigaxelifujukedo.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466181/; classtype:trojan-activity;sid:84329281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466182)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/pidipaxiworoguvosifap.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466182/; classtype:trojan-activity;sid:84329282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466183)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/rent_receipt_format_in_ms_word.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466183/; classtype:trojan-activity;sid:84329283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466184)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/nipipuk.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466184/; classtype:trojan-activity;sid:84329284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466185)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/081e0348-3bf0-4a3e-a723-749adc1aa630/downloads/67271829455.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466185/; classtype:trojan-activity;sid:84329285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466186)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c0325f5e-ab4f-48af-8631-8757a310624e/downloads/57390845107.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466186/; classtype:trojan-activity;sid:84329286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466187)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/45659404876.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466187/; classtype:trojan-activity;sid:84329287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466189)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/80200009732.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466189/; classtype:trojan-activity;sid:84329289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466190)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3a657e0c-a872-4028-94b8-811aea249c49/downloads/shl_general_ability_test_answers_reddit.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466190/; classtype:trojan-activity;sid:84329290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466175)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06823f9b-45c4-43cb-a44f-1f9f645cebcf/downloads/32406777299.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466175/; classtype:trojan-activity;sid:84329275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466177)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/7694747911.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466177/; classtype:trojan-activity;sid:84329277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466178)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/danokubiwen.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466178/; classtype:trojan-activity;sid:84329278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466179)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62128af0-82d0-4bae-b967-d393a4304003/downloads/xibuvajuxaluvotom.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466179/; classtype:trojan-activity;sid:84329279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466180)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0a0c7596-8583-4967-abed-67d8d1ffd610/downloads/8393439781.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466180/; classtype:trojan-activity;sid:84329280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466170)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/redoripedigi.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466170/; classtype:trojan-activity;sid:84329270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466172)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/how_to_cancel_print_job_on_zebra_gk420d.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466172/; classtype:trojan-activity;sid:84329272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466169)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b83dcfc0-bbe6-4498-b356-e365ec2ed396/downloads/zofafiba.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466169/; classtype:trojan-activity;sid:84329269; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466161)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a37e9011-77af-43eb-9e7b-dd6853450512/downloads/les_jours_de_la_semaine_exercices.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466161/; classtype:trojan-activity;sid:84329261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466162)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/90213521835.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466162/; classtype:trojan-activity;sid:84329262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466154)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/28725733968.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466154/; classtype:trojan-activity;sid:84329254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466149)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7aa15cc-b2d1-4fef-8a47-8d7810090a9c/downloads/jenuwegipujodunoj.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466149/; classtype:trojan-activity;sid:84329249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466151)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/dowuvibatekijutajuvavu.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466151/; classtype:trojan-activity;sid:84329251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466152)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/14196656823.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466152/; classtype:trojan-activity;sid:84329252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466153)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/44a9091e-2134-47ec-8037-250483142ad3/downloads/kenmore_elite_665.12783_k311_service_manual.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466153/; classtype:trojan-activity;sid:84329253; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466144)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/50362295282.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466144/; classtype:trojan-activity;sid:84329244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466145)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/navy_uic_code_list.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466145/; classtype:trojan-activity;sid:84329245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466147)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9f2acd38-413e-47a5-ac42-d6305581bfab/downloads/logerafanekox.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466147/; classtype:trojan-activity;sid:84329247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466140)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/zakojamoderuvovu.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466140/; classtype:trojan-activity;sid:84329240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466133)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b2a026b5-555a-437c-867f-3969f62b48d7/downloads/successfactors_recruiting_implementation_guide.pdf"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466133/; classtype:trojan-activity;sid:84329233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466134)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/97474238027.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466134/; classtype:trojan-activity;sid:84329234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466135)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ddcbbbab-f8a6-4067-a450-a2f971a66e79/downloads/daikin_ac_remote_control_guide.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466135/; classtype:trojan-activity;sid:84329235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466138)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/lebuk.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466138/; classtype:trojan-activity;sid:84329238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466139)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/71642361311.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466139/; classtype:trojan-activity;sid:84329239; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466128)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kumujadirifokekikivexe.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466128/; classtype:trojan-activity;sid:84329228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466130)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/2818265442.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466130/; classtype:trojan-activity;sid:84329230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466132)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e262bb3c-3205-4bb6-954b-f565479d59e0/downloads/examenes_psicometricos_pruebas_psicometricas_gratis_para_imp.pdf"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466132/; classtype:trojan-activity;sid:84329232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466122)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4252a31f-7a57-4ac8-a31e-ee71b2361194/downloads/61162239689.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466122/; classtype:trojan-activity;sid:84329222; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466125)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/43b3ecff-25d4-4371-99a8-6df485cf4fd5/downloads/amoeba_sisters_classification_worksheet.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466125/; classtype:trojan-activity;sid:84329225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466115)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/fundamentals_of_power_supply_design_book.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466115/; classtype:trojan-activity;sid:84329215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466116)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/her_yonuyle_modern_almanca_dursun_zengin.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466116/; classtype:trojan-activity;sid:84329216; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466117)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/15938565950.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466117/; classtype:trojan-activity;sid:84329217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466107)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d5271715-d4c2-447f-bd8c-804dbc17722c/downloads/experience_certificate_format_for_quality_control_engineer.pdf"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466107/; classtype:trojan-activity;sid:84329207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466109)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1b7f80b5-fb34-497d-8072-447feb44da09/downloads/lewamagoromizesa.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466109/; classtype:trojan-activity;sid:84329209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466110)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/courier_declaration_format.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466110/; classtype:trojan-activity;sid:84329210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466104)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/ruripumefenezalizaf.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466104/; classtype:trojan-activity;sid:84329204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466101)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/32a18e69-8d9d-488c-b50f-45023ca24343/downloads/87353354077.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466101/; classtype:trojan-activity;sid:84329201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466092)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/20305303180.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466092/; classtype:trojan-activity;sid:84329192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466099)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/kutapodisub.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466099/; classtype:trojan-activity;sid:84329199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466100)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0919b7e4-2541-44dd-b945-9d5e6d22eaf1/downloads/xibegakibojonabawaz.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466100/; classtype:trojan-activity;sid:84329200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466083)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/doxuwiponubagexotabos.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466083/; classtype:trojan-activity;sid:84329183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466084)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/54308720858.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466084/; classtype:trojan-activity;sid:84329184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466085)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/gomanelakog.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466085/; classtype:trojan-activity;sid:84329185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466089)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/nx_nastran_element_library_reference_manual.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466089/; classtype:trojan-activity;sid:84329189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466074)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/collibra_expert_i_certification_answers_sheet_download_2017.pdf"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466074/; classtype:trojan-activity;sid:84329174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466075)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4ec11559-69c0-4903-84a6-3240babfcfe7/downloads/lapagikevipewijumodoru.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466075/; classtype:trojan-activity;sid:84329175; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466076)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1bfc168f-d0df-43cb-a73e-d0c80e42fe5c/downloads/formulaire_virement_international_banque_postale.pdf"; http_uri; depth:110; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466076/; classtype:trojan-activity;sid:84329176; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466078)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/96273346643.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466078/; classtype:trojan-activity;sid:84329178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466079)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1feaf4a2-3a85-48bd-b975-ab8d5bcee640/downloads/30816276176.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466079/; classtype:trojan-activity;sid:84329179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466070)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d8f5bd9b-2c75-4c1f-8d4d-84a7de1d3443/downloads/rent_brokerage_receipt_format_word.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466070/; classtype:trojan-activity;sid:84329170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466071)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8439ca10-a5ac-4299-aa09-54ab615a2090/downloads/bozagororaxurivir.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466071/; classtype:trojan-activity;sid:84329171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466072)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/54016191818.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466072/; classtype:trojan-activity;sid:84329172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466073)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f0d27cad-ce96-47a4-a6b6-d00149677212/downloads/87562723190.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466073/; classtype:trojan-activity;sid:84329173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466066)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/swot_analysis_for_poultry_farming.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466066/; classtype:trojan-activity;sid:84329166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466067)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/bosokoxa.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466067/; classtype:trojan-activity;sid:84329167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466063)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/69034861186.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466063/; classtype:trojan-activity;sid:84329163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466065)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/14962502915.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466065/; classtype:trojan-activity;sid:84329165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466060)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/42589334771.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466060/; classtype:trojan-activity;sid:84329160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466054)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/banksman_hand_signals.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466054/; classtype:trojan-activity;sid:84329154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466055)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6cdacb6d-7fbf-4d09-a986-56cdfa4edeb2/downloads/5985868832.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466055/; classtype:trojan-activity;sid:84329155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466056)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d258c0c8-b9d9-4d64-b965-01378617d9c6/downloads/voter_list_delhi_2018.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466056/; classtype:trojan-activity;sid:84329156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466058)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/99737319160.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466058/; classtype:trojan-activity;sid:84329158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466045)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1bfc168f-d0df-43cb-a73e-d0c80e42fe5c/downloads/71653623394.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466045/; classtype:trojan-activity;sid:84329145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466047)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/testing_and_commissioning_of_electrical_equipment.pdf"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466047/; classtype:trojan-activity;sid:84329147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466048)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/1ffc09a0-c9a4-4762-8145-43798f2fda71/downloads/back_to_work_from_maternity_leave_email.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466048/; classtype:trojan-activity;sid:84329148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466049)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/xepaxijaniwitofoxipoja.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466049/; classtype:trojan-activity;sid:84329149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466051)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/de43da9e-bc77-4e56-a909-0e72ba746cf9/downloads/electricity_bill_name_change_noc_format.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466051/; classtype:trojan-activity;sid:84329151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466052)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2ad58263-1b5c-4da7-bc4a-7b8f99e22218/downloads/formulaire_ordre_de_virement_banque_postale.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466052/; classtype:trojan-activity;sid:84329152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466053)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/76135669664.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466053/; classtype:trojan-activity;sid:84329153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466039)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/23ec0b56-0ae7-4e41-8565-08e517b0b386/downloads/gatamalepuberik.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466039/; classtype:trojan-activity;sid:84329139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466040)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/97106569323.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466040/; classtype:trojan-activity;sid:84329140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466041)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3e3d230e-4918-4f4b-8a10-8ee933aabcaf/downloads/99772344048.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466041/; classtype:trojan-activity;sid:84329141; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466037)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/wapurexep.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466037/; classtype:trojan-activity;sid:84329137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466032)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/19668bf7-0111-4cbb-8050-06562ac08bba/downloads/steps_to_create_template_instance_in_tosca.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466032/; classtype:trojan-activity;sid:84329132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466033)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/bidoxefemoduxunirez.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466033/; classtype:trojan-activity;sid:84329133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466034)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/88817028453.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466034/; classtype:trojan-activity;sid:84329134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466027)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/job_work_challan_format_in_excel.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466027/; classtype:trojan-activity;sid:84329127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466028)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34794329-fa5b-49f8-8f60-fb0720b1e556/downloads/14476765670.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466028/; classtype:trojan-activity;sid:84329128; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466015)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/resignation_letter_template_family_reasons.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466015/; classtype:trojan-activity;sid:84329115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466016)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8c16f145-4fc0-4af7-a4db-de4acd818fe4/downloads/14431999044.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466016/; classtype:trojan-activity;sid:84329116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466017)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/21303726077.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466017/; classtype:trojan-activity;sid:84329117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466018)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/minupawuferogu.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466018/; classtype:trojan-activity;sid:84329118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466020)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b071d266-376f-40c9-bb70-11ca77d8051b/downloads/36008974689.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466020/; classtype:trojan-activity;sid:84329120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466021)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/60919645191.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466021/; classtype:trojan-activity;sid:84329121; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466022)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/424b0398-579a-4717-a17a-ffb972bf5819/downloads/audit_professional_clearance_letter_template.pdf"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466022/; classtype:trojan-activity;sid:84329122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466023)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/30072850819.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466023/; classtype:trojan-activity;sid:84329123; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466024)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/75213021290.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466024/; classtype:trojan-activity;sid:84329124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466025)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/law-making_process_in_zimbabwe.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466025/; classtype:trojan-activity;sid:84329125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466011)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/363b8b8c-bdd6-4ad7-ac6c-ba65cd60171b/downloads/abaqus_user_subroutine_reference_guide.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466011/; classtype:trojan-activity;sid:84329111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466014)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/85845004614.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466014/; classtype:trojan-activity;sid:84329114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466005)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/genuwafazapibiwinowafal.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466005/; classtype:trojan-activity;sid:84329105; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466006)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/20322886839.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466006/; classtype:trojan-activity;sid:84329106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466008)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/gagibipawuzepakan.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466008/; classtype:trojan-activity;sid:84329108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466002)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/sample_authorization_letter_to_get_psa_marriage_certificate.pdf"; http_uri; depth:121; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466002/; classtype:trojan-activity;sid:84329102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465993)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/8517821794.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465993/; classtype:trojan-activity;sid:84329093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465994)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/padanad.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465994/; classtype:trojan-activity;sid:84329094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465995)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9971747c-d991-46ae-b932-5ba73958e604/downloads/fojajexuretimototatoles.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465995/; classtype:trojan-activity;sid:84329095; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465996)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/mosodekasaxozebopajebibe.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465996/; classtype:trojan-activity;sid:84329096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465997)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6be9a470-c465-4776-ab76-53713c51537a/downloads/30164245456.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465997/; classtype:trojan-activity;sid:84329097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465999)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f264223f-22e7-47f1-947d-9e365a75e217/downloads/96358679127.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465999/; classtype:trojan-activity;sid:84329099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3466000)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f65856df-6ee2-426f-901a-fbcb5106e767/downloads/22057173676.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3466000/; classtype:trojan-activity;sid:84329100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465984)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/butterfly_roof_construction_detail.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465984/; classtype:trojan-activity;sid:84329084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465985)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7ebcf742-ccb2-4edb-bbc1-6f67ead5b604/downloads/baxejatoxenidomixidedax.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465985/; classtype:trojan-activity;sid:84329085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465986)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/17465496427.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465986/; classtype:trojan-activity;sid:84329086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465989)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/zabefenakozevopesomewazi.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465989/; classtype:trojan-activity;sid:84329089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465990)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/48283c5b-b198-4860-9bf9-7f30a2f8146b/downloads/zoromipubadijivonexon.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465990/; classtype:trojan-activity;sid:84329090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465991)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8df58291-e0db-425a-9cda-a9882386ada6/downloads/jaladimurefasetuzukiwaxit.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465991/; classtype:trojan-activity;sid:84329091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465992)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/wofalobomosotanavuze.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465992/; classtype:trojan-activity;sid:84329092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465980)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0d21a9d5-01df-4a9e-9327-883996b2f71d/downloads/ansi_electrical_symbols_standards.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465980/; classtype:trojan-activity;sid:84329080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465974)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a435afa7-bc93-481f-8a35-ce503cc8a972/downloads/sri_rudram_namakam_chamakam_tamil.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465974/; classtype:trojan-activity;sid:84329074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465975)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/tumiwujuluxuwaxi.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465975/; classtype:trojan-activity;sid:84329075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465977)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/denutetoraditut.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465977/; classtype:trojan-activity;sid:84329077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465961)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9569c183-65dc-4f14-a45e-e7944584cb65/downloads/bifidetogatovotuwideki.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465961/; classtype:trojan-activity;sid:84329061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465962)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/baroque_guitar_tab.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465962/; classtype:trojan-activity;sid:84329062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465963)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7f34267e-2563-449a-82e3-60f19988c45d/downloads/lic_jeevan_saral_plan_165_chart.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465963/; classtype:trojan-activity;sid:84329063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465965)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/69187265192.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465965/; classtype:trojan-activity;sid:84329065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465968)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d551812a-3c47-48f1-bc1d-3ac42c3f246c/downloads/rigumudusogepivana.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465968/; classtype:trojan-activity;sid:84329068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465969)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/5528845131.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465969/; classtype:trojan-activity;sid:84329069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465971)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/34a417cb-7930-4ae3-8428-8420716ba08a/downloads/74129229699.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465971/; classtype:trojan-activity;sid:84329071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465972)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/cancionero_catolico_jesed.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465972/; classtype:trojan-activity;sid:84329072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465957)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7a3b63b5-3e6a-48ac-8e49-14ed0037cbc4/downloads/historietas_del_medio_ambiente_largas.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465957/; classtype:trojan-activity;sid:84329057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465955)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/62049175170.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465955/; classtype:trojan-activity;sid:84329055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465949)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/10908647555.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465949/; classtype:trojan-activity;sid:84329049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465951)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/maxabamuxixotabevifutiw.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465951/; classtype:trojan-activity;sid:84329051; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465953)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/downgrade_oracle_database_from_19c_to_11g.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465953/; classtype:trojan-activity;sid:84329053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465942)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ba9b549d-a804-4d13-a818-3c55b3524acd/downloads/75189909272.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465942/; classtype:trojan-activity;sid:84329042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465945)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/individual_development_plan_powerpoint_template.pdf"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465945/; classtype:trojan-activity;sid:84329045; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465946)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/64954946228.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465946/; classtype:trojan-activity;sid:84329046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465939)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/bapozujipo.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465939/; classtype:trojan-activity;sid:84329039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465931)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4872c6d8-aa46-4e32-b809-43d741337793/downloads/74841624584.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465931/; classtype:trojan-activity;sid:84329031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465932)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3a90d4c9-f215-49ec-8178-8e50febf5250/downloads/tedutogonisijetinikiw.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465932/; classtype:trojan-activity;sid:84329032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465933)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/wipofuta.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465933/; classtype:trojan-activity;sid:84329033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465935)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4cb1e8a7-0f1a-4c3a-ae4d-65ac09f78b80/downloads/fenekipejivatoxeni.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465935/; classtype:trojan-activity;sid:84329035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465937)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/445dfc81-a427-4468-a541-314294ee0cbb/downloads/wolarodipuxusisug.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465937/; classtype:trojan-activity;sid:84329037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465938)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c3be0091-4534-4191-a72e-570acc745d3e/downloads/attestation_de_prise_en_charge_tlscontact.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465938/; classtype:trojan-activity;sid:84329038; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465924)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fa4295b9-8c98-4187-bbf8-91c9d7ce5f9e/downloads/89606848887.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465924/; classtype:trojan-activity;sid:84329024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465926)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/44d0963d-ba71-4620-abdb-e3c6631b392b/downloads/balance_confirmation_letter_format_in_word.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465926/; classtype:trojan-activity;sid:84329026; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465912)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/rollo_tomassi_the_rational_male_turkce.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465912/; classtype:trojan-activity;sid:84329012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465914)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/800bda9c-ed1b-45a1-a7d5-702e4e14f980/downloads/pmp_42_processes_chart.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465914/; classtype:trojan-activity;sid:84329014; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465915)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/86917927693.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465915/; classtype:trojan-activity;sid:84329015; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465916)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/methodologie_du_commentaire_compose_francais.pdf"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465916/; classtype:trojan-activity;sid:84329016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465919)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/gauss_elimination_method_example_with_solution.pdf"; http_uri; depth:108; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465919/; classtype:trojan-activity;sid:84329019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465910)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5f03ee03-a319-4a1e-a052-a99710c59365/downloads/bujulodipesotixugakujup.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465910/; classtype:trojan-activity;sid:84329010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465906)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/hsbc_bank_statement.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465906/; classtype:trojan-activity;sid:84329006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465909)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/94e1955e-c7d2-4e11-a6ac-7a5ec652d6cd/downloads/suzuki_dt4_owners_manual.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465909/; classtype:trojan-activity;sid:84329009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465903)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8f5eeb54-04ec-4a30-bb55-41e413d1f3ed/downloads/open_pit_mine_planning_and_design.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465903/; classtype:trojan-activity;sid:84329003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465904)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ceb9a026-f6c4-4e26-a968-d8e0e8d06aaa/downloads/tevedowopalugafaxoro.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465904/; classtype:trojan-activity;sid:84329004; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465905)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/adb32098-1c7a-4519-9e53-ced990fc5d88/downloads/kuniwuzujujurejovewo.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465905/; classtype:trojan-activity;sid:84329005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465896)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/88933df5-ca10-43b5-b140-6aa02868b89c/downloads/76236294804.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465896/; classtype:trojan-activity;sid:84328996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465897)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6ab86f22-a419-4e4f-91d4-5a654823f744/downloads/pamolitix.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465897/; classtype:trojan-activity;sid:84328997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465898)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/697088a1-6c9a-496e-9a4d-922308cd97be/downloads/42508658220.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465898/; classtype:trojan-activity;sid:84328998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465885)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/sotax_at_xtend_user_manual.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465885/; classtype:trojan-activity;sid:84328985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465886)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5d8bfe2e-b91e-431f-9bdc-3f0ea97e388e/downloads/wovivesapo.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465886/; classtype:trojan-activity;sid:84328986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465888)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06792788-ebeb-4570-893a-70dafae2a105/downloads/sample_consent_letter_from_husband_for_wife_to_travel.pdf"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465888/; classtype:trojan-activity;sid:84328988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465889)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/formulaire_renouvellement_titre_de_sejour_yvelines.pdf"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465889/; classtype:trojan-activity;sid:84328989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465891)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/71d9f42f-0bad-4406-8a48-95c698e57e68/downloads/98599689697.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465891/; classtype:trojan-activity;sid:84328991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465892)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/92007305293.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465892/; classtype:trojan-activity;sid:84328992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465893)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d07e2353-3643-42fe-ba11-ffa772b1a28d/downloads/duff_phelps_size_premium.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465893/; classtype:trojan-activity;sid:84328993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465881)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9213334f-b8c6-41b2-903d-dc8cc5791a0a/downloads/49429599069.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465881/; classtype:trojan-activity;sid:84328981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465882)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/22187922858.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465882/; classtype:trojan-activity;sid:84328982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465876)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d5e97205-d745-471d-94c2-4bc94f943a29/downloads/nafexasu.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465876/; classtype:trojan-activity;sid:84328976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465878)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/99401481523.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465878/; classtype:trojan-activity;sid:84328978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465879)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/harry_potter_ea_camara_secreta_ilustrado.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465879/; classtype:trojan-activity;sid:84328979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465870)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/800cff82-04ba-4c47-9f8b-d21367acb04d/downloads/all_gujarati_magazine.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465870/; classtype:trojan-activity;sid:84328970; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465871)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/34103705134.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465871/; classtype:trojan-activity;sid:84328971; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465872)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9a32841c-0d54-4ad0-8acd-a5b15c41cae1/downloads/nagpur_metro_phase_2_dpr.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465872/; classtype:trojan-activity;sid:84328972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465873)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/99406712648.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465873/; classtype:trojan-activity;sid:84328973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465874)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/96d7062c-715f-4c9e-82c2-ac322bf04d1a/downloads/fawafep.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465874/; classtype:trojan-activity;sid:84328974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465875)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/51e053ea-8122-46e3-bee6-6c00a935619c/downloads/28185631859.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465875/; classtype:trojan-activity;sid:84328975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465865)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/renamotoxuxesike.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465865/; classtype:trojan-activity;sid:84328965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465866)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/wixutazavadupiruzani.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465866/; classtype:trojan-activity;sid:84328966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465864)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/vixodamev.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465864/; classtype:trojan-activity;sid:84328964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465852)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pulse_secure_network_error_1329.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465852/; classtype:trojan-activity;sid:84328952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465853)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8fc62093-f93e-447d-8e21-b1e235f4d9cc/downloads/cibse_psychrometric_chart.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465853/; classtype:trojan-activity;sid:84328953; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465857)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/citrix_adc_vpx_datasheet.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465857/; classtype:trojan-activity;sid:84328957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465847)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cac64821-2205-4248-abd9-55e775312c94/downloads/rosigamosusen.pdf"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465847/; classtype:trojan-activity;sid:84328947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465848)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/fosofiboma.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465848/; classtype:trojan-activity;sid:84328948; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465850)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/600b6853-9b14-40c4-b9d1-c0a10f9ad1eb/downloads/mathematics_core_topics_sl.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465850/; classtype:trojan-activity;sid:84328950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465843)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/6e0acf5f-e652-447e-8a3a-90dcb81c48ee/downloads/loan_cancellation_letter.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465843/; classtype:trojan-activity;sid:84328943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465844)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98fd26ea-5c50-4ebf-945e-7ed158ebe1b6/downloads/workplace_printable_hurt_feelings_report.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465844/; classtype:trojan-activity;sid:84328944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465845)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/zalekebi.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465845/; classtype:trojan-activity;sid:84328945; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465833)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/58616986475.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465833/; classtype:trojan-activity;sid:84328933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465835)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/one_of_us_is_lying_character_quotes.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465835/; classtype:trojan-activity;sid:84328935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465839)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0e65d320-97ed-47cb-9ca0-bcd7400824c9/downloads/jewuzikilodejosowar.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465839/; classtype:trojan-activity;sid:84328939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465825)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/72fc6eb8-20de-4439-bced-6bfc7eecaa8e/downloads/bogev.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465825/; classtype:trojan-activity;sid:84328925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465826)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/58b13a51-176b-4b7e-ab1e-a0c84e7a5487/downloads/currency_market_mechanics_bmc_answers.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465826/; classtype:trojan-activity;sid:84328926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465827)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/018aefd4-3541-4598-a5c3-d0911ca60a82/downloads/asce_7-05_espanol_gratis.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465827/; classtype:trojan-activity;sid:84328927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465828)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tifunakarexefeguwitoda.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465828/; classtype:trojan-activity;sid:84328928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465829)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/06a2cc2e-f4bb-4ca4-a0d9-71e2fc8b7812/downloads/molaxoxekex.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465829/; classtype:trojan-activity;sid:84328929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465830)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/iata_airport_handling_manual_2019_full.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465830/; classtype:trojan-activity;sid:84328930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465831)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c1bf3ae2-f6cc-4078-b639-2ff1ca0b62be/downloads/1172286111.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465831/; classtype:trojan-activity;sid:84328931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465832)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/euchre_score_sheets_for_16_players.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465832/; classtype:trojan-activity;sid:84328932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465820)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/dungeon_crawl_classics.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465820/; classtype:trojan-activity;sid:84328920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465804)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bb45e14d-29c5-4287-b67f-843105f3b091/downloads/69904656893.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465804/; classtype:trojan-activity;sid:84328904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465806)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/emmaus_walk_letters_of_encouragement.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465806/; classtype:trojan-activity;sid:84328906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465809)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fc635392-61de-40bc-86f0-c9844fcf30fd/downloads/gramatica_portugues_brasil.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465809/; classtype:trojan-activity;sid:84328909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465814)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/647bfca3-c5f6-48a0-9ec3-35afde17c6e3/downloads/gamokul.pdf"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465814/; classtype:trojan-activity;sid:84328914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465815)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fa284320-69aa-45db-92e2-86468d4beaf0/downloads/53174458267.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465815/; classtype:trojan-activity;sid:84328915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465795)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/72502959-bd3f-431c-9582-055fb0eb9e9d/downloads/nike_employee_benefits.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465795/; classtype:trojan-activity;sid:84328895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465798)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/97767745983.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465798/; classtype:trojan-activity;sid:84328898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465799)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/country_of_origin_letter_template.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465799/; classtype:trojan-activity;sid:84328899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465802)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/39834772333.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465802/; classtype:trojan-activity;sid:84328902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465790)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/rofaruzev.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465790/; classtype:trojan-activity;sid:84328890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465791)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/990799bc-d23a-46ce-a09a-3161937bf907/downloads/verismo_701_service_manual.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465791/; classtype:trojan-activity;sid:84328891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465792)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/rodudiniruzawame.pdf"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465792/; classtype:trojan-activity;sid:84328892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465785)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3c8f7a45-f68c-4369-8f63-be6429599400/downloads/butulanimirovubeve.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465785/; classtype:trojan-activity;sid:84328885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465786)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c725aa89-ce3b-4b0b-861e-e7c40702153d/downloads/gisewonivikamadoliwozuv.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465786/; classtype:trojan-activity;sid:84328886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465787)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d1335ae9-6401-4997-a89d-ffce5d766eb7/downloads/44332900662.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465787/; classtype:trojan-activity;sid:84328887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465779)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b6f72d87-e560-495a-a5bd-684e976b53e4/downloads/nagano_keiki_km10.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465779/; classtype:trojan-activity;sid:84328879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465781)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/76488986948.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465781/; classtype:trojan-activity;sid:84328881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465782)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ac62f849-5623-435a-93ad-86e4d8edc83e/downloads/90625111849.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465782/; classtype:trojan-activity;sid:84328882; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465772)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/72445144906.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465772/; classtype:trojan-activity;sid:84328872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465773)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0e65d320-97ed-47cb-9ca0-bcd7400824c9/downloads/wrightbus_streetlite_manual.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465773/; classtype:trojan-activity;sid:84328873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465776)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5a9e93e0-0f17-4e5e-a00c-88e3958ec770/downloads/waste_management_in_dubai.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465776/; classtype:trojan-activity;sid:84328876; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465777)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/chevening_scholarship_reference_letter_sample.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465777/; classtype:trojan-activity;sid:84328877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465778)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/14409296375.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465778/; classtype:trojan-activity;sid:84328878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465766)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d128fcda-7fcc-4d89-85b3-e79c54d4414e/downloads/unit_conversion_practice_problems.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465766/; classtype:trojan-activity;sid:84328866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465768)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/11197801286.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465768/; classtype:trojan-activity;sid:84328868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465769)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/50ab7773-f1d2-4be6-a8e2-1065b2477787/downloads/41229957036.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465769/; classtype:trojan-activity;sid:84328869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465771)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/950f7924-fa6b-44be-bda3-22eaf526f43f/downloads/konujidav.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465771/; classtype:trojan-activity;sid:84328871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465760)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/burijuterapudupelirebi.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465760/; classtype:trojan-activity;sid:84328860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465761)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a85f54ee-11f7-4ab3-9970-dabd8f52d583/downloads/vowivovabafases.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465761/; classtype:trojan-activity;sid:84328861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465762)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/acb19439-02ad-48ae-a6e4-8c3bfce04694/downloads/32470708569.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465762/; classtype:trojan-activity;sid:84328862; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465763)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/xikesoxabafubuwepof.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465763/; classtype:trojan-activity;sid:84328863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465764)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/2251478862.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465764/; classtype:trojan-activity;sid:84328864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465765)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9d0d7648-4006-4e9a-bf4e-cd4f5c534844/downloads/socomec_ups_service_manual.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465765/; classtype:trojan-activity;sid:84328865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465757)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/6098867423.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465757/; classtype:trojan-activity;sid:84328857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465758)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2b383d2d-2b5a-4b4f-949f-124c21f71183/downloads/how_to_write_an_introduction_letter_to_an_embassy.pdf"; http_uri; depth:111; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465758/; classtype:trojan-activity;sid:84328858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465755)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/41780010-2245-4f59-96ea-abe2bb04704f/downloads/38265042738.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465755/; classtype:trojan-activity;sid:84328855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465747)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/183feb73-c001-4172-a9c4-8aedcbb9c085/downloads/nosasasoxanuxoxazefuz.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465747/; classtype:trojan-activity;sid:84328847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465749)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/gibekewelodi.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465749/; classtype:trojan-activity;sid:84328849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465752)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/16395777837.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465752/; classtype:trojan-activity;sid:84328852; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465753)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/710760ab-5054-4fd2-86ee-e72953d604bd/downloads/jspdf_autotable_x_position.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465753/; classtype:trojan-activity;sid:84328853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465739)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a0b0ee5f-47ab-407d-8f2e-b86a71eb1b80/downloads/cerere_demisie_fara_preaviz.pdf"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465739/; classtype:trojan-activity;sid:84328839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465740)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/0fde6049-38a2-402e-8604-5a56fc977486/downloads/request_letter_for_construction_bond_refund.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465740/; classtype:trojan-activity;sid:84328840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465741)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cdd5ea6e-1f6b-4417-9fad-928f6d1c8a68/downloads/50_verbes_irreguliers_en_anglais.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465741/; classtype:trojan-activity;sid:84328841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465742)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7a69ed85-566a-4d22-8bd3-47a8a314b3bf/downloads/molecular_mass_of_elements_list.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465742/; classtype:trojan-activity;sid:84328842; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465744)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/69278806631.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465744/; classtype:trojan-activity;sid:84328844; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465735)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e060217f-3d1d-4ed1-921e-8372b49c873f/downloads/nonisenokedevesuxumuk.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465735/; classtype:trojan-activity;sid:84328835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465729)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/mesoduwegotujowokikurixo.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465729/; classtype:trojan-activity;sid:84328829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465731)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2b383d2d-2b5a-4b4f-949f-124c21f71183/downloads/how_to_fill_up_deed_of_sale_of_motor_vehicle.pdf"; http_uri; depth:106; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465731/; classtype:trojan-activity;sid:84328831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465724)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/33d2c907-2bf6-4426-875f-30dcfdd2ea6c/downloads/takeshi_amemiya_advanced_econometrics.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465724/; classtype:trojan-activity;sid:84328824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465725)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/paxakuvenu.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465725/; classtype:trojan-activity;sid:84328825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465715)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/51d0d552-51a2-4187-835e-597cbad426c9/downloads/astm_e2500.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465715/; classtype:trojan-activity;sid:84328815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465716)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/ce6ffbd8-735a-4087-afcd-48ff437b91ba/downloads/16407212514.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465716/; classtype:trojan-activity;sid:84328816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465717)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f2215a6c-0436-4d82-8033-c5d079398259/downloads/mewivisonixapolivifit.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465717/; classtype:trojan-activity;sid:84328817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465718)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5778216d-14df-4dd7-ac4c-aefbb7c07c24/downloads/kugaduvekujewotaz.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465718/; classtype:trojan-activity;sid:84328818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465719)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/tafanavevimewom.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465719/; classtype:trojan-activity;sid:84328819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465721)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/lemowegigusazisalelupo.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465721/; classtype:trojan-activity;sid:84328821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465722)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5add4dbc-ec7d-4010-9077-0d95eef82ba1/downloads/64293794102.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465722/; classtype:trojan-activity;sid:84328822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465723)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a7c970be-6487-407b-ae67-0318aa6bed96/downloads/19932307165.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465723/; classtype:trojan-activity;sid:84328823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465709)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/lowasa.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465709/; classtype:trojan-activity;sid:84328809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465710)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/8014aeaa-17b8-4bcd-a9d7-094ad1ff7644/downloads/19999334835.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465710/; classtype:trojan-activity;sid:84328810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465711)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/921a43a6-1495-4d95-bdb1-69b79162b826/downloads/13397059696.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465711/; classtype:trojan-activity;sid:84328811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465714)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b3cb2fd2-80cf-4497-9966-46f7699e136d/downloads/kovajive.pdf"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465714/; classtype:trojan-activity;sid:84328814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465707)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/49bbfdeb-576f-4f20-b756-96ff9c705013/downloads/96422280236.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465707/; classtype:trojan-activity;sid:84328807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465708)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/c7a293a1-0904-42a6-9de6-afc19e585d66/downloads/imo_dangerous_goods_declaration_example.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465708/; classtype:trojan-activity;sid:84328808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465703)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/bd6582d9-c54a-4b0b-ad89-3fd92efb45aa/downloads/88847399269.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465703/; classtype:trojan-activity;sid:84328803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465704)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cdb9e382-acbe-48dd-9722-c531572d81a1/downloads/pugalisamelifakebage.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465704/; classtype:trojan-activity;sid:84328804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465697)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/89463890604.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465697/; classtype:trojan-activity;sid:84328797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465699)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/lotumajufinunixine.pdf"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465699/; classtype:trojan-activity;sid:84328799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465701)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d9951c46-77aa-4ac5-b843-be02d4be2067/downloads/50826134191.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465701/; classtype:trojan-activity;sid:84328801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465702)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/kasupobuwomubafujos.pdf"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465702/; classtype:trojan-activity;sid:84328802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465691)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7219dffe-e0ab-4b31-b3e7-77acd35b52f5/downloads/jotepebuzixulelomizo.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465691/; classtype:trojan-activity;sid:84328791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465692)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e51c42a2-48a1-43ea-b124-a034de3679a6/downloads/83320615193.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465692/; classtype:trojan-activity;sid:84328792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465693)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/78c14b69-39ed-4d94-8d63-a7b29776e43c/downloads/radix_temperature_controller_x_48_manual.pdf"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465693/; classtype:trojan-activity;sid:84328793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465694)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/24a9af23-a9c8-45b6-80f8-335651f17510/downloads/96094090900.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465694/; classtype:trojan-activity;sid:84328794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465695)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/22a15b49-22b8-4edf-a855-4e76194b4aaf/downloads/97812412729.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465695/; classtype:trojan-activity;sid:84328795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465685)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0c7674b-f7b5-484b-aa64-84014ad9ac8c/downloads/lizaputasu.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465685/; classtype:trojan-activity;sid:84328785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465679)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/boxikijefedajexufesibul.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465679/; classtype:trojan-activity;sid:84328779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465680)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/11012613986.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465680/; classtype:trojan-activity;sid:84328780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465682)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/bucharest_grill_nutrition_information.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465682/; classtype:trojan-activity;sid:84328782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465683)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3844a76d-a274-4a3a-ad7f-2943a29e37b3/downloads/lezopidigusaraten.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465683/; classtype:trojan-activity;sid:84328783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465675)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e9dc005a-39e6-474d-bf2f-ef67b812a261/downloads/guia_para_ingresar_al_bachillerato_conamat.pdf"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465675/; classtype:trojan-activity;sid:84328775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465678)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/robaziromumeborumapix.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465678/; classtype:trojan-activity;sid:84328778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465671)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/52e9408f-c536-4a35-bd81-6078a5dce549/downloads/5252998215.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465671/; classtype:trojan-activity;sid:84328771; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465672)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/36758652154.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465672/; classtype:trojan-activity;sid:84328772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465673)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/82f97436-460c-45aa-bd9b-74a87c48e9b0/downloads/73577237968.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465673/; classtype:trojan-activity;sid:84328773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465657)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/db112521-e536-400b-b453-631e78951ba0/downloads/louison_et_monsieur_moliere_resume.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465657/; classtype:trojan-activity;sid:84328757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465660)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a03fd264-622c-49da-819e-92c49cdd5e2b/downloads/xovifubakuforij.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465660/; classtype:trojan-activity;sid:84328760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465663)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/rupesiduvunimekesozo.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465663/; classtype:trojan-activity;sid:84328763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465664)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3209f3eb-a43c-41d3-a7ba-73b4af438585/downloads/special_forces_knife_techniques.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465664/; classtype:trojan-activity;sid:84328764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465665)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b298ce5b-3c11-48f0-9704-0e059e7cfa1a/downloads/90645579432.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465665/; classtype:trojan-activity;sid:84328765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465666)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7eafcf9d-33bd-4fd4-8489-654d240ab2f3/downloads/6130931006.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465666/; classtype:trojan-activity;sid:84328766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465667)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/e0319bbe-78e1-4446-90fc-2b4b4cc85a3e/downloads/camp_green_lake.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465667/; classtype:trojan-activity;sid:84328767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465668)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/478a916a-56a8-445d-9eb0-b1a280ba537b/downloads/27628335796.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465668/; classtype:trojan-activity;sid:84328768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465655)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/eating_questionnaire-_a_ede-a_scoring.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465655/; classtype:trojan-activity;sid:84328755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465652)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/myer_victor_sewing_machine_manual.pdf"; http_uri; depth:95; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465652/; classtype:trojan-activity;sid:84328752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465647)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/3131d044-1bdb-4fdc-8ed0-764e724b86a8/downloads/jorejujavupu.pdf"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465647/; classtype:trojan-activity;sid:84328747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465648)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/41fa09f3-79bd-43c0-909a-d1a20c3cb7f6/downloads/attestation_sur_l_honneur_de_non_ressources.pdf"; http_uri; depth:105; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465648/; classtype:trojan-activity;sid:84328748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465649)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/eb7f2f0c-e896-4e47-abeb-a05a47b6dcff/downloads/37569138292.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465649/; classtype:trojan-activity;sid:84328749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465630)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f36019eb-f077-446f-b5b6-39b8eacedf97/downloads/98482064700.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465630/; classtype:trojan-activity;sid:84328730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465631)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/83364999300.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465631/; classtype:trojan-activity;sid:84328731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465632)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/records_of_declaration_disbursements_division.pdf"; http_uri; depth:107; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465632/; classtype:trojan-activity;sid:84328732; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465633)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f6084bd9-50ce-4d5f-82c5-bb685cd57a0d/downloads/mdsap_audit_checklist.pdf"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465633/; classtype:trojan-activity;sid:84328733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465635)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/jaziz.pdf"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465635/; classtype:trojan-activity;sid:84328735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465636)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a74441e7-424c-4454-9bc5-28c3682f6c16/downloads/jupifevaperoziput.pdf"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465636/; classtype:trojan-activity;sid:84328736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465637)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f778edfd-e481-47d7-9553-9364d433dcaf/downloads/morningstar_andex_chart_2022.pdf"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465637/; classtype:trojan-activity;sid:84328737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465638)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/cabcb3ce-a861-487f-a172-56f4b47cbc63/downloads/nilefovidigutozezosanuz.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465638/; classtype:trojan-activity;sid:84328738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465640)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/39892598323.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465640/; classtype:trojan-activity;sid:84328740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465641)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/00810c7d-a901-42bd-b2e3-20945a4ad8cb/downloads/wimorawezabizu.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465641/; classtype:trojan-activity;sid:84328741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465642)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/552d21dd-b338-4bf6-8541-a1e81cff5ed8/downloads/viduwe.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465642/; classtype:trojan-activity;sid:84328742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465643)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a1b48068-f219-4487-b633-0ea4f25dfa5f/downloads/57025089155.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465643/; classtype:trojan-activity;sid:84328743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465625)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/00490ec0-0f24-4e25-91e3-8e5bedec5e60/downloads/woxudinawonetunogidubi.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465625/; classtype:trojan-activity;sid:84328725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465626)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2224247e-29ce-4f8d-b838-abfcbdf269c0/downloads/16984198490.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465626/; classtype:trojan-activity;sid:84328726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465622)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/33bb6cfc-294d-4317-8afb-5d34ed60ffe6/downloads/20222176664.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465622/; classtype:trojan-activity;sid:84328722; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465618)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/72454635563.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465618/; classtype:trojan-activity;sid:84328718; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465621)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/pisaxafubavofi.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465621/; classtype:trojan-activity;sid:84328721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465613)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/catastrophic_disaster_area_property_inspection_report.pdf"; http_uri; depth:115; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465613/; classtype:trojan-activity;sid:84328713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465615)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/citadel_document_solutions_lawsuit.pdf"; http_uri; depth:96; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465615/; classtype:trojan-activity;sid:84328715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465607)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/fumaxogufav.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465607/; classtype:trojan-activity;sid:84328707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465610)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/kigepobesewizijipakusafal.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465610/; classtype:trojan-activity;sid:84328710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465600)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/f7748e26-2d27-4aa6-89fb-b263de90f421/downloads/tabuas_sumerias_traduzidas.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465600/; classtype:trojan-activity;sid:84328700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465603)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/17054728623.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465603/; classtype:trojan-activity;sid:84328703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465604)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/678cd2ef-32fa-4621-9c35-e4f34096b4ea/downloads/airbus_cml.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465604/; classtype:trojan-activity;sid:84328704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465605)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/4402180a-d4b9-4c2e-b606-353fcb7d5a18/downloads/3730146334.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465605/; classtype:trojan-activity;sid:84328705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465606)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/36770579775.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465606/; classtype:trojan-activity;sid:84328706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465594)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a0b0ee5f-47ab-407d-8f2e-b86a71eb1b80/downloads/luxodebapiruwuneragomugef.pdf"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465594/; classtype:trojan-activity;sid:84328694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465598)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/87554570559.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465598/; classtype:trojan-activity;sid:84328698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465599)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/fff11fc4-91ee-4c26-ab94-6b71630d2bb1/downloads/resignation_letter_sample_for_bpo_company.pdf"; http_uri; depth:103; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465599/; classtype:trojan-activity;sid:84328699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465586)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5102464b-373a-4f87-829a-69343208c6ac/downloads/84675915071.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465586/; classtype:trojan-activity;sid:84328686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465588)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/17a8127f-1a20-4f1c-a234-ba1b1a8873f5/downloads/90572854820.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465588/; classtype:trojan-activity;sid:84328688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465589)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/78534035283.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465589/; classtype:trojan-activity;sid:84328689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465590)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/wudofe.pdf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465590/; classtype:trojan-activity;sid:84328690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465592)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/glassman_high_voltage_series_eq_manual.pdf"; http_uri; depth:100; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465592/; classtype:trojan-activity;sid:84328692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465593)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/57653563602.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465593/; classtype:trojan-activity;sid:84328693; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465585)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/343166b6-b38d-45a3-a768-806295759a1d/downloads/vatemunubiserotogurozem.pdf"; http_uri; depth:85; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465585/; classtype:trojan-activity;sid:84328685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465582)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/simamutozudolejezeze.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465582/; classtype:trojan-activity;sid:84328682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465583)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/a8a7b266-73df-492a-af50-f7d9f90e0e6d/downloads/salesforce_community_developer_guide.pdf"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465583/; classtype:trojan-activity;sid:84328683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465572)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/047c717c-7bd8-4cec-b09f-8a9648ff740c/downloads/zepojekowokevi.pdf"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465572/; classtype:trojan-activity;sid:84328672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465573)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/2cd8ef37-3f02-4d83-b132-5400b0b21173/downloads/can_sins_be_forgiven_in_hinduism.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465573/; classtype:trojan-activity;sid:84328673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465574)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/9390f2de-e8f5-48e5-8f1b-3aa5affb2913/downloads/ra_to_surface_finish.pdf"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465574/; classtype:trojan-activity;sid:84328674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465577)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/holman_enterprises_annual_report.pdf"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465577/; classtype:trojan-activity;sid:84328677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465551)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/chiller_factory_acceptance_test_checklist_template.pdf"; http_uri; depth:112; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465551/; classtype:trojan-activity;sid:84328651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465552)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7913e2d4-0776-44f0-af91-53eb35e22f50/downloads/broken_sous_ta_peau_2_ekladata.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465552/; classtype:trojan-activity;sid:84328652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465553)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d37a9b24-bc42-4cb1-ab3b-3d1b21b01aec/downloads/lujipipatemajipurozurile.pdf"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465553/; classtype:trojan-activity;sid:84328653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465554)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/20a6346a-1701-43f8-be7d-6426912a09c2/downloads/sottoindicato_o_sotto_indicato_treccani.pdf"; http_uri; depth:101; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465554/; classtype:trojan-activity;sid:84328654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465555)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/62fde782-5483-4905-a6da-12e04ab1250b/downloads/38559734752.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465555/; classtype:trojan-activity;sid:84328655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465556)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/dfa50dfd-b675-4866-b542-d79684ac1045/downloads/28769720040.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465556/; classtype:trojan-activity;sid:84328656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465557)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/formato_st-4_imss_para_imprimir.pdf"; http_uri; depth:93; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465557/; classtype:trojan-activity;sid:84328657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465558)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/adfd48e6-08dc-41dd-a2a1-45489e329c75/downloads/attestation_de_non_affiliation_cnas.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465558/; classtype:trojan-activity;sid:84328658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465559)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/tosca_automation_specialist_level_2_certification_questions_.pdf"; http_uri; depth:122; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465559/; classtype:trojan-activity;sid:84328659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465560)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/aabc5eee-c1de-4817-92b9-f9e17352a5c7/downloads/how_to_factory_reset_verifone_mx915.pdf"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465560/; classtype:trojan-activity;sid:84328660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465561)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/5e489076-b026-43ca-95da-8c6fe49f6d00/downloads/frm_part_2_schweser_quicksheet.pdf"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465561/; classtype:trojan-activity;sid:84328661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465562)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/incucyte_s3_user_guide.pdf"; http_uri; depth:84; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465562/; classtype:trojan-activity;sid:84328662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465563)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/671d8571-de15-47bb-8cd8-b624751dbe0e/downloads/lean_visual_management_board_examples.pdf"; http_uri; depth:99; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465563/; classtype:trojan-activity;sid:84328663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465564)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/98e3e4d1-65d1-414f-a2f4-24701527da4a/downloads/1567746722.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465564/; classtype:trojan-activity;sid:84328664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465565)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/b6875802-d83d-45fa-a01c-dd9f30c53739/downloads/xujudodavudejeb.pdf"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465565/; classtype:trojan-activity;sid:84328665; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465566)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/59062828-6c5e-403a-ae88-14483438a1b6/downloads/situation_denonciation_coupe_ou_ancre_exercices_corriges.pdf"; http_uri; depth:118; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465566/; classtype:trojan-activity;sid:84328666; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465567)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/7c4463e3-109c-48af-b9be-98e22cdf2116/downloads/wikuzidip.pdf"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465567/; classtype:trojan-activity;sid:84328667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465568)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/d5e97205-d745-471d-94c2-4bc94f943a29/downloads/87185669225.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465568/; classtype:trojan-activity;sid:84328668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465569)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/abfe7a1b-25f4-4ff2-8fb5-155a264c8ce4/downloads/likibixeve.pdf"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465569/; classtype:trojan-activity;sid:84328669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465570)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/356923eb-d23c-4b0c-808e-e9b58fb291da/downloads/exsilentia_4._0_user_guide.pdf"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465570/; classtype:trojan-activity;sid:84328670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465571)"; flow:established,from_client; content:"GET"; http_method; content:"/blobby/go/586b3ef6-c9db-4d1a-a9eb-303f942e21fa/downloads/55359157176.pdf"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"img1.wsimg.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_05; reference:url, urlhaus.abuse.ch/url/3465571/; classtype:trojan-activity;sid:84328671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3465210)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1kjjvh1muhjrkrzbajjlzjfawyi0zvxc1"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_04; reference:url, urlhaus.abuse.ch/url/3465210/; classtype:trojan-activity;sid:84328310; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3464706)"; flow:established,from_client; content:"GET"; http_method; content:"/down/wupiao.3987.com.rar"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"forspeed.onlinedown.net"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_03_03; reference:url, urlhaus.abuse.ch/url/3464706/; classtype:trojan-activity;sid:84327806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463506)"; flow:established,from_client; content:"GET"; http_method; content:"/wp/verify/index.html"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"www.pointtohealth.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463506/; classtype:trojan-activity;sid:84326606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463509)"; flow:established,from_client; content:"GET"; http_method; content:"/up/"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"blessdayservices.org"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463509/; classtype:trojan-activity;sid:84326609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463513)"; flow:established,from_client; content:"GET"; http_method; content:"/v/"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"jessespridecharters.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463513/; classtype:trojan-activity;sid:84326613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463490)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"cambodiatouristservice.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463490/; classtype:trojan-activity;sid:84326590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463480)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"admin.gestroom.it"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463480/; classtype:trojan-activity;sid:84326580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463481)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"test.peperoncinochepassione.it"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463481/; classtype:trojan-activity;sid:84326581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463482)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"first-security-verden.de"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463482/; classtype:trojan-activity;sid:84326582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463483)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"gestroom.it"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463483/; classtype:trojan-activity;sid:84326583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463470)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"www.first-security-verden.de"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463470/; classtype:trojan-activity;sid:84326570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463472)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"zamilgroups.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463472/; classtype:trojan-activity;sid:84326572; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463459)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"www.website.mypetapp.co.za"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463459/; classtype:trojan-activity;sid:84326559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463446)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"www.bratusferramentas.grupomoltz.com.br"; http_host; depth:39; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463446/; classtype:trojan-activity;sid:84326546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463437)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"website.mypetapp.co.za"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463437/; classtype:trojan-activity;sid:84326537; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463443)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"horno-rafelet.es"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463443/; classtype:trojan-activity;sid:84326543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463426)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"bmdcompany.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463426/; classtype:trojan-activity;sid:84326526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463430)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"www.zamilgroups.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463430/; classtype:trojan-activity;sid:84326530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463422)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"www.test.peperoncinochepassione.it"; http_host; depth:34; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463422/; classtype:trojan-activity;sid:84326522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463367)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"82.146.62.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463367/; classtype:trojan-activity;sid:84326467; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3463364)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"82.146.62.232"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_03_02; reference:url, urlhaus.abuse.ch/url/3463364/; classtype:trojan-activity;sid:84326464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461771)"; flow:established,from_client; content:"GET"; http_method; content:"/new/plugin2.plg"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461771/; classtype:trojan-activity;sid:84324871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461769)"; flow:established,from_client; content:"GET"; http_method; content:"/new/plugin1.plg"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461769/; classtype:trojan-activity;sid:84324869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461770)"; flow:established,from_client; content:"GET"; http_method; content:"/new/plugin2.dll"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461770/; classtype:trojan-activity;sid:84324870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461768)"; flow:established,from_client; content:"GET"; http_method; content:"/new/plugin3.plg"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461768/; classtype:trojan-activity;sid:84324868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461767)"; flow:established,from_client; content:"GET"; http_method; content:"/new/plugin1.dll"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461767/; classtype:trojan-activity;sid:84324867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461763)"; flow:established,from_client; content:"GET"; http_method; content:"/new/plugin3.dll"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461763/; classtype:trojan-activity;sid:84324863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461663)"; flow:established,from_client; content:"GET"; http_method; content:"/robertdavidgraham/masscan/zip/refs/heads/master"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461663/; classtype:trojan-activity;sid:84324763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3461661)"; flow:established,from_client; content:"GET"; http_method; content:"/robertdavidgraham/masscan/archive/refs/heads/master.zip"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_03_01; reference:url, urlhaus.abuse.ch/url/3461661/; classtype:trojan-activity;sid:84324761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3460167)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"112.4.110.28"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_02_27; reference:url, urlhaus.abuse.ch/url/3460167/; classtype:trojan-activity;sid:84323267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3460149)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.89.62.19"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_02_27; reference:url, urlhaus.abuse.ch/url/3460149/; classtype:trojan-activity;sid:84323249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3460000)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1uxmu02r04iaslsrsh9quahzfsvq3tozm"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_02_27; reference:url, urlhaus.abuse.ch/url/3460000/; classtype:trojan-activity;sid:84323100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3452200)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"95.62.202.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_25; reference:url, urlhaus.abuse.ch/url/3452200/; classtype:trojan-activity;sid:84315300; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3450176)"; flow:established,from_client; content:"GET"; http_method; content:"/temp/putty.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"book.rollingvideogames.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_02_23; reference:url, urlhaus.abuse.ch/url/3450176/; classtype:trojan-activity;sid:84313276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3450147)"; flow:established,from_client; content:"GET"; http_method; content:"/loveryajenja/lwafmwoafmw11/raw/refs/heads/main/install.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_23; reference:url, urlhaus.abuse.ch/url/3450147/; classtype:trojan-activity;sid:84313247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3450048)"; flow:established,from_client; content:"GET"; http_method; content:"/continue/45.ps1"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"www.benshamcentre.co.uk"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2025_02_23; reference:url, urlhaus.abuse.ch/url/3450048/; classtype:trojan-activity;sid:84313148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447466)"; flow:established,from_client; content:"GET"; http_method; content:"/laurenxss/36b18f37163aaa04654bd21e98d1b842/raw/dca82ba88fae8788a48ffb529f9610a0cc209781/x"; http_uri; depth:90; isdataat:!1,relative; nocase; content:"gist.githubusercontent.com"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447466/; classtype:trojan-activity;sid:84310566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447458)"; flow:established,from_client; content:"GET"; http_method; content:"/sena1.png"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"leindisncieamrocea-1341831283.cos.sa-saopaulo.myqcloud.com"; http_host; depth:58; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447458/; classtype:trojan-activity;sid:84310558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447456)"; flow:established,from_client; content:"GET"; http_method; content:"/manga1.png"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"leindisncieamrocea-1341831283.cos.sa-saopaulo.myqcloud.com"; http_host; depth:58; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447456/; classtype:trojan-activity;sid:84310556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3447457)"; flow:established,from_client; content:"GET"; http_method; content:"/colheita1.png"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"leindisncieamrocea-1341831283.cos.sa-saopaulo.myqcloud.com"; http_host; depth:58; isdataat:!1,relative; metadata:created_at 2025_02_21; reference:url, urlhaus.abuse.ch/url/3447457/; classtype:trojan-activity;sid:84310557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3446661)"; flow:established,from_client; content:"GET"; http_method; content:"/img001.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3446661/; classtype:trojan-activity;sid:84309761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3446653)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"116.171.106.3"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3446653/; classtype:trojan-activity;sid:84309753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3446649)"; flow:established,from_client; content:"GET"; http_method; content:"/info.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3446649/; classtype:trojan-activity;sid:84309749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445854)"; flow:established,from_client; content:"GET"; http_method; content:"/coracion1.png"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"vaamsmgfreocmroe-1342087530.cos.sa-saopaulo.myqcloud.com"; http_host; depth:56; isdataat:!1,relative; metadata:created_at 2025_02_20; reference:url, urlhaus.abuse.ch/url/3445854/; classtype:trojan-activity;sid:84308954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445431)"; flow:established,from_client; content:"GET"; http_method; content:"/data/df4a3196-accc-423a-a43b-6768f1aafd3e.pdf"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"hotelembuguacu.blob.core.windows.net"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2025_02_19; reference:url, urlhaus.abuse.ch/url/3445431/; classtype:trojan-activity;sid:84308531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445438)"; flow:established,from_client; content:"GET"; http_method; content:"/data/f6416fd0-71f3-45de-8c79-3d0e7281f124.pdf"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"hotelembuguacu.blob.core.windows.net"; http_host; depth:36; isdataat:!1,relative; metadata:created_at 2025_02_19; reference:url, urlhaus.abuse.ch/url/3445438/; classtype:trojan-activity;sid:84308538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3445304)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.83.158.46"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_02_19; reference:url, urlhaus.abuse.ch/url/3445304/; classtype:trojan-activity;sid:84308404; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3444507)"; flow:established,from_client; content:"GET"; http_method; content:"/leinchchanceleinch/jik/refs/heads/main/d.msi"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_02_18; reference:url, urlhaus.abuse.ch/url/3444507/; classtype:trojan-activity;sid:84307607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3444267)"; flow:established,from_client; content:"GET"; http_method; content:"/leinchchanceleinch/jik/raw/refs/heads/main/d.msi"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_18; reference:url, urlhaus.abuse.ch/url/3444267/; classtype:trojan-activity;sid:84307367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443354)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.248.3.202.ll.sta.mana.pf"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443354/; classtype:trojan-activity;sid:84306454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443353)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"99-118-215-24.lightspeed.irvnca.sbcglobal.net"; http_host; depth:45; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443353/; classtype:trojan-activity;sid:84306453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3443350)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"host-95-230-215-65.business.telecomitalia.it"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3443350/; classtype:trojan-activity;sid:84306450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442712)"; flow:established,from_client; content:"GET"; http_method; content:"/output0/client/cabalmain.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"168.138.162.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3442712/; classtype:trojan-activity;sid:84305812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442701)"; flow:established,from_client; content:"GET"; http_method; content:"/output0/client/cabal.exe"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"168.138.162.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3442701/; classtype:trojan-activity;sid:84305801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442616)"; flow:established,from_client; content:"GET"; http_method; content:"/output/client/cabalmain.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"168.138.162.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_17; reference:url, urlhaus.abuse.ch/url/3442616/; classtype:trojan-activity;sid:84305716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442198)"; flow:established,from_client; content:"GET"; http_method; content:"/xxxx"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"47.89.173.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442198/; classtype:trojan-activity;sid:84305298; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442196)"; flow:established,from_client; content:"GET"; http_method; content:"/ffff"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"47.89.173.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442196/; classtype:trojan-activity;sid:84305296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442197)"; flow:established,from_client; content:"GET"; http_method; content:"/asdf"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"47.89.173.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442197/; classtype:trojan-activity;sid:84305297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3442195)"; flow:established,from_client; content:"GET"; http_method; content:"/libmod_hellocpp_42.so"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"47.89.173.214"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3442195/; classtype:trojan-activity;sid:84305295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3441724)"; flow:established,from_client; content:"GET"; http_method; content:"/output/client/cabal.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"168.138.162.78"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_16; reference:url, urlhaus.abuse.ch/url/3441724/; classtype:trojan-activity;sid:84304824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440974)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l/rls"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440974/; classtype:trojan-activity;sid:84304074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440971)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64/rls"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440971/; classtype:trojan-activity;sid:84304071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440972)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64/rld"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440972/; classtype:trojan-activity;sid:84304072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440969)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l/kthreadrm"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440969/; classtype:trojan-activity;sid:84304069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440970)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64/kthreadrm"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440970/; classtype:trojan-activity;sid:84304070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440930)"; flow:established,from_client; content:"GET"; http_method; content:"/aarch64"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440930/; classtype:trojan-activity;sid:84304030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440931)"; flow:established,from_client; content:"GET"; http_method; content:"/arm7"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440931/; classtype:trojan-activity;sid:84304031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440932)"; flow:established,from_client; content:"GET"; http_method; content:"/x86_64"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440932/; classtype:trojan-activity;sid:84304032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3440934)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"198.166.72.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_15; reference:url, urlhaus.abuse.ch/url/3440934/; classtype:trojan-activity;sid:84304034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3439829)"; flow:established,from_client; content:"GET"; http_method; content:"/umbrella/"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"acusense.ae"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_02_14; reference:url, urlhaus.abuse.ch/url/3439829/; classtype:trojan-activity;sid:84302929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3438591)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.11.36.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_13; reference:url, urlhaus.abuse.ch/url/3438591/; classtype:trojan-activity;sid:84301691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3438594)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.11.36.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_13; reference:url, urlhaus.abuse.ch/url/3438594/; classtype:trojan-activity;sid:84301694; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3435170)"; flow:established,from_client; content:"GET"; http_method; content:"/neo23x0/signature-base/archive/master.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_02_10; reference:url, urlhaus.abuse.ch/url/3435170/; classtype:trojan-activity;sid:84298270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3435043)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"twitch.tj"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2025_02_10; reference:url, urlhaus.abuse.ch/url/3435043/; classtype:trojan-activity;sid:84298143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3433357)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"114.31.8.22"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_02_09; reference:url, urlhaus.abuse.ch/url/3433357/; classtype:trojan-activity;sid:84296457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431851)"; flow:established,from_client; content:"GET"; http_method; content:"/test/cgi-bin/mr_bean/all_bean"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"upchemicals.co.in"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431851/; classtype:trojan-activity;sid:84294951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431850)"; flow:established,from_client; content:"GET"; http_method; content:"/test/cgi-bin/mr_bean/pure_bean"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"upchemicals.co.in"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431850/; classtype:trojan-activity;sid:84294950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431687)"; flow:established,from_client; content:"GET"; http_method; content:"/bljysvhw/info.zip"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431687/; classtype:trojan-activity;sid:84294787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3431686)"; flow:established,from_client; content:"GET"; http_method; content:"/bljysvhw/img001.exe"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"200.14.250.72"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_08; reference:url, urlhaus.abuse.ch/url/3431686/; classtype:trojan-activity;sid:84294786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3429885)"; flow:established,from_client; content:"GET"; http_method; content:"/1/test.jpg"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"ofice365.github.io"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2025_02_06; reference:url, urlhaus.abuse.ch/url/3429885/; classtype:trojan-activity;sid:84292985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3429793)"; flow:established,from_client; content:"GET"; http_method; content:"/download/static/files/bootstrappernew.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"d2314eac.solaraweb-alj.pages.dev"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_02_06; reference:url, urlhaus.abuse.ch/url/3429793/; classtype:trojan-activity;sid:84292893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3429312)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.160.234.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_05; reference:url, urlhaus.abuse.ch/url/3429312/; classtype:trojan-activity;sid:84292412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3424485)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.147.196.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_02_02; reference:url, urlhaus.abuse.ch/url/3424485/; classtype:trojan-activity;sid:84287585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3424483)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.175.139.20"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_02; reference:url, urlhaus.abuse.ch/url/3424483/; classtype:trojan-activity;sid:84287583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423045)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.70.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423045/; classtype:trojan-activity;sid:84286145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423046)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.70.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423046/; classtype:trojan-activity;sid:84286146; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423047)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.70.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423047/; classtype:trojan-activity;sid:84286147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3423050)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.70.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_02_01; reference:url, urlhaus.abuse.ch/url/3423050/; classtype:trojan-activity;sid:84286150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3421183)"; flow:established,from_client; content:"GET"; http_method; content:"/xsh/xsh.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"101.126.11.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_31; reference:url, urlhaus.abuse.ch/url/3421183/; classtype:trojan-activity;sid:84284283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3421020)"; flow:established,from_client; content:"GET"; http_method; content:"/ftp/emmetprod.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"141.147.43.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_31; reference:url, urlhaus.abuse.ch/url/3421020/; classtype:trojan-activity;sid:84284120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3420564)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.70.63"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3420564/; classtype:trojan-activity;sid:84283664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419570)"; flow:established,from_client; content:"GET"; http_method; content:"/grozniy1/folder/raw/refs/heads/main/444.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419570/; classtype:trojan-activity;sid:84282670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419477)"; flow:established,from_client; content:"GET"; http_method; content:"/xevioo/xeviohub/raw/refs/heads/main/critscript.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419477/; classtype:trojan-activity;sid:84282577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3419368)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/17793058/lg246dre.txt"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_30; reference:url, urlhaus.abuse.ch/url/3419368/; classtype:trojan-activity;sid:84282468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3418042)"; flow:established,from_client; content:"GET"; http_method; content:"/cab/launcherloader.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"www.newkey.co.kr"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_01_29; reference:url, urlhaus.abuse.ch/url/3418042/; classtype:trojan-activity;sid:84281142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3417840)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"182.109.0.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_28; reference:url, urlhaus.abuse.ch/url/3417840/; classtype:trojan-activity;sid:84280940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3417095)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1t9mwfr1azhmksosp19tomch5dyi3hb2n"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2025_01_28; reference:url, urlhaus.abuse.ch/url/3417095/; classtype:trojan-activity;sid:84280195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3415209)"; flow:established,from_client; content:"GET"; http_method; content:"/loginanticheat.dll"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"43.226.39.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_26; reference:url, urlhaus.abuse.ch/url/3415209/; classtype:trojan-activity;sid:84278309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3415207)"; flow:established,from_client; content:"GET"; http_method; content:"/loginanticheat4.dll"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"43.226.39.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_26; reference:url, urlhaus.abuse.ch/url/3415207/; classtype:trojan-activity;sid:84278307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3412918)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"119.206.216.132"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_24; reference:url, urlhaus.abuse.ch/url/3412918/; classtype:trojan-activity;sid:84276018; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3410864)"; flow:established,from_client; content:"GET"; http_method; content:"/blackhatethicalhacking/fud/blob/master/access.exe|3f|raw=true"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_23; reference:url, urlhaus.abuse.ch/url/3410864/; classtype:trojan-activity;sid:84273964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3410865)"; flow:established,from_client; content:"GET"; http_method; content:"/blackhatethicalhacking/fud/raw/refs/heads/master/access.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_23; reference:url, urlhaus.abuse.ch/url/3410865/; classtype:trojan-activity;sid:84273965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3410375)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.11.36.4"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_22; reference:url, urlhaus.abuse.ch/url/3410375/; classtype:trojan-activity;sid:84273475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3409838)"; flow:established,from_client; content:"GET"; http_method; content:"/blackhatethicalhacking/fud/refs/heads/master/access.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_22; reference:url, urlhaus.abuse.ch/url/3409838/; classtype:trojan-activity;sid:84272938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3406818)"; flow:established,from_client; content:"GET"; http_method; content:"/%eb%a7%ac%ec%9b%a8%ec%96%b4.hta"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"hobobot.net"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_20; reference:url, urlhaus.abuse.ch/url/3406818/; classtype:trojan-activity;sid:84269918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3406822)"; flow:established,from_client; content:"GET"; http_method; content:"/%eb%b9%8c%ec%96%b4%20%eb%a8%b9%ec%9d%84.hta"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"hobobot.net"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_20; reference:url, urlhaus.abuse.ch/url/3406822/; classtype:trojan-activity;sid:84269922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405330)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"182.109.0.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405330/; classtype:trojan-activity;sid:84268430; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405320)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.66.30.68"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405320/; classtype:trojan-activity;sid:84268420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405323)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.66.30.68"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405323/; classtype:trojan-activity;sid:84268423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405324)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.66.30.68"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405324/; classtype:trojan-activity;sid:84268424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405319)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.66.30.68"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405319/; classtype:trojan-activity;sid:84268419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3405120)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.20.19.72"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_18; reference:url, urlhaus.abuse.ch/url/3405120/; classtype:trojan-activity;sid:84268220; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3403380)"; flow:established,from_client; content:"GET"; http_method; content:"/lehila05/pdc/refs/heads/main/payload.bin"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_17; reference:url, urlhaus.abuse.ch/url/3403380/; classtype:trojan-activity;sid:84266480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3402741)"; flow:established,from_client; content:"GET"; http_method; content:"/adobepdf-reader/pdf-reader/raw/refs/heads/main/pdf%20reader.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_16; reference:url, urlhaus.abuse.ch/url/3402741/; classtype:trojan-activity;sid:84265841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3402154)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.88.6.203"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2025_01_16; reference:url, urlhaus.abuse.ch/url/3402154/; classtype:trojan-activity;sid:84265254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3401644)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/wpr-addons/forms/code1.png"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"107.180.89.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_15; reference:url, urlhaus.abuse.ch/url/3401644/; classtype:trojan-activity;sid:84264744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3399396)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"115.178.100.190"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_13; reference:url, urlhaus.abuse.ch/url/3399396/; classtype:trojan-activity;sid:84262496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3398629)"; flow:established,from_client; content:"GET"; http_method; content:"/ox2fa/justnow/refs/heads/main/1.sh"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_13; reference:url, urlhaus.abuse.ch/url/3398629/; classtype:trojan-activity;sid:84261729; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3397531)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.168.227.130"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2025_01_11; reference:url, urlhaus.abuse.ch/url/3397531/; classtype:trojan-activity;sid:84260631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3395055)"; flow:established,from_client; content:"GET"; http_method; content:"/arvendrachhonkar/todo/releases/download/macosandwindows/install_setup_v1.2.0.dmg"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_09; reference:url, urlhaus.abuse.ch/url/3395055/; classtype:trojan-activity;sid:84258155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3394507)"; flow:established,from_client; content:"GET"; http_method; content:"/trismagi/daemon/raw/main/watchdog"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_09; reference:url, urlhaus.abuse.ch/url/3394507/; classtype:trojan-activity;sid:84257607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3394121)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"62.56.225.99"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3394121/; classtype:trojan-activity;sid:84257221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3394115)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"62.56.225.99"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3394115/; classtype:trojan-activity;sid:84257215; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3393662)"; flow:established,from_client; content:"GET"; http_method; content:"/roukistl/ud/refs/heads/main/ud.bat"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3393662/; classtype:trojan-activity;sid:84256762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3393596)"; flow:established,from_client; content:"GET"; http_method; content:"/thomson101/xhp/releases/download/release/steanings.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_08; reference:url, urlhaus.abuse.ch/url/3393596/; classtype:trojan-activity;sid:84256696; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3393047)"; flow:established,from_client; content:"GET"; http_method; content:"/thomson101/xhp/releases/download/release/steanings.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_07; reference:url, urlhaus.abuse.ch/url/3393047/; classtype:trojan-activity;sid:84256147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3389403)"; flow:established,from_client; content:"GET"; http_method; content:"/ngrokc/ctc/raw/main/ctc64.dll"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3389403/; classtype:trojan-activity;sid:84252503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3389404)"; flow:established,from_client; content:"GET"; http_method; content:"/ngrokc/ctc/main/ctc64.dll"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3389404/; classtype:trojan-activity;sid:84252504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3388858)"; flow:established,from_client; content:"GET"; http_method; content:"/download/static/files/solara.dir.zip"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"c0e5b87c.solaraweb-alj.pages.dev"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2025_01_04; reference:url, urlhaus.abuse.ch/url/3388858/; classtype:trojan-activity;sid:84251958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386507)"; flow:established,from_client; content:"GET"; http_method; content:"/file-32bit.elf"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386507/; classtype:trojan-activity;sid:84249607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386508)"; flow:established,from_client; content:"GET"; http_method; content:"/file.elf"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386508/; classtype:trojan-activity;sid:84249608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386509)"; flow:established,from_client; content:"GET"; http_method; content:"/file-arm.elf"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386509/; classtype:trojan-activity;sid:84249609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3386510)"; flow:established,from_client; content:"GET"; http_method; content:"/file-64bit.elf"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"34.45.47.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2025_01_02; reference:url, urlhaus.abuse.ch/url/3386510/; classtype:trojan-activity;sid:84249610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3385167)"; flow:established,from_client; content:"GET"; http_method; content:"/soft_hair/ultravnc.ini"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"support.clz.kr"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2025_01_01; reference:url, urlhaus.abuse.ch/url/3385167/; classtype:trojan-activity;sid:84248267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3378974)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.142.63.8"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_28; reference:url, urlhaus.abuse.ch/url/3378974/; classtype:trojan-activity;sid:84242074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373504)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"14.0.204.188"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_23; reference:url, urlhaus.abuse.ch/url/3373504/; classtype:trojan-activity;sid:84236604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373036)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.53.164.90"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3373036/; classtype:trojan-activity;sid:84236136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373040)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.170.113.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3373040/; classtype:trojan-activity;sid:84236140; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3373017)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.138.107.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3373017/; classtype:trojan-activity;sid:84236117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372979)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.93.83.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372979/; classtype:trojan-activity;sid:84236079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372968)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"212.85.166.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372968/; classtype:trojan-activity;sid:84236068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372953)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"47.49.114.179"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372953/; classtype:trojan-activity;sid:84236053; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372956)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.129.177.162"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372956/; classtype:trojan-activity;sid:84236056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372941)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.12.157.98"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372941/; classtype:trojan-activity;sid:84236041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372903)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"111.74.21.155"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372903/; classtype:trojan-activity;sid:84236003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372902)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372902/; classtype:trojan-activity;sid:84236002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372900)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372900/; classtype:trojan-activity;sid:84236000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372891)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372891/; classtype:trojan-activity;sid:84235991; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372892)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372892/; classtype:trojan-activity;sid:84235992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372893)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372893/; classtype:trojan-activity;sid:84235993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372896)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372896/; classtype:trojan-activity;sid:84235996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372898)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372898/; classtype:trojan-activity;sid:84235998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372883)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372883/; classtype:trojan-activity;sid:84235983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372884)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372884/; classtype:trojan-activity;sid:84235984; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372885)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372885/; classtype:trojan-activity;sid:84235985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372886)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372886/; classtype:trojan-activity;sid:84235986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372887)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.141.62.238"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372887/; classtype:trojan-activity;sid:84235987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372890)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372890/; classtype:trojan-activity;sid:84235990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372876)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.247.101.63"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372876/; classtype:trojan-activity;sid:84235976; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372878)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372878/; classtype:trojan-activity;sid:84235978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372879)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372879/; classtype:trojan-activity;sid:84235979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372880)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"117.240.155.245"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372880/; classtype:trojan-activity;sid:84235980; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372704)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372704/; classtype:trojan-activity;sid:84235804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372705)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372705/; classtype:trojan-activity;sid:84235805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372684)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372684/; classtype:trojan-activity;sid:84235784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372654)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372654/; classtype:trojan-activity;sid:84235754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372651)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372651/; classtype:trojan-activity;sid:84235751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372639)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372639/; classtype:trojan-activity;sid:84235739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3372615)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"195.34.102.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_22; reference:url, urlhaus.abuse.ch/url/3372615/; classtype:trojan-activity;sid:84235715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356912)"; flow:established,from_client; content:"GET"; http_method; content:"/ef/ef.bin"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"www.tdejb.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356912/; classtype:trojan-activity;sid:84220012; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356911)"; flow:established,from_client; content:"GET"; http_method; content:"/ef/skifterne.sea"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"www.tdejb.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356911/; classtype:trojan-activity;sid:84220011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356909)"; flow:established,from_client; content:"GET"; http_method; content:"/ef/ef.vbs"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"www.astenterprises.com.pk"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356909/; classtype:trojan-activity;sid:84220009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356803)"; flow:established,from_client; content:"GET"; http_method; content:"/yn5og-40i6-9gu-9hjf.html"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"bj5y6-0f-9h4-9fgg4-1324992141.cos.ap-bangkok.myqcloud.com"; http_host; depth:57; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356803/; classtype:trojan-activity;sid:84219903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356768)"; flow:established,from_client; content:"GET"; http_method; content:"/futon"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"weco2.oss-me-east-1.aliyuncs.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356768/; classtype:trojan-activity;sid:84219868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356761)"; flow:established,from_client; content:"GET"; http_method; content:"/smiple_4yue"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"weco2.oss-me-east-1.aliyuncs.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356761/; classtype:trojan-activity;sid:84219861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356758)"; flow:established,from_client; content:"GET"; http_method; content:"/36hg-04ik6-9j4-9h5.html"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"f3i5-0g49bgn-3h95-1324992141.cos.ap-jakarta.myqcloud.com"; http_host; depth:56; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356758/; classtype:trojan-activity;sid:84219858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356750)"; flow:established,from_client; content:"GET"; http_method; content:"/35-0350gh9v-39yh5g.html"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"j-0-09g-9bh-h-ggf-1324992141.cos.ap-bangkok.myqcloud.com"; http_host; depth:56; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356750/; classtype:trojan-activity;sid:84219850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356162)"; flow:established,from_client; content:"GET"; http_method; content:"/xevioo/xeviohub/refs/heads/main/critscript.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356162/; classtype:trojan-activity;sid:84219262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356134)"; flow:established,from_client; content:"GET"; http_method; content:"/pr0xylife/asyncrat/refs/heads/main/asyncrat_09.02.2022.txt"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356134/; classtype:trojan-activity;sid:84219234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356133)"; flow:established,from_client; content:"GET"; http_method; content:"/grozniy1/folder/refs/heads/main/444.exe"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356133/; classtype:trojan-activity;sid:84219233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3356118)"; flow:established,from_client; content:"GET"; http_method; content:"/deroxs/powerrat-leak/refs/heads/main/powerrat.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_18; reference:url, urlhaus.abuse.ch/url/3356118/; classtype:trojan-activity;sid:84219218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353957)"; flow:established,from_client; content:"GET"; http_method; content:"/rookievip/xx/main/loader.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353957/; classtype:trojan-activity;sid:84217057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353372)"; flow:established,from_client; content:"GET"; http_method; content:"/fengjixuchui/cve-2022-26810/refs/heads/main/shellcode.bin"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353372/; classtype:trojan-activity;sid:84216472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353348)"; flow:established,from_client; content:"GET"; http_method; content:"/deroxs/powerrat-leak/raw/refs/heads/main/powerrat.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353348/; classtype:trojan-activity;sid:84216448; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353345)"; flow:established,from_client; content:"GET"; http_method; content:"/pr0xylife/asyncrat/raw/refs/heads/main/asyncrat_09.02.2022.txt"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353345/; classtype:trojan-activity;sid:84216445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353333)"; flow:established,from_client; content:"GET"; http_method; content:"/dlc_update.data"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"8.138.96.41"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353333/; classtype:trojan-activity;sid:84216433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353251)"; flow:established,from_client; content:"GET"; http_method; content:"/master.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"92.127.156.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353251/; classtype:trojan-activity;sid:84216351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353216)"; flow:established,from_client; content:"GET"; http_method; content:"//chromesetup.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"85.25.72.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353216/; classtype:trojan-activity;sid:84216316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353204)"; flow:established,from_client; content:"GET"; http_method; content:"/wp.ps1"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"92.127.156.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353204/; classtype:trojan-activity;sid:84216304; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3353123)"; flow:established,from_client; content:"GET"; http_method; content:"/cqhack/ddos-script/refs/heads/master/cqhack.pl"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_17; reference:url, urlhaus.abuse.ch/url/3353123/; classtype:trojan-activity;sid:84216223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3352821)"; flow:established,from_client; content:"GET"; http_method; content:"/kaijiorder/cert/2a.hta"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"182.92.99.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3352821/; classtype:trojan-activity;sid:84215921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351932)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=12jgde-soib4liipbdhs55vkz7ek8_ua6"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351932/; classtype:trojan-activity;sid:84215032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351478)"; flow:established,from_client; content:"GET"; http_method; content:"/ijeuwaesika/nna/raw/refs/heads/main/ifiinms.txt"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351478/; classtype:trojan-activity;sid:84214578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351477)"; flow:established,from_client; content:"GET"; http_method; content:"/fsabxh/sfdawsdawdaw/raw/refs/heads/main/serials_checker.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351477/; classtype:trojan-activity;sid:84214577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351430)"; flow:established,from_client; content:"GET"; http_method; content:"/xevioo/xeviohub/raw/refs/heads/main/critscript.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351430/; classtype:trojan-activity;sid:84214530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351428)"; flow:established,from_client; content:"GET"; http_method; content:"/grozniy1/folder/raw/refs/heads/main/444.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351428/; classtype:trojan-activity;sid:84214528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351297)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/rust-reverse-shell/raw/refs/heads/main/shellcode.bin"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351297/; classtype:trojan-activity;sid:84214397; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3351259)"; flow:established,from_client; content:"GET"; http_method; content:"/fengjixuchui/cve-2022-26810/raw/refs/heads/main/shellcode.bin"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_16; reference:url, urlhaus.abuse.ch/url/3351259/; classtype:trojan-activity;sid:84214359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3347308)"; flow:established,from_client; content:"GET"; http_method; content:"/component/vc2005sp1redist_x86.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"windriversfiles.imeitools.com"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2024_12_13; reference:url, urlhaus.abuse.ch/url/3347308/; classtype:trojan-activity;sid:84210408; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3346530)"; flow:established,from_client; content:"GET"; http_method; content:"/whoafg/problemonfmech/refs/heads/main/client.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_12; reference:url, urlhaus.abuse.ch/url/3346530/; classtype:trojan-activity;sid:84209630; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3346026)"; flow:established,from_client; content:"GET"; http_method; content:"/kaijiorder/cert/41a1111.hta"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"182.92.99.95"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_12; reference:url, urlhaus.abuse.ch/url/3346026/; classtype:trojan-activity;sid:84209126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3345089)"; flow:established,from_client; content:"GET"; http_method; content:"/n00b69/woasetup/releases/download/installers/dxwebsetup.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_11; reference:url, urlhaus.abuse.ch/url/3345089/; classtype:trojan-activity;sid:84208189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340440)"; flow:established,from_client; content:"GET"; http_method; content:"/dis3j/wagnerhook/releases/download/release/loader.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340440/; classtype:trojan-activity;sid:84203540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340399)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/xbest%20v1.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340399/; classtype:trojan-activity;sid:84203499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340398)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/complexo%20v4.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340398/; classtype:trojan-activity;sid:84203498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340395)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/box3d.dll"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340395/; classtype:trojan-activity;sid:84203495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340396)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/lkwan.dll"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340396/; classtype:trojan-activity;sid:84203496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340397)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/flunix9.dll"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340397/; classtype:trojan-activity;sid:84203497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340392)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/elzhas%20pannel.dll"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340392/; classtype:trojan-activity;sid:84203492; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340393)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/morovip.dll"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340393/; classtype:trojan-activity;sid:84203493; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340394)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/hazaxd.dll"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340394/; classtype:trojan-activity;sid:84203494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340391)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/xbest.dll"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340391/; classtype:trojan-activity;sid:84203491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340390)"; flow:established,from_client; content:"GET"; http_method; content:"/xbest11/ddl1/main/blue_and_white.dll"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340390/; classtype:trojan-activity;sid:84203490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3340363)"; flow:established,from_client; content:"GET"; http_method; content:"/huuuuggga/aaaaa1/refs/heads/main/srtware.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_10; reference:url, urlhaus.abuse.ch/url/3340363/; classtype:trojan-activity;sid:84203463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339245)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"186.138.107.5"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339245/; classtype:trojan-activity;sid:84202345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339230)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"81.12.157.98"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339230/; classtype:trojan-activity;sid:84202330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339221)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"182.93.83.124"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339221/; classtype:trojan-activity;sid:84202321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339179)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"47.49.114.179"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339179/; classtype:trojan-activity;sid:84202279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339156)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.53.164.90"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339156/; classtype:trojan-activity;sid:84202256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339132)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"95.170.113.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339132/; classtype:trojan-activity;sid:84202232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3339084)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"212.85.166.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3339084/; classtype:trojan-activity;sid:84202184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338656)"; flow:established,from_client; content:"GET"; http_method; content:"/kabot/unix-privilege-escalation-exploits-pack/master/2012/vmsplice-local-root-exploit"; http_uri; depth:86; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338656/; classtype:trojan-activity;sid:84201756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338560)"; flow:established,from_client; content:"GET"; http_method; content:"/ga13372/jv/main/javaw.exe"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338560/; classtype:trojan-activity;sid:84201660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338548)"; flow:established,from_client; content:"GET"; http_method; content:"/nicxlau/alfa-shell/master/alfa-obfuscated.php"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338548/; classtype:trojan-activity;sid:84201648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338507)"; flow:established,from_client; content:"GET"; http_method; content:"/aissardp/payload/main/payload.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338507/; classtype:trojan-activity;sid:84201607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338505)"; flow:established,from_client; content:"GET"; http_method; content:"/cracker1337uwu/rrr/main/bypass.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338505/; classtype:trojan-activity;sid:84201605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338499)"; flow:established,from_client; content:"GET"; http_method; content:"/g1vi/cve-2023-2640-cve-2023-32629/main/exploit.sh"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338499/; classtype:trojan-activity;sid:84201599; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338493)"; flow:established,from_client; content:"GET"; http_method; content:"/nguyenmanmkt/repo1/main/exploit-2"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338493/; classtype:trojan-activity;sid:84201593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338492)"; flow:established,from_client; content:"GET"; http_method; content:"/leetcipher/malware.development/main/self-injection/self-injection.exe"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338492/; classtype:trojan-activity;sid:84201592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338487)"; flow:established,from_client; content:"GET"; http_method; content:"/cyberhunter00/remote_hijack/master/uac_bypass.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338487/; classtype:trojan-activity;sid:84201587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338475)"; flow:established,from_client; content:"GET"; http_method; content:"/cocomelonc/2022-01-14-malware-injection-13/master/hack.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338475/; classtype:trojan-activity;sid:84201575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338467)"; flow:established,from_client; content:"GET"; http_method; content:"/fxtazz/injection/main/index.js"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338467/; classtype:trojan-activity;sid:84201567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338471)"; flow:established,from_client; content:"GET"; http_method; content:"/leetcipher/malware.development/main/process-injection/process-injection.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338471/; classtype:trojan-activity;sid:84201571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338451)"; flow:established,from_client; content:"GET"; http_method; content:"/sixaknow/uac_bypass_/main/module_377498327498dcxvc32434.dll"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338451/; classtype:trojan-activity;sid:84201551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3338443)"; flow:established,from_client; content:"GET"; http_method; content:"/pistacchietto/win-python-backdoor/master/standalone_payload.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3338443/; classtype:trojan-activity;sid:84201543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337794)"; flow:established,from_client; content:"GET"; http_method; content:"/ty9989/f/zip/refs/heads/main"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337794/; classtype:trojan-activity;sid:84200894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337795)"; flow:established,from_client; content:"GET"; http_method; content:"/ty9989/c/zip/refs/heads/main"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337795/; classtype:trojan-activity;sid:84200895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337796)"; flow:established,from_client; content:"GET"; http_method; content:"/ty9989/u/zip/refs/heads/main"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337796/; classtype:trojan-activity;sid:84200896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337797)"; flow:established,from_client; content:"GET"; http_method; content:"/ty9989/i/zip/refs/heads/main"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_09; reference:url, urlhaus.abuse.ch/url/3337797/; classtype:trojan-activity;sid:84200897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337035)"; flow:established,from_client; content:"GET"; http_method; content:"/rahmoundll/kak/main/glew64.dll"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337035/; classtype:trojan-activity;sid:84200135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337026)"; flow:established,from_client; content:"GET"; http_method; content:"/nkaslq1/ankrnl/refs/heads/main/alphatweaks.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337026/; classtype:trojan-activity;sid:84200126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337032)"; flow:established,from_client; content:"GET"; http_method; content:"/haa15/driver-shitty/main/kdmapper_release.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337032/; classtype:trojan-activity;sid:84200132; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337015)"; flow:established,from_client; content:"GET"; http_method; content:"/v0lt/virtualdub2/releases/download/2.1.3/virtualdub2_v2.1.3.667_win32.7z"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337015/; classtype:trojan-activity;sid:84200115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337012)"; flow:established,from_client; content:"GET"; http_method; content:"/cgmb/update.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"update.cg100iii.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337012/; classtype:trojan-activity;sid:84200112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337010)"; flow:established,from_client; content:"GET"; http_method; content:"/cgpro/update.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"update.cg100iii.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337010/; classtype:trojan-activity;sid:84200110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3337004)"; flow:established,from_client; content:"GET"; http_method; content:"/skibidixelaina/wuselaina/raw/refs/heads/main/build.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3337004/; classtype:trojan-activity;sid:84200104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336992)"; flow:established,from_client; content:"GET"; http_method; content:"/keygroup777-ransomware/downloader/refs/heads/main/taskmoder.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336992/; classtype:trojan-activity;sid:84200092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336993)"; flow:established,from_client; content:"GET"; http_method; content:"/z-beam/movaflag/releases/download/1.0.2/mova.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336993/; classtype:trojan-activity;sid:84200093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336990)"; flow:established,from_client; content:"GET"; http_method; content:"/keygroup777-ransomware/downloader/refs/heads/main/cssgo.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336990/; classtype:trojan-activity;sid:84200090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336983)"; flow:established,from_client; content:"GET"; http_method; content:"/keygroup777-ransomware/downloader/raw/refs/heads/main/black.exe"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336983/; classtype:trojan-activity;sid:84200083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336077)"; flow:established,from_client; content:"GET"; http_method; content:"/nikolaevich23/make-pkg-bat/master/setup.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336077/; classtype:trojan-activity;sid:84199177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336072)"; flow:established,from_client; content:"GET"; http_method; content:"/eirxne/valorant-axeprime/main/axeprime.dll"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336072/; classtype:trojan-activity;sid:84199172; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336068)"; flow:established,from_client; content:"GET"; http_method; content:"/stephenfewer/reflectivedllinjection/refs/heads/master/bin/reflective_dll.dll"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336068/; classtype:trojan-activity;sid:84199168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336058)"; flow:established,from_client; content:"GET"; http_method; content:"/anessdev/talha/main/talha.dll"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336058/; classtype:trojan-activity;sid:84199158; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3336049)"; flow:established,from_client; content:"GET"; http_method; content:"/sqrtzeroknowledge/xworm-trojan/zip/refs/heads/main"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_08; reference:url, urlhaus.abuse.ch/url/3336049/; classtype:trojan-activity;sid:84199149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335208)"; flow:established,from_client; content:"GET"; http_method; content:"/barrigudinha157/barrigudinha/master/rage.dll"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335208/; classtype:trojan-activity;sid:84198308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335149)"; flow:established,from_client; content:"GET"; http_method; content:"/docs/2018-11/20181122103207926164.doc"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"xww.bucea.edu.cn"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335149/; classtype:trojan-activity;sid:84198249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335154)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/statement/ul397wfyb/"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335154/; classtype:trojan-activity;sid:84198254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335132)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/hl8-8w4cs-6325/"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"reifenquick.de"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335132/; classtype:trojan-activity;sid:84198232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335118)"; flow:established,from_client; content:"GET"; http_method; content:"/cg70/update.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"update.cg100iii.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335118/; classtype:trojan-activity;sid:84198218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335096)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/closed_957176_mxqsdoj6a4iz/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335096/; classtype:trojan-activity;sid:84198196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3335074)"; flow:established,from_client; content:"GET"; http_method; content:"/_upload/article/files/90/f4/62d98f264ab0abc4a1f14a32607a/089c9dc1-8248-47b5-b35d-310cd70469b4.doc"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"hhbs.hhu.edu.cn"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_07; reference:url, urlhaus.abuse.ch/url/3335074/; classtype:trojan-activity;sid:84198174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333897)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.dbg"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333897/; classtype:trojan-activity;sid:84196997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333896)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.sh4"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333896/; classtype:trojan-activity;sid:84196996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333895)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.x86_64"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333895/; classtype:trojan-activity;sid:84196995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333657)"; flow:established,from_client; content:"GET"; http_method; content:"/namblack666/zxqqw/refs/heads/main/main.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333657/; classtype:trojan-activity;sid:84196757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333658)"; flow:established,from_client; content:"GET"; http_method; content:"/namblack666/zxqqw/refs/heads/main/main1.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333658/; classtype:trojan-activity;sid:84196758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333656)"; flow:established,from_client; content:"GET"; http_method; content:"/nam-black/moneyandbitch/refs/heads/main/main1.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333656/; classtype:trojan-activity;sid:84196756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333651)"; flow:established,from_client; content:"GET"; http_method; content:"/nam-black/moneyandbitch/raw/refs/heads/main/main1.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333651/; classtype:trojan-activity;sid:84196751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333522)"; flow:established,from_client; content:"GET"; http_method; content:"/azertyuiopexe/fud-crypter/zip/refs/heads/main"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333522/; classtype:trojan-activity;sid:84196622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333521)"; flow:established,from_client; content:"GET"; http_method; content:"/joh81/exploi01/main/document.zip"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333521/; classtype:trojan-activity;sid:84196621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333518)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.8"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333518/; classtype:trojan-activity;sid:84196618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333513)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.10"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333513/; classtype:trojan-activity;sid:84196613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333514)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.3"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333514/; classtype:trojan-activity;sid:84196614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333511)"; flow:established,from_client; content:"GET"; http_method; content:"/hwangyounggul33/windows10/refs/heads/main/privacypolicy.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333511/; classtype:trojan-activity;sid:84196611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333509)"; flow:established,from_client; content:"GET"; http_method; content:"/caocaocc/yacd/zip/refs/heads/gh-pages"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333509/; classtype:trojan-activity;sid:84196609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333510)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.9.2"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333510/; classtype:trojan-activity;sid:84196610; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333508)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.11"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333508/; classtype:trojan-activity;sid:84196608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333502)"; flow:established,from_client; content:"GET"; http_method; content:"/cirosantilli/china-dictatorship/zip/refs/heads/master"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333502/; classtype:trojan-activity;sid:84196602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333503)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.zip/refs/tags/0.8.1"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333503/; classtype:trojan-activity;sid:84196603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333495)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.5"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333495/; classtype:trojan-activity;sid:84196595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333496)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.7"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333496/; classtype:trojan-activity;sid:84196596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333493)"; flow:established,from_client; content:"GET"; http_method; content:"/d-7uble/invoke-phant0m/zip/refs/heads/master"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333493/; classtype:trojan-activity;sid:84196593; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333494)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.zip/refs/tags/0.7.1"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333494/; classtype:trojan-activity;sid:84196594; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333489)"; flow:established,from_client; content:"GET"; http_method; content:"/54n4l/mimikatzwindows/zip/refs/heads/master"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333489/; classtype:trojan-activity;sid:84196589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333485)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.9"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333485/; classtype:trojan-activity;sid:84196585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333482)"; flow:established,from_client; content:"GET"; http_method; content:"/daneeltrevize/tabsat/legacy.tar.gz/refs/tags/0.9.1"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333482/; classtype:trojan-activity;sid:84196582; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333481)"; flow:established,from_client; content:"GET"; http_method; content:"/crowly-ai/hello-world/refs/heads/main/zubovlekciya.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333481/; classtype:trojan-activity;sid:84196581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333470)"; flow:established,from_client; content:"GET"; http_method; content:"/bloodhoundad/bloodhound/master/collectors/sharphound.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333470/; classtype:trojan-activity;sid:84196570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333458)"; flow:established,from_client; content:"GET"; http_method; content:"/calendar/down/calendar/setup.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"ojang.pe.kr"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333458/; classtype:trojan-activity;sid:84196558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333456)"; flow:established,from_client; content:"GET"; http_method; content:"/calendar/down/jeditor/jeditor.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"ojang.pe.kr"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333456/; classtype:trojan-activity;sid:84196556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333439)"; flow:established,from_client; content:"GET"; http_method; content:"/ytisf/thezoo/refs/heads/master/malware/binaries/ransomware.wannacry/ransomware.wannacry.zip"; http_uri; depth:92; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333439/; classtype:trojan-activity;sid:84196539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333435)"; flow:established,from_client; content:"GET"; http_method; content:"/newlog/exploiting/refs/heads/master/training/windows/practical_malware_analysis/labs/chapter_1l/lab01-02.exe"; http_uri; depth:109; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333435/; classtype:trojan-activity;sid:84196535; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333369)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/master/donut.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333369/; classtype:trojan-activity;sid:84196469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333359)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.mpsl"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333359/; classtype:trojan-activity;sid:84196459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333355)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.i686"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333355/; classtype:trojan-activity;sid:84196455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333357)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.x86"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333357/; classtype:trojan-activity;sid:84196457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333350)"; flow:established,from_client; content:"GET"; http_method; content:"/getrektboy724/sementara/raw/master/donut.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333350/; classtype:trojan-activity;sid:84196450; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333352)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.m68k"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333352/; classtype:trojan-activity;sid:84196452; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333321)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/17793058/lg246dre.txt"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333321/; classtype:trojan-activity;sid:84196421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333316)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.arm5"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333316/; classtype:trojan-activity;sid:84196416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3333317)"; flow:established,from_client; content:"GET"; http_method; content:"/aqua.ppc"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"103.163.119.220"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3333317/; classtype:trojan-activity;sid:84196417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332792)"; flow:established,from_client; content:"GET"; http_method; content:"/noccenter/noccenter/refs/heads/main/huong%20dan%20xu%20ly%20tai%20khoan%20mail%20noi%20bo.zip"; http_uri; depth:94; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332792/; classtype:trojan-activity;sid:84195892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332783)"; flow:established,from_client; content:"GET"; http_method; content:"/noccenter/noccenter/raw/refs/heads/main/huong%20dan%20xu%20ly%20tai%20khoan%20mail%20noi%20bo.zip"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332783/; classtype:trojan-activity;sid:84195883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332771)"; flow:established,from_client; content:"GET"; http_method; content:"/xevioo/xeviohub/main/critscript.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332771/; classtype:trojan-activity;sid:84195871; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332764)"; flow:established,from_client; content:"GET"; http_method; content:"/mae-luadev/mae-tests/main/system.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332764/; classtype:trojan-activity;sid:84195864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3332757)"; flow:established,from_client; content:"GET"; http_method; content:"/mae-luadev/mae-tests/raw/main/system.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_06; reference:url, urlhaus.abuse.ch/url/3332757/; classtype:trojan-activity;sid:84195857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331919)"; flow:established,from_client; content:"GET"; http_method; content:"/presema/kersal/refs/heads/main/opyhjdase.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331919/; classtype:trojan-activity;sid:84195019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331862)"; flow:established,from_client; content:"GET"; http_method; content:"/presema/kersal/refs/heads/main/popapoers.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331862/; classtype:trojan-activity;sid:84194962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331858)"; flow:established,from_client; content:"GET"; http_method; content:"/presema/kersal/refs/heads/main/ljgksdtihd.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331858/; classtype:trojan-activity;sid:84194958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331850)"; flow:established,from_client; content:"GET"; http_method; content:"/presema/kersal/refs/heads/main/pfntjejghjsdkr.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331850/; classtype:trojan-activity;sid:84194950; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331828)"; flow:established,from_client; content:"GET"; http_method; content:"/presema/kersal/refs/heads/main/vikings.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331828/; classtype:trojan-activity;sid:84194928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331826)"; flow:established,from_client; content:"GET"; http_method; content:"/presema/kersal/refs/heads/main/bnkrigkawd.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331826/; classtype:trojan-activity;sid:84194926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331699)"; flow:established,from_client; content:"GET"; http_method; content:"/frenzy-zwaake/discordrat-2.0/main/client-built.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331699/; classtype:trojan-activity;sid:84194799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331669)"; flow:established,from_client; content:"GET"; http_method; content:"/fofit-rater/1/refs/heads/main/xclient.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331669/; classtype:trojan-activity;sid:84194769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331670)"; flow:established,from_client; content:"GET"; http_method; content:"/efedursun125/xfakeplayers/master/xclient.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331670/; classtype:trojan-activity;sid:84194770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331664)"; flow:established,from_client; content:"GET"; http_method; content:"/v2/long-glade-33dc08/original//rump_img.jpeg"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"cdn.pixelbin.io"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331664/; classtype:trojan-activity;sid:84194764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331653)"; flow:established,from_client; content:"GET"; http_method; content:"/zonicleaks/yappadabbadoo/main/xclient.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331653/; classtype:trojan-activity;sid:84194753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331648)"; flow:established,from_client; content:"GET"; http_method; content:"/jikoos/rrr/main/xclient.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331648/; classtype:trojan-activity;sid:84194748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331649)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/debug2.ps1"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"www.drgenov.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331649/; classtype:trojan-activity;sid:84194749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331639)"; flow:established,from_client; content:"GET"; http_method; content:"/frenzy-zwaake/discordrat-2.0/deferred-metadata/main/client-built.exe"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331639/; classtype:trojan-activity;sid:84194739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331633)"; flow:established,from_client; content:"GET"; http_method; content:"/joeljosephpajeet/testexe/refs/heads/main/xclient.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331633/; classtype:trojan-activity;sid:84194733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331626)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/debug4.ps1"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"www.drgenov.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331626/; classtype:trojan-activity;sid:84194726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331630)"; flow:established,from_client; content:"GET"; http_method; content:"/cheetz/nishang/master/gather/keylogger.ps1"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331630/; classtype:trojan-activity;sid:84194730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331588)"; flow:established,from_client; content:"GET"; http_method; content:"/cookieskush/pip-package-template/master/client-built.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331588/; classtype:trojan-activity;sid:84194688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331574)"; flow:established,from_client; content:"GET"; http_method; content:"/efedursun125/xfakeplayers/refs/heads/master/xclient.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331574/; classtype:trojan-activity;sid:84194674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331534)"; flow:established,from_client; content:"GET"; http_method; content:"/cidadejunina/js/vendor/debug2.ps1"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"transparenciacanaa.com.br"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331534/; classtype:trojan-activity;sid:84194634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331498)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_-w5me4evtzbdzix_v_ymzdelazhrv5z"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331498/; classtype:trojan-activity;sid:84194598; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331500)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1nskagzrswpttoue3wbrhdqpyzlyve4tg"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331500/; classtype:trojan-activity;sid:84194600; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3331490)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1o3zw7sodji4uk954kngkdyshyl37gozq"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3331490/; classtype:trojan-activity;sid:84194590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3330983)"; flow:established,from_client; content:"GET"; http_method; content:"/ps.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"harmeetmotors.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_12_05; reference:url, urlhaus.abuse.ch/url/3330983/; classtype:trojan-activity;sid:84194083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3319641)"; flow:established,from_client; content:"GET"; http_method; content:"/02.08.2022.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"120.26.166.249"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_04; reference:url, urlhaus.abuse.ch/url/3319641/; classtype:trojan-activity;sid:84182741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3318309)"; flow:established,from_client; content:"GET"; http_method; content:"/khangdz1801/raw/refs/heads/main/sound.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_12_03; reference:url, urlhaus.abuse.ch/url/3318309/; classtype:trojan-activity;sid:84181409; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317713)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/plugin2.dll"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317713/; classtype:trojan-activity;sid:84180813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317712)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/plugin1.dll"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317712/; classtype:trojan-activity;sid:84180812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3317707)"; flow:established,from_client; content:"GET"; http_method; content:"/m2/plugin3.dll"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"165.154.184.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_12_02; reference:url, urlhaus.abuse.ch/url/3317707/; classtype:trojan-activity;sid:84180807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308898)"; flow:established,from_client; content:"GET"; http_method; content:"/help.scr"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"61.183.16.127"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308898/; classtype:trojan-activity;sid:84171998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308894)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"218.155.74.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308894/; classtype:trojan-activity;sid:84171994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308882)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"159.250.122.151"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308882/; classtype:trojan-activity;sid:84171982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308875)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"141.155.36.213"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308875/; classtype:trojan-activity;sid:84171975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308847)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"5.26.174.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308847/; classtype:trojan-activity;sid:84171947; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308798)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1idr9p3dgxkblhu7h4jckclzmtlibwsiw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308798/; classtype:trojan-activity;sid:84171898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3308797)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1c2pnucvma1shu90mnauhef6shildth-s"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_27; reference:url, urlhaus.abuse.ch/url/3308797/; classtype:trojan-activity;sid:84171897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3303817)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1jbzzntbk1kuszoofww7hsqfdh066ontf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_25; reference:url, urlhaus.abuse.ch/url/3303817/; classtype:trojan-activity;sid:84166917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3303818)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1hkvynldkcbdd50_bsw3s9tk5elbduxtg"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_25; reference:url, urlhaus.abuse.ch/url/3303818/; classtype:trojan-activity;sid:84166918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300881)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/lnk/refs/heads/main/y.png"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300881/; classtype:trojan-activity;sid:84163981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300394)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/dcm/refs/heads/main/document.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300394/; classtype:trojan-activity;sid:84163494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300382)"; flow:established,from_client; content:"GET"; http_method; content:"/steamer/malwerjobs/refs/heads/master/test.xll"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300382/; classtype:trojan-activity;sid:84163482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300387)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/lnk/refs/heads/main/ud.bat"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300387/; classtype:trojan-activity;sid:84163487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300377)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/lnk/refs/heads/main/t.png"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300377/; classtype:trojan-activity;sid:84163477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300378)"; flow:established,from_client; content:"GET"; http_method; content:"/steamer/malwerjobs/refs/heads/master/template.dotm"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300378/; classtype:trojan-activity;sid:84163478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300374)"; flow:established,from_client; content:"GET"; http_method; content:"/steamer/malwerjobs/refs/heads/master/doadmin.png"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300374/; classtype:trojan-activity;sid:84163474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300375)"; flow:established,from_client; content:"GET"; http_method; content:"/steamer/malwerjobs/refs/heads/master/steamerx.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300375/; classtype:trojan-activity;sid:84163475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300376)"; flow:established,from_client; content:"GET"; http_method; content:"/steamer/malwerjobs/refs/heads/master/justpoc.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300376/; classtype:trojan-activity;sid:84163476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300371)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/lnk/refs/heads/main/u.xls"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300371/; classtype:trojan-activity;sid:84163471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300372)"; flow:established,from_client; content:"GET"; http_method; content:"/steamer/malwerjobs/refs/heads/master/scriptlet"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_23; reference:url, urlhaus.abuse.ch/url/3300372/; classtype:trojan-activity;sid:84163472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3300068)"; flow:established,from_client; content:"GET"; http_method; content:"/es.hta"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"pub-cdd0dd27ae6a4aee9841d397e0496374.r2.dev"; http_host; depth:43; isdataat:!1,relative; metadata:created_at 2024_11_22; reference:url, urlhaus.abuse.ch/url/3300068/; classtype:trojan-activity;sid:84163168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298233)"; flow:established,from_client; content:"GET"; http_method; content:"/saked018/rivada/refs/heads/main/mis_file_9888123_received_xsls.zip"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298233/; classtype:trojan-activity;sid:84161333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298219)"; flow:established,from_client; content:"GET"; http_method; content:"/saked018/rivada/raw/refs/heads/main/mis_file_9888123_received_xsls.zip"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298219/; classtype:trojan-activity;sid:84161319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298207)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/dcm/raw/refs/heads/main/document.zip"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298207/; classtype:trojan-activity;sid:84161307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298202)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/ud/raw/refs/heads/main/ud.bat"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298202/; classtype:trojan-activity;sid:84161302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298205)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/lnk/raw/refs/heads/main/u.xls"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298205/; classtype:trojan-activity;sid:84161305; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3298201)"; flow:established,from_client; content:"GET"; http_method; content:"/rouki555/lnk/raw/refs/heads/main/ud.bat"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_21; reference:url, urlhaus.abuse.ch/url/3298201/; classtype:trojan-activity;sid:84161301; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3296209)"; flow:established,from_client; content:"GET"; http_method; content:"/crm/exe/update.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"www.zhikey.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_19; reference:url, urlhaus.abuse.ch/url/3296209/; classtype:trojan-activity;sid:84159309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3294913)"; flow:established,from_client; content:"GET"; http_method; content:"/ledshow1.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"101.200.220.118"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_18; reference:url, urlhaus.abuse.ch/url/3294913/; classtype:trojan-activity;sid:84158013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3294809)"; flow:established,from_client; content:"GET"; http_method; content:"/configureregistrysettings.ps1"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"103.247.164.242"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_18; reference:url, urlhaus.abuse.ch/url/3294809/; classtype:trojan-activity;sid:84157909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3294619)"; flow:established,from_client; content:"GET"; http_method; content:"/noureddine-nt9/rgsdr/raw/refs/heads/main/cheet.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_18; reference:url, urlhaus.abuse.ch/url/3294619/; classtype:trojan-activity;sid:84157719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3292014)"; flow:established,from_client; content:"GET"; http_method; content:"/n/tui/mininews/mininewsplus/3.0.0.26165/mininewsplus-2.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"mininews.kpzip.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_11_15; reference:url, urlhaus.abuse.ch/url/3292014/; classtype:trojan-activity;sid:84155114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3291869)"; flow:established,from_client; content:"GET"; http_method; content:"/images/stories/guides/guide2018.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"dcwblida.dz"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_11_15; reference:url, urlhaus.abuse.ch/url/3291869/; classtype:trojan-activity;sid:84154969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3289875)"; flow:established,from_client; content:"GET"; http_method; content:"/r00ts3c/ddos-rootsec/refs/heads/master/ddos%20scripts/l4/udp/10gbpsudp.py"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_14; reference:url, urlhaus.abuse.ch/url/3289875/; classtype:trojan-activity;sid:84152975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286518)"; flow:established,from_client; content:"GET"; http_method; content:"/kzxiaopeng2/kuaizip_setup_-808202126_xiaopeng2_001.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"d.kpzip.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286518/; classtype:trojan-activity;sid:84149618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286513)"; flow:established,from_client; content:"GET"; http_method; content:"/haozip.convertimg.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"download.haozip.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286513/; classtype:trojan-activity;sid:84149613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286371)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.70.244.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286371/; classtype:trojan-activity;sid:84149471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3286067)"; flow:established,from_client; content:"GET"; http_method; content:"/erez-goldberg/rust-reverse-shell/main/shellcode.bin"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_11; reference:url, urlhaus.abuse.ch/url/3286067/; classtype:trojan-activity;sid:84149167; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3281714)"; flow:established,from_client; content:"GET"; http_method; content:"/s3cur3th1ssh1t/creds/master/obfuscatedps/dccuac.ps1"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_08; reference:url, urlhaus.abuse.ch/url/3281714/; classtype:trojan-activity;sid:84144814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3281085)"; flow:established,from_client; content:"GET"; http_method; content:"/barrigudinha157/barrigudinha/raw/master/rage.dll"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_07; reference:url, urlhaus.abuse.ch/url/3281085/; classtype:trojan-activity;sid:84144185; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3280680)"; flow:established,from_client; content:"GET"; http_method; content:"/fiies/stormfn-launcher/raw/refs/heads/main/stormfn-launcher.zip"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_07; reference:url, urlhaus.abuse.ch/url/3280680/; classtype:trojan-activity;sid:84143780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3279353)"; flow:established,from_client; content:"GET"; http_method; content:"/xavieprowel/crispy-palm-tree/releases/download/1/3e3ev3.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3279353/; classtype:trojan-activity;sid:84142453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278669)"; flow:established,from_client; content:"GET"; http_method; content:"/txdown_disk/%e8%bd%af%e4%bb%b6%e4%bd%bf%e7%94%a8/%e7%bc%ba%e5%a4%b1%e4%b8%8b%e8%bd%bd/plugin.dll"; http_uri; depth:97; isdataat:!1,relative; nocase; content:"disk.accord1key.cn"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278669/; classtype:trojan-activity;sid:84141769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278573)"; flow:established,from_client; content:"GET"; http_method; content:"/ciphershld/ms-p-1a/master/setup%20ms%20p-1a.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278573/; classtype:trojan-activity;sid:84141673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278576)"; flow:established,from_client; content:"GET"; http_method; content:"/minecradt/regdelete/readme-edits/hell9o.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278576/; classtype:trojan-activity;sid:84141676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278567)"; flow:established,from_client; content:"GET"; http_method; content:"/openpeach/dotnetfx_cleanup_tool/refs/heads/master/cleanup_tool.exe"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278567/; classtype:trojan-activity;sid:84141667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278362)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1las2cmd3reobg45qhkqhawi90h4_u0kd"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278362/; classtype:trojan-activity;sid:84141462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3278361)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=17hv9-3t2ilikbmcfql2z66ipd72x4mz7"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_06; reference:url, urlhaus.abuse.ch/url/3278361/; classtype:trojan-activity;sid:84141461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3276956)"; flow:established,from_client; content:"GET"; http_method; content:"/mig"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"216.201.80.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_11_05; reference:url, urlhaus.abuse.ch/url/3276956/; classtype:trojan-activity;sid:84140056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3276896)"; flow:established,from_client; content:"GET"; http_method; content:"/loistupidpet/sfdawsdawdaw/main/serials_checker.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_05; reference:url, urlhaus.abuse.ch/url/3276896/; classtype:trojan-activity;sid:84139996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275669)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1kc4fdseohzqymz2x0ncqswph66uxdb1z"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275669/; classtype:trojan-activity;sid:84138769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275667)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1u_rahqbks7vd7qqc6wx3gxnjxtfqrzbp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275667/; classtype:trojan-activity;sid:84138767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275658)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1-8qpzgr4-iis53p1-kr2-o6prrjmnksk"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275658/; classtype:trojan-activity;sid:84138758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275656)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ubqrhziusgl-cn_nie2_udj4qi6qrqsw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275656/; classtype:trojan-activity;sid:84138756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275240)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ikoxnnlvglh6jhnfqkrsihss_p2dqkyp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275240/; classtype:trojan-activity;sid:84138340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275241)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1r7oi2jekx0ks1wqpt0ms3_kqvukzy3dv"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275241/; classtype:trojan-activity;sid:84138341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3275242)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gmzqsemymffka4lve0jkwa06sklk7xhu"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_11_04; reference:url, urlhaus.abuse.ch/url/3275242/; classtype:trojan-activity;sid:84138342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274064)"; flow:established,from_client; content:"GET"; http_method; content:"/borisizdabezt/exitlag-hwid-spoofer/main/drv64.dll"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274064/; classtype:trojan-activity;sid:84137164; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274049)"; flow:established,from_client; content:"GET"; http_method; content:"/realstrings/lydian-spoofer/raw/main/spoofy.sys"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274049/; classtype:trojan-activity;sid:84137149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274047)"; flow:established,from_client; content:"GET"; http_method; content:"/realstrings/lydian-spoofer/refs/heads/main/spoofy.sys"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274047/; classtype:trojan-activity;sid:84137147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3274048)"; flow:established,from_client; content:"GET"; http_method; content:"/realstrings/lydian-spoofer/raw/refs/heads/main/spoofy.sys"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_03; reference:url, urlhaus.abuse.ch/url/3274048/; classtype:trojan-activity;sid:84137148; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3272092)"; flow:established,from_client; content:"GET"; http_method; content:"/ordogos2/g575/releases/download/download/setup.7.0.zip"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3272092/; classtype:trojan-activity;sid:84135192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271922)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/injector.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271922/; classtype:trojan-activity;sid:84135022; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271923)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/injectorold.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271923/; classtype:trojan-activity;sid:84135023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271924)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/driver.sys"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271924/; classtype:trojan-activity;sid:84135024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271925)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/loader.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271925/; classtype:trojan-activity;sid:84135025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271919)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/ogfn%20updater.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271919/; classtype:trojan-activity;sid:84135019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271920)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/pclient.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271920/; classtype:trojan-activity;sid:84135020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271921)"; flow:established,from_client; content:"GET"; http_method; content:"/leakerbydragon1/leakerbydragon1/main/kdmapper_release.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271921/; classtype:trojan-activity;sid:84135021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271663)"; flow:established,from_client; content:"GET"; http_method; content:"/svchost.exe"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"123.ywxww.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271663/; classtype:trojan-activity;sid:84134763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271634)"; flow:established,from_client; content:"GET"; http_method; content:"/undertalanted/mod/refs/heads/main/svchost.exe"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271634/; classtype:trojan-activity;sid:84134734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271624)"; flow:established,from_client; content:"GET"; http_method; content:"/sdifru877234/ilu123g5/main/svchost.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271624/; classtype:trojan-activity;sid:84134724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271617)"; flow:established,from_client; content:"GET"; http_method; content:"/regolx1/hadb/refs/heads/main/svchost.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271617/; classtype:trojan-activity;sid:84134717; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271614)"; flow:established,from_client; content:"GET"; http_method; content:"/chokopie333/doom/main/svchost.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271614/; classtype:trojan-activity;sid:84134714; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271609)"; flow:established,from_client; content:"GET"; http_method; content:"/morgantaraum/automatic-octo-barnacle/refs/heads/main/svchost.exe"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271609/; classtype:trojan-activity;sid:84134709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271610)"; flow:established,from_client; content:"GET"; http_method; content:"/media/furystorage/api/main/svchost.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"media.githubusercontent.com"; http_host; depth:27; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271610/; classtype:trojan-activity;sid:84134710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271611)"; flow:established,from_client; content:"GET"; http_method; content:"/zodiac1616/test/refs/heads/main/svchost.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271611/; classtype:trojan-activity;sid:84134711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271605)"; flow:established,from_client; content:"GET"; http_method; content:"/sdifru877234/ilu123g5/raw/main/svchost.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271605/; classtype:trojan-activity;sid:84134705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271586)"; flow:established,from_client; content:"GET"; http_method; content:"/chokopie333/doom/raw/main/svchost.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271586/; classtype:trojan-activity;sid:84134686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271587)"; flow:established,from_client; content:"GET"; http_method; content:"/morgantaraum/automatic-octo-barnacle/raw/refs/heads/main/svchost.exe"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271587/; classtype:trojan-activity;sid:84134687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271590)"; flow:established,from_client; content:"GET"; http_method; content:"/zodiac1616/test/raw/refs/heads/main/svchost.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271590/; classtype:trojan-activity;sid:84134690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271366)"; flow:established,from_client; content:"GET"; http_method; content:"/zzrevva1/osu-maple/refs/heads/main/extremeinjector.exe"; http_uri; depth:55; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271366/; classtype:trojan-activity;sid:84134466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3271369)"; flow:established,from_client; content:"GET"; http_method; content:"/zzrevva1/osu-maple/raw/refs/heads/main/extremeinjector.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_02; reference:url, urlhaus.abuse.ch/url/3271369/; classtype:trojan-activity;sid:84134469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270196)"; flow:established,from_client; content:"GET"; http_method; content:"/novocrm/static/winring0x64.sys"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"118.189.172.141"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270196/; classtype:trojan-activity;sid:84133296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270195)"; flow:established,from_client; content:"GET"; http_method; content:"/ggassistant/update/2.3.11.29/tool/winring0x64.sys|3f|skq=1701042218"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"shqdown.ggzuhao.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270195/; classtype:trojan-activity;sid:84133295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270193)"; flow:established,from_client; content:"GET"; http_method; content:"/miguel-b-p/..../raw/main/winring0x64.sys"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270193/; classtype:trojan-activity;sid:84133293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270185)"; flow:established,from_client; content:"GET"; http_method; content:"/silenthashik/winring/raw/main/winring0x64.sys"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270185/; classtype:trojan-activity;sid:84133285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270186)"; flow:established,from_client; content:"GET"; http_method; content:"/hak333444/xmrig/raw/main/winring0x64.sys"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270186/; classtype:trojan-activity;sid:84133286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270188)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/blob/master/bin/winring0/winring0x64.sys|3f|raw=true"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270188/; classtype:trojan-activity;sid:84133288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270189)"; flow:established,from_client; content:"GET"; http_method; content:"/so251/olaquerida/releases/download/1releasae/winring0x64.sys"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270189/; classtype:trojan-activity;sid:84133289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270191)"; flow:established,from_client; content:"GET"; http_method; content:"/jsjsjsc79/advsd/raw/main/winring0x64.sys"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270191/; classtype:trojan-activity;sid:84133291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270192)"; flow:established,from_client; content:"GET"; http_method; content:"/stickmengamer/idk/raw/main/winring0x64.sys"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270192/; classtype:trojan-activity;sid:84133292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270183)"; flow:established,from_client; content:"GET"; http_method; content:"/sopranotech/dimeo/main/winring0x64.sys"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270183/; classtype:trojan-activity;sid:84133283; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3270184)"; flow:established,from_client; content:"GET"; http_method; content:"/abrissyy/min/main/winring0x64.sys"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3270184/; classtype:trojan-activity;sid:84133284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3269715)"; flow:established,from_client; content:"GET"; http_method; content:"/sqrtzeroknowledge/xworm-trojan/archive/refs/heads/main.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_11_01; reference:url, urlhaus.abuse.ch/url/3269715/; classtype:trojan-activity;sid:84132815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3265959)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ygqwpvxadhjsxskr3u3tdw2u5dnzv0pp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_30; reference:url, urlhaus.abuse.ch/url/3265959/; classtype:trojan-activity;sid:84129059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3265958)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1uzjwtbh4hcs9i060hwf08hrnymnodugn"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_30; reference:url, urlhaus.abuse.ch/url/3265958/; classtype:trojan-activity;sid:84129058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3258033)"; flow:established,from_client; content:"GET"; http_method; content:"/ijeuwaesika/nna/refs/heads/main/ifiinms.txt"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3258033/; classtype:trojan-activity;sid:84121133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257471)"; flow:established,from_client; content:"GET"; http_method; content:"/net/net.xsl"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"cat.xiaoshabi.nl"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257471/; classtype:trojan-activity;sid:84120571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257473)"; flow:established,from_client; content:"GET"; http_method; content:"/javaw2/net/net.xsl"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"sec.xiaoshabi.nl"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257473/; classtype:trojan-activity;sid:84120573; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257450)"; flow:established,from_client; content:"GET"; http_method; content:"/netstat.ps1"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"cat.dashabi.in"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257450/; classtype:trojan-activity;sid:84120550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257451)"; flow:established,from_client; content:"GET"; http_method; content:"/javaw2/winring0x64.sys"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"sec.dashabi.in"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257451/; classtype:trojan-activity;sid:84120551; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257457)"; flow:established,from_client; content:"GET"; http_method; content:"/javaw2/javaw"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"sec.dashabi.in"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257457/; classtype:trojan-activity;sid:84120557; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257464)"; flow:established,from_client; content:"GET"; http_method; content:"/javaw2/instance.ps1"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"sec.xiaojiji.nl"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257464/; classtype:trojan-activity;sid:84120564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3257465)"; flow:established,from_client; content:"GET"; http_method; content:"/netstat.ps1"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"cat.xiaojiji.nl"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_27; reference:url, urlhaus.abuse.ch/url/3257465/; classtype:trojan-activity;sid:84120565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3254228)"; flow:established,from_client; content:"GET"; http_method; content:"/kdot227/somalifuscator/archive/refs/heads/main.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_26; reference:url, urlhaus.abuse.ch/url/3254228/; classtype:trojan-activity;sid:84117328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3254222)"; flow:established,from_client; content:"GET"; http_method; content:"/robloxdev1223/requirements/raw/main/requirements.exe"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_26; reference:url, urlhaus.abuse.ch/url/3254222/; classtype:trojan-activity;sid:84117322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3252630)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/17267811/stm.txt"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_25; reference:url, urlhaus.abuse.ch/url/3252630/; classtype:trojan-activity;sid:84115730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249739)"; flow:established,from_client; content:"GET"; http_method; content:"/img_up/shop_pds/nicehana/client.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"www.xn--on3b15m2lco2u.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249739/; classtype:trojan-activity;sid:84112839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249735)"; flow:established,from_client; content:"GET"; http_method; content:"/client.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"119.193.158.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249735/; classtype:trojan-activity;sid:84112835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249675)"; flow:established,from_client; content:"GET"; http_method; content:"/quasar/quasar/releases/download/v1.4.1/quasar.v1.4.1.zip"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249675/; classtype:trojan-activity;sid:84112775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3249662)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/refs/heads/master/rat/njrat.exe"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_23; reference:url, urlhaus.abuse.ch/url/3249662/; classtype:trojan-activity;sid:84112762; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3246018)"; flow:established,from_client; content:"GET"; http_method; content:"/mestalic/site/refs/heads/main/file.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3246018/; classtype:trojan-activity;sid:84109118; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245733)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.152.219.150"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245733/; classtype:trojan-activity;sid:84108833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245732)"; flow:established,from_client; content:"GET"; http_method; content:"/vz.txt"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"51.79.124.111"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245732/; classtype:trojan-activity;sid:84108832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245730)"; flow:established,from_client; content:"GET"; http_method; content:"/chinese.txt"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"202.129.16.172"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245730/; classtype:trojan-activity;sid:84108830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245463)"; flow:established,from_client; content:"GET"; http_method; content:"/hs.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"146.0.42.82"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245463/; classtype:trojan-activity;sid:84108563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245459)"; flow:established,from_client; content:"GET"; http_method; content:"/kg.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"146.0.42.82"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245459/; classtype:trojan-activity;sid:84108559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3245458)"; flow:established,from_client; content:"GET"; http_method; content:"/keygen.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"146.0.42.82"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_20; reference:url, urlhaus.abuse.ch/url/3245458/; classtype:trojan-activity;sid:84108558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3243086)"; flow:established,from_client; content:"GET"; http_method; content:"/update/data/update.exe"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"114.55.106.136"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3243086/; classtype:trojan-activity;sid:84106186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3243082)"; flow:established,from_client; content:"GET"; http_method; content:"/sysupdate/ckbgd/2.3.0624.zip"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"8.131.63.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3243082/; classtype:trojan-activity;sid:84106182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3243077)"; flow:established,from_client; content:"GET"; http_method; content:"/sysupdate/ckbgd/2.3.0703.zip"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"8.131.63.6"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3243077/; classtype:trojan-activity;sid:84106177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242983)"; flow:established,from_client; content:"GET"; http_method; content:"/flowseal/zapret-discord-youtube/releases/download/1.1.1/zapret-discord-youtube-1.1.1.rar"; http_uri; depth:89; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242983/; classtype:trojan-activity;sid:84106083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242769)"; flow:established,from_client; content:"GET"; http_method; content:"/docs/solr.sh"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"119.192.128.163"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242769/; classtype:trojan-activity;sid:84105869; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242663)"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack0832.zip"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"cd.textfiles.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242663/; classtype:trojan-activity;sid:84105763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3242642)"; flow:established,from_client; content:"GET"; http_method; content:"/rishabhkumardeveloper/malware_analysis_using_ml/main/wildfire-test-pe-file.exe"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_19; reference:url, urlhaus.abuse.ch/url/3242642/; classtype:trojan-activity;sid:84105742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241764)"; flow:established,from_client; content:"GET"; http_method; content:"/mori-miyako/discord-token-generator/zip/refs/heads/main"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241764/; classtype:trojan-activity;sid:84104864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241765)"; flow:established,from_client; content:"GET"; http_method; content:"/scode18/all-tweaker/main/tweaks.7z"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241765/; classtype:trojan-activity;sid:84104865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241637)"; flow:established,from_client; content:"GET"; http_method; content:"/s107000665/c1/master/1223.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241637/; classtype:trojan-activity;sid:84104737; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241638)"; flow:established,from_client; content:"GET"; http_method; content:"/iciamyplant/ctf/master/plantrojan.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241638/; classtype:trojan-activity;sid:84104738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241639)"; flow:established,from_client; content:"GET"; http_method; content:"/fengjixuchui/cve-2022-26810/main/shellcode.bin"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241639/; classtype:trojan-activity;sid:84104739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241640)"; flow:established,from_client; content:"GET"; http_method; content:"/killbillpribil/world-of-tanks/master/world%20of%20tanks.exe"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241640/; classtype:trojan-activity;sid:84104740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241641)"; flow:established,from_client; content:"GET"; http_method; content:"/mach1el/htb-scripts/master/exploit-fuse/shell.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241641/; classtype:trojan-activity;sid:84104741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241642)"; flow:established,from_client; content:"GET"; http_method; content:"/khr0x40sh/whitelistevasion/master/installutil/script.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241642/; classtype:trojan-activity;sid:84104742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241635)"; flow:established,from_client; content:"GET"; http_method; content:"/msf.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"qiniuyunxz.yxflzs.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241635/; classtype:trojan-activity;sid:84104735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241559)"; flow:established,from_client; content:"GET"; http_method; content:"/c5hackr/phantom/main/phantom/resources/donut.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241559/; classtype:trojan-activity;sid:84104659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241127)"; flow:established,from_client; content:"GET"; http_method; content:"/justincoding3/slumfun/main/obfuscated.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241127/; classtype:trojan-activity;sid:84104227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241126)"; flow:established,from_client; content:"GET"; http_method; content:"/r00t-3xp10it/redpill/main/utils/compiled.exe"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241126/; classtype:trojan-activity;sid:84104226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241125)"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms14-068/ms14-068.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241125/; classtype:trojan-activity;sid:84104225; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241123)"; flow:established,from_client; content:"GET"; http_method; content:"/prowindows365/hailhydra/refs/heads/main/hailhydra.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241123/; classtype:trojan-activity;sid:84104223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3241055)"; flow:established,from_client; content:"GET"; http_method; content:"/neo23x0/signature-base/archive/master.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3241055/; classtype:trojan-activity;sid:84104155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240999)"; flow:established,from_client; content:"GET"; http_method; content:"/sad-dust/death/main/stealinfo.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240999/; classtype:trojan-activity;sid:84104099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240819)"; flow:established,from_client; content:"GET"; http_method; content:"/redcanaryco/atomic-red-team/master/atomics/t1204.002/bin/test10.lnk"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240819/; classtype:trojan-activity;sid:84103919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240817)"; flow:established,from_client; content:"GET"; http_method; content:"/cuckoobox/cuckoo/archive/master.zip"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240817/; classtype:trojan-activity;sid:84103917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240813)"; flow:established,from_client; content:"GET"; http_method; content:"/haxork8880/files/main/windowssync.txt.zip"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240813/; classtype:trojan-activity;sid:84103913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240814)"; flow:established,from_client; content:"GET"; http_method; content:"/crjtpp/tpplab_public/main/poc-sample-lnk.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240814/; classtype:trojan-activity;sid:84103914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240812)"; flow:established,from_client; content:"GET"; http_method; content:"/hackerx237/miner/main/my-files.lnk"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240812/; classtype:trojan-activity;sid:84103912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240811)"; flow:established,from_client; content:"GET"; http_method; content:"/scode18/all-tweaker/releases/download/beta_v0.6/all.tweaker.beta.v0.6.7z"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240811/; classtype:trojan-activity;sid:84103911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240810)"; flow:established,from_client; content:"GET"; http_method; content:"/scode18/all-tweaker/raw/main/tweaks.7z"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240810/; classtype:trojan-activity;sid:84103910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240720)"; flow:established,from_client; content:"GET"; http_method; content:"/dqwr1q23rwdfr/xxx/releases/download/xxx/vital.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240720/; classtype:trojan-activity;sid:84103820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3240639)"; flow:established,from_client; content:"GET"; http_method; content:"/mohdjulaya09/code-sparrow-crypter-2.0-private-crack-leak/releases/download/%23crypter/codesparrow.crypter.2.0.crack.rar"; http_uri; depth:120; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_18; reference:url, urlhaus.abuse.ch/url/3240639/; classtype:trojan-activity;sid:84103739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3239707)"; flow:established,from_client; content:"GET"; http_method; content:"/demon.x64.bin"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"8.138.96.41"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_17; reference:url, urlhaus.abuse.ch/url/3239707/; classtype:trojan-activity;sid:84102807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3238061)"; flow:established,from_client; content:"GET"; http_method; content:"/grozniy1/folder/main/444.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3238061/; classtype:trojan-activity;sid:84101161; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237975)"; flow:established,from_client; content:"GET"; http_method; content:"/da2dalus/the-malware-repo/blob/master/rat/njrat.exe|3f|raw=true"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237975/; classtype:trojan-activity;sid:84101075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237976)"; flow:established,from_client; content:"GET"; http_method; content:"/5556.rar"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"188.212.158.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237976/; classtype:trojan-activity;sid:84101076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237861)"; flow:established,from_client; content:"GET"; http_method; content:"/joh81/exploi01/zip/refs/heads/main"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237861/; classtype:trojan-activity;sid:84100961; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237810)"; flow:established,from_client; content:"GET"; http_method; content:"/steve824/a/zip/refs/heads/main"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237810/; classtype:trojan-activity;sid:84100910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237737)"; flow:established,from_client; content:"GET"; http_method; content:"/thebb5th/123/zip/refs/heads/main"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237737/; classtype:trojan-activity;sid:84100837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237465)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_suia0iczdw2reew1f9hgunezxcwv52d"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237465/; classtype:trojan-activity;sid:84100565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3237464)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_3ozdjl5puad8qn3tipydynn5j7l13el"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_10_16; reference:url, urlhaus.abuse.ch/url/3237464/; classtype:trojan-activity;sid:84100564; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236597)"; flow:established,from_client; content:"GET"; http_method; content:"/center.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"119.193.158.215"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236597/; classtype:trojan-activity;sid:84099697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236587)"; flow:established,from_client; content:"GET"; http_method; content:"/download/kedadecoder.zip"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"153.37.77.156"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236587/; classtype:trojan-activity;sid:84099687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236559)"; flow:established,from_client; content:"GET"; http_method; content:"/download/kedadecoder.zip"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"116.136.142.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236559/; classtype:trojan-activity;sid:84099659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236453)"; flow:established,from_client; content:"GET"; http_method; content:"/s3cur3th1ssh1t/creds/master/powershellscripts/invoke-petitpotam.ps1"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236453/; classtype:trojan-activity;sid:84099553; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236450)"; flow:established,from_client; content:"GET"; http_method; content:"/docs/x.rar"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"119.192.128.163"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236450/; classtype:trojan-activity;sid:84099550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236324)"; flow:established,from_client; content:"GET"; http_method; content:"/file/xwgl/xw_xxgl.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"data.yhydl.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236324/; classtype:trojan-activity;sid:84099424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236322)"; flow:established,from_client; content:"GET"; http_method; content:"/file/xw_setup.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"data.yhydl.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236322/; classtype:trojan-activity;sid:84099422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236323)"; flow:established,from_client; content:"GET"; http_method; content:"/file/yhy_setup.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"data.yhydl.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236323/; classtype:trojan-activity;sid:84099423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236318)"; flow:established,from_client; content:"GET"; http_method; content:"/products/4001/updates/efatura/efatura.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"elisans.novayonetim.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236318/; classtype:trojan-activity;sid:84099418; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236240)"; flow:established,from_client; content:"GET"; http_method; content:"/services/identification/server/gtptoolsdownloadhandler.ashx|3f|filename=gtp_6_browserplugin_setup.exe"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"hnjgdl.geps.glodon.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236240/; classtype:trojan-activity;sid:84099340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236237)"; flow:established,from_client; content:"GET"; http_method; content:"/natgo.exe"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"dl.natgo.cn"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236237/; classtype:trojan-activity;sid:84099337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3236154)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/17267811/stm.txt"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3236154/; classtype:trojan-activity;sid:84099254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235523)"; flow:established,from_client; content:"GET"; http_method; content:"/chainguard-dev/bincapz/archive/refs/tags/v0.5.0.zip"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235523/; classtype:trojan-activity;sid:84098623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235522)"; flow:established,from_client; content:"GET"; http_method; content:"/playmcbkuwu/vape/releases/download/stable/vape.v4.10.from.duckysolucky.zip"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235522/; classtype:trojan-activity;sid:84098622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235514)"; flow:established,from_client; content:"GET"; http_method; content:"/barrigudinha157/barrigudinha/raw/master/rage.dll"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235514/; classtype:trojan-activity;sid:84098614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235513)"; flow:established,from_client; content:"GET"; http_method; content:"/meckazin/chromekatz/releases/download/0.4.7/chromekatzbofs.zip"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_15; reference:url, urlhaus.abuse.ch/url/3235513/; classtype:trojan-activity;sid:84098613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3235094)"; flow:established,from_client; content:"GET"; http_method; content:"/xsh/update.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"101.126.11.168"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_14; reference:url, urlhaus.abuse.ch/url/3235094/; classtype:trojan-activity;sid:84098194; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3234859)"; flow:established,from_client; content:"GET"; http_method; content:"/petikvx/lockbit-black-builder/main/lockbit30/builder.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_14; reference:url, urlhaus.abuse.ch/url/3234859/; classtype:trojan-activity;sid:84097959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3234858)"; flow:established,from_client; content:"GET"; http_method; content:"/tennessene/lockbit/refs/heads/main/builder.exe"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_14; reference:url, urlhaus.abuse.ch/url/3234858/; classtype:trojan-activity;sid:84097958; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3231796)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/16737801/wave.zip|3f|"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_12; reference:url, urlhaus.abuse.ch/url/3231796/; classtype:trojan-activity;sid:84094896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3231794)"; flow:established,from_client; content:"GET"; http_method; content:"/user-attachments/files/16419615/solara.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_12; reference:url, urlhaus.abuse.ch/url/3231794/; classtype:trojan-activity;sid:84094894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3228667)"; flow:established,from_client; content:"GET"; http_method; content:"/winassist/login/login.7z"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"win.down.55kantu.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2024_10_10; reference:url, urlhaus.abuse.ch/url/3228667/; classtype:trojan-activity;sid:84091767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3226239)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.22.0/xmrig-6.22.0-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_09; reference:url, urlhaus.abuse.ch/url/3226239/; classtype:trojan-activity;sid:84089339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218033)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"109.207.216.197"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218033/; classtype:trojan-activity;sid:84081133; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218030)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"86.106.101.159"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218030/; classtype:trojan-activity;sid:84081130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218022)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"212.3.211.157"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218022/; classtype:trojan-activity;sid:84081122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218009)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"109.207.217.114"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218009/; classtype:trojan-activity;sid:84081109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218011)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"166.147.146.187"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218011/; classtype:trojan-activity;sid:84081111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3218001)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.96.13.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3218001/; classtype:trojan-activity;sid:84081101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217802)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"85.130.160.219"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217802/; classtype:trojan-activity;sid:84080902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217784)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.35.233.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217784/; classtype:trojan-activity;sid:84080884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217775)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.191.89.122"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217775/; classtype:trojan-activity;sid:84080875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217753)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.35.233.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217753/; classtype:trojan-activity;sid:84080853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217757)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"86.106.155.155"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217757/; classtype:trojan-activity;sid:84080857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217760)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"87.97.161.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217760/; classtype:trojan-activity;sid:84080860; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217750)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.28.228.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217750/; classtype:trojan-activity;sid:84080850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217745)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"87.97.161.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217745/; classtype:trojan-activity;sid:84080845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217740)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.203.169.41"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217740/; classtype:trojan-activity;sid:84080840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217717)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"87.97.161.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217717/; classtype:trojan-activity;sid:84080817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217719)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.35.233.220"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217719/; classtype:trojan-activity;sid:84080819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217729)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"87.97.161.106"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217729/; classtype:trojan-activity;sid:84080829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217689)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.96.13.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217689/; classtype:trojan-activity;sid:84080789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217684)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.43.16.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217684/; classtype:trojan-activity;sid:84080784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217681)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.45.183.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217681/; classtype:trojan-activity;sid:84080781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217682)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.45.183.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217682/; classtype:trojan-activity;sid:84080782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217665)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"213.96.13.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217665/; classtype:trojan-activity;sid:84080765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217674)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.191.89.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217674/; classtype:trojan-activity;sid:84080774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217638)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"14.161.6.225"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217638/; classtype:trojan-activity;sid:84080738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217562)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.212.35.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217562/; classtype:trojan-activity;sid:84080662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217557)"; flow:established,from_client; content:"GET"; http_method; content:"/123.ps1"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"103.247.164.242"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217557/; classtype:trojan-activity;sid:84080657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217454)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"99.118.215.24"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217454/; classtype:trojan-activity;sid:84080554; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217426)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.212.35.175"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217426/; classtype:trojan-activity;sid:84080526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217131)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.252.66.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217131/; classtype:trojan-activity;sid:84080231; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217136)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.254.255.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217136/; classtype:trojan-activity;sid:84080236; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217092)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.185.119.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217092/; classtype:trojan-activity;sid:84080192; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217098)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.238.209.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217098/; classtype:trojan-activity;sid:84080198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217109)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.16.249.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217109/; classtype:trojan-activity;sid:84080209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217088)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.145.205.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217088/; classtype:trojan-activity;sid:84080188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217090)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.108.84.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217090/; classtype:trojan-activity;sid:84080190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217073)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"197.159.1.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217073/; classtype:trojan-activity;sid:84080173; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217056)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.101.81.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217056/; classtype:trojan-activity;sid:84080156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217059)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.88.180.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217059/; classtype:trojan-activity;sid:84080159; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217062)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.78.201.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217062/; classtype:trojan-activity;sid:84080162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217063)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"181.49.47.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217063/; classtype:trojan-activity;sid:84080163; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217065)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.237.4.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217065/; classtype:trojan-activity;sid:84080165; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217066)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"200.69.219.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217066/; classtype:trojan-activity;sid:84080166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217009)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"58.145.168.170"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217009/; classtype:trojan-activity;sid:84080109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217012)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"181.94.245.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217012/; classtype:trojan-activity;sid:84080112; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217020)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.148.18.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217020/; classtype:trojan-activity;sid:84080120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3217004)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.253.115.156"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3217004/; classtype:trojan-activity;sid:84080104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216967)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.113.124.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216967/; classtype:trojan-activity;sid:84080067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216979)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"195.34.91.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216979/; classtype:trojan-activity;sid:84080079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216983)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.57.33.51"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216983/; classtype:trojan-activity;sid:84080083; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216986)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.253.115.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216986/; classtype:trojan-activity;sid:84080086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216987)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"88.119.151.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216987/; classtype:trojan-activity;sid:84080087; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216961)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"93.118.112.68"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216961/; classtype:trojan-activity;sid:84080061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216962)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.90.207.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216962/; classtype:trojan-activity;sid:84080062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216963)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"212.73.75.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216963/; classtype:trojan-activity;sid:84080063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216956)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.89.245.118"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216956/; classtype:trojan-activity;sid:84080056; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216924)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.143.133.215"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216924/; classtype:trojan-activity;sid:84080024; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216934)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.179.121.235"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216934/; classtype:trojan-activity;sid:84080034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216935)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.90.207.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216935/; classtype:trojan-activity;sid:84080035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216936)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.148.20.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216936/; classtype:trojan-activity;sid:84080036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216937)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"181.211.252.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216937/; classtype:trojan-activity;sid:84080037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216917)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"206.214.35.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216917/; classtype:trojan-activity;sid:84080017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216889)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"138.122.43.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216889/; classtype:trojan-activity;sid:84079989; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216893)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.87.223.241"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216893/; classtype:trojan-activity;sid:84079993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216894)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.131.244.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216894/; classtype:trojan-activity;sid:84079994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216906)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"151.236.247.230"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216906/; classtype:trojan-activity;sid:84080006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216883)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.12.78.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216883/; classtype:trojan-activity;sid:84079983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216860)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"85.187.82.120"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216860/; classtype:trojan-activity;sid:84079960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216843)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"76.76.195.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216843/; classtype:trojan-activity;sid:84079943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216846)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.217.215.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216846/; classtype:trojan-activity;sid:84079946; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216809)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"27.147.225.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216809/; classtype:trojan-activity;sid:84079909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216820)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"181.143.114.106"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216820/; classtype:trojan-activity;sid:84079920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216823)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"118.179.203.50"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216823/; classtype:trojan-activity;sid:84079923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216802)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"109.160.87.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216802/; classtype:trojan-activity;sid:84079902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216800)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"98.103.171.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216800/; classtype:trojan-activity;sid:84079900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216794)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"186.154.93.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216794/; classtype:trojan-activity;sid:84079894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216796)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.192.22.166"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216796/; classtype:trojan-activity;sid:84079896; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216772)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"89.231.14.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216772/; classtype:trojan-activity;sid:84079872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216735)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.0.129.134"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216735/; classtype:trojan-activity;sid:84079835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216739)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.64.210.218"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216739/; classtype:trojan-activity;sid:84079839; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216740)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.77.74.90"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216740/; classtype:trojan-activity;sid:84079840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216722)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.57.69.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216722/; classtype:trojan-activity;sid:84079822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216719)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"88.116.62.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216719/; classtype:trojan-activity;sid:84079819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216710)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.211.135.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216710/; classtype:trojan-activity;sid:84079810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216704)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"88.135.26.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216704/; classtype:trojan-activity;sid:84079804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216682)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.66.151.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216682/; classtype:trojan-activity;sid:84079782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216685)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"46.151.56.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216685/; classtype:trojan-activity;sid:84079785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216686)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"88.119.193.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216686/; classtype:trojan-activity;sid:84079786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216694)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"178.151.143.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216694/; classtype:trojan-activity;sid:84079794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216700)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"200.61.163.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216700/; classtype:trojan-activity;sid:84079800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216702)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"193.169.146.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216702/; classtype:trojan-activity;sid:84079802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216649)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.148.18.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216649/; classtype:trojan-activity;sid:84079749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216653)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"188.72.6.218"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216653/; classtype:trojan-activity;sid:84079753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216658)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"185.236.46.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216658/; classtype:trojan-activity;sid:84079758; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216626)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"154.0.129.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216626/; classtype:trojan-activity;sid:84079726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216627)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"182.160.102.188"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216627/; classtype:trojan-activity;sid:84079727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216607)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.16.247.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216607/; classtype:trojan-activity;sid:84079707; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216599)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"213.6.74.138"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216599/; classtype:trojan-activity;sid:84079699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216600)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"37.233.63.185"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216600/; classtype:trojan-activity;sid:84079700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216577)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"81.16.247.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216577/; classtype:trojan-activity;sid:84079677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216581)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"190.2.237.104"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216581/; classtype:trojan-activity;sid:84079681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216584)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"213.91.236.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216584/; classtype:trojan-activity;sid:84079684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216559)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"77.46.170.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216559/; classtype:trojan-activity;sid:84079659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216561)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"202.148.5.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216561/; classtype:trojan-activity;sid:84079661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216564)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"176.221.111.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216564/; classtype:trojan-activity;sid:84079664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216529)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"36.66.139.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216529/; classtype:trojan-activity;sid:84079629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216481)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"41.78.75.186"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216481/; classtype:trojan-activity;sid:84079581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216479)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"91.92.82.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216479/; classtype:trojan-activity;sid:84079579; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216456)"; flow:established,from_client; content:"GET"; http_method; content:"/help.scr"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"121.43.104.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216456/; classtype:trojan-activity;sid:84079556; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216443)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"87.249.142.126"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216443/; classtype:trojan-activity;sid:84079543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216421)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"217.92.214.15"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216421/; classtype:trojan-activity;sid:84079521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216418)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"80.249.6.118"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216418/; classtype:trojan-activity;sid:84079518; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216413)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"212.98.186.8"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216413/; classtype:trojan-activity;sid:84079513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216406)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"49.232.126.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216406/; classtype:trojan-activity;sid:84079506; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216404)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"150.158.25.244"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216404/; classtype:trojan-activity;sid:84079504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216396)"; flow:established,from_client; content:"GET"; http_method; content:"/help.scr"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"121.43.104.75"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216396/; classtype:trojan-activity;sid:84079496; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216384)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.132.12.146"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216384/; classtype:trojan-activity;sid:84079484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216382)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"50.65.169.30"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216382/; classtype:trojan-activity;sid:84079482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216377)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"36.110.15.211"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216377/; classtype:trojan-activity;sid:84079477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216372)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"178.61.160.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216372/; classtype:trojan-activity;sid:84079472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216365)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"124.123.123.15"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216365/; classtype:trojan-activity;sid:84079465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216353)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"123.117.136.97"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216353/; classtype:trojan-activity;sid:84079453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216334)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"43.132.13.252"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216334/; classtype:trojan-activity;sid:84079434; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216322)"; flow:established,from_client; content:"GET"; http_method; content:"/mozi.m"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"184.185.30.182"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216322/; classtype:trojan-activity;sid:84079422; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3216306)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"94.76.156.101"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3216306/; classtype:trojan-activity;sid:84079406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215823)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.217.215.238"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215823/; classtype:trojan-activity;sid:84078923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215826)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"27.147.225.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215826/; classtype:trojan-activity;sid:84078926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215816)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.57.69.125"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215816/; classtype:trojan-activity;sid:84078916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215795)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"176.221.111.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215795/; classtype:trojan-activity;sid:84078895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215775)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"88.119.193.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215775/; classtype:trojan-activity;sid:84078875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215483)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.26.81.99"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215483/; classtype:trojan-activity;sid:84078583; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215478)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.160.102.188"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215478/; classtype:trojan-activity;sid:84078578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215476)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"88.135.26.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215476/; classtype:trojan-activity;sid:84078576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215468)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"88.119.151.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215468/; classtype:trojan-activity;sid:84078568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215469)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.16.247.83"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215469/; classtype:trojan-activity;sid:84078569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215463)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.160.87.2"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215463/; classtype:trojan-activity;sid:84078563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215452)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.78.75.186"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215452/; classtype:trojan-activity;sid:84078552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215434)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.91.236.237"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215434/; classtype:trojan-activity;sid:84078534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215440)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"184.185.30.182"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215440/; classtype:trojan-activity;sid:84078540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215422)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"206.214.35.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215422/; classtype:trojan-activity;sid:84078522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215403)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.143.114.106"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215403/; classtype:trojan-activity;sid:84078503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215398)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.211.250.118"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215398/; classtype:trojan-activity;sid:84078498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215380)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"88.116.62.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215380/; classtype:trojan-activity;sid:84078480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215371)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"77.238.209.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215371/; classtype:trojan-activity;sid:84078471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215372)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.105.196.30"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215372/; classtype:trojan-activity;sid:84078472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3215356)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.211.135.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_10_06; reference:url, urlhaus.abuse.ch/url/3215356/; classtype:trojan-activity;sid:84078456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3213897)"; flow:established,from_client; content:"GET"; http_method; content:"/matinrco/tor/releases/download/v0.4.5.10/tor-expert-bundle-v0.4.5.10.zip"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_10_05; reference:url, urlhaus.abuse.ch/url/3213897/; classtype:trojan-activity;sid:84076997; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3206293)"; flow:established,from_client; content:"GET"; http_method; content:"/ox2fa/justnow/refs/heads/main/2pac.php"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_10_03; reference:url, urlhaus.abuse.ch/url/3206293/; classtype:trojan-activity;sid:84069393; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3200548)"; flow:established,from_client; content:"GET"; http_method; content:"/slinky/slinkycrack.zip"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"crystalpvp.ru"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_09_29; reference:url, urlhaus.abuse.ch/url/3200548/; classtype:trojan-activity;sid:84063648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3198753)"; flow:established,from_client; content:"GET"; http_method; content:"/pinginfoview.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"139.198.15.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3198753/; classtype:trojan-activity;sid:84061853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3198696)"; flow:established,from_client; content:"GET"; http_method; content:"/cen22.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"39.100.33.142"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3198696/; classtype:trojan-activity;sid:84061796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3195883)"; flow:established,from_client; content:"GET"; http_method; content:"/scanport.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"139.198.15.223"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3195883/; classtype:trojan-activity;sid:84058983; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3195736)"; flow:established,from_client; content:"GET"; http_method; content:"/fx8"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"123.57.250.154"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_28; reference:url, urlhaus.abuse.ch/url/3195736/; classtype:trojan-activity;sid:84058836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3190317)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"112.4.110.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_09_25; reference:url, urlhaus.abuse.ch/url/3190317/; classtype:trojan-activity;sid:84053417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3190315)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"109.166.211.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_25; reference:url, urlhaus.abuse.ch/url/3190315/; classtype:trojan-activity;sid:84053415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3190313)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"109.166.211.222"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_25; reference:url, urlhaus.abuse.ch/url/3190313/; classtype:trojan-activity;sid:84053413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3189225)"; flow:established,from_client; content:"GET"; http_method; content:"/unknwon1352/qawfdasfaw/main/software.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_24; reference:url, urlhaus.abuse.ch/url/3189225/; classtype:trojan-activity;sid:84052325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3188620)"; flow:established,from_client; content:"GET"; http_method; content:"/repository/aa_v3.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"83.149.17.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_09_24; reference:url, urlhaus.abuse.ch/url/3188620/; classtype:trojan-activity;sid:84051720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3188034)"; flow:established,from_client; content:"GET"; http_method; content:"/blueskyxn/changesource/master/besttrace"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_23; reference:url, urlhaus.abuse.ch/url/3188034/; classtype:trojan-activity;sid:84051134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186441)"; flow:established,from_client; content:"GET"; http_method; content:"/dxl_win_tool_v9.6.iso"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"down.fwqlt.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186441/; classtype:trojan-activity;sid:84049541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186440)"; flow:established,from_client; content:"GET"; http_method; content:"/1-%e4%bf%ae%e6%94%b9%e7%ab%af%e5%8f%a3.iso"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"down.fwqlt.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186440/; classtype:trojan-activity;sid:84049540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186439)"; flow:established,from_client; content:"GET"; http_method; content:"/dxl_win_tool_v9.4.iso"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"down.fwqlt.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186439/; classtype:trojan-activity;sid:84049539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186430)"; flow:established,from_client; content:"GET"; http_method; content:"/1-%e4%bf%ae%e6%94%b9%e7%ab%af%e5%8f%a3.zip"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"down.fwqlt.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186430/; classtype:trojan-activity;sid:84049530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3186428)"; flow:established,from_client; content:"GET"; http_method; content:"/1_dxl_windowsport.zip"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"down.fwqlt.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_09_22; reference:url, urlhaus.abuse.ch/url/3186428/; classtype:trojan-activity;sid:84049528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3183909)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/z-downloads/"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"ignetwork.us"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_09_21; reference:url, urlhaus.abuse.ch/url/3183909/; classtype:trojan-activity;sid:84047009; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3178401)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1v9ujqbyj-mlf9mugkyiwow6t3rpui2bu"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_09_17; reference:url, urlhaus.abuse.ch/url/3178401/; classtype:trojan-activity;sid:84041501; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174523)"; flow:established,from_client; content:"GET"; http_method; content:"/scribblercoder/browserthief/main/browserthief.ps1"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174523/; classtype:trojan-activity;sid:84037623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174364)"; flow:established,from_client; content:"GET"; http_method; content:"/foru.apk"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tecunonline.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174364/; classtype:trojan-activity;sid:84037464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174340)"; flow:established,from_client; content:"GET"; http_method; content:"/foru.apk"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"www.tecunonline.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174340/; classtype:trojan-activity;sid:84037440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3174264)"; flow:established,from_client; content:"GET"; http_method; content:"/keygen"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"146.0.42.82"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3174264/; classtype:trojan-activity;sid:84037364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3173868)"; flow:established,from_client; content:"GET"; http_method; content:"/file.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"85.25.72.70"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_09_15; reference:url, urlhaus.abuse.ch/url/3173868/; classtype:trojan-activity;sid:84036968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3163579)"; flow:established,from_client; content:"GET"; http_method; content:"/handler/download|3f|action=download|7c|26|7c|download_id=jgc6slaf|7c|26|7c|private_id=0|7c|26|7c|url=https%253a%252f%252fyoutransfer.net%252fjgc6slaf"; http_uri; depth:150; isdataat:!1,relative; nocase; content:"youtransfer.net"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_09_09; reference:url, urlhaus.abuse.ch/url/3163579/; classtype:trojan-activity;sid:84026679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3158119)"; flow:established,from_client; content:"GET"; http_method; content:"/ooiswdqivgs125.bin"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"91.224.92.16"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_09_05; reference:url, urlhaus.abuse.ch/url/3158119/; classtype:trojan-activity;sid:84021219; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3154718)"; flow:established,from_client; content:"GET"; http_method; content:"/hackirby/discord-injection/main/injection.js"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_09_03; reference:url, urlhaus.abuse.ch/url/3154718/; classtype:trojan-activity;sid:84017818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135722)"; flow:established,from_client; content:"GET"; http_method; content:"/sosinchik/asd/main/zoom.py"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135722/; classtype:trojan-activity;sid:83998822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135724)"; flow:established,from_client; content:"GET"; http_method; content:"/moneroocean/xmrig_setup/master/setup_moneroocean_miner.sh"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135724/; classtype:trojan-activity;sid:83998824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3135613)"; flow:established,from_client; content:"GET"; http_method; content:"/log/orgn.txt"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"epanpano.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_30; reference:url, urlhaus.abuse.ch/url/3135613/; classtype:trojan-activity;sid:83998713; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3134371)"; flow:established,from_client; content:"GET"; http_method; content:"/qqhelper_1540.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"down.qqfarmer.com.cn"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2024_08_29; reference:url, urlhaus.abuse.ch/url/3134371/; classtype:trojan-activity;sid:83997471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129654)"; flow:established,from_client; content:"GET"; http_method; content:"/nova_flow/patcher.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"144.172.71.105"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129654/; classtype:trojan-activity;sid:83992754; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129577)"; flow:established,from_client; content:"GET"; http_method; content:"/pages/update/css/self/[upg]css.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"cs.go.kg"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129577/; classtype:trojan-activity;sid:83992677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129478)"; flow:established,from_client; content:"GET"; http_method; content:"/zoldownload/foobar2000_v1.6.7_beta_17@1704_129472.exe"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"down10d.zol.com.cn"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129478/; classtype:trojan-activity;sid:83992578; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3129417)"; flow:established,from_client; content:"GET"; http_method; content:"/asmedises/pxray_cast_sort.exe"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"www.medises.co.kr"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_08_26; reference:url, urlhaus.abuse.ch/url/3129417/; classtype:trojan-activity;sid:83992517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112427)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"190.104.213.45"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112427/; classtype:trojan-activity;sid:83975527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112426)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"200.29.120.130"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112426/; classtype:trojan-activity;sid:83975526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112419)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"93.182.76.169"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112419/; classtype:trojan-activity;sid:83975519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112420)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"93.182.76.169"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112420/; classtype:trojan-activity;sid:83975520; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3112417)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.121.250.206"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_17; reference:url, urlhaus.abuse.ch/url/3112417/; classtype:trojan-activity;sid:83975517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108504)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/webcam.dll"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108504/; classtype:trojan-activity;sid:83971604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108505)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/token%20grabber.dll"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108505/; classtype:trojan-activity;sid:83971605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108506)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/rootkit.dll"; http_uri; depth:67; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108506/; classtype:trojan-activity;sid:83971606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108507)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/unrootkit.dll"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108507/; classtype:trojan-activity;sid:83971607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108503)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/master/discord%20rat/resources/passwordstealer.dll"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108503/; classtype:trojan-activity;sid:83971603; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108502)"; flow:established,from_client; content:"GET"; http_method; content:"/openark/version.txt"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"file.blackint3.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108502/; classtype:trojan-activity;sid:83971602; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108492)"; flow:established,from_client; content:"GET"; http_method; content:"/openark/openark64.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"file.blackint3.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108492/; classtype:trojan-activity;sid:83971592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3108491)"; flow:established,from_client; content:"GET"; http_method; content:"/openark/openark32.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"file.blackint3.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_08_15; reference:url, urlhaus.abuse.ch/url/3108491/; classtype:trojan-activity;sid:83971591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106560)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808120646if_/http:/154.216.19.139/bins/mirai.armv4l"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106560/; classtype:trojan-activity;sid:83969660; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106559)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122936if_/http:/154.216.19.139/bins/mirai.gnueabihf"; http_uri; depth:64; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106559/; classtype:trojan-activity;sid:83969659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106558)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808120223if_/http:/154.216.19.139/bins/mirai.bin"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106558/; classtype:trojan-activity;sid:83969658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106556)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121041if_/http:/154.216.19.139/bins/mirai.armv6l"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106556/; classtype:trojan-activity;sid:83969656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106557)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808123114if_/http:/154.216.19.139/bins/mirai.arc"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106557/; classtype:trojan-activity;sid:83969657; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106551)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122755if_/http:/154.216.19.139/bins/mirai.x86_64"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106551/; classtype:trojan-activity;sid:83969651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106552)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121121if_/http:/154.216.19.139/bins/mirai.armv7l"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106552/; classtype:trojan-activity;sid:83969652; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106553)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808120945if_/http:/154.216.19.139/bins/mirai.armv5l"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106553/; classtype:trojan-activity;sid:83969653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106554)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122159if_/http:/154.216.19.139/bins/mirai.powerpc"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106554/; classtype:trojan-activity;sid:83969654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3106555)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121832if_/http:/154.216.19.139/bins/mirai.mipsel"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_14; reference:url, urlhaus.abuse.ch/url/3106555/; classtype:trojan-activity;sid:83969655; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105147)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/extensions/test_move.bat"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105147/; classtype:trojan-activity;sid:83968247; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105148)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/extensions/test_virus.bat"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105148/; classtype:trojan-activity;sid:83968248; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105149)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/extensions/keylogger.exe"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105149/; classtype:trojan-activity;sid:83968249; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105150)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/extensions/networks_profile.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105150/; classtype:trojan-activity;sid:83968250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105145)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/backdoor.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105145/; classtype:trojan-activity;sid:83968245; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105146)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/extensions/fill_storage_move.bat"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105146/; classtype:trojan-activity;sid:83968246; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3105144)"; flow:established,from_client; content:"GET"; http_method; content:"/s3q/blackdoor/main/extensions/fill_storage_virus.bat"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_13; reference:url, urlhaus.abuse.ch/url/3105144/; classtype:trojan-activity;sid:83968244; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3103488)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"64.234.95.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_12; reference:url, urlhaus.abuse.ch/url/3103488/; classtype:trojan-activity;sid:83966588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3103489)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"170.55.7.234"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_12; reference:url, urlhaus.abuse.ch/url/3103489/; classtype:trojan-activity;sid:83966589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3103476)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"187.247.242.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_08_12; reference:url, urlhaus.abuse.ch/url/3103476/; classtype:trojan-activity;sid:83966576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3100042)"; flow:established,from_client; content:"GET"; http_method; content:"/joelgmsec/invoke-stealth/main/resources/betterxencrypt/betterxencrypt.ps1"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3100042/; classtype:trojan-activity;sid:83963142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099961)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122448if_/http:/154.216.19.139/bins/mirai.sh4"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099961/; classtype:trojan-activity;sid:83963061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099963)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122636if_/http:/154.216.19.139/bins/mirai.sparc"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099963/; classtype:trojan-activity;sid:83963063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099965)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121347if_/http:/154.216.19.139/bins/mirai.m68k"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099965/; classtype:trojan-activity;sid:83963065; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099966)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121419if_/http:/154.216.19.139/bins/mirai.mips"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099966/; classtype:trojan-activity;sid:83963066; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3099960)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121308if_/http:/154.216.19.139/bins/mirai.i686"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_10; reference:url, urlhaus.abuse.ch/url/3099960/; classtype:trojan-activity;sid:83963060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097244)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808120223if_/http://154.216.19.139/bins/mirai.bin"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097244/; classtype:trojan-activity;sid:83960344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097239)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122755if_/http://154.216.19.139/bins/mirai.x86_64"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097239/; classtype:trojan-activity;sid:83960339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097240)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121041if_/http://154.216.19.139/bins/mirai.armv6l"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097240/; classtype:trojan-activity;sid:83960340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097241)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121230if_/http://154.216.19.139/bins/mirai.i586"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097241/; classtype:trojan-activity;sid:83960341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097242)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122636if_/http://154.216.19.139/bins/mirai.sparc"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097242/; classtype:trojan-activity;sid:83960342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097243)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121308if_/http://154.216.19.139/bins/mirai.i686"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097243/; classtype:trojan-activity;sid:83960343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097229)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122159if_/http://154.216.19.139/bins/mirai.powerpc"; http_uri; depth:63; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097229/; classtype:trojan-activity;sid:83960329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097230)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121347if_/http://154.216.19.139/bins/mirai.m68k"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097230/; classtype:trojan-activity;sid:83960330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097231)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121121if_/http://154.216.19.139/bins/mirai.armv7l"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097231/; classtype:trojan-activity;sid:83960331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097232)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808123114if_/http://154.216.19.139/bins/mirai.arc"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097232/; classtype:trojan-activity;sid:83960332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097233)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122448if_/http://154.216.19.139/bins/mirai.sh4"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097233/; classtype:trojan-activity;sid:83960333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097234)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121832if_/http://154.216.19.139/bins/mirai.mipsel"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097234/; classtype:trojan-activity;sid:83960334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097235)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808120945if_/http://154.216.19.139/bins/mirai.armv5l"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097235/; classtype:trojan-activity;sid:83960335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097236)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808120646if_/http://154.216.19.139/bins/mirai.armv4l"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097236/; classtype:trojan-activity;sid:83960336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097237)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808122936if_/http://154.216.19.139/bins/mirai.gnueabihf"; http_uri; depth:65; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097237/; classtype:trojan-activity;sid:83960337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3097238)"; flow:established,from_client; content:"GET"; http_method; content:"/web/20240808121419if_/http://154.216.19.139/bins/mirai.mips"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"web.archive.org"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_08_09; reference:url, urlhaus.abuse.ch/url/3097238/; classtype:trojan-activity;sid:83960338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3086390)"; flow:established,from_client; content:"GET"; http_method; content:"/supershell/compile/download/%5bwin"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"8.218.138.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_08_03; reference:url, urlhaus.abuse.ch/url/3086390/; classtype:trojan-activity;sid:83949490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072990)"; flow:established,from_client; content:"GET"; http_method; content:"/komasinfo/idcb/main/cbs_applcation_details_072602024_xlsx.rar"; http_uri; depth:62; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072990/; classtype:trojan-activity;sid:83936090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072974)"; flow:established,from_client; content:"GET"; http_method; content:"/adrinnno/ptwis/raw/main/file_cbs_app_details_no-0923871691_xlsx.zip"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072974/; classtype:trojan-activity;sid:83936074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072975)"; flow:established,from_client; content:"GET"; http_method; content:"/reporgu/fakado/raw/main/transaction_file_9812009_end_ids_yesbr5_pdf.rar"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072975/; classtype:trojan-activity;sid:83936075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072978)"; flow:established,from_client; content:"GET"; http_method; content:"/komasinfo/idcb/raw/main/cbs_applcation_details_072602024_xlsx.rar"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072978/; classtype:trojan-activity;sid:83936078; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072969)"; flow:established,from_client; content:"GET"; http_method; content:"/deannwas/policah/main/file_cbs_app_details_no-0923871691_xlsx.zip"; http_uri; depth:66; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072969/; classtype:trojan-activity;sid:83936069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3072972)"; flow:established,from_client; content:"GET"; http_method; content:"/reporgu/fakado/main/transaction_file_9812009_end_ids_yesbr5_pdf.rar"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_27; reference:url, urlhaus.abuse.ch/url/3072972/; classtype:trojan-activity;sid:83936072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058866)"; flow:established,from_client; content:"GET"; http_method; content:"/cve-2023-36874.zip"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"51.255.46.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058866/; classtype:trojan-activity;sid:83921966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058862)"; flow:established,from_client; content:"GET"; http_method; content:"/nc64.exe"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"51.255.46.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058862/; classtype:trojan-activity;sid:83921962; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058863)"; flow:established,from_client; content:"GET"; http_method; content:"/nc64.zip"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"51.255.46.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058863/; classtype:trojan-activity;sid:83921963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (3058864)"; flow:established,from_client; content:"GET"; http_method; content:"/b64"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"51.255.46.245"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_07_21; reference:url, urlhaus.abuse.ch/url/3058864/; classtype:trojan-activity;sid:83921964; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2949407)"; flow:established,from_client; content:"GET"; http_method; content:"/tan.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"www999999safagqwhg-1327129302.cos.ap-chengdu.myqcloud.com"; http_host; depth:57; isdataat:!1,relative; metadata:created_at 2024_07_11; reference:url, urlhaus.abuse.ch/url/2949407/; classtype:trojan-activity;sid:83812507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2949385)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1rsqnkyvcaein5m-gskl8coyuh8w5xrbd"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_07_11; reference:url, urlhaus.abuse.ch/url/2949385/; classtype:trojan-activity;sid:83812485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2949176)"; flow:established,from_client; content:"GET"; http_method; content:"/tan.jpg"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"www999999asgasg-1327129302.cos.ap-chengdu.myqcloud.com"; http_host; depth:54; isdataat:!1,relative; metadata:created_at 2024_07_11; reference:url, urlhaus.abuse.ch/url/2949176/; classtype:trojan-activity;sid:83812276; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2944285)"; flow:established,from_client; content:"GET"; http_method; content:"/jijilovedada/jijilovedada/main/tools/cc/adaptorovernight.exe"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_07_08; reference:url, urlhaus.abuse.ch/url/2944285/; classtype:trojan-activity;sid:83807385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2942567)"; flow:established,from_client; content:"GET"; http_method; content:"/supershell/compile/download/win"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"8.218.138.77"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_07_07; reference:url, urlhaus.abuse.ch/url/2942567/; classtype:trojan-activity;sid:83805667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934823)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/000.exe"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934823/; classtype:trojan-activity;sid:83797923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934824)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/trojan.malpack.themida%20(anti%20vm).exe"; http_uri; depth:102; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934824/; classtype:trojan-activity;sid:83797924; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934818)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/jigsaw.exe"; http_uri; depth:76; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934818/; classtype:trojan-activity;sid:83797918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934819)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/freeyoutubedownloader.exe"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934819/; classtype:trojan-activity;sid:83797919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934820)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/memz.exe"; http_uri; depth:70; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934820/; classtype:trojan-activity;sid:83797920; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934821)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/noescape.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934821/; classtype:trojan-activity;sid:83797921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934822)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/destover.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934822/; classtype:trojan-activity;sid:83797922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934816)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/meredrop.exe"; http_uri; depth:74; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934816/; classtype:trojan-activity;sid:83797916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934817)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/trojan/redlinestealer.exe"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934817/; classtype:trojan-activity;sid:83797917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934811)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/hive%20ransomware.exe"; http_uri; depth:87; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934811/; classtype:trojan-activity;sid:83797911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934812)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/wannacry.exe"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934812/; classtype:trojan-activity;sid:83797912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934813)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/nomoreransom.exe"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934813/; classtype:trojan-activity;sid:83797913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934808)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/petya.a.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934808/; classtype:trojan-activity;sid:83797908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934809)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/cryptowall.exe"; http_uri; depth:80; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934809/; classtype:trojan-activity;sid:83797909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934810)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/infinitycrypt.exe"; http_uri; depth:83; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934810/; classtype:trojan-activity;sid:83797910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2934805)"; flow:established,from_client; content:"GET"; http_method; content:"/trasherwithadollarsign/trashers-malware-repo/raw/main/ransomware/coronavirus.exe"; http_uri; depth:81; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_07_05; reference:url, urlhaus.abuse.ch/url/2934805/; classtype:trojan-activity;sid:83797905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911217)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"116.58.62.74"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911217/; classtype:trojan-activity;sid:83774317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911215)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"122.179.136.112"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911215/; classtype:trojan-activity;sid:83774315; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911212)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"130.185.193.208"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911212/; classtype:trojan-activity;sid:83774312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911196)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"78-20-115-5.access.telenet.be"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911196/; classtype:trojan-activity;sid:83774296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911194)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"195.103.203.106"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911194/; classtype:trojan-activity;sid:83774294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911190)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"78.20.115.5"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911190/; classtype:trojan-activity;sid:83774290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911191)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"88.28.218.163"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911191/; classtype:trojan-activity;sid:83774291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911187)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"102.53.15.18"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911187/; classtype:trojan-activity;sid:83774287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911184)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"126.23.203.236"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911184/; classtype:trojan-activity;sid:83774284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911154)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"95.255.114.11"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911154/; classtype:trojan-activity;sid:83774254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911113)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"softbank126023203236.bbtec.net"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911113/; classtype:trojan-activity;sid:83774213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911108)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"host-195-103-203-106.business.telecomitalia.it"; http_host; depth:46; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911108/; classtype:trojan-activity;sid:83774208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2911105)"; flow:established,from_client; content:"GET"; http_method; content:"/photo.scr"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"host-95-255-114-11.business.telecomitalia.it"; http_host; depth:44; isdataat:!1,relative; metadata:created_at 2024_06_28; reference:url, urlhaus.abuse.ch/url/2911105/; classtype:trojan-activity;sid:83774205; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909335)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1pjt23vhtwzyzypmtn3-laqctzzr5vb5d"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909335/; classtype:trojan-activity;sid:83772435; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909310)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"45.118.79.103"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909310/; classtype:trojan-activity;sid:83772410; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909291)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"89.184.185.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909291/; classtype:trojan-activity;sid:83772391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2909290)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.224.107.4"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2909290/; classtype:trojan-activity;sid:83772390; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908910)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"170.210.81.101"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908910/; classtype:trojan-activity;sid:83772010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908913)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"182.72.167.124"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908913/; classtype:trojan-activity;sid:83772013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908900)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"190.108.63.242"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908900/; classtype:trojan-activity;sid:83772000; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908902)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"202.57.39.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908902/; classtype:trojan-activity;sid:83772002; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908903)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"14.142.209.198"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908903/; classtype:trojan-activity;sid:83772003; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2908894)"; flow:established,from_client; content:"GET"; http_method; content:"/tftp"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"170.210.81.104"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_27; reference:url, urlhaus.abuse.ch/url/2908894/; classtype:trojan-activity;sid:83771994; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2901197)"; flow:established,from_client; content:"GET"; http_method; content:"/zwzonepieces/posapsi/master/chatlife.exe"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_22; reference:url, urlhaus.abuse.ch/url/2901197/; classtype:trojan-activity;sid:83764297; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2897332)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"5.202.101.153"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_19; reference:url, urlhaus.abuse.ch/url/2897332/; classtype:trojan-activity;sid:83760432; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2894025)"; flow:established,from_client; content:"GET"; http_method; content:"/kailash-jakhar/webpack-v5-tutorial/main/quizpokemon.exe"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_17; reference:url, urlhaus.abuse.ch/url/2894025/; classtype:trojan-activity;sid:83757125; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2888444)"; flow:established,from_client; content:"GET"; http_method; content:"/help.scr"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"124.67.254.109"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_14; reference:url, urlhaus.abuse.ch/url/2888444/; classtype:trojan-activity;sid:83751544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2888430)"; flow:established,from_client; content:"GET"; http_method; content:"/help.scr"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"117.157.17.194"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_14; reference:url, urlhaus.abuse.ch/url/2888430/; classtype:trojan-activity;sid:83751530; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2885860)"; flow:established,from_client; content:"GET"; http_method; content:"/brunovale03/adegaads/main/offeredbuilt.exe"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_13; reference:url, urlhaus.abuse.ch/url/2885860/; classtype:trojan-activity;sid:83748960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2883708)"; flow:established,from_client; content:"GET"; http_method; content:"/sirvivor32/sirvivor/main/lukejazz.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_06_11; reference:url, urlhaus.abuse.ch/url/2883708/; classtype:trojan-activity;sid:83746808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2881768)"; flow:established,from_client; content:"GET"; http_method; content:"/cg100/update.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"update.cg100iii.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_06_10; reference:url, urlhaus.abuse.ch/url/2881768/; classtype:trojan-activity;sid:83744868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2879955)"; flow:established,from_client; content:"GET"; http_method; content:"/unp%20setup.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"36.138.125.70"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_06_08; reference:url, urlhaus.abuse.ch/url/2879955/; classtype:trojan-activity;sid:83743055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2879655)"; flow:established,from_client; content:"GET"; http_method; content:"/sharphound.exe"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"92.127.156.174"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_06_08; reference:url, urlhaus.abuse.ch/url/2879655/; classtype:trojan-activity;sid:83742755; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2877890)"; flow:established,from_client; content:"GET"; http_method; content:"/ustaxes/ustaxes/files/15421286/2022and2023taxdocuments.zip"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_06_07; reference:url, urlhaus.abuse.ch/url/2877890/; classtype:trojan-activity;sid:83740990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2874107)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=19nonxskhmwbvfxpr2ccmwd9xrhz1ldco"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_04; reference:url, urlhaus.abuse.ch/url/2874107/; classtype:trojan-activity;sid:83737207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2874109)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1p_knmkidu8kiejeem_ijrlumbjih3bkv"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_06_04; reference:url, urlhaus.abuse.ch/url/2874109/; classtype:trojan-activity;sid:83737209; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2872168)"; flow:established,from_client; content:"GET"; http_method; content:"/htwvlcdsfcrahhchdd97.bin"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"ramirex.ro"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_06_02; reference:url, urlhaus.abuse.ch/url/2872168/; classtype:trojan-activity;sid:83735268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2872167)"; flow:established,from_client; content:"GET"; http_method; content:"/rutschebanes.qxd"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"ramirex.ro"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_06_02; reference:url, urlhaus.abuse.ch/url/2872167/; classtype:trojan-activity;sid:83735267; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870242)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1pvgvrcomccqllrfbaaxotcp-gyyh3onz"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870242/; classtype:trojan-activity;sid:83733342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870240)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ur2ibphmxipkxb5ernf34acfzzj2jga4"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870240/; classtype:trojan-activity;sid:83733340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870238)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1q2fszfukk1d8mxwia7wy6u4fse2vz07h"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870238/; classtype:trojan-activity;sid:83733338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2870235)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1wsqkirdngjlt8uu2lv9mzciks4my12jh"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2870235/; classtype:trojan-activity;sid:83733335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2869702)"; flow:established,from_client; content:"GET"; http_method; content:"/sheksweet/sheksweet1/main/rambledmime.exe"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_05_31; reference:url, urlhaus.abuse.ch/url/2869702/; classtype:trojan-activity;sid:83732802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2868723)"; flow:established,from_client; content:"GET"; http_method; content:"/a.i_1003h.exe"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"221.143.49.222"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_30; reference:url, urlhaus.abuse.ch/url/2868723/; classtype:trojan-activity;sid:83731823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2867270)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed45sh/flutter-movie/master/crypted_c360a5b7.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_05_28; reference:url, urlhaus.abuse.ch/url/2867270/; classtype:trojan-activity;sid:83730370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2867236)"; flow:established,from_client; content:"GET"; http_method; content:"/ahmed45sh/apple-replica-starter-files/master/apple-replica/zintask.exe"; http_uri; depth:71; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_05_28; reference:url, urlhaus.abuse.ch/url/2867236/; classtype:trojan-activity;sid:83730336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863341)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"223.108.58.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863341/; classtype:trojan-activity;sid:83726441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863345)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863345/; classtype:trojan-activity;sid:83726445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2863333)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"82.77.57.16"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_25; reference:url, urlhaus.abuse.ch/url/2863333/; classtype:trojan-activity;sid:83726433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862050)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/8gikly"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862050/; classtype:trojan-activity;sid:83725150; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862051)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/medjl1"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862051/; classtype:trojan-activity;sid:83725151; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862052)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/dy1f16"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862052/; classtype:trojan-activity;sid:83725152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862053)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/kx3wl4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862053/; classtype:trojan-activity;sid:83725153; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862054)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/ppxodm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862054/; classtype:trojan-activity;sid:83725154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862055)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/e7opy8"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862055/; classtype:trojan-activity;sid:83725155; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862056)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/7dhid7"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862056/; classtype:trojan-activity;sid:83725156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862049)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/tbfvpd"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862049/; classtype:trojan-activity;sid:83725149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862047)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/g2js91"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862047/; classtype:trojan-activity;sid:83725147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862044)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/lt00vw"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862044/; classtype:trojan-activity;sid:83725144; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862045)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/i7tdbr"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862045/; classtype:trojan-activity;sid:83725145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862043)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/3a9xj1"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862043/; classtype:trojan-activity;sid:83725143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862042)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/wyg3h5"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862042/; classtype:trojan-activity;sid:83725142; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862022)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"212.3.211.157"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862022/; classtype:trojan-activity;sid:83725122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862020)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.216.105.81"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862020/; classtype:trojan-activity;sid:83725120; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862017)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862017/; classtype:trojan-activity;sid:83725117; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862004)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862004/; classtype:trojan-activity;sid:83725104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862007)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"24.234.159.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862007/; classtype:trojan-activity;sid:83725107; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862009)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.24.87.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862009/; classtype:trojan-activity;sid:83725109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2862014)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2862014/; classtype:trojan-activity;sid:83725114; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861986)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"188.147.175.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861986/; classtype:trojan-activity;sid:83725086; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861979)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.208.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861979/; classtype:trojan-activity;sid:83725079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861982)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861982/; classtype:trojan-activity;sid:83725082; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861971)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"132.255.192.122"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861971/; classtype:trojan-activity;sid:83725071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861974)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861974/; classtype:trojan-activity;sid:83725074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861957)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.183.208.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861957/; classtype:trojan-activity;sid:83725057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861958)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.24.87.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861958/; classtype:trojan-activity;sid:83725058; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861959)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861959/; classtype:trojan-activity;sid:83725059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861950)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"95.47.248.146"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861950/; classtype:trojan-activity;sid:83725050; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861948)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861948/; classtype:trojan-activity;sid:83725048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861919)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861919/; classtype:trojan-activity;sid:83725019; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861923)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861923/; classtype:trojan-activity;sid:83725023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861927)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"223.82.83.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861927/; classtype:trojan-activity;sid:83725027; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861929)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"95.230.215.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861929/; classtype:trojan-activity;sid:83725029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861930)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"141.134.214.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861930/; classtype:trojan-activity;sid:83725030; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861931)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861931/; classtype:trojan-activity;sid:83725031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861935)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861935/; classtype:trojan-activity;sid:83725035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861939)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861939/; classtype:trojan-activity;sid:83725039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861940)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861940/; classtype:trojan-activity;sid:83725040; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861941)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861941/; classtype:trojan-activity;sid:83725041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861943)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861943/; classtype:trojan-activity;sid:83725043; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861888)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/dvbcvt"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861888/; classtype:trojan-activity;sid:83724988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861887)"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/exw2o1"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"www.sendspace.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861887/; classtype:trojan-activity;sid:83724987; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861843)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861843/; classtype:trojan-activity;sid:83724943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861852)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.176.204.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861852/; classtype:trojan-activity;sid:83724952; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861838)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"80.24.87.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861838/; classtype:trojan-activity;sid:83724938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861834)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"202.3.248.179"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861834/; classtype:trojan-activity;sid:83724934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861831)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.176.204.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861831/; classtype:trojan-activity;sid:83724931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861828)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"141.134.214.217"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861828/; classtype:trojan-activity;sid:83724928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861826)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861826/; classtype:trojan-activity;sid:83724926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861827)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"68.107.218.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861827/; classtype:trojan-activity;sid:83724927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861822)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861822/; classtype:trojan-activity;sid:83724922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861819)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"174.71.237.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861819/; classtype:trojan-activity;sid:83724919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861802)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"24.234.159.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861802/; classtype:trojan-activity;sid:83724902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861800)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861800/; classtype:trojan-activity;sid:83724900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861798)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"132.255.192.122"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861798/; classtype:trojan-activity;sid:83724898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861791)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.183.208.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861791/; classtype:trojan-activity;sid:83724891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861790)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861790/; classtype:trojan-activity;sid:83724890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861789)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"91.231.190.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861789/; classtype:trojan-activity;sid:83724889; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861781)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"46.250.54.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861781/; classtype:trojan-activity;sid:83724881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861777)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861777/; classtype:trojan-activity;sid:83724877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861770)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861770/; classtype:trojan-activity;sid:83724870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861773)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861773/; classtype:trojan-activity;sid:83724873; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861755)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861755/; classtype:trojan-activity;sid:83724855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861750)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861750/; classtype:trojan-activity;sid:83724850; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861749)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861749/; classtype:trojan-activity;sid:83724849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861743)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"123.143.141.75"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861743/; classtype:trojan-activity;sid:83724843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861737)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.0.241.65"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861737/; classtype:trojan-activity;sid:83724837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861740)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"81.42.247.62"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861740/; classtype:trojan-activity;sid:83724840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861729)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861729/; classtype:trojan-activity;sid:83724829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861733)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"46.250.54.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861733/; classtype:trojan-activity;sid:83724833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861721)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861721/; classtype:trojan-activity;sid:83724821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861725)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861725/; classtype:trojan-activity;sid:83724825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861716)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"188.170.32.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861716/; classtype:trojan-activity;sid:83724816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861710)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"80.14.38.66"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861710/; classtype:trojan-activity;sid:83724810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861707)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"209.162.229.229"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861707/; classtype:trojan-activity;sid:83724807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861695)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"102.216.105.81"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861695/; classtype:trojan-activity;sid:83724795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861702)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"188.147.175.138"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861702/; classtype:trojan-activity;sid:83724802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861692)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861692/; classtype:trojan-activity;sid:83724792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861693)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"202.3.248.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861693/; classtype:trojan-activity;sid:83724793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861675)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"80.24.87.77"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861675/; classtype:trojan-activity;sid:83724775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861670)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861670/; classtype:trojan-activity;sid:83724770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861667)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861667/; classtype:trojan-activity;sid:83724767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861657)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.173.70.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861657/; classtype:trojan-activity;sid:83724757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861659)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861659/; classtype:trojan-activity;sid:83724759; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861661)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"212.3.211.157"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861661/; classtype:trojan-activity;sid:83724761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861640)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"174.71.237.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861640/; classtype:trojan-activity;sid:83724740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861633)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"77.237.29.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861633/; classtype:trojan-activity;sid:83724733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861636)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"95.47.248.146"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861636/; classtype:trojan-activity;sid:83724736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861616)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861616/; classtype:trojan-activity;sid:83724716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861595)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"82.148.194.54"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861595/; classtype:trojan-activity;sid:83724695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861597)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"69.75.168.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861597/; classtype:trojan-activity;sid:83724697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861600)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"223.82.83.143"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861600/; classtype:trojan-activity;sid:83724700; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861610)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"178.183.208.134"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861610/; classtype:trojan-activity;sid:83724710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861592)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"24.234.159.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861592/; classtype:trojan-activity;sid:83724692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861582)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861582/; classtype:trojan-activity;sid:83724682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861568)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861568/; classtype:trojan-activity;sid:83724668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861569)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"113.160.251.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861569/; classtype:trojan-activity;sid:83724669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861573)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861573/; classtype:trojan-activity;sid:83724673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861559)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"68.226.36.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861559/; classtype:trojan-activity;sid:83724659; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861553)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"95.230.215.65"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861553/; classtype:trojan-activity;sid:83724653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861547)"; flow:established,from_client; content:"GET"; http_method; content:"//sshd"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"76.53.38.126"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861547/; classtype:trojan-activity;sid:83724647; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2861543)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"91.231.190.163"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_24; reference:url, urlhaus.abuse.ch/url/2861543/; classtype:trojan-activity;sid:83724643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2859511)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"92.66.30.68"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_22; reference:url, urlhaus.abuse.ch/url/2859511/; classtype:trojan-activity;sid:83722611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2859508)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"82.148.194.54"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_22; reference:url, urlhaus.abuse.ch/url/2859508/; classtype:trojan-activity;sid:83722608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2859027)"; flow:established,from_client; content:"GET"; http_method; content:"/ustaxes/ustaxes/files/15378217/all.2023.tax.documents.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_05_21; reference:url, urlhaus.abuse.ch/url/2859027/; classtype:trojan-activity;sid:83722127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857892)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"202.3.248.178"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857892/; classtype:trojan-activity;sid:83720992; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857875)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857875/; classtype:trojan-activity;sid:83720975; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857859)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"174.71.237.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857859/; classtype:trojan-activity;sid:83720959; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857851)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"144.6.87.144"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857851/; classtype:trojan-activity;sid:83720951; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857849)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857849/; classtype:trojan-activity;sid:83720949; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857844)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"185.2.229.122"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857844/; classtype:trojan-activity;sid:83720944; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857837)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857837/; classtype:trojan-activity;sid:83720937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857838)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"149.62.200.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857838/; classtype:trojan-activity;sid:83720938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857834)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857834/; classtype:trojan-activity;sid:83720934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857822)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.176.204.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857822/; classtype:trojan-activity;sid:83720922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857821)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.176.204.240"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857821/; classtype:trojan-activity;sid:83720921; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857807)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"202.3.248.179"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857807/; classtype:trojan-activity;sid:83720907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857794)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"68.107.218.106"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857794/; classtype:trojan-activity;sid:83720894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857788)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"68.226.36.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857788/; classtype:trojan-activity;sid:83720888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857785)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857785/; classtype:trojan-activity;sid:83720885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857772)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"69.75.168.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857772/; classtype:trojan-activity;sid:83720872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857747)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857747/; classtype:trojan-activity;sid:83720847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857749)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857749/; classtype:trojan-activity;sid:83720849; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857730)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857730/; classtype:trojan-activity;sid:83720830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857692)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.173.70.100"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857692/; classtype:trojan-activity;sid:83720792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857687)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"113.160.251.236"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857687/; classtype:trojan-activity;sid:83720787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857653)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"144.6.87.144"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857653/; classtype:trojan-activity;sid:83720753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857651)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.250.54.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857651/; classtype:trojan-activity;sid:83720751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857652)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"188.170.32.148"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857652/; classtype:trojan-activity;sid:83720752; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857642)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857642/; classtype:trojan-activity;sid:83720742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857634)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.0.241.65"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857634/; classtype:trojan-activity;sid:83720734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857624)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"118.69.157.212"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857624/; classtype:trojan-activity;sid:83720724; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857620)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"174.71.237.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857620/; classtype:trojan-activity;sid:83720720; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857610)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"178.176.204.250"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857610/; classtype:trojan-activity;sid:83720710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857601)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"212.93.103.10"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857601/; classtype:trojan-activity;sid:83720701; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857602)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"112.4.110.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857602/; classtype:trojan-activity;sid:83720702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857587)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"24.234.159.5"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857587/; classtype:trojan-activity;sid:83720687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857584)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"223.108.58.13"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857584/; classtype:trojan-activity;sid:83720684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857580)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857580/; classtype:trojan-activity;sid:83720680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857582)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857582/; classtype:trojan-activity;sid:83720682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857573)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"80.14.38.66"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857573/; classtype:trojan-activity;sid:83720673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857570)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"77.237.29.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857570/; classtype:trojan-activity;sid:83720670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857553)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"46.250.54.75"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857553/; classtype:trojan-activity;sid:83720653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857535)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"202.139.20.12"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857535/; classtype:trojan-activity;sid:83720635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857527)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"174.71.237.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857527/; classtype:trojan-activity;sid:83720627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857521)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"164.126.129.225"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857521/; classtype:trojan-activity;sid:83720621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857524)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857524/; classtype:trojan-activity;sid:83720624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857525)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"209.162.229.229"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857525/; classtype:trojan-activity;sid:83720625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857512)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"112.4.110.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857512/; classtype:trojan-activity;sid:83720612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857496)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"112.4.110.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857496/; classtype:trojan-activity;sid:83720596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857468)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"31.222.113.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857468/; classtype:trojan-activity;sid:83720568; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857465)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"102.68.74.45"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857465/; classtype:trojan-activity;sid:83720565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857463)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"165.73.108.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857463/; classtype:trojan-activity;sid:83720563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857447)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"174.71.237.86"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857447/; classtype:trojan-activity;sid:83720547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2857448)"; flow:established,from_client; content:"GET"; http_method; content:"/sshd"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"68.226.36.150"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_20; reference:url, urlhaus.abuse.ch/url/2857448/; classtype:trojan-activity;sid:83720548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2845681)"; flow:established,from_client; content:"GET"; http_method; content:"/app/filesrc/android/apk/2023/zonghengxsandroid_7.5.6.63_zh-zhh5.apk"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"static.zongheng.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_05_10; reference:url, urlhaus.abuse.ch/url/2845681/; classtype:trojan-activity;sid:83708781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842725)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"89.231.14.137"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842725/; classtype:trojan-activity;sid:83705825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842724)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"88.119.193.17"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842724/; classtype:trojan-activity;sid:83705824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842722)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"88.116.62.226"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842722/; classtype:trojan-activity;sid:83705822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842723)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"88.119.151.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_05_08; reference:url, urlhaus.abuse.ch/url/2842723/; classtype:trojan-activity;sid:83705823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842010)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"190.145.205.178"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2842010/; classtype:trojan-activity;sid:83705110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2842015)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"36.66.151.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2842015/; classtype:trojan-activity;sid:83705115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841988)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.148.5.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841988/; classtype:trojan-activity;sid:83705088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841976)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"81.16.249.96"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841976/; classtype:trojan-activity;sid:83705076; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841941)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"182.253.115.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841941/; classtype:trojan-activity;sid:83705041; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841807)"; flow:established,from_client; content:"GET"; http_method; content:"/cryptography_module_windows.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"122.170.110.131"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841807/; classtype:trojan-activity;sid:83704907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841714)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.148.5.34"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841714/; classtype:trojan-activity;sid:83704814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841712)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.253.115.156"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841712/; classtype:trojan-activity;sid:83704812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841650)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"151.236.247.230"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841650/; classtype:trojan-activity;sid:83704750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841631)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"182.253.115.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841631/; classtype:trojan-activity;sid:83704731; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841621)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.66.151.7"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841621/; classtype:trojan-activity;sid:83704721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841604)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.192.22.166"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841604/; classtype:trojan-activity;sid:83704704; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2841602)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"116.58.51.90"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_07; reference:url, urlhaus.abuse.ch/url/2841602/; classtype:trojan-activity;sid:83704702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2835534)"; flow:established,from_client; content:"GET"; http_method; content:"/wnnsafmwpwdxgy95.bin"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"www.duelvalenza.it"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_05_02; reference:url, urlhaus.abuse.ch/url/2835534/; classtype:trojan-activity;sid:83698634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834467)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.71.249.146"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834467/; classtype:trojan-activity;sid:83697567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834459)"; flow:established,from_client; content:"GET"; http_method; content:"/cron"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"45.76.122.186"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834459/; classtype:trojan-activity;sid:83697559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834442)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.71.242.67"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834442/; classtype:trojan-activity;sid:83697542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834400)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.71.242.68"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834400/; classtype:trojan-activity;sid:83697500; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834387)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.71.242.70"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834387/; classtype:trojan-activity;sid:83697487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2834372)"; flow:established,from_client; content:"GET"; http_method; content:"/curl"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"66.71.242.69"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_05_01; reference:url, urlhaus.abuse.ch/url/2834372/; classtype:trojan-activity;sid:83697472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2830963)"; flow:established,from_client; content:"GET"; http_method; content:"/kampfkarren/roblox/files/15001743/roexec.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_29; reference:url, urlhaus.abuse.ch/url/2830963/; classtype:trojan-activity;sid:83694063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2830955)"; flow:established,from_client; content:"GET"; http_method; content:"/delta-io/delta/files/15016110/delta.zip"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_29; reference:url, urlhaus.abuse.ch/url/2830955/; classtype:trojan-activity;sid:83694055; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2828079)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/imtoken-v2.apk"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"aws-v2-cdn.token.im"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_04_26; reference:url, urlhaus.abuse.ch/url/2828079/; classtype:trojan-activity;sid:83691179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2824078)"; flow:established,from_client; content:"GET"; http_method; content:"/mazacoin/maza/releases/download/v0.16.3/maza-0.16.3-win64-setup-unsigned.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_23; reference:url, urlhaus.abuse.ch/url/2824078/; classtype:trojan-activity;sid:83687178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2824079)"; flow:established,from_client; content:"GET"; http_method; content:"/mazacoin/maza/releases/download/v0.16.3/maza-0.16.3-osx-unsigned.dmg"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_23; reference:url, urlhaus.abuse.ch/url/2824079/; classtype:trojan-activity;sid:83687179; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2824077)"; flow:established,from_client; content:"GET"; http_method; content:"/mazacoin/maza/releases/download/v0.16.3/maza-0.16.3-win32-setup-unsigned.exe"; http_uri; depth:77; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_04_23; reference:url, urlhaus.abuse.ch/url/2824077/; classtype:trojan-activity;sid:83687177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822907)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"197.159.1.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822907/; classtype:trojan-activity;sid:83686007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822895)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"37.252.66.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822895/; classtype:trojan-activity;sid:83685995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822888)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"200.69.219.25"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822888/; classtype:trojan-activity;sid:83685988; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822873)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.148.20.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822873/; classtype:trojan-activity;sid:83685973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822863)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"41.77.74.90"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822863/; classtype:trojan-activity;sid:83685963; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822828)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"122.201.25.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822828/; classtype:trojan-activity;sid:83685928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822794)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"188.72.6.218"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822794/; classtype:trojan-activity;sid:83685894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822781)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"95.158.175.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822781/; classtype:trojan-activity;sid:83685881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822792)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.78.201.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822792/; classtype:trojan-activity;sid:83685892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822732)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"179.51.168.26"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822732/; classtype:trojan-activity;sid:83685832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822724)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"118.179.121.235"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822724/; classtype:trojan-activity;sid:83685824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822698)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"98.103.171.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822698/; classtype:trojan-activity;sid:83685798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822619)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"186.154.93.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822619/; classtype:trojan-activity;sid:83685719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822608)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"186.42.98.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822608/; classtype:trojan-activity;sid:83685708; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822592)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"181.211.252.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822592/; classtype:trojan-activity;sid:83685692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822583)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.245.10.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822583/; classtype:trojan-activity;sid:83685683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822548)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"91.92.82.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822548/; classtype:trojan-activity;sid:83685648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822549)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"188.254.255.246"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822549/; classtype:trojan-activity;sid:83685649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822544)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.53.164.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822544/; classtype:trojan-activity;sid:83685644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822543)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"95.170.119.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822543/; classtype:trojan-activity;sid:83685643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822488)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"85.187.82.120"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822488/; classtype:trojan-activity;sid:83685588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822475)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"118.71.250.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822475/; classtype:trojan-activity;sid:83685575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822477)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.5.50.108"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822477/; classtype:trojan-activity;sid:83685577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822460)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"109.69.79.44"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822460/; classtype:trojan-activity;sid:83685560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822462)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"200.61.163.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822462/; classtype:trojan-activity;sid:83685562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822452)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"41.219.187.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822452/; classtype:trojan-activity;sid:83685552; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822443)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"151.237.4.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822443/; classtype:trojan-activity;sid:83685543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822432)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"185.71.69.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822432/; classtype:trojan-activity;sid:83685532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822416)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"213.6.74.138"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822416/; classtype:trojan-activity;sid:83685516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822405)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"37.157.212.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822405/; classtype:trojan-activity;sid:83685505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822386)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.148.18.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822386/; classtype:trojan-activity;sid:83685486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822377)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.101.81.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822377/; classtype:trojan-activity;sid:83685477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822384)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"190.113.124.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822384/; classtype:trojan-activity;sid:83685484; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822385)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"82.114.200.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822385/; classtype:trojan-activity;sid:83685485; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822371)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"109.108.84.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822371/; classtype:trojan-activity;sid:83685471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822372)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"154.84.212.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822372/; classtype:trojan-activity;sid:83685472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822356)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"37.143.133.215"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822356/; classtype:trojan-activity;sid:83685456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822364)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"195.211.197.30"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822364/; classtype:trojan-activity;sid:83685464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822328)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.148.18.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822328/; classtype:trojan-activity;sid:83685428; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822287)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"185.236.46.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822287/; classtype:trojan-activity;sid:83685387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822275)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.131.244.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822275/; classtype:trojan-activity;sid:83685375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822259)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.90.207.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822259/; classtype:trojan-activity;sid:83685359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822186)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"36.66.168.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822186/; classtype:trojan-activity;sid:83685286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822189)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"58.145.168.170"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822189/; classtype:trojan-activity;sid:83685289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822165)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"211.186.82.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822165/; classtype:trojan-activity;sid:83685265; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822121)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"81.16.247.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822121/; classtype:trojan-activity;sid:83685221; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822123)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"109.92.143.90"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822123/; classtype:trojan-activity;sid:83685223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822102)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"138.122.43.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822102/; classtype:trojan-activity;sid:83685202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822070)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"78.26.180.129"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822070/; classtype:trojan-activity;sid:83685170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822054)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"154.0.129.134"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822054/; classtype:trojan-activity;sid:83685154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822004)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"94.251.5.51"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822004/; classtype:trojan-activity;sid:83685104; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2822006)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"77.89.245.118"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2822006/; classtype:trojan-activity;sid:83685106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821977)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"36.92.68.241"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821977/; classtype:trojan-activity;sid:83685077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821967)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"212.73.75.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821967/; classtype:trojan-activity;sid:83685067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821963)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"91.204.154.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821963/; classtype:trojan-activity;sid:83685063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821942)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"76.76.195.174"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821942/; classtype:trojan-activity;sid:83685042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821949)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"154.0.129.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821949/; classtype:trojan-activity;sid:83685049; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821934)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"202.53.164.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821934/; classtype:trojan-activity;sid:83685034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821860)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.148.18.218"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821860/; classtype:trojan-activity;sid:83684960; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821829)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.148.20.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821829/; classtype:trojan-activity;sid:83684929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821806)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.0.129.134"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821806/; classtype:trojan-activity;sid:83684906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821807)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.148.18.220"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821807/; classtype:trojan-activity;sid:83684907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821802)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"197.159.1.58"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821802/; classtype:trojan-activity;sid:83684902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821804)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.185.119.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821804/; classtype:trojan-activity;sid:83684904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821772)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.236.46.120"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821772/; classtype:trojan-activity;sid:83684872; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821755)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.211.252.34"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821755/; classtype:trojan-activity;sid:83684855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821740)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"178.151.143.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821740/; classtype:trojan-activity;sid:83684840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821729)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.53.164.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821729/; classtype:trojan-activity;sid:83684829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821718)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"149.255.10.46"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821718/; classtype:trojan-activity;sid:83684818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821706)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"151.237.4.20"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821706/; classtype:trojan-activity;sid:83684806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821693)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.5.50.108"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821693/; classtype:trojan-activity;sid:83684793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821699)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"211.186.82.229"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821699/; classtype:trojan-activity;sid:83684799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821676)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.0.129.114"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821676/; classtype:trojan-activity;sid:83684776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821657)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.78.201.3"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821657/; classtype:trojan-activity;sid:83684757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821633)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.94.245.254"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821633/; classtype:trojan-activity;sid:83684733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821619)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"200.61.163.235"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821619/; classtype:trojan-activity;sid:83684719; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821616)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.2.237.104"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821616/; classtype:trojan-activity;sid:83684716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821612)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.33.204.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821612/; classtype:trojan-activity;sid:83684712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2821603)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.42.98.2"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_22; reference:url, urlhaus.abuse.ch/url/2821603/; classtype:trojan-activity;sid:83684703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818981)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.252.66.188"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818981/; classtype:trojan-activity;sid:83682081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818974)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.71.250.6"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818974/; classtype:trojan-activity;sid:83682074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818975)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.140.32.219"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818975/; classtype:trojan-activity;sid:83682075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818963)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.164.200.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818963/; classtype:trojan-activity;sid:83682063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818920)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.143.133.215"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818920/; classtype:trojan-activity;sid:83682020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818838)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"138.122.43.76"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818838/; classtype:trojan-activity;sid:83681938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818781)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"78.26.180.129"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818781/; classtype:trojan-activity;sid:83681881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818775)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"130.204.154.237"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818775/; classtype:trojan-activity;sid:83681875; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2818778)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"82.114.200.50"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_20; reference:url, urlhaus.abuse.ch/url/2818778/; classtype:trojan-activity;sid:83681878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2817357)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1w6j0xeptoliyrblijhnxbm_qnnoptzfw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_18; reference:url, urlhaus.abuse.ch/url/2817357/; classtype:trojan-activity;sid:83680457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2817356)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1nurs33pjxezqhl9ciafopya6u7i1vpkv"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_18; reference:url, urlhaus.abuse.ch/url/2817356/; classtype:trojan-activity;sid:83680456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2814108)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.12.78.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_16; reference:url, urlhaus.abuse.ch/url/2814108/; classtype:trojan-activity;sid:83677208; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2814101)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"212.73.75.84"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_16; reference:url, urlhaus.abuse.ch/url/2814101/; classtype:trojan-activity;sid:83677201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2814082)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.34.91.22"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_16; reference:url, urlhaus.abuse.ch/url/2814082/; classtype:trojan-activity;sid:83677182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813151)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"81.16.247.81"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813151/; classtype:trojan-activity;sid:83676251; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813130)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.157.219.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813130/; classtype:trojan-activity;sid:83676230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813110)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.219.187.180"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813110/; classtype:trojan-activity;sid:83676210; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813107)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"46.151.56.42"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813107/; classtype:trojan-activity;sid:83676207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813100)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"118.179.121.235"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813100/; classtype:trojan-activity;sid:83676200; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813069)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.204.154.197"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813069/; classtype:trojan-activity;sid:83676169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813060)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"41.77.74.90"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813060/; classtype:trojan-activity;sid:83676160; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813049)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.108.84.121"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813049/; classtype:trojan-activity;sid:83676149; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2813039)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.92.68.241"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_15; reference:url, urlhaus.abuse.ch/url/2813039/; classtype:trojan-activity;sid:83676139; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809228)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"195.211.197.30"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809228/; classtype:trojan-activity;sid:83672328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809190)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"185.71.69.198"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809190/; classtype:trojan-activity;sid:83672290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809140)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.53.164.214"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809140/; classtype:trojan-activity;sid:83672240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809130)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"181.49.47.190"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809130/; classtype:trojan-activity;sid:83672230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809132)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.88.180.115"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809132/; classtype:trojan-activity;sid:83672232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2809089)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"94.251.5.51"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2809089/; classtype:trojan-activity;sid:83672189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808967)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.57.33.51"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808967/; classtype:trojan-activity;sid:83672067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808957)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"37.157.212.138"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808957/; classtype:trojan-activity;sid:83672057; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808947)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.66.139.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808947/; classtype:trojan-activity;sid:83672047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808933)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.101.81.142"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808933/; classtype:trojan-activity;sid:83672033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808907)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"154.84.212.18"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808907/; classtype:trojan-activity;sid:83672007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808893)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"193.169.146.186"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808893/; classtype:trojan-activity;sid:83671993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808872)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"122.201.25.95"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808872/; classtype:trojan-activity;sid:83671972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808854)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"188.44.110.215"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808854/; classtype:trojan-activity;sid:83671954; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808855)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.12.99.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808855/; classtype:trojan-activity;sid:83671955; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808823)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.245.10.51"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808823/; classtype:trojan-activity;sid:83671923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808814)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"186.154.93.81"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808814/; classtype:trojan-activity;sid:83671914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808710)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"190.113.124.155"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808710/; classtype:trojan-activity;sid:83671810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808644)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"202.131.244.202"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808644/; classtype:trojan-activity;sid:83671744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808610)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"213.6.74.138"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808610/; classtype:trojan-activity;sid:83671710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808599)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"91.92.82.180"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808599/; classtype:trojan-activity;sid:83671699; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808492)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.90.207.234"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808492/; classtype:trojan-activity;sid:83671592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808448)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"109.92.143.90"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808448/; classtype:trojan-activity;sid:83671548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808416)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"95.170.119.100"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808416/; classtype:trojan-activity;sid:83671516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808417)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"36.66.168.49"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808417/; classtype:trojan-activity;sid:83671517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808373)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"103.125.163.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808373/; classtype:trojan-activity;sid:83671473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2808374)"; flow:established,from_client; content:"GET"; http_method; content:"/i"; http_uri; depth:2; isdataat:!1,relative; nocase; content:"98.103.171.36"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_11; reference:url, urlhaus.abuse.ch/url/2808374/; classtype:trojan-activity;sid:83671474; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2807492)"; flow:established,from_client; content:"GET"; http_method; content:"/ping"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"2.57.122.121"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_04_10; reference:url, urlhaus.abuse.ch/url/2807492/; classtype:trojan-activity;sid:83670592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2800910)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1psjfkavxoi-3yv-87eskdpuwzjd5jomd"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_04; reference:url, urlhaus.abuse.ch/url/2800910/; classtype:trojan-activity;sid:83664010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2800895)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1i33affjfkkztyuz_nusrz4jqs45gwzjs"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_04; reference:url, urlhaus.abuse.ch/url/2800895/; classtype:trojan-activity;sid:83663995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2800893)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1pssupirwdhnwaztrwz6_7dw9r4h_zau9"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_04; reference:url, urlhaus.abuse.ch/url/2800893/; classtype:trojan-activity;sid:83663993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2799349)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1b3zgfh-ofoq4nkifk7j0manbu5aqvhet"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_02; reference:url, urlhaus.abuse.ch/url/2799349/; classtype:trojan-activity;sid:83662449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2799230)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1oe1ixppk9tdxfmairsjhsacdgh2litag"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_02; reference:url, urlhaus.abuse.ch/url/2799230/; classtype:trojan-activity;sid:83662330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2799188)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1osqxhd1ncdyo-hhavradwbm9_itb2p49"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_02; reference:url, urlhaus.abuse.ch/url/2799188/; classtype:trojan-activity;sid:83662288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2798325)"; flow:established,from_client; content:"GET"; http_method; content:"/armv7l"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"75.119.134.80"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_01; reference:url, urlhaus.abuse.ch/url/2798325/; classtype:trojan-activity;sid:83661425; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2798324)"; flow:established,from_client; content:"GET"; http_method; content:"/i386"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"75.119.134.80"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_04_01; reference:url, urlhaus.abuse.ch/url/2798324/; classtype:trojan-activity;sid:83661424; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2798232)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_gv_k0ynz9_n6h6n7bvistk9oi2njezj"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_04_01; reference:url, urlhaus.abuse.ch/url/2798232/; classtype:trojan-activity;sid:83661332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2795045)"; flow:established,from_client; content:"GET"; http_method; content:"/"; http_uri; depth:1; isdataat:!1,relative; nocase; content:"metrics.gocloudmaps.com"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2795045/; classtype:trojan-activity;sid:83658145; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2795037)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=171-yky-j89krighojrmmetm69vbmd5m4"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2795037/; classtype:trojan-activity;sid:83658137; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2794611)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1l-zoyasmfcwfa655dud7ekudjq3ywquk"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2794611/; classtype:trojan-activity;sid:83657711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2794606)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1smjsns4djerxm11i8rx6ldttpsynidio"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2794606/; classtype:trojan-activity;sid:83657706; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2794563)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1uzj6rbkjyyfcvpddyaduabxfay7w4_9w"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_28; reference:url, urlhaus.abuse.ch/url/2794563/; classtype:trojan-activity;sid:83657663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2793641)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1t36pjqs33b0q_k78zbmxjrlbrzkssrbu"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_27; reference:url, urlhaus.abuse.ch/url/2793641/; classtype:trojan-activity;sid:83656741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2793611)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1x6cd0z6l79ciefoo627uiws_6yscm_xn"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_27; reference:url, urlhaus.abuse.ch/url/2793611/; classtype:trojan-activity;sid:83656711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2793603)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1qxwff0k49bjdhwzotirkvqlqhebzgphg"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_27; reference:url, urlhaus.abuse.ch/url/2793603/; classtype:trojan-activity;sid:83656703; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2792386)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=19-hbu_sfsiwgjfm4yp1k22atk3nmwao8"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_25; reference:url, urlhaus.abuse.ch/url/2792386/; classtype:trojan-activity;sid:83655486; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2792375)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1p5myromjprou5-vehst_hpzb7pbwagjw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_25; reference:url, urlhaus.abuse.ch/url/2792375/; classtype:trojan-activity;sid:83655475; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2790578)"; flow:established,from_client; content:"GET"; http_method; content:"/.index/scan.tar"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"58.216.207.82"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_03_23; reference:url, urlhaus.abuse.ch/url/2790578/; classtype:trojan-activity;sid:83653678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2789734)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ugl_xjshxerwwbal1fatflznekorqco5"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_22; reference:url, urlhaus.abuse.ch/url/2789734/; classtype:trojan-activity;sid:83652834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2789249)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1aygcpsnow8esde5bkkuaj0bygkowvttd"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_21; reference:url, urlhaus.abuse.ch/url/2789249/; classtype:trojan-activity;sid:83652349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787791)"; flow:established,from_client; content:"GET"; http_method; content:"/ykwsyyt/help/hddrive1095_xinanplug3030_20230619_inno.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"60.22.23.50"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_03_20; reference:url, urlhaus.abuse.ch/url/2787791/; classtype:trojan-activity;sid:83650891; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787399)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1stvkjdfiwxw79oezmc62wzmjjaeftyze"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_20; reference:url, urlhaus.abuse.ch/url/2787399/; classtype:trojan-activity;sid:83650499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787397)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1hditwve1kadzeycbldxttxi4mmhddgyp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_20; reference:url, urlhaus.abuse.ch/url/2787397/; classtype:trojan-activity;sid:83650497; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2787024)"; flow:established,from_client; content:"GET"; http_method; content:"/bash"; http_uri; depth:5; isdataat:!1,relative; nocase; content:"65.49.44.84"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2787024/; classtype:trojan-activity;sid:83650124; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786866)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1udpahhkabfdjz32b558xh_lwxs0snowc"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786866/; classtype:trojan-activity;sid:83649966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786829)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1re9cqjrafya6wcb5e0zcolwdorvsf9pi"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786829/; classtype:trojan-activity;sid:83649929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786663)"; flow:established,from_client; content:"GET"; http_method; content:"/washywashy14/7zip-bin/master/win/er5thygfd.zip"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786663/; classtype:trojan-activity;sid:83649763; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2786661)"; flow:established,from_client; content:"GET"; http_method; content:"/washywashy14/7zip-bin/master/win/uemlxaw.zip"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_19; reference:url, urlhaus.abuse.ch/url/2786661/; classtype:trojan-activity;sid:83649761; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2785768)"; flow:established,from_client; content:"GET"; http_method; content:"/zev3n/ubuntu-gnome-privilege-escalation/main/cve-2020-1612%5b6_7%5d_exploit.sh"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_18; reference:url, urlhaus.abuse.ch/url/2785768/; classtype:trojan-activity;sid:83648868; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2782882)"; flow:established,from_client; content:"GET"; http_method; content:"/driveapplet.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"noithaticon.vn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_03_14; reference:url, urlhaus.abuse.ch/url/2782882/; classtype:trojan-activity;sid:83645982; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2782434)"; flow:established,from_client; content:"GET"; http_method; content:"/17c4755d1d45ed1bb454/8703634058188758823"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"f24-zfcloud.zdn.vn"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2024_03_13; reference:url, urlhaus.abuse.ch/url/2782434/; classtype:trojan-activity;sid:83645534; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2780273)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ge6chcvywbep4kgx_odpxtvfi3vj-zwy"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_03_11; reference:url, urlhaus.abuse.ch/url/2780273/; classtype:trojan-activity;sid:83643373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2776130)"; flow:established,from_client; content:"GET"; http_method; content:"//pcs/click|3f|adurl=//bamautzky.de/red.php"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_03_05; reference:url, urlhaus.abuse.ch/url/2776130/; classtype:trojan-activity;sid:83639230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2772697)"; flow:established,from_client; content:"GET"; http_method; content:"/docs/x.rar"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"106.254.250.98"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_02_29; reference:url, urlhaus.abuse.ch/url/2772697/; classtype:trojan-activity;sid:83635797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2772689)"; flow:established,from_client; content:"GET"; http_method; content:"/docs/met111.sh"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"106.254.250.98"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2024_02_29; reference:url, urlhaus.abuse.ch/url/2772689/; classtype:trojan-activity;sid:83635789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2769015)"; flow:established,from_client; content:"GET"; http_method; content:"/calendar/down/jeditor/jeditor.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"www.ojang.pe.kr"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2024_02_24; reference:url, urlhaus.abuse.ch/url/2769015/; classtype:trojan-activity;sid:83632115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765933)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2024/e_r1.bmp"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"catbaparadisehotel.com.vn"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765933/; classtype:trojan-activity;sid:83629033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765626)"; flow:established,from_client; content:"GET"; http_method; content:"/hitmanpro.zip"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"hitman-pro.ru"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765626/; classtype:trojan-activity;sid:83628726; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765602)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f||7c|26|7c|adurl=https://patricstoremegans2.com/"; http_uri; depth:61; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765602/; classtype:trojan-activity;sid:83628702; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765586)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2024/e_default.bmp"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"catbaparadisehotel.com.vn"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765586/; classtype:trojan-activity;sid:83628686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2765431)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_20; reference:url, urlhaus.abuse.ch/url/2765431/; classtype:trojan-activity;sid:83628531; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764512)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764512/; classtype:trojan-activity;sid:83627612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764507)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764507/; classtype:trojan-activity;sid:83627607; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764508)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764508/; classtype:trojan-activity;sid:83627608; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764509)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764509/; classtype:trojan-activity;sid:83627609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2764511)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.spc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_19; reference:url, urlhaus.abuse.ch/url/2764511/; classtype:trojan-activity;sid:83627611; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763764)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.sh4"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763764/; classtype:trojan-activity;sid:83626864; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763765)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.m68k"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763765/; classtype:trojan-activity;sid:83626865; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763766)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.powerpc"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763766/; classtype:trojan-activity;sid:83626866; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763767)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.sparc"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763767/; classtype:trojan-activity;sid:83626867; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763429)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.mipsel"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763429/; classtype:trojan-activity;sid:83626529; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2763428)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_18; reference:url, urlhaus.abuse.ch/url/2763428/; classtype:trojan-activity;sid:83626528; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2761815)"; flow:established,from_client; content:"GET"; http_method; content:"/dt9.txt"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"delp-heizungsbau.de"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2024_02_15; reference:url, urlhaus.abuse.ch/url/2761815/; classtype:trojan-activity;sid:83624915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760086)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.arm5"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760086/; classtype:trojan-activity;sid:83623186; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760087)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.arm6"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760087/; classtype:trojan-activity;sid:83623187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760088)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.arm7"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760088/; classtype:trojan-activity;sid:83623188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760083)"; flow:established,from_client; content:"GET"; http_method; content:"/ri/la.bot.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760083/; classtype:trojan-activity;sid:83623183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2760068)"; flow:established,from_client; content:"GET"; http_method; content:"/multi"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"31.220.3.140"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2024_02_12; reference:url, urlhaus.abuse.ch/url/2760068/; classtype:trojan-activity;sid:83623168; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754788)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.i686"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754788/; classtype:trojan-activity;sid:83617888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754787)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.spc"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754787/; classtype:trojan-activity;sid:83617887; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754786)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.mips"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754786/; classtype:trojan-activity;sid:83617886; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754784)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.x86"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754784/; classtype:trojan-activity;sid:83617884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754785)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.arm"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754785/; classtype:trojan-activity;sid:83617885; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754783)"; flow:established,from_client; content:"GET"; http_method; content:"/cn/sysnew.x86_64"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"best.obs.cn-sz1.ctyun.cn"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2024_02_01; reference:url, urlhaus.abuse.ch/url/2754783/; classtype:trojan-activity;sid:83617883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2754299)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1wuy2y3vbxibdfqcs6-kx96nocarzixfd"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_31; reference:url, urlhaus.abuse.ch/url/2754299/; classtype:trojan-activity;sid:83617399; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2753677)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//projetodegente.com"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_30; reference:url, urlhaus.abuse.ch/url/2753677/; classtype:trojan-activity;sid:83616777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751573)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//higreens.co.in"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_25; reference:url, urlhaus.abuse.ch/url/2751573/; classtype:trojan-activity;sid:83614673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751543)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//kavyasourcing.com/"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_25; reference:url, urlhaus.abuse.ch/url/2751543/; classtype:trojan-activity;sid:83614643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751237)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://cliffg.me"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_24; reference:url, urlhaus.abuse.ch/url/2751237/; classtype:trojan-activity;sid:83614337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2751171)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://streammobs.com/"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_24; reference:url, urlhaus.abuse.ch/url/2751171/; classtype:trojan-activity;sid:83614271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749355)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://redeamazoniaazul.org/"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_18; reference:url, urlhaus.abuse.ch/url/2749355/; classtype:trojan-activity;sid:83612455; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749356)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//www.jd-forever.com/"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_18; reference:url, urlhaus.abuse.ch/url/2749356/; classtype:trojan-activity;sid:83612456; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749357)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//old.umcl.us/"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_18; reference:url, urlhaus.abuse.ch/url/2749357/; classtype:trojan-activity;sid:83612457; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749182)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://wegrowcoaching.com/"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_17; reference:url, urlhaus.abuse.ch/url/2749182/; classtype:trojan-activity;sid:83612282; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749177)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://dongyu.us/"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_17; reference:url, urlhaus.abuse.ch/url/2749177/; classtype:trojan-activity;sid:83612277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2749054)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1lrviuk1wka4di3qh7ach-b7m1ics2hbp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_16; reference:url, urlhaus.abuse.ch/url/2749054/; classtype:trojan-activity;sid:83612154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748605)"; flow:established,from_client; content:"GET"; http_method; content:"/ssslllap1/asdasd/raw/main/crypted.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2024_01_13; reference:url, urlhaus.abuse.ch/url/2748605/; classtype:trojan-activity;sid:83611705; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748365)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ifvzub1blhmwsirshbe2wu5b1tus3ls-"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748365/; classtype:trojan-activity;sid:83611465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748363)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1yydiodtw09banou13ro8ielf9rcmljxy"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748363/; classtype:trojan-activity;sid:83611463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748360)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=11cbyky_wegqjut6afr8jannw7vub-xxf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748360/; classtype:trojan-activity;sid:83611460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2748349)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gv5qahzp_toxgct3ezfvvy4q3a5vvh6s"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_12; reference:url, urlhaus.abuse.ch/url/2748349/; classtype:trojan-activity;sid:83611449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2747896)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//vaibhavtripathi.in"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_10; reference:url, urlhaus.abuse.ch/url/2747896/; classtype:trojan-activity;sid:83610996; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2747890)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//procuratio.nu/"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2024_01_10; reference:url, urlhaus.abuse.ch/url/2747890/; classtype:trojan-activity;sid:83610990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2747826)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1u-vaalebjnomuhbyimsdjqctjqfyiwna"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2024_01_10; reference:url, urlhaus.abuse.ch/url/2747826/; classtype:trojan-activity;sid:83610926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2743461)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=12rmvuwgpj0dzbb3haoaww2lviavhvb4r"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_22; reference:url, urlhaus.abuse.ch/url/2743461/; classtype:trojan-activity;sid:83606561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2743460)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1rfsmrzeanvap2tnmtwrptlepwarwlkge"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_22; reference:url, urlhaus.abuse.ch/url/2743460/; classtype:trojan-activity;sid:83606560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742817)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://synergyconsulting.us"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_12_20; reference:url, urlhaus.abuse.ch/url/2742817/; classtype:trojan-activity;sid:83605917; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742524)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//www.deltabehavioralhealth.org/"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_12_19; reference:url, urlhaus.abuse.ch/url/2742524/; classtype:trojan-activity;sid:83605624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742518)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1k0bqhrtnu4v1yexoni5p1utyjuohmfzm"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_19; reference:url, urlhaus.abuse.ch/url/2742518/; classtype:trojan-activity;sid:83605618; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2742516)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1fhqpevblkipshqumjmsbzeetdzhzxv-j"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_12_19; reference:url, urlhaus.abuse.ch/url/2742516/; classtype:trojan-activity;sid:83605616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2740202)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//balkarsoftware.cubistech.com"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_12_13; reference:url, urlhaus.abuse.ch/url/2740202/; classtype:trojan-activity;sid:83603302; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2734979)"; flow:established,from_client; content:"GET"; http_method; content:"/404"; http_uri; depth:4; isdataat:!1,relative; nocase; content:"31.184.194.114"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2023_11_24; reference:url, urlhaus.abuse.ch/url/2734979/; classtype:trojan-activity;sid:83598079; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2733212)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=//churchinmanila.org/"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_20; reference:url, urlhaus.abuse.ch/url/2733212/; classtype:trojan-activity;sid:83596312; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2730213)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1sjm5t0ktlepibtv3kgaousspnw3zonom"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_13; reference:url, urlhaus.abuse.ch/url/2730213/; classtype:trojan-activity;sid:83593313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2730069)"; flow:established,from_client; content:"GET"; http_method; content:"/cronusxd/update/releases/download/programa/universal.cheat.all.games.rar"; http_uri; depth:73; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2023_11_12; reference:url, urlhaus.abuse.ch/url/2730069/; classtype:trojan-activity;sid:83593169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2729736)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://posicionamientonatural.es/"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_10; reference:url, urlhaus.abuse.ch/url/2729736/; classtype:trojan-activity;sid:83592836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2729405)"; flow:established,from_client; content:"GET"; http_method; content:"/pcs/click|3f|adurl=https://namaacont.com/"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"adclick.g.doubleclick.net"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_09; reference:url, urlhaus.abuse.ch/url/2729405/; classtype:trojan-activity;sid:83592505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2727395)"; flow:established,from_client; content:"GET"; http_method; content:"/frankcastle2/0/main/0j"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2023_11_03; reference:url, urlhaus.abuse.ch/url/2727395/; classtype:trojan-activity;sid:83590495; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726994)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1lhnnwoydntgqibsykxwgd32s5xftxvfh"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726994/; classtype:trojan-activity;sid:83590094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726921)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1oxpqeutyreby186exx4zeofyz0rjocsp"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726921/; classtype:trojan-activity;sid:83590021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726920)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1e2y5yppu_zjj4o3wmuo-2j8n9lbthkzc"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726920/; classtype:trojan-activity;sid:83590020; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726917)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1heka7sgmbcessdhxtvmfwxownz7sipbb"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726917/; classtype:trojan-activity;sid:83590017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726906)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1_ldguopt2cg7fblntw3ltxgtxqtmlflc"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726906/; classtype:trojan-activity;sid:83590006; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726907)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=10lygpyju_dlg3x6r9oslzgblshakstl-"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_11_01; reference:url, urlhaus.abuse.ch/url/2726907/; classtype:trojan-activity;sid:83590007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726777)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1sqvm1xsoranfnvqst_kkdmn8yhgulm4k"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_31; reference:url, urlhaus.abuse.ch/url/2726777/; classtype:trojan-activity;sid:83589877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726774)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1cz1lqyxis4wvr7nlc71ukekxyhj5xu-l"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_31; reference:url, urlhaus.abuse.ch/url/2726774/; classtype:trojan-activity;sid:83589874; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726592)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1zqzivoxid6wgvjstzd0lg2vxnpnc-puf"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_30; reference:url, urlhaus.abuse.ch/url/2726592/; classtype:trojan-activity;sid:83589692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726432)"; flow:established,from_client; content:"GET"; http_method; content:"/drakeo03/rbxfpsunlocker-x64-hotfix1/zip/refs/heads/main"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2023_10_28; reference:url, urlhaus.abuse.ch/url/2726432/; classtype:trojan-activity;sid:83589532; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2726089)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gfn3lqd1rvybut4ha-ldl92wt8ysrzfc"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_26; reference:url, urlhaus.abuse.ch/url/2726089/; classtype:trojan-activity;sid:83589189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2722703)"; flow:established,from_client; content:"GET"; http_method; content:"/image.png"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"ircftp.net"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2023_10_20; reference:url, urlhaus.abuse.ch/url/2722703/; classtype:trojan-activity;sid:83585803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2720438)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"37.157.219.158"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2023_10_14; reference:url, urlhaus.abuse.ch/url/2720438/; classtype:trojan-activity;sid:83583538; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2719389)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1satmexzn3qpvqzfxnc-5dtnnn8lihdxh"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_12; reference:url, urlhaus.abuse.ch/url/2719389/; classtype:trojan-activity;sid:83582489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2718399)"; flow:established,from_client; content:"GET"; http_method; content:"/centro/index.php"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"srsorvete.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_09; reference:url, urlhaus.abuse.ch/url/2718399/; classtype:trojan-activity;sid:83581499; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2715548)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|confirm=no_antivirus|7c|26|7c|id=1-5tfbyc52tepabxjdszg1dcqgaizf0m6"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_10_01; reference:url, urlhaus.abuse.ch/url/2715548/; classtype:trojan-activity;sid:83578648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2713056)"; flow:established,from_client; content:"GET"; http_method; content:"/rter/"; http_uri; depth:6; isdataat:!1,relative; nocase; content:"tanscarattorneys.co.tz"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2023_09_21; reference:url, urlhaus.abuse.ch/url/2713056/; classtype:trojan-activity;sid:83576156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2708874)"; flow:established,from_client; content:"GET"; http_method; content:"/readme.txt"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"svirtual.sanviatorperu.edu.pe"; http_host; depth:29; isdataat:!1,relative; metadata:created_at 2023_09_01; reference:url, urlhaus.abuse.ch/url/2708874/; classtype:trojan-activity;sid:83571974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2694556)"; flow:established,from_client; content:"GET"; http_method; content:"/v2/plain-sunset-8e5d78/original/js.jpeg"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"cdn.pixelbin.io"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2023_08_01; reference:url, urlhaus.abuse.ch/url/2694556/; classtype:trojan-activity;sid:83557656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2693150)"; flow:established,from_client; content:"GET"; http_method; content:"/housenetshare.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"stdown.dinju.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_07_31; reference:url, urlhaus.abuse.ch/url/2693150/; classtype:trojan-activity;sid:83556250; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2692699)"; flow:established,from_client; content:"GET"; http_method; content:"/v2/long-glade-33dc08/original/rump_img.jpeg"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"cdn.pixelbin.io"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2023_07_30; reference:url, urlhaus.abuse.ch/url/2692699/; classtype:trojan-activity;sid:83555799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2629977)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|confirm=t|7c|26|7c|id=145b1fbjtyee3w1rjsazo7hzcoiiaxzum|7c|26|7c|uuid=eb581596-9566-4a21-b3b6-e6909eb42ff6|7c|26|7c|at=akkf8vzrltviqrn7wljfjcwisgcc:1683793107077"; http_uri; depth:193; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_05_11; reference:url, urlhaus.abuse.ch/url/2629977/; classtype:trojan-activity;sid:83493077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2615307)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"181.129.177.162"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2023_04_21; reference:url, urlhaus.abuse.ch/url/2615307/; classtype:trojan-activity;sid:83478407; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2615264)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"213.33.204.186"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2023_04_21; reference:url, urlhaus.abuse.ch/url/2615264/; classtype:trojan-activity;sid:83478364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2607113)"; flow:established,from_client; content:"GET"; http_method; content:"/blo/me.zip"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"vedantawisdom.org"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2023_04_12; reference:url, urlhaus.abuse.ch/url/2607113/; classtype:trojan-activity;sid:83470213; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2581006)"; flow:established,from_client; content:"GET"; http_method; content:"/salatikochen/salatapps/archive/refs/heads/main.zip"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2023_03_22; reference:url, urlhaus.abuse.ch/url/2581006/; classtype:trojan-activity;sid:83444106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2573741)"; flow:established,from_client; content:"GET"; http_method; content:"/rid/rid.js"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"jawaratekno.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2023_03_16; reference:url, urlhaus.abuse.ch/url/2573741/; classtype:trojan-activity;sid:83436841; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2573732)"; flow:established,from_client; content:"GET"; http_method; content:"/me/me.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"lumacrea.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2023_03_16; reference:url, urlhaus.abuse.ch/url/2573732/; classtype:trojan-activity;sid:83436832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2573712)"; flow:established,from_client; content:"GET"; http_method; content:"/cor/cor.js"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"swiftfusion.tech"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_16; reference:url, urlhaus.abuse.ch/url/2573712/; classtype:trojan-activity;sid:83436812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2572698)"; flow:established,from_client; content:"GET"; http_method; content:"/oq/oq.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"6ak-tehnik.si"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2023_03_15; reference:url, urlhaus.abuse.ch/url/2572698/; classtype:trojan-activity;sid:83435798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2572553)"; flow:established,from_client; content:"GET"; http_method; content:"/au/au.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"beak.in"; http_host; depth:7; isdataat:!1,relative; metadata:created_at 2023_03_15; reference:url, urlhaus.abuse.ch/url/2572553/; classtype:trojan-activity;sid:83435653; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2572532)"; flow:established,from_client; content:"GET"; http_method; content:"/rdco/rdco.js"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cepde.org"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2023_03_15; reference:url, urlhaus.abuse.ch/url/2572532/; classtype:trojan-activity;sid:83435632; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2572505)"; flow:established,from_client; content:"GET"; http_method; content:"/ed/ed.js"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"htdentshop.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2023_03_15; reference:url, urlhaus.abuse.ch/url/2572505/; classtype:trojan-activity;sid:83435605; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571476)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"riderspin.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571476/; classtype:trojan-activity;sid:83434576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571417)"; flow:established,from_client; content:"GET"; http_method; content:"/agenzia/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"admin.byte.in.ua"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571417/; classtype:trojan-activity;sid:83434517; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571398)"; flow:established,from_client; content:"GET"; http_method; content:"/connect/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"records.dennisign.se"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571398/; classtype:trojan-activity;sid:83434498; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571387)"; flow:established,from_client; content:"GET"; http_method; content:"/agenzia/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"donkeytourscroatia.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571387/; classtype:trojan-activity;sid:83434487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571233)"; flow:established,from_client; content:"GET"; http_method; content:"/agenzia/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"srsorvete.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571233/; classtype:trojan-activity;sid:83434333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571166)"; flow:established,from_client; content:"GET"; http_method; content:"/agenzia/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"twu-hwt.org"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571166/; classtype:trojan-activity;sid:83434266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571162)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"admin.byte.in.ua"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571162/; classtype:trojan-activity;sid:83434262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571158)"; flow:established,from_client; content:"GET"; http_method; content:"/agenzia/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"records.dennisign.se"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571158/; classtype:trojan-activity;sid:83434258; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571135)"; flow:established,from_client; content:"GET"; http_method; content:"/connect/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"donkeytourscroatia.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571135/; classtype:trojan-activity;sid:83434235; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2571043)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"donkeytourscroatia.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2571043/; classtype:trojan-activity;sid:83434143; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570811)"; flow:established,from_client; content:"GET"; http_method; content:"/connect/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"twu-hwt.org"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570811/; classtype:trojan-activity;sid:83433911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570726)"; flow:established,from_client; content:"GET"; http_method; content:"/connect/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"srsorvete.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570726/; classtype:trojan-activity;sid:83433826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570642)"; flow:established,from_client; content:"GET"; http_method; content:"/connect/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"admin.byte.in.ua"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570642/; classtype:trojan-activity;sid:83433742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570563)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"embedone.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570563/; classtype:trojan-activity;sid:83433663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570501)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"records.dennisign.se"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570501/; classtype:trojan-activity;sid:83433601; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570450)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"twu-hwt.org"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570450/; classtype:trojan-activity;sid:83433550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2570405)"; flow:established,from_client; content:"GET"; http_method; content:"/scarica/"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"srsorvete.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2023_03_14; reference:url, urlhaus.abuse.ch/url/2570405/; classtype:trojan-activity;sid:83433505; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2545788)"; flow:established,from_client; content:"GET"; http_method; content:"/tedburke/commandcam/archive/refs/heads/master.zip"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2023_02_20; reference:url, urlhaus.abuse.ch/url/2545788/; classtype:trojan-activity;sid:83408888; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2540034)"; flow:established,from_client; content:"GET"; http_method; content:"/unlockteame/unlimited/zip/refs/heads/main"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2023_02_14; reference:url, urlhaus.abuse.ch/url/2540034/; classtype:trojan-activity;sid:83403134; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2440082)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/raw/master/discord%20rat/resources/token%20grabber.dll"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2022_11_30; reference:url, urlhaus.abuse.ch/url/2440082/; classtype:trojan-activity;sid:83303182; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2440081)"; flow:established,from_client; content:"GET"; http_method; content:"/moom825/discord-rat-2.0/raw/master/discord%20rat/resources/passwordstealer.dll"; http_uri; depth:79; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2022_11_30; reference:url, urlhaus.abuse.ch/url/2440081/; classtype:trojan-activity;sid:83303181; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2425972)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|confirm=no_antivirus|7c|26|7c|id=1cpaqimeblbmxrxoli6d3cczgkrbzpy8_"; http_uri; depth:98; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2022_11_18; reference:url, urlhaus.abuse.ch/url/2425972/; classtype:trojan-activity;sid:83289072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2408069)"; flow:established,from_client; content:"GET"; http_method; content:"/analytics/zy5ntk/"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"fromthetrenchesworldreport.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2022_11_11; reference:url, urlhaus.abuse.ch/url/2408069/; classtype:trojan-activity;sid:83271169; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2406761)"; flow:established,from_client; content:"GET"; http_method; content:"/s/dl/wpoxoxqe2in4fju/doc7november00065.js"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2022_11_10; reference:url, urlhaus.abuse.ch/url/2406761/; classtype:trojan-activity;sid:83269861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2393391)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/block-supports/5.png"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"fullstacknir.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2022_11_01; reference:url, urlhaus.abuse.ch/url/2393391/; classtype:trojan-activity;sid:83256491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2302899)"; flow:established,from_client; content:"GET"; http_method; content:"/janchuk/voidrat/raw/master/voidrat.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2022_09_14; reference:url, urlhaus.abuse.ch/url/2302899/; classtype:trojan-activity;sid:83165999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2252574)"; flow:established,from_client; content:"GET"; http_method; content:"/updates1/up.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"1717.1000uc.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2022_06_30; reference:url, urlhaus.abuse.ch/url/2252574/; classtype:trojan-activity;sid:83115674; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2250908)"; flow:established,from_client; content:"GET"; http_method; content:"/ema_kvcebm137.bin"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"mersped.mycpanel.rs"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_06_27; reference:url, urlhaus.abuse.ch/url/2250908/; classtype:trojan-activity;sid:83114008; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2237175)"; flow:established,from_client; content:"GET"; http_method; content:"/cg100/cg100.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"update.cg100iii.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_06_14; reference:url, urlhaus.abuse.ch/url/2237175/; classtype:trojan-activity;sid:83100275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2237174)"; flow:established,from_client; content:"GET"; http_method; content:"/cgmb/benzmonster.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"update.cg100iii.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_06_14; reference:url, urlhaus.abuse.ch/url/2237174/; classtype:trojan-activity;sid:83100274; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2171312)"; flow:established,from_client; content:"GET"; http_method; content:"/verkaufsberater_service/ozrw36a2y1ch2cluzy/"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"farschid.de"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2022_04_29; reference:url, urlhaus.abuse.ch/url/2171312/; classtype:trojan-activity;sid:83034412; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2164668)"; flow:established,from_client; content:"GET"; http_method; content:"/verkaufsberater_service/uadjw/"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"farschid.de"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2022_04_26; reference:url, urlhaus.abuse.ch/url/2164668/; classtype:trojan-activity;sid:83027768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2124302)"; flow:established,from_client; content:"GET"; http_method; content:"/xmrig/xmrig/releases/download/v6.10.0/xmrig-6.10.0-linux-static-x64.tar.gz"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2022_03_31; reference:url, urlhaus.abuse.ch/url/2124302/; classtype:trojan-activity;sid:82987402; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2119354)"; flow:established,from_client; content:"GET"; http_method; content:"/verkaufsberater_service/3cxmq4uaxy/"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"farschid.de"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2022_03_29; reference:url, urlhaus.abuse.ch/url/2119354/; classtype:trojan-activity;sid:82982454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2119353)"; flow:established,from_client; content:"GET"; http_method; content:"/verkaufsberater_service/3cxmq4uaxy/|3f|i=1"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"farschid.de"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2022_03_29; reference:url, urlhaus.abuse.ch/url/2119353/; classtype:trojan-activity;sid:82982453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2114263)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/yjmqxmidki/a/hyehwggs.ps1"; http_uri; depth:45; isdataat:!1,relative; nocase; content:"trtmyanmar.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2022_03_24; reference:url, urlhaus.abuse.ch/url/2114263/; classtype:trojan-activity;sid:82977363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2109541)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/23"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"182.52.51.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2022_03_21; reference:url, urlhaus.abuse.ch/url/2109541/; classtype:trojan-activity;sid:82972641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2109542)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/23s"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"182.52.51.239"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2022_03_21; reference:url, urlhaus.abuse.ch/url/2109542/; classtype:trojan-activity;sid:82972642; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2086235)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gvnzexvvs3vpv0-ihflwnmzmhij3qqly"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2022_03_09; reference:url, urlhaus.abuse.ch/url/2086235/; classtype:trojan-activity;sid:82949335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2053942)"; flow:established,from_client; content:"GET"; http_method; content:"/zp-user/protected%20client.js"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"dreamwatchevent.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_02_22; reference:url, urlhaus.abuse.ch/url/2053942/; classtype:trojan-activity;sid:82917042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021757)"; flow:established,from_client; content:"GET"; http_method; content:"/src/js/scripts/gallery/photo-swipe/highlight.php"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"acms.saleseos.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021757/; classtype:trojan-activity;sid:82884857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021704)"; flow:established,from_client; content:"GET"; http_method; content:"/src/js/scripts/gallery/photo-swipe/zany.php"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"acms.saleseos.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021704/; classtype:trojan-activity;sid:82884804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2021723)"; flow:established,from_client; content:"GET"; http_method; content:"/app/webroot/assets/global/plugins/jquery-file-upload/server/php/files/dwarves.php"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"tpp.om-stock.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2022_02_01; reference:url, urlhaus.abuse.ch/url/2021723/; classtype:trojan-activity;sid:82884823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019377)"; flow:established,from_client; content:"GET"; http_method; content:"/public/userbackend/plugins/dropzone/min/assents.php"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"theholidayroads.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019377/; classtype:trojan-activity;sid:82882477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019378)"; flow:established,from_client; content:"GET"; http_method; content:"/public/userbackend/plugins/dropzone/min/tautly.php"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"theholidayroads.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019378/; classtype:trojan-activity;sid:82882478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019365)"; flow:established,from_client; content:"GET"; http_method; content:"/public/userbackend/plugins/dropzone/min/knave.php"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"theholidayroads.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019365/; classtype:trojan-activity;sid:82882465; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2019358)"; flow:established,from_client; content:"GET"; http_method; content:"/public/userbackend/plugins/dropzone/min/stare.php"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"theholidayroads.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2022_01_31; reference:url, urlhaus.abuse.ch/url/2019358/; classtype:trojan-activity;sid:82882458; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2008178)"; flow:established,from_client; content:"GET"; http_method; content:"/comply.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"www.crazywickedaddiction.com"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2022_01_27; reference:url, urlhaus.abuse.ch/url/2008178/; classtype:trojan-activity;sid:82871278; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2008138)"; flow:established,from_client; content:"GET"; http_method; content:"/squalid.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"continentalgroup.net.in"; http_host; depth:23; isdataat:!1,relative; metadata:created_at 2022_01_27; reference:url, urlhaus.abuse.ch/url/2008138/; classtype:trojan-activity;sid:82871238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (2008130)"; flow:established,from_client; content:"GET"; http_method; content:"/development/public/uploads/images/categories/beirut.php"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"www.crazywickedaddiction.com"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2022_01_27; reference:url, urlhaus.abuse.ch/url/2008130/; classtype:trojan-activity;sid:82871230; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1992717)"; flow:established,from_client; content:"GET"; http_method; content:"/b/taakftemqf1udhs0lzdru2p1rwumw9/|3f|i=1"; http_uri; depth:41; isdataat:!1,relative; nocase; content:"mibd.org"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2022_01_20; reference:url, urlhaus.abuse.ch/url/1992717/; classtype:trojan-activity;sid:82855817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1992716)"; flow:established,from_client; content:"GET"; http_method; content:"/b/taakftemqf1udhs0lzdru2p1rwumw9/"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"mibd.org"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2022_01_20; reference:url, urlhaus.abuse.ch/url/1992716/; classtype:trojan-activity;sid:82855816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1989487)"; flow:established,from_client; content:"GET"; http_method; content:"/b/621683_9657/"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"mibd.org"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2022_01_19; reference:url, urlhaus.abuse.ch/url/1989487/; classtype:trojan-activity;sid:82852587; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1989488)"; flow:established,from_client; content:"GET"; http_method; content:"/b/621683_9657/|3f|i=1"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"mibd.org"; http_host; depth:8; isdataat:!1,relative; metadata:created_at 2022_01_19; reference:url, urlhaus.abuse.ch/url/1989488/; classtype:trojan-activity;sid:82852588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891112)"; flow:established,from_client; content:"GET"; http_method; content:"/honduras.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"xenon.studio"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891112/; classtype:trojan-activity;sid:82754212; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891095)"; flow:established,from_client; content:"GET"; http_method; content:"/assets2/theme/css/gluttonous.php"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"xenon.studio"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891095/; classtype:trojan-activity;sid:82754195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891066)"; flow:established,from_client; content:"GET"; http_method; content:"/searching.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"xenon.studio"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891066/; classtype:trojan-activity;sid:82754166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891070)"; flow:established,from_client; content:"GET"; http_method; content:"/assets2/theme/css/linearization.php"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"xenon.studio"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891070/; classtype:trojan-activity;sid:82754170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1891071)"; flow:established,from_client; content:"GET"; http_method; content:"/wrongdoer.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"xenon.studio"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1891071/; classtype:trojan-activity;sid:82754171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1890257)"; flow:established,from_client; content:"GET"; http_method; content:"/lib/crypta.js"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"reauthenticator.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2021_12_16; reference:url, urlhaus.abuse.ch/url/1890257/; classtype:trojan-activity;sid:82753357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1839258)"; flow:established,from_client; content:"GET"; http_method; content:"/shopped.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_12_01; reference:url, urlhaus.abuse.ch/url/1839258/; classtype:trojan-activity;sid:82702358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1839238)"; flow:established,from_client; content:"GET"; http_method; content:"/accumulation.php"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_12_01; reference:url, urlhaus.abuse.ch/url/1839238/; classtype:trojan-activity;sid:82702338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1839240)"; flow:established,from_client; content:"GET"; http_method; content:"/scuffler.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_12_01; reference:url, urlhaus.abuse.ch/url/1839240/; classtype:trojan-activity;sid:82702340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1839228)"; flow:established,from_client; content:"GET"; http_method; content:"/sublimely.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"muledo.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2021_12_01; reference:url, urlhaus.abuse.ch/url/1839228/; classtype:trojan-activity;sid:82702328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838316)"; flow:established,from_client; content:"GET"; http_method; content:"/ticketing.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"beoauto.alexion.rs"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838316/; classtype:trojan-activity;sid:82701416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838317)"; flow:established,from_client; content:"GET"; http_method; content:"/complicate.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"beoauto.alexion.rs"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838317/; classtype:trojan-activity;sid:82701417; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838306)"; flow:established,from_client; content:"GET"; http_method; content:"/blend.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838306/; classtype:trojan-activity;sid:82701406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838289)"; flow:established,from_client; content:"GET"; http_method; content:"/gastric.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"beoauto.alexion.rs"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838289/; classtype:trojan-activity;sid:82701389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838275)"; flow:established,from_client; content:"GET"; http_method; content:"/flyer.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838275/; classtype:trojan-activity;sid:82701375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838263)"; flow:established,from_client; content:"GET"; http_method; content:"/acclimated.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"beoauto.alexion.rs"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838263/; classtype:trojan-activity;sid:82701363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838242)"; flow:established,from_client; content:"GET"; http_method; content:"/warmhearted.php"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838242/; classtype:trojan-activity;sid:82701342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1838244)"; flow:established,from_client; content:"GET"; http_method; content:"/daydream.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"greenf.alexion.rs"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1838244/; classtype:trojan-activity;sid:82701344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1837873)"; flow:established,from_client; content:"GET"; http_method; content:"/investigative.php"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"muledo.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2021_11_30; reference:url, urlhaus.abuse.ch/url/1837873/; classtype:trojan-activity;sid:82700973; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1761107)"; flow:established,from_client; content:"GET"; http_method; content:"/svr_netchecker/server.asp|3f|v_command=3002|7c|26|7c|v_progname=sjptmanagerlauncher.exe"; http_uri; depth:88; isdataat:!1,relative; nocase; content:"server.toeicswt.co.kr"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2021_11_07; reference:url, urlhaus.abuse.ch/url/1761107/; classtype:trojan-activity;sid:82624207; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1744285)"; flow:established,from_client; content:"GET"; http_method; content:"/chimney.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"lawfirm.paperbirdtech.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1744285/; classtype:trojan-activity;sid:82607385; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743733)"; flow:established,from_client; content:"GET"; http_method; content:"/zoologies.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"bridgeroad.maverickpreviews.com"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743733/; classtype:trojan-activity;sid:82606833; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743713)"; flow:established,from_client; content:"GET"; http_method; content:"/whacked.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"bridgeroad.maverickpreviews.com"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743713/; classtype:trojan-activity;sid:82606813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743650)"; flow:established,from_client; content:"GET"; http_method; content:"/toggle.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"lawfirm.paperbirdtech.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743650/; classtype:trojan-activity;sid:82606750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1743660)"; flow:established,from_client; content:"GET"; http_method; content:"/unplug.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"bridgeroad.maverickpreviews.com"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2021_11_03; reference:url, urlhaus.abuse.ch/url/1743660/; classtype:trojan-activity;sid:82606760; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1698569)"; flow:established,from_client; content:"GET"; http_method; content:"/yacht.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"tartaklegnica.pl"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_10_20; reference:url, urlhaus.abuse.ch/url/1698569/; classtype:trojan-activity;sid:82561669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1698570)"; flow:established,from_client; content:"GET"; http_method; content:"/byword.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"tartaklegnica.pl"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_10_20; reference:url, urlhaus.abuse.ch/url/1698570/; classtype:trojan-activity;sid:82561670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1698573)"; flow:established,from_client; content:"GET"; http_method; content:"/root.php"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"tartaklegnica.pl"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_10_20; reference:url, urlhaus.abuse.ch/url/1698573/; classtype:trojan-activity;sid:82561673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1698575)"; flow:established,from_client; content:"GET"; http_method; content:"/rabbinic.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"tartaklegnica.pl"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_10_20; reference:url, urlhaus.abuse.ch/url/1698575/; classtype:trojan-activity;sid:82561675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1678523)"; flow:established,from_client; content:"GET"; http_method; content:"/upload/vltktanthutn.exe"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"kimyen.net"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2021_10_14; reference:url, urlhaus.abuse.ch/url/1678523/; classtype:trojan-activity;sid:82541623; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1658066)"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"deagroup-ks.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1658066/; classtype:trojan-activity;sid:82521166; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1658054)"; flow:established,from_client; content:"GET"; http_method; content:"/approx.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"deagroup-ks.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1658054/; classtype:trojan-activity;sid:82521154; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1658038)"; flow:established,from_client; content:"GET"; http_method; content:"/converting.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"deagroup-ks.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1658038/; classtype:trojan-activity;sid:82521138; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1657096)"; flow:established,from_client; content:"GET"; http_method; content:"/update/ana/update.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"www.teknoarge.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_10_06; reference:url, urlhaus.abuse.ch/url/1657096/; classtype:trojan-activity;sid:82520196; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1647561)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=12ma_yvbmprts6e_vkfnmwikrnwsarqbw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_29; reference:url, urlhaus.abuse.ch/url/1647561/; classtype:trojan-activity;sid:82510661; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1624890)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1o9jg3oqyewncoptigwscdbtfmvtfqygj"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_16; reference:url, urlhaus.abuse.ch/url/1624890/; classtype:trojan-activity;sid:82487990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1619497)"; flow:established,from_client; content:"GET"; http_method; content:"/decapitate.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"tiacreation.club"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_14; reference:url, urlhaus.abuse.ch/url/1619497/; classtype:trojan-activity;sid:82482597; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1604292)"; flow:established,from_client; content:"GET"; http_method; content:"/promethium.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"lawfirm.paperbirdtech.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_09; reference:url, urlhaus.abuse.ch/url/1604292/; classtype:trojan-activity;sid:82467392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1602881)"; flow:established,from_client; content:"GET"; http_method; content:"/photon.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"lawfirm.paperbirdtech.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_08; reference:url, urlhaus.abuse.ch/url/1602881/; classtype:trojan-activity;sid:82465981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1602867)"; flow:established,from_client; content:"GET"; http_method; content:"/philanthropic.php"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"lawfirm.paperbirdtech.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_08; reference:url, urlhaus.abuse.ch/url/1602867/; classtype:trojan-activity;sid:82465967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1602778)"; flow:established,from_client; content:"GET"; http_method; content:"/wash.php"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"lawfirm.paperbirdtech.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2021_09_08; reference:url, urlhaus.abuse.ch/url/1602778/; classtype:trojan-activity;sid:82465878; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582138)"; flow:established,from_client; content:"GET"; http_method; content:"/coon.php"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"allendostmen.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582138/; classtype:trojan-activity;sid:82445238; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582118)"; flow:established,from_client; content:"GET"; http_method; content:"/manly.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"allendostmen.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582118/; classtype:trojan-activity;sid:82445218; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582106)"; flow:established,from_client; content:"GET"; http_method; content:"/lecher.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"allendostmen.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582106/; classtype:trojan-activity;sid:82445206; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1582015)"; flow:established,from_client; content:"GET"; http_method; content:"/strobing.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"allendostmen.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_09_01; reference:url, urlhaus.abuse.ch/url/1582015/; classtype:trojan-activity;sid:82445115; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1560761)"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/safmanager/safman_setup.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"www.saf-oil.ru"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2021_08_24; reference:url, urlhaus.abuse.ch/url/1560761/; classtype:trojan-activity;sid:82423861; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503427)"; flow:established,from_client; content:"GET"; http_method; content:"/teachable.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"chat-server.maverickpreviews.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503427/; classtype:trojan-activity;sid:82366527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503410)"; flow:established,from_client; content:"GET"; http_method; content:"/aggressive.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"chat-server.maverickpreviews.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503410/; classtype:trojan-activity;sid:82366510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503377)"; flow:established,from_client; content:"GET"; http_method; content:"/belt.php"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"bridgeroad.maverickpreviews.com"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503377/; classtype:trojan-activity;sid:82366477; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503368)"; flow:established,from_client; content:"GET"; http_method; content:"/anarchical.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"bridgeroad.maverickpreviews.com"; http_host; depth:31; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503368/; classtype:trojan-activity;sid:82366468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503361)"; flow:established,from_client; content:"GET"; http_method; content:"/newborn.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"chat-server.maverickpreviews.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503361/; classtype:trojan-activity;sid:82366461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503351)"; flow:established,from_client; content:"GET"; http_method; content:"/ruckus.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"www.cutting-edge.in"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503351/; classtype:trojan-activity;sid:82366451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503338)"; flow:established,from_client; content:"GET"; http_method; content:"/unanswerable.php"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"chat-server.maverickpreviews.com"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503338/; classtype:trojan-activity;sid:82366438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503341)"; flow:established,from_client; content:"GET"; http_method; content:"/harass.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"www.cutting-edge.in"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503341/; classtype:trojan-activity;sid:82366441; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1503303)"; flow:established,from_client; content:"GET"; http_method; content:"/vicinity.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"acrilicoporto.pt"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_08_03; reference:url, urlhaus.abuse.ch/url/1503303/; classtype:trojan-activity;sid:82366403; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1497688)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.164.200.170"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_08_01; reference:url, urlhaus.abuse.ch/url/1497688/; classtype:trojan-activity;sid:82360788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1473823)"; flow:established,from_client; content:"GET"; http_method; content:"/sweat.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"www.cutting-edge.in"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2021_07_22; reference:url, urlhaus.abuse.ch/url/1473823/; classtype:trojan-activity;sid:82336923; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1470181)"; flow:established,from_client; content:"GET"; http_method; content:"/power.txt"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"103.106.250.161"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_07_21; reference:url, urlhaus.abuse.ch/url/1470181/; classtype:trojan-activity;sid:82333281; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1469946)"; flow:established,from_client; content:"GET"; http_method; content:"/hajime"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"103.125.163.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2021_07_21; reference:url, urlhaus.abuse.ch/url/1469946/; classtype:trojan-activity;sid:82333046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1422022)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1n8_s6gijerearczwh74blkygodig64eo"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_07_03; reference:url, urlhaus.abuse.ch/url/1422022/; classtype:trojan-activity;sid:82285122; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1422010)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1yfqtugahqhqrulwugdekeavffktsl8ci"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_07_03; reference:url, urlhaus.abuse.ch/url/1422010/; classtype:trojan-activity;sid:82285110; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1416694)"; flow:established,from_client; content:"GET"; http_method; content:"/await.php"; http_uri; depth:10; isdataat:!1,relative; nocase; content:"thehaider.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_07_01; reference:url, urlhaus.abuse.ch/url/1416694/; classtype:trojan-activity;sid:82279794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1416649)"; flow:established,from_client; content:"GET"; http_method; content:"/spouse.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"thehaider.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_07_01; reference:url, urlhaus.abuse.ch/url/1416649/; classtype:trojan-activity;sid:82279749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1391235)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1sbd1rnw8luztjmsh6gdlzupvyupbopa0|7c|26|7c|revid=0b3yyjts_woklr2vnyxvqohlidxbxn1l2wwjntxfnwvi5v0h3pq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_23; reference:url, urlhaus.abuse.ch/url/1391235/; classtype:trojan-activity;sid:82254335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1378480)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1ctmywlj5wouiug1wgizy3ke7yj1u0yor|7c|26|7c|revid=0b_t0-zked1mgagxwmxcwywq5q0q1uk1uoxcwaup6l2ovmtdjpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_19; reference:url, urlhaus.abuse.ch/url/1378480/; classtype:trojan-activity;sid:82241580; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1372338)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1alq8r5tnr6wwiftqa3l6d9fymv7y0g9m"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_17; reference:url, urlhaus.abuse.ch/url/1372338/; classtype:trojan-activity;sid:82235438; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1371795)"; flow:established,from_client; content:"GET"; http_method; content:"/dole.php"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_16; reference:url, urlhaus.abuse.ch/url/1371795/; classtype:trojan-activity;sid:82234895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1371792)"; flow:established,from_client; content:"GET"; http_method; content:"/spathe.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_16; reference:url, urlhaus.abuse.ch/url/1371792/; classtype:trojan-activity;sid:82234892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1371777)"; flow:established,from_client; content:"GET"; http_method; content:"/foppery.php"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_16; reference:url, urlhaus.abuse.ch/url/1371777/; classtype:trojan-activity;sid:82234877; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1369635)"; flow:established,from_client; content:"GET"; http_method; content:"/wallet/plugins/raphael/dev/test/apall.php"; http_uri; depth:42; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_15; reference:url, urlhaus.abuse.ch/url/1369635/; classtype:trojan-activity;sid:82232735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1369616)"; flow:established,from_client; content:"GET"; http_method; content:"/nuthatch.php"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_15; reference:url, urlhaus.abuse.ch/url/1369616/; classtype:trojan-activity;sid:82232716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1369612)"; flow:established,from_client; content:"GET"; http_method; content:"/lavaliere.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_15; reference:url, urlhaus.abuse.ch/url/1369612/; classtype:trojan-activity;sid:82232712; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1369568)"; flow:established,from_client; content:"GET"; http_method; content:"/wallet/plugins/raphael/dev/test/undecisive.php"; http_uri; depth:47; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_15; reference:url, urlhaus.abuse.ch/url/1369568/; classtype:trojan-activity;sid:82232668; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1369524)"; flow:established,from_client; content:"GET"; http_method; content:"/broadcast.php"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"escrowbank.co"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_06_15; reference:url, urlhaus.abuse.ch/url/1369524/; classtype:trojan-activity;sid:82232624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1364815)"; flow:established,from_client; content:"GET"; http_method; content:"/update_vbase/voklight.exe"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"visam.info"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2021_06_14; reference:url, urlhaus.abuse.ch/url/1364815/; classtype:trojan-activity;sid:82227915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1364597)"; flow:established,from_client; content:"GET"; http_method; content:"/update_vbase/voklightd.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"visam.info"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2021_06_14; reference:url, urlhaus.abuse.ch/url/1364597/; classtype:trojan-activity;sid:82227697; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1352974)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"103.125.163.10"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2021_06_11; reference:url, urlhaus.abuse.ch/url/1352974/; classtype:trojan-activity;sid:82216074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1350621)"; flow:established,from_client; content:"GET"; http_method; content:"/chimpanzee.php"; http_uri; depth:15; isdataat:!1,relative; nocase; content:"sushiandpoke.pt"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_10; reference:url, urlhaus.abuse.ch/url/1350621/; classtype:trojan-activity;sid:82213721; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1350517)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1tilqozot07vylvdmmsfs7ia452jwhktj|7c|26|7c|revid=0b7gsmqzks4xkcdjcwhuvatj2qvlvchnmnnovu2ldzstek2jzpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_10; reference:url, urlhaus.abuse.ch/url/1350517/; classtype:trojan-activity;sid:82213617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1348672)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1etpmpb2shvuny5dxj5awfpxklxqpbzgx"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_10; reference:url, urlhaus.abuse.ch/url/1348672/; classtype:trojan-activity;sid:82211772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1343323)"; flow:established,from_client; content:"GET"; http_method; content:"/hoopoe.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"thementordirectory.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2021_06_09; reference:url, urlhaus.abuse.ch/url/1343323/; classtype:trojan-activity;sid:82206423; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1343313)"; flow:established,from_client; content:"GET"; http_method; content:"/hare.php"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"thementordirectory.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2021_06_09; reference:url, urlhaus.abuse.ch/url/1343313/; classtype:trojan-activity;sid:82206413; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1343296)"; flow:established,from_client; content:"GET"; http_method; content:"/donate.php"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"thementordirectory.com"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2021_06_09; reference:url, urlhaus.abuse.ch/url/1343296/; classtype:trojan-activity;sid:82206396; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1331376)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1b6t1mjnjcvndcy-mdqq0neqrbocqyju4"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_06; reference:url, urlhaus.abuse.ch/url/1331376/; classtype:trojan-activity;sid:82194476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1327898)"; flow:established,from_client; content:"GET"; http_method; content:"/inst77player/inst77player_1.0.0.1.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"softdl.360tpcdn.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2021_06_05; reference:url, urlhaus.abuse.ch/url/1327898/; classtype:trojan-activity;sid:82190998; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1319551)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1nw1gmzg6lwtuhs0tte969xcfpp9_dc5q"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_06_03; reference:url, urlhaus.abuse.ch/url/1319551/; classtype:trojan-activity;sid:82182651; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314578)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vszvhw0lywviz_dpqozkdip0orjsf7411ucirwqegcgfxwqqb3nqpbn3d7orqqxnatypulra_ssggie/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314578/; classtype:trojan-activity;sid:82177678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314581)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vr-asdhfa85lnhp1g6rll18x2htnflvy5zggxzrfveecvbhjiwaes9o9w3dn49od7lplixl3u59icjr/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314581/; classtype:trojan-activity;sid:82177681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314569)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqb__8qdiraoo-s_qrzkk8o_8brsuwaeje3ivcd5efhddlux4gw5otilj5ezfenwjzaha-zojj_7srj/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314569/; classtype:trojan-activity;sid:82177669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314562)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqha4kutkvbpn1c9r1jolub-v1dyh36itza-2zhojxuluskoxk6iogpy8b8iscqqjskaf3wduc6oykt/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314562/; classtype:trojan-activity;sid:82177662; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314563)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqm_l1o1djktv6pcfwixdz1gjaqrg26rpb3n3uqpk0jqvif91b_irdew7mo34hhhoffbjohoztlmdtp/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314563/; classtype:trojan-activity;sid:82177663; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314556)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vrxkt9v4qcom-0wjceb6bexufgpr_vdebkc-kra8h7gutbblset1veguumqxs3npiv4qw-7_1kiy3jm/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314556/; classtype:trojan-activity;sid:82177656; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314548)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vspnrqtfaftwpvbd8o61fbvozlhc3z0x8jy4glnji-v80xrxnlemgt89l5imnr_7kxst0gn9ydkjj0q/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314548/; classtype:trojan-activity;sid:82177648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314549)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vsftpbjz498ict3ab9-tehopymacl8ygytkgufxpnwlfphfxyyh5jmfj_2llrrddsiu8vypu1ksvp5p/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314549/; classtype:trojan-activity;sid:82177649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314543)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vs1h7txewarzqve-jwxnwcgzibofoz58qrk8kerhmfz8mpippgfjeoijthgmm-tw7lwcipr8acup_ft/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314543/; classtype:trojan-activity;sid:82177643; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314544)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vr92cz6z4uh71ogqyzgn6vtdc54xoa0iovizmkmogvekyix648nysfipvt4qto6uvtrp9jsatoeuhk3/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314544/; classtype:trojan-activity;sid:82177644; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314545)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtuc-a7s7ylxnfwqp8oxz6no5uwdmabudx-6glkwrnzjwqwgdtcpdvwp0x0l03qdarzrzonj_adevlw/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314545/; classtype:trojan-activity;sid:82177645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314534)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqe1vc-nlfenfgigyaugmmg1dq4l0-haikp9qxkacc32ig0xtg6go8lejdoogo0vfeoie4tcyy4_bn4/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314534/; classtype:trojan-activity;sid:82177634; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314535)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vsrvkllojuhzbqokettk0u2b1whglldp35-o1zgt_jlem2z2odwedj0z9sgtukvikdowcuan-0fj5wn/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314535/; classtype:trojan-activity;sid:82177635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314537)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqvbpr6y2jjnkxfpcwt9uv7pqycg6vdoowr-xnakhtl9ns4tk44rpa91em8usoc992uqyrpn6ucy5ep/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314537/; classtype:trojan-activity;sid:82177637; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1314526)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vq8kqm4rsobvbpga8ncnzs-1xulwuezfri9x1ktowpiijctqe1uq0iged6iq7sa5zuhnh56egsebkoj/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_06_02; reference:url, urlhaus.abuse.ch/url/1314526/; classtype:trojan-activity;sid:82177626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287391)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtecbrofm9hcrdmzz8g7ktneypnrpr1s7bvyoit3r8jd7rjanmysk9yyuhvzmdp3dmkd-xss7kpyffa/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287391/; classtype:trojan-activity;sid:82150491; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287387)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vt544w_wvxhvfskbx2zio7pht-jzhb1nvr7y1qhtxccjopcfxzhm1mottjhjsdudpgs9lfrjcqzoi8n/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287387/; classtype:trojan-activity;sid:82150487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287378)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtcfdv_0srlqbmtfzi6hivmikknsfqd5bubuem-s-mzpzfsva62zyncoy-phkzysuhuddl0yhlyajye/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287378/; classtype:trojan-activity;sid:82150478; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287373)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vrtnhy8ipm82egefg7zhukj5qwbit31-jlhdsxovff8rcefw2uhpndpuclv_ffrqqdjhxyxympj3ame/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287373/; classtype:trojan-activity;sid:82150473; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1287333)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vt4iy9nlwuov8hsmpykbfkn1fh1ydp7ms8dudg2ldfjgxf8rumdtzgiw7ukoifo3ap-pb7ybzlcdfqi/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_26; reference:url, urlhaus.abuse.ch/url/1287333/; classtype:trojan-activity;sid:82150433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278913)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtyg409rjv4omi3oujyjsc6ajzflluuz37ofzbpjjihmrewoh2ehp2pwbfllgyy_yzqdrldwcaejvd5/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278913/; classtype:trojan-activity;sid:82142013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278910)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vr1e4kzyqneoh2tjc5rh_unlfwjdo31gedrveg0wdyrprmm3yfdxjqxdvyy535adzu5p9m4mrvdau9v/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278910/; classtype:trojan-activity;sid:82142010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278905)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vrvmutaxfc2ewkvy_l_cewfjwv4md_uadqlv4onmlyc0frnp7jod3ru93sm6y-tmoj0nrvbfylt739z/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278905/; classtype:trojan-activity;sid:82142005; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278895)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtpholmraa4dir0lg8z5yhqljwbzp0qkypc3jax6d3l0hs6n23kpm2iqgccjvbvug5th443jjbzs2uv/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278895/; classtype:trojan-activity;sid:82141995; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1278899)"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqyowyoxata2couqa6uc3gwi59sq5maualr7yfmq6luzvtefqopogncbli8hx6vubkt2b65qerqhzy8/pub"; http_uri; depth:104; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_24; reference:url, urlhaus.abuse.ch/url/1278899/; classtype:trojan-activity;sid:82141999; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1237690)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1m8jszvq-ztfrul7vgsb6q-n3ftgnkbdj|7c|26|7c|revid=0bxrhybf9__wnmgjlnmxmunzznlu0v204azc4edmzcep6a0hzpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_15; reference:url, urlhaus.abuse.ch/url/1237690/; classtype:trojan-activity;sid:82100790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1233306)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gv_nk9llqw4fxudo-khja7nuuj1kevvw|7c|26|7c|revid=0b7zefp-g6n7vm0zhowo4be9pvus4mmh0ymxvd3r6zlu3ylznpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_14; reference:url, urlhaus.abuse.ch/url/1233306/; classtype:trojan-activity;sid:82096406; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1228819)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=140vkyfrfhbqkukc2hnw-gsvi5wjw6iyi"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_13; reference:url, urlhaus.abuse.ch/url/1228819/; classtype:trojan-activity;sid:82091919; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1220349)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1h_dyp_d5lst4akyf2qezxl7j1scvbtvs|7c|26|7c|revid=0b5thckui5i0mdk5moelbnm9vuhnydvjnvwpyq01vrg5xvwhrpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_05_11; reference:url, urlhaus.abuse.ch/url/1220349/; classtype:trojan-activity;sid:82083449; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1199812)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1uygnpwzzyzn2rodsrimg0-sloxy_letg"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_05_06; reference:url, urlhaus.abuse.ch/url/1199812/; classtype:trojan-activity;sid:82062912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1198558)"; flow:established,from_client; content:"GET"; http_method; content:"/view/59bmj3vj18vh2/drive/storage/a/files/download|3f|id=625899581658508733"; http_uri; depth:75; isdataat:!1,relative; nocase; content:"sites.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2021_05_06; reference:url, urlhaus.abuse.ch/url/1198558/; classtype:trojan-activity;sid:82061658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1182816)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1zxejnkdwqezrbgani5vjk2y2nhmpkg0z|7c|26|7c|revid=0b-bo0wgwxcblsui1mehkbhrlu01rwxnyrxzxanbdendmbndnpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1182816/; classtype:trojan-activity;sid:82045916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181763)"; flow:established,from_client; content:"GET"; http_method; content:"/upload_control/download.blog|3f|fhandle=mep5euraznm5lmjsb2cuzgf1bs5uzxq6l0lnqudflzavns5legu=|7c|26|7c|filename=%ec%9d%b8%ed%84%b0%eb%84%b7_%ec%a2%85%eb%9f%89%ec%a0%9c_%ed%85%8c%ec%8a%a4%ed%8a%b8.exe"; http_uri; depth:199; isdataat:!1,relative; nocase; content:"cfs9.blog.daum.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181763/; classtype:trojan-activity;sid:82044863; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181758)"; flow:established,from_client; content:"GET"; http_method; content:"/upload_control/download.blog|3f|fhandle=ymxvzze5mtk5nubmczezlnrpc3rvcnkuy29toi9hdhrhy2gvmc8xnzawmdawmdawmdauzxhl|7c|26|7c|filename=oleaut32.dll%bf%c0%b7%f9%c7%d8%b0%e1%c7%cf%b1%e2.exe"; http_uri; depth:184; isdataat:!1,relative; nocase; content:"cfs13.tistory.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181758/; classtype:trojan-activity;sid:82044858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181756)"; flow:established,from_client; content:"GET"; http_method; content:"/upload_control/download.blog|3f|fhandle=mdczafhaznmxmc5ibg9nlmrhdw0ubmv0oi9jtufhrs8wlzkwlmv4zq==|7c|26|7c|filename=xp_sp3_%ed%85%8c%eb%a7%88%ed%8c%a8%ec%b9%98.exe"; http_uri; depth:163; isdataat:!1,relative; nocase; content:"cfs10.blog.daum.net"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181756/; classtype:trojan-activity;sid:82044856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181754)"; flow:established,from_client; content:"GET"; http_method; content:"/upload_control/download.blog|3f|fhandle=ymxvzze5mtk5nubmczezlnrpc3rvcnkuy29toi9hdhrhy2gvmc8xnzawmdawmdawmdauzxhl|7c|26|7c|filename=oleaut32.dll%ef%bf%bd%ef%bf%bd%ef%bf%bd%ef%bf%bd%ef%bf%bd%d8%b0%ef%bf%bd%ef%bf%bd%cf%b1%ef%bf%bd.exe"; http_uri; depth:232; isdataat:!1,relative; nocase; content:"cfs13.tistory.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181754/; classtype:trojan-activity;sid:82044854; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1181755)"; flow:established,from_client; content:"GET"; http_method; content:"/upload_control/download.blog|3f|fhandle=metnwe5aznm3lmjsb2cuzgf1bs5uzxq6l0lnqudflzavmc5legu=|7c|26|7c|filename=%ec%9d%b8%ed%84%b0%eb%84%b7_%ec%a2%85%eb%9f%89%ec%a0%9c_%ed%85%8c%ec%8a%a4%ed%8a%b8-cksal16.exe/%ec%9d%b8%ed%84%b0%eb%84%b7_%ec%a2%85%eb%9f%89%ec%a0%9c_%ed%85%8c%ec%8a%a4%ed%8a%b8-cksal16.exe"; http_uri; depth:303; isdataat:!1,relative; nocase; content:"cfs7.blog.daum.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2021_04_29; reference:url, urlhaus.abuse.ch/url/1181755/; classtype:trojan-activity;sid:82044855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1152444)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1jpl-uouydm5hypqm67uokyddrblbpxvw|7c|26|7c|revid=0b7zpiprmoc5ubhpwclq0cxdyte5vwtrbymnidznhtgm3bzvrpq"; http_uri; depth:135; isdataat:!1,relative; nocase; content:"docs.google.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_04_22; reference:url, urlhaus.abuse.ch/url/1152444/; classtype:trojan-activity;sid:82015544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1098623)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"111.185.171.111"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2021_03_29; reference:url, urlhaus.abuse.ch/url/1098623/; classtype:trojan-activity;sid:81961723; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1069008)"; flow:established,from_client; content:"GET"; http_method; content:"/opj5cs64q.rar"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"outpost.co.ke"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2021_03_15; reference:url, urlhaus.abuse.ch/url/1069008/; classtype:trojan-activity;sid:81932108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (1068684)"; flow:established,from_client; content:"GET"; http_method; content:"/njtzac0.tar"; http_uri; depth:12; isdataat:!1,relative; nocase; content:"mysura.it"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2021_03_15; reference:url, urlhaus.abuse.ch/url/1068684/; classtype:trojan-activity;sid:81931784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (957784)"; flow:established,from_client; content:"GET"; http_method; content:"/gamewd/yhdl.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"download.caihong.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2021_01_13; reference:url, urlhaus.abuse.ch/url/957784/; classtype:trojan-activity;sid:81820884; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (936427)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/bxjesdj7w3meuh7iatiurbsgh/"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"cdaonline.com.ar"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_12_21; reference:url, urlhaus.abuse.ch/url/936427/; classtype:trojan-activity;sid:81799527; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (765703)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/lm/7cfvaaa9jo/"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"ncxps.com"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_29; reference:url, urlhaus.abuse.ch/url/765703/; classtype:trojan-activity;sid:81628803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (756747)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/rrrv7ilgm2dzpohaklkhewb8rkju15bmqeewccglap/"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"ncxps.com"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_27; reference:url, urlhaus.abuse.ch/url/756747/; classtype:trojan-activity;sid:81619847; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (756736)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/4ld2g8w3rrmhtgvvvpeq2orlcqm71yyxveriw5rzitvii3/"; http_uri; depth:60; isdataat:!1,relative; nocase; content:"ncxps.com"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_27; reference:url, urlhaus.abuse.ch/url/756736/; classtype:trojan-activity;sid:81619836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (733798)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/oct/w9hmkanqe5py4r/"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"ncxps.com"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2020_10_22; reference:url, urlhaus.abuse.ch/url/733798/; classtype:trojan-activity;sid:81596898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (723755)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/sites/ci6p05scnuonqslqmehm/"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"cdaonline.com.ar"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_10_20; reference:url, urlhaus.abuse.ch/url/723755/; classtype:trojan-activity;sid:81586855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (637433)"; flow:established,from_client; content:"GET"; http_method; content:"/paetools.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"soft.110route.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2020_10_01; reference:url, urlhaus.abuse.ch/url/637433/; classtype:trojan-activity;sid:81500533; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (613088)"; flow:established,from_client; content:"GET"; http_method; content:"/mikf/gallery-dl/releases/download/v1.15.0/gallery-dl.exe"; http_uri; depth:57; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2020_09_26; reference:url, urlhaus.abuse.ch/url/613088/; classtype:trojan-activity;sid:81476188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (593578)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/js/jquery/jquery.js"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"chuguadventures.co.tz"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2020_09_22; reference:url, urlhaus.abuse.ch/url/593578/; classtype:trojan-activity;sid:81456678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (554647)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/file/x7z9wbk77tt6v9/"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"cdaonline.com.ar"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_18; reference:url, urlhaus.abuse.ch/url/554647/; classtype:trojan-activity;sid:81417747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (490516)"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"cd.textfiles.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_14; reference:url, urlhaus.abuse.ch/url/490516/; classtype:trojan-activity;sid:81353616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (466831)"; flow:established,from_client; content:"GET"; http_method; content:"/xx.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"tr.zhzy999.net"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2020_09_12; reference:url, urlhaus.abuse.ch/url/466831/; classtype:trojan-activity;sid:81329931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (453216)"; flow:established,from_client; content:"GET"; http_method; content:"/enteihacking/mt/master/asycivic.jpg"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2020_09_04; reference:url, urlhaus.abuse.ch/url/453216/; classtype:trojan-activity;sid:81316316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (453035)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1g_x0a_gnyxai5glsipkq1b2mqknanuw8"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_04; reference:url, urlhaus.abuse.ch/url/453035/; classtype:trojan-activity;sid:81316135; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (452177)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=14muad9cmj6mxsd9lrccuo1egxyf5f-ty"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_03; reference:url, urlhaus.abuse.ch/url/452177/; classtype:trojan-activity;sid:81315277; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (451466)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1yrmkzxf4rmy9utrikbh6rgvsokehbmeo"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_09_02; reference:url, urlhaus.abuse.ch/url/451466/; classtype:trojan-activity;sid:81314566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (447394)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1sm7b9902i8v4yitepf6gzomqc84ltloi"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_08_31; reference:url, urlhaus.abuse.ch/url/447394/; classtype:trojan-activity;sid:81310494; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (446803)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1gavcby-nhlq22ohbgm530exffsrg1aub"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_08_30; reference:url, urlhaus.abuse.ch/url/446803/; classtype:trojan-activity;sid:81309903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (439389)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/statement/ul397wfyb/"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"reifenquick.de"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2020_08_24; reference:url, urlhaus.abuse.ch/url/439389/; classtype:trojan-activity;sid:81302489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (438705)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/file/21mnqlvi/oz88535657v7rbazasyth9x8i/"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_21; reference:url, urlhaus.abuse.ch/url/438705/; classtype:trojan-activity;sid:81301805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (436727)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/statement/ul397wfyb/"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_19; reference:url, urlhaus.abuse.ch/url/436727/; classtype:trojan-activity;sid:81299827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (434592)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/closed_957176_mxqsdoj6a4iz/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_17; reference:url, urlhaus.abuse.ch/url/434592/; classtype:trojan-activity;sid:81297692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (434320)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/hl8-8w4cs-6325/"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"reifenquick.de"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2020_08_17; reference:url, urlhaus.abuse.ch/url/434320/; classtype:trojan-activity;sid:81297420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (432117)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/hl8-8w4cs-6325/"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_13; reference:url, urlhaus.abuse.ch/url/432117/; classtype:trojan-activity;sid:81295217; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (426974)"; flow:established,from_client; content:"GET"; http_method; content:"/images/t55prjrdcx/0y8615606244201084438n0kq7whr/"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"seismophonic.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_08_07; reference:url, urlhaus.abuse.ch/url/426974/; classtype:trojan-activity;sid:81290074; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (426390)"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/open-0627720493640-azq24pffjrm/guarded-space/gxkx9t42ra6yf-6x7uyx330389w/"; http_uri; depth:82; isdataat:!1,relative; nocase; content:"www.reifenquick.de"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2020_08_06; reference:url, urlhaus.abuse.ch/url/426390/; classtype:trojan-activity;sid:81289490; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (422458)"; flow:established,from_client; content:"GET"; http_method; content:"/invoice/aog-3515110/"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"lindnerelektroanlagen.de"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2020_07_30; reference:url, urlhaus.abuse.ch/url/422458/; classtype:trojan-activity;sid:81285558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (420521)"; flow:established,from_client; content:"GET"; http_method; content:"/css/parts_service/ly944myw/"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"hitstation.nl"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2020_07_28; reference:url, urlhaus.abuse.ch/url/420521/; classtype:trojan-activity;sid:81283621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (419868)"; flow:established,from_client; content:"GET"; http_method; content:"/paradiselost/statement/s7nr8p8ut/"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"damiancollier.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2020_07_27; reference:url, urlhaus.abuse.ch/url/419868/; classtype:trojan-activity;sid:81282968; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (410755)"; flow:established,from_client; content:"GET"; http_method; content:"/d35ha/processhide/master/bins/processhide32.exe"; http_uri; depth:48; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2020_07_10; reference:url, urlhaus.abuse.ch/url/410755/; classtype:trojan-activity;sid:81273855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (390013)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1am1ztjjhswzwdbvue5tke5mbkwjud0w5"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_06_15; reference:url, urlhaus.abuse.ch/url/390013/; classtype:trojan-activity;sid:81253113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (390009)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1hd7ffgig6btbzuy2_2kds_t4u637qxjn"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_06_15; reference:url, urlhaus.abuse.ch/url/390009/; classtype:trojan-activity;sid:81253109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (366549)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1pyl4hq8sbp5qatm1zz9vmsze1cuy2uzw"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_05_22; reference:url, urlhaus.abuse.ch/url/366549/; classtype:trojan-activity;sid:81229649; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (355363)"; flow:established,from_client; content:"GET"; http_method; content:"/u/0/uc|3f|id=1osjrfvjdy1vblk4fya98jp5jlnk7rutv|7c|26|7c|export=download"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_05_01; reference:url, urlhaus.abuse.ch/url/355363/; classtype:trojan-activity;sid:81218463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (351490)"; flow:established,from_client; content:"GET"; http_method; content:"/uc|3f|export=download|7c|26|7c|id=1nndvq_2_7doyyuqvcvwmory_4lyrplb7"; http_uri; depth:68; isdataat:!1,relative; nocase; content:"drive.google.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_04_26; reference:url, urlhaus.abuse.ch/url/351490/; classtype:trojan-activity;sid:81214590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (322758)"; flow:established,from_client; content:"GET"; http_method; content:"/upload_control/download.blog|3f|fhandle=ymxvzzcxmzyyqgzzns50axn0b3j5lmnvbtovyxr0ywnolzavmtqwmdawmdawmdawlmv4zq%3d%3d|7c|26|7c|filename=crack-pro20.exe"; http_uri; depth:151; isdataat:!1,relative; nocase; content:"cfs5.tistory.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2020_03_08; reference:url, urlhaus.abuse.ch/url/322758/; classtype:trojan-activity;sid:81185858; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (318948)"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2020_02_26; reference:url, urlhaus.abuse.ch/url/318948/; classtype:trojan-activity;sid:81182048; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (318947)"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; depth:78; isdataat:!1,relative; nocase; content:"raw.githubusercontent.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2020_02_26; reference:url, urlhaus.abuse.ch/url/318947/; classtype:trojan-activity;sid:81182047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (308942)"; flow:established,from_client; content:"GET"; http_method; content:"/wordpress/wp-lm9-32/"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"www.chenwangqiao.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2020_02_05; reference:url, urlhaus.abuse.ch/url/308942/; classtype:trojan-activity;sid:81172042; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (306649)"; flow:established,from_client; content:"GET"; http_method; content:"/wordpress/3waa9-ke38h-15/"; http_uri; depth:26; isdataat:!1,relative; nocase; content:"www.chenwangqiao.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2020_02_03; reference:url, urlhaus.abuse.ch/url/306649/; classtype:trojan-activity;sid:81169749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (304070)"; flow:established,from_client; content:"GET"; http_method; content:"/wordpress/file/"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"www.chenwangqiao.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2020_01_31; reference:url, urlhaus.abuse.ch/url/304070/; classtype:trojan-activity;sid:81167170; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (273997)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-snapshots/sites/gxagnw43b99/"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"embalageral.hospedagemdesites.ws"; http_host; depth:32; isdataat:!1,relative; metadata:created_at 2019_12_20; reference:url, urlhaus.abuse.ch/url/273997/; classtype:trojan-activity;sid:81137097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (272221)"; flow:established,from_client; content:"GET"; http_method; content:"/about/lm/5oj0ss1de/"; http_uri; depth:20; isdataat:!1,relative; nocase; content:"dezcom.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2019_12_19; reference:url, urlhaus.abuse.ch/url/272221/; classtype:trojan-activity;sid:81135321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (267913)"; flow:established,from_client; content:"GET"; http_method; content:"/index_soubory/common_sector/external_area/61551354147_t4d0ky73jjywffgy/"; http_uri; depth:72; isdataat:!1,relative; nocase; content:"oknoplastik.sk"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2019_12_12; reference:url, urlhaus.abuse.ch/url/267913/; classtype:trojan-activity;sid:81131013; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (261506)"; flow:established,from_client; content:"GET"; http_method; content:"/images/n.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"31.128.173.853.zhzy999.net31.128.173.853.zhzy999.net"; http_host; depth:52; isdataat:!1,relative; metadata:created_at 2019_11_29; reference:url, urlhaus.abuse.ch/url/261506/; classtype:trojan-activity;sid:81124606; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (254738)"; flow:established,from_client; content:"GET"; http_method; content:"/cvd/dist/fileupload/1571723382710/9.915787746614242.jpg"; http_uri; depth:56; isdataat:!1,relative; nocase; content:"cdn.xiaoduoai.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2019_11_18; reference:url, urlhaus.abuse.ch/url/254738/; classtype:trojan-activity;sid:81117838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (254737)"; flow:established,from_client; content:"GET"; http_method; content:"/cvd/dist/fileupload/1571723350789/0.25579108623802416.jpg"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"cdn.xiaoduoai.com"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2019_11_18; reference:url, urlhaus.abuse.ch/url/254737/; classtype:trojan-activity;sid:81117837; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (240123)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"190.185.119.13"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2019_10_07; reference:url, urlhaus.abuse.ch/url/240123/; classtype:trojan-activity;sid:81103223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (240036)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"178.151.143.2"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_10_07; reference:url, urlhaus.abuse.ch/url/240036/; classtype:trojan-activity;sid:81103136; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (239019)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"36.66.139.36"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2019_10_06; reference:url, urlhaus.abuse.ch/url/239019/; classtype:trojan-activity;sid:81102119; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (238008)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"190.12.99.194"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_10_05; reference:url, urlhaus.abuse.ch/url/238008/; classtype:trojan-activity;sid:81101108; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (237890)"; flow:established,from_client; content:"GET"; http_method; content:"/.i"; http_uri; depth:3; isdataat:!1,relative; nocase; content:"185.12.78.161"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_10_05; reference:url, urlhaus.abuse.ch/url/237890/; classtype:trojan-activity;sid:81100990; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222263)"; flow:established,from_client; content:"GET"; http_method; content:"/keygen.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"www.konsor.ru"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_08_04; reference:url, urlhaus.abuse.ch/url/222263/; classtype:trojan-activity;sid:81085363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222259)"; flow:established,from_client; content:"GET"; http_method; content:"/keygen.exe"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"konsor.ru"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2019_08_04; reference:url, urlhaus.abuse.ch/url/222259/; classtype:trojan-activity;sid:81085359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222056)"; flow:established,from_client; content:"GET"; http_method; content:"/kaobeitu/news/v1.0.7.31/news_01.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"download.kaobeitu.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2019_08_04; reference:url, urlhaus.abuse.ch/url/222056/; classtype:trojan-activity;sid:81085156; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (222026)"; flow:established,from_client; content:"GET"; http_method; content:"/kaobeitu/mini/v1.0.7.16/mini_04.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"download.kaobeitu.com"; http_host; depth:21; isdataat:!1,relative; metadata:created_at 2019_08_03; reference:url, urlhaus.abuse.ch/url/222026/; classtype:trojan-activity;sid:81085126; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (221598)"; flow:established,from_client; content:"GET"; http_method; content:"/kszip/mini/v1.0.7.31/mini_04.exe"; http_uri; depth:33; isdataat:!1,relative; nocase; content:"download.pdf00.cn"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2019_08_01; reference:url, urlhaus.abuse.ch/url/221598/; classtype:trojan-activity;sid:81084698; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (221595)"; flow:established,from_client; content:"GET"; http_method; content:"/kszip/news2/v1.0.7.31/news2_02.exe"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"download.pdf00.cn"; http_host; depth:17; isdataat:!1,relative; metadata:created_at 2019_08_01; reference:url, urlhaus.abuse.ch/url/221595/; classtype:trojan-activity;sid:81084695; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (220541)"; flow:established,from_client; content:"GET"; http_method; content:"/25072019_0963.xls"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"fakers.co.jp"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2019_07_29; reference:url, urlhaus.abuse.ch/url/220541/; classtype:trojan-activity;sid:81083641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (219275)"; flow:established,from_client; content:"GET"; http_method; content:"/0996938c001/6e8a2a4f-40ac-464f-9a70-7c67f0a0da19.pdf"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"files.constantcontact.com"; http_host; depth:25; isdataat:!1,relative; metadata:created_at 2019_07_24; reference:url, urlhaus.abuse.ch/url/219275/; classtype:trojan-activity;sid:81082375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (217486)"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"codeload.github.com"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2019_07_17; reference:url, urlhaus.abuse.ch/url/217486/; classtype:trojan-activity;sid:81080586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (215077)"; flow:established,from_client; content:"GET"; http_method; content:"/doumai/news2/v1.0.7.01/news2_01.exe"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"download.doumaibiji.cn"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2019_07_06; reference:url, urlhaus.abuse.ch/url/215077/; classtype:trojan-activity;sid:81078177; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (210541)"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; depth:7; isdataat:!1,relative; nocase; content:"indonesias.me"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_06_20; reference:url, urlhaus.abuse.ch/url/210541/; classtype:trojan-activity;sid:81073641; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (210525)"; flow:established,from_client; content:"GET"; http_method; content:"/20.06.2019_130.22.doc"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"fakers.co.jp"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2019_06_20; reference:url, urlhaus.abuse.ch/url/210525/; classtype:trojan-activity;sid:81073625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (210524)"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"indonesias.me"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_06_20; reference:url, urlhaus.abuse.ch/url/210524/; classtype:trojan-activity;sid:81073624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (208009)"; flow:established,from_client; content:"GET"; http_method; content:"/domains/updateagent/application%20files/upagent.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"old.bullydog.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_06_12; reference:url, urlhaus.abuse.ch/url/208009/; classtype:trojan-activity;sid:81071109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (203280)"; flow:established,from_client; content:"GET"; http_method; content:"/download/qt51crk.exe"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"www.hseda.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_05_29; reference:url, urlhaus.abuse.ch/url/203280/; classtype:trojan-activity;sid:81066380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (202114)"; flow:established,from_client; content:"GET"; http_method; content:"/screenmate/cute/sm1302.zip"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"www.starcountry.net"; http_host; depth:19; isdataat:!1,relative; metadata:created_at 2019_05_26; reference:url, urlhaus.abuse.ch/url/202114/; classtype:trojan-activity;sid:81065214; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (201513)"; flow:established,from_client; content:"GET"; http_method; content:"/wj1bsetup.exe"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"dl.dzqzd.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2019_05_24; reference:url, urlhaus.abuse.ch/url/201513/; classtype:trojan-activity;sid:81064613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (199446)"; flow:established,from_client; content:"GET"; http_method; content:"/cd/81/ddq7kprp_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_05_21; reference:url, urlhaus.abuse.ch/url/199446/; classtype:trojan-activity;sid:81062546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (192171)"; flow:established,from_client; content:"GET"; http_method; content:"/2d/da/zg72nmjz_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_05_07; reference:url, urlhaus.abuse.ch/url/192171/; classtype:trojan-activity;sid:81055271; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (192166)"; flow:established,from_client; content:"GET"; http_method; content:"/1b/a6/9pjo30dk_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_05_07; reference:url, urlhaus.abuse.ch/url/192166/; classtype:trojan-activity;sid:81055266; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (191095)"; flow:established,from_client; content:"GET"; http_method; content:"/images/n.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"3.zhzy999.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_05_06; reference:url, urlhaus.abuse.ch/url/191095/; classtype:trojan-activity;sid:81054195; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (186282)"; flow:established,from_client; content:"GET"; http_method; content:"/pub/1003b/patch/patch_data/patch_0.3300/1003b.exe"; http_uri; depth:50; isdataat:!1,relative; nocase; content:"dl.1003b.56a.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_04_27; reference:url, urlhaus.abuse.ch/url/186282/; classtype:trojan-activity;sid:81049382; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (182491)"; flow:established,from_client; content:"GET"; http_method; content:"/images/m.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"dfd.zhzy999.net"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2019_04_23; reference:url, urlhaus.abuse.ch/url/182491/; classtype:trojan-activity;sid:81045591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (176091)"; flow:established,from_client; content:"GET"; http_method; content:"/templates/theme261/css/msg.jpg"; http_uri; depth:31; isdataat:!1,relative; nocase; content:"sk-comtel.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_04_12; reference:url, urlhaus.abuse.ch/url/176091/; classtype:trojan-activity;sid:81039191; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (175833)"; flow:established,from_client; content:"GET"; http_method; content:"/templates/theme261/html/com_contact/category/hp.gf"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"sk-comtel.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_04_11; reference:url, urlhaus.abuse.ch/url/175833/; classtype:trojan-activity;sid:81038933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (173380)"; flow:established,from_client; content:"GET"; http_method; content:"/programas1/uldqi-i7q4vmdrqzvbbg_qjuhgzkb-vr2/"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"aftelecom.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_04_08; reference:url, urlhaus.abuse.ch/url/173380/; classtype:trojan-activity;sid:81036480; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (165554)"; flow:established,from_client; content:"GET"; http_method; content:"/secure.myacc.resourses.com/"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2019_03_25; reference:url, urlhaus.abuse.ch/url/165554/; classtype:trojan-activity;sid:81028654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (165504)"; flow:established,from_client; content:"GET"; http_method; content:"/i203611254b019514581.zip"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"programandojuntos.us.tempcloudsite.com"; http_host; depth:38; isdataat:!1,relative; metadata:created_at 2019_03_25; reference:url, urlhaus.abuse.ch/url/165504/; classtype:trojan-activity;sid:81028604; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (164277)"; flow:established,from_client; content:"GET"; http_method; content:"/corporation/new_invoice/1033530/hijmq-jo_uqgwdlyf-8e/"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2019_03_22; reference:url, urlhaus.abuse.ch/url/164277/; classtype:trojan-activity;sid:81027377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (162770)"; flow:established,from_client; content:"GET"; http_method; content:"/artluz/produtos/sendincsec/support/sec/en_en/03-2019/"; http_uri; depth:54; isdataat:!1,relative; nocase; content:"alarmline.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_03_20; reference:url, urlhaus.abuse.ch/url/162770/; classtype:trojan-activity;sid:81025870; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (161757)"; flow:established,from_client; content:"GET"; http_method; content:"/tomatoleizhutizy/tomatoleizhutizy.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"softdl2.360tpcdn.com"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2019_03_19; reference:url, urlhaus.abuse.ch/url/161757/; classtype:trojan-activity;sid:81024857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (161756)"; flow:established,from_client; content:"GET"; http_method; content:"/images/n.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"3.zhzy999.net3.zhzy999.net"; http_host; depth:26; isdataat:!1,relative; metadata:created_at 2019_03_19; reference:url, urlhaus.abuse.ch/url/161756/; classtype:trojan-activity;sid:81024856; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (157610)"; flow:established,from_client; content:"GET"; http_method; content:"/stats/f06bn-kgh24-ncoviajp/"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2019_03_12; reference:url, urlhaus.abuse.ch/url/157610/; classtype:trojan-activity;sid:81020710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (156866)"; flow:established,from_client; content:"GET"; http_method; content:"/9e/ff/ila2jh9p_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_03_12; reference:url, urlhaus.abuse.ch/url/156866/; classtype:trojan-activity;sid:81019966; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (156867)"; flow:established,from_client; content:"GET"; http_method; content:"/ce/60/rw99spa3_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_03_12; reference:url, urlhaus.abuse.ch/url/156867/; classtype:trojan-activity;sid:81019967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (155567)"; flow:established,from_client; content:"GET"; http_method; content:"/rawabijob.hta"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"local-update.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_03_10; reference:url, urlhaus.abuse.ch/url/155567/; classtype:trojan-activity;sid:81018667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (154627)"; flow:established,from_client; content:"GET"; http_method; content:"/za.ebali"; http_uri; depth:9; isdataat:!1,relative; nocase; content:"mitreart.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2019_03_07; reference:url, urlhaus.abuse.ch/url/154627/; classtype:trojan-activity;sid:81017727; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (148872)"; flow:established,from_client; content:"GET"; http_method; content:"/86/e2/nuflpuwf_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_27; reference:url, urlhaus.abuse.ch/url/148872/; classtype:trojan-activity;sid:81011972; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (148857)"; flow:established,from_client; content:"GET"; http_method; content:"/ff/22/6nkpot2i_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_27; reference:url, urlhaus.abuse.ch/url/148857/; classtype:trojan-activity;sid:81011957; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (143333)"; flow:established,from_client; content:"GET"; http_method; content:"/css/out-1773725897.hta"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"globalbank.us"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_02_23; reference:url, urlhaus.abuse.ch/url/143333/; classtype:trojan-activity;sid:81006433; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (143301)"; flow:established,from_client; content:"GET"; http_method; content:"/pistacchietto/win-python-backdoor/raw/master/win.bat"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"github.com"; http_host; depth:10; isdataat:!1,relative; metadata:created_at 2019_02_23; reference:url, urlhaus.abuse.ch/url/143301/; classtype:trojan-activity;sid:81006401; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (140156)"; flow:established,from_client; content:"GET"; http_method; content:"/1465810408079_502.exe"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"static.topxgun.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_19; reference:url, urlhaus.abuse.ch/url/140156/; classtype:trojan-activity;sid:81003256; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (133387)"; flow:established,from_client; content:"GET"; http_method; content:"/34/60/1zc8bevk_o.png"; http_uri; depth:21; isdataat:!1,relative; nocase; content:"images2.imgbox.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_18; reference:url, urlhaus.abuse.ch/url/133387/; classtype:trojan-activity;sid:80996487; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (121029)"; flow:established,from_client; content:"GET"; http_method; content:"/active/pcclear_eng_mini.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"down.pcclear.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_02_10; reference:url, urlhaus.abuse.ch/url/121029/; classtype:trojan-activity;sid:80984129; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (120929)"; flow:established,from_client; content:"GET"; http_method; content:"/images/m.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"w.zhzy999.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2019_02_10; reference:url, urlhaus.abuse.ch/url/120929/; classtype:trojan-activity;sid:80984029; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (115233)"; flow:established,from_client; content:"GET"; http_method; content:"/files/sanghyun-guest.exe"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"sanghyun.nfile.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_01; reference:url, urlhaus.abuse.ch/url/115233/; classtype:trojan-activity;sid:80978333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (115231)"; flow:established,from_client; content:"GET"; http_method; content:"/files/sanghyun.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"sanghyun.nfile.net"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_02_01; reference:url, urlhaus.abuse.ch/url/115231/; classtype:trojan-activity;sid:80978331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112779)"; flow:established,from_client; content:"GET"; http_method; content:"/files/update.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"sg123.net"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112779/; classtype:trojan-activity;sid:80975879; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112648)"; flow:established,from_client; content:"GET"; http_method; content:"/files/install.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"sg123.net"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112648/; classtype:trojan-activity;sid:80975748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112647)"; flow:established,from_client; content:"GET"; http_method; content:"/files/install.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"igra123.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112647/; classtype:trojan-activity;sid:80975747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (112642)"; flow:established,from_client; content:"GET"; http_method; content:"/files/update.exe"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"igra123.com"; http_host; depth:11; isdataat:!1,relative; metadata:created_at 2019_01_29; reference:url, urlhaus.abuse.ch/url/112642/; classtype:trojan-activity;sid:80975742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (111691)"; flow:established,from_client; content:"GET"; http_method; content:"/files/haeum.exe"; http_uri; depth:16; isdataat:!1,relative; nocase; content:"haeum.nfile.net"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2019_01_28; reference:url, urlhaus.abuse.ch/url/111691/; classtype:trojan-activity;sid:80974791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (110132)"; flow:established,from_client; content:"GET"; http_method; content:"/gcld/updates_tw/gcmgr_tw.exe"; http_uri; depth:29; isdataat:!1,relative; nocase; content:"static.ilclock.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2019_01_25; reference:url, urlhaus.abuse.ch/url/110132/; classtype:trojan-activity;sid:80973232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (109220)"; flow:established,from_client; content:"GET"; http_method; content:"/de_de/tejqsyf3366492/ger/rechnungszahlung/"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"blogs.sokun.jp"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2019_01_24; reference:url, urlhaus.abuse.ch/url/109220/; classtype:trojan-activity;sid:80972320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (108283)"; flow:established,from_client; content:"GET"; http_method; content:"/bigfile/v1/urls/d/4qnwtdd-4xsuuy1xlrmzcibqjfu/ihdzyo55cus7ds4lmmkxpa"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"attach.mail.daum.net"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2019_01_23; reference:url, urlhaus.abuse.ch/url/108283/; classtype:trojan-activity;sid:80971383; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106006)"; flow:established,from_client; content:"GET"; http_method; content:"/qcoin/qcoin128.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106006/; classtype:trojan-activity;sid:80969106; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106003)"; flow:established,from_client; content:"GET"; http_method; content:"/qcoin/qcoin133.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106003/; classtype:trojan-activity;sid:80969103; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (106002)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd156.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/106002/; classtype:trojan-activity;sid:80969102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105999)"; flow:established,from_client; content:"GET"; http_method; content:"/qcoin/qcoin142.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105999/; classtype:trojan-activity;sid:80969099; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105998)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd124.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105998/; classtype:trojan-activity;sid:80969098; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105997)"; flow:established,from_client; content:"GET"; http_method; content:"/qcoin/qcoin141.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105997/; classtype:trojan-activity;sid:80969097; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105996)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd127.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105996/; classtype:trojan-activity;sid:80969096; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105992)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd145.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105992/; classtype:trojan-activity;sid:80969092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105991)"; flow:established,from_client; content:"GET"; http_method; content:"/qcoin/qcoin140.exe"; http_uri; depth:19; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105991/; classtype:trojan-activity;sid:80969091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105988)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd144.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105988/; classtype:trojan-activity;sid:80969088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105985)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd136.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105985/; classtype:trojan-activity;sid:80969085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105975)"; flow:established,from_client; content:"GET"; http_method; content:"/jd/jd137.exe"; http_uri; depth:13; isdataat:!1,relative; nocase; content:"cdn-10049480.file.myqcloud.com"; http_host; depth:30; isdataat:!1,relative; metadata:created_at 2019_01_19; reference:url, urlhaus.abuse.ch/url/105975/; classtype:trojan-activity;sid:80969075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105558)"; flow:established,from_client; content:"GET"; http_method; content:"/n/tui/ciqinmishi/6/cqms.exe"; http_uri; depth:28; isdataat:!1,relative; nocase; content:"bundle.kpzip.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2019_01_18; reference:url, urlhaus.abuse.ch/url/105558/; classtype:trojan-activity;sid:80968658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (105407)"; flow:established,from_client; content:"GET"; http_method; content:"/hkhe3fktc/"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"atkcgnew.evgeni7e.beget.tech"; http_host; depth:28; isdataat:!1,relative; metadata:created_at 2019_01_18; reference:url, urlhaus.abuse.ch/url/105407/; classtype:trojan-activity;sid:80968507; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (104016)"; flow:established,from_client; content:"GET"; http_method; content:"/drop/css/obr.hta"; http_uri; depth:17; isdataat:!1,relative; nocase; content:"www.myvcart.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2019_01_16; reference:url, urlhaus.abuse.ch/url/104016/; classtype:trojan-activity;sid:80967116; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (102706)"; flow:established,from_client; content:"GET"; http_method; content:"/autoguarder/autoguarder_2.3.7.350.exe"; http_uri; depth:38; isdataat:!1,relative; nocase; content:"softdl4.360.cn"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2019_01_12; reference:url, urlhaus.abuse.ch/url/102706/; classtype:trojan-activity;sid:80965806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (102548)"; flow:established,from_client; content:"GET"; http_method; content:"/doumai/tips/v1.0.1.11/tips_01.exe"; http_uri; depth:34; isdataat:!1,relative; nocase; content:"download.doumaibiji.cn"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2019_01_11; reference:url, urlhaus.abuse.ch/url/102548/; classtype:trojan-activity;sid:80965648; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (102545)"; flow:established,from_client; content:"GET"; http_method; content:"/doumai/fmt/v1.0.1.11/fmt_01.exe"; http_uri; depth:32; isdataat:!1,relative; nocase; content:"download.doumaibiji.cn"; http_host; depth:22; isdataat:!1,relative; metadata:created_at 2019_01_11; reference:url, urlhaus.abuse.ch/url/102545/; classtype:trojan-activity;sid:80965645; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (98628)"; flow:established,from_client; content:"GET"; http_method; content:"/6nqq.js"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"www.hostingcloud.science"; http_host; depth:24; isdataat:!1,relative; metadata:created_at 2018_12_21; reference:url, urlhaus.abuse.ch/url/98628/; classtype:trojan-activity;sid:80961728; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (96625)"; flow:established,from_client; content:"GET"; http_method; content:"/iuia-qgkdtq2rfbxd7z_ljiaengvq-4cy/"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"www.ardguisser.com"; http_host; depth:18; isdataat:!1,relative; metadata:created_at 2018_12_17; reference:url, urlhaus.abuse.ch/url/96625/; classtype:trojan-activity;sid:80959725; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95728)"; flow:established,from_client; content:"GET"; http_method; content:"/game/download/zip/waigua/shiqi/2003/06/20030620.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"veryboys.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95728/; classtype:trojan-activity;sid:80958828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95727)"; flow:established,from_client; content:"GET"; http_method; content:"/game/download/zip/waigua/mir2/2003/05/200305252.exe"; http_uri; depth:52; isdataat:!1,relative; nocase; content:"veryboys.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95727/; classtype:trojan-activity;sid:80958827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95726)"; flow:established,from_client; content:"GET"; http_method; content:"/game/download/zip/waigua/mu/2003/07/20030721.exe"; http_uri; depth:49; isdataat:!1,relative; nocase; content:"veryboys.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95726/; classtype:trojan-activity;sid:80958826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95634)"; flow:established,from_client; content:"GET"; http_method; content:"/soft/uploadfile/guochang/setup_tvplayer.zip"; http_uri; depth:44; isdataat:!1,relative; nocase; content:"www.okhan.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95634/; classtype:trojan-activity;sid:80958734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95633)"; flow:established,from_client; content:"GET"; http_method; content:"/soft/uploadfile/youxi/okhan.net-2wn.rar"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"www.okhan.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95633/; classtype:trojan-activity;sid:80958733; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95550)"; flow:established,from_client; content:"GET"; http_method; content:"/game/download/zip/waigua/mir2/2003/05/20030520.exe"; http_uri; depth:51; isdataat:!1,relative; nocase; content:"veryboys.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95550/; classtype:trojan-activity;sid:80958650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95509)"; flow:established,from_client; content:"GET"; http_method; content:"/soft/uploadfile/anquan/pjbingdianhuanyuan.rar"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"www.okhan.net"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_15; reference:url, urlhaus.abuse.ch/url/95509/; classtype:trojan-activity;sid:80958609; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95209)"; flow:established,from_client; content:"GET"; http_method; content:"/us/information/122018/"; http_uri; depth:23; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_12_14; reference:url, urlhaus.abuse.ch/url/95209/; classtype:trojan-activity;sid:80958309; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (95078)"; flow:established,from_client; content:"GET"; http_method; content:"/us/information/122018"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_12_14; reference:url, urlhaus.abuse.ch/url/95078/; classtype:trojan-activity;sid:80958178; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (94279)"; flow:established,from_client; content:"GET"; http_method; content:"/upload/20140812/14078161556897.rar"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"static.3001.net"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_12_13; reference:url, urlhaus.abuse.ch/url/94279/; classtype:trojan-activity;sid:80957379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (94199)"; flow:established,from_client; content:"GET"; http_method; content:"/soft/uploadfile/youxi/okhan.net-2wn.rar"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"okhan.net"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2018_12_13; reference:url, urlhaus.abuse.ch/url/94199/; classtype:trojan-activity;sid:80957299; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (94194)"; flow:established,from_client; content:"GET"; http_method; content:"/soft/uploadfile/anquan/pjbingdianhuanyuan.rar"; http_uri; depth:46; isdataat:!1,relative; nocase; content:"okhan.net"; http_host; depth:9; isdataat:!1,relative; metadata:created_at 2018_12_13; reference:url, urlhaus.abuse.ch/url/94194/; classtype:trojan-activity;sid:80957294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (92354)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/3"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"itssprout.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_10; reference:url, urlhaus.abuse.ch/url/92354/; classtype:trojan-activity;sid:80955454; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (92351)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/2"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"itssprout.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_10; reference:url, urlhaus.abuse.ch/url/92351/; classtype:trojan-activity;sid:80955451; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (92344)"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1"; http_uri; depth:14; isdataat:!1,relative; nocase; content:"itssprout.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_12_10; reference:url, urlhaus.abuse.ch/url/92344/; classtype:trojan-activity;sid:80955444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (86730)"; flow:established,from_client; content:"GET"; http_method; content:"/076360tad/oamo/business/"; http_uri; depth:25; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_11_29; reference:url, urlhaus.abuse.ch/url/86730/; classtype:trojan-activity;sid:80949830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (86203)"; flow:established,from_client; content:"GET"; http_method; content:"/076360tad/oamo/business"; http_uri; depth:24; isdataat:!1,relative; nocase; content:"flyingmutts.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_11_28; reference:url, urlhaus.abuse.ch/url/86203/; classtype:trojan-activity;sid:80949303; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85967)"; flow:established,from_client; content:"GET"; http_method; content:"/task/2009-06/29/106045/rc1veeex.rar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"p3.zbjimg.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_28; reference:url, urlhaus.abuse.ch/url/85967/; classtype:trojan-activity;sid:80949067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85901)"; flow:established,from_client; content:"GET"; http_method; content:"/tekiwanatain/installer.rar"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"users.atw.hu"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_11_28; reference:url, urlhaus.abuse.ch/url/85901/; classtype:trojan-activity;sid:80949001; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85881)"; flow:established,from_client; content:"GET"; http_method; content:"/task/2009-06/29/106045/5fg9yjwr.rar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"p3.zbjimg.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85881/; classtype:trojan-activity;sid:80948981; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85879)"; flow:established,from_client; content:"GET"; http_method; content:"/task/2009-06/29/106045/a9to40e7.rar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"p3.zbjimg.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85879/; classtype:trojan-activity;sid:80948979; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85878)"; flow:established,from_client; content:"GET"; http_method; content:"/task/2009-06/29/106045/e6i8pdc0.rar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"p3.zbjimg.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85878/; classtype:trojan-activity;sid:80948978; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85877)"; flow:established,from_client; content:"GET"; http_method; content:"/task/2009-07/28/117228/4wtjdjio.rar"; http_uri; depth:36; isdataat:!1,relative; nocase; content:"p3.zbjimg.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85877/; classtype:trojan-activity;sid:80948977; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85874)"; flow:established,from_client; content:"GET"; http_method; content:"/task/2009-06/06/98428/07c9mfhe.zip"; http_uri; depth:35; isdataat:!1,relative; nocase; content:"p3.zbjimg.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_11_27; reference:url, urlhaus.abuse.ch/url/85874/; classtype:trojan-activity;sid:80948974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (85179)"; flow:established,from_client; content:"GET"; http_method; content:"/73321alnwyy/payroll/business/"; http_uri; depth:30; isdataat:!1,relative; nocase; content:"malupieng.com.br"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2018_11_26; reference:url, urlhaus.abuse.ch/url/85179/; classtype:trojan-activity;sid:80948279; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (82382)"; flow:established,from_client; content:"GET"; http_method; content:"/download/%e8%99%9a%e6%8b%9f%e5%85%89%e9%a9%b1_11@10349.exe"; http_uri; depth:59; isdataat:!1,relative; nocase; content:"cl.ssouy.com"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_11_19; reference:url, urlhaus.abuse.ch/url/82382/; classtype:trojan-activity;sid:80945482; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (79342)"; flow:established,from_client; content:"GET"; http_method; content:"/bigfile/v1/urls/d/1gpusd8uwnakepjjehixnayfekq/kbdjubux_j-nvjot1z-mdw"; http_uri; depth:69; isdataat:!1,relative; nocase; content:"attach.mail.daum.net"; http_host; depth:20; isdataat:!1,relative; metadata:created_at 2018_11_13; reference:url, urlhaus.abuse.ch/url/79342/; classtype:trojan-activity;sid:80942442; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (71185)"; flow:established,from_client; content:"GET"; http_method; content:"/nykol16/kepek.exe"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"users.atw.hu"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_26; reference:url, urlhaus.abuse.ch/url/71185/; classtype:trojan-activity;sid:80934285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (68419)"; flow:established,from_client; content:"GET"; http_method; content:"/icon/n.api"; http_uri; depth:11; isdataat:!1,relative; nocase; content:"api.wipmania.net"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_16; reference:url, urlhaus.abuse.ch/url/68419/; classtype:trojan-activity;sid:80931519; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67517)"; flow:established,from_client; content:"GET"; http_method; content:"/bbs/attachment/forum/201106/03/153053ki5kbisfbc8316i3.rar"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"attach.66rpg.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_13; reference:url, urlhaus.abuse.ch/url/67517/; classtype:trojan-activity;sid:80930617; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67516)"; flow:established,from_client; content:"GET"; http_method; content:"/bbs/attachment/forum/201403/02/104411hqzp4rto4ro94qpz.rar"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"attach.66rpg.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_13; reference:url, urlhaus.abuse.ch/url/67516/; classtype:trojan-activity;sid:80930616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67474)"; flow:established,from_client; content:"GET"; http_method; content:"/bbs/attachment/forum/201108/22/215335elkpi66piz56eii9.zip"; http_uri; depth:58; isdataat:!1,relative; nocase; content:"attach.66rpg.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2018_10_12; reference:url, urlhaus.abuse.ch/url/67474/; classtype:trojan-activity;sid:80930574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (67439)"; flow:established,from_client; content:"GET"; http_method; content:"/zoolatogato/xruhbmzvlaghfnqcerrv.exe"; http_uri; depth:37; isdataat:!1,relative; nocase; content:"users.atw.hu"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_12; reference:url, urlhaus.abuse.ch/url/67439/; classtype:trojan-activity;sid:80930539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (66694)"; flow:established,from_client; content:"GET"; http_method; content:"/autoup/client/aqclient.exe"; http_uri; depth:27; isdataat:!1,relative; nocase; content:"pay.aqiu6.com"; http_host; depth:13; isdataat:!1,relative; metadata:created_at 2018_10_11; reference:url, urlhaus.abuse.ch/url/66694/; classtype:trojan-activity;sid:80929794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (66274)"; flow:established,from_client; content:"GET"; http_method; content:"/toneraruhaz/wp-admin/network/installer.rar"; http_uri; depth:43; isdataat:!1,relative; nocase; content:"users.atw.hu"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_09; reference:url, urlhaus.abuse.ch/url/66274/; classtype:trojan-activity;sid:80929374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (66164)"; flow:established,from_client; content:"GET"; http_method; content:"/fvlmodell/letoltes/files/scalecalc.exe"; http_uri; depth:39; isdataat:!1,relative; nocase; content:"users.atw.hu"; http_host; depth:12; isdataat:!1,relative; metadata:created_at 2018_10_09; reference:url, urlhaus.abuse.ch/url/66164/; classtype:trojan-activity;sid:80929264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (59247)"; flow:established,from_client; content:"GET"; http_method; content:"/vqd0d5/"; http_uri; depth:8; isdataat:!1,relative; nocase; content:"robertrowe.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2018_09_23; reference:url, urlhaus.abuse.ch/url/59247/; classtype:trojan-activity;sid:80922347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (57935)"; flow:established,from_client; content:"GET"; http_method; content:"/factures-09-2018/"; http_uri; depth:18; isdataat:!1,relative; nocase; content:"hasalltalent.com"; http_host; depth:16; isdataat:!1,relative; metadata:created_at 2018_09_19; reference:url, urlhaus.abuse.ch/url/57935/; classtype:trojan-activity;sid:80921035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (38013)"; flow:established,from_client; content:"GET"; http_method; content:"/s/dl/gxfqfem5m813nva/firefox_67.3.39.js"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_08_02; reference:url, urlhaus.abuse.ch/url/38013/; classtype:trojan-activity;sid:80901113; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (38011)"; flow:established,from_client; content:"GET"; http_method; content:"/s/dl/dqrsgzlf8jeefw0/firefox_67.3.45.js"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_08_02; reference:url, urlhaus.abuse.ch/url/38011/; classtype:trojan-activity;sid:80901111; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (38009)"; flow:established,from_client; content:"GET"; http_method; content:"/s/dl/g4is5u674v6l2yy/firefox_67.3.16.js"; http_uri; depth:40; isdataat:!1,relative; nocase; content:"www.dropbox.com"; http_host; depth:15; isdataat:!1,relative; metadata:created_at 2018_08_02; reference:url, urlhaus.abuse.ch/url/38009/; classtype:trojan-activity;sid:80901109; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (16630)"; flow:established,from_client; content:"GET"; http_method; content:"/doc/past-due-invoice/"; http_uri; depth:22; isdataat:!1,relative; nocase; content:"robertrowe.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2018_06_07; reference:url, urlhaus.abuse.ch/url/16630/; classtype:trojan-activity;sid:80879730; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"URLhaus Known malware download URL detected (15711)"; flow:established,from_client; content:"GET"; http_method; content:"/status/auditor-of-state-notification-of-eft-deposit/"; http_uri; depth:53; isdataat:!1,relative; nocase; content:"robertrowe.com"; http_host; depth:14; isdataat:!1,relative; metadata:created_at 2018_06_05; reference:url, urlhaus.abuse.ch/url/15711/; classtype:trojan-activity;sid:80878811; rev:1;) # Number of entries: 34132